&$4ͱ424ͰεέʔϥϒϧͳόονΛ࡞ͬͨ٢ాوจ ![FQIJSBOTBTΫϥεϝιουגࣜձࣾ
View Slide
εϥΠυޙͰೖख͢Δ͜ͱ͕ग़དྷ·͢ͷͰൃදதͷ༰ΛϝϞ͢Δඞཁ͋Γ·ͤΜɻࣸਅࡱӨΛ͢Δ߹ϑϥογϡɾγϟολʔԻ͕ग़ͳ͍Α͏ʹྀ͍ͩ͘͝͞Attention
#jawsug#jawsoka#soracomug
ࣗݾհ ٢ాوจ ![FQIJSBOTBTwΫϥεϝιουגࣜձࣾw$9ࣄۀຊ෦αʔόαΠυΤϯδχΞwԬࢁ+BWBϢʔβձදΦʔϓϯηϛφʔԬࢁ࣮ߦҕһw͖ͳ"84ͷαʔϏεw&$4 %ZOBNP%#
ΞδΣϯμ wΞʔΩςΫνϟ֓ཁw4XJUDI3PMFʹ͍ͭͯw424Ͱͬͨ͜ͱw&$4Ͱͬͨ͜ͱwͬͯΈͨ
ΞʔΩςΫνϟ֓ཁ
Γ͍ͨ͜ͱ wσʔλͷҰׅߋ৽wݩσʔλ$47wσʔλྔेສ݅ఔw*%ͱɺߋ৽༰͕ೖ͍ͬͯΔwߋ৽ʹ֎෦ͷ"1*Λୟ͘
Switch RoleͰͬͨ͜ͱ
w424ͷσʔλૹ৴ॲཧͰ4XJUDI3PMF͍ͨ͠w4XJUDI3PMF͢Δʹ.'"ඞਢwBXTDMJͰ͋Ε్தͰτʔΫϯΛೖྗͰ͖Δw4%,ͩͱࣗલͰΫϨσϯγϟϧΛऔಘͯ͠Δඞཁ͕͋Δ
BXTDPOpH [default]region = ap-northeast-1output = json[profile hoge]region = ap-northeast-1source_profile = defaultrole_arn = arn:aws:iam::ACCOUNT_ID:role/john-doemfa_serial = arn:aws:iam::ACCOUNT_ID:mfa/john-doe
BXTDMJͰ4XJUDI3PMF͢Δ߹ $ AWS_PROFILE=hoge aws s3 lsEnter MFA code for arn:aws:iam::ACCOUNT_ID:mfa/john-doe[MFAτʔΫϯΛೖྗ͢Δ]
"3/ɺ.'"τʔΫϯɺTUTΫϥΠΞϯτ sts_client =Aws::STS::Client.new(region: 'ap-northeast-1')role_arn =`aws configure get role_arn --profile hoge`.chompserial_number =`aws configure get mfa_serial --profile hoge`.chompputs "Input MFA token code..."token_code = gets.chomp
ΫϨσϯγϟϧੜ͠424ΫϥΠΞϯτΛ࡞ role_credentials = Aws::AssumeRoleCredentials.new(client: sts_client,role_arn: role_arn,role_session_name: "hoge_session",serial_number: serial_number,token_code: token_code)Aws::SQS::Client.new(credentials: role_credentials)
wڥม"84@130'*-&ར༻͠ͳ͍wBXTDPOpHVSFHFUͰඞཁͳ"3/Λऔಘ͢Δw.'"τʔΫϯผ్ɺೖྗͤ͞ΔwTUTΫϥΠΞϯτΛ࡞͠ɺ"TTVNF3PMF$SFEFOUJBMTͰɺΫϨσϯγϟϧΛऔಘ͢Δ
SQSͰͬͨ͜ͱ
wෳͷλεΫ͔ΒΞΫηε͞ΕΔͷͰɺ͜ΕΛ͍͍ײ͡ʹॲཧͰ͖ΔwॲཧͰ͖ͳ͔ͬͨσʔλΛɺผΩϡʔʹҠͯ͠ϦτϥΠ͘͢͢͠Δw424ͷ%FBE-FUUFS2VFVFͷΈΛ͏
#PEZ 3FDFJWF$PVOU 7JTJCMF 536&
#PEZ 3FDFJWF$PVOU 7JTJCMF '"-4&
#PEZ 3FDFJWF$PVOU 7JTJCMF 536&VisibilityTimeoutΛա͗ͯDelete͞Εͳ͔ͬͨ߹
#PEZ 3FDFJWF$PVOU 7JTJCMFReceive Count͕࠷େReceive CountΛ͑ͨ߹#PEZ 3FDFJWF$PVOU 7JTJCMF 536&DLQҠಈ
ECSͰͬͨ͜ͱ
w'BSHBUFͰϦιʔεཧͷखؒΛݮΒ͍ͨ͠wฒྻͰ࣮ߦͰ͖ΔΑ͏ʹ͍ͨ͠wঢ়گʹԠͯ͡ɺλεΫͷΛௐ͍ͨ͠w$MJFOU4FDSFUͳͲΛ҆શʹѻ͍͍ͨ
ύϥϝʔλετΞʹઃఆΛ֨ೲ aws ssm put-parameter \--name /ClientId \--value CLIENT_ID_XXXX \--type String
λεΫఆ͔ٛΒࢀর ContainerDefinitions:-Name: app...Secrets:- Name: CLIENT_IDValueFrom:!Sub "arn:aws:ssm:ap-northeast-1:${AWS::AccountId}:parameter/ClientId"- Name: CLIENT_SECRETValueFrom:!Sub "arn:aws:ssm:ap-northeast-1:${AWS::AccountId}:parameter/ClientSecret"λεΫͷڥมͰΛऔಘͰ͖Δ
ͬͯΈͨ
wରσʔλສ݅w424ͷσʔλૹ৴ʹ࣌ؒwʢͳΜ͔վળ͍ͨ͠ؾ͕͢Δw&$4ͷόονॲཧ͕࣌ؒະຬͰऴྃ
w4%,Ͱ4XJUDI3PMF͢Δʹͻͱखؒඞཁw424ΈΛཧղ͔ͯͭ͑͠ɺ͘͢͝ศརw&$4ͷฒྻλεΫΛͬͯɺεέʔϥϒϧʹ͠Α͏