Skip to main content

Posts

Langkah-Langkah membuat load balancer di Google Cloud

  Steps summary Load balancer ada beberapa komponen yang bisa di integrasi kan seperti berikut: 1. Health check 2. Instance Group 3. Auto Scaling Untuk mempermudah pemahaman bisa melihat diagram berikut: Berikut adalah salah satu contoh saja architecture load balancer di GCP https://fabianlee.org/2022/03/30/gcp-global-external-https-lb-for-securely-exposing-insecure-vm-services/ Mari bahas satu per satu Pada tutorial kali ini akan simple aja yaitu menggunakan unmanaged instance group karena belum butuh auto scaling. Berikut jenis-jenis instance group ada di sebelah kiri pada gambar dibawah ini, instance group ini akan menjadi pool/backend dari load balancer. Jenis-jenis instance group Langkah-langkah konfigurasi: 1. Buat instance 2. Buat instance group, masukan instance ke dalam group ini Bikin instance group gcloud compute instance-groups unmanaged create instance-group-name --project= your-project --zone=us-central1-a Bikin Port mapping gcloud compute instance-groups unmanaged set-n

How to configure IAP in GCP

 Create a firewall rule To allow IAP to connect to your VM instances,  create a firewall rule that: applies to all VM instances that you want to be accessible by using IAP. allows ingress traffic from the IP range 35.235.240.0/20.  This range contains all IP addresses that IAP uses for TCP forwarding. allows connections to all ports that you want to be accessible by using IAP TCP forwarding, for example, port 22 for SSH and port 3389 for RDP. Command: Firewall for IAP gcloud compute firewall-rules create allow-rdp-ingress-from-iap \ --direction=INGRESS \ --action=allow \ --rules=tcp:3389 \ --source-ranges=35.235.240.0/20 Tunnel Command gcloud compute start-iap-tunnel INSTANCE_NAME 3389 \     --local-host-port=localhost: LOCAL_PORT \     --zone= ZONE gcloud compute start-iap-tunnel nshcloudlabs-instance-group-1-9v0v 3389 --local-host-port=localhost:3389 --zone=us-central1-a       Permissions for user: roles/iap.tunnelResourceAccessor References: https://cloud.google.com/iap/do