IAM์œผ๋กœ ์•ก์„ธ์Šค ์ œ์–ด

์ด ํŽ˜์ด์ง€์—์„œ๋Š” Certificate Authority Service์˜ IAM ์—ญํ• ์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค.

CA Service๋Š” ์•ก์„ธ์Šค ์ œ์–ด์— Identity and Access Management(IAM) ์—ญํ• ์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. IAM์„ ์‚ฌ์šฉํ•˜๋ฉด ๋ˆ„๊ฐ€(ID) ์–ด๋–ค ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•œ ์–ด๋–ค ์•ก์„ธ์Šค ๊ถŒํ•œ(์—ญํ• )์„ ๊ฐ–๋Š”์ง€ ์ •์˜ํ•˜์—ฌ ์•ก์„ธ์Šค๋ฅผ ์ œ์–ดํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. IAM ์—ญํ• ์—๋Š” ์‚ฌ์šฉ์ž๊ฐ€ Google Cloud ๋ฆฌ์†Œ์Šค์—์„œ ํŠน์ • ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ฃผ๋Š” ๊ถŒํ•œ ์ง‘ํ•ฉ์ด ํฌํ•จ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. IAM ์—ญํ• ์„ ๋ถ€์—ฌํ•˜๋Š” ๋™์•ˆ ์ตœ์†Œ ๊ถŒํ•œ์˜ ์›์น™์„ ๋”ฐ๋ฅด๋ฉด Certificate Authority Service ๋ฆฌ์†Œ์Šค์˜ ๋ฌด๊ฒฐ์„ฑ์„ ๋ณดํ˜ธํ•˜๊ณ  CA ํ’€๊ณผ ์ „์ฒด ๊ณต๊ฐœ ํ‚ค ์ธํ”„๋ผ(PKI)์˜ ๋ณด์•ˆ์„ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

IAM ์—ญํ• ์„ ์‚ฌ์šฉ์ž๋‚˜ ์„œ๋น„์Šค ๊ณ„์ •์— ํ• ๋‹นํ•˜๋Š” ๋ฐฉ๋ฒ•์€ IAM ๋ฌธ์„œ์—์„œ ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•œ ์•ก์„ธ์Šค ๊ถŒํ•œ ๋ถ€์—ฌ, ๋ณ€๊ฒฝ, ์ทจ์†Œ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

์‚ฌ์ „ ์ •์˜๋œ ์—ญํ• 

๋‹ค์Œ ํ‘œ์—์„œ๋Š” ์‚ฌ์ „ ์ •์˜๋œ IAM ์—ญํ• ๊ณผ ๊ฐ ์—ญํ• ๊ณผ ์—ฐ๊ฒฐ๋œ ๊ถŒํ•œ์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.

์—ญํ•  ๊ถŒํ•œ ์„ค๋ช…
CA Service ๊ฐ์‚ฌ์ž
roles/privateca.auditor
privateca.caPools.get
privateca.caPools.getIamPolicy
privateca.caPools.list
privateca.certificateAuthorities.list
privateca.certificateAuthorities.get
privateca.certificateTemplates.get
privateca.certificateTemplates.getIamPolicy
privateca.certificateTemplates.list
privateca.certificates.list
privateca.certificates.get
privateca.locations.get
privateca.locations.list
privateca.operations.get
privateca.operations.list
privateca.certificateRevocationLists.list
privateca.certificateRevocationLists.get
privateca.certificateRevocationLists.getIamPolicy
resourcemanager.projects.get
resourcemanager.projects.list
CA Service ๊ฐ์‚ฌ์ž ์—ญํ• ์€ ๋ชจ๋“  CA Service ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•œ ์ฝ๊ธฐ ์ „์šฉ ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ๊ฐ€์ง€๋ฉฐ CA ํ’€, CA, ์ธ์ฆ์„œ, ํ•ด์ง€ ๋ชฉ๋ก, IAM ์ •์ฑ…, ํ”„๋กœ์ ํŠธ์˜ ์†์„ฑ์„ ๊ฒ€์ƒ‰ํ•˜๊ณ  ๋‚˜์—ดํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. CA ํ’€์˜ ๋ณด์•ˆ ๋ฐ ์šด์˜์„ ๊ฒ€์ฆํ•  ์ฑ…์ž„์ด ์žˆ๊ณ  ์„œ๋น„์Šค ๊ด€๋ฆฌ๋ฅผ ์œ„ํ•œ ์ผ์ผ ์ฑ…์ž„์ด ํ• ๋‹น๋˜์ง€ ์•Š์€ ๊ฐœ๋ณ„ ์‚ฌ์šฉ์ž์—๊ฒŒ ์ด ์—ญํ• ์„ ํ• ๋‹นํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค.
CA Service ์ธ์ฆ์„œ ์š”์ฒญ์ž
roles/privateca.certificateRequester
privateca.certificates.create CA Service ์ธ์ฆ์„œ ์š”์ฒญ์ž ์—ญํ• ์€ CA ํ’€์— ์ธ์ฆ์„œ ์š”์ฒญ์„ ์ œ์ถœํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ธ์ฆ์„œ๋ฅผ ์š”์ฒญํ•  ์ˆ˜ ์žˆ๋Š” ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ๊ฐœ๋ณ„ ์‚ฌ์šฉ์ž์—๊ฒŒ ์ด ์—ญํ• ์„ ๋ถ€์—ฌํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค.

์ด ์—ญํ• ์„ ๊ฐ€์ง„ ์‚ฌ์šฉ์ž๋Š” ๋ฐœ๊ธ‰ ์ •์ฑ…์— ๋”ฐ๋ผ ์ž„์˜์˜ ์ธ์ฆ์„œ๋ฅผ ์š”์ฒญํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

CA Service ์ธ์ฆ์„œ ๊ด€๋ฆฌ์ž ์—ญํ• ๊ณผ ๋‹ฌ๋ฆฌ ์ด ์—ญํ• ์—์„œ๋Š” ์‚ฌ์šฉ์ž๊ฐ€ ์ƒˆ๋กœ ๋ฐœ๊ธ‰๋œ ์ธ์ฆ์„œ๋ฅผ ๊ฐ€์ ธ์˜ค๊ฑฐ๋‚˜ ๋‚˜์—ดํ•˜๊ฑฐ๋‚˜ CA ํ’€์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ๊ฐ€์ ธ์˜ฌ ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.
CA Service ์›Œํฌ๋กœ๋“œ ์ธ์ฆ์„œ ์š”์ฒญ์ž
roles/privateca.workloadCertificateRequester
privateca.certificates.createForSelf CA Service ์›Œํฌ๋กœ๋“œ ์ธ์ฆ์„œ ์š”์ฒญ์ž๋Š” CA Service์˜ ์ธ์ฆ์„œ๋ฅผ ํ˜ธ์ถœ์ž ID๋กœ ์š”์ฒญํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
CA Service ์ธ์ฆ์„œ ๊ด€๋ฆฌ์ž
roles/privateca.certificateManager
roles/privateca.auditor์˜ ๋ชจ๋“  ๊ถŒํ•œ ๋ฐ ๋‹ค์Œ ๊ถŒํ•œ:
privateca.certificates.create
CA Service ์ธ์ฆ์„œ ๊ด€๋ฆฌ์ž๋Š” CA Service ์ธ์ฆ์„œ ์š”์ฒญ์ž์™€ ๊ฐ™์€ CA ํ’€์— ์ธ์ฆ์„œ ๋ฐœ๊ธ‰ ์š”์ฒญ์„ ์ œ์ถœํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋˜ํ•œ ์ด ์—ญํ• ์€ CA Service ๊ฐ์‚ฌ์ž ์—ญํ• ์˜ ๊ถŒํ•œ๋„ ์ƒ์†ํ•ฉ๋‹ˆ๋‹ค. ๊ด€๋ฆฌ์ž ๋˜๋Š” ๋ฆฌ๋“œ ์—”์ง€๋‹ˆ์–ด์™€ ๊ฐ™์€ CA ํ’€์—์„œ ์ธ์ฆ์„œ ์š”์ฒญ์„ ์ƒ์„ฑ, ์ถ”์ , ๊ฒ€ํ† ํ•  ์ˆ˜ ์žˆ๋Š” ๊ฐœ์ธ์—๊ฒŒ ์ด ์—ญํ• ์„ ํ• ๋‹นํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค.
CA Service ์ธ์ฆ์„œ ํ…œํ”Œ๋ฆฟ ์‚ฌ์šฉ์ž
roles/privateca.templateUser
privateca.certificateTemplates.get
privateca.certificateTemplates.list
privateca.certificateTemplates.use
CA Service ์ธ์ฆ์„œ ํ…œํ”Œ๋ฆฟ ์‚ฌ์šฉ์ž๋Š” ์ธ์ฆ์„œ ํ…œํ”Œ๋ฆฟ์„ ์ฝ๊ณ  ๋‚˜์—ดํ•˜๊ณ  ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
CA Service ์ž‘์—… ๊ด€๋ฆฌ์ž
roles/privateca.caManager
roles/privateca.auditor์˜ ๋ชจ๋“  ๊ถŒํ•œ ๋ฐ ๋‹ค์Œ ๊ถŒํ•œ:
privateca.certificates.update
privateca.caPools.create
privateca.caPools.delete
privateca.caPools.update
privateca.certificateAuthorities.create
privateca.certificateAuthorities.delete
privateca.certificateAuthorities.update
privateca.certificateRevocationLists.update
privateca.certificateTemplates.create
privateca.certificateTemplates.delete
privateca.certificateTemplates.update
privateca.certificates.update
privateca.operations.cancel
privateca.operations.delete
resourcemanager.projects.get
resourcemanager.projects.list
storage.buckets.create
CA Service ์ž‘์—… ๊ด€๋ฆฌ์ž๋Š” CA ํ’€๊ณผ CA๋ฅผ ๋งŒ๋“ค๊ณ  ์—…๋ฐ์ดํŠธํ•˜๊ณ  ์‚ญ์ œํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ์—ญํ• ์€ ๋˜ํ•œ ์ธ์ฆ์„œ๋ฅผ ์ทจ์†Œํ•˜๊ณ  Cloud Storage ๋ฒ„ํ‚ท์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค. ๋˜ํ•œ CA Service ๊ฐ์‚ฌ์ž์™€ ๋™์ผํ•œ ๊ธฐ๋Šฅ์ด ํฌํ•จ๋ฉ๋‹ˆ๋‹ค. ์ด ์—ญํ• ์—์„œ ๊ฐœ๋ณ„ ์‚ฌ์šฉ์ž๋Š” CA ํ’€ ๋ฐœ๊ธ‰ ์ •์ฑ…์˜ ๊ตฌ์„ฑ๊ณผ ํ•จ๊ป˜ ์กฐ์ง์—์„œ CA ํ’€์„ ๊ตฌ์„ฑํ•˜๊ณ  ๋ฐฐํฌํ•  ์ฑ…์ž„์ด ์žˆ์Šต๋‹ˆ๋‹ค.

์ด ์—ญํ• ์€ ์ธ์ฆ์„œ ๋งŒ๋“ค๊ธฐ๋ฅผ ํ—ˆ์šฉํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์ด๋ ‡๊ฒŒ ํ•˜๋ ค๋ฉด CA Service ์ธ์ฆ์„œ ์š”์ฒญ์ž, CA Service ์ธ์ฆ์„œ ๊ด€๋ฆฌ์ž ๋˜๋Š” CA Service ๊ด€๋ฆฌ์ž ์—ญํ• ์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.
CA Service ๊ด€๋ฆฌ์ž
roles/privateca.admin
roles/privateca.certificateManager, roles/privateca.caManager์˜ ๋ชจ๋“  ๊ถŒํ•œ ๋ฐ ๋‹ค์Œ ๊ถŒํ•œ:
privateca.*.setIamPolicy
privateca.caPools.use
privateca.operations.cancel
privateca.operations.delete
privateca.resourcemanager.projects.get
privateca.resourcemanager.projects.list
storage.buckets.create
CA Service ๊ด€๋ฆฌ์ž ์—ญํ• ์€ CA Service ์ž‘์—… ๊ด€๋ฆฌ์ž ๋ฐ CA Service ์ธ์ฆ์„œ ๊ด€๋ฆฌ์ž ์—ญํ• ์˜ ๊ถŒํ•œ์„ ์ƒ์†ํ•ฉ๋‹ˆ๋‹ค. ์ด ์—ญํ• ์€ CA Service ๋‚ด์—์„œ ๋ชจ๋“  ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. CA Service ๊ด€๋ฆฌ์ž๋Š” CA ํ’€์˜ IAM ์ •์ฑ…์„ ์„ค์ •ํ•˜๊ณ  Cloud Storage ๋ฒ„ํ‚ท์„ ๋งŒ๋“ค ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์„œ๋น„์Šค๊ฐ€ ์„ค์ •๋œ ํ›„์—๋Š” ์ด ์—ญํ• ์„ ๊ฑฐ์˜ ํ• ๋‹นํ•˜์ง€ ์•Š๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค. ์ด ์—ญํ• ์—์„œ ๊ฐœ์ธ์€ ๋‹ค๋ฅธ ์‚ฌ๋žŒ์—๊ฒŒ ๊ถŒํ•œ์„ ํ• ๋‹นํ•˜๊ณ  CA Service์—์„œ ์ธ์ฆ์„œ ์š”์ฒญ์„ ๊ด€๋ฆฌํ•˜๋Š” ๋“ฑ ๊ด€๋ฆฌ์˜ ๋ชจ๋“  ์ธก๋ฉด์„ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์Šน์ธ๋˜์ง€ ์•Š์€ ์•ก์„ธ์Šค ๋˜๋Š” ์‚ฌ์šฉ์„ ๋ฐฉ์ง€ํ•˜๊ธฐ ์œ„ํ•ด ์ด ์—ญํ•  ๊ณ„์ •์— ํŠน์ˆ˜ ์ œ์–ด ๋ฐ ์•ก์„ธ์Šค๋ฅผ ๊ตฌํ˜„ํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค.

CA Service ์„œ๋น„์Šค ์—์ด์ „ํŠธ ์—ญํ• 

CA ์ƒ์„ฑ ์ค‘์— ๊ธฐ์กด Cloud KMS ์„œ๋ช… ํ‚ค ๋˜๋Š” Cloud Storage ๋ฒ„ํ‚ท์„ ์ œ๊ณตํ•  ๋•Œ CA Service ์„œ๋น„์Šค ์—์ด์ „ํŠธ ์„œ๋น„์Šค ๊ณ„์ •(service-PROJECT_NUMBER@gcp-sa-privateca.iam.gserviceaccount.com)์—๋Š” ๊ฐ ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•œ ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

Cloud KMS์˜ ๊ฒฝ์šฐ์— roles/cloudkms.signerVerifier์€ ์„œ๋ช… ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  ๊ณต๊ฐœ ํ‚ค๋ฅผ ์ฝ๊ธฐ ์œ„ํ•ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. roles/viewer๋Š” Cloud Monitoring ํ†ตํ•ฉ์„ ์œ„ํ•ด ํ‚ค๋ฅผ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜๋Š” ๋ฐ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

Cloud Storage์˜ ๊ฒฝ์šฐ์— roles/storage.objectAdmin์€ CA ์ธ์ฆ์„œ ๋ฐ CRL์„ ๋ฒ„ํ‚ท์— ์“ฐ๊ธฐ ์œ„ํ•ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. roles/storage.legacyBucketReader๋Š” ๋ฒ„ํ‚ท์˜ Cloud Monitoring ํ†ตํ•ฉ์„ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜๊ธฐ ์œ„ํ•ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ Cloud Storage์˜ IAM ์—ญํ• ์„ ์ฐธ์กฐํ•˜์„ธ์š”.

API๋ฅผ ํ†ตํ•ด ์„œ๋น„์Šค์— ์•ก์„ธ์Šคํ•  ๋•Œ ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

  1. ์„œ๋น„์Šค ์—์ด์ „ํŠธ ์—ญํ• ์„ ์‚ฌ์šฉํ•˜์—ฌ ์„œ๋น„์Šค ๊ณ„์ •์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

    gcloud

    gcloud beta services identity create --service=privateca.googleapis.com --project=PROJECT_ID
    

    ๊ฐ ํ•ญ๋ชฉ์˜ ์˜๋ฏธ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

    • PROJECT_ID๋Š” CA ํ’€์ด ์ƒ์„ฑ๋œ ํ”„๋กœ์ ํŠธ์˜ ๊ณ ์œ  ์‹๋ณ„์ž์ž…๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ gcloud ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์„œ๋น„์Šค ๊ณ„์ •์— roles/cloudkms.signerVerifier ๋ฐ roles/viewer ์—ญํ• ์„ ๋ถ€์—ฌํ•ฉ๋‹ˆ๋‹ค.

    ๊ธฐ์กด Cloud KMS ์„œ๋ช… ํ‚ค๊ฐ€ ์ œ๊ณต๋œ ๊ฒฝ์šฐ:

    gcloud

    gcloud kms keys add-iam-policy-binding 'CRYPTOKEY_NAME' \
      --keyring='KEYRING_NAME' \
      --location='LOCATION' \
      --member='serviceAccount:service-PROJECT_NUMBER@gcp-sa-privateca.iam.gserviceaccount.com' \
      --role='roles/cloudkms.signerVerifier'
    

    ๊ฐ ํ•ญ๋ชฉ์˜ ์˜๋ฏธ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

    • 'CRYPTOKEY_NAME'์€ ํ‚ค ์ด๋ฆ„์ž…๋‹ˆ๋‹ค.
    • 'KEYRING_NAME'์€ ํ‚ค๋ง์˜ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค.
    • 'LOCATION'๋Š” ํ‚ค๋ง์„ ๋งŒ๋“  Cloud KMS ์œ„์น˜์ž…๋‹ˆ๋‹ค.
    • 'PROJECT_NUMBER'๋Š” ์„œ๋น„์Šค ๊ณ„์ •์˜ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค.
    gcloud kms keys add-iam-policy-binding 'CRYPTOKEY_NAME' \
      --keyring='KEYRING_NAME' \
      --location='LOCATION' \
      --member='serviceAccount:service-PROJECT_NUMBER@gcp-sa-privateca.iam.gserviceaccount.com' \
      --role='roles/viewer'
    
  3. ๋‹ค์Œ gcloud ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์„œ๋น„์Šค ๊ณ„์ •์— roles/storage.objectAdmin ๋ฐ roles/storage.legacyBucketReader ์—ญํ• ์„ ๋ถ€์—ฌํ•ฉ๋‹ˆ๋‹ค.

    ๊ธฐ์กด Cloud Storage ๋ฒ„ํ‚ท์ด ์ œ๊ณต๋œ ๊ฒฝ์šฐ:

    gcloud

    gcloud storage buckets add-iam-policy-binding gs://BUCKET_NAME \
      --member=serviceAccount:service-PROJECT_NUMBER@gcp-sa-privateca.iam.gserviceaccount.com \
      --role=roles/storage.objectAdmin
    

    ๊ฐ ํ•ญ๋ชฉ์˜ ์˜๋ฏธ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

    • BUCKET_NAME์€ Cloud Storage ๋ฒ„ํ‚ท์˜ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค.
    • PROJECT_NUMBER๋Š” ์„œ๋น„์Šค ๊ณ„์ •์˜ ๊ณ ์œ  ์‹๋ณ„์ž์ž…๋‹ˆ๋‹ค.
    gcloud storage buckets add-iam-policy-binding gs://BUCKET_NAME \
      --member=serviceAccount:service-PROJECT_NUMBER@gcp-sa-privateca.iam.gserviceaccount.com \
      --role=roles/storage.legacyBucketReader
    

API ๊ถŒํ•œ

๋‹ค์Œ ํ‘œ์—๋Š” ํ˜ธ์ถœ์ž๊ฐ€ CA Service API์˜ ๊ฐ ๋ฉ”์„œ๋“œ๋ฅผ ํ˜ธ์ถœํ•˜๋Š” ๋ฐ ํ•„์š”ํ•œ ๊ถŒํ•œ์ด ๋‚˜์™€ ์žˆ์Šต๋‹ˆ๋‹ค.

๊ถŒํ•œ ์„ค๋ช…
privateca.caPools.create ์ธ์ฆ ๊ธฐ๊ด€(CA) ํ’€์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค.
privateca.caPools.update CA ํ’€์„ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.
privateca.caPools.list ํ”„๋กœ์ ํŠธ์˜ CA ํ’€์„ ๋‚˜์—ดํ•ฉ๋‹ˆ๋‹ค.
privateca.caPools.get CA ํ’€์„ ๊ฒ€์ƒ‰ํ•ฉ๋‹ˆ๋‹ค.
privateca.caPools.delete CA ํ’€์„ ์‚ญ์ œํ•ฉ๋‹ˆ๋‹ค.
privateca.caPools.use CA ํ’€์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.
privateca.caPools.getIamPolicy CA ํ’€์˜ IAM ์ •์ฑ…์„ ๊ฒ€์ƒ‰ํ•ฉ๋‹ˆ๋‹ค.
privateca.caPools.setIamPolicy CA ํ’€์˜ IAM ์ •์ฑ…์„ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.
privateca.certificateAuthorities.create CA๋ฅผ ๋งŒ๋“ญ๋‹ˆ๋‹ค.
privateca.certificateAuthorities.delete CA ์‚ญ์ œ๋ฅผ ์˜ˆ์•ฝํ•ฉ๋‹ˆ๋‹ค.
privateca.certificateAuthorities.get CA ๋˜๋Š” CA ์ธ์ฆ์„œ ์„œ๋ช… ์š”์ฒญ์„ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
privateca.certificateAuthorities.list ํ”„๋กœ์ ํŠธ์˜ CA๋ฅผ ๋‚˜์—ดํ•ฉ๋‹ˆ๋‹ค.
privateca.certificateAuthorities.update CA ํ™œ์„ฑํ™”, ์‚ฌ์šฉ ์„ค์ •, ์‚ฌ์šฉ ์ค‘์ง€, ๋ณต์›์„ ํฌํ•จํ•˜์—ฌ CA๋ฅผ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.
privateca.certificates.create CA Service์˜ ์ธ์ฆ์„œ๋ฅผ ์š”์ฒญํ•ฉ๋‹ˆ๋‹ค.
privateca.certificates.createForSelf ๋ฐœ์‹ ์ž ID๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ CA Service์—์„œ ์ธ์ฆ์„œ๋ฅผ ์š”์ฒญํ•ฉ๋‹ˆ๋‹ค.
privateca.certificates.get ์ธ์ฆ์„œ ๋ฐ ํ•ด๋‹น ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ๋ฅผ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
privateca.certificates.list CA์˜ ๋ชจ๋“  ์ธ์ฆ์„œ๋ฅผ ๋‚˜์—ดํ•ฉ๋‹ˆ๋‹ค.
privateca.certificates.update ์ทจ์†Œ๋ฅผ ํฌํ•จํ•œ ์ธ์ฆ์„œ์˜ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ๋ฅผ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.
privateca.certificateRevocationLists.get CA์—์„œ ์ธ์ฆ์„œ ํ•ด์ง€ ๋ชฉ๋ก(CRL)์„ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
privateca.certificateRevocationLists.getIamPolicy CRL์˜ IAM ์ •์ฑ…์„ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
privateca.certificateRevocationLists.list CA์˜ ๋ชจ๋“  CRL์„ ๋‚˜์—ดํ•ฉ๋‹ˆ๋‹ค.
privateca.certificateRevocationLists.setIamPolicy CRL์˜ IAM ์ •์ฑ…์„ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
privateca.certificateRevocationLists.update CRL์„ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.
privateca.certificateTemplates.create ์ธ์ฆ์„œ ํ…œํ”Œ๋ฆฟ์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค.
privateca.certificateTemplates.get ์ธ์ฆ์„œ ํ…œํ”Œ๋ฆฟ์„ ๊ฒ€์ƒ‰ํ•ฉ๋‹ˆ๋‹ค.
privateca.certificateTemplates.list ๋ชจ๋“  ์ธ์ฆ์„œ ํ…œํ”Œ๋ฆฟ์„ ๋‚˜์—ดํ•ฉ๋‹ˆ๋‹ค.
privateca.certificateTemplates.update ์ธ์ฆ์„œ ํ…œํ”Œ๋ฆฟ์„ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.
privateca.certificateTemplates.delete ์ธ์ฆ์„œ ํ…œํ”Œ๋ฆฟ์„ ์‚ญ์ œํ•ฉ๋‹ˆ๋‹ค.
privateca.certificateTemplates.getIamPolicy ์ธ์ฆ์„œ ํ…œํ”Œ๋ฆฟ์˜ IAM ์ •์ฑ…์„ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
privateca.certificateTemplates.setIamPolicy ์ธ์ฆ์„œ ํ…œํ”Œ๋ฆฟ์˜ IAM ์ •์ฑ…์„ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.
privateca.certificateTemplates.use ์ธ์ฆ์„œ ํ…œํ”Œ๋ฆฟ์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.
privateca.operations.cancel ์žฅ๊ธฐ ์‹คํ–‰ ์ž‘์—…์„ ์ทจ์†Œํ•ฉ๋‹ˆ๋‹ค.
privateca.operations.delete ์žฅ๊ธฐ ์‹คํ–‰ ์ž‘์—…์„ ์‚ญ์ œํ•ฉ๋‹ˆ๋‹ค.
privateca.operations.get ์žฅ๊ธฐ ์‹คํ–‰ ์ž‘์—…์„ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค.
privateca.operations.list ํ”„๋กœ์ ํŠธ์˜ ์žฅ๊ธฐ ์‹คํ–‰ ์ž‘์—…์„ ๋‚˜์—ดํ•ฉ๋‹ˆ๋‹ค.

๋‹ค์Œ ๋‹จ๊ณ„

  • IAM์ด Google Cloud ๋ฆฌ์†Œ์Šค์˜ ๊ถŒํ•œ ๋ฐ ์•ก์„ธ์Šค ๋ฒ”์œ„๋ฅผ ์ค‘์•™์—์„œ ๊ด€๋ฆฌํ•˜๋Š” ๋ฐฉ๋ฒ• ์•Œ์•„๋ณด๊ธฐ
  • IAM ์ •์ฑ… ๊ตฌ์„ฑ ๋ฐฉ๋ฒ• ์•Œ์•„๋ณด๊ธฐ