ã¿ãã§ã.
IAM 権éã®å¶å¾¡ã¨ãã¦ãªã¼ã¸ã§ã³ã¬ãã«ã§å¶å¾¡ãããè¦ä»¶ãåºã¦ããã®ã§èª¿ã¹ã¦ã¿ãã¨ãã, aws:RequestedRegion
ã§å¶éã§ãããããªã®ã§æ¤è¨¼ããçµæãããã°ã«ã¾ã¨ãã¾ã.ãªã,ä»åæ±äº¬ãªã¼ã¸ã§ã³ã¨ã½ã¦ã«ãªã¼ã¸ã§ã³ã« EC2 ãèµ·åãã¦ããç¶æ³ã§èªã¿åã権éã¯å
¨ãªã¼ã¸ã§ã³æå¹ã§ã¯ããã, EC2 ã¸ã®å¤æ´æ¨©éãèµ·å,åæ¢ã¨ãã£ã権éã¯æ±äº¬ãªã¼ã¸ã§ã³ã®ã¿ã«éå®ãã IAM ããªã·ã¼ãè¨å®ãã¦æ¤è¨¼ãã¾ãã.
æ¤è¨¼ã¤ã¡ã¼ã¸å³
æ¤è¨¼ãã IAM ããªã·ã¼
æ¤è¨¼ã§ä½¿ã£ã IAM ããªã·ã¼ã¯ä»¥ä¸ã®éãã§ã.ãã®ããªã·ã¼ã IAM ã¦ã¼ã¶ã¼ã«é¢é£ã¥ãã¦æ±äº¬ã¨ã½ã¦ã«ã® EC2 ãèµ·å,åæ¢ãã¦ã¿ã¾ã.æå¾ ããçµæã¯æ±äº¬ãªã¼ã¸ã§ã³ã®ãµã¼ãã¼ã¯èµ·åã¨åæ¢ã¯ãã¾ããã,ã½ã¦ã«ãªã¼ã¸ã§ã³ã®ãµã¼ãã¼ã¯åæ¢ãèµ·åãã§ããªã,ã§ã.
{ "Version": "2012-10-17", "Statement": [ { "Sid": "InstanceConsoleReadOnly", "Effect": "Allow", "Action": [ "ec2:Describe*" ], "Resource": "*" }, { "Sid": "InstanceWriteRegionRestricted", "Effect": "Allow", "Action": [ "ec2:ModifyInstancePlacement", "ec2:TerminateInstances", "ec2:ImportInstance", "ec2:StartInstances", "ec2:MonitorInstances", "ec2:RunScheduledInstances", "ec2:ResetInstanceAttribute", "ec2:RunInstances", "ec2:ModifyInstanceAttribute", "ec2:StopInstances", "ec2:AssociateIamInstanceProfile", "ec2:ModifyReservedInstances" ], "Resource": "*", "Condition": { "StringEquals": { "aws:RequestedRegion": [ "ap-northeast-1" <= æ±äº¬ãªã¼ã¸ã§ã³ã®ã¿æå® ] } } } ] }
AWS ããã¥ã¡ã³ã
EC2 ã®èµ·åã¨åæ¢ã®æ¤è¨¼
æ±äº¬ãªã¼ã¸ã§ã³ã®å ´å
æ±äº¬ãªã¼ã¸ã§ã³ã§ IAMTEST
ã¤ã³ã¹ã¿ã³ã¹ãèµ·åãã¦ããã®ã§,åæ¢ã®æä½ãè¡ãªã£ã¦ã¿ãã¨ç¡äºã«åæ¢ã¾ã§æä½å¯è½ãªãã¨ã確èªã§ãã¾ãã.
次ã«,èµ·åãã¦ã¿ã¾ã.èµ·åãåé¡ãªãå®äºãã¾ãã.æ±äº¬ãªã¼ã¸ã§ã³ã¯æå¾ éãã®æä½ãã§ãããã¨ã確èªã§ãã¾ãã.
ã½ã¦ã«ãªã¼ã¸ã§ã³ã®å ´å
ã½ã¦ã«ãªã¼ã¸ã§ã³ã§ã IAMTEST
ã¤ã³ã¹ã¿ã³ã¹ãèµ·åãã¦ããã®ã§,åæ¢ã®æä½ãè¡ãªã£ã¦ã¿ãã¨åæ¢å¦çã失æãããã¨ã確èªã§ãã¾ãã.
ãªã,ã¨ã©ã¼æããã³ã¼ãããã®ã¯ä¸è¨ã® AWS CLI ã§ç¢ºèªå¯è½ã§ã.
$aws sts decode-authorization-message --encoded-message <ã¨ã©ã¼æ>
次ã«,äºåã«éã権éãæã¤ã¦ã¼ã¶ã¼ã§åæ¢ãã¦ããããµã¼ãã¼ãèµ·åãã¦ã¿ã¾ã.èµ·åã失æããã®ã§ã½ã¦ã«ãªã¼ã¸ã§ã³ã¯æå¾ éãã®æä½ãã§ãããã¨ã確èªã§ãã¾ãã.
ã¾ã¨ã
ãªã½ã¼ã¹å¶å¾¡ããªã¼ã¸ã§ã³ã¬ãã«ã§è¨å®ãã IAM ããªã·ã¼ã®ç´¹ä»ã¨IAMããªã·ã¼å¶å¾¡ã®æ¤è¨¼ã EC2 ã®æä½ã§ç¢ºããã¦ã¿ãçµæãã¾ã¨ãã¾ãã.AWS ã®ããã¥ã¡ã³ããã¼ã¸ã«ã注æäºé ã¨ãã¦è¨è¼ãããã¾ãã,ãªã¼ã¸ã§ã³ã¬ãã«ã§å¶å¾¡ãããã¨ã§åä½ããªããµã¼ãã¹ã®æä½ãããããè¨å®ãè¡ãéã¯ååã«æ³¨æã,ãã¹ãããå¾è¨å®ãè¡ãããã«ãã¾ããã.
aws:RequestedRegion æ¡ä»¶ãã¼ã使ç¨ããã¨ãå¼ã³åºããããµã¼ãã¹ã®ã¨ã³ããã¤ã³ããå¶å¾¡ã§ãã¾ããããªãã¬ã¼ã·ã§ã³ã®å½±é¿ãå¶å¾¡ãããã¨ã¯ã§ãã¾ãããä¸é¨ã®ãµã¼ãã¹ã§ã¯ãªã¼ã¸ã§ã³éã®å½±é¿ãããã¾ãããã¨ãã°ãAmazon S3 ã«ã¯ãªã¼ã¸ã§ã³éã¬ããªã±ã¼ã·ã§ã³ãå¶å¾¡ãã API ãªãã¬ã¼ã·ã§ã³ãããã¾ãã1 ã¤ã®ãªã¼ã¸ã§ã³ (s3:PutBucketReplication ã®æ¡ä»¶ãã¼ã®å½±é¿ãåãã) 㧠aws:RequestedRegion ãå¼ã³åºããã¨ã¯ã§ãã¾ãããä»ã®ãªã¼ã¸ã§ã³ã¯ã¬ããªã±ã¼ã·ã§ã³ã®æ§æè¨å®ã«åºã¥ãã¦å½±é¿ãåãã¾ãã