Google Cloud ã«ã¯ Identity and Access ManagementïŒIAMïŒæ©èœããããç¹å®ã® Google Cloud ãªãœãŒã¹ã«å¯Ÿããã¢ã¯ã»ã¹æš©ãèšå®ã§ãããããä»ã®ãªãœãŒã¹ãžã®äžèŠãªã¢ã¯ã»ã¹ãé²ãããšãã§ããŸãããã®ããŒãžã§ã¯ãCloud SQL ã IAM ãšçµ±åããæ¹æ³ãšãIAM ã䜿çšã㊠Cloud SQL ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã管çããããŒã¿ããŒã¹èªèšŒãè¡ãæ¹æ³ã«ã€ããŠèª¬æããŸãã Google Cloud IAM ã®è©³çްã«ã€ããŠã¯ãIAM ã®ããã¥ã¡ã³ããã芧ãã ããã
Cloud SQL ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹æš©ãå¶åŸ¡ã§ããããã«ãCloud SQL ã«ã¯äºåå®çŸ©ããŒã«ãçšæãããŠããŸããäºåå®çŸ©ããŒã«ã®äžã«å¿ èŠãªæš©éãä»äžãããã®ããªãå Žåã¯ãç¬èªã«ã«ã¹ã¿ã ããŒã«ãäœæããããšãã§ããŸãããŸãã以åã®åºæ¬ããŒã«ïŒç·šéè ãé²èЧè ããªãŒããŒïŒããŸã 䜿çšã§ããŸãããCloud SQL ããŒã«ã»ã©çްããå¶åŸ¡ã¯ã§ããŸãããç¹ã«ãåºæ¬ããŒã«ã§ã¯ Cloud SQL ã ãã§ã¯ãªãã Google Cloudå šäœã®ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹æš©ãä»äžãããŸãã Google Cloud åºæ¬ããŒã«ã®è©³çްã«ã€ããŠã¯ãåºæ¬ããŒã«ãã芧ãã ããã
IAM ããªã·ãŒã¯ããªãœãŒã¹éå±€ã®ä»»æã®ã¬ãã«ïŒçµç¹ã¬ãã«ããã©ã«ãã¬ãã«ããããžã§ã¯ã ã¬ãã«ïŒã§èšå®ã§ããŸãããªãœãŒã¹ã¯èŠªãªãœãŒã¹ã®ããªã·ãŒããã¹ãŠç¶æ¿ããŸãã
Cloud SQL çš IAM ãªãã¡ã¬ã³ã¹
- Google Cloud ã³ã³ãœãŒã«ã§ã®äžè¬çãªã¿ã¹ã¯ã«å¿ èŠãªæš©é
gcloud sql
ã³ãã³ãã«å¿ èŠãªæš©é- Cloud SQL Admin API ã¡ãœããã«å¿ èŠãªæš©é
- äºåå®çŸ©ããã Cloud SQL IAM ããŒã«
- æš©éãšãã®ããŒã«
- ã«ã¹ã¿ã ããŒã«
IAM èªèšŒã®ã³ã³ã»ãã
IAM èªèšŒã䜿çšããå ŽåããªãœãŒã¹ïŒCloud SQL ã€ã³ã¹ã¿ã³ã¹ïŒãžã®ã¢ã¯ã»ã¹æš©ã¯ãšã³ããŠãŒã¶ãŒã«çŽæ¥ä»äžãããŸããã代ããã«ãè€æ°ã®æš©éãããŒã«ã«ãŸãšããŠãããªã³ã·ãã«ã«ä»äžããŸãã詳现ã«ã€ããŠã¯ãIAM ã®æŠèŠãã芧ãã ããã
IAM ããŒã¿ããŒã¹èªèšŒã䜿çšããŠãã°ã€ã³ãã管çè ã¯ãIAM ããªã·ãŒã䜿çšããŠã€ã³ã¹ã¿ã³ã¹ãžã®ã¢ã¯ã»ã¹å¶åŸ¡ãäžå 管çã§ããŸãã
IAM ããªã·ãŒã«ã¯ã次ã®ãšã³ãã£ãã£ãå«ãŸããŸãã
- ããªã³ã·ãã«ãCloud SQL ã§ã¯ããŠãŒã¶ãŒ ã¢ã«ãŠã³ãããµãŒãã¹ ã¢ã«ãŠã³ãïŒã¢ããªã±ãŒã·ã§ã³çšïŒãŸãã¯ã°ã«ãŒããšããè€æ°ã®ã¿ã€ãã®ããªã³ã·ãã«ã䜿çšã§ããŸãã詳现ã«ã€ããŠã¯ãID ã«é¢ããã³ã³ã»ãããã芧ãã ããã
- ããŒã«ãããŒã«ãšã¯ãäžé£ã®æš©éã®ããšã§ããããªã³ã·ãã«ã«ããŒã«ãä»äžããŠãç¹å®ã®ã¿ã¹ã¯ã®å®è¡ã«å¿
èŠãªæš©éãä»äžã§ããŸããããšãã°ãIAM ããŒã¿ããŒã¹èªèšŒã§ã¯ãããªã³ã·ãã«ãã€ã³ã¹ã¿ã³ã¹ã«ãã°ã€ã³ããããã«
cloudsql.instances.login
æš©éãå¿ èŠã§ãããã®æš©é㯠Cloud SQL ã€ã³ã¹ã¿ã³ã¹ ãŠãŒã¶ãŒããŒã«ã«å«ãŸããŠããŸãããã®æš©éãååŸããã«ã¯ããŠãŒã¶ãŒããµãŒãã¹ ã¢ã«ãŠã³ãããŸãã¯ã°ã«ãŒãã Cloud SQL äºåå®çŸ©ããŒã«ãããã®æš©éãå«ãã«ã¹ã¿ã ããŒã«ã«ãã€ã³ãããŸããIAM ããŒã«ã®è©³çްã«ã€ããŠã¯ãããŒã«ã«ã€ããŠãã芧ãã ããã - ãªãœãŒã¹ãããªã³ã·ãã«ãã¢ã¯ã»ã¹ãããªãœãŒã¹ã¯ Cloud SQL ã€ã³ã¹ã¿ã³ã¹ã§ããããã©ã«ãã§ã¯ãIAM ããªã·ãŒ ãã€ã³ãã£ã³ã°ã¯ãããžã§ã¯ã ã¬ãã«ã§é©çšããããããããªã³ã·ãã«ã¯ãããžã§ã¯ãå ã®ãã¹ãŠã® Cloud SQL ã€ã³ã¹ã¿ã³ã¹ã®ããŒã«æš©éãåãåããŸãã
IAM ããŒã¿ããŒã¹èªèšŒ
ããŒã¿ããŒã¹èªèšŒãšã¯ãããŒã¿ããŒã¹ã«ã¢ã¯ã»ã¹ããããšããŠãããŠãŒã¶ãŒã®èº«å ã確èªããããã»ã¹ã§ããCloud SQL ã§ã¯ãããŒã¿ããŒã¹ ãŠãŒã¶ãŒã«å¯ŸããŠæ¬¡ã®çš®é¡ã®ããŒã¿ããŒã¹èªèšŒã䜿çšã§ããŸãã
- ããŒã¿ããŒã¹ã®çµã¿èŸŒã¿èªèšŒããŠãŒã¶ãŒåãšãã¹ã¯ãŒãã䜿çšããŠããŒã¿ããŒã¹ ãŠãŒã¶ãŒãèªèšŒããŸãã
- IAM ããŒã¿ããŒã¹èªèšŒãã¢ã¯ã»ã¹ ããŒã¯ã³ãš IAM ã䜿çšããŠãŠãŒã¶ãŒã®èªèšŒãè¡ããŸãã
ããŒã¿ããŒã¹èªèšŒãªãã·ã§ã³ãæ¯èŒãã
次ã®è¡šã¯ãCloud SQL ã®ããŸããŸãªããŒã¿ããŒã¹èªèšŒæ¹æ³ãæ¯èŒãããã®ã§ãã
æ©èœ | çµã¿èŸŒã¿ããŒã¿ããŒã¹èªèšŒ | IAM ããŒã¿ããŒã¹èªèšŒïŒåå¥ïŒ | IAM ã°ã«ãŒãèªèšŒ |
---|---|---|---|
èªèšŒæ¹æ³ | ãã¹ã¯ãŒã | äžæçãªèªèšŒããŒã¯ã³ | äžæçãªèªèšŒããŒã¯ã³ |
ãããã¯ãŒã¯ ãã©ãã£ãã¯ã®æå·å | SSL äžèŠ | SSL å¿ èŠ | SSL å¿ èŠ |
ãŠãŒã¶ãŒç®¡ç | æå | IAM ã§äžå å | IAM ãš Cloud Identity ã°ã«ãŒãã§äžå å |
IAM ã°ã«ãŒãèªèšŒ
IAM ã°ã«ãŒãèªèšŒã䜿çšãããšãã°ã«ãŒãã¬ãã«ã§ Cloud SQL ãŠãŒã¶ãŒã管çã§ããŸããã°ã«ãŒãã®äŸãšããŠãCloud Identity ã°ã«ãŒãããããŸãããã®æ©èœã«ãããããŒã¿ããŒã¹ã®ãŠãŒã¶ãŒç®¡çãç°¡çŽ åãããŸããè€æ°ã®ã¢ã«ãŠã³ãã® Cloud SQL IAM ããŒã«ãæš©éãäžåºŠã«ç®¡çã§ããŸããåã ã®ãŠãŒã¶ãŒãŸãã¯ãµãŒãã¹ ã¢ã«ãŠã³ããåå¥ã«æŽæ°ããå¿ èŠã¯ãããŸãããCloud Identity ã°ã«ãŒãã«å¯ŸããŠããŒã¿ããŒã¹æš©éãä»äžããããåãæ¶ãããšãã§ããŸããCloud Identity ã°ã«ãŒãã«è¿œå ããæ°ããã¢ã«ãŠã³ãã¯ããã®ã°ã«ãŒãã®æš©éãç¶æ¿ããŸãã
IAM ã°ã«ãŒãèªèšŒã䜿çšãããšã次ã®ããšãã§ããŸãã
- ã°ã«ãŒãã«ãŠãŒã¶ãŒã远å ãããã®ãŠãŒã¶ãŒã IAM ããŒã«ãšããŒã¿ããŒã¹æš©éãèªåçã«ç¶æ¿ããããã«ããŸãã
- ã°ã«ãŒããããŠãŒã¶ãŒãåé€ããŠãCloud SQL ããŒã¿ããŒã¹ãããã°ã€ã³ ã¢ã¯ã»ã¹ãšããŒã¿ããŒã¹æš©éãåé€ããŸãã
- ç°ãªããŠãŒã¶ãŒã«åãæš©éãè€æ°åä»äžãã代ããã«ãã°ã«ãŒãã«ãã°ã€ã³æš©éãŸãã¯ããŒã¿ããŒã¹æš©éãäžåºŠã ãä»äžããŸãã
- ã°ã«ãŒãã®ãã°ã€ã³æš©éãŸãã¯ããŒã¿ããŒã¹ ãªããžã§ã¯ããžã®ã¢ã¯ã»ã¹ãäžåºŠã«åé€ããŸãã
IAM ããŒã«ãšæš©éã¯ã°ã«ãŒãã¬ãã«ã§å²ãåœãŠãããŸããããŠãŒã¶ãŒãšãµãŒãã¹ ã¢ã«ãŠã³ãã¯ããã°ã€ã³ã«å ±æã°ã«ãŒã ã¢ã«ãŠã³ãã§ã¯ãªããåã ã® IAM ã¢ã«ãŠã³ããšèªèšŒæ å ±ã䜿çšããŸããCloud SQL ã¯ãæåã®ãã°ã€ã³åŸã«ããã®ãŠãŒã¶ãŒãŸãã¯ãµãŒãã¹ ã¢ã«ãŠã³ãã®ããŒã¿ããŒã¹ ã¢ã«ãŠã³ããã€ã³ã¹ã¿ã³ã¹ã«äœæããŸãã
ç£æ»ãã°ã«ã¯ãåãŠãŒã¶ãŒãŸãã¯ãµãŒãã¹ ã¢ã«ãŠã³ãã®åå¥ã®ãã°ã€ã³ ã¢ã¯ãã£ããã£ãšããŒã¿ããŒã¹ ã¢ã¯ãã£ããã£ã衚瀺ãããŸããç£æ»ç®çã§ãã©ã®ã¢ã«ãŠã³ããããŒã¿ããŒã¹ã§ã©ã®ã¢ã¯ã·ã§ã³ãå®è¡ãããã衚瀺ã§ããŸãã
Cloud Identity ã°ã«ãŒãã®æäœã®è©³çްã«ã€ããŠã¯ãCloud Identity ã®æŠèŠãã芧ãã ããã
ã°ã«ãŒãã«ãŠãŒã¶ãŒãŸãã¯ãµãŒãã¹ ã¢ã«ãŠã³ãã远å ãããšãCloud SQL ã§æ¬¡ã®å€æŽãè¡ãããŸãã
- ã°ã«ãŒãã« IAM ãã°ã€ã³æš©éããã§ã«ä»äžããŠããå ŽåããŠãŒã¶ãŒãŸãã¯ãµãŒãã¹ ã¢ã«ãŠã³ãã¯ã°ã«ãŒãã«å±ããŠããããããŠãŒã¶ãŒãŸãã¯ãµãŒãã¹ ã¢ã«ãŠã³ã㯠Cloud SQL ã€ã³ã¹ã¿ã³ã¹ã«ãã°ã€ã³ã§ããŸãã
- ãŠãŒã¶ãŒã¯ãã°ã«ãŒãã«ä»äžãããŠããããŒã¿ããŒã¹æš©éãèªåçã«ç¶æ¿ããŸãã
ã°ã«ãŒããããŠãŒã¶ãŒãŸãã¯ãµãŒãã¹ ã¢ã«ãŠã³ããåé€ãããšãCloud SQL ã§æ¬¡ã®å€æŽãè¡ãããŸãã
- ãŠãŒã¶ãŒã¯ãã°ã«ãŒãã®ã¡ã³ããŒã«ãªãããšã«ãã£ãŠä»¥åç¶æ¿ãããããŒã¿ããŒã¹æš©éã倱ããŸãã
- ãŠãŒã¶ãŒãä»ã®ã°ã«ãŒã ã¡ã³ããŒãéã㊠Cloud SQL ã€ã³ã¹ã¿ã³ã¹ã«å¯Ÿãã IAM ãã°ã€ã³æš©éãåãåããšããã°ã€ã³ã§ããå ŽåããããŸãããã ãããŠãŒã¶ãŒã¯ãã°ã€ã³æã«ã以åã®ã°ã«ãŒã ã¡ã³ããŒã®ããŒã¿ããŒã¹æš©éã倱ããŸãã
IAM ã°ã«ãŒãèªèšŒã®ãã¹ã ãã©ã¯ãã£ã¹
- Cloud Identity ã§ IAM ã°ã«ãŒãã®ãã°ã€ã³æš©éïŒ
cloudsql.instances.login
ïŒãåãæ¶ãå Žåã¯ãCloud SQL ã€ã³ã¹ã¿ã³ã¹ãããã°ã«ãŒããåé€ããŠãã ããã - Cloud Identity ããã°ã«ãŒããåé€ããå Žåã¯ããã®ã°ã«ãŒãã Cloud SQL ã€ã³ã¹ã¿ã³ã¹ãããåé€ããŠãã ããã
- ã°ã«ãŒãã䜿çšããŠãããŒã¿ããŒã¹ã«ããŒã«ããŒã¹ ã¢ã¯ã»ã¹å¶åŸ¡ãæ§æããŸããã°ã«ãŒãã«ã¯åžžã«å¿ èŠæå°éã®æš©éãä»äžããŸãã
- çµã¿èŸŒã¿ãŠãŒã¶ãŒã« IAM ã°ã«ãŒãèªèšŒããŒã«ãä»äžããªãã§ãã ãããããšãã°ãçµã¿èŸŒã¿ã®ãŠãŒã¶ãŒ
user-a
ããããIAM ã°ã«ãŒãèªèšŒãŠãŒã¶ãŒuser-b@example.com
ãäœæããå Žåãuser-b@example.com
ããŒã«ãuser-a
ã«ä»äžããªãã§ãã ããã
IAM ã°ã«ãŒãèªèšŒã®å¶é
- IAM ã°ã«ãŒãèªèšŒã䜿çšããŠããŠããªãŒãã¬ããªã«ãå«ã Cloud SQL ã€ã³ã¹ã¿ã³ã¹ãããå Žåã¯ããªãŒãã¬ããªã« ã€ã³ã¹ã¿ã³ã¹ã«ãã°ã€ã³ããåã«ããã©ã€ã㪠ã€ã³ã¹ã¿ã³ã¹ã«ãã°ã€ã³ããå¿ èŠããããŸãããã©ã€ã㪠ã€ã³ã¹ã¿ã³ã¹ã«åããŠãã°ã€ã³ãããšãã°ã«ãŒã ãŠãŒã¶ãŒæ å ±ãèªã¿åãã¬ããªã«ã«è€è£œãããŸãããã®åŸã®ãã°ã€ã³ã§ã¯ããªãŒãã¬ããªã«ã«çŽæ¥ãã°ã€ã³ã§ããŸãã
- 1 ã€ã®ã€ã³ã¹ã¿ã³ã¹ã«è¿œå ã§ãã IAM ã°ã«ãŒã㯠200 åãŸã§ã§ãã
- åãã€ã³ã¹ã¿ã³ã¹ã®ã°ã«ãŒãã«å±ããåã
ã® IAM ãŠãŒã¶ãŒãŸãã¯ãµãŒãã¹ ã¢ã«ãŠã³ãã远å ããããšã¯ã§ããŸãããã€ãŸãã
CLOUD_IAM_GROUP_USER
ãŸãã¯CLOUD_IAM_GROUP_SERVICE_ACCOUNT
ã¿ã€ãã®åäžã®ã¢ã«ãŠã³ãããã§ã«ååšããå ŽåãCLOUD_IAM_USER
ãŸãã¯CLOUD_IAM_SERVICE_ACCOUNT
ã¿ã€ãã®ã¢ã«ãŠã³ãã¯è¿œå ã§ããŸããã -
CLOUD_IAM_USER
ãŸãã¯CLOUD_IAM_SERVICE_ACCOUNT
ã¿ã€ãã®ã€ã³ã¹ã¿ã³ã¹ã«å人ã¢ã«ãŠã³ãããã§ã«ååšããå Žåããã®ã¢ã«ãŠã³ãã IAM ã°ã«ãŒãèªèšŒã«äœ¿çšããããšã¯ã§ããŸããããããã®ãŠãŒã¶ãŒã¿ã€ãã¯ãã°ã«ãŒããã IAM ããŒã«ãšããŒã¿ããŒã¹æš©éãç¶æ¿ããŸããããã®åé¡ãä¿®æ£ããŠãã¢ã«ãŠã³ãã IAM ã°ã«ãŒãèªèšŒã§äœ¿çšããã«ã¯ãåã ã® IAM ãŠãŒã¶ãŒãŸãã¯ãµãŒãã¹ ã¢ã«ãŠã³ããåé€ããŸãã
詳现ã«ã€ããŠã¯ãæ¢åã® IAM ãŠãŒã¶ãŒãŸãã¯ãµãŒãã¹ ã¢ã«ãŠã³ããããã®ã°ã«ãŒãã«ä»äžãããŠããããŒã¿ããŒã¹æš©éãç¶æ¿ããªããã芧ãã ããã - ã¢ã«ãŠã³ãã®è¿œå ãªã©ãCloud Identity ã®ã°ã«ãŒã ã¡ã³ããŒã®å€æŽãåæ ããããŸã§ã«çŽ 15 åããããŸããããã¯ãIAM ã®å€æŽã«å¿ èŠãªæéãšã¯å¥ã®ãã®ã§ãã
IAM ããŒã¿ããŒã¹ã®èªåèªèšŒãšæåèªèšŒ
Cloud SQL for PostgreSQL ã«ã¯ãIAM ããŒã¿ããŒã¹èªèšŒã« 2 ã€ã®ãªãã·ã§ã³ïŒèªåãšæåïŒããããŸãã
IAM ããŒã¿ããŒã¹ã®èªåèªèšŒ
IAM ããŒã¿ããŒã¹ã®èªåèªèšŒã䜿çšãããšãCloud SQL Auth Proxy ã Cloud SQL èšèªã³ãã¯ã¿ãªã©ã®äžéã® Cloud SQL ã³ãã¯ã¿ã«ã¢ã¯ã»ã¹ ããŒã¯ã³ã®ãªã¯ãšã¹ããšç®¡çãä»»ããããšãã§ããŸããIAM ããŒã¿ããŒã¹ã®èªåèªèšŒã§ã¯ããŠãŒã¶ãŒã¯ãã¯ã©ã€ã¢ã³ãããã®æ¥ç¶ãªã¯ãšã¹ãã§ IAM ããŒã¿ããŒã¹ã®ãŠãŒã¶ãŒåã®ã¿ãæž¡ãå¿ èŠããããŸããã³ãã¯ã¿ã¯ãã¯ã©ã€ã¢ã³ãã«ä»£ãã£ãŠãã¹ã¯ãŒã屿§ã®ã¢ã¯ã»ã¹ ããŒã¯ã³æ å ±ãéä¿¡ããŸãã
IAM ããŒã¿ããŒã¹ã®èªåèªèšŒã§ã¯ãCloud SQL ã³ãã¯ã¿ã䜿çšããå¿ èŠããããŸããããã¯ãCloud SQL Auth ProxyãGo ã³ãã¯ã¿ãJava ã³ãã¯ã¿ãPython ã³ãã¯ã¿ã§ãµããŒããããŠããŸãã
å®å šæ§ãšä¿¡é Œæ§ã確ä¿ããã«ã¯ãIAM ããŒã¿ããŒã¹èªåèªèšŒã䜿çšããããšãããããããŸããIAM ããŒã¿ããŒã¹èªèšŒã§ã¯ OAuth 2.0 ã¢ã¯ã»ã¹ ããŒã¯ã³ã䜿çšããŸãããã®ã¢ã¯ã»ã¹ ããŒã¯ã³ã¯æå¹æéãçãã1 æéã®ã¿æå¹ã§ããCloud SQL ã³ãã¯ã¿ã¯ããããã®ããŒã¯ã³ããªã¯ãšã¹ãããŠæŽæ°ã§ããŸããããã«ãããæå¹æéãé·ãããã»ã¹ãæ¥ç¶ããŒã«ã«äŸåããã¢ããªã±ãŒã·ã§ã³ã®æ¥ç¶ãå®å®ãããããšãã§ããŸããæåèªèšŒã§ã¯ãªããIAM ããŒã¿ããŒã¹ã®èªåèªèšŒãè¡ãããšã匷ãããããããŸãã
詳现ã«ã€ããŠã¯ãIAM ããŒã¿ããŒã¹ã®èªåèªèšŒã«ãããã°ã€ã³ãã芧ãã ããã
IAM ããŒã¿ããŒã¹ã®æåèªèšŒ
IAM ããŒã¿ããŒã¹ã®æåèªèšŒã§ã¯ãIAM ããªã³ã·ãã«ã¯ãã¯ã©ã€ã¢ã³ãæ¥ç¶ãªã¯ãšã¹ãã§ãã¹ã¯ãŒã屿§ã®ã¢ã¯ã»ã¹ ããŒã¯ã³ãæç€ºçã«æž¡ãå¿ èŠããããŸããããªã³ã·ãã«ã¯ãŸã Google Cloud ã«ãã°ã€ã³ããIAM ããã®ã¢ã¯ã»ã¹ ããŒã¯ã³ãæç€ºçã«ãªã¯ãšã¹ãããå¿ èŠããããŸãã
gcloud CLI ã䜿çšãããšãããŒã¿ããŒã¹ã«ãã°ã€ã³ããããã® Cloud SQL Admin API ã¹ã³ãŒãã§ OAuth 2.0 ããŒã¯ã³ãæç€ºçã«ãªã¯ãšã¹ãã§ããŸããIAM ããŒã¿ããŒã¹èªèšŒã§ããŒã¿ããŒã¹ ãŠãŒã¶ãŒãšããŠãã°ã€ã³ããå Žåã¯ãã¡ãŒã«ã¢ãã¬ã¹ããŠãŒã¶ãŒåãšããŠäœ¿çšããã¢ã¯ã»ã¹ ããŒã¯ã³ããã¹ã¯ãŒããšããŠäœ¿çšããŸãããã®æ¹æ³ã¯ãããŒã¿ããŒã¹ãžã®çŽæ¥æ¥ç¶ãŸã㯠Cloud SQL ã³ãã¯ã¿ã§äœ¿çšã§ããŸãã
IAM ããŒã¿ããŒã¹èªèšŒã䜿çšãããã°ã€ã³ã¯ãSSL æ¥ç¶çµç±ã§ã®ã¿å®è¡ã§ããŸãã
詳ããã¯ãIAM ããŒã¿ããŒã¹ã®æåèªèšŒã«ãããã°ã€ã³ãã芧ãã ããã
ã³ã³ããã¹ãã¢ãŠã§ã¢ ã¢ã¯ã»ã¹ãš IAM ããŒã¿ããŒã¹èªèšŒ
IAM æ§æã§ã³ã³ããã¹ãã¢ãŠã§ã¢ ã¢ã¯ã»ã¹ã䜿çšããŠããå ŽåãIAM ããŒã¿ããŒã¹èªèšŒã§ Cloud SQL Auth Proxy ã Cloud SQL èšèªã³ãã¯ã¿ãªã©ã® Cloud SQL ã³ãã¯ã¿ã䜿çšã§ããŸãããIAM èªèšŒã䜿çšããŠæåãŸãã¯èªåã§ãã°ã€ã³ããããšãããšã倱æããŸãã代ããã«ãã€ã³ã¹ã¿ã³ã¹ã«çŽæ¥æ¥ç¶ããŸãã
ãŠãŒã¶ãŒãšãµãŒãã¹ ã¢ã«ãŠã³ãã®ç®¡ç
IAM ããŒã¿ããŒã¹èªèšŒã䜿çšããŠãã€ã³ã¹ã¿ã³ã¹ã®ããŒã¿ããŒã¹ã«å¯ŸãããŠãŒã¶ãŒãšãµãŒãã¹ ã¢ã«ãŠã³ãã®ã¢ã¯ã»ã¹ãèš±å¯ããã«ã¯ããã®ãŠãŒã¶ãŒãã€ã³ã¹ã¿ã³ã¹ã«è¿œå ããããã€ã³ã¹ã¿ã³ã¹ã«ã¢ã¯ã»ã¹ã§ããã°ã«ãŒãã«è¿œå ããå¿ èŠããããŸãã詳现ã«ã€ããŠã¯ãIAM ã䜿çšãããŠãŒã¶ãŒãŸãã¯ãµãŒãã¹ ã¢ã«ãŠã³ãã®è¿œå ãã芧ãã ããã
Google Cloud ã³ã³ãœãŒã«ã䜿çšããŠãŠãŒã¶ãŒãŸãã¯ãµãŒãã¹ ã¢ã«ãŠã³ãã远å ããå ŽåãCloud SQL ãããCloud SQL ãŠãŒã¶ãŒãããŒã«ã远å ããããæ±ããããŸãããã®ããŒã«ã¯ããŠãŒã¶ãŒãã€ã³ã¹ã¿ã³ã¹ã«ãã°ã€ã³ããããã«å¿ èŠã§ãã
gcloud
ãŸã㯠API ã䜿çšããŠãŠãŒã¶ãŒã远å ããå Žåã¯ããã°ã€ã³æš©éãæåã§ä»äžããå¿
èŠããããŸããPostgreSQL GRANT ã³ãã³ãã䜿çšããŠããŒã¿ããŒã¹æš©éãä»äžããŸããCloud SQL IAM ããŒã¿ããŒã¹èªèšŒã®ã€ã³ã¹ã¿ã³ã¹æ§æ
ã€ã³ã¹ã¿ã³ã¹ã§ IAM ããŒã¿ããŒã¹èªèšŒãæå¹ã«ããã«ã¯ãcloudsql.iam_authentication
ãã©ã°ã䜿çšããŸãããã®ãã©ã°ãæå¹ã«ãããšãã€ã³ã¹ã¿ã³ã¹ã§ IAM ããŒã¿ããŒã¹èªèšŒçšã«æ§æãããã¢ã«ãŠã³ãã®ãã°ã€ã³ãæå¹ã«ãªããŸãã
ãã®ãã©ã°ã¯ãIAM ã°ã«ãŒãèªèšŒãš IAM ããŒã¿ããŒã¹èªèšŒã«å¿ èŠã§ãã
ãã®ãã©ã°ãèšå®ããå Žåã§ããIAM ã䜿çšããªãæ¢åã®ãŠãŒã¶ãŒã¯ããŠãŒã¶ãŒåãšãã¹ã¯ãŒãã䜿çšããŠãã°ã€ã³ã§ããŸãããã ãããã®ãã©ã°ãã€ã³ã¹ã¿ã³ã¹ã§ç¡å¹ã«ãããšã以åã« IAM ããŒã¿ããŒã¹èªèšŒã䜿çšããŠè¿œå ãããŠãŒã¶ãŒã¯ã€ã³ã¹ã¿ã³ã¹ã«ã¢ã¯ã»ã¹ã§ããªããªããŸãã詳ããã¯ãIAM ããŒã¿ããŒã¹èªèšŒã®ã€ã³ã¹ã¿ã³ã¹ã®æ§æãã芧ãã ããã
ããŸããŸãªã€ã³ã¹ã¿ã³ã¹ ã·ããªãªã«å¯Ÿãã Cloud SQL IAM ããŒã¿ããŒã¹èªèšŒ
ãªãŒãã¬ããªã« | ãã©ã€ã㪠ã€ã³ã¹ã¿ã³ã¹ã§ IAM ããŒã¿ããŒã¹èªèšŒãæå¹ã«ãªã£ãŠããå Žåã§ãããªãŒãã¬ããªã«ã§ã¯èªåçã«æå¹ã«ãªããŸãããäœæãããªãŒãã¬ããªã«ã« IAM ããŒã¿ããŒã¹èªèšŒã远å ããå¿ èŠããããŸãã詳现ã«ã€ããŠã¯ãIAM ããŒã¿ããŒã¹èªèšŒã®ãªãŒãã¬ããªã« ãã°ã€ã³ãæ§æãããã芧ãã ããã |
埩å ãããã€ã³ã¹ã¿ã³ã¹ | 以åã«ããã¯ã¢ãããããã€ã³ã¹ã¿ã³ã¹ãåããããžã§ã¯ãå ã®åãã€ã³ã¹ã¿ã³ã¹ãŸãã¯å¥ã®ã€ã³ã¹ã¿ã³ã¹ã«åŸ©å ããå ŽåãçŸåšã®ãŠãŒã¶ãŒ ãã°ã€ã³èªèšŒãé©çšãããŸããå¥ã®ãããžã§ã¯ãã®æ°ããã€ã³ã¹ã¿ã³ã¹ã«ããã¯ã¢ããã埩å ããå Žåã¯ãæ°ããã€ã³ã¹ã¿ã³ã¹ã®ãŠãŒã¶ãŒèªèšŒãèšå®ããå¿ èŠããããŸãã詳现ã«ã€ããŠã¯ãIAM ããŒã¿ããŒã¹èªèšŒã䜿çšãããŠãŒã¶ãŒãŸãã¯ãµãŒãã¹ ã¢ã«ãŠã³ãã®è¿œå ãã芧ãã ããã |
IAM Conditions ã«ã€ããŠ
IAM Conditions ã䜿çšãããšãããŸããŸãªå±æ§ã«åºã¥ããŠããŒã«ãä»äžã§ããŸããããšãã°ãç¹å®ã®æ¥æã«ã®ã¿ã¢ã¯ã»ã¹ãèš±å¯ããããšããç¹å®ã®ååã® Cloud SQL ãªãœãŒã¹ã«ã®ã¿ã¢ã¯ã»ã¹æš©ãä»äžããããšãå¯èœã§ãã
IAM Conditions ã®è©³çްã«ã€ããŠã¯ãIAM Conditions ã®æŠèŠãã芧ãã ããããŸããCloud SQL ã§ã® IAM Conditions ã®äœ¿çšã®è©³çްïŒäŸãå«ãïŒãã芧ãã ããã
Cloud Audit Logs ã䜿ã£ãæäœ
ç£æ»ãã°ã䜿çšãããšããã°ã€ã³ãªã©ã®ããŒã¿ã¢ã¯ã»ã¹ã®èšé²ãä¿æã§ããŸããããã©ã«ãã§ã¯ãCloud Audit Logs ã¯ç¡å¹ã«ãªã£ãŠããŸãããã°ã€ã³ããã©ããã³ã°ããã«ã¯ãããŒã¿ã¢ã¯ã»ã¹ã®ç£æ»ãã°ãæå¹ã«ããå¿ èŠããããŸãããã®ç®çã§ç£æ»ãã®ã³ã°ã䜿çšãããšãããŒã¿ãã®ã³ã°ã®è²»çšãçºçããŸãã詳现ã«ã€ããŠã¯ãç£æ»ãã°ãããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ã®æ§æãããŒã¿ãã®ã³ã°ã®æéãã芧ãã ããã
å¶éäºé
- IAM ããŒã¿ããŒã¹èªèšŒãŠãŒã¶ãŒ ã¢ã«ãŠã³ãã®ãã°ã€ã³ã¯ãã¹ãŠå°æåã«ããå¿
èŠããããŸããäŸ:
example-user@example.com
Example-User@example.com
ã¯èš±å¯ãããŸããã - ã»ãã¥ãªãã£äžãIAM ããŒã¿ããŒã¹èªèšŒã䜿çšãããã°ã€ã³ã¯ SSL æ¥ç¶ã§ã®ã¿äœ¿çšã§ããŸããæå·åãããŠããªãæ¥ç¶ã¯æåŠãããŸãã
- åã€ã³ã¹ã¿ã³ã¹ã«ã¯ååäœã®ãã°ã€ã³å²ãåœãŠããããŸããããã«ã¯ãæåãããã°ã€ã³ãšå€±æãããã°ã€ã³ã®äž¡æ¹ãå«ãŸããŸããå²ãåœãŠãè¶ éãããšãäžæçã«ãã°ã€ã³ã§ããªããªããŸããé »ç¹ãªãã°ã€ã³ãé¿ãããšãšãã«ãæ¿èªæžã¿ãããã¯ãŒã¯ã䜿çšããŠãã°ã€ã³ãå¶éããããšãããããããŸãããã°ã€ã³ã®æ¿èªã®å²ãåœãŠã¯ãã€ã³ã¹ã¿ã³ã¹ããšã« 1 åããã 12,000 ã§ãã
次ã®ã¹ããã
- IAM ããŒã¿ããŒã¹èªèšŒçšã«ã€ã³ã¹ã¿ã³ã¹ãæ§æããæ¹æ³ã確èªããã
- IAM ããŒã¿ããŒã¹èªèšŒã䜿çšãããŠãŒã¶ãŒ ã¢ã«ãŠã³ããŸãã¯ãµãŒãã¹ ã¢ã«ãŠã³ããããŒã¿ããŒã¹ã«è¿œå ããæ¹æ³ãåŠç¿ããã
- IAM ããŒã¿ããŒã¹èªèšŒã䜿çšã㊠Cloud SQL ããŒã¿ããŒã¹ã«ãã°ã€ã³ããæ¹æ³ãåŠç¿ããã
- ç£æ»ãã°ã«ãã°ã€ã³æ å ±ã衚瀺ããæ¹æ³ãåŠç¿ããã