éç¨
ã¿ãã§ã. æ°å¹´ã¶ãã«è¿«ã£ã¦ãã RDS 㨠Aurora ã® SSL/TLS æ¥ç¶ã§ä½¿ç¨ãã証ææ¸ã®å ¥ãæ¿ããæ±äº¬ãªã¼ã¸ã§ã³ã¯ 2024/08/22 æéã¨ãªã£ã¦ãã¾ã.ä»åã®è¨¼ææ¸ã®å ¥ãæ¿ãã«ããã£ã¦å©ç¨ãã¦ãã Aurora ã§è¨¼ææ¸å ¥ãæ¿ãæã«åèµ·åãçºçããã®ã,ã©ã®è¨¼ææ¸â¦
ã¿ãã§ã. Bytebase ã®ãã¼ã¿ãã¼ã¹å¤æ´ã®æ¿èªãè¡ãéã«,ããã©ã«ãã§ç¨æããã¦ãããã¼ã«ä»¥å¤ã«æ¿èªæ¨©ãä¸ãããå ´åããã,ã«ã¹ã¿ã ãã¼ã«ã®ä½æã¨æ¿èªããã»ã¹ãè¨å®ããã®ã§åå¿é²ã¨ãã¦è¨äºã«æ¸ãã¾ã. Bytebase ã«ãããã«ã¹ã¿ã ãã¼ã« ã«ã¹ã¿ã ãã¼â¦
ã¿ãã§ã. 以åã®è¨äºã§ãã©ã¤ãã¼ããªãã¸ããªã«ããèªä½ã® Actions ã使ãè¨äºãæ¸ãã¾ãã.ãã®è¨äºã§ã¯åæ§ã«ãã©ã¤ãã¼ããªãã¸ããªã«ãã reusable workflows ã使ãã¨ããã®ããã£ã¦ã¿ãã®ã§è¨äºã«ãã¾ã. sadayoshi-tada.hatenablog.com reusable woâ¦
ã¿ãã§ã. ååã®è¨äºã§ RDS ãã°ã S3 ã«ã¢ãããã¼ãããå¦çã ECS ã§å®æå®è¡ããããã«éç¨ãå§ãã¾ãã.éç¨ãå§ãã¦ééããæ°ã¥ãããã,ãã®ãã¨ã«ã¤ãã¦æ¬è¨äºã§æ¸ãã¦ããã¾ã. sadayoshi-tada.hatenablog.com éç¨ãå§ãã¦çºçããäºè±¡ åå 調æ»â¦
ã¿ãã§ã. AWS WAF ã®ããã¼ã¸ãã«ã¼ã«ãéç¨ãã¦ããã¨,ããã¾ã§ã¯ãããã¯ãããªãã£ãã¢ã¯ã»ã¹ããããã¯ãããçµé¨ãããã¾ã.ãã®ä¸ã«ã¯ã¢ã¯ã»ã¹ãéããããªã¯ã¨ã¹ãããã£ããããã®ã§ãã,ã«ã¼ã«ãç·©ããã«ã¢ã¯ã»ã¹ãéãããã¨æã,ã¹ã³ã¼ããã¦ã³â¦
ã¿ãã§ã. RDS éç¨ãã¦ããã¨ããããåºã¦ãã¦æ°ã¥ããªãã£ãã¿ãããªãã¨ãããã¾ã.ãã®ããã«å¿ è¦ãªãã¨ã調æ»ãããã®ã§ãã®è¨äºã«ã¾ã¨ãã¾ã. RDS ã®ãããé©ç¨éç¥ã確èªããæ¹æ³ ã¾ã¨ã RDS ã®ãããé©ç¨éç¥ã確èªããæ¹æ³ 調æ»ããå㯠EventBridgâ¦
ã¿ãã§ã. ãã©ã¤ãã¼ããªãã¸ããªã§ GitHub Actions ã®ã³ã¼ããè¤æ°ç®¡çãã¦ãããããªç¶æ³ã§,å¼ã³åºãæã©ãããã°ããã®ããªã¨æãï¼æ¤è¨¼ããæã®å°ãã¿ãã¾ã¨ãã¦ããã¾ã. æ¤è¨¼ã®æ¦è¦ æ¤è¨¼ããçµæ ã¾ã¨ã é¢é£è¨äº æ¤è¨¼ã®æ¦è¦ ã³ã¼ãã管çãããªãã¸â¦
ã¿ãã§ã. æ¥å㧠Security Hub ãã [Lambda.1] Lambda function policies should prohibit public access ã¨ããã¢ã©ã¼ããé£ãã§ãã¾ãã.対å¿ãã¦ã¢ã©ã¼ããæ¶ããã®ã§ãã,ãã®å¯¾å¿ãåå¿é²ã¨ãã¦æ¸ãã¦ããã¾ã. ã¢ã©ã¼ãã®åå åå ã®åæ ãªã½ã¼ã¹ãâ¦
ã¿ãã§ã. terraform-provider-aws ã® v4 㧠S3 ãªã½ã¼ã¹ã®å¤æ´ãã©ããã£ã¦è¡ãããªã¨æã£ã¦ããé ã« v4.9.0 㧠S3 ã®ç ´å£çå¤æ´ããªããªã£ãã¨ãã話ãã§ã¦ããã®ã§,試ããå 容ãã¾ã¨ãã¦ããã¾ã. resource/aws_s3_bucket: The acceleration_status, acl,â¦
ã¿ãã§ã. Datadog ãç£è¦ã¨ãã¦ä½¿ã£ã¦ããã®ã§ãã,ç£è¦ã¨ãã¦éãã¦ãããã¼ã¿ãä¸ãã£ã¦ããªãæã« NO DATA ã¨ãªãã¢ã©ã¼ããçºå ±ããªãã£ããã¨ç£è¦ã«ç½®ãã¦å°ãç¶æ³ã«ãªãã¾ã.ããã§,NO DATA ã«ãªã£ã¦ãããã®ããã£ããéç¥ããããã«ããæ¹æ³ã調ã¹â¦
ã¿ãã§ã. ããæè¿ã¯ Terraform ã§å¦ã¶ãã¨ãå¤ããã,ä»åããããªè¨äºã§ã.ä»åã¯ä¾ãã°,éçºã§ããã°ãªã½ã¼ã¹ãä½ããªãããã©ã¡ã¼ã¿ã¼ãå¤ãã,æ¬çªã§ããã°ãã®ãã©ã¡ã¼ã¿ã¼ãã»ããããã¨ãã£ãæ¡ä»¶ã«å¿ãããªã½ã¼ã¹ä½æãè¡ãããã®å°ãã¿ãå¦ãã ã®â¦
ã¿ãã§ã. ãã£ããã¨ãªããªãã¬ã¼ã·ã§ã³ã§ S3 ã§ç®¡çãã¦ãã Terraform ã® tfstate ããã¼ã«ã«ã§å¤æ´ããä½æ¥ãçµé¨ããã®ã§åå¿é²ã¨ãã¦è¨äºã«æ®ãã¦ããã¾ã. åæ è¡ã£ããªãã¬ã¼ã·ã§ã³ 1,tfstate ããã¼ã«ã«ã«æã£ã¦ãã 2,tfstate ãç·¨éãã 3,ãªã¢â¦
ã¿ãã§ã. Mackerel ã§ãµã¼ãã¹ã¡ããªãã¯ã使ãããã«ãªã£ã¦ãã¼ã¿ãæ稿ããä»çµã¿ã§å¦çã失æãã¦ããã®ã§ãã,ãã®ãã¨ã«æ°ä»ããã«ãã¾ãã.ããã§ãµã¼ãã¹ã¡ããªãã¯ã®éåãç£è¦ãè¨å®ããã®ã§åå¿é²ã§è¨äºã«ãã¾ã. mackerel.io ç£è¦è¨å®æ¹æ³ ç£è¦â¦
ã¿ãã§ã. 以åã®è¨äºã§ NAT Gateway ã®èªåä½æã¨åé¤ã SSM Automation ã§èªååããã®ã§ãã,2021/10/22 ã«çªå¦å¤±æããã®ã§,調ã¹ã¦å¯¾å¦ããçµæãã¾ã¨ãã¦ããã¾ã. sadayoshi-tada.hatenablog.com äºè±¡ã®è©³ç´° AWS-UpdateCloudFormationStack ã CloudWaâ¦
ã¿ãã§ã. redash ã EC2 ä¸ã®ã³ã³ããã§åããã¦ããã®ã§ãã,ãã°ãå¤åºããã¦ããªãã£ãã®ã§ä½ããã£ãããã¡ãã¡ãµã¼ãã¼ã®ä¸ã«å ¥ãå¿ è¦ãããã¾ãã.ããã§,CloudWatch Logs ã«åºãã¦è¦ããæ¹ãããã¨æã,æ¤è¨¼ããã®ã§ãã®è¨äºã§ã¾ã¨ãã¦ããã¾ã.ãªãâ¦
ã¿ãã§ã. éç¨ã«ãã㦠System Manager Automation(SSM Automation) ã使ãå§ããã®ã§ãã,ããã¾ã§ Lambda ãªã©ã§ä»çµã¿åãã¦ãããã®ã AWS ãæ©è½ã¨ãã¦æä¾ããã¦ãã¦æåããã®ã§ãã®è¨äºã§ SSM Automation ã®æ¦è¦ã¨ä»åãå ¥ãã¦ããæ©è½ãæ¸ãã¾ã. â¦
ã¿ãã§ã. æ°ãããAmazon Buildersâ Libraryãã®è¨äºã¨ãã¦ãBuilding dashboards for operational visibility(éç¨ã®å¯è¦åã®ããã®ããã·ã¥ãã¼ãã®æ§ç¯)ãã追å ããã¾ãã.ãã®ãã¼ã¸ãèªã㧠Amazon ã§ã®ç£è¦ããã·ã¥ãã¼ãæ§ç¯ã»éç¨ã®åãçµã¿ãå¦ãâ¦
ã¿ãã§ã. ãAWS Outage Alertsããæ¤è¨¼ããæã®è¨äºãæ¸ãã¾ããã,å æ¥èªåãæ å½ããæ¥åã§ãã®æ©è½ãå®è£ ãã¾ãã.å®è£ ã«è³ãã¾ã§ã«è¿½å ã§è¨å®ã調ã¹ãã,æ¤è¨¼ãã¦ããã£ããã¨ããã®è¨äºã§æ´çãã¾ã. sadayoshi-tada.hatenablog.com ãAWS Outage Alerâ¦
ã¿ãã§ã. AWS ã®é害ãçºçããæã«æç¥ããããã«Service Health Dashboardã® RSS æ å ±ãè¦ãæ¹æ³ãããã¾ã.ãã ,ç£è¦ã·ã¹ãã ã§ãµã¼ãã¹ã¹ãã¼ã¿ã¹ãçµ±å管çã§ãããéç¨ãããããã¨æãã¾ã.èªåãæ¥åã§ä½¿ã£ã¦ãã Datadog 㧠AWS ã®ãµã¼ãã¹ã¹ãã¼â¦
ã¿ãã§ã. ChatOps ãµã¼ãã¹ã® AWS Chatbot ãä¸è¬å©ç¨éå§ããã¾ãã.Amazon Chime ã Slack ã¸ä»ãµã¼ãã¹ããã®éç¥ã¡ãã»ã¼ã¸ã Lambda çã§å¦çããæéãä¸è¦ã§ã¡ãã»ã¼ã¸ãæé©åããã¦ãããã楽ã ãªã¨ãã¼ã¿æéä¸ã«æãã¾ãã.ãã®è¨äºã§ Chatbot â¦
ã¿ãã§ã. AWS ã®ãµã¼ãã¹ã®ç¶æ ãã¡ã³ããã³ã¹æ å ±ãç¥ãããã« Personal Health Dashboard(ä»¥ä¸ PHD) ã使ãã®ã¯æå¹ã§ã.PHDã¯é常 AWS ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ä¸ãã確èªã§ãã¾ãã,ä»å㯠PHD ã®éç¥ã Slack ã«èªåæ稿ããããã®è¨å®æ¹æ³ãç´¹ä»ãã¾ãâ¦
ã¿ãã§ã. 2019å¹´ãæ®ãã¨ãã1ã¶æã»ã©...ä»å¹´ã®ããæ®ãã¯ä»å¹´ã®ãã¡ã«ä¸ã¤ãã¤çä»ãããæãã§èªåã®ç°å¢ã® Terraform ã®ãã¼ã¸ã§ã³ã v0.11 ãã v0.12 ã¸ã¢ããã°ã¬ã¼ãããã®ã§å¯¾å¿æ¹æ³ãæ´çãã¦ããã¾ã. www.terraform.io v0.11 ãã v0.12 ã®ã¢ãâ¦
ã¿ãã§ã. æ¥å㧠Route53 ãã©ã¤ãã¼ããã¹ãã¾ã¼ã³ãå¥ã¢ã«ã¦ã³ãã® VPC ã§ã使ããã¨ãã§ããããè¨å®ãè¡ã£ãã®ã§ã©ã®ããã«è¨å®ããããæ´çãã¦ããã¾ã. æ¬è¨äºã§ç´¹ä»ããè¨å®ã®æ¦è¦ åèããã¥ã¡ã³ã äºãæºåãã¦ããã㨠åèããã¥ã¡ã³ã å®éã®â¦
ã¿ãã§ã. AWS ã«ã¯ãµã¼ãã¹ãã¨ã«å¶éãè¨ãããã¦ãã¾ã.EC2 ã§ããªã³ããã³ãã¤ã³ã¹ã¿ã³ã¹ã®å¶éã¨ã㦠vCPU å¶éãè¨ããããã®ã¯è¨æ¶ã«æ°ããã§ã. AWS ãµã¼ãã¹ã®å¶é docs.aws.amazon.com EC2 ã®èµ·åå¶éããµã¼ãã¼å°æ°ãã vCPU ã§ã®å¶éã¸å¤æ´ã®ã¢â¦
ã¿ãã§ã. EC2 㧠æ°ãããªã³ããã³ãã¤ã³ã¹ã¿ã³ã¹ã®å¶éãè¨ããã,vCPU ãã¼ã¹å¶éãã¢ãã¦ã³ã¹ããã¾ãã.ããã¾ã§ã®èãæ¹ã¨ç°ãªããã,ãã®è¨äºã§ã¯ä»åã®ã¢ãããã¼ãã«ã¤ãã¦å©ç¨è å´ã§ã©ããªå¯¾å¿ãå¿ è¦ã«ãªãã,ã¨ãã観ç¹ã§æ´çãã¦ããã¾ã. ä»åâ¦
ã¿ãã§ã. æ¥åã§ãã«ãã¢ã«ã¦ã³ããã¤å¤æ°ã®éçºãã³ãã¼ã®æ¹ã ãå©ç¨ããç°å¢ã®éç¨ã«ããã¦ãAWS Service Catalog(以ä¸,Service Catalog)ãã®å©ç¨å ´é¢ãããã¨æã,ã¾ãã¯ãService Catalogãã®æ¦è¦ãå©ç¨æ¹æ³ã確èªããå¾,ãã«ãã¢ã«ã¦ã³ããã¤å¤æ°ã®éâ¦
ã¿ãã§ã. ã¿ãªããã¯æ®æ®µ AWS ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ãããè¦ã¾ããï¼ GUI ã¯ç´æçã§ããã«ç¶æ 確èªãã§ãã¦ä¾¿å©ãªã®ã§ãã, GUI ã«é ¼ã£ã¦ããã¨æéããªãæãä½åº¦ãè¦ããã¼ã¸ãªãããã«ç¢ºèªã§ããè¡ãç¥ã£ã¦ããã¨éç¨æã«ã¡ãªããã大ããã¯ãã§ã. â¦
ã¿ãã§ã. ã¢ã«ã¦ã³ãã®éç¨ã§ IAM ã¦ã¼ã¶ã¼ã®ãã¹ã¯ã¼ããããªã·ã¼ã«åãã¦å¤æ´ããã¦ãªãã ã MFA æå¹åããªããã°ãªããªãã®ã«æå¹åãããªãã§æ¾ç½®ããã¦ããçå®æçã«æ£å¸ããã¦ãããã¨æãã¾ã. ä»åã¯IAM ã¦ã¼ã¶ã¼ã®æ£å¸ãã«å½¹ç«ã¤, IAM ã®ãèªè¨¼â¦