现场环境配置
步骤 1:创建一个 VPC(云内网服务)
- 打开 AWS 端点(AWS CLI 或 AWS Management Console)。
- 输入以下配置:
region my_region vpc_name my_vpc_name vpc_max_user_count 1 vpc_max_userIPAddressCount 1 vpc_max_connections 1 vpc_min_connections 1
步骤 2:配置密钥
- 在 配置文件(如
config/vpc/encrypted_config.yaml)中:- 设置内网加密:
encrypted_config: private_key: my_private_key public_key: my公钥
- 设置内网加密:
- 在 密钥管理 中,将内网密钥管理配置为:
private_key: name: my_private_key region: my_region endpoint: my_private_key_endpoint encryption: private expires: 36
网络环境配置
步骤 1:创建云网络环境(云网络)
- 选择云网络服务类型,多设备连接。
- 在 配置文件(如
config/https-config.yaml)中:- 设置云网络:
https_config: remote_user: my_remote_user remote_password: my_remote_password protocol: https
- 设置云网络:
- 在 云网络配置 中,设置云网络端口的安全配置:
- 选择云网络端口:
https_config: api_key: my_api_key api_secret: my_api_secret endpoint: my_api_endpoint
- 选择云网络端口:
- 在 加密 中,设置云网络加密:
encrypted_config: private_key: name: my_private_key region: my_region endpoint: my_private_key_endpoint encryption: private expires: 36 public_key: name: my公钥 region: my_region endpoint: my公钥_endpoint encryption: private expires: 36 publickey_url: url: my公钥
服务器配置
步骤 1:创建服务器
- 打开 AWS 端点(AWS CLI):
curl -sSL <https://my-aws.com/ssl做完的命令>
- 输入以下配置:
s3 -d -t 1 -x 1 1 -o /var/run/sage .
这会创建一个 Sage服务器(用于内网连接)。
步骤 2:配置内网连接
- 在 配置文件(如
config/server_config.yaml)中:server_config: s3: bucket_name: my_bucket bucket_path: /var/run/sage - 在 服务器配置 中,设置内网连接:
server_config: s3: access_key: my_private_key secret_key: my_private_key auth: bearer: my_private_key max_connections: 1
安全配置
步骤 1:访问控制
- 在 访问控制 中,设置访问规则:
- 检查访问规则:
access_rules: server: url: my_sage_endpoint access_type: read access_time: 18 access_time_type: hour access_time_window: 1 access_time_min: 0 access_time_max: 23 access_time_min_hour: 0 access_time_min_minute: 0 access_time_max_minute: 0 access_time_max_hour: 23 access_time_max_day: 1 access_time_max_month: 1 access_time_max_year: 1 access_time_max_week: 1 access_time_max_month_of_year: 1 access_time_max_day_of_year: 1 access_time_max_month_of_year_of_day: 1 access_time_max_day_of_month: 1 access_time_max_month_of_year_of_day_of_month: 1 access_time_max_day_of_month_of_year: 1 access_time_max_month_of_year_of_day_of_month_of_day: 1 access_time_max_day_of_month_of_year_of_day_of_month: 1 access_time_max_month_of_year_of_day_of_month_of_day_of_month: 1 access_time_max_day_of_month_of_year_of_day_of_month_of_day_of_month_of_day: 1 access_time_max_month_of_year_of_day_of_month_of_day_of_month_of_day_of_month_of_day: 1 access_time_max_day_of_month_of_year_of_day_of_month_of_day_of_month_of_day_of_month_of_day_of_month: 1 - 检查访问日志:
access_log: url: my_sage_endpoint access_time: 18 access_time_type: hour access_time_window: 1 access_time_min: 0 access_time_max: 23 access_time_min_hour: 0 access_time_min_minute: 0 access_time_max_minute: 0 access_time_max_hour: 23 access_time_max_day: 1 access_time_max_day_of_month: 1 access_time_max_month: 1 access_time_max_month_of_year: 1 access_time_max_day_of_month_of_day: 1 access_time_max_month_of_day: 1 access_time_max_month_of_month: 1 access_time_max_day_of_month_of_month_of_day: 1 access_time_max_month_of_day_of_month_of_month: 1 access_time_max_day_of_month_of_month_of_month: 1 access_time_max_month_of_month_of_day: 1 access_time_max_month_of_month_of_month: 1 access_time_max_day_of_month_of_month_of_month_of_day: 1 access_time_max_month_of_month_of_month_of_month: 1
- 检查访问记录:
access_record: url: my_sage_endpoint access_time: 18 access_time_type: hour access_time_window: 1 access_time_min: 0 access_time_max: 23 access_time_min_hour: 0 access_time_min_minute: 0 access_time_max_minute: 0 access_time_max_hour: 23 access_time_max_day: 1 access_time_max_day_of_month: 1 access_time_max_month: 1 access_time_max_month_of_year: 1 access_time_max_day_of_month_of_day: 1 access_time_max_month_of_day: 1 access_time_max_month_of_month: 1 access_time_max_day_of_month_of_month_of_day: 1 access_time_max_month_of_day_of_month_of_month: 1 access_time_max_day_of_month_of_month_of_month: 1 access_time_max_month_of_month_of_day: 1 access_time_max_month_of_month_of_month: 1 access_time_max_day_of_month_of_month_of_month_of_day: 1 access_time_max_month_of_month_of_month_of_month: 1
- 检查访问规则:
安全策略
步骤 1:加密策略
- 在 加密策略 中,设置内网加密策略:
encrypted_strategies: private: algorithm: ae_s3_gpg private_key_name: my_private_key private_key: url: my_private_key expires: 36 private: algorithm: ae_s3_gpg private_key_name: my_private_key private_key: url: my_private_key expires: 36
步骤 2:访问控制策略
- 在 访问控制策略 中,设置访问控制规则:
access_control_strategies: server: access_type: read access_time: 18 access_time_type: hour access_time_window: 1 access_time_min: 0 access_time_max: 23 access_time_min_hour: 0 access_time_min_minute: 0 access_time_max_minute: 0



