本页介绍如何使用 Identity-Aware Proxy (IAP) 保护 App Engine 实例。
准备工作
如需为 App Engine 启用 IAP,请执行以下操作:
使用启用了结算功能的 Google Cloud 控制台项目。
如果您想使用默认的 Google 管理的 OAuth 客户端,请确保项目属于某个组织。 Google Cloud 如果您没有组织,可以创建一个。 如需了解使用自定义 OAuth 客户端的好处,请参阅为 App Engine 配置自定义 OAuth 客户端。 Google 管理的 OAuth 客户端仅允许内部用户访问。
设置 App Engine 实例(如果您尚未设置)。如需查看完整演练,请参阅部署到 App Engine。
启用 IAP
控制台
如果您的项目不属于组织,则必须使用自定义 OAuth 凭证。
If you haven't configured your project's OAuth consent screen, you'll be prompted to do so. To configure your OAuth consent screen, see Setting up your OAuth consent screen.
Setting up IAP access
-
Go to the
Identity-Aware Proxy page.
Go to the Identity-Aware Proxy page - Select the project you want to secure with IAP.
- Select the checkbox next to the resource you want to grant access to.
- On the right side panel, click Add principal.
-
In the Add principals dialog that appears, enter the email addresses of groups or
individuals who should have the IAP-secured Web App User role for the project.
The following kinds of principals can have this role:
- Google Account: user@gmail.com
- Google Group: admins@googlegroups.com
- Service account: server@example.
- Google Workspace domain: example.com
Make sure to add a Google Account that you have access to.
- Select Cloud IAP > IAP-secured Web App User from the Roles drop-down list.
- Click Save.
Turning on IAP
-
On the Identity-Aware Proxy page, under Applications,
find the application you want to restrict
access to. To turn on IAP for a resource,
-
In the Turn on IAP window that appears, click Turn On to
confirm that you want IAP to secure your resource. After you turn on
IAP, it requires login credentials for all connections to your load balancer.
Only principals with the IAP-Secured Web App User (
roles/iap.httpsResourceAccessor) role on the project will be given access.
gcloud
Before you set up your project and IAP, you need an up-to-date version of the gcloud CLI. For instructions on how to install the gcloud CLI, see Install the gcloud CLI.
-
To authenticate, use the Google Cloud CLI and run the following command.
gcloud auth login - Click the URL that appears and sign in.
- After you sign in, copy the verification code that appears and paste it in the command line.
-
Run the following command to specify the project that contains the applications that you want to protect with IAP.
gcloud config set project PROJECT_ID -
To enable IAP, run the following command.
gcloud iap web enable --resource-type=app-engine --versions=version -
Add principals who should have the IAP-secured Web App user role to the project.
gcloud projects add-iam-policy-binding PROJECT_ID \ --member=PRINCIPAL_IDENTIFIER \ --role=roles/iap.httpsResourceAccessor- Replace PROJECT_ID with your project ID.
- Replace PRINCIPAL_IDENTIFIER with the necessary principals. This can be a
type of domain, group, serviceAccount, or user. For example,
user:myemail@example.com.
After you enable IAP, you can use the gcloud CLI to modify the
IAP access policy using the IAM role
roles/iap.httpsResourceAccessor. Learn more about
managing roles and permissions.
API
运行以下命令以准备
settings.json文件。cat << EOF > settings.json { "iap": { "enabled":true } } EOF运行以下命令以启用 IAP。
curl -X PATCH \ -H "Authorization: Bearer $(gcloud auth print-access-token)" \ -H "Accept: application/json" \ -H "Content-Type: application/json" \ -d @settings.json \ "https://appengine.googleapis.com/v1/apps/PROJECT_ID?updateMask=iap"
启用 IAP 后,您可以使用 Google Cloud CLI 通过 IAM 角色 roles/iap.httpsResourceAccessor 修改 IAP 访问权限政策。详细了解如何管理角色和权限。
您可以在项目中的 App Engine 服务上启用 IAP。如需使某些服务可公开访问,而另一些服务需要进行身份验证,您可以在不同服务中使用不同的访问权限级别。如需了解详情,请参阅使用 IAP 管理访问权限。如需让服务可以公开访问,请向 allAuthenticatedUsers 授予 IAP-secured Web App User 角色。
测试用户身份验证
授予角色后,主账号可以通过使用 IAP 进行身份验证来访问应用。使用被授予 IAP-secured Web App User (
roles/iap.httpsResourceAccessor) 角色的 Google 账号访问应用网址。如需测试访问权限,请在 Chrome 中打开无痕式窗口,访问应用网址,并根据提示登录。获得 IAP-secured Web App User (
roles/iap.httpsResourceAccessor) 角色的用户在成功通过身份验证后可以访问该应用。未获得所需角色或未能通过身份验证的用户无法访问该应用。