Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Developers.IO_Nagoya_Well-Architected_Frameworkでクラウドジャーニー.pdf

wanda
September 12, 2019
940

 Developers.IO_Nagoya_Well-Architected_Frameworkでクラウドジャーニー.pdf

Well-Architeted Framework

wanda

September 12, 2019
Tweet

Transcript

  1. ຊ೔ͷ಺༰ • Well-Archtected Frameworkͱ͸ʁ • Ұൠతͳઃܭͷݪଇ • ʮ৴པੑͷபʯ • Well-Arctected

    Frameworkͷ࢖͍ํͷΠϝʔδΛ೺Ѳ • ࣌ؒత౎߹͔Βʮபʯͷશ߲໨ʹ͍ͭͯ͸͓࿩͠·ͤΜɻ • ʮ৴པੑͷபʯ͔Βൈਮͯ͠۩ମతͳར༻๏Λ͓఻͑͠·͢ • Well-Architected Tool ͷ঺հͱ࢖͍ํ • ·ͱΊ
  2. 7 What’s AWS Well-Architected Framework ? • ΞʔΩςΫνϟͷઃܭɾӡ༻ʹ͓͚ΔϕετϓϥΫςΟεू • ઃܭݪଇͱ5ͭͷ෼໺(ப)ʹผΕ࣭ͨ໰ͱճ౴ܗࣜ

    • ҆શͰߴ͍ύϑΥʔϚϯεɺো֐଱ੑΛඋ͑ޮ཰తͳΠϯϑϥߏஙͷαϙʔτ • 5ຊͷபʗ46ͷ࣭໰Λ௨ͯ͠ઃܭ͕ϕετϓϥΫςΟεʹଇ͍ͬͯΔ͔Λ֬ೝ͢Δ ߟ͑ํʗϓϩηε ӡ༻্ͷ ༏लੑ ηΩϡϦ ςΟ ৴པੑ ύϑΥʔ Ϛϯε ޮ཰ ίετ ࠷దԽ
  3. 25 9ͭͷ࣭໰ 1. AWSαʔϏεͷ੍ݶΛͲͷΑ͏ʹ؅ཧ͍ͯ͠·͔͢ʁ 2. AWS্ͰͷωοτϫʔΫߏ੒ΛͲͷΑ͏ʹઃܭ͍ͯ͠·͔͢ʁ 3. γεςϜʹର͢ΔधཁͷมԽʹ͸ͲͷΑ͏ʹରԠ͍ͯ͠·͔͢ʁ 4. AWSϦιʔεΛͲͷΑ͏ʹϞχλϦϯά͍ͯ͠·͔͢ʁ

    5. มߋΛͲͷΑ͏ʹ࣮ࢪ͍ͯ͠·͔͢ʁ 6. σʔλΛͲͷΑ͏ʹόοΫΞοϓ͍ͯ͠·͔͢ʁ 7. γεςϜ͕ίϯϙʔωϯτͷΤϥʔʹ଱͑ΔΑ͏ʹͲͷΑ͏ʹઃܭ͍ͯ͠·͔͢ 8. γεςϜͷ஄ྗੑΛͲͷΑ͏ʹςετ͍ͯ͠·͔͢ʁ 9. ࡂ֐࣌ͷϦΧόϦϓϥϯ͸Ͳ͏ͳ͍ͬͯ·͔͢ʁ
  4. 26 9ͭͷ࣭໰ 1. AWSαʔϏεͷ੍ݶΛͲͷΑ͏ʹ؅ཧ͍ͯ͠·͔͢ʁ 2. AWS্ͰͷωοτϫʔΫߏ੒ΛͲͷΑ͏ʹઃܭ͍ͯ͠·͔͢ʁ 3. γεςϜʹର͢ΔधཁͷมԽʹ͸ͲͷΑ͏ʹରԠ͍ͯ͠·͔͢ʁ 4. AWSϦιʔεΛͲͷΑ͏ʹϞχλϦϯά͍ͯ͠·͔͢ʁ

    5. มߋΛͲͷΑ͏ʹ࣮ࢪ͍ͯ͠·͔͢ʁ 6. σʔλΛͲͷΑ͏ʹόοΫΞοϓ͍ͯ͠·͔͢ʁ 7. γεςϜ͕ίϯϙʔωϯτͷΤϥʔʹ଱͑ΔΑ͏ʹͲͷΑ͏ʹઃܭ͍ͯ͠·͔͢ 8. γεςϜͷ஄ྗੑΛͲͷΑ͏ʹςετ͍ͯ͠·͔͢ʁ 9. ࡂ֐࣌ͷϦΧόϦϓϥϯ͸Ͳ͏ͳ͍ͬͯ·͔͢ʁ
  5. 27 1/9ɽ AWSαʔϏεͷ੍ݶΛͲͷΑ͏ʹ؅ཧ͍ͯ͠·͔͢ʁ • ੍ݶͷ؅ཧ௥੻͸͍ͯ͠ͳ͍ • ੍ݶΛ؂ࢹ͠؅ཧΛߦ͍ͬͯΔ • ؂ࢹΛࣗಈԽ੍͠ݶͷ؅ཧΛߦ͍ͬͯΔ •

    ΞʔΩςΫνϟΛհͯ͠ݻఆαʔϏεͷ੍ݶʹରԠ͍ͯ͠Δ • ϑΣΠϧΦʔόʔʹରԠ͢ΔͨΊʹɺݱࡏͷαʔϏε੍ݶͱ࠷େ࢖༻ྔͱͷؒʹ े෼ͳࠩΛ֬อ͍ͯ͠Δ • ؔ࿈͢ΔશͯͷΞΧ΢ϯτͱϦʔδϣϯશମͷαʔϏε੍ݶΛ؅ཧ͍ͯ͠Δ
  6. 28 1/9ɽ AWSαʔϏεͷ੍ݶΛͲͷΑ͏ʹ؅ཧ͍ͯ͠·͔͢ʁ • ੍ݶͷ؅ཧ௥੻͸͍ͯ͠ͳ͍ • ੍ݶΛ؂ࢹ͠؅ཧΛߦ͍ͬͯΔ • ؂ࢹΛࣗಈԽ੍͠ݶͷ؅ཧΛߦ͍ͬͯΔ •

    ΞʔΩςΫνϟΛհͯ͠ݻఆαʔϏεͷ੍ݶʹରԠ͍ͯ͠Δ • ϑΣΠϧΦʔόʔʹରԠ͢ΔͨΊʹɺݱࡏͷαʔϏε੍ݶͱ࠷େ࢖༻ྔͱͷؒʹ े෼ͳࠩΛ֬อ͍ͯ͠Δ • ؔ࿈͢ΔશͯͷΞΧ΢ϯτͱϦʔδϣϯશମͷαʔϏε੍ݶΛ؅ཧ͍ͯ͠Δ
  7. 31 1/9ɽ AWSαʔϏεͷ੍ݶΛͲͷΑ͏ʹ؅ཧ͍ͯ͠·͔͢ʁ • ੍ݶͷ؅ཧ௥੻͸͍ͯ͠ͳ͍ • ੍ݶΛ؂ࢹ͠؅ཧΛߦ͍ͬͯΔ • ؂ࢹΛࣗಈԽ੍͠ݶͷ؅ཧΛߦ͍ͬͯΔ •

    ΞʔΩςΫνϟΛհͯ͠ݻఆαʔϏεͷ੍ݶʹରԠ͍ͯ͠Δ • ϑΣΠϧΦʔόʔʹରԠ͢ΔͨΊʹɺݱࡏͷαʔϏε੍ݶͱ࠷େ࢖༻ྔͱͷؒʹ े෼ͳࠩΛ֬อ͍ͯ͠Δ • ؔ࿈͢ΔશͯͷΞΧ΢ϯτͱϦʔδϣϯશମͷαʔϏε੍ݶΛ؅ཧ͍ͯ͠Δ
  8. 32 Trusted Advisor ֤छϦιʔεͷར༻ঢ়گͱαʔϏε੍ݶʹର͢Δঢ়ଶΛ֬ೝ • ݱࡏͷར༻ঢ়گͱ੍ݶʹର͢Δঢ়ଶΛʮGreenʯʮYellowʯʮRedʯͰදࣔ • ʮϏδωεʯʮΤϯλʔϓϥΠζʯαϙʔτར༻ͷ৔߹͸ຖिࣗಈͰߋ৽ • APIͰνΣοΫΛߋ৽Մೳ


    AWS αϙʔτAPIͷར༻ Trusted Advisor͕ఏڙ͢ΔνΣοΫͷ໊લͱIDΛऔಘ Trusted AdvisorͷνΣοΫΛ࣮ߦ Trusted AdvisorͷνΣοΫͷৄࡉ৘ใͱαϚϦʔΛऔಘ Trusted AdvisorνΣοΫͷߋ৽ ֤Trusted AdvisorνΣοΫͷεςʔλεΛऔಘ
  9. 1/9ɽ AWSαʔϏεͷ੍ݶΛͲͷΑ͏ʹ؅ཧ͍ͯ͠·͔͢ʁ • ੍ݶͷ؅ཧ௥੻͸͍ͯ͠ͳ͍ • ੍ݶΛ؂ࢹ͠؅ཧΛߦ͍ͬͯΔ • ؂ࢹΛࣗಈԽ੍͠ݶͷ؅ཧΛߦ͍ͬͯΔ • ΞʔΩςΫνϟΛհͯ͠ݻఆαʔϏεͷ੍ݶʹରԠ͍ͯ͠Δ

    • ϑΣΠϧΦʔόʔʹରԠ͢ΔͨΊʹɺݱࡏͷαʔϏε੍ݶͱ࠷େ࢖༻ྔͱͷؒʹ े෼ͳࠩΛ֬อ͍ͯ͠Δ • ؔ࿈͢ΔશͯͷΞΧ΢ϯτͱϦʔδϣϯશମͷαʔϏε੍ݶΛ؅ཧ͍ͯ͠Δ
  10. 34 CloudWatchͰαʔϏε੍ݶΛ௨஌͢Δ Trusted AdvisorͷαʔϏε੍ݶʹؔ͢ΔϝτϦΫε͕CloudWatchʹൃߦ͞ΕΔ • CloudWatch Alarmͷ࡞੒ɿ͖͍͠஋ͱͯ͠ར༻཰ʮ0.00ʙ1.00ʯΛࢦఆ • CloudWatch EventsͰεςʔλεͷ


    มߋΛݕग़Մೳ • ઃఆϦʔδϣϯ͸ʮN.Virginiaʯ https://docs.aws.amazon.com/ja_jp/awssupport/latest/user/cloudwatch-metrics-ta.html https://dev.classmethod.jp/cloud/aws/sonobe-trustedadvisor-cloudwatch-integrate/
  11. 35 CloudWatchͰαʔϏε੍ݶΛ௨஌͢Δ CloudWatch EventsͷΠϕϯτύλʔϯ { "source": [ "aws.trustedadvisor" ], "detail-type":

    [ "Trusted Advisor Check Item Refresh Notification" ], "detail": { "status": [ "ERROR" ], "check-name": [ "Service Limits", "EC2 Elastic IP Addresses", "Security Groups - Specific Ports Unrestricted" ] } }
  12. 40 1/9ɽ AWSαʔϏεͷ੍ݶΛͲͷΑ͏ʹ؅ཧ͍ͯ͠·͔͢ʁ • ੍ݶͷ؅ཧ௥੻͸͍ͯ͠ͳ͍ • ੍ݶΛ؂ࢹ͠؅ཧΛߦ͍ͬͯΔ • ؂ࢹΛࣗಈԽ੍͠ݶͷ؅ཧΛߦ͍ͬͯΔ •

    ΞʔΩςΫνϟΛհͯ͠ݻఆαʔϏεͷ੍ݶʹରԠ͍ͯ͠Δ • ϑΣΠϧΦʔόʔʹରԠ͢ΔͨΊʹɺݱࡏͷαʔϏε੍ݶͱ࠷େ࢖༻ྔͱͷؒʹ े෼ͳࠩΛ֬อ͍ͯ͠Δ • ؔ࿈͢ΔશͯͷΞΧ΢ϯτͱϦʔδϣϯશମͷαʔϏε੍ݶΛ؅ཧ͍ͯ͠Δ
  13. 41 1/9ɽ AWSαʔϏεͷ੍ݶΛͲͷΑ͏ʹ؅ཧ͍ͯ͠·͔͢ʁ • ੍ݶͷ؅ཧ௥੻͸͍ͯ͠ͳ͍ • ੍ݶΛ؂ࢹ͠؅ཧΛߦ͍ͬͯΔ • ؂ࢹΛࣗಈԽ੍͠ݶͷ؅ཧΛߦ͍ͬͯΔ •

    ΞʔΩςΫνϟΛհͯ͠ݻఆαʔϏεͷ੍ݶʹରԠ͍ͯ͠Δ • ϑΣΠϧΦʔόʔʹରԠ͢ΔͨΊʹɺݱࡏͷαʔϏε੍ݶͱ࠷େ࢖༻ྔͱͷؒʹ े෼ͳࠩΛ֬อ͍ͯ͠Δ • ؔ࿈͢ΔશͯͷΞΧ΢ϯτͱϦʔδϣϯશମͷαʔϏε੍ݶΛ؅ཧ͍ͯ͠Δ
  14. 42 9ͭͷ࣭໰ 1. AWSαʔϏεͷ੍ݶΛͲͷΑ͏ʹ؅ཧ͍ͯ͠·͔͢ʁ 2. AWS্ͰͷωοτϫʔΫߏ੒ΛͲͷΑ͏ʹઃܭ͍ͯ͠·͔͢ʁ 3. γεςϜʹର͢ΔधཁͷมԽʹ͸ͲͷΑ͏ʹରԠ͍ͯ͠·͔͢ʁ 4. AWSϦιʔεΛͲͷΑ͏ʹϞχλϦϯά͍ͯ͠·͔͢ʁ

    5. มߋΛͲͷΑ͏ʹ࣮ࢪ͍ͯ͠·͔͢ʁ 6. σʔλΛͲͷΑ͏ʹόοΫΞοϓ͍ͯ͠·͔͢ʁ 7. γεςϜ͕ίϯϙʔωϯτͷΤϥʔʹ଱͑ΔΑ͏ʹͲͷΑ͏ʹઃܭ͍ͯ͠·͔͢ 8. γεςϜͷ஄ྗੑΛͲͷΑ͏ʹςετ͍ͯ͠·͔͢ʁ 9. ࡂ֐࣌ͷϦΧόϦϓϥϯ͸Ͳ͏ͳ͍ͬͯ·͔͢ʁ ʢҧ͏࣭໰ͷ಺༰΋ݟͯΈ·͠ΐ͏ɻʣ
  15. 45 AWSαʔϏεͷϩάͷ༗ޮԽ • S3αʔόΞΫηεϩά • Elastic Load BalancerͷΞΫηεϩά • VPCϑϩʔϩά

    • CloudWatch LogsɺS3ʹग़ྗՄೳ • ར༻༻్΍ίετײͰબ୒ɻ • ClouTrail • CloudWatch LogsͰαʔό্ͷϩάΛετϦʔϛϯά • CloudWatch Agentͷར༻ • ECSͷίϯςφϩάΛCloudWatch Logsʹग़ྗ • fargateͷ৔߹ɺϩάυϥΠόʔ͸awslogsͱsplunk • LambdaͷϩάΛCloudWatch LogsʹετϦʔϛϯά
  16. 47 Network Load Balancerͷϩά • Netowork Load Balancer͸ʮTLSʯͷ৔߹ͷΈ • Ϧεφʔ͕ʮTCPʯͷͱ͖͸ग़ྗ͞Εͳ͍

    • ϩάͷϑΟʔϧυ͸L4૬౰ͷ৘ใ͕ग़ྗ • UserAgent΍ϦΫΤετ಺༰ͳͲ͕औΕͳ͍ • ҰൠతͳWebΞΫηεϩάͷղੳ༻్ʹ͸ෆ޲͖ • EC2ଆͰऔಘ͢Δඞཁ͕͋Δ tls 1.0 2018-12-20T02:59:40 net/my-network-loadbalancer/c6e77e28c25b2234 g3d4b5e8bb8464cd 72.21.218.154:51341 172.100.100.185:443 5 2 98 246 - arn:aws:acm:us-east-2:671290407336:certificate/2a108f19-aded-46b0-8493- c63eb1ef4a99 - ECDHE-RSA-AES128-SHA tlsv12 - my-network-loadbalancer-c6e77e28c25b2234.elb.us-east-2.amazonaws.com
  17. 48 CloudWatch Logs • Lambda, Elasticsearch Service, KinesisͷαϒεΫϦϓγϣϯϑΟϧλ • ϑΟϧλύλʔϯʹԠͯ͡ϦΞϧλΠϜʹసૹ

    • Kinesis͸ Kinesis Data Stream ͱ Kinesis Data Firehose • KinesisͷαϒεΫϦϓγϣϯϑΟϧλʔ͸ίϯιʔϧ͔ΒઃఆෆՄ
  18. 49 CloudWatch logs Insight • CloudWatch logsͷϩάΛΠϯλϥΫςΟϒʹ෼ੳɾՄࢹԽ • ಠࣗܗࣜͷΫΤϦίϚϯυΛൃߦ •

    ίϯιʔϧͷURL͕ͦͷΫΤϦͷ࣮ߦ݁ՌͷURLʹͳΔ • ॊೈʹ෼ੳ͍ͨ͠৔߹͸AthenaΛݕ౼ stats avg(bytes), min(bytes), max(bytes) by srcAddr, dstAddr
  19. 54 ࣗಈରԠ • Ξϥʔτݕ஌͔Β෮چ࡞ۀ·ͰࣗಈԽ • ಛఆͷΞϥʔτ͸׬શʹࣗಈԽ • ࣗಈԽ͕๬·͘͠ͳ͍΋ͷ͸ผͷΞϓϩʔν • ୲౰ऀͷ൑அΛڬΜͩ൒ࣗಈԽ

    • Slack΍ి࿩௨஌ޙɺslack͔Β෮چॲཧ / ௨࿩தʹ෮چॲཧ • ϚωʔδυαʔϏεΛར༻ͨ͠ίϯϙʔωϯτͷஔ͖׵͑ • ྫɿRDSͷMulti-AZ • EC2 Auto RecoveryʹΑΔstop/startࣗಈԽ • ج൫ଆͷো֐ൃੜ࣌ʹՔಇ͢Δج൫Λ੾Γସ͑
  20. 55 ෮چ·ͰͷࣗಈԽ • αʔό্ͷҰ࣍తͳ෮چॲཧΛࣗಈԽ • ෮چ༻ͷCloudWatch Alarm΋ొ࿥ͯ֬͠ೝ • Systems ManagerͷRun

    CommandΛLambdaͰ࣮ߦ • Run CommandͰαʔό্ͷॲཧΛ࣮ߦ • αʔϏεϨϕϧʹԠͨ͡ར༻ • ࠜຊରࡦ·Ͱͷ࢑ఆॲཧ • AutoScalingͷར༻
  21. 60 ϨϏϡʔͷํ๏ 1. ηϧϑνΣοΫ • ֤νΣοΫ߲໨ʹճ౴ͯ͠ݱঢ়ͷઃܭ΍ӡ༻ʹ͍ͭͯ୨Է͠ • Well-Architected tool ·ͨ͸ɺಉ༷ͷExcelʹهೖ

    2.ϨϏϡʔ • AWS·ͨ͸W-AೝఆύʔτφʔͷιϦϡʔγϣϯΞʔΩςΫτͱϨϏϡʔ • ηϧϑνΣοΫͷ಺༰ΛूதతʹϨϏϡʔ • վળࡦͷݕ౼΍σΟεΧογϣϯ • ༏ઌ౓෇͚ • ߲໨ຖʹཁෆཁͷ൑அ 3.վળ࣮ࢪ • վળࡦʹج͍ͮͨ࠷దԽͷ࣮ࢪ • ఆظతʹ࠶౓νΣοΫɺϨϏϡʔΛߦ͍࠷దԽΛਐΊΔ
  22. 66 ೔ຊޠԽʹ͍ͭͯ ݱ࣌఺ͰW-A Tool೔ຊޠԽͷ༧ఆͳͲ͸ެ։͞Ε͓ͯΓ·ͤΜ ʮAWS Ϋϥ΢υαʔϏε׆༻ࢿྉूʯͰ࣭໰Λ೔ຊޠԽͨ͠ࢿྉ͕ެ։ AWS Ϋϥ΢υαʔϏε׆༻ࢿྉू https://aws.amazon.com/jp/aws-jp-introduction/ AWS

    Well-Architected Framework ώΞϦϯάγʔτʢ೔ຊޠ൛ʣ https://d1.awsstatic.com/webinars/jp/pdf/services/Well- Architected%E3%83%92%E3%82%A2%E3%83%AA%E3%83%B3%E3%82%B0%E3%82%B7%E3%83%BC%E 3%83%88%E6%97%A5%E6%9C%AC%E8%AA%9E%E7%89%88.77c25d2afd0a69894be16b95aae6a4230 11f5a1f.xlsx ೔ຊޠͷϗϫΠτϖʔύʔ͸·ͩ࠷৽Խ͞Ε͍ͯ·ͤΜʢ2018೥6݄൛ʣ https://d1.awsstatic.com/International/ja_JP/Whitepapers/AWS_Well- Architected_Framework_2018_JA_final.pdf ࠷৽ͷӳޠ൛͸2019೥7݄൛
  23. 72 ϨϏϡʔ “Question does not apply to this workload” ϫʔΫϩʔυʹద༻Ͱ͖ͳ͍࣭໰ΛεΩοϓ͢

    Δͱ͖ʹνΣοΫ ྫʣʮAWSαʔϏε΁ͷϓϩάϥϜʹΑΔΞΫη εΛͲͷΑ͏ʹ੍ޚ͍ͯ͠·͔͢ʁʯˠϓϩά ϥϜʹΑΔ੍ޚΛ͍ͯ͠ͳ͍ “Notes - optional” ิ଍ࣄ߲Λهࡌ ྫʣʮRPO/RTOʹؔ͢ΔཁٻϨϕϧ͕௿͍ͨ Ίɺ୯Ұো֐఺ͷഉআ͸෇༩ʯͷΑ͏ʹɺϕε τϓϥεςΟεʹԊ͏ඞཁ͕ແ͍ཧ༝ͳͲΛهࡌ
  24. ैདྷͷExcelܗࣜͱͷҧ͍ Excelܗࣜ • ϫʔΫϩʔυ(γεςϜ)ຖʹϑΝΠϧ͕ඞཁ ◦ γʔτ͕ଟ͘ͳΔͱϑΝΠϧࣗମ͕ॏ͘ͳΔ • ϑΝΠϧͷ؅ཧࣗମΛݕ౼͕ඞཁ • ਐḿ؅ཧͰ͖ͳ͍ʢ೉͍͠ʣ

    • ϚωδϝϯτίϯιʔϧʹΞΫηεͰ͖ͳͯ͘΋ධՁͰ͖Δ Well Architected Tool • ෳ਺ͷϫʔΫϩʔυΛҰݩతʹ؅ཧͰ͖Δ • ϦεΫͷ͋Δ߲໨΍༏ઌ౓ͷߴ͍΋ͷΛ֬ೝͰ͖Δ • ϚΠϧετʔϯΛॻ͘͜ͱͰܧଓతʹධՁɾվળͰ͖Δ 80
  25. 82 Well-Architected Framework • ϕετϓϥΫςΟεʹଇ͍ͬͯΔ͔Λ֬ೝͰ͖ΔϕετϓϥΫςΟεू • ࣭໰͸Ұ؏ͯ͠ઃܭͷجຊݪଇʹଇ͍ͬͯΔ͔Λ֬ೝ͢Δ΋ͷʹͳ͍ͬͯΔ • શͯͷϕετϓϥΫςΟεʹରԠ͢Δඞཁ͸ͳ͍ •

    ༏ઌॱҐ΍ରԠͷཁෆཁ͸Ϗδωε؀ڥ΍εςʔΫϗϧμʔͷཁٻʹΑΓҟͳΔ
 ʢཁ݅΍༏ઌॱҐΛࣗ෼ͨͪͰܾΊΔʣ • Well-Archtected Framework ToolΛ࢖ͬͯϢʔβࣗ਎ͰΞηεϝϯτ࣮ࢪ • ఆظతʹϨϏϡʔͱվળΛ܁Γฦͯ͠Ϋϥ΢υ࠷దԽΛਐΊΔ
  26. 83