|
GA
|
UI:
|
|
API:
|
No known limitations
|
Other:
|
No known limitations
|
|
|
GA
|
UI:
|
-
The Container Analysis API doesn't support identity federation, so vulnerabilities information is hidden.
|
API:
|
No known limitations
|
Other:
|
-
Container Registry doesn't support identity federation. There is an information banner in the settings page in
Container Registry transition
.
|
|
|
GA
|
UI:
|
-
Scheduling queries isn't supported.
-
Saving queries isn't supported.
|
API:
|
-
The following APIs don't support workforce identity federation with BigQuery:
-
The
tabledata.insertAll
method doesn't support workforce identity federation.
|
Other:
|
-
The following features don't support workforce identity federation with BigQuery:
-
The following operations don't support workforce identity federation:
-
DDL access to the BigQuery Reservation API.
-
Loading data from Amazon S3, Azure Blob Storage, Google Drive, or
local files.
-
The following BigQuery ML models don't support workforce identity federation:
|
|
|
GA
|
UI:
|
-
The
key visualizer
isn't available for workforce identity federation.
-
The UI cost calculator isn't available for workforce identity federation.
|
API:
|
No known limitations
|
Other:
|
No known limitations
|
|
|
GA
|
UI:
|
When Cloud billing Web UI support is used with identity federation, only the following functionality is supported:
|
API:
|
|
Other:
|
Only
invoiced billing accounts
are supported.
|
|
|
GA
|
UI:
|
See
About the console (federated)
|
API:
|
No known limitations
|
Other:
|
Workforce identity federation users aren't eligible for Google Cloud Free Trial.
|
|
|
Preview
|
UI:
|
SSH-in-browser
doesn't support workforce identity federation.
|
API:
|
|
Other:
|
No known limitations
|
|
|
GA
|
UI:
|
In the edit
steward
dialog on the entry details page, contact suggestions aren't shown.
|
API:
|
Search
and
starring
is supported.
|
Other:
|
No known limitations
|
|
|
GA
|
UI:
|
datapipelines.googleapis.com
: The Dataflow
Data Pipelines
page doesn't support workforce identity federation.
|
API:
|
google.dataflow.v1beta3.SqlValidator.Validate
: Dataflow SQL Validator APIs don't support workforce identity federation.
|
Other:
|
No known limitations
|
|
|
GA
|
UI:
|
-
Workforce identity federation users can perform create, view, update, and delete operations in Cluster, Jobs, and Batches list pages. Workflows, Autoscaling policies, and component exchange aren't available to workforce identity federation users.
-
Cluster create functionality is available, except for Dataproc on GKE cluster creation, Dataproc Compute Engine cluster with personal authentication, or with Component Gateway enabled.
-
The "Output" section in the Batch and Job detail page isn't available for workforce identity federation users.
-
The "Recommend Alert" section in the Cluster and Job list page isn't available for workforce identity federation users.
|
API:
|
|
Other:
|
No known limitations
|
|
|
Preview
|
UI:
|
The Cloud Domains page isn't available.
|
API:
|
No known limitations
|
Other:
|
No known limitations
|
|
|
GA
|
UI:
|
Billing information isn't visible on the
Instance create
,
Instance edit
, and
Restore backup to New instance
pages.
|
API:
|
No known limitations
|
Other:
|
No known limitations
|
|
|
GA
|
UI:
|
-
The name column within the IAM table doesn't show display names for Google identities.
-
When adding new principals to allow policies, the
Add principals
text field supports only autocompletion for service accounts.
-
The
Add exempted principal
text field in the
Audit Logs
page supports only autocompletion for service accounts.
|
API:
|
No known limitations
|
Other:
|
No known limitations
|
|
|
GA
|
UI:
|
No known limitations
|
API:
|
No known limitations
|
Other:
|
No known limitations
|
|
|
GA
|
UI:
|
Google Container Registry tab isn't available for workforce identity federation. You must manually input the image path for an existing container image.
|
API:
|
No known limitations
|
Other:
|
No known limitations
|
|
|
GA
|
UI:
|
No known limitations
|
API:
|
No known limitations
|
Other:
|
No known limitations
|
|
|
|
UI:
|
-
The
Cost estimate
UI is unavailable.
|
API:
|
No known limitations
|
Other:
|
No known limitations
|
|
|
GA
|
UI:
|
No known limitations
|
API:
|
No known limitations
|
Other:
|
The legacy Cloud Monitoring agent
doesn't support sending metrics with identity federation. Instead, workforce identity federation users can install the
Ops Agent
.
|
|
|
GA
|
UI:
|
No known limitations
|
API:
|
Pub/Sub Lite API
doesn't have endpoints that support workforce identity federation.
|
Other:
|
No known limitations
|
|
|
GA
|
UI:
|
-
Workforce identity federation users can only view and operate on the organization for which workforce identity federation was configured. Other organizations to which the users are added are not displayed in the Google Cloud console.
-
Wait times for certain operations to be reflected in the UI are long—for example, creating a project or folder.
|
API:
|
Tags aren't supported for workforce identity federation users.
|
Other:
|
No known limitations
|
|
|
GA
|
UI:
|
|
API:
|
No known limitations
|
Other:
|
The IAM permission
run.routes.invoke
, which manages access to Cloud Run service endpoints, doesn't support workforce identity federation.
|
|
|
GA
|
UI:
|
No known limitations
|
API:
|
No known limitations
|
Other:
|
No known limitations
|
|
|
GA
|
UI:
|
No known limitations
|
API:
|
No known limitations
|
Other:
|
No known limitations
|
|
|
GA
|
UI:
|
No known limitations
|
API:
|
No known limitations
|
Other:
|
No known limitations
|
|
|
GA
|
UI:
|
No known limitations
|
API:
|
No known limitations
|
Other:
|
No known limitations
|
|
|
GA
|
UI:
|
No known limitations
|
API:
|
No known limitations
|
Other:
|
The Help Assistant isn't supported.
|
|
|
Preview
|
UI:
|
-
Authenticated browser downloads
aren't supported. Object data can be downloaded via gsutil, the API, or client libraries.
-
Viewing object details requires
uniform bucket-level access
to be enabled for the bucket.
-
Process with Cloud Functions isn't supported.
-
Scan with Cloud Data Loss Prevention isn't supported.
|
API:
|
-
Workforce identity federation with all Cloud Storage APIs is supported only for
uniform bucket-level access
buckets. Workforce identity federation access to buckets with fine-grained
access control lists (ACLs)
is rejected.
-
Workforce identity federation with authenticated browser downloads isn't supported.
-
Although anyone can use existing
signed URLs
, workforce identity federation users cannot generate signed URLs.
-
Workforce identity federation users cannot use
object change notification
.
|
Other:
|
No known limitations
|
|
|
GA
|
UI:
|
-
Due to the
limitations of Cloud Billing for workforce identity federation
, billing related Support is accessible only to the organization’s administrator through the Google Cloud account used to set up the billing account.
-
Workforce identity federation users can upload—but not download—Support Case-related files. These files are visible to the Support Engineers who handle your cases.
-
Contact details (e.g. Email Address) cannot be changed for workforce identity federation users once interaction with Support has started.
|
API:
|
Cloud Support API doesn't support workforce identity federation.
|
Other:
|
No known limitations
|
|
|
GA
|
UI:
|
No known limitations
|
API:
|
No known limitations
|
Other:
|
No known limitations
|
|