recognition rate, and utilization rate among household accounting applications and asset management applications1 A division that creates services in cooperation with clients, mainly financial institutions. Developed "Mikatano" (a business DX service for small to medium local enterprises delivered through local financial institutions), "BANK APP" (a banking application), etc. A service that visualizes money that anyone can continue with ease. Introduces centralized management to household budgets and assets to let the user grasp money flow and the current state of the assets, thereby supporting the initial step in eliminating financial anxiety ・The number of paying customers exceeded 410,000 ・No. 1 satisfaction among cloud accounting softwares1 ・No. 1 share within SaaS payroll management2 A SaaS style platform for businesses that connects back office data of various kinds and thereby optimizes tedious tasks related to accounting, human resources and labour affairs, and legal affairs 1. Delegated research by Macromill, Inc. / Survey target and number of respondents: 1,034 household accounting app users and 1,034 asset management app users in their 20s to 60s / Survey period: Household accounting app - August 13, 2024 to August 14, 2024; Asset management app - August 13, 2024 to August 16, 2024 / Survey method: Internet research 1. July 2024, JustSystems Co., Ltd. Fastask survey (responses fewer than 30 excluded). 2. Source: ITR "ITR Market View:人事・給与・就業管理市場2025" Payroll Management Market - Less than 100 Employees: Sales Revenue and Share by Vendor (FY2022-FY2024 Forecast) Business Individuals Financial Institutions
services span across the B2B, B2C and other domains. POINT 出典元 : 株式会社マネーフォワード 会社紹介資料 Business Finance Home X Money Forward for Financial Institutions & Specific Services Digital Passbook & Easy Passbook
Outside AWS(On-Prem K8s): How can we assume an IAM Role securely? • Outside AWS: Solved by IAM Roles Anywhere • Inside AWS(EKS): Solved by EKS Pod Identity 👉 Outside AWS(On-Prem K8s): Solved by a combination of IAM Roles Anywhere + EKS Pod Identity ?
Identity developed by combinating IAM Roles Anywhere and EKS Pod Identity • IAM Roles Anywhere ◦ Provides a way to get temporary credentials for a workload or process that runs outside of AWS, which means we can get around the limitation of EKS Pod Identity(work on EKS). • EKS Pod Identity ◦ Allows Kubernetes pods running on EKS to securely access AWS services by assigning IAM roles to pods.
Money Forward, Inc. (2024 Apr ~) • sig-etcd member (since 2025 Oct ~) Other Notes: • Hobby: Anime • Current obsession: LE SSERAFIM 🍝 X ID: @88888888_kota
Role credentials to Pods running on EKS. • Simplifies IAM Role assignment compared to older methods (IRSA/OIDC). • Components: ◦ EKS Pod Identity Webhook ◦ EKS Pod Identity Agent
file containing the JWT token for pod authentication • AWS_CONTAINER_CREDENTIALS_FULL_URI ◦ Specifies the endpoint (http://169.254.170.23/v1/credentials) of the EKS Pod Identity Agent ▪ 169.254.170.23: link local address for the agent
the JWT token for pod authentication • AWS_CONTAINER_CREDENTIALS_FULL_URI ◦ Specifies the endpoint (http://169.254.170.23/v1/credentials) of the EKS Pod Identity Agent AWS SDK calls (2) with the JWT Token in (1) for retrieving the credentials from EKS Pod Identity Agent
the credentials by AssumeRoleForPodIdentity API • Deamonset • Endpoint: GET http://169.254.170.23/v1/credentials • Header: Authorization: [JTW Token] • Main logic: GetIamCredentials
with specific label custom-pod-identity.example.com/enabled: “true” • Generates certificate signed by internal CA, which is the trust anchor in IAM Roles Anywhere • Creates secret in target namespaces