Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
20250903_1つのAWSアカウントに複数システムがある環境におけるアクセス制御をABA...
Search
yhana
September 03, 2025
Technology
1.3k
3
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
20250903_1つのAWSアカウントに複数システムがある環境におけるアクセス制御をABACで実現.pdf
yhana
September 03, 2025
More Decks by yhana
See All by yhana
AWS Organizations 経験者向けAzure ガバナンス速習
yhana
0
28
AWS Organizations 新機能!マルチパーティ承認の紹介
yhana
1
1.4k
AWS re:Invent 2024 ふりかえり勉強会
yhana
0
1.1k
AWS IAM Identity Center を使わないマルチアカウントのユーザー管理
yhana
2
4.7k
Guard を利用した AWS Config ルール
yhana
0
1.2k
組織的なクラウド統制のはじめの一歩_20240529
yhana
0
1.2k
Azureの基本的な権限管理の勉強会
yhana
1
6.8k
組織的なクラウド統制のはじめの一歩
yhana
0
2.4k
失敗例から学ぶAWSセキュリティサービスの導入
yhana
1
15k
Other Decks in Technology
See All in Technology
2026TECHFRESH畢業分享會 - Lightning Talk - 打造精準高效的 MCP 設計模式與測試實務
line_developers_tw
PRO
0
870
自宅LLMの話
jacopen
1
460
2026TECHFRESH畢業分享會 - 原生還是跨平台? App 開發踩坑實錄
line_developers_tw
PRO
0
880
LLMと共に進化するプロセスを目指して
ymatsuwitter
13
4.1k
Claude Codeをどのように キャッチアップしているか
oikon48
12
6.5k
爆速でマルチプロダクトを立ち上げる時 事業・CTO目線で大事にしたい事
miyatakoji
0
100
就職⽀援サービスにおけるキャリアアドバイザーのシフトスケジューリング
recruitengineers
PRO
1
140
中期計画、2回作ってみた ~業務委託と正社員、両方の視点から~
demaecan
1
690
攻撃者視点で考えるDetection Engineering
cryptopeg
2
1.3k
失敗を資産に変えるClaude Code
shinyasaita
0
540
AIはどのように 組織のアジリティを変えるのか?
junki
1
500
AI駆動開発を通して感じた、 AI時代のデザイナーの役割変化
whisaiyo
1
1.1k
Featured
See All Featured
Exploring anti-patterns in Rails
aemeredith
3
400
WENDY [Excerpt]
tessaabrams
11
38k
Music & Morning Musume
bryan
47
7.2k
Beyond borders and beyond the search box: How to win the global "messy middle" with AI-driven SEO
davidcarrasco
3
160
What the history of the web can teach us about the future of AI
inesmontani
PRO
1
610
Dominate Local Search Results - an insider guide to GBP, reviews, and Local SEO
greggifford
PRO
0
190
Stop Working from a Prison Cell
hatefulcrawdad
274
21k
Save Time (by Creating Custom Rails Generators)
garrettdimon
PRO
32
3.4k
Become a Pro
speakerdeck
PRO
31
6k
Money Talks: Using Revenue to Get Sh*t Done
nikkihalliwell
0
250
Java REST API Framework Comparison - PWX 2021
mraible
34
9.4k
It's Worth the Effort
3n
188
29k
Transcript
ͭͷ"84ΞΧϯτʹ ෳγεςϜ͕͋Δڥʹ͓͚Δ ΞΫηε੍ޚΛ"#"$Ͱ࣮ݱ ZIBOB Ϋϥεϝιουגࣜձࣾ Ϋϥυࣄۀຊ෦
ࠓ͢͜ͱ ࣍ͷΑ͏ͳ "84ΞΧϯτʹରͯ͠ɺࣗͷϓϩδΣΫτʹؔ࿈͢ΔϦιʔ ε͚ͩૢ࡞Մೳʹ͢Δӡ༻ऀ͚ͷΞΫηε੍ޚͷํ๏Λհ͠·͢ʢ˞ʣ l ୯Ұ "84ΞΧϯτʹෳͷϓϩδΣΫτʢγεςϜʣ͕ࠞࡏ͢Δڥ l ΞΧϯτʹ୯ҰϓϩδΣΫτͷ߹Ͱෳͷؔձ͕ࣾؔ༩͢Δڥ
˞͋Δఔ *".ͷ͕ࣝ͋Δલఏͷ༰Ͱ͢
ࠓ͢͜ͱ "#"$ʢ"UUSJCVUF#BTFE"DDFTT$POUSPMɿଐੑϕʔεͷΞΫηε੍ޚʣΛ ར༻͢Δํ๏ͷհͰ͢ Ҿ༻ݩɿ"#"$ೝՄͰଐੑʹج͍ͮͯΞΫηεڐՄΛఆٛ͢Δ "84*EFOUJUZBOE"DDFTT.BOBHFNFOU
͘͡ l "84*".ʹ͓͚Δ "#"$ l "84*".*EFOUJUZ$FOUFSʹ͓͚Δ "#"$ l "#"$ͷ
5JQTςΫχοΫू
"84*".ʹ͓͚Δ "#"$
"84*".ͷ "#"$λάͰ੍ޚ *".ϢʔβʔͷλάͱϦιʔεͷλάͷҰகʹΑΓૢ࡞ͷڐՄ͕Մೳ
*".ϙϦγʔͷྫ { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow",
"Action": ["ec2:List*", "ec2:Describe*", "ec2:Get*"], "Resource": "*" }, { "Effect": "Allow", "Action": ["ec2:StartInstances", "ec2:StopInstances", "ec2:RebootInstances"], "Resource": "*", "Condition": { "StringEquals": { "aws:ResourceTag/Project": "${aws:PrincipalTag/Project}" } } } ] } 1SPKFDUλάͷͷҰகΑΓ &$Πϯελϯεͷىಈɾ ఀࢭΛڐՄ͢ΔϙϦγʔྫ
"84Ϛωδϝϯτίϯιʔϧ্ͷݟ͑ํ Ϛωδϝϯτίϯιʔϧ্Ͱ ࣗͷϓϩδΣΫτͰͳ͍ λά͕Ұக͠ͳ͍ &$ ΠϯελϯεΛఀࢭ͠Α͏ͱ ͨ͠ͱ͖ͷΤϥʔը໘
"#"$ͷϝϦοτ l ཧ͢ΔϙϦγʔ͕গͳ͘ͳΔ l ར༻ͷ֦େʹ߹Θͤͯεέʔϧ͍͢͠
*".ϢʔβʔͷλάΛར༻͢Δ߹ͷ՝ *".Ϣʔβʔʹରͯ͠ɺಉ͡ ,FZ໊ͷλά ͭͷΈͷઃఆͱͳΔͨΊɺ ෳϓϩδΣΫτʹؔ༩͍ͯ͠Δར༻ऀෳͷ *".Ϣʔβʔͷ͍͚ *".Ϣʔβʔͷ͍ճ͕͠ඞཁͱͳΔ
*".Ϣʔβʔͱ *".ϩʔϧΛΈ߹ͤͨํ๏ ղܾઌͱͯ͠ɺϓϩδΣΫτຖʹ *".ϩʔϧΛ༻ҙͯ͠ *".Ϣʔβʔ͔Β εΠονϩʔϧͯ͠ར༻͢Δํ๏͕͋Δ
*".Ϣʔβʔͱ *".ϩʔϧΛΈ߹ͤͨํ๏ *".ϩʔϧͷڐՄϙϦγʔ ɺ*".ϢʔβʔͷλάΛར༻͢Δ߹ͱಉ༷ʹ ڞ௨ͷ *".ϙϦγʔͰ࣮ݱ { "Version": "2012-10-17",
"Statement": [ { "Effect": "Allow", "Action": ["ec2:List*", "ec2:Describe*", "ec2:Get*"], "Resource": "*" }, { "Effect": "Allow", "Action": ["ec2:StartInstances", "ec2:StopInstances", "ec2:RebootInstances"], "Resource": "*", "Condition": { "StringEquals": { "aws:ResourceTag/Project": "${aws:PrincipalTag/Project}" } } } ] } ڐՄϙϦγʔ ৴པϙϦγʔ ڐՄϙϦγʔ ৴པϙϦγʔ
*".Ϣʔβʔͱ *".ϩʔϧΛΈ߹ͤͨํ๏ *".ϩʔϧͷ৴པϙϦγʔʹ͓͍ͯɺεΠονϩʔϧͰ͖ΔϢʔβʔΛ੍ݶ { "Version": "2012-10-17", "Statement": [ {
"Effect": "Allow", "Principal": { "AWS": [ "arn:aws:iam::111122223333:user/test-user", "arn:aws:iam::111122223333:user/test-user2" ] }, "Action": "sts:AssumeRole",} ] } ڐՄϙϦγʔ ৴པϙϦγʔ
"84ΞΧϯτͷߏ *".Ϣʔβʔͱ *".ϩʔϧಉҰ "84ΞΧϯτͰߏՄೳ
"84ΞΧϯτͷߏ *".Ϣʔβʔͱ *".ϩʔϧΛҟͳΔ "84ΞΧϯτͰߏՄೳ
*".ϢʔβʔΛҰݩཧ͢ΔΞΧϯτΛ࡞Δ߹ *".ϢʔβʔΛू͢ΔϢʔβʔཧΞΧϯτʢผ໊ɿ+VNQΞΧϯτʣ Λ࡞͢ΔϊϋࡢͷొஃࢿྉΛࢀর͍ͩ͘͞ IUUQTEFWDMBTTNFUIPEKQBSUJDMFT NVMUJBDDPVOUVTFSNBOBHFNFOU
"84*".*EFOUJUZ$FOUFSʹ͓͚Δ "#"$
"84*".*EFOUJUZ$FOUFSϢʔβʔଐੑΛར༻ ϢʔβʔͷଐੑΩʔͱΛ "#"$ʹར༻ʢར༻Ͱ͖Δଐੑʹ੍ݶ͋Γʣ
"84*".*EFOUJUZ$FOUFSϢʔβʔଐੑΛར༻ ϢʔβʔͷଐੑΩʔͱΛ "#"$ʹར༻ʢར༻Ͱ͖Δଐੑʹ੍ݶ͋Γʣ
"84*".*EFOUJUZ$FOUFSϢʔβʔଐੑΛར༻ *".*EFOUJUZ$FOUFSͷઃఆͰɺҙͷΩʔ໊ͷͱͯ͠ଐੑͷΛؔ࿈͚
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": ["ec2:List*",
"ec2:Describe*", "ec2:Get*"], "Resource": "*" }, { "Effect": "Allow", "Action": ["ec2:StartInstances", "ec2:StopInstances", "ec2:RebootInstances"], "Resource": "*", "Condition": { "StringEquals": { "aws:ResourceTag/Project": "${aws:PrincipalTag/Project}" } } } ] } "84*".*EFOUJUZ$FOUFSϢʔβʔଐੑΛར༻ ΞΫηεڐՄηοτʹؔ࿈͚ΔϙϦγʔͰ 1SPKFDUΩʔΛࢦఆ
ϢʔβʔͷଐੑΩʔΛར༻͢Δ߹ͷ՝ *".*EFOUJUZ$FOUFSϢʔβʔͷଐੑΩʔ͝ͱʹઃఆͰ͖Δ ͭͷΈ ͦͷͨΊɺෳϓϩδΣΫτʹؔ༩͢Δར༻ऀϓϩδΣΫτຖʹ࡞͞Εͨ Ϣʔβʔͷ͍͚Ϣʔβʔͷ͍ճ͕͠ඞཁͱͳΔ
ղܾઌͱͯ͠ɺ"#"$Ͱ੍ޚ͍ͨ͠ΞΧϯτʹ͓͍ͯɺϓϩδΣΫτຖʹ *".ϩʔϧΛ༻ҙͯ͠εΠονϩʔϧͯ͠ར༻͢Δํ๏͕͋Δ *".*EFOUJUZ$FOUFSͱ *".ϩʔϧΛΈ߹ͤͨํ๏
*".*EFOUJUZ$FOUFSͱ *".ϩʔϧΛΈ߹ͤͨํ๏ "84ΞΫηεϙʔλϧ͔ΒϚωδϝϯτίϯιʔϧͷը໘ભҠΠϝʔδ スイッチロール
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action":
"sts:AssumeRole", "Resource": "*" } ] } ΞΫηεڐՄηοτʹεΠονϩʔϧͰ͖ΔݖݶΛΞλον ΞΫηεڐՄηοτʹ Ξλον͢ΔϙϦγʔ *".*EFOUJUZ$FOUFSͱ *".ϩʔϧΛΈ߹ͤͨํ๏
લड़ͨ͠ *".ϢʔβʔϩʔϧͷλάΛ͏߹ͱ ಉ༷ͷϙϦγʔ *".ϩʔϧͷڐՄϙϦγʔɺ*".ϢʔβʔϩʔϧΛΈ߹Θͤͯ ར༻͢Δ߹ͱಉ͡ϙϦγʔͰ࣮ݱՄೳ ڐՄϙϦγʔ ৴པϙϦγʔ ڐՄϙϦγʔ ৴པϙϦγʔ
*".*EFOUJUZ$FOUFSͱ *".ϩʔϧΛΈ߹ͤͨํ๏
*".ϩʔϧͷ৴པϙϦγʔͰɺ1SJODJQBMʹΞΫηεڐՄηοτʹରԠ͢Δ *".ϩʔϧΛࢦఆ͠ɺ$POEJUJPOͰεΠονϩʔϧͰ͖ΔϢʔβʔΛ੍ޚ { "Version": "2012-10-17", "Statement": [ { "Effect":
"Allow", "Principal": { "AWS": "arn:aws:iam::111122223333:role/aws- reserved/sso.amazonaws.com/ap-northeast- 1/AWSReservedSSO_AssumeRoleOnlyAccess_22e9e155f6d2118f" }, "Action": "sts:AssumeRole", "Condition": { "StringLike": { "identitystore:UserId": [ ”aaaaaaaa-1111-aaaa-1111-aaaaaaaaaaaa", ”bbbbbbbb-2222-bbbb-2222-bbbbbbbbbbbb" ] } } } ڐՄϙϦγʔ ৴པϙϦγʔ *".*EFOUJUZ$FOUFSͱ *".ϩʔϧΛΈ߹ͤͨํ๏
*".*EFOUJUZ$FOUFSϢʔβʔʹଐੑใͷઃఆෆཁ *".*EFOUJUZ$FOUFSͱ *".ϩʔϧΛΈ߹ͤͨํ๏
"#"$ͷ 5JQTςΫχοΫू
"#"$ʹରԠ͍ͯ͠ΔαʔϏε͔ Ͳ͏͔ௐΔํ๏
"84ϢʔβʔΨΠυͰ "#"$ରԠ༗ແΛௐࠪ ֤αʔϏε͕ "#"$ʹରԠ͍ͯ͠Δ͔Ͳ͏͔ϢʔβʔΨΠυʹهࡌ͕͋Δ Ҿ༻ݩɿ*".ͱ࿈ܞ͢Δ "84ͷαʔϏε "84*EFOUJUZBOE"DDFTT.BOBHFNFOU
ϢʔβʔΨΠυʹϙϦγʔྫͷهࡌ͕͋Δ߹ αʔϏεʹΑͬͯϢʔβʔΨΠυʹ "#"$ͷϙϦγʔྫͷܝࡌ͋Δ Ҿ༻ݩɿଐੑϕʔεͷΞΫηε੍ޚ "#"$ Λ༻ͯ͠γʔΫϨοτͷΞΫηεΛ੍ޚ͢Δ "844FDSFUT.BOBHFS
ෳͷλάͷ݅Ͱ "#"$
ෳͷλάͷҰகʹΑΓ੍ޚ ෳͷλάΛ݅ͱ͢Δ͜ͱՄೳʢԼਤ ͭͷλάΛ݅ͱ͍ͯ͠Δྫʣ
ෳͷλάͷҰகʹΑΓ੍ޚ ෳͷλάΛ݅ͱ͢Δ͜ͱՄೳʢԼਤ ͭͷλάΛ݅ͱ͍ͯ͠Δྫʣ { "Version": "2012-10-17", "Statement": [ {
"Effect": "Allow", "Action": ["ec2:List*", "ec2:Describe*", "ec2:Get*"], "Resource": "*" }, { "Effect": "Allow", "Action": ["ec2:StartInstances", "ec2:StopInstances", "ec2:RebootInstances"], "Resource": "*", "Condition": { "StringEquals": { "aws:ResourceTag/Project": "${aws:PrincipalTag/Project}", "aws:ResourceTag/Environment": "${aws:PrincipalTag/Environment}" } } } ] } ڐՄϙϦγʔ ৴པϙϦγʔ
$POEJUJPOͷධՁϩδοΫ ෳͷ݅Ͱ࣮ݱ͍ͨ͠߹ɺ$POEJUJPOͷධՁϩδοΫΛߟྀͯ͠ઃܭ͢Δ Ҿ༻ݩɿෳͷίϯςΩετΩʔ·ͨʹΑΔ݅ "84*EFOUJUZBOE"DDFTT.BOBHFNFOU
"#"$Ͱ੍ޚ͢Δ "DUJPOΛ ϫΠϧυΧʔυͰࢦఆ
"DUJPOΛϫΠϧυΧʔυͰࢦఆՄೳ "DUJPOΛʮFD ʯͱهࡌͯ͠ରαʔϏεͷͯ͢ͷΞΫγϣϯΛؚΊΔ ϫΠϧυΧʔυࢦఆՄೳ { "Version": "2012-10-17", "Statement": [
{ "Effect": "Allow", "Action": ["ec2:List*", "ec2:Describe*", "ec2:Get*"], "Resource": "*" }, { "Effect": "Allow", "Action": "ec2:*", "Resource": "*", "Condition": { "StringEquals": { ”aws:ResourceTag/Project": "${aws:PrincipalTag/Project}" } } } ] } ڐՄϙϦγʔ ৴པϙϦγʔ ڐՄϙϦγʔ ৴པϙϦγʔ
ϫΠϧυΧʔυࢦఆͷཹҙ ϫΠϧυΧʔυࢦఆ༰қʹ࣮ݱͰ͖ΔҰํͰɺ༩͑ΔݖݶΛѲͮ͠Β͘ͳΔ ʹཹҙ͕ඞཁ l কདྷతʹՃ͞ΕΔ৽͍͠ΞΫγϣϯࣗಈతʹڐՄ͞ΕΔ l ༧ظ͠ͳ͍ΞΫγϣϯڐՄ͞ΕΔՄೳੑ͕͋Δ ◦ ྫ͑ɺʮFD
ʯʹ 71$ʹؔ͢Δݖݶؚ·Ε͍ͯΔ l BXT3FTPVSDF5BHΛαϙʔτ͍ͯ͠ͳ͍ "DUJPOͷ "MMPXڐՄ͞Εͳ͍ ◦ ྫ͑ɺʮFD$SFBUF7QDʯڐՄ͞Εͳ͍
4ͷ "#"$ ؔ࿈ϒϩάɿ*".ϩʔϧͷλάͷͱ 4όέοτ໊ͷ෦ҰகͰૢ࡞Ͱ͖Δ 4όέοτΛ੍ݶͯ͠Έͨ c%FWFMPQFST*0 ʲ"#"$ʳ4Ͱλάϕʔε੍ޚΛߦ͏ ੍ݶ͋Γ c%FWFMPQFST*0
4ͷ "#"$ରԠ෦త 4ͷ "#"$෦తͳରԠͰ͋Γɺ൚༻όέοτະαϙʔτɺΦϒδΣΫτ αϙʔτରͱͳΔ Ҿ༻ݩɿ*".ͱ࿈ܞ͢Δ "84ͷαʔϏε "84*EFOUJUZBOE"DDFTT.BOBHFNFOU
4ΦϒδΣΫτͷ "#"$ 4ΦϒδΣΫτຖͰλά͚͕Ͱ͖ɺΦϒδΣΫτͷλάΛར༻੍ͯ͠ޚՄೳ
4ΦϒδΣΫτͷ "#"$ 4ΦϒδΣΫτ୯ҐͰλά͚͕Ͱ͖ɺΦϒδΣΫτͷλάΛར༻ͯ͠ ΞΫηε੍ޚ͕Ͱ͖Δ ڐՄϙϦγʔ ৴པϙϦγʔ { "Version": "2012-10-17",
"Statement": [ { "Effect": "Allow", "Action": ["s3:List*", "s3:GetBucketLocation"], "Resource": "*" }, { "Effect": "Allow", "Action": "s3:*", "Resource": "*", "Condition": { "StringEquals": { "s3:ExistingObjectTag/Project": "${aws:PrincipalTag/Project}" } } } ] }
4ΦϒδΣΫτͷ "#"$ 4ΦϒδΣΫτͷ "#"$Ͱ BXTͷΘΓʹ TΛར༻ Ҿ༻ݩɿ"NB[PO4Ͱͷ *".ͷػೳ
"NB[PO4JNQMF4UPSBHF4FSWJDF
4ΦϒδΣΫτͷλά͚ͷ՝ 4ΦϒδΣΫτͷλά͚ʹؔͯ͠ɺ࣍ͷ༰͕՝ͱͳΔ͜ͱ͕͋Δ l ΦϒδΣΫτʹλά͚͢Δखؒ l ΦϒδΣΫτͷλά͚༗ྉ Ҿ༻ݩɿྉۚ "NB[PO4ʛ"84
4όέοτ໊Λར༻੍ͨ͠ޚ ସࡦͱͯ͠ʮ4όέοτ໊ʯʹ *".ϩʔϧͷ "#"$༻λάͷؚ͕·Εͯ ͍Δ͜ͱΛ݅ͱ੍ͨ͠ޚͷํ๏͕͋Δ
4όέοτ໊Λར༻੍ͨ͠ޚ *".ͷڐՄϙϦγʔʹ͓͍ͯɺ3FTPVSDFͰλάͷΛಈతʹࢀর όέοτ໊ʹλάͷؚ͕·ΕΔҐஔϦιʔε໋໊نଇʹґଘ ڐՄϙϦγʔ ৴པϙϦγʔ { "Version": "2012-10-17", "Statement":
[ { "Effect": "Allow", "Action": ["s3:List*", "s3:GetBucketLocation"], "Resource": "*" }, { "Effect": "Allow", "Action": "s3:*", "Resource": [ "arn:aws:s3:::*-${aws:PrincipalTag/Project}-*", "arn:aws:s3:::*-${aws:PrincipalTag/Project}-*/*" ] } ] }
4όέοτ໊Λར༻੍ͨ͠ޚ ൚༻όέοτͷϥΠϑαΠΫϧϧʔϧϓϩύςΟͷมߋՄೳ
λά͕༩͞Ε͍ͯΔϦιʔεͷΈ "#"$Ͱ੍ޚ͢Δํ๏ ؔ࿈ϒϩάɿ"NB[PO$MPVE8BUDIϩάάϧʔϓʹରͯ͠ "#"$༻λά͕͋Δ߹ "#"$ʹΑΓಡΈऔΓڐՄΛ੍ޚͯ͠ɺ"#"$༻ λά͕ͳ͍߹ಡΈऔΓΛڐՄ͢ΔϙϦγʔΛࢼͯ͠Έͨ c%FWFMPQFST*0
λά͕͋ΔϦιʔεͷΈ "#"$Ͱ੍ޚ͢Δํ๏ ͜Ε·Ͱհ͖ͯͨ͠ɺλάͷҰகͰΞΫγϣϯΛڐՄ͢ΔϙϦγʔͰɺ λά͕ͳ͍Ϧιʔεʹର͢Δૢ࡞ͷڐՄ༩͑ΒΕͳ͍
λά͕͋ΔϦιʔεͷΈ "#"$Ͱ੍ޚ͢Δํ๏ ҰํͰɺ$MPVE8BUDI-PHTͳͲͷαʔϏεʹ͓͍ͯɺಛʹอޢ͍ͨ͠Ϧιʔε ͷΈ "#"$Ͱ੍ޚ͍ͨ͠߹͋Δ
λά͕͋ΔϦιʔεͷΈ "#"$Ͱ੍ޚ͢Δํ๏ ಡΈऔΓݖݶ λά͕ଘࡏ͔ͭλά͕Ұக͠ͳ͍߹ʹ໌ࣔతͳ %FOZͱ͢Δ ͜ͱͰ࣮ݱՄೳ { "Version": "2012-10-17",
"Statement": [ { "Effect": "Deny", "Action": ["logs:Get*", "logs:FilterLogEvents", "logs:StartQuery", "logs:StopQuery", "logs:StartLiveTail", "logs:StopLiveTail", "logs:TestMetricFilter"], "Resource": "arn:aws:logs:*:*:log-group:*", "Condition": { "Null": { "aws:ResourceTag/Project": "false" }, "StringNotEquals": { "aws:ResourceTag/Project": "${aws:PrincipalTag/Project}" } } } ] } ڐՄϙϦγʔ ৴པϙϦγʔ ʮ$MPVE8BUDI-PHT3FBE0OMZ"DDFTTʯͷಡΈऔΓݖݶ
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Deny", "Action": ["logs:Get*",
"logs:FilterLogEvents", "logs:StartQuery", "logs:StopQuery", "logs:StartLiveTail", "logs:StopLiveTail", "logs:TestMetricFilter"], "Resource": "arn:aws:logs:*:*:log-group:*", "Condition": { "Null": { "aws:ResourceTag/Project": "false" }, "StringNotEquals": { "aws:ResourceTag/Project": "${aws:PrincipalTag/Project}" } } } ] } λά͕͋ΔϦιʔεͷΈ "#"$Ͱ੍ޚ͢Δํ๏ $POEJUJPOԼهͷ "OE͕݅ຬͨ͞Εͨ߹ʹ໌ࣔతʹ %FOZ l ରϦιʔεʹ 1SPKFDUλά͕ଘࡏ͢Δʢ/VMM USVFͰଘࡏ͠ͳ͍ʣ l 1SJODJQBM *".ϩʔϧ ͱରϦιʔεͷ 1SPKFDUλάͷ͕Ұக͠ͳ͍
λά͕͋ΔϦιʔεͷΈ "#"$Ͱ੍ޚ͢Δํ๏ ݖݶͷΠϝʔδਤ ಡΈऔΓΛڐՄ $MPVE8BUDI-PHT3FBE0OMZ"DDFTT "#"$Ͱ ໌ࣔతʹڋ൱
"#"$ͱڞʹ༻͍Δ ಡΈऔΓݖݶͷύλʔϯ
ಡΈऔΓݖݶͷ༩ύλʔϯ "#"$Ͱ੍ޚ͢ΔαʔϏεʹؔ͢ΔಡΈऔΓݖݶΛҰॹʹ༩͑Δඞཁ͕͋Δ ಡΈऔΓݖݶɺ࠷খݖݶͱ͢Δํ๏ "84ཧϙϦγʔΛར༻͢Δํ๏ͳͲ ͕͋Δ /P ํ๏ ݖݶͷ͞ ཧͷखؒ උߟ
ඞཁ࠷খݶͷΞΫγϣϯͷΈࢦఆ ࠷খ େ -JTU %FTDSJCF (FU୯ҐͰࢦఆ ݶఆత த /Pͱಉ༷ͱͳΔ͜ͱ͋Δ ֤αʔϏεʹରԠͨ͠ "84ཧϙϦγʔ ͷಡΈऔΓݖݶ ݶఆత খ "NB[PO&$3FBE0OMZ"DDFTT "84ཧϙϦγʔʮ3FBE0OMZ"DDFTTʯ Ҭ খ 4ΦϒδΣΫτΛμϯϩʔυͰ ͖Δݖݶؚ·ΕΔ
ඞཁ࠷খݶͷΞΫγϣϯͷΈࢦఆ ࠷খݖݶΛ࣮ݱͰ͖Δ͕ɺௐࠪʹख͕͔͔ؒΔɺϚωδϝϯτίϯιʔϧ্ Ͱݖݶ͕ແ͍Ӿཡʹର͢ΔΤϥʔϝοηʔδʹΑΓࢹೝੑ͕མͪΔ͕ݒ೦ { "Version": "2012-10-17", "Statement": [ { "Effect":
"Allow", "Action": "ec2:DescribeInstances", "Resource": "*" }, { "Effect": "Allow", "Action": ["ec2:StartInstances", "ec2:StopInstances", "ec2:RebootInstances"], "Resource": "*", "Condition": { "StringEquals": { "aws:ResourceTag/Project": "${aws:PrincipalTag/Project}" } } } ] }
-JTU %FTDSJCF (FU୯ҐͰࢦఆ -JTU %FTDSJCF (FUؔ࿈ΞΫγϣϯΛϫΠϧυΧʔυͰ·ͱΊͯڐՄ (FUܥΞΫγϣϯʹσʔλμϯϩʔυؚ͕·ΕΔ͜ͱ͋Δʹཁҙ { "Version":
"2012-10-17", "Statement": [ { "Effect": "Allow", "Action": ["ec2:List*", "ec2:Describe*", "ec2:Get*"], "Resource": "*" }, { "Effect": "Allow", "Action": ["ec2:StartInstances", "ec2:StopInstances", "ec2:RebootInstances"], "Resource": "*", "Condition": { "StringEquals": { "aws:ResourceTag/Project": "${aws:PrincipalTag/Project}" } } } ] } ࠷খݖݶͱൺֱͯ͠ɺӾཡ࣌ʹΤϥʔϝοηʔδ͕ දࣔ͞ΕΔ͜ͱগͳ͍
-JTU %FTDSJCF (FU୯ҐͰࢦఆ ಡΈऔΓݖݶʹؔ͢Δ -JTU %FTDSJCF (FUΞΫγϣϯͷ֬ೝɺ *".ϙϦγʔ࡞࣌ͷϙϦγʔΤσΟλʢϏδϡΞϧʣ͕ચ͍ग़͠ͷࢀߟʹͳΔ
֤αʔϏεʹରԠͨ͠ "84ཧϙϦγʔͷಡΈऔΓݖݶ "84ཧϙϦγʔͷ֤αʔϏεʹରԠͨ͠ಡΈऔΓݖݶΛར༻͢Δ͜ͱͰɺ ϙϦγʔͷϝϯςϯεΛ͢Δඞཁ͕ͳ͘ͳΔϝϦοτ͋Γ { "Version": "2012-10-17", "Statement": [
{ "Effect": "Allow", "Action": ["ec2:StartInstances", "ec2:StopInstances", "ec2:RebootInstances"], "Resource": "*", "Condition": { "StringEquals": { "aws:ResourceTag/Project": "${aws:PrincipalTag/Project}" } } } ] } "84ཧϙϦγʔʮ"NB[PO&$3FBE0OMZ"DDFTTʯ FDҎ֎ʹؔ࿈͢ΔαʔϏεͷ Ұ෦ΞΫγϣϯؚ·Ε͍ͯΔ l FMBTUJDMPBECBMBODJOH%FTDSJCF l DMPVEXBUDI-JTU.FUSJDT l DMPVEXBUDI(FU.FUSJD4UBUJTUJDT l DMPVEXBUDI%FTDSJCF l BVUPTDBMJOH%FTDSJCF
֤αʔϏεʹରԠͨ͠ "84ཧϙϦγʔͷಡΈऔΓݖݶ *".ϩʔϧʹΞλονͰ͖Δ *".ϙϦγʔͷ্ݶ ͷͨΊɺ ෳͷαʔϏεΛ ͭͷ *".ϩʔϧͰ੍ޚ͢Δ߹ʹཹҙ͕ඞཁ Ҿ༻ݩɿ*".ͱ
"84454ΫΥʔλ "84 *EFOUJUZBOE"DDFTT.BOBHFNFOU
"84ཧϙϦγʔʮ3FBE0OMZ"DDFTTʯ "84શମͷಡΈऔΓݖݶ͕ ͭͷϙϦγʔͰ࣮ݱͰ͖Δ͕ັྗ ҰํͰɺσʔλͷμϯϩʔυݖݶ͕Ұ෦ؚ·ΕͯΔʹཹҙ͕ඞཁ { "Version": "2012-10-17", "Statement": [
{ "Effect": "Allow", "Action": ["ec2:StartInstances", "ec2:StopInstances", "ec2:RebootInstances"], "Resource": "*", "Condition": { "StringEquals": { "aws:ResourceTag/Project": "${aws:PrincipalTag/Project}" } } } ] } "84ཧϙϦγʔʮ3FBE0OMZ"DDFTTʯ 4ΦϒδΣΫτͷμϯϩʔυͳͲɺ σʔλΛऔಘͰ͖Δݖݶ͕Ұ෦ؚ·ΕΔ "#"$Λಋೖ͢Δ "84ΞΧϯτͰɺ ෳγεςϜ͕ࠞࡏ͍ͯ͠Δ͜ͱ͕ଟ͍ ͨΊɺؔ࿈͠ͳ͍γεςϜͷσʔλ͕औ ಘͰ͖Δ͕ͳ͍͔ͷ֬ೝඞཁ
λάͷ༩ϛεͷݮɾੋਖ਼ ؔ࿈ϒϩάɿ"84ͷλάΤσΟλΛར༻ͯ͠ίετλάͷઃఆϛεͷमਖ਼طଘͷλάͷҰׅมߋΛࢼͯ͠Έͨ c%FWFMPQFST*0
λάΤσΟλʹΑΔλάͷੋਖ਼ λάΤσΟλػೳΛར༻ͯ͠ɺλά༩ϛεͷमਖ਼͕Մೳ ྫ͑ɺ1SPKFDUλάʹؔ͢ΔԼදͷΑ͏ͳεϖϧϛεͷੋਖ਼ʹཱͭ ޡͬͨλάͷΩʔ໊ ޡ͍ͬͯΔཧ༝ QSPKFDU 1͕খจࣈ 1SPKFU D͕ൈ͚͍ͯΔ
1SPKFUD Dͱ U͕ೖΕସΘ͍ͬͯΔ 1SPKFFDU F ͕ଟ͍ 1SPKFDUT ࠷ޙʹ T͕͍͍ͭͯΔ <1SPKFDU> ࠷ޙʹεϖʔε͕ೖ͍ͬͯΔ <1SPKFDU> ࠷ॳʹεϖʔε͕ೖ͍ͬͯΔ
λάΤσΟλʹΑΔλάͷੋਖ਼ λάͷΩʔ໊Λࢦఆ͢ΔՕॴͰεϖϧϛεͷλάΛ֬ೝͰ͖Δ
λάΤσΟλʹΑΔλάͷੋਖ਼Πϝʔδ ͦͷ··λάΤσΟλͰλάͷमਖ਼͕ՄೳʢෳϦιʔεͷҰׅมߋՄೳʣ ਖ਼͍͠λάΩʔ໊ͷλάΛՃ εϖϧϛεͷλάΩʔ໊ͷλάΛআ
λάΤσΟλʹΑΔλάͷੋਖ਼ͷࢀߟࢿྉ λάΤσΟλΛར༻ͨ͠λάͷΩʔ໊ͷमਖ਼ύλʔϯͷ͍͔ͭ͘ ϒϩάͰެ։த IUUQTEFWDMBTTNFUIPEKQBSUJDMFTNPEJGZ DPTUBMMPDBUJPOUBHTJOUBHFEJUPS
"840SHBOJ[BUJPOTͷλάϙϦγʔ "840SHBOJ[BUJPOTڥʹݶΔ͕ɺλάϙϦγʔʹΑΓλάͷඪ४Խ͕Մೳ λάΩʔͷେจࣈɾখจࣈͷ౷Ұλάͱͯ͠ೖྗͰ͖Δͷࢦఆ͕Մೳ
"840SHBOJ[BUJPOTͷλάϙϦγʔ "840SHBOJ[BUJPOTڥʹݶΔ͕ɺλάϙϦγʔʹΑΓλάͷඪ४Խ͕Մೳ λάΩʔͷେจࣈɾখจࣈͷ౷Ұλάͱͯ͠ೖྗͰ͖Δͷࢦఆ͕Մೳ 1SPKFDUΩʔʹؔͯ͠ɺ࣍ͷΑ͏ ͳೖྗ͕ઃఆͰ͖ͳ͘ͳΓɺ େจࣈখจࣈͷ౷Ұ͕Ͱ͖Δ l QSPKFDU l
130+&$5 l 130KFDU
"840SHBOJ[BUJPOTͷλάϙϦγʔ "840SHBOJ[BUJPOTڥʹݶΔ͕ɺλάϙϦγʔʹΑΓλάͷඪ४Խ͕Մೳ λάΩʔͷେจࣈɾখจࣈͷ౷Ұλάͱͯ͠ೖྗͰ͖Δͷࢦఆ͕Մೳ 1SPKFDUΩʔʹରͯ͠ɺࢦఆͨ͠ λάͷΈೖྗͰ͖ΔΑ͏ʹ͢Δ l XBGGMFT l NPDIJ
λάϙϦγʔʹΑΓ੍ݶ͞Εͨͱ͖ͷྫ ʮେจࣈنଇʯʹඇ४ڌʢ1͕খจࣈʣ ʮڐՄ͞ΕΔʯʹඇ४ڌ λάϙϦγʔʹΑΓλάͷߋ৽͕ڋ൱͞ΕͨࡍͷΤϥʔϝοηʔδ
+VNQΞΧϯτߏʹ͓͍ͯ εΠονϩʔϧͰ͖Δ *".ϩʔϧ "#"$Ͱ੍ޚ ؔ࿈ϒϩάɿ+VNQΞΧϯτߏʹ͓͍ͯ *".ϢʔβʔͷλάΛར༻ͨ͠ "#"$ʹΑΓ &$ΠϯελϯεͷىಈɾఀࢭڐՄΛ༩͑Δ c %FWFMPQFST*0
εΠονϩʔϧͰ͖Δ݅ "#"$Ͱ੍ޚ *".ϢʔβʔͰ "#"$༻ͷλάΛཧ͢Δલఏͷ߹ɺ *".Ϣʔβʔ͔ΒεΠονϩʔϧͰ͖Δ *".ϩʔϧͷڐՄʹ "#"$׆༻Մೳ
εΠονϩʔϧͰ͖Δ݅ "#"$Ͱ੍ޚ *".ϢʔβʔͷڐՄϙϦγʔʹ͓͚Δ TUT"TTVNF3PMFͷ $POEJUJPOʹɺ *".ϢʔβʔͷλάͱεΠονϩʔϧઌͷ *".ϩʔϧͷλάͷҰகΛؚΊΔ { "Version":
"2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "sts:AssumeRole", "Resource": "*", "Condition": { "StringEquals": { "iam:ResourceTag/Project": "${aws:PrincipalTag/Project}" } } } ] } ڐՄϙϦγʔ
"#"$ͷ͍͠ͱ͜Ζ ʢηΩϡϦςΟάϧʔϓͷ "#"$ʣ
ηΩϡϦςΟάϧʔϓͷ "#"$ ηΩϡϦςΟάϧʔϓͷઃఆมߋ "#"$Ͱ࣮ݱՄೳʢͰ͋Δ͕ʜʣ { "Version": "2012-10-17", "Statement": [
{ "Effect": "Allow", "Action": ["ec2:List*", "ec2:Describe*", "ec2:Get*"], "Resource": "*" }, { "Effect": "Allow", "Action": "ec2:*", "Resource": "*", "Condition": { "StringEquals": { "ec2:ResourceTag/Project": "${aws:PrincipalTag/Project}" } } } ] } ڐՄϙϦγʔ
ηΩϡϦςΟάϧʔϓͷ "#"$ Ϛωδϝϯτίϯιʔϧ্Ͱૢ࡞͢Δલఏʹ͓͍ͯɺ ϧʔϧͷՃɾআͰ͖Δ͕ɺมߋͰ͖ͳ͍ʢλάΛ͚Δ·Ͱʣ ηΩϡϦςΟάϧʔϓ <1SPKFDUXBGGMFT> Πϯόϯυϧʔϧ r 5$1ڐՄ
ηΩϡϦςΟάϧʔϓͷ "#"$ Ϛωδϝϯτίϯιʔϧ্Ͱૢ࡞͢Δલఏʹ͓͍ͯɺ ϧʔϧͷՃɾআͰ͖Δ͕ɺมߋͰ͖ͳ͍ʢλάΛ͚Δ·Ͱʣ ηΩϡϦςΟάϧʔϓ <1SPKFDUXBGGMFT> ηΩϡϦςΟάϧʔϓʹର͢Δ ΠϯόϯυϧʔϧͷՃՄೳ Πϯόϯυϧʔϧ
r 5$1ڐՄ Πϯόϯυϧʔϧ r 5$1ڐՄ
ηΩϡϦςΟάϧʔϓͷ "#"$ Ϛωδϝϯτίϯιʔϧ্Ͱૢ࡞͢Δલఏʹ͓͍ͯɺ ϧʔϧͷՃɾআͰ͖Δ͕ɺมߋͰ͖ͳ͍ʢλάΛ͚Δ·Ͱʣ ηΩϡϦςΟάϧʔϓ <1SPKFDUXBGGMFT> Πϯόϯυϧʔϧ r 5$1ڐՄ
Πϯόϯυϧʔϧʹର͢Δ ߋ৽ෆՄೳ Πϯόϯυϧʔϧ r 5$1ڐՄ ˠ
ηΩϡϦςΟάϧʔϓͷ "#"$ Ϛωδϝϯτίϯιʔϧ্Ͱૢ࡞͢Δલఏʹ͓͍ͯɺ ϧʔϧͷՃɾআͰ͖Δ͕ɺมߋͰ͖ͳ͍ʢλάΛ͚Δ·Ͱʣ ηΩϡϦςΟάϧʔϓ <1SPKFDUXBGGMFT> Πϯόϯυϧʔϧ r 5$1ڐՄ
Πϯόϯυϧʔϧʹର͢Δ ߋ৽ෆՄೳʢλά͕ͳ͍ͨΊʣ Πϯόϯυϧʔϧ r 5$1ڐՄ <λάͳ͠>
ηΩϡϦςΟάϧʔϓͷ "#"$ Ϛωδϝϯτίϯιʔϧ্Ͱૢ࡞͢Δલఏʹ͓͍ͯɺ ϧʔϧͷՃɾআͰ͖Δ͕ɺมߋͰ͖ͳ͍ʢλάΛ͚Δ·Ͱʣ ηΩϡϦςΟάϧʔϓ <1SPKFDUXBGGMFT> Πϯόϯυϧʔϧ r 5$1ڐՄ
<1SPKFDUXBGGMFT> λά͕͋Γɺ͕݅߹͍ͬͯΕ ߋ৽Մೳ Πϯόϯυϧʔϧ r 5$1ڐՄ <λάͳ͠>
ηΩϡϦςΟάϧʔϓͷ "#"$ Ϛωδϝϯτίϯιʔϧ্Ͱૢ࡞͢Δલఏʹ͓͍ͯɺ ϧʔϧͷՃɾআͰ͖Δ͕ɺมߋͰ͖ͳ͍ʢλάΛ͚Δ·Ͱʣ ηΩϡϦςΟάϧʔϓ <1SPKFDUXBGGMFT> Πϯόϯυϧʔϧ r 5$1ڐՄ
<1SPKFDUXBGGMFT> Πϯόϯυϧʔϧ r 5$1ڐՄ <λάͳ͠> ηΩϡϦςΟάϧʔϓʹର͢Δ ΠϯόϯυϧʔϧͷআՄೳ
ηΩϡϦςΟάϧʔϓͷ "#"$ "84Ϛωδϝϯτίϯιʔϧͷ࡞ۀͰϧʔϧՃͱಉ࣌ʹλάΛ༩Ͱ͖ͳ͍ ߦ୯ҐͰϧʔϧͷՃͰ͖Δ͕ɺλά༩͞Εͳ͍ λά͕ແ͚ΕมߋͰ͖ͳ͍
ηΩϡϦςΟάϧʔϓͷ "#"$ ϧʔϧΛՃͨ͠ޙʹλάΛ༩͢Δ͜ͱࣗମՄೳͰ͋Δ͕ɺ ͜ͷૢ࡞ߋ৽࡞ۀͳͷͰલड़ͨ͠ "#"$ͷϙϦγʔͰλάΛ༩Ͱ͖ͳ͍
*".ϩʔϧͷҰׅ࡞
*".ϩʔϧͷҰׅ࡞ "#"$ͰλάͷҟͳΔ *".ϩʔϧΛෳ࡞͢Δඞཁ͕͋Δ *".ϙϦγʔڞ༗ԽͰ͖ΔͨΊɺεΫϦϓτͳͲʹΑΓ *".ϩʔϧͷ࡞ ޮԽͰ͖Δ
*".ϩʔϧͷҰׅ࡞ ϓϩδΣΫτຖʹҟͳΔจࣈྻΛΠϯϓοτʹͯ͠ɺ*".ϩʔϧͷҰׅ࡞ खಈͰઃఆ͢Δ߹ͱൺͯɺλάͷઃఆϛεΛ͛ΔϝϦοτ͋Γ BBB CCC DDD ⋮ CJOTI ⋮
DSFBUFJBNSPMFTTI QSPKFDUTUYU JOQVU Ұׅ࡞
*".ϩʔϧͷҰׅ࡞࣌ͷߟྀ ҰํͰɺ৴པϙϦγʔ *".ϩʔϧຖʹҟͳΔ߹͋ΔͨΊɺҰׅ࡞࣌ $$P&ςετ༻ͷϢʔβʔΛԾͰࢦఆ͓ͯ͘͠ͷߟྀ͕ඞཁͱͳΔ ҙͱͯ͠ *".Ϣʔβʔ࣮ݱ͠ͳ͚Ε *".ϩʔϧͷ࡞ʹࣦഊ͢Δ
͍͞͝ʹ
͍͞͝ʹ ୯ҰΞΧϯτʹෳͷϓϩδΣΫτ͕ࠞࡏ͢Δڥʹ͓͚Δ ΞΫηε੍ޚΛ "#"$Ͱ࣮ݱ͢Δํ๏Λհ͠·ͨ͠ "#"$ศརͳҰํɺ͍͜ͳ͢ʹ *".ʹؔ͢ΔҰఆͷ͕ࣝඞཁͰ͢ 3#"$ͱΈ߹Θͤͨར༻ "84ΞΧϯτΛϓϩδΣΫτຖʹ͚ͯΞ Ϋηε੍ޚ͢Δํ๏͝ݕ౼͍ͩ͘͞
Pʢ·ͩ·ͩॻ͖͍ͨ͜ͱ͋ΔͷͰผͷػձʹΞτϓοτ͠·͢ʣ
͍͞͝ʹ ͍͞͝ʹ߹ΘͤͯಡΈ͍ͨࢿྉΛڞ༗͠·͢ IUUQTEFWDMBTTNFUIPEKQBSUJDMFTTIVUUZP EFWJPLBXBIBSBBCBD
None