为 Cloud 配额配置 VPC Service Controls
Trusted Cloud by S3NS 借助 Virtual Private Cloud (VPC) Service Controls,您可以设置安全的边界以防数据渗漏。请使用 VPC Service Controls 配置 Cloud 配额,以使对 Cloud 配额的 API 请求保留在 VPC 服务边界内。
限制
由于 VPC Service Controls 在项目级强制执行边界,因此来自边界内客户端的 Cloud 配额请求只能在组织设置出站流量规则时访问组织资源。
如需设置出站流量规则,请参阅 VPC Service Controls 说明中的配置入站流量和出站流量政策
强制执行的操作
仅对以下 Cloud 配额操作执行 VPC Service Controls:
如需查看设置 QuotaPreference
和 QuotaInfo
的示例,请参阅 API 资源模型。如需了解参考信息,请参阅 REST API 概览。
设置
请按照以下步骤将 Cloud Quotas API 限制在您的 VPC 服务边界内:
按照说明设置 Cloud Quotas API。
按照 VPC Service Controls 快速入门完成以下任务:
- 创建服务边界。
- 将项目添加到您要保护的边界。
- 限制 Cloud Quotas API。例如,请参阅将其他 Trusted Cloud by S3NS API 添加到 VPC 服务边界的说明。
设置服务边界后,VPC Service Controls 会检查对 Cloud Quotas API 的调用,以帮助确保这些调用源自同一边界内部。
后续步骤
如未另行说明,那么本页面中的内容已根据知识共享署名 4.0 许可获得了许可,并且代码示例已根据 Apache 2.0 许可获得了许可。有关详情,请参阅 Google 开发者网站政策。Java 是 Oracle 和/或其关联公司的注册商标。
最后更新时间 (UTC):2025-08-18。
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["没有我需要的信息","missingTheInformationINeed","thumb-down"],["太复杂/步骤太多","tooComplicatedTooManySteps","thumb-down"],["内容需要更新","outOfDate","thumb-down"],["翻译问题","translationIssue","thumb-down"],["示例/代码问题","samplesCodeIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-08-18。"],[[["Google Cloud VPC Service Controls allows you to establish a secure perimeter to prevent data exfiltration, ensuring Cloud Quotas API requests remain within the designated boundary."],["VPC Service Controls for Cloud Quotas are enforced on specific actions, including quota preference creation, update, get, and list, as well as quota info get and list operations."],["To access organization resources via Cloud Quotas from within the service perimeter, an egress rule must be configured by the organization."],["Setting up VPC Service Controls for Cloud Quotas involves creating a service perimeter, adding protected projects, and restricting the Cloud Quotas API within that perimeter, following provided instructions."],["After the perimeter is configured, VPC Service Controls verifies that calls to the Cloud Quotas API originate from within the same defined perimeter."]]],[]]