CIé¨ ä½ç«¹ã§ãã
æ¬æ¥ã¯ãAWSã®ãã¯ã¤ããã¼ãã¼ï¼ç½æ¸ï¼ãèªã¿ãªãããAWS Organizations ã® OU ã«é¢ãããã¹ããã©ã¯ãã£ã¹ãå¦ã³ããã¨æãã¾ãã
- ã¯ããã«
- Organizations ã®ãã¯ã¤ããã¼ãã¼
- Recommended OUs
- Security OU
- Log archive account
- Security tooling accounts
- Security read-only access account
- Security break-glass account
- Example structure
- Infrastructure OU
- Sandbox OU
- Workloads OU
- Policy Staging OU
- Suspended OU
- Individual Business Users OU
- Exceptions OU
- Deployments OU
- AWSç°å¢ã®å¤ã«åå¨ããCI/CDæ©è½ã®ä½¿ç¨
- CI/CD管çæ©è½ã¨ã¯ã¼ã¯ãã¼ãã®åé¢
- ãããã¤ã¡ã³ãã¢ã«ã¦ã³ãã§ã®CIã¸ã§ãããã³CDãã«ãã¹ãã¼ã¸ã®å®è¡
- CI/CDã¢ã«ã¦ã³ãã¨ã¯ã¼ã¯ãã¼ãã®ã°ã«ã¼ãã¨ã®æ´åæ§
- ãã«ãããã³ãåã®å ±æCI/CDãµã¼ãã¹ã®å©ç¨ãæ¤è¨ãã
- æ¬çªCI/CDãµã¼ãã¹ã¸ã®ãã¼ã ã®ã¢ã¯ã»ã¹ãå¯è½ã«ãã
- ã¯ã¼ã¯ãã¼ãã¢ã«ã¦ã³ãã¸ã® CD ãã¤ãã©ã¤ã³ã¢ã¯ã»ã¹ã®æä¾
- CI/CDæ©è½ã®å¤æ´ããã¹ããã
- CIã¸ã§ãã¨CDãã¤ãã©ã¤ã³ã®éçºã¨ãã¹ã
- Example structure
- Transitional OU
- 2024å¹´6æ13æ¥ è¿½è¨ Business Continuity OU
- Security OU
- ä½è«
- ã¾ã¨ã
ã¯ããã«
ã¾ã㯠AWS Organizations ã«é¢ããç¨èªããç´¹ä»ãã¾ãã
Organization (çµç¹)
Organization 㯠Root ãé ç¹ã«ããããªã¼æ§é ã¨ãªã1ã¤ã®çµç¹ã§ããRoot ã®åä½ã Organization ã®åä½ã«ãªããããããã®çµç¹ã«ã¯ä¸æã¨ãªãIDãå²ãæ¯ããã¾ãã
SCP (ãµã¼ãã¹ã³ã³ããã¼ã«ããªã·ã¼)
- IAM Policy ã®ããã«åä½ããããªã·ã¼ã§ã
- SCP ã¯åã¨ã³ãã£ãã£ã«ããããè¤æ°åä»ä¸ãå¯è½ã«ãªã£ã¦ãã¾ãï¼æ大5ã¤ï¼
ã¨ã³ãã£ãã£
ã¨ã³ãã£ãã£ã¯ã以ä¸ã®3ã¤ï¼Root, OU, Accountï¼ã§ãã
Root
- ã«ã¼ãã¯ãã®çµç¹å é¨ã§ 1 ã¤ã®ã¿ï¼1ã¤ã®AWSã¢ã«ã¦ã³ãã®ã¿ï¼æã¤ãã¨ãã§ãã¾ã
- Root 㯠OU ã®ããã«åä½ãããããRoot ã«ç´æ¥ SCP ãã¢ã¿ãããããã¨ãå¯è½ã§ã
OU (organizational unit)
- AWSã¢ã«ã¦ã³ãã¯ããããã® OU ã«é ç½®ãããããããã㯠Root ç´æ¥ã«é ç½®ããã¾ã
- OU ã¯ä»ã® OU ã«æå±ããããã¨ãå¯è½ã§ãé層æ§é ãæã¤ãã¨ãå¯è½ã§ã(æ大5é層)
ã¢ã«ã¦ã³ã
- åå¥ã®AWSã¢ã«ã¦ã³ã1ã¤ãæãã¾ã
- AWSã¢ã«ã¦ã³ããã¨ã³ãã£ãã£ã§ãããããç´æ¥ SCP ãã¢ã¿ãããããã¨ãå¯è½ã§ã
- Management Accountï¼ç®¡çã¢ã«ã¦ã³ãï¼ ã¯ Organization å ã«1ã¤åå¨ã Payerï¼æ¯æè ï¼ã¨ãã¦åä½ãã¾ã
- Management Account 㯠Member Accountï¼ã¡ã³ãã¼ã¢ã«ã¦ã³ãï¼ ã¨å¼ã°ããAWSã¢ã«ã¦ã³ããæãåºããã¨ãå¯è½ã§ã
æ§æå³
以ä¸ãç°¡æç㪠Organizations ã®æ§æå³ã§ãã
Root ãé ç¹ã«å OU ãé
ç½®ãããå OU ã« AWS ã¢ã«ã¦ã³ããé
ç½®ããã¾ããManagement Account 㯠Root ã«ç´æ¥é
ç½®ããã¦ãããç¾æç¹ã§ã¯ Management Account = Root
ã¨èãã¦é ãã¦åé¡ããã¾ããã
Management Account ã¯ãã®å½¹å²ããã親ã¢ã«ã¦ã³ããã¨å¼ã°ãããã¨ãããã¾ããMember Accountã¯ãåã¢ã«ã¦ã³ããã¨å¼ã°ãããã¨ãããã¾ãã
Organizations ã«ãããæ©ã¿
AWS Organizations ã®æ§ç¯ã«ããã¦æ©ã¿ã®ç¨®ã¨ãªãã®ã¯ããã©ã®åä½ã§ OU ãåããã®ããã«ã¤ãã¾ããOrganizations ã«ãã㦠OU ã®å½¹å²ã¯é常ã«éè¦ã§ããããã¯ä»¥ä¸ã®çç±ãããããã¾ãã
- SCP 㯠OU åä½ã§ã¢ã¿ããå¯è½ã§ãããã¢ã¿ããããã SCP ã¯ãã®é ä¸ã®ã¨ã³ãã£ãã£ã«ç¶æ¿ããã
- CloudFormation StackSets 㯠OU åä½ã§å®è¡ãããã¨ãå¯è½
ã¤ã¾ã OU ã®åä½ã§æ©è½å¶éãçµ±å¶ãããããã¨ã«ãªããããé©åã« OU ãè¨è¨ãããã¨ãé©åãªéç¨ã«ã¤ãªããã¾ãã
ããã§ãä»å㯠AWS å ¬å¼ã®ãã¯ã¤ããã¼ãã¼ãã OU ã«é¢ãããã¹ããã©ã¯ãã£ã¹ãå¦ã³ããã¨èãã¦ãã¾ãã
Organizations ã®ãã¯ã¤ããã¼ãã¼
以ä¸ã®ããã°ã§ç´¹ä»ããã¦ããéãã2021å¹´6æ2æ¥ã« Organizations ã®ãã¯ã¤ããã¼ãã¼ãã¢ãã¦ã³ã¹ããã¾ããã
以ä¸ããã®ãã¯ã¤ããã¼ãã¼ã«ãªãã¾ããç¾æç¹ã§ã¯è±èªã®ã¿ã§é²è¦§å¯è½ã§ãã
ãã®ä¸ã«ãããRecommended OUsããä»åãç´¹ä»ãããã¼ã¸ã¨ãªãã¾ãã
è£è¶³ã§ããããã®å 容ã¯2020å¹´7æ21æ¥ã«ä»¥ä¸ã®ããã°ã§ã¢ãã¦ã³ã¹ãããå 容ã¨åºæ¬çã«åããã®ã¨ãªã£ã¦ãã¾ãã
ããã§ã¯ããã¯ã¤ããã¼ãã¼ã翻訳ããªãããã¹ããã©ã¯ãã£ã¹ããç´¹ä»ãã¾ãã
ãªããè£è¶³ï¼ãããå§ã¾ãæç« ã¯ç§ãè£è¶³èª¬æã®ããã«è¿½è¨ããæç« ã§ãããåæã«ã¯åå¨ãã¾ããã
Recommended OUs
ã客æ§ã®è¦ä»¶ã«ãã£ã¦ã¯ãæ¨å¥¨ããããã¹ã¦ã®OUãè¨å®ããå¿ è¦ããªãå ´åãããã¾ããAWSãå°å ¥ãããã¼ãºãããæ·±ãç¥ããã¨ã§ãOUã®å ¨ä½çãªã»ãããæ¡å¼µãããã¨ãã§ãã¾ããAWSã¢ã«ã¦ã³ããæ´çããæ¹æ³ã®ä¾ã«ã¤ãã¦ã¯ããAWSã¢ã«ã¦ã³ããçµç¹ãããã¿ã¼ã³ããåç §ãã¦ãã ããã
æ¨å¥¨ãããOUã¯ä¸è¬çãªã¦ã¼ã¹ã±ã¼ã¹ã«åããã¦è¨å®ããã¦ãã¾ããããã¼ãºã«åããã¦ç¬èªã®OUæ§é ãå®ç¾©ãããã¨ãå¯è½ã§ãããã®ã¬ã¤ãã³ã¹ã¯ãã»ã¨ãã©ã®ã客æ§ã®ãã¼ãºãæºãããã¨ãç®çã¨ãã¦ãã¾ãããã ãããã¹ã¦ã®ã¦ã¼ã¹ã±ã¼ã¹ã«å¯¾å¿ãããã®ã§ã¯ããã¾ããã
æ¨å¥¨ãããOUã¯ä»¥ä¸ã®æ§æããæãã¾ãï¼
- Security OU
- Infrastructure OU
- Sandbox OU
- Workloads OU
- Policy Staging OU
- Suspended OU
- Individual Business Users OU
- Exceptions OU
- Deployments OU
- Transitional OU
å½ç¤¾ã¯ãã»ãã¥ãªãã£OUã¨ã¤ã³ãã©ã¹ãã©ã¯ãã£OUãåºç¤ç (foundational) ãªãã®ã¨ãã¦åé¡ãã¦ãã¾ããfoundational OU ã«ã¯ãã¢ã«ã¦ã³ããã¯ã¼ã¯ãã¼ãããã®ä»ã®AWSãªã½ã¼ã¹ãå«ã¾ããAWSç°å¢å ¨ä½ãå®å ¨ã«ãµãã¼ãããããã®å ±éã®ã»ãã¥ãªãã£ããã³ã¤ã³ãã©ã¹ãã©ã¯ãã£æ©è½ãæä¾ãã¾ãã
foundational OU ã«åå¨ãããã¢ã«ã¦ã³ããã¯ã¼ã¯ãã¼ããããã³ãã¼ã¿ãã¯ãé常ãã»ãã¥ãªãã£ãã¼ã ãã¤ã³ãã©ã¹ãã©ã¯ãã£ãã¼ã ãããã³ãªãã¬ã¼ã·ã§ã³ãã¼ã ããããªãã¯ãã¹ãã¡ã³ã¯ã·ã§ãã«ãªä»£è¡¨è ã§æ§æãããã¯ã©ã¦ããã©ãããã©ã¼ã ããããã¯ã¯ã©ã¦ãã¨ã³ã¸ãã¢ãªã³ã°ãã¼ã ã«ãã£ã¦ç®¡ç/ææããã¾ãã
ã客æ§ã®ã¢ã«ã¦ã³ãã®å¤§é¨åã¯ããã®ä»ã®OUã«å«ã¾ãã¦ããããããã®OUã¯ã客æ§ã®ãã¸ãã¹é¢é£ã®ã¯ã¼ã¯ãã¼ããæ ¼ç´ãããã¨ãç®çã¨ãã¦ãã¾ããã¾ããã客æ§ã®ãã¸ãã¹é¢é£ã®ãµã¼ãã¹ããã¼ã¿ã®ã©ã¤ããµã¤ã¯ã«å ¨ä½ããµãã¼ããããã¼ã«ããµã¼ãã¹ãå«ã¾ãã¦ãã¾ãã
Security OU
Security OU ã¯åºæ¬ã¨ãªã OU ã§ããã»ãã¥ãªãã£çµç¹ã¯ããã® OU ãåOU ããã³é¢é£ããã¢ã«ã¦ã³ãã¨ã¨ãã«ææã»ç®¡çããå¿ è¦ãããã¾ããSecurity OUã«ã¯ã以ä¸ã®ã¢ã«ã¦ã³ããä½æãããã¨ãæ¨å¥¨ãã¾ãã
- ãã°ã¢ã¼ã«ã¤ãï¼Log archive
- ã»ãã¥ãªã㣠ãã¼ãªã³ã°ï¼Security tooling
- ã»ãã¥ãªãã£ã®èªã¿åãå°ç¨ã¢ã¯ã»ã¹ï¼Security read-only access
- ã»ãã¥ãªã㣠ãã¬ã¼ã¯ã°ã©ã¹ï¼Security break-glass
åæã®è¦ä»¶ã«ãã£ã¦ã¯ããããã®ã¢ã«ã¦ã³ãã®ãã¹ã¦ãä½æããå¿ è¦ã¯ãªãããããã¾ãããAWSå°å ¥ã®åæ段éã§ãã使ããã OU ã¨ã¢ã«ã¦ã³ãã®ã»ããä¾ã«ã¤ãã¦ã¯ãPatterns for organizing your AWS accountsãåç §ãã¦ãã ããã
è£è¶³ï¼ãã¬ã¼ã¯ã°ã©ã¹ã¨ã¯ãç«ç½å ±ç¥å¨ãé³´ããããã«ã¬ã©ã¹ãå²ããã¨ããåã¥ãããããã®ã§ãç¹å®ã®æ å ±ã¸ã®ã¢ã¯ã»ã¹æ¨©éãæããªã人ããå¿ è¦ãªã¨ãã«ç´ æ©ãã¢ã¯ã»ã¹ã§ããæ段ã®ãã¨ãè¨ãã¾ããããã¯ãç·æ¥äºæ ã«ã¯æ¨©éã®å£ãçªç ´ã§ããã¨ãããã¨ã§ã
Log archive account
ãã°ã¢ã¼ã«ã¤ãã¯ãçµç¹å ã®ãã¹ã¦ã®ã¢ã«ã¦ã³ãããåéããããã°ãã¼ã¿ã®éç´ãã¤ã³ãã¨ãã¦æ©è½ããã¢ã«ã¦ã³ãã§ã主ã«ã»ãã¥ãªãã£ãéç¨ãç£æ»ãã³ã³ãã©ã¤ã¢ã³ã¹ã®åãã¼ã ãå©ç¨ãã¾ãã
ä¾ãã°ãAWS CloudTrail ã«è¨é²ãããAWS APIã¢ã¯ã»ã¹ãã°ããAWS Config ã«è¨é²ãããAWSãªã½ã¼ã¹ã¸ã®å¤æ´ãã°ãªã©ãã»ãã¥ãªãã£ã«é¢ãããã°ããã®ã¢ã«ã¦ã³ãã«éç´ãããã¨ãæ¨å¥¨ãã¾ããã¾ããã¢ã«ã¦ã³ãé㧠VPC ãã¢ãªã³ã°ãå©ç¨ãã¦ããã®ã§ããã°ãVPCããã¼ãã°ã®ãã¼ã¿ããã®ã¢ã«ã¦ã³ãã«éç´ããã®ãå¹æçã§ãã
ãã®çµ±åããããã°ãã¼ã¿ãSIEMï¼Security Information and Event Managementï¼ã½ãªã¥ã¼ã·ã§ã³ã¨çµ±åããã®ã¯ä¸è¬çãªæ¹æ³ã§ãã
AWS Control Tower ã使ã£ã¦AWSç°å¢å ¨ä½ã管çãã¦ããã®ã§ããã°ãåã¢ã«ã¦ã³ã㧠CloudTrail ãèªåçã«æå¹ã«ãªããCloudTrail ã®ãã°ã¯ Log archive ã¢ã«ã¦ã³ãã® Amazon S3 ãã±ããã«éç´ããã¾ãã
éç¨ãã°ãã¼ã¿
ã¤ã³ãã©ã¹ãã©ã¯ãã£ããªãã¬ã¼ã·ã§ã³ãåã³ã¯ã¼ã¯ãã¼ããææããåãã¼ã ã«ãã£ã¦ä½¿ç¨ãããéç¨ãã°ãã¼ã¿ã¯ãã»ãã¥ãªãã£ãç£æ»ãã³ã³ãã©ã¤ã¢ã³ã¹ãã¼ã ã«ãã£ã¦ä½¿ç¨ããããã°ãã¼ã¿ã¨éè¤ãããã¨ãããããã¾ãã
ãã®ãããéç¨ãã°ãã¼ã¿ããã°ã¢ã¼ã«ã¤ãã¢ã«ã¦ã³ãã«çµ±åãããã¨ãæ¨å¥¨ãã¾ããã»ãã¥ãªãã£ãã¬ããã³ã¹ã®è¦ä»¶ã«å¿ãã¦ããã®ã¢ã«ã¦ã³ãã«ä¿åãããéç¨ãã°ãã¼ã¿ããã£ã«ã¿ãªã³ã°ããå¿ è¦ãããããããã¾ãããã¾ãããã°ã¢ã¼ã«ã¤ãã¢ã«ã¦ã³ãã«ä¿åãããéç¨ãã°ãã¼ã¿ã«ã¢ã¯ã»ã¹ã§ãã人ãå¶éãããã¨ããé²è¦§ã§ããå 容ãå¶éããå¿ è¦ãããã¾ãã
ä¸å¤çãªãã°ãã¼ã¿
ãã°ã¢ã¼ã«ã¤ã ã¢ã«ã¦ã³ãã«ä¿åããããã°ãã¼ã¿ã¯ãå¤æ´ããããã¨ããªãä¸å¤ã®ãã®ã¨ãã¦è¦ãªããã¾ãã
ãã®ã¢ã«ã¦ã³ãã¸ã®ã¢ã¯ã»ã¹ã®ç®¡ç
ãã®ã¢ã«ã¦ã³ãã«ã¯ããã°ãã¼ã¿ã®ã¿ãå容ãããã°ãã¼ã¿ãæä½ãããããªã¯ã¼ã¯ãã¼ããå«ããªããã¨ãå¼·ãæ¨å¥¨ãã¾ãããããããã¨ã§ããã®ã¢ã«ã¦ã³ãã¸ã®ã¢ã¯ã»ã¹ãå¤§å¹ ã«éå®ãããã¨ãã§ãã¾ãã
çµ±åããããã°ãã¼ã¿ãæ¶è²»ï¼æ´»ç¨ï¼ããå¿ è¦ã®ããã¯ã¼ã¯ãã¼ãããã¼ã«ã¯ãé常ãä»ã®ã¢ã«ã¦ã³ãã«å容ãããIAM ãã¼ã«ãä»ãã¦ã¢ã«ã¦ã³ã横æçãªã¢ã¯ã»ã¹ï¼ã¯ãã¹ã¢ã«ã¦ã³ãã¢ã¯ã»ã¹ï¼ãä¸ããããèªã¿åãå°ç¨ã®æå°ç¹æ¨©ã§ãã°ãã¼ã¿ã«ã¢ã¯ã»ã¹ãã¾ãã
Security tooling accounts
ã»ãã¥ãªãã£ãµã¼ãã¹ããã¼ã«ãããã³ãµãã¼ããã¼ã¿ã®å½¢ã§åºãé©ç¨å¯è½ãªã»ãã¥ãªãã£æåã®ã¯ã¼ã¯ãã¼ããæ ¼ç´ããããã«ã1ã¤ä»¥ä¸ã®ã»ãã¥ãªãã£ãã¼ãªã³ã°ã¢ã«ã¦ã³ãã使ç¨ãããã¨ãæ¨å¥¨ãã¾ãã使ç¨ããã»ãã¥ãªãã£ãã¼ãªã³ã°ã¢ã«ã¦ã³ãã®æ°ã¯ãAWSã¢ã«ã¦ã³ããæ´çããããã®è¨è¨ååãèæ ®ãã¦æ±ºå®ãã¦ãã ããã
AWSãµã¼ãã¹ã®ä¸è¬çãªä¾
ã»ãã¥ãªãã£ãã¼ãªã³ã°ã¢ã«ã¦ã³ãã§ä¸å çã«ã¢ã¯ã»ã¹ã»ç®¡çã§ããã»ãã¥ãªãã£æ©è½ãAWSãµã¼ãã¹ã®ä¸è¬çãªä¾ã¨ãã¦ã¯ã以ä¸ã®ãããªãã®ãããã¾ãã
Detection
- AWS Security Hubï¼AWSçµç¹å ã®ãã¹ã¦ã®ã¢ã«ã¦ã³ãã§AWS Security Hubãæå¹ã«ãããã¨ãæ¨å¥¨ãã¾ããã»ãã¥ãªãã£ãã¼ãªã³ã°ã¢ã«ã¦ã³ãã®1ã¤ããSecurity Hubã®å§ä»»ããã管çè ã¨ãã¦æå®ã§ãã¾ãã
- Amazon GuardDutyï¼AWSçµç¹å ã®ãã¹ã¦ã®ã¢ã«ã¦ã³ãã§ãAmazon GuardDutyãæå¹ã«ãããã¨ãæ¨å¥¨ãã¾ããã»ãã¥ãªãã£ãã¼ãªã³ã°ã¢ã«ã¦ã³ãã®1ã¤ããGuardDutyã®å§ä»»ç®¡çè ã¨ãã¦æå®ã§ãã¾ãã
- AWS Configï¼AWSãªã½ã¼ã¹ãAWS Configã«ã¼ã«ãAWSãªã½ã¼ã¹ã®ã³ã³ãã©ã¤ã¢ã³ã¹ç¶æ ãéç´ãã¦è¦ããã¨ãã§ããããã«ãã»ãã¥ãªãã£ãã¼ãªã³ã°ã¢ã«ã¦ã³ãã®1ã¤ã«AWS Configã¢ã°ãªã²ã¼ã¿ãè¨å®ãããã¨ãæ¨å¥¨ãã¾ãã
Identity and Access Management
- IAM Access Analyzerï¼IAM Access Analyzerã¯ãAWSçµç¹å ¨ä½ãä¿¡é ¼ã¾ã¼ã³ã¨ãã¦è¨å®ãã¦ä½¿ç¨ãããã¨ãæ¨å¥¨ãã¾ããããã«ããããªã½ã¼ã¹ããªã·ã¼ãç´ æ©ã確èªããæå³ããªããããªãã¯ã¢ã¯ã»ã¹ãã¯ãã¹ã¢ã«ã¦ã³ãã¢ã¯ã»ã¹ãæã¤ãªã½ã¼ã¹ãç¹å®ãããã¨ã容æã«ãªãã¾ãããã®ã¢ãã©ã¤ã¶ã¯ãã»ãã¥ãªãã£ãã¼ãªã³ã°ã¢ã«ã¦ã³ãã®1ã¤ã«è¨å®ãããã¨ãæ¨å¥¨ãã¾ãã
Incident Response
- Amazon Detectiveï¼ã»ãã¥ãªãã£ãã¼ãªã³ã°ã¢ã«ã¦ã³ãã®1ã¤ããAmazon DetectiveãAmazon GuardDutyãããã³AWS Security Hubã®å§ä»»ç®¡çè ã¨ãã¦æå®ãããã¨ãæ¨å¥¨ãã¾ãããããããã¨ã§ããããã®ãµã¼ãã¹éã®çµ±åãå©ç¨ãããã¨ãã§ãã¾ãã
Data Protection
- Amazon Macieï¼AWSçµç¹å ¨ä½ã§Amazon Macieã使ç¨ããå ´åã¯ãã»ãã¥ãªãã£ãã¼ãªã³ã°ã¢ã«ã¦ã³ãã®1ã¤ãMacieã®å§ä»»ç®¡çè ã¨ãã¦æå®ãããã¨ãæ¨å¥¨ãã¾ãã
Infrastructure Protection
- AWS Firewall Managerï¼AWS Firewall ManagerãAWSçµç¹å ¨ä½ã§ä½¿ç¨ããäºå®ã®å ´åãã»ãã¥ãªãã£ãã¼ãªã³ã°ã¢ã«ã¦ã³ãã®1ã¤ãFirewall Managerã®å§ä»»ç®¡çè ã¨ãã¦æå®ãããã¨ãæ¨å¥¨ãã¾ãã
ãµã¼ããã¼ãã£ã®ã¯ã©ã¦ãã»ãã¥ãªãã£ç£è¦ãã¼ã«
ãµã¼ããã¼ãã£ã®ã¯ã©ã¦ãã»ãã¥ãªãã£ç£è¦ãµã¼ãã¹ããã¼ã«ããã»ãã¥ãªãã£ãã¼ãªã³ã°ã¢ã«ã¦ã³ãã«å容ãããã¨ãã§ãã¾ããä¾ãã°ããããã®ã¢ã«ã¦ã³ãã«ã¯ãé常ãã»ãã¥ãªãã£æ å ±ããã³ã¤ãã³ã管çï¼SIEMï¼ãã¼ã«ãèå¼±æ§ã¹ãã£ãã¼ãå«ã¾ãã¦ãã¾ãã
èªåæ¤ç¥ã»å¯¾å¿ã¯ã¼ã¯ããã¼
ãããã®ãµã¼ãã¹ã§åéããããã¼ã¿ã«åºã¥ãã¦åä½ããèªåæ¤åºããã³å¿çã¯ã¼ã¯ããã¼ã¯ãé常ãã»ãã¥ãªãã£ãã¼ãªã³ã°ã¢ã«ã¦ã³ãã«å«ã¾ãã¦ãã¾ãã
ã¤ã³ã·ãã³ã対å¿ï¼IRï¼ãµãã¼ã
æåã®ã¤ã³ã·ãã³ã対å¿ï¼IRï¼æé ããµãã¼ããããã¼ã«ã¯ãé常ãã»ãã¥ãªãã£ãã¼ãªã³ã°ã¢ã«ã¦ã³ãã«å«ã¾ãã¦ãã¾ãã
詳細ã«ã¤ãã¦ã¯ããAWS Security Incident Response Guideããåç §ãã¦ãã ããã
ã»ãã¥ãªãã£ãã¼ã ã®ã¢ã¯ã»ã¹
ã»ãã¥ãªãã£ãã¼ã ã®ã¡ã³ãã¼ã¯ãã»ãã¥ãªãã£ãµã¼ãã¹ããã¼ã«ã®æ©è½ãæä½ããããæ½å¨çã«è¨å®ãããããããã«ãæ¥å¸¸çã«ãããã®ãµã¼ãã¹ãã¢ããªã±ã¼ã·ã§ã³ã«ã¢ã¯ã»ã¹ããå¿ è¦ãããã¾ãããã®ã¢ã¯ã»ã¹ã¯æå°éã«ã¨ã©ããå¿ è¦ãªã¢ã¯ã·ã§ã³ï¼ãã¨ãã°ãã»ãã¥ãªãã£ãã¼ã«ã®ã³ã³ã½ã¼ã«ã»ããã·ã¥ãã¼ãã®è¡¨ç¤ºãæä½ï¼ã«éå®ããå¿ è¦ãããã¾ãã
å¯è½ã§ããã°ãã»ãã¥ãªãã£ãã¼ã 㯠IaCï¼Infrastructure-as-Codeï¼æè¡ã使ç¨ãã¦ãã»ãã¥ãªãã£ãã¼ãªã³ã°ã¢ã«ã¦ã³ãã«åå¨ãããµã¼ãã¹ããã¼ã«ã®åºæ¬çãªè¨å®ãèªååãããã¨ãæ¨å¥¨ãã¾ãã
Security read-only access account
éç´é ç½®ããããã°ããã®ä»ã®æ段ãä¸ååãªå ´åããç£æ»ãæ¢ç´¢çãªã»ãã¥ãªãã£ã»ãã¹ããããã³èª¿æ»ããæ¯æ´ãããããã»ãã¥ãªãã£ãã¼ã ã®ã¡ã³ãã¼ã¯AWSç°å¢ã®åã¢ã«ã¦ã³ãã¸ã®èªã¿åãå°ç¨ã¢ã¯ã»ã¹ãå¿ è¦ã¨ãã¾ãã
ä¸è¬çãªã¢ããã¼ãã¯ããã§ãã¬ã¼ãããã¢ã¯ã»ã¹ã使ç¨ãã¦ãã¢ã«ã¦ã³ãã¸ã®ç´æ¥ã®èªã¿åãå°ç¨ã¢ã¯ã»ã¹ãæä¾ãããã¨ã§ããAWSã¢ã«ã¦ã³ãã¸ã®ç´æ¥ã®ãã§ãã¬ã¼ãããã¢ã¯ã»ã¹ã§ã¯ãã»ãã¥ãªãã£ç¨ã®èªã¿åãå°ç¨ã¢ã¯ã»ã¹ã¢ã«ã¦ã³ãã使ç¨ããå¿ è¦ã¯ããã¾ããã
ããããç´æ¥ãã§ãã¬ã¼ã·ã§ã³ã§ã¯ãªããã¯ãã¹ã¢ã«ã¦ã³ãã®ãã¼ã«ï¼ã¹ã¤ãããã¼ã«ï¼ã使ç¨ãããå ´åã¯ããã®ã»ãã¥ãªãã£èªã¿åãå°ç¨ã¢ã«ã¦ã³ãã使ç¨ãããã¨ãæ¨å¥¨ãã¾ããä¾ãã°ãã»ãã¥ãªãã£ã¤ã³ã·ãã³ãã®çããããå ´åã®èª¿æ»ã®åæ段éã§ãã»ãã¥ãªãã£ãã¼ã ã®ã¡ã³ãã¼ãã¾ããã®ã¢ã«ã¦ã³ãã«ã¢ã¯ã»ã¹ããèªã¿åãå°ç¨ã®IAMã¯ãã¹ã¢ã«ã¦ã³ããã¼ã«ã使ã£ã¦ä»ã®ã¢ã«ã¦ã³ãã«ã¢ã¯ã»ã¹ãããªã½ã¼ã¹ã®ç¶æ ã確èªã»ç£è¦ãããããªå ´åã§ãã
é常ããã®ã¢ã«ã¦ã³ãã«ã¯æ°¸ç¶çãªã¯ã¼ã¯ãã¼ãã¯å«ã¾ãã¦ãã¾ããããããããã¼ã ã¡ã³ãã¼ã¯ãä»ã®ã¢ã«ã¦ã³ãã«ã¤ã³ã¿ã©ã¯ãã£ãã«ã¢ã¯ã»ã¹ããããã«ããã®ã¢ã«ã¦ã³ããæä»çã«ä½¿ç¨ãã¾ãã
ã»ãã¥ãªãã£ç¨ã®èªã¿åãå°ç¨ã¢ã«ã¦ã³ãã使ç¨ããå ´åã¯ãã»ãã¥ãªãã£ãã¼ã ã®ã¡ã³ãã¼ããã®ã¢ã«ã¦ã³ãã«ã¢ã¯ã»ã¹ã§ããããã«ããã§ãã¬ã¼ãããã¢ã¯ã»ã¹ã使ç¨ãããã¨ãæ¨å¥¨ãã¾ããã»ãã¥ãªãã£ãã¼ã ã®ã¡ã³ãã¼ããã§ãã¬ã¼ãããã¢ã¯ã»ã¹ã§ãã®ã¢ã«ã¦ã³ãã«ã¢ã¯ã»ã¹ããããã¯ãã¹ã¢ã«ã¦ã³ãIAMãã¼ã«ã使ç¨ãã¦ãã»ãã¥ãªãã£ãã¼ã ã®ã¡ã³ãã¼ã«å¯¾è±¡ã¨ãªãåã¢ã«ã¦ã³ãã¸ã®ã¯ãã¹ã¢ã«ã¦ã³ãã¢ã¯ã»ã¹ãæä¾ãããã¨ãæ¨å¥¨ãã¾ãã
Security break-glass account
ã»ãã¥ãªãã£ã¤ã³ã·ãã³ãããæ¨æºçãªã¢ã¯ã»ã¹ã¡ã«ããºã ãå©ç¨ã§ããªãä¾å¤çãªã±ã¼ã¹ããµãã¼ãããããã«ã権éã®ãã管çè ãä¸æçã«ã¢ã«ã¦ã³ãã¸ã®å¿ è¦ãªã¢ã¯ã»ã¹ãå¾ããã¨ãã§ããããã»ã¹ãç¨æããå¿ è¦ãããã¾ãã
æ¿èªããã管çè ã«ãã¢ã«ã¦ã³ãã¸ã®ä¸æçãªãã¬ã¤ã¯ã°ã©ã¹ã¢ã¯ã»ã¹ãæä¾ããããã®å ¨ä½çãªããã»ã¹ã«ãã£ã¦ã¯ãã»ãã¥ãªãã£ãã¬ã¤ã¯ã°ã©ã¹ã¢ã«ã¦ã³ããå¿ è¦ãªãå ´åãããã¾ãããã ããå ¨ä½çãªãã¬ã¤ã¯ã°ã©ã¹ããã»ã¹ã«ã¯ãã¹ã¢ã«ã¦ã³ããã¼ã«ã®æ´»ç¨ãå«ã¾ããå ´åãã»ãã¥ãªãã£ãã¬ã¤ã¯ã°ã©ã¹ã¢ã«ã¦ã³ãã使ç¨ãããã¨ã§ã¡ãªãããå¾ãããå ´åãããã¾ãã
ãã®ãããªã¢ã«ã¦ã³ãã¯ãã£ãã«å©ç¨ããããã®ã§ã¯ããã¾ããããã»ãã¥ãªãã£ãã¼ã ãéç¨ãã¼ã ã®ã¡ã³ãã¼ããæ¨æºçãªã¢ã¯ã»ã¹ã¡ã«ããºã ãå©ç¨ã§ããªãå ´åã§ããã¢ã«ã¦ã³ãã¸ã®åºç¯ãªæ¸ãè¾¼ã¿ã¢ã¯ã»ã¹ãå¯è½ã«ãããã¨ãå¯è½ã¨ãªãã¾ããã¤ã³ã·ãã³ãçºçæã«ã»ãã¥ãªãã£ãã¼ã ããªãã¬ã¼ã·ã§ã³ãã¼ã ã®ã¡ã³ãã¼ããã®ã¢ã«ã¦ã³ãã«ã¢ã¯ã»ã¹ããã«ã¯ãç¹å¥ãªæ¨©éãå¿ è¦ã§ããããã¹ã¦ã®ã¢ã«ã¦ã³ãã¢ã¯ã»ã¹ã¯è©³ç´°ã«è¨é²ããã¾ããã¤ã³ã·ãã³ãã解決ãããã¨ããã®ã¢ã«ã¦ã³ãã¸ã®ä¸æçãªã¢ã¯ã»ã¹ã¯åãæ¶ããã¾ãã
é常ããã®ã¢ã«ã¦ã³ãã«å¿ è¦ãªãµãã¼ããã¼ã«ã¯ãèªååã使ç¨ãã¦ãªã³ããã³ãã§ä½æããã¤ã³ã·ãã³ãã解決ããå¾ã«ãããã®ãµãã¼ããã¼ã«ãåé¤ãã¾ãã
Example structure
以ä¸ã®æ§æä¾ã¯ãProd ããã³ Test ã®å OU ãéãã¦ãæ¬çªç°å¢ã®ã¯ã¼ã¯ãã¼ãã¨ãªã½ã¼ã¹ãéæ¬çªç°å¢ããåé¢ãããã¨ãæ¨å¥¨ãã¦ãã¾ãã
ã¢ã«ã¦ã³ãåã®ä¾ã«ã¯ã-testããã³-prodã¨ãã修飾åãä»ãã¦ãã¾ããtest修飾åã¯ãéãããã¯ã·ã§ã³ç°å¢ãæå³ãã¾ããprod修飾åã¯ãç¹å®ã®ã±ã¤ãããªãã£ã¾ãã¯ã¯ã¼ã¯ãã¼ãã«å¯¾ããå®å®ãããããã¯ã·ã§ã³å質ã®ç°å¢ã示ãã¾ããprod修飾åã¯ãã±ã¤ãããªãã£ã¾ãã¯ã¯ã¼ã¯ãã¼ãã®ç°å¢ããä»ã®æ¬çªå質ã®ã±ã¤ãããªãã£ã¾ãã¯ã¯ã¼ã¯ãã¼ãã®ãµã¼ãã¹ã®ã¿ã«éå®ããããã¨ãæå³ãããã®ã§ã¯ããã¾ããã
ä¾ãã°ãlog-archive-prodã¨ããä¾ç¤ºçãªååã§è¡¨ãããã¢ã«ã¦ã³ãã¯ããã¹ã¦ã®ã¢ã«ã¦ã³ãã«ããããã¹ã¦ã®ãã°ãã¼ã¿ã®çµ±åãã¤ã³ãã¨ãªããã¨ãæå¾ ããã¾ããããã¯åã«ããã°ã¢ã¼ã«ã¤ãæ©è½ã®å®å®ããæ¬çªå質ã®å½¢æ ã§ãã
åæ§ã«ãä»ã®ã¢ã«ã¦ã³ãã§-prod修飾åã使ç¨ãããã¨ã¯ããããã®ã¢ã«ã¦ã³ãã®æ¬çªç°å¢ã¸ã®é©ç¨ãå¶éãããã¨ãæå³ãã¦ãã¾ããã
ã¯ã©ã¦ããªã½ã¼ã¹ã®å½åè¦åã«ãã£ã¦ã¯ãå®å®ããæ¬çªå質ã®ã±ã¤ãããªãã£ãã¯ã¼ã¯ãã¼ããå«ãAWSã¢ã«ã¦ã³ãã®ååã«ä¿®é£¾åãé©ç¨ããªããã¨ãã§ãã¾ãã
次ã®ä¾ã§ã¯ãsecurity-tooling-testã¢ã«ã¦ã³ãã¾ãã¯ç°å¢ãå«ã¾ãã¦ãã¾ãããã®ã¢ã«ã¦ã³ãã§ã¯ãæ°ãããªã½ã¼ã¹æ§æãå¤æ´ããããªã½ã¼ã¹æ§æãããããã®å¤æ´ãsecurity-tooling-prodã¢ã«ã¦ã³ãã«ææ ¼ããåã«ãã¹ãããã³æ¤è¨¼ãããã¨ãã§ãã¾ãã
æ¬çªç¨ã¨éæ¬çªç¨ã®ã¯ã¼ã¯ãã¼ããåé¢ããããã®ä¸è¬çãªã¬ã¤ãã³ã¹ã«ã¤ãã¦ã¯ãOrganizing workload-oriented OUsããåç §ãã¦ãã ããã
Infrastructure OU
ã¤ã³ãã©ã¹ãã©ã¯ã㣠OU ã¯ãå ±æã¤ã³ãã©ã¹ãã©ã¯ã㣠ãµã¼ãã¹ãæ ¼ç´ããããã®åºç¤ã¨ãªã OU ã§ããã¤ã³ãã©ãã¼ã ã¯ããã®OUãåOUãããã³é¢é£ããã¢ã«ã¦ã³ããææãã管çããå¿ è¦ãããã¾ãã
ãã®OUã®ä¸è¬çãªä½¿ç¨ä¾ã¨ãã¦ã¯ãå¤ãã®ãããã¯ã¼ã¯ãªã½ã¼ã¹ã®éä¸ç®¡çãæãããã¾ããä¾ãã°ãAWS Site-to-Site VPNæ¥ç¶ãAWS Direct Connectçµ±åãAWS Transit Gatewayæ§æãDNSãµã¼ãã¹ãAmazon VPCã¨ã³ããã¤ã³ããå ±æVPCã¨ãµãããããªã©ã§ããããé«åº¦ãªã¦ã¼ã¹ã±ã¼ã¹ã¨ãã¦ã¯ãã¤ã³ã¿ã¼ããããã©ãã£ãã¯ã®ã¤ã³ãã¦ã³ãããã³ã¢ã¦ããã¦ã³ãã®ãããã·ããã³ãã£ã«ã¿ãªã³ã°ã®éä¸ç®¡çã«ä½¿ç¨ãããVPCããããã¯ã¼ã¯ã»ãã¥ãªãã£ã¹ã¿ãã¯ãããã¾ãã
å ±æãããã¯ã¼ã¯ãµã¼ãã¹ä»¥å¤ã«ãããã®OUã§ä»ã®å ±æã¤ã³ãã©ãµã¼ãã¹ã管çãããã¨ãã§ãã¾ããä¾ãã°ããã¤ããªããDNSã¨ãã£ã¬ã¯ããªãµã¼ãã¹ã®ããã®Amazon Route 53ãªã¾ã«ãã¨ã³ããã¤ã³ããå«ãå ±æã¤ã³ãã©ã¹ãã©ã¯ãã£ãµã¼ãã¹VPCã管çãããã¨ãã§ãã¾ãã
ã¤ã³ãã©ã¹ãã©ã¯ãã£ä»¥å¤ã®å ±æãµã¼ãã¹ãå«ããå ´æã«ã¤ãã¦ã®ã¬ã¤ãã³ã¹ã¯ããã¯ã¼ã¯ãã¼ãOUããåç §ãã¦ãã ããã
Example structure
Security OU ã®ä¾ã¨åæ§ã«ã以ä¸ã®æ§é ä¾ã¯ãProd ããã³ Test ã®å OU ãéãã¦ãæ¬çªç°å¢ã®ã¯ã¼ã¯ãã¼ãã¨ãªã½ã¼ã¹ãéæ¬çªç°å¢ããåé¢ãããã¨ãæ¨å¥¨ãã¦ãã¾ãã
ãã®ä¾ã§ã¯ãnetwork-prod ã¢ã«ã¦ã³ãã«ã¯ãå®å®ããæ¬çªå質ã®ãããã¯ã¼ã¯æ©è½ã¨ã¯ã¼ã¯ãã¼ããå«ã¾ãã¦ãã¾ãããããã®æ©è½ãã¯ã¼ã¯ãã¼ãã®æ§è³ªã«ãã£ã¦ã¯ãæ¬çªç°å¢ã¨éæ¬çªç°å¢ã®ä¸¡æ¹ããµãã¼ããããã¨ã«ãªãã¾ãã
network-testããã³shared-infra-testã¢ã«ã¦ã³ãã¯ãæ¬çªå質ã®ç°å¢ã«å¤æ´ãåæ ãããåã«ããã¼ã ãå ±éã®ãããã¯ã¼ã¯æ©è½ãå ±æã¤ã³ãã©ã¹ãã©ã¯ãã£ã»ãµã¼ãã¹ã¸ã®å¤æ´ããã¹ãããæ¤è¨¼ããããã®åå¥ã®ç°å¢ãç¨æããä¾ã示ãã¦ãã¾ãã
æ¬çªç°å¢ã¨éæ¬çªç°å¢ã®ã¯ã¼ã¯ãã¼ããåé¢ããããã®ä¸è¬çãªã¬ã¤ãã³ã¹ã«ã¤ãã¦ã¯ããOrganizing workload-oriented OUsããåç §ãã¦ãã ããã
Sandbox OU
ãµã³ãããã¯ã¹OUã«ã¯ãAWSãµã¼ãã¹ããã®ä»ã®ãã¼ã«ããµã¼ãã¹ãã許容ããã使ç¨ããªã·ã¼ã«å¾ã£ã¦ãä¸è¬çã«ãã«ãã¼ãèªç±ã«æ¢ç´¢ã»å®é¨ã§ããã¢ã«ã¦ã³ããå«ã¾ãã¦ãã¾ãããããã®ç°å¢ã¯é常ãã客æ§ã®å é¨ãããã¯ã¼ã¯ãå é¨ãµã¼ãã¹ããåãé¢ããã¦ãã¾ãã
ãã«ãã¼ã¾ãã¯ãã¼ã ãã¨ã®ãµã³ãããã¯ã¹ã¨æ¯æãå¶é
ä¸è¬çã«ã¯ãåãã«ãã¼ãå°è¦æ¨¡ãªãã¼ã ã«ãµã³ãããã¯ã¹ã¢ã«ã¦ã³ããæä¾ããã¯ã©ã¦ãã®å©ç¨äºç®ãè¨å®ãããã¨ã§ãAWSã®å©ç¨ãããªã·ã¼ã«æ²¿ã£ã¦ãããã¨ã確èªãã¾ããããé«åº¦ãªã·ããªãªã§ã¯ããã«ãã¼ããã¼ã ã«è¤æ°ã®ãµã³ãããã¯ã¹ã¢ã«ã¦ã³ããæã¤ãªãã·ã§ã³ãæä¾ãã¦ãè¤æ°ã®ã¢ã«ã¦ã³ãã使ç¨ããæ§æãããèªç±ã«è©¦ããã¨ãã§ããããã«ãããã¨ãã§ãã¾ãï¼ä¾ãã°ãã¯ãã¹ã¢ã«ã¦ã³ãã®IAMãã¼ã«ã®å®é¨ãªã©ï¼ã
çµç¹å ã®ã¢ã«ã¦ã³ãæ°ã«ã¯ä¸éãããã¾ããä½å人ãã®ãã«ãã¼ããã¦ãåãã«ãã¼ã«ãµã³ãããã¯ã¹ç°å¢ãå²ãå½ã¦ããã¨ãæ³å®ãã¦ããå ´åãã¢ã«ã¦ã³ãã®æ大å²å½æ°ã«æµè§¦ããå¯è½æ§ãããã¾ããçµç¹å ã®æ大ã¢ã«ã¦ã³ãæ°ã®è©³ç´°ã«ã¤ãã¦ã¯ããAWSçµç¹ã®ã¯ã©ã¼ã¿ããåç §ãã¦ãã ããã
æ°å以ä¸ã®ãµã³ãããã¯ã¹ã¢ã«ã¦ã³ããå¿ è¦ãªå ´åã¯ããµã³ãããã¯ã¹ã¢ã«ã¦ã³ããå«ã1ã¤ã¾ãã¯è¤æ°ã®å¥ã®çµç¹ãä½æãããã使ç¨ããªããªã£ããµã³ãããã¯ã¹ããªãµã¤ã¯ã«ããããã»ã¹ã確ç«ãããã¨ãæ¤è¨ãã¦ãã ããã
ä¸æçãªãªã½ã¼ã¹ã¨ç°å¢
æ°¸ç¶çãªéçºç°å¢ã¨ã¯ç°ãªãããµã³ãããã¯ã¹ç°å¢ã§ä½æããããªã½ã¼ã¹ã¯ä¸æçãªãã®ã§ãããã¨ããã«ãã¼ã«æå¾ ããã®ãä¸è¬çã§ããã³ã¹ãã³ã³ããã¼ã«ã®æ段ã¨ãã¦ãã¾ããµã³ãããã¯ã¹ãªã½ã¼ã¹ã®ä¸æçãªæ§è³ªãå¼·åããããã«ããããã®ç°å¢ã§ä½æããããªã½ã¼ã¹ãå®æçã«ãã¼ã¸ããèªååãããæé ãå°å ¥ãããã¨ãã§ãã¾ããã¾ããã³ã¹ãåæ¸ã®ããã«ãé常ã®å¶æ¥æéå¤ã«Amazon EC2ã¤ã³ã¹ã¿ã³ã¹ãªã©ã®ãªã½ã¼ã¹ãèªåã§åæ¢ãããã¨ãã§ãã¾ãã
åºç¯å²ãªã¢ã¯ã»ã¹
ãµã³ãããã¯ã¹åã®ã¢ã«ã¦ã³ãã§ã¯ãåã¢ã«ã¦ã³ãå ã§ã®ç®¡çè çãªã¢ã¯ã»ã¹ãã»ã¨ãã©ã®AWSãµã¼ãã¹ã¸ã®ãã«ã¢ã¯ã»ã¹ãããã¦å ´åã«ãã£ã¦ã¯ã¤ã³ã¿ã¼ãããã¸ã®ã¢ã¦ããã¦ã³ãããã³ã¤ã³ãã¦ã³ãã®ã¢ã¯ã»ã¹ãªã©ãåºç¯å²ã®ã¢ã¯ã»ã¹ãä¸è¬çã«æä¾ããã¾ããã¤ã³ã¿ã¼ãããã¸ã®ã¢ã¯ã»ã¹ã¯ãAWSãµã¼ãã¹ã®APIã¸ã®æ¥ç¶ãå¤é¨ããã¢ã¯ã»ã¹å¯è½ãªã½ããã¦ã§ã¢ããã±ã¼ã¸ã®ãã¦ã³ãã¼ããä¸è¬ã«å ¬éããã¦ãããµã¼ãã¹ã¨ã®çµ±åãªã©ã«å¿ è¦ã¨ãªãå ´åãããã¾ãã
ä¼æ¥ã®ãªã½ã¼ã¹ãéå ¬éãã¼ã¿ã¸ã®ã¢ã¯ã»ã¹ä¸å¯
ãµã³ãããã¯ã¹ç°å¢ã§æä¾ãããã¢ã¯ã»ã¹ã®ç¯å²ãèããã¨ãä¼æ¥ã¯é常ãã¬ã¼ãã¬ã¼ã«ã¨å é¨ä½¿ç¨å¥ç´ãçµã¿åããã¦ãæ§ç¯è ããµã³ãããã¯ã¹ã¢ã«ã¦ã³ãããä¼æ¥ã®ãªã½ã¼ã¹ããã¼ã¿ã«ã¢ã¯ã»ã¹ãããã¨ãå¶éãã¦ãã¾ããã¾ãããµã³ãããã¯ã¹ç°å¢ã§ã¯ãå°æã®ã½ã¼ã¹ã³ã¼ãããã¤ããªãªã©ã®éå ¬éãã¼ã¿ãç¥ç財ç£ã®ä½¿ç¨ã¯é常èªãããã¾ããã
ãµã³ãããã¯ã¹ã¨éçºç°å¢
éå ¬éãã¼ã¿ã®ä½¿ç¨ããéçºç°å¢ã§å®è¡ãããä½æ¥ã®ããæ£å¼ãªæ§è³ªã®ããããµã³ãããã¯ã¹ç°å¢ã¨éçºç°å¢ãé«ã¬ãã«ã§åºå¥ãããã¨ãæ¨å¥¨ãã¾ããä¾ãã°ãéçºç°å¢ã§ã¯ãã客æ§ã®ãã¼ã ã¯ããæ£å¼ãªå®é¨ãæ¥å¸¸çãªéçºãåæã®ãã¹ãä½æ¥ãè¡ã£ã¦ãããã客æ§ã®ç¥ç財ç£ãã½ã¼ã¹ã³ã¼ããææç©ã®ç®¡çãªã©ã®ã¨ã³ã¿ã¼ãã©ã¤ãºãµã¼ãã¹ã¸ã®ã¢ã¯ã»ã¹ãå¿ è¦ã¨ãªãã¾ãã
ãµã³ãããã¯ã¹ç°å¢ãéçºç°å¢ãããã³ãã®ä»ã®ç°å¢éã®æ½å¨çãªéãã«ã¤ãã¦ã¯ã以ä¸ã®ä»é²ãåç §ãã¦ãã ããã
- Appendix B â Worksheet for mapping workload environment purposes to hosting environment types
- Appendix C â Worksheet for identifying attributes of workload hosting environments
Example structures
ãã«ãã¼ã¾ãã¯ãã¼ã ãã¨ã®ãµã³ãããã¯ã¹
以ä¸ã®ä¾ã§ã¯ããµã³ãããã¯ã¹ã¢ã«ã¦ã³ãã¯ãåã ã®ãã«ãã¼ã¨ãã¼ã ã®ããã«è¡¨ç¾ããã¦ãã¾ããããã¦ã¼ã¶ã¼ã¯2ã¤ã®ãµã³ãããã¯ã¹ã¢ã«ã¦ã³ããæã£ã¦ãããè¤æ°ã®ã¢ã«ã¦ã³ããå¿ è¦ã¨ããå®é¨ãè¡ããããã«ãªã£ã¦ãã¾ãã
ã¾ããããã«ã½ã³ãªã©ã®ã¤ãã³ãã§ã¯ãä¸æçãªãã¼ã ã®ããã«ä¸æçãªãµã³ãããã¯ã¹ã¢ã«ã¦ã³ããä½æãããã¨ãæå¹ã§ãã
ä¸æçãªãªãµã¤ã¯ã«ãµã³ãããã¯ã¹
以ä¸ã®ä¾ã§ã¯ããµã³ãããã¯ã¹ã®ã¢ã«ã¦ã³ãã¯ãç°å¢ã®ç¾å¨ã®ã¦ã¼ã¶ã¼ã¨ã¯ç¬ç«ããååã«ãªã£ã¦ãã¾ãããµã³ãããã¯ã¹ç°å¢ã¯ããã«ãã¼ããã¼ã ã«ãã£ã¦ãã§ãã¯ã¢ã¦ããããä¸æçã«ä½¿ç¨ãããå¾ãå°æ¥ã®ä½¿ç¨ã®ããã«ãªãµã¤ã¯ã«ããã¾ãã
Workloads OU
Workloads OUã¯ãæ¬çªç°å¢ã¨éæ¬çªç°å¢ã®ä¸¡æ¹ãå«ãããã¸ãã¹ã«ç¹åããã¯ã¼ã¯ãã¼ãã®ã»ã¨ãã©ãå容ãããã¨ãç®çã¨ãã¦ãã¾ãããããã®ã¯ã¼ã¯ãã¼ãã«ã¯ãå¸è²©ã®COTSï¼Commercial Off-the-Shelfï¼ã¢ããªã±ã¼ã·ã§ã³ã¨ãèªç¤¾ã§éçºããã«ã¹ã¿ã ã¢ããªã±ã¼ã·ã§ã³ããã¼ã¿ãµã¼ãã¹ãæ··å¨ãã¦ãã¾ãã
ãã®OUã®ã¯ã¼ã¯ãã¼ãã«ã¯ãä»ã®ã¯ã¼ã¯ãã¼ãã§ä½¿ç¨ãããå ±æã¢ããªã±ã¼ã·ã§ã³ããã³ãã¼ã¿ãµã¼ãã¹ãå«ã¾ãããã¨ãããããã¾ãã
Example structure
以ä¸ã®ä¾ã¯ãåºæ¬çãªæ§é ã表ãã¦ãã¾ããæ§ã ãªãã¸ãã¹ã¦ãããããã¼ã ãææããã¯ã¼ã¯ãã¼ãã®ã»ãããã2ã¤ã®åOUã«åå¨ãã¾ããProdãã¨ãTestãã§ãããã®ä¾ã§ã¯ããããã®é åã«å ±éã®ã¬ããã³ã¹ã¨éç¨ã¢ãã«ãé©ç¨ããã¦ãã¾ãããã®ä¾ã§ã¯ãdata-lake-prodã¢ã«ã¦ã³ãã«ã¯ãä»ã®æ¬çªã¯ã¼ã¯ãã¼ããã¢ã«ã¦ã³ãã¨å ±æããããã¼ã¿ãµã¼ãã¹ãå«ã¾ãã¦ãã¾ãã
æ¬çªç°å¢ã¨éæ¬çªç°å¢ã®ã¯ã¼ã¯ãã¼ãã¨ãªã½ã¼ã¹ã®åé¢ã«é¢ããä¸è¬çãªã¬ã¤ãã³ã¹ã«ã¤ãã¦ã¯ããã¯ã¼ã¯ãã¼ãæåã®OUã®æ´çããåç §ãã¦ãã ããã
Policy Staging OU
Policy Staging OUã¯ãAWSç°å¢ã®å ¨ä½çãªããªã·ã¼ã管çãããã¼ã ããåºç¯å²ã«å½±é¿ãä¸ããå¯è½æ§ã®ããããªã·ã¼å¤æ´ããæå³ããOUãã¢ã«ã¦ã³ãã«é©ç¨ããåã«å®å ¨ã«ãã¹ããããã¨ãç®çã¨ãã¦ãã¾ããä¾ãã°ãSCPãã¿ã°ã®ããªã·ã¼ã¯ãæå³ããOUãã¢ã«ã¦ã³ãã«é©ç¨ããåã«ãã¹ãããå¿ è¦ãããã¾ãã
åæ§ã«ãåºç¯å²ã«é©ç¨ãããã¢ã«ã¦ã³ããã¼ã¹ã©ã¤ã³ã®IAMãã¼ã«ãããªã·ã¼ããããªã·ã¼ã¹ãã¼ã¸ã³ã°OUã使ç¨ãã¦ãã¹ãããå¿ è¦ãããã¾ãã
ã¯ã¼ã¯ãã¼ãåºæã®ããªã·ã¼
ã¯ã¼ã¯ãã¼ãåºæã®IAMãã¼ã«ã¨ããªã·ã¼ã®éçºã¨ãã¹ãã¯ãããªã·ã¼ã¹ãã¼ã¸ã³ã°OUã使ç¨ããå¿ è¦ã¯ããã¾ãããããããã¯ã¼ã¯ãã¼ããææãããã¼ã ã¯é常ãSecurity, Infrastructure, and Workloads OUå ã®éçºããã³ãã¹ãã¢ã«ã¦ã³ãã§ãä»ã®ã¯ã¼ã¯ãã¼ãåºæã®ãªã½ã¼ã¹ã¨ä¸ç·ã«ãããã®ãªã½ã¼ã¹ãéçºããã³ãã¹ããã¾ãã
æ¨å¥¨ããããã¹ãããã³ããã¢ã¼ã·ã§ã³ã®ã¯ã¼ã¯ããã¼
ããªã·ã¼ ã¹ãã¼ã¸ã³ã° OU ã§å¤æ´ããã¹ãããããããªã·ã¼ã®å¤æ´ãç®çã® OU å ã® 1 ã¤ã®ã¢ã«ã¦ã³ãã«ä¸æçã«é¢é£ä»ãããã¨ãæ¨å¥¨ãã¾ããå¤æ´ãæçµçã«OUã対象ã¨ãã¦ããå ´åã¯ãå¤æ´ãæå³ããOUã«é©ç¨ããå¤æ´ãæå³ããã¨ããã«åä½ãã¦ãããã¨ãæ¤è¨¼ããå¾ã«ãã¢ã«ã¦ã³ãããå¤æ´ãåé¤ãã¾ãã
ãã®æ¹æ³ã§ã¯ãæ¬çªç°å¢ã§å¤æ´ãæ¤è¨¼ãã¦ãããããåºç¯å²ã«å¤æ´ãé©ç¨ãããã¨ãã§ãã¾ãã
Example structure
ãã®ä¾ã§ã¯ãä¸é£ã®å OU ãå ¨ä½ã® OU æ§é ãåæ ãã¦ãã¾ããååOUã®ä¸ã«ã¯ãå°ãªãã¨ã1ã¤ã®ãã¹ãã¢ã«ã¦ã³ããå«ã¾ãã¦ãã¾ãã
OU ã¬ãã«ã§é©ç¨ããããã¨ãæå³ããã¦ãã SCP ããã³ã¿ã°ã»ããªã·ã¼ã®ãã¹ããæ¯æ´ããããã«ãåãã¼ã ã¯ã¾ããã¹ãç¨ã®å OU ã® 1 ã¤ã«ããããé©ç¨ããå¿ è¦ãããã¾ããç¹å®ã®ã¢ã«ã¦ã³ãã«é©ç¨ãããSCPãã¿ã°ã»ããªã·ã¼ã¯ãé©åãªãã¹ãç¨ã®åOUã®ä¸ã«ãã¹ãã»ã¢ã«ã¦ã³ããä½æããå¿ è¦ãããã¾ãã
Suspended OU
Suspended OUã¯ãä¸æçã¾ãã¯æä¹ çã«ä½¿ç¨ãåæ¢ããå¿ è¦ã®ããã¢ã«ã¦ã³ãã®ä¸æçãªä¿ç®¡å ´æã¨ãã¦ä½¿ç¨ããã¾ãã
ã¢ã«ã¦ã³ãããã®OUã«ç§»åãã¦ãããã®ã¢ã«ã¦ã³ãã®å ¨ä½çãªã¹ãã¼ã¿ã¹ãèªåçã«å¤æ´ãããããã§ã¯ããã¾ãããä¾ãã°ãã¢ã«ã¦ã³ãã®ä½¿ç¨ãæ°¸ä¹ ã«åæ¢ããå ´åã¯ããã¢ã«ã¦ã³ãã®ééãã®ããã»ã¹ã«å¾ã£ã¦ã¢ã«ã¦ã³ããæ°¸ä¹ ã«ééãã¾ãã
Suspended OU ã®ä½¿ç¨ä¾ã¨ãã¦ã¯ã以ä¸ã®ãããªãã®ãããã¾ãã
- ãã人ã®ãµã³ãããã¯ã¹ã¢ã«ã¦ã³ããããã®äººã®é社ã«ããä¸è¦ã«ãªã£ãå ´åã
- ã¯ã¼ã¯ãã¼ãã¢ã«ã¦ã³ããããªã½ã¼ã¹ã®å¼éãä»ã®ã¢ã«ã¦ã³ãã¸ã®ç§»è¡ã«ããä¸è¦ã«ãªã£ãå ´åã
åæ¢ä¸ã®ã¢ã«ã¦ã³ãã§ã®æ´»åã®æå¶
ãµã¼ãã¹ã³ã³ããã¼ã«ããªã·ã¼ï¼SCPï¼ã使ç¨ãã¦ãã»ãã¥ãªãã£ãã¼ã ã¨ã¯ã©ã¦ããã©ãããã©ã¼ã ãã¼ã 以å¤ã®ã¦ã¼ã¶ã¼ãåã¢ã«ã¦ã³ãã§AWS APIã使ç¨ãããã¨ãç¦æ¢ãããã¨ãã§ãã¾ããããã«ãã¢ããªã±ã¼ã·ã§ã³ã¬ãã«ã®ã¢ã¯ã»ã¹ãåé¤ãã¦ãã¦ã¼ã¶ã¼ãåæ¢ãããåã¢ã«ã¦ã³ãã®ã¢ããªã±ã¼ã·ã§ã³ãªã½ã¼ã¹ã«ã¢ã¯ã»ã¹ããã管çãããã§ããªããããã¨ãã§ãã¾ãã
ãªã¹ã¯ãä½æ¸ããã³ã¹ããæå°éã«æããå¯è½æ§ããããããåæ¢ãããåã¢ã«ã¦ã³ãã§å®è¡ä¸ã®ãªã½ã¼ã¹ãã¢ããªã±ã¼ã·ã§ã³ãåæ¢ãããã¨ãã§ãã¾ãã
ã¢ã«ã¦ã³ãã®ééãæå³ããã¦ããªãéããåæ¢ä¸ã®ã¢ã«ã¦ã³ããããªã½ã¼ã¹ãåé¤ãã¦ã¯ããã¾ããã
åæ¢ä¸ã®ã¢ã«ã¦ã³ãã¸ã®ã¿ã°ä»ã
ä¸æåæ¢ãããOUã¯æ§ã ãªç¨éã§ä½¿ç¨ãããå¯è½æ§ããããããåã¢ã«ã¦ã³ãã«ã¿ã°ãé©ç¨ãã¦ãã¢ã«ã¦ã³ãã移åããçç±ã¨ã¢ã«ã¦ã³ãã®å ã¨ãªã£ãOUãè¨é²ãããã¨ãæ¨å¥¨ãã¾ããä¸æåæ¢ã®ã¦ã¼ã¹ã±ã¼ã¹ããµãã¼ãããããã«ç¢ºç«ããåããã»ã¹ã¯ãã¿ã°ã使ç¨ãã¦ãä¸æåæ¢ãããã¢ã«ã¦ã³ããèªåçã«å¦çãããã¨ãã§ãã¾ããã¾ãããã®ã¿ã°ã¯ãã¢ã«ã¦ã³ãã®ã©ã¤ããµã¤ã¯ã«ãå é¨ã§è¿½è·¡ã»ç£æ»ããéã«ãå½¹ç«ã¡ã¾ãã
è£è¶³ï¼AWS Organizationsã®æ©è½ã§ãåã¢ã«ã¦ã³ããOUã«ã¿ã°ãä»ä¸ãããã¨ãå¯è½ã§ã
åæ¢ãããã¢ã«ã¦ã³ãã®éé
ã¢ã«ã¦ã³ããééããã»ã¹ã®éå§åã«ãã®OUã«ç§»åãããå ´åãã¢ã«ã¦ã³ãããã®OUã«ç§»åããã¦ããä¸å®ã®æ¥æ°å¾ã«ã¢ã«ã¦ã³ãééããã»ã¹ãèªåçã«éå§ããããªã·ã¼ã¨ããã»ã¹ãå®è£ ãããã¨ãã§ãã¾ãã
ã¢ã«ã¦ã³ãã®ééããã»ã¹ãå®äºããã¨ããã®ã¢ã«ã¦ã³ãã¯çµç¹å ã§è¡¨ç¤ºãããªããªãã¾ãã
è£è¶³ï¼ééãããAWSã¢ã«ã¦ã³ãã¯æ°ã«æéæ¯æãå¦çãªã©ã®çç±ã§åé¤ãããã«æ®åãã¾ãããã®éãCloudFormation StackSets ã¯ééãããã¢ã«ã¦ã³ãã§ãå®è¡ããã¾ããã¹ã¿ãã¯ã¯å¤±æãã¾ãããã®ãã失æãã¦ãåé¡ããªãã¨ãã Suspended OU ã«ç§»åãããã®ã¯ StackSets ã®ç®¡çé¢ã§ãæå¹ã§ãã
Individual Business Users OU
Individual Business Users OUã«ã¯ãWorkloads OUã§ç®¡çããã¦ãããªã½ã¼ã¹ã®ã³ã³ããã¹ãå¤ã®AWSãªã½ã¼ã¹ãç´æ¥ç®¡çããããã®ã¢ã¯ã»ã¹ãå¿ è¦ã¨ãããåã ã®ãã¸ãã¹ã¦ã¼ã¶ã¼ããã¼ã ã®ã¢ã«ã¦ã³ããå容ããã¦ãã¾ãã
ããã¤ãã®ã±ã¼ã¹ã§ã¯ãå°æ°ã®AWSãªã½ã¼ã¹ãã¯ã¼ã¯ãã¼ã以å¤ã®ãã®ã¨ãã¦èãããã¨ãã§ãã¾ããä¾ãã°ããã¸ãã¹ãã¼ã ãããã¼ã±ãã£ã³ã°ãããªããã¼ã¿ããã¸ãã¹ãã¼ããã¼ã¨å ±æããããã«ãAmazon S3ãã±ããã¸ã®æ¸ãè¾¼ã¿ã¢ã¯ã»ã¹ãå¿ è¦ã¨ããå ´åãããã¾ãããã®ãããªå ´åã«ã¯ãã¯ã¼ã¯ãã¼ãOUã®ã¢ã«ã¦ã³ãã§ã¯ãªããåã ã®ãã¸ãã¹ã¦ã¼ã¶ã¼OUå ã®ã¢ã«ã¦ã³ãã§ãããã®ãªã½ã¼ã¹ã管çãããã¨ãé¸æãããã¨ãã§ãã¾ãã
ã¬ã¼ãã¬ã¼ã«
ãã®OUã¨è¨±å¯ãããã¦ã¼ã¶ã¼ã«ã¯ãSCPã¨IAMãã¼ããã·ã§ã³ã®çµã¿åãããé©ç¨ãããã¨ãæ¨å¥¨ãã¾ããããã«ãããå¿ è¦ãªAWSãµã¼ãã¹ããªã½ã¼ã¹ãã¢ã¯ã·ã§ã³ã®ã¿ãä»ä¸ãããããã«ãªãã¾ããã¦ã¼ã¹ã±ã¼ã¹ã®æ§è³ªã«å¿ãã¦ããã®OUã®åã ã®ã¢ã«ã¦ã³ãã«ã¬ã¼ãã¬ã¼ã«ãé©ç¨ãããã¨ãã§ãã¾ãã
ã¢ã«ã¦ã³ãã¸ã®ã¦ã¼ã¶ã¼ã®ç´æ¥ã¢ã¯ã»ã¹ãå¿ è¦ã¨ããªããµã¼ãã¹ï¼è£è¶³ï¼IAM Userãçµãã¨ã使ç¨ã§ãããµã¼ãã¹ï¼
ã¢ã«ã¦ã³ãã¸ã®ç´æ¥ã¢ã¯ã»ã¹ãå¿ è¦ã¨ããã«ãã¦ã¼ã¶ã¼ãã¢ããªã±ã¼ã·ã§ã³ããµã¼ãã¹ãå©ç¨ããããã®èªè¨¼ã権éä»ä¸ãå¯è½ãªå ´åãåã ã®ãã¸ãã¹ã¦ã¼ã¶ã¼OUã¯é©ç¨ããã¾ãããä¾ãã°ããã¸ãã¹ã»ã¦ã¼ã¶ã¼ã¯ããã¸ãã¹ã»ã¤ã³ããªã¸ã§ã³ã¹(BI)ã®ç®çã§Amazon QuickSightã¸ã®ã¢ã¯ã»ã¹ãå¿ è¦ã¨ãããã¨ãããããã¾ããQuickSightãã¼ã¹ã®BIæ©è½ãã¯ã¼ã¯ãã¼ãã¨ã¿ãªããå ´åãWorkloads OUã®ã¯ã¼ã¯ãã¼ãã¢ã«ã¦ã³ãã«QuickSightãªã½ã¼ã¹ã¨ãã¼ã¿ãé ç½®ã§ãã¾ãããã®å ´åãBIã¦ã¼ã¶ã¼ã¯ãã¢ã«ã¦ã³ãã¬ãã«ã§ã®ã¢ã¯ã»ã¹ãå¿ è¦ã¨ããã«QuickSightãµã¼ãã¹ã«ç´æ¥ã¢ã¯ã»ã¹ãã権éãä¸ãããã¾ãã
è£è¶³ï¼QuickSight ã¯ãã©ã¦ã¶ããURLã§ã¢ã¯ã»ã¹ãããµã¼ãã¹ã§ãããAWSã¢ã«ã¦ã³ãã«ãã°ã¤ã³ãã¦å©ç¨ãããµã¼ãã¹ã§ã¯ãªãããã§ãããã®ãããªãµã¼ãã¹ã¯ä»ã«ã WorkDocs ã WorkSpaces çããããããã§ããã
Exceptions OU
Exceptions OUã«ã¯ãWorkloads OUã«é©ç¨ããã¦ããã»ãã¥ãªãã£ããªã·ã¼ã®ä¾å¤ãå¿ è¦ã¨ããã¢ã«ã¦ã³ããæ ¼ç´ããã¾ãï¼è£è¶³ï¼ã¤ã¾ããã»ãã¥ãªãã£ããªã·ã¼ãæå³çã«é¤å¤ããOUã§ãï¼ãé常ããã®OUã«åå ãããã¢ã«ã¦ã³ãã®æ°ã¯ããããã£ãã¨ãã¦ãæå°éã¨ãã¹ãã§ãã
ãµã¼ãã¹ã³ã³ããã¼ã«ããªã·ã¼ã¨ç²¾æ»
ä¾å¤ã¨ãããªç¬èªã®æ§è³ªãèæ ®ããé常 SCP ã¯ãã® OU ã®ã¢ã«ã¦ã³ãã¬ãã«ã§é©ç¨ããã¾ãï¼è£è¶³ï¼SCP ã¯åºæ¬çã« OU ã«ã¢ã¿ãããã¦ãã® OU é ä¸ã®å ¨ã¢ã«ã¦ã³ãã«ç¶æ¿ããããã®ã§ãããæ¬ OU ã§ã¯ä¾å¤çã«åã¡ã³ãã¼ã¢ã«ã¦ã³ãã« SCP ãç´æ¥ã¢ã¿ããããã¨ãããã¨ã§ãï¼ã
ãããã®ã¢ã«ã¦ã³ãã«ã¯ã«ã¹ã¿ãã¤ãºãããã»ãã¥ãªãã£å¶å¾¡ãé©ç¨ãããããããããã®ã¢ã«ã¦ã³ãã®ææè ã¯ãã»ãã¥ãªãã£ç£è¦ã·ã¹ãã ããããå³ããç£è¦ãåãããã¨ãäºæ³ããã¾ãã
Workloads OUã®æ¤è¨
è¤æ°ã®ã¢ã«ã¦ã³ããåãä¾å¤ãå¿ è¦ã¨ãããã¿ã¼ã³ãçºè¦ãããå ´åããæ¢åã®ã¯ã¼ã¯ãã¼ã OU ç¨ SCP ãä¿®æ£ããããããããã¯ãã¯ã¼ã¯ãã¼ã OU ã®é層æ§é ãæ¡å¼µããããã«æ°ã㪠OU 㨠SCP ãé©ç¨ãããããã©ã¡ãããæ¤è¨ãããã¨ã§ãã¢ã«ã¦ã³ããã¯ã¼ã¯ãã¼ã OU ä¸ã«å容ãããã¨ãæ¨å¥¨ãã¾ããã¯ã¼ã¯ãã¼ã OU ä¸ã«å¥ã®ã¬ãã«ã® OU ãå°å ¥ãã¦ãè¤æ°ã®ã¯ã¼ã¯ãã¼ãç°å¢ã«é©ç¨å¯è½ãªå ±éã®ã»ãã¥ãªãã£ããªã·ã¼ããã³/ã¾ãã¯éç¨ããã»ã¹ã表ããã¨ãã§ãã¾ãã詳細ã¯ããOrganizing workload-oriented OUsããåç §ãã¦ãã ããã
Deployments OU
Deployments OUã«ã¯ãã¯ã¼ã¯ãã¼ãã¸ã®å¤æ´ãæ§ç¯ãæ¤è¨¼ãä¿é²ããªãªã¼ã¹ããæ¹æ³ããµãã¼ããããªã½ã¼ã¹ã¨ã¯ã¼ã¯ãã¼ããå«ã¾ãã¦ãã¾ãã
ç¶ç¶çã¤ã³ãã°ã¬ã¼ã·ã§ã³ï¼ç¶ç¶çããªããªï¼CI/CDï¼æ©è½ã使ç¨ãã¦ããã¾ãã¾ãªç¨®é¡ã®ã½ã¼ã¹ã³ã¼ãã«å¯¾ããå¤æ´ã®å¦çã管çããã³èªååãã¦ããå ´åãããã§ãããã
AWSç°å¢ã®å¤ã«åå¨ããCI/CDæ©è½ã®ä½¿ç¨
AWSç°å¢ã®å¤ã«åå¨ãããªã³ãã¬ãã¹ããã³/ã¾ãã¯ããã¼ã¸ãCI/CDã«é¢é£ããæ©è½ããã§ã«ä½¿ç¨ãã¦ãããè¿ãå°æ¥ã«AWSç°å¢å ã§CI/CDãµã¼ãã¹ã使ç¨ããã³/ã¾ãã¯ç®¡çãããã¨ãäºæ³ãããªãå ´åãDeployments OUã¨é¢é£ããCI/CDæåã®ã¢ã«ã¦ã³ãã®ã»ãããããã«ç¢ºç«ããå¿ è¦ã¯ãªãããããã¾ããã
ãã®ã·ããªãªã§ã¯ãAWSç°å¢ã®å¤ã«åå¨ããCI/CDæ©è½ã¨AWSå ã®ã¯ã¼ã¯ãã¼ãç°å¢ã¨ã®éã®ã¢ã¯ã»ã¹ã¨æ½å¨çãªãããã¯ã¼ã¯æ¥ç¶ã®ä¾åé¢ä¿ã解決ããå¿ è¦ãããã¾ãã
CI/CD管çæ©è½ã¨ã¯ã¼ã¯ãã¼ãã®åé¢
AWSã§ç¬èªã®CI/CDæ©è½ãå±éã»ç®¡çããå ´åããAWSã管çããCI/CDãµã¼ãã¹ã使ç¨ããå ´åã¯ãDeployments OUå ã®ä¸é£ã®æ¬çªç¨ãããã¤ã¡ã³ãã¢ã«ã¦ã³ãã使ç¨ãã¦CI/CD管çæ©è½ãå容ãããã¨ãæ¨å¥¨ãã¾ãã
CI/CD管çæ©è½ãã¯ã¼ã¯ãã¼ãç°å¢ããåé¢ããçç±ã¯ä»¥ä¸ã®éãã§ãã
- CI/CDæ©è½ãæããéè¦ãªå½¹å² - CI/CDæ©è½ã¯ãå質æ¤è¨¼ãã»ãã¥ãªãã£ã»ã³ã³ãã©ã¤ã¢ã³ã¹ã»ãã§ãã¯ãæ¬çªåè£ã¢ã¼ãã£ãã¡ã¯ãã®æ§ç¯ã¨å ¬éãã¢ã¼ãã£ãã¡ã¯ãã®ä¿é²ãããã¦æçµçã«æ¬çªç°å¢ã¸ã®ã¢ã¼ãã£ãã¡ã¯ãã®ãªãªã¼ã¹ã®ããªã¬ã¼ãçµç¹åããå½¹å²ãæ ã£ã¦ãã¾ãããããã®å½¹å²ã®éè¦æ§ãèæ ®ããã¨ãã¯ã¼ã¯ãã¼ãç°å¢ã«é©ç¨ããããã®ã¨ã¯ç°ãªãé©åãªããªã·ã¼ã¨éç¨æ¹æ³ãCI/CDæ©è½ã«é©ç¨ã§ãããã¨ãéè¦ã§ãã
ä¾ãã°ãCIã¸ã§ããCDãã¤ãã©ã¤ã³ã§ã¯ãã¢ã¼ãã£ãã¡ã¯ã管çãµã¼ãã¹ã«åè£ã¨ãªãã¢ã¼ãã£ãã¡ã¯ããå ¬éããããããã¢ã¼ããããããããã«ãé常ã¯æ¸ãè¾¼ã¿æ¨©éãå¿ è¦ã§ããããããæ¬çªã¯ã¼ã¯ãã¼ãç°å¢ã§ã¯ããã§ã«æ§ç¯ãããããã¢ã¼ããããææç©ãåå¾ããããã«ãææç©ç®¡çãµã¼ãã¹ã¸ã®èªã¿åãã¢ã¯ã»ã¹ã®ã¿ãå¿ è¦ã§ãã
- CD ãã¤ãã©ã¤ã³ãéãããã¯ã·ã§ã³ããã³ãããã¯ã·ã§ã³ã®ã¯ã¼ã¯ãã¼ãç°å¢ã«å½±é¿ãä¸ãã - CD ãã¤ãã©ã¤ã³ãå¤æ´ã®æ¤è¨¼ãçµç¹åããæçµçã«ãããã¯ã·ã§ã³ã¸ã®å¤æ´ã®ãªãªã¼ã¹ãããªã¬ã¼ããå ´åããã¤ãã©ã¤ã³ã¯ãã°ãã°éãããã¯ã·ã§ã³ã®ãã¹ãããã³ãããã¯ã·ã§ã³ã®ã¯ã¼ã¯ãã¼ãç°å¢ã®ä¸¡æ¹ã«åå¨ããã¯ã¼ã¯ãã¼ãã«ã¢ã¯ã»ã¹ããå¿ è¦ãããã¾ãã
ä¾ãã°ãæ¬çªã¯ã¼ã¯ãã¼ãç°å¢ã§CI/CDæ©è½ã管çãã¦ããå ´åãæ¬çªã¯ã¼ã¯ãã¼ãç°å¢ããéæ¬çªç°å¢ã¸ã®ã¢ã¯ã»ã¹ã許å¯ããå¿ è¦ãããã¾ããCI/CDæ©è½ãCI/CDã¢ã«ã¦ã³ãã«éç´ãããã¨ã§ãæ¬çªã¯ã¼ã¯ãã¼ãç°å¢ããéæ¬çªç°å¢ã¸ã®ã¢ã¯ã»ã¹ã許å¯ããªãããã«ãããã¨ãã§ãã¾ãã
- CI/CDæ©è½ãç¬èªã®ãã¼ã«ã«ä¾åãã¦ãã - CI/CD管çæ©è½ãCIã¸ã§ããCDãã¤ãã©ã¤ã³ã¯ãã¯ã¼ã¯ãã¼ãã®å®è¡ã»éç¨ã«å¿ è¦ãªãã¼ã«ã¨ã¯ç°ãªããã¼ã«ã«ä¾åãã¦ãããã¨ãå¤ãã§ãããããã®ãã¼ã«ã®ä½¿ç¨ãCI/CDã¢ã«ã¦ã³ãã«éå®ãããã¨ã§ãã¯ã¼ã¯ãã¼ãç°å¢ã®è¤éããæ»æ対象ã軽æ¸ãããã¨ãã§ãã¾ãã
ãããã¤ã¡ã³ãã¢ã«ã¦ã³ãã§ã®CIã¸ã§ãããã³CDãã«ãã¹ãã¼ã¸ã®å®è¡
CIã¸ã§ãã¨CDãã¤ãã©ã¤ã³ã®ãã«ãã¹ãã¼ã¸ã¯æ£å¼ãªåè£ã®ã¢ã¼ãã£ãã¡ã¯ã(è£è¶³ï¼æ£å¼ãã¼ã¸ã§ã³ã¨ãã¦ãªãªã¼ã¹ãããå¯è½æ§ã®ããææç©)ãçæããå½¹å²ãæ ã£ã¦ããããããããã®ã¢ã¯ãã£ããã£ãæ¬çªç°å¢ã§å®è¡ãããã¨ãæ¨å¥¨ãã¾ãããããã®ã¢ã¯ãã£ããã£ãæ¬çªã¯ã¼ã¯ãã¼ãç°å¢ã§å®è¡ããã®ã§ã¯ãªããæ¬çªCI/CDã¢ã«ã¦ã³ãã§å®è¡ãããã¨ãæ¨å¥¨ãã¾ãã
CI/CDã¢ã«ã¦ã³ãã¨ã¯ã¼ã¯ãã¼ãã®ã°ã«ã¼ãã¨ã®æ´åæ§
ã¯ã¼ã¯ãã¼ãæåã®OUã§é¢é£ããã¯ã¼ã¯ãã¼ããã°ã«ã¼ãåããæ¹æ³ã«åããã¦ãDeployments OUã§CI/CDã¢ã«ã¦ã³ããå®ç¾©ãããã¨ãæ¨å¥¨ãã¾ãããããããã¨ã§ãã¯ã¼ã¯ãã¼ãã®åã°ã«ã¼ãã®ã»ãã¥ãªãã£ããªã·ã¼ãéç¨è¦ä»¶ã¨ãããã«ä»éããCI/CDã¢ã«ã¦ã³ããããç°¡åã«ä¸è´ããããã¨ãã§ãã¾ãã
ãã®æ¹æ³ã§ã¯ãCI/CDã¢ã«ã¦ã³ãã®åé¡ã®å½±é¿ç¯å²ãåä¸ã®ã¯ã¼ã¯ãã¼ãã¾ãã¯ã¯ã¼ã¯ãã¼ãã®ã°ã«ã¼ãã«éå®ãããã¨ãã§ãã¾ãã1ã¤ã®CI/CDã¢ã«ã¦ã³ãã§çºçããã¢ã¯ã»ã¹ã®åé¡ããªã½ã¼ã¹ã®ç«¶åã¯ãã»ã¨ãã©ã®å ´åãé¢é£ããã¯ã¼ã¯ãã¼ãã®ã°ã«ã¼ãã¨ã¯ã¼ã¯ãã¼ããåå¨ããã¢ã«ã¦ã³ãã«ã®ã¿å½±é¿ãä¸ããã
以ä¸ã®å³ã§ã¯ãã¯ã¼ã¯ãã¼ã1ã¯ãç¬èªã®æ¬çªã¢ã«ã¦ã³ãå°ç¨ã®ã¯ã¼ã¯ãã¼ãã表ãã¦ãã¾ããã¯ã¼ã¯ãã¼ã 2ã3ãããã³ 4 ã¯ãé¢é£ããã¯ã¼ã¯ãã¼ãã®ã°ã«ã¼ãã¨ãã¦æ§æãããå¥ã®æ¬çªã¢ ã«ã¦ã³ãã§ç®¡çããã¾ãã
ã¾ãããã¹ãã¢ã«ã¦ã³ãã«ã¯ãã¯ã¼ã¯ãã¼ãã®ãã¹ãã¤ã³ã¹ã¿ã³ã¹ãå«ã¾ãã¦ãã¾ããåãã¹ãã¢ã«ã¦ã³ãã§ã¯ãæ§ã ãªå½¢æ ã®ãã¹ããåæã«ãµãã¼ãã§ããããã«ãç¹å®ã®ã¯ã¼ã¯ãã¼ã㫠対ãã¦è¤æ°ã®ã¯ã¼ã¯ãã¼ãç°å¢ãåå¨ããå¯è½æ§ãããã¾ãã
ã¯ã¼ã¯ãã¼ã 1 ããµãã¼ãããããã« CI/CD ã¢ã«ã¦ã³ããä½æãããé¢é£ããã¯ã¼ã¯ãã¼ã 2ã 3ã4 ã®ã»ããããµãã¼ãããããã« 2 çªç®ã® CI/CD ã¢ã«ã¦ã³ããä½æããã¦ãã¾ããåæ¬çªç¨CI/CDã¢ã«ã¦ã³ãã®CI/CDãªã½ã¼ã¹ã¯ããã¹ãã¢ã«ã¦ã³ãã¨æ¬çªç¨ã¢ã«ã¦ã³ãã®ä¸¡æ¹ã§ã対象ã¨ãªãã¯ã¼ã¯ãã¼ãç°å¢ã¨å¯¾è©±ããå¿ è¦ãããããããã¾ããã
ãã«ãããã³ãåã®å ±æCI/CDãµã¼ãã¹ã®å©ç¨ãæ¤è¨ãã
å¤æ§ãªã¯ã¼ã¯ãã¼ãããµãã¼ãããããã«å ±éã®CI/CDã¢ã«ã¦ã³ãã使ç¨ãããã¨ã¯ãç°å¢ã®ç®¡çã¨ã»ãã¥ãªãã£ã®ç¢ºä¿ãå°é£ã«ãªãããããå§ãã§ãã¾ããããã®æ¹æ³ã§ã¯ãæ§ã ãªãã¼ã ãå ±éã®CI/CDãµã¼ãã¹ã¸ã®ã¢ã¯ã»ã¹ãå¿ è¦ã¨ããå¯è½æ§ãããã¾ããå ±éã® CI/CD ã¢ã«ã¦ã³ãå ã§ãã¼ã éã®ã¢ã¯ã»ã¹ãåé¢ããå¤æ°ã®ã¯ã¼ã¯ãã¼ãã¢ã«ã¦ã³ãã«ã¾ãããæªå½±é¿ãå¶éãããã¨ã¯ãã¯ã¼ã¯ãã¼ãã®ã°ã«ã¼ããã¨ã«åå¥ã® CI/CD ã¢ã«ã¦ã³ãã使ç¨ããå ´åãããè¤éã§ãã¨ã©ã¼ãçºçãããããªãã¾ãã
æ¬çªCI/CDãµã¼ãã¹ã¸ã®ãã¼ã ã®ã¢ã¯ã»ã¹ãå¯è½ã«ãã
ç¹å®ã®ã¯ã¼ã¯ãã¼ããææãããã¼ã ã¡ã³ãã¼ã¯ããããã®ã¯ã¼ã¯ãã¼ãã«é¢é£ããæ¬çªCI/CDãµã¼ãã¹ã¸ã®ããç¨åº¦ã®ã¢ã¯ã»ã¹ãå¿ è¦ã¨ãã¾ããæä½ã§ããCIã¸ã§ããCDãã¤ãã©ã¤ã³ã®å®è¡ãç£è¦ããæ©è½ãå¿ è¦ã§ãã
CIã¸ã§ãã¨CDãã¤ãã©ã¤ã³ãæ¬çªç¨CI/CDã¢ã«ã¦ã³ãã«ææ ¼ããããã»ã¹ã«ãã£ã¦ã¯ãCIã¸ã§ãã¨CDãã¤ãã©ã¤ã³ãææãããã¼ã å ã®æå®ããã管çè ã«ãCIã¸ã§ãã¨CDãã¤ãã©ã¤ã³ã¸ã®éå®ãããç¨åº¦ã®æ¸ãè¾¼ã¿ã¢ã¯ã»ã¹ãå¿ è¦ãªå ´åãããã¾ãã
ãã¼ã ã¡ã³ãã¼ãCI/CDãµã¼ãã¹ãåå¨ããã¢ã«ã¦ã³ãã«ç´æ¥ã¢ã¯ã»ã¹ããå¿ è¦ããããã©ããã¯ã使ç¨ãã¦ããCI/CDãã¼ã«ã®ç¨®é¡ã«ãã£ã¦ç°ãªãã¾ããä¾ãã°ãç¬èªã®CI/CDãã¼ã«ã管çãã¦ããå ´åãã¢ã¯ã»ã¹å¶å¾¡ã¯CI/CDãã¼ã«ã®ä¸ã§ç®¡çãããèªè¨¼ã¯CI/CDãã¼ã«ãåå¨ããã¢ã«ã¦ã³ãã®ã³ã³ããã¹ãã®å¤ã§è¡ããããã¨ãå¤ãã§ãããããã®ä¾ã§ã¯ããã¼ã ã¡ã³ãã¼ã¯CI/CDã¢ã«ã¦ã³ãã«ç´æ¥ã¢ã¯ã»ã¹ããå¿ è¦ã¯ãªãã§ãããã
AWSã®ããã¼ã¸ãCI/CDãµã¼ãã¹ã使ç¨ãã¦ããå ´åããã¼ã ã¡ã³ãã¼ã¯CIã¸ã§ããCDãã¤ãã©ã¤ã³ã®å®è¡ãç£è¦ããããã«ãCI/CDã¢ã«ã¦ã³ãã¸ã®å°ãªãã¨ãèªã¿åãã¢ã¯ã»ã¹ãå¿ è¦ã§ãã
次ã®å³ã§ã¯ãåæ¬çªCI/CDã¢ã«ã¦ã³ãã«é¢é£ããã¯ã¼ã¯ãã¼ããææãããã¼ã ããããããã®ã¢ã«ã¦ã³ãã®CI/CDãªã½ã¼ã¹ã«ã¢ã¯ã»ã¹ãã¦ããæ§åã示ããã¦ãã¾ãã
ã¯ã¼ã¯ãã¼ãã¢ã«ã¦ã³ãã¸ã® CD ãã¤ãã©ã¤ã³ã¢ã¯ã»ã¹ã®æä¾
CD ãã¤ãã©ã¤ã³ãã¯ã¼ã¯ãã¼ãç°å¢ã«å¤æ´ãããã·ã¥ããããã«ãããã¤ã¡ã³ãæ¹æ³ã¨ãã¼ã«ã使ç¨ããå ´åãCD ãã¤ãã©ã¤ã³ã¾ãã¯ãããã¤ã¡ã³ãã¿ã¹ã¯ãå§ä»»ããã¦ãããããã¤ã¡ã³ããã¼ã«ã®ããããããã¿ã¼ã²ããã¯ã¼ã¯ãã¼ãç°å¢ã¸ã®ååãªæ¸ãè¾¼ã¿ã¢ã¯ã»ã¹ãå¿ è¦ã¨ãã¾ãã
ã¯ã¼ã¯ãã¼ãç°å¢ã¸ã®å¤æ´ããããã¤ããå¥ã®æ¹æ³ã¨ãã¦ãCDãã¤ãã©ã¤ã³ãã¿ã¼ã²ããã®ã¯ã¼ã¯ãã¼ãç°å¢ã¸ã®æ¸ãè¾¼ã¿ã¢ã¯ã»ã¹ãå¿ è¦ã¨ããªãããã«ãããã«åã®ãããã¤ã¡ã³ããããã¾ãããã«ã¢ãã«ã§ã¯ã対象ã¨ãªãã¯ã¼ã¯ãã¼ãç°å¢å ã®ãã¼ã«ã¯ã対象ã¨ãªãå¤æ´ï¼ä¾ãã°ãæ°ããããã¢ã¼ããããã¢ã¼ãã£ãã¡ã¯ããæ§æã®å¤æ´ãªã©ï¼ãæ¤åºããã¯ã¼ã¯ãã¼ãç°å¢å ã«ãããã®å¤æ´ããã¼ã«ã«ã«ãããã¤ããããã«å¿ è¦ãªæ¨©éãæã£ã¦ãã¾ãã
CI/CDæ©è½ã®å¤æ´ããã¹ããã
Deployments OUã«éæ¬çªç¨ã®ãã¹ãã¢ã«ã¦ã³ããè¨å®ãããã¨ãæ¨å¥¨ãã¾ãããããã®ã¢ã«ã¦ã³ãã¯ãæ¬çªã® CI/CD ç°å¢ã«å¤æ´ãåæ ãããåã«ãCI/CD æ©è½ã®ä½¿ç¨æ¹æ³ã管çæ¹æ³ã®å¤æ´ããã¹ãããããã«ä½¿ç¨ã§ãã¾ãã
AWSã§CI/CDãã¼ã«ã管çãããã¨ãè¨ç»ãã¦ããå ´åãCI/CDç¨ã®ãã¹ãã¢ã«ã¦ã³ãã®ã»ããã確ç«ãããã¨ãæãéè¦ã§ãããããã®ãã¼ã«ã®ä½¿ç¨ããµãã¼ãããé²åãããããã«ã¯ãæ¬çªç°å¢ã¨ã¯å¥ã«ãã¹ãç°å¢ãç¨æããå¿ è¦ãããã¾ãã
AWS CodePipelineãAWS CodeBuildãAWS Protonãããã³/ã¾ãã¯AWS CodeDeployãå«ãAWSããã¼ã¸ãCI/CDé¢é£ãµã¼ãã¹ã使ç¨ãã¦ããå ´åã§ãããã¹ãç°å¢ãæã¤ãã¨ã§ããããã®ããã¼ã¸ããµã¼ãã¹ãå®å ¨ã«ä½¿ç¨ããæ¹æ³ã®å¤æ´ããã¹ããããã¨ãã§ããæçã§ãã
ä¸è¬çã«ã¯ããã¹ãç¨ã®CI/CDç°å¢ã¯ãæ¬çªç¨ã®CI/CDç°å¢ãæ¬çªç¨ã®ã¯ã¼ã¯ãã¼ãç°å¢ã«ã¯ã¢ã¯ã»ã¹ã§ããªãããã«ãã¾ãã代ããã«ããã¹ãCI/CDç°å¢ã¸ã®ã¢ã¯ã»ã¹ã¯ãéæ¬çªã®ã¯ã¼ã¯ãã¼ãç°å¢ã«éå®ãããã¹ãã§ãã
CIã¸ã§ãã¨CDãã¤ãã©ã¤ã³ã®éçºã¨ãã¹ã
Deployments OUã¯ããã¼ã ãCIã¸ã§ããCDãã¤ãã©ã¤ã³ãéçºã»ãã¹ãããããã®æ段ã¨ãã¦ä½¿ç¨ãããã¨ãæå³ãã¦ãã¾ãããããããä»ã®ã¯ã¼ã¯ãã¼ãã®éçºãåæãã¹ãã¨åæ§ã«ãéçºç¨ã®AWSç°å¢ã§CIã¸ã§ããCDãã¤ãã©ã¤ã³ãéçºããã¹ããããã¨ãæ¨å¥¨ãã¾ãã
ä»ã®ç¨®é¡ã®ã³ã¼ãã¨åæ§ã«ãCIã¸ã§ããCDãã¤ãã©ã¤ã³ã®ã½ã¼ã¹ããCIã¸ã§ããCDãã¤ãã©ã¤ã³ã®ããã¢ã¼ã·ã§ã³ã«åãããããã»ã¹ã使ã£ã¦ãæ¬çªã®CI/CDç°å¢ã«ããã¢ã¼ããããã¨ãã§ãã¾ãããã®æ¹æ³ã«ãããæ¬çªã®CI/CDç°å¢ã§å¿ è¦ãªã¢ã¯ã»ã¹ãæå°éã«æãããããã¤ã¡ã³ãOUå ã®ãã¹ãç¨CI/CDç°å¢ãCI/CDæ©è½èªä½ã®ãã¹ãã«éå®ãããã¨ãã§ãã¾ãã
Example structure
以ä¸ã®ä¾ã§ã¯ãä¸é£ã®æ¬çªã¢ã«ã¦ã³ãã¯ãä¸å¤®ã§ç®¡çãããå ±æã®CI/CDãµã¼ãã¹ã¨ãé£æºãã¦ç®¡çããããã¸ãã¹ã¦ãããã®CI/CDãªã½ã¼ã¹ã®ã»ããã表ãã¦ãã¾ãã
å ¸åçãªã·ããªãªã§ã¯ã-prodã§ä¿®é£¾ãããã¢ã«ã¦ã³ãã®å®å®ããæ¬çªå質ã®CI/CDæ©è½ã¯ãæ¬çªããã³éæ¬çªã®ã¯ã¼ã¯ãã¼ãç°å¢ã®ä¸¡æ¹ã§å¤æ´ããããããã¨ãæå¾ ããã¾ãããã®-prodã¨ãã修飾èªã¯ãåã«ããããå®å®ããæ¬çªå質ã®CI/CDç°å¢ã§ãããã¨ã示ãã¦ãã¾ãã
Test OUã®ã¢ã«ã¦ã³ãä¾ã¯ã-testã§ä¿®é£¾ããã¦ãã¾ãããããã®ã¢ã«ã¦ã³ãã¯ãå®å®ããæ¬çªå質ã®CI/CDç°å¢ã«å¤æ´ãé©ç¨ããåã«ãCI/CDãã©ãããã©ã¼ã ã¸ã®å¤æ´ãããã¼ã¸ãCI/CDãµã¼ãã¹ã®ä½¿ç¨æ¹æ³ããã¹ãããããã®ç°å¢ã表ãã¦ãã¾ãã
æ¬çªç°å¢ã¨éæ¬çªç°å¢ã®ã¯ã¼ã¯ãã¼ãã¨ãªã½ã¼ã¹ãåé¢ããããã®ä¸è¬çãªã¬ã¤ãã³ã¹ã«ã¤ãã¦ã¯ããOrganizing workload-oriented OUsããåç §ãã¦ãã ããã
Transitional OU
移è¡ç¨OUã¯ãæ¢åã®ã¢ã«ã¦ã³ããã¯ã¼ã¯ãã¼ãããAWSç°å¢ã®æ¨æºåãããé åã«æ£å¼ã«çµ±åããåã«ãçµç¹ã«ç§»è¡ããããã®ä¸æçãªä¿ç®¡å ´æã¨ãã¦ä½¿ç¨ãããã¨ãç®çã¨ãã¦ãã¾ãã
ã¢ã«ã¦ã³ããçµç¹ã«ç§»è¡ããä¸è¬çãªçç±
ã¢ã«ã¦ã³ããçµç¹ã«ç§»è¡ããä¸è¬çãªçç±ã¯ä»¥ä¸ã®éãã§ãã
- æ¢ã«AWSãå©ç¨ãã¦ãã¦ã¢ã«ã¦ã³ããæã£ã¦ããä¼æ¥ã®è²·å
- æ°ããAWSç°å¢æ§æãæ§ç¯ããåã«ä½æãããç¬èªã®ã¢ã«ã¦ã³ããåå¨ããã
- ãµã¼ããã¼ãã£ã管çãã¦ããã¢ã«ã¦ã³ãã®ç§»è¡
AWSçµç¹ã¸ã®ã¢ã«ã¦ã³ã移è¡ã®ã¡ãªãã
æ¢åã®ã¢ã«ã¦ã³ããçµç¹ã«ç§»è¡ãããã¨ã§ãAWSçµç¹ãå©ç¨ãããã¨ã§ä»¥ä¸ã®ãããªã¡ãªãããå¾ãããããã«ãªãã¾ãã
- ä¸å åãããå¯è¦æ§
- å ±éã®ããªã·ã¼ãé©ç¨ããããã®ãªãã·ã§ã³
- çµ±åãããè«æ±ãã³ã¹ããããã³è³ç£ç®¡ç
- AWS Organizationsã«å¯¾å¿ããAWSã»ãã¥ãªãã£ãµã¼ãã¹ã®ç°¡ç´ åãããå©ç¨
- æ¢åã®ãã§ãã¬ã¼ãããã»ã¢ã¯ã»ã¹æ©è½ã¨ã®çµ±å
ã¢ã«ã¦ã³ããçµç¹ã«ç§»åããéã®æ³¨æç¹
æ¢åã®çµç¹ããã¢ã«ã¦ã³ãã移åããå ´åã¯ãã¾ããã®ã¢ã«ã¦ã³ããçµç¹ããåé¤ããå¿ è¦ãããã¾ãã詳細ã¯ããã¡ã³ãã¼ã¢ã«ã¦ã³ããçµç¹ããåé¤ããããåç §ãã¦ãã ãããã¢ã«ã¦ã³ããçµç¹ããåé¤ããã¨ããã®ã¢ã«ã¦ã³ãã¯ã¹ã¿ã³ãã¢ãã³ã¢ã«ã¦ã³ãã¨å¼ã°ãã¾ãã
ä»ã®ã¢ã«ã¦ã³ãã«ä¾åãã¦ããªãã¹ã¿ã³ãã¢ãã³ã¢ã«ã¦ã³ãã®ç§»åã¯ãç°¡åãªæé ã§è¡ãã¾ãããã®å ´åãé常ã移åããã¢ã«ã¦ã³ãã®æ¢åã®ã¯ã¼ã¯ãã¼ãã移è¡ã¾ãã¯å¤æ´ããå¿ è¦ã¯ããã¾ããã詳細ã¯ããçµç¹ã«åå ããã¢ã«ã¦ã³ããæå¾ ããããåç §ãã¦ãã ããã
移åããã¹ã¿ã³ãã¢ãã³ã¢ã«ã¦ã³ããä»ã®ã¢ã«ã¦ã³ãã«ä¾åãã¦ããå ´åã¯ããããã®ä¾åé¢ä¿ãè©ä¾¡ãã¦ãã¢ã«ã¦ã³ãã移åããåã«å¯¾å¦ãã¹ããã©ãããå¤æããå¿ è¦ãããã¾ãã
対象ã¨ãªãçµç¹ã§ã¯ãçµç¹ã®ã«ã¼ãã«ããSCPã確èªãããããã®SCPã移åããã¢ã«ã¦ã³ãã«æªå½±é¿ãåã¼ããªããã¨ã確èªãããã¨ãæ¨å¥¨ãã¾ãã
é¢é£ããã¢ã«ã¦ã³ãã®ã»ãããçµç¹ã«ç§»åããå ´åã¯ãé¢é£ããã¢ã«ã¦ã³ãã®ã»ããã®ããã«ç§»è¡OUã®ä¸ã«åOUãä½æãããã¨ãã§ãã¾ãã
ã¢ã«ã¦ã³ã移åå¾
æéã®çµéã¨ã¨ãã«ããããã®ã¢ã«ã¦ã³ãã¨ãã®ä¸ã«å«ã¾ããã¯ã¼ã¯ãã¼ãã®æ¹åæ§ãããæ·±ãç解ã§ããããã«ãªãã¨ãã¢ã«ã¦ã³ãããã®ã¾ã¾ã¯ã¼ã¯ãã¼ãOUã«ç§»åããããã¯ã¼ã¯ãã¼ããä»ã®ã¢ã«ã¦ã³ãã«ç§»è¡ããããã®æè³ãè¡ã£ãããã¯ã¼ã¯ãã¼ãã¾ãã¯ã¢ã«ã¦ã³ãã®ãããããå»æ¢ããããããã¨ãã§ãã¾ãã
Recommended OUs ã®ç¿»è¨³ã¯ããã¾ã§ã¨ãªãã¾ãã
2024å¹´6æ13æ¥ è¿½è¨ Business Continuity OU
2024å¹´6æç¾å¨ã¯æ¨å¥¨ OU ã«11åç®ã¨ãã¦ãBusiness Continuity OUãã追å ããã¦ãã¾ãã
ããåç¬ã®è§£èª¬ããã°ãè¨è¼ãã¾ããã®ã§ãåããã¦ã覧ãã ããã
ä½è«
AWS Control Tower
AWS Control Tower ã«ã¤ãã¦å°ã触ãã¾ãã
2021å¹´4æã«ä»¥ä¸ã®éãæ±äº¬ãªã¼ã¸ã§ã³ã§ãå©ç¨ãå¯è½ã¨ãªã£ã AWS Control Tower ã§ãããAWS Control Tower ã¨ä¸è¨ãã¹ããã©ã¯ãã£ã¹ã¯ OU ã®æ§æãç°ãªã£ã¦ãã¾ãã
ãã£ããã§ã¯ããã¾ããã以ä¸ã Control Tower ã®åºæ¬ç㪠OU æ§æã§ãã
Core OU ã«ãã°ã¢ã¼ã«ã¤ãå°ç¨ã®ã¢ã«ã¦ã³ãã¨ãç£æ»ç¨ã®ã¢ã«ã¦ã³ããç¨æãã¾ããã¾ã Custom OU é ä¸ã«ã¯ã¢ããªã±ã¼ã·ã§ã³çãæ§ç¯ããã¢ã«ã¦ã³ããé ç½®ãã¦ãããã¨ã«ãªãã¾ãã
AWS Landing Zone
é¢é£ãã¦ã§ããã AWS Landing Zone ã®ã½ãªã¥ã¼ã·ã§ã³ã§ãç°ãªã OU æ§é ã«ãªã£ã¦ãã¾ãã
Landing Zone ã§ã¯ãCore OU ã«å ±æãµã¼ãã¹ã¢ã«ã¦ã³ãããã°ã¢ã¼ã«ã¤ãã¢ã«ã¦ã³ããã»ãã¥ãªãã£ã¢ã«ã¦ã³ããé ç½®ããããã«ãªã£ã¦ãã¾ãã
ãããã®2ã¤ã¯ AWS ããåºã¦ãã¦ãããµã¼ãã¹ãã½ãªã¥ã¼ã·ã§ã³ã§ããããã® OU æ§é ã®ãã¹ããã©ã¯ãã£ã¹ãæéã¨å ±ã«å¤åãã¦ããã®ã¯ AWS Organizations ã®å©ç¨ãå¢ãã¦ããããã¨èãã¦ãã¾ãã
AWS ã® Organizations ã®æ§æã«æ£è§£ãããããã§ã¯ããã¾ãããã客æ§ã®å©ç¨æ¹æ³ã«ãã£ã¦ãå人åè²ã¨ãªããã®ã§ãããã ãããã¹ããã©ã¯ãã£ã¹ã¯ããã¾ããã¾ãããã¯æ代ã«ãã£ã¦ç°ãªã£ã¦ãããã®ã§ãããã¾ãã®ã§ãå®æçã« OU æ§æã®æ£å¸ããããã®ãè¯ãããããã¾ããã
ã¾ã¨ã
æ¬æ¥ã¯ AWS ã®ãã¯ã¤ããã¼ãã¼ãOrganizing Your AWS Environment Using Multiple Accountsãä¸ãããRecommended OUsããç´¹ä»ãã¤ã¤å訳ããã¦é ãã¾ãããOUã®æ¨å¥¨ã ãã§ãããªãã®ããªã¥ã¼ã ã«ãªã£ã¦ãã¾ãããã
ãã¹ã¦ã®ã¦ã¼ã¶ã¼ã§ããããã®10åã® OU ãå¿ è¦ã¨ãããã¨ã§ã¯ããã¾ãããã¾ãæåãããã®10åã® OU ã SCP å«ãã¦ä½ãããã®ã«ã¯æéãç¨ãã¾ãããã¯ã¤ããã¼ãã¼ã«ã¯ SCP ã®å ·ä½çãªè¨å®å¤ã§ãã json ã¯æä¾ããã¦ãã¾ããã§ããã
AWSã®è¯ãã¯ãæ©ãå§ãããã¨ãã§ããå¾ããé²æã«å¿ãã¦æé©åã§ããã¨ããã¨ããã§ããæå°éã® OU ã§ã¾ãã¯éå§ãã¦ãå¾ã å¿ è¦ã«ãªã OU ã SCP ãé©å®è¿½å ãããã»ããã¯ã¤ãã¯ã§è¯ãã¨èãã¾ãã
ç§ã§ããã°ãã§ãããã¾ã㯠Security OUãInfrastructure OU ãåºç¤ã¨ãã¦æ§ç¯ããSandbox OUãWorkloads OU ãç¨ãã¦ã¢ããªã±ã¼ã·ã§ã³ãå®è£ ãã¾ããåé¤ããã¢ã«ã¦ã³ããåºã¦ããã¿ã¤ãã³ã°ã§ Suspended OU ãç¨æããã§ãããã
ã©ãã¾ã§ OU ãè¨è¨ãããæ©ããããªå ´åã¯ããPatterns for organizing your AWS accountsãã«ããããã®ãã¿ã¼ã³å¥ã«æ§æã®ç´¹ä»ãããã¾ããç§ãå ã«è¨è¼ãããã®ã¯ãBasic organization with infrastructure servicesãã¨åæ§ã®è¨è¨ã§ããã
ããããã®æ§æå³ãåèã«ãã¦ã¿ã¦ãã ããã
è£è¶³
å¾æ¥ãè¤æ°æ¡ä»¶ã® OU è¨è¨ãè¡ã£ãçµæã¨ãã¦ã以ä¸ã® OU æ§æãéç¨ä¸ãã¿ã¼ã ã¨èããããã¨ããããã°ãç¦å³¶ãè¨è¼ãã¦ããã¾ããããåããã¦åèãã ããã
ã§ã¯ã¾ããä¼ããã¾ãããã
ä½ç«¹ é½ä¸ (Yoichi Satake) ã¨ã³ã¸ãã¢ããã°ã®è¨äºä¸è¦§ã¯ã³ãã©
ããã¼ã¸ããµã¼ãã¹é¨æå±ãAWSè³æ ¼å ¨å ã2010å¹´1æããAWSãå©ç¨ãã¦ãã¦ãã¾ãã2021-2022 AWS Ambassadors/2023-2024 Japan AWS Top Engineers/2020-2024 All Certifications EngineersãAWSã®ã³ã¹ãåæ¸ãæé©åãå¾æã¨ãã¦ãã¾ãã