本教學課程說明如何搭配使用 Secret Manager 和 Cloud Build,從建構作業存取私人的 GitHub 存放區。Secret Manager 是一項 Google Cloud 服務,可安全地儲存 API 金鑰、密碼和其他機密資料。
目標
- 設定 GitHub 安全殼層 (SSH) 金鑰組。
- 將公開安全殼層金鑰新增至私人存放區的部署金鑰。
- 將 SSH 私密金鑰儲存在 Secret Manager。
- 提交建構作業,從 Secret Manager 存取金鑰,並使用該金鑰存取私有存放區。
費用
在本文件中,您將使用下列 Google Cloud計費元件:
- Secret Manager
- Cloud Build
如要根據預測用量估算費用,請使用 Pricing Calculator。
事前準備
- 登入 Google Cloud 帳戶。如果您是 Google Cloud新手,歡迎 建立帳戶,親自體驗產品的實際應用成效。新客戶還能獲得價值 $300 美元的免費抵免額,能用於執行、測試及部署工作負載。
-
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
-
Verify that billing is enabled for your Google Cloud project.
Enable the Cloud Build and Secret Manager APIs, if any are not already enabled.
Roles required to enable APIs
To enable APIs, you need the
serviceusage.services.enablepermission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.-
Install the Google Cloud CLI.
-
If you're using an external identity provider (IdP), you must first sign in to the gcloud CLI with your federated identity.
-
To initialize the gcloud CLI, run the following command:
gcloud init -
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
-
Verify that billing is enabled for your Google Cloud project.
Enable the Cloud Build and Secret Manager APIs, if any are not already enabled.
Roles required to enable APIs
To enable APIs, you need the
serviceusage.services.enablepermission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.-
Install the Google Cloud CLI.
-
If you're using an external identity provider (IdP), you must first sign in to the gcloud CLI with your federated identity.
-
To initialize the gcloud CLI, run the following command:
gcloud init - 選用。完成 Secret Manager 快速入門導覽課程,熟悉這項產品。
建立安全殼層金鑰
開啟終端機視窗。
建立名為
workingdir的新目錄,然後前往該目錄:mkdir workingdir cd workingdir建立新的 GitHub 安全殼層金鑰,其中 github-email 是您的 GitHub 電子郵件地址:
ssh-keygen -t rsa -b 4096 -N '' -f id_github -C github-email這個指令會建立新的 SSH 金鑰
workingdir/id_github,且不含 SSH 金鑰的通關密語。如果安全殼層金鑰受到密碼保護,Cloud Build 無法使用該金鑰。
將私人安全殼層金鑰儲存在 Secret Manager
建立 SSH 金鑰時,系統會在環境中建立 id_github 檔案。由於任何人都能使用這個檔案驗證您的帳戶,因此您必須先將檔案儲存在 Secret Manager 中,才能用於建構作業。
如要將 SSH 金鑰儲存在 Secret Manager,請按照下列步驟操作:
前往 Google Cloud 控制台的「Secret Manager」頁面:
在「Secret Manager」頁面中,按一下「Create Secret」。
在「建立密鑰」頁面的「名稱」下方,輸入密鑰名稱。
在「密鑰值」欄位中,按一下「上傳」,然後上傳
workingdir/id_github檔案。請勿變更「區域」部分。
按一下「建立密鑰」按鈕。
以上步驟會將 id_github 檔案上傳至 Secret Manager。
將公開安全殼層金鑰新增至私人存放區的部署金鑰
登入 GitHub。
依序點選右上角的個人資料相片和「Your profile」。
在個人資料頁面點選「Repositories」,然後點選存放區名稱。
點選存放區的「Settings」。
點選側欄的「Deploy Keys」,然後點選「Add deploy key」。
輸入標題,然後貼上
workingdir/id_github.pub的公開安全殼層金鑰。如要授予這個金鑰存放區的寫入權限,請選取「Allow write access」。具備寫入權限的部署金鑰可讓部署作業推送至存放區。
按一下「Add key」。
將安全殼層金鑰從磁碟中刪除:
rm id_github*
授予權限
您必須授予服務帳戶存取 Secret Manager 的權限,才能用於建構作業。
-
前往 Google Cloud 控制台的 settings「Cloud Build Permissions」(Cloud Build 權限) 頁面:
從下拉式清單中,選取要變更角色的服務帳戶。
將
Secret Manager Secret Accessor角色的狀態設為「啟用」。
將公開安全殼層金鑰新增至已知主機
大多數電腦都包含名為 known_hosts 的檔案,其中含有遠端主機的已知金鑰。首次連線至遠端主機時,系統通常會從遠端主機收集金鑰,但您也可以手動新增金鑰。這個檔案中的金鑰用於驗證遠端主機的身分,並防範冒用身分。
您必須將公開安全殼層金鑰新增至 Cloud Build 建構環境的 known_hosts 檔案,Cloud Build 才能連線至 GitHub。方法是在暫時的 known_hosts.github 檔案中新增金鑰,然後將 known_hosts.github 的內容複製到 Cloud Build 建構環境中的 known_hosts 檔案。
在 workingdir 目錄 (與 cloudbuild.yaml 位於同一個目錄) 中,建立名為 known_hosts.github 的檔案。您提交給 Cloud Build 的原始碼必須包含這個檔案,以便在建構執行期間使用。如果您使用含觸發條件的 Git 存放區,請將這個檔案提交至存放區。將公開安全殼層金鑰新增至這個檔案:
ssh-keyscan -t rsa github.com > known_hosts.github
在下一節中設定建構作業時,您會在 Cloud Build 設定檔中新增指令,將 known_hosts.github 的內容複製到 Cloud Build 建構環境中的 known_hosts 檔案。
設定建構作業
如要設定建構作業,請按照下列步驟操作:
建立名為
cloudbuild.yaml的建構設定檔,其中包含兩個步驟:第一個步驟gcloud會存取 Secret Manager 中的 SSH 金鑰,並將其儲存為id_rsa,以及known_hosts.github的副本,存放在名為ssh的磁碟區。磁碟區用於在建構步驟中保留檔案。 第二個git步驟會使用id_rsa中的金鑰,連線至git@github.com:git-username/git-repository的存放區。# Access the id_github file from Secret Manager, and setup SSH steps: - name: 'gcr.io/cloud-builders/git' secretEnv: ['SSH_KEY'] entrypoint: 'bash' args: - -c - | echo "$$SSH_KEY" >> /root/.ssh/id_rsa chmod 400 /root/.ssh/id_rsa cp known_hosts.github /root/.ssh/known_hosts volumes: - name: 'ssh' path: /root/.ssh # Clone the repository - name: 'gcr.io/cloud-builders/git' args: - clone - --recurse-submodules - git@github.com:GIT_USERNAME/GIT_REPOSITORY volumes: - name: 'ssh' path: /root/.ssh availableSecrets: secretManager: - versionName: projects/PROJECT_ID/secrets/SECRET_NAME/versions/latest env: 'SSH_KEY'
將上述指令中的預留位置值替換為下列值:
GIT_USERNAME:存放區擁有者的 GitHub 使用者名稱。GIT_REPOSITORY:要存取的 GitHub 存放區名稱。PROJECT_ID:儲存密鑰的 Google Cloud 專案 ID。SECRET_NAME:您在 Secret Manager 中建立的密鑰名稱。
如要瞭解上述程式碼片段中使用的 YAML 多行字串,請參閱「YAML 多行」。
提交建構
如要提交建構作業,請執行下列指令:
gcloud builds submit --config=cloudbuild.yaml .
輸出結果會與下列內容相似:
Creating temporary tarball archive of 3 file(s) totalling 4.1 KiB before compression.
Uploading tarball of [.] to [gs://[PROJECT-ID]_cloudbuild/source/1504288639.02---.tgz]
Created [https://cloudbuild.googleapis.com/v1/projects/[PROJECT-ID]/builds/871b68bc---].
Logs are available at [https://console.cloud.google.com/cloud-build/builds/871b68bc---?project=[PROJECT-ID]].
----------------------------- REMOTE BUILD OUTPUT ------------------------------
starting build "871b68bc-cefc-4411-856c-2a2b7c7d2487"
FETCHSOURCE
Fetching storage object: gs://[PROJECT-ID]_cloudbuild/source/1504288639.02---.tgz#1504288640827178
Copying gs://[PROJECT-ID]_cloudbuild/source/1504288639.02---.tgz#1504288640827178...
/ [1 files][ 3.9 KiB/ 3.9 KiB]
Operation completed over 1 objects/3.9 KiB.
BUILD
Step #0: Already have image (with digest): gcr.io/cloud-builders/gcloud
Starting Step #0
Finished Step #0
Step #1: Already have image (with digest): gcr.io/cloud-builders/git
Starting Step #1
Step #1: # github.com SSH-2.0-libssh_0.7.0
Finished Step #1
Step #2: Already have image (with digest): gcr.io/cloud-builders/git
Starting Step #2
Step #2: Cloning into '[REPOSITORY-NAME]'...
Step #2: Warning: Permanently added the RSA host key for IP address 'XXX.XXX.XXX.XXX' to the list of known hosts.
Finished Step #2
PUSH
DONE
-----------------------------------------------------------------------------------------------------------------
ID CREATE_TIME DURATION SOURCE IMAGES STATUS
871b68bc-cefc-4411-856c-2a2b7c7d2487 XXXX-XX-XXT17:57:21+00:00 13S gs://[PROJECT-ID]_cloudbuild/source/1504288639.02---.tgz - SUCCESS
清除所用資源
為避免因為本教學課程所用資源,導致系統向 Google Cloud 收取費用,請刪除含有相關資源的專案,或者保留專案但刪除個別資源。
刪除專案
如要避免付費,最簡單的方法就是刪除您為了本教學課程所建立的專案。
刪除專案的方法如下:
- 前往 Google Cloud 控制台的「Manage resources」(管理資源) 頁面。
- 在專案清單中選取要刪除的專案,然後點選「Delete」(刪除)。
- 在對話方塊中輸入專案 ID,然後按一下 [Shut down] (關閉) 以刪除專案。
從存放區刪除部署金鑰
在 GitHub 中,前往存放區的主頁面。
在您的存放區名稱之下,按一下 [Settings] (設定)。
在左側邊欄中,按一下「Deploy keys」。
在「Deploy keys」頁面中,找出與存放區相關聯的部署金鑰,然後按一下「Delete」。
後續步驟
- 瞭解如何建立 GitHub 觸發條件。
- 進一步瞭解如何在 Cloud Build 中使用加密資源。
- 進一步瞭解 Secret Manager。