VPC Service Controls 是一项 Google Cloud 功能,可让您为资源设置服务边界并创建数据传输边界 Google Cloud 。VPC Service Controls 可为您的 App Hub 资源提供更强的安全保障,例如降低数据渗漏的风险。使用 VPC Service Controls,您可以将项目添加到服务边界,从而防止应用、服务和工作负载受到跨边界的请求的影响。
App Hub 资源会显示在 apphub.googleapis.com API 上,该 API 可让您执行操作,例如创建和删除应用、服务和工作负载。您可以通过限制与此 API 表面的连接来设置 VPC Service Controls 和 App Hub。
我们建议您在创建服务边界时保护所有 App Hub 资源。
限制
您必须先在 App Hub 宿主项目和服务项目中设置 VPC Service Controls,然后才能创建应用并将服务和工作负载注册到应用。App Hub 支持以下资源类型:
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-04-22。"],[[["VPC Service Controls enhances security for Google Cloud resources by establishing a service perimeter and a data transfer boundary, reducing the risk of data exfiltration."],["App Hub resources, accessible through the `apphub.googleapis.com` API, can be secured using VPC Service Controls by limiting connectivity to this API."],["Protecting all App Hub resources within a service perimeter is a recommended practice."],["VPC Service Controls must be configured on the App Hub host and service projects prior to creating applications and registering services/workloads."],["App Hub allows different resource types such as Applications, Discovered Services, Discovered Workloads, Services, Service Project Attachments and Workloads."]]],[]]