Kyash TechTalk #4 ã®ç»å£è³æã§ãã ç»å£æã®åç»ã¯ YouTube ããé²è¦§ã§ãã¾ãã
Amazon Web Servicesï¼AWSï¼ã¯ãæªæã®ããåä½ãæ¤åºãããAmazon GuardDutyãã®æ°æ©è½ã¨ãã¦ããã«ã¦ã§ã¢ã®æ¤åºæ©è½ã«å¯¾å¿ãããã¨ãã7æ26æ¥ã27æ¥ã«éå¬ããã¤ãã³ããAWS re:Inforce 2022ãã§çºè¡¨ãã¾ããã Amazon GuardDutyã¯ããã¾ã§ãã¯ã¼ã¯ãã¼ããç£è¦ãã¦æªæã®ããåä½ãæ¤åºããæ©è½ãæä¾ãã¦ãã¾ãããæ°ãã«è¿½å ããããã«ã¦ã§ã¢æ¤åºæ©è½ã¯ãEC2ã¤ã³ã¹ã¿ã³ã¹ã¾ãã¯EC2ä¸ã§åä½ããã³ã³ããã¯ã¼ã¯ãã¼ãã®ããããã§çãããåä½ãGuardDutyãæ¤åºããã¨ãã«é¢é£ããAmazon EBSã®ã¹ãããã·ã§ãããã¨ãããã¯ã¼ã¯ãã¼ãã®åä½ãé»å®³ãããã¨ãªãAmazon GuardDutyã«ãããã«ã¦ã§ã¢ã¹ãã£ã³ãéå§ãããããã«ãªã£ã¦ãã¾ãã ã¹ãã£ã³ã®å¯¾è±¡ã¯Windowsããã³Linuxã®å®è¡ãã¡ã¤ã«ãPDFãã¡ã¤ã«ãã¢ã¼
[ç¥ã¢ãããã¼ã]GuardDutyãEC2ãECSã®ãã«ã¦ã§ã¢æ¤ç¥æã®ã¹ãã£ã³ã«å¯¾å¿ããã®ã§å®éã«ã¹ãã£ã³ããã¦ã¿ã #reinforce ç¥æ©è½ãæä¾ããã¾ãããEC2ãã³ã³ããã§ãã«ã¦ã§ã¢ææã®æåãæ¤ç¥ããããGuardDutyããã«ã¦ã§ã¢ã¹ãã£ã³ãå®æ½ã§ããããã«ãªãã¾ãããã¦ã¼ã¶ã¼ãé å¼µããã¨ã1ã¤æ¸ãã¾ãããæ§ããã«è¨ã£ã¦æé«ã§ããã ããã«ã¡ã¯ãè¼ç°ã§ãã ã¿ãªãããAWSã§è å¨æ¤ç¥ãã¦ã¾ããï¼(æ¨æ¶ ç¥æ©è½ããªãªã¼ã¹ããã¾ããï¼ç¾å¨éå¬ããã¦ããAWSã®ã»ãã¥ãªãã£ã«ã³ãã¡ã¬ã³ã¹re:Inforceã«ã¦EC2ãECS/EKSãªã©ã®ã³ã³ããã¯ã¼ã¯ãã¼ãä¸ã§ãã«ã¦ã§ã¢ãæ¤ç¥ããéã«ã¹ãã£ã³ããæ©è½ãçºè¡¨ããã¾ããï¼ New for Amazon GuardDuty â Malware Detection for Amazon EBS Volumes | AWS News Bl
ããã«ã¡ã¯ï¼ã³ã³ãµã«é¨ã®inomaso(@inomasosan)ã§ãã SSMã»ãã·ã§ã³ããã¼ã¸ã£ã¼ã使ç¨ããã°ããã©ã¤ãã¼ããµããããã«ããEC2 Linuxã«ãSSHãªãã§ç°¡åã«æ¥ç¶ãããã¨ãã§ãã¾ãã ãããæ¥åä¸ã®è¦ä»¶ã§ãã¼ã«ã«ç«¯æ«ããEC2ã«ç´æ¥ãã¡ã¤ã«éåä¿¡ãããå ´åãSSHæ¥ç¶ãæ¤è¨ããå¿ è¦ãããã¾ãã SSMã»ãã·ã§ã³ããã¼ã¸ã£ã¼ã§ã¯ãSSHããã§ãæ¥ç¶å¯è½ã§ãã Windows端æ«ã®å ´åã¯OpenSSHã使ç¨ãã¦é ãã®ãä¸çªæåãæ©ãã§ãã ãã ãTera Termãå©ç¨ãããã±ã¼ã¹ããããã¨æãã¾ãã®ã§ãä»åã¯åºæ¬çãªæ¥ç¶æ¹æ³ã試ãã¦ã¿ã¾ããã SSMã»ãã·ã§ã³ããã¼ã¸ã£ã¼ã®æºå 以ä¸ã®ããã°ãåèã«æºåãã¾ããã ä¸è¨ããã°ã¯AWS CLIã®ãã¼ã¸ã§ã³ãå¤ããããææ°ã®ãã¼ã¸ã§ã³2ãã¤ã³ã¹ãã¼ã«ãã¦ãã¾ãã å°ãSSHã®configã¯ä»åã®æ¤è¨¼ã§ã¯è¨å®ä¸è¦ã§ãã ãã
ã¯ããã¾ãã¦ãfreee ã® SRE ãã¼ã ã«æå±ãã¦ãã nkgw ï¼Twitterï¼ ã§ãã æ®æ®µã¯ã¨ã³ã¸ãã¢ãªã³ã°ããã¼ã¸ã£ã¼ããã¤ã¤ãéçºãã¼ã ã®æ°è¦ãããã¯ããªãªã¼ã¹ãµãã¼ãããã£ã¦ãã¾ãã æã ã®ãã¼ã ã¯å¤§é¨åã®ãããã¯ãã®ã³ã³ãã¥ã¼ãã£ã³ã°ãªã½ã¼ã¹ (CPU / Memory ãªã©) ã Amazon Elastic Kubernetes Service (EKS) ã§å®è¡ã§ããããã«ã¤ã³ãã©åºç¤ç§»è¡ (EC2 â EKS) ãé²ãã¦ãã¾ããã 移è¡ããã¸ã§ã¯ãã®å¤§é¨å㯠2021 å¹´ 7 æã«ç¡äºçµãã£ãã®ã§ããã移è¡ã¹ã±ã¸ã¥ã¼ã«ãæåªå ã¨ããããå²ãå½ã¦ã¦ããåãªã½ã¼ã¹ã¯ããªãä¿å®ç & éå°ã§ããã (移è¡å¾ã®æ§è½å£åãæãã£ããããEC2 æ代ã¨æ¯è¼ãã1.5 åã®ãããã¡ãç©ããªã©... etc) ã³ã¹ãå¢å¤§ããã°ã©ã ãã®çµæã å»å¹´ã¨æ¯è¼ãã¦ãã³ã¹ããå以ä¸ã«è·³
CloudWatchã¢ã©ã¼ã è¨å®ç¥ãããéæ¾ããã ããã«ã¡ã¯ãã®ãã(@non____97)ã§ãã çããã¯EC2ã¤ã³ã¹ã¿ã³ã¹ã«è¨å®ããAuto Recoveryã®è¨å®é¢åã ãªã¨æã£ããã¨ã¯ããã¾ãã? ç§ã¯ããã¾ãã Auto Recoveryã¯ç©çãã¹ãã®é»æºããããã¯ã¼ã¯æ¥ç¶åªå¤±ãªã©AWSã®åºç¤ã®åé¡ã§ãEC2ã¤ã³ã¹ã¿ã³ã¹ããã¦ã³ããã¨ãèªåçã«ã¤ã³ã¹ã¿ã³ã¹ã®å¾©æ§ããã¦ãããæ©è½ã§ãã 復æ§ãããEC2ã¤ã³ã¹ã¿ã³ã¹ã¯ã¤ã³ã¹ã¿ã³ã¹IDãIPã¢ãã¬ã¹ããã¹ã¦ã®ã¤ã³ã¹ã¿ã³ã¹ã¡ã¿ãã¼ã¿ãå«ããå ã®ã¤ã³ã¹ã¿ã³ã¹ã¨åããã®ã¨ããåªããã®ã§ãã ããããå¾æ¥ã¯Auto Recoveryãããããã«ã¯ãEC2ã¤ã³ã¹ã¿ã³ã¹æ¯ã«CloudWatchã¢ã©ã¼ã ã§å¾©æ§ã¢ã¯ã·ã§ã³ãå®ç¾©ãã¦ãããå¿ è¦ãããã¾ããã AWS CLIã使ãã°å¤å°ã¯æ¥½ã§ãããEC2ã¤ã³ã¹ã¿ã³ã¹ä¸ã¤ä¸ã¤ã«Auto Recoveryã®è¨
ç®æ¬¡ ã¯ããã« äºåæºå SESå¶éç·©åç³è« SESä½æ EC2ãã¼ã«ã«SESããªã·ã¼ãã¢ã¿ãã ãã¦ã³ã¹ãè¦æ 対ç DMARCè¨å® DNSç»é² ãã°åºåè¨å® åèæ å ± 1.ã¯ããã« çããããã«ã¡ã¯ã奥平ã§ãã ä»åã¯SESç°å¢ãæ§ç¯ãããã¨æãã¾ãã SESç°å¢æ§ç¯ãæ¸ããçç±ã«ã¤ãã¾ãã¦ã¯ã2022å¹´ã«ãªã£ã¦SESã®WEBç»é¢ï¼UIï¼ã大ããå¤æ´ããããè±èªã ããã«ãªã£ã¦ãã¾ããæ§ç¯ãã¥ããã¨æã£ãã®ã§ãã¬ãã¸æ®ãã¨ãã¦è¨äºã«ãã¾ããã â»ä»åã¯SESæ§ç¯ãä¸å¿ã¨ãã¾ãã®ã§ãIAMãã¼ã«ä½æãSNSä½æããã®ä»ãªã½ã¼ã¹ä½æã«ã¤ãã¾ãã¦ã¯çç¥è´ãã¾ãã â»æ¬å½ã¯CLIçã§æ§ç¯åºæ¥ãããã«ãªã£ãæ¹ãè¯ãã®ã§ãããããã¯ã¾ãã®æ©ä¼ã«è´ãã¾ãã 2.äºåæºå ãã¹ãç¨DNSãµã¼ãã¹ãRoute53ã«ç»é²ãã¦ããã¦ãã ããã ä»åã¯ä¸è¨ãã¹ãç¨ãã¡ã¤ã³ãç¨æãã¾ããã SESãã¹ãç¨ãã¡ã¤ã³ï¼
[ã¢ãããã¼ã]GuardDutyãçã¾ããEC2ã®ã¯ã¬ãã³ã·ã£ã«ãå¥AWSã¢ã«ã¦ã³ãã§å©ç¨ããããã¨ãæ¤ç¥ã§ããããã«ãªã£ãã®ã§å®éã«è©¦ãã¦ã¤ãã§ã«Detectiveã§èª¿æ»ãã¦ã¿ã GuardDutyãEC2ããæ¾åãããã¯ã¬ãã³ã·ã£ã«ãå¥AWSã¢ã«ã¦ã³ãã§å©ç¨ãã¦ãæ¤ç¥ãã¦ãããããã«ãªãã¾ãããå®éã«ã¤ã³ã·ãã³ããçºçããå ´åã®å¯¾å¦æ¹æ³ãåããã¦è§£èª¬ãã¦ãã¾ãã ããã«ã¡ã¯ãè¼ç°ã§ãã ã¿ãªãããGuardDuty使ã£ã¦ã¾ããï¼(æ¨æ¶ ä»æ¥ã¯ç´ æ´ãããã¢ãããã¼ããæ¥ã¾ãããEC2ããæ¾åãããã¯ã¬ãã³ã·ã£ã«ãå¥AWSã¢ã«ã¦ã³ãã§å©ç¨ãããã¨ãã«Amazon GuardDutyã§æ¤ç¥ãããã¨ãåºæ¥ãããã«ãªãã¾ããï¼ Amazon GuardDuty now detects EC2 instance credentials used from another AWS account
ããã«ã¡ã¯ãè¼ç°ã§ãã ã¿ãªãããAWSã®ææ°æ å ±ã¯ãã£ããã¢ããã§ãã¦ãã¾ããï¼(æ¨æ¶ 社å ã§è¡ã£ã¦ããAWSãã¬ã³ããã§ãã¯åå¼·ä¼ã®è³æãããã°ã«ãã¾ããã AWSãã¬ã³ããã§ãã¯åå¼·ä¼ã¨ã¯ããæ¥ã ããããåºãAWSã®ææ°æ å ±ã¨ããããã°ã§ãã£ããã¢ãããã¦ãã¿ããªã§ãã¬ã³ãã£ã«ãªãããããã¼ãã«å®æ½ãã¦ãã社å åå¼·ä¼ã§ãã ãã®ããã°ãµã¤ãã§ããDevelopersIOã«ã¯æ¥ã ããã¨ããããããã°ãæ稿ããã¾ããããã®ä¸ã§ãAWSã®ã¢ãããã¼ããä¸å¿ã«ç§ã®ç¬æã¨åè¦ã§é¢ç½ãã¨æã£ããã®(ãã¨èªåã®ããã°ã®å®£ä¼)ãããã¯ã¢ãããã¦ãã ãããæ1ã§ç°¡åã«ç´¹ä»ãã¦ãã¾ãã 12æã¯re:Invent 2021ãå æããç¶ãã¦ãã¦ãã¡ããã¡ãè¨äºãããã¾ããã¨ããããã§ä»å¹´ã2åã«åå²ãã¾ãã ã¡ãªã¿ã«AWSã®ææ°æ å ±ããã£ããã¢ããããã ããªãé±åAWSãããããã§ãããDeveloper
ããã«ã¡ã¯ããµã¼ãã¹ã°ã«ã¼ãã®æ¦ç°ã§ãããã®ã¨ã³ããªã¯ã2018å¹´ããå ¬éãã¦ããAWSå ¨ãµã¼ãã¹ã¾ã¨ãã®2022å¹´çã§ãã ããã«ã¡ã¯ããµã¼ãã¹ã°ã«ã¼ãã®æ¦ç°ã§ãã ãã®ã¨ã³ããªã¯ã2018å¹´ããæ¯å¹´å ¬éãã¦ãã AWSå ¨ãµã¼ãã¹ã¾ã¨ãã®2022å¹´ç ã§ããæ¨å¹´ã¾ã§ã®ãã®ã¯æ¬¡ã®ãªã³ã¯ãããã©ã£ã¦ãã ããã AWSã«ã¯ããããã®ãµã¼ãã¹ãããã¾ããããçµå±ãã®ãµã¼ãã¹ã£ã¦ãªããªã®ï¼ãã¨ããçåãèªåãªãã«ç解ããããã«ã¾ã¨ãã¾ããã ä»åãããã¸ã¡ã³ãã³ã³ã½ã¼ã«ãéããããµã¼ãã¹ãã®ä¸è¦§ããã¨ã«ä¸è¦§åãã¾ããããã®ããããã¬ãã¥ã¼çãªã©ä¸è¦§ã«è¼ã£ã¦ããªããµã¼ãã¹ã¯å«ã¾ãã¦ãã¾ãããã¾ã2021å¹´ã«ã¾ã¨ãããã®ã®ã¢ãããã¼ãçã¨ãããã¨ã§ãæ°ããã«ãã´ãªã«è¿½å ããããµã¼ãã¹ã«ã¯[New]ãæç« ãæ´æ°ãããã®ã«ã¯[Update]ãä»ãã¾ãããã¡ãªã¿ã«ãµã¼ãã¹æ°ã¯ 223å ã§ãã ã¾ã¨ããã«ã
SREãã¼ã ã®å®é(@adachin0817)ã§ããä»åWordPressãµã¼ãã¼ã§ããEC2ããECS/Fargateã«ç§»è¡ãã¾ããããç´ä½æ²æãå¾ã¦ãè¦å´ããã¨ãããæè¡çãªé¨åãæçµçã«ã¯è¤æ°ã®ãªãã¸ããªãä¸ã¤ã«ã¾ã¨ãããã¨ãªã©ãç´¹ä»ãããã¨æãã¾ããã¾ãã¯ããã¸ã§ã¯ãã¨ãµã¼ãã¼ã®æ§æãã説æãã¦ããã¾ãããã ã©ã³ãµã¼ãºã®WordPressã¨ECSæ代ã®ãµã¼ãã¼æ§æ https://engineer.blog.lancers.jp https://info.lancers.jp https://l-ap.jp https://connect.lohai.jp https://lohai.jp https://tips.lancers.jp https://www.lancers.co.jp https://www.lancers.jp/assistant/cases https:/
Steven J. Vaughan-Nichols ï¼ZDNET.comï¼Â ç¿»è¨³æ ¡æ£ï¼Â ç·¨éé¨ 2021-11-25 11:55 ãããªãã¯ã¯ã©ã¦ãã®ã»ã¨ãã©ã§ã¯Linuxã稼åãã¦ããã¨è¨ã£ã¦ããã ããããMicrosoft Azureãã®é¡§å®¢ãå«ããã»ã¨ãã©ã®ã¦ã¼ã¶ã¼ã¯ã¯ã©ã¦ãã§Linuxãå®è¡ãã¦ããã Amazon Web Servicesï¼AWSï¼ã®å ´åãã¦ã¼ã¶ã¼ã¯ãã¾ãã¾ãªLinuxãã£ã¹ããªãã¥ã¼ã·ã§ã³ã ãã§ãªããAWSãç¬èªã«éçºãããAmazon Linux 2ãï¼AL2ï¼ãé¸æã§ãããããã¦å社ã¯ç±³å½æé11æ22æ¥ã次æãã£ã¹ããªãã¥ã¼ã·ã§ã³ãAmazon Linux 2022ãï¼AL2022ï¼ã®ãã¬ãã¥ã¼çããªãªã¼ã¹ããã¨çºè¡¨ãããRed Hatãæ¯æ´ããã³ãã¥ããã£ã¼LinuxãFedoraãããã¼ã¹ã«ãªã£ã¦ããã AWSã¯ä»¥åããããAmazon Linuxãã«
ããã«ã¡ã¯ãCXäºæ¥æ¬é¨MADäºæ¥é¨ã®ããããã¼(@joe_king_sh)ã§ãã AWSã§ã¤ã³ãã©ãæ§ç¯ããéã«å¿ ãæ¸ããã®ã AWSæ§æå³ çããã¯ã©ããã£ã¦æãã¦ãã¾ããï¼ åããããã£ã¡ã決ãã¦ä½ããã¨ãããã°ã試è¡é¯èª¤ããå¾ãæå¾ã«æ®ãããã¥ã¡ã³ãã¨ãã¦æãããããã§ãããã¨ãªããªãã¹ã楽ãã¦ä½æãããã§ãããã ããã§ä»åã¯ãCDKã§æ§ç¯ããAWSç°å¢ã®æ§æå³ãèªåçæãããã¼ã«ãCDK-Diaãããå®éã©ãããã使ããã®ãæ¤è¨¼ãã¦ã¿ã¾ããã CDK-Diaã®ä½¿ãæ¹ ç°å¢ macOS Big Sur 11.5.1 node v14.17.6 cdk 1.131.0 cdk-dia 0.3.0 ã¤ã³ã¹ãã¼ã« CDK-Diaã¨æ§æå³ã®æåã«ä½¿ç¨ããGraphvizãã¤ã³ã¹ãã¼ã«ãã¾ãã $ npm install cdk-dia $ brew install graphviz 使ã
é¢é£ãã¼ã¯ã¼ã Amazon Web Services | Oracleï¼ãªã©ã¯ã«ï¼ | å¯å£«é | IaaS IaaSï¼Infrastructure as a Serviceï¼ã«é¢ããã¹ãã«ã身ã«ä»ãããã¨æã£ãããã¯ã©ã¦ããã³ãã¼ã®ç¡æãµã¼ãã¹ãå©ç¨ããã®ãä¸ã¤ã®æã ãã¯ã©ã¦ããµã¼ãã¹ã®èªå®è©¦é¨ãå¦ç¿ææã®ç¡ææä¾éå§ãã¯ã©ã¦ããµã¼ãã¹å°å ¥äºä¾ãªã©ãã¯ã©ã¦ãã«é¢ãã主è¦ãªãã¥ã¼ã¹ã6ã¤ç´¹ä»ããã ä½µãã¦èªã¿ãããè¦ãè¨äº OCIã«ã¤ãã¦è©³ãã Oracleãã1ã³ã¢1æé1ã»ã³ããã®Armã¤ã³ã¹ã¿ã³ã¹æä¾éå§ å¸¸ã«ç¡æã®OCIãAlways Freeãã®åºç¤ãä½ã使ããï¼ãAWSç¡æãã©ã³ã¨ã®éãã¯ï¼ AWSã§ã¯ãªããAzureããGCPããIBM CloudããOCIããé¸ã³ãããªãå¼·ã¿ã¨ã¯ï¼ ç¦äºéè¡ã顧客æ å ±ç®¡çã·ã¹ãã ãã¯ã©ã¦ã移è¡ããã®çç±ã¨ã¯ ãªã³ãã¬ãã¹ã¤ã³ãã©ã§ç¨¼åãã
æå°æ¨©éã®IAM Policyãä½æããã®ã£ã¦å°å³ã«é¢åã§ãããã以åç§ã¯ãRoute53ãã¹ãã¾ã¼ã³ã«DNSã¬ã³ã¼ãä½æããã®ã«å¿ è¦ãªæå°æ¨©éã®Policyãä½ãããã権éã¼ãã®ç¶æ ããå§ãã¦ã権éä¸è¶³ã¨ã©ã¼ãåºããã³ã«æ¨©éã足ãã¦ããã¨ããåæã§Policyãä½ã£ããã¨ãããã¾ãã Route53ãã¹ãã¾ã¼ã³ã«DNSã¬ã³ã¼ããTerraformã§ä½æããã®ã«å¿ è¦ãªæå°æ¨©é | DevelopersIO ããã¡ãã£ã¨ã¹ãã¼ããªããæ¹ããCloudFormation(CFn)ã®ã³ãã³ãã使ãã¨ã§ããå ´åããããã¨ãå¦ãã ã®ã§ã¬ãã¼ããã¾ãã aws cloudformation describe-type ãã®ã³ãã³ããã aws cloudformation describe-typeã§ãã--typeãªãã·ã§ã³ã§RESOURCEãæå®ãã¦ã --type-nameã§CFnã®ãªã½ã¼ã¹ã¿ã¤
ã¯ã©ã¦ãã®éç¨è ã«ç¦ç¹ãå½ã¦ããæè¡è åãã®æ°ããããã¯ã¤ãã³ããCloud Operator Days Tokyo ããããã§æ ªå¼ä¼ç¤¾ã«ãµã¬ã¢ã«ã®æ°æ´¥æ°ãããããã£ãã®èª°ï¼ãããã¼ãã«ç»å£ãèªååãããªãã¬ã¼ã·ã§ã³ã«å¯¾ãã¦çããçåã¨å¦ã³ã«ã¤ãã¦ç´¹ä»ãã¾ãã èªå·±ç´¹ä»ã¨ä»åã®ãã¼ã æ°æ´¥ä½å æ°ï¼ä»¥ä¸ãæ°æ´¥ï¼ï¼ã¿ãªãããããã«ã¡ã¯ãæ ªå¼ä¼ç¤¾ã«ãµã¬ã¢ã«ã®æ°æ´¥ä½å ã¨è¨ãã¾ããæ¬æ¥ã¯ããããã£ãã®èª°ï¼ãã¨ããã¿ã¤ãã«ã®ã話ããã¾ãã ããããã£ãã®èª°ï¼ãã«ã¤ãã¦ã§ãããDevOpsã¨åããã¦èªååãé²ãã¦ããä¸ã§ãèªååãããªãã¬ã¼ã·ã§ã³ã«å¯¾ãã¦ãçãããã®çåã«ãå®æ¥åã®ä¸ã§ããããã¦åãåã£ã¦ã¿ã¾ãããä¸è¨äºä¾ã®è©³ç´°ã¨ç¾æç¹ã§ã®æã ã®çããç´¹ä»ãã¾ãã ã¾ãæ¬æ¥ã話ãããå 容ã§ãããã¹ã©ã¤ãã«æ¸ããã¦ãããããªåºç¤ã®éç¨æ å½è ã®ã¦ã¼ã¹ã±ã¼ã¹ã«é¢ããã話ã«ãªãã¾ããã©ã®ãããªã¦ã¼ã¹ã±ã¼ã¹ãã¨ã
ã³ã³ãã³ããåèï¼å¹¸ï¼ã§ãã ãªã¶ã¼ããã¤ã³ã¹ã¿ã³ã¹ï¼ä»¥ä¸ãRIãï¼ã¨ Savings Plans ï¼ä»¥ä¸ãSPãï¼ã¯ãã©ã¡ããä¸å®æéã®ä½¿ç¨ãã³ããããããã¨ã§ãã£ã¹ã«ã¦ã³ããåããããä»çµã¿ã§ãã 両è ã§å ±éããç¹ãããã°ãç°ãªãç¹ãããã¾ããã©ã¡ããé¸æããã¹ããè¿·ãæ©ä¼ãå¤ãã®ã§ã¯ãªãã§ããããã両è ã®ç¹æ§ãç解ãæé©ãªé¸æãããããã«ãæ¯è¼è¡¨ãä½æãã¦ã¿ã¾ããã®ã§ãã²ãåèãã ããã ãªããRI ããã³ SP ã®å¯¾è±¡ã¨ãªã AWS ãµã¼ãã¹ã¯ããã¤ãããã¾ãããä»å㯠Amazon EC2 ã対象ã«ãããã®ã®ã¿ãèãã¾ãã RI 㨠SP ã®è¦ç´ ã®å ¨ä½å æ¯è¼è¡¨ã確èªããåã«ãåºæ¬çãªè¦ç´ ã«ã¤ãã¦æ¼ããã¦ããã¾ãããã RI ã®è¦ç´ ã®å ¨ä½å ã¹ã³ã¼ãã¨æä¾ã¯ã©ã¹ã¨ããèãæ¹ããããã¨ãæ¼ããã¦ãã ãããè³¼å ¥ã®æ¹æ³ã«ããå²å¼çãç°ãªãé¨åã«ã¤ãã¦ã¯ãå²å¼ç é«ããªã©ã®ãã¼ã¯ã§è¡¨ãã¦
AWSã«ãããã³ã³ããããã¹ãããæ段ã¯ãæ ¼æ®µã«é²åãç¶ãã¦ãã¾ããECSããã¯ãã¾ããEKSãFargateãApp RunnerãProtonï¼Lambdaã³ã³ããã¼ããã®ã»ãã·ã§ã³ã§ã¯ããããæ段ãæ¯è¼ããä»ããªãããã³ã³ãããAWSç°å¢ã«ãã¹ãããã«ãããå¿ è¦ãªãã®ãé¸æããããã®ç¾ éç¤ã¨ãªãæ â¦
ããã«ã¡ã¯ãã¨ã¦ã¬ã« SRE ãã¼ã ã®åç°ã§ãã ä»å¹´ (2021å¹´) ã¨ã¦ã¬ã«ã§ã¯ãå ¬ééµèªè¨¼ã§æ¥ç¶ããEC2ã®è¸ã¿å°ãµã¼ããå»æ¢ãã代ããã«åãµã¼ãã¸ã®æ¥ç¶ãIAMã§èªè¨¼ã§ããSSM Session Managerã¸ã®ãªãã¬ã¼ã¹ãè¡ãã¾ãããæ¬è¨äºã§ã¯ãã®ã¢ããã¼ã·ã§ã³ããå®è£ ã®ãã¤ã³ããç´¹ä»ãã¦ããããã¨æãã¾ãã æ§æ¥ã®è¸ã¿å°ãµã¼ã æ§æ¥ã®è¸ã¿å°ãµã¼ãã¨ã¦ã¬ã«ã§é·ãéç¨ããã¦ããè¸ã¿å°ãµã¼ã (Gateway) ã¯ä»¥ä¸ã®ãããªãã®ã§ããã åéçºè ã¯ãèªåã®ç§å¯éµã使ã£ã¦è¸ã¿å°ãµã¼ãã¸SSHãè¡ã ( è¸ã¿å°ãµã¼ãä¸ã«ã¯åéçºè ã®åå¥ã¦ã¼ã¶ã¼ããã³å ¬ééµãç»é²ããã¦ãã )è¸ã¿å°ä¸ã§ã¯ãæ¥ç¶ã許å¯ããã¦ããSSH対象ã®ãµã¼ãã®ç§å¯éµãã¦ã¼ã¶ã¼æ¯ã«é ç½®ããã¦ããããã®éµã§åãµã¼ãã«SSHããMySQL / Elasticsearch / Redis ãªã©ãPrivate Subnet
ããã«ã¡ã¯ã ãæ©å«ãããã§ããããã "No human labor is no human error" ã大好ã㪠ãã¯ã¹ãã¢ã¼ãæ ªå¼ä¼ç¤¾ ã®åäºã§ãã SSM Change Calendar ã«ãµã¼ããã¼ãã£ã®ã«ã¬ã³ãã¼ãã¤ã³ãã¼ãå¯è½ã«ãªãã¾ããã å·çæ¥æç¹ã§ä»¥ä¸ã®ã«ã¬ã³ãã¼ãã ics å½¢å¼ã§ã¤ã³ãã¼ãã§ãã¾ãã Google Calendars Microsoft Outlook Calendars Apple iCloud Calendars SSM Change Calendar ã¨ã¯ Systems Manager 㧠Automation ã RunCommand ãå®è¡ããéã«ãå®è¡ããæ¥ããªãæ¥ãã«ã¬ã³ãã¼ã§æå®ã§ãããµã¼ãã¹ã§ãã ä¾ãã°ãéçºæ¤è¨¼ç°å¢ã® EC2 ãå¹³æ¥æ¥åæé帯ã ãèªåèµ·ååæ¢ããã¨ãã£ã使ãæ¹ããã¾ãã å¾æ¥ã ã¨èªåã§æ¥æ¬ã®ç¥æ¥ãç»é²ããªã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}