Regulatory support in Eventarc

This document describes the features, configurations and APIs in Eventarc that align with the controls for supported control packages. This document assumes that you're using Assured Workloads.

Data Boundary for ITAR

Supported services

The following table lists the Eventarc APIs and versions that meet the requirements of Data Boundary for ITAR.

Service Version Status
eventarc.googleapis.com v1 SUPPORTED

Compliance supported regions

Eventarc is available for Data Boundary for ITAR in the following Google Cloud regions:

  • us-central1
  • us-central2
  • us-east1
  • us-east4
  • us-east5
  • us-south1
  • us-west1
  • us-west2
  • us-west3
  • us-west4

Fields not intended for Sensitive data

The following table provides an illustrative list of field categories and specific fields that aren't suitable for sensitive information. To maintain compliance, avoid placing protected data in these fields. For a complete list, contact your Google Cloud representative.

Category Fields
Authentication and authorization
  • channel.cryptoKeyName
  • googleApiSource.cryptoKeyName
  • kafkaSource.authenticationConfig.saslAuth.usernameSecret
  • pipeline.destinations.authenticationConfig.oauthToken.scope
  • trigger.serviceAccount
Paging and filtering
  • filter
  • orderBy
  • pageToken
Parent resource specification
  • parent
Resource configuration - channels
  • channel.provider
  • channelConnection.activationToken
  • channelConnection.channel
Resource configuration - enrollments
  • enrollment.celMatch
  • enrollment.destination
  • enrollment.messageBus
Resource configuration - pipelines
  • pipeline.destinations.topic
  • pipeline.destinations.workflow
  • pipeline.inputPayloadFormat.protobuf.schemaDefinition
Resource configuration - sources
  • googleApiSource.destination
  • kafkaSource.brokerUris
  • kafkaSource.topics
Resource configuration - triggers
  • trigger.destination.cloudRun.service
  • trigger.destination.gke.cluster
  • trigger.eventFilters.attribute
Resource identification
  • channelId
  • enrollmentId
  • googleApiSourceId
  • kafkaSourceId
  • messageBusId
  • pipelineId
Resource naming
  • channel.name
  • enrollment.name
  • googleApiSource.name
  • kafkaSource.name
  • messageBus.name
  • name

What's next