ããã«ã¡ã¯ï¼ã¤ã¼ã´ãªã§ãã
EC2ããããªãã¯ãµããããã«ããå ´åãåé¡ãªãã¤ã³ã¿ã¼ãããã²ã¼ãã¦ã§ã¤çµç±ã§S3ã¸ã¢ã¯ã»ã¹ãã§ãã¾ãã
ãªãããã©ã¤ãã¼ããµããããã«ããEC2ããS3ã«ã¢ã¯ã»ã¹ãããå ´åãNATã²ã¼ãã¦ã§ã¤çµç±ã§ãS3ã«ã¢ã¯ã»ã¹ãã§ãã¾ãããS3ã®ããã ãã«NATã²ã¼ãã¦ã§ã¤ãæ§ç¯ããNATã²ã¼ãã¦ã§ã¤çµç±ã§S3ã«ã¢ã¯ã»ã¹ãããå ´åããã¡ãªããã¨ãã¦ã¯ãNAT Gatewayæéåã³NAT Gatewayãçµç±ããéä¿¡æããããã¾ãã®ã§ãã注æãã ããã
ä½ãããããªãã¯ãµããããã«NATã²ã¼ãã¦ã§ã¤ããªãå ´åããã©ã¤ãã¼ããµããããã«ããEC2ããS3ã«ã¢ã¯ã»ã¹ã¯ã§ãã¾ããã
NATã²ã¼ãã¦ã§ã¤ãã¤ã³ã¿ã¼ãããã²ã¼ãã¦ã§ã¤ã¸ã®ã¢ã¯ã»ã¹ããªãå ´åããããã¯ããã©ã¤ãã¼ããµãããããããã©ãã£ãã¯æéãªã©ãçºçããªãããã«S3ã«ã¢ã¯ã»ã¹ããããå ´åãS3 Endpoint Gatewayãä½æããå¿ è¦ãããã¾ãã®ã§ãä»åã®è¨äºã§ã¯ããã©ããã£ã¦VPCã¨ã³ããã¤ã³ãçµç±ã§S3ã¸ã¢ã¯ã»ã¹ã§ããããã¨ããè¨äºããç´¹ä»ãããã¨æãã¾ãã
VPCã¨ã³ããã¤ã³ãæ¦è¦
VPNã¨ã³ããã¤ã³ãã®ç¨®é¡ã¯ï¼ã¤ããã¾ããã²ã¼ãã¦ã§ã¤ VPC ã¨ã³ããã¤ã³ãï¼Gateway VPC Endpointï¼ã¨ã¤ã³ã¿ã¼ãã§ã¤ã¹ VPC ã¨ã³ããã¤ã³ã (AWS PrivateLink)ã§ãã
çµè«ããè¨ãã¾ãã¨ãã²ã¼ãã¦ã§ã¤ VPC ã¨ã³ããã¤ã³ãã¯ç¡æã§ãããç¾æç¹ï¼2022/7/5ï¼ã§ãã²ã¼ãã¦ã§ã¤ VPC ã¨ã³ããã¤ã³ãã¯S3ã¨Dynamo DBã®ããã ãã«åå¨ãã¦ãã¾ãã
ä»ã®ãµã¼ãã¹ã®ããã«ã¨ã³ããã¤ã³ãã使ç¨ãããå ´åãã¤ã³ã¿ã¼ãã§ã¤ã¹ VPC ã¨ã³ããã¤ã³ã (AWS PrivateLink)ãé¸ã¶å¿ è¦ãããã¾ãã
ã²ã¼ãã¦ã§ã¤ VPC ã¨ã³ããã¤ã³ãã®ç¹å¾´
ã²ã¼ãã¦ã§ã¤ VPC ã¨ã³ããã¤ã³ãã使ã主ãªã¡ãªããã¯ç¡æã§ãããã¨ã§ãã
ã²ã¼ãã¦ã§ã¤ VPC ã¨ã³ããã¤ã³ãã使ãå ´åãä¸è¨ã®å³ã®éãã対象ãµããããã®ã«ã¼ããã¼ãã«ã«ã²ã¼ãã¦ã§ã¤ VPC ã¨ã³ããã¤ã³ãã®ã«ã¼ãã追å ããã¾ãã®ã§ãæ®éã®AWSã²ã¼ãã¦ã§ã¤åã®åä½ã¨ãªãã¾ãã
ãªããã²ã¼ãã¦ã§ã¤ VPC ã¨ã³ããã¤ã³ãã«ãããªãã¯IPãä»ä¸ããã¾ãã®ã§ãNetwork ACLï¼NACLï¼ã§é信許å¯ããã©ã¤ãã¼ãIPã®ç¯å²å ã®ã¿ã¨æå®ãã¦ãã¾ãã¨ãã²ã¼ãã¦ã§ã¤ VPC ã¨ã³ããã¤ã³ãçµç±ã§ã®éä¿¡ãéããªããªãã®ã§ãè¨è¨æã«ã注æãã ããã
ã²ã¼ãã¦ã§ã¤ VPC ã¨ã³ããã¤ã³ãã®å ´åãVPC ã¨ã³ããã¤ã³ãããªã·ã¼ãä½æãããã¨ãã§ãã¾ãã®ã§ããµã¼ãã¹ã¸ã®ã¢ã¯ã»ã¹ã管çã§ãã¾ãï¼IAMãã±ããããªã·ã¼ã®ããã«ã¢ã¯ã»ã¹ãå¶éã§ãã¾ãï¼ã
ã¤ã³ã¿ã¼ãã§ã¤ã¹ VPC ã¨ã³ããã¤ã³ã (AWS PrivateLink)ã®ç¹å¾´
å®å ¨ã«ãã©ã¤ãã¼ãIPã®éä¿¡ã§S3ã«ã¢ã¯ã»ã¹ãããå ´åãã¤ã³ã¿ã¼ãã§ã¤ã¹ VPC ã¨ã³ããã¤ã³ããé¸ã¶å¿ è¦ãããã¾ãã
ä¸è¨ã®å³ã®éãã対象ãµãããããã¨ã«Elastic Network Interface (ENI)ã追å ãããã®ã§ãã²ã¼ãã¦ã§ã¤ VPC ã¨ã³ããã¤ã³ãã¨éã£ã¦ããªã·ã¼ã§ã®ã¢ã¯ã»ã¹å¶éã§ã¯ãªããã»ãã¥ãªãã£ã°ã«ã¼ãã§ã®å¶éãè¡ããã¦ãã¾ãã
Elastic Network Interface (ENI)ã®è¿½å ã«ãã£ã¦å¯¾è±¡ãµããããå ã®ãã©ã¤ãã¼ãIPãä¸ã¤æ¶è²»ããã¾ãã®ã§ãInterfaceåã®å ´åãIPã®æ¶è²»ã«ã¤ãã¦èæ ®ããå¿ è¦ãããã¾ãã
ãªããæéãããã®ã¨ã³ããã¤ã³ãã®å©ç¨æåã³ã¨ã³ããã¤ã³ãçµç±ã§ã®éä¿¡æãçºçãã¾ãã®ã§ãè¨è¨æã«ã注æãã ããã
VPCã¨ã³ããã¤ã³ãã®ä½æ
è¨è¨ã«ãã£ã¦æ§ç¯æ¹æ³ãç°ãªãã¾ãã®ã§ãä¸è¨ã®ï¼ã¤ã®ä¸ããã¨ã³ããã¤ã³ãã®ã¿ã¤ããé¸ãã§ãã ããã
ä»åã¯ãS3ã®ã²ã¼ãã¦ã§ã¤ VPC ã¨ã³ããã¤ã³ããé¸æãã¾ãï¼è¨è¨ã«ããã¾ãããæ®éã¯ã²ã¼ãã¦ã§ã¤ VPC ã¨ã³ããã¤ã³ããé¸æããã»ããè¯ããã¨æãã¾ãï¼ã
ã²ã¼ãã¦ã§ã¤ VPC ã¨ã³ããã¤ã³ãã®ä½æï¼ä»åãé¸ãã ã¿ã¤ãï¼
[VPC]>[ã¨ã³ããã¤ã³ã]>[ã¨ã³ããã¤ã³ããä½æ]ãã¯ãªãã¯ãã¾ãã
[AWSãµã¼ãã¹]ãé¸æããä¸ãä¸ã«ããæ¤ç´¢æ¬ã§S3ãå ¥åãã¾ããããã¦ãGatewayãã®ã¿ã¤ããé¸æãã¾ãã
ãGatewayãã®ã¿ã¤ããé¸æãããã¨ã§ãVPCãé¸æããã©ã®ãµããããã«ã«ã¼ãã追å ããããé¸æãã¾ãï¼æåã§ãã«ã¼ããã¼ãã«ã«ã«ã¼ãã®è¿½å ã¯å¯è½ã§ãããæ§ç¯æã«é¸æããã»ãã楽ã§ãï¼ã
[ããªã·ã¼]ããã¹ã¦è¨±å¯ã«ãããã®ã§ãããã«ã¢ã¯ã»ã¹ããé¸æãã¾ãããIAMããªã·ã¼ã§VPCã¨ã³ããã¤ã³ããå¶éãããå ´åããã«ã¹ã¿ã ããé¸æãã¦ãã ããã
[ã¨ã³ããã¤ã³ããä½æ]ãã¯ãªãã¯ãã¾ãã
çµæ
対象ã«ã¼ããã¼ãã«ãè¦ã¾ãã¨ãã«ã¼ããã¼ãã«ã«vpce-xxxã¨è¨è¼ãããã®ã§ãããã¯S3ã¨ã³ããã¤ã³ãã²ã¼ãã¦ã§ã¤å®ã®ã«ã¼ãã§ãã
ã¤ã³ã¿ã¼ãã§ã¤ã¹ VPC ã¨ã³ããã¤ã³ãã®ä½æï¼ä¸è¨ã®æ¹æ³ãããã¾ãï¼
ååã®è¨äºã§SSMç¨ã®ã¤ã³ã¿ã¼ãã§ã¤ã¹ VPC ã¨ã³ããã¤ã³ããä½æãã¾ããã®ã§ããåèãã ããï¼S3ã®ã¤ã³ã¿ã¼ãã§ã¤ã¹ VPC ã¨ã³ããã¤ã³ããä½æãããå ´åãS3 (Interface)ãé¸æãã¾ãï¼ã
以ä¸ã御ä¸èªãããã¨ããããã¾ããã
æ¬ç° ã¤ã¼ã´ãª (è¨äºä¸è¦§)
ã«ã¹ã¿ãã¼ãµã¯ã»ã¹é¨
ã»2024 Japan AWS Top Engineers (Security)
ã»AWS SAP, DOP, SCS, DBS, SAA, DVA, CLF
ã»Azure AZ-900
ã»EC-Council CCSE
趣å³ï¼æ¥æ¬å½å æ è¡(47é½éåºçå¶è¦)ã»ãã©ã¤ãã»é³æ¥½