2022-07-01ãã1ã¶æéã®è¨äºä¸è¦§
ããã«ã¡ã¯ãAWS CLIã好ããªç¦å³¶ã§ãã ã¯ããã« æ¦è¦å³ ãã¤ã³ã ä½æ¥ã®æµã â IAMãã¼ã«ã®ä½æ â -â EC2ã®IAMãã¼ã« â -â¡ CodeDeployã®IAMãã¼ã« â¡èµ·åãã³ãã¬ã¼ãã®ä½æ â¡-â èµ·åãã³ãã¬ã¼ãã®ç»é¢ãéãã¾ãã â¡-â¡èµ·åãã³ãã¬ã¼ããä½æãæ¼ä¸ãã¾ãã â¡â¦
ããã«ã¡ã¯ãã©ã¼ãã³ã°ã¨ã¯ã¹ããªã¨ã³ã¹èª²ã®å°åã§ãã AWS Certified Solutions Architect - Associate ã®æ°ãã¼ã¸ã§ã³ (SAA-C03) ã 2022/8/30 ããåé¨ã§ãã2022/7/26 ããåé¨ç³è¾¼ãã§ããããã«ãªãã¾ãããæ§ãã¼ã¸ã§ã³ (SAA-C02) 㯠2022/8/29 ã¾ã§â¦
ããã«ã¡ã¯ã2022å¹´7æãããµã¼ãã¼ã¯ã¼ã¯ã¹ã«ã¸ã§ã¤ã³ãã¾ããIE課ã®å°è ã§ãã IE課ã¯Internal Education課ã®ç¥ç§°ã§2022å¹´3æã«æ°è¨ãããä¸éæ¡ç¨ã§å ¥ç¤¾ããæ¹åãã®é¤ææã«ãªã£ã¦ãã¦ç§ããã®èª²ã®ç¬¬ä¸å·ãããã§ãã å½ç¤¾ã¯å ¨å½ã©ãã«ä½ãã§ãã¦ãä»äºâ¦
ã¯ã©ã¦ãã¤ã³ãã°ã¬ã¼ã·ã§ã³2é¨æè¡3課ã®å±±ä¸ã§ãã ä»åã¯ãAWS Secrets Managerã§ã·ã¼ã¯ã¬ããæ å ±ã®èªåãã¼ãã¼ã·ã§ã³ãè¨å®ããéã®ã ãã¼ãã¼ã·ã§ã³ã®ã¹ã±ã¸ã¥ã¼ã«è¨å®ã«ã¤ãã¦æ¸ãããã¨æãã¾ãã ï¼èæ¯ï¼æ¯æ1æ¥ã®AM3æï¼æ¥æ¬æéï¼ã«ãã¼ãã¼ã·â¦
ããã«ã¡ã¯ãã©ã¼ãã³ã°ã¨ã¯ã¹ããªã¨ã³ã¹èª²ã®å°åã§ãã 以åãAWS èªå®ã®ç¡æã®æ¨¡æ¬è©¦é¨ã®åããããããã°ã§ç´¹ä»ãã¾ãããããã¡ãã®åããããå°ãå¤ããã¾ããã®ã§ãåããã¾ã§ã®æé ãç´¹ä»ãã¾ãã 2022/7/27 ç¾å¨ã以ä¸ã®æ¨¡æ¬è©¦é¨(å 20 å) ãæ¥æ¬èªâ¦
ããã«ã¡ã¯ãã¯ã©ã¦ãã¤ã³ãã°ã¬ã¼ã·ã§ã³2é¨ æè¡1課 宮形 ã§ãã AWS ã® Application Load Balancer (以ä¸ALB) ã§ã¯ãALBã®é ç½®å ã¨ã«ã¼ãã£ã³ã°å ã®EC2ã¤ã³ã¹ã¿ã³ã¹ã¯åä¸VPCã¨ããæ§æãä¸è¬çã§ãããå®ã¯ALBã¨EC2ã¤ã³ã¹ã¿ã³ã¹ãç°ãªããªã¼ã¸ã§ã³ã»ç°ãªâ¦
ããã«ã¡ã¯ï¼ã¤ã¼ã´ãªã§ãã æ¬æ¥ã®è¨äºã§ã¯ãªã³ãã¬ãã¹ç°å¢ã«ãããµã¼ãã¼/端æ«ããDX/VPNãªã©ãçµç±ãã¦AWSç°å¢ã«ããRoute 53ã§DNSåå解決ãããæ¹æ³ããç´¹ä»è´ãã¾ãã ä¸è¨ã®å³ã®éãããã©ã¤ãã¼ããã¹ãã¾ã¼ã³ã®Route 53ã®ä½æã¨Resolver ã¤ã³ãã¦â¦
æè¡2課ã®æ¾ç°ã§ããããã«ã¡ã¯ã Fleet Managerã®ãªã¢ã¼ããã¹ã¯ãããï¼RDPï¼æ¥ç¶ã«é¢ããå°ãã¿ãããã¤ãã¾ã¨ãã¾ããã®ã§ãç´¹ä»ãã¾ãã Fleet Manager is ä½ RDPæ¥ç¶ãã¦ã¿ã åææ¡ä»¶ æ¥ç¶ãã¦ã¿ã ã³ãããã§ããªãåé¡ã®å¯¾å¦æ¹æ³ ãªã¢ã¼ããã¹ã¯ãâ¦
ã¯ã©ã¦ãã¤ã³ãã°ã¬ã¼ã·ã§ã³2é¨æè¡3課ã®å±±ä¸ã§ãã ä»åã¯ãAmazon Elastic Container Serviceï¼ä»¥ä¸ãECSï¼ã® ã¿ã¹ã¯ãã¼ã«ã¨ã¿ã¹ã¯å®è¡ãã¼ã«ã®éãã«ã¤ãã¦ã ç°¡åãªãµã³ãã«ã¢ããªãç¨æãã¦æ¤è¨¼ãã¦ã¿ããã¨æãã¾ãã (èæ¯) ã¿ã¹ã¯ãã¼ã«ã¨ã¿ã¹ã¯å®â¦
ããã«ã¡ã¯ãAWS CLIã好ããªç¦å³¶ã§ãã ã¯ããã« GUIã«ããã¢ã¯ã»ã¹æ¹æ³ â ã¦ã¼ã¶ã¼ãã¼ã¿ã«URLã¸ã®ã¢ã¯ã»ã¹ â¡ã¦ã¼ã¶ã¼åã®å ¥å â¢ãã¹ã¯ã¼ãã®å ¥å â£MFAã®å ¥å â¤AWSã¢ã«ã¦ã³ãã¸ã®ã¢ã¯ã»ã¹ â¥ãã°ã¤ã³ç¢ºèª CLIã«ããã¢ã¯ã»ã¹æ¹æ³ â AWS CLIã®å°å ¥ â¡SSOã®è¨å® â¢â¦
ããã«ã¡ã¯ãAWS CLIã好ããªç¦å³¶ã§ãã ã¯ããã« æ¦è¦å³ Before After çµè« 使ãæ¹ å®è¡ä¾ VPC Subnet 詳細 ãã¡ã¤ã«æ§æ â prd-fk-param.json â¡serverworks-vpc.yml â¢serverworks-subnet.yml â£create-stack.sh çµããã« ã¯ããã« ä»åã¯ãAWS CLIã使ããClâ¦
Amazon S3ã®ãã¼ã¸ã§ãã³ã°ã«ã¤ãã¦è©¦ãã¦ã¿ãçµæãã使ç¨ããä¸ã§ã®æ³¨æç¹ãã¾ã¨ãã¦ã¿ã¾ããã
CI2é¨ æè¡2課ã®å±±ï¨ã§ãã AWS Organizationsã®SCPãå©ç¨ããéãä¸ããããªã·ã¼è¨è¨ãããã®ã¯ç°¡åã§ã¯ããã¾ããã ããã¯SCPã¯IAM Policyã¨ã¯ç¨éãç°ãªããã¨ãå¤ãï¼æå¦ãªã¹ããAWSã¢ã«ã¦ã³ãå ¨ä½ã®ã¢ã¯ã»ã¹çµ±å¶ã¨ãã¦å©ç¨ãããã¨ãå¤ãï¼ãããåãâ¦
CI2é¨ æè¡2課ã®å±±ï¨ã§ãã è¤æ°ã®AWSã¢ã«ã¦ã³ããªãã³ã«è¤æ°ã®ãªã¼ã¸ã§ã³ã«ã¯ã³ãªãã¬ã¼ã·ã§ã³ã§AWSãªã½ã¼ã¹ããããã¤ãããã¨ãã§ããCloudFormation StackSetsã¯ã¨ã¦ã便å©ã§ããã«ãã¢ã«ã¦ã³ãéç¨ããã¦ããå ´åã¯éå®ããã¦ããæ¹ãããã£ãããã®ã§â¦
CI2é¨ æè¡2課ã®å±±ï¨ã§ãã 5ã7æã«ããã¦RDS Performance Insights ã®ã¢ãããã¼ãã3ã¤ããã¾ããã®ã§ãä»åã¯ããããç°¡åã«ãç´¹ä»ãããã¨æãã¾ãã ãããã RDS Performance Insights ã¨ã¯ï¼ ã¢ãããã¼ãæ¦è¦ â 確èªãããã¡ããªã¯ã¹ã®æ£ç¢ºãªæéç¯â¦
CI2é¨ æè¡2課ã®å±±ï¨ã§ãã 7æã«Amazon Athena ããã©ã¡ã¼ã¿ã¯ã¨ãªããµãã¼ããã¾ããã®ã§ç°¡åã«ãç´¹ä»ãããã¨æãã¾ãã ãããã Amazon Athena ã¨ã¯ï¼ ã¢ãããã¼ãæ¦è¦ ãã©ã¡ã¼ã¿ã¯ã¨ãªãå®è¡ã§ããããã«ãªãã¾ãã ããã¾ã§ã®ã¯ã¨ãªã¨ã®æ¯è¼ ãã©ã¡â¦
CI2é¨ æè¡2課ã®å±±ï¨ã§ãã 7æã«Transit Gateway ã VPC Flow Logs ããµãã¼ããã¾ããã®ã§ç°¡åã«ãç´¹ä»ãããã¨æãã¾ãã ãããã VPC Flow Logs ã¨ã¯ï¼ ã¢ãããã¼ãæ¦è¦ Transit Gateway ã VPC Flow Logs ããµãã¼ããã¾ãã Transit Gateway ãåå¾â¦
ããã«ã¡ã¯ãAWS CLIã好ããªç¦å³¶ã§ãã ã¯ããã« æ¦è¦å³ åæ æµã â IAMããªã·ã¼ã®ä½æ â -â ChatbotãSSMã®ããã¥ã¡ã³ããå®è¡ã§ããããIAMããªã·ã¼ãä½æãã¾ãã â¡IAMãã¼ã«ã®ä½æ â¡-â IAMãã¼ã«ãä½æããâ ã§ä½æããIAMããªã·ã¼ãã¢ã¿ããããä¿¡é ¼é¢ä¿â¦
ã¯ããã« ã¤ã³ããã â ãAWSã®ææ°æ å ±ããè±èªã§ç¢ºèªãã æ¥æ¬èªã§ã¯ãªããè±èªã§ãã§ãã¯ãã 30å以ä¸ã¯æéããããªã â¡ãããã¥ã¡ã³ãå±¥æ´ãã確èªãã â¢ãAWS ãã¥ã¼ã¹ããã°ãã確èªãã ã¢ã¦ãããã â£ç¤¾å ã®Slackãã£ã³ãã«ã§ãã£ããã¢ããããã¢â¦
ããã«ã¡ã¯ãCIé¨ æ¿ï¨ã§ãã æè¿ã¯ãããã³ãã³ã®ã¹ããã·ã¥ããã¬ã¤ã«æã¦ãããã«ãªã£ã¦ãã¦ããã楽ããã¦ä»æ¹ããã¾ããã ä»åã¯ALBã®ãªã¹ãã¼ã«ã¼ã«ã®åªå 度ã«ç¦ç¹ãå½ã¦ã¦ããããã¨æãã¾ãã â»æ¬ããã°ã®å·çæç¹(2022å¹´7æ)ã§ã®æ å ±ã¨ãªãã¾ãã®â¦
ã«ã¹ã¿ãã¼ãµã¯ã»ã¹é¨ ä½ç«¹ã§ãã æ¬æ¥ã¯ãAWS Certified Advanced Networking â Specialty (ANS-C01) ã«åæ ¼ãã¾ããã®ã§ããã®å¯¾çãææ³ã«ã¤ãã¦æã£ããã¨ãè¨è¼ãã¦ããã¾ããæ¬ããã°ãä½ãã®åèã«ãªãã°å¹¸ãã§ãã
ããã«ã¡ã¯ãAWS CLIã好ããªç¦å³¶ã§ãã ã¯ããã« ä»åã¯ã以ä¸ã®ãã³ãºãªã³ãå®æ½ããããããã³ãºãªã³ã®å 容ãåºã«CI/CD for Amazon ECSã®èªåãããã¤ã®æµããã¾ã¨ãã¦ã¿ã¾ãã âAWS CI/CD for Amazon ECS ãã³ãºãªã³ https://pages.awscloud.com/rs/112-â¦
ããã«ã¡ã¯ãAWS CLIã好ããªç¦å³¶ã§ãã ã¯ããã« æ¦è¦å³ ãã¡ã¤ã«ä¸è¦§ ãã©ã«ãæ§æ åãã¡ã¤ã«ã®è©³ç´° CodeBuildã§å©ç¨ 1. buildspec.yml: ãã«ãå¦çã®å®ç¾©æ¸ buildspec.ymlã®ä¾ version pre_build(ãã«ãã®åå¦ç) build(ãã«ã) post_build(ãã«ãã®å¾å¦â¦
ããã«ã¡ã¯ãAWS CLIã好ããªç¦å³¶ã§ãã ã¯ããã« çµè« â Access Analyzer for S3ã«ã¦æ¤ç¥ããã¦ããªãã㨠ãããããIAM Access Analyzerã¨ã¯ Access Analyzer for S3ã®ç¢ºèªæ¹æ³ IAM Access Analyzerã¸ã®ã¢ã¯ã»ã¹ ãããªãã¯ã¢ã¯ã»ã¹ãå¯è½ãªS3ã®ç¢ºèª è£è¶³ â¦
ããã«ã¡ã¯ãAWS CLIã好ããªç¦å³¶ã§ãã ã¯ããã« CLIã使ã£ãCodeCommitã¸ã®ã¢ã¯ã»ã¹æ¹æ³ æ¦è¦å³ åæ æé â git-remote-codecommitã®å°å ¥(æ¢ã«å°å ¥ããã¦ããå ´åã対å¿ä¸è¦ã§ãã) â¡AWS CLIã®å°å ¥(æ¢ã«å°å ¥ããã¦ããå ´åã対å¿ä¸è¦ã§ãã) â¢Gitã®å°å ¥(æ¢â¦
ããã«ã¡ã¯ãã¯ã©ã¦ãã¤ã³ãã°ã¬ã¼ã·ã§ã³2é¨ æè¡1課 宮形 ã§ããä»åã¯ã²ããã¶ãã« Amazon WorkSpaces (ä»¥ä¸ WorkSpaces ã¨è¨) ã«ã¤ãã¦ã®BLOGã«ãªãã¾ãã WorkSpaces ã®å±éä½æ¥ãå¹çåããããå©ç¨ã¦ã¼ã¶ã¼ã®åæè¨å®ä½æ¥ã®è² æ ã軽æ¸ããããã¨ããæ¤â¦
ããã«ã¡ã¯ï¼ã¤ã¼ã´ãªã§ãã æ¢åãµããããã«ãããªã½ã¼ã¹ã®ãã©ã¤ãã¼ãIPã¢ãã¬ã¹ã®ç¶æ³ãåãããªãç¶æ ã§ãä»åæ§ç¯ããAWSãªã½ã¼ã¹ã®IPã¢ãã¬ã¹ãæå®ãããå ´åããã©ã®ãã©ã¤ãã¼ãIPã¢ãã¬ã¹ã使ãã°è¯ãããã®æ¹æ³ããã®è¨äºã§ã¯ãç´¹ä»ãããã¨æâ¦
ããã«ã¡ã¯ãAWS CLIã好ããªç¦å³¶ã§ãã ã¯ããã« èæ¯ æ¦è¦å³ ããæ¹ âªäºåæºå â ã¯ã¬ãã³ã·ã£ã«ã®è¨å®ãè¡ãã¾ãã â Cyberduckãéãããæ°è¦æ¥ç¶ããæ¼ä¸ãã¾ãã â¡ãã«ãã¦ã³ãæ¼ä¸ããã詳細è¨å®ããæ¼ä¸ãã¾ãã â¢ãProfilesããé¸æããæ¤ç´¢ãã¼ã«ãSâ¦
ããã«ã¡ã¯ï¼SRE2課 å ¥åã§ãã ä»åã¯EventBridgeã使ã£ã¦S3ãã±ããã«æå®ããæ°ã®ãã¡ã¤ã«ãã¢ãããã¼ãããããã Glueã¯ã¼ã¯ããã¼ãèµ·åããã¦ããã®ä¸ã§æå®ããGlueã¸ã§ããå®è¡ããè¨å®ã試ãã¦ã¿ã¾ããã æ§æ åæ è¨å® Glueã¯ã¼ã¯ããã¼ã®ä½æ â¦
ããã«ã¡ã¯ï¼ã¤ã¼ã´ãªã§ãã EC2ããããªãã¯ãµããããã«ããå ´åãåé¡ãªãã¤ã³ã¿ã¼ãããã²ã¼ãã¦ã§ã¤çµç±ã§S3ã¸ã¢ã¯ã»ã¹ãã§ãã¾ãã ãªãããã©ã¤ãã¼ããµããããã«ããEC2ããS3ã«ã¢ã¯ã»ã¹ãããå ´åãNATã²ã¼ãã¦ã§ã¤çµç±ã§ãS3ã«ã¢ã¯ã»ã¹ãã§ãã¾ãâ¦
ããã«ã¡ã¯ãã¯ã©ã¦ãã¤ã³ãã°ã¬ã¼ã·ã§ã³2é¨ æè¡1課 宮形 ã§ãã Windows Server éå®ã®ãã¼ãã«ãªãã¾ãããActice Directory ãã¡ã¤ã³åå ããã¡ã³ãã¼ãµã¼ãã¼(ä»¥ä¸ "ADåå ããâ ã¨ç¥) ã® EC2 ããAMI ã¨ãã¦ãªã³ã©ã¤ã³ããã¯ã¢ããããéç¨ã«ããã¦ãâ¦
ã¯ãã㫠対象è åæ 使ãæ¹ config.ymlã®ç·¨éã®ä»æ¹ ãã¡ã¤ã«åï¼SG_Check.py ãã¡ã¤ã«åï¼config.yml åºåçµæãµã³ãã« ã¯ããã« SRE1課ã®ç³äºã§ãã ç¾å¨ããã¸ã§ã¯ãã§ç¨¼åãã¦ããCLBãå ¨ã¦ALBã«ç½®ãæããä½æ¥ãè¡ã£ã¦ãã¾ãã ç¾ç°å¢ã§ã¯ã¤ã³ã¿ã¼ãâ¦
é¢ç½ãããªãµã¼ãã¹ãè¦ã¤ããã®ã§ç´¹ä»ãã¾ããã¿ã¤ãã«éããTailscaleã¨ãããµã¼ãã¹ãå©ç¨ããSSHã®ãã¼ç®¡çç¡ãã§SSHç°å¢ãæ§æã»éç¨ã§ãã¾ã*1ã tailscale.com Tailscaleã«ã¤ã㦠ã¾ããTailscaleã«ã¤ãã¦ç°¡åã«ç´¹ä»ãã¾ãã Tailscaleã¯ããã¼ã¸ãã®â¦
ããã«ã¡ã¯ãAWS CLIã好ããªç¦å³¶ã§ãã ã¯ããã« åé¤ä¿è·ã«ã¤ã㦠åãµã¼ãã¹ãã¨ã®åé¤ä¿è·ã«ã¤ã㦠EC2ã®åé¤ä¿è·ã«ã¤ã㦠GUI CLI RDSã®åé¤ä¿è·ã«ã¤ã㦠GUI CLI Auroraã®åé¤ä¿è·ã«ã¤ã㦠GUI CLI ALBã®åé¤ä¿è·ã«ã¤ã㦠GUI CLI çµããã« ã¯ããã« â¦
ããã«ã¡ã¯ï¼ã¤ã¼ã´ãªã§ãã æ¬æ¥ã®è¨äºã§ã¯ãAWS CloudFormationã§Amazon S3ã®ãããã¯ãããªãã¯ã¢ã¯ã»ã¹ã®æ¹æ³ããç´¹ä»è´ãã¾ãã AWSTemplateFormatVersion: "2010-09-09" Description: "Blocking public access to your S3 Bucket" Resources: S3Bucketâ¦
æè¡2課ã®æ¾ç°ã§ããããã«ã¡ã¯ã ALBããªãªã¸ã³ã¨ãã¦æå®ããAmazon CloudFrontã§ãã¯ã©ã¤ã¢ã³ãï½CloudFrontéã¨CloudFrontï½ALBéã®ä¸¡æ¹ã§ã«ã¹ã¿ã ãã¡ã¤ã³ã®è¨¼ææ¸ãç¨ãã¦æå·åããæ¹æ³ãã¾ã¨ãã¾ããã ä»åã®æ§æ æ§ç¯æé ï¼ï¼ãã¹ãã¾ã¼ã³ã®ä½æ â¦