【发布时间】:2021-07-04 20:16:01
【问题描述】:
这与以下问题有关,已过时
- Possible to get static IP address for Google Cloud Functions?
- Google Cloud - Egress IP / NAT / Proxy for google cloud functions
目前 GCP 有 VPC Serverless Connector,可让您通过 VPC 连接器路由所有流量并设置 Cloud NAT 以获取静态 IP 地址。
我已按照以下指南 https://cloud.google.com/functions/docs/networking/network-settings#associate-static-ip 使用区域 us-east4,但来自我的云功能的外部请求总是超时。
我不确定这是一个错误还是我遗漏了什么。
编辑:
为确保我已遵循所有步骤,我尽可能使用gcloud 命令完成所有步骤。这些命令是从 GCP 的指南中复制而来的。
- 设置项目 ID 以供将来使用
PROJECT_ID=my-test-gcf-vpc-nat
转到控制台并启用计费
设置 VPC 和测试 VM 以测试 Cloud NAT
gcloud services enable compute.googleapis.com \
--project $PROJECT_ID
gcloud compute networks create custom-network1 \
--subnet-mode custom \
--project $PROJECT_ID
gcloud compute networks subnets create subnet-us-east-192 \
--network custom-network1 \
--region us-east4 \
--range 192.168.1.0/24 \
--project $PROJECT_ID
gcloud compute instances create nat-test-1 \
--image-family debian-9 \
--image-project debian-cloud \
--network custom-network1 \
--subnet subnet-us-east-192 \
--zone us-east4-c \
--no-address \
--project $PROJECT_ID
gcloud compute firewall-rules create allow-ssh \
--network custom-network1 \
--source-ranges 35.235.240.0/20 \
--allow tcp:22 \
--project $PROJECT_ID
使用控制台创建 IAP SSH 权限
测试网络配置,没有 Cloud NAT,VM 应该无法访问互联网
gcloud compute ssh nat-test-1 \
--zone us-east4-c \
--command "curl -s ifconfig.io" \
--tunnel-through-iap \
--project $PROJECT_ID
命令回复connection timed out
- 设置云 NAT
gcloud compute routers create nat-router \
--network custom-network1 \
--region us-east4 \
--project $PROJECT_ID
gcloud compute routers nats create nat-config \
--router-region us-east4 \
--router nat-router \
--nat-all-subnet-ip-ranges \
--auto-allocate-nat-external-ips \
--project $PROJECT_ID
- 再次测试网络配置,虚拟机应该可以通过 Cloud NAT 访问互联网
gcloud compute ssh nat-test-1 \
--zone us-east4-c \
--command "curl -s ifconfig.io" \
--tunnel-through-iap \
--project $PROJECT_ID
命令以 IP 地址响应
- 已创建 VPC 访问连接器
gcloud services enable vpcaccess.googleapis.com \
--project $PROJECT_ID
gcloud compute networks vpc-access connectors create custom-network1-us-east4 \
--network custom-network1 \
--region us-east4 \
--range 10.8.0.0/28 \
--project $PROJECT_ID
gcloud compute networks vpc-access connectors describe custom-network1-us-east4 \
--region us-east4 \
--project $PROJECT_ID
- 为 Google Cloud Functions 服务帐号添加了权限
gcloud services enable cloudfunctions.googleapis.com \
--project $PROJECT_ID
PROJECT_NUMBER=$(gcloud projects describe $PROJECT_ID --format="value(projectNumber)")
gcloud projects add-iam-policy-binding $PROJECT_ID \
--member=serviceAccount:service-$PROJECT_NUMBER@gcf-admin-robot.iam.gserviceaccount.com \
--role=roles/viewer
gcloud projects add-iam-policy-binding $PROJECT_ID \
--member=serviceAccount:service-$PROJECT_NUMBER@gcf-admin-robot.iam.gserviceaccount.com \
--role=roles/compute.networkUser
- 有建议我应该添加额外的防火墙规则和服务帐户权限
# Additional Firewall Rules
gcloud compute firewall-rules create custom-network1-allow-http \
--network custom-network1 \
--source-ranges 0.0.0.0/0 \
--allow tcp:80 \
--project $PROJECT_ID
gcloud compute firewall-rules create custom-network1-allow-https \
--network custom-network1 \
--source-ranges 0.0.0.0/0 \
--allow tcp:443 \
--project $PROJECT_ID
# Additional Permission, actually this service account has an Editor role already.
gcloud projects add-iam-policy-binding $PROJECT_ID \
--member=serviceAccount:$PROJECT_ID@appspot.gserviceaccount.com \
--role=roles/compute.networkUser
- 已部署测试 Cloud Functions
index.js
const publicIp = require('public-ip')
exports.testVPC = async (req, res) => {
const v4 = await publicIp.v4()
const v6 = await publicIp.v6()
console.log('ip', [v4, v6])
return res.end(JSON.stringify([v4, v6]))
}
exports.testNoVPC = exports.testVPC
# Cloud Function with VPC Connector
gcloud functions deploy testVPC \
--runtime nodejs10 \
--trigger-http \
--vpc-connector custom-network1-us-east4 \
--egress-settings all \
--region us-east4 \
--allow-unauthenticated \
--project $PROJECT_ID
# Cloud Function without VPC Connector
gcloud functions deploy testNoVPC \
--runtime nodejs10 \
--trigger-http \
--region us-east4 \
--allow-unauthenticated \
--project $PROJECT_ID
没有 VPC 连接器的 Cloud Function 以 IP 地址响应 https://us-east4-my-test-gcf-vpc-nat.cloudfunctions.net/testNoVPC
具有 VPC 连接器的 Cloud Functions 超时 https://us-east4-my-test-gcf-vpc-nat.cloudfunctions.net/testVPC
【问题讨论】:
-
您好,您解决了这个问题吗?我已经尝试了 2 天,仍然没有:( stackoverflow.com/questions/64711513/…
-
是的,我有,请按照我的cmets在下面的答案,问题是包
public-ip没有按预期工作,您可以尝试其他方法获取静态IP -
不管我用什么,该功能似乎无法连接到互联网(在我的特殊情况下是尝试连接到 ftp 服务器以删除一些文件)
标签: google-cloud-platform google-cloud-functions google-cloud-networking