ServerlessDays Tokyo 2019 åå ã¡ã¢
ServerlessDays Tokyo 2019ã®åå ã¡ã¢ã§ãã
åå ããåã¯ã»ãã·ã§ã³ãé¸ã¹ãªãã®ã§å¾®å¦ã¨ãæã£ã¦ã¾ããããå®éåå ããã¨æ®æ®µè§¦ããªã話(â»ä¸»ã«Azure)ãè²ã
èããã®ã§è¯ãã£ãã§ããæ¼ããã®åå ã¨ãªã£ãã®ãæ®å¿µã§ãããããæ¼ã飯ã«ã¯éã«åãã¾ãããããããã£ãã§ãï¼ï¼å°ä¸¦
â ServerlessDays Tokyo 2019
tokyo.serverlessdays.io
ã¹ã©ã¤ããªã©ã¯ã#ServerlessDaysããã大ä½è¿½ããã¨æãã¾ãã
twitter.com
以ä¸ã»ãã·ã§ã³ã®ã¡ã¢ã§ãã
â All You Need Is JavaScript
ã»CloudFlareã®ä¸ã®äººãæ¥æ¬èªã§çºè¡¨ããã¦ããã
ã»TypeScriptã¯JavaScriptã«è¿½ãã¤ãã¤ã¤ããã
ã»CloudFlareã¯CDNãµã¼ãã¹ãã»ãã¥ãªãã£ãµã¼ãã¹ãªã©ãæä¾ããäºæ¥è
ã
âAkamaiçãªä¼æ¥ã
https://ja.wikipedia.org/wiki/Cloudflare
â Zero Scale Abstraction in Knative Serving
ã»Knative
âk8sããµã¼ãã¬ã¹ã§åããããã®ã¯ã¼ã¯ãã¼ã
https://cloud.google.com/knative/?hl=ja
ã»Herokuã¨ä¼¼ããã©ãããã©ã¼ã
âk8sã®ä¸ã«æ¡å¼µãã¦ããã
ã»ãk8sãã¯ã©ã¦ãä¸ã§æ½è±¡åãããµã¼ãã¹ã
ã»yamlå°çã«ãªããªããknativeå´ã§ã³ã¼ãåå¯è½ ã
ã»GoLangã§æ¸ããã¦ãã
ã»kubectlãªã©ã®k8sã®CLIãå©ç¨ããã®ã§ã¯ãªãã
ãGitä¸ã§Knativeã®æ§æ管çãå®æ½ããããGitOpsããã
ãâãpush code, not containerã
https://thinkit.co.jp/article/14164
ã»podã«å梱ã§ããã³ã³ããã¯ï¼ã¤ã ããï¼sidecarãªã©ã¯ã§ããªãï¼
ã»ããªã¥ã¼ã ã®ã¢ã¿ãããã§ããªã
âç念ã«ããããªã
ã»podãã©ã®ã¤ã³ã¹ã¿ã³ã¹ã§ç«ã¦ãããæå®ã§ããªã
âç念ã«ããããªã
ã»ãªã¼ãã¹ã±ã¼ã«æªå¯¾å¿ããããæ¯ã®æ¯ãåãæªå¯¾å¿ã
ã»Cyberã§å©ç¨æ¤è¨ä¸ãk8sãç´æ¥å©ç¨ããã®ã¯æ·å±
ãé«ãã
âGCPã§ã¯ãµã¼ãã¹æä¾ããã¦ããããAWSä¸ã§Knativeç«ã¦ããã¨ãã¦ããã
ã»Knativeã®ãã¼ã¸ã§ã³ã¢ããã¯AWSã®Global Acceleratorãå©ç¨ãããã¨ãã¦ããã
â 空調è¨ååãIoTã·ã¹ãã ã«ãããã¯ã©ã¦ãã©ã³ãã³ã°ã³ã¹ã
ã»ã³ã¹ãåæ¸ã®ã話ãAWS DynamoDBã®ä¸å¿ã«ç´¹ä»
ã»30ä¸äººãå©ç¨ããIoTã·ã¹ãã
âãµã¼ãã¬ã¹ãå¿
é
https://aws.amazon.com/jp/solutions/case-studies/daikin/
ã»ãµã¼ãã¬ã¹éçºã¯åå¼·å·¥ã¹ãã¨ã®éã
ã»ç©ºèª¿æ©âkinesisâDynamoDB
âé éæä½ãå¿
è¦ãªæ©å¨ã®ãã¼ã¿ãæ ¼ç´
âé転ãã¼ã¿ãµã¤ãºï¼æ大ã§æ°ï¼ï¼ï½ï½ï¼ãé£ãã§ãã
ã»1åã®APIã³ã¼ã«ã§æ°ååã®æ©å¨ãã¼ã¿ãåå¾ãã使ãæ¹ããã
ã»Lambdaã®å¦çæéã¨DynamoDBã®DPUãã³ã¹ãã®å¤§åãå ããããã«ãªã£ãã
ã»DynamoDBã®èª²éä»æ§ãè¸ã¾ããã¢ã¤ãã ãåå²ããã
âæ¸ãæãã対象ã®ãã¼ã¿å®¹éãå°ããããã
ã»ä¸æ¬æ´æ°ãããããªã¯ã¨ãªãããå ´åã¯ã¤ã³ããã¯ã¹ã追å ãã¦ä¸æ¬æ´æ°ã§ããããã«ããã
âå¦çæéã®ç縮ã«ããLambdaå¦çæéã®ç縮
ã»DynamoDBã®ãã¼æ§é ãéè¦ï¼æ§è½ã»ã³ã¹ãï¼
ã»ã³ã¹ãã®å¤±æ
âã¤ã³ã¹ã¿ã³ã¹èµ·åãã£ã±ãªã
ãâè² è·ãã¼ã«ããµã¼ãã¬ã¹ã§ä½ãæ¹ããã
âãã°å¤ããåé¡
ãâCloudWatch Logsã®ã³ã¹ããé«ã
â ISPããµã¼ãã¬ã¹ã«æãåºãã
ã»OCNã®ä¸ã®äºº
ã»PPPoEæ··ã¿ããåé¡(IPv4)
âVirtualConncect(IPv6) /56ãæä¾ããã
ã»v4 over v6 tunnel
âã客æ§å´æ©å¨ã«å¯¾ãã¦IPv6æ¥ç¶ãè¦æ±ããå¿
è¦ãããã
ã»ç¤¾å
åºæºã¨é»éæ³å¯¾å¿
âãã¾ãã¾èªç¤¾ã¯ã©ã¦ããIPv4対å¿ãã¦ããªãã£ããä»æ¹ãªãã®ã§IPv6ã§å¯¾å¿
âåç·æ°ã«å¿ãã¦ä¿¡é ¼æ§ãæ
ä¿ããå¿
è¦ããããï¼â»ç·åçã¸ã®å ±åãçºçãããããï¼
âAWSï¼ã¯ã©ã¦ãï¼ãæ¬å½ã«ä¿¡é ¼ã«è¶³ãããã¨ãã調æ»ãããã
ã»Azure CDN
âcommon nameãæå®ã§ããªãï¼è¨å®ãæ¶ããï¼ï¼ï¼
âAWSã¸ä¹ãæãããDynamoDB GlobalTableå©ç¨ã
ã»ãã¹ãèªåå
âServerlessFrameworkï¼ãã¼ã«ã«ã§ãåããããï¼
ãâãã©ã°ã¤ã³ã®ã¢ãããã¼ããæ©ã
ãâç´°ããã¨ããã¯é対å¿ã®ã¨ãããããï¼CDNç³»ã¨ãã®è¨å®é
ç®ãªã©ï¼
âgatlingã¨ããè² è·ãã¼ã«ã使ã£ã¦ãã
https://qiita.com/ntrv/items/394a38d26e94565db31a
âè² è·ããããã¨ã¦ãããã®åãæ¿ãã»è¿½å ã®ã¿ã¤ãã³ã°ãã¿ãããã®ã§ããã«ãªã£ãã
ã»B-Gãããã¤ã®æ¹æ³ã§æ©ãã ï¼CDNã§åãæ¿ããï¼
ã»CloudWatchãã«æ´»ç¨ã
âCloudwatch LogInsightsã§ã¨ã©ã¼åæããã£ã¦ãããCloudWatchãç´æ¥è¦ãã®ã¯ã¾ãã
ã»æ¨æºåãä»å¾ãã£ã¦ãããã
ã»äººéãããã«ããã¯ã«ãªã£ã¦ããï¼ï¼äººããããªãã®ã§â¦ã¨ã®ãã¨ï¼
â AWS Lake Formation ã§å®ç¾ããã¤ã¯ããµã¼ãã¹ã®ãµã¼ãã¼ã¬ã¹ãªåæ£ãã¬ã¼ã·ã³ã°
ã»è¤éã«çµ¡ãã ãµã¼ãã¹ã®ã¨ã©ã¼èª¿æ»ãåæ£ãã¬ã¼ã·ã³ã°ã§è§£æ±ºãã話
ã»step functionsãå©ç¨ãããã°ã®åºå
ã»ãã¬ã¼ã·ã³ã°ID
âX-Rayã¯éåæå¦çã«å¯¾å¿ã§ããªãã®ã§ãã¬ã¼ã¹IDã®åãåããå¿
è¦ã
ãâAPIGW(HTTPããã)âSNSï¼æ§é åã¡ã¿ãã¼ã¿ãè¨å®ï¼âSQSï¼MessageAttributeï¼
ã âSTEP Fn(ResultPathãå©ç¨)âS3(Object metadata)
â Donât think Serverless Security, think Application Security
ã»ã¤ã¹ã©ã¨ã«ã®ã¹ã¿ã¼ãã¢ããä¼æ¥ã®æ¹ï¼Nuwebaï¼ãå
¨ç·¨è±èªã ã£ãã®ã§ééã£ã¦ãããããã
https://www.nuweba.com/
ã»ãµã¼ãã¬ã¹ã»ãã¥ãªãã£ã
https://www.nuweba.com/dont-think-serverless-security-think-application-security
ã»new cyber security risks
ï¼ï¼attackï¼trigger, eventï¼
âæ»æ対象ã®å¤æ§åãä¾ãã°APIGW,Lambda,IoTãªã©ã
ï¼ï¼harder to manage
âãµã¼ãã¬ã¹ãªãã©ãããã©ã¼ã ã®å ´åãæ»æã«æ°ã¥ãã®ãé£ãã
ï¼ï¼denial of wallet
âãªã½ã¼ã¹ã®éå°æ¶è²»æ»æ
https://www.helpnetsecurity.com/2019/03/29/serverless-challenges/
ï¼ï¼Serverless leads to over-privilleged functions IAM permissions
âèªå¯ã¨èªè¨¼ã®å¯¾è±¡ãç¯å²ãé©åã«ç®¡çããå¿
è¦ããã
ï¼ï¼ï¼ãµã¼ãã¬ã¹ã§ãã£ã¦ãï¼ã³ã¼ãã®èå¼±æ§ã¯æ··å
¥ããæããããï¼ï¼ï¼
â Azure ã§ãµã¼ãã¼ã¬ã¹ã Infrastructure as Code ã©ããã¦ã¾ããï¼
ã»IaCã®è©±ã
ã»ã¯ã©ã¦ãã«ããããªã½ã¼ã¹ç®¡ç
âARM(Azure Resource Manager)ãã³ãã¬ã¼ããJSONã
ã»VSCodeã ã¨ã·ã³ã¿ãã¯ã¹ãå¹ãã¾ãã
ã»Azureã®GUIä¸ã§å
容確èªå¯è½
ã»Azureã ã¨ã¢ãããã¼ãããzipã®ä¸ã®ãã¡ã³ã¯ã·ã§ã³ãæå®ãã¦å®è¡å¯è½ã
âãããã¤å¾ã«ããå®è¡ãå¯è½
ã»https://docs.microsoft.com/ja-jp/azure/azure-functions/functions-infrastructure-as-code
ã»ãªã½ã¼ã¹åã®ã¤ãæ¹ã«æ³¨æï¼å¶ç´ãããã24æå以å
ï¼
ã»IaCï¼CI/CDã®æ´»ç¨ãæããæ°è¦åç»è
ã«ãããã
â The hidden cost and technical debt of running huge Serverless service on production
ã»æ¬çªç°å¢ã§å·¨å¤§ãªã³ã³ããã¯ã¼ã¯ãã¼ããå®è¡ããã¨ãã®èª²é¡
ã»1TBä½ã®EBSã«é害ãèµ·ããããç¹å®ã®ãã¬ã¼ã ã¯ã¼ã¯ãã使ãã¾ãããªã©
ã»ãµã¼ãã¹ãææ°ã®ç¶æ
ã«ä¿ã¤å¿
è¦ããã
ã»å©ç¨ãµã¼ãã¹ã®ç¶ç¶çãªè¦ç´ããå¿
è¦ã
âAWS Simple Workflowã§ã¯ãªãStepFunctionã使ãetc
ã»æåãããã¸ã§ãã³ã°
ã»ãã¼ã¿ãã¼ã¹ã®ãããã¸ã§ãã³ã°
ã»ãã³ãã¼ããã¯ã¤ã³
âãã³ãã¼ããªã¼ã«ãããã¨ã¯é£ãã
ã»è«æ±ç®¡çãéç´ãããã¨ã§ç®¡çã容æã«ãªã
ã»ãã³ãã¼ãçµ±ä¸ãããã¨ã¯ã³ã¹ãé¢ã§æå©