本教學課程說明平台管理員如何使用 Policy Controller 政策,控管如何使用 Config Connector 建立 Google Cloud 資源。
本頁面適用於 IT 管理員和操作員,他們希望確保在雲端平台中執行的所有資源都符合組織法規遵循要求,方法是提供及維護自動化功能來稽核或強制執行,以及管理基礎技術基礎架構的生命週期。如要進一步瞭解Google Cloud 內容中提及的常見角色和工作範例,請參閱「常見的 GKE 使用者角色和工作」。
本教學課程的指示假設您具備 Kubernetes 或 Google Kubernetes Engine (GKE) 的基本知識。在本教學課程中,您將定義一項政策,限制 Cloud Storage bucket 的允許位置。
Policy Controller 會按照安全性、法規或商業規範的相關政策,檢查及稽核 Kubernetes 叢集資源,並確保資源確實遵循這些政策。Policy Controller 是以 OPA Gatekeeper 開放原始碼專案為基礎建構而成。
Config Connector 會將Kubernetes 自訂資源描述為Google Cloud 資源,並建立及管理這些資源的生命週期。如要建立 Google Cloud 資源,請在 Config Connector 管理的命名空間中建立 Kubernetes 資源。以下範例說明如何使用 Config Connector 描述 Cloud Storage bucket:
apiVersion: storage.cnrm.cloud.google.com/v1beta1 kind: StorageBucket metadata: name: my-bucket spec: location: us-east1
使用 Config Connector 管理 Google Cloud 資源時,您可以在 Google Kubernetes Engine 叢集中建立這些資源,並套用 Policy Controller 政策。您可以透過這些政策,防止或回報以違反政策的方式建立或修改資源的動作。例如,您可以強制執行限制 Cloud Storage bucket 位置的政策。
這種方法以 Kubernetes 資源模型 (KRM) 為基礎,可讓您使用一組一致的工具和工作流程,同時管理 Kubernetes 和 Google Cloud 資源。本教學課程將示範如何完成下列作業:
- 定義 Google Cloud 資源的管理政策。
- 實施控管措施,禁止開發人員和管理員建立違反政策的 Google Cloud 資源。
- 導入控管措施,根據政策稽核現有 Google Cloud 資源,即使這些資源是在 Config Connector 外部建立也適用。
- 在開發人員和管理員建立及更新資源定義時,快速提供意見回饋。
- 先根據政策驗證 Google Cloud 資源定義,再嘗試將定義套用至 Kubernetes 叢集。
目標
- 建立包含 Config Connector 外掛程式的 GKE 叢集。
- 安裝 Policy Controller。
- 建立政策,限制允許的 Cloud Storage bucket 位置。
- 確認政策可防止在未獲許可的位置建立 Cloud Storage 值區。
- 在開發期間評估 Cloud Storage bucket 定義的政策遵循情況。
- 稽核現有的 Cloud Storage bucket,確認是否符合政策規定。
費用
在本文件中,您會使用下列 Google Cloud計費元件:
如要根據預測用量估算費用,請使用 Pricing Calculator。
事前準備
-
在 Google Cloud 控制台的專案選擇器頁面中,選取或建立 Google Cloud 專案。
選取或建立專案所需的角色
- 選取專案:選取專案時,不需具備特定 IAM 角色,只要您在專案中獲派角色,即可選取該專案。
-
建立專案:如要建立專案,您需要專案建立者角色 (
roles/resourcemanager.projectCreator),其中包含resourcemanager.projects.create權限。瞭解如何授予角色。
-
在 Google Cloud 控制台中啟用 Cloud Shell。
在 Cloud Shell 中,設定要用於本教學課程的 Google Cloud 專案:
gcloud config set project PROJECT_ID將
PROJECT_ID替換為專案的Google Cloud 專案 ID。執行這項指令時,Cloud Shell 會建立名為GOOGLE_CLOUD_PROJECT的匯出環境變數,其中包含您的專案 ID。如果您未使用 Cloud Shell,可以透過下列指令建立環境變數:export GOOGLE_CLOUD_PROJECT=$(gcloud config get-value core/project)啟用 GKE API:
gcloud services enable container.googleapis.com啟用 Policy Controller API:
gcloud services enable anthospolicycontroller.googleapis.com建立目錄來儲存本教學課程建立的檔案:
mkdir -p ~/cnrm-gatekeeper-tutorial前往您建立的目錄:
cd ~/cnrm-gatekeeper-tutorial
建立 GKE 叢集
在 Cloud Shell 中,使用 Config Connector 外掛程式和 Workload Identity Federation for GKE 建立 GKE 叢集:
gcloud container clusters create CLUSTER_NAME \ --addons ConfigConnector \ --enable-ip-alias \ --num-nodes 4 \ --release-channel regular \ --scopes cloud-platform \ --workload-pool $GOOGLE_CLOUD_PROJECT.svc.id.goog \ --zone ZONE更改下列內容:
CLUSTER_NAME:要用於這個專案的叢集名稱,例如cnrm-gatekeeper-tutorial。ZONE:靠近您所在位置的 Compute Engine 區域,例如asia-southeast1-b。
Config Connector 外掛程式會在 GKE 叢集中安裝自訂資源定義 (CRD),以供Google Cloud 資源使用。
選用:如果您在自己的環境中使用私人叢集,請新增防火牆規則,允許 GKE 叢集控制層連線至 Policy Controller Webhook:
gcloud compute firewall-rules create allow-cluster-control-plane-tcp-8443 \ --allow tcp:8443 \ --network default \ --source-ranges CONTROL_PLANE_CIDR \ --target-tags NODE_TAG更改下列內容:
CONTROL_PLANE_CIDR:GKE 叢集控制層的 IP 範圍,例如172.16.0.16/28。NODE_TAG:套用至 GKE 叢集中所有節點的標記。
如果叢集使用私人節點,則必須套用這項選用防火牆規則,Policy Controller 網路鉤才能正常運作。
設定 Config Connector
安裝 Config Connector 的專案稱為 Google Cloud 主專案。使用 Config Connector 管理資源的專案稱為「代管專案」。在本教學課程中,您會使用 Config Connector 在與 GKE 叢集相同的專案中建立Google Cloud 資源,因此主專案和代管專案是同一個專案。
在 Cloud Shell 中,為 Config Connector 建立 Google 服務帳戶:
gcloud iam service-accounts create SERVICE_ACCOUNT_NAME \ --display-name "Config Connector Gatekeeper tutorial"將
SERVICE_ACCOUNT_NAME替換成要用於這個服務帳戶的名稱,例如cnrm-gatekeeper-tutorial。Config Connector 會使用這個 Google 服務帳戶,在受管理專案中建立資源。將儲存空間管理員角色授予 Google 服務帳戶:
gcloud projects add-iam-policy-binding $GOOGLE_CLOUD_PROJECT \ --member "serviceAccount:SERVICE_ACCOUNT_NAME@$GOOGLE_CLOUD_PROJECT.iam.gserviceaccount.com" \ --role roles/storage.admin在本教學課程中,您將使用 Storage Admin 角色,因為您會使用 Config Connector 建立 Cloud Storage bucket。在您自己的環境中,授予管理要為「Config Connector」建立的 Google Cloud 資源所需的角色。如要進一步瞭解預先定義的角色,請參閱 IAM 說明文件中的「瞭解角色」。
為您在本教學課程中建立的 Config Connector 資源建立 Kubernetes 命名空間:
kubectl create namespace NAMESPACE將 NAMESPACE 替換為您要在教學課程中使用的 Kubernetes 命名空間,例如
tutorial。為命名空間加上註解,指定 Config Connector 應使用哪個專案建立 Google Cloud 資源 (受管理專案):
kubectl annotate namespace NAMESPACE \ cnrm.cloud.google.com/project-id=$GOOGLE_CLOUD_PROJECT建立
ConfigConnectorContext資源,為 Kubernetes 命名空間啟用 Config Connector,並與您建立的 Google 服務帳戶建立關聯:cat << EOF | kubectl apply -f - apiVersion: core.cnrm.cloud.google.com/v1beta1 kind: ConfigConnectorContext metadata: name: configconnectorcontext.core.cnrm.cloud.google.com namespace: NAMESPACE spec: googleServiceAccount: SERVICE_ACCOUNT_NAME@$GOOGLE_CLOUD_PROJECT.iam.gserviceaccount.com EOF建立
ConfigConnectorContext資源時,Config Connector 會在cnrm-system命名空間中建立 Kubernetes 服務帳戶和 StatefulSet,以便管理命名空間中的 Config Connector 資源。等待命名空間的 Config Connector 控制器 Pod:
kubectl wait --namespace cnrm-system --for=condition=Ready pod \ -l cnrm.cloud.google.com/component=cnrm-controller-manager,cnrm.cloud.google.com/scoped-namespace=NAMESPACEPod 準備就緒後,系統會顯示 Cloud Shell 提示。如果收到
error: no matching resources found訊息,請稍候一分鐘再試一次。建立 IAM 政策繫結,將 Config Connector Kubernetes 服務帳戶繫結至 Google 服務帳戶:
gcloud iam service-accounts add-iam-policy-binding \ SERVICE_ACCOUNT_NAME@$GOOGLE_CLOUD_PROJECT.iam.gserviceaccount.com \ --member "serviceAccount:$GOOGLE_CLOUD_PROJECT.svc.id.goog[cnrm-system/cnrm-controller-manager-NAMESPACE]" \ --role roles/iam.workloadIdentityUser這項繫結可讓
cnrm-system命名空間中的cnrm-controller-manager-NAMESPACEKubernetes 服務帳戶,做為您建立的 Google 服務帳戶。
安裝 Policy Controller
按照安裝說明安裝 Policy Controller。
使用 60 秒的稽核間隔。
使用 Config Connector 建立 Google Cloud 資源
在 Cloud Shell 中,建立代表
us-central1區域中 Cloud Storage bucket 的 Config Connector 資訊清單:cat << EOF > tutorial-storagebucket-us-central1.yaml apiVersion: storage.cnrm.cloud.google.com/v1beta1 kind: StorageBucket metadata: name: tutorial-us-central1-$GOOGLE_CLOUD_PROJECT namespace: NAMESPACE spec: location: us-central1 uniformBucketLevelAccess: true EOF如要建立 Cloud Storage bucket,請套用資訊清單:
kubectl apply -f tutorial-storagebucket-us-central1.yaml確認 Config Connector 已建立 Cloud Storage bucket:
gcloud storage ls | grep tutorial輸出結果會與下列內容相似:
gs://tutorial-us-central1-PROJECT_ID/
輸出內容會包含
PROJECT_ID,也就是您的 Google Cloud 專案 ID。如果沒有看到這項輸出內容,請稍候一分鐘,然後再次執行這個步驟。
建立政策
Policy Controller 中的政策由限制範本和限制組成。限制範本包含政策邏輯。限制會指定政策的適用位置,以及政策邏輯的輸入參數。
在 Cloud Shell 中,建立限制 Cloud Storage bucket 位置的限制範本:
cat << EOF > tutorial-storagebucket-location-template.yaml apiVersion: templates.gatekeeper.sh/v1beta1 kind: ConstraintTemplate metadata: name: gcpstoragelocationconstraintv1 spec: crd: spec: names: kind: GCPStorageLocationConstraintV1 validation: openAPIV3Schema: properties: locations: type: array items: type: string exemptions: type: array items: type: string targets: - target: admission.k8s.gatekeeper.sh rego: | package gcpstoragelocationconstraintv1 allowedLocation(reviewLocation) { locations := input.parameters.locations satisfied := [ good | location = locations[_] good = lower(location) == lower(reviewLocation)] any(satisfied) } exempt(reviewName) { input.parameters.exemptions[_] == reviewName } violation[{"msg": msg}] { bucketName := input.review.object.metadata.name bucketLocation := input.review.object.spec.location not allowedLocation(bucketLocation) not exempt(bucketName) msg := sprintf("Cloud Storage bucket <%v> uses a disallowed location <%v>, allowed locations are %v", [bucketName, bucketLocation, input.parameters.locations]) } violation[{"msg": msg}] { not input.parameters.locations bucketName := input.review.object.metadata.name msg := sprintf("No permitted locations provided in constraint for Cloud Storage bucket <%v>", [bucketName]) } EOF套用範本來建立 Cloud Storage bucket:
kubectl apply -f tutorial-storagebucket-location-template.yaml建立限制,只允許新加坡和雅加達區域 (
asia-southeast1和asia-southeast2) 中的 bucket。這項限制會套用至您先前建立的命名空間。這項規則會排除 Cloud Build 的預設 Cloud Storage bucket。cat << EOF > tutorial-storagebucket-location-constraint.yaml apiVersion: constraints.gatekeeper.sh/v1beta1 kind: GCPStorageLocationConstraintV1 metadata: name: singapore-and-jakarta-only spec: enforcementAction: deny match: kinds: - apiGroups: - storage.cnrm.cloud.google.com kinds: - StorageBucket namespaces: - NAMESPACE parameters: locations: - asia-southeast1 - asia-southeast2 exemptions: - ${GOOGLE_CLOUD_PROJECT}_cloudbuild EOF如要限制 bucket 可存在的可用區,請套用下列限制:
kubectl apply -f tutorial-storagebucket-location-constraint.yaml
驗證政策
建立資訊清單,代表位於不允許位置 (
us-west1) 的 Cloud Storage bucket:cat << EOF > tutorial-storagebucket-us-west1.yaml apiVersion: storage.cnrm.cloud.google.com/v1beta1 kind: StorageBucket metadata: name: tutorial-us-west1-$GOOGLE_CLOUD_PROJECT namespace: NAMESPACE spec: location: us-west1 uniformBucketLevelAccess: true EOF如要建立 Cloud Storage bucket,請套用資訊清單:
kubectl apply -f tutorial-storagebucket-us-west1.yaml輸出結果會與下列內容相似:
Error from server ([singapore-and-jakarta-only] Cloud Storage bucket <tutorial-us-west1-PROJECT_ID> uses a disallowed location <us-west1>, allowed locations are ["asia-southeast1", "asia-southeast2"]): error when creating "tutorial-storagebucket-us-west1.yaml": admission webhook "validation.gatekeeper.sh" denied the request: [singapore-and-jakarta-only] Cloud Storage bucket <tutorial-us-west1-PROJECT_ID> uses a disallowed location <us-west1>, allowed locations are ["asia-southeast1", "asia-southeast2"]
選用:您可以在 Cloud 稽核記錄中查看拒絕要求的決策記錄。查詢專案的管理員活動記錄:
gcloud logging read --limit=1 \ "logName=\"projects/$GOOGLE_CLOUD_PROJECT/logs/cloudaudit.googleapis.com%2Factivity\""' resource.type="k8s_cluster" resource.labels.cluster_name="CLUSTER_NAME" resource.labels.location="ZONE" protoPayload.authenticationInfo.principalEmail!~"system:serviceaccount:cnrm-system:.*" protoPayload.methodName:"com.google.cloud.cnrm." protoPayload.status.code=7'輸出結果會與下列內容相似:
insertId: 3c6940bb-de14-4d18-ac4d-9a6becc70828 labels: authorization.k8s.io/decision: allow authorization.k8s.io/reason: '' mutation.webhook.admission.k8s.io/round_0_index_0: '{"configuration":"mutating-webhook.cnrm.cloud.google.com","webhook":"container-annotation-handler.cnrm.cloud.google.com","mutated":true}' mutation.webhook.admission.k8s.io/round_0_index_1: '{"configuration":"mutating-webhook.cnrm.cloud.google.com","webhook":"management-conflict-annotation-defaulter.cnrm.cloud.google.com","mutated":true}' logName: projects/PROJECT_ID/logs/cloudaudit.googleapis.com%2Factivity operation: first: true id: 3c6940bb-de14-4d18-ac4d-9a6becc70828 last: true producer: k8s.io protoPayload: '@type': type.googleapis.com/google.cloud.audit.AuditLog authenticationInfo: principalEmail: user@example.com authorizationInfo: - permission: com.google.cloud.cnrm.storage.v1beta1.storagebuckets.create resource: storage.cnrm.cloud.google.com/v1beta1/namespaces/NAMESPACE/storagebuckets/tutorial-us-west1-PROJECT_ID methodName: com.google.cloud.cnrm.storage.v1beta1.storagebuckets.create requestMetadata: callerIp: 203.0.113.1 callerSuppliedUserAgent: kubectl/v1.21.1 (linux/amd64) kubernetes/5e58841 resourceName: storage.cnrm.cloud.google.com/v1beta1/namespaces/NAMESPACE/storagebuckets/tutorial-us-west1-PROJECT_ID serviceName: k8s.io status: code: 7 message: Forbidden receiveTimestamp: '2021-05-21T06:56:24.940264678Z' resource: labels: cluster_name: CLUSTER_NAME location: CLUSTER_ZONE project_id: PROJECT_ID type: k8s_cluster timestamp: '2021-05-21T06:56:09.060635Z'
methodName欄位會顯示嘗試執行的作業,resourceName則會顯示 Config Connector 資源的完整名稱,而status區段會顯示要求未成功,並提供錯誤代碼7和訊息Forbidden。建立資訊清單,代表位於允許位置 (
asia-southeast1) 的 Cloud Storage bucket:cat << EOF > tutorial-storagebucket-asia-southeast1.yaml apiVersion: storage.cnrm.cloud.google.com/v1beta1 kind: StorageBucket metadata: name: tutorial-asia-southeast1-$GOOGLE_CLOUD_PROJECT namespace: NAMESPACE spec: location: asia-southeast1 uniformBucketLevelAccess: true EOF如要建立 Cloud Storage bucket,請套用資訊清單:
kubectl apply -f tutorial-storagebucket-asia-southeast1.yaml輸出結果會與下列內容相似:
storagebucket.storage.cnrm.cloud.google.com/tutorial-asia-southeast1-PROJECT_ID created
輸出內容會包含
PROJECT_ID,也就是您的 Google Cloud 專案 ID。確認 Config Connector 已建立 Cloud Storage bucket:
gcloud storage ls | grep tutorial輸出結果會與下列內容相似:
gs://tutorial-asia-southeast1-PROJECT_ID/ gs://tutorial-us-central1-PROJECT_ID/
如果沒有看到這項輸出內容,請稍候一分鐘,然後再次執行這個步驟。
稽核限制
Policy Controller 中的稽核控制器會定期根據限制評估資源。對於在限制條件之前建立的資源,以及在 Config Connector 外部建立的資源,控制器會偵測政策違規情形。
在 Cloud Shell 中,查看使用
GCPStorageLocationConstraintV1限制範本的所有限制違規事項:kubectl get gcpstoragelocationconstraintv1 -o json \ | jq '.items[].status.violations'輸出結果會與下列內容相似:
[ { "enforcementAction": "deny", "kind": "StorageBucket", "message": "Cloud Storage bucket <tutorial-us-central1-PROJECT_ID> uses a disallowed location <us-central1>, allowed locations are \"asia-southeast1\", \"asia-southeast2\"", "name": "tutorial-us-central1-PROJECT_ID", "namespace": "NAMESPACE" } ]您會看到在建立限制條件之前,於
us-central1中建立的 Cloud Storage bucket。
在開發期間驗證資源
在開發和持續整合建構期間,建議您先根據限制條件驗證資源,再將這些資源套用至 GKE 叢集。驗證功能可快速提供意見回饋,協助您及早發現資源和限制的問題。下列步驟說明如何使用 kpt 驗證資源。kpt 指令列工具可讓您管理及套用 Kubernetes 資源資訊清單。
在 Cloud Shell 中,使用 kpt 執行
gatekeeperKRM 函式:kpt fn eval . --image=gcr.io/kpt-fn/gatekeeper:v0.2 --truncate-output=falseKRM 函式是一種程式,可變動或驗證儲存在本機檔案系統中的 Kubernetes 資源 (以 YAML 檔案形式)。
gatekeeperKRM 函式會根據 Gatekeeper 政策,驗證 Config Connector Cloud Storage bucket 資源。gatekeeperKRM 函式會封裝為容器映像檔,並儲存在 Artifact Registry。函式會回報
us-central1和us-west1區域中 Cloud Storage bucket 的資訊清單檔案違反限制。輸出結果會與下列內容相似:
[RUNNING] "gcr.io/kpt-fn/gatekeeper:v0.2" [FAIL] "gcr.io/kpt-fn/gatekeeper:v0.2" Results: [ERROR] Cloud Storage bucket <tutorial-us-central1-PROJECT_ID> uses a disallowed location <us-central1>, allowed locations are ["asia-southeast1", "asia-southeast2"] violatedConstraint: singapore-and-jakarta-only in object "storage.cnrm.cloud.google.com/v1beta1/StorageBucket/tutorial/tutorial-us-central1-GOOGLE_CLOUD_PROJECT" in file "tutorial-storagebucket-us-central1.yaml" [ERROR] Cloud Storage bucket <tutorial-us-west1-PROJECT_ID> uses a disallowed location <us-west1>, allowed locations are ["asia-southeast1", "asia-southeast2"] violatedConstraint: singapore-and-jakarta-only in object "storage.cnrm.cloud.google.com/v1beta1/StorageBucket/tutorial/tutorial-us-west1-GOOGLE_CLOUD_PROJECT" in file "tutorial-storagebucket-us-west1.yaml" Stderr: "[error] storage.cnrm.cloud.google.com/v1beta1/StorageBucket/test/tutorial-us-central1-PROJECT_ID : Cloud Storage bucket <tutorial-us-central1-PROJECT_ID> uses a disallowed location <us-central1>, allowed locations are [\"asia-southeast1\", \"asia-southeast2\"]" "violatedConstraint: singapore-and-jakarta-only" "" "[error] storage.cnrm.cloud.google.com/v1beta1/StorageBucket/test/tutorial-us-west1-PROJECT_IDT : Cloud Storage bucket <tutorial-us-west1-PROJECT_IDgt; uses a disallowed location <us-west1>, allowed locations are [\"asia-southeast1\", \"asia-southeast2\"]" "violatedConstraint: singapore-and-jakarta-only" "" Exit code: 1
驗證在 Config Connector 外部建立的資源
您可以匯出在 Config Connector 外部建立的 Google Cloud 資源,藉此驗證這些資源。匯出資源後,請使用下列任一選項,根據匯出的資源評估 Policy Controller 政策:
使用
gatekeeperKRM 函式驗證資源。將資源匯入 Config Connector。
如要匯出資源,請使用 Cloud Asset Inventory。
在 Cloud Shell 中啟用 Cloud Asset API:
gcloud services enable cloudasset.googleapis.com刪除
us-central1和us-west1中 Cloud Storage bucket 的 Kubernetes 資源資訊清單檔案:rm tutorial-storagebucket-us-*.yaml匯出目前專案中的所有 Cloud Storage 資源,並將輸出內容儲存在名為
export.yaml的檔案中:gcloud beta resource-config bulk-export \ --project $GOOGLE_CLOUD_PROJECT \ --resource-format krm \ --resource-types StorageBucket > export.yaml輸出結果會與下列內容相似:
Exporting resource configurations to stdout... Export complete.
透過串連 KRM 函式,建立 kpt 管道。這個管道會根據 Cloud Storage bucket 位置政策,驗證目前目錄中的資源:
kpt fn source . \ | kpt fn eval - --image=gcr.io/kpt-fn/set-namespace:v0.1 -- namespace=NAMESPACE \ | kpt fn eval - --image=gcr.io/kpt-fn/gatekeeper:v0.2 --truncate-output=false匯出的資源沒有
namespace中繼資料屬性的值。這個管道會使用名為set-namespace的 KRM 函式,設定所有資源的namespace值。輸出內容類似於下列內容,且會顯示您匯出資源的違規事項:
[RUNNING] "gcr.io/kpt-fn/set-namespace:v0.1" [PASS] "gcr.io/kpt-fn/set-namespace:v0.1" [RUNNING] "gcr.io/kpt-fn/gatekeeper:v0.2" [FAIL] "gcr.io/kpt-fn/gatekeeper:v0.2" Results: [ERROR] Cloud Storage bucket <tutorial-us-central1-PROJECT_ID> uses a disallowed location <us-central1>, allowed locations are ["asia-southeast1", "asia-southeast2"] violatedConstraint: singapore-and-jakarta-only in object "storage.cnrm.cloud.google.com/v1beta1/StorageBucket/tutorial/tutorial-us-central1-GOOGLE_CLOUD_PROJECT" in file "export.yaml" Stderr: "[error] storage.cnrm.cloud.google.com/v1beta1/StorageBucket/test/tutorial-us-central1-PROJECT_ID : Cloud Storage bucket <tutorial-us-central1-PROJECT_ID> uses a disallowed location <us-central1>, allowed locations are [\"asia-southeast1\", \"asia-southeast2\"]" "violatedConstraint: singapore-and-jakarta-only" "" Exit code: 1如果 Google Cloud 專案包含您在本教學課程前建立的 Cloud Storage bucket,且這些 bucket 的位置違反限制,輸出內容中就會顯示先前建立的 bucket。
恭喜,您已成功設定政策,控管 Cloud Storage bucket 的允許位置。教學課程已完成。 現在可以繼續為其他 Google Cloud資源新增自己的政策。
疑難排解
如果 Config Connector 未建立預期資源,請在 Cloud Shell 中使用下列指令,查看 Config Connector 控制器管理員的記錄: Google Cloud
kubectl logs --namespace cnrm-system --container manager \
--selector cnrm.cloud.google.com/component=cnrm-controller-manager,cnrm.cloud.google.com/scoped-namespace=NAMESPACE
如果 Policy Controller 未正確強制執行政策,請使用下列指令查看控制器管理員的記錄:
kubectl logs deployment/gatekeeper-controller-manager \
--namespace gatekeeper-system
如果 Policy Controller 未在限制物件的 status 欄位中回報違規事項,請使用下列指令查看稽核控制器記錄:
kubectl logs deployment/gatekeeper-audit --namespace gatekeeper-system
如果本教學課程有其他問題,建議您參閱下列文件:
清除所用資源
為避免因為本教學課程所用資源,導致系統向 Google Cloud 收取費用,請刪除含有相關資源的專案,或者保留專案但刪除個別資源。
刪除專案
- 前往 Google Cloud 控制台的「Manage resources」(管理資源) 頁面。
- 如果您要刪除的專案隸屬於某個組織,請展開「Name」(名稱) 欄中的「Organization」(組織) 清單。
- 在專案清單中選取要刪除的專案,然後點選「Delete」(刪除)。
- 在對話方塊中輸入專案 ID,然後按一下 [Shut down] (關閉) 以刪除專案。
刪除資源
如要保留本教學課程使用的 Google Cloud 專案,請刪除個別資源。
在 Cloud Shell 中,刪除 Cloud Storage bucket 位置限制:
kubectl delete -f tutorial-storagebucket-location-constraint.yaml在 Config Connector 管理的命名空間中,為所有
storagebucket資源新增cnrm.cloud.google.com/force-destroy註解,並將字串值設為true:kubectl annotate storagebucket --all --namespace NAMESPACE \ cnrm.cloud.google.com/force-destroy=true這項註解是指令,可讓 Config Connector 在您刪除 GKE 叢集中的對應
storagebucket資源時,一併刪除 Cloud Storage bucket,即使 bucket 含有物件也一樣。刪除代表 Cloud Storage bucket 的 Config Connector 資源:
kubectl delete --namespace NAMESPACE storagebucket --all刪除 GKE 叢集:
gcloud container clusters delete CLUSTER_NAME \ --zone ZONE --async --quiet在 IAM 中刪除 Workload Identity 政策繫結:
gcloud iam service-accounts remove-iam-policy-binding \ SERVICE_ACCOUNT_NAME@$GOOGLE_CLOUD_PROJECT.iam.gserviceaccount.com \ --member "serviceAccount:$GOOGLE_CLOUD_PROJECT.svc.id.goog[cnrm-system/cnrm-controller-manager-NAMESPACE]" \ --role roles/iam.workloadIdentityUser刪除 Google 服務帳戶的 Cloud Storage 管理員角色繫結:
gcloud projects remove-iam-policy-binding $GOOGLE_CLOUD_PROJECT \ --member "serviceAccount:SERVICE_ACCOUNT_NAME@$GOOGLE_CLOUD_PROJECT.iam.gserviceaccount.com" \ --role roles/storage.admin刪除為 Config Connector 建立的 Google 服務帳戶:
gcloud iam service-accounts delete --quiet \ SERVICE_ACCOUNT_NAME@$GOOGLE_CLOUD_PROJECT.iam.gserviceaccount.com