2022-06-01ãã1ã¶æéã®è¨äºä¸è¦§
ã¯ãã㫠対象è åæã¨ç°å¢æºåã®å 容 Cloud9ã«ã¤ã㦠Cloud9æ¦è¦ï¼ ã¡ãªããï¼ Cloud9ã®ç°å¢æºå SAMã«ã¤ã㦠AWS SAM ãã³ãã¬ã¼ã SAMè¦ç´ï¼ ã¡ãªããï¼ ããã¸ã§ã¯ãéå§ sam init sam build sam deploy StateMachineã®å®è¡ åèæç® ã¯ããã« SRE1課ã®â¦
ããã«ã¡ã¯ï¼ å¶æ¥é¨ã®æ± æ°¸ã§ãã ãã®åº¦AWS Certified Solutions Architect - Professionalã®èªå®ãåå¾ãã¾ããã ã¹ã³ã¢ï¼798 ä»åã®è¨äºã§ã¯ãAWSæ´2å¹´ãå¶æ¥è·ã®ç§ã§ã1åã®åé¨ã§åæ ¼ã§ããåå¼·æ¹æ³ããä¼ãã§ããã°ã¨æãã¾ãã ç§ã®çµæ´ æç³»ï¼å¹´å¤§â¦
ããã«ã¡ã¯ãã©ã¼ãã³ã°ã¨ã¯ã¹ããªã¨ã³ã¹èª²ã®å°åã§ããå æ¥ã2022å¹´4æã«ãªãªã¼ã¹ãããæ°ããAWSèªå®ãAWS Certified: SAP on AWS - Specialty 試é¨ã«åæ ¼ãã¾ãããä»ã®ã¨ãããå»æ¢ã«ãªã£ã2ã¤ã®èªå®ãã¾ã æå¹æéå ãªã®ã§ãAWSèªå®ã¯14å ã§ãã ãã¼ã¿â¦
æåã§CloudWatch ã¨ã¼ã¸ã§ã³ãè¨å®ãã¡ã¤ã«ãä½æããã¯ãããã®ã®ããããããè¨å®ãã¡ã¤ã«ã©ãï¼ã©ãï¼ã ã£ããããããã¨ãªã£ãæã«è¦ã¤ãåºããã³ããç´¹ä»
ããã«ã¡ã¯ãAWS CLIã好ããªç¦å³¶ã§ãã ã¯ããã« åè GuardDutyã¨ã¯ S3ã®æ¤åºã¿ã¤ãã«ã¤ã㦠æ¦è¦ å ¨ä½ 1. Discovery 2. Exfiltration 3. Impact 4. PenTest 5. Policy 5. Stealth 6. UnauthorizedAccess ã¢ã©ã¼ãã®å¯¾å¿æ¹æ³ çµããã« ã¯ããã« ä»åã¯ã以â¦
ããã«ã¡ã¯ï¼æè¡1課ã濱岡ã§ãã ã¿ãªããã¯ãç®çç¼ãã«ã¯å¡©æ´¾ï¼é¤æ²¹æ´¾ï¼ã½ã¼ã¹æ´¾ï¼ã®ã©ãã§ããï¼ ç§ã¯åºæ¬ä½ãã¤ããã«é£ãã³ã«ä¹ã£ãã¦é£ã¹ã¦ããã®ã§ãããªæ´¾é¥ããããã ãªã¨æãã¾ããã ãã¦ãä»åã¯AWS Systems Managerã®ãã©ã¡ã¼ã¿ã¹ãã¢ã®ã話ã§â¦
ããã«ã¡ã¯ãå±±ä¸ã§ãã AWS Lambda ã§ã¨ãããããµã¯ã㨠AWS ã®å種ãµã¼ãã¹ãåããããã°ã©ã ãè¼ãã¦ãã¾ãã â» æ£å¸¸ç³»ã®ã¿ (ã¨ã©ã¼å¦çãªã©ã¯æ¸ãã¦ããªã) ãªã®ã§ãããã¾ã§æ¤è¨¼ç°å¢ã§è©¦ããã¨ãæ³å®ãã¦ãã¾ãã ä»å㯠AWS Lambda 㧠EC2 ã¤ã³ã¹ã¿â¦
CIé¨SRE1課ã®å¤å·(æº)ã§ãã Windows端æ«ã§ã·ã§ã«ã¹ã¯ãªãããç·¨éãããã/bin/sh^M: bad interpreter: No such file or directoryãã¨ããã¨ã©ã¼ãåºã¦ãã¾ããã ä»åã¯ãããªã¨ãã®å¯¾å¦æ³ã«ã¤ãã¦æ¸ãã¦ããã¾ãã ç¶æ³ 解決æ¹æ³ ç¾å¨ã®ãã¡ã¤ã«ãã©ã¼ãâ¦
ã«ã¹ã¿ãã¼ãµã¯ã»ã¹é¨ ä½ç«¹ã§ãã æ¬æ¥ã¯ãAmazon RDS ã«ããã Multi-AZ ãªãã·ã§ã³ã DB ã¨ã³ã¸ã³ãã¨ã«æ´çããç®çã§ããã°ãè¨è¼ãã¾ããRDS ã® Multi-AZ DB cluster ãåºããã¨ã§ Multi-AZ ãªãã·ã§ã³ãè¤éã«ãªã£ãã¨æãã¾ãããæ¬ããã°ãèªããã¨â¦
ããã«ã¡ã¯ãå±±ä¸ã§ãã AWS Lambda ã§ã¨ãããããµã¯ã㨠AWS ã®å種ãµã¼ãã¹ãåããããã°ã©ã ãè¼ãã¦ãã¾ãã â» æ£å¸¸ç³»ã®ã¿ (ã¨ã©ã¼å¦çãªã©ã¯æ¸ãã¦ããªã) ãªã®ã§ãããã¾ã§æ¤è¨¼ç°å¢ã§è©¦ããã¨ãæ³å®ãã¦ãã¾ãã ä»å㯠AWS Lambda 㧠EC2 ã¤ã³ã¹ã¿â¦
ããã«ã¡ã¯ãã¤ã¼ã´ãªã§ãï¼ ããã©ã¤ãã¼ããµããããã«ããEC2ã¤ã³ã¹ã¿ã³ã¹ã«è¸å°ãµã¼ãã使ããã«OSãã°ã¤ã³ããã«ã¯ã©ãããã°è¯ãã®ï¼ãã¨çåã«æãæ¹ã¸ãæ¬æ¥ã®è¨äºã§VPC ã¨ã³ããã¤ã³ãããç´¹ä»ãããã¨æãã¾ãã è¨äºã®ç®æ¨ 解決æ¹æ³ VPC ã¨ã³ããâ¦
ããã«ã¡ã¯ãå±±ä¸ã§ãã AWS Lambda ã§ã¨ãããããµã¯ã㨠AWS ã®å種ãµã¼ãã¹ãåããããã°ã©ã ãè¼ãã¦ãã¾ãã â» æ£å¸¸ç³»ã®ã¿ (ã¨ã©ã¼å¦çãªã©ã¯æ¸ãã¦ããªã) ãªã®ã§ãããã¾ã§æ¤è¨¼ç°å¢ã§è©¦ããã¨ãæ³å®ãã¦ãã¾ãã ä»å㯠AWS Lambda 㧠EC2 ã®åæ¢ãâ¦
ããã«ã¡ã¯ãAWS CLIã好ããªç¦å³¶ã§ãã ã¯ããã« åè GuardDutyã¨ã¯ IAMã®æ¤åºã¿ã¤ãã«ã¤ã㦠æ¦è¦ å ¨ä½ 1. AnomalousBehavior(æ¤åºèå¥å) 1.1. Exfiltration:IAMUser/AnomalousBehavior 1.2. Impact:IAMUser/AnomalousBehavior 1.3. CredentialAccess:IAâ¦
ããã«ã¡ã¯ãã¯ã©ã¦ãã¤ã³ãã°ã¬ã¼ã·ã§ã³2é¨ æè¡1課 宮形 ã§ãã ååãåã åBLOGã§ããªã³ãã¬ãã¹ Microsoft Active Directory ãµã¼ãã¼ (以ä¸ADãµã¼ãã¼) ãããAWS Managed Microsoft AD (ä»¥ä¸ Managed MSAD) ã¸ãã¦ã¼ã¶ã¼ã¢ã«ã¦ã³ããã³ã³ãã¥ã¼ã¿ãã°â¦
ããã«ã¡ã¯ãå±±ä¸ã§ãã AWS Lambda ã§ã¨ãããããµã¯ã㨠AWS ã®å種ãµã¼ãã¹ãåããããã°ã©ã ãè¼ãã¦ãã¾ãã â» æ£å¸¸ç³»ã®ã¿ (ã¨ã©ã¼å¦çãªã©ã¯æ¸ãã¦ããªã) ãªã®ã§ãããã¾ã§æ¤è¨¼ç°å¢ã§è©¦ããã¨ãæ³å®ãã¦ãã¾ãã ä»å㯠AWS Lambda 㧠EC2 ã®èµ·åãâ¦
ç¥ã¢ããæ¥ã¾ããï¼ aws.amazon.com Before å¾æ¥ã®AWS Step Functionsï¼ä»¥ä¸Step Functionsï¼ã®ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã®ã¤ãã³ãå±¥æ´ã¯ä»¥ä¸ã®ãããªUIã§ããã éç¨ã®ä¸ã«ããã¦ä»¥ä¸ã®ãããªèª²é¡ãããã¾ãããç¹ã«ã¤ãã³ã件æ°ãä½åã¨ãã£ãã¬ãã«ã§ããâ¦
ããã«ã¡ã¯ãAWS CLIã好ããªç¦å³¶ã§ãã ã¯ããã« åè GuardDutyã¨ã¯ EC2ã®æ¤åºã¿ã¤ãã«ã¤ã㦠æ¦è¦ å ¨ä½ 1. Backdoor 2. Behavior 3. CryptoCurrency 4. Impact 5. Recon 6. Trojan 7. UnauthorizedAccess 対å¿æ¹æ³ EC2ã侵害ãããå ´å æªãããã¡ã¤ã³ã¸â¦
ã¯ããã« ããã«ã¡ã¯ãã¢ããªã±ã¼ã·ã§ã³ãµã¼ãã¹é¨ æ²³éã§ãã åå¹´ç¨åã«ãServerless Framework 3 ç³»ããªãªã¼ã¹ããã¾ããã ç¾å¨ã® latest ãã¼ã¸ã§ã³ã¯ 3.19.0 ã§ãã ããããã3 ç³»ã«ã¢ããã°ã¬ã¼ãããããªã¨æãç«ã¡ãå¤æ´ç¹ã¯ææ¡ãã¦ãããã¨ããâ¦
ããã£ã¦ã¿ããYubikeyãè²·ã£ãã®ã§å¤è¦ç´ èªè¨¼ã®è¨å®ãããã楽ã«ãªã£ãï¼
ããã«ã¡ãï¼ãµã¼ãã¼ã¯ã¼ã¯ã¹æ¥æ¬æå端社å¡ã®ä¹ ä¿çäºï¼ãã¼ãã¾ãï¼ã§ããæè¿ã®æ²ç¸ã¯æ¢ é¨ææã§æ¹¿åº¦ããããäºã«ãªã£ã¦ã¾ãã ãã¦ä»åã¯Yubikeyãªãå¤è¦ç´ èªè¨¼ã®ãã¼ãã¦ã§ã¢ãè³¼å ¥ãã¾ããã®ã§ãAWS IAMã¦ã¼ã¶ã¼ã§ã®ãã°ã¤ã³ãOneLoginã§å©ç¨ã§ãããâ¦
Amazon Connectã¯é¡§å®¢ã¨ã®é話ãåãæ±ãæ©è½ã§ãã é話è¨é²ã«ã¯é¡§å®¢ã®é»è©±çªå·ãå ¥åå 容ãå«ã¾ãã¾ãããCRMçã¨ãã¼ã¿çµ±åãã¦ããå ´åã¯ä¼æ¥åã»æ°åçã®æ å ±ãåãåããå±æ§ããã°ã«å«ã¾ããã±ã¼ã¹ãããã¾ããã ãããã¯æ©å¯ã¬ãã«ã®é«ãæ å ±ã§ããâ¦
ããã«ã¡ã¯ãã¯ã©ã¦ãã¤ã³ãã°ã¬ã¼ã·ã§ã³2é¨ æè¡1課 宮形 ã§ãã AWS ã¸ãªã³ãã¬ãã¹ç°å¢ã移è¡ããéãMicrosoft Active Directory ãµã¼ãã¼ (以ä¸ADãµã¼ãã¼)ãã©ã®ããã«ãããæ¯åº¦æ¤è¨ã«ãããã¾ãã ãEC2 ã«ADãµã¼ãã¼ã¤ã³ã¹ãã¼ã«ãã¦ç§»è¡ããããéâ¦
ããã«ã¡ã¯ãã¯ã©ã¦ãã¤ã³ãã°ã¬ã¼ã·ã§ã³2é¨ æè¡1課 宮形 ã§ãã ååBLOGã§ã¯ãActive Directory 移è¡ãã¼ã«ããã (ä»¥ä¸ ADMT) 㨠ãã¹ã¯ã¼ãã¨ã¯ã¹ãã¼ããµã¼ãã¹ (ä»¥ä¸ PES) ãç¨ã㦠ãªã³ãã¬ãã¹ Microsoft Active Directory ãµã¼ãã¼ (以ä¸ADãµã¼ãâ¦
ï¼£ï½ï½ï½ï½ï½ ãã©ã¦ã¶ã«ãããå¼·å¶ãªãã¼ãã®æ¹æ³ã§ãã ãã£ãã·ã¥ã¨ã¯ åé¡ç¹ ï¼£ï½romeãã©ã¦ã¶ã«ãããæé æ¡ä»¶ ãããããã¼ãã¼ã«ã表示 ãã£ãã·ã¥ã®æ¶å»ã¨ãã¼ãåèªã¿è¾¼ã¿ãå®æ½ åè å¤ãã®è¦ç´ ããã£ãã·ã¥ãã表示ããå ´å Webãµã¼ãã¼ããèªã¿â¦
CI2é¨ã®å±±ï¨ã§ãã IAMããã¥ã¡ã³ãã®æ´æ°å±¥æ´ãè¦ãæ©ä¼ããããããã§ã¢ã¯ã»ã¹ããªã·ã¼ã®è©ä¾¡ãã¸ãã¯ãæ´æ°ããã¦ãã¾ããã®ã§ããã®ç¹ã«ã¤ãã¦ç°¡åã«ãç´¹ä»ããã¦é ãã¾ãã ã¯ããã« å¤æ´ç¹ æ´æ°å æ´æ°å¾ å種ã¢ã¯ã»ã¹ããªã·ã¼ã«ã¤ã㦠æå¦ã®è©ä¾¡ï¼æâ¦
ã«ã¹ã¿ãã¼ãµã¯ã»ã¹é¨ ä½ç«¹ã§ãã æ¬æ¥ã¯ã³ã¹ãæé©åã®ããã«æå¹ãªãAmazon EBS Snapshots Archiveãã¨ãRecycle Binããçµã¿åãã㦠AMI ã¨ç´ã¥ã Snapshot ãã¢ã¼ã«ã¤ãããæ¹æ³ã«ã¤ãã¦è¨è¼ãã¾ãã
ããã«ã¡ã¯ï¼ã¤ã¼ã´ãªã§ãã ä¸è¨ã®æ¹æ³ã使ãã°ãWindowsã§ä»»æã®ãµã¤ãºã®ãã¡ã¤ã«ãä½æãããã¨ãã§ãã¾ããï¼ fsutilã³ãã³ãï¼CMD / PowerShellï¼ ä¾ãã°ãä½ãããã®ãã¹ãã®ããã«ããã©ã¤ãCã§ç´10MBï¼10MBã¯10485760ã¨ãªãã¾ããã10000000ãå ¥åãâ¦
ããã«ã¡ã¯ãå±æ ¹è£ã¨ã³ã¸ãã¢ã®ææ¸ã§ã ã¤ãã«å±æ ¹è£ã«ã¨ã¢ã³ã³ãåãä»ãã¾ãã ãã®å¤ã¯å¿«é©ã«ä»äºãã§ãããã§ãã ã¯ããã« Amazon API Gateway ãã©ã¤ãã¼ãçµ±åã¨ã¯ åæ VPCãªã³ã¯ ä½æ API Gateway REST API ä½æ ãªã½ã¼ã¹ ä½æ ãã¹ã å®è¡ API â¦
ããã«ã¡ã¯ï¼ã¤ã¼ã´ãªã§ãã Amazon ECS 㧠Amazon ECR ã®ã¤ã¡ã¼ã¸ãããã¿ã¹ã¯å®ç¾©ãæå®ããããã¹ãã¼ã¿ã¹ããRUNNINGãã§ã¯ãªãããSTOPPEDãã«ãªã£ãå ´åï¼ä½ãããã®ECSã®ã¨ã©ã¼ãçºçããå ´åï¼ãã©ããã£ã¦è§£æ±ºããã°ãããããã®è¨äºã§ãç´¹ä»ããã¦â¦
ã¯ããã« æ¥æ¿ã«æ°æ¸©ãä¸ãã£ã¦ãã¦ãã¨ã¢ã³ã³ãå ¥ãããå ¥ããªãããè¿·ããããã Lambdaã®éçºç°å¢ã¥ãããèããªãã¨ãããªããªã¨æã£ãã ã¢ããªã±ã¼ã·ã§ã³ãµã¼ãã¹é¨ã®æ£®ã§ãã ä»åã¯Lambdaé¢æ°ãä½ãã¨ãã®éçºç°å¢ã¥ããã«ã¤ãã¦ã®ããã°ã§ãã ãã®â¦
ããã«ã¡ã¯ï¼ã¤ã¼ã´ãªã§ãã ååã®ECSè¨äºã®ç¶ãã¨ãã¦ãä»åã®è¨äºã§ã¯ãAmazon Elastic Container Service (Fargate)ããç´¹ä»ãããã¨æãã¾ãã Fargate 㨠EC2 Linux + ãããã¯ã¼ãã³ã° ã®æ¯è¼ ECSã¯ã©ã¹ã¿ã¼ã®ä½æ ã¿ã¹ã¯å®ç¾©ã®ä½æ ã¿ã¹ã¯å®ç¾©ã®èµ·åâ¦
ããã«ã¡ã¯ãã¯ã©ã¦ãã¤ã³ãã°ã¬ã¼ã·ã§ã³2é¨ æè¡1課 宮形 ã§ãã Amazon Cognito (ä»¥ä¸ Cognito)ã®å°å ¥ã§ãCognito Hosted UI ã«ã¦ç¬èªãã¡ã¤ã³ãå©ç¨ããå ´åã®ããããã¤ã³ãã«ééããã®ã§ãæ¬BLOGã«ã¦ç´¹ä»ããã¦ããã ãã¾ãã åæç°å¢ã¨ããããäº ãâ¦
CloudFormation ã§çæãããã¼ãã¢ã®ä»æ§ æ¤è¨ããã㨠çµæ ã¹ã¯ãªãã 使ãæ¹ ãããã« æè¡ 1 課ã®æ°´æ¬ã§ããæè¿ã¯é常ã®æ¥åã®åéã§ã¹ã¯ãªãããæ¸ãããã社å ã®å質管ççãé²ããããã¦ãã¾ãã ãã¦ãä»å㯠CloudFormation ã§ä½æãããã¼ãã¢ãâ¦
æè¡2課ã®æ¾ç°ã§ããããã«ã¡ã¯ã ä»åã¯AWS CloudFormation StackSetsã使ã£ã¦AWS Organizationsé ä¸ã®ã¢ã«ã¦ã³ãã«IAM Roleãä¸æ¬ãããã¤ããæ¹æ³ã«ã¤ãã¦è§£èª¬ãã¾ãã ä»åã®æ§æ å©ç¨ãµã¼ãã¹ã«ã¤ã㦠AWS Organizationsã«ã¤ã㦠AWSãµã¼ãã¹ã®çµ±å Serâ¦
ã³ã¼ãã¼ã好ããªæ¨è°·æ è¦ã§ãã æ¬æ¥ã¯ãAWS Systems Manager ã®ã»ãã·ã§ã³ããã¼ã¸ã£ã¼ã使ç¨ãããªã¢ã¼ããã¹ãã¸ã®ãã¼ããã©ã¯ã¼ããå¶éãã¦ã¿ã¾ãã ã»ãã·ã§ã³ããã¼ã¸ã£ã¼ã§ãªã¢ã¼ããã¹ãã¸ã®ãã¼ããã©ã¯ã¼ããå¶éããçµç·¯ æºåï¼ãªã¢ã¼ããã¹ãâ¦
ããã«ã¡ã¯ãããã¼ã¸ããµã¼ãã¹é¨MSï¼èª²ã®å¡©éã§ãã æè¿é³å£°åæã½ããã試ãæ©ä¼ããã£ã¦ãè²ã 調ã¹ã¦ãããã¡ã«PowerShellã®ã³ãã³ãã©ã¤ã³ããããã¹ããããã¨ãã§ããã¨ãããã¨ãç¥ã£ãã®ã§ã試ãããã¨ãã¾ã¨ãã¦ã¿ã¾ããã é³å£°åæã«ã¤ã㦠SAPIâ¦
ããã«ã¡ã¯ï¼ã¤ã¼ã´ãªã§ãã ååã®è¨äºã«ç¶ããä»åã®è¨äºã§ã¯ãAmazon Elastic Container Service (EC2 Linux + ãããã¯ã¼ãã³ã°)ããç´¹ä»ãããã¨æãã¾ããï¼ã¡ãªã¿ã«ã次ã®è¨äºã§ã¯ããµã¼ãã¼ã¬ã¼ã¹ï¼Fargateï¼æ¹æ³ããç´¹ä»ãã¾ãï¼ ECSã¯ã©ã¹ã¿ã¼ã®ä½â¦
ããã«ã¡ã¯ããã¯ãã«ã«ãµãã¼ã課ã®å¤§ç³(ä¸)ã§ãã Amazon EC2 ã®ã¤ã³ã¹ã¿ã³ã¹ã¿ã¤ãã®å ãTç³»ã¤ã³ã¹ã¿ã³ã¹ã®ã³ã¹ãã«ã¤ãã¦ãååãããã ãæ©ä¼ãããã¾ããã ç¹ã« Unlimided ã¢ã¼ã㧠CPU ã¯ã¬ã¸ãããæ¯æ¸ããã¨ãã®ã³ã¹ãã®èãæ¹ããããã«ããã£ãâ¦