2024-04-01ãã1ã¶æéã®è¨äºä¸è¦§
ãµã¼ãã¼ã¯ã¼ã¯ã¹ã®æä¸ã§ãã 2024å¹´4æ24æ¥ã«Guardrails for Amazon Bedrockã®ä¸è¬æä¾ãéå§ããã¾ããã aws.amazon.com Guardrails for Amazon Bedrockã§ã¯ãå種ãã£ã«ã¿ã¼ãè¨å®ããçæAIã¢ããªã±ã¼ã·ã§ã³ã®æ害ãªå ¥åã»åºåããããã¯ãããã¨ãã§â¦
ã«ã¹ã¿ãã¼ãµã¯ã»ã¹é¨ã®å±±ï¨ã§ãã HTTPSãSMTPSçãåºãå©ç¨ããã¦ããSSL/TLSã«ããã¦å©ç¨ããã¦ããæè¡ã¨ãã®ä»çµã¿ãæ´çãã¦ã¿ã¾ããã SSL/TLSã«ã¤ã㦠æ¦è¦ SSL/TLSã§ä½¿ç¨ãã¦ãã3ã¤ã®æè¡ æå·å ããã·ã¥å ãã¸ã¿ã«ç½²å ãã¸ã¿ã«ç½²åã«ã¤ãã¦æ·±â¦
ããã«ã¡ã¯ãEnterprise Cloudé¨ ã½ãªã¥ã¼ã·ã§ã³ã¢ã¼ããã¯ã1課 宮形 ã§ãã 令å6年度ã¯ã¬ãã¡ã³ãã¯ã©ã¦ãã¸ã®æ©æ移è¡å£ä½æ¤è¨¼äºæ¥ã¸ç³è¾¼ããããã¾ãã¯ããããç³è¾¼äºå®ã®å°æ¹èªæ²»ä½æ§ãå¤ãããããã¨äºæ³ãã¾ããããã«åããã¦å¿ è¦ãªAWSãªã½ã¼ã¹å©ç¨â¦
ã«ã¹ã¿ãã¼ãµã¯ã»ã¹é¨ã®å±±ï¨ã§ãã EventBridgeãç¨ãã¦ãã«ãã¢ã«ã¦ã³ãã§ã¤ãã³ãã®éç´ç®¡çãè¡ãæ¹æ³ã«ã¤ãã¦æ¤è¨¼ãã¦ã¿ã¾ãã ä»åã®æ§æ ããå®è£ ã¤ãã³ãéç´ç¨ã¢ã«ã¦ã³ã 1. EventBridgeã§ã«ã¹ã¿ã ã¤ãã³ããã¹ãä½æãã 2. ã«ã¹ã¿ã ã¤ãã³ããã¹â¦
ã«ã¹ã¿ãã¼ãµã¯ã»ã¹é¨ã®å±±ï¨ã§ãã ä»åã¯ACM for Nitro Enclaves ãå©ç¨ãã¦Nginxã¸ã®HTTPSéä¿¡ãå®è£ ãã¦ã¿ã¾ãã ä»åã®æ§æ AWS Nitro Enclaves ã«ã¤ã㦠AWS Certicate Manager ã«ã¤ã㦠ACM for Nitro Enclaves ã«ã¤ã㦠å®è£ ãã¦ã¿ã äºåä½æ¥ ãªãã¼â¦
ããã«ã¡ã¯ããã¼ã¸ããµã¼ãã¹é¨ 大åã§ãã ååã®ããã° ã®ç¶ããæ¸ãã¾ããä»å㯠Python ã§è©¦ãã¦ã¿ã¾ãã New Relic APM ãã¤ã³ã¹ãã¼ã«ããå¾ãããã«ããã¯ãã©ãã«ããã®ã確èªãã¦ãå°ãã ããã¥ã¼ãã³ã°ãã¾ãã åæºå ãã£ã¦ã¿ã ãã¥ã¼ãã³ã°ãªâ¦
ããã«ã¡ã¯ãEnterprise Cloudé¨ ã½ãªã¥ã¼ã·ã§ã³ã¢ã¼ããã¯ã1課 宮形 ã§ããä»å¹´ã«å ¥ã£ã¦ã¬ãã¡ã³ãã¯ã©ã¦ãã®ããã°ãæ¸ãããã«ãªãã¾ãã¦ãã©ã®è¨äºãååãã§ãã¸ãã£ããªå 容ãå¿ããã¦ããã¾ããããä»åã¯ä¸è»¢ãã¦å¾ãåããªã¿ã¤ãã«ã«ãªãã¾ãã æ¬â¦
ããã«ã¡ã¯ï¼DS1課ã濱岡ã§ãï¼ re:Invent2023ã§é ã£ã¦ããBuilderCardsã§éãã§ã¿ã¾ããï¼ Youtubeã®åç»ãããã®ã§ãã¡ãããã²ã覧ãã ããï¼ www.youtube.com www.youtube.com ã«ã¼ã«èª¬æ å®éã®ã«ã¼ã«ã«ã¤ãã¦ã¯ãã¡ãããâ https://d2jm2rwvncgxr.clouâ¦
ããã«ã¡ã¯ããããã趣å³ã®åæ¬ï¼@t_sakamï¼ã§ããä»åã¯ãAmazon Bedrock ãå©ç¨ãã Alexa ã¹ãã«ãAI åºç¤ãããã®è£å´ã§å©ç¨ãã¦ãã AWS ã®ãµã¼ãã¹ãæ§æã確èªãã¦ããããã¨æãã¾ãã ãAI åºç¤ãããã®æ§æã¯ãã»ã¼ Alexa ã¹ãã«å¶ä½ã®ä¸è¬çãªæ§â¦
ã¨ã³ã¿ã¼ãã©ã¤ãºã¯ã©ã¦ãé¨ã®å±±ä¸(ç¥)ã§ãã æ¬ããã°ã§ã¯ãIAMã¦ã¼ã¶ã¼ã®èªè¨¼æ å ±ãæ¼æ´©ããéã®å¯¾å¦ããã·ã³ãã«ã«åºæ¥ããèãã¦ã¿ããã¨æãã¾ãã èæ¯ çæäºé åææ¡ä»¶ 対象ã¨ããèªè¨¼æ å ± 対象ãªã½ã¼ã¹ 対象ãã§ã¼ãº èå¯ No.1ã«ã¤ã㦠No.2ã«ã¤ãâ¦
ããã«ã¡ã¯ãæ«å»£ã§ãã ååã®ããã°ã§ã¯ CodeBuild ã®ã³ã³ãã¥ã¼ãã£ã³ã°ã§ Lambda ã使ç¨ãã¦å®è¡ãããã®ãç´¹ä»ãã¾ããã blog.serverworks.co.jp æ¬ããã°ã§ã¯åæ§ã« Lambda ã³ã³ãã¥ã¼ãã£ã³ã°ã使ç¨ãã¦ãã¢ãããã¼ãã«ã¦è¿½å ãããã«ã¹ã¿ã ã¤ã¡ã¼â¦
å£è¦ï¼ããã¿ï¼ã§ãã æè¿ãAWS Direct Connectï¼DXï¼ä¸ã«è¤æ°ãããªã½ã¼ã¹ã®ãã¡ããã¤ãã®åé¤ãçµé¨ããæ©ä¼ãããã¾ããã ããããåç·ç³»ã®ãµã¼ãã¹ã£ã¦è§¦ã£ã¦å¤±æããã¨ãã®å½±é¿ãèããã¨ä¸å®ã§ãããããããªã®ã«ãæ°è»½ãªæ¤è¨¼ããã«ããä¸è¬ã®è³æâ¦
ããã«ã¡ã¯ï¼ã¨ã³ã¿ã¼ãã©ã¤ãºã¯ã©ã¦ãé¨ã¯ã©ã¦ãã³ã³ãµã«ãã£ã³ã°èª²ã®æ¥é«ã§ãã ããç§ã®ãã¨ãå°ãã§ãç¥ãããã¨æã£ã¦ããã ãããªããç§ã®å¾è¼©ãæ¸ãã¦ããã以ä¸ã®ããã°ãè¦ãã¦ã¿ã¦ãã ããã sabawaku.serverworks.co.jp ä»åã¯ãAWS Healthã®éè¦â¦
ããã«ã¡ã¯ããããã趣å³ã®åæ¬ï¼@t_sakamï¼ã§ããClaude 3 ã®æä¸ä½ ã¢ãã«ã§ãã Opus ã Amazon Bedrock ã§å©ç¨ã§ããããã«ãªãã¾ããã以åã®ããã°ã§ Claude 3 Sonnet ã Amazon Bedrock ã§å©ç¨ã§ããããã«ãªã£ãéã« Amazon Bedrock ã®ãã£ããã®ãâ¦
ããã«ã¡ã¯ ã«ã¹ã¿ãã¼ãµã¯ã»ã¹é¨ã®å±±æ¬ã§ãã 以åããããæ©è½ãªãã®ã®ãAurora ã®ã¢ã¯ãã£ããã£ã¹ããªã¼ã ã«ã¤ãã¦åãã¦èª¿ã¹ãã®ã§è¨äºã«ãã¾ãã ã¢ã¯ãã£ããã£ã¹ããªã¼ã ã¯ãã¼ã¿ãã¼ã¹æä½ã®ç£æ»ãè¡ãæ©è½ã§ãã ç£æ»ãã°æ©è½ã¯ä»ã«ãããã®ã§ã使â¦
ã¨ããã®ãæè¿ç¥ãã¾ããã ãµã¼ãã¹éçºèª²ã®ããã°ããã§ãã 表é¡ã®ä»¶ããã¾ãééãããã¨ã¯ç¡ãã¨æãã¾ãããåãEBSã¹ãããã·ã§ããããä½åº¦ãAMIãä½æãããããã¨çºçãã¾ãã ããã¦ãAMIã¨ç´ã¥ãã¦ããã¹ãããã·ã§ããã¯åé¤ã§ããªããããä¾â¦
ããã«ã¡ã¯ï¼ã¤ã¼ã´ãªã§ãã ä»æ¥ã¯Terraformã§ç®¡çããAWSãªã½ã¼ã¹ãæåã§ä½ãç´ãã¦ãã¾ã£ãå ´åã®å¯¾çæ¹æ³ãç´¹ä»ãããã¨æãã¾ãã èæ¯ .tfãã¡ã¤ã« terraform planã®çµæ 大ã¾ããªä½æ¥ã®æµã æé æåã§åé¤ãããAWSãªã½ã¼ã¹ã.tfstateããåé¤ããâ¦
ãµã¼ãã¼ã¯ã¼ã¯ã¹ã®æä¸ã§ãã Amazon Bedrockã§Claude 3 Opusãå©ç¨å¯è½ã«ãªã£ãã¨ããã¢ãããã¼ããããã¾ããã aws.amazon.com ããã§Claude 3ãã¡ããªã¼ãã¹ã¦ãAmazon Bedrockã§å©ç¨å¯è½ã«ãªãã¾ããã ãã®ããã°ã§ã¯ããããã¦Claude 3 ãã¡ããªã¼â¦
ããã«ã¡ã¯ããã¯ãã«ã«ãµãã¼ã課㮠ä½è¤ å æã§ãã æ¬ããã°ã¯ EC2 ã¤ã³ã¹ã¿ã³ã¹ã® Windows Server 2022 ã«æ¤è¨¼ãç®çã¨ãã Oracle Database ãæ§ç¯ããæé ä¾ãç´¹ä»ããããã°ã¨ãªãã¾ãã æ¬ããã°ã§ã¤ã³ã¹ãã¼ã«ãã Oracle Database 19c 㯠OTN éçºâ¦
ã¨ã³ã¿ã¼ãã©ã¤ãºã¯ã©ã¦ãé¨ã®å±±ä¸(ç¥)ã§ãã æ¬ããã°ã§ã¯ãç¹å®ã¿ã°ã®ã¿ç·¨éã»åé¤ãåºæ¥ãªãããã«ããIAMããªã·ã¼ã«ã¤ãã¦èª¬æãã¾ãã ã¦ã¼ã¹ã±ã¼ã¹ã®ä¾ ãµã³ãã«ããªã·ã¼ åä½æ¤è¨¼ Environmentã¿ã°ã®ç·¨éã»åé¤ ãã®ä»ã®ã¿ã°ã®ä½æã»ç·¨éã»åé¤ Enviroâ¦
ã¯ããã« æ¡ã®å£ç¯ãªã¯ããã®ã«ãæãããªã£ããå¯ããªã£ããæãããªã£ããã¨ããããããæãã§ããã ãããªã¨ããããä½ãåããã¦ãªãã¬ãã·ã¥ããã®ãããããããã¾ãããã ã¨ãããã¨ã§ãã©ããã温度ã¨æ¯åã®ãã¨ãæé ã«ãããã¨ããæãè¦ãã¾ãâ¦
ããã«ã¡ã¯ï¼ã¨ã³ã¿ã¼ãã©ã¤ãºã¯ã©ã¦ãé¨ã¯ã©ã¦ãã³ã³ãµã«ãã£ã³ã°èª²ã®æ¥é«ã§ãã ããç§ã®ãã¨ãå°ãã§ãç¥ãããã¨æã£ã¦ããã ãããªããç§ã®å¾è¼©ãæ¸ãã¦ããã以ä¸ã®ããã°ãè¦ãã¦ã¿ã¦ãã ããã sabawaku.serverworks.co.jp ä»åã¯ãAWS Network Fireâ¦
ããã«ã¡ã¯ãEnterprise Cloudé¨ ã½ãªã¥ã¼ã·ã§ã³ã¢ã¼ããã¯ã1課 宮形 ã§ãã æ¬BLOGã§ã¯ã¬ãã¡ã³ãã¯ã©ã¦ãAWSã«ããã¦ããªã³ãã¬ãã¹ã®ãµã¼ãã¼ãP2VãV2Vã®ææ³ã§ã¯ã©ã¦ããªãã(ã¯ã©ã¦ã移è¡)ãããã¨ãå¯è½ãæ¤è¨ããå 容ããç´¹ä»ãã¾ãã æ¿åºãã¸ã¿ã«â¦
3æããã«ã¹ã¿ãã¼ãµã¯ã»ã¹é¨ã«ç°åãã¾ããå±±ï¨ã§ãã ä»åã¯ã¯ãã¹ã¢ã«ã¦ã³ãã§Secrets Managerã®ã·ã¼ã¯ã¬ãããåå¾ããæ¹æ³ã«ã¤ãã¦æ´çãããã¨æãã¾ã æ³å®ããã¦ã¼ã¹ã±ã¼ã¹ ä»åã®æ§æ åAWSã¢ã«ã¦ã³ãã§å¿ è¦ã¨ãªãä½æ¥ ã¢ã«ã¦ã³ãA IAM 管çã¢ã«ã¦â¦
ããã¼ã¸ããµã¼ãã¹é¨ ä½ç«¹ã§ããæ¬ããã°ã§ã¯ãããã©ã«ããµã¼ãã¹ãã¼ã§ãããaws/rdsãã§æå·åæ¸ã¿ã® RDS DB ã¤ã³ã¹ã¿ã³ã¹ãããã®ä»ã® AWS ã¢ã«ã¦ã³ãã¸ç§»è¡ããæ¹æ³ã«ã¤ãã¦è¨è¼ãã¦ãã¾ããæ¬ããã°ãå¤ãã®ããããã¤ã³ããåé¿ããã¯ãã¹ã¢ã«ã¦ã³ãâ¦
ããã«ã¡ã¯ãAWS CLIã好ããªç¦å³¶ã§ãã ã¯ããã« åèæ å ± æ§æå³ Webã¢ããªä¸ã§ã¦ã¼ã¶ã¼æ å ±ãåå¾ããæ¹æ³ ã¦ã¼ã¶ã¼æ å ±ã確èªã§ããALBã®ãªã¯ã¨ã¹ããããã¼ x-amzn-oidc-accesstoken(Cognitoãçºè¡) x-amzn-oidc-data(ALBãçºè¡) è£è¶³ ãã¤ã³ã ã©ã®ãµâ¦
ã¨ã³ã¿ã¼ãã©ã¤ãºã¯ã©ã¦ãé¨ã®å±±ä¸(ç¥)ã§ãã æ¬ããã°ã§ã¯ãAWS Network Firewallï¼ä»¥ä¸ãNFWï¼ã®ã¹ãã¼ããã«ã«ã¼ã«ã®ããããã¢ã¯ã·ã§ã³ã§é¸æå¯è½ãªãã確ç«ãããæ¥ç¶ã®ãã±ããããããããã¨ããã¹ã¦ããããããã®æåã®éãã確èªãã¾ãã ãæ¨æºã¹â¦
ã¯ããã« æ¥ã«ãªãã¾ããããæ¥ã¨ããã°ã ãã¨ã¯ãã å ¥å¦ãå ¥ç¤¾ãªã©æ°ãã«ä¸æ©ãè¸ã¿åºããã¨ãå¤ãå£ç¯ã«ãªãã¾ãã ã¨ãããã¨ã§ãã¢ããªã±ã¼ã·ã§ã³ãµã¼ãã¹é¨ã®æ£®ã§ãã åããªã«ãæ°ãããã¨ããããããªï¼ã¨æããä¹ ã ã¨ã³ã¸ãã¢ãªã³ã°çãªææ¦ããã¦â¦
AWS Network Firewall ã®ãã¹ããªã¼ã ä¾å¤ããªã·ã¼ãã«ããã¦ããContinueããé¸æããã±ã¼ã¹ãæ¸ãã¦ã¿ãã
apt updateããæã«apt-keyã®ã¨ã©ã¼ã§ã¢ãããã¼ãã§ããªãã£ãã®ã§ããã®éã«èª¿ã¹ããã¨ãã¾ã¨ãã¾ããã
ããã«ã¡ã¯ããã¯ãã«ã«ãµãã¼ã課㮠ä½è¤ å æã§ãã æ¬ããã°ã¯ AWS ã® RDS DB ã¤ã³ã¹ã¿ã³ã¹ãããªã³ãã¬ãã¹ç°å¢ä¸ã« DB ç°å¢ãæ§ç¯ããã« SQL ã®ç·´ç¿ãããæ¹æ³ãç´¹ä»ãã¾ãã ä»å¾ã®ãã£ãªã¢ãæ¡ä»¶ç㧠DBA ã¨ãã¦æ´»èºãèãã¦ããå ´åã«ã¯ DB ã¨ã³ã¸ã³â¦
ããã«ã¡ã¯ããã¯ãã«ã«ãµãã¼ã課ã®æ£®æ¬ã§ãã ã客æ§ããã®ãåãåãããããã ãä¸ã§ãDynamoDB ãã¼ãã«ã®ããã¯ã¢ããã AWS Backup ã«ã¦åå¾ããéã« KMS ãã¼ã¨ã©ã¼ãçºçããã¨ã®ãåãåãããããã ãã¾ããã®ã§ãã®é¡æ«ãç´¹ä»ãããã¾ãã [åæâ¦
3æããã«ã¹ã¿ãã¼ãµã¯ã»ã¹é¨ã«ç°åãã¾ããå±±ï¨ã§ãã å¼ç¤¾å ã§ã¯Slackãã¡ã¤ã³ã®ã³ãã¥ãã±ã¼ã·ã§ã³ãã¼ã«ã§ãããããã¡ã¼ã«ãé »ç¹ã«å©ç¨ãããã¨ã¯ããã¾ããã ãã ãç§ãã¡ãæ®æ®µãªã«ããªãå©ç¨ãã¦ããã¡ã¼ã«ã®ä»çµã¿ãæ°ã«ãªã£ãã®ã§å°ã調ã¹ã¦æ¤è¨¼â¦
ããã«ã¡ã¯ãæ«å»£ã§ãã å¼ç¤¾å±±æ¬ã®ããã°ã§ç´¹ä»ããã¦ãã ãCodeBuild 㧠AWS Lambda ã®ã©ã³ã¿ã¤ã ã使ç¨ãããã«ããå¯è½ã«ãªãã¾ããããå®éã« Lambda ã使ç¨ã㦠Java ããã°ã©ã ããã«ããã¦ã¿ãã®ã§ããã°ã«ã¾ã¨ãã¾ãã blog.serverworks.co.jp ãâ¦
ããã«ã¡ã¯ãEnterprise Cloudé¨ ã½ãªã¥ã¼ã·ã§ã³ã¢ã¼ããã¯ã1課 宮形 ã§ãã ä»äºæãã¸ã¿ã«åºã®ãã¼ã ãºã¼ã¸ãè¦ãæ©ä¼ãå¤ãã®ã§ãããå人çãªææã§ã¬ã¤ã¢ã¦ããã·ã³ãã«ã§è¦ãããããã«å é²çã»æªæ¥çã§ã«ãã³ãããªã¨æã£ã¦ãã¾ãããæåãã©ã³ãã¯â¦
ããã¼ã¸ããµã¼ãã¹é¨ ä½ç«¹ã§ããæ¬ããã°ã§ã¯ãæ°æ©è½ã§ããã³ã¹ãé åã¿ã°ã®ããã¯ãã£ã« (Backfill) ã«ã¤ãã¦ãã³ã¹ãé åã¿ã°ã®ä»æ§ã¨å ±ã«æ©è½ã®è©³ç´°ã解説ãã¦ãã¾ããæ¬æ©è½ã¯ãæ大12ãæåã¾ã§ãç¾å¨ã®ã³ã¹ãé åã¿ã°ã® Active / Inactive ã®è¨å®ãâ¦
ã¨ã³ã¿ã¼ãã©ã¤ãºã¯ã©ã¦ãé¨ã®æ¾ç°ã§ããããã«ã¡ã¯ã ä»åã¯æ¥åã§è¡ã£ãæè¡æ¤è¨¼ã®è¨é²ã«ãªãã¾ãã å°ã éå¤ãªè¨äºã«ãªãã¾ãããä»ãåãé ãã¾ãã¨å¹¸ãã§ãã ããããã㨠1. åã¨ã¼ã¸ã§ã³ããã©ããã£ã¦ã¤ã³ã¹ãã¼ã«ããã 2. SSMããã³CloudWatchã®â¦
WAFã®ã«ã¦ã³ãã¢ã¼ãã®ããã«ã¢ã©ã¼ãã«ã¼ã«ã®ã¿è¨å®ããã°é信許å¯&ã¢ã©ã¼ããã°åºååºæ¥ãã ããã¨æã£ã¦ãããéã£ããããåããããªåéããåºããã¨ãé²ãããè¨äºã«ãã¾ããã
Network Firewallã®ã«ã¼ã«è¨å®ã«ããããã©ãã£ãã¯ã®æ¹åããªãã·ã§ã³ã«ã¤ãã¦å®éã«åä½æ¤è¨¼ãã¦ã¿ã¾ããã
Terraformã使ç¨ãã¦ãS3ã®CloudTrailãã¼ã¿ã¤ãã³ãããªã³ã«ããæ¹æ³ã試ãã¦ã¿ã¾ããã
çãããããã«ã¡ã¯ï¼ãµã¼ãã¼ã¯ã¼ã¯ã¹ã®Anhã§ãã AWSç°å¢ä¸ã§çæAIã¢ãã«ã®æ§ç¯ã«èå³ããããAmazon SageMakerã®Studioã¨Canvasã®éããæ°ã«ãªã£ãã®ã§èª¿æ»ãã¾ããã ãã®ããã°ã§ã¯ã主ã«ãããã®ãµã¼ãã¹ã®æ¦è¦ã«è§¦ãã¦ãã¾ãã SageMaker Studioã¨Saâ¦
ããã«ã¡ã¯ãããã¼ã¸ããµã¼ãã¹å¤§åã§ãã ISUCONéå»åã®ç°å¢ã«ãRubyãPythonãphpã®New Relic APMãå ¥ãã¦ã¿ã¾ãããå½ããã°ã§ã¯ä¸ã®å 容ãæ¸ãã¾ãã AWSã«ãªã¼ã«ã¤ã³ã¯ã³ç°å¢æºå New Relic APM ã¤ã³ã¹ãã¼ã« ãã³ããã¼ã¯ãã¼ã«ãå®è¡ New Relicã«ãâ¦
ããã«ã¡ã¯ãEnterprise Cloudé¨ ã½ãªã¥ã¼ã·ã§ã³ã¢ã¼ããã¯ã1課 宮形 ã§ãã æ¨å¹´ 令å5年度ã¯ã¬ãã¡ã³ãã¯ã©ã¦ãé¢é£ã®ããã¸ã§ã¯ãã«é¢ããæ©ä¼ãããã ããå°æ¹èªæ²»ä½æ§åãã«AWSã®å½¹åè²»ç¨ã»å©ç¨æéã®è¦ç©ããæä¼ãããæ©ä¼ãå¤ã ããã¾ããããã®ãªâ¦