Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
bitbankのAWSアカウント作成管理術
Search
やったん
October 04, 2019
Technology
0
890
bitbankのAWSアカウント作成管理術
AWS DevDay 2019 懇親会でLTした時の資料です。
やったん
October 04, 2019
Tweet
Share
More Decks by やったん
See All by やったん
Fargate + ECR で elastalertを構築
mdps513
4
1.6k
Other Decks in Technology
See All in Technology
I tried making a solo advent calendar!
zzzzico
0
130
投資戦略を量産せよ 2 - マケデコセミナー(2025/12/26)
gamella
1
610
Authlete で実装する MCP OAuth 認可サーバー #CIMD の実装を添えて
watahani
0
410
20251225_たのしい出張報告&IgniteRecap!
ponponmikankan
0
110
迷わない!AI×MCP連携のリファレンスアーキテクチャ完全ガイド
cdataj
0
250
AWS re:Invent 2025 を振り返る
kazzpapa3
2
110
CQRS/ESになぜアクターモデルが必要なのか
j5ik2o
0
630
2025年のデザインシステムとAI 活用を振り返る
leveragestech
0
700
プロンプトエンジニアリングを超えて:自由と統制のあいだでつくる Platform × Context Engineering
yuriemori
0
160
2025年 山梨の技術コミュニティを振り返る
yuukis
0
150
「アウトプット脳からユーザー価値脳へ」がそんなに簡単にできたら苦労しない #RSGT2026
aki_iinuma
8
4k
Claude Codeを使った情報整理術
knishioka
20
12k
Featured
See All Featured
What's in a price? How to price your products and services
michaelherold
246
13k
A better future with KSS
kneath
240
18k
How to Think Like a Performance Engineer
csswizardry
28
2.4k
AI Search: Implications for SEO and How to Move Forward - #ShenzhenSEOConference
aleyda
1
1.1k
Beyond borders and beyond the search box: How to win the global "messy middle" with AI-driven SEO
davidcarrasco
0
34
YesSQL, Process and Tooling at Scale
rocio
174
15k
Technical Leadership for Architectural Decision Making
baasie
0
200
Ethics towards AI in product and experience design
skipperchong
1
160
Visualizing Your Data: Incorporating Mongo into Loggly Infrastructure
mongodb
48
9.8k
Crafting Experiences
bethany
0
25
A Soul's Torment
seathinner
2
2.1k
Let's Do A Bunch of Simple Stuff to Make Websites Faster
chriscoyier
508
140k
Transcript
bitbankͷAWSΞΧ ϯτ࡞ཧज़ AWS DevDay 2019 ࠙ձLT @mdps513 ͬͨΜ
Service
࣍ • എܠ • ղܾ͢ΔͨΊʹͬͨ͜ͱ • ݁Ռ • ͜Ε͔Β
എܠ • AWS SSOΛ͍ͬͯΔ • ݱࡏฐࣾͰཧ͍ͯ͠ΔAWSΞΧϯτ60ݸ΄ͲͰຖ݄૿ ͍͑ͯΔ • ΞΧϯτ࡞ґཔ͕݄ʹ1,2݅,ଟ͍࣌ʹຖिඈΜͰ͘Δ •
ݱࡏAWSνʔϜ4໊ • ͦΕͧΕϓϩδΣΫτ͓࣋ͬͯΓɺΞΧϯτཧઐͷϓϩδΣ Ϋτͷਓ୭͍ͳ͍
ΞΧϯτ࡞࣌ͷϑϩʔ (ฐࣾͷྫ) 1. GlugentFlowͰਃ 2. ΞΧϯτ࡞ 3. CloudTrailઃఆ 4. AWS
Configઃఆ 5. GuardDutyઃఆ 6. Cost Visualizer ϩʔϧઃఆ 7. ΤϯλʔϓϥΠζαϙʔτՃೖ 8. Organaizational Unitઃఆ 9. RootΞΧϯτ෧ҹ 10. ݖݶ༩
ΞΧϯτ࡞࣌ͷϑϩʔ (ฐࣾͷྫ) 1. GlugentFlowͰਃ 2. ΞΧϯτ࡞ 3. CloudTrailઃఆ 4. AWS
Configઃఆ 5. GuardDutyઃఆ 6. Cost Visualizer ϩʔϧઃఆ 7. ΤϯλʔϓϥΠζαϙʔτՃೖ 8. Organaizational Unitઃఆ 9. RootΞΧϯτ෧ҹ 10. ݖݶ༩ ଟ͍͠໘͍͘͞ɻɻɻ (※ݸਓͷײͰ͢)
͜ΕͰΞΧϯτ࡞Ͱ͕Ε ͯ͠·͏…
ΞΧϯτ࡞࣌ͷϑϩʔ (ฐࣾͷྫ) • 1. GlugentFlowͰਃ • 2. ΞΧϯτ࡞ • 3.
organaizational Unitઃఆ • 4. CloudTrailઃఆ • 5. AWS Configઃఆ • 6. GuardDutyઃఆ • 7. Cost Visualizer ϩʔϧઃఆ • 8. ΤϯλʔϓϥΠζαϙʔτՃೖ • 9. RootΞΧϯτ෧ҹ • 10. ݖݶ༩ ͜͜ɺ ࣗಈԽͰ͖ͳ͍ʁ
ͦ͏ͩɺࣗಈԽ͠Α͏ɻ
ͬͨ͜ͱ ͦͷ1 ΞΧϯτ࡞ͱorganaizational Unitઃఆ • GlugentFlow͔Βਃ͕͋ͬͨΒ API Gateway͔ΒLambdaΛൃՐ • CreateAPI͕ୟ͔Εͯࣗಈతʹ࡞
͞ΕΔ • ͦͷޙదͳOrganizational Unit ʹৼΓ͚ΒΕΔ
ͬͨ͜ͱ ͦͷ2 CloudTrail, Config, GuardDuty,ͦ ͷଞϩʔϧઃఆ • Organizational
UnitʹՃ͞Ε ͨ࣌ͷCloudWatchEventsΛτ ϦΨʔ͠ɺLambdaΛൃՐ • CloudTrail,Config, GuardDuty ͳͲͷ֤छϩʔϧ CloudFormationStacksetsΛ༻ ͍֤ͯΞΧϯτʹઃఆΛө
ͦͷ2ͷStackSetsΛ༗ޮԽ͢Δ ࡍʹҙ͍ͯ͠Δ͜ͱ • ฐࣾͰϩάΛϩάऩू༻ͷS3 όέοτʹू͍ͯ͠Δ • ϩάΛ֘ͷS3ʹॻ͖ࠐΉͨΊ ʹΫϩεΞΧϯτͰͷόέο τϙϦγʔͷΞΫηεڐՄ͕ඞཁ •
LambdaͰOrganizationAPI͔Β ΞΧϯτΛऔಘͯ͠ stsAssumeRoleΛ༻͍ͯOUຖʹ S3policyUpdate
ͬͨ͜ͱ ͦͷ3 • ΤϯλʔϓϥΠζαϙʔτՃೖ • αϙʔτAPIΛLambdaͰൃՐ ͤͯ͞ΞΫςΟϕʔγϣϯґཔ
ͬͨ͜ͱ ͦͷ4 • StepFunctionͰͷ ϑϩʔ࡞
݁Ռ ࠓ·Ͱ3࣌ؒఔऔΒΕ͍ͯͨΞΧϯτ࡞࣌ ʹ͔͔Δ͕࣌ؒ30͘Β͍ʹઅͰ͖ͨ ຊདྷΔ͖͜ͱʹूதͰ͖ΔΑ͏ʹͳͬͨ ΞΧϯτ࡞ґཔ͕ා͘ͳ͘ͳͬͯ ͙ͬ͢ΓΕΔΑ͏ʹͳͬͨ
͜Ε͔Β • GuardDutyͷΞΧϯτ༗ޮԽΞΫςΟϕʔ γϣϯϑϩʔࣗಈԽ͍ͨ͠ • ࡞։࢝࣌ɺऴྃ࣌ɺΤϥʔ࣌ʹSlack௨Λ ͢ΔΑ͏ʹ͍ͨ͠
͍͞͝ʹ ϏοτόϯΫͰ AWSΤϯδχΞΛ ืू͍ͯ͠·͢ʂ
͓ΘΓ