ããã«ã¡ã¯ãEnterprise Cloudé¨ ã½ãªã¥ã¼ã·ã§ã³ã¢ã¼ããã¯ã1課 宮形 ã§ãã
æ¬BLOGãè¨è¼ãã¦ããã®ã¯ 2024å¹´6æä¸æ¬ãªã®ã§ããã令å6年度ã¬ãã¡ã³ãã¯ã©ã¦ãæ©æ移è¡å£ä½æ¤è¨¼äºæ¥ã®ç¬¬2åå ¬åæé*1ãè¡ããã¦ããæã§ãããå¾æ¥å ¬åã®æ¡æçµæãå ¬éãããã¨æãã¾ãã®ã§ãçæ§ãä½ãã®å¸çºæã対象ã«ãªã£ã¦ãããçºããã®ãããããããã¾ããã
ä»åã®BLOGã§ã¯ãã¬ãã¡ã³ãã¯ã©ã¦ãããå©ç¨éå§ãããå°æ¹èªæ²»ä½æ§ãããç¸è«ã®å¤ããè·å¡ãéç¨ç®¡çè£å©è ãå©ç¨ããéçºã»éç¨IAMãã¼ã«ã®æ¨©éå¶éãã©ã®ããã«ããã°ããããã«ã¤ãã¦ãç§ãªãã®æ¤è¨ããå 容ããç´¹ä»ãããã¨æãã¾ãã
æ¬BLOGã®å 容ã¯ãç§ãããã¾ã§ã®è·åã§å¾ãçµé¨ã«åºã¥ãå人çãªèå¯ã«ãªãã¾ãããåèããã ãéã¯ããã®æ¹ã®è²¬ä»»ã®ç¯çã§ãé¡ããããã¾ãã è¨è¼ã«ééããç¡ããã注æãæã£ã¦ããã¾ãããåçåºããæ¡å ãããã¬ã¤ãã©ã¤ã³ãè³æãAWSã®å ¬å¼ããã¥ã¡ã³ãã¨å·®ç°ãããå ´åã¯ããããã®è³æãæ£ã¨ãããããé¡ããã¾ãã
- ã¬ãã¡ã³ãã¯ã©ã¦ãã«ããããã¹ã¤ãããã¼ã«ãã¨ãéçºã»éç¨IAMãã¼ã«ãã«ã¤ãã¦
- ãªã権éå¶éãè¡ãå¿ è¦ãããã®ã
- IAMãã¼ã«ã§æ¨©éå¶éãã¹ãæ¯ãèã
- Systems Manager Session ManagerãFleet Managerã EC2 Instance Connect Endpoint ã®å©ç¨ç¦æ¢
- AMIãEBSã¹ãããã·ã§ãããRDS ã¹ãããã·ã§ãããSystem Manager Document ã®ä»ã¢ã«ã¦ã³ãã¸ã®å ±æç¦æ¢
- NAT GatewayãInternet GatewayãVPC Peering ã®ä½æç¦æ¢
- æ°ããªIAMã¦ã¼ã¶ã¼ã®ä½æç¦æ¢
- IAMã¦ã¼ã¶ã¼ã¸ã® ã¢ã¯ã»ã¹ãã¼ãã·ã¼ã¯ã¬ãããã¼ã®è¨å®ç¦æ¢
- AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ä¸ã§ã® S3ãRDSãCloudWatch çã®å®ãã¼ã¿ã®èªã¿åãè¡çºç¦æ¢
- ã³ã³ã½ã¼ã«ä¸ããã® Amazon RDS ã¸ã® Export è¡çºç¦æ¢
- CloudShell ã®å©ç¨ç¦æ¢
- ã¾ã¨ã
ã¬ãã¡ã³ãã¯ã©ã¦ãã«ããããã¹ã¤ãããã¼ã«ãã¨ãéçºã»éç¨IAMãã¼ã«ãã«ã¤ãã¦
ãã¹ã¤ãããã¼ã«ãã«ã¤ãã¦ã¯ããã¾ã§æ°å¤ãã®å¼ç¤¾BLOGãä¸è¬Webãµã¤ãã§ç´¹ä»ããã¦ããã¾ãã®ã§ã説æã¯å²æãã¾ãã å¼ç¤¾ã®ä¸è¨è¨äºãå®éã®æä½ç»é¢ã¤ã¡ã¼ã¸ãããå人çã«ãããããããã¨æãã¾ããåè¦ã®æ¹ã¯æ¯éã覧ãã ããã
ã¬ãã¡ã³ãã¯ã©ã¦ãã«ããã¦ã¯ GCAS-SSO ã¸ã®ç§»è¡ã«ä¼´ããä¸è¬çãªAWSå©ç¨ã«ãããã¹ã¤ãããã¼ã«ã¨ã¯ç°ãªã£ã¦ããã¾ããä¸è¨ã®é¢ä¿ã«ãªã£ã¦ããã¾ãã*2
ãã®å³ã§ãããéçºã»éç¨IAMãã¼ã«ãããè·å¡ãéç¨ç®¡çè£å©è ã®å¾äºè ãAWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã§æ§ç¯ã»éç¨ä¿å®ãè¡ãæã®æ¨©éã«ç¸å½ãã¾ããä»åã¯ãã®IAMãã¼ã«ã®æ¨©éå¶å¾¡ãèãã¾ããGCAS-SSO ã«ã¤ãã¦ã¯ä¸è¨BLOGã§ãç´¹ä»ãã¦ããã¾ãã®ã§ããããã¦ã覧ããã ããã¨å¹¸ãã§ãã
ãªã権éå¶éãè¡ãå¿ è¦ãããã®ã
ãªã権éå¶éãè¡ãå¿ è¦ãããã®ãã¨ããã¨ãã¬ãã¡ã³ãã¯ã©ã¦ãä¸ã®ã·ã¹ãã ãæ§ç¯ã»éç¨ä¿å®ããè·å¡ããã³ãã¼ï¼éç¨ç®¡çè£å©è ï¼å¾äºè ã«ãã¦æ¬²ãããªãäºãããããã§ãããã®æãããã®ãããã¼ã¿ã®å¤é¨ã¸ã®æã¡åºããã ã¨æããã¾ãã
å°æ¹èªæ²»ä½æ§ã®å©ç¨ããã¬ãã¡ã³ãã¯ã©ã¦ãã«ããã¦ã¯ãå¸çºæã«ãä½ãæ¹ã ã®ãã¤ãã³ãã¼ãå«ãå人æ å ±ãæ ¼ç´ããã¦ããã¾ãããããã¯æ±ºãã¦å¤é¨ã«æ¼æ´©ãã¦ã¯ããã¾ããã®ã§ãè·å¡ããã³ãã¼ãæ æã®æç¡ãé¢ããããã¼ã¿ãå¤é¨ã«æã¡åºããç¶æ ã«ãã£ã¦ã¯ããã¾ããã
ã¬ãã¡ã³ãã¯ã©ã¦ãAWSã®æ§ç¯ã»éç¨ä¿å®ã®æä½ã¯ãã²ã¨ã¤ã®ã¦ã§ããã©ã¦ã¶ä¸ã§æä½ãå®çµãã AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã« ãå©ç¨ãã¾ããAWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã¯ã¤ã³ã¿ã¼ãããã«æ¥ç¶ãã¦å©ç¨ãã¾ãããã®AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ä¸ã§å人æ å ±ãæ¼æ´©ããå¯è½æ§ã®ããè¡çºã¯æ±ºãã¦è¡ã£ã¦ã»ãããªãçã§ãããã³ã³ã½ã¼ã«ä¸ã§ã®æä½ã®æ¨©éå¶éããå°æ¹èªæ²»ä½æ§ã§ã®æ¤è¨ãã¼ãã¨ãªãã¾ãã
IAMãã¼ã«ã§æ¨©éå¶éãã¹ãæ¯ãèã
ããããã¯ãç§ãªãã«èããã¬ãã¡ã³ãã¯ã©ã¦ãAWSã§ã®ãéçºã»éç¨IAMãã¼ã«ãã«æ¨©éå¶å¾¡ããã¹ãã¨æãããè¡çºã¨ããã®è¡çºãç¦æ¢ããããã®è¨å®æ¹æ³ããç´¹ä»ãã¾ãããã®ãã¡ã®å¤ã㯠IAMããªã·ã¼ ã¨ãã IAMãã¼ã«ãå«ã IAM ã¢ã¤ãã³ãã£ã㣠ã¾ã㯠AWSãªã½ã¼ã¹ã«ã¢ã¿ãã(å²ãå½ã¦)ãã権éã»ããã§å®ç¾ãã¾ããè¨å®ã¨ãã¦ã¯ JSON ãã©ã¼ãããã§è¨è¼ãå¯è½ã¨ãªã£ã¦ããã¾ãã®ã§ããã®ãµã³ãã«ãåããã¦ãç´¹ä»ãã¾ãã
Systems Manager Session ManagerãFleet Managerã EC2 Instance Connect Endpoint ã®å©ç¨ç¦æ¢
Systems Manager Session ManagerãFleet ManagerãEC2 Instance Connect Endpoint ã¯ãä»®æ³ãµã¼ãã¼ã«ããã EC2 ã®ã³ã³ã½ã¼ã«ãæä¾ããAWSæ©è½ã«ãªãã¾ããWebãã¼ã¹ã® AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã« ãããµã¼ãã¼ã®CLIãGUI ãå©ç¨ã§ãã¾ãã®ã§ãéç¨ä¿å®ã容æã«ããå°ç¨ã®ä¿å®ç«¯æ«ããããã¯ã¼ã¯ãä¸è¦ã¨ãªãã³ã¹ãåæ¸ã«ãå¯ä¸ãã¾ããAWSããã¸ã¡ã³ãã³ã³ã½ã¼ã« ãå©ç¨ããä¿å®ç«¯æ«ã®ã»ãã¥ãªãã£æ¬¡ç¬¬ãªã¨ãããããã¾ãããå°æ¹èªæ²»ä½æ§æ¯ã®ã»ãã¥ãªãã£ããªã·ã¼ã«ãã£ã¦ã¯å©ç¨ãå¶éããããã±ã¼ã¹ãããããã¨æããã¾ãã
ãã®å ´åã¯ããããã®æ©è½å©ç¨ãç¦æ¢ããããªã·ã¼ããéçºã»éç¨IAMãã¼ã«ãã«é©ç¨ããã¹ããã¨æããã¾ãã
AMIãEBSã¹ãããã·ã§ãããRDS ã¹ãããã·ã§ãããSystem Manager Document ã®ä»ã¢ã«ã¦ã³ãã¸ã®å ±æç¦æ¢
Amazon ãã·ã³ã¤ã¡ã¼ã¸ (以ä¸AMIã¨è¨)ãAmazon Elastic Block Store (以ä¸EBSã¨è¨)ã®ã¹ãããã·ã§ãããAmazon RDS ã®ã¹ãããã·ã§ããããããã¯ãµã¼ãã¼ã®ããã¯ã¢ããã¨ãã¦ä¸è¬çã«å©ç¨ãããAWSã®æ©è½ã«ãªãã¾ãããã®ããã¯ã¢ããã¯ä»ã®AWSã¢ã«ã¦ã³ãåãã«å ±æãããã¨ãå¯è½ã§ãAWSéã®ãã¼ã¿ç§»è¡ããµã¼ãã¼ã¤ã¡ã¼ã¸ã®å¤é¨å ¬éãªã©ã«å©ç¨ã§ãã¾ãã便å©ãªæ©è½ã§ã¯ããã¾ããããã¤ãã³ãã¼ãå«ãæ¨æºæºæ ã·ã¹ãã çã§ã¯å¤é¨ã¸ã®ãã¼ã¿æ¼æ´©ã®åã£æãã«ãªããã¾ãã
ãããã®å ±æè¡çºãç¦æ¢ããããªã·ã¼ããéçºã»éç¨IAMãã¼ã«ãã«é©ç¨ããã¹ããã¨æããã¾ãã
NAT GatewayãInternet GatewayãVPC Peering ã®ä½æç¦æ¢
NAT Gatewayã Internet Gateway 㯠VPC å ã®ãã©ã¤ãã¼ããããã¯ã¼ã¯ä¸ã®AWSãªã½ã¼ã¹ãå¤é¨ã¤ã³ã¿ã¼ãããã¸æ¥ç¶ããéããéã«å¤é¨ã¤ã³ã¿ã¼ãããåãã«ãã©ã¤ãã¼ããããã¯ã¼ã¯å ã®ãã¼ããã©ã³ãµã¼ããµã¼ãã¼ãå ¬éãã¦å¤é¨ããã®ã¢ã¯ã»ã¹ããéãªã©ã«å©ç¨ãã¾ãããã¤ãã³ãã¼ãå«ãæ¨æºæºæ ã·ã¹ãã çã¯å¤é¨ã¤ã³ã¿ã¼ãããããåé¢ããå¿ è¦ãããã¾ã*3ã
åãµã¼ãã¼ãã¤ã³ã¿ã¼ãããã¨æ¥ç¶ããã¨ãå¤é¨ã¸ã®ãã¼ã¿æ¼æ´©ã®ãªã¹ã¯ãé«ã¾ãã¾ãã®ã§ãNAT GatewayãInternet Gateway ã®ä½æè¡çºãç¦æ¢ããããªã·ã¼ããéçºã»éç¨IAMãã¼ã«ãã«é©ç¨ããã¹ããã¨æããã¾ãã
ã¾ããVPC Peering ã¯VPCå士ãæ¥ç¶ããæ©è½ã§ããæå³ãããã¤ãã³ãã¼ç³»ãããã¯ã¼ã¯ä»¥å¤ã¨æ¥ç¶ãã¦ãã¾ããªã¹ã¯ã«ããªããã¾ãã®ã§ããã¡ããç¦æ¢ããããªã·ã¼ã®é©ç¨æ¤è¨ä½å°ããããã¨æãã¾ãã
ãªããå®éæä½ã§ç¢ºèªã¯ãã¦ããªãã®ã§ãããã¬ãã¡ã³ãã¯ã©ã¦ãAWSã«ããã¦ã¯æ¬çªã¢ã«ã¦ã³ãã§ã¯æ¨æºã§ Internet Gateway ã®ä½æãç¦æ¢ããã¦ããããã以å¤ã®éç¨ç®¡çã¢ã«ã¦ã³ããæ¤è¨¼ã¢ã«ã¦ã³ãã§ã¯ãã®å¶éã¯ç¡ãããã§ãããããã¯ã¼ã¯æ§æ次第ã§ãããæ¬çªã¢ã«ã¦ã³ã以å¤ã§ãå¤é¨ã¤ã³ã¿ã¼ãããã¨ã®æ¥ç¶ç¹ã¯ä½æãããã¹ãã§ã¯ãªãã¨èããå°æ¹èªæ²»ä½æ§ã大åãã¨æãã¾ãã
æ°ããªIAMã¦ã¼ã¶ã¼ã®ä½æç¦æ¢
IAMã¦ã¼ã¶ã¼ã¯AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã¸ã®æ¥ç¶ã«ãã¡ããIDãã¹ã¯ã¼ãèªè¨¼ã¨ãè¡ãæä½ã®ç¯å²ãå®ç¾©ããèªå¯ã§æ§æããã¾ããã¬ãã¡ã³ãã¯ã©ã¦ãã«ããã¦ã¯AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã¸æ¥ç¶ã®èªè¨¼ã«IAMã¦ã¼ã¶ã¼ã¯å©ç¨ãããGCASå´ã§æä¾ããèªè¨¼æ å ±ãç¨ãã¾ããèªè¨¼æ å ±ã¯å¿ è¦æå°éã¨ããã¹ãã§ãããã¾ãè·å¡ãéç¨ç®¡çè£å©è ã®å¾äºè ãæ°ãã«IAMã¦ã¼ã¶ã¼ãä½æããã¨ããªããã¾ããèªè¨¼æ å ±ã®æ¼æ´©ãªã¹ã¯ãé«ã¾ãã¾ããIAMã¦ã¼ã¶ã¼ä½æãç¦æ¢ããããªã·ã¼ããéçºã»éç¨IAMãã¼ã«ãã«é©ç¨ããã¹ããã¨æããã¾ãã
ãªããAWSã§ã¯ç®¡çããªã·ã¼ã¨ã㦠PowerUserAccess ãæä¾ããã¦ããããã¡ãã«ã¯AWSãªã½ã¼ã¹ã®æ§ç¯ã»éç¨ä¿å®ãè¡ãããã§ã®å¿ è¦ååãªæ¨©éãä»ä¸ããã¦ããã¾ãããIAMã¦ã¼ã¶ã¼ãIAMã°ã«ã¼ãã«é¢ãããã¹ã¦ã®æ¨©éãå«ã¾ãã¦ããã¾ãããPowerUserAccess ãç¨ãããã¨ã§IAMã¦ã¼ã¶ã¼ä½æãç¦æ¢ãããã¨ãã§ãã¾ãã
IAMã¦ã¼ã¶ã¼ã¸ã® ã¢ã¯ã»ã¹ãã¼ãã·ã¼ã¯ã¬ãããã¼ã®è¨å®ç¦æ¢
IAMã¦ã¼ã¶ã¼ã«ã¢ã¯ã»ã¹ãã¼ãã·ã¼ã¯ã¬ãããã¼ãè¨å®ãããã¨ã§ãå¤é¨ã¯ã©ã¦ãããªã³ãã¬ãã¹ç AWS以å¤ã®ã·ã¹ãã ããµã¼ãã¹ã¨AWSéãé£æºãããã¨ãã§ãã¾ããã¢ã¯ã»ã¹ãã¼ãã·ã¼ã¯ã¬ãããã¼ã¯é©åãªå©ç¨ã«ããã¦ã¯ä¾¿å©ã§ãããå¤é¨æ¼æ´©ããã¨ä¹ã£åããä¸æ£ã¢ã¯ã»ã¹ã«æªç¨ãããã¨ãã£ããªã¹ã¯ãããã¾ãã
ã¬ãã¡ã³ãã¯ã©ã¦ãã«ããã¦ã¯ã¢ã¯ã»ã¹ãã¼ãã·ã¼ã¯ã¬ãããã¼ã®å©ç¨ã¯ååç¦æ¢ã¨ãªã£ã¦ãã*4ããã¸ã¿ã«åºã®ããªã·ã¼æ¨æºã§è¨å®ã§ããªãã¨ããã¾ãã®ã§ããéçºã»éç¨IAMãã¼ã«ãã«ããã¦ããã®å¶éãè¸è¥²ãããã¨æããã¾ãã
AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ä¸ã§ã® S3ãRDSãCloudWatch çã®å®ãã¼ã¿ã®èªã¿åãè¡çºç¦æ¢
S3ãã±ãããRDS ã¯æ¨æºæºæ ã·ã¹ãã çã§ãã¼ã¿ããã°ã®æ ¼ç´ã«å©ç¨ãããã¨ãå¤ãã¨æããã¾ããã¾ã CloudWatch Logs ããã°ã®æ ¼ç´ã«å©ç¨ããã¾ãã注æãå¿ è¦ãªã®ããAWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã«ã¯ãããAWSãµã¼ãã¹ããªã½ã¼ã¹ä¸ã®ãã¼ã¿ãéããããã¦ã³ãã¼ããããããæ©è½ãåãã£ã¦ãããã¨ã§ããå人æ å ±ãå«ããã¼ã¿ãé²è¦§ããè·å権éãä¸ããããªãè·å¡ãéç¨ç®¡çè£å©è ããæå³ãããã¼ã¿ãå ¥æãã¦ãã¾ããªããããéçºã»éç¨IAMãã¼ã«ãã«ããã¦ã¯è¡çºãç¦æ¢ãã¹ããã¨æãã¾ãã
ã¬ãã¡ã³ãã¯ã©ã¦ãã«ããã¦ã¯æ¨æºã§ AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ä¸ã§ã® S3ãRDSãCloudWatch çã®å®ãã¼ã¿ã®èªã¿åããè¡ããªãããå¶éãæãã£ã¦ããã¨ã®æ å ±ãããã¾ãããéçºã»éç¨IAMãã¼ã«ãã«ããã¦ããã®å¶éãè¸è¥²ãããã¨æããã¾ãããææ°ã®ä»æ§ã«ã¤ãã¦ã¯ãã¸ã¿ã«åºããæ¡å ãããè³æãã覧ãã ããã
ã³ã³ã½ã¼ã«ä¸ããã® Amazon RDS ã¸ã® Export è¡çºç¦æ¢
Amazon RDS ã¯AWSãæä¾ãããªã¬ã¼ã·ã§ãã«ãã¼ã¿ãã¼ã¹ã®ããã¼ã¸ããµã¼ãã¹ã§ããOSãå©ç¨è ãéç¨ä¿å®ããå¿ è¦ããªããã¨ãããAWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ããè¤æ°ã®ãã¼ã¿ãã¼ã¹æä½ãè¡ããããã«ãªã£ã¦ãã¾ãããã®æä½ã§ã¯ Export (ãã¼ã¿ãã¼ã¹ã«ãã£ã¦ã¯ãã³ããã·ãªã¢ã©ã¤ãºçã¨è¡¨ç¾)ãå¯è½ã¨ãªãã¾ããAmazon RDS ã¯æ¨æºæºæ ã·ã¹ãã çã®ãã¼ã¿ãæ ¼ç´ãã¦ãã¾ãã®ã§å人æ å ±ãå«ããã¨ãèãããã¾ããExportããè¡çºã¯ãã¼ã¿ã®é²è¦§ã¨åæ§ã¨è¦ãªããã¾ãã®ã§ãè·å権éãä¸ããããªãè·å¡ãéç¨ç®¡çè£å©è ãä¸ç¨æã«ãã¼ã¿æã¡åºããããªããããéçºã»éç¨IAMãã¼ã«ãã«ããã¦ãããè¡çºãç¦æ¢ãã¹ããã¨æãã¾ãã
ã¬ãã¡ã³ãã¯ã©ã¦ãã«ããã¦ã¯æ¨æºã§ã¯ AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ãã RDS ã¸ã® Exportè¡çº ã«å¶éãæãã£ã¦ããã¨ã®æ å ±ãããã¾ãããéçºã»éç¨IAMãã¼ã«ãã«ããã¦ããã®å¶éãè¸è¥²ãããã¨æããã¾ãããææ°ã®ä»æ§ã«ã¤ãã¦ã¯ãã¸ã¿ã«åºããæ¡å ãããè³æãã覧ãã ããã
CloudShell ã®å©ç¨ç¦æ¢
CloudShell ãå©ç¨ãããã¨ã§ãAWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ä¸ãã Webãã©ã¦ã¶ãç¨ãã¦CLIã§AWSãµã¼ãã¹ããªã½ã¼ã¹ãå¶å¾¡ãããã¨ãã§ãã¾ãããã® CloudShell ã§ãããEC2ã®OSãªã¢ã¼ãæ¥ç¶ãRDSã®ãã¼ã¿ãã¼ã¹æ¥ç¶ãS3ãã±ããã®ç §ä¼ã¨ãã£ãè¡çºãCLIä¸ã§åºæ¥ã¦ãã¾ãã¾ããæå³ããæ¨æºæºæ ã·ã¹ãã çã®ãã¼ã¿ãAWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ä¸ã§è¡¨ç¤ºã§ãã¦ãã¾ãå¯è½æ§ããããã¨ãããéçºã»éç¨IAMãã¼ã«ãã«ããã¦å©ç¨ãç¦æ¢ãã¹ããã¨æãã¾ãã
ã¬ãã¡ã³ãã¯ã©ã¦ãã«ããã¦ã¯æ¨æºã§ã¯ AWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ãã CloudShell ãèµ·åã§ããªãããå¶éãæãã£ã¦ããã¨ã®æ å ±ãããã¾ãããéçºã»éç¨IAMãã¼ã«ãã«ããã¦ããã®å¶éãè¸è¥²ãããã¨æããã¾ãããææ°ã®ä»æ§ã«ã¤ãã¦ã¯ãã¸ã¿ã«åºããæ¡å ãããè³æãã覧ãã ããã
ã¾ã¨ã
ãããã§ããã§ãããããAWSçã®ãããªãã¯ã¯ã©ã¦ãã¯ã¤ã³ã¿ã¼ãããä¸ã§å©ç¨ããã¤ã¡ã¼ã¸ãããæ©å¯æ§ã®é«ããã¼ã¿ãæ ¼ç´ãããã¨ããå¿é ãããæ¹ãå¤ãã¨æãã¾ããæ¬BLOGã§ãç´¹ä»ããæ¯ãèãããéçºã»éç¨IAMãã¼ã«ãã§å¶éãããã¨ã§ãæå³ãããã¼ã¿ãå¤é¨ã¸æã¡åºãããããªã¹ã¯ãå¤§å¹ ã«æå¶ã§ãããã¨ããåããããã ãããã¨æãã¾ããæ¬BLOGã®å 容ãçæ§ã®å°ãã§ãã®ãåèã«ãªãã°å¹¸ãã§ãã
*1:令å6年度ã¬ãã¡ã³ãã¯ã©ã¦ãæ©æ移è¡å£ä½æ¤è¨¼äºæ¥ï¼https://www.digital.go.jp/news/413c222d-5837-4017-b344-6d3e54d15405
*2:ãã¸ã¿ã«åº GCASã¬ã¤ãï¼ãã¼ã ã¬ãã¡ã³ãã¯ã©ã¦ã AWS å©ç¨ã¬ã¤ãGCAS-SSOã¸ã®ç§»è¡ã«ä¼´ã対å¿(AWSç·¨)
*3:2023å¹´9æ - å°æ¹å ¬å ±å£ä½æ å ±ã·ã¹ãã æ¨æºååºæ¬æ¹é : https://www.digital.go.jp/assets/contents/node/basic_page/field_ref_resources/c58162cb-92e5-4a43-9ad5-095b7c45100c/f6ea9ca6/20230908_policies_local_governments_outline_03.pdf
*4:ãã¸ã¿ã«åº GCASã¬ã¤ãï¼ã¬ãã¡ã³ãã¯ã©ã¦ãï¼AWSå©ç¨ã¬ã¤ãï¼ã¦ã¼ã¶ã¼ç®¡çæ¹æ³(AWSç·¨)
宮形ç´å¹³(å·çè¨äºã®ä¸è¦§)
ã¨ã³ã¿ã¼ãã©ã¤ãºã¯ã©ã¦ãé¨ ã½ãªã¥ã¼ã·ã§ã³ã¢ã¼ããã¯ã1課
好ããªãé ã¯ç¼¶ãã¥ã¼ãã¤ã¨æ¬æ ¼ç¼é