Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
bitbankのAWSアカウント作成管理術
Search
やったん
October 04, 2019
Technology
0
880
bitbankのAWSアカウント作成管理術
AWS DevDay 2019 懇親会でLTした時の資料です。
やったん
October 04, 2019
Tweet
Share
More Decks by やったん
See All by やったん
Fargate + ECR で elastalertを構築
mdps513
4
1.6k
Other Decks in Technology
See All in Technology
20250807_Kiroと私の反省会
riz3f7
0
200
Amazon GuardDuty での脅威検出:脅威検出の実例から学ぶ
kintotechdev
0
100
AI関数が早くなったので試してみよう
kumakura
0
270
Kiroから考える AIコーディングツールの潮流
oikon48
4
680
アカデミーキャンプ 2025 SuuuuuuMMeR「燃えろ!!ロボコン」 / Academy Camp 2025 SuuuuuuMMeR "Burn the Spirit, Robocon!!" DAY 1
ks91
PRO
0
140
2025新卒研修・HTML/CSS #弁護士ドットコム
bengo4com
3
13k
プロダクトエンジニアリングで開発の楽しさを拡張する話
barometrica
0
140
【新卒研修資料】数理最適化 / Mathematical Optimization
brainpadpr
26
13k
猫でもわかるQ_CLI(CDK開発編)+ちょっとだけKiro
kentapapa
0
3.4k
Vision Language Modelと自動運転AIの最前線_20250730
yuyamaguchi
4
1.3k
Google Agentspaceを実際に導入した効果と今後の展望
mixi_engineers
PRO
3
400
20250807 Applied Engineer Open House
sakana_ai
PRO
0
190
Featured
See All Featured
A Tale of Four Properties
chriscoyier
160
23k
Fireside Chat
paigeccino
38
3.6k
The Pragmatic Product Professional
lauravandoore
36
6.8k
Practical Orchestrator
shlominoach
190
11k
Adopting Sorbet at Scale
ufuk
77
9.5k
Build The Right Thing And Hit Your Dates
maggiecrowley
37
2.8k
[Rails World 2023 - Day 1 Closing Keynote] - The Magic of Rails
eileencodes
36
2.5k
Fashionably flexible responsive web design (full day workshop)
malarkey
407
66k
[RailsConf 2023 Opening Keynote] The Magic of Rails
eileencodes
29
9.6k
ピンチをチャンスに:未来をつくるプロダクトロードマップ #pmconf2020
aki_iinuma
126
53k
Templates, Plugins, & Blocks: Oh My! Creating the theme that thinks of everything
marktimemedia
31
2.5k
Principles of Awesome APIs and How to Build Them.
keavy
126
17k
Transcript
bitbankͷAWSΞΧ ϯτ࡞ཧज़ AWS DevDay 2019 ࠙ձLT @mdps513 ͬͨΜ
Service
࣍ • എܠ • ղܾ͢ΔͨΊʹͬͨ͜ͱ • ݁Ռ • ͜Ε͔Β
എܠ • AWS SSOΛ͍ͬͯΔ • ݱࡏฐࣾͰཧ͍ͯ͠ΔAWSΞΧϯτ60ݸ΄ͲͰຖ݄૿ ͍͑ͯΔ • ΞΧϯτ࡞ґཔ͕݄ʹ1,2݅,ଟ͍࣌ʹຖिඈΜͰ͘Δ •
ݱࡏAWSνʔϜ4໊ • ͦΕͧΕϓϩδΣΫτ͓࣋ͬͯΓɺΞΧϯτཧઐͷϓϩδΣ Ϋτͷਓ୭͍ͳ͍
ΞΧϯτ࡞࣌ͷϑϩʔ (ฐࣾͷྫ) 1. GlugentFlowͰਃ 2. ΞΧϯτ࡞ 3. CloudTrailઃఆ 4. AWS
Configઃఆ 5. GuardDutyઃఆ 6. Cost Visualizer ϩʔϧઃఆ 7. ΤϯλʔϓϥΠζαϙʔτՃೖ 8. Organaizational Unitઃఆ 9. RootΞΧϯτ෧ҹ 10. ݖݶ༩
ΞΧϯτ࡞࣌ͷϑϩʔ (ฐࣾͷྫ) 1. GlugentFlowͰਃ 2. ΞΧϯτ࡞ 3. CloudTrailઃఆ 4. AWS
Configઃఆ 5. GuardDutyઃఆ 6. Cost Visualizer ϩʔϧઃఆ 7. ΤϯλʔϓϥΠζαϙʔτՃೖ 8. Organaizational Unitઃఆ 9. RootΞΧϯτ෧ҹ 10. ݖݶ༩ ଟ͍͠໘͍͘͞ɻɻɻ (※ݸਓͷײͰ͢)
͜ΕͰΞΧϯτ࡞Ͱ͕Ε ͯ͠·͏…
ΞΧϯτ࡞࣌ͷϑϩʔ (ฐࣾͷྫ) • 1. GlugentFlowͰਃ • 2. ΞΧϯτ࡞ • 3.
organaizational Unitઃఆ • 4. CloudTrailઃఆ • 5. AWS Configઃఆ • 6. GuardDutyઃఆ • 7. Cost Visualizer ϩʔϧઃఆ • 8. ΤϯλʔϓϥΠζαϙʔτՃೖ • 9. RootΞΧϯτ෧ҹ • 10. ݖݶ༩ ͜͜ɺ ࣗಈԽͰ͖ͳ͍ʁ
ͦ͏ͩɺࣗಈԽ͠Α͏ɻ
ͬͨ͜ͱ ͦͷ1 ΞΧϯτ࡞ͱorganaizational Unitઃఆ • GlugentFlow͔Βਃ͕͋ͬͨΒ API Gateway͔ΒLambdaΛൃՐ • CreateAPI͕ୟ͔Εͯࣗಈతʹ࡞
͞ΕΔ • ͦͷޙదͳOrganizational Unit ʹৼΓ͚ΒΕΔ
ͬͨ͜ͱ ͦͷ2 CloudTrail, Config, GuardDuty,ͦ ͷଞϩʔϧઃఆ • Organizational
UnitʹՃ͞Ε ͨ࣌ͷCloudWatchEventsΛτ ϦΨʔ͠ɺLambdaΛൃՐ • CloudTrail,Config, GuardDuty ͳͲͷ֤छϩʔϧ CloudFormationStacksetsΛ༻ ͍֤ͯΞΧϯτʹઃఆΛө
ͦͷ2ͷStackSetsΛ༗ޮԽ͢Δ ࡍʹҙ͍ͯ͠Δ͜ͱ • ฐࣾͰϩάΛϩάऩू༻ͷS3 όέοτʹू͍ͯ͠Δ • ϩάΛ֘ͷS3ʹॻ͖ࠐΉͨΊ ʹΫϩεΞΧϯτͰͷόέο τϙϦγʔͷΞΫηεڐՄ͕ඞཁ •
LambdaͰOrganizationAPI͔Β ΞΧϯτΛऔಘͯ͠ stsAssumeRoleΛ༻͍ͯOUຖʹ S3policyUpdate
ͬͨ͜ͱ ͦͷ3 • ΤϯλʔϓϥΠζαϙʔτՃೖ • αϙʔτAPIΛLambdaͰൃՐ ͤͯ͞ΞΫςΟϕʔγϣϯґཔ
ͬͨ͜ͱ ͦͷ4 • StepFunctionͰͷ ϑϩʔ࡞
݁Ռ ࠓ·Ͱ3࣌ؒఔऔΒΕ͍ͯͨΞΧϯτ࡞࣌ ʹ͔͔Δ͕࣌ؒ30͘Β͍ʹઅͰ͖ͨ ຊདྷΔ͖͜ͱʹूதͰ͖ΔΑ͏ʹͳͬͨ ΞΧϯτ࡞ґཔ͕ා͘ͳ͘ͳͬͯ ͙ͬ͢ΓΕΔΑ͏ʹͳͬͨ
͜Ε͔Β • GuardDutyͷΞΧϯτ༗ޮԽΞΫςΟϕʔ γϣϯϑϩʔࣗಈԽ͍ͨ͠ • ࡞։࢝࣌ɺऴྃ࣌ɺΤϥʔ࣌ʹSlack௨Λ ͢ΔΑ͏ʹ͍ͨ͠
͍͞͝ʹ ϏοτόϯΫͰ AWSΤϯδχΞΛ ืू͍ͯ͠·͢ʂ
͓ΘΓ