์›Œํฌ๋กœ๋“œ ์—…๋ฐ์ดํŠธ ์ ์šฉ

์ด ํŽ˜์ด์ง€์—์„œ๋Š” Assured Workloads ํด๋”์˜ ์›Œํฌ๋กœ๋“œ ์—…๋ฐ์ดํŠธ๋ฅผ ์‚ฌ์šฉ ์„ค์ •, ํ™•์ธ, ์ ์šฉํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค. Assured Workloads๋Š” ์—…๋ฐ์ดํŠธ๋œ ์กฐ์ง ์ •์ฑ… ์ œ์•ฝ์กฐ๊ฑด ๊ฐ’๊ณผ ๊ฐ™์€ ์ผ๋ฐ˜ ๊ฐœ์„ ์‚ฌํ•ญ๊ณผ ์ƒˆ๋กœ์šด ์„ค์ •์œผ๋กœ ์ œ์–ด ํŒจํ‚ค์ง€๋ฅผ ์ •๊ธฐ์ ์œผ๋กœ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค. ์ด ๊ธฐ๋Šฅ์„ ์‚ฌ์šฉํ•˜๋ฉด ํ˜„์žฌ Assured Workloads ํด๋” ๊ตฌ์„ฑ์„ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์ตœ์‹  ๊ตฌ์„ฑ๊ณผ ๋น„๊ตํ•˜์—ฌ ํ‰๊ฐ€ํ•˜๊ณ  ์ œ์•ˆ๋œ ์—…๋ฐ์ดํŠธ๋ฅผ ์ ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๊ธฐ๋ณธ์ ์œผ๋กœ ์ด ๊ธฐ๋Šฅ์€ ์ƒˆ Assured Workloads ํด๋”์— ์ž๋™์œผ๋กœ ์‚ฌ์šฉ ์„ค์ •๋ฉ๋‹ˆ๋‹ค. ๊ธฐ์กด ํด๋”์˜ ๊ฒฝ์šฐ ์›Œํฌ๋กœ๋“œ ์—…๋ฐ์ดํŠธ๋ฅผ ์‚ฌ์šฉ ์„ค์ •ํ•˜๋Š” ๋‹จ๊ณ„๋ฅผ ๋”ฐ๋ฅด๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค.

์ด ๊ธฐ๋Šฅ์— ๋Œ€ํ•œ ์ถ”๊ฐ€ ์š”๊ธˆ์ด ๋ฐœ์ƒํ•˜์ง€ ์•Š๊ฑฐ๋‚˜ Assured Workloads ๋ชจ๋‹ˆํ„ฐ๋ง์˜ ๋™์ž‘์€ ์˜ํ–ฅ์„ ๋ฐ›์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๊ตฌ์„ฑ ์—…๋ฐ์ดํŠธ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š”์ง€ ์—ฌ๋ถ€์™€ ๊ด€๊ณ„์—†์ด ํด๋” ํ˜„์žฌ ๊ตฌ์„ฑ์œผ๋กœ ๊ทœ์ •์„ ์ค€์ˆ˜ํ•˜์ง€ ์•Š์œผ๋ฉด ๊ณ„์† ์•Œ๋ฆผ์ด ์ „์†ก๋ฉ๋‹ˆ๋‹ค.

์›Œํฌ๋กœ๋“œ ์—…๋ฐ์ดํŠธ ๊ฐœ์š”

์ƒˆ Assured Workloads ํด๋”๋ฅผ ๋งŒ๋“ค ๋•Œ ์„ ํƒํ•œ ์ œ์–ด ํŒจํ‚ค์ง€ ์œ ํ˜•(์˜ˆ: FedRAMP Moderate)์— ๋”ฐ๋ผ ์›Œํฌ๋กœ๋“œ์— ์ ์šฉ๋˜๋Š” ๋‹ค์–‘ํ•œ ๊ตฌ์„ฑ ์„ค์ •์ด ๊ฒฐ์ •๋ฉ๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ์„ค์ • ์ค‘ ์ผ๋ถ€๋Š” ์กฐ์ง ์ •์ฑ… ์ œ์•ฝ ์กฐ๊ฑด์˜ ํ˜•ํƒœ๋กœ ์™ธ๋ถ€์— ํ‘œ์‹œ๋˜์ง€๋งŒ, ๋‹ค๋ฅธ ์„ค์ •์€ Google์˜ ๋‚ด๋ถ€ ์‹œ์Šคํ…œ์—๋งŒ ์ ์šฉ๋ฉ๋‹ˆ๋‹ค. Assured Workloads๋Š” ๋‚ด๋ถ€ ๊ตฌ์„ฑ ๋ฒ„์ „ ๊ด€๋ฆฌ ์‹œ์Šคํ…œ์„ ์‚ฌ์šฉํ•˜์—ฌ ๊ฐ ์ œ์–ด ํŒจํ‚ค์ง€ ์œ ํ˜•์˜ ๋ณ€๊ฒฝ์‚ฌํ•ญ์„ ์œ ์ง€ํ•ฉ๋‹ˆ๋‹ค.

์ƒˆ ๋‚ด๋ถ€ ๊ตฌ์„ฑ ๋ฒ„์ „์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋˜๋ฉด Assured Workloads๋Š” ์›Œํฌ๋กœ๋“œ์˜ ๊ตฌ์„ฑ์„ ์ƒˆ ๋‚ด๋ถ€ ๋ฒ„์ „๊ณผ ๋น„๊ตํ•ฉ๋‹ˆ๋‹ค. ์ฐจ์ด๊ฐ€ ์žˆ๋Š” ๊ฒฝ์šฐ ์ด๋ฅผ ๋ถ„์„ํ•˜๊ณ  ๊ทธ ๊ฒฐ๊ณผ ์–ป์€ ๊ฐœ์„ ์‚ฌํ•ญ์„ ์›Œํฌ๋กœ๋“œ ๊ตฌ์„ฑ์— ์ ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ์—…๋ฐ์ดํŠธ๋กœ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ Assured Workloads ์—…๋ฐ์ดํŠธ๋Š” ์›Œํฌ๋กœ๋“œ์˜ ์ œ์–ด ํŒจํ‚ค์ง€ ์š”๊ตฌ์‚ฌํ•ญ์„ ์ค€์ˆ˜ํ•˜๋Š” ๊ฒƒ์œผ๋กœ Google์—์„œ ํ™•์ธํ•œ ๊ฒƒ์ž…๋‹ˆ๋‹ค. ํ•˜์ง€๋งŒ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ๊ฐ ์—…๋ฐ์ดํŠธ๊ฐ€ ์กฐ์ง์˜ ๊ทœ์ œ ๋˜๋Š” ๊ทœ์ • ์ค€์ˆ˜ ์š”๊ตฌ์‚ฌํ•ญ์„ ์ถฉ์กฑํ•˜๋Š”์ง€ ๊ฒ€ํ† ํ•  ์ฑ…์ž„์€ ์—ฌ์ „ํžˆ ์‚ฌ์šฉ์ž์—๊ฒŒ ์žˆ์Šต๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ Assured Workloads์˜ ๊ณต์œ  ์ฑ…์ž„์„ ์ฐธ์กฐํ•˜์„ธ์š”.

์ง€์›๋˜๋Š” ์—…๋ฐ์ดํŠธ ์œ ํ˜•

์ด ๊ธฐ๋Šฅ์€ Assured Workloads ํด๋”์—์„œ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์œ ํ˜•์˜ ์—…๋ฐ์ดํŠธ๋ฅผ ๋ณด๊ณ  ์ ์šฉํ•˜๋Š” ๊ฒƒ์„ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค.

  • ์กฐ์ง ์ •์ฑ… ์ œ์•ฝ ์กฐ๊ฑด: ์›Œํฌ๋กœ๋“œ์— ์ ์šฉ๋˜๊ณ  Assured Workloads์—์„œ ์‹œํ–‰ํ•˜๋Š” ๋ชจ๋“  ์กฐ์ง ์ •์ฑ… ์ œ์•ฝ ์กฐ๊ฑด์€ ์›Œํฌ๋กœ๋“œ ์—…๋ฐ์ดํŠธ์— ํฌํ•จ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‹จ, ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์˜ˆ์™ธ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค.

    • gcp.resourceLocations
    • gcp.restrictCmekCryptoKeyProjects

์‹œ์ž‘ํ•˜๊ธฐ ์ „์—

  • ์—…๋ฐ์ดํŠธ๋ฅผ ์‚ฌ์šฉ ์„ค์ •ํ•  Assured Workloads ํด๋”์˜ ๋ฆฌ์†Œ์Šค ID๋ฅผ ์‹๋ณ„ํ•ฉ๋‹ˆ๋‹ค.
  • ๋Œ€์ƒ Assured Workloads ํด๋”์™€ ์›Œํฌ๋กœ๋“œ์— ๋Œ€ํ•œ IAM ๊ถŒํ•œ์„ ํ• ๋‹นํ•˜๊ฑฐ๋‚˜ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

ํ•„์ˆ˜ IAM ๊ถŒํ•œ

์›Œํฌ๋กœ๋“œ ์—…๋ฐ์ดํŠธ๋ฅผ ์‚ฌ์šฉ ์„ค์ •, ํ™•์ธ ๋˜๋Š” ์ ์šฉํ•˜๋ ค๋ฉด ๋” ๊ด‘๋ฒ”์œ„ํ•œ ๊ถŒํ•œ ์ง‘ํ•ฉ์ด ํฌํ•จ๋œ ์‚ฌ์ „ ์ •์˜๋œ ์—ญํ•  ๋˜๋Š” ํ•„์š”ํ•œ ์ตœ์†Œ ๊ถŒํ•œ์œผ๋กœ ์ œํ•œ๋œ ์ปค์Šคํ…€ ์—ญํ•  ์ค‘ ํ•˜๋‚˜๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ˜ธ์ถœ์ž์—๊ฒŒ IAM ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ํ•„์š”ํ•œ orgpolicy.policy.set ๊ถŒํ•œ์€ ์ปค์Šคํ…€ ์—ญํ• ์—์„œ ์‚ฌ์šฉํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.

๋‹ค์Œ ๊ถŒํ•œ์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

์›Œํฌ๋กœ๋“œ ์—…๋ฐ์ดํŠธ ์‚ฌ์šฉ ์„ค์ •

์›Œํฌ๋กœ๋“œ ์—…๋ฐ์ดํŠธ๋ฅผ ์‚ฌ์šฉ ์„ค์ •ํ•˜๋ฉด Assured Workloads ์„œ๋น„์Šค ์—์ด์ „ํŠธ๊ฐ€ ์ƒ์„ฑ๋ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋ฉด ์ด ์„œ๋น„์Šค ์—์ด์ „ํŠธ์— ๋Œ€์ƒ Assured Workloads ํด๋”์— ๋Œ€ํ•œ Assured Workloads ์„œ๋น„์Šค ์—์ด์ „ํŠธ(roles/assuredworkloads.serviceAgent) ์—ญํ• ์ด ๋ถ€์—ฌ๋ฉ๋‹ˆ๋‹ค. ์ด ์—ญํ• ์„ ํ†ตํ•ด ์„œ๋น„์Šค ์—์ด์ „ํŠธ๊ฐ€ ํด๋”์—์„œ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์—…๋ฐ์ดํŠธ๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์›Œํฌ๋กœ๋“œ ์—…๋ฐ์ดํŠธ๋ฅผ ์‚ฌ์šฉ ์„ค์ •ํ•˜๋ ค๋ฉด ๋‹ค์Œ ๋‹จ๊ณ„๋ฅผ ์™„๋ฃŒํ•ฉ๋‹ˆ๋‹ค.

์ฝ˜์†”

  1. Google Cloud ์ฝ˜์†”์—์„œ Assured Workloads ํŽ˜์ด์ง€๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.

    Assured Workloads๋กœ ์ด๋™

  2. ๊ทœ์ • ์ค€์ˆ˜ ์—…๋ฐ์ดํŠธ ์†Œ๊ฐœ ์ฐฝ์˜ ํŽ˜์ด์ง€ ์ƒ๋‹จ์— ์žˆ๋Š” ๊ทœ์ • ์ค€์ˆ˜ ์—…๋ฐ์ดํŠธ ์‚ฌ์šฉ ์„ค์ •์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  3. ๊ทœ์ • ์ค€์ˆ˜ ์—…๋ฐ์ดํŠธ๋ฅผ ์‚ฌ์šฉ ์„ค์ •ํ•˜์‹œ๊ฒ ์Šต๋‹ˆ๊นŒ?๋ผ๋Š” ๋ฉ”์‹œ์ง€๊ฐ€ ํ‘œ์‹œ๋˜๋ฉด ์‚ฌ์šฉ ์„ค์ •์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

์ด์ œ ์กฐ์ง์˜ ๋ชจ๋“  Assured Workloads ํด๋”์— ์›Œํฌ๋กœ๋“œ ์—…๋ฐ์ดํŠธ๊ฐ€ ์‚ฌ์šฉ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.

REST

enableComplianceUpdates ๋ฉ”์„œ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด Assured Workloads์—์„œ ๋‹จ์ผ Assured Workloads ํด๋”์˜ ์—…๋ฐ์ดํŠธ๋ฅผ ์•Œ๋ฆด ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

HTTP ๋ฉ”์„œ๋“œ, URL, ์ฟผ๋ฆฌ ๋งค๊ฐœ๋ณ€์ˆ˜:

PUT https://[ENDPOINT_URI]/v1beta1/organizations/[ORGANIZATION_ID]/locations/[LOCATION_ID]/workloads/[WORKLOAD_ID]:enableComplianceUpdates

๋‹ค์Œ ์ž๋ฆฌํ‘œ์‹œ์ž ๊ฐ’์„ ์ง์ ‘ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.

  • ENDPOINT_URI: Assured Workloads ์„œ๋น„์Šค ์—”๋“œํฌ์ธํŠธ URI. ์ด URI๋Š” ๋Œ€์ƒ ์›Œํฌ๋กœ๋“œ์˜ ์œ„์น˜์™€ ์ผ์น˜ํ•˜๋Š” ์—”๋“œํฌ์ธํŠธ์—ฌ์•ผ ํ•ฉ๋‹ˆ๋‹ค(์˜ˆ: us-west1 ๋ฆฌ์ „์˜ ๋ฆฌ์ „ํ™”๋œ ์›Œํฌ๋กœ๋“œ์˜ ๊ฒฝ์šฐ https://us-west1-assuredworkloads.googleapis.com, ๋ฏธ๊ตญ์˜ ๋ฉ€ํ‹ฐ ๋ฆฌ์ „์˜ ๊ฒฝ์šฐ https://us-assuredworkloads.googleapis.com).
  • ORGANIZATION_ID: Assured Workloads ํด๋”์˜ ์กฐ์ง ID์ž…๋‹ˆ๋‹ค(์˜ˆ: 919698201234).
  • LOCATION_ID: Assured Workloads ํด๋”์˜ ์œ„์น˜์ž…๋‹ˆ๋‹ค(์˜ˆ: us-west1 ๋˜๋Š” us). ์›Œํฌ๋กœ๋“œ์˜ data region ๊ฐ’์— ํ•ด๋‹นํ•ฉ๋‹ˆ๋‹ค.
  • WORKLOAD_ID: ์—…๋ฐ์ดํŠธ๋ฅผ ์‚ฌ์šฉ ์„ค์ •ํ•  Assured Workloads ์›Œํฌ๋กœ๋“œ์˜ ID์ž…๋‹ˆ๋‹ค(์˜ˆ: 00-701ea036-7152-4780-a867-9f5).

์˜ˆ๋ฅผ ๋“ค๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

PUT https://us-west1-assuredworkloads.googleapis.com/v1beta1/organizations/919698298765/locations/us-west1/workloads/00-701ea036-7152-4781-a867-9f5:enableComplianceUpdates

์›Œํฌ๋กœ๋“œ ์—…๋ฐ์ดํŠธ ๋ณด๊ธฐ

์›Œํฌ๋กœ๋“œ ์—…๋ฐ์ดํŠธ๋ฅผ ๋ณด๋ ค๋ฉด ๋‹ค์Œ ๋‹จ๊ณ„๋ฅผ ์™„๋ฃŒํ•ฉ๋‹ˆ๋‹ค.

์ฝ˜์†”

  1. Google Cloud ์ฝ˜์†”์—์„œ Assured Workloads ํŽ˜์ด์ง€๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.

    Assured Workloads๋กœ ์ด๋™

  2. ์ด๋ฆ„ ์—ด์—์„œ ์—…๋ฐ์ดํŠธ๋ฅผ ๋ณด๋ ค๋Š” Assured Workloads ํด๋”์˜ ์ด๋ฆ„์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค. ๋˜๋Š” ํด๋”์— ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์—…๋ฐ์ดํŠธ๊ฐ€ ์žˆ๋Š” ๊ฒฝ์šฐ ์—…๋ฐ์ดํŠธ ์—ด์˜ ๋งํฌ๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  3. ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์—…๋ฐ์ดํŠธ์—์„œ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์—…๋ฐ์ดํŠธ ๊ฒ€ํ† ๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  4. ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ๊ฒฝ์šฐ ์กฐ์ง ์ •์ฑ… ํƒญ์— ์กฐ์ง ์ •์ฑ… ์—…๋ฐ์ดํŠธ๊ฐ€ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค. ์˜ํ–ฅ์„ ๋ฐ›๋Š” ์กฐ์ง ์ •์ฑ… ์ œ์•ฝ ์กฐ๊ฑด์„ ๊ฒ€ํ† ํ•˜๊ณ  ์—…๋ฐ์ดํŠธ ๋ณด๊ธฐ๋ฅผ ํด๋ฆญํ•˜์—ฌ ์—…๋ฐ์ดํŠธ์— ์˜ํ•ด ์ ์šฉ๋  ์ œ์•ฝ ์กฐ๊ฑด ์„ค์ •์„ ๋ฏธ๋ฆฌ ๋ด…๋‹ˆ๋‹ค.

REST

organizations.locations.workloads.updates.list ๋ฉ”์„œ๋“œ๋Š” Assured Workloads ์›Œํฌ๋กœ๋“œ์— ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์—…๋ฐ์ดํŠธ๋ฅผ ๋‚˜์—ดํ•ฉ๋‹ˆ๋‹ค.

HTTP ๋ฉ”์„œ๋“œ, URL, ์ฟผ๋ฆฌ ๋งค๊ฐœ๋ณ€์ˆ˜:

GET https://[ENDPOINT_URI]/v1beta1/organizations/[ORGANIZATION_ID]/locations/[LOCATION_ID]/workloads/[WORKLOAD_ID]/updates?page_size=[PAGE_SIZE]&page_token=[PAGE_TOKEN]

๋‹ค์Œ ์ž๋ฆฌํ‘œ์‹œ์ž ๊ฐ’์„ ์ง์ ‘ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.

  • ENDPOINT_URI: Assured Workloads ์„œ๋น„์Šค ์—”๋“œํฌ์ธํŠธ URI. ์ด URI๋Š” ๋Œ€์ƒ ์›Œํฌ๋กœ๋“œ์˜ ์œ„์น˜์™€ ์ผ์น˜ํ•˜๋Š” ์—”๋“œํฌ์ธํŠธ์—ฌ์•ผ ํ•ฉ๋‹ˆ๋‹ค(์˜ˆ: us-central1 ๋ฆฌ์ „์˜ ๋ฆฌ์ „ํ™”๋œ ์›Œํฌ๋กœ๋“œ์˜ ๊ฒฝ์šฐ https://us-central1-assuredworkloads.googleapis.com, ๋ฏธ๊ตญ์˜ ๋ฉ€ํ‹ฐ ๋ฆฌ์ „์˜ ๊ฒฝ์šฐ https://us-assuredworkloads.googleapis.com).
  • ORGANIZATION_ID: Assured Workloads ํด๋”์˜ ์กฐ์ง ID์ž…๋‹ˆ๋‹ค(์˜ˆ: 919698201234).
  • LOCATION_ID: Assured Workloads ํด๋”์˜ ์œ„์น˜์ž…๋‹ˆ๋‹ค(์˜ˆ: us-central1 ๋˜๋Š” us). ์›Œํฌ๋กœ๋“œ์˜ data region ๊ฐ’์— ํ•ด๋‹นํ•ฉ๋‹ˆ๋‹ค.
  • WORKLOAD_ID: ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์—…๋ฐ์ดํŠธ๋ฅผ ๋‚˜์—ดํ•  Assured Workloads ์›Œํฌ๋กœ๋“œ์˜ ID์ž…๋‹ˆ๋‹ค(์˜ˆ: 00-701ea036-7152-4780-a867-9f5).
  • PAGE_SIZE(์„ ํƒ์‚ฌํ•ญ): ์‘๋‹ต์— ๋ฐ˜ํ™˜๋˜๋Š” ์—…๋ฐ์ดํŠธ ์ˆ˜๋ฅผ ์ œํ•œํ•ฉ๋‹ˆ๋‹ค. ์ง€์ •ํ•˜์ง€ ์•Š์œผ๋ฉด ๊ธฐ๋ณธ๊ฐ’์ด 20์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค. ์ตœ๋Œ“๊ฐ’์€ 100์ž…๋‹ˆ๋‹ค.
  • PAGE_TOKEN(์„ ํƒ์‚ฌํ•ญ): ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ํŽ˜์ด์ง€๊ฐ€ ํ•˜๋‚˜ ์ด์ƒ์ธ ๊ฒฝ์šฐ JSON ์‘๋‹ต์— ๋‹ค์Œ ํŽ˜์ด์ง€์˜ ํ† ํฐ์ด ๋ฐ˜ํ™˜๋ฉ๋‹ˆ๋‹ค(์˜ˆ: nextPageToken": "chEKD4IBDAid1e-3BhCo68f6AQ). ์ง€์ •ํ•˜์ง€ ์•Š์œผ๋ฉด ํ›„์† ํŽ˜์ด์ง€๊ฐ€ ๋ฐ˜ํ™˜๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

์˜ˆ๋ฅผ ๋“ค๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

GET https://us-central1-assuredworkloads.googleapis.com/v1beta1/organizations/919698298765/locations/us-west1/workloads/00-701ea036-7152-4781-a867-9f5/updates

์„ฑ๊ณตํ•˜๋ฉด ๋‹ค์Œ ์˜ˆ์‹œ์™€ ์œ ์‚ฌํ•œ JSON ์‘๋‹ต์ด ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค.

{
  "workloadUpdates": [
    {
      "name": "organizations/919698298765/locations/us-central1/workloads/00-701ea036-7152-4781-a867-9f5/updates/5320de45-6c98-41af-b4a0-2ef930b124c3",
      "state": "AVAILABLE",
      "createTime": "2024-10-01T16:33:10.154368Z",
      "updateTime": "2024-10-01T16:33:10.154368Z",
      "details": {
        "orgPolicyUpdate": {
          "appliedPolicy": {
            "resource": "folders/376585579673",
            "constraint": "constraints/gcp.resourceLocations",
            "rule": {
              "values": {
                "allowedValues": [
                  "us-central1",
                ]
              }
            }
          },
          "suggestedPolicy": {
            "resource": "folders/376585579673",
            "constraint": "constraints/gcp.resourceLocations",
            "rule": {
              "values": {
                "allowedValues": [
                  "us-central1",
                  "us-central2",
                  "us-west1",
                ]
              }
            }
          }
        }
      }
    }
  ],
  "nextPageToken": "chEKD4IBDAid1e-3BhCo68f6AQ"
}

์›Œํฌ๋กœ๋“œ ์—…๋ฐ์ดํŠธ ์ ์šฉ

์›Œํฌ๋กœ๋“œ์— ์›Œํฌ๋กœ๋“œ ์—…๋ฐ์ดํŠธ๋ฅผ ์ ์šฉํ•˜๋Š” ์ž‘์—…์€ ์žฅ๊ธฐ ์‹คํ–‰ ์ž‘์—…์ž…๋‹ˆ๋‹ค. ์ž‘์—…์„ ์‹œ์ž‘ํ•œ ํ›„ ์™„๋ฃŒ๋˜๊ธฐ ์ „์— ์›Œํฌ๋กœ๋“œ ๊ตฌ์„ฑ์ด ๋ณ€๊ฒฝ๋˜๋ฉด ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋˜ํ•œ ์›Œํฌ๋กœ๋“œ ์—…๋ฐ์ดํŠธ๋Š” ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์ตœ์‹  ๊ตฌ์„ฑ์„ ๊ธฐ์ค€์œผ๋กœ ์ฃผ๊ธฐ์ ์œผ๋กœ ์žฌํ‰๊ฐ€๋ฉ๋‹ˆ๋‹ค. ์ด ๊ฒฝ์šฐ ์—…๋ฐ์ดํŠธ๋ฅผ ์ ์šฉํ•œ ์งํ›„์— ์ถ”๊ฐ€ ์—…๋ฐ์ดํŠธ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์›Œํฌ๋กœ๋“œ ์—…๋ฐ์ดํŠธ๋ฅผ ์ ์šฉํ•˜๋ ค๋ฉด ๋‹ค์Œ ๋‹จ๊ณ„๋ฅผ ์™„๋ฃŒํ•˜์„ธ์š”.

์ฝ˜์†”

  1. Google Cloud ์ฝ˜์†”์—์„œ Assured Workloads ํŽ˜์ด์ง€๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.

    Assured Workloads๋กœ ์ด๋™

  2. ์ด๋ฆ„ ์—ด์—์„œ ์—…๋ฐ์ดํŠธ๋ฅผ ๋ณด๋ ค๋Š” Assured Workloads ํด๋”์˜ ์ด๋ฆ„์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค. ๋˜๋Š” ํด๋”์— ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์—…๋ฐ์ดํŠธ๊ฐ€ ์žˆ๋Š” ๊ฒฝ์šฐ ์—…๋ฐ์ดํŠธ ์—ด์˜ ๋งํฌ๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  3. ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์—…๋ฐ์ดํŠธ์—์„œ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์—…๋ฐ์ดํŠธ ๊ฒ€ํ† ๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  4. ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ๊ฒฝ์šฐ ์กฐ์ง ์ •์ฑ… ํƒญ์— ์กฐ์ง ์ •์ฑ… ์—…๋ฐ์ดํŠธ๊ฐ€ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค. ์˜ํ–ฅ์„ ๋ฐ›๋Š” ์กฐ์ง ์ •์ฑ… ์ œ์•ฝ ์กฐ๊ฑด์„ ๊ฒ€ํ† ํ•˜๊ณ  ์—…๋ฐ์ดํŠธ ๋ณด๊ธฐ๋ฅผ ํด๋ฆญํ•˜์—ฌ ์—…๋ฐ์ดํŠธ๋œ ์ œ์•ฝ ์กฐ๊ฑด ์„ค์ •์„ ๋ฏธ๋ฆฌ ๋ด…๋‹ˆ๋‹ค.

  5. ์กฐ์ง ์ •์ฑ… ์—…๋ฐ์ดํŠธ๋ฅผ ํด๋ฆญํ•˜์—ฌ ์—…๋ฐ์ดํŠธ๋ฅผ ์ ์šฉํ•ฉ๋‹ˆ๋‹ค.

์žฅ๊ธฐ ์‹คํ–‰ ์—…๋ฐ์ดํŠธ ์ž‘์—…์ด ์‹œ์ž‘๋˜๊ณ  ํด๋”์˜ ์ƒˆ ์กฐ์ง ์ •์ฑ… ์„ค์ •์ด ์ ์šฉ๋ฉ๋‹ˆ๋‹ค.

REST

organizations.locations.workloads.updates.apply ๋ฉ”์„œ๋“œ๋Š” Assured Workloads ์›Œํฌ๋กœ๋“œ์˜ ์ง€์ •๋œ ์—…๋ฐ์ดํŠธ๋ฅผ ์ ์šฉํ•ฉ๋‹ˆ๋‹ค.

HTTP ๋ฉ”์„œ๋“œ, URL, ์ฟผ๋ฆฌ ๋งค๊ฐœ๋ณ€์ˆ˜:

POST https://[ENDPOINT_URI]/v1beta1/organizations/[ORGANIZATION_ID]/locations/[LOCATION_ID]/workloads/[WORKLOAD_ID]/updates/[UPDATE_ID]:apply

๋‹ค์Œ ์ž๋ฆฌํ‘œ์‹œ์ž ๊ฐ’์„ ์ง์ ‘ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.

  • ENDPOINT_URI: Assured Workloads ์„œ๋น„์Šค ์—”๋“œํฌ์ธํŠธ URI. ์ด URI๋Š” ๋Œ€์ƒ ์›Œํฌ๋กœ๋“œ์˜ ์œ„์น˜์™€ ์ผ์น˜ํ•˜๋Š” ์—”๋“œํฌ์ธํŠธ์—ฌ์•ผ ํ•ฉ๋‹ˆ๋‹ค(์˜ˆ: us-central1 ๋ฆฌ์ „์˜ ๋ฆฌ์ „ํ™”๋œ ์›Œํฌ๋กœ๋“œ์˜ ๊ฒฝ์šฐ https://us-central1-assuredworkloads.googleapis.com, ๋ฏธ๊ตญ์˜ ๋ฉ€ํ‹ฐ ๋ฆฌ์ „์˜ ๊ฒฝ์šฐ https://us-assuredworkloads.googleapis.com).
  • ORGANIZATION_ID: Assured Workloads ํด๋”์˜ ์กฐ์ง ID์ž…๋‹ˆ๋‹ค(์˜ˆ: 919698201234).
  • LOCATION_ID: Assured Workloads ํด๋”์˜ ์œ„์น˜์ž…๋‹ˆ๋‹ค(์˜ˆ: us-central1 ๋˜๋Š” us). ์›Œํฌ๋กœ๋“œ์˜ data region ๊ฐ’์— ํ•ด๋‹นํ•ฉ๋‹ˆ๋‹ค.
  • WORKLOAD_ID: ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์—…๋ฐ์ดํŠธ๋ฅผ ๋‚˜์—ดํ•  Assured Workloads ์›Œํฌ๋กœ๋“œ์˜ ID์ž…๋‹ˆ๋‹ค(์˜ˆ: 00-701ea036-7152-4780-a867-9f5).
  • UPDATE_ID: ์ ์šฉํ•  ์—…๋ฐ์ดํŠธ์˜ ID์ž…๋‹ˆ๋‹ค. organizations.locations.workloads.updates.list ๋ฉ”์„œ๋“œ์—์„œ ๋ฐ˜ํ™˜๋œ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์—…๋ฐ์ดํŠธ ๋ชฉ๋ก์—์„œ ์„ ํƒ๋ฉ๋‹ˆ๋‹ค(์˜ˆ: edb84871-833b-45ec-9c00-c9b5c19d2d87).

์š”์ฒญ ๋ณธ๋ฌธ:

{
  "name":"organizations/[ORGANIZATION_ID]/locations/[LOCATION_ID]/workloads/[WORKLOAD_ID]/updates/[UPDATE_ID]",
  "action": "APPLY"
}

์˜ˆ๋ฅผ ๋“ค๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

POST https://us-central1-assuredworkloads.googleapis.com/v1beta1/organizations/919698298765/locations/us-central1/workloads/00-701ea036-7152-4781-a867-9f5/updates/edb84871-833b-45ec-9c00-c9b5c19d2d87:apply

{
  "name": "organizations/919698298765/locations/us-central1/workloads/00-701ea036-7152-4781-a867-9f5/updates/edb84871-833b-45ec-9c00-c9b5c19d2d87",
  "action": "APPLY"
}

์„ฑ๊ณตํ•˜๋ฉด ๋‹ค์Œ ์˜ˆ์‹œ์™€ ์œ ์‚ฌํ•œ JSON ์‘๋‹ต์ด ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค.

{
  "name": "organizations/919698298765/locations/us-central1/operations/647b1c77-b9a5-45d2-965e-70a1e867fe5b",
  "metadata": {
    "@type": "type.googleapis.com/google.cloud.assuredworkloads.v1beta1.ApplyWorkloadUpdateOperationMetadata",
    "update_name": "organizations/919698298765/locations/us-central1/workloads/00-701ea036-7152-4781-a867-9f5/updates/edb84871-833b-45ec-9c00-c9b5c19d2d87",
    "create_time": "2024-10-01T14:34:30.290896Z",
    "action": "APPLY"
  }
}

์žฅ๊ธฐ ์‹คํ–‰ ์—…๋ฐ์ดํŠธ ์ž‘์—…์˜ ์ƒํƒœ๋ฅผ ๊ฐ€์ ธ์˜ค๋ ค๋ฉด JSON ์‘๋‹ต์˜ name ๊ฐ’์— ์žˆ๋Š” ์ž‘์—… ID๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. ์ด์ „ ์˜ˆ์‹œ๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ์ž‘์—… ID๋Š” 647b1c77-b9a5-45d2-965e-70a1e867fe5b์ž…๋‹ˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  ๋‹ค์Œ ์š”์ฒญ์„ ์‹คํ–‰ํ•˜์—ฌ ์ž๋ฆฌํ‘œ์‹œ์ž ๊ฐ’์„ ์ง์ ‘ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.

GET https://[ENDPOINT_URI]/v1/organizations/[ORGANIZATION_ID]/locations/[LOCATION_ID]/operations/[OPERATION_ID]

์˜ˆ๋ฅผ ๋“ค๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

GET https://us-central1-assuredworkloads.googleapis.com/v1/organizations/919698298765/locations/us-central1/operations/647b1c77-b9a5-45d2-965e-70a1e867fe5b

์„ฑ๊ณตํ•˜๋ฉด ๋‹ค์Œ ์˜ˆ์‹œ์™€ ์œ ์‚ฌํ•œ JSON ์‘๋‹ต์ด ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค.

{
  "name": "organizations/919698298765/locations/us-central1/operations/647b1c77-b9a5-45d2-965e-70a1e867fe5b",
  "metadata": {
    "@type": "type.googleapis.com/google.cloud.assuredworkloads.v1beta1.ApplyWorkloadUpdateOperationMetadata",
    "updateName": "organizations/919698298765/locations/us-central1/workloads/00-701ea036-7152-4781-a867-9f5/updates/edb84871-833b-45ec-9c00-c9b5c19d2d87",
    "createTime": "2024-10-01T13:33:09Z"
    "action": "APPLY"
  },
  "done": true
  "response": {
    "@type": "type.googleapis.com/google.cloud.assuredworkloads.v1beta1.ApplyWorkloadUpdateResponse",
    "appliedUpdate": {
      "name": "organizations/531459884741/locations/us-central1/workloads/00-0b328e90-da70-431e-befc-a4a/updates/db556beb-ce66-4260-bd3b-28115f1ec300",
      "state": "APPLIED",
      "createTime": "2024-10-01T14:31:24.310323Z",
      "updateTime": "2024-10-01T14:34:30.855792Z",
      "details": {
        "orgPolicyUpdate": {
          "appliedPolicy": {
            "resource": "folders/196232301850",
            "constraint": "constraints/compute.disableInstanceDataAccessApis",
            "rule": {
              "enforce": true
            }
          },
          "suggestedPolicy": {
            "resource": "folders/196232301850",
            "constraint": "constraints/compute.disableInstanceDataAccessApis",
            "rule": {
              "enforce": false
            }
          }
        }
      }
    }
  }
}