ã¿ãªããããã«ã¡ã¯! æè¡1課ä¸æã§ãã ä»æ¥ã®è¨äºã¯ãVPC Endpointã使ã£ã¦S3ã«ã¢ã¯ã»ã¹ãã話ã§ãã
VPC Endpointèªä½ã¯ä»å¹´ã®5æã«ãªãªã¼ã¹ãããæ©è½ã¨ãªãã¾ãã
S3ã使ã£ã¦ã¾ããï¼
ã¨ããã§ãS3ã¯çãã使ã£ã¦ã¾ããï¼
容éã¯ç¡éã99.999999999% ã®å
ç¢æ§ã¨ã99.99%ã®å¯ç¨æ§ã
ããã«ã¯ã¹ãã¬ã¼ã¸æéã¯1GBããã$0.033(æ±äº¬ãªã¼ã¸ã§ã³)ã¨ãç´ æ´ããããµã¼ãã¹ã§ãã
AWSã§ã¯EC2ã«ä¸¦ã¶æåãªãµã¼ãã¹ã ã¨æãã¾ãã ããã«ã¯ãæè¿ã¯ã¯ãã¹ãªã¼ã¸ã§ã³ã¬ããªã±ã¼ã·ã§ã³ã®æ©è½ã追å ããã 大è¦æ¨¡ç½å®³ã«ãåãããã¨ãã§ããããã«ãªãã¾ããã ãã ããS3ã«ã¢ã¯ã»ã¹ããã«ã¯ã¤ã³ã¿ã¼ããããçµç±ãã¦ã¢ã¯ã»ã¹ããªããã°ãªããªããã¨ããå¶ç´ãããã¾ããã
ãã®ãããã¤ã³ã¿ã¼ãããã«åºãå¿
è¦ãªãæ¥åã·ã¹ãã ãªã©ãAWSã«æ§ç¯ããå ´åã§ãã
S3ã«ã¢ã¯ã»ã¹ããããã«ã¯VPCã«IGWãã¢ã¿ãããã¦ã ä¸åº¦IGWããã¤ã³ã¿ã¼ãããã«åºã¦ããS3ã«ã¢ã¯ã»ã¹ããå¿
è¦ãããã¾ããã ä»åã話ããVPC Endpointæ©è½ã使ãã¨ã
VPCã¨å¥ã®AWSãµã¼ãã¹ã¨ã®éã§ãã©ã¤ãã¼ãæ¥ç¶ãä½æã§ããããã«ãªãã¾ãã
ã¤ã¾ããS3ã«ã¢ã¯ã»ã¹ããéã«ããã¤ã³ã¿ã¼ããããçµç±ããªãã¦ãããªããã§ããã ã§ã¯ãæ©éè¨å®ãé²ãã¾ãããã
æé ã¯ã¨ã¦ãç°¡åã§ãã
1. VPC Endpointãä½æ
ã¾ãã¯VPC Endpointãä½æãã¾ãã
VPCã®ããã·ã¥ãã¼ãããEndpointãé¸æãã¾ãã
2. VPCã®é¸æã¨Policyã®å ¥å
VPC Endpointãé¸æããããEndpointãä½æããVPCã¨ãPolicyãå
¥åãã¾ãã
S3 Bucket Policyã®ããã«ç´°ããå¶å¾¡ãããã¨ãã§ãã¾ãããä»åã¯VPCå
ããã®ã¢ã¯ã»ã¹ã¯å
¨ã¦è¨±å¯ããè¨å®ã«ãã¾ãã
3. RouteTableã®é¸æ
Policyãå
¥åãçµãã£ãããVPC Endpointã¸ã®Routeãé©ç¨ãã
RouteTableãé¸æãã¾ãã
â»ã¹ã¯ãªã¼ã³ã·ã§ããã§ãè¦åãåºã¦ãã¾ããã
VPCã¨ã³ããã¤ã³ããä½æããéã¯ã ãµããããä¸ã®S3ã¨ã®éä¿¡ãä¸æ¦åæããã¾ãã®ã§ã注æãã ããã æé ã¯ããã§çµããã§ãï¼
確èª
ãã¦ãEndpointãä½æããã¨ããã§ã確èªãã¦ã¿ã¾ãããã
AWSã®VPCã«ãã¤ã³ã¿ã¼ãããã«åºã¦ãããªããµãããããä½æããã¤ã³ã¹ã¿ã³ã¹ãç«ã¦ã¾ãã
ããã¦ãã¤ã³ã¹ã¿ã³ã¹ããS3 Objectã«curlã³ãã³ããæã£ã¦ã¿ã¾ãããã
8.8.8.8(Google)ã«ã¯ã¢ã¯ã»ã¹ã§ãã¦ãã¾ããããS3ã«ã¯ã¡ããã¨ã¢ã¯ã»ã¹ã§ãã¦ãã¾ããã ã¤ãã§ã«ãRouteTableãè¦ã¦ã¿ã¾ãããã com.amazonaws.ap-northeast-1.s3ã«Routeãæ¸ããã¦ãããã¨ã確èªã§ãã¾ãã
ã¡ãªã¿ã«ãã®Routeã¯ãã®ç»é¢ããç·¨éã§ããªãã®ã§ããã®Routeãæ¶ãå ´åã¯VPCã®Endpointããç·¨éãã¾ãããã
(ä¸ã®æé ã®3çªã§ã)
ã¾ã¨ã
ã¨ããããã§ä»æ¥ã¯VPC Endpointã使ã£ã¦S3ã«ã¢ã¯ã»ã¹ãã話ã§ããã
è¨å®ã¯ã¨ã¦ãç°¡åãªã®ã§ãç©æ¥µçã«ä½¿ã£ã¦ããã¾ãããï¼
追è¨
2021å¹´2æã«è¿½å ãããPrivateLinkçã®S3 VPC Endpointã«ã¤ãã¦ã¯ä»¥ä¸ã®ããã°ããåèãã ããã