VM 기본 서비스 계정의 권한 검토

VM의 용도에 맞는 서비스 계정과 최소 권한을 구성하세요.

설명

여러 VM이 기본 Compute Engine 서비스 계정을 공유하면 권한 분리와 회수가 어려워질 수 있습니다. 기본 계정에 항상 전체 권한이 있는 것은 아니므로 실제 IAM 역할을 확인해야 합니다.

잠재적 영향

계정에 넓은 역할이 부여되어 있으면 침해된 워크로드가 다른 리소스에도 접근할 수 있습니다.

해결 방법

용도별 서비스 계정을 만들고 필요한 IAM 역할만 부여한 뒤 service_accounts의 email로 VM에 연결하세요. Ansible 실행 자격 증명과 VM에 연결하는 계정은 별도로 관리하세요.

예시

변경 후는 미리 준비한 vm_service_account_email을 지정합니다. 이 예시는 IAM 역할을 부여하지 않습니다. 기존 VM에서는 지원되는 계정 변경 절차를 사용하고 실제 연결을 확인하세요.

변경 전

yaml
- name: create a instance1
  google.cloud.gcp_compute_instance:
    name: test-object1
    machine_type: n1-standard-1
    zone: us-central1-a
    project: "{{ gcp_project_id }}"
    auth_kind: serviceaccount
    state: present

- name: create a instance4
  google.cloud.gcp_compute_instance:
    name: test-object4
    machine_type: n1-standard-1
    zone: us-central1-a
    project: "{{ gcp_project_id }}"
    auth_kind: serviceaccount
    service_accounts:
      - email: "{{ project_number }}-compute@developer.gserviceaccount.com"
    state: present

변경 후

yaml
- name: create a instance
  google.cloud.gcp_compute_instance:
    name: test-object
    machine_type: n1-standard-1
    zone: us-central1-a
    project: "{{ gcp_project_id }}"
    auth_kind: serviceaccount
    service_accounts:
      - email: "{{ vm_service_account_email }}"
        scopes:
          - https://www.googleapis.com/auth/cloud-platform
    state: present

참조