Google Cloud 提供了两种组织政策限制条件,以帮助确保在整个组织范围内使用 CMEK:
constraints/gcp.restrictNonCmekServices用于要求 CMEK 保护。constraints/gcp.restrictCmekCryptoKeyProjects用于限制哪些 Cloud KMS 密钥可用于 CMEK 保护。
CMEK 组织政策仅适用于 支持的 Google Cloud 服务中新创建的资源。
所需的角色
为了确保每个用户在创建资源时都具有检查组织政策所需的权限,请让您的管理员为组织中的每个用户授予Organization Policy Viewer (roles/orgpolicy.policyViewer) IAM 角色。如需详细了解如何授予角色,请参阅管理对项目、文件夹和组织的访问权限。
此预定义角色包含 在创建资源时检查组织政策所需的权限。如需查看所需的确切权限,请展开所需权限部分:
所需权限
在创建资源时检查组织政策需要以下权限:
-
如需查看完整的组织政策详细信息:
orgpolicy.policy.get -
如需在创建资源时检查组织政策:
orgpolicy.policies.check
您的管理员也可以使用自定义角色或其他预定义角色向每个用户授予这些权限。
当组织政策处于有效状态时,创建受 CMEK 密钥保护的资源需要 orgpolicy.policies.check 权限
Google Cloud 。没有此权限的用户可以使用 Google Cloud 控制台创建受 CMEK 保护的
资源,但他们可以选择 restrictCmekCryptoKeyProjects 限制条件不允许的 CMEK 密钥。如果选择的密钥不符合此限制条件,资源创建最终会失败。
要求 CMEK 保护
如需为您的组织要求 CMEK 保护,请配置 constraints/gcp.restrictNonCmekServices 组织政策。
作为列表限制条件,此限制条件接受的值是 Google Cloud
服务名称(例如 bigquery.googleapis.com)。如需使用此限制条件,请
提供 Google Cloud 服务名称列表并将限制条件设置为
拒绝。如果资源不受 CMEK 保护,此配置会阻止在这些服务中创建资源。换句话说,如果不指定 Cloud KMS 密钥,则在服务中创建资源的请求将失败。此外,此限制条件还会阻止从这些服务中的资源移除 CMEK 保护。此限制条件
只能应用于支持的服务。
限制使用 Cloud KMS 密钥进行 CMEK
如需限制哪些 Cloud KMS 密钥可用于 CMEK 保护,请配置 constraints/gcp.restrictCmekCryptoKeyProjects 限制条件。
作为列表限制条件,它接受的值是资源层次结构指示符(例如
projects/PROJECT_ID
under:folders/FOLDER_ID 和
under:organizations/ORGANIZATION_ID)。要使用此限制条件,请
配置资源层次结构指示符列表并将限制条件
设置为 允许。此配置会限制支持的服务,以便仅从列出的项目、文件夹和组织中选择 CMEK 密钥。
如果没有来自允许资源之一的 Cloud KMS 密钥,则无法在已配置的服务中成功创建受 CMEK 保护的资源。如果已配置,此限制条件将应用于所有支持的服务
。
支持的服务
| 服务 | 要求 CMEK 时的限制条件值 |
|---|---|
| Agent Assist | dialogflow.googleapis.com |
| Agent Search | discoveryengine.googleapis.com |
| AlloyDB for PostgreSQL | alloydb.googleapis.com |
| Apigee | apigee.googleapis.com |
| Application Integration | integrations.googleapis.com |
| Artifact Registry | artifactregistry.googleapis.com |
| Backup and DR Service | backupdr.googleapis.com |
| Backup for GKE | gkebackup.googleapis.com |
| BigQuery | bigquery.googleapis.com |
| Bigtable | bigtable.googleapis.com |
| Cloud Data Fusion | datafusion.googleapis.com |
| Cloud Logging | logging.googleapis.com |
| Cloud Run | run.googleapis.com |
| Cloud Run functions | cloudfunctions.googleapis.com |
| Cloud SQL | sqladmin.googleapis.com |
| Cloud Storage | storage.googleapis.com |
| Cloud Tasks | cloudtasks.googleapis.com |
| Cloud TPU | tpu.googleapis.com |
| Cloud Workstations | workstations.googleapis.com |
| Colab Enterprise | aiplatform.googleapis.com |
| Compute Engine | compute.googleapis.com |
| Customer Experience Insights | contactcenterinsights.googleapis.com |
| 数据洞察 | datastudio.googleapis.com |
| Database Migration Service | datamigration.googleapis.com |
| Dataflow | dataflow.googleapis.com |
| Dataform | dataform.googleapis.com |
| Datastream | datastream.googleapis.com |
| Dialogflow CX | dialogflow.googleapis.com |
| Document AI | documentai.googleapis.com |
| Eventarc Advanced(预览版) | eventarc.googleapis.com |
| Eventarc Standard | eventarc.googleapis.com |
| Filestore | file.googleapis.com |
| Firestore | firestore.googleapis.com |
| Gemini Enterprise | discoveryengine.googleapis.com |
| Google Cloud Managed Lustre | lustre.googleapis.com |
| Google Cloud Managed Service for Apache Kafka | managedkafka.googleapis.com |
| Google Cloud NetApp Volumes | netapp.googleapis.com |
| Google Cloud Observability(预览版) | observability.googleapis.com |
| Google Kubernetes Engine(预览版) | container.googleapis.com |
| Google Security Operations | chronicleservicemanager.googleapis.com |
| Knowledge Catalog | dataplex.googleapis.com |
| Looker (Google Cloud Core) | looker.googleapis.com |
| Managed Service for Apache Airflow | composer.googleapis.com |
| Managed Service for Apache Spark | dataproc.googleapis.com |
| Memorystore for Redis | redis.googleapis.com |
| Memorystore for Redis Cluster |