Finatextã«ãããAWSã®ã¬ã¼ãã¬ã¼ã«æ¦ç¥ã®ç´¹ä»
ã¯ããã«
ããã«ã¡ã¯ãFinatextã§ã¨ã³ã¸ãã¢ããã¦ãã @s_tajima ã§ãã
Finatextã§ã¯ãç¾å¨ç´40åã®AWSã¢ã«ã¦ã³ãã管çãã¦ãã¾ãã
ããããã®AWSã¢ã«ã¦ã³ãã¯ããããµã¼ãã¹å°ç¨ã«ãªã£ã¦ããããããã¤ãã®ãµã¼ãã¹ãåå±
ãã¦ããããæ¬çªç°å¢ç¨ã ã£ãããéçºç°å¢ç¨ã ã£ããã¨ç¨éã¯æ§ã
ã§ãã
ãã®ä¸ã«ã¯ã 証å¸ãã¸ãã¹ãã©ãããã©ã¼ã ã®BaaS ãæä¾ãã¦ããAWSã¢ã«ã¦ã³ããå«ã¾ãã¾ãã
ãã®BaaSã«éããã¨ããéèãã¡ã¤ã³ã§åºããµã¼ãã¹ãæä¾ãã¦ããFinatextã§ã¯ããã®åºç¤ã¨ãªã£ã¦ããAWSã®ã»ãã¥ãªãã£ã®ç®¡çãé常ã«éè¦ã«ãªã£ã¦ãã¾ãã
ä»åã¯ãå¼ç¤¾ãAWSã®ã»ãã¥ãªãã£ãæ
ä¿ããããã«ã©ããªéç¨ããã¦ãããã¨ããã話ã§ãã
æ¢ã«è¤æ°ã®AWSã¢ã«ã¦ã³ãã管çãã¦ããæ¹ãç¹ã«ç®¡çã¯ãã¦ãããã®ã®ãã¾ãã¡é©åãªç¶æ
ã«ãªã£ã¦ããªãã¨æãã¦ããæ¹ã«èªãã§ããã ããã¨ããããªã¨æã£ã¦ãã¾ãã
ä¸é¨ã®è©±ã¯ã6æã«è¡ãããAWS Summit Tokyo 2019ã§ãç´¹ä»ãã¦ãã¾ãã®ã§åããã¦ã覧ãã ããã
https://aws.amazon.com/jp/blogs/startup/summit2019_day2_recap/
åºæ¬æ¹é
å¼ç¤¾ã§ã¯ãç¾æç¹ã§ã¯ã¨ã³ã¸ãã¢ããã¢ããªã±ã¼ã·ã§ã³ã¨ã³ã¸ãã¢/ã¤ã³ãã©ã¨ã³ã¸ãã¢/AWSã¨ã³ã¸ãã¢/XXXã¨ã³ã¸ãã¢çã¨æ確ã«åºå¥ãããã¨ã¯ãããå¤ãã®ã¨ã³ã¸ãã¢ãå¿ è¦ã«å¿ãã¦AWSã®ãªã½ã¼ã¹ãæä½ããæ©ä¼ãå¿ è¦æ§ãä½ã£ã¦ãã¾ãã
ãã£ã¦ãåºæ¬æ¹éã¨ãã¦ã¯ãIAMã®æ¨©éãå³ãããä¿æãã人ã極度ã«éå®ãã¦å®å ¨æ§ãé«ãããã¨ããããã¯ãã権éã¯ä»ä¸ããããæ¬å½ã«ãªã¹ã¯ã®é«ãæä½ã¯ã§ããªãããããã¯ããã«ããã«æ°ã¥ããã¨ãã§ãããã°ã確å®ã«è¿½ããã¨ãã§ãããç¶æ ãç®æãã¦ãã¾ãã
ããã¯ãè¿å¹´AWSãæå±ãã¦ãããã¬ã¼ãã¬ã¼ã«ãã®èãæ¹ãåèã«ãã¦ãã¾ãã
ä»åã¯ããã®æ¹éã«åºã¥ãã©ããªéç¨ãè¡ã£ã¦ãããããé
ç®ã¨ãã¦
- AWSã¢ã«ã¦ã³ãã®ä¸è¦§ç®¡ç
- AWSã¢ã«ã¦ã³ãã¸ã®ãã°ã¤ã³ã®ç®¡ç
- AWSä¸ã®ãã°ã®ç®¡ç
- AWSä¸ã®ãªãã¬ã¼ã·ã§ã³ã®å¶é
- AWSä¸ã®ãªãã¬ã¼ã·ã§ã³ã®ç£è¦
ã¨ãããããã§ç´¹ä»ãã¾ãã
å
¨ä½ã®æ¦è¦å³ã¯ãããªæãã§ãã
AWSã¢ã«ã¦ã³ãã®ä¸è¦§ç®¡ç
ãAWSã¢ã«ã¦ã³ãã®ã»ãã¥ãªãã£ãæ ä¿ãã¾ãããï¼ãã¨è¨ã£ã¦ããã¾ãã¯å¯¾è±¡ã¨ãªãAWSã¢ã«ã¦ã³ãããã¡ãã¨ææ¡ã§ããªããã°ããã¾ããã
å¼ç¤¾ã§ã¯ãåºæ¬çã«ã¯ãã¹ã¦ã®AWSã¢ã«ã¦ã³ãã1ã¤ã®AWS Organizationã§ç®¡çãã¦ãã¾ãã
https://aws.amazon.com/jp/organizations/
AWS Organizationã使ããã¨ã§ãAWSã¢ã«ã¦ã³ãã®ä¸è¦§ãç°¡åã«åç
§ã§ããããã«ãªãã ãã§ãªãã
å¾è¿°ã®SCPs (Service control policies) ã使ããã¨ã§ãã«ã¼ãã¢ã«ã¦ã³ãã«å¯¾ãã¦ã権éã®å¶éãããããã¨ãã§ããããã«ãªãã¾ããã¾ããæ°ããAWSã¢ã«ã¦ã³ãã®ä½æããã»ã¹ãç°¡åã«ãªãã¾ãã
AWS Organizationã使ããã«è¤æ°ã®AWSã¢ã«ã¦ã³ãã管çãã¦ããç¶æ
ããã1ã¤ã®Organizationã§ç®¡çãã§ããç¶æ
ã«æã£ã¦ããã«ã¯ã1ã¤ã²ã¨ã¤ã®ã¢ã«ã¦ã³ããæå¾
ããå¿
è¦ããããæ°ã«ãã£ã¦ã¯å°ã骨ãæãã¾ãã
ã¾ããOrganizationåä½ã§AWSã®è«æ±ãã¾ã¨ã¾ãã®ã§ãä¼ç¤¾ã®çµçã®æ¹ã¨ã®èª¿æ´ãå¿
è¦ã«ãªãå ´åãããã®ã§ãã®ç¹ã¯æ³¨æã§ãã
AWSã¢ã«ã¦ã³ãã¸ã®ãã°ã¤ã³ã®ç®¡ç
人é (â»ãããçã§ã¯ãªãã¨ããæå³) ãAWSã®ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã«ãã°ã¤ã³ããããCLIçããAWSã®æä½ãããå ´åã¯ãããå°ç¨ã®AWSã¢ã«ã¦ã³ãã«ä½æããå人ç¨ã®IAMã¦ã¼ã¶ã使ããæä½å¯¾è±¡AWSã¢ã«ã¦ã³ãã«ä½ã£ãIAMãã¼ã«ã«å¯¾ããAssumeRoleããã¦ã¯ãã¹ã¢ã«ã¦ã³ãã¢ã¯ã»ã¹ããã¾ããã¤ã¾ããããããã®AWSã¢ã«ã¦ã³ãã«å人ç¨ã®IAMã¦ã¼ã¶ãä½ãã¨ãããã¨ã¯ãã¾ããã
ãã®æ¹å¼ãæ¡ç¨ãããã¨ã§ãIAMã®ã¯ã¬ãã³ã·ã£ã«ãå®æçã«ãã¼ãã¼ãããããMFAãå¼·å¶ããããéè·è ã®ã¢ã«ã¦ã³ãåé¤ãããããªã©ã®ç®¡çã®æéãå¤§å¹ ã«æ¸ãã¾ãã
AWSä¸ã®ãã°ã®ç®¡ç
CloudTrail, AWS Config, VPC FlowLogs, ALBã®ã¢ã¯ã»ã¹ãã°ã¨ãã£ããAWSã§åºåã§ãããã°ã¯åºæ¬çã«ã¯ãã¹ã¦æå¹åããæ¹éã§ãã
ã¾ããåºåå
ã¯åå¥ã®AWSã¢ã«ã¦ã³ãã§ã¯ãªããå°ç¨ã®AWSã¢ã«ã¦ã³ãã«ãã¦ãã¾ãã
ããã«ã¯ã
- å°ç¨ã®AWSã¢ã«ã¦ã³ãã§ããã°æ¨©éãå³ããããããã®ã§ã誰ããã°ãåé¤ã§ããªãç¶æ ã«ã§ããã
- ãã°ãä¸ç®æã«éä¸ããã®ã§ãã°ãç£æ»ããä»çµã¿ã¯ããã対象ã«ããã ãã§ããã
ã¨ããã¡ãªãããããã¾ãã
AWSä¸ã®ãªãã¬ã¼ã·ã§ã³ã®å¶é
åè¿°ã®AWS Organizationã®SCPsã使ãã¨ããã¨ãAdministratorAccessã®æ¨©éããã£ã¦ãå®è¡ã§ããªãAPIãå®ç¾©ãããã¨ãã§ãã¾ãã
å¼ç¤¾ã§ã¯ããã®SCPsãæ´»ç¨ãã以ä¸ã®ãããªå¶éãããã¦ãã¾ãã(ãªã³ã¯å
ãããªã·ã¼ã®JSONã®ãµã³ãã«ã«ãªã£ã¦ãã¾ãã)
- AWS Organizationããã®è±éã®ç¦æ¢
- CloudTrail, AWS Config, GuardDuty, SecurityHubã®è¨å®ã®å¤æ´ã®ç¦æ¢
- RDS, ElastiCache, S3 Bucketçã®æ°¸ç¶åãã¼ã¿ãç½®ãããããªã½ã¼ã¹ã®åé¤ã®ç¦æ¢
- æ±äº¬ãªã¼ã¸ã§ã³ä»¥å¤ã®å©ç¨ç¦æ¢
æå¾ã®æ±äº¬ãªã¼ã¸ã§ã³ä»¥å¤ã®å©ç¨ç¦æ¢ãè¨å®ãããã¨ã§ã社å ã®ã¡ã³ãã¼ãããã¯æªæã®ãã第ä¸è ããæµ·å¤ãªã¼ã¸ã§ã³ã«ãªã½ã¼ã¹ãä½æãã¦ãã¾ããããã«é·ãéæ°ä»ããã«ãªãã¨ãã£ãäºæ ãé²ããã¨ãã§ãã¾ããã¾ãããããã®ãªã¼ã¸ã§ã³ã§ãªã½ã¼ã¹ãèµ·åã§ããªããã¨ãæ ä¿ã§ããã°ãAWS Config, GuardDutyã®ãããªãªã¼ã¸ã§ã³æ¯ã«è¨å®ããªããã°ãªããªããµã¼ãã¹ã®è¨å®ãçç¥ãããã¨ãã§ããã ããã¨ããèãã§ãã
AWSä¸ã®ãªãã¬ã¼ã·ã§ã³ã®ç£è¦
AWSä¸ã§è¡ããããªãã¬ã¼ã·ã§ã³ã®ãã¡ãé«ããªã¹ã¯ãçºçããããã®ã«ã¤ãã¦ã¯Slackã«éç¥ãé£ã¶ããã«ãªã£ã¦ãã¾ãã
ããã¯ãCloudTrailãAWS Configã®ãã°ãLambdaã§ç£è¦ãããã¨ã§å®ç¾ãã¦ãã¾ãã
å
·ä½çã«ã¯ä»¥ä¸ã®ãããªå½¢ã§ãã
0.0.0.0/0 ã«éæ¾ããå ´åã«ã¯ã¡ã³ã·ã§ã³ãã¤ãããã«ãªã£ã¦ãã¾ãã
ãããããã¨ã§ãAWSã«æ £ãã¦ããªãã£ãããã¾ã æè¡çç解度ãé«ããªãã¡ã³ãã¼ã«ã権éãããããã¨ãã§ããä¸é©åãªãªãã¬ã¼ã·ã§ã³ãçºçããã¨ãã«ã¯åãã人ã声ãããã¦æ¹åã§ãããããªç°å¢ã«ãªã£ã¦ãã¾ãã
ä»¥ä¸ ãFinatextã«ãããAWSã®ã¬ã¼ãã¬ã¼ã«ã®å®ç¾æ¹æ³ã®ç´¹ä»ã§ããã
ãã®ãããªã¬ã¼ãã¬ã¼ã«ãå¹ççã«ç®¡çããããã«ãè¨å®ããã¹ã¦Terraformã§ç®¡çããAtlantis ãã¤ãã£ã¦éç¨ã®ã³ã¹ããåæ¸ãã工夫ãªã©ããã¦ããã®ã§ãããããã«ã¤ãã¦ã¯å¥ã®è¨äºã§ã·ã§ã¢ã§ããã°ã¨æãã¾ãã
æå¾ã«
Finatextã§ã¯ãä¸ç·ã«åã仲éãåéãã¦ãã¾ãï¼
å
¨ãæ°ããéèãã¸ãã¹ãã©ãããã©ã¼ã ãåµé ãããã¨ã«èå³ãããæ¹ããã²ãé£çµ¡ãã ããï¼
https://recruit.jobcan.jp/finatext/show/001/115496