שימוש במדיניות ארגונית בהתאמה אישית

בדף הזה מוסבר איך להשתמש באילוצים מותאמים אישית של שירות מדיניות הארגון כדי להגביל פעולות ספציפיות במשאבים הבאים של Google Cloud :

  • cloudbuild.googleapis.com/BitbucketServerConfig
  • cloudbuild.googleapis.com/Build
  • cloudbuild.googleapis.com/BuildTrigger
  • cloudbuild.googleapis.com/Connection
  • cloudbuild.googleapis.com/GithubEnterpriseConfig
  • cloudbuild.googleapis.com/Repository
  • cloudbuild.googleapis.com/WorkerPool

מידע נוסף על מדיניות הארגון זמין במאמר בנושא מדיניות ארגונית בהתאמה אישית.

מידע על מדיניות הארגון ואילוצים

שירות מדיניות הארגון של Google Cloud מאפשר לכם לקבל שליטה מרוכזת ופרוגרמטית על המשאבים של הארגון. בתור אדמינים של מדיניות הארגון, אתם יכולים להגדיר מדיניות ארגונית, שהיא קבוצה של הגבלות שנקראות אילוצים שחלות על משאבים ב-Google Cloud ועל משאבים שנגזרים מהם בGoogle Cloud היררכיית המשאבים. אפשר לאכוף את מדיניות הארגון ברמת הארגון, התיקייה או הפרויקט.

שירות מדיניות הארגון מספק אילוצים מנוהלים מובנים עבור שירותים שונים של Google Cloud . עם זאת, אם אתם רוצים שליטה מדויקת יותר בשדות הספציפיים שמוגבלים במדיניות הארגון, אתם יכולים גם ליצור אילוצים בהתאמה אישית ולהשתמש בהם במדיניות הארגון.

העברה בירושה של מדיניות

כברירת מחדל, מדיניות הארגון עוברת בירושה לצאצאים של המשאבים שבהם אתם אוכפים את המדיניות. לדוגמה, אם אוכפים מדיניות בתיקייה, Google Cloud המדיניות נאכפת בכל הפרויקטים בתיקייה. מידע נוסף על ההתנהגות הזו ועל שינוי שלה זמין במאמר בנושא כללי הערכה היררכיים.

לפני שמתחילים

  1. נכנסים לחשבון Google Cloud . אם אתם משתמשים חדשים ב- Google Cloud, צרו חשבון כדי שתוכלו להעריך את הביצועים של המוצרים שלנו בתרחישים מהעולם האמיתי. לקוחות חדשים מקבלים בחינם גם קרדיט בשווי 300$ להרצה, לבדיקה ולפריסה של עומסי העבודה.
  2. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

  3. Verify that billing is enabled for your Google Cloud project.

  4. התקינו את ה-CLI של Google Cloud.

  5. אם אתם משתמשים בספק זהויות חיצוני (IdP), קודם אתם צריכים להיכנס ל-CLI של gcloud באמצעות המאגר המאוחד לניהול זהויות.

  6. כדי לאתחל את ה-CLI של gcloud, הריצו את הפקודה הבאה:

    gcloud init
  7. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

  8. Verify that billing is enabled for your Google Cloud project.

  9. התקינו את ה-CLI של Google Cloud.

  10. אם אתם משתמשים בספק זהויות חיצוני (IdP), קודם אתם צריכים להיכנס ל-CLI של gcloud באמצעות המאגר המאוחד לניהול זהויות.

  11. כדי לאתחל את ה-CLI של gcloud, הריצו את הפקודה הבאה:

    gcloud init
  12. חשוב לוודא שאתם יודעים מהו מספר הארגון שלכם.

התפקידים הנדרשים

כדי לקבל את ההרשאות שדרושות לניהול מדיניות ארגונית בהתאמה אישית, צריך לבקש מהאדמין להקצות לכם את תפקיד ה-IAM‏ Organization Policy Administrator (אדמין של מדיניות ארגונית) ‏(roles/orgpolicy.policyAdmin) במשאב הארגון. כדי לקרוא הסבר על מתן תפקידים, ראו איך מנהלים את הגישה ברמת הפרויקט, התיקייה והארגון.

יכול להיות שאפשר לקבל את ההרשאות הנדרשות גם באמצעות תפקידים בהתאמה אישית או תפקידים מוגדרים מראש.

משאבים נתמכים ב-Cloud Build

בטבלה הבאה מפורטים המשאבים של Cloud Build שאפשר להפנות אליהם באילוצים בהתאמה אישית.

משאב שדה
cloudbuild.googleapis.com/BitbucketServerConfig resource.apiKey
resource.hostUri
resource.name
resource.peeredNetwork
resource.peeredNetworkIpRange
resource.secrets.adminAccessTokenVersionName
resource.secrets.readAccessTokenVersionName
resource.secrets.webhookSecretVersionName
resource.sslCa
resource.username
cloudbuild.googleapis.com/Build resource.artifacts.goModules.modulePath
resource.artifacts.goModules.moduleVersion
resource.artifacts.goModules.repositoryLocation
resource.artifacts.goModules.repositoryName
resource.artifacts.goModules.repositoryProjectId
resource.artifacts.goModules.sourcePath
resource.artifacts.images
resource.artifacts.mavenArtifacts.artifactId
resource.artifacts.mavenArtifacts.groupId
resource.artifacts.mavenArtifacts.path
resource.artifacts.mavenArtifacts.repository
resource.artifacts.mavenArtifacts.version
resource.artifacts.npmPackages.packagePath
resource.artifacts.npmPackages.repository
resource.artifacts.objects.location
resource.artifacts.objects.paths
resource.artifacts.pythonPackages.paths
resource.artifacts.pythonPackages.repository
resource.availableSecrets.inline.envMap
resource.availableSecrets.inline.kmsKeyName
resource.availableSecrets.secretManager.env
resource.availableSecrets.secretManager.versionName
resource.dependencies.empty
resource.dependencies.gitSource.depth
resource.dependencies.gitSource.destPath
resource.dependencies.gitSource.recurseSubmodules
resource.dependencies.gitSource.repository.developerConnect
resource.dependencies.gitSource.repository.url
resource.dependencies.gitSource.revision
resource.gitConfig.http.proxySecretVersionName
resource.images
resource.logsBucket
resource.options.automapSubstitutions
resource.options.defaultLogsBucketBehavior
resource.options.diskSizeGb
resource.options.dynamicSubstitutions
resource.options.enableStructuredLogging
resource.options.env
resource.options.logging
resource.options.logStreamingOption
resource.options.machineType
resource.options.pool.name
resource.options.pubsubTopic
resource.options.requestedVerifyOption
resource.options.secretEnv
resource.options.sourceProvenanceHash
resource.options.substitutionOption
resource.options.volumes.name
resource.options.volumes.path
resource.queueTtl
resource.secrets.kmsKeyName
resource.secrets.secretEnv
resource.serviceAccount
resource.source.connectedRepository.dir
resource.source.connectedRepository.repository
resource.source.connectedRepository.revision
resource.source.developerConnectConfig.dir
resource.source.developerConnectConfig.gitRepositoryLink
resource.source.developerConnectConfig.revision
resource.source.gitSource.dir
resource.source.gitSource.revision
resource.source.gitSource.url
resource.source.repoSource.branchName
resource.source.repoSource.commitSha
resource.source.repoSource.dir
resource.source.repoSource.invertRegex
resource.source.repoSource.projectId
resource.source.repoSource.repoName
resource.source.repoSource.substitutions
resource.source.repoSource.tagName
resource.source.storageSource.bucket
resource.source.storageSource.generation
resource.source.storageSource.object
resource.source.storageSource.sourceFetcher
resource.source.storageSourceManifest.bucket
resource.source.storageSourceManifest.generation
resource.source.storageSourceManifest.object
resource.steps.allowExitCodes
resource.steps.allowFailure
resource.steps.args
resource.steps.automapSubstitutions
resource.steps.dir
resource.steps.entrypoint
resource.steps.env
resource.steps.id
resource.steps.name
resource.steps.script
resource.steps.secretEnv
resource.steps.timeout
resource.steps.volumes.name
resource.steps.volumes.path
resource.steps.waitFor
resource.substitutions
resource.tags
resource.timeout
cloudbuild.googleapis.com/BuildTrigger resource.approvalConfig.approvalRequired
resource.autodetect
resource.bitbucketServerTriggerConfig.bitbucketServerConfigResource
resource.bitbucketServerTriggerConfig.projectKey
resource.bitbucketServerTriggerConfig.pullRequest.branch
resource.bitbucketServerTriggerConfig.pullRequest.commentControl
resource.bitbucketServerTriggerConfig.pullRequest.invertRegex
resource.bitbucketServerTriggerConfig.push.branch
resource.bitbucketServerTriggerConfig.push.invertRegex
resource.bitbucketServerTriggerConfig.push.tag
resource.bitbucketServerTriggerConfig.repoSlug
resource.build.artifacts.images
resource.build.artifacts.mavenArtifacts.artifactId
resource.build.artifacts.mavenArtifacts.groupId
resource.build.artifacts.mavenArtifacts.path
resource.build.artifacts.mavenArtifacts.repository
resource.build.artifacts.mavenArtifacts.version
resource.build.artifacts.npmPackages.packagePath
resource.build.artifacts.npmPackages.repository
resource.build.artifacts.objects.location
resource.build.artifacts.objects.paths
resource.build.artifacts.pythonPackages.paths
resource.build.artifacts.pythonPackages.repository
resource.build.availableSecrets.inline.envMap
resource.build.availableSecrets.inline.kmsKeyName
resource.build.availableSecrets.secretManager.env
resource.build.availableSecrets.secretManager.versionName
resource.build.dependencies.empty
resource.build.dependencies.gitSource.depth
resource.build.dependencies.gitSource.destPath
resource.build.dependencies.gitSource.recurseSubmodules
resource.build.dependencies.gitSource.repository.developerConnect
resource.build.dependencies.gitSource.repository.url
resource.build.dependencies.gitSource.revision
resource.build.gitConfig.http.proxySecretVersionName
resource.build.images
resource.build.logsBucket
resource.build.options.automapSubstitutions
resource.build.options.defaultLogsBucketBehavior
resource.build.options.diskSizeGb
resource.build.options.dynamicSubstitutions
resource.build.options.env
resource.build.options.logging
resource.build.options.logStreamingOption
resource.build.options.machineType
resource.build.options.pool.name
resource.build.options.requestedVerifyOption
resource.build.options.secretEnv
resource.build.options.sourceProvenanceHash
resource.build.options.substitutionOption
resource.build.options.volumes.name
resource.build.options.volumes.path
resource.build.queueTtl
resource.build.secrets.kmsKeyName
resource.build.secrets.secretEnv
resource.build.serviceAccount
resource.build.source.connectedRepository.dir
resource.build.source.connectedRepository.repository
resource.build.source.connectedRepository.revision
resource.build.source.developerConnectConfig.dir
resource.build.source.developerConnectConfig.gitRepositoryLink
resource.build.source.developerConnectConfig.revision
resource.build.source.gitSource.dir
resource.build.source.gitSource.revision
resource.build.source.gitSource.url
resource.build.source.repoSource.branchName
resource.build.source.repoSource.commitSha
resource.build.source.repoSource.dir
resource.build.source.repoSource.invertRegex
resource.build.source.repoSource.projectId
resource.build.source.repoSource.repoName
resource.build.source.repoSource.substitutions
resource.build.source.repoSource.tagName
resource.build.source.storageSource.bucket
resource.build.source.storageSource.generation
resource.build.source.storageSource.object
resource.build.source.storageSource.sourceFetcher
resource.build.source.storageSourceManifest.bucket
resource.build.source.storageSourceManifest.generation
resource.build.source.storageSourceManifest.object
resource.build.steps.allowExitCodes
resource.build.steps.allowFailure
resource.build.steps.args
resource.build.steps.automapSubstitutions
resource.build.steps.dir
resource.build.steps.entrypoint
resource.build.steps.env
resource.build.steps.id
resource.build.steps.name
resource.build.steps.script
resource.build.steps.secretEnv
resource.build.steps.timeout
resource.build.steps.volumes.name
resource.build.steps.volumes.path
resource.build.steps.waitFor
resource.build.substitutions
resource.build.tags
resource.build.timeout
resource.description
resource.disabled
resource.eventType
resource.filename
resource.filter
resource.gitFileSource.bitbucketServerConfig
resource.gitFileSource.githubEnterpriseConfig
resource.gitFileSource.path
resource.gitFileSource.repository
resource.gitFileSource.repoType
resource.gitFileSource.revision
resource.gitFileSource.uri
resource.github.enterpriseConfigResourceName
resource.github.name
resource.github.owner
resource.github.pullRequest.branch
resource.github.pullRequest.commentControl
resource.github.pullRequest.invertRegex
resource.github.push.branch
resource.github.push.invertRegex
resource.github.push.tag
resource.gitlabEnterpriseEventsConfig.gitlabConfigResource
resource.gitlabEnterpriseEventsConfig.projectNamespace
resource.gitlabEnterpriseEventsConfig.pullRequest.branch
resource.gitlabEnterpriseEventsConfig.pullRequest.commentControl
resource.gitlabEnterpriseEventsConfig.pullRequest.invertRegex
resource.gitlabEnterpriseEventsConfig.push.branch
resource.gitlabEnterpriseEventsConfig.push.invertRegex
resource.gitlabEnterpriseEventsConfig.push.tag
resource.ignoredFiles
resource.includeBuildLogs
resource.includedFiles
resource.name
resource.pubsubConfig.serviceAccountEmail
resource.pubsubConfig.topic
resource.repositoryEventConfig.pullRequest.branch
resource.repositoryEventConfig.pullRequest.commentControl
resource.repositoryEventConfig.pullRequest.invertRegex
resource.repositoryEventConfig.push.branch
resource.repositoryEventConfig.push.invertRegex
resource.repositoryEventConfig.push.tag
resource.repositoryEventConfig.repository
resource.resourceName
resource.serviceAccount
resource.sourceToBuild.bitbucketServerConfig
resource.sourceToBuild.githubEnterpriseConfig
resource.sourceToBuild.ref
resource.sourceToBuild.repository
resource.sourceToBuild.repoType
resource.sourceToBuild.uri
resource.substitutions
resource.tags
resource.triggerTemplate.branchName
resource.triggerTemplate.commitSha
resource.triggerTemplate.dir
resource.triggerTemplate.invertRegex
resource.triggerTemplate.projectId
resource.triggerTemplate.repoName
resource.triggerTemplate.substitutions
resource.triggerTemplate.tagName
resource.webhookConfig.secret
cloudbuild.googleapis.com/Connection resource.annotations
resource.bitbucketCloudConfig.authorizerCredential.userTokenSecretVersion
resource.bitbucketCloudConfig.readAuthorizerCredential.userTokenSecretVersion
resource.bitbucketCloudConfig.webhookSecretSecretVersion
resource.bitbucketCloudConfig.workspace
resource.bitbucketDataCenterConfig.authorizerCredential.userTokenSecretVersion
resource.bitbucketDataCenterConfig.hostUri
resource.bitbucketDataCenterConfig.readAuthorizerCredential.userTokenSecretVersion
resource.bitbucketDataCenterConfig.serviceDirectoryConfig.service
resource.bitbucketDataCenterConfig.sslCa
resource.bitbucketDataCenterConfig.webhookSecretSecretVersion
resource.disabled
resource.githubConfig.appInstallationId
resource.githubConfig.authorizerCredential.oauthTokenSecretVersion
resource.githubEnterpriseConfig.apiKey
resource.githubEnterpriseConfig.appId
resource.githubEnterpriseConfig.appInstallationId
resource.githubEnterpriseConfig.appSlug
resource.githubEnterpriseConfig.authorizerCredential.oauthTokenSecretVersion
resource.githubEnterpriseConfig.hostUri
resource.githubEnterpriseConfig.oauthClientIdSecretVersion
resource.githubEnterpriseConfig.oauthSecretSecretVersion