๊ณ ๊ฐ ๊ด€๋ฆฌ ์•”ํ˜ธํ™” ํ‚ค(CMEK)

๊ธฐ๋ณธ์ ์œผ๋กœ Vertex AI Workbench๋Š” ์ €์žฅ ์ค‘์ธ ๊ณ ๊ฐ ์ฝ˜ํ…์ธ ๋ฅผ ์•”ํ˜ธํ™”ํ•ฉ๋‹ˆ๋‹ค. Vertex AI Workbench๋Š” ์‚ฌ์šฉ์ž๊ฐ€ ์ถ”๊ฐ€ ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•  ํ•„์š” ์—†์ด ์ž๋™์œผ๋กœ ์•”ํ˜ธํ™”๋ฅผ ์ฒ˜๋ฆฌํ•ฉ๋‹ˆ๋‹ค. ์ด ์˜ต์…˜์„ Google ๊ธฐ๋ณธ ์•”ํ˜ธํ™”๋ผ๊ณ  ๋ถ€๋ฆ…๋‹ˆ๋‹ค.

์•”ํ˜ธํ™” ํ‚ค๋ฅผ ์ œ์–ดํ•˜๋ ค๋ฉด Vertex AI Workbench๋ฅผ ํฌํ•จํ•œ CMEK ํ†ตํ•ฉ ์„œ๋น„์Šค์™€ ํ•จ๊ป˜ Cloud KMS์—์„œ ๊ณ ๊ฐ ๊ด€๋ฆฌ ์•”ํ˜ธํ™” ํ‚ค(CMEK)๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค. Cloud KMS ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ๋ณดํ˜ธ ์ˆ˜์ค€, ์œ„์น˜, ์ˆœํ™˜ ์ผ์ •, ์‚ฌ์šฉ ๋ฐ ์•ก์„ธ์Šค ๊ถŒํ•œ, ์•”ํ˜ธํ™” ๊ฒฝ๊ณ„๋ฅผ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. Cloud KMS๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ํ‚ค ์‚ฌ์šฉ์„ ์ถ”์ ํ•˜๊ณ , ๊ฐ์‚ฌ ๋กœ๊ทธ๋ฅผ ๋ณด๊ณ , ํ‚ค ์ˆ˜๋ช… ์ฃผ๊ธฐ๋ฅผ ์ œ์–ดํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค. Google์—์„œ ๋ฐ์ดํ„ฐ๋ฅผ ๋ณดํ˜ธํ•˜๋Š” ๋Œ€์นญ ํ‚ค ์•”ํ˜ธํ™” ํ‚ค(KEK)๋ฅผ ์†Œ์œ ํ•˜๊ณ  ๊ด€๋ฆฌํ•˜๋Š” ๋Œ€์‹  ์‚ฌ์šฉ์ž๊ฐ€ Cloud KMS์—์„œ ์ด๋Ÿฌํ•œ ํ‚ค๋ฅผ ์ œ์–ดํ•˜๊ณ  ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

CMEK๋กœ ๋ฆฌ์†Œ์Šค๋ฅผ ์„ค์ •ํ•œ ํ›„ Vertex AI Workbench ๋ฆฌ์†Œ์Šค์— ์•ก์„ธ์Šคํ•˜๋Š” ํ™˜๊ฒฝ์€ Google ๊ธฐ๋ณธ ์•”ํ˜ธํ™”๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ๊ณผ ์œ ์‚ฌํ•ฉ๋‹ˆ๋‹ค. ์•”ํ˜ธํ™” ์˜ต์…˜์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ๊ณ ๊ฐ ๊ด€๋ฆฌ ์•”ํ˜ธํ™” ํ‚ค(CMEK)๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

์ด ํŽ˜์ด์ง€์—์„œ๋Š” Vertex AI Workbench ๋…ธํŠธ๋ถ๊ณผ ํ•จ๊ป˜ CMEK๋ฅผ ์‚ฌ์šฉํ•  ๋•Œ์˜ ๋ช‡ ๊ฐ€์ง€ ๊ตฌ์ฒด์ ์ธ ์ด์ ๊ณผ ์ œํ•œ์‚ฌํ•ญ์„ ์„ค๋ช…ํ•˜๊ณ  CMEK๋ฅผ ์‚ฌ์šฉํ•˜๋„๋ก ์ƒˆ๋กœ์šด Vertex AI Workbench ์ธ์Šคํ„ด์Šค๋ฅผ ๊ตฌ์„ฑํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.

Vertex AI์— CMEK๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๋ฐฉ๋ฒ•์€ Vertex AI CMEK ํŽ˜์ด์ง€๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

CMEK์˜ ์ด์ 

์ผ๋ฐ˜์ ์œผ๋กœ CMEK๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ์•”ํ˜ธํ™”ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋˜๋Š” ํ‚ค๋ฅผ ์™„์ „ํžˆ ์ œ์–ดํ•ด์•ผ ํ•˜๋Š” ๊ฒฝ์šฐ์— ๊ฐ€์žฅ ์œ ์šฉํ•ฉ๋‹ˆ๋‹ค. CMEK๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด Cloud Key Management Service๋‚ด์—์„œ ํ‚ค๋ฅผ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด ํ‚ค๋ฅผ ์ˆœํ™˜ ๋˜๋Š” ์‚ฌ์šฉ ์ค‘์ง€ํ•˜๊ฑฐ๋‚˜ Cloud KMS API๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ˆœํ™˜ ์ผ์ •์„ ์„ค์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Vertex AI Workbench ์ธ์Šคํ„ด์Šค๋ฅผ ์‹คํ–‰ํ•˜๋ฉด Vertex AI Workbench์—์„œ ๊ด€๋ฆฌ๋˜๋Š” ๊ฐ€์ƒ ๋จธ์‹ (VM)์—์„œ ์ธ์Šคํ„ด์Šค๊ฐ€ ์‹คํ–‰๋ฉ๋‹ˆ๋‹ค. Vertex AI Workbench ์ธ์Šคํ„ด์Šค์— ๋Œ€ํ•ด CMEK๋ฅผ ์‚ฌ์šฉ ์„ค์ •ํ•˜๋ฉด Vertex AI Workbench๋Š” Google์—์„œ ๊ด€๋ฆฌํ•˜๋Š” ํ‚ค๊ฐ€ ์•„๋‹Œ ์‚ฌ์šฉ์ž๊ฐ€ ์ง€์ •ํ•œ ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ VM์˜ ๋ถ€ํŒ… ๋””์Šคํฌ์— ์žˆ๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ์•”ํ˜ธํ™”ํ•ฉ๋‹ˆ๋‹ค.

CMEK ํ‚ค๋Š” Vertex AI Workbench ์ธ์Šคํ„ด์Šค์™€ ๊ด€๋ จ๋œ ์ธ์Šคํ„ด์Šค ์ด๋ฆ„ ๋ฐ ๋ฆฌ์ „๊ณผ ๊ฐ™์€ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ๋ฅผ ์•”ํ˜ธํ™”ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. Vertex AI Workbench ์ธ์Šคํ„ด์Šค์™€ ๊ด€๋ จ๋œ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ๋Š” ํ•ญ์ƒ Google์˜ ๊ธฐ๋ณธ ์•”ํ˜ธํ™” ๋ฉ”์ปค๋‹ˆ์ฆ˜์„ ์‚ฌ์šฉํ•˜์—ฌ ์•”ํ˜ธํ™”๋ฉ๋‹ˆ๋‹ค.

CMEK์˜ ์ œํ•œ์‚ฌํ•ญ

์ง€์—ฐ ์‹œ๊ฐ„์„ ์ค„์ด๊ณ  ๋ฆฌ์†Œ์Šค๊ฐ€ ์—ฌ๋Ÿฌ ์žฅ์•  ๋„๋ฉ”์ธ์— ๋ถ„์‚ฐ๋œ ์„œ๋น„์Šค์— ์˜์กดํ•˜์ง€ ์•Š๋„๋ก ๋™์ผํ•œ ์œ„์น˜์— ์žˆ๋Š” ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฆฌ์ „ Vertex AI Workbench ์ธ์Šคํ„ด์Šค๋ฅผ ๋ณดํ˜ธํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค.

  • ๋™์ผํ•œ ์œ„์น˜ ๋˜๋Š” ์ „์—ญ ์œ„์น˜์—์„œ ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฆฌ์ „ Vertex AI Workbench ์ธ์Šคํ„ด์Šค๋ฅผ ์•”ํ˜ธํ™”ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด us-west1 ๋˜๋Š” global์˜ ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ us-west1-a ์˜์—ญ์˜ ๋””์Šคํฌ์— ์žˆ๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ์•”ํ˜ธํ™”ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • ๋ชจ๋“  ์œ„์น˜์˜ ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ „์—ญ ์ธ์Šคํ„ด์Šค๋ฅผ ์•”ํ˜ธํ™”ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • Vertex AI Workbench์šฉ CMEK๋ฅผ ๊ตฌ์„ฑํ•ด๋„ ์‚ฌ์šฉ ์ค‘์ธ ๋‹ค๋ฅธ Google Cloud ์ œํ’ˆ์— CMEK๊ฐ€ ์ž๋™์œผ๋กœ ๊ตฌ์„ฑ๋˜์ง€๋Š” ์•Š์Šต๋‹ˆ๋‹ค. CMEK๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋‹ค๋ฅธ Google Cloud ์ œํ’ˆ์˜ ๋ฐ์ดํ„ฐ๋ฅผ ์•”ํ˜ธํ™”ํ•˜๋ ค๋ฉด ์ถ”๊ฐ€ ๊ตฌ์„ฑ์„ ์™„๋ฃŒํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

Vertex AI Workbench ์ธ์Šคํ„ด์Šค์˜ CMEK ๊ตฌ์„ฑ

๋‹ค์Œ ์„น์…˜์—์„œ๋Š” Cloud Key Management Service์—์„œ ํ‚ค๋ง ๋ฐ ํ‚ค๋ฅผ ๋งŒ๋“ค๊ณ  ์„œ๋น„์Šค ๊ณ„์ •์— ํ‚ค์— ๋Œ€ํ•œ ์•”ํ˜ธํ™” ๋ฐ ๋ณตํ˜ธํ™” ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•˜๊ณ , CMEK๋ฅผ ์‚ฌ์šฉํ•˜๋Š” Vertex AI Workbench ์ธ์Šคํ„ด์Šค๋ฅผ ๋งŒ๋“œ๋Š” ๋ฐฉ๋ฒ•์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค.

์‹œ์ž‘ํ•˜๊ธฐ ์ „์—

์—…๋ฌด ๋ถ„์žฅ์„ ์ง€์›ํ•˜๋Š” ์„ค์ •์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค. Vertex AI Workbench์šฉ CMEK๋ฅผ ๊ตฌ์„ฑํ•˜๋ ค๋ฉด ๋ณ„๋„์˜ ๋‘ Google Cloud ํ”„๋กœ์ ํŠธ๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค.

  • Cloud KMS ํ”„๋กœ์ ํŠธ: ์•”ํ˜ธํ™” ํ‚ค ๊ด€๋ฆฌ ํ”„๋กœ์ ํŠธ
  • Vertex AI Workbench ํ”„๋กœ์ ํŠธ: Vertex AI Workbench ์ธ์Šคํ„ด์Šค์— ์•ก์„ธ์Šคํ•˜๊ณ  ์‚ฌ์šฉ ์‚ฌ๋ก€์— ํ•„์š”ํ•œ ๋‹ค๋ฅธ Google Cloud ์ œํ’ˆ๊ณผ ์ƒํ˜ธ์ž‘์šฉํ•˜๋Š” ํ”„๋กœ์ ํŠธ

๋˜๋Š” ๋‹จ์ผ Google Cloud ํ”„๋กœ์ ํŠธ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฅผ ์œ„ํ•ด์„œ๋Š” ๋‹ค์Œ ๋ชจ๋“  ์ž‘์—…์— ๋™์ผํ•œ ํ”„๋กœ์ ํŠธ๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

Cloud KMS ํ”„๋กœ์ ํŠธ ์„ค์ •

  1. Sign in to your Google Cloud account. If you're new to Google Cloud, create an account to evaluate how our products perform in real-world scenarios. New customers also get $300 in free credits to run, test, and deploy workloads.
  2. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Go to project selector

  3. Verify that billing is enabled for your Google Cloud project.

  4. Enable the Cloud KMS API.

    Enable the API

  5. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Go to project selector

  6. Verify that billing is enabled for your Google Cloud project.

  7. Enable the Cloud KMS API.

    Enable the API

Vertex AI Workbench ํ”„๋กœ์ ํŠธ ์„ค์ •

  1. Sign in to your Google Cloud account. If you're new to Google Cloud, create an account to evaluate how our products perform in real-world scenarios. New customers also get $300 in free credits to run, test, and deploy workloads.
  2. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Go to project selector

  3. Verify that billing is enabled for your Google Cloud project.

  4. Enable the Notebooks API.

    Enable the API

  5. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Go to project selector

  6. Verify that billing is enabled for your Google Cloud project.

  7. Enable the Notebooks API.

    Enable the API

Google Cloud CLI ์„ค์ •

์ด ํŽ˜์ด์ง€์˜ ์ผ๋ถ€ ๋‹จ๊ณ„์—์„œ๋Š” gcloud CLI๊ฐ€ ํ•„์š”ํ•˜๋ฉฐ ๋‹ค๋ฅธ ๊ฒฝ์šฐ์—๋Š” ์„ ํƒ ์‚ฌํ•ญ์ž…๋‹ˆ๋‹ค.

Install the Google Cloud CLI. After installation, initialize the Google Cloud CLI by running the following command:

gcloud init

If you're using an external identity provider (IdP), you must first sign in to the gcloud CLI with your federated identity.

ํ‚ค๋ง ๋ฐ ํ‚ค ๋งŒ๋“ค๊ธฐ

ํ‚ค๋ง๊ณผ ํ‚ค๋ฅผ ๋งŒ๋“ค ๋•Œ ๋‹ค์Œ ์š”๊ตฌ์‚ฌํ•ญ์— ์œ ์˜ํ•˜์„ธ์š”.

  • ํ‚ค๋ง์˜ ์œ„์น˜๋ฅผ ์„ ํƒํ•  ๋•Œ global ๋˜๋Š” Vertex AI Workbench ์ธ์Šคํ„ด์Šค๊ฐ€ ๋ฐฐ์น˜๋  ์œ„์น˜๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

  • Cloud KMS ํ”„๋กœ์ ํŠธ์—์„œ ํ‚ค๋ง๊ณผ ํ‚ค๋ฅผ ๋งŒ๋“ค์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

ํ‚ค๋ง๊ณผ ํ‚ค๋ฅผ ๋งŒ๋“ค๋ ค๋ฉด ๋Œ€์นญ ์•”ํ˜ธํ™” ํ‚ค ๋งŒ๋“ค๊ธฐ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

Vertex AI Workbench ๊ถŒํ•œ ๋ถ€์—ฌ

Vertex AI Workbench ์ธ์Šคํ„ด์Šค์— CMEK๋ฅผ ์‚ฌ์šฉํ•˜๋ ค๋ฉด Vertex AI Workbench ์ธ์Šคํ„ด์Šค์— ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฐ์ดํ„ฐ๋ฅผ ์•”ํ˜ธํ™” ๋ฐ ๋ณตํ˜ธํ™”ํ•˜๋Š” ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ด ๊ถŒํ•œ์„ ํ”„๋กœ์ ํŠธ์˜ ์„œ๋น„์Šค ์—์ด์ „ํŠธ ๋ฐ Compute Engine ์„œ๋น„์Šค ๊ณ„์ •์— ๋ถ€์—ฌํ•ฉ๋‹ˆ๋‹ค.

Vertex AI Workbench ํ”„๋กœ์ ํŠธ์˜ ํŠน์ • ๊ณ„์ •์„ ์ฐพ์œผ๋ ค๋ฉด Google Cloud ์ฝ˜์†”์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

  1. Google Cloud ์ฝ˜์†”์—์„œ IAM ํŽ˜์ด์ง€๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.

    IAM์œผ๋กœ ์ด๋™

  2. Google ์ œ๊ณต ์—ญํ•  ๋ถ€์—ฌ ํฌํ•จ์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

  3. ๋‹ค์Œ ์ด๋ฉ”์ผ ์ฃผ์†Œ ํ˜•์‹๊ณผ ์ผ์น˜ํ•˜๋Š” ๊ตฌ์„ฑ์›์„ ์ฐพ์Šต๋‹ˆ๋‹ค. ์ด๋ฉ”์ผ ์ฃผ์†Œ๋ฅผ ๊ธฐ๋กํ•˜๊ณ  ๋‹ค์Œ ๋‹จ๊ณ„์—์„œ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

    • ํ”„๋กœ์ ํŠธ์˜ ์„œ๋น„์Šค ์—์ด์ „ํŠธ ์ด๋ฉ”์ผ ์ฃผ์†Œ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

      service-NOTEBOOKS_PROJECT_NUMBER@gcp-sa-notebooks.iam.gserviceaccount.com
    • Compute Engine ์„œ๋น„์Šค ๊ณ„์ •์˜ ์ด๋ฉ”์ผ ์ฃผ์†Œ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

      service-NOTEBOOKS_PROJECT_NUMBER@compute-system.iam.gserviceaccount.com

    NOTEBOOKS_PROJECT_NUMBER๋ฅผ Vertex AI Workbench ํ”„๋กœ์ ํŠธ์˜ ํ”„๋กœ์ ํŠธ ๋ฒˆํ˜ธ๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.

    ์ด๋Ÿฌํ•œ ๊ณ„์ •์— ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฐ์ดํ„ฐ๋ฅผ ์•”ํ˜ธํ™” ๋ฐ ๋ณตํ˜ธํ™”ํ•  ์ˆ˜ ์žˆ๋Š” ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•˜๋ ค๋ฉด Google Cloud ์ฝ˜์†” ๋˜๋Š” Google Cloud CLI๋ฅผ ์‚ฌ์šฉํ•˜์„ธ์š”.

    ์ฝ˜์†”

    1. Google Cloud ์ฝ˜์†”์—์„œ ํ‚ค ๊ด€๋ฆฌ ํŽ˜์ด์ง€๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.

      ํ‚ค ๊ด€๋ฆฌ๋กœ ์ด๋™

    2. Cloud KMS ํ”„๋กœ์ ํŠธ๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

    3. ํ‚ค๋ง ๋ฐ ํ‚ค ๋งŒ๋“ค๊ธฐ์—์„œ ๋งŒ๋“  ํ‚ค๋ง์˜ ์ด๋ฆ„์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค. ํ‚ค๋ง ์„ธ๋ถ€์ •๋ณด ํŽ˜์ด์ง€๊ฐ€ ์—ด๋ฆฝ๋‹ˆ๋‹ค.

    4. ํ‚ค๋ง ๋ฐ ํ‚ค ๋งŒ๋“ค๊ธฐ์—์„œ ๋งŒ๋“  ํ‚ค์˜ ์ฒดํฌ๋ฐ•์Šค๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค. ํ‚ค ์ด๋ฆ„์œผ๋กœ ๋ผ๋ฒจ์ด ์ง€์ •๋œ ์ •๋ณด ํŒจ๋„์ด ์•„์ง ์—ด๋ ค ์žˆ์ง€ ์•Š์€ ๊ฒฝ์šฐ ์ •๋ณด ํŒจ๋„ ํ‘œ์‹œ๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

    5. ์ •๋ณด ํŒจ๋„์—์„œ  ๊ตฌ์„ฑ์› ์ถ”๊ฐ€๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค. 'KEY_NAME'์— ๊ตฌ์„ฑ์› ์ถ”๊ฐ€ ๋Œ€ํ™”์ƒ์ž๊ฐ€ ์—ด๋ฆฝ๋‹ˆ๋‹ค. ์ด ๋Œ€ํ™”์ƒ์ž์—์„œ ๋‹ค์Œ ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

      1. ์ƒˆ ๊ตฌ์„ฑ์› ํ•„๋“œ์— ํ”„๋กœ์ ํŠธ์˜ ์„œ๋น„์Šค ์—์ด์ „ํŠธ ์ด๋ฉ”์ผ ์ฃผ์†Œ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.

        service-NOTEBOOKS_PROJECT_NUMBER@gcp-sa-notebooks.iam.gserviceaccount.com
      2. ์—ญํ•  ์„ ํƒ ๋ชฉ๋ก์—์„œ Cloud KMS๋ฅผ ํด๋ฆญํ•œ ๋‹ค์Œ Cloud KMS CryptoKey Encrypter/Decrypter ์—ญํ• ์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

      3. ์ €์žฅ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

    6. Compute Engine ์„œ๋น„์Šค ์—์ด์ „ํŠธ์—์„œ ๋‹ค์Œ ๋‹จ๊ณ„๋ฅผ ๋ฐ˜๋ณตํ•ฉ๋‹ˆ๋‹ค.

      service-NOTEBOOKS_PROJECT_NUMBER@compute-system.iam.gserviceaccount.com

    gcloud

    1. ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฐ์ดํ„ฐ๋ฅผ ์•”ํ˜ธํ™” ๋ฐ ๋ณตํ˜ธํ™”ํ•  ์ˆ˜ ์žˆ๋Š” ๊ถŒํ•œ์„ ํ”„๋กœ์ ํŠธ์˜ ์„œ๋น„์Šค ์—์ด์ „ํŠธ์— ๋ถ€์—ฌํ•˜๋ ค๋ฉด ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•˜์„ธ์š”.

      gcloud kms keys add-iam-policy-binding KEY_NAME \
        --keyring=KEY_RING_NAME \
        --location=REGION \
        --project=KMS_PROJECT_ID \
        --member=serviceAccount:service-NOTEBOOKS_PROJECT_NUMBER@gcp-sa-notebooks.iam.gserviceaccount.com \
        --role=roles/cloudkms.cryptoKeyEncrypterDecrypter

      ๋‹ค์Œ์„ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.

      • KEY_NAME: ํ‚ค๋ง ๋ฐ ํ‚ค ๋งŒ๋“ค๊ธฐ์—์„œ ๋งŒ๋“  ํ‚ค์˜ ์ด๋ฆ„
      • KEY_RING_NAME: ํ‚ค๋ง ๋ฐ ํ‚ค ๋งŒ๋“ค๊ธฐ์—์„œ ๋งŒ๋“  ํ‚ค๋ง
      • REGION: ํ‚ค๋ง์„ ๋งŒ๋“  ๋ฆฌ์ „
      • KMS_PROJECT_ID: Cloud KMS ํ”„๋กœ์ ํŠธ์˜ ID
      • NOTEBOOKS_PROJECT_NUMBER: ์ด์ „ ์„น์…˜์—์„œ ์„œ๋น„์Šค ๊ณ„์ • ์ด๋ฉ”์ผ ์ฃผ์†Œ์˜ ์ผ๋ถ€๋กœ ๊ธฐ๋กํ•ด ๋‘” Vertex AI Workbench ํ”„๋กœ์ ํŠธ์˜ ํ”„๋กœ์ ํŠธ ๋ฒˆํ˜ธ
    2. Compute Engine ์„œ๋น„์Šค ๊ณ„์ •์— ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฐ์ดํ„ฐ๋ฅผ ์•”ํ˜ธํ™” ๋ฐ ๋ณตํ˜ธํ™”ํ•  ์ˆ˜ ์žˆ๋Š” ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•˜๋ ค๋ฉด ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

      gcloud kms keys add-iam-policy-binding KEY_NAME \
        --keyring=KEY_RING_NAME \
        --location=REGION \
        --project=KMS_PROJECT_ID \
        --member=serviceAccount:service-NOTEBOOKS_PROJECT_NUMBER@compute-system.iam.gserviceaccount.com \
        --role=roles/cloudkms.cryptoKeyEncrypterDecrypter

CMEK๋กœ Vertex AI Workbench ์ธ์Šคํ„ด์Šค ๋งŒ๋“ค๊ธฐ

ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฐ์ดํ„ฐ๋ฅผ ์•”ํ˜ธํ™” ๋ฐ ๋ณตํ˜ธํ™”ํ•  ์ˆ˜ ์žˆ๋Š” ๊ถŒํ•œ์„ Vertex AI Workbench ์ธ์Šคํ„ด์Šค์— ๋ถ€์—ฌํ–ˆ์œผ๋ฏ€๋กœ, ์ด ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฐ์ดํ„ฐ๋ฅผ ์•”ํ˜ธํ™”ํ•˜๋Š” Vertex AI Workbench ์ธ์Šคํ„ด์Šค๋ฅผ ๋งŒ๋“ค ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋‹ค์Œ ์˜ˆ์‹œ์—์„œ๋Š” Google Cloud ์ฝ˜์†”์—์„œ ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฐ์ดํ„ฐ๋ฅผ ์•”ํ˜ธํ™” ๋ฐ ๋ณตํ˜ธํ™”ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.

๊ณ ๊ฐ ๊ด€๋ฆฌ ์•”ํ˜ธํ™” ํ‚ค๋กœ Vertex AI Workbench ์ธ์Šคํ„ด์Šค๋ฅผ ๋งŒ๋“ค๋ ค๋ฉด ๋‹ค์Œ ์•ˆ๋‚ด๋ฅผ ๋”ฐ๋ฅด์„ธ์š”.

  1. Google Cloud ์ฝ˜์†”์—์„œ ์ธ์Šคํ„ด์Šค ํŽ˜์ด์ง€๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.

    ์ธ์Šคํ„ด์Šค๋กœ ์ด๋™

  2. ์ƒˆ๋กœ ๋งŒ๋“ค๊ธฐ๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  3. ์ƒˆ ์ธ์Šคํ„ด์Šค ๋Œ€ํ™”์ƒ์ž์—์„œ ๊ณ ๊ธ‰ ์˜ต์…˜์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  4. ์ธ์Šคํ„ด์Šค ๋งŒ๋“ค๊ธฐ ๋Œ€ํ™”์ƒ์ž์˜ ์„ธ๋ถ€์ •๋ณด ์„น์…˜์—์„œ ์ƒˆ ์ธ์Šคํ„ด์Šค์— ๋Œ€ํ•ด ๋‹ค์Œ ์ •๋ณด๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

    • ์ด๋ฆ„: ์ƒˆ ์ธ์Šคํ„ด์Šค ์ด๋ฆ„
    • ๋ฆฌ์ „: ํ‚ค ๋ฐ ํ‚ค๋ง์ด ์žˆ๋Š” ๋ฆฌ์ „
    • ์˜์—ญ - ์„ ํƒํ•œ ๋ฆฌ์ „์— ์žˆ๋Š” ์˜์—ญ
  5. ๋””์Šคํฌ ์„น์…˜์˜ ์•”ํ˜ธํ™”์—์„œ ๊ณ ๊ฐ ๊ด€๋ฆฌ ์•”ํ˜ธํ™” ํ‚ค(CMEK)๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

  6. ๊ณ ๊ฐ ๊ด€๋ฆฌ ํ‚ค ์„ ํƒ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

    • ์‚ฌ์šฉํ•˜๋ ค๋Š” ๊ณ ๊ฐ ๊ด€๋ฆฌ ํ‚ค๊ฐ€ ๋ชฉ๋ก์— ์žˆ์œผ๋ฉด ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
    • ์‚ฌ์šฉํ•˜๋ ค๋Š” ๊ณ ๊ฐ ๊ด€๋ฆฌ ํ‚ค๊ฐ€ ๋ชฉ๋ก์— ์—†์œผ๋ฉด ๊ณ ๊ฐ ๊ด€๋ฆฌ ํ‚ค์˜ ๋ฆฌ์†Œ์Šค ID๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค. ๊ณ ๊ฐ ๊ด€๋ฆฌ ํ‚ค์˜ ๋ฆฌ์†Œ์Šค ID๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

      projects/NOTEBOOKS_PROJECT_NUMBER/locations/global/keyRings/KEY_RING_NAME/cryptoKeys/KEY_NAME

      ๋‹ค์Œ์„ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.

  7. ์ธ์Šคํ„ด์Šค ๋งŒ๋“ค๊ธฐ ๋Œ€ํ™”์ƒ์ž์˜ ๋‚˜๋จธ์ง€ ๋ถ€๋ถ„์„ ์™„๋ฃŒํ•œ ํ›„ ๋งŒ๋“ค๊ธฐ๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

๋‹ค์Œ ๋‹จ๊ณ„