MART ๊ตฌ์„ฑ

Apigee Hybrid ๊ด€๋ฆฌ ์˜์—ญ์€ ๋Ÿฐํƒ€์ž„ ์˜์—ญ์—์„œ MART ์„œ๋น„์Šค์— ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ์ด์œ ๋กœ MART ์—”๋“œํฌ์ธํŠธ๋Š” ํด๋Ÿฌ์Šคํ„ฐ ์™ธ๋ถ€์—์„œ ์ˆ˜์‹ ๋˜๋Š” ์š”์ฒญ์— ๋…ธ์ถœ๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. MART ์—”๋“œํฌ์ธํŠธ๋Š” ๋ณด์•ˆ TLS ์—ฐ๊ฒฐ์ž…๋‹ˆ๋‹ค. ํ•˜์ด๋ธŒ๋ฆฌ๋“œ์—์„œ๋Š” Istio ์ธ๊ทธ๋ ˆ์Šค ๊ฒŒ์ดํŠธ์›จ์ด ์„œ๋น„์Šค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ด ์—”๋“œํฌ์ธํŠธ์— ํŠธ๋ž˜ํ”ฝ์„ ๋…ธ์ถœํ•ฉ๋‹ˆ๋‹ค.

์ด ์ฃผ์ œ์—์„œ๋Š” MART ์—”๋“œํฌ์ธํŠธ๋ฅผ ๋…ธ์ถœํ•˜๋Š” ๋‹จ๊ณ„๋ฅผ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค.

MART ์„œ๋น„์Šค ๊ณ„์ • ์ถ”๊ฐ€

MART์—์„œ๋Š” ์ธ์ฆ์„ ์œ„ํ•ด GCP ์„œ๋น„์Šค ๊ณ„์ •์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

  1. GCP ์„ค์ • ๋‹จ๊ณ„์—์„œ ์„œ๋น„์Šค ๊ณ„์ • ์ถ”๊ฐ€๋ฅผ ํ†ตํ•ด MART์— ๋Œ€ํ•ด ์—ญํ•  ์—†๋Š” ์„œ๋น„์Šค ๊ณ„์ •์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค. ํ•ด๋‹น ์„œ๋น„์Šค ๊ณ„์ •์— ๋‹ค์šด๋กœ๋“œ ํ•œ ํ‚ค ํŒŒ์ผ์„ ์ฐพ์Šต๋‹ˆ๋‹ค. ํŒŒ์ผ์˜ ํ™•์žฅ์ž๋Š” .json์ด์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
  2. ํ‚ค ํŒŒ์ผ ๊ฒฝ๋กœ๋ฅผ mart.serviceAccountPath ์†์„ฑ์— ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.
    ...
    mart:
      sslCertPath:
      sslKeyPath:
      hostAlias:
      serviceAccountPath: "path to a file"
    ...

    ์˜ˆ๋ฅผ ๋“ค๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

    ...
    mart:
      sslCertPath:
      sslKeyPath:
      hostAlias:
      serviceAccountPath: "your_keypath/mart-service-account.json
    ...

TLS ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด ๋ฐ ํ˜ธ์ŠคํŠธ ๋ณ„์นญ ์ถ”๊ฐ€

  1. ์žฌ์ •์˜ ํŒŒ์ผ์„ ์—ฝ๋‹ˆ๋‹ค.
  2. mart.sslCertPath, mart.sslKeyPath, mart.hostAlias ๋ฐ ์†์„ฑ์„ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค. ๋‹ค์Œ ํ‘œ์—์„œ๋Š” ์ด๋Ÿฌํ•œ ์†์„ฑ์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค.
    ์†์„ฑ ๊ฐ’
    mart.sslCertPath
    mart.sslKeyPath
    MART ์ธ์ฆ์„œ/ํ‚ค ์Œ์€ ์ธ์ฆ ๊ธฐ๊ด€(CA)์˜ ์Šน์ธ์„ ๋ฐ›์•„์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์Šน์ธ๋œ ์ธ์ฆ์„œ/ํ‚ค ์Œ์„ ์•„์ง ๋งŒ๋“ค์ง€ ์•Š์•˜๋‹ค๋ฉด ์ง€๊ธˆ ๋งŒ๋“ค๊ณ  ํ•ด๋‹น ์†์„ฑ ๊ฐ’์— ๋Œ€ํ•œ ์ธ์ฆ์„œ์™€ ํ‚ค ํŒŒ์ผ ์ด๋ฆ„์„ ์ž…๋ ฅํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์Šน์ธ๋œ ์ธ์ฆ์„œ/ํ‚ค ์Œ์„ ์ƒ์„ฑํ•˜๋Š” ๋ฐ ๋„์›€์ด ํ•„์š”ํ•œ ๊ฒฝ์šฐ TLS ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด ๊ฐ€์ ธ์˜ค๊ธฐ: ์˜ˆ์‹œ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.
    mart.hostAlias. (ํ•„์ˆ˜) MART ์„œ๋ฒ„ ์—”๋“œํฌ์ธํŠธ์˜ ์ •๊ทœํ™”๋œ DNS ์ด๋ฆ„์ž…๋‹ˆ๋‹ค. ์˜ˆ: foo-mart.mydomain.com

    ์˜ˆ๋ฅผ ๋“ค์–ด ํ˜ธ์ŠคํŠธ ๋ณ„์นญ์ด ์ •๊ทœํ™”๋œ ๋„๋ฉ”์ธ ์ด๋ฆ„์ธ ๊ฒฝ์šฐ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

    ...
    
    mart:
      sslCertPath: path-to-file/mart-server.crt
      sslKeyPath: path-to-file/mart-server.key
      hostAlias: foo-mart.mydomain.com
      serviceAccountPath: "your_keypath/mart-service-account.json
    
    ...
    
  3. ๋ณ€๊ฒฝ์‚ฌํ•ญ์„ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.