הגדרת Policy API
בדף הזה מוסבר איך להגדיר את Cloud Identity Policy API לפני הצגה ואחזור של מדיניות.
התקנה של ספריית הלקוח של Python
כדי להתקין את ספריית הלקוח של Python, מריצים את הפקודה הבאה:
pip install --upgrade google-api-python-client google-auth \
google-auth-oauthlib google-auth-httplib2 absly-py
מידע נוסף על הגדרת סביבת הפיתוח בשפת Python מופיע במדריך להגדרת סביבת הפיתוח בשפת Python.
הפעלת ה-API והגדרת פרטי כניסה לחשבון שירות
- נכנסים לחשבון Google Cloud . אם אתם משתמשים חדשים ב- Google Cloud, צרו חשבון כדי שתוכלו להעריך את הביצועים של המוצרים שלנו בתרחישים מהעולם האמיתי. לקוחות חדשים מקבלים בחינם גם קרדיט בשווי 300$ להרצה, לבדיקה ולפריסה של עומסי העבודה.
-
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
-
Verify that billing is enabled for your Google Cloud project.
Enable the Cloud Identity API.
Roles required to enable APIs
To enable APIs, you need the
serviceusage.services.enablepermission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.-
Create a service account:
-
Ensure that you have the Create Service Accounts IAM role
(
roles/iam.serviceAccountCreator) and the Project IAM Admin role (roles/resourcemanager.projectIamAdmin). Learn how to grant roles. -
In the Google Cloud console, go to the Create service account page.
Go to Create service account - Select your project.
-
In the Service account name field, enter a name. The Google Cloud console fills in the Service account ID field based on this name.
In the Service account description field, enter a description. For example,
Service account for quickstart. - Click Create and continue.
-
Grant the Service Account Token Creator role to the service account.
To grant the role, find the Select a role list, then select Service Account Token Creator.
- Click Continue.
-
In the Service account users role field, enter the identifier for the principal that will attach the service account to other resources, such as Compute Engine instances.
This is typically the email address for a Google Account.
-
Click Done to finish creating the service account.
-
Ensure that you have the Create Service Accounts IAM role
(
-
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
-
Verify that billing is enabled for your Google Cloud project.
Enable the Cloud Identity API.
Roles required to enable APIs
To enable APIs, you need the
serviceusage.services.enablepermission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.-
Create a service account:
-
Ensure that you have the Create Service Accounts IAM role
(
roles/iam.serviceAccountCreator) and the Project IAM Admin role (roles/resourcemanager.projectIamAdmin). Learn how to grant roles. -
In the Google Cloud console, go to the Create service account page.
Go to Create service account - Select your project.
-
In the Service account name field, enter a name. The Google Cloud console fills in the Service account ID field based on this name.
In the Service account description field, enter a description. For example,
Service account for quickstart. - Click Create and continue.
-
Grant the Service Account Token Creator role to the service account.
To grant the role, find the Select a role list, then select Service Account Token Creator.
- Click Continue.
-
In the Service account users role field, enter the identifier for the principal that will attach the service account to other resources, such as Compute Engine instances.
This is typically the email address for a Google Account.
-
Click Done to finish creating the service account.
-
Ensure that you have the Create Service Accounts IAM role
(
אימות כחשבון שירות עם הקצאת הרשאות ברמת הדומיין
אם אתם אדמינים שמנהלים מדיניות זהויות, או אם אתם רוצים להעניק לחשבון הרשאות ברמת הדומיין כדי שהוא יוכל לנהל מדיניות של Google בשם האדמינים, אתם צריכים לבצע אימות כחשבון שירות ואז להעניק לחשבון השירות הרשאות ברמת הדומיין.
פרטים על הגדרת הענקת גישה ברמת הדומיין זמינים במאמר בנושא שליטה בהרשאות הגישה ל-API באמצעות הענקת גישה ברמת הדומיין. מומלץ לעיין בשיטות המומלצות כדי לצמצם את סיכוני האבטחה שקשורים לשימוש במתן הרשאות גישה ברמת הדומיין.
אחרי שמגדירים הענקת גישה ברמת הדומיין, אפשר להשתמש ב-Application Default Credentials (ADC) לאימות. כשעובדים עם ADC, הקוד יכול לפעול גם בסביבת הפיתוח וגם בסביבת הייצור, בלי שתצטרכו לשנות את שיטת האימות של האפליקציות מול השירותים וממשקי ה-API של Google Cloud.
כשמאתחלים את פרטי הכניסה בקוד, מציינים את כתובת האימייל שחשבון השירות פועל בשמה באמצעות הפרמטר subject() בפרטי הכניסה. מוודאים שלכתובת האימייל הוקצה התפקיד Service Account User בחשבון השירות (כפי שמתואר למעלה).
לדוגמה:
חשוב: היקפי ההרשאות של OAuth שצוינו בקוד האפליקציה ששימש ליצירת פרטי כניסה עם הרשאת גישה צריכים להופיע ברשימת היקפי ההרשאות המורשים להענקת הרשאת גישה לכל הדומיין במסוף Google Admin. היקף רחב יותר או היקף עם פחות הגבלות לא יעבוד. אם היקף ההרשאות שהאפליקציה מבקשת כדי ליצור פרטי כניסה עם הרשאת גישה לא מורשה בהענקת גישה ברמת הדומיין, האפליקציה מקבלת שגיאה
unauthorized_client.
Python
AUTH_SCOPES = ['https://www.googleapis.com/auth/iam']
# The read and write scope of the API. Note that you must authorize the
# exact same scope for domain-wide delegation in the Google Admin Console.
POLICY_SCOPES = ['https://www.googleapis.com/auth/cloud-identity.policies']
TOKEN_URI = "https://accounts.google.com/o/oauth2/token"
_ADMIN_EMAIL = flags.DEFINE_string(
name='admin_email',
default=None,
help='Administrator email to call as',
required=True,
)
# Fetch application default credentials (ADC)
credentials, _ = google.auth.default(scopes=AUTH_SCOPES)
# Populate account information
request = requests.Request()
credentials.refresh(request)
# Create an IAM signer
signer = iam.Signer(request, credentials,
credentials.service_account_email)
# Create domain-wide delegated (DWD) credentials
delegated_credentials = service_account.Credentials(
signer=signer,
service_account_email=credentials.service_account_email,
token_uri=TOKEN_URI,
scopes=POLICY_SCOPES,
subject=_ADMIN_EMAIL.value
)
כדי להתחזות לחשבון שירות כשמשתמשים בפרטי כניסה שמוגדרים כברירת מחדל באפליקציה, משתמשים בדגל impersonate-service-account.
מעטפת
gcloud auth application-default login --impersonate-service-account=<service_account_email>
--scopes=https://www.googleapis.com/auth/iam,https://www.googleapis.com/auth/cloud-identity.policies
דוגמאות מפורטות לקוד לדוגמה לקריאה ל-Policy API, כולל הקוד לאימות, מופיעות במאמר Listing and getting policies.