Tetap teratur dengan koleksi
Simpan dan kategorikan konten berdasarkan preferensi Anda.
Batasan kebijakan keamanan Cloud Service Mesh
Cloud Service Mesh menyediakan API yang andal dan fleksibel yang dapat Anda gunakan untuk mengonfigurasi
mesh. Namun, tanpa pengelolaan yang tepat atas resource ini, mesh Anda
mungkin mengekspos kerentanan keamanan. Mengintegrasikan
Policy Controller
dengan batasan kebijakan keamanan Cloud Service Mesh dapat membantu menerapkan mesh Anda
dengan praktik terbaik keamanan dan mencegah kerentanan.
Halaman ini mengasumsikan bahwa Anda sudah memahami
batasan kebijakan.
Template batasan
Saat Anda menginstal Pengontrol Kebijakan,
pilih Instal library template default. Opsi ini men-deploy
semua template batasan kebijakan keamanan Cloud Service Mesh yang diperlukan untuk
mesh Anda. Untuk daftar lengkap template batasan keamanan Cloud Service Mesh, lihat
Library template batasan
dan cari template yang diawali dengan Asm.
Beberapa template batasan diinstal dengan library template default,
tetapi tidak disertakan dalam paket kebijakan keamanan. Template batasan ini
mendukung kasus penggunaan tertentu, dan Anda dapat mengonfigurasi batasan Anda sendiri:
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-09-04 UTC."],[],[],null,["Cloud Service Mesh security policy constraints\n\nCloud Service Mesh provides you with powerful and flexible APIs that you can use to configure\nyour mesh. However, without proper management over these resources, your mesh\nmight expose security vulnerabilities. Integrating\n[Policy Controller](/anthos-config-management/docs/concepts/policy-controller)\nwith Cloud Service Mesh security policy constraints can help enforce your mesh\nwith security best practices and prevent vulnerabilities.\n\nThis page assumes you are already familiar with\n[policy constraints](/anthos-config-management/docs/how-to/creating-policy-controller-constraints).\n\nConstraints templates\n\nWhen you [install Policy Controller](/anthos-config-management/docs/how-to/installing-policy-controller),\nselect **Install default template library** . This option deploys\nall of the Cloud Service Mesh security policy constraint templates needed for your\nmesh. For a full list of the Cloud Service Mesh security constraint templates, see\nthe [Constraint template library](/anthos-config-management/docs/latest/reference/constraint-template-library)\nand look for templates that are prefixed with `Asm`.\n\nConstraints bundle\n\nWe offer an out-of-box constraints bundle for Cloud Service Mesh security policy.\nFor the bundle details and instructions, see\n[Using Cloud Service Mesh security policies](/anthos-config-management/docs/how-to/using-asm-security-policy).\n\nTo follow a tutorial that shows you how to apply this bundle, see\n[Strengthen your app's security with Cloud Service Mesh, Config Sync, and Policy Controller](/service-mesh/v1.20/docs/strengthen-app-security).\n\nAdd-on constraints\n\nSome constraint templates are installed with the default template library,\nbut not included in the security policy bundle. These constraint\ntemplates serve specific use cases, and you can configure your own constraints:\n\n- [AsmAuthzPolicyDisallowedPrefix](/anthos-config-management/docs/latest/reference/constraint-template-library#asmauthzpolicydisallowedprefix)\n- [AsmAuthzPolicyEnforceSourcePrincipals](/anthos-config-management/docs/latest/reference/constraint-template-library#asmauthzpolicyenforcesourceprincipals)"]]