本頁說明如何為 AlloyDB for PostgreSQL 叢集和備份檔新增預先定義的組織政策,以便在專案、資料夾或組織層級限制 AlloyDB。
客戶自行管理的加密金鑰 (CMEK) 組織政策
您可以使用 CMEK 組織政策,控管 AlloyDB 叢集和備份的 CMEK 設定。這項政策可讓您控管用於保護資料的 Cloud KMS 金鑰。
AlloyDB 支援兩項組織政策限制,可協助確保整個機構採用 CMEK 保護措施:
constraints/gcp.restrictNonCmekServices:必須為alloydb.googleapis.com使用 CMEK 保護措施。新增這項限制,並將alloydb.googleapis.com新增至服務的Deny政策清單後,AlloyDB 會拒絕建立新叢集或備份,除非這些項目已啟用 CMEK。constraints/gcp.restrictCmekCryptoKeyProjects:限制您可在 AlloyDB 叢集和備份中,用於 CMEK 保護的 Cloud KMS CryptoKey。設定這項限制後,AlloyDB 建立啟用 CMEK 的新叢集或備份時,CryptoKey 必須來自允許的專案、資料夾或機構。
這些限制只會強制套用至新建立的 AlloyDB 叢集和備份。
如需更多總覽資訊,請參閱「CMEK 組織政策」。如要瞭解 CMEK 組織政策限制,請參閱「組織政策限制」。
事前準備
- 登入 Google Cloud 帳戶。如果您是 Google Cloud新手,歡迎 建立帳戶,親自體驗產品的實際應用成效。新客戶還能獲得價值 $300 美元的免費抵免額,能用於執行、測試及部署工作負載。
-
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
-
Verify that billing is enabled for your Google Cloud project.
-
Install the Google Cloud CLI.
-
If you're using an external identity provider (IdP), you must first sign in to the gcloud CLI with your federated identity.
-
To initialize the gcloud CLI, run the following command:
gcloud init -
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
-
Verify that billing is enabled for your Google Cloud project.
-
Install the Google Cloud CLI.
-
If you're using an external identity provider (IdP), you must first sign in to the gcloud CLI with your federated identity.
-
To initialize the gcloud CLI, run the following command:
gcloud init - 從「IAM & Admin」(IAM 與管理) 頁面,將「機構政策管理員」角色 (
roles/orgpolicy.policyAdmin) 新增至使用者或服務帳戶。
新增 CMEK 組織政策
如要新增 CMEK 組織政策,請按照下列步驟操作:
前往「組織政策」頁面。
按一下 Google Cloud 控制台選單列中的下拉式選單,然後選取需要組織政策的專案、資料夾或組織。「Organization policies」(組織政策) 頁面會顯示可用的組織政策限制清單。
如要設定
constraints/gcp.restrictNonCmekServices,請按照下列步驟操作:- 使用
ID篩選限制條件:constraints/gcp.restrictNonCmekServices,或使用Name:Restrict which services may create resources without CMEK。 - 按一下限制的「名稱」。
- 按一下 [編輯]。
- 點按「自訂」。
- 按一下「Add rule」(新增規則)。
- 在「政策值」下方,按一下「自訂」。
- 在「政策類型」下方,選取「拒絕」。
- 在「Custom values」(自訂值)下方輸入
alloydb.googleapis.com。確保在建立 AlloyDB 叢集和備份時強制執行 CMEK。
- 使用
如要設定
constraints/gcp.restrictCmekCryptoKeyProjects,請按照下列步驟操作:- 篩選限制
ID:constraints/gcp.restrictCmekCryptoKeyProjects或Name:Restrict which projects may supply KMS CryptoKeys for CMEK。 - 按一下限制的「名稱」。
- 按一下 [編輯]。
- 點按「自訂」。
- 按一下「Add rule」(新增規則)。
- 在「政策值」下方,按一下「自訂」。
- 在「政策類型」下方,選取「允許」。
在「Custom values」(自訂值)下方,輸入資源,格式如下:
under:organizations/ORGANIZATION_ID、under:folders/FOLDER_ID或projects/PROJECT_ID。確保 AlloyDB 叢集和備份只使用允許專案、資料夾或機構中的 Cloud KMS 金鑰。
- 篩選限制
依序按一下 [完成] 和 [儲存]。
後續步驟
- 進一步瞭解 AlloyDB for PostgreSQL 的客戶自行管理加密金鑰 (CMEK)。
- 如要進一步瞭解組織政策,請參閱組織政策服務簡介。
- 進一步瞭解如何建立及管理組織政策。
- 查看預先定義組織政策限制的完整清單。
- 使用公開 IP 連線。
- 建立主要執行個體。