Policy Analyzer ã§ã¯ãIAM èš±å¯ããªã·ãŒã«åºã¥ããŠãã©ã®ããªã³ã·ãã«ïŒäŸ: ãŠãŒã¶ãŒããµãŒãã¹ ã¢ã«ãŠã³ããã°ã«ãŒãããã¡ã€ã³ïŒãã©ã® Google Cloud ãªãœãŒã¹ã«å¯ŸããŠã©ã®ãããªã¢ã¯ã»ã¹æš©ãä»äžãããŠãããã調ã¹ãããšãã§ããŸãã
èš±å¯ããªã·ãŒã® Policy Analyzer ã¯ã次ã®ãããªè³ªåã«åçããã®ã«åœ¹ç«ã¡ãŸãã
- ãã® IAM ãµãŒãã¹ ã¢ã«ãŠã³ããžã®ã¢ã¯ã»ã¹æš©ãä»äžãããŠããã®ã¯ã©ã®ãŠãŒã¶ãŒãã
- å人ãç¹å®ã§ããæ å ±ïŒPIIïŒãå«ãŸãããã® BigQuery ããŒã¿ã»ããã®ããŒã¿ãèªã¿åãããšãã§ããã®ã¯ã©ã®ãŠãŒã¶ãŒãã
dev-testers
ã°ã«ãŒãã«ã¯ããã®ãããžã§ã¯ãã®ãªãœãŒã¹ã«å¯Ÿããã©ã®ãããªããŒã«ãšæš©éãä»äžãããŠãããã- ãããžã§ã¯ã A ã§ Tal ãåé€ã§ããã®ã¯ã©ã® Compute Engine ä»®æ³ãã·ã³ïŒVMïŒã€ã³ã¹ã¿ã³ã¹ãã
- ååŸ 7 æã«ãã® Cloud Storage ãã±ããã«ã¢ã¯ã»ã¹ã§ããã®ã¯ã©ã®ãŠãŒã¶ãŒãã
èš±å¯ããªã·ãŒçšã® Policy Analyzer ã®ä»çµã¿
èš±å¯ããªã·ãŒã« Policy Analyzer ã䜿çšããã«ã¯ãåæã¯ãšãªãäœæããåæã®ã¹ã³ãŒããæå®ããŠãã¯ãšãªãå®è¡ããŸãã
åæã¯ãšãª
Policy Analyzer ã䜿çšããã«ã¯ã次㮠1 ã€ä»¥äžã®ãã£ãŒã«ããæå®ããåæã¯ãšãªãäœæããŸãã
- ããªã³ã·ãã«: ã¢ã¯ã»ã¹æš©ã確èªãã察象㮠IDïŒãŠãŒã¶ãŒããµãŒãã¹ ã¢ã«ãŠã³ããã°ã«ãŒãããã¡ã€ã³ãªã©ïŒ
- ã¢ã¯ã»ã¹æš©: 確èªããæš©éãšããŒã«
- ãªãœãŒã¹: ã¢ã¯ã»ã¹æš©ã確èªãã察象ãªãœãŒã¹
- ïŒAPI ã®ã¿ïŒæ¡ä»¶ã®ã³ã³ããã¹ã: ã¢ã¯ã»ã¹ã確èªããéã®ã³ã³ããã¹ãïŒæå»ãªã©ïŒ
éåžžãåæã¯ãšãªã§ãããã®ãã£ãŒã«ãã 1 ã€ãŸã㯠2 ã€æå®ããã¯ãšãªçµæã䜿çšããŠãæå®ããªãã£ããã£ãŒã«ãã«é¢ãã詳现æ å ±ãååŸããŸããããšãã°ãç¹å®ã®ãªãœãŒã¹ã«å¯Ÿããç¹å®ã®æš©éãä»äžãããŠãããŠãŒã¶ãŒãææ¡ããå Žåã¯ãåæã¯ãšãªã§ã¢ã¯ã»ã¹æš©ãšãªãœãŒã¹ãæå®ããŸãããããªã³ã·ãã«ã¯æå®ããŸããã
äœæã§ããã¯ãšãªã®çš®é¡ã«é¢ãããã®ä»ã®äŸã«ã€ããŠã¯ãäžè¬çãªã¯ãšãªã®çš®é¡ãã芧ãã ããã
åæå¯Ÿè±¡ç¯å²
åæã¯ãšãªãå®è¡ããã«ã¯ãåæããã¹ã³ãŒããæå®ããå¿ èŠããããŸããã¹ã³ãŒãã¯ãå¶éããåæã宿œãã察象ã®çµç¹ããã©ã«ãããŸãã¯ãããžã§ã¯ãã§ããã¹ã³ãŒããšããŠäœ¿çšãããŠãããªãœãŒã¹ãšãã®åå«ã«ã¢ã¿ãããããŠãã IAM èš±å¯ããªã·ãŒã®ã¿ãåæãããŸãã
REST API ãš gcloud CLI ã§ã¯ãã¹ã³ãŒããæåã§æå®ããŸããGoogle Cloud ã³ã³ãœãŒã«ã§ã¯ãã¹ã³ãŒãã¯ãçŸåšç®¡çããŠãããããžã§ã¯ãããã©ã«ãããŸãã¯çµç¹ã«åºã¥ããŠèªåçã«æ±ºå®ãããŸãã
åæã¯ãšãªãäœæããŠã¹ã³ãŒããæå®ããããã¯ãšãªãå®è¡ããŠå¯Ÿè±¡ã¹ã³ãŒãå ã®ããªã·ãŒãåæã§ããŸãã
ã¯ãšãªçµæ
åæã¯ãšãªãå®è¡ãããšãã¯ãšãªã«æå®ããããªã³ã·ãã«ãã¢ã¯ã»ã¹ããªãœãŒã¹ãå«ãããŒã« ãã€ã³ãã£ã³ã°ã Policy Analyzer ã«ãã£ãŠå ±åãããŸããããŒã« ãã€ã³ãã£ã³ã°ããšã«ããã€ã³ãã£ã³ã°ã®ããªã³ã·ãã«ããã€ã³ãã£ã³ã°ãä»äžããã¢ã¯ã»ã¹æš©ïŒããŒã«ãšæš©éïŒããã€ã³ãã£ã³ã°ãã¢ã¯ã»ã¹æš©ãä»äžãããªãœãŒã¹ãå ±åãããŸãã
ãããã®çµæã確èªãããšããããžã§ã¯ãããã©ã«ããçµç¹å ã®ã¢ã¯ã»ã¹æš©ãè©³çŽ°ã«ææ¡ã§ããŸããããšãã°ãç¹å®ã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããããªã³ã·ãã«ã確èªããããã«ã¯ãšãªãå®è¡ããå Žåã¯ãã¯ãšãªçµæã§ããªã³ã·ãã«ã確èªããŸãã
ã¯ãšãªçµæã®æ å ±ã調æŽããã«ã¯ãã¯ãšãª ãªãã·ã§ã³ãæå¹ã«ããŸãã
ãµããŒããããŠããããªã·ãŒã¿ã€ã
èš±å¯ããªã·ãŒçšã® Policy Analyzer ã¯ãIAM èš±å¯ããªã·ãŒã®ã¿ããµããŒãããŸãã
èš±å¯ããªã·ãŒã® Policy Analyzer ã¯ã次ã®åœ¢åŒã®ã¢ã¯ã»ã¹å¶åŸ¡ããµããŒãããŠããŸããã
- IAM æåŠããªã·ãŒ
- IAM ããªã³ã·ãã« ã¢ã¯ã»ã¹å¢çããªã·ãŒ
- Google Kubernetes Engine ã®ããŒã«ããŒã¹ ã¢ã¯ã»ã¹å¶åŸ¡
- Cloud Storage ã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ã
- Cloud Storage å ¬éã¢ã¯ã»ã¹ã®é²æ¢
Policy Analyzer ã®ã¯ãšãªçµæã«ã¯ããµããŒããããŠããªãããªã·ãŒã¿ã€ãã¯å«ãŸããŸãããããšãã°ãèš±å¯ããªã·ãŒã«ãããŠãŒã¶ãŒã«ãããžã§ã¯ãã«å¯Ÿãã iam.roles.get
æš©éãä»äžãããŠãããã®ã®ãæåŠããªã·ãŒã«ãããã®æš©éã䜿çšã§ããªãå Žåãªã©ã§ããPolicy Analyzer ã¯ãæåŠããªã·ãŒã«ãããããããiam.roles.get
æš©éãããããšãå ±åããŸãã
ããªã·ãŒã®ç¶æ¿
ããªã·ãŒã®ç¶æ¿ãèæ ®ãããããPolicy Analyzer ã¯ããªãœãŒã¹éå±€ã®ã©ãã«ãããã«ããããããæå®ãããã¹ã³ãŒãå ã®ãã¹ãŠã®èš±å¯ããªã·ãŒãèªåçã«åæããŸãã
ããšãã°ãIAM ãµãŒãã¹ ã¢ã«ãŠã³ãã«ã¢ã¯ã»ã¹ã§ãããŠãŒã¶ãŒã確èªããããšããŠãããšããŸãã
- ã¯ãšãªã®ã¹ã³ãŒãããããžã§ã¯ãã«èšå®ãããšãPolicy Analyzer ã¯ãµãŒãã¹ ã¢ã«ãŠã³ãã®èš±å¯ããªã·ãŒãšãããžã§ã¯ãã®èš±å¯ããªã·ãŒãåæããŸãã
- ã¯ãšãªã®ã¹ã³ãŒããçµç¹ã«èšå®ãããšãPolicy Analyzer ã¯ãµãŒãã¹ ã¢ã«ãŠã³ãã®èš±å¯ããªã·ãŒããµãŒãã¹ ã¢ã«ãŠã³ããææãããããžã§ã¯ãã®èš±å¯ããªã·ãŒããããžã§ã¯ããå«ããã©ã«ãã®èš±å¯ããªã·ãŒãçµç¹ã®èš±å¯ããªã·ãŒãåæããŸãã
æ¡ä»¶ä»ãã¢ã¯ã»ã¹
ããŒã« ãã€ã³ãã£ã³ã°ã«æ¡ä»¶ãååšããå Žåã¯ãæ¡ä»¶ãæºããããå Žåã«ã®ã¿ããªã³ã·ãã«ã«ã¢ã¯ã»ã¹æš©ãä»äžãããŸããPolicy Analyzer ã¯ãé¢é£ããããŒã« ãã€ã³ãã£ã³ã°ã«é©çšãããŠããæ¡ä»¶ãåžžã«å ±åããŸããé¢é£ããããŒã« ãã€ã³ãã£ã³ã°ã¯ãåæã¯ãšãªã§æå®ããããªã³ã·ãã«ãã¢ã¯ã»ã¹æš©ããªãœãŒã¹ãå«ãããŒã« ãã€ã³ãã£ã³ã°ã§ãã
å Žåã«ãã£ãŠã¯ãPolicy Analyzer ã«ãã£ãŠæ¡ä»¶ãåæã§ããå¯èœæ§ããããŸããã€ãŸããæ¡ä»¶ãæºããããŠãããã©ãããå ±åã§ããŸããPolicy Analyzer ã¯ã次ã®ã¿ã€ãã®æ¡ä»¶ãåæã§ããŸãã
- ãªãœãŒã¹å±æ§ã«åºã¥ãæ¡ä»¶ããªãœãŒã¹åãæå®ãããªãœãŒã¹ã¿ã€ãåãã
- æ¥ææ¡ä»¶ïŒAPI ãš gcloud CLI ã®ã¿ïŒãPolicy Analyzer ããããã®æ¡ä»¶ãåæããã«ã¯ãåæã¯ãšãªã§ã¢ã¯ã»ã¹æå»ïŒ
accessTime
ïŒãæå®ããå¿ èŠããããŸãããã®ã³ã³ããã¹ããæå®ããæ¹æ³ã«ã€ããŠã¯ãç¹å®ã®æå»ã«ãããã¢ã¯ã»ã¹æš©ãç¹å®ãããã芧ãã ããã
é¢é£ããããŒã« ãã€ã³ãã£ã³ã°ã«æ¡ä»¶ãå«ãŸããŠããå ŽåãPolicy Analyzer ã¯æ¬¡ã®ãããããè¡ããŸãã
Policy Analyzer ãæ¡ä»¶ãåæã§ããå Žåã¯ã次ã®ãããããè¡ããŸãã
- æ¡ä»¶ã true ãšè©äŸ¡ãããå ŽåãPolicy Analyzer ã¯ã¯ãšãªçµæã«ããŒã« ãã€ã³ãã£ã³ã°ãå«ããæ¡ä»¶è©äŸ¡ã
TRUE
ãšããŠããŒã¯ããŸãã - æ¡ä»¶ã false ãšè©äŸ¡ãããå ŽåãPolicy Analyzer ã¯ã¯ãšãªçµæã«ããŒã«ãå«ãŸãããã«ããŸããã
- æ¡ä»¶ã true ãšè©äŸ¡ãããå ŽåãPolicy Analyzer ã¯ã¯ãšãªçµæã«ããŒã« ãã€ã³ãã£ã³ã°ãå«ããæ¡ä»¶è©äŸ¡ã
Policy Analyzer ãé¢é£ããããŒã« ãã€ã³ãã£ã³ã°ã®æ¡ä»¶ãåæããããšãã§ããªãå Žåã¯ãã¯ãšãªçµæã«ããŒã«ãå«ãŸããæ¡ä»¶è©äŸ¡ã
CONDITIONAL
ãšããŠããŒã¯ãããŸãã
ããŒã¿ã®æŽæ°é »åºŠ
Policy Analyzer ã¯ããã¹ããšãã©ãŒãåã®ããŒã¿ã®æŽæ°é床ãæäŸãã Cloud Asset API ã䜿çšããŸããããªã·ãŒæŽæ°ã®ã»ãšãã©ãæ°åã§ Policy Analyzer ã«è¡šç€ºãããŸãããPolicy Analyzer ã«ã¯ææ°ã®ããªã·ãŒæŽæ°ãå«ãŸããªãå¯èœæ§ããããŸãã
äžè¬çãªã¯ãšãªã®çš®é¡
ãã®ã»ã¯ã·ã§ã³ã§ã¯ãåæã¯ãšãªã䜿çšããŠã¢ã¯ã»ã¹ã«é¢ããäžè¬çãªè³ªåã«åçããæ¹æ³ã«ã€ããŠèª¬æããŸãã
ãã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããããªã³ã·ãã«ã¯ã©ãã
ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããããªã³ã·ãã«ãç¹å®ããã«ã¯ããªãœãŒã¹ãæå®ããåæã¯ãšãªãäœæããå¿ èŠã«å¿ããŠç¢ºèªããããŒã«ãšæš©éãæå®ããŸãã
ãããã®è³ªåã¯ã次ã®ãããªçåãžã®çããèŠã€ããéã«æŽ»çšã§ããŸãã
- ãã® IAM ãµãŒãã¹ ã¢ã«ãŠã³ããžã®ã¢ã¯ã»ã¹æš©ãä»äžãããŠãããŠãŒã¶ãŒã¯èª°ãïŒ
- ãã® IAM ãµãŒãã¹ ã¢ã«ãŠã³ãã«ãªãããŸãããã®æš©éãä»äžãããŠãããŠãŒã¶ãŒã¯èª°ãïŒ
- ãããžã§ã¯ã A ã®èª²é管çè ã¯èª°ãïŒ
- ïŒAPI ãš gcloud CLI ã®ã¿ïŒ: ãµãŒãã¹ ã¢ã«ãŠã³ãã«ãªãããŸããŠãããžã§ã¯ã A ãæŽæ°ã§ãããŠãŒã¶ãŒã¯èª°ãïŒ
ãããã®ã¯ãšãªãäœæããŠéä¿¡ããæ¹æ³ã«ã€ããŠã¯ããªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããããªã³ã·ãã«ãç¹å®ãããã芧ãã ããã
ãããã®ããŒã«ãšæš©éãä»äžãããŠããããªã³ã·ãã«
ç¹å®ã®ããŒã«ãšæš©éãä»äžãããŠããããªã³ã·ãã«ãç¹å®ããã«ã¯ãããªã³ã·ãã«ãšç¢ºèªããäžé£ã®ããŒã«ãšæš©éãæå®ããåæã¯ãšãªãäœæããŸãã
ãããã®è³ªåã¯ã次ã®ãããªçåãžã®çããèŠã€ããéã«æŽ»çšã§ããŸãã
- çµç¹å ã§ãµãŒãã¹ ã¢ã«ãŠã³ãã«ãªãããŸãããã®æš©éãä»äžãããŠããã®ã¯ã©ã®ãŠãŒã¶ãŒãïŒ
- çµç¹ã®èª²é管çè ã¯ã©ã®ãŠãŒã¶ãŒãïŒ
- å人ãç¹å®ã§ããæ å ±ïŒPIIïŒãå«ãŸãããã® BigQuery ããŒã¿ã»ããã®ããŒã¿ãèªã¿åãããšãã§ããã®ã¯ã©ã®ãŠãŒã¶ãŒãã
- ïŒAPI ãš gcloud CLI ã®ã¿ïŒ: ãµãŒãã¹ ã¢ã«ãŠã³ãã«ãªãããŸã㊠BigQuery ããŒã¿ã»ãããèªã¿åãããšãã§ããçµç¹å ã®ãŠãŒã¶ãŒã¯èª°ãïŒ
ãããã®ã¯ãšãªãäœæããŠéä¿¡ããæ¹æ³ã«ã€ããŠã¯ãç¹å®ã®ããŒã«ãŸãã¯æš©éãæã€ããªã³ã·ãã«ãç¹å®ãããã芧ãã ããã
ãã®ãªãœãŒã¹ã«å¯ŸããŠãã®ããªã³ã·ãã«ã«ä»äžãããŠããããŒã«ãšæš©é
ç¹å®ã®ãªãœãŒã¹ã«å¯ŸããŠããªã³ã·ãã«ã«ä»äžãããŠããããŒã«ãšæš©éãç¹å®ããã«ã¯ãããªã³ã·ãã«ãšæš©éã確èªãã察象ã®ãªãœãŒã¹ãæå®ããåæã¯ãšãªãäœæããŸãã
ãããã®è³ªåã¯ã次ã®ãããªçåãžã®çããèŠã€ããéã«æŽ»çšã§ããŸãã
- ãã® BigQuery ããŒã¿ã»ããã«å¯ŸããŠãŠãŒã¶ãŒ Sasha ã¯ã©ã®ããŒã«ãšæš©éãä»äžãããŠãããã
dev-testers
ã°ã«ãŒãã«ã¯ããã®ãããžã§ã¯ãã®ãªãœãŒã¹ã«å¯ŸããŠã©ã®ãããªããŒã«ãšæš©éãä»äžãããŠãããã- ïŒAPI ãš gcloud CLI ã®ã¿ïŒ: Dana ããµãŒãã¹ ã¢ã«ãŠã³ãã«ãªãããŸããå Žåã«ããã® BigQuery ããŒã¿ã»ããã«å¯Ÿã㊠Dana ã«ä»äžãããŠããããŒã«ãšæš©éã
ãããã®ã¯ãšãªãäœæããŠéä¿¡ããæ¹æ³ã«ã€ããŠã¯ãããªã³ã·ãã«ããªãœãŒã¹ã«å¯ŸããŠæã£ãŠããã¢ã¯ã»ã¹æš©ãç¹å®ãããã芧ãã ããã
ãã®ããªã³ã·ãã«ãã¢ã¯ã»ã¹ã§ãããªãœãŒã¹
ç¹å®ã®ããªã³ã·ãã«ãã¢ã¯ã»ã¹ã§ãããªãœãŒã¹ãç¹å®ããã«ã¯ãããªã³ã·ãã«ãšç¢ºèªããããŒã«ãšæš©éãæå®ããåæã¯ãšãªãäœæããŸãã
ãããã®è³ªåã¯ã次ã®ãããªçåãžã®çããèŠã€ããéã«æŽ»çšã§ããŸãã
- ãŠãŒã¶ãŒ Mahan ã¯ã©ã® BigQuery ããŒã¿ã»ããã®èªã¿åãæš©éãæã£ãŠãããã
dev-testers
ã°ã«ãŒããããŒã¿ãªãŒããŒã§ããã®ã¯ãã©ã® BigQuery ããŒã¿ã»ãããã- ãããžã§ã¯ã A ã§ Tal ãåé€ã§ããã®ã¯ã©ã® VM ãã
- ïŒAPI ãš gcloud CLI ã®ã¿ïŒ: ãŠãŒã¶ãŒã® John ããµãŒãã¹ ã¢ã«ãŠã³ãã«ãªãããŸãããšã«ãã£ãŠãåé€ã§ããã®ã¯ã©ã® VM ãã
ãããã®ã¯ãšãªãäœæããŠéä¿¡ããæ¹æ³ã«ã€ããŠã¯ãããªã³ã·ãã«ãã¢ã¯ã»ã¹ã§ãããªãœãŒã¹ãç¹å®ãããã芧ãã ããã
ä¿åãããåæã¯ãšãª
REST API ã䜿çšããŠããå Žåã¯ãåæã¯ãšãªãä¿åããŠåå©çšããããŸãã¯ä»ã®ãŠãŒã¶ãŒãšå ±æããããšãã§ããŸããä¿åããã¯ãšãªã¯ãä»ã®ã¯ãšãªãšåæ§ã«å®è¡ã§ããŸãã
ã¯ãšãªã®ä¿åã®è©³çްã«ã€ããŠã¯ãä¿åããã¯ãšãªã管çãããã芧ãã ããã
ã¯ãšãªçµæããšã¯ã¹ããŒããã
analyzeIamPolicyLongrunning
ã䜿çšãããšãã¯ãšãªãéåæã§å®è¡ããã¯ãšãªçµæã BigQuery ãŸã㯠Cloud Storage ã«ãšã¯ã¹ããŒãã§ããŸãã
ã¯ãšãªçµæã BigQuery ã«ãšã¯ã¹ããŒãããæ¹æ³ã«ã€ããŠã¯ãããªã·ãŒåæã BigQuery ã«æžã蟌ããã芧ãã ããã
ã¯ãšãªçµæã Cloud Storage ã«ãšã¯ã¹ããŒãããæ¹æ³ã«ã€ããŠã¯ãããªã·ãŒåæã Cloud Storage ã«æžã蟌ããã芧ãã ããã
ã¯ãšãª ãªãã·ã§ã³
Policy Analyzer ã«ã¯ãã¯ãšãªçµæã«è©³çްã远å ãããªãã·ã§ã³ãããã€ãçšæãããŠããŸãã
ãããã®ãªãã·ã§ã³ãæå¹ã«ããæ¹æ³ã«ã€ããŠã¯ããªãã·ã§ã³ãæå¹ã«ãããã芧ãã ããã
ã°ã«ãŒãå±é
ã°ã«ãŒãå±éãæå¹ã«ãããšãã¯ãšãªçµæã®ãã¹ãŠã®ã°ã«ãŒããåã ã®ã¡ã³ããŒã«å±éãããŸãããã®å±éã®äžéã¯ãã°ã«ãŒãããã 1,000 ã¡ã³ããŒã«å¶éãããŠããŸããååãªã°ã«ãŒãæš©éãä»äžãããŠããå Žåã¯ããã¹ããããã°ã«ãŒããå±éãããŸãããã®ãªãã·ã§ã³ã¯ãã¯ãšãªã§ããªã³ã·ãã«ãæå®ããŠããªãå Žåã«ã®ã¿æå¹ã§ãã
ããšãã°ããproject-1
ã«å¯Ÿãã storage.buckets.delete
æš©éãããã®ã¯èª°ãããšããã¯ãšãªã«å¯ŸããŠã°ã«ãŒãå±éãæå¹ã«ãããšããŸããPolicy Analyzer ã storage.buckets.delete
æš©éãæã€ã°ã«ãŒããæ€åºãããšãã¯ãšãªçµæã«ã¯ã°ã«ãŒã ID ã ãã§ãªããã°ã«ãŒãå
ã®ãã¹ãŠã®ã¡ã³ããŒã衚瀺ãããŸãã
ãã®ãªãã·ã§ã³ã䜿çšãããšãã°ã«ãŒãã®ã¡ã³ããŒã·ãããåå ã§ã¢ã¯ã»ã¹æš©ãä»äžãããŠããå Žåã§ããåã ã®ãŠãŒã¶ãŒã®ã¢ã¯ã»ã¹æš©ãææ¡ã§ããŸãã
ããŒã«ã®æ¡åŒµ
ããŒã«ã®æ¡åŒµãæå¹ã«ãããšãã¯ãšãªçµæã«ã¯ãããŒã«èªäœã«å ããŠãåããŒã«å ã®ãã¹ãŠã®æš©éãäžèŠ§è¡šç€ºãããŸãããã®ãªãã·ã§ã³ã¯ãã¯ãšãªã§æš©éãããŒã«ãæå®ããŠããªãå Žåã«ã®ã¿äœ¿çšã§ããŸãã
ããšãã°ããmy-user@example.com
ããã±ãã bucket-1
ã«å¯ŸããŠæã€ã¢ã¯ã»ã¹æš©ããšããã¯ãšãªã«å¯ŸããŠããŒã«æ¡åŒµãæå¹ã«ãããšããŸããmy-user@example.com
ã« bucket-1
ãžã®ã¢ã¯ã»ã¹æš©ãä»äžããããŒã«ã Policy Analyzer ã«ãã£ãŠæ€åºããããšãã¯ãšãªçµæã«ã¯ãããŒã«åã ãã§ãªããã®ããŒã«ã«å«ãŸãããã¹ãŠã®æš©éããªã¹ããããŸãã
ãã®ãªãã·ã§ã³ã§ã¯ãããªã³ã·ãã«ã«ä»äžãããŠããæ£ç¢ºãªæš©éã確èªã§ããŸãã
ãªãœãŒã¹å±é
Policy Analyzer ã¯ãšãªã§ãªãœãŒã¹æ¡åŒµãæå¹ã«ãããšãã¯ãšãªçµæã«ã芪ãªãœãŒã¹ïŒãããžã§ã¯ãããã©ã«ããçµç¹ïŒã®é¢é£ãããã¹ãŠã®åå«ãªãœãŒã¹ãäžèŠ§è¡šç€ºãããŸãããã®æ¡åŒµã¯ãPolicy Analyzer ã®ã¯ãšãªã§ã¯èŠªãªãœãŒã¹ããã 1,000 åã®ãªãœãŒã¹ãé·æéå®è¡ããã Policy Analyzer ã®ã¯ãšãªã§ã¯èŠªãªãœãŒã¹ããšã« 100,000 åã®ãªãœãŒã¹ã«å¶éãããŠããŸãã
ããšãã°ããªãœãŒã¹æ¡åŒµã次ã®ã¯ãšãªã«ã©ã®ããã«åœ±é¿ãããã«ã€ããŠèããŠã¿ãŸãããã
project-1
ã«å¯Ÿããstorage.buckets.delete
æš©éãä»äžãããŠãããŠãŒã¶ãŒããã®ã¯ãšãªã§ãªãœãŒã¹æ¡åŒµãæå¹ã«ãããšãã¯ãšãªçµæã®ãªãœãŒã¹ ã»ã¯ã·ã§ã³ã«ã¯ããããžã§ã¯ãã ãã§ãªãããããžã§ã¯ãå ã®ãã¹ãŠã®ã¹ãã¬ãŒãž ãã±ãããäžèŠ§è¡šç€ºãããŸãã
my-user@example.com
ãcompute.instances.setIamPolicy
æš©éãä»äžãããŠãã察象ãªãœãŒã¹ãã®ã¯ãšãªã§ãªãœãŒã¹æ¡åŒµãæå¹ã«ããPolicy Analyzer ã
my-user@example.com
ã«å¯Ÿè±¡ã®æš©éãå«ããããžã§ã¯ã ã¬ãã«ã®ããŒã«ãããããšãæ€åºããå Žåãã¯ãšãªçµæã®ãªãœãŒã¹ ã»ã¯ã·ã§ã³ã«ã¯ãããžã§ã¯ãã ãã§ãªãããããžã§ã¯ãå ã®ãã¹ãŠã® Compute Engine ã€ã³ã¹ã¿ã³ã¹ãäžèŠ§è¡šç€ºãããŸãã
ãã®ãªãã·ã§ã³ã䜿çšãããšãããªã³ã·ãã«ãã¢ã¯ã»ã¹ã§ãããªãœãŒã¹ã®è©³çްã確èªã§ããŸãã
ãµãŒãã¹ ã¢ã«ãŠã³ãã®æš©éåçš
REST API ãŸã㯠gcloud CLI ã䜿çšããŠããå Žåã¯ããµãŒãã¹ ã¢ã«ãŠã³ãã®æš©éåçšã®åæãæå¹ã«ã§ããŸãã
ãã®ãªãã·ã§ã³ãæå¹ã«ãããšãPolicy Analyzer ã«ãã£ãŠè¿œå ã®åæã¯ãšãªãå®è¡ãããæå®ãããªãœãŒã¹ãžã®æå®ããã¢ã¯ã»ã¹æš©ãä»äžãããŠãããµãŒãã¹ ã¢ã«ãŠã³ãã®æš©éãåçšã§ãããŠãŒã¶ãŒãç¹å®ãããŸããPolicy Analyzer ã§ã¯ãã¯ãšãªçµæã«å«ãŸãããµãŒãã¹ ã¢ã«ãŠã³ãããšã« 1 ã€ã®ã¯ãšãªãå®è¡ãããŸãããããã®ã¯ãšãªã¯ããµãŒãã¹ ã¢ã«ãŠã³ãã«å¯Ÿããæ¬¡ã®ããããã®æš©éãä»äžãããŠãããŠãŒã¶ãŒãåæããŸãã
iam.serviceAccounts.actAs
iam.serviceAccounts.getAccessToken
iam.serviceAccounts.getOpenIdToken
iam.serviceAccounts.implicitDelegation
iam.serviceAccounts.signBlob
iam.serviceAccounts.signJwt
å²ãåœãŠãšäžé
Cloud Asset Inventory ã§ã¯ãã³ã³ã·ã¥ãŒã ãããžã§ã¯ãã«åºã¥ããŠãããªã·ãŒåæãªã¯ãšã¹ããå«ãåä¿¡ãªã¯ãšã¹ãã®ã¬ãŒããé©çšãããŸããCloud Asset Inventory ã§ã¯ãã°ã«ãŒã ã¡ã³ããŒã·ããå ã®ã°ã«ãŒãå±éãšãªãœãŒã¹éå±€å ã®ãªãœãŒã¹å±éãå¶éãããŸãã
Policy Analyzer ã®ããã©ã«ãã®å²ãåœãŠãšäžéã確èªããã«ã¯ãCloud Asset Inventory ããã¥ã¡ã³ãã®å²ãåœãŠãšäžéãã芧ãã ããã
æé
åçµç¹ã¯ã1 æ¥ã«æå€§ 20 ä»¶ã®åæã¯ãšãªãç¡æã§å®è¡ã§ããŸãããã®äžéã«ã¯ãèš±å¯ããªã·ãŒåæãšçµç¹ããªã·ãŒåæã®äž¡æ¹ãå«ãŸããŸãã
1 æ¥ããã 20 ä»¶ãè¶ ããåæã¯ãšãªãå®è¡ããå Žåã¯ãSecurity Command Center ã®ãã¬ãã¢ã ãã£ã¢ãçµç¹ã¬ãã«ã§æå¹ã«ãªã£ãŠããå¿ èŠããããŸãã詳现ã«ã€ããŠã¯ããæ¯æãã«ã€ããŠãã芧ãã ããã
次ã®ã¹ããã
- Policy Analyzer ã䜿çšããŠèš±å¯ããªã·ãŒãåæããæ¹æ³ã確èªããã
- REST API ã䜿çšããŠããªã·ãŒåæã¯ãšãªãä¿åããæ¹æ³ã確èªããã