設定密鑰輪替
透過集合功能整理內容
你可以依據偏好儲存及分類內容。
本頁面列出相關資源,說明如何為 Google Distributed Cloud (GDC) 氣隙式裝置設定及設定密鑰輪替。
- BM 安全殼層金鑰和憑證:PLATAUTH-G0003
- 機箱憑證、使用者名稱和密碼輪替:APPL-G0001
- 變更主機板管理控制器 (BMC) 和機殼的 iLO 使用者名稱和密碼:
- 整合式 Lights-Out (iLO) 憑證輪替:SERV P0002
- BMC 憑證輪替:SERV P0003
- Ironic 憑證輪替:SERV P0004
- Harbor:
- 叢集內 Harbor 管理員憑證輪替:SAR-R2001
- Harbor 機器人帳戶憑證輪替:SAR-R2003
- 輪替 SAR 憑證:SAR-T0001
- 輪替 Harbor 元件憑證:SAR-T0002
- 輪替識別資訊提供者密鑰:
- Keycloak:IAM-T0001
- 物件儲存空間:
- 物件儲存空間憑證。
- 磁碟加密金鑰。
- 儲存驗證金鑰和憑證。
- 實體網路 (PNET):
- 切換憑證:
gdcloud appliance rotate switch-credentials
- 切換憑證:
gdcloud appliance rotate switch-certificate
如要存取 IO 工具容器中的 Runbook,請參閱「設定 IO 工具以存取 Runbook」一文。
除非另有註明,否則本頁面中的內容是採用創用 CC 姓名標示 4.0 授權,程式碼範例則為阿帕契 2.0 授權。詳情請參閱《Google Developers 網站政策》。Java 是 Oracle 和/或其關聯企業的註冊商標。
上次更新時間:2025-09-04 (世界標準時間)。
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-09-04 (世界標準時間)。"],[],[],null,["# Configure secret rotations\n\nThis page lists the resources for information on how to set up and configure secret rotations for Google Distributed Cloud (GDC) air-gapped appliance.\n\n1. BM SSH keys and certificate: [PLATAUTH-G0003](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/platauth/guides/platauth-g0003)\n2. Chassis certificate, username and password rotation: [APPL-G0001](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/appl/guides/appl-g0001)\n3. Changing the iLO username and password for Baseboard Management Controller (BMC) and chassis:\n 1. Integrated Lights-Out (iLO) credential rotation: [SERV P0002](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/serv/processes/serv-p0002)\n 2. BMC certificate rotation: [SERV P0003](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/serv/processes/serv-p0003)\n 3. Ironic certificate rotation: [SERV P0004](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/serv/processes/serv-p0004)\n4. Harbor:\n 1. In-cluster Harbor admin credentials rotation: [SAR-R2001](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/sar/runbooks/sar-r2001)\n 2. Harbor robot account credentials rotation: [SAR-R2003](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/sar/runbooks/sar-r2003)\n 3. Rotating SAR certificates: [SAR-T0001](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/sar/toil/sar-t0001)\n 4. Rotating Harbor components credentials: [SAR-T0002](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/sar/toil/sar-t0002)\n5. Identity provider secrets rotation:\n 1. Keycloak: [IAM-T0001](/distributed-cloud/hosted/docs/latest/gdch/gdch-io/service-manual/iam/toil/iam-t0001)\n6. Object storage:\n 1. [Object storage credentials](/distributed-cloud/hosted/docs/latest/appliance/admin/object-storage-key-rotation).\n 2. [Disk encryption keys](/distributed-cloud/hosted/docs/latest/appliance/admin/disk-encryption-key-rotation).\n 3. [Storage authentication keys and certificates](/distributed-cloud/hosted/docs/latest/appliance/admin/storage-auth-key-and-cert-rotation).\n7. Physical networking (PNET):\n 1. Switch credentials: [`gdcloud appliance rotate switch-credentials`](/distributed-cloud/hosted/docs/latest/appliance/resources/gdcloud-reference/gdcloud-appliance-rotate-switch-credentials)\n 2. Switch certificate: [`gdcloud appliance rotate switch-certificate`](/distributed-cloud/hosted/docs/latest/appliance/resources/gdcloud-reference/gdcloud-appliance-rotate-switch-certificate)\n\nTo access the runbooks in the IO tools container, see [Set up the IO tools to access runbooks](/distributed-cloud/hosted/docs/latest/appliance/admin/iotool-setup)"]]