透過集合功能整理內容
你可以依據偏好儲存及分類內容。
聯合工作負載的身分反映
您可以搭配工作負載身分集區和身分反映功能使用 Certificate Authority Service,以聯盟第三方身分並取得證明該身分的憑證。
身分反映是一種特殊的憑證核發模式,可限制沒有權限的憑證要求者,只能要求具有與其憑證中身分相符的主體別名 (SAN) 的憑證。舉例來說,具有同盟第三方身分識別權杖的 Cloud Service Mesh 工作負載,或許可以要求使用對應於其網格身分識別的 SAN 憑證,但無法要求使用任何其他 SAN 憑證。
後續步驟
除非另有註明,否則本頁面中的內容是採用創用 CC 姓名標示 4.0 授權,程式碼範例則為阿帕契 2.0 授權。詳情請參閱《Google Developers 網站政策》。Java 是 Oracle 和/或其關聯企業的註冊商標。
上次更新時間:2025-07-14 (世界標準時間)。
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-07-14 (世界標準時間)。"],[[["Identity reflection allows federating a third-party identity to obtain a certificate that attests to that identity through the Certificate Authority Service and workload identity pools."],["This process restricts certificate requesters to only request certificates with a subject alternative name (SAN) that matches their identity."],["Identity reflection is especially useful for workloads, like those in Cloud Service Mesh, that use federated third-party identity tokens."],["You can use Identity reflection with IAM workload identity federation to reflect third-party identities."]]],[]]