You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Terraform中声明GCP Cloud Armor高级模式规则选项块?

使用Terraform配置GCP Cloud Armor高级规则验证HTTP请求头

要在Terraform中为Cloud Armor配置验证HTTP请求头的高级规则,核心是利用google_compute_security_policy资源的rule块中的expression字段编写CEL(Common Expression Language)表达式,替代简单匹配规则。

核心配置示例

以下是完整的Terraform配置,包含多个验证请求头的高级规则:

resource "google_compute_security_policy" "app_security_policy" {
  name        = "app-security-policy"
  description = "Security policy with advanced HTTP header validation"

  # 规则1:验证请求是否通过HTTPS转发
  rule {
    name        = "enforce-https"
    priority    = 1000
    action      = "allow"
    description = "Allow only requests forwarded over HTTPS"

    expression = "request.headers['X-Forwarded-Proto'].lower() == 'https'"
  }

  # 规则2:验证Authorization头是否包含Bearer Token
  rule {
    name        = "validate-auth-token"
    priority    = 900
    action      = "deny(401)"
    description = "Deny requests missing valid Bearer token"

    expression = "request.headers['Authorization'].startsWith('Bearer ')"
  }

  # 规则3:验证自定义业务头的合法性
  rule {
    name        = "validate-app-key"
    priority    = 800
    action      = "deny(403)"
    description = "Allow only requests with valid X-App-Key"

    expression = "request.headers['X-App-Key'] == 'your-secure-app-key-2024'"
  }

  # 默认规则:拒绝所有未匹配的请求
  rule {
    name        = "default-deny-all"
    priority    = 2147483647
    action      = "deny(403)"
    description = "Default rule to deny unallowed requests"
  }
}

关键语法说明

  • CEL表达式基础:通过request.headers['Header-Name']访问请求头,头名称不区分大小写,可配合lower()/upper()统一大小写避免匹配问题。
  • 常用字符串操作:
    • startsWith('prefix'):验证头内容是否以指定前缀开头
    • matches('regex-pattern'):用正则表达式验证格式,比如验证Token格式:request.headers['Authorization'].matches('^Bearer [A-Za-z0-9-_]{10,}$')
    • &&/||:组合多个验证条件,例如request.headers['X-Forwarded-Proto'].lower() == 'https' && request.headers['X-App-Key'] == 'valid-key'
  • 动作类型:支持allow、deny(status_code)(如deny(401)返回未授权)、redirect等。

关联到负载均衡器

将配置好的安全策略关联到后端服务,即可让负载均衡器应用这些规则:

resource "google_compute_backend_service" "app_backend" {
  name        = "app-backend-service"
  protocol    = "HTTP"
  port_name   = "http"
  timeout_sec = 10

  backend {
    group = google_compute_instance_group_manager.app_instance_group.self_link
  }

  # 关联Cloud Armor安全策略
  security_policy = google_compute_security_policy.app_security_policy.self_link
}

验证规则有效性

可以用GCP CLI测试表达式逻辑,确保规则符合预期:

gcloud compute security-policies rules test \
  --security-policy=app-security-policy \
  --expression="request.headers['X-Forwarded-Proto'].lower() == 'https'" \
  --headers="X-Forwarded-Proto:HTTPS"

内容的提问来源于stack exchange,提问作者Abhishek Sc

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 07:18:30