AWS
CloudWatch Logsã«ãã°ãæºãè¾¼ãã®ã¯ã³ã¹ãçã«é¿ãããã§ããããCloudWatch Logsã«ã¯S3ã«ãã°ãã¨ã¯ã¹ãã¼ãããæ©è½ããã®ã§ããããªããæåå®è¡ã«ãã対å¿ãã¦ãã¾ãããèªåçã«ã¨ã¯ã¹ãã¼ãããã«ã¯Lambdaãå®æå®è¡ããããEventBridge Schedulerã§â¦
Terraformã®AWSãããã¤ãã¼ã«ã¯allowed_account_idsã¨ããè¨å®é ç®ãããã®ããåç¥ã§ããããï¼ã³ã¼ããå®è¡ãã対象ã®AWSã¢ã«ã¦ã³ããçµããè¨å®ã§ãã registry.terraform.io ã³ã¼ãã«ç´æ¥IAMã¦ã¼ã¶ã¼ã®ã¯ã¬ãã³ã·ã£ã«ãæ¸ãã¦ããã°ãç°å¢ã®åãéãã¯â¦
ååã®è¨äºã§SQSã®ãã¼ã«ã«éçºç°å¢ç¨ã¨ãã¦ElasticMQã使ã£ã¦ã¿ã¾ããã ä»åã¯ElasticMQã§ãããã¬ã¿ã¼ãã¥ã¼ã«ã¤ãã¦å¦ãã§ã¿ã¾ãããã ãããã¬ã¿ã¼ãã¥ã¼ã¨ã¯ ãããã¬ã¿ã¼ãã¥ã¼ã¯ãã¡ãã»ã¼ã¸ã®å¦çã«å¤±æããå ´åã«ããã®ã¡ãã»ã¼ã¸ãå¥ã®ãã¥ã¼ã«â¦
ååã®è¨äºã§Dev Containersã使ã£ã¦Goã®éçºç°å¢ãæ§ç¯ãã¾ããã ä»åã¯ãã®ç¶ãã§ãSQSã®ãã¼ã«ã«ç°å¢ç¨ã«ElasticMQãåããã¦ã¿ã¾ãã ElasticMQã¨ã¯ SQSäºæã®REST(ã¯ã¨ãª)ã¤ã³ã¿ã¼ãã§ã¼ã¹ãæä¾ããã¡ãã»ã¼ã¸ãã¥ã¼ã·ã¹ãã ã§ããElasticMQã¯ãREST(â¦
ã»ãã¥ãªãã£ä¸ã®çç±ãããAWSããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã¸ã®ãã°ã¤ã³ã¤ãã³ãããã¡ã¼ã«ãSlackã«éç¥ãããã¨ã¯ããããã¾ããããç¾å¨ã§ã¯AWS User Notificationsã使ãã°ãç°¡åã«å®ç¾ã§ãã¾ãã ããã¨ã¯å¥ã«ãã¢ã¯ã»ã¹ãã¼ã®ä½¿ç¨ãæ¤åºããããã¨ã£ã¦ãªãâ¦
AWS CLIã¯~/.aws/credentialsã«å¹³æã§ã¯ã¬ãã³ã·ã£ã«ãä¿åãã¾ããç°¡åã«ã¯ã¬ãã³ã·ã£ã«ã確èªã§ãã¦ãã¾ãã®ã§ã³ã³ãã¥ã¼ã¿ã¼ã«ããã¯ããããªãã¾ã¾é¢å¸ãã¦ãã¾ã£ãæ¥ã«ã¯æ¼ãã¦ãã¦ãããããããã¾ãããããã§ã¯ã¬ãã³ã·ã£ã«ãæå·åãã·ã¹ãã ã®ãã¼â¦
AWSã®Lambda使ã£ã¦ã¾ãã? 便å©ã§ãããã ã¡ãã£ã¨ããæ©è½ããµã¼ãã¼ã¬ã¹ã§å®è£ ã§ããLambdaã§ãããAWSã®å¤é¨ããWebhookçã«é¢æ°ãã³ã¼ã«ãããã¨ããã¨ãå¾æ¥ã¯API Gatewayãç¨æãã¦ãããå¿ è¦ãããã¾ãããã¨ãããæè¿ã§ã¯ãLambdaã«é¢æ°URLã¨ããâ¦
ååã¯AWSã®æéãåå¾ããã³ãã³ããç´¹ä»ãã¾ãããä»åã¯ã¢ã¯ãã£ããªãªã½ã¼ã¹ä¸è¦§ãåå¾ããæ¹æ³ãç´¹ä»ãã¾ãã AWS Resource Explorer docs.aws.amazon.com AWS Resource Explorerã¯AWSãªã¼ã¸ã§ã³ã横æãã¦AWSãªã½ã¼ã¹ãæ¤ç´¢ãããã¨ãã§ãã¾ããæ¤ç´¢ã§â¦
AWSã®ã³ã¹ãæ°ã«ãªãã¾ããããå人ã§éç¨ãã¦ããç°å¢ã ã¨å°æ´ããã ãæ¯æ¥AWSã®ã³ã³ã½ã¼ã«ã«ãã°ã¤ã³ãã¦ã³ã¹ãã¨ã¯ã¹ããã¼ã©ã¼ãçºããã®ãããã¯ããã§çµæ§ãªè² æ ã«ãªãã®ã§ãAWS CLIã§ã³ã¹ããåå¾ãã¦ã確èªãããããã¦ã¿ã¾ãã aws ce ã³ãã³ãããâ¦
IAMã¦ã¼ã¶ã¼ã®MFAãè¤æ°ç»é²ã§ããããã«ãªã£ã¦ããã¿ããã§ãããå ¨ç¶æ°ã¥ãã¦ãã¾ããã§ããã aws.amazon.com æ大ã§8åã¾ã§ç»é²ã§ããããã§ããæ®æ®µä½¿ãã«YubiKeyã¨ããã¯ã¢ããã®TOTPã2ã¤ãããç»é²ãã¦ããã°æ¦ãå°ããªããã§ãã ãã£ããè¨å®ãã¦â¦
æ°ãã人ãå ¥ã£ã¦ããæãã誰ããåºã¦ããæãªã©ãEKSã®aws-auth ConfigMapã«IAMã¦ã¼ã¶ã¼ã足ãããå¼ããããããã¨ã¯ããããã¨æãã¾ãããã®ConfigMapãæ§æãééã£ã¦ãã¦ãä¿åã§ãã¦ãã¾ããã§ããããã¨ã©ã¼ã®ã¾ã¾ä¿åãã¦ãã¾ãã¨ãããã§ç®¡çããâ¦
å æ¥ãã¨ããããã¸ã§ã¯ãã§kube2iamã®ãã°ãè¦ã¦ããã¨ã以ä¸ã®ãããªãã°ãçºè¦ãã¾ããã kube2iam-XXXXX kube2iam time="2022-09-26T10:34:03Z" level=info msg="PUT /latest/api/token (403) took 2.837123 ms" req.method=PUT req.path=/latest/api/toâ¦
EKS 1.21ã¨ããããKubernetes 1.21以éã§æå¹ã«ãªã£ãBoundServiceAccountTokenVolumeã«ã¤ãã¦ã®è©±ã§ããã docs.aws.amazon.com ç°¡åã«ããã¨ãKubernetes 1.21以åã§ã¯ãã¼ã¯ã³ã«æå¹æéããªãã£ãã®ã«å¯¾ãã1.21以éã¯1æéã®å¶éãã¤ãã¾ããã£ã¨ããâ¦
eksctlã使ãã¨EKSã«ãµã¼ãã¹ã¢ã«ã¦ã³ããç¨æãã¦ããã¾ããããã®ä½ãå¬ãããã¨ããã¨ãKubernetesã®ServiceAccountã¨IAMãã¼ã«ãç´ã¥ãã¦ãããã®ã§ãkube2iamãkiamã使ããªãã¦ãKubernetesããAWSã®ãªã½ã¼ã¹ã®æä½ãã§ããããã«ãªãã¾ãããã£ããâ â¦
AWSç°å¢ãæä½ããå ´åãçååãèªååã®ããã«awsã³ãã³ããã¿ã¼ããã«ããå©ãã®ã¯æ¥å¸¸çã§ããããæä½ããç°å¢ãã²ã¨ã¤ã ãã§ããã°ããã®ã§ããããã¹ãç°å¢ã¨æ¬çªç°å¢ã§ã¢ã«ã¦ã³ããåããã¦ããããã¾ãè¤æ°ã®ããã¸ã§ã¯ãã«åç»ãã¦ããå ´åã«åé¡â¦