Lộ trình
Google CloudAssociateTuần 3: Kiến trúc & bảo mậtBài 18 / 30

Ngày 18: Networking — VPC

Thời lượng: 45 phút
Mục tiêu: 2 nhiệm vụ chính
Tiến độ lộ trình
gcp-acengày 18
hoàn thành18 / 30 bài
Bối cảnh bài học

Thiết kế GCP VPC bằng subnet, route, firewall và identity-aware boundaries; kiểm chứng request path trước khi mở traffic.

đọc hiểuthực hànhcheckpoint
Bài giảng hôm nay

Học hiểu, rồi mới thực hành

Thiết kế GCP VPC bằng subnet, route, firewall và identity-aware boundaries; kiểm chứng request path trước khi mở traffic.

Bắt đầu đọc bài giảng

Nhiệm vụ bài học hôm nay

  • Học VPC, Subnet, Firewall Rules
  • Thực hành tạo Firewall Rule cho phép SSH
Instructor walkthrough

Bài giảng chi tiết: từ bài toán đến bằng chứng

Scenario xuyên suốt

Một VM có external IP nhưng SSH timeout; một firewall rule cho phép SSH từ mọi nơi vào toàn project; team lại tạo subnet sai region. Bài học phân biệt VPC global, subnet regional, route và firewall để thiết kế network có chủ đích.

01Đọc bài toán

Xác định actor, workload, constraint và trạng thái cuối cần đạt.

02Vẽ luồng / boundary

Chỉ ra request, dependency, identity và failure domain trước khi chọn công cụ.

03Chọn và thực hành

Thay đổi nhỏ nhất trong lab cô lập; command nào cũng phải nói rõ nó kiểm tra điều gì.

04Kiểm chứng / recovery

Đối chiếu trạng thái thực tế, tạo một failure variant và ghi cách hoàn tác.

Cách nối lý thuyết với thực tế
  • VPC network là global resource; subnet là regional và chứa IP range; VM interface phải ở subnet đúng region.
  • Routes quyết định next hop; firewall rules là stateful policy theo direction/priority/target/source, không thay route hoặc IAM.
  • Target tags/service accounts giới hạn firewall scope; implied rules và default network có thể tạo surprise exposure.
  • Private Google Access, Cloud NAT, external IP, IAP và VPN/Interconnect là các connectivity choices khác nhau.

Đọc VPC theo request path

Một flow phải trả lời: source ở đâu, destination là gì, interface/subnet nào, route next hop nào và firewall rule nào allow/deny. VPC global không có nghĩa subnet dùng chung mọi region; subnet là regional. Firewall không tạo route và IAM không mở TCP port.

Scope và exposure

Custom VPC giúp kiểm soát CIDR/subnet. Target tag/service account làm rule hẹp hơn; tránh default network và SSH toàn Internet. Private Google Access/NAT/IAP giải quyết các đường đi khác nhau: API private, outbound Internet không cần external IP, hoặc admin access có kiểm soát.

Bài tập

Thiết kế network cho private VM gọi Cloud Storage và nhận admin qua IAP. Inspect read-only metadata, mô phỏng một deny/allow rule, ghi evidence và cleanup. Nếu tạo lab, dùng CIDR riêng, explicit project/region và không đụng shared network.

Terminal reference

Command list và cách dùng

Chạy từng lệnh theo đúng thứ tự. Trước các lệnh có thể tạo hoặc thay đổi tài nguyên, hãy kiểm tra profile, account và region.

Commands · read-only checkpoints
gcloud compute networks list --project=LAB_PROJECT_ID --format="table(name,autoCreateSubnetworks,peerings)"
gcloud compute networks subnets list --network=VPC_NAME --project=LAB_PROJECT_ID --format="table(name,region,ipCidrRange,privateIpGoogleAccess)"
gcloud compute routes list --project=LAB_PROJECT_ID --filter="network:VPC_NAME" --format="table(name,destRange,nextHopGateway,nextHopInstance,priority)"
gcloud compute firewall-rules list --project=LAB_PROJECT_ID --filter="network:VPC_NAME" --format="table(name,direction,priority,sourceRanges,targetTags,allowed,denied)"
Hands-on lab

Thực hành theo scenario

  1. Vẽ flow private VM → Cloud Storage/API, inbound IAP/HTTP và outbound Internet; ghi source/destination, route, subnet, firewall, identity và expected evidence.
  2. Inspect networks/subnets/routes/firewall rules read-only; kiểm tra default network, priority, target tags/service accounts và region.
  3. Nếu có sandbox, dùng custom VPC/subnet nhỏ, không mở SSH `0.0.0.0/0`, ưu tiên IAP/private access, tạo một rule có target hẹp rồi test allow/deny.
  4. Cleanup test VM/rule/subnet/network/NAT theo dependency; verify routes/firewall/IP ranges và không xóa shared/production network.
Evidence checkpoint

Kiểm chứng kết quả

Không coi lệnh chạy thành công là đủ. Hãy đối chiếu output với trạng thái mong đợi:

  • Phân biệt global VPC, regional subnet, route và firewall.
  • Request path có source/destination/next hop/control.
  • Firewall scope/priority/target không mở rộng ngoài requirement.
  • Private access/NAT/IAP có rationale.
  • Cleanup network resources an toàn và có inventory evidence.
Transfer to exam / production

Bẫy thường gặp và trade-off

ACE thường nhầm global VPC với regional subnet, firewall với route và IAM với network policy. Đọc chiều traffic, target và priority trước khi chọn rule.

Checkpoint · 3 phút

Kiểm tra nhanh

Câu hỏi: VM không có external IP cần gọi Cloud Storage và admin không muốn mở SSH public. Thiết kế nào phù hợp nhất?

Kết thúc bài

Checklist trước khi sang Ngày 2