ãæ¥æ¬ã®AWSã®APN Ambassadorãéã¾ã£ã¦ä½ãä¸ããJapan APN Ambassador Advent Calendar 2020ã®åæ¥ã§ããä½ã æ¨ã®æ¹ããã¯ãæè¿ã®é¢å¿äºé ã§ãããã«ãã¢ã«ã¦ã³ã管çã®ä¸ãããèªè¨¼ï¼ãã°ã¤ã³ï¼ã®ä¸å åã®è¨è¨ã«ã¤ãã¦èãã¦ã¿ã¾ãããã
ãã«ãã¢ã«ã¦ã³ã管çã«ãããèªè¨¼ï¼ãã°ã¤ã³ï¼ã®ä¸å åã®å¿ è¦æ§
ãAWSãæ¬æ ¼çã«ä½¿ãå§ããã¨ããã«ç´é¢ããã®ããå©ç¨ããAWSã¢ã«ã¦ã³ãã®å¢å¤§ã§ããAWSã®ãå§ãã®ãã©ã¯ãã£ã¹ã®ä¸ã¤ã¨ãã¦ãç¨éãã¨ã«AWSã¢ã«ã¦ã³ãã使ãåãã¦ãªã¹ã¯ãä¸ããã¨ããã®ãããã¾ããæ¬çªç°å¢ã¨éçºç°å¢ãåå± ãã¦ãããããåé¢ããä¸ã§ä½¿ããã¦ã¼ã¶ã¼ãå½¹å²ãã¨ã«éå®ããæ¹ããªã¹ã¯ãä¸ãããã¨ãã§ãã¾ããããä¸æ¹ã§ãããã¸ã§ã¯ããã¨ã»ç°å¢ãã¨ã«AWSã¢ã«ã¦ã³ããåé¢ãã¦ããã¨ããã«10ã20ã®ã¢ã«ã¦ã³ãã«ãªã£ã¦ãã¾ãã¾ãããã®æã«ç¬¬ä¸ã®èª²é¡ã¨ãªãã®ããIAMã¦ã¼ã¶ã¼ã®åé¡ã§ãã
ãAWSã¢ã«ã¦ã³ããã¨ã«IAMã¦ã¼ã¶ã¼ãä½ã£ã¦ããã¨ãã¦ã¼ã¶ã¼ãã¨ã«IAMã¦ã¼ã¶ã¼ã®IDã¨ãã¹ã¯ã¼ãã10åã20åãã§ãã¦ãã¾ããããã«AWSã«æºãã人ãæ°å人ããããæ°ç¾ã®ãªã¼ãã¼ã®ID管çãå¿ è¦ã¨ãªãã¾ãããããåã ã®ã¦ã¼ã¶ã¼ä»»ãã§é©åã«ç®¡çãããã¨ãã§ããã§ããããï¼ãªããªãé£ããã®ãç¾ç¶ã§ãæ¾ã£ã¦ããã¨å ¨é¨åãIDã»ãã¹ã¯ã¼ãã§éç¨ãããã¨ãã£ããã¨ãçºçãããã§ããããããã§ãå¿ è¦ã«ãªã£ã¦ããã®ãèªè¨¼ï¼ãã°ã¤ã³ï¼ã®ä¸å 管çã§ãã
èªè¨¼ã®ä¸å åã®ãã¶ã¤ã³ãã¿ã¼ã³
èªè¨¼ã®ä¸å 管çã«ããAWSã®æ©è½ã®ã¿ã§ç®¡çãããã¿ã¼ã³ããµã¼ããã¼ãã£ã®ãã¼ã«ãé§ä½¿ãããã¿ã¼ã³ãªã©å¹¾ã¤ãããã¾ãã代表çãªãã¿ã¼ã³ãå¹¾ã¤ãã¿ã¦ããã¾ãããã
è¸ã¿å°AWSã¢ã«ã¦ã³ããã¿ã¼ã³
ãä¸çªãæ軽ãªã®ãè¸ã¿å°AWSã¢ã«ã¦ã³ããã¿ã¼ã³ã§ããè¸ã¿å°ã¨ãªãAWSã¢ã«ã¦ã³ãã®ã¿ã«IAMã¦ã¼ã¶ã¼ãçºè¡ããå¾ã¯ã¯ãã¹ã¢ã«ã¦ã³ãã®ã¹ã¤ãããã¼ã«ã§ã¹ã¤ãããã¦ãããã¿ã¼ã³ã§ãã
ããã®ãã¿ã¼ã³ã¯ãè¸ã¿å°ã¨ãªãä¸ã¤ã®AWSã¢ã«ã¦ã³ãã®ã¿ã«IAMã¦ã¼ã¶ã¼ãçºè¡ããä»ã®AWSã¢ã«ã¦ã³ãã«ã¯IAMãã¼ã«ã®ã¿çºè¡ãã¾ããè¸ã¿å°ã«ãã°ã¤ã³å¾ã«ã¹ã¤ãããã¼ã«ãå©ç¨ãã¦ããããã®AWSã¢ã«ã¦ã³ããå©ç¨ãã¾ããã¹ã¤ãããããå´ã®IAMãã¼ã«ã§ãã¹ã¤ããã§ããIAMã¦ã¼ã¶ã¼ãå¶éã§ããã®ã§åã¢ã«ã¦ã³ãå´ã§æ¨©éã®å¶å¾¡ãã§ããã®ããã¤ã³ãã§ããã¾ãããã®ãã¿ã¼ã³ã ã¨AWS Organizationsã§ç®¡çå¤ã®ãã®ã§ãç°¡åã«å©ç¨ã§ããã¨ããã¡ãªãããããã¾ãããã ããã¹ã¤ããå
ã®åã¢ã«ã¦ã³ãã§CLIãå©ç¨ãããå ´åã¯ãä¸å·¥å¤«ãå¿
è¦ã¨ãªãã¾ãã
ããªãããã®ãã¿ã¼ã³åã¯ãç§ãåæã«åä»ãã¦ããã ãã§ãã
ãµã¼ããã¼ãã£ã®IdPï¼Identity Providerï¼ãå©ç¨ãããã¿ã¼ã³
ã次ã«ç´¹ä»ãããã¿ã¼ã³ã¯ãããæå³çéã§ãããµã¼ããã¼ãã£ã®IdPï¼Identity Providerï¼ãå©ç¨ãããã¿ã¼ã³ã§ããIdPã¯èªè¨¼é¨åãå°ç¨ã®ã·ã¹ãã ã«å§è¨ããèªè¨¼ããçµæãåãåã£ã¦AWSã¢ã«ã¦ã³ãã®å©ç¨ã許å¯ãããã¿ã¼ã³ã§ããIdPãå©ç¨ããã¨AWSå´ã§ID/ãã¹ã¯ã¼ãã®ç®¡çãä¸è¦ã«ãªãã¾ãã代表çãªIdPã¨ãã¦ã¯ãMicrosoft Active Directoryï¼ADï¼ãGoogle Workspaceï¼æ§G Suiteï¼,Okta,OneLoginãªã©ãããã¾ãã
ãIdPãå©ç¨ãããã¿ã¼ã³ããAWSé¨åã¯IAMãã¼ã«ã使ãã¾ãããã®ãããè¸ã¿å°AWSã¢ã«ã¦ã³ããã¿ã¼ã³ã¨æ§æçã«ã¯å¤§ããéããªãããã«è¦ãã¾ãããããããã¤ã³ãã¯AWSã¢ã«ã¦ã³ãå ã«ä¸åIDã¨ãã¹ã¯ã¼ããæã¤å¿ è¦ããªãç¹ã«ããã¾ããAWSã使ããããªçµç¹ã¯ãAWS以å¤ã«ãæ§ã ãªã·ã¹ãã ãå©ç¨ããID/ãã¹ã¯ã¼ãã管çããå¿ è¦ãããã¾ããããã«AWSã®ID管çãçµ±åã§ããã®ã¯å¤§ããªã¡ãªããã§ããä¸æ¹ã§ãè¸ã¿å°AWSã¢ã«ã¦ã³ããã¿ã¼ã³åæ§ã«CLIãå©ç¨ãããå ´åã¯ä¸å·¥å¤«ãå¿ è¦ã§ãã
AWS SSOãå©ç¨ãããã¿ã¼ã³
ã3ã¤ç®ã®ãã¿ã¼ã³ã¨ãã¦ã¯ãAWS SSOï¼AWS Single Sign-Onï¼ã§ããAWS SSOã¯ããã®åã®éããã«ãã¢ã«ã¦ã³ãã§ã®AWSéç¨ãæ³å®ãããµã¼ãã¹ã§ããAWS SSOç¨ã®ãã°ã¤ã³ç»é¢ãããããã°ã¤ã³å¾ã«èªèº«ãå©ç¨ã§ããAWSã¢ã«ã¦ã³ããé¸æã§ããããã«ãªã£ã¦ãã¾ãã
ãæ§æçã«ã¯ãIdPãã¿ã¼ã³ã¨å¤§ããå¤ããã¾ããããã¡ãªããã¯å¹¾ã¤ãããã¾ãããã®ãã¡ã®ï¼ã¤ããSSOããå©ç¨ãã¦ããã¦ã¼ã¶ã¼ãCLIï¼v2ï¼ã使ãããã¨ã§ããããä¸ã¤ã¯ãã¢ã¯ã»ã¹æ¨©éã»ããã¨ããæ©è½ã使ã£ã¦ãè¤æ°ã¢ã«ã¦ã³ãã®ã¢ã¯ã»ã¹æ¨©éãä¸å 管çã§ãããã¨ã§ãããã ããSSOã®å©ç¨ã¯AWS Organizationsãåæã¨ãªãã¾ããããã«ãã¦ãããããããããã£ã¦ãªãã¾ãããããã ããå§ãã®ä½¿ãæ¹ã¨ãã¦ã¯å¥ãã¿ã¼ã³ãããã®ã§ãSSOã®ã¢ã¯ã»ã¹æ¨©éã»ããã説æã®å¾ã§ç´¹ä»ãããã¨æãã¾ãã
AWS SSOã®ã¢ã¯ã»ã¹æ¨©éã»ãã
ãå
ç¨ç´¹ä»ããã©ã®ãã¿ã¼ã³ã§ããIAMãã¼ã«ãèã«ãªã£ã¦ããã®ã解ãã§ããããï¼èªè¨¼ã®ä¸å
åã¯ã§ãã¦ããã©ã®æ©è½ã使ãããã¨ããèªå¯ã®é¨åã«ã¤ãã¦ã¯åã¢ã«ã¦ã³ãã«è¨å®ãããIAMãã¼ã«ã«ä¾åãããã¨ã«ãªãã¾ãããã®ãããåã
ã®ã¢ã«ã¦ã³ãã«IAMãã¼ã«ãè¨å®ãã¦ããã¨ããä½æ¥ãå¿
è¦ã«ãªãã¾ããAWS Organizationsã¨CloudFormation StackSetsã使ãã°ãã®è¾ºãã®ä½æ¥ãã ãã¶æ¥½ã«ã¯ãªãã¾ãããä¸å
管çã¨ã¯å°ãé ãä¸çã§ãã
ãããã§ç»å ´ããã®ãAWS SSOã®ã¢ã¯ã»ã¹æ¨©éã»ããã§ããã¢ã¯ã»ã¹æ¨©éã»ããã¯ã¦ã¼ã¶ã¼ãã¨ã®ã¢ã¯ã»ã¹æ¨©éãä¸å
管çããä»çµã¿ã§ããSSOãè¨å®ããOrganizationsã®ç®¡çã¢ã«ã¦ã³ãï¼æ§ãã¹ã¿ã¼ã¢ã«ã¦ã³ãï¼ã§å®ç¾©ãã¾ããã¢ã¯ã»ã¹æ¨©éã»ããã¨å¼ã°ããããªã·ã¼ãä½æããã¦ã¼ã¶ã¼ãã©ã®æ¨©éãå©ç¨ã§ããããç´ä»ãã¾ãã管çè
ã®æä½ã¨ãã¦ã¯ããã ããªã®ã§ãããã¢ã¯ã»ã¹æ¨©éã»ããã®è¯ãã¨ããã¯ãè£ã§å¯¾è±¡ã®AWSã¢ã«ã¦ã³ãã®æ¹ã«ãã¢ã¯ã»ã¹æ¨©éã»ããã¨å¯¾å¿ããIAMãã¼ã«ãä½ã£ã¦ããã¨ãããã¨ã§ããã¾ãããä¸å
管çï¼ï¼
ãå§ãã®ãã¶ã¤ã³ãã¿ã¼ã³ IdP + AWS SSO
ãã¢ã¯ã»ã¹æ¨©éã»ããã¨CLI対å¿ã®2ç¹ã§AWS SSOããå§ãã§ããä¸æ¹ã§ããããããªç¾å ´ã§SSOãç´¹ä»ãã¦ãããã£ã±ãæ¢åã®IdPã使ãããã¨ããã±ã¼ã¹ãå¤ãã§ãããã£ã±ãIDã®äºé管çã¯å«ã§ããããããããªæã«ãå§ããIdP + AWS SSOã¨ãããã¿ã¼ã³ã§ã
ãæ§æã¨ãã¦ã¯ãã¦ã¼ã¶ã¼ã¯IdPã§ã¾ãèªè¨¼ãã¾ããèªè¨¼å¾ã«AWS SSOã®ãã¼ã¿ã«ç»é¢ã«ç§»åãã¾ããããã¦ãä»»æã®AWSã¢ã«ã¦ã³ãã«ç§»åããã¨ãããã¿ã¼ã³ã§ããç»é¢é·ç§»ãä¸ã¤å¢ããã¨ããæéãå¢ãã¾ããããã®ãã¿ã¼ã³ã«ã¯å¤§ããªã¡ãªãããããã¾ã
- ID管çãAWS以å¤ãå«ãã¦ä¸å åã§ãã
- èªè¨¼ï¼IdPï¼ã¨èªå¯ï¼ã¢ã¯ã»ã¹æ¨©éï¼ãæ示çã«åé¢ã§ãã
- AWS SSOã®æ©è½ã100%å©ç¨ã§ãã
- ä»å¾AWS SSOã®æ©è½ãå¢ãã¦ãã°ããã¨ãªããªã
ã¾ã¨ã
ãAWSã®ãã«ãã¢ã«ã¦ã³ã管çã«ã¤ãã¦ã¯ãè¸ã¿å°AWSã¢ã«ã¦ã³ããããããå§ãã人ãå¤ãã®ã§ã¯ã¨æãã¾ããã³ã¹ããæãããªãã®ã§ãããã§å
åãªå ´åãå¤ãã§ããä¸æ¹ã§å¤§è¦æ¨¡ã«ãªãã¨è¾ããªãã¨ãããã¨ãããã¾ãããããªéã®åèã«ãªããã°ãªã¨æãã¾ãã
ããã¤ã¯ãã®è¾ºã®è©±ãAWSã®èãæ¬â
¢ã¨ãã¦ã¾ã¨ãããã¨æãã¤ã¤ãã¯ãåå¹´ãéãã¾ãããï¼è¡ãããã¦ãã¾ãããå¹´å
ã«å·çå¨åº«ãä¸å±¤ãã¦ãå¹´åãããããåãããããã°ã¨æã£ã¦ããã¾ãã®ã§ãçæããç®ã§è¦å®ã£ã¦ãã ãããã¾ããAWS SSOã使ãä¸ã§ã¯ãOrganizationsãå¿
é ã¨ãªãã¾ããè«æ±ä»£è¡ä½¿ã£ã¦ã¦Organizations使ããªããã¨ããæ¹ã¯ãOrganizations対å¿ã®æ¯æã代è¡ã¨ããã¦ããã¨ãããæ¤è¨ããã¨ããããããªãããªã¨æãã¾ããï¼ã¹ããï¼
ãä»åã¯è«çè¨è¨ã®è©±ãä¸å¿ã ã£ãã®ã§ãããå°ãå
·ä½çãªè©±ãä»å¾ç´¹ä»ãã¦ããã¾ããä¹ããæå¾
ï¼ï¼