瞭解管理及控管 Certificate Manager (第 2 代) 資源存取權所需的 Identity and Access Management (IAM) 預先定義角色和權限。這些資源包括觀察到的憑證、核發設定和信任設定。您可以使用 IAM 權限,控管哪些人可以在專案層級或更高等級建立、查看、更新或刪除這些資源。如要瞭解負載平衡器資源的相關權限,請參閱「負載平衡適用的 IAM 角色和權限」。
預先定義的角色
IAM 提供預先定義的角色,可對特定 Google Cloud 資源授予精細的存取權,避免未經授權者存取其他資源。
下表說明包含 Certificate Manager (第 2 代) 資源權限的預先定義角色。
| 角色 | 說明 |
|---|---|
| Certificate Manager 編輯者角色 ( roles/certificatemanager.editor) |
可讀取及寫入 Certificate Manager 資源, 包括核發設定、信任設定和觀察到的憑證等 Certificate Manager (第 2 代) 資源。 |
| Certificate Manager 檢視者角色 ( roles/certificatemanager.viewer) |
授予 Certificate Manager 資源的唯讀存取權,包括 Certificate Manager (第 2 代) 資源,例如簽發設定、信任設定和觀察到的憑證。 |
權限
下表列出 Certificate Manager (第 2 代) 資源的權限。這些權限包含在 Certificate Manager 編輯者角色 (roles/certificatemanager.editor) 和 Certificate Manager 檢視者角色 (roles/certificatemanager.viewer) 中。
| 權限 | 說明 |
|---|---|
certificatemanager.observedcerts.get |
查看資產清單中觀察到的憑證詳細資料。 |
certificatemanager.observedcerts.list |
列出商品目錄中觀察到的憑證。 |
certificatemanager.certs.create |
建立憑證。 |
certificatemanager.certs.list |
列出憑證。 |
certificatemanager.certs.get |
查看憑證詳細資料。 |
certificatemanager.certs.update |
更新憑證。 |
certificatemanager.certs.use |
將憑證與資源建立關聯。 |
certificatemanager.certs.delete |
刪除憑證。 |
certificatemanager.certmaps.create |
建立憑證對應組合。 |
certificatemanager.certmaps.list |
列出憑證對應關係。 |
certificatemanager.certmaps.get |
查看憑證對應組合的詳細資料。 |
certificatemanager.certmaps.update |
更新憑證對應組合。 |
certificatemanager.certmaps.use |
將憑證對應組合附加至資源。 |
certificatemanager.certmaps.delete |
刪除憑證對應組合。 |
certificatemanager.certmapentries.create |
建立憑證對應關係。 |
certificatemanager.certmapentries.list |
列出憑證對應項目。 |
certificatemanager.certmapentries.get |
查看憑證對應關係詳細資料。 |
certificatemanager.certmapentries.update |
更新憑證對應關係。 |
certificatemanager.certmapentries.delete |
刪除憑證對應關係。 |
certificatemanager.dnsauthorizations.create |
建立 DNS 授權。 |
certificatemanager.dnsauthorizations.list |
列出 DNS 授權。 |
certificatemanager.dnsauthorizations.get |
查看 DNS 授權的詳細資料。 |
certificatemanager.dnsauthorizations.update |
更新 DNS 授權。 |
certificatemanager.dnsauthorizations.delete |
刪除 DNS 授權。 |
certificatemanager.certissuanceconfigs.create |
建立憑證核發設定。 |
certificatemanager.certissuanceconfigs.list |
列出憑證核發設定。 |
certificatemanager.certissuanceconfigs.get |
查看憑證核發設定。 |
certificatemanager.certissuanceconfigs.delete |
刪除憑證核發設定。 |
certificatemanager.trustconfigs.create |
建立信任設定。 |
certificatemanager.trustconfigs.list |
列出信任設定。 |
certificatemanager.trustconfigs.update |
更新信任設定。 |
certificatemanager.trustconfigs.get |
查看信任設定的詳細資料。 |
certificatemanager.trustconfigs.use |
將信任設定與資源建立關聯。 |
certificatemanager.trustconfigs.delete |
刪除信任設定。 |
後續步驟
- 使用 CA 服務核發憑證,並在 Certificate Manager (第 2 代) 中驗證
- 自動執行負載平衡器的憑證生命週期
- 設定受管理工作負載的生命週期管理機制
- 設定負載平衡器的生命週期管理機制
- 查看憑證庫存