现已推出具有 MongoDB 兼容性的 Firestore 企业版!
了解详情。
VPC Service Controls
透過集合功能整理內容
你可以依據偏好儲存及分類內容。
機構可透過 VPC Service Controls,在 Google Cloud 資源周圍定義安全範圍,降低資料遭竊的風險。透過 VPC Service Controls,您可以建立 perimeter,保護您明確指定的服務資源和資料。
套裝組合Cloud Firestore服務
VPC Service Controls 會將下列 API 組合在一起:
firestore.googleapis.com
datastore.googleapis.com
firestorekeyvisualizer.googleapis.com
在範圍中限制 firestore.googleapis.com
服務時,範圍也會限制 datastore.googleapis.com
和 firestorekeyvisualizer.googleapis.com
服務。
限制 datastore.googleapis.com 服務
datastore.googleapis.com
服務會與 firestore.googleapis.com
服務一併提供。如要限制 datastore.googleapis.com
服務,請按照下列步驟限制 firestore.googleapis.com
服務:
App Engine 舊版服務套裝組合,適用於 Datastore
App Engine 舊版服務套裝組合 (適用於 Datastore) 不支援服務範圍。使用服務範圍保護Datastore
服務時,系統會封鎖來自舊版套裝服務的流量。App Engine舊版套裝組合服務包括:
匯入和匯出作業的輸出保護措施
與 MongoDB 相容的 Cloud Firestore 支援 VPC Service Controls,但需要額外設定,才能在匯入和匯出作業中獲得完整的輸出保護。您必須使用 Cloud Firestore 服務代理程式授權匯入和匯出作業,而非預設的 App Engine 服務帳戶。請按照下列操作說明,查看及設定匯入和匯出作業的授權帳戶。
除非另有註明,否則本頁面中的內容是採用創用 CC 姓名標示 4.0 授權,程式碼範例則為阿帕契 2.0 授權。詳情請參閱《Google Developers 網站政策》。Java 是 Oracle 和/或其關聯企業的註冊商標。
上次更新時間:2025-08-29 (世界標準時間)。
[null,null,["上次更新時間:2025-08-29 (世界標準時間)。"],[],[],null,["\u003cbr /\u003e\n\n[VPC Service Controls](https://cloud.google.com/vpc-service-controls/) lets organizations define a perimeter around\nGoogle Cloud resources to mitigate data exfiltration risks. With\nVPC Service Controls, you create perimeters that protect the resources and data\nof services that you explicitly specify.\n\nBundled Cloud Firestore services\n\nThe following APIs are bundled together in VPC Service Controls:\n\n- `firestore.googleapis.com`\n- `datastore.googleapis.com`\n- `firestorekeyvisualizer.googleapis.com`\n\nWhen you restrict the `firestore.googleapis.com` service in a perimeter,\nthe perimeter also restricts the `datastore.googleapis.com` and\n`firestorekeyvisualizer.googleapis.com` services.\n\nRestrict the datastore.googleapis.com service\n\nThe `datastore.googleapis.com` service is bundled under the\n`firestore.googleapis.com` service. To restrict the\n`datastore.googleapis.com`\nservice, you must restrict the `firestore.googleapis.com` service\nas follows:\n\n- When creating a service perimeter using the Google Cloud console, add Cloud Firestore as the restricted service.\n- When creating a service perimeter using the Google Cloud CLI, use\n `firestore.googleapis.com` instead of `datastore.googleapis.com`.\n\n --perimeter-restricted-services=firestore.googleapis.com\n\nApp Engine legacy bundled services for Datastore\n\n[App Engine legacy bundled services for Datastore](https://cloud.google.com/appengine/docs/standard/python/bundled-services-overview)\ndon't support service perimeters. Protecting the Datastore\nservice with a service perimeter blocks traffic from\nApp Engine legacy bundled services. Legacy bundled services include:\n\n- [Java 8 Datastore with App Engine APIs](https://cloud.google.com/appengine/docs/standard/java/datastore)\n- [Python 2 NDB client library for Datastore](https://cloud.google.com/appengine/docs/standard/python/ndb/creating-entities)\n- [Go 1.11 Datastore with App Engine APIs](https://cloud.google.com/appengine/docs/standard/go111/datastore)\n\nEgress protection on import and export operations\n\nCloud Firestore with MongoDB compatibility supports VPC Service Controls but requires additional\nconfiguration to get full egress protection on import and export operations.\nYou must use the Cloud Firestore service agent to authorize import and\nexport operations instead of the default App Engine service\naccount. Use the following instructions to view and configure the authorization\naccount for import and export operations."]]