ניהול משאבי NetApp Volumes באמצעות אילוצים מותאמים אישית

בדף הזה מוסבר איך להשתמש באילוצים מותאמים אישית של שירות מדיניות הארגון כדי להגביל פעולות ספציפיות במשאבים הבאים של Google Cloud :

  • netapp.googleapis.com/ActiveDirectory
  • netapp.googleapis.com/Backup
  • netapp.googleapis.com/BackupPolicy
  • netapp.googleapis.com/BackupVault
  • netapp.googleapis.com/HostGroup
  • netapp.googleapis.com/KmsConfig
  • netapp.googleapis.com/QuotaRule
  • netapp.googleapis.com/Snapshot
  • netapp.googleapis.com/StoragePool
  • netapp.googleapis.com/Volume

מידע נוסף על מדיניות הארגון זמין במאמר בנושא מדיניות ארגונית בהתאמה אישית.

מידע על מדיניות הארגון ואילוצים

Google Cloud שירות מדיניות הארגון מאפשר לכם לקבל שליטה מרוכזת ופרוגרמטית על המשאבים של הארגון. בתור אדמינים של מדיניות הארגון, אתם יכולים להגדיר מדיניות ארגונית, שהיא קבוצה של הגבלות שנקראות אילוצים שחלות על משאבים ב-Google Cloud ועל משאבים שנגזרים מהם בGoogle Cloud היררכיית המשאבים. אפשר לאכוף את מדיניות הארגון ברמת הארגון, התיקייה או הפרויקט.

שירות מדיניות הארגון מספק אילוצים מנוהלים מובנים עבור שירותים שונים של Google Cloud . עם זאת, אם אתם רוצים שליטה מדויקת יותר בשדות הספציפיים שמוגבלים במדיניות הארגון, אתם יכולים גם ליצור אילוצים בהתאמה אישית ולהשתמש בהם במדיניות הארגון.

העברה בירושה של מדיניות

כברירת מחדל, מדיניות הארגון עוברת בירושה לצאצאים של המשאבים שבהם אתם אוכפים את המדיניות. לדוגמה, אם אוכפים מדיניות בתיקייה, Google Cloud המדיניות נאכפת בכל הפרויקטים בתיקייה. מידע נוסף על ההתנהגות הזו ועל שינוי שלה זמין במאמר בנושא כללי הערכה היררכיים.

לפני שמתחילים

  1. נכנסים לחשבון Google Cloud . אם אתם משתמשים חדשים ב- Google Cloud, צרו חשבון כדי שתוכלו להעריך את הביצועים של המוצרים שלנו בתרחישים מהעולם האמיתי. לקוחות חדשים מקבלים בחינם גם קרדיט בשווי 300$ להרצה, לבדיקה ולפריסה של עומסי העבודה.
  2. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

  3. Verify that billing is enabled for your Google Cloud project.

  4. התקינו את ה-CLI של Google Cloud.

  5. אם אתם משתמשים בספק זהויות חיצוני (IdP), קודם אתם צריכים להיכנס ל-CLI של gcloud באמצעות המאגר המאוחד לניהול זהויות.

  6. כדי לאתחל את ה-CLI של gcloud, הריצו את הפקודה הבאה:

    gcloud init
  7. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

  8. Verify that billing is enabled for your Google Cloud project.

  9. התקינו את ה-CLI של Google Cloud.

  10. אם אתם משתמשים בספק זהויות חיצוני (IdP), קודם אתם צריכים להיכנס ל-CLI של gcloud באמצעות המאגר המאוחד לניהול זהויות.

  11. כדי לאתחל את ה-CLI של gcloud, הריצו את הפקודה הבאה:

    gcloud init
  12. חשוב לוודא שאתם יודעים מהו מזהה הארגון שלכם.

התפקידים הנדרשים

כדי לקבל את ההרשאות שדרושות לניהול מדיניות ארגונית בהתאמה אישית, צריך לבקש מהאדמין להקצות לכם את תפקיד ה-IAM‏ Organization Policy Administrator (אדמין של מדיניות ארגונית) ‏(roles/orgpolicy.policyAdmin) במשאב הארגון. כדי לקרוא הסבר על מתן תפקידים, ראו איך מנהלים את הגישה ברמת הפרויקט, התיקייה והארגון.

יכול להיות שאפשר לקבל את ההרשאות הנדרשות גם באמצעות תפקידים בהתאמה אישית או תפקידים מוגדרים מראש.

משאבים נתמכים ב-Google Cloud NetApp Volumes

בטבלה הבאה מפורטים המשאבים של Google Cloud NetApp Volumes שאפשר להפנות אליהם באילוצים בהתאמה אישית.

משאב שדה
netapp.googleapis.com/ActiveDirectory resource.aesEncryption
resource.description
resource.dns
resource.domain
resource.encryptDcConnections
resource.kdcHostname
resource.kdcIp
resource.ldapSigning
resource.name
resource.netBiosPrefix
resource.nfsUsersWithLdap
resource.organizationalUnit
resource.site
netapp.googleapis.com/Backup resource.description
resource.name
resource.ontapSource.snapshotUuid
resource.ontapSource.storagePool
resource.ontapSource.volumeUuid
resource.sourceSnapshot
resource.sourceVolume
netapp.googleapis.com/BackupPolicy resource.dailyBackupLimit
resource.description
resource.enabled
resource.monthlyBackupLimit
resource.name
resource.weeklyBackupLimit
netapp.googleapis.com/BackupVault resource.backupRegion
resource.backupRetentionPolicy.backupMinimumEnforcedRetentionDays
resource.backupRetentionPolicy.dailyBackupImmutable
resource.backupRetentionPolicy.manualBackupImmutable
resource.backupRetentionPolicy.monthlyBackupImmutable
resource.backupRetentionPolicy.weeklyBackupImmutable
resource.backupVaultType
resource.description
resource.kmsConfig
resource.name
resource.sourceRegion
netapp.googleapis.com/HostGroup resource.description
resource.hosts
resource.name
resource.osType
resource.type
netapp.googleapis.com/KmsConfig resource.cryptoKeyName
resource.description
resource.name
netapp.googleapis.com/QuotaRule resource.description
resource.diskLimitMib
resource.name
resource.type
netapp.googleapis.com/Snapshot resource.description
resource.name
netapp.googleapis.com/StoragePool resource.activeDirectory
resource.allowAutoTiering
resource.capacityGib
resource.customPerformanceEnabled
resource.description
resource.enableHotTierAutoResize
resource.hotTierSizeGib
resource.kmsConfig
resource.ldapEnabled
resource.mode
resource.name
resource.network
resource.psaRange
resource.qosType
resource.replicaZone
resource.scaleType
resource.serviceLevel
resource.totalIops
resource.totalThroughputMibps
resource.type
resource.zone
netapp.googleapis.com/Volume resource.backupConfig.backupPolicies
resource.backupConfig.backupVault
resource.backupConfig.scheduledBackupEnabled
resource.blockDevices.hostGroups
resource.blockDevices.name
resource.blockDevices.osType
resource.blockDevices.sizeGib
resource.cacheParameters.cacheConfig.cachePrePopulate.excludePathList
resource.cacheParameters.cacheConfig.cachePrePopulate.pathList
resource.cacheParameters.cacheConfig.cachePrePopulate.recursion
resource.cacheParameters.cacheConfig.cifsChangeNotifyEnabled
resource.cacheParameters.cacheConfig.writebackEnabled
resource.cacheParameters.enableGlobalFileLock
resource.cacheParameters.peerClusterName
resource.cacheParameters.peeringCommandExpiryTime
resource.cacheParameters.peerIpAddresses
resource.cacheParameters.peerSvmName
resource.cacheParameters.peerVolumeName
resource.capacityGib
resource.description
resource.exportPolicy.rules.accessType
resource.exportPolicy.rules.allowedClients
resource.exportPolicy.rules.anonUid
resource.exportPolicy.rules.hasRootAccess
resource.exportPolicy.rules.kerberos5iReadOnly
resource.exportPolicy.rules.kerberos5iReadWrite
resource.exportPolicy.rules.kerberos5pReadOnly
resource.exportPolicy.rules.kerberos5pReadWrite
resource.exportPolicy.rules.kerberos5ReadOnly
resource.exportPolicy.rules.kerberos5ReadWrite
resource.exportPolicy.rules.nfsv3
resource.exportPolicy.rules.nfsv4
resource.exportPolicy.rules.squashMode
resource.hybridReplicationParameters.clusterLocation
resource.hybridReplicationParameters.description
resource.hybridReplicationParameters.hybridReplicationType
resource.hybridReplicationParameters.largeVolumeConstituentCount
resource.hybridReplicationParameters.peerClusterName
resource.hybridReplicationParameters.peerIpAddresses
resource.hybridReplicationParameters.peerSvmName
resource.hybridReplicationParameters.peerVolumeName
resource.hybridReplicationParameters.replication
resource.hybridReplicationParameters.replicationSchedule
resource.kerberosEnabled
resource.largeCapacity
resource.largeCapacityConfig.constituentCount
resource.multipleEndpoints
resource.name
resource.protocols
resource.restoreParameters.sourceBackup
resource.restoreParameters.sourceSnapshot
resource.restrictedActions
resource.securityStyle
resource.shareName
resource.smbSettings
resource.snapReserve
resource.snapshotDirectory
resource.snapshotPolicy.dailySchedule.hour
resource.snapshotPolicy.dailySchedule.minute
resource.snapshotPolicy.dailySchedule.snapshotsToKeep
resource.snapshotPolicy.enabled
resource.snapshotPolicy.hourlySchedule.minute
resource.snapshotPolicy.hourlySchedule.snapshotsToKeep
resource.snapshotPolicy.monthlySchedule.daysOfMonth
resource.snapshotPolicy.monthlySchedule.hour
resource.snapshotPolicy.monthlySchedule.minute
resource.snapshotPolicy.monthlySchedule.snapshotsToKeep
resource.snapshotPolicy.weeklySchedule.day
resource.snapshotPolicy.weeklySchedule.hour
resource.snapshotPolicy.weeklySchedule.minute
resource.snapshotPolicy.weeklySchedule.snapshotsToKeep
resource.storagePool
resource.throughputMibps
resource.tieringPolicy.coolingThresholdDays
resource.tieringPolicy.hotTierBypassModeEnabled
resource.tieringPolicy.tierAction
resource.unixPermissions

הגדרת אילוץ בהתאמה אישית

אילוץ בהתאמה אישית מוגדר בקובץ YAML לפי המשאבים, השיטות, התנאים והפעולות שנתמכים על ידי השירות שבו אתם אוכפים את מדיניות הארגון. התנאים להגבלות המותאמות אישית מוגדרים באמצעות Common Expression Language ‏ (CEL). מידע נוסף על יצירת תנאים באילוצים מותאמים אישית באמצעות CEL זמין בקטע על CEL במאמר יצירה וניהול של אילוצים מותאמים אישית.

המסוף

כדי ליצור אילוץ בהתאמה אישית:

  1. נכנסים לדף Organization policies במסוף Google Cloud .

    מעבר למדיניות הארגון

  2. בתפריט לבחירת פרויקט, בוחרים את הפרויקט שרוצים להגדיר עבורו את מדיניות הארגון.
  3. לוחצים על Custom constraint (הגבלה מותאמת אישית).
  4. בתיבה שם לתצוגה, מזינים שם שאנשים יכולים לקרוא לאילוץ. השם הזה משמש בהודעות שגיאה, ואפשר להשתמש בו לצורך זיהוי וניפוי באגים. אל תשתמשו בפרטים אישיים מזהים (PII) או במידע אישי רגיש בשמות לתצוגה, כי השם הזה עלול להיחשף בהודעות שגיאה. השדה הזה יכול להכיל עד 200 תווים.
  5. בתיבה Constraint ID (מזהה ההגבלה), מזינים את המזהה שרוצים להגדיר להגבלה החדשה בהתאמה אישית. אילוץ מותאם אישית יכול להכיל רק אותיות (כולל אותיות גדולות וקטנות) או מספרים, למשל custom.restrictStoragePoolCapacity. השדה הזה יכול להכיל עד 70 תווים, לא כולל הקידומת (custom.), לדוגמה, organizations/123456789/customConstraints/custom. אל תכללו פרטים אישיים מזהים (PII) או נתונים רגישים במזהה האילוץ, כי הם עלולים להיחשף בהודעות שגיאה.
  6. בתיבה Description, מזינים תיאור של האילוץ שקל לקרוא ולהבין. התיאור הזה משמש כהודעת שגיאה כשמתרחשת הפרה של המדיניות. לכלול פרטים על הסיבה להפרת המדיניות ואיך לפתור אותה. אל תכללו בתיאור פרטים אישיים מזהים (PII) או מידע אישי רגיש, כי הם עלולים להיחשף בהודעות שגיאה. השדה הזה יכול להכיל עד 2,000 תווים.
  7. בתיבה Resource type, בוחרים את השם של Google Cloud משאב REST שמכיל את האובייקט והשדה שרוצים להגביל – לדוגמה, container.googleapis.com/NodePool. רוב סוגי המשאבים תומכים בעד 20 אילוצים מותאמים אישית. אם תנסו ליצור עוד אילוצים בהתאמה אישית, הפעולה תיכשל.
  8. בקטע שיטת אכיפה, בוחרים אם לאכוף את ההגבלה על שיטת REST‏ CREATE או על שיטות CREATE ו-UPDATE. אם אוכפים את האילוץ באמצעות השיטה UPDATE במשאב שמפר את האילוץ, מדיניות הארגון חוסמת שינויים במשאב הזה, אלא אם השינוי פותר את ההפרה.
  9. כדי לראות את השיטות הנתמכות לכל שירות, מחפשים את השירות בקטע שירותים שתומכים באילוצים בהתאמה אישית.

  10. כדי להגדיר תנאי, לוחצים על Edit condition.
    1. בחלונית Add condition, יוצרים תנאי CEL שמתייחס למשאב שירות נתמך, לדוגמה, resource.management.autoUpgrade == false. השדה הזה יכול להכיל עד 1,000 תווים. פרטים על השימוש ב-CEL זמינים במאמר בנושא Common Expression Language. מידע נוסף על משאבי השירות שאפשר להשתמש בהם באילוצים בהתאמה אישית זמין במאמר שירותים שתומכים באילוצים בהתאמה אישית.
    2. לוחצים על Save.
  11. בקטע פעולה, בוחרים אם לאשר או לדחות את השיטה שנבדקה אם התנאי מתקיים.
  12. הפעולה deny (דחייה) פירושה שהפעולה ליצירה או לעדכון של המשאב נחסמת אם התנאי מוערך כ-True.

    הפעולה allow (אישור) אומרת שהפעולה ליצירה או לעדכון של המשאב מותרת רק אם התנאי מחזיר את הערך true. כל מקרה אחר, מלבד אלה שמפורטים במפורש בתנאי, נחסם.

  13. לוחצים על יצירת אילוץ.
  14. אחרי שמזינים ערך בכל שדה, מופיעה משמאל הגדרת ה-YAML המקבילה לאילוץ המותאם אישית הזה.

gcloud

  1. כדי ליצור אילוץ בהתאמה אישית, יוצרים קובץ YAML בפורמט הבא:
  2. name: organizations/ORGANIZATION_ID/customConstraints/CONSTRAINT_NAME
    resourceTypes: RESOURCE_NAME
    methodTypes:
      - CREATE
    - UPDATE
    condition: "CONDITION" actionType: ACTION displayName: DISPLAY_NAME description: DESCRIPTION

    מחליפים את מה שכתוב בשדות הבאים:

    • ‫ORGANIZATION_ID: מזהה הארגון, כמו 123456789.
    • ‫CONSTRAINT_NAME: השם שרוצים לתת לאילוץ המותאם אישית החדש. אילוץ מותאם אישית יכול להכיל רק אותיות (כולל אותיות רישיות וקטנות) או מספרים, למשל, custom.restrictStoragePoolCapacity. השדה הזה יכול להכיל עד 70 תווים, לא כולל הקידומת (custom.) – לדוגמה, organizations/123456789/customConstraints/custom. אל תכללו פרטים אישיים מזהים (PII) או נתונים רגישים במזהה האילוץ, כי הם עלולים להיחשף בהודעות שגיאה.
    • ‫RESOURCE_NAME: השם מוגדר במלואו של המשאב Google Cloudשמכיל את האובייקט והשדה שרוצים להגביל. לדוגמה, netapp.googleapis.com/StoragePool. רוב סוגי המשאבים תומכים בעד 20 אילוצים מותאמים אישית. אם תנסו ליצור עוד אילוצים בהתאמה אישית, הפעולה תיכשל.
    • ‫methodTypes: שיטות ה-REST שבהן האילוץ נאכף. הערך יכול להיות CREATE או גם CREATE וגם UPDATE. אם אוכפים את האילוץ באמצעות השיטה UPDATE על משאב שמפר את האילוץ, מדיניות הארגון חוסמת שינויים במשאב הזה, אלא אם השינוי פותר את ההפרה.
    • כדי לראות את השיטות הנתמכות לכל שירות, מחפשים את השירות ב שירותים שתומכים באילוצים בהתאמה אישית.

    • ‫CONDITION: תנאי CEL שנכתב על סמך ייצוג של משאב שירות נתמך. השדה הזה יכול להכיל עד 1,000 תווים. לדוגמה, "resource.capacityGib <= 10240".
    • מידע נוסף על המשאבים שאפשר לכתוב תנאים לגביהם זמין במאמר משאבים נתמכים.

    • ‫ACTION: הפעולה שתתבצע אם התנאי condition יתקיים. הערכים האפשריים הם ALLOW ו-DENY.
    • פעולת ההרשאה פירושה שאם התנאי מקבל את הערך True, הפעולה ליצירה או לעדכון של המשאב מותרת. המשמעות היא שכל מקרה אחר, חוץ מהמקרה שמופיע במפורש בתנאי, ייחסם.

      הפעולה deny (דחייה) פירושה שאם התנאי מחזיר את הערך True, הפעולה ליצירה או לעדכון של המשאב נחסמת.

    • DISPLAY_NAME: שם קריא לאנשים של האילוץ. השם הזה מופיע בהודעות שגיאה ויכול לשמש לזיהוי ולניפוי באגים. אל תשתמשו בפרטים אישיים מזהים (PII) או במידע אישי רגיש בשמות המוצגים, כי השם הזה עלול להיחשף בהודעות שגיאה. השדה הזה יכול להכיל עד 200 תווים.
    • ‫DESCRIPTION: תיאור ידידותי למשתמש של האילוץ שיוצג כהודעת שגיאה אם המדיניות תופר. השדה הזה יכול להכיל עד 2,000 תווים.
  3. אחרי שיוצרים קובץ YAML לאילוץ חדש בהתאמה אישית, צריך להגדיר אותו כדי שיהיה זמין למדיניות הארגון בארגון שלכם. כדי להגדיר אילוץ בהתאמה אישית, משתמשים בפקודה gcloud org-policies set-custom-constraint:
  4. gcloud org-policies set-custom-constraint CONSTRAINT_PATH

    מחליפים את CONSTRAINT_PATH בנתיב המלא לקובץ האילוצים המותאמים אישית. לדוגמה, /home/user/customconstraint.yaml.

    אחרי שהפעולה הזו תושלם, האילוצים המותאמים אישית יהיו זמינים כמדיניות ארגונית ברשימת Google Cloud מדיניות הארגון.

  5. כדי לוודא שהאילוץ המותאם אישית קיים, משתמשים בפקודה gcloud org-policies list-custom-constraints:
  6. gcloud org-policies list-custom-constraints --organization=ORGANIZATION_ID

    מחליפים את ORGANIZATION_ID במזהה של משאב הארגון.

    מידע נוסף זמין במאמר בנושא צפייה במדיניות הארגון.

אכיפה של מדיניות ארגון מותאמת אישית

כדי לאכוף אילוץ, יוצרים מדיניות ארגון שמפנה אליו, ואז מחילים את מדיניות הארגון הזו על משאב Google Cloud .

המסוף

  1. נכנסים לדף Organization policies במסוף Google Cloud .

    מעבר למדיניות הארגון

  2. בכלי לבחירת פרויקטים, בוחרים את הפרויקט שרוצים להגדיר לו את מדיניות הארגון.
  3. מהרשימה בדף מדיניות הארגון, בוחרים את האילוץ כדי לראות את הדף פרטי המדיניות של האילוץ הזה.
  4. כדי להגדיר את מדיניות הארגון עבור המשאב הזה, לוחצים על ניהול מדיניות.
  5. בדף עריכת המדיניות, בוחרים באפשרות במקום המדיניות של המשאב הראשי.
  6. לוחצים על Add a rule.
  7. בקטע Enforcement (אכיפה), בוחרים אם מדיניות הארגון הזו נאכפת או לא.
  8. אופציונלי: כדי להגדיר את מדיניות הארגון כתלויה בתג, לוחצים על הוספת תנאי. הערה: אם מוסיפים כלל מותנה למדיניות ארגון, צריך להוסיף לפחות כלל לא מותנה אחד, אחרת אי אפשר לשמור את המדיניות. מידע נוסף על מדיניות ארגונית עם תגים
  9. לוחצים על בדיקת שינויים כדי לדמות את ההשפעה של מדיניות הארגון. מידע נוסף זמין במאמר בדיקת שינויים במדיניות הארגון באמצעות סימולטור המדיניות.
  10. כדי לאכוף את המדיניות של הארגון במצב פרימטר לבדיקות, לוחצים על הגדרת המדיניות להרצת בדיקה. מידע נוסף זמין במאמר בנושא בדיקת מדיניות הארגון.
  11. אחרי שמוודאים שמדיניות הארגון במצב הרצה יבשה פועלת כמו שרוצים, לוחצים על הגדרת מדיניות כדי להגדיר את המדיניות הפעילה.

gcloud

  1. כדי ליצור מדיניות ארגונית עם כללים בוליאניים, יוצרים קובץ YAML של מדיניות שמפנה לאילוץ:
  2. name: projects/PROJECT_ID/policies/CONSTRAINT_NAME
    spec:
      rules:
      - enforce: true
    
    dryRunSpec:
      rules:
      - enforce: true

    מחליפים את מה שכתוב בשדות הבאים:

    • ‫PROJECT_ID: הפרויקט שבו רוצים לאכוף את האילוץ.
    • CONSTRAINT_NAME: השם שהגדרתם לאילוץ המותאם אישית. לדוגמה, custom.restrictStoragePoolCapacity.
  3. כדי לאכוף את מדיניות הארגון במצב הרצה יבשה, מריצים את הפקודה הבאה עם הדגל dryRunSpec:
  4. gcloud org-policies set-policy POLICY_PATH --update-mask=dryRunSpec

    מחליפים את הערך POLICY_PATH בנתיב המלא לקובץ ה-YAML של מדיניות הארגון. יכול להיות שיחלפו עד 15 דקות עד שהמדיניות תיכנס לתוקף.

  5. אחרי שמוודאים שמדיניות הארגון במצב הרצה יבשה פועלת כמו שרוצים, מגדירים את המדיניות הפעילה באמצעות הפקודה org-policies set-policy והדגל spec:
  6. gcloud org-policies set-policy POLICY_PATH --update-mask=spec

    מחליפים את הערך POLICY_PATH בנתיב המלא לקובץ ה-YAML של מדיניות הארגון. יכול להיות שיחלפו עד 15 דקות עד שהמדיניות תיכנס לתוקף.

בדיקה של מדיניות הארגון המותאמת אישית

בדוגמה הבאה נוצרת מדיניות ואילוץ מותאמים אישית שמאפשרים למשתמשים ליצור מאגר אחסון של NetApp Volumes אם הערך בשדה capacityGib קטן או שווה ל-10240.

יצירת האילוץ

  1. שומרים את הקובץ הבא בשם constraint-storage-pool-capacity.yaml:

    name: organizations/ORGANIZATION_ID/customConstraints/custom.restrictStoragePoolCapacity
    resourceTypes: netapp.googleapis.com/StoragePool
    methodTypes:
    - CREATE
    condition: "resource.capacityGib <= 10240"
    actionType: ALLOW
    displayName: Restrict storage pool capacity
    description: Restrict storage pool capacity to 10,240 GiB.
    

    מחליפים את ORGANIZATION_ID במזהה הארגון.

  2. החלת האילוץ:

    gcloud org-policies set-custom-constraint constraint-storage-pool-capacity.yaml
    
  3. מוודאים שהאילוץ קיים:

    gcloud org-policies list-custom-constraints --organization=ORGANIZATION_ID
    

    הפלט אמור להיראות כך:

    CUSTOM_CONSTRAINT                   ACTION_TYPE  METHOD_TYPES   RESOURCE_TYPES                     DISPLAY_NAME
    custom.restrictStoragePoolCapacity  ALLOW        CREATE         netapp.googleapis.com/StoragePool  Restrict storage pool capacity
    
    ...
    

יצירת המדיניות

  1. שומרים את הקובץ הבא בשם policy-storage-pool-capacity.yaml:

    name: projects/PROJECT_ID/policies/custom.restrictStoragePoolCapacity
    spec:
      rules:
      - enforce: true
    

    מחליפים את PROJECT_ID במזהה הפרויקט.

  2. החלת המדיניות:

    gcloud org-policies set-policy policy-storage-pool-capacity.yaml
    
  3. מוודאים שהמדיניות קיימת:

    gcloud org-policies list --project=PROJECT_ID
    

    הפלט אמור להיראות כך:

    CONSTRAINT                          LIST_POLICY  BOOLEAN_POLICY  ETAG
    custom.restrictStoragePoolCapacity  -            SET             CKrb785HFNjBzHF=-
    

אחרי שמחילים את המדיניות, מחכים כשתי דקות עד ש- Google Cloud יתחיל לאכוף את המדיניות.

בדיקת המדיניות

  • אפשר לנסות ליצור מאגר אחסון עם הערך capacityGib שגדול מ-10240:

    gcloud netapp storage-pools create test-pool --location=us-central1 --service-level=standard --capacity=10241 --network=name=default --description="example description"
    

    הבקשה נכשלת ומוחזרת שגיאה שדומה לשגיאה הבאה:

    ERROR: (gcloud.netapp.storage-pools.create) FAILED_PRECONDITION: Operation denied by custom org policy on resource 'projects/test-project/locations/us-central1/storagePools/test-pool': ["customConstraints/custom.restrictStoragePoolCapacity": "Restrict storage pool capacity to less than or equal to 10,240 GiB"].
    

דוגמאות למדיניות מותאמת אישית של הארגון לתרחישים נפוצים

בטבלה הבאה מופיעות דוגמאות לתחביר של כמה אילוצים נפוצים בהתאמה אישית.

תיאור תחביר של אילוצים
דחיית יצירה או עדכון של מאגר אחסון אם הקיבולת חורגת מ-10,000 GiB
    name: organizations/ORGANIZATION_ID/customConstraints/custom.restrictStoragePoolCapacity
    resourceTypes: netapp.googleapis.com/StoragePool
    methodTypes:
    - CREATE
    - UPDATE
    condition: "resource.capacityGib > 10000"
    actionType: DENY
    displayName: Restrict storage pool capacity
    description: Prevent creation or update of storage pools with capacity greater than 10,000 GiB.
דרישה של רמת שירות Premium או Extreme למאגרי אחסון
    name: organizations/ORGANIZATION_ID/customConstraints/custom.enforcePremiumServiceLevel
    resourceTypes: netapp.googleapis.com/StoragePool
    methodTypes:
    - CREATE
    - UPDATE
    condition: "!(resource.serviceLevel in ['PREMIUM', 'EXTREME'])"
    actionType: DENY
    displayName: Enforce Premium or Extreme service level
    description: Make sure that the storage pools are created only for the Premium or Extreme service level.
דחיית יצירה או עדכון של נפח אחסון אם הקיבולת חורגת מ-5,000‎ GiB
    name: organizations/ORGANIZATION_ID/customConstraints/custom.restrictVolumeCapacity
    resourceTypes: netapp.googleapis.com/Volume
    methodTypes:
    - CREATE
    - UPDATE
    condition: "resource.capacityGib > 5000"
    actionType: DENY
    displayName: Restrict volume capacity
    description: Prevent creation or update of volumes with capacity greater than 5,000 GiB.
דרישה להוספת תיאור לגיבויים
    name: organizations/ORGANIZATION_ID/customConstraints/custom.requireBackupDescription
    resourceTypes: netapp.googleapis.com/Backup
    methodTypes:
    - CREATE
    - UPDATE
    condition: "resource.description.size() == 0"
    actionType: DENY
    displayName: Require backup description
    description: Prevent creation or update of backups without a description.

המאמרים הבאים