简体   繁体   English

将云身份添加到现有的 Google Cloud 项目

[英]Add cloud identity to existing Google Cloud Projects

I have 2 Google Cloud projects with GKE and various other services enabled and running.我有 2 个启用并运行 GKE 和其他各种服务的 Google Cloud 项目。 None of those projects has an organization resource assigned.这些项目都没有分配组织资源。 There are also many Users and serviceaccounts inside the projects that are used in production.项目中还有许多用于生产的用户和服务帐户。 We use (example) adminaccount@example.com for those projects.对于这些项目,我们使用(示例)adminaccount@example.com。 I would like to add Google Identity Free, so that I will be able to use Azure AD Users with SSO我想添加 Google Identity Free,这样我就可以通过 SSO 使用 Azure AD 用户

So I created a new Google Identity Account with the username identityadmin@example.com which is not member of my existing Gcloud projects.因此,我使用用户名 identityadmin@example.com 创建了一个新的 Google 身份帐户,该帐户不是我现有 Gcloud 项目的成员。 The domain (example.com) has not been verified so far.到目前为止,域 (example.com) 尚未经过验证。

What will I have to do to get this running with my existing projects?我必须做些什么才能让我现有的项目运行起来? I read that first I would need an organization resource, which would be created after I verify the domain.我首先阅读了我需要一个组织资源,该资源将在我验证域后创建。 Is it safe to do that?这样做安全吗? Will I afterwards be able to link my existing projects to this new organization without downtime and loss of existing permissions?之后我是否能够将现有项目链接到这个新组织而无需停机和丢失现有权限?

I don't understand how a new organization could be recognized by my existing projects, because there is no link between them.我不明白我现有的项目如何识别新组织,因为它们之间没有联系。

The goal of course is not to have any downtime.目标当然是不停机。

Sure, I would purchase Google support, but that's only possible If you have an organization, what I don't have.当然,我会购买 Google 支持,但这只有在你有组织的情况下才有可能,而我没有。 I'm really confused and troubled.我真的很困惑和困扰。

Looking forward to any suggestions.期待任何建议。 Many thanks in advance!提前谢谢了! Roland罗兰

Firstly, you need to create your new organization.首先,您需要创建新组织。 Start by creating a Google Workspace environment (go to https://admin.google.com and create it).首先创建一个 Google Workspace 环境(转到https://admin.google.com并创建它)。 You can create the org with a Google Workspace free trial and then cancel your subscription, no worry, I'm paying nothing!您可以通过 Google Workspace 免费试用创建组织,然后取消订阅,不用担心,我无需支付任何费用!

Secondly, with your new Google Workspace account, and your new user, go to https://console.cloud.google.com .其次,使用您的新 Google Workspace 帐户和新用户 go 到https://console.cloud.google.com Here, select your organization, and go to IAM.在这里,select 是您的组织,go 是 IAM。 Here add as member the user account where your project are created in the "No Organization" organisation, and grant it the role Organization Administrator在此处将在“无组织”组织中创建项目的用户帐户添加为成员,并授予其角色Organization Administrator

在此处输入图像描述

Perfect.完美的。 Now, go back to your user account (freshly granted) and go to ressource manager.现在,go 回到您的用户帐户(新授予)和 go 到资源管理器。 I use the project picker window to go there我在那里使用项目选择器 window 到 go

在此处输入图像描述

And eventually, migrate your project.最后,迁移您的项目。 Select one project from "No Organization", click on migrate, select the Organization, and validate. Select 来自“无组织”的一个项目,点击迁移,select 组织,并验证。 That's all.就这样。 No downtime没有停机时间

在此处输入图像描述

Your Cloud Identity organization is created when you finish your signup and setup steps for your Cloud Identity service您的 Cloud Identity 组织在您完成 Cloud Identity 服务的注册和设置步骤后创建

To answer your questions:要回答您的问题:

What will I have to do to get this running with my existing projects?我必须做些什么才能让我现有的项目运行起来?

The simple answer is Migrate projects and billing accounts and set permissions This documentation explains how Grant access to billing accounts and Grant access to projects简单的答案是迁移项目和计费帐户并设置权限此文档说明如何授予对计费帐户的访问权限和授予对项目的访问权限

Will I afterwards be able to link my existing projects to this new organization without downtime and loss of existing permissions?之后我是否能够将现有项目链接到这个新组织而无需停机和丢失现有权限?

Once a Google Cloud Organization resource has been created for your domain, you can move your existing projects into the organization.为您的域创建 Google Cloud 组织资源后,您可以将现有项目移至组织中。 There should be NO server downtime or impact as a result of migration.迁移不会导致服务器停机或影响。

Take into consideration that the link between projects and billing accounts is preserved, irrespective of the hierarchy.考虑到项目和计费帐户之间的链接被保留,而与层次结构无关。

To migrate a project using you will need the following permissions: resourcemanager.projects.create on the destination organization, typically granted by the Project Creator role.要使用您迁移项目,您需要以下权限:目标组织上的resourcemanager.projects.create ,通常由Project Creator角色授予。

resourcemanager.projects.update and resourcemanager.projects.setIAMPolicy on the project you are migrating, typically granted by the Owner role.正在迁移的项目上的resourcemanager.projects.updateresourcemanager.projects.setIAMPolicy ,通常由Owner角色授予。

You can get further information in the following link: Migrating projects with no organization您可以在以下链接中获得更多信息: 迁移没有组织的项目

在此处输入图像描述

Additionally to contact support you could create a case using this link and it doesn't matter if you don't have an organization.此外,要联系支持人员,您可以使用此链接创建案例,如果您没有组织也没关系。

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

相关问题 链接现有的Firebase和Google Cloud项目 - Link existing Firebase and Google Cloud projects Google Cloud Monitor - 在一个仪表板中添加不同的项目 - Google Cloud Monitor - add different projects in one dashboard Firebase和Google Cloud项目整合 - Firebase and Google Cloud projects consolidation 在 Google Cloud Platform 中更新项目 - Updating projects in Google Cloud Platform Google Cloud上的自定义身份提供商 - Custom Identity Provider on Google Cloud Google Cloud项目和Firebase项目有限制吗? - There is limit on google cloud projects and firebase projects? Google Cloud“Cloud Identity”、“Firebase Auth”、“Identity Platform”之间的区别 - Difference between Google Cloud "Cloud Identity", "Firebase Auth", "Identity Platform" Google云平台:为现有实例添加新界面 - Google cloud platform: Add new interface to existing instance 将新节点添加到Google Cloud上的现有datastax集群 - Add a new node to existing datastax cluster on google cloud google-cloud/resource' cloud function 未列出所有项目作为响应 - google-cloud/resource' cloud function not listing all projects in response
 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM