Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
AWS IAM の知っておくべき話と知らなくてもいい話 DevIO2023/ AWS IAM DevIO 2023
Search
YukihiroChiba
July 27, 2023
0
3k
AWS IAM の知っておくべき話と知らなくてもいい話 DevIO2023/ AWS IAM DevIO 2023
YukihiroChiba
July 27, 2023
Tweet
Share
More Decks by YukihiroChiba
See All by YukihiroChiba
AWS IAM の結果整合性を避けるためセッションポリシーを用いてポリシーの動作確認を行う、を解説する
yukihirochiba
0
510
SSMエージェントはIAMロールの夢を見るか/ Do SSM Agents Dream Of IAM Roles?
yukihirochiba
0
1.7k
デジタルアイデンティティWGミニウェビナー第4回「IaaSとアイデンティティ」/ jnsa-iaas-identity
yukihirochiba
0
590
学習エンジンがうなりを上げているチームの作り方 / How to build a team with a learning engine humming along
yukihirochiba
0
3.6k
Amazon Route 53 Application Recovery Controller zonal shift 試してみた
yukihirochiba
0
1.5k
re:Growth 2022 Amazon Verified Permissions/妄想を膨らませる_チバユキ
yukihirochiba
0
4.5k
どこで動いてるの?AWS IAM のコントロールプレーンとデータプレーンに思いを馳せる/iam-background
yukihirochiba
0
4.2k
ここが好きだよAWS管理ポリシー_devio2022/i_am_iam_lover
yukihirochiba
0
4.8k
AWS Service Namespace を流行らせたい/ AWS Service Namespace to become popular
yukihirochiba
0
2k
Featured
See All Featured
Mobile First: as difficult as doing things right
swwweet
217
8.6k
Visualizing Your Data: Incorporating Mongo into Loggly Infrastructure
mongodb
34
8.9k
Why Our Code Smells
bkeepers
PRO
331
56k
[RailsConf 2023] Rails as a piece of cake
palkan
27
4k
"I'm Feeling Lucky" - Building Great Search Experiences for Today's Users (#IAC19)
danielanewman
222
21k
Code Reviewing Like a Champion
maltzj
515
39k
Large-scale JavaScript Application Architecture
addyosmani
504
110k
Design by the Numbers
sachag
274
18k
Designing for humans not robots
tammielis
248
25k
I Don’t Have Time: Getting Over the Fear to Launch Your Podcast
jcasabona
22
1.6k
Designing with Data
zakiwarfel
96
4.8k
Designing Dashboards & Data Visualisations in Web Apps
destraynor
226
51k
Transcript
"84*".ͷ͓͖ͬͯ͘ͱ Βͳ͍͍ͯ͘ "84ࣄۀຊ෦νόϢΩ
ࣗݾհ ઍ༿ (νόϢΩ) •2020ೖࣾ •͖ͳAWSαʔϏεɿIAM •͖ͳΞΫγϣϯɿsts:AssumeRole IUUQTEFWDMBTTNFUIPEKQBVUIPSDIJCBZVLJIJSP
ࠓͷҙؾࠐΈ w ͜ͷ࣌ؒʮνϣʔΫτʔΫʯͰ͢ w Θ͕ͨ͠ҰํతʹΔͷͰͳ͘ɺͥͻํͰΓऔΓ͠·͠ΐ͏ w །Ұͷਖ਼ղ͕͋ΔͷͰ͋Γ·ͤΜ w ʮΈΜͳͲ͏ͯ͠ΔΜͩΖ͏ʯΛڞ༗ͨ͠Γ
w ʮͲ͏͢Δͷ͕ΑΓྑ͍ͩΖ͏ʯΛҰॹʹߟ͑ͨΓ͠·͠ΐ͏
ࠓͷ͓ଋ w Έͳ͞Μʹݺͼ͔͚͍ͨ͜ͱ͕͋Δ߹ɺεϥ Πυͷӈ্ʹ͜Μͳͷ͕ग़͖ͯ·͢ ํλΠϜ w ڍखɺεέονϒοΫͷॻ͖ࠐΈɺϚΠΫͰͷ ൃݴͳͲɺํͰΓऔΓ͍ͨ͠ͷͰ͝ڠྗ ͓ئ͍͠·͢
ͬͦͬͯ͘͞ΈΑ͏ ํλΠϜ Έͳ͞Μͷ*".ϨϕϧΛڭ͍͑ͯͩ͘͞ɻ *".Λ৮ͬͨ͜ͱ͕ͳ͍ *".ϢʔβʔɺάϧʔϓɺϩʔϧɺϙϦγʔΛ͍ͬͯΔ *".ϦιʔεΛઃܭ͋Δ͍ߏஙͨ͜͠ͱ͕͋Δ
4$1͘͠1FSNJTTJPOTCPVOEBSZΛͬͨ͜ͱ͕͋Δ ηογϣϯϙϦγʔΛͬͨ͜ͱ͕͋Δ εέονϒοΫʹࣈΛॻ͍͍ͯͩ͘͞
͞ΒʹͬͯΈΑ͏ ํλΠϜ ྡͷ੮ͷਓͱ؆୯ͳࣗݾհͱ ʮࠓԿΛֶͼ͍͔ͨʯΛ͠·͠ΐ͏ ʢͻͱΓͣͭʣ
ࠓͷςʔϚ
ࠓͷςʔϚ *".ઃܭͷʢߏɺݖݶͷ࣋ͨͤํʣ *".ϕετϓϥΫςΟεͷ ධՁཧͷ σʔλϓϨʔϯͱίϯτϩʔϧϓϨʔϯͷ
ࠓͷςʔϚ *".ઃܭͷʢߏɺݖݶͷ࣋ͨͤํʣ *".ϕετϓϥΫςΟεͷ ධՁཧͷ σʔλϓϨʔϯͱίϯτϩʔϧϓϨʔϯͷ
্͔Βॱʹʮ͓͖ͬͯ͘ʯ͕ߴ͍ Լ͔Βॱʹʮ͠ΌΓ͍ͨʯ͕ߴ͍ ͓͖ͬͯ͘ ͠ΌΓ͍ͨ
ࠓͷςʔϚ *".ઃܭͷʢߏɺݖݶͷ࣋ͨͤํʣ *".ϕετϓϥΫςΟεͷ ධՁཧͷ σʔλϓϨʔϯͱίϯτϩʔϧϓϨʔϯͷ
ํλΠϜ Έͳ͞Μ͕ڵຯ͋ΔͷΛ ڍखͰڭ͍͑ͯͩ͘͞ Γ͍ͨ༰ΛεέονϒοΫʹ ॻ͍͍ͯͩ͘͞
*".ઃܭͷ ʢߏɺݖݶͷ࣋ͨͤํʣ
ߏͱݖݶͷ࣋ͨͤํ ✦ ʮߏʯͷྫ w *".ϢʔβʔͷΈʁεΠονϩʔϧʁ w *".ϩʔϧΛ͍ͬͯΔ߹ɺϢʔβʔͱʁ w "84*".*EFOUJUZ$FOUFSʁ*".4".-ϑΣσϨʔγϣϯʁ
w ϚϧνΞΧϯτʁͦͷ߹Ͳͷ͘Β͍ͷنʁ ✦ ʮݖݶͷ࣋ͨͤํʯͷྫ w Ͳͷ͘Βׂ͍Λ͚ͯΔʁ w ࠷খݖݶΛͲͷ͘Β͍ٻͯ͠Δʁ w Ͳͷ͘Β͍ϙϦγʔΧελϚΠζͯ͠Δʁ w ΨʔυϨʔϧ༻ͯ͠Δʁ
*".ઃܭʹؔͯ͠σΟεΧογϣϯλΠϜ ํλΠϜ *".ઃܭʢߏɾݖݶͷ࣋ͨͤํʣʹؔͯ͠ ࠔΓ͝ͱɺฉ͍ͯΈ͍ͨ͜ͱ͕ ͋Εͥͻޱ಄Ͱ͓ئ͍͠·͢
ࢀߟʹͳΔࢥ ✦ຊ൪ɺεςʔδϯάɺ։ൃͰ"84 ΞΧϯτΛ͚Δ ✦ҎԼͷׂͰ͚Δ wཧऀ wΞϓϦνʔϜ wΠϯϑϥνʔϜ wӡ༻νʔϜ ✦ͳΔ͘ਓ͕৮Βͳ্ͨ͘͠Ͱ
ΊʹݖݶΛ༩͑Δ IUUQTEFWDMBTTNFUIPEKQBSUJDMFTJBNSPMFCBTFQFSNJTTJPO
*".ϕετϓϥΫςΟεͷ
*".ʹϕετϓϥΫςΟε͕͋Γ·͢ IUUQTEPDTBXTBNB[PODPNKB@KQ*".MBUFTU6TFS(VJEFCFTUQSBDUJDFTIUNM
ཁ͢Δͱ͜Μͳײ͡ ਓʹ*%ϑΣσϨʔγϣϯͬͯͶ ϫʔΫϩʔυʹ*".ϩʔϧͬͯͶ .'"༗ޮԽͯ͠Ͷ ΞΫηεΩʔϩʔςͯ͠Ͷ
ϧʔτϢʔβʔΘͳ͍ͰͶ ࠷খݖݶΛࢦͯ͠Ͷ ఆظతʹ*".Ϧιʔε୨Էͯ͠͠Ͷ *".ϙϦγʔͰ݅ΩʔͬͯͶ *"."DDFTT"OBMZ[FSͬͯͶ 0SHBOJ[BUJPOT4$1ͬͯͶ 1FSNJTTJPOTCPVOEBSZͬͯͶ
ಠஅͱภݟʹΑΔϥϕϧ͚ͮ ਓʹ*%ϑΣσϨʔγϣϯͬͯͶ ϫʔΫϩʔυʹ*".ϩʔϧͬͯͶ .'"༗ޮԽͯ͠Ͷ ΞΫηεΩʔϩʔςͯ͠Ͷ
ϧʔτϢʔβʔΘͳ͍ͰͶ ࠷খݖݶΛࢦͯ͠Ͷ ఆظతʹ*".Ϧιʔε୨Էͯ͠͠Ͷ *".ϙϦγʔͰ݅ΩʔͬͯͶ *"."DDFTT"OBMZ[FSͬͯͶ 0SHBOJ[BUJPOT4$1ͬͯͶ 1FSNJTTJPOTCPVOEBSZͬͯͶ ݫक Ͱ͖ΔݶΓ ༨༟͕͋Ε ༨༟͕͋Ε ༨༟͕͋Ε ༨༟͕͋Ε Ͱ͖ΔݶΓ ༨༟͕͋Ε Ͱ͖ΔݶΓ ༨༟͕͋Ε Ͱ͖ΔݶΓ
ϕετϓϥΫςΟεʹؔ͢Δ͋Ε͜Εɹɹ ਓʹ*%ϑΣσϨʔγϣϯͬͯͶ ϫʔΫϩʔυʹ*".ϩʔϧͬͯͶ .'"༗ޮԽͯ͠Ͷ ΞΫηεΩʔϩʔςͯ͠Ͷ
ϧʔτϢʔβʔΘͳ͍ͰͶ ࠷খݖݶΛࢦͯ͠Ͷ ఆظతʹ*".Ϧιʔε୨Էͯ͠͠Ͷ *".ϙϦγʔͰ݅ΩʔͬͯͶ *"."DDFTT"OBMZ[FSͬͯͶ 0SHBOJ[BUJPOT4$1ͬͯͶ 1FSNJTTJPOTCPVOEBSZͬͯͶ ݫक Ͱ͖ΔݶΓ ༨༟͕͋Ε ༨༟͕͋Ε ༨༟͕͋Ε ༨༟͕͋Ε Ͱ͖ΔݶΓ ༨༟͕͋Ε Ͱ͖ΔݶΓ ༨༟͕͋Ε Ͱ͖ΔݶΓ ํλΠϜ ͍Ζ͍Ζ ฉ͔͍ͤͯͩ͘͞
ධՁཧͷ
ධՁཧͱ "84SF*OWFOU)BSOFTTQPXFSPG*".QPMJDJFT SFJOJOQFSNJTTJPOTX"DDFTT"OBMZ[FS 4&$ ΑΓ ✦ "84*".ҎԼΛಥ͖߹Θͤͯ ධՁ͢Δ w
ϦΫΤετͷίϯςΩετ w ධՁରͷϙϦγʔ ✦ ධՁͷ݁ՌҎԼͷ͍ͣΕ͔ w ڐՄ w ڋ൱
ධՁཧϑϩʔνϟʔτઈରΈΑ͏ ˞୯ҰΞΧϯτʹ͓͚ΔϑϩʔνϟʔτͰ͋Δ͜ͱʹҙ IUUQTEPDTBXTBNB[PODPNKB@KQ*".MBUFTU6TFS(VJEFSFGFSFODF@QPMJDJFT@FWBMVBUJPOMPHJDIUNMQPMJDZFWBMEFOZBMMPX
͜Ε͚͓֮ͩ͑ͯ͜͏ ✦ σϑΥϧτͰڋ൱ʢ҉తͳڋ൱ʣ ✦ ໌ࣔతͳڋ൱͕Ͳ͔͜ʹ͋Ε݁Ռڋ൱ ✦ ʮ໌ࣔతͳڐՄʯΛ༩͑ΒΕΔͷҎԼͷΈ w ΞΠσϯςΟςΟϕʔεϙϦγʔ
w ϦιʔεϕʔεϙϦγʔ ✦ ҎԼΨʔυϨʔϧͱͯ͠ػೳ w 0SHBOJ[BUJPOT4$1 w 1FSNJTTJPOTCPVOEBSZ w ηογϣϯϙϦγʔʢείʔϓμϯϙϦγʔʣ w ʢ71$ΤϯυϙΠϯτϙϦγʔʣ
͜Ε͚͓֮ͩ͑ͯ͜͏ ✦ ୯ҰΞΧϯτͷ߹ɺҎԼͷ͍ͣΕ͔ͷΞΫηεڐՄͷ ༩ͷΈͰ݁Ռ͕ڐՄʹͳΔ߹͕͋Δ w ΞΠσϯςΟςΟϕʔεϙϦγʔ w ϦιʔεϕʔεϙϦγʔ ✦
ϦιʔεϕʔεϙϦγʔͰڐՄ͢ΔϓϦϯγύϧʹΑͬͯ ධՁཧ͕มΘΔ߹͕͋Δ ✦ ΫϩεΞΧϯτͷ߹ɺํͰڐՄ͕ඞཁ
ϑϦʔͷ࣭λΠϜ ํλΠϜ ͜͜ͷ෦͕ฉ͖͍ͨΜ͕ͩʁΛ ืू͍ͯ͠·͢
ʹཱͪͦ͏ͳϦϯΫू IUUQTEFWDMBTTNFUIPEKQBSUJDMFTOFXQPMJDZFWBMVBUJPOMPHJD fl PXDIBSU IUUQTEFWDMBTTNFUIPEKQBSUJDMFTEFWJPJBNFWBMVBUJPOMPHJD IUUQTEFWDMBTTNFUIPEKQBSUJDMFTQSJODJQBMFMFNFOUJBNSPMFPSSPMFTFTTJPO
σʔλϓϨʔϯͱ ίϯτϩʔϧϓϨʔϯͷ
*".ʹσʔλϓϨʔϯͱίϯτϩʔϧϓϨʔϯ͕͋Δ IUUQTEFWDMBTTNFUIPEKQBSUJDMFTBXTJBNDPOUSPMQMBOFEBUBQMBOF
ϑϦʔͷ࣭λΠϜ ํλΠϜ ฉ͖͍ͨ͜ͱʜʜ͋Γ·͢ʁ
ʹཱͪͦ͏ͳϦϯΫू IUUQTEFWDMBTTNFUIPEKQBSUJDMFTBXTGBVMUJTPMBUJPOCPVOEBSJFT IUUQTEFWDMBTTNFUIPEKQBSUJDMFTBXTJBNFWFOUVBMDPOTJTUFODZTFTTJPOQPMJDZ IUUQTEFWDMBTTNFUIPEKQBSUJDMFTBXTJBNCBDLHSPVOEEFWJP
͓͠·͍
ηογϣϯΞϯέʔτ%": ຬ্ҐͷηογϣϯΛޙϒϩάͰެ։༧ఆʂ ճͷ͝ڠྗΛΑΖ͓͘͠ئ͍͠·͢ɻ ෳճՄɺ લճͷ༰Ҿ͖ܧ͗·͢ ऴྃ͠·ͨ͠
None