Présentation de la configuration de Cloud Service Mesh
Restez organisé à l'aide des collections
Enregistrez et classez les contenus selon vos préférences.
Cette page explique comment configurer l'autorisation binaire à utiliser avec Cloud Service Mesh.
Avant de commencer
Avant d'utiliser l'autorisation binaire pour Cloud Service Mesh, vous devez installer Cloud Service Mesh sur Google Kubernetes Engine (GKE). Pour en savoir plus, consultez le guide de démarrage rapide ou les guides d'installation de GKE.
Procédure de configuration
Pour configurer l'autorisation binaire pour Cloud Service Mesh, procédez comme suit :
Sauf indication contraire, le contenu de cette page est régi par une licence Creative Commons Attribution 4.0, et les échantillons de code sont régis par une licence Apache 2.0. Pour en savoir plus, consultez les Règles du site Google Developers. Java est une marque déposée d'Oracle et/ou de ses sociétés affiliées.
Dernière mise à jour le 2025/09/02 (UTC).
[[["Facile à comprendre","easyToUnderstand","thumb-up"],["J'ai pu résoudre mon problème","solvedMyProblem","thumb-up"],["Autre","otherUp","thumb-up"]],[["Difficile à comprendre","hardToUnderstand","thumb-down"],["Informations ou exemple de code incorrects","incorrectInformationOrSampleCode","thumb-down"],["Il n'y a pas l'information/les exemples dont j'ai besoin","missingTheInformationSamplesINeed","thumb-down"],["Problème de traduction","translationIssue","thumb-down"],["Autre","otherDown","thumb-down"]],["Dernière mise à jour le 2025/09/02 (UTC)."],[[["\u003cp\u003eThis guide details how to set up Binary Authorization for Cloud Service Mesh, which is only available on Google Kubernetes Engine (GKE).\u003c/p\u003e\n"],["\u003cp\u003eBefore setting up Binary Authorization, Cloud Service Mesh must be installed on GKE, referencing the quickstart or GKE installation guides for this process.\u003c/p\u003e\n"],["\u003cp\u003eThe setup involves enabling Binary Authorization, configuring its policy, and optionally using the \u003ccode\u003ebuilt-by-cloud-build\u003c/code\u003e attestor or attestations.\u003c/p\u003e\n"],["\u003cp\u003eThe policy can be configured with default rules, specific rules for the Cloud Service Mesh service identity, and exempt images.\u003c/p\u003e\n"],["\u003cp\u003eBinary Authorization for GKE with Cloud Service Mesh can be disabled by following the provided instructions, and audit logs can be viewed for GKE as well.\u003c/p\u003e\n"]]],[],null,["This page provides an overview of how to set up Binary Authorization for use with\nCloud Service Mesh.\n\nBefore you begin\n\nBefore you use Binary Authorization for Cloud Service Mesh, you must first\ninstall Cloud Service Mesh on Google Kubernetes Engine (GKE). For more information,\nsee the [quickstart](/service-mesh/docs/quickstart-asm) or the [GKE installation guides](/service-mesh/docs/all-gke-install-guides).\n\nSetup Steps\n\nTo set up Binary Authorization for Cloud Service Mesh, perform the following steps:\n\n1. [Enable Binary Authorization](/binary-authorization/docs/enabling).\n2. Configure your Binary Authorization policy.\n\n | **Note:** Skip this step if you want to use attestations.\n\n You can configure the following features in your policy:\n - [Default rule](/binary-authorization/docs/configuring-policy-console#default-rule).\n - [Specific rules for your Cloud Service Mesh service identity](/binary-authorization/docs/configuring-policy-console#add-specific-rules-asm).\n - [Exempt images](/binary-authorization/docs/configuring-policy-console#exempt_images). [Learn more about exempt images](/binary-authorization/docs/key-concepts#exempt_images).\n3. Optional: Use the `built-by-cloud-build` attestor to [deploy only images built by Cloud Build](/binary-authorization/docs/deploy-cloud-build).\n\n4. Optional: [Use attestations](/binary-authorization/docs/attestations).\n\n5. View audit logs by following instructions in [View audit logs for GKE](/binary-authorization/docs/viewing-audit-logs).\n\nDisable Binary Authorization for GKE with Cloud Service Mesh\n\nTo disable Binary Authorization for GKE with Cloud Service Mesh enabled,\nfollow the instructions in [Disable Binary Authorization for\nGKE](/binary-authorization/docs/disabling)."]]