שימוש במדיניות ארגונית בהתאמה אישית

בדף הזה מוסבר איך להשתמש באילוצים מותאמים אישית של שירות מדיניות הארגון כדי להגביל פעולות ספציפיות במשאבים הבאים של Google Cloud :

  • clouddeploy.googleapis.com/Automation
  • clouddeploy.googleapis.com/CustomTargetType
  • clouddeploy.googleapis.com/DeliveryPipeline
  • clouddeploy.googleapis.com/DeployPolicy
  • clouddeploy.googleapis.com/Release
  • clouddeploy.googleapis.com/Rollout
  • clouddeploy.googleapis.com/Target

מידע נוסף על מדיניות הארגון זמין במאמר בנושא מדיניות ארגונית בהתאמה אישית.

מידע על מדיניות הארגון ואילוצים

שירות מדיניות הארגון של Google Cloud מאפשר לכם לקבל שליטה מרוכזת ופרוגרמטית על המשאבים של הארגון. אדמינים של מדיניות הארגון יכולים להגדיר מדיניות ארגונית, שהיא קבוצה של הגבלות שנקראות אילוצים, שחלות על משאבים ב-Google Cloud ועל משאבים שנגזרים מהם בGoogle Cloud היררכיית המשאבים. אפשר לאכוף את מדיניות הארגון ברמת הארגון, התיקייה או הפרויקט.

שירות מדיניות הארגון מספק אילוצים מנוהלים מובנים עבור שירותים שונים של Google Cloud . עם זאת, אם אתם רוצים שליטה מדויקת יותר בשדות הספציפיים שמוגבלים במדיניות הארגון, אתם יכולים גם ליצור אילוצים בהתאמה אישית ולהשתמש בהם במדיניות הארגון.

העברה בירושה של מדיניות

כברירת מחדל, מדיניות הארגון עוברת בירושה לצאצאים של המשאבים שבהם אתם אוכפים את המדיניות. לדוגמה, אם אוכפים מדיניות בתיקייה, Google Cloud המדיניות נאכפת בכל הפרויקטים בתיקייה. מידע נוסף על ההתנהגות הזו ועל שינוי שלה זמין במאמר בנושא כללי הערכה היררכיים.

לפני שמתחילים

  1. נכנסים לחשבון Google Cloud . אם אתם משתמשים חדשים ב- Google Cloud, צרו חשבון כדי שתוכלו להעריך את הביצועים של המוצרים שלנו בתרחישים מהעולם האמיתי. לקוחות חדשים מקבלים בחינם גם קרדיט בשווי 300$ להרצה, לבדיקה ולפריסה של עומסי העבודה.
  2. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

  3. Verify that billing is enabled for your Google Cloud project.

  4. התקינו את ה-CLI של Google Cloud.

  5. אם אתם משתמשים בספק זהויות חיצוני (IdP), קודם אתם צריכים להיכנס ל-CLI של gcloud באמצעות המאגר המאוחד לניהול זהויות.

  6. כדי לאתחל את ה-CLI של gcloud, הריצו את הפקודה הבאה:

    gcloud init
  7. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

  8. Verify that billing is enabled for your Google Cloud project.

  9. התקינו את ה-CLI של Google Cloud.

  10. אם אתם משתמשים בספק זהויות חיצוני (IdP), קודם אתם צריכים להיכנס ל-CLI של gcloud באמצעות המאגר המאוחד לניהול זהויות.

  11. כדי לאתחל את ה-CLI של gcloud, הריצו את הפקודה הבאה:

    gcloud init
  12. חשוב לוודא שאתם יודעים מהו מספר הארגון שלכם.

התפקידים הנדרשים

כדי לקבל את ההרשאות שדרושות לניהול מדיניות ארגונית בהתאמה אישית, צריך לבקש מהאדמין להקצות לכם את תפקיד ה-IAM‏ Organization Policy Administrator (אדמין של מדיניות ארגונית) ‏(roles/orgpolicy.policyAdmin) במשאב הארגון. כדי לקרוא הסבר על מתן תפקידים, ראו איך מנהלים את הגישה ברמת הפרויקט, התיקייה והארגון.

יכול להיות שאפשר לקבל את ההרשאות הנדרשות גם באמצעות תפקידים בהתאמה אישית או תפקידים מוגדרים מראש.

משאבים נתמכים ב-Cloud Deploy

בטבלה הבאה מפורטים המשאבים של Cloud Deploy שאפשר להפנות אליהם באילוצים בהתאמה אישית.

משאב שדה
clouddeploy.googleapis.com/Automation resource.annotations
resource.description
resource.rules.advanceRolloutRule.id
resource.rules.advanceRolloutRule.sourcePhases
resource.rules.advanceRolloutRule.wait
resource.rules.promoteReleaseRule.destinationPhase
resource.rules.promoteReleaseRule.destinationTargetId
resource.rules.promoteReleaseRule.id
resource.rules.promoteReleaseRule.wait
resource.rules.repairRolloutRule.id
resource.rules.repairRolloutRule.jobs
resource.rules.repairRolloutRule.phases
resource.rules.repairRolloutRule.repairPhases.retry.attempts
resource.rules.repairRolloutRule.repairPhases.retry.backoffMode
resource.rules.repairRolloutRule.repairPhases.retry.wait
resource.rules.repairRolloutRule.repairPhases.rollback.destinationPhase
resource.rules.repairRolloutRule.repairPhases.rollback.disableRollbackIfRolloutPending
resource.rules.timedPromoteReleaseRule.destinationPhase
resource.rules.timedPromoteReleaseRule.destinationTargetId
resource.rules.timedPromoteReleaseRule.id
resource.rules.timedPromoteReleaseRule.schedule
resource.rules.timedPromoteReleaseRule.timeZone
resource.selector.targets.id
resource.serviceAccount
resource.suspended
clouddeploy.googleapis.com/CustomTargetType resource.annotations
resource.customActions.deployAction
resource.customActions.includeSkaffoldModules.configs
resource.customActions.includeSkaffoldModules.git.path
resource.customActions.includeSkaffoldModules.git.ref
resource.customActions.includeSkaffoldModules.git.repo
resource.customActions.includeSkaffoldModules.googleCloudBuildRepo.path
resource.customActions.includeSkaffoldModules.googleCloudBuildRepo.ref
resource.customActions.includeSkaffoldModules.googleCloudBuildRepo.repository
resource.customActions.includeSkaffoldModules.googleCloudStorage.path
resource.customActions.includeSkaffoldModules.googleCloudStorage.source
resource.customActions.renderAction
resource.description
resource.name
clouddeploy.googleapis.com/DeliveryPipeline resource.annotations
resource.description
resource.name
resource.serialPipeline.stages.deployParameters.matchTargetLabels
resource.serialPipeline.stages.deployParameters.values
resource.serialPipeline.stages.profiles
resource.serialPipeline.stages.strategy.canary.canaryDeployment.percentages
resource.serialPipeline.stages.strategy.canary.canaryDeployment.postdeploy.actions
resource.serialPipeline.stages.strategy.canary.canaryDeployment.predeploy.actions
resource.serialPipeline.stages.strategy.canary.canaryDeployment.verify
resource.serialPipeline.stages.strategy.canary.customCanaryDeployment.phaseConfigs.percentage
resource.serialPipeline.stages.strategy.canary.customCanaryDeployment.phaseConfigs.phaseId
resource.serialPipeline.stages.strategy.canary.customCanaryDeployment.phaseConfigs.postdeploy.actions
resource.serialPipeline.stages.strategy.canary.customCanaryDeployment.phaseConfigs.predeploy.actions
resource.serialPipeline.stages.strategy.canary.customCanaryDeployment.phaseConfigs.profiles
resource.serialPipeline.stages.strategy.canary.customCanaryDeployment.phaseConfigs.verify
resource.serialPipeline.stages.strategy.canary.runtimeConfig.cloudRun.automaticTrafficControl
resource.serialPipeline.stages.strategy.canary.runtimeConfig.cloudRun.canaryRevisionTags
resource.serialPipeline.stages.strategy.canary.runtimeConfig.cloudRun.priorRevisionTags
resource.serialPipeline.stages.strategy.canary.runtimeConfig.cloudRun.stableRevisionTags
resource.serialPipeline.stages.strategy.canary.runtimeConfig.kubernetes.gatewayServiceMesh.deployment
resource.serialPipeline.stages.strategy.canary.runtimeConfig.kubernetes.gatewayServiceMesh.httpRoute
resource.serialPipeline.stages.strategy.canary.runtimeConfig.kubernetes.gatewayServiceMesh.podSelectorLabel
resource.serialPipeline.stages.strategy.canary.runtimeConfig.kubernetes.gatewayServiceMesh.routeDestinations.destinationIds
resource.serialPipeline.stages.strategy.canary.runtimeConfig.kubernetes.gatewayServiceMesh.routeDestinations.propagateService
resource.serialPipeline.stages.strategy.canary.runtimeConfig.kubernetes.gatewayServiceMesh.routeUpdateWaitTime
resource.serialPipeline.stages.strategy.canary.runtimeConfig.kubernetes.gatewayServiceMesh.service
resource.serialPipeline.stages.strategy.canary.runtimeConfig.kubernetes.gatewayServiceMesh.stableCutbackDuration
resource.serialPipeline.stages.strategy.canary.runtimeConfig.kubernetes.serviceNetworking.deployment
resource.serialPipeline.stages.strategy.canary.runtimeConfig.kubernetes.serviceNetworking.disablePodOverprovisioning
resource.serialPipeline.stages.strategy.canary.runtimeConfig.kubernetes.serviceNetworking.podSelectorLabel
resource.serialPipeline.stages.strategy.canary.runtimeConfig.kubernetes.serviceNetworking.service
resource.serialPipeline.stages.strategy.standard.postdeploy.actions
resource.serialPipeline.stages.strategy.standard.predeploy.actions
resource.serialPipeline.stages.strategy.standard.verify
resource.serialPipeline.stages.targetId
resource.suspended
clouddeploy.googleapis.com/DeployPolicy resource.annotations
resource.description
resource.rules.rolloutRestriction.actions
resource.rules.rolloutRestriction.id
resource.rules.rolloutRestriction.invokers
resource.rules.rolloutRestriction.timeWindows.oneTimeWindows.endDate
resource.rules.rolloutRestriction.timeWindows.oneTimeWindows.endTime
resource.rules.rolloutRestriction.timeWindows.oneTimeWindows.startDate
resource.rules.rolloutRestriction.timeWindows.oneTimeWindows.startTime
resource.rules.rolloutRestriction.timeWindows.timeZone
resource.rules.rolloutRestriction.timeWindows.weeklyWindows.daysOfWeek
resource.rules.rolloutRestriction.timeWindows.weeklyWindows.endTime
resource.rules.rolloutRestriction.timeWindows.weeklyWindows.startTime
resource.selectors.deliveryPipeline.id
resource.selectors.target.id
resource.suspended
clouddeploy.googleapis.com/Release resource.annotations
resource.buildArtifacts.image
resource.buildArtifacts.tag
resource.deployParameters
resource.description
resource.name
resource.skaffoldConfigPath
resource.skaffoldConfigUri
resource.skaffoldVersion
clouddeploy.googleapis.com/Rollout resource.annotations
resource.description
resource.name
resource.targetId
clouddeploy.googleapis.com/Target resource.annotations
resource.anthosCluster.membership
resource.associatedEntities[*].anthosClusters.membership
resource.associatedEntities[*].gkeClusters.cluster
resource.associatedEntities[*].gkeClusters.dnsEndpoint
resource.associatedEntities[*].gkeClusters.internalIp
resource.associatedEntities[*].gkeClusters.proxyUrl
resource.customTarget.customTargetType
resource.deployParameters
resource.description
resource.executionConfigs.artifactStorage
resource.executionConfigs.defaultPool.artifactStorage
resource.executionConfigs.defaultPool.serviceAccount
resource.executionConfigs.executionTimeout
resource.executionConfigs.privatePool.artifactStorage
resource.executionConfigs.privatePool.serviceAccount
resource.executionConfigs.privatePool.workerPool
resource.executionConfigs.serviceAccount
resource.executionConfigs.usages
resource.executionConfigs.verbose
resource.executionConfigs.workerPool
resource.gke.cluster
resource.gke.dnsEndpoint
resource.gke.internalIp
resource.gke.proxyUrl
resource.multiTarget.targetIds
resource.name
resource.requireApproval
resource.run.location

הגדרת אילוץ בהתאמה אישית

אילוץ בהתאמה אישית מוגדר בקובץ YAML לפי המשאבים, השיטות, התנאים והפעולות שנתמכים על ידי השירות שבו אתם אוכפים את מדיניות הארגון. התנאים להגבלות המותאמות אישית מוגדרים באמצעות Common Expression Language ‏ (CEL). מידע נוסף על יצירת תנאים באילוצים מותאמים אישית באמצעות CEL זמין בקטע על CEL במאמר יצירה וניהול של אילוצים מותאמים אישית.

המסוף

כדי ליצור אילוץ בהתאמה אישית:

  1. נכנסים לדף Organization policies במסוף Google Cloud .

    מעבר למדיניות הארגון

  2. בבורר הפרויקטים, בוחרים את הפרויקט שרוצים להגדיר לו את מדיניות הארגון.
  3. לוחצים על Custom constraint (הגבלה מותאמת אישית).
  4. בתיבה שם לתצוגה, מזינים שם שאנשים יכולים לקרוא לאילוץ. השם הזה משמש בהודעות שגיאה, ואפשר להשתמש בו לצורך זיהוי וניפוי באגים. אל תשתמשו בפרטים אישיים מזהים (PII) או במידע אישי רגיש בשמות לתצוגה, כי השם הזה עלול להיחשף בהודעות שגיאה. השדה הזה יכול להכיל עד 200 תווים.
  5. בתיבה Constraint ID (מזהה ההגבלה), מזינים את המזהה שרוצים להגדיר להגבלה החדשה בהתאמה אישית. אילוץ מותאם אישית יכול להכיל רק אותיות (כולל אותיות גדולות וקטנות) או מספרים, למשל custom.enableGkeTargets. השדה הזה יכול להכיל עד 70 תווים, לא כולל הקידומת (custom.), לדוגמה, organizations/123456789/customConstraints/custom. אל תכללו פרטים אישיים מזהים (PII) או נתונים רגישים במזהה האילוץ, כי הם עלולים להיחשף בהודעות שגיאה.
  6. בתיבה Description, מזינים תיאור של האילוץ שקל לקרוא ולהבין. התיאור הזה משמש כהודעת שגיאה כשמתרחשת הפרה של המדיניות. לכלול פרטים על הסיבה להפרת המדיניות ואיך לפתור אותה. אל תכללו בתיאור פרטים אישיים מזהים (PII) או מידע אישי רגיש, כי הם עלולים להיחשף בהודעות שגיאה. השדה הזה יכול להכיל עד 2,000 תווים.
  7. בתיבה Resource type, בוחרים את השם של Google Cloud משאב REST שמכיל את האובייקט והשדה שרוצים להגביל – לדוגמה, container.googleapis.com/NodePool. רוב סוגי המשאבים תומכים בעד 20 אילוצים מותאמים אישית. אם תנסו ליצור עוד אילוצים בהתאמה אישית, הפעולה תיכשל.
  8. בקטע