VPC Service Controls


Confidential Space 需要拥有 Cloud Storage 存储分区的读取权限,才能下载用于验证其证明令牌的证书。如果这些 Cloud Storage 存储分区位于边界外,您必须创建以下出站流量规则

- egressTo:
      operations:
      - serviceName: storage.googleapis.com
        methodSelectors:
        - method: google.storage.objects.get
      resources:
      - projects/870449385679
      - projects/180376494128
    egressFrom:
      identityType: ANY_IDENTITY