Cloud Trace 中的法規支援

本文說明 Cloud Trace 中與支援的控制項套件控制項一致的功能、設定和 API。本文假設您使用的是 Assured Workloads。

ITAR 資料邊界

支援的服務

下表列出符合 ITAR 資料邊界規定的 Cloud Trace API 和版本。

服務 版本 狀態
cloudtrace.googleapis.com v1 支援
cloudtrace.googleapis.com v2 支援
cloudtrace.googleapis.com v2beta1 支援

支援法規遵循的區域

Cloud Trace 適用於下列 Google Cloud 區域的 ITAR 資料邊界:

  • us-central1
  • us-central2
  • us-east1
  • us-east4
  • us-east5
  • us-south1
  • us-west1
  • us-west2
  • us-west3
  • us-west4

機密資料的 API 欄位

資源:沒有資源

下表列出 API 資源和欄位,這些資源和欄位專門用來處理受 ITAR 資料邊界保護的資料。

API 方法 受保護的欄位

服務類型:cloudtrace.googleapis.com

REST API:GET /v1/projects/{project_id}/traces

RPC 方法:

  • google.devtools.cloudtrace.v1.TraceService.ListTraces
  • filter

服務類型:cloudtrace.googleapis.com

REST API:PATCH /v1/projects/{project_id}/traces

RPC 方法:

  • google.devtools.cloudtrace.v1.TraceService.PatchTraces
  • traces.traces.spans.labels.key
  • traces.traces.spans.labels.value

服務類型:cloudtrace.googleapis.com

REST API:POST /v2/{name=projects/*}/traces:batchWrite

RPC 方法:

  • google.devtools.cloudtrace.v2.TraceService.BatchWriteSpans
  • spans.attributes.attributeMap.key
  • spans.attributes.attributeMap.value.boolValue
  • spans.attributes.attributeMap.value.intValue
  • spans.attributes.attributeMap.value.stringValue.truncatedByteCount
  • spans.attributes.attributeMap.value.stringValue.value
  • spans.links.link.attributes.attributeMap.key
  • spans.links.link.attributes.attributeMap.value.boolValue
  • spans.links.link.attributes.attributeMap.value.intValue
  • spans.links.link.attributes.attributeMap.value.stringValue.truncatedByteCount
  • spans.links.link.attributes.attributeMap.value.stringValue.value
  • spans.stackTrace.stackFrames.frame.functionName.truncatedByteCount
  • spans.stackTrace.stackFrames.frame.functionName.value
  • spans.stackTrace.stackFrames.frame.originalFunctionName.truncatedByteCount
  • spans.stackTrace.stackFrames.frame.originalFunctionName.value
  • spans.status.code
  • spans.status.details.typeUrl
  • spans.status.details.value
  • spans.status.message
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap.key
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap.value.boolValue
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap.value.intValue
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap.value.stringValue.truncatedByteCount
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap.value.stringValue.value
  • spans.timeEvents.timeEvent.annotation.description.truncatedByteCount
  • spans.timeEvents.timeEvent.annotation.description.value

資源:cloudtrace.googleapis.com/Span

下表列出 API 資源和欄位,這些資源和欄位專門用來處理受 ITAR 資料邊界保護的資料。

API 方法 受保護的欄位

服務類型:cloudtrace.googleapis.com

REST API:POST /v2/{name=projects/*/traces/*/spans/*}

RPC 方法:

  • google.devtools.cloudtrace.v2.TraceService.CreateSpan
  • attributes.attributeMap.key
  • attributes.attributeMap.value.boolValue
  • attributes.attributeMap.value.intValue
  • attributes.attributeMap.value.stringValue.truncatedByteCount
  • attributes.attributeMap.value.stringValue.value
  • links.link.attributes.attributeMap.key
  • links.link.attributes.attributeMap.value.boolValue
  • links.link.attributes.attributeMap.value.intValue
  • links.link.attributes.attributeMap.value.stringValue.truncatedByteCount
  • links.link.attributes.attributeMap.value.stringValue.value
  • stackTrace.stackFrames.frame.functionName.truncatedByteCount
  • stackTrace.stackFrames.frame.functionName.value
  • stackTrace.stackFrames.frame.originalFunctionName.truncatedByteCount
  • stackTrace.stackFrames.frame.originalFunctionName.value
  • status.code
  • status.details.typeUrl
  • status.details.value
  • status.message
  • timeEvents.timeEvent.annotation.attributes.attributeMap.key
  • timeEvents.timeEvent.annotation.attributes.attributeMap.value.boolValue
  • timeEvents.timeEvent.annotation.attributes.attributeMap.value.intValue
  • timeEvents.timeEvent.annotation.attributes.attributeMap.value.stringValue.truncatedByteCount
  • timeEvents.timeEvent.annotation.attributes.attributeMap.value.stringValue.value
  • timeEvents.timeEvent.annotation.description.truncatedByteCount
  • timeEvents.timeEvent.annotation.description.value

不適合用於機密資料的欄位

下表列出不適合用於敏感資訊的欄位類別和特定欄位,僅供參考。為確保符合規定,請勿在這些欄位中放置受保護的資料。如需完整清單,請與 Google Cloud 代表聯絡。

類別 欄位
分頁和排序
  • orderBy
  • pageToken
專案和資源識別
  • name
  • parent
  • projectId
  • traceSink.name
  • traceSink.outputConfig.destination
  • traceSink.outputConfig.pubsubConfig.openTelemetryFormat.version
範圍和資源篩選
  • scope.resourceNames
  • scope.traceId
  • traceScope.resourceNames
時距顯示和背景資訊
  • displayName.value
  • spans.displayName.value
  • spans.name
  • traces.traces.spans.name
堆疊追蹤建構資訊
  • spans.stackTrace.stackFrames.frame.loadModule.buildId.value
  • stackTrace.stackFrames.frame.loadModule.buildId.value
堆疊追蹤檔案資訊
  • spans.stackTrace.stackFrames.frame.fileName.value
  • stackTrace.stackFrames.frame.fileName.value
堆疊追蹤模組資訊
  • spans.stackTrace.stackFrames.frame.loadModule.module.value
  • stackTrace.stackFrames.frame.loadModule.module.value
堆疊追蹤版本資訊
  • spans.stackTrace.stackFrames.frame.sourceVersion.value
  • stackTrace.stackFrames.frame.sourceVersion.value
追蹤記錄範圍詳細資料
  • traceScope.description
  • traceScope.name
追蹤特定 ID
  • spans.parentSpanId
  • spans.spanId
  • traceId
OpenTelemetry 語意慣例屬性
  • spans.attributes.attributeMap["cloud.account.id"]
  • spans.attributes.attributeMap["cloud.availability_zone"]
  • spans.attributes.attributeMap["cloud.platform"]
  • spans.attributes.attributeMap["cloud.provider"]
  • spans.attributes.attributeMap["cloud.region"]
  • spans.attributes.attributeMap["cloud.resource_id"]
  • spans.attributes.attributeMap["error.type"]
  • spans.attributes.attributeMap["faas.name"]
  • spans.attributes.attributeMap["gcp.apphub.application.container"]
  • spans.attributes.attributeMap["gcp.apphub.application.id"]
  • spans.attributes.attributeMap["gcp.apphub.application.location"]
  • spans.attributes.attributeMap["gcp.apphub.service.id"]
  • spans.attributes.attributeMap["gcp.apphub.workload.id"]
  • spans.attributes.attributeMap["gcp.cloud_run.job.execution"]
  • spans.attributes.attributeMap["gcp.gce.instance_group_manager.name"]
  • spans.attributes.attributeMap["gcp.gce.instance_group_manager.region"]
  • spans.attributes.attributeMap["gcp.gce.instance_group_manager.zone"]
  • spans.attributes.attributeMap["gcp.project_id"]
  • spans.attributes.attributeMap["gcp.resource.location"]
  • spans.attributes.attributeMap["gcp.resource.name"]
  • spans.attributes.attributeMap["http.response.status.code"]
  • spans.attributes.attributeMap["k8s.cluster.name"]
  • spans.attributes.attributeMap["k8s.cronjob.name"]
  • spans.attributes.attributeMap["k8s.daemonset.name"]
  • spans.attributes.attributeMap["k8s.deployment.name"]
  • spans.attributes.attributeMap["k8s.namespace"]
  • spans.attributes.attributeMap["k8s.statefulset.name"]
  • spans.attributes.attributeMap["rpc.grpc.status_code"]
  • spans.attributes.attributeMap["rpc.system"]
  • spans.links.link.attributes.attributeMap["cloud.account.id"]
  • spans.links.link.attributes.attributeMap["cloud.availability_zone"]
  • spans.links.link.attributes.attributeMap["cloud.platform"]
  • spans.links.link.attributes.attributeMap["cloud.provider"]
  • spans.links.link.attributes.attributeMap["cloud.region"]
  • spans.links.link.attributes.attributeMap["cloud.resource_id"]
  • spans.links.link.attributes.attributeMap["error.type"]
  • spans.links.link.attributes.attributeMap["faas.name"]
  • spans.links.link.attributes.attributeMap["gcp.apphub.application.container"]
  • spans.links.link.attributes.attributeMap["gcp.apphub.application.id"]
  • spans.links.link.attributes.attributeMap["gcp.apphub.application.location"]
  • spans.links.link.attributes.attributeMap["gcp.apphub.service.id"]
  • spans.links.link.attributes.attributeMap["gcp.apphub.workload.id"]
  • spans.links.link.attributes.attributeMap["gcp.cloud_run.job.execution"]
  • spans.links.link.attributes.attributeMap["gcp.gce.instance_group_manager.name"]
  • spans.links.link.attributes.attributeMap["gcp.gce.instance_group_manager.region"]
  • spans.links.link.attributes.attributeMap["gcp.gce.instance_group_manager.zone"]
  • spans.links.link.attributes.attributeMap["gcp.project_id"]
  • spans.links.link.attributes.attributeMap["gcp.resource.location"]
  • spans.links.link.attributes.attributeMap["gcp.resource.name"]
  • spans.links.link.attributes.attributeMap["http.response.status.code"]
  • spans.links.link.attributes.attributeMap["k8s.cluster.name"]
  • spans.links.link.attributes.attributeMap["k8s.cronjob.name"]
  • spans.links.link.attributes.attributeMap["k8s.daemonset.name"]
  • spans.links.link.attributes.attributeMap["k8s.deployment.name"]
  • spans.links.link.attributes.attributeMap["k8s.namespace"]
  • spans.links.link.attributes.attributeMap["k8s.statefulset.name"]
  • spans.links.link.attributes.attributeMap["rpc.grpc.status_code"]
  • spans.links.link.attributes.attributeMap["rpc.system"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.account.id"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.availability_zone"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.platform"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.provider"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.region"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.resource_id"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["error.type"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["faas.name"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.application.container"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.application.id"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.application.location"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.service.id"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.workload.id"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.cloud_run.job.execution"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.gce.instance_group_manager.name"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.gce.instance_group_manager.region"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.gce.instance_group_manager.zone"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.project_id"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.resource.location"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.resource.name"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["http.response.status.code"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.cluster.name"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.cronjob.name"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.daemonset.name"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.deployment.name"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.namespace"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.statefulset.name"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["rpc.grpc.status_code"]
  • spans.timeEvents.timeEvent.annotation.attributes.attributeMap["rpc.system"]
  • attributes.attributeMap["cloud.account.id"]
  • attributes.attributeMap["cloud.availability_zone"]
  • attributes.attributeMap["cloud.platform"]
  • attributes.attributeMap["cloud.provider"]
  • attributes.attributeMap["cloud.region"]
  • attributes.attributeMap["cloud.resource_id"]
  • attributes.attributeMap["error.type"]
  • attributes.attributeMap["faas.name"]
  • attributes.attributeMap["gcp.apphub.application.container"]
  • attributes.attributeMap["gcp.apphub.application.id"]
  • attributes.attributeMap["gcp.apphub.application.location"]
  • attributes.attributeMap["gcp.apphub.service.id"]
  • attributes.attributeMap["gcp.apphub.workload.id"]
  • attributes.attributeMap["gcp.cloud_run.job.execution"]
  • attributes.attributeMap["gcp.gce.instance_group_manager.name"]
  • attributes.attributeMap["gcp.gce.instance_group_manager.region"]
  • attributes.attributeMap["gcp.gce.instance_group_manager.zone"]
  • attributes.attributeMap["gcp.project_id"]
  • attributes.attributeMap["gcp.resource.location"]
  • attributes.attributeMap["gcp.resource.name"]
  • attributes.attributeMap["http.response.status.code"]
  • attributes.attributeMap["k8s.cluster.name"]
  • attributes.attributeMap["k8s.cronjob.name"]
  • attributes.attributeMap["k8s.daemonset.name"]
  • attributes.attributeMap["k8s.deployment.name"]
  • attributes.attributeMap["k8s.namespace"]
  • attributes.attributeMap["k8s.statefulset.name"]
  • attributes.attributeMap["rpc.grpc.status_code"]
  • attributes.attributeMap["rpc.system"]
  • links.link.attributes.attributeMap["cloud.account.id"]
  • links.link.attributes.attributeMap["cloud.availability_zone"]
  • links.link.attributes.attributeMap["cloud.platform"]
  • links.link.attributes.attributeMap["cloud.provider"]
  • links.link.attributes.attributeMap["cloud.region"]
  • links.link.attributes.attributeMap["cloud.resource_id"]
  • links.link.attributes.attributeMap["error.type"]
  • links.link.attributes.attributeMap["faas.name"]
  • links.link.attributes.attributeMap["gcp.apphub.application.container"]
  • links.link.attributes.attributeMap["gcp.apphub.application.id"]
  • links.link.attributes.attributeMap["gcp.apphub.application.location"]
  • links.link.attributes.attributeMap["gcp.apphub.service.id"]
  • links.link.attributes.attributeMap["gcp.apphub.workload.id"]
  • links.link.attributes.attributeMap["gcp.cloud_run.job.execution"]
  • links.link.attributes.attributeMap["gcp.gce.instance_group_manager.name"]
  • links.link.attributes.attributeMap["gcp.gce.instance_group_manager.region"]
  • links.link.attributes.attributeMap["gcp.gce.instance_group_manager.zone"]
  • links.link.attributes.attributeMap["gcp.project_id"]
  • links.link.attributes.attributeMap["gcp.resource.location"]
  • links.link.attributes.attributeMap["gcp.resource.name"]
  • links.link.attributes.attributeMap["http.response.status.code"]
  • links.link.attributes.attributeMap["k8s.cluster.name"]
  • links.link.attributes.attributeMap["k8s.cronjob.name"]
  • links.link.attributes.attributeMap["k8s.daemonset.name"]
  • links.link.attributes.attributeMap["k8s.deployment.name"]
  • links.link.attributes.attributeMap["k8s.namespace"]
  • links.link.attributes.attributeMap["k8s.statefulset.name"]
  • links.link.attributes.attributeMap["rpc.grpc.status_code"]
  • links.link.attributes.attributeMap["rpc.system"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.account.id"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.availability_zone"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.platform"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.provider"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.region"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["cloud.resource_id"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["error.type"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["faas.name"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.application.container"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.application.id"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.application.location"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.service.id"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.apphub.workload.id"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.cloud_run.job.execution"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.gce.instance_group_manager.name"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.gce.instance_group_manager.region"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.gce.instance_group_manager.zone"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.project_id"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.resource.location"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["gcp.resource.name"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["http.response.status.code"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.cluster.name"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.cronjob.name"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.daemonset.name"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.deployment.name"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.namespace"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["k8s.statefulset.name"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["rpc.grpc.status_code"]
  • timeEvents.timeEvent.annotation.attributes.attributeMap["rpc.system"]

附錄

受保護的地圖欄位中的鍵/值組合 (在 OpenTelemetry 中有完善的語意慣例) 不受保護,不適合用於私密資訊:

  • cloud.account.id
  • cloud.availability_zone
  • cloud.platform
  • cloud.provider
  • cloud.region
  • cloud.resource_id
  • error.type
  • faas.name
  • gcp.apphub.application.container
  • gcp.apphub.application.id
  • gcp.apphub.application.location
  • gcp.apphub.service.id
  • gcp.apphub.workload.id
  • gcp.cloud_run.job.execution
  • gcp.gce.instance_group_manager.name
  • gcp.gce.instance_group_manager.region
  • gcp.gce.instance_group_manager.zone
  • gcp.project_id
  • gcp.resource.location
  • gcp.resource.name
  • http.response.status.code
  • k8s.cluster.name
  • k8s.cronjob.name
  • k8s.daemonset.name
  • k8s.deployment.name
  • k8s.namespace
  • k8s.statefulset.name
  • rpc.grpc.status_code
  • rpc.system


後續步驟