AWS Dev Day 2023 E-2: Amazon S3ã»Amazon Cognitoã»AWS Lambdaã®ã¢ã³ããã¿ã¼ã³ã§å¦ã¶ã»ãã¥ãªãã£ã»ãã¤ã»ãã¶ã¤ã³
ããã«ã¡ã¯ãã·ã¹ãã ã»ãã¥ãªãã£æ¨é²ã°ã«ã¼ãã®è±å¡ã§ããæ¬è¨äºã¯ãAWSã«ãããè å¨æ¤ç¥ã®ããã«åãçµãã å 容ã«ã¤ãã¦ç´¹ä»ãã¾ãã AWSä¸ã§è å¨æ¤ç¥ã¨ããã°ãGuardDutyãªã©ã®ãµã¼ãã¹ã使ã£ã¦å®è£ ããã®ãä¸è¬çã ã¨æãã¾ãããä»çµã¿ã¯æ§ç¯ã§ãã¦ã以ä¸ã®ãããªæ©ã¿ãæããããã¨ã¯ããã¾ããã§ããããã ä»çµã¿ã¯å®æãããã©ãçµå±ã¢ã©ã¼ãã対å¿ãããã«æ¾ç½®ããã¦ãã éããã人çãªã½ã¼ã¹ã®ä¸ã§å¤§éã®ã¢ã©ã¼ããæããããªã ä»çµã¿ã¯æ§ç¯ã§ãã¦ããä¸è¨ã®ãããªéç¨é¢ã«é¢ããé£ãããæããäºã¯å°ãªããªãã¨æãã¾ããããã§ããã®è¨äºã§ã¯ãæ§ç¯ããä»çµã¿ã¨ãã®ä»çµã¿ãçããã¾ã§ã®éç¨æ¹æ³ã®å¤é·ã«ã¤ãã¦è©³ãããç´¹ä»ãã¾ãã 大è¦æ¨¡ãªã¯ã©ã¦ãç°å¢ã«å¯¾ãã¦ãã»ãã¥ãªãã£ãã¹ã±ã¼ã«ããããæ¹ã«ã¨ã£ã¦å°ãã§ãåèã«ãªãã°å¹¸ãã§ãã ç®æ¬¡ èæ¯ æ§ç¯ããä»çµã¿ éç¨ã¨ãã®å¤é· æå¾ã« èæ¯ è©±ãé²ããåã«ã
ãã¡ã㯠ANDPAD Advent Calendar 2022 ã®19æ¥ç®ã®è¨äºã§ãã ããã«ã¡ã¯ã ã¢ã³ããããSREã®å®é座ã§ãã ä»åã¯ã¢ããã³ãã«ã¬ã³ãã¼ã¨ãããã¨ã§ãAmazon S3ã®å ¬éãæ¤ç¥ãã¦Slackã«éç¥ããä»çµã¿ãã·ã³ãã«ã«è¡ãæ¹æ³ã«é¢ãã¦æ¸ããã¨æãã¾ãã Amazon S3ã®éè¦æ§ S3ãã±ããã®å ¬éãé²ãã«ã¯ S3ã®å ¬éæ¤ç¥ã®ä¾ AWS Config ãå©ç¨ããæ¹æ³ Lambdaã®ä½æ AWS Configã§ããã¼ã¸ãã«ã¼ã«ãæå¹å Event Bridgeãä½æãã åä½ç¢ºèª å°ãã¿: AWS Configã§ä»»æã®ã¿ã¤ãã³ã°ã§ã«ã¼ã«ã®è©ä¾¡ãè¡ãæ¹æ³ Amazon Guard Dutyãå©ç¨ããæ¹æ³ ã¾ã¨ã çµããã« Amazon S3ã®éè¦æ§ ⻠以éãæ¬æä¸ã§ã¯Amazon S3ãS3ã¨ç縮表è¨ãã¾ãã AWSãå©ç¨ããã¦ããå ´åãS3ã¯ãã¾ãã¾ãªãã¼ã¿
Datadogã®ã»ãã¥ãªãã£ã¢ãã¿ãªã³ã°ã使ã£ãä¸æ£ãã°ã¤ã³æ¤ç¥ã®å®è£ æ¹æ³ã«ã¤ãã¦
ã¹ã©ã¤ãæ¦è¦ SPA(Single Page Application)ã®æ®åãä¸å±¤é²ãã§ãããå¾æ¥åã®MPAãç¥ããªãã¦ã§ãéçºè ãçã¾ãã¤ã¤ããããã§ããSPA対å¿ã®ãã¬ã¼ã ã¯ã¼ã¯ã§ã¯åºæ¬çãªèå¼±æ§ã«ã¤ãã¦ã¯å¯¾çæ©è½ãç¨æããã¦ãã¾ãããããã«ãé¢ããããèå¼±æ§è¨ºæçã§åºæ¬çãªèå¼±æ§ãææãããã±ã¼ã¹ã¯ãããå¢ãã¤ã¤ããã¾ãã æ¬ã»ãã·ã§ã³ã§ã¯ãLaravelã¨Reactã§éçºããã¢ããªã±ã¼ã·ã§ã³ãã¢ãã«ã¨ãã¦ãSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ãã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ãèªå¯å¶å¾¡ä¸åçã®èå¼±æ§ã®å®ä¾ãç´¹ä»ããªãããç¾å®çãªå¯¾çã«ã¤ãã¦ç´¹ä»ãã¾ããLaravelãReact以å¤ã®ãã¬ã¼ã ã¯ã¼ã¯å©ç¨è ã«ãå½¹ç«ã¤èª¬æãå¿ããã¾ãã PHPã«ã³ãã¡ã¬ã³ã¹2022ã§ã®è¬æ¼è³æã§ãã PHPã«ã³ãã¡ã¬ã³ã¹ã§ã®åç»URL https://www.youtube.com/watch?v=jZ6sWyGxcCs
ã½ããã¦ã§ã¢éçºè ã§ãªãã¨ããã»ãã¥ãªãã£ã»ãã¤ã»ãã¶ã¤ã³ã¨ããè¨èã¯èãããã¨ãããã¨æãã¾ããããããã»ãã¥ãªãã£ã»ãã¤ã»ãã¶ã¤ã³ãååã«å®æ½ã§ãã¦ããã¨è¨ããçµç¹ã¯å¤ããªãã®ã§ã¯ãªãã§ããããã ããã»ãã¥ãªãã£ã»ãã¤ã»ãã¶ã¤ã³ãå®æ½ãããã¨ãã¦ããä½ãããã°ããã®ã ããï¼ããã©ãããã°è¯ãã®ã ããï¼ãã¨ãªããªãæãåããªãããããªç¶æ³ã®ä¸å©ã¨ãªããããæã ãã»ãã¥ãªãã£ã»ãã¤ã»ãã¶ã¤ã³ãå¦ã³ãå®è·µããå 容ãææ¸åãå ¬éããéã³ã¨ãã¾ããã ã»ãã¥ãªãã£åå¿è ã§ãèªã¿ãããããã«ã以ä¸ã®ç¹å¾´ã念é ã«ããã¦æ¬æ¸ãå·çãã¾ããã 軽快ãªæç« å³è¡¨ãå¤ç¨ããã°ã©ãã£ã«ã«ãªè¦ãç® ãã£ã©ã¯ã¿ã¼ã®ã»ãªãã«å ±æããªããç解ãã§ãã 1ç« ãã»ãã¥ãªãã£ã»ãã¤ã»ãã¶ã¤ã³ ï¼ã»ãã¥ãªãã£ã»ãã¤ã»ãã¶ã¤ã³ã®æ¦è¦ãå¿ è¦æ§ã®èª¬æ 2ç« ãè å¨åæ ï¼çµç¹ãã·ã¹ãã ã«å¯¾ããè å¨åæã®å®æ½æ¹æ³ 3ç« ãã»ãã¥ãªãã£
ã¯ããã« ããã«ã¡ã¯ãæ ªå¼ä¼ç¤¾Flatt Securityã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã®æä¸ @0x003f ã§ãã ããã¾ã§å¼ç¤¾ããã°ã§ã¯æ§ã ãªãä»æ§ã¨ã»ãã¥ãªãã£è¦³ç¹ã®è§£èª¬è¨äºããçºè¡¨ãã¦ãã¾ãããä»åã¯ãã¾ã¾ã§ã®è¨äºãæ¹ãã¦ç´¹ä»ãã¤ã¤ãèªè ã®çæ§ãéçºä¸ã®ãµã¼ãã¹ã§ã»ã«ããã§ãã¯ãè¡ãããããä»æ§ã¨ã»ãã¥ãªãã£è¦³ç¹ãã§ãã¯ãªã¹ãããä½æãã¾ããããæ´»ç¨ããã ããã¨å¹¸ãã§ãã ãã¦ã³ãã¼ãã¯ä¸è¨ã®GitHubãªã³ã¯ããã©ããã ã¾ããæ ªå¼ä¼ç¤¾Flatt Securityã§ã¯ã客æ§ã®ãããã¯ãã«èå¼±æ§ããªããå°éã®ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã調æ»ããã»ãã¥ãªãã£è¨ºæãµã¼ãã¹ãæä¾ãã¦ãã¾ããæéã«é¢ããè³æãé å¸ä¸ã§ãã®ã§ããèå³ã®ããæ¹ã¯æ¯éã覧ãã ããã ã¯ããã« ã¢ããªã±ã¼ã·ã§ã³ã®ä»æ§èµ·å ã®èå¼±æ§ã¨ã¯ ã¢ããªã±ã¼ã·ã§ã³ã®ä»æ§èµ·å ã®èå¼±æ§ãé²ãããã« ä»æ§ã®èå¼±æ§ã«ããè¦ãããå ±éç¹ 1. ã¯
Amazon Web Services ããã° [AWS Black Belt Online Seminar] ã³ã³ããã»ãã¥ãªãã£å ¥é AWS Black Belt ãªã³ã©ã¤ã³ã»ããã¼ãã³ã³ããã»ãã¥ãªãã£å ¥é ããå ¬éãã¾ãã ã³ã³ããã¢ããªã±ã¼ã·ã§ã³ãéç¨ããä¸ã§ã®ã»ãã¥ãªãã£ã«ã¤ãã¦ãç¹å®ã®AWSãµã¼ãã¹ã«ã¯ä¾åããªãä¸è¬çãªèãæ¹ãç´¹ä»ããã»ããã¼ã¨ãªã£ã¦ãã¾ããã³ã³ããã®ã©ã¤ããµã¤ã¯ã«ã«æ²¿ã£ã¦ãã»ãã¥ãªãã£ã®ãã¤ã³ããè¤æ°åã«åãã¦è§£èª¬ãã¾ãã è¦è´ããã³è³æé²è¦§ã¯ä»¥ä¸ããå¯è½ã§ãã Part 1, ã³ã³ããã¤ã¡ã¼ã¸ä½æ: YouTube / SlideShare Part 2, ãµãã©ã¤ãã§ã¼ã³ããªã¼ã±ã¹ãã¬ã¼ã¿ã¼: YouTube / SlideShare Part 3, ãã¹ããã©ã³ã¿ã¤ã ã»ãã¥ãªãã£: YouTube / SlideShare ãã®ã»ãã·ã§ã³ã§ã¯ãã³ã³ã
AWSãã¯ããã¨ããã¯ã©ã¦ããã©ãããã©ã¼ã ã®æ®åã«ä¼´ããDevã¨Opsã®å¢ç®ã¯ããªãææ§ã«ãªã£ã¦ãã¾ãããã®ä¸ã§ãIAMã®ç®¡çã¯è¨å®ã«ãã£ã¦ã¯æ¨©éææ ¼ãå¼ãèµ·ãããããªããã¨ããããã®ç®¡ç権éã¯æ éãªç®¡çã«ãªããã¡ã§ããçµæçã«ãIAMã¯å±äººçãªç®¡çãè¡ã£ã¦ããçµç¹ãå¤ãã®ã§ã¯ãªãã§ããããã â¦
ã¨ãã¨ãAWSã«ãCloudShellï¼ä»ã¨éã£ã¦ã¹ãã¼ã¹ãªãï¼ããã£ã¦ãã¾ããããã©ã¦ã¶ãã¼ã¹ã®ã·ã§ã«ç°å¢ãã¨ã¦ã便å©ã§å©ç¨ã·ã¼ã³ãå¤ããã§ãããã»ãã¥ãªãã£ã»çµ±å¶é¢ã§ã¯æ¸å¿µç¹ãããã¾ããçµæçã«ç¾æç¹ã§ã¯ã«ã¼ã«ãæºãããç¦æ¢ããã«è³ã£ãã®ã§ãã®çµç·¯ãæ¸ãçãã¦ããã¾ãã 2020/12/29 AWâ¦
Amazon Web Services ããã° AWSä¸ã§ã©ã®ããã«ã¼ããã©ã¹ãã¢ã¼ããã¯ãã£ãèãã¦ããã 2021å¹´7æ追è¨ï¼ AWSã«ãããã¼ããã©ã¹ãã«é¢ããã¢ãããã¼ããããæ å ±ã¯ã以ä¸ããåç §ãã ããã https://aws.amazon.com/jp/security/zero-trust/ ã¾ããæ¬Blogã詳細ã«ã¢ãããã¼ãããBlogè¨äºãããã¾ãã®ã§é©å®ãåç §ãã ããã ãã¼ããã©ã¹ãã¢ã¼ããã¯ãã£: AWS ã®è¦ç¹ã https://aws.amazon.com/jp/blogs/news/zero-trust-architectures-an-aws-perspective/ ââââââââââââââââââââââ å³ããè¦å¶ã¸ã®å¯¾å¿ããªã¹ã¯åé¿ãèæ ®äºé ã¨ãã¦æããã客æ§ã¯ãã¬ã¬ã·ã¼ã¢ããªã±ã¼ã·ã§ã³ã®ãªãã¡ã¯ã¿ãªã³ã°ãæ°ããã¢ããªã±ã¼ã·ã§ã³ã®ãããã¤ã«é
Gravitational ãteleportããteleconsoleããªã©ãã¯ã©ã¦ããã¤ãã£ãã®ã¢ããªã±ã¼ã·ã§ã³ã¨ã¤ã³ãã©ã¹ãã©ã¯ãã£ãæä¾ãããªã¼ãã³ã½ã¼ã¹ã½ããã¦ã§ã¢ãã³ãã¼ ãã®è¨äºã¯ãèè ã®è¨±å¯ãå¾ã¦é ä¿¡ãã¦ãã¾ãã https://gravitational.com/blog/solid-infrastructure-security-without-slowing-down-developers/ ãã®è¨äºã§ã¯ãSaaSä¼æ¥ãå¼·åºãªã¯ã©ã¦ãã»ã¤ã³ãã©ã¹ãã©ã¯ãã£ã»ã»ãã¥ãªãã£ãæã¤ãã¨ã¨ãããããã¦èªç¤¾ã®ã¨ã³ã¸ãã¢ãæããã¦ãã¾ããã¨ã®ãã¬ã¼ããªãã«ã©ã®ããã«ã¢ããã¼ããã¦ãããã«ã¤ãã¦ãç§ã®è¦è§£ãå ±æãããã¨æãã¾ãã ã»ãã¥ãªãã£ã¨ãããã®ã¯ã¤ã©ã¤ã©ã®åå ã«ãªãã¾ããã»ãã¥ãªãã£ãã¤ã©ã¤ã©ã®åå ã«ãªããªããã°ãæ¥ã ã®æ®ããããã£ã¨æ¥½ã«ãªãããããã¾ãããããããªããSR
OAuth 2.0 Security Best Current Practice Abstract This document describes best current security practice for OAuth 2.0. It updates and extends the OAuth 2.0 Security Threat Model to incorporate practical experiences gathered since OAuth 2.0 was published and covers new threats relevant due to the broader application of OAuth 2.0.¶ Status of This Memo This Internet-Draft is submitted in full confor
ã¨ã³ã¿ã¼ãã©ã¤ãºä¼æ¥ãæ°ããã¯ã©ã¦ããµã¼ãã¹ãå°å ¥ããæã«ã¯ãèªç¤¾ã®ã»ãã¥ãªãã£åºæºãæºããã¦ãããã¨ã確èªããã®ãéä¾ã§ããããã»ãã¥ãªãã£ãã§ãã¯ã·ã¼ããã¨å¼ã°ããã¨ã¯ã»ã«ã·ã¼ããå©ç¨ãã¦ä¸ç¹ä¸ç¹ãã§ãã¯ãã¦ãããã¨ãå¤ããï¼ãã®è³ªå票ã§èãããå 容ãå社ãã¨ã«ã°ãã°ãã§ãã·ã¹ãã å°å ¥æã«åæ¹ã®è² æ ã«ãªã£ã¦ãã¾ã£ã¦ããã®ãæ¨æºåãã¦ãªãã¨ãã§ããªããã¨æããã¨ã¯ãããããã®è¨äºã§ã¯ããã«ã¯è§¦ããªããï¼ ããããã®ãããã¢ã³ãã¦ã£ã«ã¹ã½ããã¦ã§ã¢ããµã¼ãã¼ã«ã¤ã³ã¹ãã¼ã«ãã¦ãããã¨ãã¨ãããã§ãã¯é ç®ã ãæå¿«ãªè³ªåã®ããã«è¦ãããå ·ä½ã§å®ç¾ããããã«ã¯è²ã èããªããã°ãããªããã¨ããããæ¨æºçãªãµã¼ãã¼æ§æãã¤ã¾ãããã¼ãã¦ã§ã¢ããã£ã¦ããã®ä¸ã§OSã稼åãã¦ãã¦ããã®ä¸ã§ã¢ããªã±ã¼ã·ã§ã³ãåãã¦ããã¨ããã·ã³ãã«ãªæ§æã§ããã°è¯ãã®ã ããã¯ã©ã¦ãã¤ã³ãã©ã使ãåãããã«ãªã£ãä»ã§ã¯ãã¤
Gitã§ã¯PGPéµãå©ç¨ããCommitã¸ã®ç½²åãã§ãããã¨ã以åããç¥ã£ã¦ãã¾ããã, ä¸è¨è¨äºãæè¦ãã¦ç°¡åã«è¨å®ã§ãããã¨ãç¥ã£ãã®ã§PGPéµã®çæããè¨å®ã¾ã§ãããã¨æãã¾ãã. ã¾ã, ã¨ããããã¸ã§ã¯ãã®Code Ownerã«ãªã£ããã, ãªãã¸ããªã¸ã®Commitã«å¯¾ãã¦ç½²åããããã¨ã§å½è£ ãé²ããæ¹ãè¯ãã®ã§ã¯ãªããã¨æãããã¨ã«ãèµ·å ãã¦ãã¾ã. æ¬è¨äºã§ã¯, ä¸è¨4ç¹ã«ã¤ãã¦å®æ½ãããã¨ãã¾ã¨ãã¾ã. macOSã§ã®PGPéµã®çæ Gitã§ã®ç½²åã¤ãCommitã®å®è¡ GitHubã¸ã®å ¬ééµã®ç»é² ä»ã®PCã¸ã®ç§å¯éµã®ã¤ã³ãã¼ã macOSã§ã®PGPéµã®çæ ã¾ãã¯å¿ è¦ãªãã¼ã«ãã¤ã³ã¹ãã¼ã«ãã¾ã. PGPéµãçæããããã®GnuPGã¨ãã¹ãã¬ã¼ãºå ¥åã«å©ç¨ããPinentryãã¤ã³ã¹ãã¼ã«ãã¾ã. ã¤ã³ã¹ãã¼ã«ãå®äºãããGnuPGã®ãã¼ã¸ã§ã³ã確èªãã¦, 2以éã§ã
â ã¯ããã« æ¬æ¸ã¯ Auth å±ã®ãé°å²æ° OAuth ã·ãªã¼ãºã第ä¸å¼¾ã§ãããOAuth 㨠OpenID Connect ã¸ã®æ»æã¨å¯¾çã«ã¤ãã¦ã®æ¬ã§ããæ»æå ¨è¬ã§ã¯ãªããæ»æ対象ã¨ãã¦ä¸çªçãããããªãã¤ã¬ã¯ã é¨åã¸ã®æ»æãã«ç¹åããå 容ã«ãªã£ã¦ãã¾ãããªãã¤ã¬ã¯ãé¨åã¸ã®æ»æã®ä»çµ ã¿ã¨ãstateãnonce ãã¯ããã¨ãã対çã«ã¤ãã¦ã®ä»çµã¿ãç解ããã°ãé°å²æ° OAuth使ã ãè±ããã¨è¨ããã§ãããã â æ³å®èªè ⢠OAuthã»OIDC ã«ã¤ãã¦ç¨èªãæ¦å¿µãä»çµã¿ã¯ã ãããç解ãã¦ã(Auth å± ã®åèã¯èªãã !) ⢠stateãnonceãPKCEãc_hashãat_hashã¯èãããã¨ã¯ãããç解ã¯ã㦠ãªãã ⢠ã¯ã©ã¤ã¢ã³ãããªã©ã¤ã³ã°ã»ãã¼ãã£ã¨ãã¦ã¢ããªãä½ããããããªã ãã OAuthã»OIDC ã«ã¤ãã¦ã®ç解ãããããããã§ããã°ããã²ã以ä¸
Spring Bootã«ããAPIããã¯ã¨ã³ãæ§ç¯å®è·µã¬ã¤ã 第2ç ä½å人ãã®éçºè ããInfoQã®ããããã¯ãPractical Guide to Building an API Back End with Spring BootããããSpring Bootã使ã£ãREST APIæ§ç¯ã®åºç¤ãå¦ãã ããã®æ¬ã§ã¯ãåºçæã«æ°ãããªãªã¼ã¹ããããã¼ã¸ã§ã³ã§ãã Spring Boot 2 ã使ç¨ãã¦ãããããããSpring Boot3ãæè¿ãªãªã¼ã¹ãããéè¦ãªå¤...
S3 ãã±ããã«ä¿åããã¦ãããã¡ã¤ã«ã®ã¦ã£ã«ã¹ã¹ãã£ã³ã AWS Lambda ã使ã£ã¦ãã£ã¦ã¿ãããã ããã«ã¡ã¯ãã³ã³ãµã«ãã£ã³ã°é¨ã®ææã§ãã 1æãã¯ãã¾ã£ãã¨æã£ãããããçµããããã§ããã®èª¿åã ã¨ãã·ã³ã»ã¨ã´ã¡ã³ã²ãªãªã³åå ´çãã®å ¬éãããããã§ãã!! ãã¦ãä»å㯠S3 ãã±ããã«ä¿åããã¦ãããã¡ã¤ã«ã®ã¦ã£ã«ã¹ã¹ãã£ã³ã AWS Lambda ã使ã£ã¦ãã£ã¦ã¿ãã®ã§ããã°ã«ã¾ã¨ãã¾ããã ç¾å¨ãS3 ã«ã¯ã¦ã£ã«ã¹ã¹ãã£ã³ã¨ããæ©è½ã¯ãªããS3 ã¸ãã¡ã¤ã«ãã¢ãããã¼ãããåããã¢ãããã¼ãå¾ã«ãã¦ã³ãã¼ãããã¦ã£ã«ã¹ã¹ãã£ã³ããæ¹æ³ãå¤ããã¨æãã¾ãã ä»åã®æ¹æ³ã¯ãä¸è¨ã½ããã¦ã§ã¢ã使ã£ã¦ Lambda ãå©ç¨ãããããã¦ã£ã«ã¹ã¹ãã£ã³ç¨ã« EC2 ãªã©å¥éç¨æãããã¨ãªããæ軽ã«è¡ããã¨ãã§ãããããç°¡åã«è©¦ãã¦ã¿ããã¨ãã§ãã¾ãã upsidetravel/buc
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}