支持自定义限制条件的服务

借助自定义组织政策,管理员可以针对 Google Cloud 服务定义自己的限制。如需详细了解自定义限制条件,请参阅自定义组织政策概览

每项服务都定义了一组自定义限制条件字段,可用于对服务资源强制执行组织政策。如需了解哪些 Google Cloud 服务支持自定义限制条件,请参阅支持的服务资源列表。如需了解如何创建自定义限制条件,请参阅创建和管理自定义限制条件

如需查看示例自定义限制条件列表,请参阅 GitHub 上的自定义组织政策库

支持的服务资源

与以下服务关联的资源可能会受到自定义限制条件的约束。并非所有资源属性都适用于这些资源。请参阅特定于服务的文档,了解可供使用的资源和属性。

Google Cloud 服务 资源类型 发布状态
Access Context Manager accesscontextmanager.googleapis.com/AccessLevel

GA

accesscontextmanager.googleapis.com/AccessPolicy

GA

accesscontextmanager.googleapis.com/AuthorizedOrgsDesc

GA

accesscontextmanager.googleapis.com/ServicePerimeter

GA

AI Platform Training aiplatform.googleapis.com/CustomJob

GA

aiplatform.googleapis.com/HyperparameterTuningJob

GA

aiplatform.googleapis.com/NasJob

GA

AlloyDB for PostgreSQL alloydb.googleapis.com/Backup

预览

alloydb.googleapis.com/Cluster

预览

alloydb.googleapis.com/Instance

预览

API 密钥 apikeys.googleapis.com/Key

预览

Artifact Registry artifactregistry.googleapis.com/Repository

GA

Google Cloud Armor compute.googleapis.com/NetworkEdgeSecurityService

GA

compute.googleapis.com/SecurityPolicy

GA

BigQuery bigquery.googleapis.com/Dataset

预览

Cloud Bigtable Admin API bigtableadmin.googleapis.com/AppProfile

GA

bigtableadmin.googleapis.com/Backup

GA

bigtableadmin.googleapis.com/Cluster

GA

bigtableadmin.googleapis.com/Instance

GA

bigtableadmin.googleapis.com/Table

GA

Binary Authorization binaryauthorization.googleapis.com/Attestor

GA

binaryauthorization.googleapis.com/Policy

GA

BigQuery Data Transfer Service bigquerydatatransfer.googleapis.com/TransferConfig

GA

Cloud Build cloudbuild.googleapis.com/BitbucketServerConfig

GA

cloudbuild.googleapis.com/BuildTrigger

GA

cloudbuild.googleapis.com/Connection

GA

cloudbuild.googleapis.com/GithubEnterpriseConfig

GA

cloudbuild.googleapis.com/Repository

GA

cloudbuild.googleapis.com/WorkerPool

GA

Google Cloud Contact Center as a Service contactcenteraiplatform.googleapis.com/ContactCenter

预览

Certificate Manager certificatemanager.googleapis.com/Certificate

GA

certificatemanager.googleapis.com/CertificateIssuanceConfig

GA

certificatemanager.googleapis.com/CertificateMap

GA

certificatemanager.googleapis.com/CertificateMapEntry

GA

certificatemanager.googleapis.com/DnsAuthorization

GA

certificatemanager.googleapis.com/TrustConfig

GA

Identity Platform identitytoolkit.googleapis.com/Config

GA

identitytoolkit.googleapis.com/DefaultSupportedIdpConfig

GA

identitytoolkit.googleapis.com/InboundSamlConfig

GA

identitytoolkit.googleapis.com/OauthIdpConfig

GA

identitytoolkit.googleapis.com/Tenant

GA

Cloud 配额 cloudquotas.googleapis.com/QuotaPreference

预览

Cloud Run functions cloudfunctions.googleapis.com/Function

GA

Cloud Run run.googleapis.com/Job

GA

run.googleapis.com/Service

GA

Colab Enterprise aiplatform.googleapis.com/NotebookExecutionJob

预览

aiplatform.googleapis.com/NotebookRuntime

GA

aiplatform.googleapis.com/NotebookRuntimeTemplate

GA

Cloud Composer composer.googleapis.com/Environment

GA

Compute Engine compute.googleapis.com/Disk

GA

compute.googleapis.com/Image

GA

compute.googleapis.com/Instance

GA

compute.googleapis.com/PreviewFeature

预览

Resource Manager cloudresourcemanager.googleapis.com/Folder

预览

cloudresourcemanager.googleapis.com/Project

预览

Cloud Data Fusion datafusion.googleapis.com/DnsPeering

GA

datafusion.googleapis.com/Instance

GA

Data Lineage API datalineage.googleapis.com/Process

GA

Dataflow dataflow.googleapis.com/Job

GA

Dataplex Universal Catalog dataplex.googleapis.com/AspectType

GA

dataplex.googleapis.com/DataScan

GA

dataplex.googleapis.com/EntryGroup

GA

dataplex.googleapis.com/EntryType

GA

dataplex.googleapis.com/MetadataJob

GA

Dataproc dataproc.googleapis.com/Cluster

GA

Dataproc Metastore metastore.googleapis.com/Backup

GA

metastore.googleapis.com/MetadataImport

GA

metastore.googleapis.com/Service

GA

Dataproc Serverless dataproc.googleapis.com/Batch

GA

dataproc.googleapis.com/Session

GA

Developer Connect developerconnect.googleapis.com/Connection

GA

developerconnect.googleapis.com/GitRepositoryLink

GA

Cloud DNS dns.googleapis.com/ManagedZone

GA

dns.googleapis.com/Policy

GA

dns.googleapis.com/ResponsePolicy

GA

dns.googleapis.com/ResponsePolicyRule

GA

重要联系人 essentialcontacts.googleapis.com/Contact

GA

Eventarc eventarc.googleapis.com/Channel

GA

eventarc.googleapis.com/ChannelConnection

GA

eventarc.googleapis.com/Enrollment

GA

eventarc.googleapis.com/GoogleApiSource

GA

eventarc.googleapis.com/GoogleChannelConfig

GA

eventarc.googleapis.com/MessageBus

GA

eventarc.googleapis.com/Pipeline

GA

eventarc.googleapis.com/Trigger

GA

Filestore file.googleapis.com/Backup

GA

file.googleapis.com/Instance

GA

file.googleapis.com/Snapshot

GA

Firestore firestore.googleapis.com/Database

GA

Cloud 新一代防火墙 compute.googleapis.com/Firewall

GA

compute.googleapis.com/FirewallPolicy

GA

GKE 关联集群 gkemulticloud.googleapis.com/AttachedCluster

GA

GKE on AWS gkemulticloud.googleapis.com/AwsCluster

GA

gkemulticloud.googleapis.com/AwsNodePool

GA

GKE on Azure gkemulticloud.googleapis.com/AzureClient

GA

gkemulticloud.googleapis.com/AzureCluster

GA

gkemulticloud.googleapis.com/AzureNodePool

GA

GKE container.googleapis.com/Cluster

GA

container.googleapis.com/NodePool

GA

GKE On-Prem API gkeonprem.googleapis.com/BareMetalAdminCluster

GA

gkeonprem.googleapis.com/BareMetalCluster

GA

gkeonprem.googleapis.com/BareMetalNodePool

GA

gkeonprem.googleapis.com/VmwareAdminCluster

GA

gkeonprem.googleapis.com/VmwareCluster

GA

gkeonprem.googleapis.com/VmwareNodePool

GA

Cloud Healthcare API healthcare.googleapis.com/ConsentStore

GA

healthcare.googleapis.com/Dataset

GA

healthcare.googleapis.com/DicomStore

GA

healthcare.googleapis.com/FhirStore

GA

healthcare.googleapis.com/Hl7V2Store

GA

Hub gkehub.googleapis.com/Feature

GA

gkehub.googleapis.com/Fleet

GA

gkehub.googleapis.com/Membership

GA

gkehub.googleapis.com/MembershipBinding

GA

gkehub.googleapis.com/MembershipFeature

GA

gkehub.googleapis.com/Namespace

GA

gkehub.googleapis.com/RBACRoleBinding

GA

gkehub.googleapis.com/Scope

GA

Identity and Access Management iam.googleapis.com/AllowPolicy

GA

iam.googleapis.com/ServiceAccount

GA

iam.googleapis.com/ServiceAccountKey

GA

Identity-Aware Proxy iap.googleapis.com/TunnelDestGroup

GA

Cloud Interconnect compute.googleapis.com/Interconnect

GA

compute.googleapis.com/InterconnectAttachment

GA

Cloud Key Management Service cloudkms.googleapis.com/AutokeyConfig

GA

cloudkms.googleapis.com/CryptoKey

GA

cloudkms.googleapis.com/CryptoKeyVersion

GA

cloudkms.googleapis.com/EkmConfig

GA

cloudkms.googleapis.com/EkmConnection

GA

cloudkms.googleapis.com/ImportJob

GA

cloudkms.googleapis.com/KeyHandle

GA

Cloud Load Balancing compute.googleapis.com/BackendBucket

GA

compute.googleapis.com/BackendService

GA

compute.googleapis.com/ForwardingRule

GA

compute.googleapis.com/HealthCheck

GA

compute.googleapis.com/InstanceGroup

GA

compute.googleapis.com/NetworkEndpointGroup

GA

compute.googleapis.com/SslPolicy

GA

compute.googleapis.com/TargetGrpcProxy

GA

compute.googleapis.com/TargetHttpProxy

GA

compute.googleapis.com/TargetHttpsProxy

GA

compute.googleapis.com/TargetInstance

GA

compute.googleapis.com/TargetPool

GA

compute.googleapis.com/TargetSslProxy

GA

compute.googleapis.com/TargetTcpProxy

GA

compute.googleapis.com/UrlMap

GA

networkservices.googleapis.com/ServiceLbPolicy

GA

Cloud Logging logging.googleapis.com/Link

GA

logging.googleapis.com/LogBucket

GA

logging.googleapis.com/LogMetric

GA

logging.googleapis.com/LogSink

GA

logging.googleapis.com/LogView

GA

logging.googleapis.com/SavedQuery

GA

Service Management servicemanagement.googleapis.com/Service

预览

Memorystore redis.googleapis.com/Instance

GA

Memorystore for Redis Cluster redis.googleapis.com/Cluster

GA

Cloud Monitoring monitoring.googleapis.com/AlertPolicy

GA

monitoring.googleapis.com/NotificationChannel

GA

monitoring.googleapis.com/Snooze

GA

Network Connectivity networkconnectivity.googleapis.com/Group

GA

networkconnectivity.googleapis.com/Hub

GA

networkconnectivity.googleapis.com/Spoke

GA

Private Service Connect compute.googleapis.com/NetworkAttachment

GA

compute.googleapis.com/ServiceAttachment

GA

Pub/Sub pubsub.googleapis.com/Schema

GA

pubsub.googleapis.com/Snapshot

GA

pubsub.googleapis.com/Subscription

GA

pubsub.googleapis.com/Topic

GA

reCAPTCHA recaptchaenterprise.googleapis.com/FirewallPolicy

GA

recaptchaenterprise.googleapis.com/Key

GA

Cloud Router、Cloud NAT compute.googleapis.com/Router

GA

Web Security Scanner websecurityscanner.googleapis.com/ScanConfig

GA

Security Command Center securitycenter.googleapis.com/BigQueryExport

GA

securitycenter.googleapis.com/ContainerThreatDetectionSettings

GA

securitycenter.googleapis.com/EventThreatDetectionSettings

GA

securitycenter.googleapis.com/MuteConfig

GA

securitycenter.googleapis.com/NotificationConfig

GA

securitycenter.googleapis.com/ResourceValueConfig

GA

securitycenter.googleapis.com/SecurityHealthAnalyticsSettings

GA

securitycenter.googleapis.com/VirtualMachineThreatDetectionSettings

GA

securitycenter.googleapis.com/WebSecurityScannerSettings

GA

securitycentermanagement.googleapis.com/EventThreatDetectionCustomModule

GA

securitycentermanagement.googleapis.com/SecurityCenterService

GA

securitycentermanagement.googleapis.com/SecurityHealthAnalyticsCustomModule

GA

Secret Manager secretmanager.googleapis.com/Secret

GA

安全状况 securityposture.googleapis.com/Posture

GA

securityposture.googleapis.com/PostureDeployment

GA

Serverless VPC Access vpcaccess.googleapis.com/Connector

GA

服务扩展程序 networkservices.googleapis.com/LbRouteExtension

GA

networkservices.googleapis.com/LbTrafficExtension

GA

Cloud Service Mesh networksecurity.googleapis.com/AuthorizationPolicy

GA

networksecurity.googleapis.com/ClientTlsPolicy

GA

networksecurity.googleapis.com/ServerTlsPolicy

GA

networkservices.googleapis.com/EndpointPolicy

GA

networkservices.googleapis.com/Gateway

GA

networkservices.googleapis.com/GrpcRoute

GA

networkservices.googleapis.com/HttpRoute

GA

networkservices.googleapis.com/Mesh

GA

networkservices.googleapis.com/ServiceBinding

GA

networkservices.googleapis.com/TcpRoute

GA

networkservices.googleapis.com/TlsRoute

GA

Spanner spanner.googleapis.com/Backup

GA

spanner.googleapis.com/Database

GA

spanner.googleapis.com/Instance

GA

spanner.googleapis.com/InstanceConfig

GA

Cloud SQL sqladmin.googleapis.com/BackupRun

GA

sqladmin.googleapis.com/Instance

GA

Secure Source Manager securesourcemanager.googleapis.com/Instance

GA

Cloud Storage storage.googleapis.com/Bucket

GA

Vector Search aiplatform.googleapis.com/Index

GA

aiplatform.googleapis.com/IndexEndpoint

GA

Vertex ML Metadata aiplatform.googleapis.com/MetadataStore

GA

Vertex AI Pipelines aiplatform.googleapis.com/PipelineJob

预览

Vertex AI Inference aiplatform.googleapis.com/DeploymentResourcePool

预览

aiplatform.googleapis.com/Endpoint

预览

Video Stitcher API videostitcher.googleapis.com/CdnKey

GA

videostitcher.googleapis.com/LiveConfig

GA

videostitcher.googleapis.com/Slate

GA

videostitcher.googleapis.com/VodConfig

GA

虚拟私有云 compute.googleapis.com/Network

GA

compute.googleapis.com/PacketMirroring

GA

compute.googleapis.com/Route

GA

compute.googleapis.com/Subnetwork

GA

Cloud VPN compute.googleapis.com/ExternalVpnGateway

GA

compute.googleapis.com/TargetVpnGateway

GA

compute.googleapis.com/VpnGateway

GA

compute.googleapis.com/VpnTunnel

GA

Workflows workflows.googleapis.com/Workflow

GA

Cloud Workstations workstations.googleapis.com/Workstation

GA

workstations.googleapis.com/WorkstationCluster

GA

workstations.googleapis.com/WorkstationConfig

GA