Assistance pour la conformité réglementaire dans Cloud Trace

Ce document décrit les fonctionnalités, les configurations et les API de Cloud Trace qui correspondent aux contrôles des packages de contrôles compatibles. Ce document suppose que vous utilisez Assured Workloads.

Périmètre de données pour l'ITAR

Services compatibles

Le tableau suivant liste les API et les versions Cloud Trace qui répondent aux exigences du périmètre de données pour l'ITAR.

Service Version État
cloudtrace.googleapis.com v1 COMPATIBLE
cloudtrace.googleapis.com v2 COMPATIBLE
cloudtrace.googleapis.com v2beta1 COMPATIBLE

Régions compatibles avec la conformité

Cloud Trace est disponible pour le périmètre de données pour l'ITAR dans les régions suivantes : Google Cloud

  • us-central1
  • us-central2
  • us-east1
  • us-east4
  • us-east5
  • us-south1
  • us-west1
  • us-west2
  • us-west3
  • us-west4

Champs d'API pour les données sensibles

Ressource : aucune ressource

Le tableau suivant spécifie les ressources et les champs de l'API conçus pour gérer les données protégées par le périmètre de données pour l'ITAR.

Méthode API Champs protégés

Service : cloudtrace.googleapis.com

API REST : GET /v1/projects/{project_id}/traces

Méthodes RPC :

  • google.devtools.cloudtrace.v1.TraceService.ListTraces
  • filter

Service : cloudtrace.googleapis.com

API REST : PATCH /v1/projects/{project_id}/traces

Méthodes RPC :

  • google.devtools.cloudtrace.v1.TraceService.PatchTraces
  • traces.traces.spans.labels.key
  • traces.traces.spans.labels.value

Service : cloudtrace.googleapis.com

API REST : POST /v2/{name=projects/*}/traces:batchWrite

Méthodes RPC :

  • google.devtools.cloudtrace.v2.TraceService.BatchWriteSpans
  • spans.attributes.attributeMap.key
  • spans.attributes.attributeMap.value.boolValue
  • spans.attributes.attributeMap.value.intValue
  • spans.attributes.attributeMap.value.stringValue.truncatedByteCount
  • spans.attributes.attributeMap.value.stringValue.value
  • spans.links.link.attributes.attributeMap.key
  • spans.links.link.attributes.attributeMap.value.boolValue
  • spans.links.link.attributes.attributeMap.value.intValue
  • spans.links.link.attributes.attributeMap.value.stringValue.truncatedByteCount
  • spans.links.link.attributes.attributeMap.value.stringValue.value
  • spans.stackTrace.stackFrames.frame.functionName.truncatedByteCount
  • spans.stackTrace.stackFrames.frame.functionName.value
  • spans.stackTrace.stackFrames.frame.originalFunctionName.truncatedByteCount
  • spans.stackTrace.stackFrames.frame.originalFunctionName.value
  • spans.status.code
  • spans.status.details.typeUrl
  • spans.status.details.value
  • spans.status.message
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap.key
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap.value.boolValue
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap.value.intValue
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap.value.stringValue.truncatedByteCount
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap.value.stringValue.value
  • spans.timeEvents.timeEvent.annotation.description.truncatedByteCount
  • spans.timeEvents.timeEvent.annotation.description.value

Ressource : cloudtrace.googleapis.com/Span

Le tableau suivant spécifie les ressources et les champs de l'API conçus pour gérer les données protégées par le périmètre de données pour l'ITAR.

Méthode API Champs protégés

Service : cloudtrace.googleapis.com

API REST : POST /v2/{name=projects/*/traces/*/spans/*}

Méthodes RPC :

  • google.devtools.cloudtrace.v2.TraceService.CreateSpan
  • attributes.attributeMap.key
  • attributes.attributeMap.value.boolValue
  • attributes.attributeMap.value.intValue
  • attributes.attributeMap.value.stringValue.truncatedByteCount
  • attributes.attributeMap.value.stringValue.value
  • links.link.attributes.attributeMap.key
  • links.link.attributes.attributeMap.value.boolValue
  • links.link.attributes.attributeMap.value.intValue
  • links.link.attributes.attributeMap.value.stringValue.truncatedByteCount
  • links.link.attributes.attributeMap.value.stringValue.value
  • stackTrace.stackFrames.frame.functionName.truncatedByteCount
  • stackTrace.stackFrames.frame.functionName.value
  • stackTrace.stackFrames.frame.originalFunctionName.truncatedByteCount
  • stackTrace.stackFrames.frame.originalFunctionName.value
  • status.code
  • status.details.typeUrl
  • status.details.value
  • status.message
  • timeEvents.timeEvent.annotation.attributes.attributeMap.key
  • timeEvents.timeEvent.annotation.attributes.attributeMap.value.boolValue
  • timeEvents.timeEvent.annotation.attributes.attributeMap.value.intValue
  • timeEvents.timeEvent.annotation.attributes.attributeMap.value.stringValue.truncatedByteCount
  • timeEvents.timeEvent.annotation.attributes.attributeMap.value.stringValue.value
  • timeEvents.timeEvent.annotation.description.truncatedByteCount
  • timeEvents.timeEvent.annotation.description.value

Champs non destinés aux données sensibles

Le tableau suivant fournit une liste illustrative des catégories de champs et des champs spécifiques qui ne conviennent pas aux informations sensibles. Pour rester conforme, évitez de placer des données protégées dans ces champs. Pour obtenir la liste complète, contactez votre représentant Google Cloud.

Catégorie Champs
Pagination et ordre
  • orderBy
  • pageToken
Identification des projets et des ressources
  • name
  • parent
  • projectId
  • traceSink.name
  • traceSink.outputConfig.destination
  • traceSink.outputConfig.pubsubConfig.openTelemetryFormat.version
Filtrage du champ d'application et des ressources
  • scope.resourceNames
  • scope.traceId
  • traceScope.resourceNames
Affichage et contexte des segments
  • displayName.value
  • spans.displayName.value
  • spans.name
  • traces.traces.spans.name
Informations de compilation de la trace de la pile
  • spans.stackTrace.stackFrames.frame.loadModule.buildId.value
  • stackTrace.stackFrames.frame.loadModule.buildId.value
Informations sur le fichier de trace de la pile
  • spans.stackTrace.stackFrames.frame.fileName.value
  • stackTrace.stackFrames.frame.fileName.value
Informations sur le module de trace de la pile
  • spans.stackTrace.stackFrames.frame.loadModule.module.value
  • stackTrace.stackFrames.frame.loadModule.module.value
Informations sur la version de la trace de la pile
  • spans.stackTrace.stackFrames.frame.sourceVersion.value
  • stackTrace.stackFrames.frame.sourceVersion.value
Détails du champ d'application de Trace
  • traceScope.description
  • traceScope.name
Identifiants spécifiques aux traces
  • spans.parentSpanId
  • spans.spanId
  • traceId
Attributs de convention sémantique OpenTelemetry
  • spans.attributes.attributeMap["cloud.account.id"]
  • spans.attributes.attributeMap["cloud.availability_zone"]
  • spans.attributes.attributeMap["cloud.platform"]
  • spans.attributes.attributeMap["cloud.provider"]
  • spans.attributes.attributeMap["cloud.region"]
  • spans.attributes.attributeMap["cloud.resource_id"]
  • spans.attributes.attributeMap["error.type"]
  • spans.attributes.attributeMap["faas.name"]
  • spans.attributes.attributeMap["gcp.apphub.application.container"]
  • spans.attributes.attributeMap["gcp.apphub.application.id"]
  • spans.attributes.attributeMap["gcp.apphub.application.location"]
  • spans.attributes.attributeMap["gcp.apphub.service.id"]
  • spans.attributes.attributeMap["gcp.apphub.workload.id"]
  • spans.attributes.attributeMap["gcp.cloud_run.job.execution"]
  • spans.attributes.attributeMap["gcp.gce.instance_group_manager.name"]
  • spans.attributes.attributeMap["gcp.gce.instance_group_manager.region"]
  • spans.attributes.attributeMap["gcp.gce.instance_group_manager.zone"]
  • spans.attributes.attributeMap["gcp.project_id"]
  • spans.attributes.attributeMap["gcp.resource.location"]
  • spans.attributes.attributeMap["gcp.resource.name"]
  • spans.attributes.attributeMap["http.response.status.code"]
  • spans.attributes.attributeMap["k8s.cluster.name"]
  • spans.attributes.attributeMap["k8s.cronjob.name"]
  • spans.attributes.attributeMap["k8s.daemonset.name"]
  • spans.attributes.attributeMap["k8s.deployment.name"]
  • spans.attributes.attributeMap["k8s.namespace"]
  • spans.attributes.attributeMap["k8s.statefulset.name"]
  • spans.attributes.attributeMap["rpc.grpc.status_code"]
  • spans.attributes.attributeMap["rpc.system"]
  • spans.links.link.attributes.attributeMap["cloud.account.id"]
  • spans.links.link.attributes.attributeMap["cloud.availability_zone"]
  • spans.links.link.attributes.attributeMap["cloud.platform"]
  • spans.links.link.attributes.attributeMap["cloud.provider"]
  • spans.links.link.attributes.attributeMap["cloud.region"]
  • spans.links.link.attributes.attributeMap["cloud.resource_id"]
  • spans.links.link.attributes.attributeMap["error.type"]
  • spans.links.link.attributes.attributeMap["faas.name"]
  • spans.links.link.attributes.attributeMap["gcp.apphub.application.container"]
  • spans.links.link.attributes.attributeMap["gcp.apphub.application.id"]
  • spans.links.link.attributes.attributeMap["gcp.apphub.application.location"]
  • spans.links.link.attributes.attributeMap["gcp.apphub.service.id"]
  • spans.links.link.attributes.attributeMap["gcp.apphub.workload.id"]
  • spans.links.link.attributes.attributeMap["gcp.cloud_run.job.execution"]
  • spans.links.link.attributes.attributeMap["gcp.gce.instance_group_manager.name"]
  • spans.links.link.attributes.attributeMap["gcp.gce.instance_group_manager.region"]
  • spans.links.link.attributes.attributeMap["gcp.gce.instance_group_manager.zone"]
  • spans.links.link.attributes.attributeMap["gcp.project_id"]
  • spans.links.link.attributes.attributeMap["gcp.resource.location"]
  • spans.links.link.attributes.attributeMap["gcp.resource.name"]
  • spans.links.link.attributes.attributeMap["http.response.status.code"]
  • spans.links.link.attributes.attributeMap["k8s.cluster.name"]
  • spans.links.link.attributes.attributeMap["k8s.cronjob.name"]
  • spans.links.link.attributes.attributeMap["k8s.daemonset.name"]
  • spans.links.link.attributes.attributeMap["k8s.deployment.name"]
  • spans.links.link.attributes.attributeMap["k8s.namespace"]
  • spans.links.link.attributes.attributeMap["k8s.statefulset.name"]
  • spans.links.link.attributes.attributeMap["rpc.grpc.status_code"]
  • spans.links.link.attributes.attributeMap["rpc.system"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.account.id"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.availability_zone"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.platform"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.provider"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.region"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.resource_id"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["error.type"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["faas.name"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.application.container"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.application.id"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.application.location"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.service.id"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.workload.id"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.cloud_run.job.execution"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.gce.instance_group_manager.name"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.gce.instance_group_manager.region"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.gce.instance_group_manager.zone"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.project_id"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.resource.location"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.resource.name"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["http.response.status.code"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.cluster.name"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.cronjob.name"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.daemonset.name"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.deployment.name"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.namespace"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.statefulset.name"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["rpc.grpc.status_code"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["rpc.system"]
  • attributes.attributeMap["cloud.account.id"]
  • attributes.attributeMap["cloud.availability_zone"]
  • attributes.attributeMap["cloud.platform"]
  • attributes.attributeMap["cloud.provider"]
  • attributes.attributeMap["cloud.region"]
  • attributes.attributeMap["cloud.resource_id"]
  • attributes.attributeMap["error.type"]
  • attributes.attributeMap["faas.name"]
  • attributes.attributeMap["gcp.apphub.application.container"]
  • attributes.attributeMap["gcp.apphub.application.id"]
  • attributes.attributeMap["gcp.apphub.application.location"]
  • attributes.attributeMap["gcp.apphub.service.id"]
  • attributes.attributeMap["gcp.apphub.workload.id"]
  • attributes.attributeMap["gcp.cloud_run.job.execution"]
  • attributes.attributeMap["gcp.gce.instance_group_manager.name"]
  • attributes.attributeMap["gcp.gce.instance_group_manager.region"]
  • attributes.attributeMap["gcp.gce.instance_group_manager.zone"]
  • attributes.attributeMap["gcp.project_id"]
  • attributes.attributeMap["gcp.resource.location"]
  • attributes.attributeMap["gcp.resource.name"]
  • attributes.attributeMap["http.response.status.code"]
  • attributes.attributeMap["k8s.cluster.name"]
  • attributes.attributeMap["k8s.cronjob.name"]
  • attributes.attributeMap["k8s.daemonset.name"]
  • attributes.attributeMap["k8s.deployment.name"]
  • attributes.attributeMap["k8s.namespace"]
  • attributes.attributeMap["k8s.statefulset.name"]
  • attributes.attributeMap["rpc.grpc.status_code"]
  • attributes.attributeMap["rpc.system"]
  • links.link.attributes.attributeMap["cloud.account.id"]
  • links.link.attributes.attributeMap["cloud.availability_zone"]
  • links.link.attributes.attributeMap["cloud.platform"]
  • links.link.attributes.attributeMap["cloud.provider"]
  • links.link.attributes.attributeMap["cloud.region"]
  • links.link.attributes.attributeMap["cloud.resource_id"]
  • links.link.attributes.attributeMap["error.type"]
  • links.link.attributes.attributeMap["faas.name"]
  • links.link.attributes.attributeMap["gcp.apphub.application.container"]
  • links.link.attributes.attributeMap["gcp.apphub.application.id"]
  • links.link.attributes.attributeMap["gcp.apphub.application.location"]
  • links.link.attributes.attributeMap["gcp.apphub.service.id"]
  • links.link.attributes.attributeMap["gcp.apphub.workload.id"]
  • links.link.attributes.attributeMap["gcp.cloud_run.job.execution"]
  • links.link.attributes.attributeMap["gcp.gce.instance_group_manager.name"]
  • links.link.attributes.attributeMap["gcp.gce.instance_group_manager.region"]
  • links.link.attributes.attributeMap["gcp.gce.instance_group_manager.zone"]
  • links.link.attributes.attributeMap["gcp.project_id"]
  • links.link.attributes.attributeMap["gcp.resource.location"]
  • links.link.attributes.attributeMap["gcp.resource.name"]
  • links.link.attributes.attributeMap["http.response.status.code"]
  • links.link.attributes.attributeMap["k8s.cluster.name"]
  • links.link.attributes.attributeMap["k8s.cronjob.name"]
  • links.link.attributes.attributeMap["k8s.daemonset.name"]
  • links.link.attributes.attributeMap["k8s.deployment.name"]
  • links.link.attributes.attributeMap["k8s.namespace"]
  • links.link.attributes.attributeMap["k8s.statefulset.name"]
  • links.link.attributes.attributeMap["rpc.grpc.status_code"]
  • links.link.attributes.attributeMap["rpc.system"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.account.id"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.availability_zone"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.platform"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.provider"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.region"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.resource_id"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["error.type"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["faas.name"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.application.container"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.application.id"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.application.location"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.service.id"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.workload.id"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.cloud_run.job.execution"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.gce.instance_group_manager.name"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.gce.instance_group_manager.region"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.gce.instance_group_manager.zone"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.project_id"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.resource.location"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.resource.name"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["http.response.status.code"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.cluster.name"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.cronjob.name"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.daemonset.name"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.deployment.name"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.namespace"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.statefulset.name"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["rpc.grpc.status_code"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["rpc.system"]

Annexe

Les paires clé/valeur dans les champs de carte protégés, qui ont des conventions sémantiques bien établies dans OpenTelemetry, ne sont pas protégées et ne conviennent pas aux informations sensibles :

  • cloud.account.id
  • cloud.availability_zone
  • cloud.platform
  • cloud.provider
  • cloud.region
  • cloud.resource_id
  • error.type
  • faas.name
  • gcp.apphub.application.container
  • gcp.apphub.application.id
  • gcp.apphub.application.location
  • gcp.apphub.service.id
  • gcp.apphub.workload.id
  • gcp.cloud_run.job.execution
  • gcp.gce.instance_group_manager.name
  • gcp.gce.instance_group_manager.region
  • gcp.gce.instance_group_manager.zone
  • gcp.project_id
  • gcp.resource.location
  • gcp.resource.name
  • http.response.status.code
  • k8s.cluster.name
  • k8s.cronjob.name
  • k8s.daemonset.name
  • k8s.deployment.name
  • k8s.namespace
  • k8s.statefulset.name
  • rpc.grpc.status_code
  • rpc.system


Étapes suivantes