Skip to content

Configure sovereign cloud profiles

Use the Google Cloud Environment setting on each Google account to restrict collection for that account to a supported Google Sovereign Controls by Partners data boundary.

Supported values are:

  • Commercial Google Cloud
  • France Data Boundary by S3NS
  • Germany Data Boundary by T-Systems

The default value for each account is Commercial Google Cloud.

Supported collection paths

The France and Germany profiles continue to use standard Google API endpoints and Google client libraries. The add-on does not switch to a separate API universe.

The following collection paths remain supported with sovereign profile validation:

  • Cloud Pub/Sub
  • Pub/Sub-based bucket input
  • Cloud Storage bucket input
  • Cloud Monitoring
  • Cloud BigQuery Billing
  • Compute Engine resource metadata
  • Kubernetes resource metadata
  • Cloud Storage resource metadata for bucket metadata

Restricted collection paths

When either sovereign profile is selected, the add-on blocks:

  • Cloud Pub/Sub Lite inputs
  • VPC Access resource metadata inputs
  • Cloud Storage ACL metadata APIs:
  • bucket_access_controls
  • default_object_access_controls
  • object_access_controls

For general resource-location validation, France Data Boundary by S3NS allows europe-west1, europe-west4, and europe-west9. Germany Data Boundary by T-Systems allows europe-west3 and the partner-specific location u-germany-northeast1.

For BigQuery Billing, the add-on validates dataset location using BigQuery’s product-specific rule for Sovereign Controls by Partners: single-region EU dataset locations are supported, but the EU multi-region is rejected. Germany Data Boundary by T-Systems also supports the partner-specific BigQuery location u-germany-northeast1.

Customer responsibilities

The sovereign profile setting validates add-on configuration and prevents known unsupported collection paths. It does not guarantee end-to-end data sovereignty after data is ingested into Splunk.

You are responsible for:

  • Creating Google resources in compliant Sovereign Controls by Partners folders.
  • Keeping Google organization policies and CMEK requirements compliant.
  • Configuring Pub/Sub topic storage policies for the selected data boundary.
  • Running Splunk indexers, forwarders, backups, and retention in locations that meet your residency requirements.