ããã«ã¡ã¯ã6æããECé¨æè¡3課ã«é
å±ããã¾ãããå±±æ¬ææµ·ã§ãã
ã¶ã»ããªã¹ã®å¥½ããªã¢ã«ãã ã¯ã¼ãã¤ãã¿ã»ã¢ã³ããã¿ã§ãã
ä»åã¯ã¹ããªãããã¥ã¼DNSã«ã¤ãã¦ã®èª¿æ»ã¨å®è£
æ¹æ³ããæ¡å
ãã¾ãã
ã¹ããªãããã¥ã¼DNSã¨ã¯
DNSã¯ã¨ãªéä¿¡å
ã«ãã£ã¦ãç°ãªãDNSæ
å ±ã®ã»ãããæä¾ããæ©è½ãã¹ããªãããã¥ã¼DNSã¨ããã¾ãã
ã¹ããªãããã¥ã¼DNSã«ã¯ãä»ã«ãã¹ããªãããã©ã¤ãºã³DNS, ã¹ããªãããã¬ã¤ã³DNS, ã¹ããªããDNSã¨ããå¼ã³æ¹ããããã§ããã
ä»åã¯ã¹ããªãããã¥ã¼DNSã¨ããå¼ç§°ã§çµ±ä¸ãã¦è©±ãé²ãã¾ãã
ã¹ããªãããã¥ã¼DNSãå©ç¨ãããã¨ã§ãVPCå é¨ããã®DNSã¯ã¨ãªã¸ã®å¿çã¨ã¤ã³ã¿ã¼ãããããã®DNSã¯ã¨ãªã®å¿çãå¤ãããã¨ãã§ãã¾ãã ã¾ããVPCå é¨ããã®ã¿åå解決ã§ãããã¡ã¤ã³ãç¨æãããã¨ãã§ãã¾ãã
AWSç°å¢ã¸ã®ãã¤ã°ã¬ã¼ã·ã§ã³æã«ãã¹ããªãããã¥ã¼DNSãå®è£ ãããã¨ã§ããã¾ã§ã¤ã³ã¿ã¼ãããã«å ¬éãã¦ãã社å ç¨ãã¡ã¤ã³ãããã¼ã«ã«ã社å ãããã¯ã¼ã¯ããããåå解決ã§ããªãããã«æ¹ä¿®ããããªã©ã®ãè¦æã«å¯¾å¿ã§ãã¾ãã
AWSã§ã®ã¹ããªãããã¥ã¼DNSã®å®è£ æ¹æ³
AWSã®DNSãµã¼ãã¹Amazon Route53ã«ã¯ãã¹ãã¾ã¼ã³ããã©ã¤ãã¼ãã«ãããªãã·ã§ã³ãããã¾ãã ãããªãã¯ãã¹ãã¾ã¼ã³ã¯ã¤ã³ã¿ã¼ãããããã®åå解決æã«ä½¿ãã¾ãã webãµã¤ããªã©ä¸è¬å ¬éããå ´åã«ä½¿ç¨ããã¾ãã
ãã©ã¤ãã¼ããã¹ãã¾ã¼ã³ã¯ã¤ã³ã¿ã¼ãããã«ã¯å ¬éãããVPCããªã³ãã¬ãã¹ç°å¢ããåå解決ãããã¨ãå¯è½ã§ãã ã¾ããåããã¡ã¤ã³ã®ãã¹ãã¾ã¼ã³ããããªãã¯ããã©ã¤ãã¼ãã®ä¸¡æ¹ã®å ¬éç¯å²ã§ä½æãããã¨ã§ãã¹ããªãããã¥ã¼DNSãå®è£ ã§ãã¾ãã
ãã³ãºãªã³1. ã¹ããªãããã¥ã¼DNSãå®è£ ãå¿çãç°ãªããã¨ã確èªãã
Route53ã«åããã¡ã¤ã³ã§ãããªãã¯ã¨ãã©ã¤ãã¼ãã®ãã¹ãã¾ã¼ã³ãä½æãã ã¹ããªãããã¥ã¼DNSãæ¤è¨¼ãã¾ããæé ã¯ä»¥ä¸ã®éãã§ãã
- ãããªãã¯ãã¹ãã¾ã¼ã³ã®ä½æ
- ãã©ã¤ãã¼ããã¹ãã¾ã¼ã³ã®ä½æ
- ã³ãã³ãã«ããæ¤è¨¼
äºåæºå
äºåæºåã¨ãã¦ã使ç¨ãããã¡ã¤ã³ããã¡ã¤ã³ã¬ã¸ã¹ãã©ã§ãç¨æãã ãããããã§ã¯ tkm-ymmt-test.xyzã使ç¨ãã¾ãã
AWSã«ã¯VPCã¨ãããªãã¯ãµãããããä½æãã¾ãã
VPCä½ææã«enableDnsHostnamesã¨enableDnsSupportã®è¨å®ã確èªãã¾ãã
ãã©ã¤ãã¼ããã¹ãã¾ã¼ã³ã使ç¨ããã«ã¯ã次㮠Amazon VPC è¨å®ã§ true ãæå®ããå¿ è¦ãããã¾ã:
enableDnsHostnames
enableDnsSupport
https://docs.aws.amazon.com/ja_jp/Route53/latest/DeveloperGuide/hosted-zone-private-considerations.html#hosted-zone-private-considerations-vpc-settings
ãããªãã¯ãµããããã«EC2ãç«ã¦ããããªãã¯IPã®èªåå²ãå½ã¦ãæå¹åãã¾ãã ã¤ã³ã¹ã¿ã³ã¹ã®IPv4ã®å¤ã¨VPC IDãã¡ã¢ãã¾ãã äºåæºåå®äºå¾ã®æ§æå³ã§ãã
1. ãããªãã¯ãã¹ãã¾ã¼ã³ã®ä½æ
Route53ã«ãããªãã¯ãã¹ãã¾ã¼ã³ãä½ãã¾ãã
â 1 Route53ã®ããã·ã¥ãã¼ãç»é¢ããããã¹ãã¾ã¼ã³ã®ç»é¢ã¸é·ç§»ãããã¹ãã¾ã¼ã³ã®ä½æãã¯ãªãã¯ãã¾ãã
â 2 é·ç§»ããç»é¢ã§ãã¡ã¤ã³ã®å¿ è¦ãªæ å ±ãè¨å ¥ãã¾ãããããªãã¯ãã¹ãã¾ã¼ã³ãé¸æãã¦ãããã¨ã確èªããããã¹ãã¾ã¼ã³ã®ä½æããã¯ãªãã¯ãã¾ãã
â 3 ãããªãã¯ãã¹ãã¾ã¼ã³ãã§ãã¾ããã次ã«Aã¬ã³ã¼ããä½æãã¾ããã¬ã³ã¼ããä½æãã¿ã³ãã¯ãªãã¯ããç»é¢é·ç§»ãã¾ãã
â 4 Aã¬ã³ã¼ããç·¨éãã¾ããIPã¢ãã¬ã¹ã¯äºåæºåã§ã¡ã¢ããEC2ã¤ã³ã¹ã¿ã³ã¹ã«ç´ã¥ãã¦ãããããªãã¯IPã使ãã¾ããã¬ã³ã¼ããä½æãã¿ã³ãã¯ãªãã¯ãã¾ãã
Aã¬ã³ã¼ããä½æãã¾ããã
注æç¹
Route53以å¤ã®ãã¡ã¤ã³ã¬ã¸ã¹ãã©ï¼ãã¡ã¤ã³åå¾ãµã¼ãã¹ï¼ã§ãã¡ã¤ã³ãè³¼å ¥ããå ´åã ä½æãããNSã¬ã³ã¼ãããå©ç¨ã®ã¬ã¸ã¹ãã©ã®ãã¡ã¤ã³ç®¡çç»é¢ã«ã¦ãã¼ã ãµã¼ãã¨ãã¦ç»é²ã®å¿ è¦ãããã¾ãã®ã§ã対å¿ãã ããã
2. ãã©ã¤ãã¼ããã¹ãã¾ã¼ã³ã®ä½æ
ç¶ãã¦ãRoute53ã«ãã©ã¤ãã¼ããã¹ãã¾ã¼ã³ãä½ãã¾ãã
â 1 ãã¹ãã¾ã¼ã³ã®ç»é¢ã®ãã¹ãã¾ã¼ã³ã®ä½æãã¯ãªãã¯ãã¾ãã
â 2 é·ç§»ããç»é¢ã§ãã¡ã¤ã³ã®å¿ è¦ãªæ å ±ãè¨å ¥ãã¾ãããã©ã¤ãã¼ããã¹ãã¾ã¼ã³ãé¸æãã¦ãããã¨ã確èªãã¾ããäºåæºåã§ã¡ã¢ãã¦ãããVPC IDããã¹ãã¾ã¼ã³ã«é¢é£ä»ããVPC IDãå ¥åããããã¹ãã¾ã¼ã³ã®ä½æããã¯ãªãã¯ãã¾ãã
â 3 ãã©ã¤ãã¼ããã¹ãã¾ã¼ã³ãã§ãã¾ããããã¡ãã«ãAã¬ã³ã¼ããä½æãã¾ããã¬ã³ã¼ããä½æãã¿ã³ãã¯ãªãã¯ããç»é¢é·ç§»ãã¾ãã
â 4 Aã¬ã³ã¼ããç·¨éãã¾ããIPã¢ãã¬ã¹ã¯EC2ã¤ã³ã¹ã¿ã³ã¹ã«ç´ã¥ãã¦ãããã©ã¤ãã¼ãIPã使ãã¾ãã
Aã¬ã³ã¼ããä½æãã¾ããã ãã©ã¤ãã¼ããã¹ãã¾ã¼ã³ã¯ãã¼ã ãµã¼ãç»é²ã®å¿ è¦ã¯ããã¾ããã ããã¾ã§ã§ãåããã¡ã¤ã³ã§ãããªãã¯ãã¹ãã¾ã¼ã³ããã©ã¤ãã¼ããã¹ãã¾ã¼ã³ã®ç¨æãã§ãã¾ããã
3. digã³ãã³ãã«ããæ¤è¨¼
äºåæºåã§ç¨æããã¤ã³ã¹ã¿ã³ã¹ãããã¡ã¤ã³ã®åå解決ã確èªããåã«ã ãã¼ã ãµã¼ãã®IPã¢ãã¬ã¹ãè¨è¿°ãã¦ãã /etc/resolve.confãè¦ã¦ã¿ã¾ãã
options timeout:2 attempts:5 search ap-northeast-1.compute.internal nameserver 10.0.0.2
10.0.0.2ã«ãªã£ã¦ãã¾ãã AWSã¯VPCå ã®Route53 Resolverï¼ããã§ã¯ãã¼ã ãµã¼ãã¨èãã¦OKï¼ã®ã¢ãã¬ã¹ã«é¢ãã¦ä»¥ä¸ã®éãã¢ãã¦ã³ã¹ãã¦ããã ããã©ã«ãã®è¨å®ã§ã¯ãã®å 容ãåæ ããã¦ããç¶æ ã§ãã
Route 53 Resolver 㯠169.254.169.253 (IPv4)ãfd00:ec2::253 (IPv6)ãããã³ VPC+2 ã«ãããã¸ã§ãã³ã°ããããã©ã¤ããªãã©ã¤ãã¼ã IPV4 CIDR ç¯å²ã«é ç½®ããã¦ãã¾ãã ä¾ãã°ãIPv4 CIDR ã 10.0.0.0/16 ã§ãIPv6 CIDR ã fd00:ec2::253 ã® VPC ãããå ´åãRoute 53 Resolver ã«ã¯ 169.254.169.253 (IPv4)ãfd00:ec2::253 (IPv6)ãã¾ã㯠10.0.0.2 (IPv4) ã§ã¢ã¯ã»ã¹ã§ãã¾ãã https://docs.aws.amazon.com/ja_jp/vpc/latest/userguide/vpc-dns.html#AmazonDNS
ãã®ãããVPCå é¨ã§DNSã¯ã¨ãªãéä¿¡ããå ´åããã©ã¤ãã¼ããã¹ãã¾ã¼ã³ã®å¤ãå¿çãããã¯ãã§ãã
# ãã©ã¤ãã¼ããã¹ãã¾ã¼ã³ã¸ã®åãåãã $ dig -t any tkm-ymmt-test.xyz ;; ANSWER SECTION: tkm-ymmt-test.xyz. 60 IN A 10.0.0.206 ;; Query time: 1 msec ;; SERVER: 10.0.0.2#53(10.0.0.2) ;; WHEN: Thu Jun 08 00:56:24 UTC 2023 ;; MSG SIZE rcvd: 62
å¿çããã¾ããã
次ã«ãããªãã¯ãã¹ãã¾ã¼ã³ã®å¤ã確èªãã¦ã¿ã¾ãã
ãªãã·ã§ã³ã§ãã¼ã ãµã¼ãã®å¤ãå¤æ´ãããã¨ã§ãã¤ã³ã¿ã¼ãããããã®åå解決ãè¡ãã確èªãã¦ã¿ã¾ãã
# ãããªãã¯ãã¹ãã¾ã¼ã³ã¸ã®åãåãã $ dig -t a @8.8.8.8 tkm-ymmt-test.xyz ;; ANSWER SECTION: tkm-ymmt-test.xyz. 60 IN A 18.183.116.228 ;; Query time: 8 msec ;; SERVER: 8.8.8.8#53(8.8.8.8) ;; WHEN: Thu Jun 08 00:56:33 UTC 2023 ;; MSG SIZE rcvd: 62
確èªã§ãã¾ããã ã¹ããªãããã¥ã¼DNSã¯å®è£ ããã¦ããç¶æ ã§ãã
ãã³ãºãªã³2. å¥ã¢ã«ã¦ã³ãã®VPCãããã©ã¤ãã¼ããã¹ãã¾ã¼ã³ã§åå解決ããã
Route53ã管çããã¢ã«ã¦ã³ãï¼ã¢ã«ã¦ã³ãAï¼ã¨å¥ã¢ã«ã¦ã³ãï¼ã¢ã«ã¦ã³ãBï¼ã®VPCã«ãã©ã¤ãã¼ããã¹ãã¾ã¼ã³ãç´ã¥ãã¦ãã¢ã«ã¦ã³ãBã®VPCå
ããã®DNSã¯ã¨ãªã®å¿çããã©ã¤ãã¼ããã¹ãã¾ã¼ã³ã§è¨å®ããå
容ã§ãããã¨ã確ããã¾ãã
ã¢ã«ã¦ã³ãã®è¦æ¨¡ã大ãããªããã¨ã§ãã¢ããªã±ã¼ã·ã§ã³ããã¹ãããã¢ã«ã¦ã³ãã¨ç°ãªãã¢ã«ã¦ã³ãã§Route53ã®ãã¹ãã¾ã¼ã³ã管çãããã¨ããããã¨æãã¾ãã
å¥ã¢ã«ã¦ã³ãã§ã以ä¸ã®æ§æãç¨æãã¾ãã
â 1 ã¢ã«ã¦ã³ãAã®CloudShellã§ä»¥ä¸ã®ã³ãã³ããå®è¡ãã¾ããVPC IDã¯ã¢ã«ã¦ã³ãBã«æºåããVPC IDã使ç¨ãã¾ãããªã¼ã¸ã§ã³ã¯ã使ç¨ä¸ã®ãªã¼ã¸ã§ã³åãã使ããã ããã
$ aws route53 create-vpc-association-authorization --hosted-zone-id <ãã©ã¤ãã¼ããã¹ãã¾ã¼ã³ã®ID> --vpc VPCRegion=<ãªã¼ã¸ã§ã³å>,VPCId=<ã¢ã«ã¦ã³ãBã®VPC ID> --region us-east-1 { "HostedZoneId": "ãã©ã¤ãã¼ããã¹ãã¾ã¼ã³ã®ID", "VPC": { "VPCRegion": "ãªã¼ã¸ã§ã³å", "VPCId": "ã¢ã«ã¦ã³ãBã®VPC ID" } }
â 2 ã¢ã«ã¦ã³ãBã®CloudShellã§ä»¥ä¸ã®ã³ãã³ããå®è¡ããã¢ã«ã¦ã³ã A ã®ãã©ã¤ãã¼ããã¹ãã¾ã¼ã³ã¨ã¢ã«ã¦ã³ã B ã® VPC éã®é¢é£ä»ããä½æãã¾ãã
$ aws route53 associate-vpc-with-hosted-zone --hosted-zone-id <ãã©ã¤ãã¼ããã¹ãã¾ã¼ã³ã®ID> --vpc VPCRegion=<ãªã¼ã¸ã§ã³å>,VPCId=<ã¢ã«ã¦ã³ãBã®VPC ID> --region us-east-1 { "ChangeInfo": { "Id": "/change/C102003CQ3FF", "Status": "PENDING", "SubmittedAt": "2023-06-08T14:01:01.320000+00:00", "Comment": "" } }
â 3 ã¢ã«ã¦ã³ãAã®CloudShellã«æ»ãã以ä¸ã®ã³ãã³ããå®è¡ãé¢é£ä»ãã®ç¶æ ã確èªãã¾ãã
$ aws route53 list-vpc-association-authorizations --hosted-zone-id <ãã©ã¤ãã¼ããã¹ãã¾ã¼ã³ã®ID> --region us-east-1 { "VPCs": [ { "VPCRegion": "ap-northeast-1", "VPCId": "<ã¢ã«ã¦ã³ãBã®VPC ID>" } ], "HostedZoneId": "<ãã©ã¤ãã¼ããã¹ãã¾ã¼ã³ã®ID>" }
é¢é£ä»ãããã¦ããã®ã確èªã§ãã¾ããã
â 4 ã¢ã«ã¦ã³ãBã®EC2ããã³ãã³ãã§æ¤è¨¼ãã
$ dig -t a tkm-ymmt-test.xyz ;; ANSWER SECTION: tkm-ymmt-test.xyz. 60 IN A 10.0.0.206 ;; Query time: 1 msec ;; SERVER: 10.0.0.2#53(10.0.0.2) ;; WHEN: Thu Jun 08 14:12:13 UTC 2023 ;; MSG SIZE rcvd: 62
ãã®ã¢ã«ã¦ã³ãããããã©ã¤ãã¼ããã¹ãã¾ã¼ã³ã¨VPCãé¢é£ä»ãããã¦ãããã¨ã確èªã§ãã¾ããã
注æç¹
ã¢ã«ã¦ã³ããã¾ããã ãã©ã¤ãã¼ããã¹ãã¾ã¼ã³ä½¿ç¨æã®æ³¨æç¹ã¨ãã¦ããã©ã¤ãã¼ãã¢ãã¬ã¹ãå¿çãããå ´åãåä¸VPCå ã®IPã¢ãã¬ã¹ã¸ã«ã¼ãã£ã³ã°ããªããããCIDRããããã¯ã¼ã¯ã®è¨è¨ãããå¿ è¦ãããã¾ãã
æå¾ã«
Route53ã®ãããªãã¯ãã¹ãã¾ã¼ã³ã¨ãã©ã¤ãã¼ããã¹ãã¾ã¼ã³ã使ã£ã¦ãã¹ããªãããã¥ã¼DNSãå®è£
ãã¦ã¿ã¾ããã
ãã®è¨äºããå½¹ã«ãã¦ãã°å¹¸ãã§ãã