Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
bitbankのAWSアカウント作成管理術
Search
Sponsored
·
Your Podcast. Everywhere. Effortlessly.
Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.
→
やったん
October 04, 2019
Technology
890
0
Share
bitbankのAWSアカウント作成管理術
AWS DevDay 2019 懇親会でLTした時の資料です。
やったん
October 04, 2019
More Decks by やったん
See All by やったん
Fargate + ECR で elastalertを構築
mdps513
4
1.6k
Other Decks in Technology
See All in Technology
自動テストだけで リリース判断できるチームへ - 鍵はテストの量ではなくリリース判断基準の再設計にあった / Redesigning Release Criteria for Lightweight Releases
ewa
7
3.6k
AI 時代の Platform Engineering
recruitengineers
PRO
1
130
Vision Banana: Image Generators are Generalist Vision Learners
kzykmyzw
0
330
生成AIはソフトウェア開発の革命か、ソフトウェア工学の宿題再提出なのか -ソフトウェア品質特性の追加提案-
kyonmm
PRO
2
870
Swift Sequence の便利 API 再発見
treastrain
1
230
なぜ、私がCommunity Builderに?〜活動期間1か月半でも選出されたワケ〜
yama3133
0
110
React 19×Rustツール 進化の「ズレ」を設計で埋める
remrem0090
1
110
Sociotechnical Architecture Reviews: Understanding Teams, not just Artefacts
ewolff
1
160
ブラウザの投機的読み込みと投機ルールAPIを理解し、Webサービスのパフォーマンスを最適化する
shuta13
3
300
要件定義の精度を高めるための型と生成AIの活用 / Using Types and Generative AI to Improve the Accuracy of Requirements Definition
haru860
0
310
「QA=テスト」「シフトレフト=スクラムイベントの参加者の一員」の呪縛を解く。アジャイルな開発を止めないために、10Xで挑んだ「右側のしわ寄せ」解消記 #scrumniigata
nihonbuson
PRO
4
960
Modernizing Your HCL Connections Experience: Visual Report to chain, Profile Enhancements, and AI Integration
wannesrams
0
290
Featured
See All Featured
Digital Projects Gone Horribly Wrong (And the UX Pros Who Still Save the Day) - Dean Schuster
uxyall
0
1.3k
Automating Front-end Workflow
addyosmani
1370
200k
A designer walks into a library…
pauljervisheath
211
24k
SEO Brein meetup: CTRL+C is not how to scale international SEO
lindahogenes
1
2.6k
Connecting the Dots Between Site Speed, User Experience & Your Business [WebExpo 2025]
tammyeverts
11
910
Making Projects Easy
brettharned
120
6.6k
Accessibility Awareness
sabderemane
1
110
Odyssey Design
rkendrick25
PRO
2
610
How to audit for AI Accessibility on your Front & Back End
davetheseo
0
360
The Limits of Empathy - UXLibs8
cassininazir
1
320
ピンチをチャンスに:未来をつくるプロダクトロードマップ #pmconf2020
aki_iinuma
128
55k
The Power of CSS Pseudo Elements
geoffreycrofte
82
6.2k
Transcript
bitbankͷAWSΞΧ ϯτ࡞ཧज़ AWS DevDay 2019 ࠙ձLT @mdps513 ͬͨΜ
Service
࣍ • എܠ • ղܾ͢ΔͨΊʹͬͨ͜ͱ • ݁Ռ • ͜Ε͔Β
എܠ • AWS SSOΛ͍ͬͯΔ • ݱࡏฐࣾͰཧ͍ͯ͠ΔAWSΞΧϯτ60ݸ΄ͲͰຖ݄૿ ͍͑ͯΔ • ΞΧϯτ࡞ґཔ͕݄ʹ1,2݅,ଟ͍࣌ʹຖिඈΜͰ͘Δ •
ݱࡏAWSνʔϜ4໊ • ͦΕͧΕϓϩδΣΫτ͓࣋ͬͯΓɺΞΧϯτཧઐͷϓϩδΣ Ϋτͷਓ୭͍ͳ͍
ΞΧϯτ࡞࣌ͷϑϩʔ (ฐࣾͷྫ) 1. GlugentFlowͰਃ 2. ΞΧϯτ࡞ 3. CloudTrailઃఆ 4. AWS
Configઃఆ 5. GuardDutyઃఆ 6. Cost Visualizer ϩʔϧઃఆ 7. ΤϯλʔϓϥΠζαϙʔτՃೖ 8. Organaizational Unitઃఆ 9. RootΞΧϯτ෧ҹ 10. ݖݶ༩
ΞΧϯτ࡞࣌ͷϑϩʔ (ฐࣾͷྫ) 1. GlugentFlowͰਃ 2. ΞΧϯτ࡞ 3. CloudTrailઃఆ 4. AWS
Configઃఆ 5. GuardDutyઃఆ 6. Cost Visualizer ϩʔϧઃఆ 7. ΤϯλʔϓϥΠζαϙʔτՃೖ 8. Organaizational Unitઃఆ 9. RootΞΧϯτ෧ҹ 10. ݖݶ༩ ଟ͍͠໘͍͘͞ɻɻɻ (※ݸਓͷײͰ͢)
͜ΕͰΞΧϯτ࡞Ͱ͕Ε ͯ͠·͏…
ΞΧϯτ࡞࣌ͷϑϩʔ (ฐࣾͷྫ) • 1. GlugentFlowͰਃ • 2. ΞΧϯτ࡞ • 3.
organaizational Unitઃఆ • 4. CloudTrailઃఆ • 5. AWS Configઃఆ • 6. GuardDutyઃఆ • 7. Cost Visualizer ϩʔϧઃఆ • 8. ΤϯλʔϓϥΠζαϙʔτՃೖ • 9. RootΞΧϯτ෧ҹ • 10. ݖݶ༩ ͜͜ɺ ࣗಈԽͰ͖ͳ͍ʁ
ͦ͏ͩɺࣗಈԽ͠Α͏ɻ
ͬͨ͜ͱ ͦͷ1 ΞΧϯτ࡞ͱorganaizational Unitઃఆ • GlugentFlow͔Βਃ͕͋ͬͨΒ API Gateway͔ΒLambdaΛൃՐ • CreateAPI͕ୟ͔Εͯࣗಈతʹ࡞
͞ΕΔ • ͦͷޙదͳOrganizational Unit ʹৼΓ͚ΒΕΔ
ͬͨ͜ͱ ͦͷ2 CloudTrail, Config, GuardDuty,ͦ ͷଞϩʔϧઃఆ • Organizational
UnitʹՃ͞Ε ͨ࣌ͷCloudWatchEventsΛτ ϦΨʔ͠ɺLambdaΛൃՐ • CloudTrail,Config, GuardDuty ͳͲͷ֤छϩʔϧ CloudFormationStacksetsΛ༻ ͍֤ͯΞΧϯτʹઃఆΛө
ͦͷ2ͷStackSetsΛ༗ޮԽ͢Δ ࡍʹҙ͍ͯ͠Δ͜ͱ • ฐࣾͰϩάΛϩάऩू༻ͷS3 όέοτʹू͍ͯ͠Δ • ϩάΛ֘ͷS3ʹॻ͖ࠐΉͨΊ ʹΫϩεΞΧϯτͰͷόέο τϙϦγʔͷΞΫηεڐՄ͕ඞཁ •
LambdaͰOrganizationAPI͔Β ΞΧϯτΛऔಘͯ͠ stsAssumeRoleΛ༻͍ͯOUຖʹ S3policyUpdate
ͬͨ͜ͱ ͦͷ3 • ΤϯλʔϓϥΠζαϙʔτՃೖ • αϙʔτAPIΛLambdaͰൃՐ ͤͯ͞ΞΫςΟϕʔγϣϯґཔ
ͬͨ͜ͱ ͦͷ4 • StepFunctionͰͷ ϑϩʔ࡞
݁Ռ ࠓ·Ͱ3࣌ؒఔऔΒΕ͍ͯͨΞΧϯτ࡞࣌ ʹ͔͔Δ͕࣌ؒ30͘Β͍ʹઅͰ͖ͨ ຊདྷΔ͖͜ͱʹूதͰ͖ΔΑ͏ʹͳͬͨ ΞΧϯτ࡞ґཔ͕ා͘ͳ͘ͳͬͯ ͙ͬ͢ΓΕΔΑ͏ʹͳͬͨ
͜Ε͔Β • GuardDutyͷΞΧϯτ༗ޮԽΞΫςΟϕʔ γϣϯϑϩʔࣗಈԽ͍ͨ͠ • ࡞։࢝࣌ɺऴྃ࣌ɺΤϥʔ࣌ʹSlack௨Λ ͢ΔΑ͏ʹ͍ͨ͠
͍͞͝ʹ ϏοτόϯΫͰ AWSΤϯδχΞΛ ืू͍ͯ͠·͢ʂ
͓ΘΓ