Upgrade to Pro — share decks privately, control downloads, hide ads and more …

AWS Service Namespace を流行らせたい/ AWS Service Namespace to become popular

AWS Service Namespace を流行らせたい/ AWS Service Namespace to become popular

YukihiroChiba

January 28, 2022
Tweet

More Decks by YukihiroChiba

Other Decks in Technology

Transcript

  1.  ઀಄ࣙ"84͔"NB[PO͔໎͍͕ͪ ͪΐͬͱ೿ੜͯ͠ ਖ਼໊ࣜশ໎͍͕ͪ໰୊ •Amazon Elastic Compute Cloudʁ •Amazon EC2ʁ

    •Amazon Simple Storage Serviceʁ •Amazon S3ʁ ͳͲͳͲ…… ΋͔ͯ͠͠ʮAmazon Elastic Compute Cloud (EC2)ʯʁ
  2.  ԿΛ΋ͬͯzαʔϏεz͔೰Ή Ϛωίϯ ੡඼ϖʔδ υΩϡϝϯτ &-# ʮ&$ʯͷ Ұ෦ ͋Δ τοϓϖʔδ

    ʹ͋Δ 5SBOTJU(BUFXBZ ʮ71$ʯͷ Ұ෦ ͋Δ ʮ71$ʯʹ ͋Δ .BSLFUQMBDF αʔϏεը໘ ͕͋Δ ͳ͍ τοϓϖʔδ ʹ͋Δ ྫ͑͹……
  3.  "84αʔϏε͋Δ͋Δ ͦͷ1. ଟ͍ɻ ͦͷ2. ઀಄ࣙ AWS ͔ Amazon ͔໎͍͕ͪ

    ͦͷ3. ԿΛ΋ͬͯ”αʔϏε”͔೰Ή ͏ʔΉ…… 🤔
  4.  "844FSWJDF/BNFTQBDFͱ͸ • IAM JSON ϙϦγʔʹ΋ొ৔͠·͢ • Action • Condition

    • αʔϏεϓϨϑΟοΫεͱ΋ ec2:CreateVpc s3:GetObject Actionͷྫɻ ɹରԠ͢ΔAPI͕ແ͘ݖݶ෇༩ͷͨΊʹͷΈ͋Δ΋ͷ΋
  5.  "844FSWJDF/BNFTQBDFͱ͸ • IAM JSON ϙϦγʔʹ΋ొ৔͠·͢ • Action • Condition

    • αʔϏεϓϨϑΟοΫεͱ΋ ec2:CreateVpc s3:GetObject iam:AWSServiceName rds:DatabaseName Actionͷྫɻ ɹରԠ͢ΔAPI͕ແ͘ݖݶ෇༩ͷͨΊʹͷΈ͋Δ΋ͷ΋ Conditionͷྫɻ ɹάϩʔόϧ৚݅Ωʔʹରͯ͠ ɹ αʔϏεݻ༗ͷ৚݅Ωʔͱݺ͹ΕΔ
  6.  ίϚϯυΛୟ͜͏ i=`aws iam generate-service-last-accessed-details --arn arn:aws:iam::aws:policy/AdministratorAccess --output text` \

    && sleep 1 \ && aws iam get-service-last-accessed-details --job-id $i --max-items 1000 \ | jq -c '.ServicesLastAccessed[] | [.ServiceName,.ServiceNamespace]' ࠓ೥ͷ AWS αʔϏε໊લۭؒɺࠓ೥ͷ͏ͪʹɻ 2021 https://dev.classmethod.jp/articles/aws-service- namespace-2021/ ҎԼʹࡌͬͯ·͢ɻ
  7.  ͪΌΜͱϦϑΝϨϯεͰݟ͍ͨ • αʔϏεೝূϦϑΝϨϯεΛΈΑ͏ • Service Authorization Reference ͳͷͰʮೝՄʯͱ༁ͯ͠΄͘͠΋ ͋Δͱ͔ͳ͍ͱ͔

    • αʔϏεϓϨϑΟοΫε͝ͱʹϖʔδ͕࡞ΒΕ͍ͯ·͢ ϙϦγʔઃܭ͢Δ࣌ʹ ֎ͤͳ͍Ͱ͢ΑͶ https://docs.aws.amazon.com/ja_jp/service-authorization/latest/reference/reference_policies_actions-resources-contextkeys.html
  8.  ͪΌΜͱϦϑΝϨϯεͰݟ͍ͨ • ʮAWS IAMͱ࿈ܞ͢ΔαʔϏεʯϖʔδ΋େࣄ • AWS IAM ͷυΩϡϝϯτͷҰ෦Ͱ͢ •

    ͜͜ͰͷʮαʔϏεʯ͸αʔϏεϓϨϑΟοΫε͕ج४Ͱ͢ ϒοΫϚʔΫͯ͠ͳ͍…ʁ ͳΜͰ……ʁ https://docs.aws.amazon.com/ja_jp/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html
  9.  ΍Δ͜ͱ • ਖ਼Ҿ͖ • AWSαʔϏε͔Β໊લۭؒΛߟ͑Δ • ٯҾ͖ • ໊લۭ͔ؒΒAWSαʔϏεΛߟ͑Δ

    ͜͜Ͱͷʮਖ਼Ҿ͖ʯͱ͔ʮٯҾ͖ʯ͸Θͨ͠ ͕উखʹͦ͏ݺΜͰΔ͚ͩͰ͢ɻ ΑͦͰݴ͏ͱ ஏΛ͔͖·͢Α
  10.  ໊લۭؒFDଟ͍Αʜʜ • Amazon EC2 actions • Amazon EBS actions

    • Amazon VPC actions • Amazon IPAM actions • AWS Transit Gateway actions • AWS PrivateLink actions • AWS Client VPN actions • AWS Site-to-Site VPN actions • AWS Outposts actions • AWS Wavelength actions • VM Import/Export actions • AWS Nitro Enclaves https://docs.aws.amazon.com/AWSEC2/latest/APIReference/OperationList-query.html
  11.  ୈೋ໰ "NB[PO3%4 ೉қ౓ɿ AWSαʔϏε AWS Service Namespace Amazon RDS

    Custom for Oracle ͷ ɹΠϯετʔϧϝσΟΞʹର͢ΔݖݶΛ෇༩͢ΔͨΊͷ໊લۭؒɻɻ NFEJBJNQPSU
  12.  ୈࡾ໰ ೉қ౓ɿ AWSαʔϏε AWS Service Namespace UJSPT ਖ਼֬ʹݴ͑͹ Amazon

    VPC Reachability Analyzer ͕ ɹ΋ͬͱ΋ؔΘΓ͕ڧ͍ "NB[PO71$ ڧ͍ͯݴ͑͹