[IAM] Cloud IAM: Qwik Start

yejinยท2026๋…„ 4์›” 16์ผ

Google Skills

๋ชฉ๋ก ๋ณด๊ธฐ
7/46

Course

Cloud Engineering

Lab

๋ชฉ๋ก

  • Cloud IAM: Qwik Start โฌ…๏ธ ์˜ค๋Š˜์˜ Lab!
  • Introduction to SQL for BigQuery and Cloud SQL
  • Multiple VPC Networks
  • Cloud Monitoring: Qwik Start
  • Managing Deployments Using Kubernetes Engine

๐ŸŒ Cloud IAM: Qwik Start

๊ฐœ์š”

Google Cloud์˜ Identity and Access Management(IAM) ์„œ๋น„์Šค๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด Google Cloud ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•œ ๊ถŒํ•œ์„ ๋งŒ๋“ค๊ณ  ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ๋‹ค.
์„œ๋กœ ๋‹ค๋ฅธ ๋‘ ๊ฐ€์ง€ ์‚ฌ์šฉ์ž ์ธ์ฆ ์ •๋ณด๋กœ ๋กœ๊ทธ์ธํ•˜์—ฌ Google Cloud ํ”„๋กœ์ ํŠธ ์†Œ์œ ์ž ๋ฐ ๋ทฐ์–ด ์—ญํ• ์—์„œ ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•˜๊ณ  ์ทจ์†Œํ•ด๋ณด์ž!

์‹ค์Šต ๊ณผ์ •

์ฐธ๊ณ โœณ๏ธ

์ด๋ฒˆ ์‹ค์Šต์—๋Š” ํ‰์†Œ ๊ณผ์ •๊ณผ ๋‹ฌ๋ฆฌ, ์„œ๋กœ ๋‹ค๋ฅธ ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ๊ฐ€์ง„ ๋กœ๊ทธ์ธ ๊ณ„์ •์ด 2๊ฐœ๊ฐ€ ์ œ๊ณต๋œ๋‹ค. Open Goolge Console ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜์—ฌ ์ง์ ‘ ์•„์ด๋””(Username)์™€ ๋น„๋ฐ€๋ฒˆํ˜ธ(Password)๋ฅผ ์ž…๋ ฅํ•˜์—ฌ ๋‘ ๊ณ„์ • ๋ชจ๋‘ ๋กœ๊ทธ์ธํ•˜์ž! (๋‘ ๊ณ„์ •์— ๋Œ€ํ•œ ๋น„๋ฐ€๋ฒˆํ˜ธ๋Š” ๋™์ผํ•˜๋‹ค.)

๊ณ„์ • ์ „ํ™˜ ๋ฐฉ๋ฒ•๐Ÿ”

  1. ์‹œํฌ๋ฆฟ ๋ชจ๋“œ๋กœ ์ƒˆ ํƒญ์„ ์—ฌ๋Ÿฌ ๊ฐœ ์—ด์–ด์„œ ๊ฐ๊ฐ์˜ ํƒญ๋งˆ๋‹ค Username1, Username2 ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธํ•œ๋‹ค.
  2. ํ•˜๋‚˜์˜ ํƒญ์—์„œ ์ง„ํ–‰ํ•  ๊ฒฝ์šฐ์—๋Š” ์šฐ์ธก ์ƒ๋‹จ์˜ ํ”„๋กœํ•„ ์‚ฌ์ง„์„ ํด๋ฆญํ•˜๋ฉด ์•„๋ž˜ ๋กœ๊ทธ์ธ ๋œ ๊ณ„์ • ๋ชฉ๋ก์„ ๋ณผ ์ˆ˜ ์žˆ๋‹ค. ๋กœ๊ทธ์ธ์„ ์›ํ•˜๋Š” ๊ณ„์ •์„ ํด๋ฆญ ์‹œ ํ•ด๋‹น ๊ณ„์ •์œผ๋กœ ์ „ํ™˜๋œ๋‹ค.

1. [Username1] IAM ๊ถŒํ•œ ํ™•์ธํ•˜๊ธฐ

1) Username1๋กœ ๋กœ๊ทธ์ธ ํ›„ Cloud Console ์ฐฝ ์—ด๊ธฐ

2) ๋„ค๋น„๊ฒŒ์ด์…˜ ๋ฉ”๋‰ด > IAM & Admin > IAM ๋ฉ”๋‰ด ํด๋ฆญ

3) ๊ถŒํ•œ ๋ถ€์—ฌ ๋ฐฉ๋ฒ• ํ™•์ธ

โžก๏ธ [+Grant Access] ํด๋ฆญ > Basic ์„ ํƒ > ์ƒ์„ธ ๊ถŒํ•œ ์„ ํƒ
โžก๏ธ ํ˜„์žฌ Username1 ๊ณ„์ •์€ ํ•„์š”ํ•œ ๊ถŒํ•œ์ด ๋ถ€์—ฌ๋œ ์ƒํƒœ์ด๋ฏ€๋กœ ๋ณ„๋‹ค๋ฅธ ์ž‘์—…์„ ์•ˆํ•ด๋„ ๋œ๋‹ค. (Cancel ๋ฒ„ํŠผ ํด๋ฆญํ•˜์—ฌ ์ฐฝ ๋‹ซ๊ธฐ)

์ฐธ๊ณ โœจ

์—ญํ•  ์ด๋ฆ„๊ถŒํ•œ
viewr(๋ทฐ์–ด)์ฝ๊ธฐ ์ „์šฉ ์ž‘์—…์— ๋Œ€ํ•œ ๊ถŒํ•œ
Editor(ํŽธ์ง‘์ž)๋ชจ๋“  viwer ๊ถŒํ•œ + ์ƒํƒœ๋ฅผ ๋ณ€๊ฒฝํ•˜๋Š” ์ž‘์—…์— ๋Œ€ํ•œ ๊ถŒํ•œ
Owner(์†Œ์œ ์ž)๋ชจ๋“  Editor ๊ถŒํ•œ + ํ”„๋กœ์ ํŠธ ๋ฐ ํ”„๋กœ์„ธ์Šค ๋‚ด ๋ชจ๋“  ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•œ ์—ญํ•  ๋ฐ ๊ด€๋ฆฌ

4) ๊ฐ ๊ณ„์ •๋ณ„ ๊ถŒํ•œ ํ™•์ธ


2. [Username2] IAM ๊ถŒํ•œ ํ™•์ธํ•˜๊ธฐ

1) Username2๋กœ ๋กœ๊ทธ์ธ ํ›„ Cloud Console ์ฐฝ ์—ด๊ธฐ

2) ๋„ค๋น„๊ฒŒ์ด์…˜ ๋ฉ”๋‰ด > IAM & Admin > IAM ๋ฉ”๋‰ด ํด๋ฆญ

3) (Project๊ฐ€ ์•ˆ ๋œฌ๋‹ค๋ฉด?) Project ์„ ํƒ


โžก๏ธ IAM ๋ฉ”๋‰ด ์ƒ๋‹จ์˜ [Select a progject] ๋ฒ„ํŠผ ํด๋ฆญ > ์‹ค์Šต์šฉ์œผ๋กœ ์ œ๊ณต ๋ฐ›์€ Project ID์™€ ๋™์ผํ•œ ํ”„๋กœ์ ํŠธ ์„ ํƒ

4) ๊ถŒํ•œ ํ™•์ธ


โžก๏ธ ๋ทฐ์–ด ๊ถŒํ•œ๋งŒ ์žˆ๊ธฐ ๋•Œ๋ฌธ์— ๊ถŒํ•œ ์ถ”๊ฐ€ํ•˜๋Š” ๋ฒ„ํŠผ์ด ๋น„ํ™œ์„ฑํ™” ๋˜์–ด ์žˆ๋‹ค.


3. [Username1] Cloud Storage Bucket ์ƒ์„ฑ

1) Cloud Storage > Bucket ๋ฉ”๋‰ด ์ ‘์† > Create bucket ํด๋ฆญ

2) Bucket ์ƒ์„ฑ

  • Name: ์ „์—ญ์œผ๋กœ ๊ณ ์œ ํ•œ ์ด๋ฆ„ ์ง์ ‘ ์ž‘์„ฑ
    (๋‚˜๋Š” 'Username1 ๊ณ„์ •-bucket'์œผ๋กœ ์„ค์ •ํ–ˆ๋‹ค.)
  • Location Type(์œ„์น˜ ์œ ํ˜•): Multi-Region (๊ธฐ๋ณธ๊ฐ’)

์ฐธ๊ณ 


โžก๏ธ ์ƒ์„ฑ ์‹œ ์ด๋Ÿฐ ํŒ์—…์ฐฝ์ด ๋œจ๋ฉด ์ด ์ƒํƒœ๋กœ Confirm ๋ฒ„ํŠผ ํด๋ฆญ!


4. [Username1] Bucket์— ํŒŒ์ผ ์—…๋กœ๋“œ

โžก๏ธ ํŒŒ์ผ ์—…๋กœ๋“œ ๋ฐฉ๋ฒ•์€ ์ด์ „ ํฌ์ŠคํŠธ ๋‚ด์— ์—…๋กœ๋“œ ๋ถ€๋ถ„์„ ์ฐธ๊ณ ํ•˜์—ฌ ์ง„ํ–‰ํ•˜๋ฉด ๋œ๋‹ค. (๋ณ„๋„์˜ ํŒŒ์ผ ์ ‘๊ทผ ๊ถŒํ•œ ๋“ฑ์€ ์„ค์ •ํ•˜์ง€ ์•Š์•„๋„ ๋œ๋‹ค.)


5. [Username2] Bucket ๊ถŒํ•œ ํ™•์ธ

1) Username2๋กœ Cloud Console ์ ‘์† ํ›„ Cloud Storage > Bucket ๋ฉ”๋‰ด ์„ ํƒ

2) 3. ์—์„œ Username1์ด ๋งŒ๋“  Bucket ์ด ๋ณด์ด๋Š” ์ง€ ํ™•์ธ


6. [Username1] Project Viewer ๊ถŒํ•œ ์‚ญ์ œ

1) ๋„ค๋น„๊ฒŒ์ด์…˜ ๋ฉ”๋‰ด > IAM & Admin > IAM ๋ฉ”๋‰ด

2) Username2 ๊ณ„์ • ์˜†์— ํŽธ์ง‘(โœ๏ธ) ๋ฒ„ํŠผ ํด๋ฆญ

3) ์„ค์ •๋˜์–ด ์žˆ๋Š” Viewer ๊ถŒํ•œ์„ ์‚ญ์ œ(๐Ÿ—‘๏ธ)


7. [Username2] Project Viewer ๊ถŒํ•œ ํ™•์ธ

โžก๏ธ ๋„ค๋น„๊ฒŒ์ด์…˜ ๋ฉ”๋‰ด > Cloud Storage > Bucket > Select a project > 2-3. ์—์„œ ํ™•์ธํ–ˆ์—ˆ๋˜ Username1์ด ๋งŒ๋“  Bucket์ด ๋ชฉ๋ก์— ๋ณด์ด์ง€ ์•Š์Œ์„ ํ™•์ธ (=๊ถŒํ•œ ์—†์Œ)


8. [Username1] Cloud Storage ๊ถŒํ•œ ์ถ”๊ฐ€

1) Username2 ์ด๋ฆ„ ๋ณต์‚ฌ

2) Username1์˜ Cloud Console ์ „ํ™˜

3) ๋„ค๋น„๊ฒŒ์ด์…˜ ๋ฉ”๋‰ด > IAM & Admin > IAM ํด๋ฆญ

4) [+GRANT ACCESS] ๋ฒ„ํŠผ์„ ํ†ตํ•ด ๊ถŒํ•œ ๋ถ€์—ฌ

์„ค์ • ํ•ญ๋ชฉ

  1. New principlas: Username2 ์ด๋ฆ„
  2. Assign roles > Select a role > Cloud Storage > Storage Object Viewr ์„ ํƒ

9. [Username2] Access ํ™•์ธ

1) Username2 Cloud Console ์ „ํ™˜

2) Storage Object Viewer ๊ถŒํ•œ ํ™•์ธ

์ฐธ๊ณ ๐Ÿ’ก

Username2๋Š” Project Viewer ๊ถŒํ•œ์ด ์—†์–ด์„œ ์ฝ˜์†”์—์„œ ํ”„๋กœ์ ํŠธ ๋˜๋Š” ํ”„๋กœ์ ํŠธ์˜ ๋ฆฌ์†Œ์Šค๋ฅผ ๋ณผ ์ˆ˜ ์—†๋‹ค. ํ•˜์ง€๋งŒ ์ด์ „ 8. ๋ฒˆ์—์„œ Cloud Storage์— ๋Œ€ํ•œ ํŠน์ • ์•ก์„ธ์Šค ๊ถŒํ•œ์ธ Storage Object Viewer์„ ๋ถ€์—ฌ ๋ฐ›์•˜์œผ๋ฏ€๋กœ Cloud Storage ๋ฒ„ํ‚ท์— ๋Œ€ํ•œ ๋ณด๊ธฐ ๊ถŒํ•œ์ด ์žˆ๋‹ค.

a. Cloud Shell์„ ํ™œ์„ฑํ™”ํ•œ๋‹ค.
b. ๋‹ค์Œ์˜ ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ•œ๋‹ค.

gsutil ls gs://[YOUR_BUCKET_NAME]
#Bucket์˜ ์ด๋ฆ„์€ Cloud Storage > Bucket ์—์„œ ๋งŒ๋“  ์ด๋ฆ„์ด๋‹ค.

c. ์ถœ๋ ฅ ๊ฒฐ๊ณผ ํ™•์ธ

gs://[YOUR_BUCKET_NAME]/sample.txt

โžก๏ธ Username2 ์—๊ฒŒ Cloud Storage ๋ฒ„ํ‚ท์— ๋Œ€ํ•œ ๋ณด๊ธฐ ๊ถŒํ•œ์ด ๋ถ€์—ฌ๋˜์–ด ๋ฒ„ํ‚ท ์•ˆ์— ์žˆ๋Š” ๋ชฉ๋ก๋“ค์„ ์กฐํšŒํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋˜์—ˆ๋‹ค.

profile
์ƒˆ์‹น ๊ฐœ๋ฐœ์ž

0๊ฐœ์˜ ๋Œ“๊ธ€