Google Cloud 가상 프라이빗 클라우드(VPC) 서비스 제어를 사용하면 데이터 무단 반출로부터 보호할 수 있는 보안 경계를 설정할 수 있습니다. Cloud 할당량에 대한 API 요청이 VPC 서비스 경계 내에 있도록 VPC 서비스 제어와 함께 Cloud 할당량을 구성합니다.
제한사항
VPC 서비스 제어는 프로젝트 수준에서 경계를 적용하므로 경계 내부의 클라이언트에서 발생하는 Cloud Quotas 요청은 조직에서 이그레스 규칙을 설정한 경우에만 조직 리소스에 액세스할 수 있습니다.
이그레스 규칙을 설정하려면 인그레스 및 이그레스 정책 구성에 대한 VPC 서비스 제어 안내를 참조하세요.
[[["이해하기 쉬움","easyToUnderstand","thumb-up"],["문제가 해결됨","solvedMyProblem","thumb-up"],["기타","otherUp","thumb-up"]],[["이해하기 어려움","hardToUnderstand","thumb-down"],["잘못된 정보 또는 샘플 코드","incorrectInformationOrSampleCode","thumb-down"],["필요한 정보/샘플이 없음","missingTheInformationSamplesINeed","thumb-down"],["번역 문제","translationIssue","thumb-down"],["기타","otherDown","thumb-down"]],["최종 업데이트: 2025-09-04(UTC)"],[[["\u003cp\u003eGoogle Cloud VPC Service Controls allows you to establish a secure perimeter to prevent data exfiltration, ensuring Cloud Quotas API requests remain within the designated boundary.\u003c/p\u003e\n"],["\u003cp\u003eVPC Service Controls for Cloud Quotas are enforced on specific actions, including quota preference creation, update, get, and list, as well as quota info get and list operations.\u003c/p\u003e\n"],["\u003cp\u003eTo access organization resources via Cloud Quotas from within the service perimeter, an egress rule must be configured by the organization.\u003c/p\u003e\n"],["\u003cp\u003eSetting up VPC Service Controls for Cloud Quotas involves creating a service perimeter, adding protected projects, and restricting the Cloud Quotas API within that perimeter, following provided instructions.\u003c/p\u003e\n"],["\u003cp\u003eAfter the perimeter is configured, VPC Service Controls verifies that calls to the Cloud Quotas API originate from within the same defined perimeter.\u003c/p\u003e\n"]]],[],null,["# Configure VPC Service Controls for Cloud Quotas\n\nGoogle Cloud Virtual Private Cloud (VPC) Service Controls lets you set up a\nsecure perimeter to guard against data exfiltration. Configure\nCloud Quotas with\n[VPC Service Controls](/vpc-service-controls/docs/overview) so that API\nrequests to Cloud Quotas stay within the VPC\nservice perimeter boundary.\n\nLimitations\n-----------\n\nBecause VPC Service Controls enforces boundaries at the project level,\nCloud Quotas requests that originate from clients within the\nperimeter can only access organization resources if the organization sets up an\n[egress rule](/vpc-service-controls/docs/ingress-egress-rules).\nTo set up an egress rule, see the VPC Service Controls instructions for\n[configuring ingress and egress policies](/vpc-service-controls/docs/configuring-ingress-egress-policies)\n\nEnforced actions\n----------------\n\nVPC Service Controls is only enforced on the following\nCloud Quotas actions:\n\n- [Quota preference](/docs/quotas/api-overview#quota_preference) creation, update, get and list.\n- [Quota info](/docs/quotas/api-overview#quota_info) get and list.\n\nFor examples of setting\n[`QuotaPreference`](/docs/quotas/api-overview#quota_preference) and\n[`QuotaInfo`](/docs/quotas/api-overview#quota_info), see the description of\nthe [API resource model](/docs/quotas/api-overview#api_resource_model).\nFor reference information, see the\n[REST API overview](/docs/quotas/reference/rest).\n\nSet up\n------\n\nFollow these steps to restrict the Cloud Quotas API to your\nVPC service perimeter:\n\n1. Follow the instructions to [set up the Cloud Quotas API](/docs/quotas/development-environment).\n\n2. Follow the [VPC Service Controls Quickstart](/vpc-service-controls/docs/set-up-service-perimeter)\n to complete the following tasks:\n\n 1. [Create a service perimeter](/vpc-service-controls/docs/set-up-service-perimeter#set-up-perimeter).\n 2. [Add projects to the perimeter](/vpc-service-controls/docs/set-up-service-perimeter#add-projects-perimeter) that you want to protect.\n 3. Restrict the Cloud Quotas API. For example, see these instructions that add [other Google Cloud APIs to the VPC service\n perimeter](/vpc-service-controls/docs/set-up-service-perimeter#secure-services-perimeter).\n\nAfter setting up your service perimeter, VPC Service Controls checks calls\nto the Cloud Quotas API to help make sure that the calls originate\nfrom within the same perimeter.\n\nWhat's next\n-----------\n\n- Learn about [VPC Service Controls](/vpc-service-controls/docs/overview).\n- See the Cloud Quotas entry in the [VPC Service Controls supported products table](/vpc-service-controls/docs/supported-products#table_quotas).\n- Refer to the description of the Cloud Quotas [API resource model](/docs/quotas/api-overview#api_resource_model) for examples."]]