設定負載平衡器憑證的方式有很多種,具體取決於負載平衡器的屬性,以及先前設定的憑證設定參數。憑證管理員 (第 2 代) 介面會偵測特定負載平衡器的可用項目,並顯示適當的設定方法。
可用的選項如下:
- 設定具備 SSL 憑證的全域負載平衡器。
- 使用網路憑證或 Compute SSL 憑證設定區域負載平衡器。
- 設定具備憑證對應關係的全域負載平衡器。
- 設定具有網路憑證的全域負載平衡器。
事前準備
- 登入 Google Cloud 帳戶。如果您是 Google Cloud新手,歡迎 建立帳戶,親自評估產品在實際工作環境中的成效。新客戶還能獲得價值 $300 美元的免費抵免額,可用於執行、測試及部署工作負載。
-
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
-
If you're using an existing project for this guide, verify that you have the permissions required to complete this guide. If you created a new project, then you already have the required permissions.
-
Verify that billing is enabled for your Google Cloud project.
Enable the Compute Engine, Certificate Manager, Certificate Authority Service APIs.
Roles required to enable APIs
To enable APIs, you need the
serviceusage.services.enablepermission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.-
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
-
If you're using an existing project for this guide, verify that you have the permissions required to complete this guide. If you created a new project, then you already have the required permissions.
-
Verify that billing is enabled for your Google Cloud project.
Enable the Compute Engine, Certificate Manager, Certificate Authority Service APIs.
Roles required to enable APIs
To enable APIs, you need the
serviceusage.services.enablepermission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.- 請確認您目前已有應用程式負載平衡器,且至少有一個目標 HTTPS Proxy。詳情請參閱選擇負載平衡器。
必要的角色
如要取得設定生命週期管理所需的權限,請要求管理員授予您專案的下列 IAM 角色:
- Certificate Manager 編輯者 (
roles/certificatemanager.editor) - Compute 網路管理員 (
roles/compute.networkAdmin)
如要進一步瞭解如何授予角色,請參閱「管理專案、資料夾和組織的存取權」。
設定負載平衡器的生命週期
如要設定負載平衡器憑證的生命週期管理,請按照特定負載平衡器設定的步驟操作:
使用 Compute SSL 憑證的全球負載平衡器
前往 Google Cloud 控制台的「Certificate Manager (2nd gen)」。
在導覽選單中,按一下「管理生命週期」。
按一下「負載平衡」分頁標籤。系統會顯示負載平衡器清單。
找出負載平衡器,然後點選切換節點展開資料列,查看相關聯的目標 Proxy。
按一下目標 Proxy 的名稱。
按一下「設定生命週期管理」。這個頁面會顯示與目標 Proxy 相關聯的憑證。
從可用清單中選取憑證。您可以使用自己的憑證,也可以使用 Google 代管的憑證。
依序按一下「其他憑證」和「新增憑證」。
從可用清單中選取憑證。負載平衡器的每項轉送規則都能額外含有 1 至 14 組憑證。
按一下「更新」,將變更套用至目標 Proxy。這項操作會更新基礎憑證對應關係,或建立新的對應關係。
具有網路或 SSL 憑證的區域負載平衡器
前往 Google Cloud 控制台的「Certificate Manager (2nd gen)」。
在導覽選單中,按一下「管理生命週期」。
按一下「負載平衡」分頁標籤。系統會顯示負載平衡器清單。
找出負載平衡器,然後點選切換節點展開資料列,查看相關聯的目標 Proxy。
按一下目標 Proxy 的名稱。
按一下「設定生命週期管理」。這個頁面會顯示與目標 Proxy 有效憑證對應組合相關聯的憑證。
選取存放區類型:「憑證」或「傳統憑證」。
按一下「新增憑證」。
選取現有憑證或建立新憑證。
輸入新憑證的下列詳細資料:
- 名稱:這個憑證資源的專屬名稱 (例如
my-lb-cert)。 - 範圍:選取適當的金鑰發布範圍 (例如
Default)。 - 憑證類型:自行管理或 Google 代管的憑證類型。
- 網域名稱:這個憑證涵蓋的網域名稱 (例如
app.example.com)。這個網域必須由您控管。 - 核發設定:從清單中選取現有的核發設定。這項設定會決定 CA、生命週期和金鑰類型。
- 名稱:這個憑證資源的專屬名稱 (例如
點按「Create」(建立)。控制台會將新憑證新增至目標 Proxy 的清單。
查看憑證清單,然後按一下「更新」,將變更套用至目標 Proxy。這項動作會更新基礎憑證對應關係項目,或建立新的項目。
使用憑證對應的全域負載平衡器
前往 Google Cloud 控制台的「Certificate Manager (2nd gen)」。
在導覽選單中,按一下「管理生命週期」。
按一下「負載平衡」分頁標籤。系統會顯示負載平衡器清單。
找出負載平衡器,然後點選切換節點展開資料列,查看相關聯的目標 Proxy。
按一下目標 Proxy 的名稱。
按一下「更新憑證對應組合」。頁面會顯示憑證對應詳細資料和憑證對應項目。
依序點選「編輯」和「新增地圖項目」。
輸入新對應項目的下列詳細資料:
- 名稱:這個憑證資源的專屬名稱 (例如
my-lb-cert)。 - 主機名稱:選取適當的主機名稱。憑證搜尋結果會與所提供的主機名稱完全相符。如為單一層級子網域,搜尋結果也會包含為上層網域萬用字元核發的憑證。舉例來說,輸入
app.example.com會傳回app.example.com和*.example.com的憑證。
- 名稱:這個憑證資源的專屬名稱 (例如
選取現有憑證或建立新憑證。
按一下「Add」(新增)。控制台會將新憑證新增至目標 Proxy 的清單。
查看憑證清單,然後按一下「儲存」,將變更套用至目標 Proxy。這項動作會更新基礎憑證對應關係項目,或建立新的項目。
具有網路憑證的全球負載平衡器
前往 Google Cloud 控制台的「Certificate Manager (2nd gen)」。
在導覽選單中,按一下「管理生命週期」。
按一下「負載平衡」分頁標籤。系統會顯示負載平衡器清單。
找出負載平衡器,然後點選切換節點展開資料列,查看相關聯的目標 Proxy。
按一下目標 Proxy 的名稱。
按一下「設定生命週期管理」。這個頁面會顯示與目標 Proxy 有效憑證對應組合相關聯的憑證。
按一下「新增憑證」。
選取現有憑證或建立新憑證。
輸入新憑證的下列詳細資料:
- 名稱:這個憑證資源的專屬名稱 (例如
my-lb-cert)。 - 範圍:選取適當的金鑰發布範圍 (例如
Default)。 - 憑證類型:自行管理或 Google 代管的憑證類型。
- 網域名稱:這個憑證涵蓋的網域名稱 (例如
app.example.com)。這個網域必須由您控管。 - 核發設定:從清單中選取現有的核發設定。這項設定會決定 CA、生命週期和金鑰類型。
- 名稱:這個憑證資源的專屬名稱 (例如
點按「Create」(建立)。控制台會將新憑證新增至目標 Proxy 的清單。
查看憑證清單,然後按一下「更新」,將變更套用至目標 Proxy。這項動作會更新基礎憑證對應關係項目,或建立新的項目。