3.4 KiB
STATUS (2026-05-25): Ikke startet — Phase 5 scope.
opax.vauco.nosvarer{"status":"ok"}på/healthuten IAP. IAP-oppsett starter når Phase 4 docs hardening er fullført. Neste ansvarlig: OPS · Gate: ingen (Phase 5 er neste roadmap-steg)
Google Cloud IAP Setup Guide
This guide provides the gcloud commands to configure Identity-Aware Proxy (IAP) for the Vauco TUI Bridge, securing it so that only user:chris.christiansen@vauco.no can access it.
1. Enable Required APIs
First, enable the IAP API for your project.
gcloud services enable iap.googleapis.com
2. Deploy the Service and Create a Load Balancer
Deploy your Cloud Run service (if you haven't already using the deploy_cloudrun.sh script) and then set up a global external HTTPS load balancer that points to it.
Create a Serverless NEG
gcloud compute network-endpoint-groups create vauco-tui-bridge-neg
--region=europe-west1
--network-endpoint-type=serverless
--cloud-run-service=vauco-tui-bridge
Create a Backend Service
gcloud compute backend-services create vauco-tui-bridge-backend
--global
Add the NEG to the Backend Service
gcloud compute backend-services add-backend vauco-tui-bridge-backend
--global
--network-endpoint-group=vauco-tui-bridge-neg
--network-endpoint-group-region=europe-west1
Create a URL Map
gcloud compute url-maps create vauco-tui-bridge-url-map
--default-service vauco-tui-bridge-backend
Create a Target HTTPS Proxy
# You will need a managed SSL certificate for this step
gcloud compute ssl-certificates create vauco-tui-bridge-cert
--domains=your-domain.com # Replace with your actual domain
gcloud compute target-https-proxies create vauco-tui-bridge-https-proxy
--url-map=vauco-tui-bridge-url-map
--ssl-certificates=vauco-tui-bridge-cert
Create a Global Forwarding Rule (This creates the Load Balancer)
gcloud compute forwarding-rules create vauco-tui-bridge-forwarding-rule
--global
--target-https-proxy=vauco-tui-bridge-https-proxy
--ports=443
3. Enable IAP on the Backend Service
Now, enable IAP for the backend service you created. You will need your OAuth2 client ID and secret, which can be created in the Google Cloud Console under "APIs & Services" -> "Credentials".
Get the Backend Service ID
BACKEND_SERVICE_ID=$(gcloud compute backend-services describe vauco-tui-bridge-backend --global --format="value(id)")
Enable IAP
gcloud iap web enable --resource-type=backend-service --service=vauco-tui-bridge-backend
4. Grant Access to the User
Grant the IAP-secured Web App User role to chris.christiansen@vauco.no.
gcloud projects add-iam-policy-binding <YOUR_PROJECT_ID>
--member="user:chris.christiansen@vauco.no"
--role="roles/iap.httpsResourceAccessor"
5. Verify Access
-
Verify access for
chris.christiansen@vauco.no: Open a browser where you are logged in aschris.christiansen@vauco.noand navigate to the HTTPS URL of the load balancer. You should be able to access the bridge's root endpoint. -
Verify access is denied for other accounts: Open an incognito browser window or a browser where you are logged in with a different Google account. Navigate to the same URL. You should see a "You don't have access" message from Google, not the application.