ãçãããIAM使ã£ã¦ã¾ãããï¼
ä»æ¥ã¯ãIAMã®ãã¹ããã©ã¯ãã£ã¹ã®ä¸ã«åªç¸ã®ããã«åå¨ãããæå°æ¨©éããã¼ãã«æ©ã¿ãèªã£ã¦ã¿ããã¨æãã¾ãã
IAMã§ã®ã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹
ãã¾ãã¯ãIAMã®ãã¹ããã©ã¯ãã£ã¹ã®ç¢ºèªã§ãã2020å¹´7æç¾å¨ã§ã¯ã17ååå¨ãã¦ãã¾ããä¸çªæå¾ã®ãããªã§èª¬æããã®åçªæ以å¤ã¯ãã©ããç´å¾æãããå 容ã§å®è·µã»éµå®ãã¹ãã§ãã
- AWS ã¢ã«ã¦ã³ãã®ã«ã¼ãã¦ã¼ã¶ã¼ ã¢ã¯ã»ã¹ãã¼ãããã¯ãã
- åã ã® IAM ã¦ã¼ã¶ã¼ã®ä½æ
- IAM ã¦ã¼ã¶ã¼ã¸ã®ã¢ã¯ã»ã¹è¨±å¯ãå²ãå½ã¦ãããã«ã°ã«ã¼ãã使ç¨ãã
- æå°æ¨©éãä»ä¸ãã
- AWS 管çããªã·ã¼ã使ç¨ããã¢ã¯ã»ã¹è¨±å¯ã®ä½¿ç¨éå§
- ã¤ã³ã©ã¤ã³ããªã·ã¼ã§ã¯ãªãã«ã¹ã¿ãã¼ç®¡çããªã·ã¼ã使ç¨ãã
- ã¢ã¯ã»ã¹ã¬ãã«ã使ç¨ãã¦ãIAM 権éã確èªãã
- ã¦ã¼ã¶ã¼ã®å¼·åãªãã¹ã¯ã¼ãããªã·ã¼ãè¨å®
- MFA ã®æå¹å
- Amazon EC2 ã¤ã³ã¹ã¿ã³ã¹ã§å®è¡ããã¢ããªã±ã¼ã·ã§ã³ã«å¯¾ãããã¼ã«ã使ç¨ãã
- ãã¼ã«ã使ç¨ããã¢ã¯ã»ã¹è¨±å¯ã®å§ä»»
- ã¢ã¯ã»ã¹ãã¼ãå ±æããªã
- èªè¨¼æ å ±ãå®æçã«ãã¼ãã¼ã·ã§ã³ãã
- ä¸è¦ãªèªè¨¼æ å ±ãåé¤ãã
- 追å ã»ãã¥ãªãã£ã«å¯¾ããããªã·ã¼æ¡ä»¶ã使ç¨ãã
- AWS ã¢ã«ã¦ã³ãã®ã¢ã¯ãã£ããã£ã®ç£è¦
- IAM ãã¹ããã©ã¯ãã£ã¹ã«ã¤ãã¦ãããªã§èª¬æãã
ãæå°æ¨©éãä»ä¸ãããé£ãã
ãããããå®éã«ãã®ãã¹ããã©ã¯ãã£ã¹ãå®è·µãã¦ããã¨ãä¸ã¤ã ãé£æ度ãæ ¼æ®µã«é«ããã®ããããã¨ã«æ°ãã¤ãã§ããããããã¯ããæå°æ¨©éãä»ä¸ãããã§ããæå°æ¨©éã«ã¯äºéã®æå³ã®é£ãããããã¾ãã
- æå°æ¨©éãé©ç¨ããã«ã¯ãIAMã®ç¥èã¨æ¢ç´¢ã®æéãå¿ è¦
- æå°æ¨©éãæ¢æ±ããããã«ã¯ãIAMã®æ¨©éãå¿ è¦
ã1ã¤ç®ã¯è¨ãããããªãã¨æãã¾ããæå°æ¨©éãä»ä¸ããã«ã¯ãIAMãæ£ããç解ãã¦ããå¿
è¦ãããã¾ãããã®ä¸ã§ãå®éã«ä»ä¸ããéã¯ãããªã·ã¼ãä½ã£ã¦å®éã«åããã¦ã¿ã¦ã¨è©¦è¡é¯èª¤ãå¿
è¦ã§ãããããçµæ§ãæéãæããã¾ãããã¯ããã¯çãªé¢ã¨ãã¦ã¯ã大ããã®æ¨©éãæåã«ä¸ãã¦ããã¦ãå¾ã§IAMã®æ¨©éã®å©ç¨å±¥æ´ãã¿ã¦çµãè¾¼ãã¨ãã£ãæ¹æ³ãããã¾ãããããã§ãæéãæããã§ãããã
ã2ã¤ç®ã®æ¢æ±ããã«ã¯ãIAMã®æ¨©éãå¿
è¦ã¨ããåã°ç¦
åççãªåé¡ã§ããæå°æ¨©éãä»ä¸ããããã«ã¯ããã以ä¸ã®æ¨©éãæã£ã¦ãã人ãå®è¡ããªããã°ãªããªãã®ã§ããçµç¹çãªè©±ã§ããã¨ããããä¸çªããã¸ãã§ããIAMãæä½ã§ãã人ãçµãè¾¼ã¿ããããä»ä¸ãã権éãæå°éã«æãè¾¼ã¿ãããã§ããããããã¨AWSã®ã¢ã«ã¦ã³ãããã¼ã¸ã£ã¼çãªç«å ´ã®äººããã²ãããIAMã®æ¨©éã«ã¤ãã¦èããªãã¨ãããªããªãã¾ãã
ãæã§ããã°ããã®ã¢ãã«ã§ãä½ã¨ããªã£ãããããã¾ãããããããä»ã ã¨ãã®æ¹å¼ã§ããã¨ç ´ç¶»ããå¯è½æ§ãé«ãã§ãããªããªããä»ã®AWSã®è¨è¨ã»éçºã¯ãIAMãã¼ã«ã¨åããããå¿
è¦ãããããã§ãã
IAMãã¼ã«ã¨åãåã
ããIAMãã¼ã«ã¨åãåããã¨ã¯ãªãã§ããããï¼å¾æ¥ã®AWSã®æ§ç¯ã¯ãVPCã§ãããã¯ã¼ã¯ãä½ã£ã¦ãã®ä¸ã«EC2ããã¦ã¦ããã«ã»ã¢ããªã®è¨è¨ããã¦ã¨ããå½¢ãå¤ãã£ããã¨æãã¾ãããã®ããã職能機能のAWS管理ポリシーã«ä»£è¡¨ããããããªãããã¯ã¼ã¯ç®¡çè
ããã¼ã¿ãã¼ã¹ç®¡çè
ã¨ãã£ãå½¹å²å¥ã®æ¨©éãä»ä¸ãã¦è·åãéè¡ãã¦ããããã¨ã«ãªãã¾ãã
ãä»ã¯ãããã«å ãã¦AWSã®ããã¼ã¸ããµã¼ãã¹ãæ´»ç¨ãããã¨ãå¤ããªã£ã¦ãã¾ãããããã£ãéã«ãä½ãå¿
è¦ã§ããããï¼IAMãã¼ã«ãã²ãããä½ããã¨ãå¿
è¦ã«ãªã£ã¦ãã¾ããIAMãã¼ã«ãä½ãã«ã¯ãIAMã®æ¨©éãå¿
è¦ã«ãªãã¾ããIAMã®æ¨©éã¨ã¯ãå®è³ªçã«ç®¡çè
ã®æ¨©éã§ããAdministratorAccessã¨PowerUserAccessã®éããã¿ãã¨è§£ãã®ã§ãããIAMã®æ¨©éãããããªããã®éããããªãã®ã§ãã
ãã¨ããäºã§IAMã¯å®è³ªçã«ç®¡çè
権éã§ãIAMãã¼ã«ãä½ãã«ã¯ãã®æ¨©éãå¿
è¦ã«ãªãã¾ããæå°æ¨©éãä½ãããã«ãæ大ã®æ¨©éã渡ãã¨ãããã®çç¾ã«æ°ãä»ããç¬éã«ãä½ãå¼ãè£ããããããªæããããäºã«ãªãã¾ãã
ã
SCPã¨Permission Boundary
ãAWSããã®çç¾ã«æ°ãä»ãã¦ãã¦ã対çã¨ãªããµã¼ãã¹ãæä¾ãã¦ãã¾ããAWS Organizationsã®ãµã¼ãã¹ã³ã³ããã¼ã«ããªã·ã¼(SCPï¼ã¨ãIAMã®Permission Boundaryã§ããã©ã¡ããä¼¼ããããªæ©è½ãæã¡ãä¾ãIAMã®æ¨©éãæã£ã¦ããã¨ãã¦ããäºã許å¯ããç¯å²ãã権éãæå¹ã«ãªããªããªãã¾ãã次ã®å³ã®ããã«ç©éåã§ããã
ããã®IAMã®Permission Boundaryã使ã£ã¦IAMãã¼ã«ã¯ä½ãããã©ãä½ããç¯å²ãéå®ããã¨ãã£ãäºãã§ãã¾ãã詳ããæé ã¯ãã®ãã¡è§£èª¬ãããã¨æãã¾ãããæ¢ã«ãã°ããã解説è¨äºãããã®ã§ç´¹ä»ãã¦ããã¾ãã
ããã ããã®Permission Boundaryã使ãããªãã®ãä¸ã é£ããã¨ããã®ãããã¾ããIAMãã¡ããã¨ç解ãã¦ãã©ã®ç¯å²ã許å¯ããã®ãããã®è¾ºãã®çµ¶å¦ãªè¨è¨ãå¿ è¦ã«ãªãã¾ãã人é¡ã®IAMã¬ãã«ãä¸ããªãã¨ãã¾ã ã¾ã ä¸äººåãã§ãªãã®ããªãã¨ããå°è±¡ã§ããç§ããããã§ãããã¨ããçãã«ã¯éãã¦ãªãã§ãã
ãµã³ãããã¯ã¹ã¢ã«ã¦ã³ã
ãããä¸ã¤ã®å¯¾çã¨ãã¦ã¯ããµã³ãããã¯ã¹ã¢ã«ã¦ã³ãã¨ããèãæ¹ãããã¾ããé常ã®ç°å¢ã¨éé¢ããAWSã¢ã«ã¦ã³ããä½ãããã®ä¸ã§IAMã®ç®¡çè
権éãä¸ãèªç±ã«ãã£ã¦ãããæ¹æ³ã§ãã
ãéé¢ããã¢ã«ã¦ã³ãã¨ããã©ããã¢ã¯ã»ã¹ãã¼ã»ã·ã¼ã¯ã¬ããã¢ã¯ã»ã¹ãã¼ãªã©ã»ãã¥ãªãã£ã»ã¯ã¬ãã³ã·ã£ã«ã®æµå¤±ã§ãAWSã¢ã«ã¦ã³ããä¹ã£åãããã大äºæ
ãçºçãã¾ãã対çã¨ãã¦ã¯åè¿°ã®SCPãªã©ãå©ç¨ãã¦ãããã ãã¯é²ãã¨ããåä½ãç¦æ¢ããæ¹æ³ãããã¾ãã
ãã©ã¡ããä¸é·ä¸çã§ããããµã³ãããã¯ã¹ã¢ã«ã¦ã³ãã®æ¹ããèªç±åº¦ãé«ã管çè
ã®è² è·ã¯å°ãªãå¾åã«ããã¾ãã
ãããããæå°æ¨©éãã¨ã¯ï¼
ãããã¾ã§æ¸ãã¦ãã¦ãå®ã¯ãããããæå°æ¨©éãã®å®ç¾©ã«ã¤ãã¦ãä½ã触ãã¦ããªããã¨ã«æ°ãã¤ãããããã¾ãããæ¥æ¬äººçãªå 帳é¢ãã§ãæå°æ¨©éã¨èãã¨åé¢ãã®ã¾ã¾ã«ãæ¬å½ã®æå°æ¨©éãæãæµ®ãã¹ã¦ããã¨æãã¾ããä¾ãã°ãS3ã¸ã®æ¸ãè¾¼ã¿æ¨©éã§ããã°å¯¾è±¡ãã±ããã«å¯¾ãã¦ã®æ¸ãè¾¼ã¿æ¨©éã®ã¿ã¨ãããªãã¬ã¼ã¿ã¼ã§ããã°åç
§æ¨©éã¨EC2çã®èµ·åã»åæ¢ã®æ¨©éã®ã¿ã¨ãã
ãæè¿ããã¹ããã©ã¯ãã£ã¹ã®è¨ããæå°æ¨©éãã£ã¦ãããã¾ã§å³å¯ãªæå³ã§ã®æå°æ¨©éã¨è¨ã£ã¦ããã®ã§ã¯ãªãã®ã§ã¯ãªãããªã¨æããããã«ãªã£ã¦ãã¾ãããä¾ãã°ãéçºè
ã®ããããã«Admin権é渡ããã«ã職能機能のAWS管理ポリシーãä»ä¸ãããã ããçãªå¤§éæããæãã¦ããã®ã§ã¯ãªããã¨ããæ°ããã¦ãã¾ãããããã¯ãåã
ã®ã¢ã¯ã·ã§ã³åä½ã®é¸å®ã§ã¯ãªããListãRead,Write,Permission Managementãªã©ã®アクセスレベルãæãã¦ããã¨ãã
ããã¾ãç¥çµè³ªã«æå°æ¨©éã追æ±ãã¦å®ç¾ã§ããªããããããç¨åº¦ã®å¤§éæãã許容ãã¦ããæ¹ããç¾å®çã«ã¯éç¨ã¯åããäºæ
ãå°ãªãã¨æãã¾ãããã®ä¸ã§ãæ¬å½ã«æ°ãä»ããªãã¨ãããªãS3å¨ãã®ãã¼ããã·ã§ã³çãå³æ ¼ã«å®ç¾©ããã®ãè¯ãã®ã§ã¯ãªãã§ããããã
ã¾ã¨ãï¼
ã話ãå
¨ç¶ç· ã¾ããã«æ¨ªã«å¤ãã¦ããã¾ããããIAMã®æå°æ¨©éã®æ¢ç©¶ã®æ©ã¾ãããä¼ããã¾ããã§ããããï¼ä¸äººã§æå°æ¨©éã追æ±ãã¦ãæã¯ãå¥ã«ãããã§ãããã»ãã¥ãªãã£ãã©ãã¾ã§è¿½æ±ãããããããã«æããå·¥æ°ãèªåã§ã³ã³ããã¼ã«ã§ãããããã§ããçµç¹ã§éç¨ããã¨ãªã£ãããé端ã«æ©ã¾ãããªãã¾ããã©ãã¾ã§æ¨©éãå§è²ããã®ãã®è¨è¨ããæ³å®ãã¦ããå§è²ç¯å²ããé¸è±ãã¦ããªããã®ç¢ºèªãå¿
è¦ã«ãªãã¾ããèãåºãã¨æ¢ã¾ããªããªãã®ãããIAMã®æå°æ¨©éãã§ãããã²ä¸ç·ã«ããã®æ¢æ±ã®æ²¼æ
ã«åºããã¾ãããï¼ï¼