2019-03-01ãã1ã¶æéã®è¨äºä¸è¦§
ããã«ã¡ã¯ãAWSã»ã¼ã«ã¹ã¨ã³ã¸ãã¢ã®å è¤ä¸åã§ãã ä½ãã¨ç¹ãã£ã¦ãããæ¨ä»ã§ãã ãããªæãDirect Connect Gatewayã®ãã«ãã¢ã«ã¦ã³ã対å¿ã®çºè¡¨ãããã¾ããã®ã§ãã«ã³ã¨å ±åãã¾ãã å¾æ¥ã®Direct Connect Gatewayã¯ã©ãã ã£ãï¼ Direct Connect Gatâ¦
ããã«ã¡ã¯ããµã¼ãã¼ã¯ã¼ã¯ã¹ã®ãããã®äººãåæ¬ï¼@t_sakamï¼ã§ããæ¬æ¥ãOrganizationsã®æ©è½ã¢ãããã¼ããçºè¡¨ããã¾ããããã®ã¢ãããã¼ãã§ããã¾ã¾ã§ãã£ããã¨ããè¨å®ããã§ããªãã£ãSCPï¼ãµã¼ãã¹ã³ã³ããã¼ã«ããªã·ã¼ï¼ã§ãResourceãããCondiâ¦
SQSåãã®VPC Endpoint (Private Link)ãå©ç¨ããã¨ãã®æ³¨æç¹ã§ããç¹ã«ãAWS CLIããå©ç¨ã®æ¹ã ãªãæ¬ããã°ã§ã¯ãä¸è¨ã®ãã¼ã¸ã§ã³ã®AWS CLIã§æ¤è¨¼ãè¡ã£ã¦ãã¾ããï¼2019/03/03æç¹ã§ææ°ï¼ [ec2-user@swx-bastion-l01 ~]$ aws --version aws-cli/1.16.â¦
ããã«ã¡ã¯ã3æããæè¡1課ã«æ£å¼é å±ã¨ãªãã¾ããå è¤åä¹ã§ãã ç ä¿®ãOJTã®1å¹´éãçµã¦ã¤ãã«é å±ã§ããé å¼µãããããã ãã¦ä»åã¯ãã¢ã«ã¦ã³ãå ã«ããCloudFormation(以å¾ãCFn)ã¹ã¿ãã¯å ¨ã¦ã®åé¤ä¿è·ãæå¹åããã¹ã¯ãªãããä½æããã®ã§ãæ°ãã¤â¦
ããã«ã¡ã¯ãæè¡3課ã®åã§ãã ä»åã¯AWSã§ActiveDirectoryï¼ä»¥éãADï¼ç°å¢ã«ã¦SSMãå©ç¨ããä¸ã§ããã£ããã¤ã³ãããã£ãã®ã§ãå ±æãããã¨æãã¾ãã æåã«ã¾ã¨ãã®3è¡ é·ããªããããªã®ã§ãæåã«ã¾ã¨ãã¦ããã¾ãã SSMãVPCã¨ã³ããã¤ã³ãçµç±ã§å©â¦
宮澤ã§ãã ä»åã¯ãOneLoginã¨WorkSpacesãçµã¿åããã¦ã2段éèªè¨¼ãå®ç¾ããæé ãç´¹ä»ãã¾ãã ç´¹ä»ããæé ã¯ãäºé ã®åææ¡ä»¶ãæ§ç¯ãè¨å®ããã¦ããå¿ è¦ãããã¾ãã åææ¡ä»¶ Active Directoryã¨AWS Directry Serviceã®AD Conectorãé£æºãã¦ãã htâ¦
ããã«ã¡ã¯ãæè¡3課ã®åã§ãã 3æã§æãå¤ããã¾ãã¦ãæè¡4課âæè¡3課ã«ç°åã¨ãªãã¾ããã ãã¦ã以åã«å½ç¤¾æ¸¡è¾ºãã¨ãããã¨ã§ä¸è¨ç´¹ä»ãã¦ã¾ãããAWS CLIã§ãç°¡åã«ããã¾ãããã¨ããã¨ããããè¦ããããã¨æãã¾ãã EBSã«ã¿ã°ãã¤ããã¹ã¯ãªããâ¦
ã¯ããã« æè¡ä¸èª²ã®å±±ä¸ã§ãã å æ¥ååã«ã®ãããã¦ä»¥ä¸ãè³¼å ¥ãã¾ããã Yubico | YubiKey 5C Nano Security Key | USB-C | Strong authentication å©ç¨ãã¦ã¿ã¦ããã便å©ãªãã¨ã¯å®æã§ããã®ã§ããããã¾ãã¡ä»ã¾ã§ã®èªè¨¼æ¹å¼ã¨ä½ãéãã®ãããããªãâ¦
ã¯ããã« æè¡ä¸èª²ã®å±±ä¸ã§ãã S3 ã®ã³ã³ãã³ãã«å¯¾ã㦠CloudFront 㨠Lambda@Edge ãå©ç¨ã㦠Basic èªè¨¼ãããããã¨ã®è¦æããã£ãã®ã§ãæ¤è¨¼ãã¦ã¿ã¾ããã äºåæºå S3 ãã±ããã®ä½æ éçã³ã³ãã³ããé ç½®ããããã® S3 ãã±ãããä½æãã¦ãã ããâ¦