Upgrade to Pro — share decks privately, control downloads, hide ads and more …

IAM Access Analyzer を活用して最小権限を目指そう

IAM Access Analyzer を活用して最小権限を目指そう

「IAM Access Analyzer を活用して最小権限を目指そう」というタイトルで登壇した際の資料です

YukihiroChiba

May 19, 2021
Tweet

More Decks by YukihiroChiba

Other Decks in Technology

Transcript

  1. ࣗݾ঺հ  ઍ༿ ޾޺ • 2020 ΫϥεϝιουδϣΠϯ • 2021 APN

    AWS Top EngineerΑ • ޷͖ͳAWSΞΫγϣϯɿ • sts:AssumeRole
  2. ᶄ8"ϑϨʔϜϫʔΫηΩϡϦςΟͷப  • ΞΠσϯςΟςΟϕʔεϙϦγʔ • ϚωʔδυϙϦγʔ • AWS ؅ཧϙϦγʔ •

    ΧελϚʔ؅ཧϙϦγʔ • ΠϯϥΠϯϙϦγʔ ʮ΄ͱΜͲͷ৔߹ɺ࠷খݖݶͷݪଇʹैͬͯɺ ɹಠࣗͷΧελϚʔ؅ཧϙϦγʔΛ࡞੒͢Δඞཁ͕͋Γ·͢ɻʯ
  3. ᶄ8"ϑϨʔϜϫʔΫηΩϡϦςΟͷப  • ৚݅ɺϦιʔεɺΞΫγϣϯΛ࠷খԽ͢Δ • άϧʔϓ΍ଐੑʹΑΓಈతʹΞΫηεڐՄΛ༩͑Δ ʢݸʑͷϢʔβʔʹ෇༩͠ͳ͍ʣ • Ϧιʔε΍IAMΤϯςΟςΟʹΞλον͢ΔϙϦ γʔʹΑΓΞΫηεΛ੍ޚ͢Δ

    • Permissions boundary΍ABACΛ׆༻͢Δ ʮ͜ͷݪଇʹج͍ͮͯӡ༻͢Δͱɺҙਤ͠ͳ͍ΞΫηε੍͕ݶ͞Εɺ ɹɹ୭͕ͲͷϦιʔεʹΞΫηεͰ͖Δ͔؂ࠪͰ͖ΔΑ͏ʹͳΓ·͢ɻʯ
  4. ͭͷϙϦγʔλΠϓ  • ΞΠσϯςΟςΟϕʔεϙϦγʔ • ϦιʔεϕʔεϙϦγʔ • ΞΫηεڐՄͷڥքʢPermissions boundaryʣ •

    Organizations SCPʢαʔϏείϯτϩʔϧϙϦγʔʣ • ΞΫηείϯτϩʔϧϦετʢACLʣ • ηογϣϯϙϦγʔ ʁ ʁ ʁ ʁ ʁ ʁ ʁ ʁ ʁ
  5. ͭͷϙϦγʔλΠϓ  • ΞΠσϯςΟςΟϕʔεϙϦγʔ • ϦιʔεϕʔεϙϦγʔ • ΞΫηεڐՄͷڥքʢPermissions boundaryʣ •

    Organizations SCPʢαʔϏείϯτϩʔϧϙϦγʔʣ • ΞΫηείϯτϩʔϧϦετʢACLʣ • ηογϣϯϙϦγʔ ʁ ʁ ʁ ʁ ʁ ʁ ʁ ʁ ʁ 71$ΤϯυϙΠϯτϙϦγʔ͸ ͜͜ʹଐ͢Δ͕ɺ ʮͪΐͬͱ܅͕ͪ͘ͳ͍ʁʯͱ ࢥ͍ͬͯΔ
  6. ͭͷϙϦγʔλΠϓ  • ΞΠσϯςΟςΟϕʔεϙϦγʔ • ϦιʔεϕʔεϙϦγʔ • ΞΫηεڐՄͷڥքʢPermissions boundaryʣ •

    Organizations SCPʢαʔϏείϯτϩʔϧϙϦγʔʣ • ΞΫηείϯτϩʔϧϦετʢACLʣ • ηογϣϯϙϦγʔ ͍ΘΏΔʮIAMϙϦγʔʯ όέοτϙϦγʔɺIAMϩʔϧ৴པϙϦγʔͳͲ όέοτACLͳͲ IAMϩʔϧͷҾ͖ड͚࣌ʹઃఆՄೳ
  7. ͭͷϙϦγʔλΠϓ  • ΞΠσϯςΟςΟϕʔεϙϦγʔ • ϦιʔεϕʔεϙϦγʔ • ΞΫηεڐՄͷڥքʢPermissions boundaryʣ •

    Organizations SCPʢαʔϏείϯτϩʔϧϙϦγʔʣ • ΞΫηείϯτϩʔϧϦετʢACLʣ • ηογϣϯϙϦγʔ +40/ +40/ +40/ +40/ +40/
  8. *"."DDFTT"OBMZ[FSͷྺ࢙  • 2019/12 ϦϦʔε • S3ɺIAM ϩʔϧɺKMSɺLambdaɺSQSͷϦιʔεϕʔεϙϦγʔΛ෼ੳ • 2021/01

    ෼ੳର৅͕௥Ճ • Secrets Manager γʔΫϨοτʹରԠ • 2021/03 ʮࣄલݕূʯʹରԠ • ϦιʔεϕʔεϙϦγʔͷมߋલʹ෼ੳ͕Մೳ • ϚωδϝϯτίϯιʔϧͰ͸ S3 όέοτϙϦγʔͷΈ
  9. *"."DDFTT"OBMZ[FSͷྺ࢙  • 2019/12 ϦϦʔε • S3ɺIAM ϩʔϧɺKMSɺLambdaɺSQSͷϦιʔεϕʔεϙϦγʔΛ෼ੳ • 2021/01

    ෼ੳର৅͕௥Ճ • Secrets Manager γʔΫϨοτʹରԠ • 2021/03 ʮࣄલݕূʯʹରԠ • ϦιʔεϕʔεϙϦγʔͷมߋલʹ෼ੳ͕Մೳ • ϚωδϝϯτίϯιʔϧͰ͸ S3 όέοτϙϦγʔͷΈ ٸʹྲྀΕ͕มΘΔ
  10. *"."DDFTT"OBMZ[FSͷྺ࢙  • 2019/12 ϦϦʔε • 2021/01 ෼ੳର৅͕௥Ճ • 2021/03

    ʮࣄલݕূʯʹରԠ • 2021/03 ʮϙϦγʔνΣοΫʯʹରԠ • ϙϦγʔݕূʢValidationʣͱ΋ • ΞΠσϯςΟςΟϕʔεϙϦγʔ͕ϝΠϯ • AWS CLI Ͱ͸ SCP ΍ϦιʔεϕʔεϙϦγʔʹ΋ରԠ
  11. *"."DDFTT"OBMZ[FSͷྺ࢙  • 2019/12 ϦϦʔε • 2021/01 ෼ੳର৅͕௥Ճ • 2021/03

    ʮࣄલݕূʯʹରԠ • 2021/03 ʮϙϦγʔνΣοΫʯʹରԠ • ϙϦγʔݕূʢValidationʣͱ΋ • ΞΠσϯςΟςΟϕʔεϙϦγʔ͕ϝΠϯ • AWS CLI Ͱ͸ SCP ΍ϦιʔεϕʔεϙϦγʔʹ΋ରԠ • 2021/04 ʮϙϦγʔͷੜ੒ʯʹରԠ • ΞΠσϯςΟςΟϕʔεϙϦγʔͷΈ͕ର৅
  12. ΞφϥΠβʔͱΞυόΠβʔ  *"."DDFTT"OBMZ[FS *"."DDFTT"EWJTPS *".ΞΫηεʁ ΞφϥΠβʔʂ ΞυόΠβʔʂ Կ͕Ͱ͖Δ͔ ɾϦιʔεϕʔεϙϦγʔͷ෼ੳ ɾ֤छϙϦγʔͷݕূ

    ɾΞΠσϯςΟςΟϕʔεϙϦγʔͷੜ੒ ɾ*".Ϧιʔε୯ҐͰͷɺ ΞΫηεڐՄͱΞΫηεཤྺͷදࣔ αʔϏε͔Ͳ͏͔ ɾ"84αʔϏεͰ͋Δ ɾϦιʔε΋ଘࡏ͢Δ ɾαʔϏε༻ͷϩʔϧ΋ଘࡏ͢Δ ɾ"84αʔϏεͰ͸ͳ͍ ɾෳ਺ͷ"1*ʹΑΔػೳͷ໊শ ར༻ྉ ແྉͰࠓ͙͓͢࢖͍͍͚ͨͩ·͢ ແྉͰࠓ͙͓͢࢖͍͍͚ͨͩ·͢
  13. ϙϦγʔͷݕূͱ͸  • IAM Access Analyzer ʹΑΔػೳ • ҎԼͷϙϦγʔʹର͍͍ͯ͠ײ͡ͷνΣοΫΛͯ͘͠ΕΔ •

    ΞΠσϯςΟςΟϕʔεϙϦγʔ • SCPʢαʔϏείϯτϩʔϧϙϦγʔʣ※ϚωίϯෆՄ • ϦιʔεϕʔεϙϦγʔɹ※ϚωίϯෆՄ
  14. ஫ҙ఺ͦͷ  •ਫ਼ࠪͯ͘͠ΕΔͷ͸ Action ͷΈ •Resource ΍ Codition ʹ͸աڈͷΞΫςΟϏςΟ͸൓ө͞Ε ͳ͍

    ʮ͜ͷϢʔβʔ͸աڈ೔ؒͰ ಛఆͷ4όέοτʹରͯ͠ͷΈΞΫηεͯ͠Δ͔Β 3FTPVSDFͰ͜ͷ4όέοτ͚ͩʹߜΔͱ͍͍Αʯ ͳΜͯ͜ͱ͸ͯ͘͠Ε·ͤΜɻ
  15. ஫ҙ఺ͦͷ  •͢΂ͯͷαʔϏεͰ Action ϨϕϧͰਫ਼ࠪͯ͘͠ΕΔΘ͚Ͱ͸ͳ͍ ্هҎ֎ͷαʔϏε͸ ʮαʔϏεϨϕϧʯͰͷ ચ͍ग़ͩ͠Α ◦ IAM


    ◦ AWS KMS
 ◦ AWS Lambda
 ◦ AWS RAM
 ◦ Amazon RDS
 ◦ AWS Resource Groups
 ◦ Amazon S3
 ◦ AWS Security Token Service
 ◦ AWS Systems Manager
 ◦ IAM Access Analyzer
 ◦ Amazon CloudWatch
 ◦ Amazon Cognito Identity
 ◦ Amazon Cognito user pools
 ◦ Amazon EC2
 ◦ Amazon ECS
 ◦ Elastic Load Balancing

  16. ࠷ऴΞΫηε৘ใͷར༻ͱ͸  • IAM ΞΫηεΞυόΠβʔ ʹΑΔػೳ • IAMϦιʔεʢϢʔβʔ/άϧʔϓ/ϩʔϧ/ϙϦγʔʣ୯ҐͰҎԼΛ֬ ೝͰ͖Δ •

    ΞΫηεՄೳͳAWSαʔϏε • ࠷ऴΞΫηεཤྺ • ҎԼͷAWSαʔϏεʹରͯ͠͸ΞΫγϣϯϨϕϧͰ֬ೝՄೳ • Amazon S3 • Amazon EC2 • AWS IAM • AWS Lambda