You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过API获取GKE集群安全态势中的配置问题(Concerns)

获取GKE Security Posture中Workload配置问题的API方法

要拉取GKE「Security Posture」里的Pod Security Spec相关配置问题(即UI中的Concerns),需要使用Google Cloud Security Command Center (SCC) 的Container Security API,以下是具体实现步骤:

1. 权限准备

给用于调用API的服务账号授予以下角色之一:

  • roles/securitycenter.viewer:只读权限,足够获取扫描结果
  • roles/securitycenter.adminViewer:包含更多管理权限的只读角色

2. API调用方式

用gcloud命令行快速验证

先通过gcloud命令测试是否能获取结果,替换括号内的参数:

gcloud scc findings list \
  --organization=organizations/[你的组织ID] \
  --filter="resource_type=\"WORKLOAD_CONFIGURATION\" AND resource_name:\"projects/[项目ID]/locations/[集群区域]/clusters/[集群名称]\"" \
  --format=json

REST API请求

直接发送GET请求(需携带OAuth2认证令牌):

GET https://securitycenter.googleapis.com/v1/organizations/[你的组织ID]/findings?filter=resource_type%3D%22WORKLOAD_CONFIGURATION%22%20AND%20resource_name%3A%22projects%2F[项目ID]%2Flocations%2F[集群区域]%2Fclusters%2F[集群名称]%22

Python代码示例

使用官方SDK封装逻辑,先安装依赖:pip install google-cloud-securitycenter

from google.cloud import securitycenter

def fetch_gke_workload_concerns(org_id, project_id, cluster_loc, cluster_name):
    client = securitycenter.SecurityCenterClient()
    org_resource = f"organizations/{org_id}"
    # 过滤条件:指定资源类型为工作负载配置,关联目标集群
    filter_expr = (
        f'resource_type="WORKLOAD_CONFIGURATION" AND '
        f'resource_name:"projects/{project_id}/locations/{cluster_loc}/clusters/{cluster_name}"'
    )

    findings = client.list_findings(request={"parent": org_resource, "filter": filter_expr})

    # 整理符合UI中Concern定义的字段
    concern_list = []
    for finding in findings:
        concern = {
            "concern_id": finding.name.split("/")[-1],
            "category": finding.category,  # 对应UI中的问题类型(如Pod Security标准违规)
            "affected_resource": finding.resource_name,  # 关联的Pod/Deployment等资源
            "severity": finding.severity,
            "details": finding.source_properties,  # 具体配置违规详情
            "detected_at": finding.create_time,
            "updated_at": finding.update_time
        }
        concern_list.append(concern)
    return concern_list

# 调用示例
if __name__ == "__main__":
    org_id = "123456789012"
    project_id = "your-gcp-project-id"
    cluster_loc = "us-central1"
    cluster_name = "your-gke-cluster-name"
    
    results = fetch_gke_workload_concerns(org_id, project_id, cluster_loc, cluster_name)
    print(results)

3. 返回结果说明

返回的Finding对象中,关键字段对应UI中的信息:

  • category:对应UI里的Concern类型(如POD_SECURITY_STANDARD_BASIC)
  • source_properties:包含具体违规细节,比如不符合的安全控制项、资源的具体配置值
  • severity:问题的严重等级(如MEDIUM/HIGH)

内容的提问来源于stack exchange,提问作者NP-complete

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.14 22:25:27