Security

Security

Overview

Security ํŽ˜์ด์ง€์—์„œ QueryPie ์ „๋ฐ˜์— ๋Œ€ํ•œ ๋ณด์•ˆ ์„ค์ •์„ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๋ฌธ์„œ์—์„œ๋Š” ๊ฐ ๋ณด์•ˆ ์„ค์ •์— ๋Œ€ํ•œ ์„ค๋ช…์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

10.3.0 ๋ถ€ํ„ฐ ๊ฐ ์„œ๋น„์Šค ๋ณ„ ์„ค์ • ํ•ญ๋ชฉ์ด Administrator > General > Security ํ•˜์œ„์—์„œ ๊ฐ ์„œ๋น„์Šค(Databases / Servers / Kubernetes) ์˜ General ํ•˜์œ„(Administrator > {Service} > General > Configurations)๋กœ ์ด๋™๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

์›น ์ฝ˜์†” ๋กœ๊ทธ์ธ ์„ค์ •

QueryPie Web ๋กœ๊ทธ์ธ ๊ด€๋ จ ๋ณด์•ˆ ์„ค์ •์„ ๊ด€๋ฆฌํ•ฉ๋‹ˆ๋‹ค.

ย 

Account Security Policy

QueryPie ๊ณ„์ •์˜ ์ž ๊ธˆ ๋ฐ ๋งŒ๋ฃŒ ๋“ฑ์˜ ๋ณด์•ˆ ์ •์ฑ…์„ ์„ค์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

  • Account Expiration Period (Days) : ๊ณ„์ • ๋งŒ๋ฃŒ ์ฒ˜๋ฆฌ๋ฅผ ์œ„ํ•œ ์žฅ๊ธฐ ๋ฏธ์ ‘์† ์ผ์ž ๊ธฐ์ค€

  • Expiration Reminder (Days) : ๊ณ„์ • ๋งŒ๋ฃŒ ์•Œ๋ฆผ ์ด๋ฉ”์ผ์„ ๋ฐœ์†กํ•  ๊ธฐ์ค€์ผ์„ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. ๋“œ๋กญ๋‹ค์šด ๋ชฉ๋ก์—์„œ 1์ผ๋ถ€ํ„ฐ 14์ผ๊นŒ์ง€ ์›ํ•˜๋Š” ๋‚ ์งœ๋ฅผ ์—ฌ๋Ÿฌ ๊ฐœ ์„ ํƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด, 14, 7, 1์„ ์„ ํƒํ•˜๋ฉด ๊ณ„์ • ๋งŒ๋ฃŒ 14์ผ, 7์ผ, 1์ผ ์ „์— ๊ฐ๊ฐ ์•Œ๋ฆผ ๋ฉ”์ผ์ด ๋ฐœ์†ก๋ฉ๋‹ˆ๋‹ค.

    • ์ด ๊ธฐ๋Šฅ์€ Integration ๋ฉ”๋‰ด์— Email ์„ค์ •์ด ์™„๋ฃŒ๋œ ํ™˜๊ฒฝ์—์„œ๋งŒ ๋™์ž‘ํ•ฉ๋‹ˆ๋‹ค.

    • ์•Œ๋ฆผ ๊ธฐ๊ฐ„์„ ์•„๋ฌด๊ฒƒ๋„ ์„ ํƒํ•˜์ง€ ์•Š์œผ๋ฉด, ๋งŒ๋ฃŒ ์•Œ๋ฆผ ๋ฉ”์ผ์€ ๋ฐœ์†ก๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

  • Maximum Login Failures before Account Lockout : ๋กœ๊ทธ์ธ ์‹คํŒจ ์‹œ ๊ณ„์ • ์ž ๊ธˆ ์ •์ฑ…

    • QueryPie ๋กœ๊ทธ์ธ ์‹คํŒจ ์ตœ๋Œ€ ํ—ˆ์šฉ ํšŸ์ˆ˜ ์ง€์ • (Default : 60๋ถ„, 5ํšŒ)

    • Enable ์„ ํƒ ์‹œ ํšŸ์ˆ˜ ๋ฐ ๊ธฐ๊ฐ„ ๋ฒ”์œ„ ๊ธฐ์ค€ ์ถ”๊ฐ€ ์ž…๋ ฅ ๊ฐ€๋Šฅ (์˜ˆ: 1440๋ถ„ ๋‚ด 5ํšŒ ์‹คํŒจ ์‹œ ๊ณ„์ • ์ž ๊ธˆ)

  • Restrict Concurrent Login : ๋™์‹œ ๋กœ๊ทธ์ธ ์ œํ•œ ๊ธฐ๋Šฅ์œผ๋กœ ์‚ฌ์šฉ์ž ๋กœ๊ทธ์ธ ๊ณ„์ • ํ•˜๋‚˜์— ๋Œ€ํ•ด ๋™์‹œ์— ์—ฌ๋Ÿฌ ํ™˜๊ฒฝ(Web, Agent ๊ฐ๊ฐ)์—์„œ ํ™œ์„ฑํ™”๋  ์ˆ˜ ์žˆ๋Š” ๋กœ๊ทธ์ธ ์ˆ˜๋ฅผ 1๊ฐœ๋กœ ์ œํ•œํ•˜์—ฌ, ๊ฐ€์žฅ ์ตœ๊ทผ ๋กœ๊ทธ์ธ๋งŒ ํ™œ์„ฑ ์ƒํƒœ๋กœ ์œ ์ง€ํ•˜๊ณ  ์ด์ „ ๋กœ๊ทธ์ธ์€ ๋‹ค์Œ ํ™œ๋™ ์‹œ ์ž๋™ ๋กœ๊ทธ์•„์›ƒ์‹œ์ผœ ๊ณ„์ • ๋ณด์•ˆ์„ ๊ฐ•ํ™”ํ•˜๋Š” ์ •์ฑ….

    • ๋™์‹œ ๋กœ๊ทธ์ธ ์ œํ•œ ๋ฐฉ์‹ : ํ•ด๋‹น ์˜ต์…˜์ด ํ™œ์„ฑํ™”๋˜๋ฉด, ๊ฐ€์žฅ ์˜ค๋ž˜๋œ ๋กœ๊ทธ์ธ ์„ธ์…˜์„ ์ข…๋ฃŒํ•˜๊ณ  ์‹ ๊ทœ ๋กœ๊ทธ์ธ์„ ํ—ˆ์šฉํ•ฉ๋‹ˆ๋‹ค.

      • ๋‹จ, ์˜ต์…˜์„ ํ™œ์„ฑํ™”ํ•œ ์‹œ์ ์— ์ด๋ฏธ ๋กœ๊ทธ์ธ๋œ ์„ธ์…˜์€ ์ฆ‰์‹œ ์ข…๋ฃŒ๋˜์ง€ ์•Š๊ณ  ์œ ์ง€๋ฉ๋‹ˆ๋‹ค. ์ดํ›„ ์ƒˆ๋กœ์šด ์‚ฌ์šฉ์ž๊ฐ€ ๋กœ๊ทธ์ธํ•˜๋ฉด, ๊ธฐ์กด ์‚ฌ์šฉ์ž ์„ธ์…˜์€ ๋กœ๊ทธ์•„์›ƒ๋ฉ๋‹ˆ๋‹ค.

    • ๋กœ๊ทธ์•„์›ƒ ์•Œ๋ฆผ ํ‘œ์‹œ ๋ฐฉ์‹: ๋™์ผ ๊ณ„์ •์œผ๋กœ ๋‹ค๋ฅธ ํ™˜๊ฒฝ์—์„œ ๋กœ๊ทธ์ธํ•  ๊ฒฝ์šฐ, ๊ธฐ์กด ์„ธ์…˜์€ ์ข…๋ฃŒ๋˜๋ฉฐ ์‚ฌ์šฉ์ž์—๊ฒŒ ์•Œ๋ฆผ์ด ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค.

      • ์‚ฌ์šฉ์ž๊ฐ€ Web Inactivity Timeout ๋˜๋Š” Agent Session Timeout ๋ฒ”์œ„ ๋‚ด์—์„œ ํ™œ๋™ ์ค‘์ผ ๊ฒฝ์šฐ, ๋ช…์‹œ์ ์ธ UI ๋™์ž‘(์˜ˆ: ๋ฒ„ํŠผ ํด๋ฆญ, ํŽ˜์ด์ง€ ์ „ํ™˜ ๋“ฑ)์„ ํ†ตํ•ด ์„œ๋ฒ„์™€ ํ†ต์‹ ํ•  ๋•Œ ์•Œ๋ฆผ์ด ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค.

      • ๋ฒ„ํŠผ ํด๋ฆญ ๋“ฑ ์‚ฌ์šฉ์ž API ํ˜ธ์ถœ์‹œ ์•Œ๋ฆผ์ด ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค. ์•Œ๋ฆผ์€ ๋‹ค๋ฅธ ๋กœ๊ทธ์ธ ๋ฐœ์ƒ ์‹œ์ ๋ถ€ํ„ฐ 24์‹œ๊ฐ„ ๋™์•ˆ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค. Web, User Agent, Multi-Agent๋Š” ๊ฐ๊ฐ ๊ฐœ๋ณ„์ ์œผ๋กœ ๋™์‹œ ๋กœ๊ทธ์ธ ์ œํ•œ์ด ์ ์šฉ๋ฉ๋‹ˆ๋‹ค.

ย 

Password Setting

QueryPie ๊ณ„์ •์˜ ํŒจ์Šค์›Œ๋“œ ์ •์ฑ…์„ ์„ค์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

image-20250515-091250.png
  • Maximum Password Age : ๋น„๋ฐ€๋ฒˆํ˜ธ ๋ณ€๊ฒฝ ์ฃผ๊ธฐ (Default : 90์ผ)

  • Password History : ์ด์ „ ๋น„๋ฐ€๋ฒˆํ˜ธ ์žฌ์‚ฌ์šฉ ๊ธˆ์ง€ ํšŸ์ˆ˜ ๊ธฐ์ค€

    • ์„ค์ •๋œ ์ˆซ์ž๋งŒํผ์˜ ๋น„๋ฐ€๋ฒˆํ˜ธ ์ด๋ ฅ์„ ์ €์žฅํ•˜๊ณ , ๋น„๋ฐ€๋ฒˆํ˜ธ ๋ณ€๊ฒฝ์‹œ ๋™์ผํ•œ ๋น„๋ฐ€๋ฒˆํ˜ธ ์‚ฌ์šฉ์„ ๊ธˆ์ง€ํ•จ

  • Minimum Length : ๋น„๋ฐ€๋ฒˆํ˜ธ ์ตœ์†Œ ๊ธธ์ด (Default : 9์ž)

  • Password Complexity Requirements : ํŒจ์Šค์›Œ๋“œ ๋ณต์žก๋„ ์„ค์ •

    • Lower case letter (a-z) : ์†Œ๋ฌธ์ž ํ•„์ˆ˜

    • Upper case letter (A-Z) : ๋Œ€๋ฌธ์ž ํ•„์ˆ˜

    • Number (0-9) : ์ˆซ์ž ํ•„์ˆ˜

    • Special character (e.g., !@#$%^&*) : ํŠน์ˆ˜๋ฌธ์ž ํ•„์ˆ˜

    • Limit 3 repeating characters and numbers (e.g., aaa, bbb) : 3์ž ์ด์ƒ ๋ฐ˜๋ณต๋˜๋Š” ๋ฌธ์ž/์ˆซ์ž ์ œํ•œ

    • Limit 3 consecutive characters and numbers (e.g., abc, 123) : 3์ž ์ด์ƒ ์—ฐ์†๋˜๋Š” ๋ฌธ์ž/์ˆซ์ž ์ œํ•œ

    • Restrict nearby characters on the keyboard (e.g., qwe, ert) : : 3์ž ์ด์ƒ ํ‚ค๋ณด๋“œ ์ƒ ๋‚˜๋ž€ํžˆ ์žˆ๋Š” ๋ฌธ์ž์—ด ์ œํ•œ

    • Does not contain part of personal information (Username, Primary email) : ํŒจ์Šค์›Œ๋“œ ๋‚ด ๊ฐœ์ธ์ •๋ณด(Username, Primary email) ์‚ฌ์šฉ ์ œํ•œ

ย 

Timeout

์›น ์ฝ˜์†”๊ณผ ์—์ด์ „ํŠธ์˜ ํƒ€์ž„์•„์›ƒ ์ •์ฑ…์„ ์„ค์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

image-20251009-051727.png
  • Web Inactivity Timeout : ์›น ์ฝ˜์†” ํƒ€์ž„์•„์›ƒ ๊ธฐ์ค€ (Default : 60๋ถ„)

    • ์ง€์ •๋œ ์‹œ๊ฐ„ ๋™์•ˆ ํ™œ๋™์ด ์—†์„ ๊ฒฝ์šฐ ํƒ€์ž„์•„์›ƒ ์ฒ˜๋ฆฌ

  • Agent Session Timeout : ์—์ด์ „ํŠธ ์„ธ์…˜ ํƒ€์ž„์•„์›ƒ ๊ธฐ์ค€ (Default : 1,440๋ถ„)

    • ์ง€์ •๋œ ์‹œ๊ฐ„ ๋™์•ˆ ์—์ด์ „ํŠธ ์•ฑ ๋กœ๊ทธ์ธ์„ ์œ ์ง€ํ•˜๊ณ , ๊ฒฝ๊ณผ ์‹œ ๋กœ๊ทธ์•„์›ƒ ์ฒ˜๋ฆฌ

  • User Inactivity Timeout (on agent) :

    Agent Session Timeout ๊ธฐ๋Šฅ์— ์ถ”๊ฐ€๋กœ Agent๊ฐ€ ์‚ฌ์šฉ์ž์˜ ๋งˆ์šฐ์Šค, ํ‚ค๋ณด๋“œ ์ž…๋ ฅ์„ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜๊ณ  ์ง€์ •๋œ ์‹œ๊ฐ„์„ ์ดˆ๊ณผํ•˜์—ฌ ํ–‰์œ„(ํ‚ค๋ณด๋“œ์˜ ํ‚ค ์ž…๋ ฅ, ๋งˆ์šฐ์Šค ํด๋ฆญ, ๋งˆ์šฐ์Šค ํฌ์ธํ„ฐ ์ด๋™, ๋งˆ์šฐ์Šค ํœ  ์กฐ์ž‘, ๋งˆ์šฐ์Šค ๋“œ๋ž˜๊ทธ)๊ฐ€ ์—†์œผ๋ฉด ์„ธ์…˜์„ ๊ฐ•์ œ ์ข…๋ฃŒํ•ฉ๋‹ˆ๋‹ค. ์œ ํœด ์ƒํƒœ์ธ ๊ฒฝ์šฐ, ์žฅ์‹œ๊ฐ„ ์ฟผ๋ฆฌ๋ฅผ ์‹คํ–‰ํ•˜๊ณ  ์žˆ์–ด๋„ ๋งˆ์šฐ์Šค ๋ฐ ํ‚ค๋ณด๋“œ ์›€์ง์ž„์ด ์—†๋‹ค๋ฉด ๋ฌด์กฐ๊ฑด ์„ธ์…˜์ด ์ข…๋ฃŒ๋˜์–ด ๋กœ๊ทธ์•„์›ƒ์ฒ˜๋ฆฌ ๋ฉ๋‹ˆ๋‹ค. ์‚ฌ์šฉ์ž ํ–‰์œ„ ๊ฐ์‹œ๋Š” 30์ดˆ๋งˆ๋‹ค ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค. ์ตœ๋Œ€ ์œ ํœด ๋งŒ๋ฃŒ์‹œ๊ฐ„์ด Agent Session Timeout์„ ์ดˆ๊ณผ ํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.

User Inactivity Timeout (on agent) ์„ค์ • ์˜ˆ์‹œ

  • Agent Session Timeout์ด 30๋ถ„์ด๊ณ  User Inactivity Timeout 15๋ถ„์ผ ๊ฒฝ์šฐ๋ฅผ ๊ฐ€์ •ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์Šต๋‹ˆ๋‹ค.

    • 12:00๋ถ„์— ๋กœ๊ทธ์ธ ํ–ˆ์„ ๊ฒฝ์šฐ ์ตœ์ดˆ ์œ ํœด ๋งŒ๋ฃŒ ์‹œ๊ฐ„์€ 12:15:00 ์ž…๋‹ˆ๋‹ค.

    • 12:08๋ถ„์—(t+8๋ถ„) ๋งˆ์ง€๋ง‰ ํ™œ๋™์„ ํ•œ๊ฒƒ์œผ๋กœ ํ™•์ธ๋˜๋ฉด, ์ƒˆ๋กœ์šด ์œ ํœด ๋งŒ๋ฃŒ ์‹œ๊ฐ„์€ 12:23:00 ์ž…๋‹ˆ๋‹ค.

    • ๊ทธ ๋’ค 1๋ถ„์ด ์ง€๋‚œ 12:09๋ถ„์— ํ™œ๋™์„ ํ•œ๊ฒƒ์„ ํ™•์ธ๋˜๋ฉด, ์ƒˆ๋กœ์šด ์œ ํœด ๋งŒ๋ฃŒ ์‹œ๊ฐ„์€ 12:24:00 ์ž…๋‹ˆ๋‹ค.

    • Agent Session Timeout์ด 30๋ถ„์ด๋ฏ€๋กœ ์‚ฌ์šฉ์ž์˜ ํ–‰์œ„ ์œ ๋ฌด์™€ ๊ด€๊ณ„์—†์ด 12:30:00์— ์„ธ์…˜์ด ์ข…๋ฃŒ๋ฉ๋‹ˆ๋‹ค.

ย 

QueryPie Web IP Access Control

QueryPie ์ ‘์† ์‹œ IP ์ œํ•œ ์ •์ฑ…์„ ์„ค์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

  • All Users : ๋ชจ๋“  ์‚ฌ์šฉ์ž์— ๋Œ€ํ•ด ์ ์šฉ๋˜๋Š” IP ์ œํ•œ ์„ค์ • (Default : 0.0.0.0/0)

  • Each User : ํ† ๊ธ€์„ ์ผœ๋ฉด ๊ฐœ๋ณ„ ์‚ฌ์šฉ์ž์— ๋Œ€ํ•ด Allowed Zone ์„ค์ • ๊ฐ€๋Šฅ

    • ์‚ฌ์šฉ์ž๋ณ„ Allowed Zone ์„ค์ • ๋ฐฉ๋ฒ•์€ ์‚ฌ์šฉ์ž ํ”„๋กœํ•„ ์—์„œ ํ™•์ธ ๊ฐ€๋Šฅ

    • Use Individual Configuration of Allowed Zones for Each User : ์‚ฌ์šฉ์ž๋ณ„ ๊ฐœ๋ณ„ IP ํ—ˆ์šฉ ์˜์—ญ(Allowed Zone)์„ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.

      • ํ™œ์„ฑํ™” ์‹œ, ์‚ฌ์šฉ์ž ๋ชฉ๋ก ๋ฐ ๊ฐ ์‚ฌ์šฉ์ž์—๊ฒŒ ํ• ๋‹น๋œ IP ํ—ˆ์šฉ ์˜์—ญ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋Š” View User to Allowed Zone Mappings ๋งํฌ๊ฐ€ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค.

      • View User to Allowed Zone Mappings: ํด๋ฆญ ์‹œ ์‚ฌ์šฉ์ž๋ณ„ Allowed Zone ๋ชฉ๋ก์„ ๋ชจ๋‹ฌ(Modal) ์ฐฝ์—์„œ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์‚ฌ์šฉ์ž ์ด๋ฆ„(Display Name)์œผ๋กœ ๊ฒ€์ƒ‰์ด ๊ฐ€๋Šฅํ•˜๋ฉฐ, ๋ชฉ๋ก์—๋Š” ์‚ฌ์šฉ์ž์˜ ์ด๋ฆ„, ๋กœ๊ทธ์ธ ID, ์ด๋ฉ”์ผ, ๊ทธ๋ฆฌ๊ณ  ํ• ๋‹น๋œ ๋ชจ๋“  IP ์ฃผ์†Œ๊ฐ€ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค.

    • Require Allowed Zones for User Access : ์‚ฌ์šฉ์ž์˜ IP ํ—ˆ์šฉ ์˜์—ญ ์„ค์ •์„ ํ•„์ˆ˜๋กœ ๊ฐ•์ œํ•˜๋Š” ์ •์ฑ…์ž…๋‹ˆ๋‹ค.

      • ์ด ์˜ต์…˜์„ ํ™œ์„ฑํ™”ํ•˜๋ฉด, ๊ฐœ๋ณ„ IP ํ—ˆ์šฉ ์˜์—ญ(Allowed Zone)์ด ์„ค์ •๋˜์ง€ ์•Š์€ ์‚ฌ์šฉ์ž๋Š” QueryPie์— ๋กœ๊ทธ์ธํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. ๋กœ๊ทธ์ธ ํŽ˜์ด์ง€ ์ ‘๊ทผ์€ ๊ฐ€๋Šฅํ•˜์ง€๋งŒ, ๋กœ๊ทธ์ธ ์‹œ๋„๊ฐ€ ์ฐจ๋‹จ๋ฉ๋‹ˆ๋‹ค.

IP ์ ‘๊ทผ ์ œ์–ด ์ •์ฑ… ํ™œ์„ฑํ™” ์‹œ ์œ ์˜์‚ฌํ•ญ

Require Allowed Zones for User Access ์˜ต์…˜ ํ™œ์„ฑํ™”๋กœ ์ธํ•ด ๋กœ๊ทธ์ธ์ด ์ฐจ๋‹จ๋œ ์‚ฌ์šฉ์ž๋Š” 'IP Registration Request' ์›Œํฌํ”Œ๋กœ์šฐ๋ฅผ ํ†ตํ•ด ์‹ ๊ทœ IP ์ฃผ์†Œ์— ๋Œ€ํ•œ ์ ‘๊ทผ ํ—ˆ์šฉ์„ ์š”์ฒญํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. (์ž์„ธํ•œ ๋‚ด์šฉ์€ IP Registration Request ์š”์ฒญํ•˜๊ธฐ ๋ฌธ์„œ๋ฅผ ์ฐธ๊ณ ํ•˜์‹ญ์‹œ์˜ค.)

  • Admin Page Access Control : ๊ด€๋ฆฌ์ž ํŽ˜์ด์ง€์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๋Š” ๊ด€๋ฆฌ์ž์˜ IP๋ฅผ ์ œํ•œํ•˜๋Š” ์ •์ฑ…์„ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. ํ† ๊ธ€์„ ํ™œ์„ฑํ™”ํ•˜์—ฌ ํŠน์ • IP ์ฃผ์†Œ ๋˜๋Š” ๋Œ€์—ญ์—์„œ ์ ‘์†ํ•˜๋Š” ๊ด€๋ฆฌ์ž๋งŒ ๊ด€๋ฆฌ์ž ํŽ˜์ด์ง€์— ์ ‘๊ทผํ•˜๋„๋ก ์ œํ•œํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

    image-20251212-161723.png
    Admin ํŽ˜์ด์ง€ IP ์ ‘๊ทผ ์ฐจ๋‹จ ์‹œ ํ™”๋ฉด
    • ์ ‘๊ทผ ์š”๊ตฌ ์กฐ๊ฑด:

      • ์‚ฌ์šฉ์ž๋Š” ๊ด€๋ฆฌ์ž ๊ถŒํ•œ์„ ๊ฐ€์ง€๊ณ  ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

      • ์‚ฌ์šฉ์ž์˜ ์ ‘์† IP๋Š” 'All Users'์— ์„ค์ •๋œ IP ๋Œ€์—ญ์— ํฌํ•จ๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

      • ์‚ฌ์šฉ์ž์˜ ์ ‘์† IP๋Š” 'Admin Page Access Control'์— ๋“ฑ๋ก๋œ IP ๋ชฉ๋ก์— ํฌํ•จ๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

    • ๊ด€๋ฆฌ์ž ํŽ˜์ด์ง€ ์ ‘๊ทผ ์ œ์–ด ์„ค์ • ์‹œ ์œ ์˜์‚ฌํ•ญ

      • Admin Page Access Control์— IP๋ฅผ ์ถ”๊ฐ€ํ•  ๊ฒฝ์šฐ, ํ•ด๋‹น IP๋Š” ๋ฐ˜๋“œ์‹œ ์ƒ์œ„์˜ All Users ์„ค์ •์—๋„ ํฌํ•จ๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๋งŒ์•ฝ All Users์— ๋“ฑ๋ก๋˜์ง€ ์•Š์€ IP๋ฅผ ์ถ”๊ฐ€ํ•˜๊ณ  ์ €์žฅ์„ ์‹œ๋„ํ•  ๊ฒฝ์šฐ, ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ•˜๋ฉฐ ์„ค์ •์ด ์ €์žฅ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

Q. ๋งŒ์•ฝ ์‚ฌ์šฉ์ž๊ฐ€ ํ—ˆ์šฉ๋˜์ง€ ์•Š์€ IP ์—์„œ QueryPie ์›น ์ฝ˜์†” ์ ‘์† ์‹œ๋„ ์‹œ ์–ด๋–ค ํ™”๋ฉด์„ ๋ณด๊ฒŒ ๋˜๋‚˜์š”?

A. ํ—ˆ์šฉ๋˜์ง€ ์•Š์€ IP์—์„œ ์ ‘์† ์‹œ๋„ ์‹œ QueryPie ์›น ์ฝ˜์†” ๋‚ด ์–ด๋–ค ํŽ˜์ด์ง€์ด๋“  ์ ‘๊ทผ์ด ๋ถˆ๊ฐ€ํ•˜์—ฌ ์•„๋ž˜์™€ ๊ฐ™์€ ์•ˆ๋‚ด ํ™”๋ฉด์„ ๋ณด๊ฒŒ ๋ฉ๋‹ˆ๋‹ค. ๋งŒ์•ฝ All Users์— ๊ธฐ๋ณธ๊ฐ’(0.0.0.0/0)์ด ๋“ฑ๋ก๋˜์–ด ์žˆ๊ณ , ๊ฐœ๋ณ„ ์‚ฌ์šฉ์ž์—๊ฒŒ ํŠน์ • Allowed Zone ์ด ์„ค์ •๋˜์–ด ์žˆ๋‹ค๋ฉด ๋กœ๊ทธ์ธ ํŽ˜์ด์ง€๊นŒ์ง€๋Š” ์ ‘์†์ด ๊ฐ€๋Šฅํ•˜๋‚˜ ๋กœ๊ทธ์ธ์€ ๋ถˆ๊ฐ€ํ•˜๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.

image-20251218-082726.png
Each User ์„ค์ •์˜ IP ์ ‘๊ทผ ์ฐจ๋‹จ ์‹œ ํ™”๋ฉด
image-20251212-162103.png
All User ์„ค์ •์˜ IP ์ ‘๊ทผ์ฐจ๋‹จ ์‹œ ํ™”๋ฉด

ย 

IP ์ œํ•œ ์„ค์ • ์ฃผ์˜

Security ํŽ˜์ด์ง€์˜ ์„ค์ •์€ ์ €์žฅ ์ฆ‰์‹œ ๋ฐ˜์˜๋ฉ๋‹ˆ๋‹ค. ๋”ฐ๋ผ์„œ ์ž…๋ ฅํ•œ IP์™€ ํ•ด๋‹น ์˜ต์…˜์„ ์„ค์ •ํ•œ ๊ด€๋ฆฌ์ž์˜ IP๊ฐ€ ์ผ์น˜ํ•˜์ง€ ์•Š์„ ๊ฒฝ์šฐ ๊ด€๋ฆฌ์ž๋ผ ํ•˜๋”๋ผ๋„ ์ €์žฅ ์ฆ‰์‹œ ๋กœ๊ทธ์•„์›ƒ ์ฒ˜๋ฆฌ๋˜๋‹ˆ ์ฃผ์˜ํ•ด์„œ ์ ์šฉํ•ด ์ฃผ์‹œ๊ธฐ ๋ฐ”๋ž๋‹ˆ๋‹ค.

ย 

Secret Store ์„ค์ •

Secret Store ์‚ฌ์šฉ ์—ฌ๋ถ€๋ฅผ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. ํ˜„์žฌ HashiCorp Vault๋ฅผ ์ง€์›ํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

แ„‰แ…ณแ„แ…ณแ„…แ…ตแ†ซแ„‰แ…ฃแ†บ 2024-07-26 แ„‹แ…ฉแ„’แ…ฎ 3.20.42.png

Vault ๋“ฑ๋ก์€ General > Integrations ๋ฉ”๋‰ด์—์„œ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

Q. Secret Store ํ™œ์„ฑํ™”๋ฅผ ํ•ด์ œํ•˜๊ณ  ์‹ถ์€๋ฐ, ํ† ๊ธ€์ด ๋น„ํ™œ์„ฑํ™” ์ƒํƒœ์ž…๋‹ˆ๋‹ค.

A. Administrator > General > Integrations > HashiCorp Valut ๋ฉ”๋‰ด์— ๋“ฑ๋ก๋œ Vault ๊ฐ€ ๋‚จ์•„์žˆ๋Š”์ง€ ํ™•์ธํ•ด๋ณด์„ธ์š”. ๋“ฑ๋ก๋œ Vault๊ฐ€ ๋ชจ๋‘ ์ œ๊ฑฐ๋œ ํ›„ ํ† ๊ธ€ ๋น„ํ™œ์„ฑํ™” ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

ย 

Secret Store ์‚ฌ์šฉ ํ™œ์„ฑํ™” ๋ฐ Vault ๋“ฑ๋ก์ด ์™„๋ฃŒ๋œ ํ›„, DB ์ปค๋„ฅ์…˜ ์ƒ์„ธ ํŽ˜์ด์ง€ ๋˜๋Š” Server Group ์ƒ์„ธ ํŽ˜์ด์ง€์—์„œ ์ธ์ฆ ์ •๋ณด ์ €์žฅ์†Œ๋ฅผ ์„ ํƒํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.

ย 

แ„‰แ…ณแ„แ…ณแ„…แ…ตแ†ซแ„‰แ…ฃแ†บ 2024-07-26 แ„‹แ…ฉแ„’แ…ฎ 6.59.46.png
DB Connection ์ƒ์„ธ ํŽ˜์ด์ง€ ๋‚ด Connection Information > Secret Store ์„ ํƒ

ย 

แ„‰แ…ณแ„แ…ณแ„…แ…ตแ†ซแ„‰แ…ฃแ†บ 2024-07-26 แ„‹แ…ฉแ„’แ…ฎ 7.00.34.png
Server Group ์ƒ์„ธ ํŽ˜์ด์ง€ ๋‚ด Accounts > Secret Store ์„ ํƒ

11.1.0์— OAuth Client ๊ด€๋ จ ์„ค์ •์ด Admin > General > Company Management > Security ํ•˜์œ„ ํ•ญ๋ชฉ์œผ๋กœ ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค.(๋‹จ์ผ ํด๋ผ์ด์–ธํŠธ ์„ค์ •๋งŒ ๊ฐ€๋Šฅ)

11.3.0์— Client ์„ค์ •์„ ๋‹ค์ค‘ ์„ค์ •์ด ๊ฐ€๋Šฅํ•˜๋„๋ก ๊ฐœ์„ ๋˜๋ฉด์„œ Admin > General > System > Integrations ํ•ญ๋ชฉ์œผ๋กœ ์ด๋™๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

๊ธฐํƒ€

๊ธฐํƒ€ ๋ณด์•ˆ ์„ค์ •์„ ๊ด€๋ฆฌํ•ฉ๋‹ˆ๋‹ค.

แ„‰แ…ณแ„แ…ณแ„…แ…ตแ†ซแ„‰แ…ฃแ†บ 2024-07-26 แ„‹แ…ฉแ„’แ…ฎ 3.20.51.png
  • Export a file with Encryption : ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ ์‹œ ์•”ํ˜ธ ์ž…๋ ฅ ์—ฌ๋ถ€

    • Required ์„ ํƒ ์‹œ, ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ ์‹œ์— ํŒŒ์ผ ์•”ํ˜ธ ์ง€์ • ํ•„์ˆ˜

ย