OSVauco/docs/IAP-SETUP.md

3.1 KiB

Google Cloud IAP Setup Guide

This guide provides the gcloud commands to configure Identity-Aware Proxy (IAP) for the Vauco TUI Bridge, securing it so that only user:chris.christiansen@vauco.no can access it.

1. Enable Required APIs

First, enable the IAP API for your project.

gcloud services enable iap.googleapis.com

2. Deploy the Service and Create a Load Balancer

Deploy your Cloud Run service (if you haven't already using the deploy_cloudrun.sh script) and then set up a global external HTTPS load balancer that points to it.

Create a Serverless NEG

gcloud compute network-endpoint-groups create vauco-tui-bridge-neg 
    --region=europe-west1 
    --network-endpoint-type=serverless 
    --cloud-run-service=vauco-tui-bridge

Create a Backend Service

gcloud compute backend-services create vauco-tui-bridge-backend 
    --global

Add the NEG to the Backend Service

gcloud compute backend-services add-backend vauco-tui-bridge-backend 
    --global 
    --network-endpoint-group=vauco-tui-bridge-neg 
    --network-endpoint-group-region=europe-west1

Create a URL Map

gcloud compute url-maps create vauco-tui-bridge-url-map 
    --default-service vauco-tui-bridge-backend

Create a Target HTTPS Proxy

# You will need a managed SSL certificate for this step
gcloud compute ssl-certificates create vauco-tui-bridge-cert 
    --domains=your-domain.com # Replace with your actual domain

gcloud compute target-https-proxies create vauco-tui-bridge-https-proxy 
    --url-map=vauco-tui-bridge-url-map 
    --ssl-certificates=vauco-tui-bridge-cert

Create a Global Forwarding Rule (This creates the Load Balancer)

gcloud compute forwarding-rules create vauco-tui-bridge-forwarding-rule 
    --global 
    --target-https-proxy=vauco-tui-bridge-https-proxy 
    --ports=443

3. Enable IAP on the Backend Service

Now, enable IAP for the backend service you created. You will need your OAuth2 client ID and secret, which can be created in the Google Cloud Console under "APIs & Services" -> "Credentials".

Get the Backend Service ID

BACKEND_SERVICE_ID=$(gcloud compute backend-services describe vauco-tui-bridge-backend --global --format="value(id)")

Enable IAP

gcloud iap web enable --resource-type=backend-service --service=vauco-tui-bridge-backend

4. Grant Access to the User

Grant the IAP-secured Web App User role to chris.christiansen@vauco.no.

gcloud projects add-iam-policy-binding <YOUR_PROJECT_ID> 
    --member="user:chris.christiansen@vauco.no" 
    --role="roles/iap.httpsResourceAccessor"

5. Verify Access

  • Verify access for chris.christiansen@vauco.no: Open a browser where you are logged in as chris.christiansen@vauco.no and navigate to the HTTPS URL of the load balancer. You should be able to access the bridge's root endpoint.

  • Verify access is denied for other accounts: Open an incognito browser window or a browser where you are logged in with a different Google account. Navigate to the same URL. You should see a "You don't have access" message from Google, not the application.