配額與限制

這份文件列出 Google Cloud Armor 適用的配額和系統限制。

  • 「配額」有預設值,但通常可以申請調整。
  • 「系統限制」是固定值,無法變更。

Cloud de Confiance by S3NS 使用配額來確保公平性,並減少資源使用量和可用性出現劇烈波動的情況。配額會限制 Cloud de Confiance 專案可使用的Cloud de Confiance 資源數量,且適用多種資源類型,包括軟硬體和網路元件。舉例來說,配額可能會限制能向特定服務發出的 API 呼叫次數、專案可同時使用的負載平衡器數量,或是可建立的專案數量。配額機制可防止服務過載,保障Cloud de Confiance 使用者社群的權益,同時也有助於您管理自己的 Cloud de Confiance 資源。

Cloud Quotas 系統具備以下功能:

如果嘗試使用的資源量超過配額限制,系統通常會阻擋該資源的存取活動,您所執行的工作就會失敗。

配額的計算通常是以 Cloud de Confiance 專案為基準。在某個專案中使用資源,不會影響另一個專案的可用配額。在同一個 Cloud de Confiance 專案內,所有應用程式和 IP 位址會共用配額。

詳情請參閱「Cloud Quotas 總覽」。

Cloud Armor 資源也有「系統限制」,而且無法變更。

配額

Google Cloud Armor 資源配額是根據下列兩項條件整理:

  • 配額範圍:
    • 全球
    • 區域
  • Cloud Armor 安全性政策類型:
    • 後端安全性政策
    • 邊緣安全性政策
    • 網路邊緣安全性政策

全域後端安全性政策和全域邊緣安全性政策

Cloud Armor 會對全域邊緣安全性政策、全域後端安全性政策,以及其中的規則,使用下列每項專案配額:

資源 配額 說明
每項專案的全域安全性政策 配額

這項配額的上限定義了專案中全域邊緣安全性政策全域後端安全性政策的總數上限。

配額名稱:SECURITY_POLICIES

可用指標:

  • compute.googleapis.com/quota/security_policies/limit
  • compute.googleapis.com/quota/security_policies/usage
  • compute.googleapis.com/quota/security_policies/exceeded
每項專案的全域安全性政策規則 配額

這項配額的上限定義了專案中全域邊緣安全性政策和全域後端安全性政策的規則總數上限。這項配額的使用量會計入下列項目:

  • 全域邊緣安全性政策中的基本規則
  • 全域後端安全性政策中的基本規則
  • 全域邊緣安全性政策中含有進階比對條件的規則
  • 全域後端安全性政策中含有進階比對條件的規則

配額名稱:SECURITY_POLICY_RULES

可用指標:

  • compute.googleapis.com/quota/security_policy_rules/limit
  • compute.googleapis.com/quota/security_policy_rules/usage
  • compute.googleapis.com/quota/security_policy_rules/exceeded
每項專案的進階比對條件全域安全性政策規則 配額

這項配額的上限定義了專案中,全域邊緣安全性政策和全域後端安全性政策中含有進階比對條件的規則總數上限。這項配額的使用量包含下列項目:

  • 全域邊緣安全性政策中含有進階比對條件的規則
  • 全域後端安全性政策中含有進階比對條件的規則

配額名稱:SECURITY_POLICY_CEVAL_RULES

可用指標:

  • compute.googleapis.com/quota/security_policy_ceval_rules/limit
  • compute.googleapis.com/quota/security_policy_ceval_rules/usage
  • compute.googleapis.com/quota/security_policy_ceval_rules/exceeded

每個全域安全性政策的配額,適用於含有進階比對條件的規則

Cloud Armor 對於全域邊緣安全性政策和全域後端安全性政策中,具有進階比對條件的規則,會採用下列每個安全性政策的配額:

資源 配額 說明
每個全域邊緣安全性政策中含有進階比對條件的規則數 配額

這項配額的上限定義了特定全域邊緣安全政策中,含有進階比對條件的規則數量上限。

配額名稱:SECURITY_POLICY_ADVANCED_RULES_PER_EDGE_SECURITY_POLICY

可用指標:

  • compute.googleapis.com/quota/advanced_rules_per_edge_security_policy/limit
  • compute.googleapis.com/quota/advanced_rules_per_edge_security_policy/usage
  • compute.googleapis.com/quota/advanced_rules_per_edge_security_policy/exceeded
每個全域後端安全性政策中含有進階比對條件的規則數 配額

這項配額的上限定義了特定全域後端安全政策中,含有進階比對條件的規則數量上限。

配額名稱:SECURITY_POLICY_ADVANCED_RULES_PER_SECURITY_POLICY

可用指標:

  • compute.googleapis.com/quota/advanced_rules_per_security_policy/limit
  • compute.googleapis.com/quota/advanced_rules_per_security_policy/usage
  • compute.googleapis.com/quota/advanced_rules_per_security_policy/exceeded

全域安全性政策中規則的配額計數摘要

下表列出全域安全性政策中基本規則和含有進階比對條件的規則,會計入哪些配額:

規則 計入這些配額的使用量
全域邊緣安全性政策中的基本規則
  • 每個專案的全域安全政策規則 (SECURITY_POLICY_RULES)
全域後端安全性政策中的基本規則
  • 每個專案的全域安全政策規則 (SECURITY_POLICY_RULES)
全域邊緣安全性政策中含有進階比對條件的規則
  • 每個專案的全域安全政策規則 (SECURITY_POLICY_RULES)
  • 每項專案的全球安全性政策規則 (含進階比對條件) (SECURITY_POLICY_CEVAL_RULES)
  • 每項全域邊緣安全性政策的進階比對條件規則數 (SECURITY_POLICY_ADVANCED_RULES_PER_EDGE_SECURITY_POLICY)
全域後端安全性政策中含有進階比對條件的規則
  • 每個專案的全域安全政策規則 (SECURITY_POLICY_RULES)
  • 每項專案的全球安全性政策規則 (含進階比對條件) (SECURITY_POLICY_CEVAL_RULES)
  • 每個全域後端安全政策中含有進階比對條件的規則數 (SECURITY_POLICY_ADVANCED_RULES_PER_SECURITY_POLICY)

區域後端安全性政策

Cloud Armor 會對區域後端安全性政策及其規則,採用下列每項專案、每個區域的配額:

資源 配額 說明
每個區域每項專案的區域後端安全政策 配額

這項配額的上限定義了專案區域中區域後端安全政策的數量上限。

配額名稱:SECURITY_POLICIES_PER_REGION

可用指標:

  • compute.googleapis.com/quota/regional_security_policies/limit
  • compute.googleapis.com/quota/regional_security_policies/usage
  • compute.googleapis.com/quota/regional_security_policies/exceeded
每個區域每項專案的區域後端安全政策規則 配額

這項配額的上限定義了專案區域中,區域後端安全政策的規則總數上限。這項配額的用量會同時計入基本規則和具備進階比對條件的規則。

配額名稱:SECURITY_POLICY_RULES_PER_REGION

可用指標:

  • compute.googleapis.com/quota/regional_security_policy_rules/limit
  • compute.googleapis.com/quota/regional_security_policy_rules/usage
  • compute.googleapis.com/quota/regional_security_policy_rules/exceeded
每個區域每項專案的區域後端安全性政策規則,且含有進階比對條件 配額

這項配額的限制定義了專案區域中,區域後端安全政策內含有進階比對條件的規則總數上限。這項配額的用量只會計算具有進階比對條件的規則。

配額名稱:SECURITY_POLICY_ADVANCED_RULES_PER_REGION

可用指標:

  • compute.googleapis.com/quota/regional_security_policy_advanced_rules/limit
  • compute.googleapis.com/quota/regional_security_policy_advanced_rules/usage
  • compute.googleapis.com/quota/regional_security_policy_advanced_rules/exceeded

每個區域後端安全政策的配額,適用於含有進階比對條件的規則

Cloud Armor 會對區域後端安全性政策中具有進階比對條件的規則,套用下列每項安全性政策配額:

資源 配額 說明
每個區域後端安全性政策中含有進階比對條件的規則數 配額

這項配額的上限定義特定區域後端安全政策中的進階規則數量上限。

配額名稱:SECURITY_POLICY_ADVANCED_RULES_PER_REGIONAL_SECURITY_POLICY

可用指標:

  • compute.googleapis.com/quota/advanced_rules_per_regional_security_policy/limit
  • compute.googleapis.com/quota/advanced_rules_per_regional_security_policy/usage
  • compute.googleapis.com/quota/advanced_rules_per_regional_security_policy/exceeded

區域後端安全政策中規則的配額摘要

下表列出區域後端安全政策中,基本規則和具備進階比對條件的規則所計入的配額:

規則 計入這些配額的使用量
區域後端安全性政策中的基本規則
  • 每個專案的每個區域,區域後端安全政策規則數量 (SECURITY_POLICY_RULES_PER_REGION)
區域後端安全性政策中含有進階比對條件的規則
  • 每個專案的每個區域,區域後端安全政策規則數量 (SECURITY_POLICY_RULES_PER_REGION)
  • 每項專案中,每個區域的區域後端安全性政策規則 (含進階比對條件) 數量 (SECURITY_POLICY_ADVANCED_RULES_PER_REGION )
  • 每個區域後端安全政策的進階比對條件規則數 (SECURITY_POLICY_ADVANCED_RULES_PER_REGIONAL_SECURITY_POLICY)

區域網路邊緣安全性政策

Cloud Armor 會使用下列每項專案、每個區域的配額,處理區域網路邊緣安全性政策和其中的規則:

資源 配額 說明
每個區域每項專案的區域性網路邊緣安全性政策數 配額

這項配額的上限定義了專案中每個區域的區域網路邊緣安全政策數量上限。

配額名稱:NET_LB_SECURITY_POLICIES_PER_REGION

可用指標:

  • compute.googleapis.com/quota/regional_net_lb_security_policies/limit
  • compute.googleapis.com/quota/regional_net_lb_security_policies/usage
  • compute.googleapis.com/quota/regional_net_lb_security_policies/exceeded
每個區域每項專案的區域網路邊緣安全性政策規則數 配額

這項配額的限制定義了專案中每個區域的區域網路邊緣安全政策規則總數上限。

配額名稱:NET_LB_SECURITY_POLICY_RULES_PER_REGION

可用指標:

  • compute.googleapis.com/quota/regional_net_lb_security_policy_rules/limit
  • compute.googleapis.com/quota/regional_net_lb_security_policy_rules/usage
  • compute.googleapis.com/quota/regional_net_lb_security_policy_rules/exceeded
每個區域每項專案的區域網路邊緣安全性政策規則比對值 配額

這項配額的限制定義了專案中每個區域的區域網路邊緣安全政策規則中,屬性的總數上限。這項配額的用量是專案區域中,每個網路邊緣安全政策的每項規則中,SecurityPolicy.NetworkMatch 屬性的總和。

配額名稱:NET_LB_SECURITY_POLICY_RULE_ATTRIBUTES_PER_REGION

可用指標:

  • compute.googleapis.com/quota/regional_net_lb_security_policy_rule_attributes/limit
  • compute.googleapis.com/quota/regional_net_lb_security_policy_rule_attributes/usage
  • compute.googleapis.com/quota/regional_net_lb_security_policy_rule_attributes/exceeded

除了 Cloud Armor 配額,使用 Cloud Armor 的產品也有自己的配額。例如,請參閱「Cloud Load Balancing 配額和限制」。

基於多種理由,Cloud de Confiance by S3NS 會對資源用量實施配額限制。舉例來說,限制配額可以預防用量突然暴增的情況,進而保障 Cloud de Confiance 使用者社群的權益。 Cloud de Confiance 也提供免費試用配額,讓新建立的Cloud de Confiance 專案免費試用部分功能。

並非所有專案的配額都相同。隨著您的 Cloud de Confiance使用量成長,系統可能會視情況自動提升配額。如果您預期用量將大幅攀升,可以透過 Cloud de Confiance 控制台的「配額」頁面主動要求提高配額。

您必須具備 serviceusage.quotas.update 權限,才能要求更多配額。根據預設,擁有者、編輯者和配額管理員這些預先定義的角色都具備這項權限。請至少提前一週規劃所需的額外資源並提出申請,確保您的申請可以及時獲得核准。如要申請更多配額,請參閱「申請更多配額」一節。

限制

Google Cloud Armor 有下列限制:

項目 限制
每項規則的 IP 位址數或 IP 位址範圍數 10
具備自訂運算式的各項規則所含子運算式數 10
自訂運算式中每項子運算式的字元數 1024
自訂運算式的字元數 2048

在具備 Cloud Armor 安全性政策的所有後端中,每項專案每秒要求數

這項限制不會強制執行。Google 保留權利,可限制每項專案中所有安全性政策能夠處理的流量。請一律將提高 QPS 的要求交給帳戶團隊負責。

20,000
每個專案在每個區域的網路邊緣安全服務數量 1
網路邊緣安全性政策中的規則數 100
每個機構的階層式安全性政策數量 50
每個機構的所有階層式安全性政策規則數 200
每個機構的所有階層式安全性政策中,含有進階比對條件的規則數 20
<0x0

Manage quotas

Google Cloud Armor enforces quotas on resource usage for various reasons. For example, quotas protect the community of Cloud de Confiance by S3NS users by preventing unforeseen spikes in usage. Quotas also help users who are exploring Cloud de Confiance with the free tier to stay within their trial.

All projects start with the same quotas, which you can change by requesting additional quota. Some quotas might increase automatically based on your use of a product.

Permissions

To view quotas or request quota increases, Identity and Access Management (IAM) principals need one of the following roles.

Task Required role
Check quotas for a project One of the following:
Modify quotas, request additional quota One of the following:
  • Project Owner (roles/owner)
  • Project Editor (roles/editor)
  • Quota Administrator (roles/servicemanagement.quotaAdmin)
  • A custom role with the serviceusage.quotas.update permission

Check your quota

Console

  1. In the Cloud de Confiance console, go to the Quotas page.

    Go to Quotas

  2. To search for the quota that you want to update, use the Filter table. If you don't know the name of the quota, use the links on this page instead.

gcloud

Using the Google Cloud CLI, run the following command to check your quotas. Replace PROJECT_ID with your own project ID.

    gcloud compute project-info describe --project PROJECT_ID

To check your used quota in a region, run the following command:

    gcloud compute regions describe example-region
    

Errors when exceeding your quota

If you exceed a quota with a gcloud command, gcloud outputs a quota exceeded error message and returns with the exit code 1.

If you exceed a quota with an API request, Cloud de Confiance returns the following HTTP status code: 413 Request Entity Too Large.

Request additional quota

To adjust most quotas, use the Cloud de Confiance console. For more information, see Request a quota adjustment.

Resource availability

Each quota represents a maximum number for a particular type of resource that you can create, if that resource is available. It's important to note that quotas don't guarantee resource availability. Even if you have available quota, you can't create a new resource if it is not available.

For example, you might have sufficient quota to create a new regional, external IP address in a given region. However, that is not possible if there are no available external IP addresses in that region. Zonal resource availability can also affect your ability to create a new resource.

Situations where resources are unavailable in an entire region are rare. However, resources within a zone can be depleted from time to time.