主机静态index.html通过云存储+负载平衡器(外部,classi)+没有公共桶的装甲边缘政策?
我的目标:
- 静态索引的储物桶
- 。
- 带有 ....
问题:
是否可以实现这种情况而无需公开存储桶?因此,将 /test/index.html的请求路由到(私有)存储后端存储桶?
我能找到的所有教程始终将储物存储桶公开向“ Allusers”公开。在这种情况下,即使拥有带有边缘安全策略的负载平衡器,也可以在击中存储存储桶公共网址时直接访问该文件。
我们希望发布仅应与另一支团队管理的AWS(固定NAT IP)托管的代理服务的前端零件。因此,我希望能够将这些前部零件放入通过外部负载平衡器获得服务的储物桶中(经典),但不应公开,因为每个请求都应通过LB路由后端桶有一个云装甲边缘。仅允许通过某些IP范围访问的安全存储桶(来自另一个团队的AWS NAT IP)
是可能的吗?
my goals:
- storage bucket with static index.html (that is not public to "allUsers")
- global external load balancer (classic) with backend bucket + cloud armor edge policy allowing only certain ip ranges
- url mapping etc....
question:
is it possible to achive this scenario WITHOUT making the storage bucket public? so a request for /test/index.html is routed to the (private) storage backend bucket?
all tutorials i can find always make the storage bucket public to "allUsers". in this case even having a load balancer with edge security policy one can access the file directly when hitting the storage bucket public url.
we want to publish frontend parts that should only be reachable to a proxy service that is hosted in aws (with fixed nat ips) managed by another team. so i want to be able to put these frontent parts into a storage bucket that gets services via an external load balancer (classic) but it should not be public as every request should be routed through the lb where the backend bucket has an cloud armor edge security bucket attached only allowing access via certain ip ranges (the aws nat ips from the other team)
is that possible?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论