IAM์œผ๋กœ ์•ก์„ธ์Šค ์ œ์–ด

์ด ํŽ˜์ด์ง€์—์„œ๋Š” VPC ์„œ๋น„์Šค ์ œ์–ด๋ฅผ ๊ตฌ์„ฑํ•˜๋Š” ๋ฐ ํ•„์š”ํ•œ ID ๋ฐ ์•ก์„ธ์Šค ๊ด€๋ฆฌ(IAM) ์—ญํ• ์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค.

ํ•„์š”ํ•œ ์—ญํ• 

๋‹ค์Œ ํ‘œ์—๋Š” ์•ก์„ธ์Šค ์ •์ฑ…์„ ๋งŒ๋“ค๊ณ  ๋‚˜์—ดํ•˜๋Š” ๋ฐ ํ•„์š”ํ•œ ๊ถŒํ•œ๊ณผ ์—ญํ• ์ด ๋‚˜์™€ ์žˆ์Šต๋‹ˆ๋‹ค.

์ž‘์—… ํ•„์ˆ˜ ๊ถŒํ•œ ๋ฐ ์—ญํ• 
์กฐ์ง ์ˆ˜์ค€ ์•ก์„ธ์Šค ์ •์ฑ… ๋˜๋Š” ๋ฒ”์œ„๊ฐ€ ์ง€์ •๋œ ์ •์ฑ… ๋งŒ๋“ค๊ธฐ

๊ถŒํ•œ: accesscontextmanager.policies.create

๊ถŒํ•œ์„ ์ œ๊ณตํ•˜๋Š” ์—ญํ• : Access Context Manager ํŽธ์ง‘์ž ์—ญํ• (roles/accesscontextmanager.policyEditor)

์กฐ์ง ์ˆ˜์ค€ ์•ก์„ธ์Šค ์ •์ฑ… ๋˜๋Š” ๋ฒ”์œ„๊ฐ€ ์ง€์ •๋œ ์ •์ฑ… ๋‚˜์—ด

๊ถŒํ•œ: accesscontextmanager.policies.list

๊ถŒํ•œ์„ ์ œ๊ณตํ•˜๋Š” ์—ญํ• :
  • Access Context Manager ํŽธ์ง‘์ž ์—ญํ• (roles/accesscontextmanager.policyEditor)
  • Access Context Manager ๋ฆฌ๋” ์—ญํ• (roles/accesscontextmanager.policyReader)

์กฐ์ง ์ˆ˜์ค€์—์„œ ๊ถŒํ•œ์ด ์žˆ๋Š” ๊ฒฝ์šฐ์—๋งŒ ๋ฒ”์œ„ ์ง€์ • ์ •์ฑ…์„ ๋งŒ๋“ค๊ฑฐ๋‚˜ ๋‚˜์—ดํ•˜๊ฑฐ๋‚˜ ์œ„์ž„ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋ฒ”์œ„๊ฐ€ ์ง€์ •๋œ ์ •์ฑ…์„ ๋งŒ๋“  ํ›„์—๋Š” ๋ฒ”์œ„๊ฐ€ ์ง€์ •๋œ ์ •์ฑ…์— IAM binding์„ ์ถ”๊ฐ€ํ•˜์—ฌ ์ •์ฑ…์„ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ๋Š” ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์กฐ์ง ์ˆ˜์ค€์—์„œ ๋ถ€์—ฌ๋œ ๊ถŒํ•œ์€ ์กฐ์ง ์ˆ˜์ค€ ์ •์ฑ… ๋ฐ ๋ชจ๋“  ๋ฒ”์œ„ ์ •์ฑ…์„ ํฌํ•จํ•œ ๋ชจ๋“  ์•ก์„ธ์Šค ์ •์ฑ…์— ์ ์šฉ๋ฉ๋‹ˆ๋‹ค.

๋‹ค์Œ๊ณผ ๊ฐ™์€ ์‚ฌ์ „ ์ •์˜๋œ IAM ์—ญํ• ์—์„œ ์„œ๋น„์Šค ๊ฒฝ๊ณ„์™€ ์•ก์„ธ์Šค ์ˆ˜์ค€์„ ๋ณด๊ฑฐ๋‚˜ ๊ตฌ์„ฑํ•˜๋Š” ๋ฐ ํ•„์š”ํ•œ ๊ถŒํ•œ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

  • Access Context Manager ๊ด€๋ฆฌ์ž(roles/accesscontextmanager.policyAdmin)
  • Access Context Manager ํŽธ์ง‘์ž(roles/accesscontextmanager.policyEditor)
  • Access Context Manager ๋ฆฌ๋”(roles/accesscontextmanager.policyReader)

์ด๋Ÿฌํ•œ ์—ญํ•  ์ค‘ ํ•˜๋‚˜๋ฅผ ๋ถ€์—ฌํ•˜๋ ค๋ฉด Google Cloud ์ฝ˜์†”์„ ์‚ฌ์šฉํ•˜๊ฑฐ๋‚˜ gcloud CLI์—์„œ ๋‹ค์Œ ๋ช…๋ น์–ด ์ค‘ ํ•˜๋‚˜๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค. ORGANIZATION_ID๋ฅผ Google Cloud์กฐ์ง์˜ ID๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.

์ฝ๊ธฐ-์“ฐ๊ธฐ ์•ก์„ธ์Šค๋ฅผ ํ—ˆ์šฉํ•˜๋Š” ๊ด€๋ฆฌ์ž ๊ด€๋ฆฌ ์—ญํ•  ๋ถ€์—ฌ

gcloud organizations add-iam-policy-binding ORGANIZATION_ID \
    --member="user:example@customer.org" \
    --role="roles/accesscontextmanager.policyAdmin"

์ฝ๊ธฐ-์“ฐ๊ธฐ ์•ก์„ธ์Šค๋ฅผ ํ—ˆ์šฉํ•˜๋Š” ๊ด€๋ฆฌ์ž ํŽธ์ง‘์ž ์—ญํ•  ๋ถ€์—ฌ

gcloud organizations add-iam-policy-binding ORGANIZATION_ID \
    --member="user:example@customer.org" \
    --role="roles/accesscontextmanager.policyEditor"

์ฝ๊ธฐ ์ „์šฉ ์•ก์„ธ์Šค๋ฅผ ํ—ˆ์šฉํ•˜๋Š” ๊ด€๋ฆฌ์ž ๋ฆฌ๋” ์—ญํ•  ๋ถ€์—ฌ

gcloud organizations add-iam-policy-binding ORGANIZATION_ID \
    --member="user:example@customer.org" \
    --role="roles/accesscontextmanager.policyReader"