US Data Boundary and Support
This page describes the set of controls that are applied on US Data Boundary and Support workloads in Assured Workloads. It provides detailed information about data residency , supported Google Cloud products and their API endpoints, and any applicable restrictions or limitations on those products. The following additional information applies to US Data Boundary and Support:
- Data residency: The US Data Boundary and Support control package sets data location controls to support US-only regions . See the Google Cloud-wide organization policy constraints section for more information.
- Support: Technical support services for US Data Boundary and Support workloads are available with Enhanced or Premium Cloud Customer Care subscriptions. US Data Boundary and Support workloads support cases are routed to US Persons located in the US; see Getting support for more information.
- Pricing: The US Data Boundary and Support control package is included in Assured Workloads' Premium tier , which incurs a 5% additional charge. See Assured Workloads pricing for more information.
Supported products and API endpoints
Unless otherwise noted, users can access all supported products through the Google Cloud console. Restrictions or limitations that affect the features of a supported product, including those that are enforced through organization policy constraint settings , are listed in the following table.
If a product is not listed, that product is unsupported and has not met the control requirements for US Data Boundary and Support. Unsupported products are not recommended for use without due diligence and a thorough understanding of your responsibilities in the shared responsibility model . Before using an unsupported product, ensure that you are aware of and are willing to accept any associated risks involved, such as negative impacts to data residency or data sovereignty.
Supported product | API endpoints | Restrictions or limitations |
---|---|---|
accessapproval.googleapis.com
|
None | |
accesscontextmanager.googleapis.com
|
None | |
accessapproval.googleapis.com
|
None | |
alloydb.googleapis.com
|
None | |
mesh.googleapis.com
meshca.googleapis.com
meshconfig.googleapis.com
|
None | |
apigee.googleapis.com
|
None | |
artifactregistry.googleapis.com
|
None | |
gkebackup.googleapis.com
|
None | |
bigquery.googleapis.com
bigqueryconnection.googleapis.com
bigquerydatapolicy.googleapis.com
bigquerydatatransfer.googleapis.com
bigquerymigration.googleapis.com
bigqueryreservation.googleapis.com
bigquerystorage.googleapis.com
|
Affected features | |
bigtable.googleapis.com
bigtableadmin.googleapis.com
|
None | |
binaryauthorization.googleapis.com
|
None | |
privateca.googleapis.com
|
None | |
cloudasset.googleapis.com
|
None | |
cloudbuild.googleapis.com
|
None | |
composer.googleapis.com
|
None | |
dns.googleapis.com
|
None | |
datafusion.googleapis.com
|
None | |
cloudkms.googleapis.com
|
None | |
cloudkms.googleapis.com
|
None | |
compute.googleapis.com
|
None | |
cloudkms.googleapis.com
|
None | |
compute.googleapis.com
|
None | |
logging.googleapis.com
|
Affected features | |
monitoring.googleapis.com
|
None | |
compute.googleapis.com
|
None | |
oslogin.googleapis.com
|
None | |
compute.googleapis.com
|
None | |
run.googleapis.com
|
Affected features | |
run.googleapis.com
|
None | |
sqladmin.googleapis.com
|
None | |
sqladmin.googleapis.com
|
None | |
storage.googleapis.com
|
None | |
cloudtasks.googleapis.com
|
None | |
compute.googleapis.com
|
None | |
vision.googleapis.com
|
None | |
workstations.googleapis.com
|
None | |
compute.googleapis.com
|
Affected features and organization policy constraints | |
anthosconfigmanagement.googleapis.com
|
None | |
gkeconnect.googleapis.com
|
None | |
dlp.googleapis.com
|
None | |
Not applicable
|
None | |
dataflow.googleapis.com
datapipelines.googleapis.com
|
None | |
dataform.googleapis.com
|
None | |
dataplex.googleapis.com
datalineage.googleapis.com
|
None | |
dataproc-control.googleapis.com
dataproc.googleapis.com
|
None | |
documentai.googleapis.com
|
None | |
essentialcontacts.googleapis.com
|
None | |
eventarc.googleapis.com
|
None | |
file.googleapis.com
|
None | |
firebaserules.googleapis.com
|
None | |
firestore.googleapis.com
|
None | |
gkehub.googleapis.com
|
None | |
anthosidentityservice.googleapis.com
|
None | |
aiplatform.googleapis.com
|
None | |
discoveryengine.googleapis.com
|
None | |
compute.googleapis.com
networksecurity.googleapis.com
|
Affected features | |
netapp.googleapis.com
|
Affected features | |
container.googleapis.com
containersecurity.googleapis.com
|
None | |
chronicle.googleapis.com
chronicleservicemanager.googleapis.com
|
None | |
Not applicable
|
None | |
iam.googleapis.com
|
None | |
iap.googleapis.com
|
None | |
config.googleapis.com
|
None | |
looker.googleapis.com
|
None | |
redis.googleapis.com
|
None | |
modelarmor.googleapis.com
|
None | |
networkconnectivity.googleapis.com
|
None | |
orgpolicy.googleapis.com
|
None | |
compute.googleapis.com
|
None | |
servicehealth.googleapis.com
|
None | |
pubsub.googleapis.com
|
None | |
cloudresourcemanager.googleapis.com
|
None | |
secretmanager.googleapis.com
|
None | |
securesourcemanager.googleapis.com
|
None | |
vpcaccess.googleapis.com
|
None | |
spanner.googleapis.com
|
None | |
speech.googleapis.com
|
None | |
storagetransfer.googleapis.com
|
None | |
texttospeech.googleapis.com
|
None | |
trafficdirector.googleapis.com
|
None | |
accesscontextmanager.googleapis.com
|
None | |
aiplatform.googleapis.com
|
None | |
aiplatform.googleapis.com
|
None | |
aiplatform.googleapis.com
|
None | |
aiplatform.googleapis.com
|
None | |
aiplatform.googleapis.com
|
None | |
discoveryengine.googleapis.com
|
None | |
aiplatform.googleapis.com
|
None | |
compute.googleapis.com
|
None | |
webrisk.googleapis.com
|
None |
Restrictions and limitations
The following sections describe Google Cloud-wide or product-specific restrictions or limitations for features, including any organization policy constraints that are set by default on US Data Boundary and Support folders. Other applicable organization policy constraints —even if not set by default— can provide additional defense-in-depth to further protect your organization's Google Cloud resources.
Google Cloud-wide
Google Cloud-wide organization policy constraints
The following organization policy constraints apply across Google Cloud.
allowedValues
list: -
us-central1
-
us-central2
-
us-east4
-
us-east1
-
us-west1
-
us-west4
-
us-west3
-
us-west2
-
us-south1
-
us-east5
Changing this value by making it less restrictive potentially undermines data residency by allowing data to be created or stored outside of a compliant data boundary.
Determines which services can be used by restricting runtime access to their resources. For more information, see Restricting resource usage .
-
TLS_1_0
-
TLS_1_1
BigQuery
Affected BigQuery features
- In the Google Cloud console, go to the Assured Workloads page.
- Select your new Assured Workloads folder from the list.
- On the Folder Details page in the Allowed services section, click Review Available Updates .
- In the Allowed services
pane, review the services to be added to the Resource Usage Restriction
organization policy for the folder. If BigQuery services are listed, click Allow Services
to add them.
If BigQuery services are not listed, wait for the internal process to complete. If the services are not listed within 12 hours of folder creation, contact Cloud Customer Care .
After the enablement process is completed, you can use BigQuery in your Assured Workloads folder.
Gemini in BigQuery is not supported by Assured Workloads.
- Interaction with remote data sources
- Externally-trained BQML models are not supported. Internally-trained BQML models are supported.
- Dynamic data masking
- GDrive export
- Remote functions
- Saved queries
- Workflow scheduling
- For BigQuery Studio, notebooks are unsupported.
- Gemini in BigQuery is not supported.
gcloud --version
and then gcloud components update
to update to
the newest version.projectname.dataset.table
in the BigQuery
CLI._default
logging buckets or restrict _default
buckets to
in-scope regions to maintain compliance using the following command:gcloud alpha logging settings update --organization=ORGANIZATION_ID --disable-default-sink
See Regionalize your logs for more information.
Compute Engine
Affected Compute Engine features
Feature | Description |
---|---|
Guest environment | It is possible for scripts, daemons, and binaries that are included with the guest
environment to access unencrypted at-rest and in-use data. Depending on your VM
configuration, updates to this software may be installed by default. See Guest environment
for specific
information about each package's contents, source code, and more. These components help you meet data sovereignty through internal security controls and processes. However, if you want additional control, you can also curate your own images or agents and optionally use the compute.trustedImageProjects
organization policy
constraint.See the Building a custom image page for more information. |
OS policies in VM Manager | Inline scripts and binary output files within the OS policy files
are not encrypted using customer-managed encryption keys (CMEK).
Therefore, don't include any sensitive information in these files.
Alternatively, consider storing these
scripts and output files in Cloud Storage buckets. For more information, see Example OS policies
. If you want to restrict the creation or modification of OS policy resources that use inline scripts or binary output files, enable the constraints/osconfig.restrictInlineScriptAndOutputFileUsage
organization policy constraint.For more information, see Constraints for OS Config . |
Compute Engine organization policy constraints
Organization policy constraint | Description |
---|---|
compute.disableGlobalCloudArmorPolicy
|
Set to True
. Disables the creation of new global Google Cloud Armor security policies , and the addition or modification of rules to existing global Google Cloud Armor security policies. This constraint doesn't restrict the removal of rules or the ability to remove or change the description and listing of global Google Cloud Armor security policies. Regional Google Cloud Armor security policies are unaffected by this constraint. All global and regional security policies that exist prior to the enforcement of this constraint remain in effect. |
compute.restrictNonConfidentialComputing
|
(Optional) Value is not set. Set this value to provide additional defense-in-depth. See
the Confidential VM documentation
for more information. |
compute.trustedImageProjects
|
(Optional) Value is not set. Set this value to provide additional defense-in-depth. Setting this value constrains image storage and disk instantiation to the specified list of projects. This value affects data sovereignty by preventing use of any unauthorized images or agents. |
Cloud Logging
Affected Cloud Logging features
Feature | Description |
---|---|
Log sinks | Filters shouldn't contain Customer Data. Log sinks include filters which are stored as configuration. Don't create filters that contain Customer Data. |
Live tailing log entries | Filters shouldn't contain Customer Data. A live tailing session includes a filter which is stored as configuration. Tailing logs doesn't store any log entry data itself, but can query and transmit data across regions. Don't create filters that contain Customer Data. |
Google Cloud NetApp Volumes
Affected Google Cloud NetApp Volumes features
Feature | Description |
---|---|
Flex service level | The Flex service level is not available in the US Data Boundary and Support control package. |
What's next
- Learn how to create an Assured Workloads folder
- Learn about the US Data Boundary control package
- Understand Assured Workloads pricing