์ธ๊ทธ๋ ˆ์Šค ๋ฐ ์ด๊ทธ๋ ˆ์Šค ์ •์ฑ… ๊ตฌ์„ฑ

์ด ํŽ˜์ด์ง€์—์„œ๋Š” VPC ์„œ๋น„์Šค ์ œ์–ด ๊ฒฝ๊ณ„์— ์ธ๊ทธ๋ ˆ์Šค ๋ฐ ์ด๊ทธ๋ ˆ์Šค ์ •์ฑ…์„ ๊ตฌ์„ฑํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค.

๊ธฐ์กด ๊ฒฝ๊ณ„์— ๋Œ€ํ•œ ์ธ๊ทธ๋ ˆ์Šค ๋ฐ ์ด๊ทธ๋ ˆ์Šค ์ •์ฑ…์„ ๊ตฌ์„ฑํ•˜๊ฑฐ๋‚˜ ๊ฒฝ๊ณ„๋ฅผ ๋งŒ๋“ค ๋•Œ ์ด ์ •์ฑ…์„ ํฌํ•จํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์„œ๋น„์Šค ๊ฒฝ๊ณ„์˜ ์ธ๊ทธ๋ ˆ์Šค ๋ฐ ์ด๊ทธ๋ ˆ์Šค ์ •์ฑ… ์—…๋ฐ์ดํŠธ

์ฝ˜์†”

  1. Google Cloud ์ฝ˜์†” ํƒ์ƒ‰ ๋ฉ”๋‰ด์—์„œ ๋ณด์•ˆ์„ ํด๋ฆญํ•œ ๋‹ค์Œ VPC ์„œ๋น„์Šค ์ œ์–ด๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

    VPC ์„œ๋น„์Šค ์ œ์–ด ํŽ˜์ด์ง€๋กœ ์ด๋™

  2. ๊ธฐ์กด ์„œ๋น„์Šค ๊ฒฝ๊ณ„๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

  3. ์ˆ˜์ •์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  4. ์„œ๋น„์Šค ๊ฒฝ๊ณ„ ์ˆ˜์ • ํŽ˜์ด์ง€์—์„œ ์ธ๊ทธ๋ ˆ์Šค ์ •์ฑ… ๋˜๋Š” ์ด๊ทธ๋ ˆ์Šค ์ •์ฑ…์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  5. ์ˆ˜์ •ํ•˜๋ ค๋Š” ์ธ๊ทธ๋ ˆ์Šค ๋˜๋Š” ์ด๊ทธ๋ ˆ์Šค ๊ทœ์น™์„ ํŽผ์นฉ๋‹ˆ๋‹ค.

  6. From ๋ฐ To ์„น์…˜์—์„œ ๋ณ€๊ฒฝํ•˜๋ ค๋Š” ์ธ๊ทธ๋ ˆ์Šค ๋˜๋Š” ์ด๊ทธ๋ ˆ์Šค ๊ทœ์น™ ์†์„ฑ์„ ์ˆ˜์ •ํ•ฉ๋‹ˆ๋‹ค.

    YAML ์†์„ฑ ์ฐธ์กฐ๋Š” Google Cloud ์ฝ˜์†”์—์„œ ์ฐพ์„ ์ˆ˜ ์žˆ๋Š” ์†์„ฑ๊ณผ ๋™์ผํ•œ ์†์„ฑ์„ ์„ค๋ช…ํ•˜์ง€๋งŒ Google Cloud ์ฝ˜์†”์—์„œ๋Š” ์•ฝ๊ฐ„ ๋‹ค๋ฅธ ์ด๋ฆ„์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

  7. ์ €์žฅ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

gcloud

๊ฒฝ๊ณ„ ์ •์ฑ…์„ ์—…๋ฐ์ดํŠธํ•˜๋ ค๋ฉด variables๋ฅผ ์ ์ ˆํ•œ ๊ฐ’์œผ๋กœ ๋ฐ”๊ฟ” ๋‹ค์Œ ๋ช…๋ น์–ด ์ค‘ ํ•˜๋‚˜๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

gcloud access-context-manager perimeters update PERIMETER_NAME --set-ingress-policies=INGRESS-FILENAME.yaml

gcloud access-context-manager perimeters update PERIMETER_NAME --set-egress-policies=EGRESS-FILENAME.yaml

์˜ˆ๋ฅผ ๋“ค๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

gcloud access-context-manager perimeters update my-perimeter --set-ingress-policies=my-ingress-rule.yaml

์ธ๊ทธ๋ ˆ์Šค ๋ฐ ์ด๊ทธ๋ ˆ์Šค ๊ทœ์น™์„ YAML ํŒŒ์ผ๋กœ ๊ตฌ์„ฑํ•˜๋Š” ๋ฐฉ๋ฒ•์— ๊ด€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์ธ๊ทธ๋ ˆ์Šค ๊ทœ์น™ ์ฐธ์กฐ ๋ฐ ์ด๊ทธ๋ ˆ์Šค ๊ทœ์น™ ์ฐธ์กฐ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

๊ฒฝ๊ณ„ ์ƒ์„ฑ ์ค‘์— ์ธ๊ทธ๋ ˆ์Šค ๋ฐ ์ด๊ทธ๋ ˆ์Šค ์ •์ฑ… ์„ค์ •

์ฝ˜์†”

  1. Google Cloud ์ฝ˜์†” ํƒ์ƒ‰ ๋ฉ”๋‰ด์—์„œ ๋ณด์•ˆ์„ ํด๋ฆญํ•œ ๋‹ค์Œ VPC ์„œ๋น„์Šค ์ œ์–ด๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

    VPC ์„œ๋น„์Šค ์ œ์–ด ํŽ˜์ด์ง€๋กœ ์ด๋™

  2. ์ƒˆ ๊ฒฝ๊ณ„๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

    ๋‹ค๋ฅธ ์„œ๋น„์Šค ๊ฒฝ๊ณ„ ๊ตฌ์„ฑ์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์„œ๋น„์Šค ๊ฒฝ๊ณ„ ๋งŒ๋“ค๊ธฐ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

  3. ์„œ๋น„์Šค ๊ฒฝ๊ณ„ ๋งŒ๋“ค๊ธฐ ํŽ˜์ด์ง€์—์„œ ์ธ๊ทธ๋ ˆ์Šค ์ •์ฑ… ๋˜๋Š” ์ด๊ทธ๋ ˆ์Šค ์ •์ฑ…์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  4. ๊ทœ์น™ ์ถ”๊ฐ€๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

  5. From ๋ฐ To ์„น์…˜์—์„œ ๊ตฌ์„ฑํ•˜๋ ค๋Š” ์ธ๊ทธ๋ ˆ์Šค ๋˜๋Š” ์ด๊ทธ๋ ˆ์Šค ๊ทœ์น™ ์†์„ฑ์„ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

    YAML ์†์„ฑ ์ฐธ์กฐ๋Š” Google Cloud ์ฝ˜์†”์—์„œ ์ฐพ์„ ์ˆ˜ ์žˆ๋Š” ์†์„ฑ๊ณผ ๋™์ผํ•œ ์†์„ฑ์„ ์„ค๋ช…ํ•˜์ง€๋งŒ Google Cloud ์ฝ˜์†”์—์„œ๋Š” ์•ฝ๊ฐ„ ๋‹ค๋ฅธ ์ด๋ฆ„์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

  6. ๋งŒ๋“ค๊ธฐ๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

gcloud

๊ฒฝ๊ณ„ ์ƒ์„ฑ ์ค‘์— ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•˜์—ฌ ์ธ๊ทธ๋ ˆ์Šค/์ด๊ทธ๋ ˆ์Šค ์ •์ฑ…์„ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

gcloud access-context-manager perimeters create PERIMETER_NAME --title=TITLE --ingress-policies=INGRESS-FILENAME.yaml --restricted-services=SERVICE --resources="projects/PROJECT"

gcloud access-context-manager perimeters create PERIMETER_NAME --title=TITLE --egress-policies=-EGRESS-FILENAME.yaml --restricted-services=SERVICE --resources="projects/PROJECT"

์˜ˆ๋ฅผ ๋“ค๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

gcloud access-context-manager perimeters create my-perimeter --title=perimeter-for-project-1 --ingress-policies=my-ingress-rule.yaml --restricted-services=storage.googelapis.com --resources="projects/myproject"

์ธ๊ทธ๋ ˆ์Šค ๋ฐ ์ด๊ทธ๋ ˆ์Šค ๊ทœ์น™์„ YAML ํŒŒ์ผ๋กœ ๊ตฌ์„ฑํ•˜๋Š” ๋ฐฉ๋ฒ•์— ๊ด€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ์ธ๊ทธ๋ ˆ์Šค ๊ทœ์น™ ์ฐธ์กฐ ๋ฐ ์ด๊ทธ๋ ˆ์Šค ๊ทœ์น™ ์ฐธ์กฐ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.