Atom
GEK介紹

GEK介紹

前陣子在進行弱點掃描時拿到了比較特殊的備註:

項目 內容
Host Name Example.com.tw
IP Address 111.111.111.111
Environment Type Production(PRD)
Operating System Container-Optimized OS(Node)/Linux(Container)
Comments 該 IP 為 GKE Ingress 共用 IP

一、什麼是 Container?

Container 會將下列內容封裝在一起:

  • 應用程式
  • Runtime
  • 函式庫
  • 相依套件
  • 部分環境設定

例如,一個網站可能被封裝成以下 Container Image:

1
2
3
4
5
Alpine Linux
├── Nginx
├── Node.js
├── 應用程式原始碼
└── 所需函式庫

之後只要有支援 Container Runtime 的環境,就能啟動這個應用程式。

常見的 Container 技術包括:

  • Docker
  • containerd
  • CRI-O

需要注意的是,Container 並不是完整的虛擬機器。Container 通常會共享主機的作業系統核心,因此比傳統 VM 更輕量,啟動速度也更快。


二、什麼是 Kubernetes?

當系統只有一兩個 Container 時,可以直接使用 Docker 或其他 Container Runtime 管理。

但正式環境可能同時存在數十、數百,甚至數千個 Container,此時就會遇到許多管理問題:

  • Container 異常停止後,誰負責重新啟動?
  • 使用量增加時,如何自動增加 Container?
  • 使用量下降時,如何縮減資源?
  • 如何將流量分散到不同 Container?
  • 如何執行滾動更新?
  • 如何管理不同版本?
  • 如何處理服務發現?
  • 如何保存密碼與設定?
  • 如何讓服務對外提供存取?

Kubernetes,簡稱 K8s,就是用來解決這些問題的開源 Container Orchestration Platform,也就是「容器編排平台」。

Kubernetes 最初由 Google 開發,其設計經驗源自 Google 內部的大規模叢集管理系統 Borg,之後成為開源專案。Google Cloud 的 GKE 則是 Kubernetes 的託管服務。官方將 GKE 定義為用於在 Google Cloud 部署 Containerized Applications 的 Managed Kubernetes Service。


三、什麼是 GKE?

GKE 全名為:

1
Google Kubernetes Engine

GKE 是 Google Cloud 提供的 Managed Kubernetes Service

所謂 Managed Service,代表使用者不必完全自行建置與維護 Kubernetes 的所有元件。部分複雜工作會由 Google Cloud 處理

客戶通常僅需負責:

  • Container Image
  • 應用程式弱點
  • Kubernetes 設定
  • IAM 權限
  • Secret 管理
  • Network Policy
  • Ingress 規則
  • 對外開放的 Service
  • Node 與 Pod 的安全設定
  • 第三方套件與應用程式更新

四、GKE 的基本架構

一個簡化的 GKE 架構如下:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
Internet


DNS

Example.com.tw


External IP
111.111.111.111


Google Cloud Load Balancer


GKE Ingress


Kubernetes Service

├── Pod 1
├── Pod 2
└── Pod 3


Container

接下來分別介紹架構中的元件。


什麼是 GKE Ingress 共用 IP?

Ingress 可以依照 HTTP Host Header,將流量送到不同的 Kubernetes Service:
因此,雖然三個網站的 IP 相同,實際上可能是完全不同的應用程式。
這就是「共用 Ingress IP」的概念。


HTTP Host Header 的作用

瀏覽器連線網站時,不只會連到 IP,也會在 HTTP Request 中提供目標 Host Name。

例如:

1
2
3
GET / HTTP/1.1
Host: tcloud.gov.tw
User-Agent: Mozilla/5.0

Ingress 看到:

1
Host: tcloud.gov.tw

才知道要把流量轉送到 tcloud.gov.tw 對應的 Service。

如果直接存取:

1
https://35.185.155.213

HTTP Request 可能變成:

1
Host: 35.185.155.213

此時可能出現:

  • Ingress 預設頁面
  • 404 Not Found
  • 憑證名稱不符合
  • 其他預設 Backend
  • 非預期服務
  • 無法正確識別網站
  • 掃描到授權範圍外的內容

從弱點掃描角度看 GKE

面對 GKE 環境時,需要先判斷掃描層級。

外部網路弱掃

從 Internet 對公開 IP 或 Domain 進行掃描,通常能看到:

  • Load Balancer
  • Ingress
  • 公開 Port
  • TLS Configuration
  • HTTP Response
  • Web Server 特徵
  • Web Application 弱點

但通常無法直接完整判斷:

  • Node 真實作業系統版本
  • 內部 Pod IP
  • 未公開的 Service
  • Container Image 套件
  • Kubernetes RBAC
  • Cluster Configuration
  • Secret
  • Network Policy

Container Image Scan

用來檢查:

  • Alpine Package
  • Debian/Ubuntu Package
  • Application Dependency
  • CVE
  • Secret
  • 惡意檔案
  • 不安全設定

常見工具包括:

  • Trivy
  • Grype
  • Snyk Container
  • Google Artifact Analysis
  • AWS ECR Image Scanning
  • Microsoft Defender for Containers

Kubernetes Configuration Scan

用來檢查:

  • Privileged Container
  • hostNetwork
  • hostPID
  • hostPath
  • Root Container
  • 過度寬鬆 RBAC
  • 缺少 Resource Limit
  • Secret 管理不當
  • Pod Security 設定
  • Network Policy 缺失

Node Vulnerability Scan

用來檢查:

  • Node OS
  • Kernel
  • SSH
  • 系統套件
  • Container Runtime
  • kubelet
  • 開放 Port

因此單純從外部使用 Nessus 掃描網域,不能代表已完整檢查整個 GKE 環境。

本文作者:Atom
本文鏈接:https://d0ngd.github.io/2026/07/20/GEK介紹/
版權聲明:本文採用 CC BY-NC-SA 3.0 CN 協議進行許可