ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒã¯ãGoogle Cloud ãµãŒãã¹ã®èªèšŒã«ãã䜿çšãããŸãããã ããé©åã«ç®¡çãããŠããªãå ŽåãèªèšŒæ å ±ã®æŒæŽ©ãæš©éææ Œãæ å ±é瀺ãåŠèªé²æ¢ãªã©ã®è åšã«å¯Ÿããè匱æ§ãé«ãŸãå¯èœæ§ããããŸãã
å€ãã®å ŽåããµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®ä»£ããã«ãããå®å šãªæ¹æ³ã§èªèšŒãè¡ãããšãã§ããŸãããã®ã¬ã€ãã¯ããµãŒãã¹ ã¢ã«ãŠã³ã ããŒãæ¬åœã«å¿ èŠãªå Žåãé€ãããµãŒãã¹ ã¢ã«ãŠã³ã ããŒãã¡ã€ã³ã®èªèšŒã¡ã«ããºã ãšããæ¹æ³ããããå®å šãªèªèšŒææ®µã«ç§»è¡ããæ¹æ³ã«ã€ããŠèª¬æããŸãã
ãã®ããã¥ã¡ã³ãã¯ãããå®å šãªèªèšŒã¡ã«ããºã ãåªå ããŠãµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®äœ¿çšãæžãããã»ãã¥ãªã㣠ãã¹ãã£ãŒã匷åããããšèããŠããã»ãã¥ãªãã£ç®¡çè ã察象ãšããŠããŸããæ¢åã®æ¬çªç°å¢ã¯ãŒã¯ããŒããããããããŒã®ã¯ãŒã¯ãããŒããµãŒãã¹ ã¢ã«ãŠã³ã ããŒã䜿çšããå éšããã»ã¹ã®ã»ãã¥ãªãã£ãæ åœããŠãã管çè ã察象ãšãªãå ŽåããããŸãã
æŠèŠ
æ¢åã®ã¯ãŒã¯ããŒããããµãŒãã¹ ã¢ã«ãŠã³ã ããŒãåé€ããå Žåã¯ãå¶çºçãªäžæãé²ããããæ éã«èšç»ãç«ãŠãå¿ èŠããããŸããæ¬¡ã®ç§»è¡èšç»ã¯ãããããããŒã®æ··ä¹±ãæå°éã«æããªããéäžçã«ç®¡çã§ããããã«èšèšãããŠããŸãã
ãã®ç§»è¡èšç»ã«ã¯ã次㮠3 ã€ã®ãã§ãŒãºããããŸãã
- è©äŸ¡: ãã®ãã§ãŒãºã§ã¯ãæ¢åã®ç°å¢ãè©äŸ¡ããŠããµãŒãã¹ ã¢ã«ãŠã³ã ããŒãååšããå ŽæãšãããŒã䜿çšäžãã©ããã確èªããŸãã
- èšç»: ãã®ãã§ãŒãºã§ã¯ãæçµçã«ãããã€ããã³ã³ãããŒã«ã決å®ããé¢ä¿è ã«ç§»è¡èšç»ãäŒããŸãã
- ãããã€: ãã®ãã§ãŒãºã§ã¯ããµãŒãã¹ ã¢ã«ãŠã³ã ããŒã«ä»£ããããå®å šãªæ¹æ³ã§èªèšŒãè¡ããããã¯ãŒã¯ããŒãã®ãªãã¡ã¯ã¿ãªã³ã°ãéå§ããŸãããŸããç°å¢ãç¶ç¶çã«ã¢ãã¿ãªã³ã°ããŠãå°æ¥ã®ãªã¹ã¯ã軜æžããè¿œå æ©èœãæ§ç¯ããŸãã
ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®äœ¿çšç¶æ³ãè©äŸ¡ãã
ãã®ãã§ãŒãºã§ã¯ãæ¢åã®ç°å¢ãè©äŸ¡ããŠããµãŒãã¹ ã¢ã«ãŠã³ã ããŒãååšããå ŽæãšãããŒã䜿çšäžãã©ããã確èªããŸãã
以éã®ã»ã¯ã·ã§ã³ã§ã¯ãçµç¹ã§ã®ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®äœ¿ç𿹿³ãææ¡ããããã«åéããããŒã¿ã«ã€ããŠèª¬æããŸãã
ããŒã®äœ¿çšç¶æ³ã«é¢ããããŒã¿ãåéãã
ãŸãããµãŒãã¹ ã¢ã«ãŠã³ã ããŒãååšããå Žæãšäœ¿çšç¶æ³ã確èªããŸãã
Google Cloud ã«ã¯ããµãŒãã¹ ã¢ã«ãŠã³ãã®äœ¿çšç¶æ³ãææ¡ããããã®ããŒã«ãçšæãããŠããŸãããããã®ããŒã«ã¯ãèªèšŒã«æè¿äœ¿çšããããµãŒãã¹ ã¢ã«ãŠã³ããšããŒãéå» 90 æ¥é䜿çšãããŠããªããµãŒãã¹ ã¢ã«ãŠã³ããéå°ãªæš©éãå«ãããŒã«ãä»äžããããµãŒãã¹ ã¢ã«ãŠã³ããç¹å®ããéã«åœ¹ç«ã¡ãŸãã
ãããã®ããŒã«ã®æ å ±ãçµã¿åãããããšã§ãçµç¹å šäœã§ãµãŒãã¹ ã¢ã«ãŠã³ããšããŒãã©ã®ããã«äœ¿çšãããŠããããããæ£ç¢ºã«ææ¡ã§ããŸãã ãããããœãŒã¹ããã®æ å ±ãçµç¹å šäœã§çµ±åããæ¹æ³ã®äŸã«ã€ããŠã¯ãGitHub ã®ãããã€å¯èœãªãªãã¡ã¬ã³ã¹ ã¢ãŒããã¯ãã£ãã芧ãã ããããã®ãªãã¡ã¬ã³ã¹ ã¢ãŒããã¯ãã£ã¯ãããŸããŸãªããŒã«ããåéããããŒã¿ãéçŽããåæã®ããã«å®æçã« BigQuery ããŒãã«ã«ãšã¯ã¹ããŒãããŸãã
ãã®ãªãã¡ã¬ã³ã¹ ã¢ãŒããã¯ãã£ã§ã¯ãCloud Asset Inventory ã«ã¯ãšãªãå®è¡ããŠçµç¹å
ã®ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒãç¹å®ããããŒã¿ ãã€ãã©ã€ã³ããããã€ããŸããæ¬¡ã«ããã®ããŒã¿ããé¢é£ããã¢ã«ãŠã³ãã®ããŒã®äœ¿çšç¶æ³ãšæš©éã®äœ¿çšç¶æ³ã«é¢ããããŒã¿ãšçµ±åããŸããçµæã®ããŒãã«ïŒsa_key_usage
ïŒãããæ¬¡ã®ãããªããšã確èªããããšãã§ããŸãã
- äœæãããæ°žç¶ããŒã®æ°ããã®æ°å€ã¯ãããŒããã®ç§»è¡ã®é²è¡ç¶æ³ã远跡ããããã®å€§ãŸããªææšãšããŠåœ¹ç«ã¡ãŸãã
- ããŒã䜿çšãããããžã§ã¯ããšãµãŒãã¹ ã¢ã«ãŠã³ãããã®æ å ±ã¯ããµãŒãã¹ ã¢ã«ãŠã³ã ããŒã䜿çšããã¯ãŒã¯ããŒãã®ãªãŒããŒãèå¥ããã®ã«åœ¹ç«ã¡ãŸãã
- ã¢ã¯ãã£ãã§ãªãããŒããããã®ããŒã¯ãã¯ãŒã¯ããŒã ãªãŒããŒããã®è©äŸ¡ãåŸ ããã«åé€ã§ããŸãã
- éå°ãªæš©éã«é¢ããæšå¥šäºé ããããµãŒãã¹ ã¢ã«ãŠã³ãã®ããŒããµãŒãã¹ ã¢ã«ãŠã³ã ããŒããéå°ãªæš©éãæã€ãµãŒãã¹ ã¢ã«ãŠã³ãïŒç¹ã«ãªãŒããŒãç·šéè ãé²èЧè ã®ããŒã«ãæã€ã¢ã«ãŠã³ãïŒã«é¢é£ä»ããããŠããå Žåããã®ããŒã®ãªã¹ã¯ã¯ç¹ã«é«ããªãå¯èœæ§ããããŸããããŒã«ã®æšå¥šäºé ããããµãŒãã¹ ã¢ã«ãŠã³ããæ¢ããšãéå°ãªæš©éãæã€ãµãŒãã¹ ã¢ã«ãŠã³ããç¹å®ã§ããŸãããããã®ãµãŒãã¹ ã¢ã«ãŠã³ããç¹å®ããåŸãã¯ãŒã¯ããŒãã®ç§»è¡ã«åªå é äœãä»ããããšãã§ããŸããããŒã«ã®æšå¥šäºé ãé©çšããŠãéå°ãªæš©éãäºåã«æžããããšãã§ããŸãã
ãã®ããŒã¿ ãã€ãã©ã€ã³ã¯æ¯æ¥å®è¡ãããæ¥ä»åå²ã® BigQuery ããŒãã«ã«æžã蟌ãŸããŸãããã®ããŒãã«ã䜿çšããŠãç¹å®ã®ãµãŒãã¹ ã¢ã«ãŠã³ããŸãã¯ããŒã調æ»ã§ããŸãããŸããLooker Studio ãªã©ã®ããã·ã¥ããŒã ããŒã«ã§ä¿®åŸ©ç¶æ³ã远跡ããããšãã§ããŸãã
ã³ã³ããã¹ãã远å ããŠããŒã®äœ¿çšç¶æ³ããŒã¿ãæ¡å ãã
ããŒã®äœ¿çšç¶æ³ã«é¢ããããŒã¿ãåéããåŸãå¿ èŠã«å¿ããŠè¿œå ã®ããŒã¿ãœãŒã¹ã䜿çšããŠããŒã¿ãæ¡å ã§ããŸãããªãœãŒã¹ã®ã¬ããã³ã¹ã𿥿Žã远跡ããããã«äœ¿çšããŠããããŒã¿ãœãŒã¹ã远å ããããšãããããããŸããæ¢åã®ã¬ããã³ã¹ã«å¿ããŠã次ã®ãããªããŒã¿ã远å ã§ããŸãã
- æ§æç®¡çããŒã¿ããŒã¹ïŒCMDBïŒãŸãã¯åæ§ã®ã·ã¹ãã ããåéããæææš©æ å ±ã
- ãããžã§ã¯ã ã©ãã«ã§æ§æãããã¬ããã³ã¹æ å ±ïŒãããžã§ã¯ããæ åœããããŒã ãã³ã¹ãã»ã³ã¿ãŒãªã©ïŒã
- Google Cloudã®å€éšç°å¢ã®ã¯ãŒã¯ããŒãã«äœ¿çšãããããŒã«é¢ããç°å¢æ å ±ã
ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®äœ¿çšéãæžããããã®èšç»ãäœæãã
ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®äœ¿çšéãæžããããã«å€æŽããããã€ããåã«ã圱é¿ãåããã¯ãŒã¯ããŒããšç°å¢ããããã®å€æŽã®é©ç𿹿³ã決å®ããå¿ èŠããããŸãããŸãããã®èšç»ãããžãã¹å šäœã§å ±æããã¯ãŒã¯ããŒã ãªãŒããŒãèšç»ããµããŒãããããã«ããå¿ èŠããããŸãã
以äžã®ã»ã¯ã·ã§ã³ã§ã¯ãèšç»ã§å¯ŸåŠãã¹ãäž»ãªãããã¯ã«ã€ããŠèª¬æããŸããå ·äœçãªèšç»ã¯ãçµç¹ã®èŠæš¡ãã¯ãŒã¯ããŒãåºæã®èŠä»¶ã«ãã£ãŠç°ãªããŸãã
çŸåšã®ã¯ãŒã¯ããŒã ãªãŒããŒã®è²¬ä»»ã決å®ãã
äžå€®ã®ã»ãã¥ãªã㣠ããŒã ã¯ååšããããŒãè©äŸ¡ã§ããŸãããç§»è¡ãæåãããã«ã¯ã¯ãŒã¯ããŒã ãªãŒããŒã®ãµããŒããæ¬ ãããŸãããç§»è¡å¯Ÿè±¡ã®ããŒã®å Žåãã¯ãŒã¯ããŒã ãªãŒããŒã¯ãå©çšå¯èœãªèªèšŒæ¹æ³ã®äžãããŠãŒã¹ã±ãŒã¹ã«é©ãããã®ã倿ãããã®ç§»è¡ãå®è¡ããå¿ èŠããããŸãã
æ¢åã®ã»ãã¥ãªã㣠ãã¹ãã£ãŒã®æ¹åãšãã¯ãŒã¯ããŒã ãªãŒããŒã®åŽåãšã®ãã©ã³ã¹ãåãæ¹æ³ãæ€èšããå¿ èŠããããŸãã以äžã®ã»ã¯ã·ã§ã³ã§ã¯ã2 ã€ã®ãµã³ãã« ã¢ãããŒãã«ã€ããŠèª¬æããŸãã1 ã€ã¯ã»ãã¥ãªãã£å¯Ÿçã®æ¹åã«éç¹ã眮ãã¢ãããŒãã§ããã 1 ã€ã¯ã¯ãŒã¯ããŒã ãªãŒããŒã®åŽåãæå°éã«æããããšãåªå ããã¢ãããŒãã§ããå®éã®ã¢ãããŒãã¯ããããšã¯ç°ãªãå ŽåããããŸããããšãã°ã察象ãšãªãã¯ãŒã¯ããŒããåå¥ã«éžæããå ŽåããããŸãã
äŸ: çŸåšã®ãã¹ãŠã®ã¯ãŒã¯ããŒããç§»è¡å¯Ÿè±¡ãšããŠè©äŸ¡ããã
èããããã¢ãããŒãã®äžã€ã¯ãçŸåšãšå°æ¥ã®ãã¹ãŠã®ã¯ãŒã¯ããŒãã«ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®å¶åŸ¡ãé©çšããããšã§ãããã®å Žåãæ¬¡ã®ãããªã¹ããããèããããŸãã
- ã¯ãŒã¯ããŒã ãªãŒããŒãšååããŠãæ¢åã®ã¯ãŒã¯ããŒãã®ããŒã®äœ¿çšç¶æ³ãè©äŸ¡ããŸãã
- äŸå€ãèªããããŠããªãéããã¯ãŒã¯ããŒã ãªãŒããŒã¯ãããŒã䜿çšããæ¢åã®ã¯ãŒã¯ããŒãããã¹ãŠç§»è¡ããå¿ èŠããããŸãã
- äŸå€ãèªããããŠããªãéããä»åŸã®ãã¹ãŠã®ã¯ãŒã¯ããŒãã§ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒã䜿çšã§ããªãããã«ããå¿ èŠããããŸãã
ãã®ã¢ãããŒãã¯æ¢åã®ã»ãã¥ãªã㣠ãã¹ãã£ãŒã®æ¹åãåªå ããŠããŸãããçæçã«ã¯ããããããŒãšã¯ãŒã¯ããŒã ãªãŒããŒã®è² æ ãå¢å ããŸãããã®ãããªèšç»ãæåãããã«ã¯ãã¯ãŒã¯ããŒã ãªãŒããŒãã¯ãŒã¯ããŒãã®ã¬ãã¥ãŒãšãªãã¡ã¯ã¿ãªã³ã°ã«åå ããå¿ èŠããããŸãã
äŸ: çŸåšã®ã¯ãŒã¯ããŒãã¯ç§»è¡å¯Ÿè±¡ãšããŠè©äŸ¡ãããŠããªã
ãã 1 ã€ã®ã¢ãããŒãã¯ãæ¢åã®ã¯ãŒã¯ããŒãã§ã¯ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®ç¶ç¶äœ¿çšãèš±å¯ããä»åŸã®ã¯ãŒã¯ããŒãã«ã®ã¿æ°ããã³ã³ãããŒã«ãé©çšããæ¹æ³ã§ãã
ãã®ã¢ãããŒãã§ã¯ãå°æ¥ã®ã¯ãŒã¯ããŒãã®ã»ãã¥ãªã㣠ãã¹ãã£ãŒãåäžããçŸåšã®ã¯ãŒã¯ããŒã ãªãŒããŒã®è² æ ã¯æå°éã«æããããŸãããã ããæ¢åã®ã¯ãŒã¯ããŒãã®ã»ãã¥ãªã㣠ãã¹ãã£ãŒã¯åäžããŸããã
çæéã§åŸãããææãç¹å®ãã
è©äŸ¡ã§ã¯ãã¯ãŒã¯ããŒã ãªãŒããŒã«ãã远å ã®ä¿®åŸ©äœæ¥ãªãã§å®å šã«åé€ã§ããããŒãç¹å®ã§ããå ŽåããããŸããããšãã°ãããŒã 90 æ¥éã¢ã¯ãã£ãã§ãªãå Žåããã¢ã¯ãã£ãã§ãªããªã£ããªãœãŒã¹ã«ããŒãé¢é£ä»ããããŠããå Žåã¯ãå¥ã®èªèšŒã¡ã«ããºã ã«ç§»è¡ããªããŠããããŒãå®å šã«åé€ã§ããŸãã
ãã®æ¡ä»¶ãæºããããŒã®ãªã¹ããäœæããŸãããã®ãªã¹ãã¯ãããã〠ãã§ãŒãºã§äžèŠãªããŒãåé€ããããã«äœ¿çšããŸããããŒããªã¹ãã«è¿œå ããåã«ããµãŒãã¹ ã¢ã«ãŠã³ã ããŒã«äŸåããæ¬çªç°å¢ãžã®ç·æ¥ã®ã¢ã¯ã»ã¹ãªã©ããµãŒãã¹ ã¢ã«ãŠã³ã ããŒãé »ç¹ã«å¿ èŠãšããªããŠãŒã¹ã±ãŒã¹ããããã©ããã確èªããŸãã
çµç¹ã®ããªã·ãŒã®å€æŽãé©çšããå Žæãèšç»ãã
ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒããã®ç§»è¡ãæåãããã«ã¯ãæ°ããããŒãäœæãããªãããã«ããå¿
èŠããããŸããããã〠ãã§ãŒãºã§ãiam.disableServiceAccountKeyCreation
çµç¹ã®ããªã·ãŒã®å¶çŽãé©çšããæ°ãããµãŒãã¹ ã¢ã«ãŠã³ã ããŒãäœæãããªãããã«ããŸãã
ãã®å¶çŽã«ãã£ãŠæ¢åã®ããŒã®äœ¿çšã劚ããããããšã¯ãããŸããããããŒã宿çã«ããŒããŒã·ã§ã³ããæ¢åã®ã¯ãŒã¯ããŒããäžæãããå¯èœæ§ããããŸããäžæãæå°éã«æããããã«ãããã〠ãã§ãŒãºãéå§ããåã«ãªãœãŒã¹éå±€ã®ã©ãã«å¶çŽãé©çšãããæ±ºå®ããŸãã
æåã¯çµç¹ã¬ãã«ã§ã¯ãªãããããžã§ã¯ã ã¬ãã«ãŸãã¯ãã©ã«ãã¬ãã«ã§å¶çŽãé©çšããããšãã§ããŸããããšãã°ãæ¬çªç°å¢çšã®ãã©ã«ãã«ãããã€ããåã«ãéçºç°å¢ã«äœ¿çšãããã©ã«ãã«å¶çŽãé©çšããŸãããŸãã倿°ã®ããŒã ãååšããå€§èŠæš¡ãªçµç¹ã®å Žåã¯ãæåã« 1 ã€ã®ããŒã ã®ãã©ã«ãã«å¶çŽãé©çšããç§»è¡æã«è¿œå ã®ãã©ã«ãã«å¶çŽãé©çšããããšãã§ããŸãã
ã¿ã°ã䜿çšããçµç¹ã®ããªã·ãŒã䜿çšããŠããããžã§ã¯ã ã¬ãã«ãŸãã¯ãã©ã«ãã¬ãã«ã§çµç¹ããªã·ãŒãæ¡ä»¶ä»ãã§é©çšã§ããŸãã
äŸå€ããã»ã¹ãèšèšãã
ãã®ç§»è¡ã®ç®çã¯ããµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®äœ¿çšãåæžãŸãã¯æé€ããããšã§ããããµãŒãã¹ ã¢ã«ãŠã³ã ããŒãå¿ èŠãšããæ£åœãªãŠãŒã¹ã±ãŒã¹ããããŸããæ¢åã®ã¯ãŒã¯ããŒãã«ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒãå¿ èŠãªãå Žåã§ããå°æ¥ã®ã¯ãŒã¯ããŒãã§ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒãå¿ èŠã«ãªãå¯èœæ§ããããŸãããããã£ãŠããµãŒãã¹ ã¢ã«ãŠã³ã ããŒãå¿ èŠãšãããŠãŒã¹ã±ãŒã¹ãè©äŸ¡ããŠã®äŸå€ãšããŠæ¿èªããéçšããã»ã¹ãå®çŸ©ããŠããå¿ èŠããããŸãã
ã¯ãŒã¯ããŒã ãªãŒããŒãã¯ãŒã¯ããŒãã§ã®ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®äŸå€äœ¿çšããªã¯ãšã¹ãã§ããããã»ã¹ãå®çŸ©ããŸããäŸå€ãæ åœããæææ±ºå®è ã«ã¯ããŠãŒã¹ã±ãŒã¹ãæ€èšŒããããã®æè¡çãªç¥èãå¿ èŠã§ãããµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®ä»£ãããšãªãå®å šãªæ¹æ³ãã¯ãŒã¯ããŒãã®ãªãŒããŒãšæ€èšã§ããç¥èãå¿ èŠã§ãããŸãããµãŒãã¹ ã¢ã«ãŠã³ã ããŒã管çããããã®ãã¹ã ãã©ã¯ãã£ã¹ã«ã€ããŠã¯ãŒã¯ããŒã ãªãŒããŒã«ã¢ããã€ã¹ã§ããèœåãæ±ããããŸãã
ä»åŸã®å€æŽãã¯ãŒã¯ããŒã ãªãŒããŒã«äŒãã
èšç»ãçå®ãããããã®èšç»ãçµç¹å šäœã«æç¢ºã«æªéå¿ãé¢ä¿è ïŒç¹ã«äžçŽå¹¹éšïŒãç§»è¡ã«ç©æ¥µçã«é¢äžã§ããããã«ããå¿ èŠããããŸãã
å ·äœçãªç§»è¡ã®è©³çްã¯çµç¹ã«ãã£ãŠç°ãªããŸãããã³ãã¥ãã±ãŒã·ã§ã³èšç»ã«æ¬¡ã®ãããã¯ãå«ããããšãæ€èšããŠãã ããã
- å®å šã§ãªããµãŒãã¹ ã¢ã«ãŠã³ã ããŒãçµç¹ã«ããããæªåœ±é¿ãšããµãŒãã¹ ã¢ã«ãŠã³ã ããŒããç§»è¡ããç®çã
- ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®äœæãé²ãæ°ããã»ãã¥ãªã㣠ã³ã³ãããŒã«ãšãæ¢åã®ããã»ã¹ãžã®åœ±é¿ã
- ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒã«ä»£ããããå®å šãªæ¹æ³ãç¹å®ããããã®ããããããŒåãã®ã¬ã€ãã³ã¹ã
- ããŒã ããµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®äŸå€äœ¿çšããªã¯ãšã¹ãããããã»ã¹ïŒãã®äŸå€ãåè©äŸ¡ãããé »åºŠãå«ãïŒã
- ææ¡ããã倿Žãé©çšããã¿ã€ã ã©ã€ã³ã
ã¯ãŒã¯ããŒã ãªãŒããŒãšååããŠèšç»ãç·Žããçµç¹å šäœã§æ©èœããããã«ããŸãã
ã³ã³ãããŒã«ã®ãããã€ãšã¯ãŒã¯ããŒãã®ãªãã¡ã¯ã¿ãªã³ã°
èšç»ãäœæããŠã¯ãŒã¯ããŒã ãªãŒããŒã«äŒãããããµãŒãã¹ ã¢ã«ãŠã³ã ããŒããã®ç§»è¡ãéå§ã§ããŸãã
ãã®ãã§ãŒãºã§ã¯ããµãŒãã¹ ã¢ã«ãŠã³ã ããŒã«ä»£ããããå®å šãªæ¹æ³ã§èªèšŒãè¡ãããã«ãã¯ãŒã¯ããŒãããªãã¡ã¯ã¿ãªã³ã°ããŸãããŸããç°å¢ãç¶ç¶çã«ã¢ãã¿ãªã³ã°ããŠãå°æ¥ã®ãªã¹ã¯ã軜æžããè¿œå æ©èœãæ§ç¯ããŸãã
以éã®ã»ã¯ã·ã§ã³ã§ã¯ãäžæãæå°éã«æããªããã¯ãŒã¯ããŒãããªãã¡ã¯ã¿ãªã³ã°ããããŒãåé€ããã¹ãããã«ã€ããŠèª¬æããŸãããããã®ã¹ãããã¯ãçµç¹ã«å¿ èŠãªåªå 床ãšäœæ¥éã«åºã¥ããŠãä»»æã®é åºã§è¡ãããšãã§ããŸãã
æ°ãããµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®äœæã忢ããå¶åŸ¡ãé©çšãã
æ°ãããµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®äœæã忢ããã«ã¯ãiam.disableServiceAccountKeyCreation
çµç¹ã®ããªã·ãŒã®å¶çŽãé©çšããŸãã
ãã ãããã®å¶çŽãé©çšããåã«ãããªã·ãŒããé€å€ãããããžã§ã¯ããŸãã¯ãã©ã«ãã«ã¿ã°ã远å ããå¿ èŠããããŸãããµãŒãã¹ ã¢ã«ãŠã³ã ããŒããç§»è¡ã§ããªãæ¢åã®ã¯ãŒã¯ããŒããããµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®ã¿ã§èªèšŒãè¡ãæ£åœãªçç±ãããæ°ããã¯ãŒã¯ããŒãã«ã€ããŠã¯ãäŸå€ãèš±å¯ã§ããŸãã
é€å€å¯Ÿè±¡ã®ãããžã§ã¯ããšãã©ã«ãã«ã¿ã°ã远å ããããã¿ã°ã䜿çšããçµç¹ã®ããªã·ãŒãèšå®ããŠãé€å€å¯Ÿè±¡å€ã®ãããžã§ã¯ããšãã©ã«ãã« iam.disableServiceAccountKeyCreation
å¶çŽãé©çšã§ããŸãã
é©çšå¯Ÿè±¡å€ã®ãã¹ãŠã®ãããžã§ã¯ããšãã©ã«ãã§ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒãäœæãããªãããã«ããã«ã¯ãæ¬¡ã®æäœãè¡ããŸãã
-
çµç¹ã¬ãã«ã§ã¿ã°ç®¡çè
ããŒã«ïŒ
roles/resourcemanager.tagAdmin
ïŒãšçµç¹ããªã·ãŒç®¡çè ããŒã«ïŒroles/orgpolicy.policyAdmin
ïŒãããããšã確èªããŸããçµç¹ã¬ãã«ã§ããŒã«ãä»äžããæ¹æ³ã«ã€ããŠã¯ããããžã§ã¯ãããã©ã«ããçµç¹ãžã®ã¢ã¯ã»ã¹æš©ã®ç®¡çãã芧ãã ããã -
çµç¹ã¬ãã«ã§ããªãœãŒã¹ãçµç¹ã®ããªã·ãŒããé€å€ãããã©ãããå®çŸ©ããããã«ãã¿ã°ããŒãšã¿ã°å€ãäœæããŸããããŒ
disableServiceAccountKeyCreation
ãšå€enforced
ãnot_enforced
ã䜿çšããŠã¿ã°ãäœæããããšãããããããŸããã¿ã°ããŒãšã¿ã°å€ã®äœææ¹æ³ã«ã€ããŠã¯ãæ°ããã¿ã°ã®äœæãšå®çŸ©ãã芧ãã ããã
-
disableServiceAccountKeyCreation
ã¿ã°ãçµç¹ã«é©çšãããã®å€ãenforced
ã«èšå®ããŸããçµç¹å ã®ãã¹ãŠã®ãªãœãŒã¹ã¯ãå¥ã®ã¿ã°å€ã§äžæžããããªãéãããã®ã¿ã°å€ãç¶æ¿ããŸãããªãœãŒã¹ã«ã¿ã°ãé©çšããæ¹æ³ã«ã€ããŠã¯ããªãœãŒã¹ãžã®ã¿ã°ã®é©çšãã芧ãã ããã
-
çµç¹ã®ããªã·ãŒããé€å€ãããããžã§ã¯ããŸãã¯ãã©ã«ãããšã«
disableServiceAccountKeyCreation
ã¿ã°ãä»ããŠããã®å€ãnot_enforced
ã«èšå®ããŸãããã®æ¹æ³ã§ãããžã§ã¯ããŸãã¯ãã©ã«ãã«ã¿ã°å€ãèšå®ãããšãçµç¹ããç¶æ¿ãããã¿ã°å€ããªãŒããŒã©ã€ããããŸãã -
é€å€ãªãœãŒã¹ãé€ããã¹ãŠã®ãªãœãŒã¹ã®ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒãäœæã§ããªãããã«ããçµç¹ã®ããªã·ãŒãäœæããŸãããã®ããªã·ãŒã«ã¯ã次ã®ã«ãŒã«ãå¿ èŠã§ãã
-
disableServiceAccountKeyCreation: not_enforced
ã¿ã°ã®ä»ãããªãœãŒã¹ã«é©çšãããªãããã«iam.disableServiceAccountKeyCreation
å¶çŽãæ§æããŸãããã®ã«ãŒã«ã®æ¡ä»¶ã¯æ¬¡ã®ããã«ãªããŸãã"resource.matchTag('ORGANIZATION_ID/disableServiceAccountKeyCreation', 'not_enforced')"
-
ä»ã®ãã¹ãŠã®ãªãœãŒã¹ã«é©çšãããããã«
iam.disableServiceAccountKeyCreation
å¶çŽãæ§æããŸãã
-
æ¢åã®ã¯ãŒã¯ããŒããä¿®æ£ãã
ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒã䜿çšããã¯ãŒã¯ããŒãããšã«ãã¯ãŒã¯ããŒãã®ãªãŒããŒãšååããŠãå¥ã®èªèšŒæ¹æ³ãéžæããŠå®è£ ããŸãã
Google Cloud CLIãCloud ã¯ã©ã€ã¢ã³ã ã©ã€ãã©ãªãTerraform ãªã©ãã¢ããªã±ãŒã·ã§ã³ã®ããã©ã«ãèªèšŒæ å ±ïŒADCïŒããµããŒãããããŒã«ãŸã㯠REST ãªã¯ãšã¹ããä»ã㊠Google Cloud ãµãŒãã¹ã«ã¢ã¯ã»ã¹ããå Žåã¯ã次ã®å³ãåèã«ããŠèªèšŒæ¹æ³ãéžæããŠãã ããã
ãã®å³ã«ã¯ã次ã®è³ªåãèšèŒãããŠããŸãã
-
ã·ã³ã°ã« ãŠãŒã¶ãŒéçºç°å¢ïŒç¬èªã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ãCloud Shellãä»®æ³ãã¹ã¯ããã ã€ã³ã¿ãŒãã§ãŒã¹ãªã©ïŒã§ã³ãŒããå®è¡ããŠããŸããïŒ
- ãã¯ããã®å Žåã¯ã質å 4 ã«é²ã¿ãŸãã
- ãããããã®å Žåã¯ã質å 2 ã«é²ã¿ãŸãã
- Google Cloudã§ã³ãŒããå®è¡ããŠããŸããïŒ
- ãã¯ããã®å Žåã¯ã質å 3 ã«é²ã¿ãŸãã
- ãããããã®å Žåã¯ã質å 5 ã«é²ã¿ãŸãã
- Google Kubernetes Engine ã§ã³ã³ãããå®è¡ããŠããŸããïŒ
- ãã¯ããã®å Žåã¯ãWorkload Identity Federation for GKE ã䜿çšããŠããµãŒãã¹ ã¢ã«ãŠã³ãã Kubernetes Pod ã«æ¥ç¶ããŸãã
- ããã§ãªãå Žåã¯ããªãœãŒã¹ã«ãµãŒãã¹ ã¢ã«ãŠã³ããæ¥ç¶ããŸãã
-
ãŠãŒã¹ã±ãŒã¹ã«ãµãŒãã¹ ã¢ã«ãŠã³ããå¿ èŠã§ããïŒ
ããšãã°ããã¹ãŠã®ç°å¢ã§ã¢ããªã±ãŒã·ã§ã³ã®èªèšŒãšèªå¯ãäžè²«ããŠæ§æããããšããŸãã
- ãããããã®å Žåã¯ããŠãŒã¶ãŒèªèšŒæ å ±ã§èªèšŒãè¡ããŸãã
- ãã¯ããã®å Žåã¯ããŠãŒã¶ãŒèªèšŒæ å ±ã䜿çšããŠãµãŒãã¹ ã¢ã«ãŠã³ãã®æš©éãåçšããŸãã
-
ã¯ãŒã¯ããŒã㯠Workload Identity 飿ºããµããŒãããå€éš ID ãããã€ãã§èªèšŒãããŸããïŒ
- ãã¯ããã®å Žåã¯ãWorkload Identity 飿ºãæ§æããŠããªã³ãã¬ãã¹ãä»ã®ã¯ã©ãŠã ãããã€ãã§å®è¡ãããŠããã¢ããªã±ãŒã·ã§ã³ããµãŒãã¹ ã¢ã«ãŠã³ãã䜿çšã§ããããã«ããŸãã
- ãããããã®å Žåã¯ããµãŒãã¹ ã¢ã«ãŠã³ã ããŒãäœæããŸãã
å Žåã«ãã£ãŠã¯ããµãŒãã¹ ã¢ã«ãŠã³ã ããŒä»¥å€ã®èªèšŒæ¹æ³ã䜿çšã§ããªãããšããããŸãããµãŒãã¹ ã¢ã«ãŠã³ã ããŒä»¥å€ã¯äœ¿çšã§ããªãäŸãšããŠã¯ã次ã®ãããªå ŽåããããŸãã
- åžè²©ã®è£œåïŒCOTSïŒãŸã㯠Software as a ServiceïŒSaaSïŒã¢ããªã±ãŒã·ã§ã³ã䜿çšããŠãGoogle Cloud ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒããŠãŒã¶ãŒ ã€ã³ã¿ãŒãã§ãŒã¹ã«çŽæ¥å ¥åããŠããã
- ã¯ãŒã¯ããŒãã Google Cloud ã®å€éšã§å®è¡ãããŠãããWorkload Identity 飿ºããµããŒãã§ãã ID ãããã€ãã§èªèšŒãããŠããªãã
ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒãåŒãç¶ã䜿çšããå¿ èŠãããå Žåã¯ããµãŒãã¹ ã¢ã«ãŠã³ã ããŒã管çããããã®ãã¹ã ãã©ã¯ãã£ã¹ã«åŸããŸãã
ãŸãããµãŒãã¹ ã¢ã«ãŠã³ã ããŒãç¶ç¶ããŠäœ¿çšãããªã¹ã¯ãšå¥ã®èªèšŒæ¹æ³ã«åãæ¿ããã³ã¹ããæ€èšããçµæãç¹å®ã®ã¯ãŒã¯ããŒããä¿®æ£ããªãããšã«ããå ŽåããããŸãã
äžèŠãªããŒãåé€ãã
ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒãäžèŠã§ããããšã確å®ãªå Žåã¯ãããŒãåé€ããå¿ èŠããããŸããäžèŠãªããŒãšããŠã¯ã次ã®ãã®ããããŸãã
æè¿äœ¿çšãããŠããªãããŒããŸãã¯æªäœ¿çšã®ãªãœãŒã¹ã«é¢é£ä»ããããŠããããŒïŒãã®ããŒãžã®çæéã§åŸãããææãç¹å®ãããåç §ïŒã
ä»ã®èªèšŒæ¹æ³ã«ç§»è¡ããã¯ãŒã¯ããŒãã®ããŒã
ãããžã§ã¯ãå ã®ãã¹ãŠã®ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒãåé€ãããããã®ãããžã§ã¯ãã«
iam.disableServiceAccountKeyCreation
å¶çŽãé©çšãããŠããããšã確èªããŸãããããžã§ã¯ãããã®å¶çŽããé€å€ãããŠããå Žåã¯ãé€å€ãèš±å¯ããã¿ã°ãåé€ããŸãã
ããŒãå®å šã«åé€ããã«ã¯ãåé€ããåã«ããŒãç¡å¹ã«ããããšãããããããŸããåé€ãããšå ã«æ»ããŸããããç¡å¹ã«ãããšãäºæããªãåé¡ãèŠã€ãã£ãå Žåã«ããŒããã°ããæå¹ã«ããããšãã§ããŸããããŒãç¡å¹ã«ããåŸãããŒãå®å šã«åé€ããŠãåé¡ããªãããšã確èªããŠãããããŒãåé€ããŸããããŒãç¡å¹ã«ããåŸã«äºæããªãåé¡ãèŠã€ãã£ãå Žåã¯ãããŒãå床æå¹ã«ããŠåé¡ã解決ããŸããããŒãå®å šã«åé€ã§ããããã«ãªããŸã§ããã®ããã»ã¹ãç¹°ãè¿ããŸãã
çµã¿èŸŒã¿ã®ã³ã³ãããŒã«ã䜿çšããŠããŒã®æŒæŽ©ã«å¯ŸåŠãã
Google Cloud ã«ã¯ãæŒæŽ©ãããµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®æ€åºãšå¯Ÿå¿ã«åœ¹ç«ã€ããŒã«ãšãµãŒãã¹ãçšæãããŠããŸããæŒæŽ©ãããµãŒãã¹ ã¢ã«ãŠã³ã ããŒã«å¯Ÿå¿ããããã«ã次ã®ã¡ã«ããºã ã®äœ¿çšãæ€èšããŠãã ããã
- ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®æŒæŽ©å¯Ÿå¿ã®å¶çŽã«ããã Google Cloud ãæ€åºããå ¬ééµãèªåçã«ç¡å¹ã«ã§ããŸãã
ãµãŒãã¹ ã¢ã«ãŠã³ã管çã®ç¶ç¶çãªæ¹å
å¯èœãªéãããµãŒãã¹ ã¢ã«ãŠã³ã ããŒã管çããããã®ãã¹ã ãã©ã¯ãã£ã¹ãå®è£ ããŠãã ãããããŒç®¡çããã»ã¹ãæ¹åããããšã§ãçµç¹ã«æ®ã£ãŠãããµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®ãªã¹ã¯ã軜æžã§ããŸãã
次ã®ã¹ããã
- ãµãŒãã¹ ã¢ã«ãŠã³ãã®äœ¿çšã«é¢ãããã¹ã ãã©ã¯ãã£ã¹
- ãµãŒãã¹ ã¢ã«ãŠã³ã ããŒã管çããããã®ãã¹ã ãã©ã¯ãã£ã¹
- å ±åã€ã³ã·ãã³ã管çããã»ã¹ãæ§ç¯ãã