ãããã«ã¡ã¯ä½ã æ¨ã§ãã以åããAWSã®ã°ãã¼ãã«IPã®ç©ºéã¯ã¤ã³ã¿ã¼ããããªã®ãï¼ãã¨é¡ãã¦ãAWSã®ãããªãã¯IPå士ã®éä¿¡ãä½æ AWSã®ãã©ã¤ãã¼ããããã¯ã¼ã¯ã®éä¿¡ã«ãªãã®ãã¨ãã話ããã¾ããããã®ä¸ã§ãPrivateLinkã®å¿ è¦æ§ã¯ã©ãèããã¹ããªã®ãã¨ããäºã«ãå°ãã ãè¨åãã¾ãããä»åã¯ããããããå°ãã ãæ·±ã¼ã£ã¦è¦ã¦ã¿ã¾ããããã¦ã¼ã¹ã±ã¼ã¹ã¨ãã¦ãå¤ãã§ããããEC2ããS3ã®éä¿¡ã®ä¾ã§ã¿ã¦ã¿ã¾ãã
EC2ããS3ã¸ã¢ã¯ã»ã¹ããï¼ã¤ã®ã«ã¼ã
EC2ããS3ã¸ã¢ã¯ã»ã¹ããã«ã¼ãã¨ãã¦ã¯æ¬¡ã®ï¼ã¤ãããã¾ã
- Internet Gateway
- NAT Gateway
- VPC Endpointï¼Gatewayã¿ã¤ãï¼
- PrivateLinkï¼Interfaceã¿ã¤ãï¼
ããããã®æ§æã¨å©ç¨ã«é¢ããè²»ç¨ãã¿ã¦ã¿ã¾ãããããªããä»åãç´¹ä»ããã³ã¹ãã¯ãS3ã¸ã®éä¿¡ã«é¢ããã³ã¹ãã§ããS3ã¸ã®ãã¼ã¿ã®ä¿åãAPIã¢ã¯ã»ã¹ã«é¢ããã³ã¹ãã¯å¥éå¿ è¦ãªã®ã§ã注æãã ãã
Internet Gateway
ãã¾ãæåã«Internet Gatewayçµç±ã®çµè·¯ã§ãããããä¸çªåºæ¬çãªã«ã¼ãã¨ãªãã§ããããEC2ããåä¸ãªã¼ã¸ã§ã³ã®S3ã¸ã®éä¿¡æã«ã¤ãã¦ã¯ãç¡æã¨ãªãã¾ãã
ãInternet Gatewayãå©ç¨ããããã«ã¯ã次ã®ï¼ã¤ã®æ¡ä»¶ãå¿ è¦ã§ãã
- ãããªãã¯ãµããããã«å±ãã¦ãããã¨
- ã¤ã³ã¹ã¿ã³ã¹ã«ãããªãã¯IPãä»ä¸ããã¦ãããã¨
AWSã«ããããããªãã¯ãµããããã¨ã¯ãã«ã¼ããã¼ãã«ã§0.0.0.0/0 ï¼ããã©ã«ãã²ã¼ãã¦ã§ã¤ã¸ã®éä¿¡ï¼ãInternet Gatewayã«åãã¦ãããµãããããæãã¾ãããã®ä¸ã§ãã¤ã³ã¹ã¿ã³ã¹ã«ãããªãã¯IPãä»ä¸ããã¦ããã¨ã¤ã³ã¿ã¼ãããã«å¯¾ãã¦ã®éä¿¡ãå©ç¨å¯è½ã§ããS3ã¸ã®éä¿¡ãã¤ã³ã¿ã¼ãããæ±ãã«ãªãã®ã§ããã®æ¡ä»¶ãå¿ è¦ã«ãªãã¾ãã
NAT Gateway
ãããã§ã¯ããããªãã¯ãµããããã«å±ãã¦ããªã or ãããªãã¯IPãä»ä¸ããã¦ããªãEC2ã¤ã³ã¹ã¿ã³ã¹ã¯ã©ããããè¯ãã®ã§ããããï¼ããããæã®æ¹æ³ã®ï¼ã¤ã¨ãã¦ã¯ãNAT Gatewayãå©ç¨ããã®ãä¸è¬çã§ããNAT Gatewayã¯ãããªãã¯ãµããããã«é ç½®ããããããã·ã®ãããªãã®ã§ãããã®NAT Gatewayã«ãããªãã¯IPï¼Elastic IPï¼ãä»ä¸ãããããããçµç±ã§ã¤ã³ã¿ã¼ãããã«éä¿¡ãã§ãã¾ãã
ãNAT Gatewayãå©ç¨ããå ´åã®æ³¨æç¹ã¨ãã¦ã¯ããããªãã®è²»ç¨ãçºçãããã¨ã§ããNAT Gatewayèµ·åã«é¢ããæéã¨ããããçµç±ããéä¿¡æã§ãã
VPC Endpointï¼Gatewayã¿ã¤ãï¼
ããã©ã¤ãã¼ããµããããããã®S3ã®éä¿¡æ¹æ³ã¨ãã¦ã¯ãVPC Endpointãå©ç¨ããæ¹æ³ãããã¾ããVPC Endpointã¨ã¯ãInternet Gatewayãçµç±ããã«S3ãªã©ã®AWSãªã½ã¼ã¹ã«ã¢ã¯ã»ã¹ããããã®çµè·¯ã§ããVPC Endpointãå©ç¨ãããã¨ã§ãVPCã«ããããInternet Gatewayãã¢ã¿ããããªãã¨ããæ§æãã§ãã¾ããVPC Endpointã¯ãGatewayã¿ã¤ãã¨Interfaceã¿ã¤ããããã¾ããGatewayã¿ã¤ãã¯ãS3ã¨DynamoDBã®ã¿å©ç¨å¯è½ã§ããInterfaceã¿ã¤ãã¯å¤æ°ã®ãµã¼ãã¹ã対å¿ãã¦ãããPrivate Linkã¨å¼ã°ãã¾ãã
ãVPC Endpointã®Gatewayã¿ã¤ãã®ã¡ãªããã¨ãã¦ã¯ãã¨ã³ããã¤ã³ãã®å©ç¨æãããããçµç±ããéä¿¡æãç¡æã¨ãããã¨ã§ããS3ãDynamoDBãå©ç¨ããå ´åã¯ãã¾ãããããæ¤è¨ãã¦ã¿ãã¨ããã§ããããä¸æ¹ã§ã¡ãã£ã¨ç¹æ®ãªä½ãããã¦ãã¦ãã¨ã³ããã¤ã³ãã¯ã°ãã¼ãã«IPæ±ãã«ãªã£ã¦ãã¾ãããã®ãããNetwork ACLã§é信許å¯ããã©ã¤ãã¼ãIPã®ç¯å²å ã®ã¿ã¨æå®ãã¦ããã¨ãä¾ãVPC Endpointãå©ç¨ãã¦ãã¦ãS3ã«éä¿¡ã§ããªãã®ã§ã注æãã ããã
PrivateLinkï¼Interfaceã¿ã¤ãï¼
ãããä¸ã¤ã®VPC Endpointã¨ãã¦Interfaceã¿ã¤ãã§ããPrivateLinkãããã¾ããInterfaceã¿ã¤ãã¨ããã®ã¯ãVPCã®ãµããããå ã«ã¨ã³ããã¤ã³ãã®ã¤ã³ã¿ã¼ãã§ã¤ã¹ã¨ãã¦Elastic Network Interfaceï¼ENIï¼ããã§ãã£ã¨çãã¦ããä»çµã¿ã¨ãªã£ã¦ãã¾ãããã®ããããµããããå ã®ãã©ã¤ãã¼ãIPãä¸ã¤æ¶è²»ãã¾ãã
ãENIçµç±ãªã®ã§ãGatewayã¿ã¤ãã¨éã£ã¦å®å ¨ã«ãã©ã¤ãã¼ãIPã®éä¿¡ã§S3ã«ã¢ã¯ã»ã¹ã§ãã¾ããInterfaceã¿ã¤ãã§ã®S3ã®å©ç¨ã¯é·ãã対å¿ãã¦ããªãã£ãã®ã§ããã2021å¹´ã®2æã«ããããå©ç¨å¯è½ã¨ãªãã¾ããã ãã¢ã¼ããã¯ãã£ãèããä¸ã§ã¨ã£ã¦ãæç¨ãªã®ã§ãããè²»ç¨ããããªãã«æããã®ãé£ç¹ã§ããæéãããã®ã¨ã³ããã¤ã³ãã®å©ç¨æã¨ããããçµç±ããéä¿¡æããããã¾ããä½ãèããã«å ¨é¨PrivateLinkã«ãã¦ããã¨æãã¬ã³ã¹ããçºçãããã¨ã«ãªãã¾ãã
S3ã¸éä¿¡ããããã®ã³ã¹ãã®ã¾ã¨ã
ãEC2ããS3ã¸éä¿¡ããéã®ï¼ã¤ã®çµè·¯ã表ã«ã¾ã¨ããã¨æ¬¡ã®ããã«ãªãã¾ãã
éä¿¡çµè·¯ | ã³ã¹ã |
---|---|
Internet Gateway | åä¸ãªã¼ã¸ã§ã³å ç¡æ |
Nat Gateway | ã»Nat Gatewayå©ç¨æï¼0.062USD/æé ã»Nat Gatewayãã¼ã¿è»¢éæéï¼0.062USD/GB |
VPC Endpointï¼Gatewayã¿ã¤ãï¼ | ç¡æ â»åä¸ãªã¼ã¸ã§ã³ã®ã¿å©ç¨å¯è½ |
PrivateLinkï¼Interfaceã¿ã¤ãï¼ | ã»ã¨ã³ããã¤ã³ãå©ç¨æéï¼0.014USD/æé ã»ãã¼ã¿è»¢éæéï¼0.0035USD/GB â»ã¤ã³ã¿ã¼ãªã¼ã¸ã§ã³ VPC ãã¢ãªã³ã°å©ç¨ã§ ä»ãªã¼ã¸ã§ã³ãå©ç¨å¯è½ |
ãã¾ãNAT Gatewayçµç±ã§ã®S3ã¸ã®éä¿¡ã¯ãã³ã¹ãé¢ã§ä¸å©ã¨ãããã¨ã¯ãã£ããã¨èªèãã¦ããã¾ããããç¹ã«å¶ç´ããªãã®ã§ããã°ããããªãã¯ãµããããã«ããå ´åã¯Intenet Gatewayçµç±ããã©ã¤ãã¼ããµããããã«ããå ´åã¯VPC Endpointï¼Gatewayã¿ã¤ãï¼ãå©ç¨ããã®ãè¯ãã®ã解ãã¾ããè¨è¨ã®éã®åèã«ãã¦ãã ãã
ã¯ã©ã¦ãè¨è¨ã®æé©åã¯NRIãããã³ã ã«ãä»»ããã ããã
AWSã®ãã¹ãã»ãã©ã¯ãã£ã¹ãéããAWS Well-Architected ãã¬ã¼ã ã¯ã¼ã¯ããã¨ã«è¨ºæãã課é¡ã®æ´ãåºãã¨ã¨ãã«åªå é ä½ãã¤ãã¦ã©ã®ããã«æ¹åãã¦ãããã®ãææ¡ããã¾ãã
- ã¯ã©ã¦ãæé©å診æãµã¼ãã¹ - NRIãããã³ã
- AWSã½ãªã¥ã¼ã·ã§ã³ã«é¢ãããåãåãã