如何将Google Compute Engine的访问权限仅限于我的Firebase云功能

8 firebase google-compute-engine google-cloud-platform google-cloud-functions

是否可以在Compute引擎上保护我的服务,以便只有我的Firebase功能可以使用vpc /防火墙规则访问它?

Dav*_*vid 3

您可以使用Identity-Aware Proxy ,并使用 Cloud Functions 的默认服务帐户 (project_id@appspot.gserviceaccount.com)让函数作为服务帐户进行身份验证,而不是使用 VPC/防火墙来保护 GCE 实例。这对于网络变化非常强大,并且非常灵活。