CMEK ๋ฌธ์ œ ํ•ด๊ฒฐ

๊ณ ๊ฐ ๊ด€๋ฆฌ ์•”ํ˜ธํ™” ํ‚ค(CMEK)๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ Eventarc๋ฅผ ๋ณดํ˜ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ํ‚ค๋Š” Cloud Key Management Service(Cloud KMS)๋ฅผ ํ†ตํ•ด ์ƒ์„ฑ๋˜๊ณ  ๊ด€๋ฆฌ๋ฉ๋‹ˆ๋‹ค. ๋‹ค์Œ ํ‘œ์—์„œ๋Š” Eventarc์™€ ํ•จ๊ป˜ Cloud KMS๋ฅผ ์‚ฌ์šฉํ•  ๋•Œ ๋ฐœ์ƒํ•˜๋Š” ๋‹ค์–‘ํ•œ CMEK ๋ฌธ์ œ์™€ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค.

Eventarc ๋ฆฌ์†Œ์Šค๋ฅผ ๋งŒ๋“ค๊ฑฐ๋‚˜ ์—…๋ฐ์ดํŠธํ•  ๋•Œ ๋ฐœ์ƒํ•˜๋Š” ๋ฌธ์ œ

CMEK ๋ฌธ์ œ ์˜ค๋ฅ˜ ๋ฉ”์‹œ์ง€ ์„ค๋ช…
์‚ฌ์šฉ ์ค‘์ง€๋œ ํ‚ค $KEY is not enabled, current state is: DISABLED

์ œ๊ณต๋œ Cloud KMS ํ‚ค๊ฐ€ Eventarc ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•ด ์‚ฌ์šฉ ์ค‘์ง€๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๋ฆฌ์†Œ์Šค์™€ ์—ฐ๊ฒฐ๋œ ์ด๋ฒคํŠธ ๋˜๋Š” ๋ฉ”์‹œ์ง€๊ฐ€ ๋” ์ด์ƒ ๋ณดํ˜ธ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

ํ•ด๊ฒฐ์ฑ…:

  1. ์ฑ„๋„์— ์‚ฌ์šฉ๋œ ํ‚ค๋ฅผ ํ‘œ์‹œํ•ฉ๋‹ˆ๋‹ค.
  2. Cloud KMS ํ‚ค๋ฅผ ๋‹ค์‹œ ์‚ฌ์šฉ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.
ํ• ๋‹น๋Ÿ‰ ์ดˆ๊ณผ Quota exceeded for limit

Cloud KMS ์š”์ฒญ์˜ ํ• ๋‹น๋Ÿ‰ ํ•œ๋„์— ๋„๋‹ฌํ–ˆ์Šต๋‹ˆ๋‹ค.

ํ•ด๊ฒฐ์ฑ…:

  • Cloud KMS ํ˜ธ์ถœ ์ˆ˜๋ฅผ ์ œํ•œํ•ฉ๋‹ˆ๋‹ค.
  • ํ• ๋‹น๋Ÿ‰์„ ๋Š˜๋ฆฝ๋‹ˆ๋‹ค.
์ž์„ธํ•œ ๋‚ด์šฉ์€ Cloud KMS ํ• ๋‹น๋Ÿ‰ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ์กฐ์ •์„ ์ฐธ์กฐํ•˜์„ธ์š”.
์ผ์น˜ํ•˜์ง€ ์•Š๋Š” ๋ฆฌ์ „ Key region $REGION must match the resource to be protected

์ œ๊ณต๋œ KMS ํ‚ค ๋ฆฌ์ „์ด ์ฑ„๋„ ๋ฆฌ์ „๊ณผ ๋‹ค๋ฆ…๋‹ˆ๋‹ค.

ํ•ด๊ฒฐ์ฑ…:

๋™์ผํ•œ ๋ฆฌ์ „์˜ Cloud KMS ํ‚ค๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. ๋ฉ€ํ‹ฐ ๋ฆฌ์ „ eu์˜ ์ฑ„๋„์€ ๋ฉ€ํ‹ฐ ๋ฆฌ์ „ europe์˜ Cloud KMS ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ณดํ˜ธํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ Cloud KMS ์œ„์น˜ ๋ฐ Eventarc ๋ฉ€ํ‹ฐ ๋ฆฌ์ „ ์œ„์น˜๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

์กฐ์ง ์ •์ฑ… ์ œ์•ฝ์กฐ๊ฑด project/PROJECT_ID violated org policy constraint

Eventarc๋Š” ์กฐ์ง ์ „๋ฐ˜์—์„œ CMEK ์‚ฌ์šฉ์„ ๋ณด์žฅํ•˜๊ธฐ ์œ„ํ•ด ๋‹ค์Œ ๋‘ ๊ฐ€์ง€ ์กฐ์ง ์ •์ฑ… ์ œ์•ฝ์กฐ๊ฑด๊ณผ ํ†ตํ•ฉ๋ฉ๋‹ˆ๋‹ค. ๊ธฐ์กด Eventarc ๋ฆฌ์†Œ์Šค์—๋Š” ๋ฆฌ์†Œ์Šค๊ฐ€ ์ƒ์„ฑ๋œ ํ›„์— ์„ค์ •๋œ ์ •์ฑ…์ด ์ ์šฉ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ํ•˜์ง€๋งŒ ๋ฆฌ์†Œ์Šค๋ฅผ ์—…๋ฐ์ดํŠธํ•˜๋ฉด ์‹คํŒจํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

  • constraints/gcp.restrictNonCmekServices: ์ง€์ •๋œ Cloud KMS ํ‚ค๊ฐ€ ์—†๋Š” ๋ชจ๋“  ๋ฆฌ์†Œ์Šค ๋งŒ๋“ค๊ธฐ ์š”์ฒญ์ด ์‹คํŒจํ•ฉ๋‹ˆ๋‹ค.

    ํ•ด๊ฒฐ์ฑ…:

    Eventarc ๋ฆฌ์†Œ์Šค์˜ Cloud KMS ํ‚ค๋ฅผ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์ƒˆ Eventarc ๋ฆฌ์†Œ์Šค์— CMEK ์š”๊ตฌ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

  • constraints/gcp.restrictCmekCryptoKeyProjects๋Š” Eventarc ๋ฆฌ์†Œ์Šค๋ฅผ ๋ณดํ˜ธํ•˜๋Š” ๋ฐ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” Cloud KMS ํ‚ค๋ฅผ ์ œํ•œํ•ฉ๋‹ˆ๋‹ค.

    ํ•ด๊ฒฐ์ฑ…:

    Eventarc ํ”„๋กœ์ ํŠธ์— ์ง€์›๋˜๋Š” Cloud KMS ํ‚ค๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ Eventarc ํ”„๋กœ์ ํŠธ์˜ Cloud KMS ํ‚ค ์ œํ•œ์„ ์ฐธ์กฐํ•˜์„ธ์š”.

์ด๋ฒคํŠธ ์ „์†ก ์ค‘์— ๋ฐœ์ƒํ•˜๋Š” ๋ฌธ์ œ

CMEK ๋ฌธ์ œ ์˜ค๋ฅ˜ ๋ฉ”์‹œ์ง€ ์„ค๋ช…
์‚ฌ์šฉ ์ค‘์ง€๋œ ํ‚ค $KEY is not enabled, current state is: DISABLED

์ œ๊ณต๋œ Cloud KMS ํ‚ค๊ฐ€ Eventarc ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•ด ์‚ฌ์šฉ ์ค‘์ง€๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๋ฆฌ์†Œ์Šค์™€ ์—ฐ๊ฒฐ๋œ ์ด๋ฒคํŠธ ๋˜๋Š” ๋ฉ”์‹œ์ง€๊ฐ€ ๋” ์ด์ƒ ๋ณดํ˜ธ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

ํ•ด๊ฒฐ์ฑ…:

  1. ์ฑ„๋„์— ์‚ฌ์šฉ๋œ ํ‚ค๋ฅผ ํ‘œ์‹œํ•ฉ๋‹ˆ๋‹ค.
  2. Cloud KMS ํ‚ค๋ฅผ ๋‹ค์‹œ ์‚ฌ์šฉ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.
ํ• ๋‹น๋Ÿ‰ ์ดˆ๊ณผ Quota exceeded for limit

Cloud KMS ์š”์ฒญ์˜ ํ• ๋‹น๋Ÿ‰ ํ•œ๋„์— ๋„๋‹ฌํ–ˆ์Šต๋‹ˆ๋‹ค.

ํ•ด๊ฒฐ์ฑ…:

  • Cloud KMS ํ˜ธ์ถœ ์ˆ˜๋ฅผ ์ œํ•œํ•ฉ๋‹ˆ๋‹ค.
  • ํ• ๋‹น๋Ÿ‰์„ ๋Š˜๋ฆฝ๋‹ˆ๋‹ค.
์ž์„ธํ•œ ๋‚ด์šฉ์€ Cloud KMS ํ• ๋‹น๋Ÿ‰ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ์กฐ์ •์„ ์ฐธ์กฐํ•˜์„ธ์š”.
๊ถŒํ•œ ์˜ค๋ฅ˜ Permission 'cloudkms.cryptoKeyVersions.useToEncrypt' denied on resource $KEY (or it may not exist)

์ œ๊ณต๋œ Cloud KMS ํ‚ค๊ฐ€ ์—†๊ฑฐ๋‚˜ Identity and Access Management(IAM) ๊ถŒํ•œ์ด ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ๊ตฌ์„ฑ๋˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค.

ํ•ด๊ฒฐ์ฑ…:

Cloud ์™ธ๋ถ€ ํ‚ค ๊ด€๋ฆฌ์ž(Cloud EKM)๋ฅผ ํ†ตํ•ด ์™ธ๋ถ€ ๊ด€๋ฆฌ ํ‚ค๋ฅผ ์‚ฌ์šฉํ•  ๋•Œ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ๋Š” ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๋ ค๋ฉด Cloud EKM ์˜ค๋ฅ˜ ์ฐธ์กฐ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

๋‹ค์Œ ๋‹จ๊ณ„