使用客戶管理的加密建立檔案共用
使用儲存於 Key Protect 中的根金鑰,建立具備客戶自管加密功能的 File Storage for VPC 共享,以實現 BYOK 資料保護。
建立檔案共用之後,您無法變更加密類型。
預設情況下,File Storage for VPC 共用資料夾會使用 IBM 系統管理的加密方式進行加密。 如需有關信封加密的更多資訊,請參閱《 使用信封加密保護資料 》。
開始之前
要使用客戶管理的加密建立檔案共享,您必須擁有自己的客戶根密鑰。 您可以設定金鑰管理服務 (KMS),並建立或匯入您的客戶根金鑰 (CRK)。 您可以選擇 Key Protect 單租戶或多租戶實例。 接著,在 File Storage for VPC 與您所建立的 KMS 實例之間 建立服務對服務的授權。
Hyper Protect Crypto Services 已被標記為過時。 客戶可在 2027 年 3 月 20 日前使用現有的實體。 如需更多資訊,請參閱 《 IBM Cloud Hyper Protect Crypto Services 已停用 》。 為了持續確保安全性,請考慮將現有的加密金鑰遷移至專用的 Key Protect 執行個體。 如需更多資訊,請參閱《 遷移指南 》。
也可以使用其他帳戶的客戶根密鑰。 在IBM Cloud中,KMS 可以位於與使用加密金鑰的服務相同的帳戶中,也可以位於另一個帳戶中。 這種部署模式允許企業集中管理所有公司帳戶的加密金鑰。 有關詳細信息,請參閱 加密金鑰管理。
一般而言,帳號管理員或擁有 CRK 的帳號的其他權限使用者,邀請使用者 第二個帳號,並建立共用 CRK 的授權。 如需詳細資訊,請參閱 使用 Key Protect 授權存取鑰匙。 然後,第二個帳戶的使用者可以使用 CRK 加密 IBM Cloud 中的資料。
設定所有必要的 服務間授權 服務間授權服務間授權服務間授權,連通 File Storage for VPC (來源服務) 與持有客戶根金鑰的 KMS 執行個體 (目標服務)。 如果您使用其他帳戶的 CRK 來佈建磁碟區,請要求該帳戶的管理員在其帳戶中設定授權,並分享根金鑰的 CRN。
在主控台中使用客戶管理的加密功能建立檔案共用
當您建立檔案共用時,請遵循此程序來指定客戶管理的加密。
-
在 IBM Cloud 主控台中,移至功能表圖示
> Infrastructure
> 儲存 > 檔案儲存共用。
-
按一下建立。
-
輸入表 1 中說明的資訊。
| 欄位 | 值 |
|---|---|
| 可用性 |
|
| 位置 | 如果您選擇單一區域可用性,請選擇新檔案共用的地理位置、區域和區域,例如北美洲、達拉斯 (us-south)、us-south-2。 如果您選擇區域可用性,請選擇區域。 例如,達拉斯(美國南部)。 |
| 詳細資料 | |
| 名稱 | 為檔案共用選擇有意義的名稱。 共用名稱最多可以為 63 個小寫英數字元,並包含連字號 (-),且必須以小寫字母開頭。 如果您願意,稍後可以編輯這個名稱。 |
| 資源群組 | 指定 資源群組。 資源群組可協助組織帳戶資源,以用於存取控制及計費用途。 |
| 標籤 | 標籤用來組織、追蹤甚至管理檔案共用資源的存取權。 您可以為相關資源加上標籤,並透過在資源清單中依標籤篩選,在整個帳戶中檢視這些資源。 使用者標籤在整個帳戶中都是可看見的。 請避免在標籤名稱中包括機密資料。 如需相關資訊,請參閱使用標籤。 |
| 存取管理標籤 | 您可以使用 access-management 標籤在檔案共用上套用彈性存取原則。 如需相關資訊,請參閱 使用標籤控制對資源的存取權。 |
| 設定檔 |
設定檔會根據您的資料可用性選擇自動填入。 如需詳細資訊,請參閱檔案儲存設定檔。
|
| 允許的傳輸加密模式 | 身為共用擁有者,您可以指定您要如何讓帳戶及授權帳戶內的用戶端連接至檔案共用。 如果您不希望它們在傳輸過程中使用加密,則可以選擇無。 如果您希望它們在傳輸過程中使用加密,請為您的區域檔案選擇 ipsec,或為您的區域檔案選擇 stunnel。 |
-
建立 掛載目標 是可選的。 如果您現在不想建立裝載目標,則可以跳過此步驟。 但是,您需要一個掛載到計算主機上的檔案共用。 檔案共用可以有多個掛載目標,因此您可以從多個 VPC 存取。 在每個檔案共用中,每個 VPC 可以建立一個裝載目標。 若要建立,請按一下建立。 提供下列資訊,以定義掛載目標:
- 提供掛載目標名稱。 名稱最多可以為 63 個小寫英數字元,並包含連字號 (-),且必須以小寫字母開頭。 如果需要,您日後可以編輯該名稱。
- 選取可用的 VPC。 此清單僅包含在所選位置擁有子網的 VPC。 位置選擇繼承自檔案共用 (例如 us-south-2 )。
- 會產生預設虛擬網路介面。 您可以按一下 Edit(編輯)圖示
來自訂。 如果位置中有多個可用的子網路,您可以變更名稱或子網路。 您也可以選擇現有的 VNI 來附加到掛載目標。 顯示 VPC 中可用的 VNI 清單和位置。 由於所附加的 VNI 次要 IP 位址無法被接受為檔案共用掛載目標,因此會被篩選出清單。 - 按下一步。
- 對於區域共享,傳輸中加密預設為停用狀態;對於區域共享,傳輸中加密預設為啟用狀態。 按一下切換鍵可變更預設值。 如需有關此功能的詳細資訊,請參閱 傳輸中加密 - 保護檔案共用與主機之間的掛載連線。
- 然後按下一步。
- 檢視您的選擇,然後按一下返回以返回並更新您的選擇,或按一下建立。
-
更新靜態加密部分中的欄位。
- 選擇加密類型。 預設情況下,所有檔案共用均由IBM管理的金鑰加密。 您也可以選擇使用自己的金鑰為您的共用建立信封加密。 如果您想要使用自己的金鑰,請選擇 金鑰管理服務 之一:Key Protect或Hyper Protect Crypto Services。
- 透過依實例或其 CRN 定位來指定金鑰。
- 如果您選擇依據實體定位,請從 Encryption 服務實體功能表中選擇一個實體。 接著,請從清單中選取「金鑰名稱」。
- 如果您選擇透過 CRN 定位,請輸入 CRN 值。 當您想要使用其他帳戶的金鑰 CRN 時,請使用此選項,因為您無法在實例選擇器中看到該金鑰。
-
當輸入所有必要資訊時,請按一下 建立檔案共用。 您回到 File Storage for VPC 頁面,其中一則訊息指出檔案共用正在佈建。 當交易完成時,共用狀態會變更為 作用中。
若您是透過私有端點建立您的 Key Protect 或 Hyper Protect Crypto Services 執行個體,則使用該執行個體所建立的根金鑰將不會顯示於控制台。 您必須使用 CLI 或 API 來存取及使用這些根金鑰。
從 CLI 使用客戶管理的加密來建立檔案共用
在使用 CLI 之前,您必須先安裝「IBM Cloud」CLI 以及 VPC CLI 外掛程式。 如需相關資訊,請參閱 CLI 必要條件。
-
收集佈建共用所需的資訊,例如檔案共用必須具有的唯一名稱、位置、容量及效能性質。 如果您要使用 虛擬網路介面 來建立裝載目標,請使用適當的 CLI 指令來列出可用的 子網路、子網路中的保留 IP 位址 及 安全群組。 如需相關資訊,請參閱 從 CLI 收集資訊。
-
對於加密,擷取金鑰管理服務的 ID 以及該服務中主要金鑰的 CRN。
- 使用
ibmcloud resource service-instances指令列出可用的 KMS 實例。
ibmcloud resource service-instancesRetrieving instances with type service_instance in all resource groups in all locations under account Test Account as test.user@ibm.com... OK Name Location State Type Resource Group ID KeyProtect-ki us-south active service_instance db8e8d865a83e0aae03f25a492c5b39e schematics us-south active service_instance db8e8d865a83e0aae03f25a492c5b39e- 使用
ibmcloud resource service-instance指令來取得實例 ID。 ID 是 CRN 中帳戶號碼之後的最後一個字串。
ibmcloud resource service-instance KeyProtect-ki -location us-south --idRetrieving service instance KeyProtect-ki in all resource groups under account Test Account as test.user@ibm.com... crn:v1:bluemix:public:kms:us-south:a/a1234567:: 22e573bd-c02c-4d7f-81e2-2aa867da176d- 使用
ibmcloud kp keys指令中的 ID 來擷取金鑰資訊。
ibmcloud kp keys -c --instance-id 22e573bd-c02c-4d7f-81e2-2aa867da176dTargeting endpoint: https://qa.us-south.kms.cloud.ibm.com Retrieving keys... OK Key ID Key Name CRN 2fb8d675-bde3-4780-b127-3d0b413631c1 my-file-key crn:v1:bluemix:public:kms:us-south:a/a1234567:22e573bd-c02c-4d7f-81e2-2aa867da176d:key:2fb8d675-bde3-4780-b127-3d0b413631c1如果您打算使用其他帳戶的加密金鑰,則必須在其他帳戶上執行之前的步驟。 即使您有權使用其他帳戶的資源,您也無法列出這些資源。
- 使用
-
如果您是具有預覽區域檔案共用設定檔特殊存取權限的客戶,您可以使用
rfs設定檔建立檔案共用。 若要從 CLI 建立和管理區域檔案共用,請使用下列指令設定適當的環境變數。export IBMCLOUD_IS_FEATURE_SHARE_DENALI_REGIONAL_AVAILABILITY=true只有當此環境變數設定為「true「時,CLI 才會傳回」Allowed Access Protocols」、"Availability Mode"、「Bandwidth「和」Storage Generation」的屬性。
-
指定
ibmcloud is share-create指令並指定--encryption-key選項,以使用客戶管理的加密來建立檔案共用。encryption_key選項後面必須接著金鑰管理服務中根金鑰的有效 CRN。 如果您也想要在傳輸中啟用加密,請在裝載目標 JSON 中指定該項目。 您與掛載目標關聯的安全群組必須允許 TCP 通訊協定從您要掛載共用的所有伺服器 NFS 連接埠的入站存取。-
下列範例會使用客戶管理的加密、安全群組存取模式及具有虛擬網路介面的裝載目標來建立檔案共用。 未啟用傳輸中加密。
ibmcloud is share-create --name my-encrypted-file-share --zone us-south-2 --profile dp2 --size 500 --iops 2000 --user-tags env:dev --encryption-key crn:v1:bluemix:public:kms:us-south:a/a1234567:key:2fb8d675-bde3-4780-b127-3d0b413631c1 --mount-targets '[{"name":"my-new-mount-target","virtual_network_interface": {"name":"my-vni-2","subnet": {"id":"r006-298acd6c-e71e-4204-a04f-fe4a4dd89805"},"security_groups":[{"id":"r006-7f369ca2-ca49-4053-b007-5cab79b9873b"}]}}]'Creating file share my-encrypted-file-share under account Test Account as user test.user@ibm.com... ID r006-d44298fe-aced-4f55-a690-8a3830e9fd90 Name my-encrypted-file-share CRN crn:v1:bluemix:public:is:us-south-2:a/a1234567::share:r006-d44298fe-aced-4f55-a690-8a3830e9fd90 Lifecycle state pending Access control mode security_group Accessor binding role none Zone us-south-2 Profile dp2 Size(GB) 500 IOPS 2000 User Tags env:dev Encryption user_managed Mount Targets ID Name r006-00432317-436e-4940-ab7d-8b26c186b00f my-new-mount-target Resource group ID Name db8e8d865a83e0aae03f25a492c5b39e Default Created 2023-10-19T21:16:27+00:00 Encryption key crn:v1:bluemix:public:kms:us-south:a/a1234567:key:2fb8d675-bde3-4780-b127-3d0b413631c1 Replication role none Replication status none Replication status reasons Status code Status message - - Snapshot count 10 Snapshot size 10 Source snapshot -ibmcloud is share-mount-targets my-encrypted-file-shareListing share mount target of my-encrypted-file-share in all resource groups and region us-south under account Test Account as user test.user@ibm.com... ID Name VPC Lifecycle state Transit Encryption r006-00432317-436e-4940-ab7d-8b26c186b00f my-new-mount-target my-vpc stable none -
下列範例會使用客戶管理的加密、安全群組存取模式及已啟用虛擬網路介面及傳輸中加密的裝載目標來建立檔案共用。
ibmcloud is share-create --name my-encrypted-eit-file-share --zone us-south-2 --profile dp2 --size 500 --iops 2000 --user-tags env:dev --encryption_key crn:v1:bluemix:public::kms:us-south:a/a1234567:key:2fb8d675-bde3-4780-b127-3d0b413631c1 --mount-targets '[{"name":"my-new-mount-target","transit_encryption": "user_managed","virtual_network_interface": {"name":"my-vni-3","subnet": {"id":"r006-298acd6c-e71e-4204-a04f-fe4a4dd89805"},"security_groups":[{"id":"r006-7f369ca2-ca49-4053-b007-5cab79b9873b"}]}}]'回應內容與以下範例類似。
Creating file share my-encrypted-eit-file-share under account Test Account as user test.user@ibm.com... ID r006-f6bf049e-f46c-4160-b548-4a36d27256ac Name my-encrypted-eit-file-share CRN crn:v1:bluemix:public::is:us-south-2:a/a1234567::share:r006-f6bf049e-f46c-4160-b548-4a36d27256ac Lifecycle state pending Access control mode security_group Accessor binding role none Zone us-south-2 Profile dp2 Size(GB) 500 IOPS 2000 User Tags env:dev Encryption user_managed Mount Targets ID Name r006-e6bd52b8-c656-4ba6-8749-1bb41bfa2c3c my-new-mount-target Resource group ID Name db8e8d865a83e0aae03f25a492c5b39e Default Created 2023-10-20T03:05:38+00:00 Encryption key crn:v1:bluemix:public:kms:us-south:a/a1234567-c02c-4d7f-81e2-2aa867da176d:key:2fb8d675-bde3-4780-b127-3d0b413631c1 Replication role none Replication status none Replication status reasons Status code Status message - - Snapshot count 0 Snapshot size 0 Source snapshot -ibmcloud is share-mount-targets my-encrypted-eit-file-share回應內容與以下範例類似。
Listing share mount target of my-encrypted-eit-file-share in all resource groups and region us-south under account Test Account as user test.user@ibm.com... ID Name VPC Lifecycle state Transit Encryption r006-e6bd52b8-c656-4ba6-8749-1bb41bfa2c3c my-new-mount-target my-vpc stable user_managed- 以下範例建立一個區域檔案共用,並啟用客戶管理加密、安全群組存取模式和傳輸中加密。
ibmcloud is share-create --name my-regional-file-share --profile rfs --size 40 --bandwidth 800 --atem stunnel,none --encryption-key crn:v1:bluemix:public::kms:us-south:a/a1234567:key:2fb8d675-bde3-4780-b127-3d0b413631c1回應內容與以下範例類似。
Creating file share my-file-share1 under account Test Account as user test.user@ibm.com... ID r006-9ae55188-610e-4cf9-9350-d0b675026ff8 Name my-regional-file-share CRN crn:v1:bluemix:public:is:us-south:a/a1234567::share:r006-9ae55188-610e-4cf9-9350-d0b675026ff8 Lifecycle state pending Access control mode security_group Accessor binding role none Allowed transit encryption modes stunnel,none Zone - Profile rfs Size(GB) 40 IOPS 35000 Encryption user_managed Mount Targets ID Name No mounted targets found. Resource group ID Name 11caaa983d9c4beb82690daab08717e9 Default Created 2025-09-22T21:17:23+05:30 Encryption key crn:v1:bluemix:public:kms:us-south:a/a1234567-c02c-4d7f-81e2-2aa867da176d:key:2fb8d675-bde3-4780-b127-3d0b413631c1 Replication role none Replication status none Replication status reasons Status code Status message - - Snapshot count 0 Snapshot size 0 Source snapshot - Allowed Access Protocols nsf4 Availability Mode regional Bandwidth(Mbps) 800 Storage Generation 2 -
如需指令選項的相關資訊,請參閱 ibmcloud is share-create。
使用 API 透過客戶管理的加密建立檔案共用
您可以呼叫 Virtual Private Cloud(VPC)API,以使用客戶管理的加密來建立檔案共用。
提出 POST /shares 要求,並指定 encryption_key 參數,以識別您的客戶根金鑰 (CRK)。 在範例中,它顯示為 crn:[...key:...]。
您必須提供 generation 參數並指定 generation=2。 如需更多資訊,請參閱《 虛擬私有雲 API 參考手冊 》中的「生成」章節。
以下範例建立具有掛載目標的區域檔案共用,並指定用於客戶管理加密的根金鑰的 CRN。
curl -X POST \
"$vpc_api_endpoint/v1/shares?version=2024-11-05&generation=2" -H "Authorization: Bearer $iam_token" \
-d '{
"name": "my-encrypted-share",
"mount_targets": [
{
"name": "docs-mount-1",
"virtual_network_interface": {
"name": "my-virtual-network-interface-1",
"allow_ip_spoofing": false,
"auto_delete": true,
"enable_infrastructure_nat": true,
"primary_ip": {"auto_delete": true},
"subnet": {"id": "0727-267015ac-7b12-4f62-bda9-52fcb9483fc4"},
"ips": [],
"security_groups": [{"id": "r006-bf9475c2-6846-4c39-b392-587643b2e2f8"}],
"protocol_state_filtering_mode": "auto"
},
"transit_encryption": "none"
}
],
"profile": {"name": "dp2"},
"size": 100,
"zone": {"name": "us-south-2"},
"iops": 3000,
"allowed_transit_encryption_modes": ["none","user_managed"],
"encryption_key": {"crn": "crn:v1:bluemix:public:kms:us-south:a/a1234567-c02c-4d7f-81e2-2aa867da176d:key:2fb8d675-bde3-4780-b127-3d0b413631c1"},
"resource_group": {"id": "db00a952a88945a987b7be1980fdae8e"},
"access_control_mode": "security_group"
}'
以下範例建立一個沒有掛載目標的區域檔案共用,並指定用於客戶管理加密的根金鑰的 CRN。
curl -X POST \
"$vpc_api_endpoint/v1/shares?version=2025-09-02&generation=2" -H "Authorization: Bearer $iam_token" \
-d '{
"name": "my-encrypted-regional-share",
"profile": {"name": "rfs"},
"size": 1000,
"bandwidth": 800,
"allowed_transit_encryption_modes": ["none","stunnel"],
"encryption_key": {"crn": "crn:v1:bluemix:public:kms:us-south:a/a1234567-c02c-4d7f-81e2-2aa867da176d:key:2fb8d675-bde3-4780-b127-3d0b413631c1"},
"resource_group": {"id": "db00a952a88945a987b7be1980fdae8e"},
"access_control_mode": "security_group"
}'
您也可以在 POST /shares 呼叫中指定來自不同帳戶之根金鑰的 CRN。 如果要這樣做,請聯絡其他帳戶的管理員,以確保服務對服務的授權已就緒,並取得加密金鑰的 CRN。
使用 Terraform 以客戶管理的加密建立檔案共用
若要建立檔案共用,請使用 ibm_is_share 資源。 以下範例會建立具有 800 GiB 容量和 dp2 效能設定檔的區域檔案共用。 檔案共用是使用其 CRN 所識別的金鑰來加密。 此範例也指定具有虛擬網路介面的新裝載目標。
resource "ibm_is_share" "share4" {
zone = "us-south-2"
size = "800"
iops = "3000"
name = "my-share4"
profile = "dp2"
encryption_key = "crn:v1:bluemix:public:kms:us-south:a/a1234567:key:2fb8d675-bde3-4780-b127-3d0b413631c1"
access_control_mode = "security_group"
mount_target {
name = "target"
security_groups = [<security_group_ids>]
virtual_network_interface {
primary_ip {
address = "10.240.64.5"
auto_delete = true
name = "my-example-pip"
}
}
}
}
以下範例會建立具有 1000 GiB 容量和 rfs 效能設定檔的區域檔案共用。 檔案共用是使用其 CRN 所識別的金鑰來加密。
resource "ibm_is_share" "regional-share" {
size = "1000"
name = "my-regional-share"
profile = "rfs"
bandwidth = "800"
encryption_key = "crn:v1:bluemix:public:kms:us-south:a/a1234567:key:2fb8d675-bde3-4780-b127-3d0b413631c1"
access_control_mode = "security_group"
}
如需引數及屬性的相關資訊,請參閱 ibm_is_share。
下一步
-
使用 IBM Cloud 檔案共用裝載 Helper 公用程式,將加密檔案共用裝載至授權的 Compute 實例。
-
請考量為您的共用設定抄寫。 如需相關資訊,請參閱 關於檔案共用抄寫。
-
瞭解 從另一個帳戶共用及裝載檔案共用。