Upgrade to Pro — share decks privately, control downloads, hide ads and more …

20220624 私の検証環境のいま

20220624 私の検証環境のいま

2022/6/24 第26回 JAWS-UG札幌 勉強会の資料です。

Masaru Ogura

June 24, 2022
Tweet

More Decks by Masaru Ogura

Other Decks in Technology

Transcript

  1. 自己紹介 • 小倉 大 (マサル) Facebook : https://www.facebook.com/masaru.ogura.71 Twitter :

    @MasaruOgura • 株式会社サーバーワークス • ススキノが生んだエンジニア • 2020 / 2021 / 2022 APN ALL AWS Certifications Engineer
  2. AWS Cloud VPC Public subnet Amazon Linux 2 (WordPress) CentOS

    5 (WordPress) Amazon CloudFront ACM Systems Manager CloudWatch alarm AWS Backup AWS Lambda Amazon SNS 最終形 WAF (HTTPS) (HTTP) Amazon Route 53
  3. ネットワーク構成 AWS Cloud VPC Public subnet Corporate data center さくらのVPS

    Internet レプリケーション サーバ ターゲット TCP 443 TCP 443 TCP 1500 AWS API (レプリケーション設定) データ複製(暗号化)
  4. 構成の遷移 AWS Cloud VPC Public subnet CentOS 5 (WordPress) (HTTP)

    Amazon Route 53 ドメインをRoute 53へ移管
  5. 構成の遷移 AWS Cloud VPC Public subnet Amazon Linux 2 (WordPress)

    CentOS 5 (WordPress) (HTTP) Amazon Route 53 CentOSから Amazon Linux 2へ移行
  6. 構成の遷移 AWS Cloud VPC Public subnet Amazon Linux 2 (WordPress)

    CentOS 5 (WordPress) Amazon CloudFront ACM (HTTPS) (HTTP) Amazon Route 53 CloudFrontを入れて ACMで証明書適用
  7. 構成の遷移 AWS Cloud VPC Public subnet Amazon Linux 2 (WordPress)

    CentOS 5 (WordPress) Amazon CloudFront ACM AWS Backup (HTTPS) (HTTP) Amazon Route 53 1日おきにバックアップ取得
  8. 構成の遷移 AWS Cloud VPC Public subnet Amazon Linux 2 (WordPress)

    CentOS 5 (WordPress) Amazon CloudFront ACM Systems Manager (Session Manager) AWS Backup (HTTPS) (HTTP) Amazon Route 53 セッションマネージャーでログイン セキュリティグループのSSHを削除
  9. 構成の遷移 AWS Cloud VPC Public subnet Amazon Linux 2 (WordPress)

    CentOS 5 (WordPress) Amazon CloudFront ACM Systems Manager (Patch Manager) AWS Backup (HTTPS) (HTTP) Amazon Route 53 セキュリティパッチを定期的に適用
  10. 構成の遷移 AWS Cloud VPC Public subnet Amazon Linux 2 (WordPress)

    CentOS 5 (WordPress) Amazon CloudFront ACM Systems Manager (Run Command) CloudWatch alarm AWS Backup AWS Lambda Amazon SNS (HTTPS) (HTTP) Amazon Route 53
  11. 構成の遷移 AWS Cloud VPC Public subnet Amazon Linux 2 (WordPress)

    CentOS 5 (WordPress) Amazon CloudFront ACM Systems Manager (Run Command) CloudWatch alarm AWS Backup AWS Lambda Amazon SNS (HTTPS) (HTTP) Amazon Route 53 プロセス数を確認
  12. 構成の遷移 AWS Cloud VPC Public subnet Amazon Linux 2 (WordPress)

    CentOS 5 (WordPress) Amazon CloudFront ACM Systems Manager (Run Command) CloudWatch alarm AWS Backup AWS Lambda Amazon SNS (HTTPS) (HTTP) Amazon Route 53 SNSへ通知
  13. 構成の遷移 AWS Cloud VPC Public subnet Amazon Linux 2 (WordPress)

    CentOS 5 (WordPress) Amazon CloudFront ACM Systems Manager (Run Command) CloudWatch alarm AWS Backup AWS Lambda Amazon SNS (HTTPS) (HTTP) Amazon Route 53 SNSからLambdaを起動
  14. 構成の遷移 AWS Cloud VPC Public subnet Amazon Linux 2 (WordPress)

    CentOS 5 (WordPress) Amazon CloudFront ACM Systems Manager (Run Command) CloudWatch alarm AWS Backup AWS Lambda Amazon SNS (HTTPS) (HTTP) Amazon Route 53 Lambdaから Run Commandを起動
  15. 構成の遷移 AWS Cloud VPC Public subnet Amazon Linux 2 (WordPress)

    CentOS 5 (WordPress) Amazon CloudFront ACM Systems Manager (Run Command) CloudWatch alarm AWS Backup AWS Lambda Amazon SNS (HTTPS) (HTTP) Amazon Route 53 Run Commandで プロセス再起動
  16. 構成の遷移 AWS Cloud VPC Public subnet Amazon Linux 2 (WordPress)

    CentOS 5 (WordPress) Amazon CloudFront ACM Systems Manager CloudWatch alarm AWS Backup AWS Lambda Amazon SNS WAF (HTTPS) (HTTP) Amazon Route 53 日本以外からの アクセスを拒否