æ¬è¨äºã¯
ããæ¨ãï½AWSã¢ã¯ã¼ãã¨ã³ã¸ãã¢ç·¨ï½
1æ¥ç®ã®è¨äºã§ãã
ð»
ã¤ãã³ãåç¥
â¶â¶ æ¬è¨äº â¶â¶
2æ¥ç®
ð»
ããã«ã¡ã¯ãä¸éã§ãã
NRIãããã³ã ã2022 Japan APN Ambassadors / Top Engineers / ALL Certificate Engineers ã«ããæ¨ããã¯ã·ãªã¼ãºã§ãã
ç§ãç´¹ä»ããã®ã¯AWS Single Sign-On (AWS SSO)ã§ããæé«ã®ãµã¼ãã¹ã§ãã
AWS SSOã®æ¦è¦
AWS SSOãæå¹ã«ããã¨ãä¸å 管çãããï¼ä¸ã¤ã®ï¼ã¦ã¼ã¶ã¼å/ãã¹ã¯ã¼ãã§ãã°ã¤ã³ãããã¨ã«ãããè¤æ°ã®AWSã¢ã«ã¦ã³ãã¸ãã°ã¤ã³ã§ããããã«ãªãã¾ãã
âã¯ãã°ã¤ã³ç»é¢ã§ãã
ãã°ã¤ã³ããã¨ã»ã»æ¨©éãããAWSã¢ã«ã¦ã³ããä¸è¦§ã§è¡¨ç¤ºãããåAWSã¢ã«ã¦ã³ãã¸ãã°ã¤ã³ã§ãã¾ãã
便å©ã§ããã
AWS SSOã®ä»çµã¿
AWS SSOã§éè¦ã¨ãªã£ã¦ããã®ãã¦ã¼ã¶ã¼ãã°ã«ã¼ãã権éã»ããã¨ããè¦ç´ ã§ãã
ã¦ã¼ã¶ã¼ãã°ã«ã¼ãã¯ããããããã¨æãã¾ããAWS SSOä¸ã«ã¦ã¼ã¶ã¼ããã¹ã¯ã¼ãã®æ å ±ãä½æãã¦ç®¡çãã¾ããã¦ã¼ã¶ã¼ã®æ å ±ã¯Azure Active Directory(Azure AD)çå¤é¨ã®IdP(Identify Provider)ãå©ç¨ãããã¨ãå¯è½ã§ãã
権éã»ããã¯ããã®åã®ã¨ãããã¦ã¼ã¶ã¼ã¾ãã¯ã°ã«ã¼ãã«ä»ä¸ãããã¢ã¯ã»ã¹æ¨©éã®éã¾ãã§ããAWSã¢ã«ã¦ã³ãå ã§ä½¿ç¨ããIAMãã¼ã«ã«è¿ãã§ããIAMã®ããã¼ã¸ãããªã·ã¼ãã«ã¹ã¿ã ããªã·ã¼ãçµã¿åããã¦ã権éã»ãããä½æãã¦ç®¡çãã¾ãã権éã»ããã«ã¯ãæ大10åã®ããã¼ã¸ãããªã·ã¼ã¨ãæ大1åã®ã«ã¹ã¿ã ããªã·ã¼ï¼JSONã§è¨è¼ï¼ãå«ããã§ãã¾ãã
ã¦ã¼ã¶ã¼ã¨æ¨©éã»ãããä½æããã ãã§ã¯ãã©ã®ã¦ã¼ã¶ã¼ãAWSã¢ã«ã¦ã³ãã¸ã¯ãã°ã¤ã³ã§ãã¾ãããã¦ã¼ã¶ã¼orã°ã«ã¼ãã権éã»ãããAWSã¢ã«ã¦ã³ãã®3ç¹ãç´ã¥ãããã¨ã«ãã£ã¦ãåãã¦è¨å®ããAWSã¢ã«ã¦ã³ãã¸ãã°ã¤ã³ã§ããããã«ãªãã¾ãã
ãã¨ãã°ä»¥ä¸ã®è¨å®ã§ã¯ã
ã°ã«ã¼ãαã«æå±ãã2åãã権éã»ãã1ã®æ¨©éã§ãã¢ã«ã¦ã³ãSys01ã¸ã
ã¦ã¼ã¶ã¼Cãã権éã»ãã2ã®æ¨©éã§ãã¢ã«ã¦ã³ãSys02ã¸ã¢ã¯ã»ã¹ã§ãã¾ãã
権éã»ããã¨ã¢ã«ã¦ã³ããç´ã¥ãã¦è¨å®ããæç¹ã§ãåã¢ã«ã¦ã³ãã«IAMãã¼ã«ãä½æããããã®IAMãã¼ã«ãSSOã®ã¦ã¼ã¶ã¼ãå¼ãåããä»çµã¿ã¨ãªã£ã¦ãã¾ãã
AWS SSOã®æ¨ããã¤ã³ã
ç§ã®æ¨ããã¤ã³ããããã¤ãç´¹ä»ãã¾ãã
èªè¨¼æ å ±ãä¸å 管çã§ãã
AWS Well-Architected ãã¬ã¼ã ã¯ã¼ã¯ã®ã»ãã¥ãªãã£ã®æ±ããã¹ããã©ã¯ãã£ã¹ã«ãããã¨ããããä¸å åããã ID ãããã¤ãã¼ãå©ç¨ãããã»ããå®å ¨ã§ããã¦ã¼ã¶ã¼/ãã¹ã¯ã¼ãã®æ å ±ã1ç®æã§ç®¡çã§ããã®ã§ãMFAã®è¨å®ãæ£å¸ãªã©ã¦ã¼ã¶ã¼åé¤ã®éç¨ããã¹ã¯ã¼ãããªã·ã¼ã1ç®æã§æ¸ã¿ã¾ãã
å¤é¨ã®IdPã¨é£æºã§ãã
Azure ADãGoogle WorkSpaceçãAWSå¤é¨ã®IDãæ¥åã§ä½¿ç¨ãã¦ããå ´åããããã£ãå¤é¨IdPã¨çµ±åã§ããã®ã§ãããå®å ¨ã«ãªãããã¹ã¯ã¼ããMFAæä½ãå ±éã¨ãªãããã°ã¤ã³ããã»ã¹ã楽ã«ãªãã¾ãã
ä¸æã¢ã¯ã»ã¹ãã¼ãç°¡åã«çºè¡ã§ãã
ãã¼ã«ã«PCç°å¢ã§AWSã®SDKã使ç¨ãã¦éçºããããCloudFormationãCDKã®Iacãã¼ã«ãå®è¡ããå ´åãIAMã¦ã¼ã¶ã¼ã®æ°¸ç¶çãªã¢ã¯ã»ã¹ãã¼ã使ããã¨ãããã¾ãããAWS SSOã§ã¯ä¸æçãªã¢ã¯ã»ã¹ãã¼ãç°¡åã«çºè¡ã§ããã®ã§ãããå®å ¨ã«AWSéçºãã§ãã¾ãã
aws configure sso
ã使ç¨ãããããã¡ã¤ã«ã®è¨å®ãå¯è½ã§ãã
AWS Single Sign-On ã使ç¨ããããã® AWS CLI ã®è¨å® - AWS Command Line Interface
AWS SSOã®ç®¡çãå¥ã¢ã«ã¦ã³ãã¸å§ä»»ã§ãã
2022å¹´5æã«åºãã¢ãããã¼ãã«ãã£ã¦ãAWS SSOã®ç®¡çãManagementã¢ã«ã¦ã³ã以å¤ã§ãã§ããããã«ãªãã¾ããã
ã¢ãããã¼ãåã¯Managementã¢ã«ã¦ã³ãã§ã®ã¿AWS SSOã®è¨å®ãå¯è½ã§ãããæè¿ã®ãã¹ããã©ã¯ãã£ã¹ã§ã¯ã1ã¢ã«ã¦ã³ã1ç¨éã¨ãããã¨ãå¤ãã§ããManagementã¢ã«ã¦ã³ãã¯è«æ±æ å ±ãã¢ã«ã¦ã³ãä½æã®ç®¡çãè¡ãã®ã§ããããããã£ã管çã¨ã¦ã¼ã¶ã¼ã»åã¢ã«ã¦ã³ãã®æ¨©é管çã¯ç¨éãç°ãªã管çè ãç°ãªããã¨ãããã¾ãã
AWS SSOã®ç®¡çããç¬ç«ããAWSã¢ã«ã¦ã³ãã§ã§ããããã«ãªã£ãã®ã¯å¬ããã¢ãããã¼ãã§ãã
大è¦æ¨¡çµç¹ã«ãããAWS SSOã®èª²é¡
便å©ãªAWS SSOã§ãããAWSã¢ã«ã¦ã³ãæ°ã100ãè¶ ãããããªå¤§è¦æ¨¡ãªæ§æãªå ´åã権éã»ãããã¢ã«ã¦ã³ãã¨ã®ç´ã¥ã管çãè¤éã«ãªãé£ãããªã£ã¦ãã¾ããã¦ã¼ã¶ã¼ã«æ¸¡ã権éã¯ãåºæ¬çã«AWSã¢ã«ã¦ã³ããã¯ã¼ã¯ãã¼ãåä½ã§è¨å®ãããã¨ãå¤ãããããããã®ç®¡çãAWS SSOã®ç»é¢ä¸ã ãã§ç®¡çããã®ã¯ãªããªã大å¤ã¨ããã®ãç§ã®ææ³ã§ãã大è¦æ¨¡ãªå©ç¨ãæ³å®ããå ´åã¯ãIaCçã®ãã¼ã«ã使ç¨ãã管çãæ¤è¨ããã»ããè¯ãã§ãããã
Organizationsãåããã°ãAWS SSOã®ç®¡çãåãããã¨ãã§ããã®ã§ãããã³ã¹ãã®ç®¡çã¯ã権éã®ç®¡çããã大ããªç¯å²ã§è¡ããããã¿ã¼ã³ãå¤ãã§ããå¾éå¶å²å¼ãããªã¶ã¼ããã¤ã³ã¹ã¿ã³ã¹ã»SavingsPlansã®è³¼å ¥ããµãã¼ãæéã¯Organizationsåä½ã§é©ç¨ãããã®ã§ãå¤ãã®ã¢ã«ã¦ã³ããã¾ã¨ããã»ãããå¾ã«ãªãã¾ãã
以ä¸ã®å³ã¯ä¸ä¾ã§ãã
大è¦æ¨¡ãªOrganizationsã§ããã¾ã権éã管çã§ããã¨è¯ãã®ã§ããããºããªã³ã¬ï¼ã¿ãããªæ¹æ³ã¯ç§ãè¦ã¤ãã£ã¦ããªãç¶æ³ã§ããã管çè ãç³è«ãã¼ã¹ã§SSOã®æ¨©éã»ãããé©åã«ç®¡çããããå©ç¨è ã«æ¨©é管çãä»»ãããå ´åã¯ãAWS SSOã諦ãã¦è¸ã¿å°ã¢ã«ã¦ã³ãï¼IAMãã¼ã«ã¸ã¹ã¤ãããã¨ããæ¡ããããã¨æãã¾ããçµç¹ã«ãã£ã¦å©ç¨æ¹æ³ã大ããç°ãªãã®ã§ä½¿ãæ¹ã«åããã¦ç®¡çæ¹æ³ãèããå¿ è¦ãããã¾ããã
ã¾ã¨ã
æ¨ããµã¼ãã¹ã¨ãã¦AWS SSOãç´¹ä»ãã¾ãããæå¾ã«èª²é¡ãæ¸ãã¾ããããåºæ¬çã«ã¯ãã¡ããã¡ã便å©ãªãµã¼ãã¹ãªã®ã§ãããããAWSãå§ããæ¹ãæ¯éAWS SSOã®å©ç¨ãæ¤è¨ãã¦ããããã¨å¬ããã§ãã