AWS
Amazon Linux
Patched Kernel
RedHat Linux ϕʔε
ӡ༻ϊϋ͕͋Δ
grsecurity
fork bomb
restrict bind
Slide 20
Slide 20 text
AWS
؋ͷEC2Πϯελϯε
lxc ͰϚϧνςφϯτΛ࣮ݱ
Ruby ͱ PHP Λར༻Մೳ
Slide 21
Slide 21 text
00:06:00
Slide 22
Slide 22 text
1BB4ͷ࡞Γํ
4RBMFͷ߹
!IJCPNB
QBQFSCPZDP
Slide 23
Slide 23 text
3VCZίϯςφ
w /HJOY3VCZ 3BDLΞϓϦ
Λಈ͔ͤΔ-9$ڥ
w 3VCZʙͷ࠷৽ύονϨϕϧΛఏڙ
w TVQFSWJTPSEͰ/HJOYͱ3BDLΞϓϦΛࢹ
w 44)
$SPO༻Մ
w σϓϩΠ͢ΔͱCVOEMFJOTUBMM
BTTFUTQSFDPNQJMFͳͲΛ
ࣗಈͰߦ͍3BDLΞϓϦΛ࠶ىಈ͢Δ
ఏڙத
Slide 24
Slide 24 text
3VCZίϯςφ
w /HJOYQPSUOͰMJTUFO
w TTIEQPSUOͰMJTUFO
w Oίϯςφ͝ͱʹҰҙͷ
w OFUXPSLOBNFTQBDF༻͍ͯ͠ͳ͍
w ίϯςφͰ5$1QPSUͷCJOE
Λ੍ݶ͢Δύονͯͨ
Slide 25
Slide 25 text
1)1ίϯςφ
w "QBDIFQIQGQNΛಈ͔ͤΔ-9$ڥ
w
ܥΛఏڙ
w TVQFSWJTPSEͰ"QBDIFͱQIQGQNΛࢹ
w 44)
$SPO༻Մ
Slide 26
Slide 26 text
SPPUGT
w ίϯςφ༻ͷϑΝΠϧπϦʔΛSPPUGTͱݺΜͰ͍·͢
w શͯͷίϯςφͰNPVOU͢ΔσΟϨΫτϦπϦʔ
Slide 27
Slide 27 text
$ sudo yum --releasever=$ver --installroot=/var/rootfs/$role/ groupinstall Base
SPPUGTͷߏங
w 3VCZ
1)1ͦΕͧΕ༻ͷSPPUGT 㲈DISPPUڥ
Λ࡞Δ
ZVNJOTUBMMSPPUͰϕʔεΛ࡞Δ
SVCZDIFGTPMPೖΕΔ
DISPPUͯ͠DIFGTPMPͰϖνϖνͯ͠ߏங
ɾ/HJOYͱ͔"QBDIFͱ͔3VCZ
1)1Λ͍Εͯ͘
w ߏங࣌ʹMYDͷςϯϓϨʔτͬͯͳ͍
w ͓खຊͱͯ͠Կࢀর͠·ͨ͠
Slide 28
Slide 28 text
SPPUGT
w SPPUGTΛMYDTUBSUىಈ࣌ʹͱͯ͠NPVOUCJOE SP
ߋʹϢʔβྖҬ
ΛNPVOUCJOE
w ϢʔβྖҬҎ֎SFBEPOMZ FSSOPJT&30'4
Slide 29
Slide 29 text
Ϧιʔε੍ݶ
w 2ίϯςφͷ$16
ϝϞϦͷϦιʔε੍ݶ
w "DHSPVQDQVTFU
DHSPVQNFNPSZͰجຊ௨Γ
w MYDTUBSUͷઃఆϑΝΠϧʹهड़
w ಈతʹมߋ͢Δӡ༻ ·ͩ
͍ͯ͠ͳ͍
Slide 30
Slide 30 text
MYDTUBSUͷࢹ
w MYDTUBSUNPOJUͰࢹ
MYDTUBSU͕όάͰࢭ·ͬͨ͜ͱࠓΜॴ؍ଌͯ͠ແ͍
w ͘͝ॳظʹTVQFSWJTPSEͰࢹ͕ͯͨ͠
TVQFSWJTPSEΛఀࢭ͢ΔͱMYDTUBSU͕PSQIBOFE
ʹͳͬͯհͳͷͰNPOJUʹͨ͠
Slide 31
Slide 31 text
00:10:00
Slide 32
Slide 32 text
ϧʔςΟϯά
w ίϯςφΛ࡞ͬͯ࣍ʹߟ͑ͳ͍ͱ͍͚ͳ͍͜ͱ
w υϝΠϯཧͲ͏͢Δ
w )551
44)
(JU PWFS44)
ͰͲ͏ΞΫηεͤ͞Δ
w ϩʔυόϥϯαϦόʔεϓϩΩγΛհͯ͠ΞΫηε͍ͤͨ͞
w )5513FWFSTF1SPYZ
w 44)3FWFSTF1SPYZ
Slide 33
Slide 33 text
υϝΠϯཧ
w 3PVUFͰTRBMFKQυϝΠϯΛཧ
w $/".&Λ&-#ʹ͚͍ͯΔ
w
w ίϯςφ࡞ഁغͷλΠϛϯάͰ3PVUFͷ"1*Λୟ͘
ELB Proxy
CNAME: ruby-hiboma.sqale.jp
ruby-hiboma.sqale.jp. 0 IN CNAME proxy-lb001-******.ap-northeast-1.elb.amazonaws.com.
Route53
HTTP
DNS