Configure sovereign cloud profiles¶
Use the Google Cloud Environment setting on each Google account to restrict collection for that account to a supported Google Sovereign Controls by Partners data boundary.
Supported values are:
- Commercial Google Cloud
- France Data Boundary by S3NS
- Germany Data Boundary by T-Systems
The default value for each account is Commercial Google Cloud.
Supported collection paths¶
The France and Germany profiles continue to use standard Google API endpoints and Google client libraries. The add-on does not switch to a separate API universe.
The following collection paths remain supported with sovereign profile validation:
- Cloud Pub/Sub
- Pub/Sub-based bucket input
- Cloud Storage bucket input
- Cloud Monitoring
- Cloud BigQuery Billing
- Compute Engine resource metadata
- Kubernetes resource metadata
- Cloud Storage resource metadata for bucket metadata
Restricted collection paths¶
When either sovereign profile is selected, the add-on blocks:
- Cloud Pub/Sub Lite inputs
- VPC Access resource metadata inputs
- Cloud Storage ACL metadata APIs:
bucket_access_controlsdefault_object_access_controlsobject_access_controls
For general resource-location validation, France Data Boundary by S3NS allows europe-west1, europe-west4, and europe-west9. Germany Data Boundary by T-Systems allows europe-west3 and the partner-specific location u-germany-northeast1.
For BigQuery Billing, the add-on validates dataset location using BigQuery’s product-specific rule for Sovereign Controls by Partners: single-region EU dataset locations are supported, but the EU multi-region is rejected. Germany Data Boundary by T-Systems also supports the partner-specific BigQuery location u-germany-northeast1.
Customer responsibilities¶
The sovereign profile setting validates add-on configuration and prevents known unsupported collection paths. It does not guarantee end-to-end data sovereignty after data is ingested into Splunk.
You are responsible for:
- Creating Google resources in compliant Sovereign Controls by Partners folders.
- Keeping Google organization policies and CMEK requirements compliant.
- Configuring Pub/Sub topic storage policies for the selected data boundary.
- Running Splunk indexers, forwarders, backups, and retention in locations that meet your residency requirements.