Cloud Trace enforces organization policies for observability buckets
The create-observability bucket flow now enforces organization policies for resource locations, Customer-Managed Encryption Keys (CMEKs), and key storage projects. This change enhances security and compliance for trace data stored in observability buckets. The feature is available now for organizations using Cloud Trace with applicable policies.
Features (1) ›
- Cloud Trace
The create-observability bucket flow enforces organization policies with constraints on resource locations. This flow also enforces policies that require customer-managed encryption keys (CMEKs) and that restrict the projects that store those keys. Your trace data is stored in an observability bucket. For more information, see the following: Set defaults for observability buckets Support for CMEKs
https://docs.cloud.google.com/release-notes#June_02_2026
