配置密文轮替
使用集合让一切井井有条
根据您的偏好保存内容并对其进行分类。
本页面列出了相关资源,其中包含有关如何为 Google Distributed Cloud (GDC) 气隙设备设置和配置密钥轮换的信息。
- BM SSH 密钥和证书:PLATAUTH-G0003
- 机箱证书、用户名和密码轮换:APPL-G0001
- 更改基板管理控制器 (BMC) 和机箱的 iLO 用户名和密码:
- Integrated Lights-Out (iLO) 凭据轮替:SERV P0002
- BMC 证书轮替:SERV P0003
- Ironic 证书轮替:SERV P0004
- 港口:
- 集群内 Harbor 管理员凭据轮替:SAR-R2001
- Harbor 机器人账号凭据轮替:SAR-R2003
- 轮替 SAR 证书:SAR-T0001
- 轮替 Harbor 组件凭据:SAR-T0002
- 身份提供方密钥轮替:
- Keycloak:IAM-T0001
- 对象存储:
- 对象存储凭据。
- 磁盘加密密钥。
- 存储身份验证密钥和证书。
- 实体网络 (PNET):
- 切换凭据:
gdcloud appliance rotate switch-credentials
- 切换证书:
gdcloud appliance rotate switch-certificate
如需访问 IO 工具容器中的 runbook,请参阅设置 IO 工具以访问 runbook
如未另行说明,那么本页面中的内容已根据知识共享署名 4.0 许可获得了许可,并且代码示例已根据 Apache 2.0 许可获得了许可。有关详情,请参阅 Google 开发者网站政策。Java 是 Oracle 和/或其关联公司的注册商标。
最后更新时间 (UTC):2025-09-04。
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-09-04。"],[],[],null,["# Configure secret rotations\n\nThis page lists the resources for information on how to set up and configure secret rotations for Google Distributed Cloud (GDC) air-gapped appliance.\n\n1. BM SSH keys and certificate: [PLATAUTH-G0003](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/platauth/guides/platauth-g0003)\n2. Chassis certificate, username and password rotation: [APPL-G0001](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/appl/guides/appl-g0001)\n3. Changing the iLO username and password for Baseboard Management Controller (BMC) and chassis:\n 1. Integrated Lights-Out (iLO) credential rotation: [SERV P0002](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/serv/processes/serv-p0002)\n 2. BMC certificate rotation: [SERV P0003](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/serv/processes/serv-p0003)\n 3. Ironic certificate rotation: [SERV P0004](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/serv/processes/serv-p0004)\n4. Harbor:\n 1. In-cluster Harbor admin credentials rotation: [SAR-R2001](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/sar/runbooks/sar-r2001)\n 2. Harbor robot account credentials rotation: [SAR-R2003](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/sar/runbooks/sar-r2003)\n 3. Rotating SAR certificates: [SAR-T0001](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/sar/toil/sar-t0001)\n 4. Rotating Harbor components credentials: [SAR-T0002](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/sar/toil/sar-t0002)\n5. Identity provider secrets rotation:\n 1. Keycloak: [IAM-T0001](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/iam/toil/iam-t0001)\n6. Object storage:\n 1. [Object storage credentials](/distributed-cloud/hosted/docs/latest/appliance/admin/object-storage-key-rotation).\n 2. [Disk encryption keys](/distributed-cloud/hosted/docs/latest/appliance/admin/disk-encryption-key-rotation).\n 3. [Storage authentication keys and certificates](/distributed-cloud/hosted/docs/latest/appliance/admin/storage-auth-key-and-cert-rotation).\n7. Physical networking (PNET):\n 1. Switch credentials: [`gdcloud appliance rotate switch-credentials`](/distributed-cloud/hosted/docs/latest/appliance/resources/gdcloud-reference/gdcloud-appliance-rotate-switch-credentials)\n 2. Switch certificate: [`gdcloud appliance rotate switch-certificate`](/distributed-cloud/hosted/docs/latest/appliance/resources/gdcloud-reference/gdcloud-appliance-rotate-switch-certificate)\n\nTo access the runbooks in the IO tools container, see [Set up the IO tools to access runbooks](/distributed-cloud/hosted/docs/latest/appliance/admin/iotool-setup)"]]