ããã«ã¡ã¯ãEnterprise Cloudé¨ ã½ãªã¥ã¼ã·ã§ã³ã¢ã¼ããã¯ã1課 宮形 ã§ãã
ä»äºæãã¸ã¿ã«åºã®ãã¼ã ãºã¼ã¸ãè¦ãæ©ä¼ãå¤ãã®ã§ãããå人çãªææã§ã¬ã¤ã¢ã¦ããã·ã³ãã«ã§è¦ãããããã«å é²çã»æªæ¥çã§ã«ãã³ãããªã¨æã£ã¦ãã¾ãããæåãã©ã³ãã¯ãªã¼ãã³ã½ã¼ã¹æ¸ä½ã§ããGoogle Noto Sans ãªã®ã ããã§ããApache License 2.0 ã®ã©ã¤ã»ã³ã¹ã«ã¼ã«ã®ãã¨ç¡åå©ç¨ã»åé å¸ãèªãããã¦ããã¨ã®ãã¨ã§ãå¼ç¤¾BLOGã§ãå®å¿ãã¦è¡¨è¨ãããã¨ãåºæ¥ããã§ããã
æ¬BLOG㯠令å6年度ã¬ãã¡ã³ãã¯ã©ã¦ãæ©æ移è¡å£ä½æ¤è¨¼äºæ¥ ãã移è¡æ¤è¨¼ã¨ãªã£ã GCAS ã«ã¤ãã¦ã¨ããã®èªè¨¼çµ±åã«å©ç¨ãã AWS IAM Identity Center ã«ã¤ãã¦èªåã®ç解ãæ´çãããã¾ã¨ããå 容ã¨ãªãã¾ãããã¸ã¿ã«åºã®è³æã«ããã¼ã¯ã¼ãã¨ãã¦ç»å ´ããæ©ä¼ãå¤ããªã£ã¦ããã®ã§ããããæ©ã«ãç¥ãã«ãªãããæ¹ã«ãåèã«ãªãã°å¹¸ãã§ãã
- GCAS ã¨ã¯
- GCAS 移è¡ã«ããã AWS IAM Identity Center ã®å½¹å²ã¨ã¯
- GCAS 㨠AWS ãèªè¨¼çµ±åããã¡ãªããã¾ã¨ã
- ææ
GCAS ã¨ã¯
GCAS ã¨ã¯ãGovernment Cloud Assistant Serviceï¼ã¬ãã¡ã³ãã¯ã©ã¦ãæ´»ç¨æ¯æ´ãµã¼ãã¹ãã®ç¥ç§°ã¨ãªãã¾ãããã¸ã¿ã«åºãéå¶ããã¬ãã¡ã³ãã¯ã©ã¦ãã®å©ç¨è åãã®ãµãã¼ããã¼ã¿ã«ãµã¤ãã¨ããä½ç½®ã¥ããã¨æã£ã¦ããã¾ããæ¬BLOGå·çæç¹ã§ã¯ç§ãã¾ã ãã¼ã¿ã«ãµã¤ããè¦ããã¨ããªãã®ã§ãããGoogle Cloud ãæ´»ç¨ãã¦ãããã㧠Google ã®ãã¼ã ãºã¼ã¸*1ã§ã¯ä¸è¨æ©è½ãå®è£ ãããã¨ç´¹ä»ããã¦ãã¾ãã
- GCAS æ©è½æç²
- ã¦ã¼ã¶ã¼ç»é²ã»èªè¨¼
- å©ç¨ã¬ã¤ã
- ã·ã¹ãã æ å ±ç»é²ã»ç°å¢æåºç³è«
- ãã«ããã¹ã¯ã»FAQ
- å ¨ä½ EBPM ããã·ã¥ãã¼ã
GCAS 移è¡ã«ããã AWS IAM Identity Center ã®å½¹å²ã¨ã¯
ãã®GCASã§ãããæ¬BLOGå·çæç¹(2024å¹´4æ)ã§ã¯æ¢ã«ãªãªã¼ã¹ããã¦ãã*2 ä¸é¨æ©è½ãå©ç¨å¯è½ã§ãä»å¾é 次 æ©è½ãæ¡å ãããããã§ãããã®æ©è½ã®ä¸ã«ãã¬ãã¡ã³ãã¯ã©ã¦ãã®åCSP(AWSãAzureãGoogle CloudãOCI...) 管çGUI(ã³ã³ã½ã¼ã«)ã¸ã®SSOããããã¾ãã
- SSOã¨ã¯
- ã·ã³ã°ã«ãµã¤ã³ãªã³ï¼1度ã®ã¦ã¼ã¶ã¼èªè¨¼ã§è¤æ°ã®ã·ã¹ãã ã®å©ç¨ãå¯è½ã«ãªãä»çµã¿
AWSã®ç®¡çGUIã«ããã AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã« ã«ãããã®SSOãè¡ãããã«è¤æ°ã®ææ³ãæä¾ããã¦ãã¾ãããGCASã§ã¯ AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã¨ã®SSOã®å®ç¾ã« AWS IAM Identity Center ãå©ç¨ãããããã§ãããã® AWS IAM Identity Center ã®å©ç¨ã«ããå¾æ¥ AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã®ãã°ã¤ã³èªè¨¼ã«å©ç¨ãã¦ããIAMã¦ã¼ã¶ã¼ãä¸è¦ã¨ãªãæçµçã«ã¯ã¬ãã¡ã³ãã¯ã©ã¦ãã§ã¯IAMã¦ã¼ã¶ã¼ã®å©ç¨ãå»æ¢ããã¾ããæ¬BLOGã§ã¯ãããGCAS移è¡ã¨è¡¨è¨ãã¾ãããã®GCAS移è¡ã«ããã AWS IAM Identity Center ã®å½¹å²ãã¿ã¦ããããã¨æãã¾ãã
AWSå ¬å¼ãã¼ã¸ã§ã¯ä¸è¨ã®ããã«ç´¹ä»ããã¦ãã¾ãã
AWS IAM ã¢ã¤ãã³ãã£ãã£ã»ã³ã¿ã¼ã¯ãAWS ã¢ããªã±ã¼ã·ã§ã³ãããã¯è¤æ°ã® AWS ã¢ã«ã¦ã³ã (ã¾ãã¯ãã®ä¸¡æ¹) ã«å¯¾ããã¯ã¼ã¯ãã©ã¼ã¹ã®ã¢ã¯ã»ã¹ã管çããããã«æ¨å¥¨ããããµã¼ãã¹ã§ããããã¯ãæ¢åã® ID ã½ã¼ã¹ãæ¥ç¶ããããAWS ã§ã¦ã¼ã¶ã¼ãä½æãããããããã«ä½¿ç¨ã§ããæè»ãªã½ãªã¥ã¼ã·ã§ã³ã§ããIAM ã¢ã¤ãã³ãã£ãã£ã»ã³ã¿ã¼ã¯ãæ¢åã® AWS ã¢ã«ã¦ã³ãã®ã¢ã¯ã»ã¹è¨å®ã¨ã¨ãã«ä½¿ç¨ã§ãã¾ãã
ã¾ã㯠AWS IAM Identity Center ãå©ç¨ããªãéç¨ããã¿ã¦ããã¾ããAWSã§ã¯ ã¢ã«ã¦ã³ã (以ä¸AWSã¢ã«ã¦ã³ãã¨è¨) ã¨ããæ ã§è«æ±ã管çãåºå¥ãã¦ãã¾ãããã®AWSã¢ã«ã¦ã³ãæ¯ã«ç®¡çGUIã«ããã AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã« ãç¨æããã¾ããä¸è¨ã¯ç§ã®å人æ¤è¨¼ç°å¢ã«ãã°ã¤ã³ããæã®ç»é¢ã·ã§ããã«ãªãã¾ãã
ãã®AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã¸ã®ãã°ã¤ã³èªè¨¼ã«å©ç¨ãããã®ã IAMã¦ã¼ã¶ã¼ ã«ãªãã¾ãããã®IAMã¦ã¼ã¶ã¼ã¯AWSã¢ã«ã¦ã³ãæ¯ã«ä½æããèªè¨¼æ å ±ã¯ã¦ã¼ã¶ã¼åã¨ãã¹ã¯ã¼ãã§æ§æããã¾ããAWSã¢ã«ã¦ã³ãã¯é¨ç½²ãç°å¢æ¯ã§å¥ã ã§ç®¡çãããã¨ãæ¨å¥¨ããã*3ã®ã§ãä¸è¨ã®å³ã®ããã«ãªãã¾ãã
ãã®ä¾ã ã¨SCOTTããããä¸äººã§è¤æ°ã®ã·ã¹ãã ãéç¨ä¿å®ãã¦ããç¶æ³ã§ããèªè¨¼æ å ±ãåAWSã¢ã«ã¦ã³ãæ¯ã«éãã¾ãã®ã§ããã¹ã¯ã¼ãã®å¤æ´ãããããè¦ãã¦ããè² æ ãå¢ãã¾ããæ©ã¾ããã§ããã
ãã®åé¡ã解決ããããã« AWS ã§ã¯æ°ã ã®ææ³ãæä¾ããã¦ãã¾ãããå®çªãªã®ã¯ãè¸ã¿å°ã¢ã«ã¦ã³ãããè¨ãã Switch Role (ãã¼ã«ã®åãæ¿ã) ã§ããä¸è¨ã®å³ã®ããã«ãªãã¾ãã
IAMã¦ã¼ã¶ã¼ã¯è¸ã¿å°ã¢ã«ã¦ã³ãã«ã®ã¿åå¨ããããããåé¨ç½²ãç°å¢æ¯ã®AWSã¢ã«ã¦ã³ãã¸åæ¿ã¦ç®¡çã»ä¿å®ãè¡ããã¨ãã§ãã¾ããå®éã®AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã§ã¯æåã®è¸ã¿å°ã¢ã«ã¦ã³ãã«ãã°ã¤ã³ãããã¨å³ä¸ã®ãã¿ã³ããæä½ãã¾ãã
å¤ãã®ã±ã¼ã¹ã§ã¯ãã®è¸ã¿å°ã¢ã«ã¦ã³ãã§ã® Switch Role æ¹å¼ã§èªè¨¼æ å ±ã®ä¹±ç«ãé²ããã¨ãã§ããéç¨ã«ããã¦ãåé¡ã¨ãªããã¨ã¯ããã¾ããã§ããããããã¯ã©ã¦ãã®æ®åã«ãããAWS以å¤ã®ãããªãã¯ã¯ã©ã¦ããSaaSãidp ãçµã¿åããã¦å©ç¨ãããã«ãã¯ã©ã¦ãã®çµç¹ãå¢ãã¦ãããã¨ã§ããããªãèªè¨¼æ å ±ã®çµ±ä¸ãå¿ è¦ã¨ãªãã¾ãããããããç¶æ³ã§æ´»ç¨ããã®ã AWS IAM Identity Center ã§ããè¸ã¿å°ã¢ã«ã¦ã³ãã®IAMã¦ã¼ã¶ã¼ã§ã¯ãªããAWS IAM Identity Center å ã§ç®¡çããã¦ã¼ã¶ã¼åããã¹ã¯ã¼ããç¨ãã¦èªè¨¼ãã¾ããä¸è¨ã®å³ã®ããã«ãªãã¾ãã
ããã ã¨è¸ã¿å°ã¢ã«ã¦ã³ãã§ã® Switch Role æ¹å¼ã¨å¤§ããå¤ãã£ã¦ãªãæ°ããã¾ããæ¯è¼ããã¨å¤ã ã¡ãªããã¯ããã®ã§ããããã§ã¯å²æãã¾ããAWS IAM Identity Center ã§ãã°ã¤ã³ããã¨ãä¸è¨ã®å³ããã«å¾æ¥ã¨ã¯ç°ãªããã¼ã¿ã«ã表示ãããä¸è¦§ããå©ç¨ãããAWSã¢ã«ã¦ã³ããã¯ãªãã¯ããã¨æ¬¡ç»é¢ã§ãã®AWSã¢ã«ã¦ã³ãã®ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã表示ããã¾ãã
ãã® AWS IAM Identity Center ã¯ãå ã»ã©è¨ãããã«ãã¯ã©ã¦ãç°å¢ãæ³å®ããæ©è½ã«ãªãã¾ããä»ã®ã¯ã©ã¦ãã¢ããªã±ã¼ã·ã§ã³ã¨ã®èªè¨¼çµ±åããæ©è½ãå å®ãã¦ãã¾ããä¾ãã°ãä¸è¨ã®å³ã®ããã«å¥ã®ã¯ã©ã¦ããµã¼ãã¹ã®idp(èªè¨¼)ãç¨ãã¦AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã¸ã¢ã¯ã»ã¹ãããã¨å¯è½ã«ãªãã¾ããã¾ããAWS以å¤ã®ã¢ããªã±ã¼ã·ã§ã³ã®èªè¨¼ã«å©ç¨ãããã¨ãã§ãã¾ããã¯ã©ã¦ãã§é »ç¹ã«å©ç¨ããã SAML ã«ããããã®ãããªæè»ãªæ§æãã¨ããããã«ãªãã¾ãã
ä»åã¬ãã¡ã³ãã¯ã©ã¦ãæ©æ移è¡å£ä½æ¤è¨¼äºæ¥ã§ç§»è¡æ¤è¨¼ãè¡ãããGCASã«ããã¦ãSAMLãå©ç¨ã§ãã¾ãã®ã§ãAWS IAM Identity Center ãç¨ãããã¨ã§ä¸è¨ã®å³ã®ããã«SSOç°å¢ãå®ç¾å¯è½ã¨ãªãã¾ããã¬ãã¡ã³ãã¯ã©ã¦ãã®AWS以å¤ã®CSP(AzureãGoogle CloudãOCI...) ã¸ã®èªè¨¼çµ±åãå®ç¾ã§ãã¾ãã
ãã®GCASã«ã¯MFAããã¤ã¹ãç¨ããå¤è¦ç´ èªè¨¼ãå®è£ ããã¾ãã®ã§ãçµæçã«AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã¸ã®æ¥ç¶ã«ãå¤è¦ç´ èªè¨¼ãä¼´ããã¨ã«ãªãããªããã¾ããé²ããã¨ãã§ãã¾ãããããã¡ãªããã次ã»ã¯ã·ã§ã³ã§ã¾ã¨ãããã¨æãã¾ãã
ãªããAWS IAM Identity Center ã¯ãã¸ã¿ã«åºã®éå¶ç®¡çã«ãªãã¾ãã®ã§ãå°æ¹èªæ²»ä½æ§ãéç¨ç®¡çè£å©è æ§(ãã³ãã¼)ãè¨å®ãéç¨ä¿å®ãããã¨ã¯ããã¾ããããã®èªè¨¼ã®å½¹å²ã¾ã§ç解ããã ããã°è¯ããã¨æãã¾ãããã詳ãããç¥ãã«ãªãããæ¹ã¯ãå¼ç¤¾ã¨ã³ã¸ãã¢BLOGããåç §ãã ããã
GCAS 㨠AWS ãèªè¨¼çµ±åããã¡ãªããã¾ã¨ã
IAMã¦ã¼ã¶ã¼ã®å©ç¨ãããã¦ãGCAS 㨠AWS IAM Identity Center ã®èªè¨¼çµ±åã¸ç§»è¡ããã¡ãªããã¨ãã¦ã¯ä¸è¨ã«ãªãè¦è§£ã§ããããããè¤æ°CSP(AWSãAzureãGoogle CloudãOCI...) ã§çµ±ä¸ã§ããã®ã¯ãããããã§ãã
- ãã°ã¤ã³ID èªè¨¼æ
å ±ã®ä¹±ç«é²æ¢
- ãã¸ã¿ã«åºãGCASä¸ã§æä¾ããã¢ããªã±ã¼ã·ã§ã³éã§ã®ã·ã³ã°ã«ãµã¤ã³ãªã³ã®å®ç¾
- AWSãã«ãã¢ã«ã¦ã³ã(è¤æ°ããã³ã) ã§ã®èªè¨¼æ å ±ã®çµ±ä¸
- ãã«ãã¯ã©ã¦ãç°å¢ä¸ã§ã®èªè¨¼æ å ±ã®çµ±ä¸
- ã»ãã¥ãªãã£ã¬ããã³ã¹ã®çµ±ä¸
- ãªããã¾ãé²æ¢
- AWSå«ããã¬ãã¡ã³ãã¯ã©ã¦ãåCSPã®ç®¡çã³ã³ã½ã¼ã«ã¸ã®ãã°ã¤ã³æMFA(å¤è¦ç´ èªè¨¼)ã®å¼·å¶ã¨çµ±ä¸
- AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã¸ã®ã¢ã¯ã»ã¹å
ããã¤ã¹ã®ç¹å®
- BeyondCorp Enterpriseï¼BCEï¼ãç¨ãããã¨ã§AWSãå«ããã¬ãã¡ã³ãã¯ã©ã¦ãåCSPã®ç®¡çã³ã³ã½ã¼ã«ã¸ã®ã¢ã¯ã»ã¹å ããã¤ã¹å¶å¾¡
- ããã¤ã¹å¶å¾¡ã«ã¯ã·ãªã¢ã«çªå·ã¨IPã¢ãã¬ã¹ãå©ç¨å¯è½ã¨ã®ã㨠*4
ãããAWSã§ã¯ã¬ã¬ã·ã¼ãªã¢ããªã±ã¼ã·ã§ã³ç IAMã¦ã¼ã¶ã¼ã§ããå®ç¾ã§ããªãã£ããã¨ãããããã§ãä¾ãã°ã¢ã¯ã»ã¹ãã¼ã®å©ç¨ãããã¾ããã¢ã¯ã»ã¹ãã¼ã¯æ¼æ´©ããã¨ã¯ã©ã¦ãä¸ã®æä½æªç¨ããããªã¹ã¯ããããã¨ãããå©ç¨é¿ãããã¨ãæ¨å¥¨ããã¦ãã¾ãããã¬ãã¡ã³ãã¯ã©ã¦ãã§ããã®èãã¯è¸è¥²ããã¦ãã¾ãããã¢ããªã±ã¼ã·ã§ã³äºæçãããå¾ãªãå ´åã¯ãå±ãåºããããã¨ã§å¯©æ»å¦¥å½ã¨å¤æãããéãã§å©ç¨ãèªããããã¨ããã¾ãã*5
é«ãã»ãã¥ãªãã£ã¯æã¨ãã¦éå»è³ç£ç¶æ¿ã®å¶ç´ã¨ãªãã¾ãããã¬ãã¡ã³ãã¯ã©ã¦ããåå¥äºæ ã«ãé æ ®ãããç¹ã¯å¥½å°è±¡ã§ããããã¡ããã¢ã¯ã»ã¹ãã¼ã®å©ç¨ã¯æ¨å¥¨ããã¾ããã®ã§ãã¢ããªã±ã¼ã·ã§ã³éçºè æ§ããµã¼ãã¹ãããã¤ãã¼æ§ã«ã¯ä»£æ¿æ¡ã¸ã®ç§»è¡ãå¼·ãæ¨å¥¨ãããã¾ãã
IAM ã§ã®ã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ - AWS Identity and Access Management
ææ
ãããã§ããã§ããããããã¸ã¿ã«åºã®GCASã¬ã¤ãã«ããã¨ãIAMã¦ã¼ã¶ã¼ã®å»æ¢ã¨ GCASã¢ã«ã¦ã³ãã¸ã®åæ¿ã¯ä»¤å6å¹´12æã¾ã§ã«å®äºããå¿ è¦ãããã¨è¨è¼ããã¦ãã¾ããæ©æ移è¡å£ä½æ¤è¨¼äºæ¥ã§æ¢ã«ã¬ãã¡ã³ãã¯ã©ã¦ããå©ç¨éå§ããã¦ããå°æ¹èªæ²»ä½æ§ã¯ããã¸ã¿ã«åºããã®æéã«åºã¥ãGCASã¸ã®ç§»è¡å¯¾å¿ãè¡ãå¿ è¦ãããã¾ããããããAWS ã Google Cloud ã®å°éç¨èªãé£ã³äº¤ãåè³æãã¬ã¤ãã©ã¤ã³ãã¿ã¦ãä½ããæãä»ãã¦ãããæ©ã¾ãã¦ããæ¹ãå¤ãã®ã§ã¯ã¨äºæ³ãã¾ããå¶ç´ãå¤ãå°è±¡ãåãã¾ãããã»ãã¥ãªãã£ãéç¨ã³ã¹ãã®å´é¢ã§ã¯å¤ãã®ã¡ãªãããããããæãã¾ãã®ã§ããã²ã¯ã©ã¦ãå©æ´»ç¨ã®æ¨é²ã«ãå½¹ç«ã¡ããã ããã°ã¨æãã¾ããæ¬BLOGã®å 容ãçæ§ã®å°ãã§ãã®ãåèã«ãªãã°å¹¸ãã§ãã
æ¬BLOGã¯ééãããªãããåå注æãã¦è¨è¼ãã¦ããã¾ããããã¸ã¿ã«åºã®è³æã¨å·®ç°ãããå ´åã¯ãã¡ããæ£ã¨ãã¦ããã ãã¾ããããé¡ããã¾ãã
*1:Google Cloud ãããã¸ã¿ã«åºã¬ãã¡ã³ãã¯ã©ã¦ãã®å©ç¨ãä¿é²ãããµã¼ãã¬ã¹ã® Web ã¢ããªã±ã¼ã·ã§ã³éçºãæ¯æ´ : https://cloud.google.com/blog/ja/products/gcp/application-development-to-accelerate-the-use-of-the-government-cloud/
*2:ãã¸ã¿ã«åº - å®å ¨ã»å®å¿ã§å¼·é±ãªãã¸ã¿ã«åºç¤ã®å®ç¾ : https://www.digital.go.jp/policies/report-202209-202308/digital-infrastructure
*3:AWS Well-Architected Framework - SEC01-BP01 ã¢ã«ã¦ã³ãã使ç¨ãã¦ã¯ã¼ã¯ãã¼ããåãã: : https://docs.aws.amazon.com/ja_jp/wellarchitected/latest/security-pillar/sec_securely_operate_multi_accounts.html
*4:æ¬BLOGå·çæç¹ ãã¸ã¿ã«åº GCASã¬ã¤ã - CSP管çGUIã¸ã®æ¥ç¶å ã¢ã¯ã»ã¹å å¶å¾¡ åç §
*5:æ¬BLOGå·çæç¹ ãã¸ã¿ã«åº GCASã¬ã¤ã - ã¦ã¼ã¶ã¼ç®¡çæ¹æ³(AWSç·¨)
宮形ç´å¹³(å·çè¨äºã®ä¸è¦§)
ã¨ã³ã¿ã¼ãã©ã¤ãºã¯ã©ã¦ãé¨ ã½ãªã¥ã¼ã·ã§ã³ã¢ã¼ããã¯ã1課
好ããªãé ã¯ç¼¶ãã¥ã¼ãã¤ã¨æ¬æ ¼ç¼é