更新二進位授權政策

本文說明如何豁免二進位授權政策中的映像檔。

本文將更新政策,豁免 Artifact Registry 中的容器映像檔,使其不受二進位授權強制執行機制限制,並將預設規則設為禁止部署所有其他容器。

事前準備

  1. 登入 Google Cloud 帳戶。如果您是 Google Cloud新手,歡迎 建立帳戶,親自體驗產品的實際應用成效。新客戶還能獲得價值 $300 美元的免費抵免額,能用於執行、測試及部署工作負載。
  2. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

  3. Verify that billing is enabled for your Google Cloud project.

  4. Enable the Artifact Registry, Binary Authorization APIs, if any are not already enabled.

    Roles required to enable APIs

    To enable APIs, you need the serviceusage.services.enable permission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.

    Enable the APIs

  5. Install the Google Cloud CLI.

  6. If you're using an external identity provider (IdP), you must first sign in to the gcloud CLI with your federated identity.

  7. To initialize the gcloud CLI, run the following command:

    gcloud init
  8. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

  9. Verify that billing is enabled for your Google Cloud project.

  10. Enable the Artifact Registry, Binary Authorization APIs, if any are not already enabled.

    Roles required to enable APIs

    To enable APIs, you need the serviceusage.services.enable permission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.

    Enable the APIs

  11. Install the Google Cloud CLI.

  12. If you're using an external identity provider (IdP), you must first sign in to the gcloud CLI with your federated identity.

  13. To initialize the gcloud CLI, run the following command:

    gcloud init
  14. 如果未使用 Cloud Shell,請安裝 kubectl。

建立啟用二進位授權的叢集

建立啟用二進位授權的 GKE 叢集。這是要執行已部署容器映像檔的叢集。

Google Cloud 控制台

  1. 前往Google Cloud 控制台的 GKE「Clusters」(叢集) 頁面。

    前往 GKE

    控制台會顯示 Google Cloud 專案中的 GKE 叢集清單。

  2. 點選「建立叢集」。

  3. 在「Name」欄位中輸入 test-cluster。

    標準叢集範本中的名稱欄位

  4. 在「位置類型」選項中選取「區域」。

  5. 從「可用區」下拉式選單選取「us-central1-a」。

  6. 在導覽窗格的「叢集」部分,點選「進階設定」。

  7. 在「二進位授權」列中,按一下「編輯設定」。

  8. 選取「啟用二進位授權」。

    啟用二進位授權選項

  9. 選取「僅強制執行」,然後按一下「儲存」。

  10. 點選「建立」。

gcloud

執行 gcloud container clusters create 並啟用 --binauthz-evaluation-mode=PROJECT_SINGLETON_POLICY_ENFORCE 旗標。

gcloud container clusters create \
    --binauthz-evaluation-mode=PROJECT_SINGLETON_POLICY_ENFORCE \
    --zone us-central1-a \
    test-cluster

查看預設政策

根據預設,二進位授權政策會允許部署所有容器映像檔。

Google Cloud 控制台

如要查看預設政策,請按照下列步驟操作:

  1. 前往 Google Cloud 控制台的「二進位授權」頁面。

    前往二進位授權

    控制台會顯示政策的詳細資料。

  2. 點選「編輯政策」。

  3. 在「專案預設規則」中,選取「允許所有映像檔」選項。

gcloud

如要查看預設政策,請匯出政策 YAML 檔案,方法如下:

gcloud container binauthz policy export

根據預設,檔案包含下列內容:

globalPolicyEvaluationMode: ENABLE
defaultAdmissionRule:
  evaluationMode: ALWAYS_ALLOW
  enforcementMode: ENFORCED_BLOCK_AND_AUDIT_LOG
name: projects/<var>PROJECT_ID</var>/policy

REST API

如要查看預設政策,請按照下列步驟以 JSON 格式擷取:

curl \
    -H "Authorization: Bearer $(gcloud auth application-default print-access-token)" \
    -H "x-goog-user-project: ${PROJECT_ID}" \
    "https://binaryauthorization.googleapis.com/v1/projects/${PROJECT_ID}/policy"

REST API 會傳回下列內容:

{
  "name": "projects/PROJECT_ID/policy",
  "globalPolicyEvaluationMode": "ENABLE",
  "defaultAdmissionRule": {
    "evaluationMode": "ALWAYS_ALLOW",
    "enforcementMode": "ENFORCED_BLOCK_AND_AUDIT_LOG"
  }
}

只允許豁免圖片

本節說明如何修改政策,豁免映像檔並禁止部署所有其他映像檔。

Google Cloud 控制台

如要修改政策,請按照下列步驟操作:

  1. 返回 Google Cloud 控制台的「Binary Authorization」(二進位授權) 頁面。

    前往二進位授權

  2. 點選「編輯政策」。

  3. 選取「禁止顯示所有圖片」。

  4. 在「Images exempt from deployment rules」(可免除部署規則的圖片) 下方,展開「Image paths」(圖片路徑)。

  5. 按一下「新增圖片路徑」。

    Artifact Registry

    在「New image path」(新映像檔路徑) 中,貼上 Artifact Registry 存放區的下列路徑:

    us-docker.pkg.dev/google-samples/containers/gke/hello-app:1.0
    
  6. 按一下「完成」即可儲存圖片路徑。

  7. 點選 [儲存政策]。

gcloud

如要修改政策,允許使用 Artifact Registry 中的範例映像檔,請按照下列步驟操作:

  1. 匯出政策 YAML 檔案:

    gcloud container binauthz policy export  > /tmp/policy.yaml
    
  2. 在文字編輯器中,將 evaluationMode 從 ALWAYS_ALLOW 變更為 ALWAYS_DENY,並將豁免圖片新增至 admissionWhitelistPatterns。

    如要從 Artifact Registry 排除下列範例圖片,請按照下列方式修改政策 YAML 檔案:

    admissionWhitelistPatterns:
    - namePattern: us-docker.pkg.dev/google-samples/containers/gke/hello-app:1.0
    globalPolicyEvaluationMode: ENABLE
    defaultAdmissionRule:
      evaluationMode: ALWAYS_DENY
      enforcementMode: ENFORCED_BLOCK_AND_AUDIT_LOG
    name: projects/<var>PROJECT_ID</var>/policy
    
  3. 將政策 YAML 檔案匯回二進位授權:

    gcloud container binauthz policy import /tmp/policy.yaml
    

REST API

如要修改政策,請按照下列步驟操作:

  1. 建立文字檔,並以 JSON 格式加入更新後的政策:

    cat > /tmp/policy.json << EOM
    {
      "name": "projects/${PROJECT_ID}/policy",
      "admissionWhitelistPatterns": [
        {
          "namePattern": "us-docker.pkg.dev/google-samples/containers/gke/hello-app:1.0"
        }
      ],
      "globalPolicyEvaluationMode": "ENABLE",
      "defaultAdmissionRule": {
        "evaluationMode": "ALWAYS_DENY",
        "enforcementMode": "ENFORCED_BLOCK_AND_AUDIT_LOG"
      }
    }
    EOM
    
  2. 將更新後的政策傳送至 REST API:

    curl -X PUT \
        -H "Content-Type: application/json" \
        -H "Authorization: Bearer $(gcloud auth application-default print-access-token)" \
        -H "x-goog-user-project: ${PROJECT_ID}" \
        --data-binary @/tmp/policy.json  \
        "https://binaryauthorization.googleapis.com/v1/projects/${PROJECT_ID}/policy"
    

測試政策

如要測試政策,請部署您新增至 Exempt image 許可清單的映像檔,步驟如下:

  1. 將豁免映像檔部署至叢集。

    Google Cloud 控制台

    部署豁免映像檔:

    1. 前往Google Cloud 控制台的 GKE「Clusters」(叢集) 頁面。

      前往 GKE

    2. 點選「Deploy」(部署)。

      控制台會提示您輸入部署作業的詳細資料。

    3. 選取「現有容器映像檔」。

    4. 輸入容器映像檔路徑。

      Artifact Registry

      如要從 Artifact Registry 部署映像檔,請輸入下列內容:

      us-docker.pkg.dev/google-samples/containers/gke/hello-app:1.0
      
    5. 按一下「繼續」。

    6. 在「Application Name」(應用程式名稱) 欄位中輸入 hello-server。

    7. 點選「Deploy」(部署)。

    kubectl

    Artifact Registry

    從 Artifact Registry 部署映像檔:

    kubectl run hello-server --image us-docker.pkg.dev/google-samples/containers/gke/hello-app:1.0 --port 8080
    
  2. 確認映像檔已獲准部署:

    Google Cloud 控制台

    如要確認映像檔已部署,請執行下列操作:

    1. 前往 GKE 頁面。

    前往 GKE

    1. 前往「工作負載」頁面。

    hello-server 工作負載會顯示綠色圖示,表示正在執行。

    kubectl

    如要確認映像檔是否允許部署,請輸入下列指令:

    kubectl get pods
    

    您會看到映像檔正在執行。

  3. 刪除 Pod。

    Google Cloud 控制台

    在 GKE「Workloads」(工作負載) 頁面中:

    1. 選取「hello-server」工作負載。

    2. 點選「刪除」。

    3. 當系統提示刪除資源時,按一下「刪除」。

    kubectl

    kubectl delete pod hello-server
    

清除所用資源

為了避免系統向您的 Google Cloud 帳戶收取本頁面所用資源的費用,請按照下列步驟操作。

刪除您在 GKE 中建立的叢集:

控制台

如要刪除叢集,請按照下列步驟操作:

  1. 前往Google Cloud 控制台的 GKE「Clusters」(叢集) 頁面。

    前往 GKE

  2. 選取 test-cluster 叢集,然後按一下「刪除」。

gcloud

如要刪除叢集,請輸入下列指令:

gcloud container clusters delete \
    --zone=us-central1-a \
    test-cluster

後續步驟