GCP authentication, permissions and supported regions 🔗
前提条件 🔗
GCP 接続を作成するには、Splunk Observability Cloud 組織の管理者である必要があります。
Authenticate your Google account 🔗
You need your service account keys to be able to integrate your GCP services with Splunk Observability Cloud. Check the restrictions on your organization’s account keys before connecting to Splunk Observability Cloud.
For more information, refer to:
GCP’s docs on Service account keys
Google’s official announcement on the new permission policies at Introducing stronger default Org Policies for our customers
Authenticate using Workload Identity Federation 🔗
Alternatively, if you’re connecting to Splunk Observability Cloud using the API you can use GCP’s Workload Identity Federation (WIF) to access your Google Cloud resources and authenticate them. It’s safer, and with WIF you won’t have to export and rotate service account keys.
See how to authenticate with WIF in the Splunk Observability Cloud developer documentation at Integrate GCP .
GCP role permissions 🔗
You can use GCP’s Viewer role as it comes with the permissions you need for most scenarios.
Alternatively you can create a more restrictive role using the permissions in the table:
アクセス許可 |
必須ですか? |
Included in GCP’s Viewer role? |
---|---|---|
|
はい、Compute Engineサービスが有効になっている場合 |
はい |
|
はい、Compute Engineサービスが有効になっている場合 |
はい |
|
はい、Kubernetes (GKE) サービスが有効化されている場合 |
はい |
|
はい、Kubernetes (GKE) サービスが有効化されている場合 |
はい |
|
はい、Kubernetes (GKE) サービスが有効化されている場合 |
はい |
|
はい |
はい |
|
はい |
はい |
|
はい |
はい |
|
Yes, if you want to sync project metadata (such as labels) |
はい |
|
Yes, if you either want to activate the use of a quota from the project where metrics are stored or sync cloud sql metadata |
No, but included in |
|
はい、スパナーサービスが有効な場合 |
はい |
|
はい、スパナーサービスが有効な場合 |
はい |
|
Yes, if the cloud sql service is activated |
はい |
|
Yes, if the cloud sql service is activated |
はい |
|
Yes, if the pub/sub service is activated |
はい |
|
Yes, if the pub/sub service is activated |
はい |
|
Yes, if the cloud run service is activated |
はい |
|
Yes, if the cloud run service is activated |
はい |
|
Yes, if the cloud run service is activated |
はい |
|
Yes, if the cloud functions service is activated |
はい |
Supported regions 🔗
Splunk Observability Cloud はすべての GCP リージョンをサポートしています。