如何配置GCP云函数仅允许API网关访问 禁止外部直连
问题场景
- 部署了基于Functions Framework的HTTP类型Cloud Function,实现代码如下:
import functions from "@google-cloud/functions-framework"; const protectedExample = (req, res) => { res.send('Protected example'); }; functions.http('protectedExample', protectedExample); export {protectedExample}
- 为该函数配套部署了API网关做访问鉴权,使用的Swagger 2.0配置如下:
swagger: '2.0' info: title: hw-api Gateway description: Sample API Gateway version: 1.0.1 securityDefinitions: auth0: type: oauth2 flow: implicit x-google-issuer: https://.../ x-google-jwks_uri: https://.../.well-known/jwks.json x-google-audiences: https://.../node authorizationUrl: https://.../authorize scopes: "access:node": Grants read access schemes: - https produces: - application/json paths: /protected: get: security: - auth0: [ "access:node" ] summary: Greet a user operationId: hello x-google-backend: address: https://us-central1-....cloudfunctions.net/protectedExample responses: '200': description: A successful response schema: type: string
- 现有异常现象:
- 经API网关入口访问时,鉴权、请求转发逻辑全部正常
- 通过
gcloud functions describe protectedExample查询到函数公网直连地址(httpsTrigger.url字段值)后,无需经过API网关的Auth0鉴权即可直接访问函数,存在鉴权绕过风险
- 已尝试的无效方案:
给函数设置--ingress-settings=internal-and-gclb入站规则后,经API网关访问函数返回403 Forbidden错误,错误响应内容如下:
<body text=#000000 bgcolor=#ffffff> <h1>Error: Forbidden</h1> <h2>Access is forbidden.</h2> <h2></h2> </body>
- 核心诉求:实现访问控制,禁止外部用户直连访问Cloud Function,仅允许API网关转发的流量到达函数。
原因说明
设置--ingress-settings=internal-and-gclb后API网关访问报403的核心原因:该入站规则仅放行两类流量——VPC内网流量、经过Google Cloud原生负载均衡(GCLB)转发且携带合法内部标识的流量。默认配置下API网关通过公网链路直连Cloud Function公网地址,不属于上述两类放行范围,因此直接被入站规则拦截。
配置方案
推荐采用IAM权限收口+网络层隔离的两层控制方案,配置完成后既可以阻断公网直连访问,也不会影响API网关的正常转发:
- 第一步:收口函数IAM调用权限(必选,配置完即可阻断无权限的公网直连)
- 移除函数默认授予所有公网用户的调用权限,执行以下命令:
gcloud functions remove-iam-policy-binding protectedExample \ --member=allUsers \ --role=roles/cloudfunctions.invoker \ --region=<替换为函数部署区域,例如us-central1> - 找到API网关使用的默认服务账号,格式为
service-<项目数字ID>@gcp-sa-apigateway.iam.gserviceaccount.com,给该服务账号授予函数的调用权限:gcloud functions add-iam-policy-binding protectedExample \ --member=serviceAccount:<替换为API网关服务账号完整邮箱> \ --role=roles/cloudfunctions.invoker \ --region=<替换为函数部署区域> - 修改API网关的Swagger配置,在
x-google-backend段新增jwt_audience字段,值为Cloud Function的直连地址,让API网关调用后端时自动携带合法的OIDC认证令牌通过IAM校验,修改后的后端配置段示例:x-google-backend: address: https://us-central1-....cloudfunctions.net/protectedExample jwt_audience: https://us-central1-....cloudfunctions.net/protectedExample
- 移除函数默认授予所有公网用户的调用权限,执行以下命令:
- 第二步:配置网络层隔离(可选,高安全要求场景配置)
如果需要从网络层面彻底阻断公网到函数的访问链路,在第一步配置完成的基础上继续操作:- 创建无服务器VPC访问连接器,和函数部署在同区域
- 在API网关的
x-google-backend段新增VPC连接器配置,让API网关到函数的流量走Google内部私有链路,而非公网转发,配置示例:x-google-backend: address: https://us-central1-....cloudfunctions.net/protectedExample jwt_audience: https://us-central1-....cloudfunctions.net/protectedExample vpc_access_connector: projects/<项目ID>/locations/<区域>/connectors/<创建的VPC连接器名称> - 给函数设置
--ingress-settings=internal-and-gclb入站规则,此时API网关的流量走内部私有链路,会被入站规则正常放行,不会再出现403错误。
内容的提问来源于stack exchange,提问作者Jackie
相关产品推荐
相关产品推荐

