使用 IAM 控管存取權

這個頁面說明如何設定 Cloud Customer Care 支援服務的存取控管機制。

事前準備

什麼是身分與存取權管理 (IAM)

Google Cloud 提供 IAM 功能,可對特定Google Cloud 資源授予更精細的存取權,避免未經授權者存取其他資源。IAM 採用最小權限安全原則,可確保您僅授予使用者必要的資源存取權限。

您可以設定 IAM 政策,控管「哪些使用者」(身分) 具備「哪些資源」的「何種存取權」(角色),透過 IAM 政策授予主體特定角色,讓對方擁有特定權限。舉例來說,您可以將特定資源 (例如專案) 的技術支援檢視者角色 (roles/cloudsupport.techSupportViewer) 指派給某個 Google 帳戶,這個帳戶就有權查看該專案中的客服案件,但是無權管理。

存取權注意事項

請注意,如果您原來採用舊版白銀級、爍金級或白金級支援方案,現已無法再透過 Google Cloud支援中心 (GCSC) 存取客服案件。啟用 Standard、Enhanced 或 Premium 支援服務後,您可以授予使用者、群組或網域 IAM 角色,藉此管理轉移後的案件存取權。

組織層級案件

您可以在組織或專案中建立 Customer Care 案件。

如要管理組織層級的案件,使用者「必須」擁有組織層級的 resourcemanager.organizations.get 權限,否則無法在 Google Cloud 控制台中選取組織。

授予這項權限最簡單的方法,是授予使用者組織的 roles/resourcemanager.organizationViewer 角色。這個角色只會授予 resourcemanager.organizations.get 權限。

注意:授予使用者 Organization Viewer 角色,與在組織層級授予使用者 Viewer 角色並不相同,這一點常讓人混淆。Organization Viewer 角色不會授予使用者查看所有組織資源的權限,只允許使用者查看組織是否存在。

此外,使用者也必須具備相關的技術支援 IAM 權限,詳情請參閱以下章節。

Customer Care IAM 角色

使用 IAM 時,每位支援使用者都必須具備適當權限,才能查看及管理案件和使用者。您只要將使用者新增至某個 IAM 角色、屬於該角色的群組或指派給該角色的網域,使用者便會獲得對應的權限。

下表列出 Cloud Customer Care 使用者可用的 IAM 角色、各資源的相關權限,以及可套用權限的最低資源層級。

Role Permissions

(roles/cloudsupport.admin)

Allows management of a support account without giving access to support cases. See the Cloud Support documentation for more information.

Lowest-level resources where you can grant this role:

  • Organization

cloudsupport.accounts.*

  • cloudsupport.accounts.create
  • cloudsupport.accounts.delete
  • cloudsupport.accounts.get
  • cloudsupport.accounts.getIamPolicy
  • cloudsupport.accounts.getUserRoles
  • cloudsupport.accounts.list
  • cloudsupport.accounts.purchase
  • cloudsupport.accounts.setIamPolicy
  • cloudsupport.accounts.update
  • cloudsupport.accounts.updateUserRoles

cloudsupport.operations.get

cloudsupport.properties.get

resourcemanager.organizations.get

(roles/cloudsupport.viewer)

Read-only access to details of a support account. This does not allow viewing cases. See the Cloud Support documentation for more information.

Lowest-level resources where you can grant this role:

  • Organization

cloudsupport.accounts.get

cloudsupport.accounts.getUserRoles

cloudsupport.accounts.list

cloudsupport.properties.get

(roles/cloudsupport.advisorySupportEditor)

Full read-write access to advisory support cases applicable for GCP Customer Care.

cloudasset.assets.searchAllResources

cloudsupport.properties.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/cloudsupport.advisorySupportViewer)

Read-only access to advisory support cases applicable for GCP Customer Care.

cloudsupport.properties.get

resourcemanager.projects.get

resourcemanager.projects.list

(roles/