Cara kerja workload identity terkelola
Managed workload identity memberi beban kerja Compute Engine dan GKE Anda identitas yang dibuktikan, beserta sertifikat dan anchor tepercaya yang digunakan beban kerja untuk saling mengautentikasi melalui TLS timbal balik (mTLS). Managed workload identity dikelompokkan ke dalam workload identity pool, yang bertindak sebagai batas kepercayaan untuk identitas di dalamnya.
Saat Anda menautkan workload identity pool ke pool Layanan CA, CA Service akan Google Cloud secara otomatis menerbitkan dan memperbarui sertifikat untuk workload Anda. Otomatisasi ini menghilangkan pengelolaan kredensial secara manual dan mencegah gangguan layanan.
Sebelum memulai
- Login ke akun Google Cloud Anda. Jika Anda baru menggunakan Google Cloud, buat akun untuk mengevaluasi performa produk kami dalam skenario dunia nyata. Pelanggan baru juga mendapatkan kredit gratis senilai $300 untuk menjalankan, menguji, dan men-deploy workload.
-
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
-
If you're using an existing project for this guide, verify that you have the permissions required to complete this guide. If you created a new project, then you already have the required permissions.
-
Verify that billing is enabled for your Google Cloud project.
Enable the Compute Engine, Certificate Manager, Certificate Authority Service APIs, if any are not already enabled.
Roles required to enable APIs
To enable APIs, you need the
serviceusage.services.enablepermission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.-
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
-
If you're using an existing project for this guide, verify that you have the permissions required to complete this guide. If you created a new project, then you already have the required permissions.
-
Verify that billing is enabled for your Google Cloud project.
Enable the Compute Engine, Certificate Manager, Certificate Authority Service APIs, if any are not already enabled.
Roles required to enable APIs
To enable APIs, you need the
serviceusage.services.enablepermission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.- Pastikan Anda memiliki workload identity pool yang ada dengan identitas workload terkelola. Untuk mengetahui informasi selengkapnya, lihat Mengonfigurasi autentikasi managed workload identity untuk Compute Engine atau Mengonfigurasi autentikasi managed workload identity untuk GKE.
- Pastikan Anda memiliki kumpulan CA Service yang ada yang dapat menerbitkan sertifikat ke workload Anda. Untuk mengetahui informasi selengkapnya, lihat Membuat kumpulan CA.
Peran yang diperlukan
Untuk mendapatkan izin yang Anda perlukan guna mengonfigurasi pengelolaan siklus proses, minta administrator Anda untuk memberi Anda peran IAM berikut di project Anda:
- Certificate Manager Editor (
roles/certificatemanager.editor) - CA Service Certificate Manager (
roles/privateca.certificateManager) - Admin Workload Identity Pool (
roles/iam.workloadIdentityPoolAdmin)
Untuk mengetahui informasi selengkapnya tentang pemberian peran, lihat Mengelola akses ke project, folder, dan organisasi.
Anda mungkin juga bisa mendapatkan izin yang diperlukan melalui peran khusus atau peran bawaan lainnya.
Mengonfigurasi siklus proses untuk workload terkelola
Konfigurasi managed workload identity pool untuk menentukan cara workload terkait menerima dan memperbarui sertifikat dari kumpulan Layanan CA yang ada.
- Di konsol Google Cloud , buka halaman Certificate Manager (generasi ke-2).
- Di panel navigasi, klik Manage Lifecycle.
- Pilih tab Managed Workload Identity.
- Temukan workload identity pool yang ingin Anda konfigurasi, lalu klik Konfigurasi pengelolaan siklus proses.
- Pilih Region dan CA pool untuk region.
- Di kolom Masa berlaku sertifikat, tentukan validitas sertifikat yang dikeluarkan. Nilainya harus antara 21 dan 30 hari.
- Tetapkan Periode rotasi ke nilai antara 50 dan 80. Ini adalah persentase masa berlaku sertifikat yang memicu perpanjangan.
- Di kolom Algoritma kunci, pilih algoritma enkripsi yang akan digunakan untuk membuat kunci pribadi.
- Klik Update.
Langkah berikutnya
- Melihat inventaris sertifikat
- Membuat konfigurasi penerbitan
- Memantau sertifikat Anda
- Mengonfigurasi pengelolaan siklus proses untuk load balancer
- Buat konfigurasi kepercayaan