這個頁面說明如何設定 Cloud Customer Care 支援服務的存取控管機制。
事前準備
- 您必須訂閱 Standard 支援服務、Enhanced 支援服務或 Premium 支援服務。
- 您必須具備 Google Cloud 組織的組織管理員角色 (
roles/resourcemanager.organizationAdmin)。
什麼是身分與存取權管理 (IAM)
Google Cloud 提供 IAM 功能,可對特定Google Cloud 資源授予更精細的存取權,避免未經授權者存取其他資源。IAM 採用最小權限安全原則,可確保您僅授予使用者必要的資源存取權限。
您可以設定 IAM 政策,控管「哪些使用者」(身分) 具備「哪些資源」的「何種存取權」(角色),透過 IAM 政策授予主體特定角色,讓對方擁有特定權限。舉例來說,您可以將特定資源 (例如專案) 的技術支援檢視者角色 (roles/cloudsupport.techSupportViewer) 指派給某個 Google 帳戶,這個帳戶就有權查看該專案中的客服案件,但是無權管理。
存取權注意事項
請注意,如果您原來採用舊版白銀級、爍金級或白金級支援方案,現已無法再透過 Google Cloud支援中心 (GCSC) 存取客服案件。啟用 Standard、Enhanced 或 Premium 支援服務後,您可以授予使用者、群組或網域 IAM 角色,藉此管理轉移後的案件存取權。
組織層級案件
您可以在組織或專案中建立 Customer Care 案件。
如要管理組織層級的案件,使用者「必須」擁有組織層級的 resourcemanager.organizations.get 權限,否則無法在 Google Cloud 控制台中選取組織。
授予這項權限最簡單的方法,是授予使用者組織的 roles/resourcemanager.organizationViewer 角色。這個角色只會授予 resourcemanager.organizations.get 權限。
注意:授予使用者 Organization Viewer 角色,與在組織層級授予使用者 Viewer 角色並不相同,這一點常讓人混淆。Organization Viewer 角色不會授予使用者查看所有組織資源的權限,只允許使用者查看組織是否存在。
此外,使用者也必須具備相關的技術支援 IAM 權限,詳情請參閱以下章節。
Customer Care IAM 角色
使用 IAM 時,每位支援使用者都必須具備適當權限,才能查看及管理案件和使用者。您只要將使用者新增至某個 IAM 角色、屬於該角色的群組或指派給該角色的網域,使用者便會獲得對應的權限。
下表列出 Cloud Customer Care 使用者可用的 IAM 角色、各資源的相關權限,以及可套用權限的最低資源層級。
| Role | Permissions |
|---|---|
Support Account Administrator( Allows management of a support account without giving access to support cases. See the Cloud Support documentation for more information. Lowest-level resources where you can grant this role:
|
|
Support Account Viewer( Read-only access to details of a support account. This does not allow viewing cases. See the Cloud Support documentation for more information. Lowest-level resources where you can grant this role:
|
|
Advisory Support Editor( Full read-write access to advisory support cases applicable for GCP Customer Care. |
|
Advisory Support Viewer( Read-only access to advisory support cases applicable for GCP Customer Care. |
|
Support Subscription Editor( |