GMO Research Tech Conference 2023 ã§çºè¡¨ãã¾ããã
Amazon Aurora âï¸ ã¯ããã« æ¬ãã¼ã¸ã¯ãAWS ã«é¢ããå人ã®åå¼·ããã³åå¼·ä¼ã§ä½¿ç¨ãããã¨ãç®çã«ãAWS ããã¥ã¡ã³ããªã©ãåç §ãä½æãã¦ããã¾ãããè¨è¼ã®èª¤ãçãå«ã¾ããå ´åããããã¾ãã ææ°ã®æ å ±ã«ã¤ãã¦ã¯ãAWS å ¬å¼ããã¥ã¡ã³ãããåç §ãã ããã ð Contents Aurora ã«ã¤ãã¦ç¥ãã«ã¯ Aurora ã«ã¤ãã¦ç¥ãã«ã¯(ãã®ä») Amazon Aurora ã¨ã¯ ãµãã¼ãããã¦ãããã¼ã¿ãã¼ã¹ã¨ã³ã¸ã³ Aurora ã®åºæ¬çãªæ§æ SLA å¯ç¨æ§ åä¸æ§æ ã¬ããªã«æ§æ ã¬ããªã«ã®ææ ¼ ã¤ã³ã¹ã¿ã³ã¹ã¿ã¤ã ã¹ã±ã¼ã«ã¢ãã/ãã¦ã³ ã¹ãã¬ã¼ã¸ã®èªåã¹ã±ã¼ãªã³ã° Aurora ã®ãã° Serverless Global Database Blue/Green Deployments(New: 2022-11-27) ð ã¾ã¨ã Aurora ã«ã¤ã
ãã2度ã¨ã°ã°ããããªã ããã«ã¡ã¯ï¼AWSäºæ¥æ¬é¨ã®ãã¤ã¾ã¿ã§ãã çãããVPCã¨ã³ããã¤ã³ãã¨AWS PrivateLinkã®éãããèªåã®è¨èã§èª¬æã§ãã¾ããï¼ç§ã¯ææãè¨æ¶åªå¤±ã«ãªãéããå¿ãã¦ãã¾ãã¾ãã ãã2度ã¨ã°ã°ããããªãã¨ããæãããããä»åã¯éããã¾ã¨ãã¾ããã å®éã«ãã³ãºãªã³ã§ããããåå¿è åãã®å 容ã¨ãªã£ã¦ãããããVPCã¨ã³ããã¤ã³ããPrivateLinkã®ç¥èãå ¨ããªãæ¹ã®ãå½¹ã«ç«ã¦ãã°ã¨æãã¾ãï¼ çµè« VPCã¨ã³ããã¤ã³ã VPCã¨ä»ãµã¼ãã¹éã§ãã©ã¤ãã¼ããªæ¥ç¶ãæä¾ããã³ã³ãã¼ãã³ã ãµã¼ãã¹å©ç¨å´ã®VPCå ã§ä½æ AWS PrivateLink ãã©ã¤ãã¼ãæ¥ç¶ãä»ãããµã¼ãã¹ãæä¾ããããã®ãµã¼ã㹠以ä¸ã®2ã¤ãã»ããã¨ãªããAWS PrivateLinkãæä¾ããã¦ããã - VPCã¨ã³ããã¤ã³ãï¼ãµã¼ãã¹å©ç¨å´ã®VPCå ã§ä½æï¼ - VP
ã¯ããã« IAMã®PassRoleã使ã£ããã¨ããã¾ããï¼ä½ããªãã ãããããªãæ¹ãããã®ååããã ãããæ³åã§ããã¨æãã¾ãã IAMã®PassRoleã¨ã¯ãã®åã®ã¨ããIAMãã¼ã«ããã¹(Pass)ãããã¨ã§ãããã ãããã®ãã¹ã®å¯¾è±¡ã¯äººã§ã¯ãªãAWSã®ãµã¼ãã¹ã§ãã PassRoleã«ãã£ã¦èªè¨¼æ å ±ãã»ãã¥ã¢ã«AWSãµã¼ãã¹ã«æ¸¡ããã¨ãã§ãã¾ãããä¸æ¹ã§ä¸å¯§ã«ä½¿ç¨ããªãã¨ã»ãã¥ãªãã£ãªã¹ã¯ã«ç¹ãã£ã¦ãã¾ãã¾ããæ¬è¨äºã§ã¯ãããªIAMã®ãã¹ãã¼ã«ã¨ã»ãã¥ãªãã£ã«ã¤ãã¦è§£èª¬ãããã¨æãã¾ãã IAMã®PassRoleã¨ã¯ IAMã®PassRoleã¯ãIAMããªã·ã¼ã®è¨è¿°ã®ä¸ã§ iam:PassRole ã¨è¡¨ç¾ããã¢ã¯ã»ã¹è¨±å¯ã§ãããã㯠ããªã·ã¼ãã¢ã¿ããããã¦ããããªã³ã·ãã«(IAMã¦ã¼ã¶ã¨IAMãã¼ã«) ãã AWSã®ãµã¼ãã¹(EC2ãLambdaãªã©) ã«ãã¼ã«ã渡ããã¨ãæå³ãã¦
Amazon Web Services(AWS)ã§ã¯CloudWatchã§ãã¾ãã¾ãªç£è¦ããããã¨ãã§ãã¾ãããã®è¨äºã§ã¯CloudWatchã§S3ãç£è¦ããæé ã詳ããç´¹ä»ãã¾ããã¾ããç¡æãã¤ç°¡åã«S3ãã¯ããã¨ããAWSã®ç£è¦ãå§ããæ¹æ³ãç´¹ä»ãã¾ãã®ã§åèã«ãã¦ã¿ã¦ãã ããã S3ãç£è¦ããçç± AWSã®S3ã¯ããã¾ãã¾ãªãã¼ã¿ãä¿åã§ãããªãã¸ã§ã¯ãã¹ãã¬ã¼ã¸ãµã¼ãã¹ã§ããã¦ã§ããµã¤ããã¢ãã¤ã«ã¢ããªã±ã¼ã·ã§ã³ãããã¯ã¢ããããã°ã®ä¿ç®¡ãIoT ããã¤ã¹ãããã°ãã¼ã¿åæãªã©ã®æ§ã ãªç¨éã«ä½¿ããã¨ãã§ãã¾ãã S3ã¯å®¹éã使ã£ãåã ãæéããããå¾é課éå¶ã§ãåºæ¬çã«å®¹éç¡å¶éã§å©ç¨ã§ãã¾ããããããå®ä¾¡ã ããã¨ãã£ã¦ãã¼ã¿ãå ¥ããã¾ã¾æ¾ã£ã¦ãããããééã£ãè¨å®ããã¦ããã¨æå³ããæéãããã£ã¦ãã¾ãã¾ãã ã¾ããS3ã¸ã®æ£å¸¸ãªã¢ã¯ã»ã¹ç¶æ ãç£è¦ããç°å¸¸ãããã°æ©æçºè¦ãã¦èª¿æ»
å ¨ã¦ã®ã¦ã¼ã¶ã¼ã¯ããã©ã«ã㧠Public ãã¼ã«ã«å±ãã¦ãã¾ãã Â¥l ãã¼ã¿ãã¼ã¹ã®ä¸è¦§ ãxx00ããxy00ããèªåã§ä½æãããã¼ã¿ãã¼ã¹ã§ããããã㯠Public ãã¼ã«ã«ããã¢ã¯ã»ã¹ãå¶éãã¦ãã¾ãã masterdb=> \l ãã¼ã¿ãã¼ã¹ä¸è¦§ åå | ææè | ã¨ã³ã³ã¼ãã£ã³ã° | ç §åé åº | Ctype(å¤ææ¼ç®å) | ã¢ã¯ã»ã¹æ¨©é -----------+------------+------------------+-------------+-------------------+--------------------------- masterdb | masteruser | UTF8 | en_US.UTF-8 | en_US.UTF-8 | masteruser=CTc/masteruser postgres | masteruser | UTF
ã³ã³ãã³ããåèï¼å¹¸ï¼ã§ãã KMS åãã® VPC ã¨ã³ããã¤ã³ãï¼ã¤ã³ã¿ãã§ã¼ã¹ï¼ãã¨ã³ããã¤ã³ãããªã·ã¼ã®è¨å®ã«å¯¾å¿ãã¾ããï¼ AWS Key Management Service (AWS KMS) now supports VPC Endpoint Policies ããç´°ããã¢ã¯ã»ã¹å¶å¾¡ãè¡ããã¨ãã§ããããã«ãªãã¾ãããï¼ï¼ã§ããã®åãå ¨ä½ã®è¨è¨ã¯ããããããªããï¼ï¼ ç®æ¬¡ VPC ã¨ã³ããã¤ã³ãã¨ã¯ ã²ã¼ãã¦ã§ã¤åã®å ´å ã¤ã³ã¿ãã§ã¼ã¹åã®å ´å VPC ã¨ã³ããã¤ã³ãããªã·ã¼ ã¨ã¯ ããã¥ã¡ã³ãã確èªãã¦ã¿ã ãã¿ã¼ã³1. ç¹å®ã®ã¦ã¼ã¶ã¼ãç¹å®ã®ãã¼ã«å¯¾ãã¦ç¹å®ã®ã¢ã¯ã·ã§ã³ãå¯è½ ãã¿ã¼ã³2. å¤é¨ã¢ã«ã¦ã³ãã®ããªã³ã·ãã«ã«ããã¢ã¯ã·ã§ã³ãæå¦ ãã£ã¦ã¿ã ã«ã¹ã¿ãã¼ç®¡ç CMK ã®æºå VPC ã¨ã³ããã¤ã³ãããªã·ã¼ãè¨å®ããªãã§è©¦ãã¦ã¿ã VPC ã¨ã³ããã¤ã³ãããªã·ã¼
ããã«ã¡ã¯ãå¹³éã§ãã å æ¥å©ç¨å¯è½ã¨ãªãã¾ãããData API for Redshiftï¼ä»¥ä¸DataAPIï¼ã ã¿ãªãã使ãããªãã¦ããã£ãããã§ããããï¼ [ã¢ãããã¼ã] API ã§éåæ㪠SQL ã¯ã¨ãªãå®è¡ã§ããï¼Amazon Redshift 㧠Data API ãå©ç¨å¯è½ã«ãªãã¾ãã ä»åLambdaé¢æ°ããDataAPIãå©ç¨ããæ©ä¼ããããææ¦ãã¦ã¿ã¾ããã ã¡ãã£ã¨ããã£ããã¤ã³ããããã¤ã¤ããã¾ãã¯ã¨ãªãæµããã¨ãã§ããã®ã§æµãããç´¹ä»ãã¾ãã æ¤è¨¼ç¨Redshift ã¾ãã¯æ¤è¨¼ç¨ã«Redshiftãæ°ããç«ã¦ã¾ããã ãã¼ãã¿ã¤ãã¯dc2.largeã§ããä¸é¨ã®ãã¼ãã¿ã¤ãã§ã¯DataAPIã«é対å¿ãªã®ã§ã注æãå¿ è¦ã§ãã DataAPIã§ã¯ãAWSã®IAMã«ããèªè¨¼ã§ã¯ã©ã¹ã¿ã«ã¯ã¨ãªãæããããã¨ããã®ãã¦ãªãªã®ã§ã åºæ¥ãã ãå¤ããã¯æ¥ç¶ã§ããªãå ´æã«ã¯
åãã« Aurora ã使ãæ©ä¼ããã£ãã®ã§èªåãªãã«è§¦ã£ã¦ã¿ããã¨ã®ã¡ã¢ã§ãã ãã¼ã¿ãã¼ã¹ã®ä½æ ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ããããã¼ã¿ãã¼ã¹ã®ä½æããã¯ãªãã¯ããä½ææ¹æ³ã¨ã¨ã³ã¸ã³ã®ã¿ã¤ããé¸æãã¾ããã¨ãã£ã·ã§ã³ã¯ PostgreSQL äºæãé¸æãã¾ãã ã¨ã³ã¸ã³ãã¼ã¸ã§ã³ã¯ææ°ã® 13.6 ãé¸æãã¾ããæ¤è¨¼ç¨ãªã®ã§ãã³ãã¬ã¼ãã¯ãéçº/ãã¹ãããé¸æãã¾ãã 以ä¸ãå¿ è¦ãªæ å ±ãå ¥åãã¾ããèªè¨¼æ å ±ã¯ãã°ã¤ã³æã«å¿ è¦ã«ãªãã¾ãã æ¤è¨¼ç¨ã®ãããæ±ç¨ã®å°ããã¤ã³ã¹ã¿ã³ã¹ã¿ã¤ããé¸æãã¾ãã VPC ãªã©ã¯é©åãªãã®ãé¸æãã¾ãã 以ä¸ã¯ããã©ã«ãã®ã¾ã¾é²ãã¾ãã ãã¼ã¿ãã¼ã¹åã¯ããã©ã«ãã§ä½æããããã¼ã¿ãã¼ã¹ã§ãã空æ¬ã«ããã¨ä½æããã¾ããããã°ã¤ã³å¾ãæåã§ä½æããã®ã§ç©ºæ¬ã«ãã¾ãã æ¤è¨¼ç¨ãããæå·åã Perfomance Insight ãç¡å¹åãã¦ããã¾ãã ã¡ã³ããã³
åå¼·åã¤ã¡ã¼ã¸ ãã ã§åå¼·ãããããã£ã¦ã¿ãã ãã¹ã¯ã¼ãã¨ããæ ¼ç´ãããããã®ããã ã¾ã AWS Secrets Manager ã¨ã¯ ãµã¼ãã¹ãç°å¢ãã¢ããªã±ã¼ã·ã§ã³ã«æ¥ç¶ããããã®ãã¹ã¯ã¼ããªã©ã®æ©å¯æ å ±ã管çããããã®ãµã¼ãã¹ã§ãã 詳細㯠ãã¡ã ã§è¦ã¦ãã ãã ãã£ãããã£ã¦ã¿ã æ§æ EC2ãç«ã¦ã¦ãRDSã¸æ¥ç¶ããç°¡åãªæ§æã æ¥ç¶æ å ±ã¯Secrets Managerã使ç¨ããã£ã¦æãã§è¨å®ãã¦ããããã¨æãã¾ã EC2 instanceãä½æ ãã¤ãã®ãã¨ãªã®ã§è©³ç´°ã¯çãã¾ããã ãã¡ã ãåèã«ãã¦ããæãã«EC2 instanceä½ã£ã¦ãã ããã 以ä¸ã®ããã«é©å½ã«ã¤ã³ã¹ã¿ã³ã¹ä½ãã¾ããã aws configure ã³ãã³ãã§è¨å®ãçµãããã¾ãã jqã³ãã³ããå¿ è¦ãªã®ã§ãä»ã®ãã¡ã«å ¥ãã¦ããã¦ãã ãã RDSãä½æ ãã¡ããé©å½ã«RDSãä½ãã¾ãã å ¨ç¶éãè¨
AWSã®ã»ãã¥ãªãã£ã°ã«ã¼ãã¨ã¯ãVPCå ã§Amazon EC2ï¼ä»®æ³ãµã¼ãã¼ï¼ãªã©ã®ãªã½ã¼ã¹ã«é©ç¨ã§ããä»®æ³ãã¡ã¤ã¢ã¦ã©ã¼ã«æ©è½ã§ããéä¿¡ã®ã«ã¼ã«ãå®ç¾©ãããã®ã§ãããããAWSç°å¢ãå®å ¨ã«éç¨ããã«ã¯ã»ãã¥ãªãã£ã°ã«ã¼ãã®ç¥èãæ¬ ããã¾ããã ãã®è¨äºã§ã¯ã»ãã¥ãªãã£ã°ã«ã¼ãã®åºæ¬çãªæ©è½ãã«ã¼ã«ããããã¯ã¼ã¯ACLã¨ã®éãããã¹ããã©ã¯ãã£ã¹ã¾ã§è©³ãã解説ãã¾ãã AWSã»ãã¥ãªãã£ã°ã«ã¼ãã¨ã¯ AWSã®ã»ãã¥ãªãã£ã°ã«ã¼ãã¨ã¯ãVPCï¼Amazon Virtual Private Cloudï¼AWSã®ä»®æ³ãããã¯ã¼ã¯ï¼ä¸ã«æ§ç¯ããAmazon EC2ãªã©ã®ãªã½ã¼ã¹ã«å¯¾ãã¦é©ç¨ã§ããä»®æ³ãã¡ã¤ã¢ã¦ã©ã¼ã«æ©è½ã§ãã ã»ãã¥ãªãã£ã°ã«ã¼ãã«é¢é£ä»ãããããªã½ã¼ã¹ã¸ã®ã¤ã³ãã¦ã³ãã»ã¢ã¦ããã¦ã³ãã®ãã©ãã£ãã¯ãå¶å¾¡ã§ãã¾ããã¤ã³ãã¦ã³ãã¨ã¯å¤é¨ããEC2ã¤ã³ã¹ã¿ã³ã¹ã¸åããå åãã®éä¿¡ãã¢
ãã¡ãã®è¨äºã§ã¯ãAWS Systems Managerã®ä¸é¨ã®æ©è½ã§ããSession Managerãå©ç¨ãã¦ãEC2ã¤ã³ã¹ã¿ã³ã¹ã¸ãã¼ãã¢ãªãã§ã¢ã¯ã»ã¹ããã¾ã§ã®æ¹æ³ã解説ãã¾ãã ã©ããã¦ã»ãã·ã§ã³ããã¼ã¸ã£ã¼ã§EC2ã¢ã¯ã»ã¹ããã®ãï¼ Session Managerã使ç¨ãããã¨ã§ãã»ãã¥ãªãã£ã°ã«ã¼ãã®SSHæ¥ç¶ç¨ã®22çªãã¼ãã®éæ¾ãå¿ è¦ãªããªããã¢ã¯ã»ã¹å±¥æ´ãCloud Trailã¸ä¿åã§ããããã«ãªããªã©ã®ã¡ãªããããããã»ãã¥ãªãã£é¢ã«ããã¦ããå ç¢ã«éç¨ãããã¨ãå¯è½ã§ãã AWSãå ¬éãã¦ããEC2ã¤ã³ã¹ã¿ã³ã¹ã«ã¢ã¯ã»ã¹ãããã¹ããã©ã¯ãã£ã¹ã¨ãã¦ããSession Managerã«ã¤ãã¦è§¦ãããã¦ãã¾ãã AWSå ¬å¼ AWS Systems Managerã¨ã¯ AWS Systems Managerã¨ã¯ãEC2ãä¸å¿ã¨ããAWSç°å¢ã®éç¨ãããªã³ãã¬ãã¹ç°å¢ã®éç¨
ã¯ããã« AWSãæä¾ãã代表çãªDBãµã¼ãã¹ã«ã¯ãã¯ã©ã¦ãåæã§è¨è¨ãããRDBã®Amazon Auroraã ãã¼ã¿åæç¹ååRDBã®Amazon Redshiftãã¯ã¤ãã«ã©ã åDB(NoSQL)ã®Amazon DynamoDB1ãããã¾ããAWSã®åDBãµã¼ãã¹ã®ä½¿ãåãã«ã¤ãã¦ã¯ãä¸è¬çã«ã¯æ¦ãæ¥åç³»ã·ã¹ãã ã®DBã«ã¯AuroraãDynamoDBãåæç³»ã·ã¹ãã ã®DBã«ã¯Redshiftãå©ç¨ããã°è¯ãã¨ããã¦ãã¾ãã2ããã®æ ¹æ ã«ã¤ãã¦å®éçã«ç¢ºããã¦ã¿ããã¨æã£ãã®ã§ãå®éã«OLTP/OLAPã¯ã¼ã¯ãã¼ãå¥ã®è² è·ãããã¦åDBãµã¼ãã¹ã®æ§è½ç¹æ§ã®éãã«ã¤ãã¦ç¢ºèªãã¦ã¿ã¾ããã â»å®éã®ã·ã¹ãã æ§è½ã¯æ§ã ãªæ¡ä»¶ã«ããå¤åãã¾ããããã¾ã§ãåèæ å ±ã®ä¸ã¤ã¨ãã¦æãã¦ããã ãã¾ããããé¡ããã¾ãã åæç¥è ã¾ãåæã¨ãªãèãæ¹ã¨ãã¦ãOLTP/OLAPã¯ã¼ã¯ãã¼ãã«ã¤ãã¦æ¦èª¬ã
2015/2/23ããæ¸ãè¾¼ã¿å¾ã®èªã¿è¾¼ã¿ãæ´åæ§ã«ã¤ãã¦æ´æ°ãã¾ããã Amazon S3 ã®ä½¿ãã©ãã ååã®è¨äºã§ã¯ãAmazon S3 ã§ãã¼ã ãã¼ã¸ãä½ããã¨ããè¨äºãæ¸ãã¾ãããããããªããã¡ã¤ã«ã®ã¹ãã¼ã¿ã¹ã使ã£ã¦ãã©ã³ã¶ã¯ã·ã§ã³å¦çã«ã使ããã®ã§ã¯ï¼ã¨æãæ¹ãï¼ï¼ï¼äººä¸ï¼äººãããããã£ãããã®ã§ã¯ãªãã§ããããã çãããè¨ãã¾ãã¨ãAmazon S3 ã§ã¯ãã©ã³ã¶ã¯ã·ã§ã³ã®å¶å¾¡ã¯ã§ãã¾ããããã©ã³ã¶ã¯ã·ã§ã³ãå®ç¾ããããã«ã¯ãSimpleDBã使ãå¿ è¦ãããã¾ããï¼æ£ç¢ºã«ã¯ãSimpleDBã§ããã¢ã¼ãã«è¨å®ããï¼ ããã§ã¯ãAmazon S3 ã¯ã©ã®ãããªèãæ¹ã§ã¤ã³ã¿ã¼ãããã¹ãã¬ã¼ã¸ãå®ç¾ãã¦ããã®ã解説ãã¾ãã èªã¿åãä¸è²«æ§ Amazon S3 ã®ç¹æ§ãç解ããããã«ãèªã¿åãä¸è²«æ§ã«ã¤ãã¦ãç´¹ä»ãã¾ããèªã¿åãä¸è²«æ§ã¯ããã¼ã¿ãã¼ã¹ã®ãã©ã³ã¶ã¯ã·ã§ã³ç®¡çãè¡ã
å°ã£ã¦ããå 容 AWS ã®ã¢ã«ã¦ã³ãå ã§ãè¤æ°ã®ãµã¼ãã¹ï¼EC2ãRDSãS3çï¼ãè¤æ°ãªã¼ã¸ã§ã³ã«ã¾ããã£ããªã½ã¼ã¹ã®ä¸ãããç¹å®ã®ã¿ã°ãè¨å®ããããªã½ã¼ã¹ã®ä¸è¦§ãåå¾ããããã©ãããã°ããã§ããï¼ ã©ã対å¿ããã°ããã®ï¼ ãã¿ã°ã¨ãã£ã¿ã¼ï¼Tag Editorï¼ããå©ç¨ãã¦ãç¹å®ã®ã¿ã°ãä»ãããªã½ã¼ã¹ãæ¤ç´¢ã§ãã¾ãã ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã§ã®æä½ ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã«ãã°ã¤ã³ããResource Groups & Tag Editorãã®ã³ã³ã½ã¼ã«ç»é¢ãéãã¾ãã å·¦å´ã¡ãã¥ã¼ã®ãTag Editorãã¸ç§»åããæ¤ç´¢ããããªã½ã¼ã¹ã®æ¡ä»¶ãå ¥åãã¦ããªã½ã¼ã¹ãæ¤ç´¢ããã¯ãªãã¯ãã¾ãã ä»åã¯ä¾ã¨ãã¦ãã¿ã°ãã¼ï¼Envionment ã¿ã°å¤ï¼Productionããä»ä¸ããããªã½ã¼ã¹ããå ¨ãªã¼ã¸ã§ã³ã»å ¨AWSãµã¼ãã¹ã横æãã¦æ¤ç´¢ãããããã以ä¸ã®ããã«å ¥åãã¾ããã 該å½ãããªã½ã¼
ã©ãããå°æã§ãã 3度ç®ã®æ稿ã«ãã¦åãã¦æè¡çãªãã¨ãæ¸ããã¨ãã¦ãã¾ãã 以åæ¸ããAWSèªå® ã»ãã¥ãªãã£ã®å¯¾çæ¬ã«ã¦è¸ã¿å°ãµã¼ãæ§æã®è©±ãæ¸ãã¾ããã ãã¤ã³ã¿ã¼ãããã«å ¬éããEC2ã¤ã³ã¹ã¿ã³ã¹ã®æ°ã¯æå°ã«ãããããã¨ããã話ã ã£ããã§ããã ä»ã¯SSMï¼AWS Systems Managerï¼ã®Session Managerã使ãã°è¸ã¿å°ãµã¼ãããªãã¨ã ç´æ¥ãã©ã¤ãã¼ããµããããå«ãåã¤ã³ã¹ã¿ã³ã¹ã®ã·ã§ã«ç°å¢ã使ããããã«ãªã£ã¦ãã¦ãã¾ãã ã¨ãããã¨ã¯è¸ã¿å°ãµã¼ãã¸Session Managerã§æ¥ç¶ããããã«ããã°ãè¸ã¿å°ãµã¼ããã¤ã³ã¿ã¼ãããã«å ¬éããªãã¦è¯ãã®ã§ã¯ï¼ã¨æãã ããããèãã¦ã¿ããã¨ãæ¸ãã¦ããããã¨æãã¾ãã ãªããè¨ç»ã¨æ¤è¨¼ã®è¨é²ã主ãªè©±ã§ãæåã®ç®è«ã¿ã©ããã«ã¯ãªããªãã£ããã¨ããæããã¦ããã¾ãã ãã®å 容ãã©ãªããã®åèã«ãªãã°å¹¸ãã§ãã ã
ç®ç ä»ã¾ã§ã¤ã³ã¹ã¿ã³ã¹ã«æ¥ç¶ããã®ã«ã¬ã¬ã·ã¼ã«Teratermã§sshæ¥ç¶ãã¦ããããå¿ãå ¥ãæ¿ãã¦ãã»ãã¥ã¢ã«Sesson Managerã使ãããã«å¤ãã¦ãããããªã¨æãã使ãæ¹ã確èªããã AWS Systems Manager Session Manager ã¨ã¯ï¼èªåã®çè§£ï¼ AWS Systems Managerã®ä¸ã®ä¸æ©è½ã§ãsshãããã«ãAWSã®æ©è½ã¨ãã¦Linuxã«ã·ã§ã«ã¢ã¯ã»ã¹(Windowsã«ã¯PowerShell)ã§ããã ãã£ãã㨠以ä¸ã®ç°å¢ã®EC2ã¤ã³ã¹ã¿ã³ã¹(Amazon linux 2)ã¸Session Managerãç¨ãã¦æ¥ç¶ã§ãããã¨ã確èªããã ã¤ã³ã¿ã¼ãããæ¥ç¶ãã(IGW/EIP, NatGateway) ã¤ã³ã¿ã¼ãããæ¥ç¶ãªã(VPCã¨ã³ããã¤ã³ã) æ¥ç¶ã®ãã°ãåãããã¨ã確èªããã æ§æå³ äºç¿ å ¬å¼ããã¥ã¡ã³ãçãè¦ã¦ãSessio
ã¯ããã« AWSã®ãããã¯ã¼ã¯å¨ãã®ç¥èããããµããªãã¨ãå¤æãããã復ç¿ãééã£ã¦ãããææãé¡ããã¾ãã VPC AWSå ã®å©ç¨è å°ç¨ã®ä»®æ³ãã©ã¤ãã¼ããããã¯ã¼ã¯ ãªã¼ã¸ã§ã³ã®ä¸ã«ä½æãã CIDRãããã¯ã¯/16ã/28ã®ç¯å²ã§ä½æã§ãã (ä¾ï¼10.0.0.0/16) å¯è½ãªéã大ããªãµã¤ãº(/16)ã§ä½æãã ã¢ãã¬ã¹ä¸è¶³ãé²ããã ãµãããã VPCãããã«å°ããªãããã¯ã¼ã¯ã«åºåã£ãåä½ CIDRãããã¯ã¯/16ã/28ã®ç¯å²ã§ä½æã§ãã VPCãããå°ããªç¯å²ãæå®ãã (ä¾ï¼10.0.1.0/24) ã¤ã³ã¿ã¼ãããã¨éä¿¡ãããµããããï¼ãããªãã¯ãµããããï¼ãéä¿¡ããªããµããããï¼ãã©ã¤ãã¼ããµããããï¼ãªã©ãå½¹å²ã»ã«ã¼ãã£ã³ã°ã«ãã£ã¦åå²ãã åä¸ã®å½¹å²ãæã£ããµããããããªã½ã¼ã¹ç¾¤ãè¤æ°ã®AZã«ä½æãããã¨ã§ãèé害æ§ã®åä¸ã«ç¹ããï¼ãã«ãAZï¼ ã«ã¼ããã¼ãã« ã
ããã«ã¡ã¯ï¼ ã¹ã«ã¤ã¢ã¼ãHRã½ãªã¥ã¼ã·ã§ã³ãºã®Ryojiã§ãã ãã¤ããæ¥åã§IAMã®ã¹ã¤ãããã¼ã«ã使ç¨ãã¦ä½æ¥ãã¦ããã®ã§ããããã®è¨å®ãä¿®æ£ããæ©ä¼ããããå°ã æéåã£ã¦ãã¾ãã¾ããã ããã§ãæ¹ãã¦ã¹ã¤ãããã¼ã«ã¨ã¯ï¼ã¨ããã¨ãããã調ã¹ãªããã¦ã¿ãã®ã§ãæ´çãã¦è¨äºã¨ãã¦ã¾ã¨ãã¦ã¿ããã¨æãã¾ãã ã¹ã¤ãããã¼ã«ã¨ã¯ ã¹ã¤ãããã¼ã«ã¨ã¯ãã¢ã¯ã»ã¹æ¨©éã®åãæ¿ããè¡ããã¨ãã§ãããAWS IAMãæä¾ããæ©è½ã®ä¸ã¤ã§ãã AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã§ã®ã¢ã¯ã»ã¹æ¨©éãããã¦ã¼ã¶ã¼ã¯ãã¹ã¤ãããã¼ã«ã使ç¨ãããã¨ã§ãç°ãªãAWSã¢ã«ã¦ã³ããã¾ãã¯ç°ãªãIAMã¦ã¼ã¶ã¼ã«ã¹ã¤ãããããã¨ãã§ãã¾ãã ããã«ãããè¤æ°ã®AWSã¢ã«ã¦ã³ããIAMã¦ã¼ã¶ã¼ãåãæ¿ãããã¨ãªããç°ãªãã¢ã«ã¦ã³ããã¦ã¼ã¶ã¼ã®æä½ãè¡ããã¨ãã§ããããã«ãªãã¾ãã ã¹ã¤ãããã¼ã«ã®ä½æ ã¹ã¤ãããã¼ã«ã使ç¨ããã«
ã¯ããã« IAMã®ãã¼ã«ä½ææã«èããããä¿¡é ¼ãããã¨ã³ãã£ãã£ãã£ã¦ä½ã¨ãªã£ãã®ã§èª¿ã¹ã¦åãã£ãäºãåå¿é²ã¨ãã¦ãæ®ã ä¿¡é ¼ãããã¨ã³ãã£ãã£ã¨ã¯ IAMã§ä½æãããã¼ã«ã¯ã¦ã¼ã¶ã ãã§ãªããµã¼ãã¹ï¼s3ã¨ãLambdaã¨ãï¼ã«ãä»ä¸ãããã¨ãã§ãããããã®ä»ä¸å¯è½ãªãµã¼ãã¹ãè¨å®ãã¦ããã®ããä¿¡é ¼ãããã¨ã³ãã£ãã£ãã®é¨å ãã®ãä¿¡é ¼ãããã¨ã³ãã£ãã£ãã«ãªããµã¼ãã¹ã«ã¯ãã¼ã«ãã¢ã¿ããã§ããªã å ·ä½çã«è¦ã¦ãã ãã¼ã«ä½æ ãã¼ã«ãIAMã§ä½æããã¨ä»¥ä¸ã®ãããªç»é¢ãåºã¦ããããããã§é¸æãããµã¼ãã¹ããä¿¡é ¼ãããã¨ã³ãã£ãã£ï¼ï¼ä»ä½æä¸ã®ãã¼ã«ãã¢ã¿ããã§ãã対象ã¨ãã¦è¨±å¯ããï¼ãã¨ã¿ãªãããã«ãªã ä½æãããã¼ã«ã®ä¿¡é ¼é¢ä¿ï¼ã©ã®ãµã¼ãã¹ãªããã®ãã¼ã«ãã¢ã¿ããã§ãããï¼ï¼ ãä¿¡é ¼ãããã¨ã³ãã£ãã£ãã®æã«lambda.amazonaws.comã¨æ¸ããã¦ããéããLambdaã§ãã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}