Managed Airflow (第 3 代) | Managed Airflow (第 2 代) | Managed Airflow (舊版第 1 代)
VPC Service Controls 可讓機構為Google Cloud 資源定義 perimeter,降低資料竊取風險。
您可以在服務邊界內部署 Managed Airflow 環境。透過 VPC Service Controls 設定環境,您就能使用 Managed Airflow 的全代管工作流程協調功能,同時維持機密資料的隱密性。
Managed Airflow 支援 VPC Service Controls,因此:
- 現在可以選取 Managed Airflow,做為 VPC Service Controls 範圍內的受保護服務。
- Managed Airflow 使用的所有基礎資源都已設定為支援 VPC Service Controls 架構,並遵循相關規則。
使用 VPC Service Controls 部署 Managed Airflow 環境可提供下列優點:
- 降低資料竊取風險。
- 防止因存取控管設定錯誤而導致資料外洩。
- 降低惡意使用者將資料複製到未經授權Google Cloud 資源的風險,或外部攻擊者從網際網路存取Google Cloud 資源的風險。
Managed Airflow 中的 VPC Service Controls
- 所有 VPC Service Controls 網路限制也適用於 Managed Airflow 環境。詳情請參閱 VPC Service Controls 說明文件。
如果 Managed Airflow 環境受到 perimeter 保護,系統會限制公開 PyPI 存放區的存取權。詳情請參閱「在 VPC Service Controls 中安裝 PyPI 套件」。
如果您的環境使用私人 IP 網路,所有內部流量都會路由至虛擬私有雲網路,但透過 Private Google Access 可供私人 IP 環境使用的 Google API、服務和網域除外。
視虛擬私有雲網路的設定方式而定,私人 IP 環境可透過虛擬私有雲網路存取網際網路。
Managed Airflow 不支援在輸入和輸出規則中使用第三方身分,允許 Apache Airflow UI 作業。不過,您可以在輸入和輸出規則中使用
ANY_IDENTITY身分類型,允許存取所有身分,包括第三方身分。如要進一步瞭解ANY_IDENTITY身分類型,請參閱「輸入和輸出規則」一文。在 VPC Service Controls 模式下,網頁伺服器的存取權會受到 perimeter 保護,系統會封鎖來自 perimeter 外部的存取要求。如要允許從服務範圍外部存取,請視需要設定存取層級或輸入和輸出規則。此外,您也可以限制只有特定 IP 範圍能存取網頁伺服器。
關於 VPC Service Controls 中連至 Google API 和服務的連線能力
Managed Airflow (第 3 代) 會透過 restricted.googleapis.com 將流量導向 Google 服務,以便存取這個範圍支援的 Google API、服務和網域。
如要進一步瞭解可透過 restricted.googleapis.com 存取的服務和網域清單,請參閱虛擬私有雲文件中的「網路設定」。
Managed Airflow (第 3 代) 環境會封鎖對 Google API、服務和網域的呼叫,這些項目不在必要 API 和服務清單中。如要從 DAG 呼叫 API:
- 確認服務支援 VPC Service Controls。
- 將服務新增至受限制的服務。
- 將服務新增至可透過虛擬私有雲存取的服務。
舉例來說,如果您使用 VertexAI Operator,請將 aiplatform.googleapis.com 同時新增至受限制的服務和可透過虛擬私有雲存取的服務。
如要進一步瞭解如何將服務新增至 service perimeter,請參閱 VPC Service Controls 說明文件的「管理 service perimeter」。
在 Managed Airflow (第 3 代) 中,如果服務不支援 VPC Service Controls,且無法透過 restricted.googleapis.com 存取,就無法從受 VPC Service Controls 保護的環境存取。為提升環境安全性,Managed Airflow (第 3 代) 新增了這項限制。雖然 Managed Airflow (第 2 代) 允許設定存取這類不支援的服務,但我們強烈建議您在任何受 VPC Service Controls 保護的環境中,都不要這麼做。
使用 Shared VPC 和 CMEK 的環境邊界
如果您的環境受到服務範圍保護,且使用 Shared VPC、客戶管理的加密金鑰 (CMEK) 或兩者,請確保下列專案位於同一個服務範圍:
- 服務專案:內含 Managed Airflow 環境的專案。
- 主專案:包含共用虛擬私有雲網路的專案。
- 用於代管 Cloud Key Management Service 金鑰的專案。
在範圍內建立環境
如要在安全防護範圍內部署 Managed Airflow,請按照下列步驟操作:
為專案啟用 Access Context Manager API 和 Cloud Composer API。請參閱「啟用 API」。
按照 VPC Service Controls 說明文件中的範圍設定指示建立範圍。請確認受 perimeter 保護的服務清單包含 Managed Airflow 使用的所有服務,以及您要限制的其他服務:
- Cloud Composer API (composer.googleapis.com)
- Artifact Registry API (artifactregistry.googleapis.com)
- Compute Engine API (compute.googleapis.com)
- Kubernetes Engine API (container.googleapis.com)
- Container File System API (containerfilesystem.googleapis.com)
- Cloud DNS API (dns.googleapis.com)
- Backup for GKE API (gkebackup.googleapis.com)
- Service Account Credentials API (iamcredentials.googleapis.com)
- Cloud Logging API (logging.googleapis.com)
- Cloud Monitoring API (monitoring.googleapis.com)
- Cloud Pub/Sub API (pubsub.googleapis.com)
- Cloud SQL Admin API (sqladmin.googleapis.com)
Cloud Storage API (storage.googleapis.com)
對於 DAG 使用的所有其他服務:
- 將服務新增至受限制的服務。
- 將服務新增至可透過虛擬私有雲存取的服務。
如果服務邊界使用可透過虛擬私有雲存取的服務限制 API 存取權,請確認允許的服務清單包含 Managed Airflow 使用的所有服務。
建立新的 Managed Airflow 環境:
- 使用 Google Cloud CLI 建立環境。
- 使用
--enable-private-environment引數啟用私人 IP。 - 使用
--web-server-allow-all、--web-server-allow-ip或--web-server-deny-all引數,指定網頁伺服器的存取參數。如要進一步瞭解如何使用這些引數,請參閱「建立環境」。為提升保護力,請僅允許特定 IP 範圍存取 Web 伺服器。 使用
--enable-private-builds-only引數,禁止從公開網際網路存放區安裝套件。範例:
gcloud composer environments create example-environment \ --location us-central1 \ --enable-private-environment \ --web-server-allow-all \ --enable-private-builds-only
根據預設,只有在安全防護範圍內,才能存取 Airflow UI 和 API。如要允許從安全防護範圍外存取,請設定存取層級或輸入和輸出規則。
根據預設,您的環境無法存取 perimeter 外部的資源,即使對應的 API 已新增至可透過虛擬私有雲存取的服務清單,也無法存取。如要允許存取 perimeter 外部的資源,請設定perimeter 橋接器、輸出和輸入規則,或將資源移至相同 perimeter。
舉例來說,假設您在 perimeter A 中有 Cloud KMS 金鑰,在 perimeter B 中有 Managed Airflow 環境。即使您使用可透過虛擬私有雲存取的服務,在 perimeter B 中允許 Cloud Key Management Service API,環境仍無法存取金鑰。您也必須設定跨越 perimeter 邊界的通訊。
將現有環境新增至範圍
如果環境使用私有 IP,且已停用從公開存放區安裝 PyPI 套件,您可以將含有環境的專案新增至安全防護範圍。
如要將現有的 Managed Airflow (第 3 代) 環境更新為這項設定,請按照下列步驟操作:
- 請確認您已建立或設定上一節所述的邊界。
- 使用 Google Cloud CLI 更新環境。
- 使用
--enable-private-environment引數啟用私人 IP。 - 使用
--enable-private-builds-only引數,禁止從公開網際網路存放區安裝套件。 - 如有需要,請設定 Airflow 網路伺服器的存取權。為提升保護力,請只允許特定 IP 範圍存取網頁伺服器。
範例:
gcloud composer environments update example-environment \
--location us-central1 \
--enable-private-environment \
--enable-private-builds-only
在 VPC Service Controls 中安裝 PyPI 套件
在預設的 VPC Service Controls 設定中,Managed Airflow 僅支援從可透過虛擬私有雲網路內部 IP 位址空間存取的私人存放區,安裝 PyPI 套件。
根據預設,VPC Service Controls perimeter 內的所有 Managed Airflow 環境都無法存取公開 PyPI 存放區。
從私人存放區安裝
建議設定私人 PyPI 存放區:
填入貴機構使用的經過審查的套件,然後設定 Managed Airflow,從私人存放區安裝 Python 依附元件。
從公開存放區安裝
如要從外部存放區安裝 PyPI 套件,請按照下列步驟操作:
- 建立 Artifact Registry 遠端存放區。
- 授予這個存放區上游來源的存取權。
- 設定 Airflow,從 Artifact Registry 存放區安裝套件。
VPC Service Controls 記錄
排解環境建立問題時,您可以分析 VPC Service Controls 產生的稽核記錄。
除了其他記錄訊息,您也可以查看記錄,瞭解設定環境元件的 cloud-airflow-prod@system.gserviceaccount.com 和 service-PROJECT_ID@cloudcomposer-accounts.iam.gserviceaccount.com 服務帳戶資訊。
Managed Airflow 服務會使用cloud-airflow-prod@system.gserviceaccount.com服務帳戶,管理環境的租戶專案元件。
服務帳戶 (又稱 Composer 服務代理程式服務帳戶) 會管理服務和主專案中的環境元件。service-PROJECT_ID@cloudcomposer-accounts.iam.gserviceaccount.com