Cloud de Confiance 中的 Secret Manager 与 Google Cloud 的对比

Secret Manager 是一个安全便捷的存储系统,用于存储 API 密钥、密码、证书和其他敏感数据。 本页面介绍了 Cloud de Confiance 与 Google Cloud 版本的 Secret Manager 之间的差异。

如需详细了解 Secret Manager,请参阅 Secret Manager 概览以及 Secret Manager 文档的其余部分。

主要差异

Cloud de Confiance 版本的 Secret Manager 与 Google Cloud 版本之间存在一些差异。一些显著的差异包括:

  • 密文的用户管理型复制功能不可用。
  • 仅提供 Secret Manager API 的 v1 版本。
  • 区域端点不可用。

本部分的其余部分提供了更详细的差异列表。如果您已经熟悉 Google Cloud,我们建议您仔细查看这些差异,尤其是在设计要在 Cloud de Confiance上运行的应用之前。我们还建议您查看 Cloud de Confiance 与 Google Cloud 之间的一般差异

如果您想使用 Cloud de Confiance中目前尚不提供的特定 Secret Manager 功能,请与Cloud de Confiance 支持团队联系。如需在 Cloud de Confiance中发布新功能时收到通知,请订阅版本说明。 除非另有说明,否则预览版功能在 Cloud de Confiance中不可用。

可用性和灾难恢复

密文复制

具有用户管理的复制功能的密文不可用。如需创建不指定存储区域的密文,请使用自动复制。为了满足数据驻留要求,请创建区域级 Secret。

工作流和工具

API 版本

仅提供 Secret Manager API 的 v1 版本。v1beta1 和 v1beta2 API 版本不可用。

网络

区域端点

区域端点不可用。不再使用区域端点,而是 Cloud de Confiance 使用全球服务负载平衡器自动将流量定向到相应的区域堆栈。

在 Google Cloud 和 Cloud de Confiance 领域中,用于访问区域级 Secret 的网址格式有所不同。

Google Cloud:

https://secretmanager.REGION.rep.googleapis.com/v1/projects/PROJECT_ID/locations/REGION/secrets?secret_id=SECRET_ID

Cloud de Confiance:

https://secretmanager.s3nsapis.fr/v1/projects/PROJECT_ID/locations/REGION/secrets?secret_id=SECRET_ID

以下信息也可能会影响您在 Cloud de Confiance by S3NS中如何使用 Secret Manager,以及如何针对 Secret Manager 进行设计。这些指南包含有关在 Cloud de Confiance中开展工作的一般信息,包括文档、安全和访问权限控制、结算、工具和服务使用情况。

如需详细了解 Cloud de Confiance 中的其他服务和功能以及它们与 Google Cloud 对应服务和功能的差异,请参阅产品列表