You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置GCP云函数仅允许API网关访问 禁止外部直连

问题场景
  • 部署了基于Functions Framework的HTTP类型Cloud Function,实现代码如下:
import functions from "@google-cloud/functions-framework";
const protectedExample = (req, res) => {
  res.send('Protected example');
};
functions.http('protectedExample', protectedExample);
export {protectedExample}
  • 为该函数配套部署了API网关做访问鉴权,使用的Swagger 2.0配置如下:
swagger: '2.0'
info:
  title: hw-api Gateway
  description: Sample API Gateway
  version: 1.0.1
securityDefinitions:
  auth0:
    type: oauth2
    flow: implicit
    x-google-issuer: https://.../
    x-google-jwks_uri: https://.../.well-known/jwks.json
    x-google-audiences: https://.../node
    authorizationUrl: https://.../authorize
    scopes:
      "access:node": Grants read access
schemes:
  - https
produces:
  - application/json
paths:
  /protected:
    get:
      security:
        - auth0: [ "access:node" ]
      summary: Greet a user
      operationId: hello
      x-google-backend:
        address: https://us-central1-....cloudfunctions.net/protectedExample
      responses:
        '200':
          description: A successful response
          schema:
            type: string
  • 现有异常现象:
    1. 经API网关入口访问时,鉴权、请求转发逻辑全部正常
    2. 通过gcloud functions describe protectedExample查询到函数公网直连地址(httpsTrigger.url字段值)后,无需经过API网关的Auth0鉴权即可直接访问函数,存在鉴权绕过风险
  • 已尝试的无效方案:
    给函数设置--ingress-settings=internal-and-gclb入站规则后,经API网关访问函数返回403 Forbidden错误,错误响应内容如下:
<body text=#000000 bgcolor=#ffffff>
    <h1>Error: Forbidden</h1>
    <h2>Access is forbidden.</h2>
    <h2></h2>
</body>
  • 核心诉求:实现访问控制,禁止外部用户直连访问Cloud Function,仅允许API网关转发的流量到达函数。
原因说明

设置--ingress-settings=internal-and-gclb后API网关访问报403的核心原因:该入站规则仅放行两类流量——VPC内网流量、经过Google Cloud原生负载均衡(GCLB)转发且携带合法内部标识的流量。默认配置下API网关通过公网链路直连Cloud Function公网地址,不属于上述两类放行范围,因此直接被入站规则拦截。

配置方案

推荐采用IAM权限收口+网络层隔离的两层控制方案,配置完成后既可以阻断公网直连访问,也不会影响API网关的正常转发:

  1. 第一步:收口函数IAM调用权限(必选,配置完即可阻断无权限的公网直连)
    • 移除函数默认授予所有公网用户的调用权限,执行以下命令:
      gcloud functions remove-iam-policy-binding protectedExample \
        --member=allUsers \
        --role=roles/cloudfunctions.invoker \
        --region=<替换为函数部署区域,例如us-central1>
      
    • 找到API网关使用的默认服务账号,格式为service-<项目数字ID>@gcp-sa-apigateway.iam.gserviceaccount.com,给该服务账号授予函数的调用权限:
      gcloud functions add-iam-policy-binding protectedExample \
        --member=serviceAccount:<替换为API网关服务账号完整邮箱> \
        --role=roles/cloudfunctions.invoker \
        --region=<替换为函数部署区域>
      
    • 修改API网关的Swagger配置,在x-google-backend段新增jwt_audience字段,值为Cloud Function的直连地址,让API网关调用后端时自动携带合法的OIDC认证令牌通过IAM校验,修改后的后端配置段示例:
      x-google-backend:
        address: https://us-central1-....cloudfunctions.net/protectedExample
        jwt_audience: https://us-central1-....cloudfunctions.net/protectedExample
      
    这一步配置完成后重新部署API网关,普通用户直连函数地址会因为缺少IAM权限返回403,API网关的转发请求可正常通过校验。
  2. 第二步:配置网络层隔离(可选,高安全要求场景配置)
    如果需要从网络层面彻底阻断公网到函数的访问链路,在第一步配置完成的基础上继续操作:
    • 创建无服务器VPC访问连接器,和函数部署在同区域
    • 在API网关的x-google-backend段新增VPC连接器配置,让API网关到函数的流量走Google内部私有链路,而非公网转发,配置示例:
      x-google-backend:
        address: https://us-central1-....cloudfunctions.net/protectedExample
        jwt_audience: https://us-central1-....cloudfunctions.net/protectedExample
        vpc_access_connector: projects/<项目ID>/locations/<区域>/connectors/<创建的VPC连接器名称>
      
    • 给函数设置--ingress-settings=internal-and-gclb入站规则,此时API网关的流量走内部私有链路,会被入站规则正常放行,不会再出现403错误。

内容的提问来源于stack exchange,提问作者Jackie

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.28 11:39:40