2023-03-01ãã1ã¶æéã®è¨äºä¸è¦§
æ¬è¨äºã¯ãAWS Gateway Load Balancer ã® TCP ããã¼ã®ã¢ã¤ãã«ã¿ã¤ã ã¢ã¦ãã«å¯¾ãããã¹ããã©ã¯ãã£ã¹ã®ç´¹ä»ã§ãã
ããã«ã¡ã¯ãAWS CLIã好ããªç¦å³¶ã§ãã ã¯ããã« åè æ¦è¦å³ ããã㨠â IDãããã¤ãã¼ã®è¨å® â¡IDãããã¤ãã¼ã¸ã®IAMãã¼ã«ã®å²ãå½ã¦ â¢â¡ã§ä½æããIAMãã¼ã«ã®ä¿¡é ¼é¢ä¿ã®ç·¨é â£GitHubã®Secretsã«IAMãã¼ã«ã®ARNãä¿å â¤GitHub Actionsã«ããGitHubããS3â¦
ããã«ã¡ã¯ãAWS CLIã好ããªç¦å³¶ã§ãã ã¯ããã« å©ç¨ããã³ãã³ã,ãµãã³ãã³ã <command> <subcommand> ã¯ã©ã¹ã¿ã®ä¸è¦§ ç¹å®ã®ã¯ã©ã¹ã¿ã§ç¨¼åãã¦ãããµã¼ãã¹ä¸è¦§ ã¿ã¹ã¯å®ç¾©ã®ä¸è¦§ ææ°ã®å ¨ã¿ã¹ã¯å®ç¾©ã®JSONæ å ±(ãã¡ã¤ã«ã«åºå) å ¨ã¯ã©ã¹ã¿ã§ç¨¼åãã¦ãããµã¼ãã¹ä¸è¦§ å ¨ã¯</subcommand></command>â¦
ã³ã¼ãã¬ã¼ãã¨ã³ã¸ãã¢ãªã³ã°é¨ã®å®®æ¾¤ã§ããæè¿ãAuth0ããããã¨ãªãã¤ã¤ããã¾ãããä»åã¯Auth0ããKaonaviã«SAMLãã°ã¤ã³ããããã®è¨å®æé ãç´¹ä»ãããã¨æãã¾ãã Auth0ã®Applicationsä½æ Auth0ã«ç®¡çè ã¢ã«ã¦ã³ãã§ãã°ã¤ã³ã"Applicatons"ã¡ãâ¦
Amazon Connectã®ç®¡çç»é¢ãCCPã¸ã¢ã¯ã»ã¹ããéã®ãã¡ã¤ã³ã¯2種é¡åå¨ãã¦ãã¾ãã ç¾å¨Amazon Connectã¤ã³ã¹ã¿ã³ã¹ãä½æãã㨠https://****.my.connect.aws ï¼****=ã¤ã³ã¹ã¿ã³ã¹ã¨ã¤ãªã¢ã¹åï¼ã¨ãããã¡ã¤ã³ãå²ãå½ã¦ããã¾ããã以å㯠https://****.â¦
ECé¨æè¡1課ã®æ¾ç°ã§ããããã«ã¡ã¯ã ä»åã¯åä¸VPCã§AWS Network Firewallã使ç¨ããéã®æ§æä¾ããç´¹ä»ãã¾ãã 1. AWS Network Firewallã«ã¤ã㦠2. 代表çãªå©ç¨æ§æ 2.1. ãããªãã¯ãµããããã¨IGWã®éã«é ç½® 2.2. ãã©ã¤ãã¼ããµããããã¨NATã®éã«â¦
å½ç¤¾ã®ç£è¦ãµã¼ãã¹ã§å©ç¨ãã¦ããNew Relicã®ç£è¦ã¨ã¼ã¸ã§ã³ãã«ã¤ãã¦ãã¤ã³ã¹ãã¼ã«åå¾ã®ãªã½ã¼ã¹ç¶æ³ã調æ»ãã¦ã¿ã¾ããã
IAM Roles Anywhere ãæ§ç¯ãã¦ã¿ããï¼èªèº«ã管çããèªè¨¼å±ã使ç¨ããæ¹å¼ï¼
ããã«ã¡ã¯ã æè¡èª²ã®å±±æ¬ã§ãã 以åã«ãIAM Roles Anywhere ã«ã¤ãã¦ãï¼ã¤ããã°ãè¨è¼ãã¦ãã¾ãã blog.serverworks.co.jp blog.serverworks.co.jp ä¸ã®ããã°ã§ã¯ãèªè¨¼å±ã« AWS Certificate Manager ã使ç¨ãã¾ããã æ¬è¨äºã§ã¯ãEC2 ä¸ã«ãèªèº«ãâ¦
ããã«ã¡ã¯ãAWS CLIã好ããªç¦å³¶ã§ãã ã¯ããã« åè æ§æã¤ã¡ã¼ã¸ ããã㨠â Cognitoã®ã¦ã¼ã¶ã¼ãã¼ã«ä½æ[AWS] â¡ã¦ã¼ã¶ã¼ãã¼ã«ã¸ã®ãã¡ã¤ã³è¿½å [AWS] â¢ã¨ã³ã¿ã¼ãã©ã¤ãºã¢ããªã±ã¼ã·ã§ã³ã®ä½æ[Azure] â£ã·ã³ã°ã«ãµã¤ã³ãªã³ã®è¨å®[Azure] â¤ã¦ã¼ã¶ã¼ã¾ãâ¦
ããã«ã¡ã¯ã æè¡èª²ã®å±±æ¬ã§ãã 以ä¸è¨äºã§ã¯ãECR ã®ãããªãã¯ãªãã¸ããªã«ãã AWS å ¬å¼ã® Fluent Bit ã®ã³ã³ããã¤ã¡ã¼ã¸ããECSã¿ã¹ã¯ã§ç´æ¥å©ç¨ããæ¹æ³ãããã¨åããã¾ããã å©ç¨è å´ã§ã¯ãFluent Bit ã®è¨å®ãã¡ã¤ã«ããS3 ãã±ããä¸ã«é ç½®ããâ¦
ããã«ã¡ã¯ãEnterprise Cloudé¨ æè¡1課 宮形 ã§ããä»åBLOGã§ã¯ãElastic Load Balancing (以ä¸ELB) ããå©ç¨ã®ç°å¢ã«ããã¦ã HTTPSæå·åéä¿¡ã®ãã¡TLS1.0ãTLS1.1ãç¡å¹åããè¨å®æé ãè¨è¼ãã¾ãã TLS1.0ãTLS1.1 ãç¡å¹åããçç± ç¾ç¶ã®ç¢ºèª è¨å®â¦
ã¯ããã« ããã«ã¡ã¯ãã¢ããªã±ã¼ã·ã§ã³ãµã¼ãã¹é¨ã®æ²³éã§ãã ä»åã¯ãVue3 ã§ãã©ãã°&ããããã® UI ãç°¡åã«å®è£ ã§ãã vue.draggable.next ã©ã¤ãã©ãªã®ç´¹ä»ã§ãã åºæ¬çãªä½¿ãæ¹ããå¿ç¨ç·¨ã¨ãã¦ãã¼ãã«é移åã®å®è£ æ¹æ³ã«ã¤ãã¦è¨è¼ãã¾ãã å®è£ â¦
ããã«ã¡ã¯ãAWS CLIã好ããªç¦å³¶ã§ãã ã¯ããã« åè å¬ãããã¤ã³ã çæäºé äºåæºå 試ãã¦ã¿ã ææ ã¯ããã« ä»åã¯ãå æ¥ã®ã¢ãããã¼ãã§è¿½å ãããIAMã®ã°ãã¼ãã«æ¡ä»¶ãã¼ãå©ç¨ãã¦ã EC2ã®èªè¨¼æ å ±ãå¤é¨ã§å©ç¨ãããªãããªã·ã¼ãè¨å®ã§ãããâ¦
ããã«ã¡ã¯ãEnterprise Cloudé¨ æè¡1課 宮形 ã§ããä»åBLOGã§ã¯ãAmazon WorkSpaces (ä»¥ä¸ WorkSpaces ã¨è¨) ã管çããããã«ãã°ã«ã¼ãããªã·ã¼ãªãã¸ã§ã¯ããå©ç¨ããããã®è¨å®æé ããç´¹ä»ãã¾ãã WorkSpaces ããå©ç¨ãè©ä¾¡ãããã客æ§ããããé â¦
ã¿ãªãããããã«ã¡ã¯ãAWS CLI ã好ããªãã¯ãã«ã«ãµãã¼ã課ã®å¸éã§ãã ãã¦ãå¾ ã¡ã«å¾ ã£ã次ä¸ä»£ã® Amazon Linux ãAmazon Linux 2023 (AL2023) ãã GAï¼General Availabilityï¼ã¨ãªãã¾ããã aws.amazon.com æ·±æããã¦ããããã¨ã¿ã¦ããããã¨ããâ¦
ããã«ã¡ã¯ï¼ç¾å¨IE課ç ä¿®ä¸ã®æ¥é«ã§ãã æ¬æ¥ã¯ä»¥åæ¸ãããã³ã³ããã¼ã«ãã¬ã¼ã³ã¨ãã¼ã¿ãã¬ã¼ã³ã®æ¦å¿µããèããAWS CLIã§ã®S3ã³ãã³ãã®åé¡æ¹æ³ãã®ããã°ã®ç¶ç·¨ã¨ãã¦aws s3ï½ã®ã³ãã³ãã«ã¤ãã¦ããã°ãæ¸ãã¦ããããã¨æãã¾ãã ãããããã°ãã¡â¦
ã³ã¼ãã¬ã¼ãã¨ã³ã¸ãã¢ãªã³ã°é¨ã®å®®æ¾¤ã§ãã以ä¸ã®GoogleWorkspaceã¢ãããã¼ãããã°ã§å ¬éããã¦ããéãã管çè å´ããã«ã¹ã¿ã ãããã¼ãã£ã«èæ¯ãé å¸ã§ããããã«ãªãã¾ããã workspaceupdates.googleblog.com ãªããã®è¨å®ã便å©ãï¼ æ¨ä»ãå¨å® ã¯â¦
ããã«ã¡ã¯ï¼ç¾å¨IE課ã§ç ä¿®ä¸ã®æ¥é«ã§ãã çããCLI使ã£ã¦ãã¾ããï¼ï¼ç§ã¯ã¾ã ã¾ã 使ãã¦ãã¾ãã... ã¨ãããã¨ã§ãAWS CLIã使ããããã«ãªãããã«ãä»åã¯AWS CLIã®æ§é ã¨S3é¢é£ã®ã³ãã³ãã«ã¤ãã¦èª¿ã¹ã¦ã¿ã¾ããã AWS CLIã®æ§é AWS CLI Command Reâ¦
ããã«ã¡ã¯ãæè¡èª²ã®å±±æ¬ã§ãã 以åã®è¨äºã§ IAM Roles Anywhere ã®æ¦è¦ã«è§¦ãã¾ããã ãã¾ããOpenSSL ç¯ï¼ ä»åã¯ä¸ã®è¨äºã§è§£èª¬ããæ§æããå®éã«æ§ç¯ãã¦ã¿ã¾ãã èªè¨¼å±ã¯ Private CA (Short-Liveã¢ã¼ã) ã使ç¨ãã¦æ§ç¯ãã¾ãã â» å³å ã«æ¸ãã¦ãâ¦
ããã«ã¡ã¯ãEnterprise Cloudé¨ æè¡1課 宮形 ã§ãã ã¯ãããã®ã§ Serverworks ã«ã¸ã§ã¤ã³ãã¦1年以ä¸ãã¡ã¾ããããã®éãããã®ä»²ééã¨ã®åºä¼ãããããçãããããã°ãããç¹å¾´ãå¼·å³ããã£ã¦ãããåºæ¿ãå¤ãããã1å¹´ã§ãããå ±éãã¦æããã®ã¯çâ¦
Cloud OneFile Storage Securityã®åæè¨å®æ¹æ³ãç´¹ä»ããè¨äºã«ãªãã¾ãã
ããã«ã¡ã¯ãæè¡èª²ã®å±±æ¬ã§ãã IAM Roles Anywhere ã®èªè¨¼æ¹å¼ãç解ããããã«ãä¸éã触ã£ã¦ã¿ã¦ãæ¦è¦ãæ´çãã¦ã¿ã¾ããã å ·ä½çãªæé çã¯å¥ã®è¨äºã«è¨è¼äºå®ã§ãã â©æ¸ãã¾ããã Private CA ç¯ï¼ OpenSSL ç¯ï¼ IAM Roles Anywhere ã®å©ç¨ç®ç IAM â¦
ããã«ã¡ã¯ããµã¼ãã¼ã¯ã¼ã¯ã¹ã®æä¸ã§ãã ã¤ãã«ã¬ã¤ã«ã¼ãºããã¬ã¤ã¤ã³åå ã®é ä½ã«ä¸ããã¾ãããï¼2023å¹´3æ10æ¥ç¾å¨ï¼ã What a night pic.twitter.com/eWU0N73cXaâ Los Angeles Lakers (@Lakers) 2023å¹´3æ8æ¥ ãã¬ã¤ãªããè¦ãã¦ããï¼ã¨ãããã¨ã§â¦
ããã«ã¡ã¯ãä»å¹´ã®ã¹ã®è±ç²éã¯ä¾å¹´ã®10åã¨èããæããã®ã®ãã¦ããCS2課ã®çéã§ãã ç§ãä¸éå ¥ç¤¾å¾ãIE課ã®ç ä¿®ã§æ©ãã VPCå ã®ã¤ã³ã¹ã¿ã³ã¹éã«ã¼ãã£ã³ã°ã«ã¤ãã¦è¨äºã«ãã¦ã¿ã¾ããã å®ç¾ãããã㨠æ§æ Webãµã¼ãããDBãµã¼ãã¸ã®æ¥ç¶ è¸ã¿å°ãµâ¦
ä¾åé¢ä¿ã® CVE ã Dependabot ããéç¥ãã¦ããã£ã¦ãè½åçã«ãã§ãã¯ããªãã¦ãéçºè ã¨ãã¦ãã¹ããã¨ãè¦ããç¶æ ãä½ãããã£ãããã°
ããã«ã¡ã¯ãããã¼ã¸ããµã¼ãã¹é¨ãã¯ãã«ã«ãµãã¼ã課ã®åå£ã§ãã æè¿ãAWSã®CDK for Terraform(以ä¸ãCDKTF)ã使ç¨ãã¦Webã·ã¹ãã ãæ§ç¯ãããã¨ã«ææ¦ãã¾ããã ã¯ããã« ç°å¢ æ§æå³ CDKTFã®ã¤ã³ã¹ãã¼ã« ããã¸ã§ã¯ãã®ä½æ ãªã½ã¼ã¹ã®æ§ç¯ äºåä½â¦
æ¬è¨äºã§ã¯æ¢åã® Amazon SNS ãããã¯ã«æ°è¦ãµãã¹ã¯ãªãã·ã§ã³ãä½æã E ã¡ã¼ã«éç¥å ã追å ããæ¹æ³ãè¨è¼ãã¾ãã 追å 対象ã®SNS ãããã¯ãéã ãµãã¹ã¯ãªãã·ã§ã³ã®è¿½å ãµãã¹ã¯ãªãã·ã§ã³ã®æ¿èª 追å 対象ã®SNS ãããã¯ãéã ããã¸ã¡ã³ãã³ã³ã½â¦
ããã«ã¡ã¯ï¼ç¾å¨IE課ã§ç ä¿®ä¸ã®æ¥é«ã§ãã æ¬æ¥ã¯ãAmazon EC2 Auto Scalingã®æ¦è¦ã«ã¤ãã¦ãããã¦ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã«ã¦Amazon EC2 Auto Scalingã®ã¹ãããã¹ã±ã¼ãªã³ã°ããªã·ã¼ãè¨å®ãã¦ããããã¨æãã¾ãã åæ Amazon EC2 Auto Scaling Amazonâ¦
ã³ã¼ãã¬ã¼ãã¨ã³ã¸ãã¢ãªã³ã°é¨ã®å®®æ¾¤ã§ããä»åã¯Auth0ã®Enterpriseæ¥ç¶æ©è½ãå©ç¨ãã¦Auth0ã¨OneLoginãSAMLé£æºãããæé ãç´¹ä»ãã¾ãã Auth0ã®Enterpriseæ¥ç¶æ©è½ã«ã¤ã㦠Auth0ã®Enterpriseæ¥ç¶æ©è½ãå©ç¨ããå ´åã¯ããããã§ãã·ã§ãã«ãã©ã³ä»¥ä¸â¦
ããã«ã¡ã¯ï¼ç¾å¨IE課ã§ç ä¿®ä¸ã®æ¥é«ã§ãã æ¬æ¥ã¯Amazon EC2 Auto Scalingã®ãèµ·åãã³ãã¬ã¼ãããä½æããéã«ããã£ããã¤ã³ãã«ã¤ãã¦æ¸ãã¦ããããã¨æãã¾ãã å°ã£ã¦ããå 容 ã©ã対å¿ããã°ããã ã¾ã¨ã å°ã£ã¦ããå 容 Apacheãèµ·åãã¦ããEC2â¦
ã¯ããã« é«æ© (ãã¤ã³ã³å ) ã§ããæè¿ã¯æ²¼ã¨ããæçãã»ã¼æ¯æ¥é£ã¹ã¦ãã¾ãã ä»å㯠NLB ã®ã¿ã¼ã²ããã®ã»ãã¥ãªãã£ã°ã«ã¼ãè¨å®ã§ã¡ãã£ã¨ããã£ãã®ã§ããã°åãã¾ããã è¨ãããã㨠ããã°ã®ã¿ã¤ãã«ã«ããéã... ãNLB ã§ã¯ã©ã¤ã¢ã³ãã®ã»ãã¥ãªâ¦
ã³ã¼ãã¬ã¼ãã¨ã³ã¸ãã¢ãªã³ã°é¨ã®å®®æ¾¤ã§ãã ä»åã¯OneLoginã¨KaonaviãSAMLè¨å®ããæé ãç´¹ä»ãã¾ãã OneLoginã§ã³ãã¯ã¿ã®ä½æ OneLoginã«ç®¡çè ã¢ã«ã¦ã³ãã§ãã°ã¤ã³ãã管çç»é¢ãéã"Applications > Applications"ãéãâAdd Appsâãæ¼ãã¾ãã âSAâ¦
ããã«ã¡ã¯ããµã¼ãã¼ã¯ã¼ã¯ã¹å ¥ç¤¾ãã5ãæãçµã£ããã¯ãã«ã«ãµãã¼ã課㮠ä½è¤ å æã§ãã çªç¶ã§ãããçæ§ã¯æ¥å¸¸çæ´»ãä»äºã®ä¸ã§ã©ãããããã«ããã¹ã¯ãã¦ã¼ã¶ã¼ãµãã¼ãããã¯ãã«ã«ãµãã¼ãã«ãåãåããããã¦ããã¾ãã§ããããã ãåãåããâ¦
ããã¼ã¸ããµã¼ãã¹é¨ ä½ç«¹ã§ãã æ¬ããã°ã§ã¯ãAmazon GuardDuty ã® æ¤åºçµæã®ãã¡ãæ¼ããªããªã¢ã«ã¿ã¤ã ã§ç¢ºèªããã Severity ã High ã®æ¤åºçµæãã Amazon EventBridge 㨠AWS Chatbot ãæ´»ç¨ã Slack ãã£ã³ãã«ã¸ã¨é£æºããè¨å®æ¹æ³ã«ã¤ãã¦è¨è¼â¦
ããã«ã¡ã¯ã æè¡èª²ã®å±±æ¬ã§ãã 以ä¸è¨äºã§ã¯ãJava ã³ã³ããã®åºåããè¤æ°è¡ã®ãã°ããCloudWatchä¸ã§è¤æ°ã®ãã°ã¬ã³ã¼ãã«åããã¦ãã¾ãå ´åã«ãï¼ã¤ã®ãã°ã¬ã³ã¼ãã«ã¾ã¨ããæ¹æ³ã解説ãã¾ããã AWS Fargate 㧠FireLens ãå©ç¨ããFireLens ã® mulâ¦
ããã«ã¡ã¯ãã¨ã³ã¿ã¼ãã©ã¤ãºã¯ã©ã¦ã課ã®å è¤ãã§ãã Athenaã¨Glueã®æéãã¼ã¸ã解èªããã®ãã¤ããã£ãã®ã§ãã¾ã¨ãã¦ã¿ã¾ããã ãªãå½è¨äºã«è¨è¼ããæ å ±ã¯ã2023å¹´3æ1æ¥ç¾å¨ã®ãã®ã§ãã ææ°æéä½ç³»ã¯è¨è¼ã®å ¬å¼ããã¥ã¡ã³ããã確èªãã ããã Aâ¦
ããã«ã¡ã¯ã æè¡èª²ã®å±±æ¬ã§ãã 以ä¸ã®è¨äºã§ãSSM Automation ã®ç¬èªã©ã³ããã¯ãä½æããä»»æã® Lambda é¢æ°ãå®è¡ãã¦ã¿ã¾ããã blog.serverworks.co.jp æ¬è¨äºã§ã¯ã ECS ã¿ã¹ã¯ï¼RunTaskï¼ ãå®è¡ãã¦ã¿ã¾ãã Lambda ã®å®è¡æã¨åæ§ã«ãç¬èªã©ã³ãâ¦
ããã«ã¡ã¯ãã¢ããªã±ã¼ã·ã§ã³ãµã¼ãã¹é¨ãã£ããããã¡ã³ããµã¼ãã¹2課ã®æ£®ç°ã§ãã å½è¨äºã§ã¯ Amazon Connect ã®ãªãã¬ã¼ã¿ã¼ã®å¯¾å¿ç¶æ³ãã Salesforce ã«é£æºããæ¹æ³ãæ¸ãã¦ããã¾ãã CTI Adapter ã使ç¨ãããã¨ã§ Amazon Connect 㨠Salesforce ãâ¦
ããã«ã¡ã¯ã æè¡èª²ã®å±±æ¬ã§ãã SSM Automation ã試ãããã¨ããªãã£ãã®ã§ã触ã£ã¦ã¿ã¾ããã SSM Automation ã使ã Lambda é¢æ°ãå®è¡ãã¦ã¿ã¾ããã ã¯ããã«ãAmazon æä¾ã® Runbook ã®ãç´¹ä» ç¬èªã® Runbook ãä½æãã AWS Lambda ã®é¢æ°ãå®è¡ãâ¦
ããã«ã¡ã¯ï¼æè¡1課ã濱岡ã§ãï¼ æè¿ããã¡ããç¾å³ããã¦ãã¤ãã¤ãé£ã¹ã¦ãã¾ãã¾ãããã ä»åã¯Amazon Inspectorã®Lambdaé¢æ°ã®èå¼±æ§ã¹ãã£ã³ã試ãã¦ã¿ã¾ããï¼ Amazon Inspectorã¨ã¯ï¼ Amazon Inspector ã¯ãã½ããã¦ã§ã¢ã®èå¼±æ§ãæå³ããªããã°â¦