2023-10-01ãã1ã¶æéã®è¨äºä¸è¦§
ããã㨠terraformã§API Gatewayï¼Lambdaã®æ§æãä½æããã æ§æ ãã©ã¦ã¶ â APIGateway â Lambda(Python) å®è·µ ï¼ï¼Pythonã³ã¼ãä½æ # vi lambda_function.py import json def lambda_handler(event, context): # TODO implement return { 'statusCode':â¦
WAFã使ã£ãç°å¢æ§ç¯æ¡ä»¶ãå¢ããããªã®ã§ãåå¼·ãã¦ã¿ãã ããã㨠terraformã§WAFï¼ALBï¼EC2ã®ç°å¢ãä½æãããã®å¾æ¥ç¶å ã®IPãå¶éããè¨å®ãå ¥ãæåã確èªããã ç°å¢ æ¥ç¶å â AWS WAF â ALB â EC2(Nginx) å®è·µï¼ ï¼ï¼ç°å¢ä½æ # vi main.tf provideâ¦
ä¸è¨ã§ä½æããã«ã¹ã¿ã ãããã¼è¨å®ããCloudFrontï¼ALBï¼EC2(Nginx)ã®æ§æãterraformã®importã使ç¨ãã¦ã³ã¼ãã«èµ·ããã¦ã¿ãã CloudFront+ALBã§ã«ã¹ã¿ã ãããã¼ãå©ç¨ãã¦ãALBã§CloudFrontããã®æ¥ç¶ã®ã¿è¨±å¯ãã - ãããããã®ITããã° terraform iâ¦
ã«ã¹ã¿ã ãããã¼ãå©ç¨ãã¦ãCloudFrontããã®æ¥ç¶ã®ã¿ALBã§è¨±å¯ããè¨å®ãå ¥ãã¦ã¿ãã ããã㨠Terraformã§CloudFrontï¼ALBï¼EC2(Nginx)ã®ç°å¢ãæ§ç¯ããCloudFrontããã®æ¥ç¶ã®ã¿ãALBã§è¨±å¯ããããã«ã¹ã¿ã ãããã¼ã«è¨å®ãå ¥ãã¦ãCloudFrontãALBãâ¦
AWS CLIã§è¨¼ææ¸ã®ä¸è¦§ãåå¾ãããã¨ãããä¸é¨ãåå¾ãããªãç¶æ³ã確èªããã®ã§èª¿ã¹ã¦ã¿ã åå¾ã§ããªã証ææ¸ ã©ãããã¼ã¢ã«ã´ãªãºã ã®ãEC_prime256v1ããåå¾ã§ããªã模æ§ã åå ãªãã¡ã¬ã³ã¹ãèªãã¨ãã¼ã¢ã«ã´ãªãºã ãRSA_2048ãã§ãã£ã«ã¿ãããâ¦
AWS WAFã®WebACLã«è¨å®ãããã¿ã°ã¯GUIã§ã¯ç¢ºèªã§ããªãã®ã§CLI確èªããæ¹æ³ã調ã¹ã¦ã¿ã å®è·µï¼ ï¼ï¼ç°å¢ä½æ â»ä¸è¨ã使ç¨ãã¦ç°å¢ãä½æããã amegaeru.hatenablog.jp ï¼ï¼WebACLã®ARNãç¢ºèª â»CloudShellã§å®è¡ # aws wafv2 list-web-acls --scope REGIONâ¦
terraformã§æ¤è¨¼ãã¦ããã¨S3ãã±ããã«ãªãã¸ã§ã¯ããããã¨åé¤ã§ããã«ã¨ã©ã¼ã«ãªãã®ã§é½åº¦GUIã§åé¤ããã®ã大å¤é¢åã§ã調ã¹ã¦ã¿ããæ¹æ³ããã£ãã®ã§ãã£ã¦ã¿ãã çç¶ S3ãã±ããå ã«ãªãã¸ã§ã¯ããããã¨ä¸è¨ã¨ã©ã¼ãã§ãã 対ç S3ãã±ããã®ã³ã¼â¦
Amazon CloudFrontï¼S3ã®æ§æã§ç´æ¥S3ã«ã¢ã¯ã»ã¹ãããããªãã®ã§ãOAI(ãªãªã¸ã³ã¢ã¯ã»ã¹ã¢ã¤ãã³ãã£ãã£)ãè¨å®ãã¦CloudFrontããã®æ¥ç¶ä»¥å¤ã¯åãä»ããªãããã«ããã Amazon CloudFrontã¨ã¯ é«ãããã©ã¼ãã³ã¹ãã»ãã¥ãªãã£ããããããã¼ã®å©ä¾¿æ§ã®â¦
AWS WAFã使ãæ©ä¼ããã£ãã®ã§ã¡ããã¨èª¿ã¹ã¦ã¿ãã AWS WAFã¨ã¯ Web ã¢ããªã±ã¼ã·ã§ã³ã®éä¿¡ããã£ã«ã¿ã¼ãç£è¦ããããã¯ããããã®ã½ããã¦ã§ã¢ã¾ãã¯ããã¼ãã¦ã§ã¢ã®ã»ãã¥ãªãã£å¯¾çã ä¸è¬ã®ãã¡ã¤ã¢ã¦ã©ã¼ã«ã IDS/IPS ã¨ã®éãã¯ãã¢ããªã±ã¼ã·ã§â¦
S3ãè¦ã¦ããã¨ãã±ããåä½ã®ãããªãã¯ã¢ã¯ã»ã¹ãããã¯ã®ã»ãã«ã¢ã«ã¦ã³ãã¬ãã«ã§ã®ãããªãã¯ã¢ã¯ã»ã¹ãããã¯ã®è¨å®ããã£ãã®ã§èª¿ã¹ã¦ã¿ãã ã¢ã«ã¦ã³ãã¬ãã«ã®ã¢ã¯ã»ã¹ãããã¯ã¨ã¯ Amazon S3 ã®ãããªãã¯ã¢ã¯ã»ã¹ãããã¯ã¯ãAmazon S3 ã®ãªã½ã¼â¦