配置 VPC Service Controls

Managed Airflow(第 3 代) | Managed Airflow(第 2 代) | Managed Airflow(旧版第 1 代)

借助 VPC Service Controls,组织可以为 Google Cloud 资源定义边界,从而降低数据渗漏风险。

Managed Airflow 环境可以部署在服务边界内。通过使用 VPC Service Controls 配置您的环境,您可以在利用 Managed Airflow 的全代管式工作流编排功能的同时确保敏感数据的私密性。

VPC Service Controls 对 Managed Airflow 的支持意味着:

  • 现在可以选择 Managed Airflow 作为 VPC Service Controls 边界内的安全服务。
  • 将 Managed Airflow 使用的所有底层资源都配置为支持 VPC Service Controls 架构并遵循其规则。

使用 VPC Service Controls 部署 Managed Airflow 环境时,您可以:

  • 降低数据渗漏风险。
  • 防止因访问权限控制配置错误而导致数据泄露。
  • 降低恶意用户将数据复制到未经授权的 Google Cloud 资源或外部攻击者从互联网访问 Google Cloud 资源的风险。

关于 Managed Airflow 中的 VPC Service Controls

  • 所有 VPC Service Controls 网络限制也适用于您的 Managed Airflow 环境。如需了解详情,请参阅 VPC Service Controls 文档

使用共享 VPC 和 CMEK 的环境的边界

如果您的环境受到服务边界的保护,并且使用 共享 VPC客户管理的加密密钥 (CMEK)或同时使用两者,请确保 以下项目位于同一服务边界内:

  • 服务项目:包含 Managed Airflow 环境的项目。
  • 宿主项目:包含共享 VPC 网络的项目。
  • 托管 Cloud Key Management Service 密钥的项目。