הגדרת ניהול מחזור חיים לעומסי עבודה מנוהלים

במאמר הזה מוסבר איך להגדיר ניהול מחזור חיים של אישורים לעומסי עבודה מנוהלים כמו Compute Engine ו-Google Kubernetes Engine ‏ (GKE), באמצעות Certificate Manager (דור שני). אפשר לקשר מאגר מנוהל של זהויות של עומסי עבודה למאגר של שירות רשות האישורים באמצעות הגדרת הנפקת אישורים, וכך להפוך את הנפקת האישורים והחידוש שלהם לאוטומטיים. כך אפשר למנוע הפסקות בשירות שנגרמות בגלל אישורים שתוקפם פג.

איך פועל ניהול זהויות של עומסי עבודה

זהות מנוהלת של עומס עבודה מספקת לעומסי עבודה ב-Compute Engine וב-GKE זהות מאומתת, בנוסף לאישור ולנקודות האמון שבהן עומסי העבודה משתמשים כדי לבצע אימות אחד לשני באמצעות TLS הדדי (mTLS). זהויות מנוהלות של עומסי עבודה מקובצות במאגר זהויות של עומסי עבודה, שמשמש כגבול האמון של הזהויות שבו.

כשמקשרים מאגר זהויות של עומסי עבודה למאגר של CA Service,‏Google Cloud המערכת מנפיקה ומחדשת אוטומטית אישורים לעומסי העבודה. האוטומציה הזו מבטלת את הצורך בניהול ידני של פרטי הכניסה ומונעת הפסקות בשירות.

לפני שמתחילים

  1. נכנסים לחשבון Google Cloud . אם אתם משתמשים חדשים ב- Google Cloud, צרו חשבון כדי שתוכלו להעריך את הביצועים של המוצרים שלנו בתרחישים מהעולם האמיתי. לקוחות חדשים מקבלים בחינם גם קרדיט בשווי 300$ להרצה, לבדיקה ולפריסה של עומסי העבודה.
  2. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

  3. If you're using an existing project for this guide, verify that you have the permissions required to complete this guide. If you created a new project, then you already have the required permissions.

  4. Verify that billing is enabled for your Google Cloud project.

  5. Enable the Compute Engine, Certificate Manager, Certificate Authority Service APIs, if any are not already enabled.

    Roles required to enable APIs

    To enable APIs, you need the serviceusage.services.enable permission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.

    Enable the APIs

  6. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

  7. If you're using an existing project for this guide, verify that you have the permissions required to complete this guide. If you created a new project, then you already have the required permissions.

  8. Verify that billing is enabled for your Google Cloud project.

  9. Enable the Compute Engine, Certificate Manager, Certificate Authority Service APIs, if any are not already enabled.

    Roles required to enable APIs

    To enable APIs, you need the serviceusage.services.enable permission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.

    Enable the APIs

  10. מוודאים שיש לכם מאגר זהויות קיים של עומסי עבודה עם זהויות מנוהלות של עומסי עבודה. מידע נוסף זמין במאמרים הגדרת אימות מנוהל של זהויות לעומסי עבודה ב-Compute Engine או הגדרת אימות מנוהל של זהויות לעומסי עבודה ב-GKE.
  11. מוודאים שיש לכם מאגר קיים של CA Service שיכול להנפיק אישורים לעומסי העבודה. מידע נוסף זמין במאמר בנושא יצירת מאגר של רשויות אישורים.

התפקידים הנדרשים

כדי לקבל את ההרשאות שדרושות להגדרה של ניהול מחזור החיים, צריך לבקש מהאדמין להקצות לכם את תפקידי ה-IAM הבאים בפרויקט:

להסבר על מתן תפקידים, ראו איך מנהלים את הגישה ברמת הפרויקט, התיקייה והארגון.

יכול להיות שאפשר לקבל את ההרשאות הנדרשות גם באמצעות תפקידים בהתאמה אישית או תפקידים מוגדרים מראש.

הגדרת מחזור חיים לעומסי עבודה מנוהלים

מגדירים מאגר זהויות מנוהל של עומסי עבודה כדי לציין איך עומסי עבודה משויכים מקבלים ומחדשים אישורים ממאגר קיים של CA Service.

  1. נכנסים לדף Certificate Manager (דור שני) במסוף Google Cloud .

    מעבר אל Certificate Manager (דור שני)

  2. בחלונית הניווט, לוחצים על Manage Lifecycle (ניהול מחזור החיים).
  3. לוחצים על הכרטיסייה Managed Workload Identity (זהויות עומס עבודה מנוהלות).
  4. מאתרים את מאגר הזהויות של עומסי עבודה שרוצים להגדיר ולוחצים על Configure lifecycle management (הגדרת ניהול מחזור חיים).
  5. בוחרים את האזור ואת מאגר האישורים לאזור.
  6. בשדה Certificate lifetime, מציינים את משך התוקף של האישור שהונפק. הערך צריך להיות בין 21 ל-30 ימים.
  7. מגדירים את חלון הרוטציה לערך בין 50 ל-80. זהו אחוז ממחזור החיים של האישור שמפעיל חידוש.
  8. בשדה אלגוריתם המפתח, בוחרים את אלגוריתם ההצפנה שבו יש להשתמש כדי ליצור את המפתח הפרטי.
  9. לוחצים על עדכון.

המאמרים הבאים