5๋‹จ๊ณ„: TLS ์ธ์ฆ์„œ ๋งŒ๋“ค๊ธฐ

์ด ๋‹จ๊ณ„์—์„œ๋Š” Apigee Hybrid ์ž‘๋™์— ํ•„์š”ํ•œ TLS ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด๋ฅผ ๋งŒ๋“œ๋Š” ๋ฐฉ๋ฒ•์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค.

TLS ์ธ์ฆ์„œ ๋งŒ๋“ค๊ธฐ

Apigee Hybrid ๊ตฌ์„ฑ์— ๋Ÿฐํƒ€์ž„ ์ธ๊ทธ๋ ˆ์Šค ๊ฒŒ์ดํŠธ์›จ์ด์— ๋Œ€ํ•œ TLS ์ธ์ฆ์„œ๋ฅผ ์ œ๊ณตํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ด ๋น ๋ฅธ ์‹œ์ž‘(๋น„ํ”„๋กœ๋•์…˜ ๋ฌด๋ฃŒ ์ฒดํ—˜ํŒ ์„ค์น˜)์—์„œ ๋Ÿฐํƒ€์ž„ ๊ฒŒ์ดํŠธ์›จ์ด๋Š” ์ž์ฒด ์„œ๋ช… ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด๋ฅผ ์ˆ˜๋ฝํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‹ค์Œ์˜ ์ ˆ์ฐจ์—์„œ openssl์€ ์ž์ฒด ์„œ๋ช… ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด๋ฅผ ์ƒ์„ฑํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.

์ด ๋‹จ๊ณ„์—์„œ๋Š” TLS ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด ํŒŒ์ผ์„ ๋งŒ๋“ค์–ด $APIGEE_HELM_CHARTS_HOME/certs ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค. 6๋‹จ๊ณ„: ์žฌ์ •์˜ ๋งŒ๋“ค๊ธฐ์—์„œ๋Š” ํŒŒ์ผ ๊ฒฝ๋กœ๋ฅผ ํด๋Ÿฌ์Šคํ„ฐ ๊ตฌ์„ฑ ํŒŒ์ผ์— ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

  1. ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด ํŒŒ์ผ์„ ์œ„ํ•œ ๋””๋ ‰ํ„ฐ๋ฆฌ๋ฅผ ๋งŒ๋“ญ๋‹ˆ๋‹ค. Helm ์ฐจํŠธ๋Š” ์ฐจํŠธ ๋””๋ ‰ํ„ฐ๋ฆฌ ์™ธ๋ถ€์˜ ํŒŒ์ผ์„ ์ฝ์„ ์ˆ˜ ์—†์œผ๋ฉฐ TLS ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด๋Š” apigee-virtualhost ์ฐจํŠธ๋กœ ๊ด€๋ฆฌ๋ฉ๋‹ˆ๋‹ค. ๋”ฐ๋ผ์„œ $APIGEE_HELM_CHARTS_HOME/apigee-virtualhost/ ๋””๋ ‰ํ„ฐ๋ฆฌ ๋‚ด์— ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด ํŒŒ์ผ์„ ์œ„ํ•œ ๋””๋ ‰ํ„ฐ๋ฆฌ๋ฅผ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

    ์˜ˆ๋ฅผ ๋“ค๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

    mkdir $APIGEE_HELM_CHARTS_HOME/apigee-virtualhost/certs/
  2. ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•˜์—ฌ ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด ํŒŒ์ผ์„ ๋งŒ๋“ค๊ณ  $APIGEE_HELM_CHARTS_HOME/apigee-virtualhost/certs ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.
    openssl req  -nodes -new -x509 -keyout $APIGEE_HELM_CHARTS_HOME/apigee-virtualhost/certs/keystore_$ENV_GROUP.key -out \
        $APIGEE_HELM_CHARTS_HOME/apigee-virtualhost/certs/keystore_$ENV_GROUP.pem -subj '/CN='$DOMAIN'' -days 3650

    ๊ฐ ํ•ญ๋ชฉ์˜ ์˜๋ฏธ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

    • DOMAIN์€ ํ™˜๊ฒฝ ๊ทธ๋ฃน ๋งŒ๋“ค๊ธฐ์—์„œ ๋งŒ๋“  ํ™˜๊ฒฝ ๊ทธ๋ฃน์˜ ํ˜ธ์ŠคํŠธ ์ด๋ฆ„์œผ๋กœ ์ œ๊ณต๋œ ๋„๋ฉ”์ธ์ž…๋‹ˆ๋‹ค.
    • ENV_GROUP์€ ๋„๋ฉ”์ธ์ด ํ˜ธ์ŠคํŠธ ์ด๋ฆ„์œผ๋กœ ์ง€์ •๋œ ํ™˜๊ฒฝ ๊ทธ๋ฃน์˜ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค. ์—ฌ๋Ÿฌ ํ™˜๊ฒฝ ๊ทธ๋ฃน์˜ ํ‚ค๋ฅผ ๋งŒ๋“œ๋Š” ๊ฒฝ์šฐ ๋™์ผํ•œ ๋„๋ฉ”์ธ ๊ฐ’์„ ์‹ค์ˆ˜๋กœ ์žฌ์‚ฌ์šฉํ•˜์ง€ ์•Š๋„๋ก ํ‚ค ๋ฐ ํ‚ค ์ €์žฅ์†Œ ์ด๋ฆ„์— ํ™˜๊ฒฝ ๊ทธ๋ฃน ์ด๋ฆ„์„ ํฌํ•จํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค.

    ์ด ๋ช…๋ น์–ด๋Š” ๋น ๋ฅธ ์‹œ์ž‘ ์„ค์น˜์— ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ์ž์ฒด ์„œ๋ช… ์ธ์ฆ์„œ/ํ‚ค ์Œ์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

    ๊ณ ์œ ํ•œ ๋„๋ฉ”์ธ ์ด๋ฆ„์„ ๊ฐ€์ง„ ์ถ”๊ฐ€ ํ™˜๊ฒฝ ๊ทธ๋ฃน์ด ์žˆ์œผ๋ฉด ๊ฐ ํ™˜๊ฒฝ ๊ทธ๋ฃน๋งˆ๋‹ค ์ด ๋‹จ๊ณ„๋ฅผ ๋ฐ˜๋ณตํ•ฉ๋‹ˆ๋‹ค. ํด๋Ÿฌ์Šคํ„ฐ ๊ตฌ์„ฑ ๋‹จ๊ณ„์—์„œ ์ด๋Ÿฌํ•œ ๊ทธ๋ฃน๊ณผ ์ธ์ฆ์„œ๋ฅผ ์ฐธ์กฐํ•ฉ๋‹ˆ๋‹ค.

  3. ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํŒŒ์ผ์ด $APIGEE_HELM_CHARTS_HOME/apigee-virtualhost/certs ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.
    ls $APIGEE_HELM_CHARTS_HOME/apigee-virtualhost/certs

    ๊ทธ๋Ÿฌ๋ฉด ๋‘ ๊ฐœ์˜ ํŒŒ์ผ์ด ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค.

    • keystore_ENV_GROUP.pem ๋˜๋Š” keystore_ENV_GROUP.crt๋Š” ์ž์ฒด ์„œ๋ช… TLS ์ธ์ฆ์„œ ํŒŒ์ผ์ž…๋‹ˆ๋‹ค.
    • keystore_ENV_GROUP.key๋Š” ํ‚ค ํŒŒ์ผ์ž…๋‹ˆ๋‹ค.

์ด์ œ Kubernetes ํด๋Ÿฌ์Šคํ„ฐ์—์„œ Apigee Hybrid๋ฅผ ๊ด€๋ฆฌํ•˜๋Š” ๋ฐ ํ•„์š”ํ•œ ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด๊ฐ€ ์ค€๋น„๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๋‹ค์Œ ๋‹จ๊ณ„๋กœ ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ๋Ÿฐํƒ€์ž„ ๊ตฌ์„ฑ์š”์†Œ๋ฅผ ํด๋Ÿฌ์Šคํ„ฐ์— ๋ฐฐํฌํ•˜๊ธฐ ์œ„ํ•ด Kubernetes์—์„œ ์‚ฌ์šฉ๋˜๋Š” ์žฌ์ •์˜ ํŒŒ์ผ์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

๋‹ค์Œ ๋‹จ๊ณ„

1 2 3 4 5 (๋‹ค์Œ) 6๋‹จ๊ณ„: ์žฌ์ •์˜ ๋งŒ๋“ค๊ธฐ 7 8 9 10 11