You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何限制GCP App Engine部署的网站仅允许企业内网访问?

如何限制GCP App Engine网站仅对企业内网开放

Hey there, let's break down the most practical, production-proven ways to lock down your App Engine site so only users on your corporate network can access it:

1. IP地址白名单(快速直接的方案)

If your corporate network has static public IP ranges, this is the simplest approach. You can configure it directly in your app.yaml (for standard environments) or use Cloud Armor for more flexibility (ideal for multiple IP segments or frequent rule updates).

直接在app.yaml配置(标准环境)

Add an ip_whitelist section to your handler rules to allow only your corporate IPs:

runtime: python39
service: internal-corp-site

handlers:
- url: /.*
  script: auto
  secure: always
  ip_whitelist:
    - 192.168.0.0/16  # 替换为你的企业公网IP段
    - 203.0.113.10/32 # 单个特定IP示例

注意:这个方法仅适用于App Engine标准环境。如果使用灵活环境,优先选择Cloud Armor。

使用Cloud Armor(企业级灵活方案)

  1. 打开Cloud Armor控制台,创建新的安全策略。
  2. 添加"允许"规则,将企业IP范围设为源IP。
  3. 关联该安全策略到App Engine的HTTPS负载均衡器(需先为App Engine配置负载均衡)。
  4. 可选:添加"拒绝所有其他流量"的默认规则,确保白名单外的请求全部被拦截。

2. VPC连接+防火墙限制(适合已对接企业内网到GCP的场景)

If your corporate network is connected to GCP via VPN or Cloud Interconnect, use Serverless VPC Access to tie your App Engine service to your VPC, then leverage firewall rules to lock down access.

  1. 创建Serverless VPC Access连接器,将App Engine接入你的GCP VPC。
  2. 在app.yaml中配置使用该连接器:
vpc_access_connector:
  name: projects/[你的项目ID]/locations/[区域]/connectors/[连接器名称]
  1. 在VPC防火墙中创建规则,仅允许来自企业内网IP范围的流量访问App Engine的80/443端口。
  2. 确保App Engine服务不对外暴露独立IP,所有流量必须通过VPC或负载均衡进入。

3. IAP双重验证(身份+IP的双重保障)

For an extra layer of security, combine Identity-Aware Proxy (IAP) with IP restrictions. This ensures only authenticated corporate users on your network can access the site.

  1. 启用App Engine的IAP保护,关联你的企业身份提供商(如G Suite、Azure AD)。
  2. 在IAP访问权限设置中,添加你的企业用户组或域。
  3. 配置IAP的IP限制规则,仅允许来自企业网络IP范围的请求通过验证。
  4. 这样即便有人获取了企业用户凭据,也无法从外部网络访问你的站点。

内容的提问来源于stack exchange,提问作者VIVEK KUMAR

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 09:26:23