Tetap teratur dengan koleksi
Simpan dan kategorikan konten berdasarkan preferensi Anda.
Menginstal Config Sync dan Policy Controller
Config Sync dan Pengontrol Kebijakan menerapkan konfigurasi umum di seluruh infrastruktur Anda. Anda dapat menentukan konfigurasi, seperti kebijakan keamanan kustom.
Konfigurasi ini disimpan dalam sumber tepercaya yang dikontrol versinya, seperti repositori Git.
Config Sync dan Pengontrol Kebijakan kemudian memastikan bahwa infrastruktur Anda selaras dengan konfigurasi ini.
Sebelum memulai
Jika Anda menghosting sumber kebenaran Config Sync di lokasi yang tidak dapat diakses dari Azure Virtual Network (VNet), Anda harus membuka akses keluar ke host sumber kebenaran dari grup keamanan kumpulan node.
Daftar berikut berisi port default berdasarkan metode autentikasi Anda.
Untuk mengaktifkan Config Sync agar menyinkronkan file konfigurasi Kubernetes dari sumber kebenaran, ikuti petunjuk penginstalan dalam dokumentasi Config Sync.
Untuk mengaktifkan Pengontrol Kebijakan agar dapat mengaudit dan menerapkan kebijakan kontrol akses, ikuti petunjuk penginstalan dalam dokumentasi Pengontrol Kebijakan.
Apa langkah selanjutnya?
Pelajari cara menambahkan Konfigurasi
ke sumber tepercaya.
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-07-22 UTC."],[],[],null,["# Install Config Sync and Policy Controller\n=========================================\n\nConfig Sync and Policy Controller enforce a common configuration across your\nentire infrastructure. You define configurations, such as custom security policies.\nThese configurations are stored in a version-controlled source of truth, such as a Git repository.\nConfig Sync and Policy Controller then ensure that your infrastructure aligns with these configurations.\n\nBefore you begin\n----------------\n\nIf you host your Config Sync source of truth at a location\nthat's inaccessible from your Azure Virtual Network (VNet), you must open outbound access to your\nsource of truth host from your\n[node pool security group](/kubernetes-engine/multi-cloud/docs/azure/reference/security-groups#node_pool_security_groups).\nThe following list contains default ports based on your authentication\nmethod.\n\nFor more information about modifying Azure security groups, see [Azure network security groups](https://docs.microsoft.com/azure/virtual-network/network-security-groups-overview) and [Azure application security groups](https://docs.microsoft.com/azure/virtual-network/application-security-groups).\n\nInstallation instructions\n-------------------------\n\nTo enable Config Sync to sync Kubernetes configuration\nfiles from a source of truth, follow the\ninstallation instructions in the\n[Config Sync](/anthos-config-management/docs/how-to/installing-config-sync)\ndocumentation.\n\nTo enable Policy Controller to audit and enforce admission control policies,\nfollow the installation instructions in the\n[Policy Controller](/anthos-config-management/docs/how-to/installing-policy-controller)\ndocumentation.\n\nWhat's next?\n------------\n\n- Learn about adding [Configs](/anthos-config-management/docs/concepts/configs)\n to a source of truth.\n\n- Check the\n [examples GitHub repository](https://github.com/GoogleCloudPlatform/anthos-config-management-samples)."]]