[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-03-12。"],[[["This PCI on Google Kubernetes Engine (GKE) blueprint provides Terraform configurations and scripts for creating a Payment Card Industry (PCI) compliant environment in Google Cloud, utilizing the Online Boutique application as its core."],["The blueprint supports PCI DSS version 3.2.1 compliance by offering a framework for deploying workloads on GKE in a repeatable, secure, and supported manner, and helps implement a cardholder data environment (CDE) with specific Google Cloud projects for Network, Management, In-scope, and Out-of-scope resources."],["Key aspects of the blueprint's architecture include logical segmentation through Google Cloud projects, role-based access control, organization-level policies, Shared VPC for network segregation, and cluster security hardening as detailed in the GKE hardening guide."],["The solution uses encrypted communication both internally and externally, including TLS-encrypted traffic, and relies on Istio for mTLS encryption within clusters."],["The blueprint addresses a variety of PCI DSS requirements, offering guidance and implementation examples, but emphasizes that achieving full PCI compliance is a shared responsibility between the customer and Google Cloud, and requires thorough evaluation and approval from a Qualified Security Assessor (QSA)."]]],[]]