Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
AWS Service Namespace を流行らせたい/ AWS Service Name...
Search
YukihiroChiba
January 28, 2022
Technology
2.6k
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
AWS Service Namespace を流行らせたい/ AWS Service Namespace to become popular
YukihiroChiba
January 28, 2022
More Decks by YukihiroChiba
See All by YukihiroChiba
DevelopersIO 2025 RIとSP基礎講座
yukihirochiba
1
2.4k
わたしの業務の中に住み着いたCacoo/Cacoo has taken up residence in my work routine
yukihirochiba
0
1.3k
Amazon VPCでの IPv6利用に向けた はじめの一歩/first-step-towards-using-ipv6-in-amazon-vpc
yukihirochiba
0
1.2k
AWS IAM の結果整合性を避けるためセッションポリシーを用いてポリシーの動作確認を行う、を解説する
yukihirochiba
0
1.2k
SSMエージェントはIAMロールの夢を見るか/ Do SSM Agents Dream Of IAM Roles?
yukihirochiba
0
3.2k
AWS IAM の知っておくべき話と知らなくてもいい話 DevIO2023/ AWS IAM DevIO 2023
yukihirochiba
0
3.7k
デジタルアイデンティティWGミニウェビナー第4回「IaaSとアイデンティティ」/ jnsa-iaas-identity
yukihirochiba
0
860
学習エンジンがうなりを上げているチームの作り方 / How to build a team with a learning engine humming along
yukihirochiba
0
7.4k
Amazon Route 53 Application Recovery Controller zonal shift 試してみた
yukihirochiba
0
2.4k
Other Decks in Technology
See All in Technology
「ビジネスがわかるエンジニア」とは何か?
ryooob
0
340
AIAU_UMEMOGU_ninomiya_slide
ninomiya_ii
0
270
元銀行員がAIだけでアプリを量産!「バイブコーディング実演セミナー 」
tatsuya1970
0
110
週末にループ・エンジニアリングの理解を深めるためのスライド
nagatsu
0
470
秘密度ラベル初心者が第1歩でつまづかないための「設計・運用」ポイント
seafay
PRO
1
500
事業会社における 機械学習・推薦システム技術の活用事例と必要な能力 / ml-recsys-in-layerx-wantedly-2026
yuya4
0
160
徹底討論!ECS vs EKS!
daitak
3
1.7k
Lightning近況報告
kozy4324
0
220
千葉での単身赴任からAWSをやり続け、千葉に戻ってきた話
yama3133
1
120
起点・思考・出力で分解する 〜PM業務の自動化設計〜
kazu_kichi_67
2
1.1k
2026-06-24_人とAIの責務分離に基づく開発プロセスの提案.pdf
takahiromatsui
0
230
Comment regagner la souveraineté de vos données tout en étant payé grâce à Nostr !
rlifchitz
0
210
Featured
See All Featured
End of SEO as We Know It (SMX Advanced Version)
ipullrank
3
4.2k
JavaScript: Past, Present, and Future - NDC Porto 2020
reverentgeek
52
6k
GraphQLとの向き合い方2022年版
quramy
50
15k
Docker and Python
trallard
47
3.9k
Fashionably flexible responsive web design (full day workshop)
malarkey
408
66k
Public Speaking Without Barfing On Your Shoes - THAT 2023
reverentgeek
1
440
Neural Spatial Audio Processing for Sound Field Analysis and Control
skoyamalab
0
340
How to build a perfect <img>
jonoalderson
1
5.7k
KATA
mclloyd
PRO
35
15k
The Curse of the Amulet
leimatthew05
2
13k
Test your architecture with Archunit
thirion
1
2.3k
Tips & Tricks on How to Get Your First Job In Tech
honzajavorek
1
540
Transcript
ʜʜྲྀߦΒ͍ͤͨɺ "844FSWJDF/BNFTQBDFΛɻ ઍ༿ʢνόϢΩʣ
ࣗݾհ ઍ༿ (νόϢΩ) ࣦޮ ͠·ͨ͠
ࣗݾհ ઍ༿ (νόϢΩ) ɾ20201݄ΫϥεϝιουJOINɹɹɹɹ ࣦޮ ͠·ͨ͠
ࣗݾհ ઍ༿ (νόϢΩ) ɾ20201݄ΫϥεϝιουJOINɹɹɹɹ ɾ2021 APN AWS Top
Engineer ࣦޮ ͠·ͨ͠
ࣗݾհ ઍ༿ (νόϢΩ) ɾ20201݄ΫϥεϝιουJOINɹɹɹɹ ɾ2021 APN AWS Top
Engineer ɾ͖ͳAWSαʔϏεɿIAM
͖ͳʜʜ ͖ͳAWSαʔϏεɿIAM
͖ͳʜʜ ͖ͳAWSαʔϏεɿIAM ͖ͳAWSϦιʔεɿIAMϩʔϧ
͖ͳʜʜ ͖ͳAWSαʔϏεɿIAM ͖ͳAWSϦιʔεɿIAMϩʔϧ ͖ͳΞΫγϣϯɿsts:AssumeRole
͖ͳʜʜ ͖ͳAWSαʔϏεɿIAM ͖ͳAWSϦιʔεɿIAMϩʔϧ ͖ͳΞΫγϣϯɿsts:AssumeRole ͖ͳAWS Service Namespaceɿtiros
͖ͳʜʜ ͖ͳAWSαʔϏεɿIAM ͖ͳAWSϦιʔεɿIAMϩʔϧ ͖ͳΞΫγϣϯɿsts:AssumeRole ͖ͳAWS Service Namespaceɿtiros φχίϨʁʁ
͖ͳ AWS Service Namespace Λ ܾΊ·͠ΐ͏ ϝΠϯςʔϚ
"HFOEB 1.AWSαʔϏε͋Δ͋Δ 2.AWS Service Namespace 1.ͱ 2.ௐํ 3.ΫΠζ 1.ਖ਼Ҿ͖
2.ٯҾ͖
AWS αʔϏε͋Δ͋Δ ݴ͍͍ͨ
"84αʔϏε͋Δ͋Δ ͦͷ1. ͦͷ2. ͦͷ3.
"84αʔϏε͋Δ͋Δ ͦͷ1. ଟ͍ɻ ͦͷ2. ͦͷ3.
ଟ͍ɻ ͳΜͰ223ݸ͋Δͱ͔…… ɹͳ͍ͱ͔…… ֮͑ΒΕͳ͍Α……
"84αʔϏε͋Δ͋Δ ͦͷ1. ଟ͍ɻ ͦͷ2. ͦͷ3.
"84αʔϏε͋Δ͋Δ ͦͷ1. ଟ͍ɻ ͦͷ2. ಄ࣙ AWS ͔ Amazon ͔໎͍͕ͪ
ͦͷ3.
಄ࣙ"84͔"NB[PO͔໎͍͕ͪ Ұઆʹɻ ʮAWSʯ͕ͭ͘ͷ…… ɹɹଞͷAWSαʔϏεͱΈ߹ΘͤΔલఏ ɹɹɹɹAWS LambdaɺAWS BackupɺAWS IAM... ʮAmazonʯ͕ͭ͘ͷ……
ɹɹ୯ಠͰ͑Δͷ Amazon EC2ɺAmazon Route53ɺAmazon S3…
಄ࣙ"84͔"NB[PO͔໎͍͕ͪ ͪΐͬͱੜͯ͠ ਖ਼໊ࣜশ໎͍͕ͪ •Amazon Elastic Compute Cloudʁ •Amazon EC2ʁ
•Amazon Simple Storage Serviceʁ •Amazon S3ʁ ͳͲͳͲ…… ͔ͯ͠͠ʮAmazon Elastic Compute Cloud (EC2)ʯʁ
"84αʔϏε͋Δ͋Δ ͦͷ1. ଟ͍ɻ ͦͷ2. ಄ࣙ AWS ͔ Amazon ͔໎͍͕ͪ
ͦͷ3.
"84αʔϏε͋Δ͋Δ ͦͷ1. ଟ͍ɻ ͦͷ2. ಄ࣙ AWS ͔ Amazon ͔໎͍͕ͪ
ͦͷ3. ԿΛͬͯ”αʔϏε”͔Ή
ԿΛͬͯzαʔϏεz͔Ή Ϛωδϝϯτίϯιʔϧج४ʁ ΫϥυҰཡج४ʁ AWSυΩϡϝϯτج४ʁ
ԿΛͬͯzαʔϏεz͔Ή Ϛωίϯ ϖʔδ υΩϡϝϯτ &-# ʮ&$ʯͷ Ұ෦ ͋Δ τοϓϖʔδ
ʹ͋Δ 5SBOTJU(BUFXBZ ʮ71$ʯͷ Ұ෦ ͋Δ ʮ71$ʯʹ ͋Δ .BSLFUQMBDF αʔϏεը໘ ͕͋Δ ͳ͍ τοϓϖʔδ ʹ͋Δ ྫ͑……
"84αʔϏε͋Δ͋Δ ͦͷ1. ଟ͍ɻ ͦͷ2. ಄ࣙ AWS ͔ Amazon ͔໎͍͕ͪ
ͦͷ3. ԿΛͬͯ”αʔϏε”͔Ή ͏ʔΉ…… 🤔
ͦ͜Ͱ AWS Service Namespace Ͱ͢Α ΊΔ͋ͳͨ
"844FSWJDF/BNFTQBDF ɾج४͕໌֬🤗 ɹɹϦϑΝϨϯεͰఆٛ͞ΕͯΔ ɾ ɾ
"844FSWJDF/BNFTQBDF ɾج४͕໌֬🤗 ɹɹϦϑΝϨϯεͰఆٛ͞ΕͯΔ ɾAWS Amazon ͔ͭͳ͍🤗 ɹɹେମུশΛ͓͚֮͑ͯOK ɾ
"844FSWJDF/BNFTQBDF ɾج४͕໌֬🤗 ɹɹϦϑΝϨϯεͰఆٛ͞ΕͯΔ ɾAWS Amazon ͔ͭͳ͍🤗 ɹɹେମུশΛ͓͚֮͑ͯOK ɾAWSαʔϏεΑΓଟ͍🥺
ɹɹ2022/1/27࣌Ͱ301ݸ͋Γ·͢
AWS Service Namespace ͱԿ͔ ࠓͷຊ
"844FSWJDF/BNFTQBDFͱ arn:aws:s3:::my_corporate_bucket arn:aws:iam::123456789012:user/Test • AWS Λࣝผ͢ΔͨΊͷαʔϏε໊લۭؒ • ARN ʹొ͠·͢
"844FSWJDF/BNFTQBDFͱ • IAM JSON ϙϦγʔʹొ͠·͢ • Action • Condition
• αʔϏεϓϨϑΟοΫεͱ
"844FSWJDF/BNFTQBDFͱ • IAM JSON ϙϦγʔʹొ͠·͢ • Action • Condition
• αʔϏεϓϨϑΟοΫεͱ ec2:CreateVpc s3:GetObject Actionͷྫɻ ɹରԠ͢ΔAPI͕ແ͘ݖݶ༩ͷͨΊʹͷΈ͋Δͷ
"844FSWJDF/BNFTQBDFͱ • IAM JSON ϙϦγʔʹొ͠·͢ • Action • Condition
• αʔϏεϓϨϑΟοΫεͱ ec2:CreateVpc s3:GetObject iam:AWSServiceName rds:DatabaseName Actionͷྫɻ ɹରԠ͢ΔAPI͕ແ͘ݖݶ༩ͷͨΊʹͷΈ͋Δͷ Conditionͷྫɻ ɹάϩʔόϧ݅Ωʔʹରͯ͠ ɹ αʔϏεݻ༗ͷ݅ΩʔͱݺΕΔ
"844FSWJDF/BNFTQBDFͱ • AWS CLI ͷίϚϯυ໊ʹͳ͍ͬͯΔ͜ͱ͕ଟ͍ • ྫ֎͋Γ·͢ʢaws con fi
gserviceͱ͔ʣ aws sts get-caller-identity aws ecr put-image
"844FSWJDF/BNFTQBDFͱ"84αʔϏε • 1ର1ʹͳ͍ͬͯΔ͜ͱ͕ଟ͍ • ҰͭͷAWSαʔϏε͕ෳͷAWS Service NamespaceΛ࣋ͭ͜ͱ͋Δ • ҟͳΔAWSαʔϏε͕ಉ͡AWS
Service Namespace Λ࣋ͭ͜ͱ͋Δ
Ͳ͏ͬͯ֬ೝ͢ΕΑ͍͔ "844FSWJDF/BNFTQBDF
ίϚϯυΛୟ͜͏ i=`aws iam generate-service-last-accessed-details --arn arn:aws:iam::aws:policy/AdministratorAccess --output text` \
&& sleep 1 \ && aws iam get-service-last-accessed-details --job-id $i --max-items 1000 \ | jq -c '.ServicesLastAccessed[] | [.ServiceName,.ServiceNamespace]' ࠓͷ AWS αʔϏε໊લۭؒɺࠓͷ͏ͪʹɻ 2021 https://dev.classmethod.jp/articles/aws-service- namespace-2021/ ҎԼʹࡌͬͯ·͢ɻ
ͳʹɺͦͷίϚϯυʜʜ AdministratorAccessΛΞΫηεΞυόΠβʔͰ ݟΔͷͱಉ͜͡ͱΛ AWS CLI Ͱͬͯ·͢ɻ ΞΫηεՄೳͳ ʮαʔϏεʯͱ ࠷ऴΞΫηε࣌ؒΛ
දࣔ͢ΔΑ
ͪΌΜͱϦϑΝϨϯεͰݟ͍ͨ • αʔϏεೝূϦϑΝϨϯεΛΈΑ͏ • Service Authorization Reference ͳͷͰʮೝՄʯͱ༁ͯ͠΄͘͠ ͋Δͱ͔ͳ͍ͱ͔
• αʔϏεϓϨϑΟοΫε͝ͱʹϖʔδ͕࡞ΒΕ͍ͯ·͢ ϙϦγʔઃܭ͢Δ࣌ʹ ֎ͤͳ͍Ͱ͢ΑͶ https://docs.aws.amazon.com/ja_jp/service-authorization/latest/reference/reference_policies_actions-resources-contextkeys.html
ͪΌΜͱϦϑΝϨϯεͰݟ͍ͨ • ʮAWS IAMͱ࿈ܞ͢ΔαʔϏεʯϖʔδେࣄ • AWS IAM ͷυΩϡϝϯτͷҰ෦Ͱ͢ •
͜͜ͰͷʮαʔϏεʯαʔϏεϓϨϑΟοΫε͕ج४Ͱ͢ ϒοΫϚʔΫͯ͠ͳ͍…ʁ ͳΜͰ……ʁ https://docs.aws.amazon.com/ja_jp/IAM/latest/UserGuide/reference_aws-services-that-work-with-iam.html
IAM ͱྑ͘ͳΔͳΒ AWSαʔϏε͡Όͳ͘ AWS Service Namespace Λҙࣝ͠Α͏ "844FSWJDF/BNFTQBDF
AWS Service Namespace ΫΠζʂʂʂʂʂ νϟϨϯδ͠Α͏
Δ͜ͱ • ਖ਼Ҿ͖ • AWSαʔϏε͔Β໊લۭؒΛߟ͑Δ • ٯҾ͖ • ໊લۭ͔ؒΒAWSαʔϏεΛߟ͑Δ
͜͜Ͱͷʮਖ਼Ҿ͖ʯͱ͔ʮٯҾ͖ʯΘͨ͠ ͕উखʹͦ͏ݺΜͰΔ͚ͩͰ͢ɻ ΑͦͰݴ͏ͱ ஏΛ͔͖·͢Α
ਖ਼Ҿ͖ฤ "844FSWJDF/BNFTQBDFΫΠζ
ୈҰ "NB[PO&$ қɿ ʁ AWSαʔϏε AWS Service Namespace
ୈҰ "NB[PO&$ FD қɿ AWSαʔϏε AWS Service Namespace ؆୯Ͱ͢Ͷɻ
ୈೋ "NB[PO4 қɿ ʁ AWSαʔϏε AWS Service Namespace
ୈೋ "NB[PO4 T қɿ AWSαʔϏε AWS Service Namespace ๏ଇΘ͔͖ͬͯ·ͨ͠Ͷɻ
ୈࡾ "NB[PO71$ қɿ ʁ AWSαʔϏε AWS Service Namespace
ୈࡾ "NB[PO71$ қɿ AWSαʔϏε AWS Service Namespace FD ʮvpcʯͰ͋Γ·ͤΜΑɻ
໊લۭؒFDଟ͍Αʜʜ • Amazon EC2 actions • Amazon EBS actions
• Amazon VPC actions • Amazon IPAM actions • AWS Transit Gateway actions • AWS PrivateLink actions • AWS Client VPN actions • AWS Site-to-Site VPN actions • AWS Outposts actions • AWS Wavelength actions • VM Import/Export actions • AWS Nitro Enclaves https://docs.aws.amazon.com/AWSEC2/latest/APIReference/OperationList-query.html
ٯҾ͖ฤ "844FSWJDF/BNFTQBDFΫΠζ
ୈҰ "NB[PO3%4 қɿ AWSαʔϏε AWS Service Namespace SET Amazon
RDS Ҏ֎ͰԿ͕͋ΔͰ͠ΐ͏ʁ ʁ
ୈҰ "NB[PO3%4 қɿ AWSαʔϏε AWS Service Namespace SET "NB[PO
%PDVNFOU%# ͦ͏ͳΜͩ……ɻ
ୈೋ қɿ AWSαʔϏε AWS Service Namespace NFEJBJNQPSU ϝσΟΞܥͷαʔϏε͔ͳʁʁʁʁ ʁ
ୈೋ "NB[PO3%4 қɿ AWSαʔϏε AWS Service Namespace Amazon RDS
Custom for Oracle ͷ ɹΠϯετʔϧϝσΟΞʹର͢ΔݖݶΛ༩͢ΔͨΊͷ໊લۭؒɻɻ NFEJBJNQPSU
ୈࡾ қɿ AWSαʔϏε AWS Service Namespace UJSPT ฉ͍ͨ͜ͱͳ͍Α…… ʁ
ୈࡾ қɿ AWSαʔϏε AWS Service Namespace UJSPT ਖ਼֬ʹݴ͑ Amazon
VPC Reachability Analyzer ͕ ɹͬͱؔΘΓ͕ڧ͍ "NB[PO71$ ڧ͍ͯݴ͑
UJSPTJTԿ https://aws.amazon.com/jp/security/provable-security/ • ਪπʔϧʁੳج൫ʁΈ͍ͨͳͷ • Inspector ΞΫηεΞφϥΠβʔͰ༻͞ΕΔ • ઐ༻ͷAPIΛୟ͚ΔΘ͚Ͱͳ͘ڐՄΛ༩͑ΔͨΊʹඞཁ
• ྫ͑ Inspector v2 ͷαʔϏεϦϯΫϩʔϧͷIAMϙϦγʔΛோΊͯΈΑ͏
͋ͳͨԿਖ਼ղͰ͖·͔ͨ͠ʁ "844FSWJDF/BNFTQBDFΫΠζ
·ͱΊ Α͏͘ऴΘΓͰ͢
"844FSWJDF/BNFTQBDF͍͍ͧ IAMʹৄ͘͠ͳΔͳΒආ͚ͯ௨Εͳ͍ 300ݸҎ্όϦΤʔγϣϯ͕͋Δ ਪ͠Λݟ͚͍͔͚ͭͯΑ͏
ऴΘΓʹɿΘͨ͠ͷࣥ೦ΛோΊ͍ͯͩ͘͞ https://dev.classmethod.jp/articles/aws-services-with-aws-servicenamespaces/ ࢝ͷ࣌ؒΛ๋͛·ͨ͠