Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Serverless Framework ユーザーが CDK に引っ越しして感じたハードルにつ...

Serverless Framework ユーザーが CDK に引っ越しして感じたハードルについて言語化してみる

AWS CDK Conference Japan 2023 の登壇スライドです
https://jawsug-cdk.connpass.com/event/278205/

## スライド内で紹介した記事
[1] AWS Cloud Development Kit (AWS CDK) v2 - Concepts
https://docs.aws.amazon.com/cdk/v2/guide/core_concepts.html

[2] [AWS CDK] Step Functions の Lambda タスクを同期呼び出しする場合の ASL の書き方について紹介・比較する
https://zenn.dev/hassaku63/articles/aefff9ebfee49f

[3] aws/aws-cdk - Security And Safety Dev Guide
https://github.com/aws/aws-cdk/wiki/Security-And-Safety-Dev-Guide

[4] CDK Security And Safety Dev Guide を読んでみた
https://tech.isid.co.jp/entry/cdk-security-and-safety-dev-guide

Avatar for hassaku63

hassaku63

May 20, 2023
Tweet

More Decks by hassaku63

Other Decks in Technology

Transcript

  1. ͜ͷൃදʹ͍ͭͯ w 4FSWFSMFTT'SBNFXPSL Ҏ߱ TMTͱදه 1ZUIPOར༻ऀ͔Βݟͨ"84$%, w $%,৮ͬͯΈͨษڧͯ͠Έͨײ૝ w 5ZQF4DSJQU͸ଟগ

    w ൃදऀࣗ਎͕ʢ΄΅ʣ$%,ϏΪφʔͰ͋Δ w ͜͜Ͱఏࣔ͢Δ৘ใ΍ݟղ͕ʮਖ਼ղʯͱ͸ݴ͑ͳ͍ʢൃදऀͷझຯᅂ޷ɺภݟ΋ଟʑʣ w དྷ৔͍ͯ͠Δ$%,ϕςϥϯͷݟղ΋࢕ͬͯΈ͍ͨ
  2. IBTTBLV5BLVZB)BTIJNPUP $PSQPSBUF4&BU4FSWFSXPSLT w ओͳ׆ಈ w ٕज़ॻయʮ࣮ફ"84$%,ʯʢڞஶʣ w "84%FW%BZ  w

    FUD TFF(JU)VCQSP fi MF  w 'BWPSJUF w 4FSWFSMFTT w 4UFQ'VODUJPOT 4QFBLFS 5XJUUFS!IBTTBLV@ 
 (JU)VCIBTTBLV
  3. IBTTBLV5BLVZB)BTIJNPUP $PSQPSBUF4&BU4FSWFSXPSLT w ओͳ׆ಈ w ٕज़ॻయʮ࣮ફ"84$%,ʯʢڞஶʣ w "84%FW%BZ  w

    FUD TFF(JU)VCQSP fi MF  w 'BWPSJUF w 4FSWFSMFTT w 4UFQ'VODUJPOT 4QFBLFS 5XJUUFS!IBTTBLV@ 
 (JU)VCIBTTBLV
  4. ࠓ೔ͷ࿦఺ w TMTͱ$%,Ͱ࢖͍উख͕ҟͳΔཁૉ w -BNCEBͷσϓϩΠํ๏ w ʮεςʔδʯ w 4UFQ'VODUJPOT w

    DPOUFYU DELKTPO ͷѻ͍ w ࣗ෼ͷ୲౰ൣғͩͱTMT͕ศརʹײ͡Δ৔߹͕ଟ͍ɺͱ͍͏࿩
  5. ࠓ೔ͷ࿦఺ w TMTͱ$%,Ͱ࢖͍উख͕ҟͳΔཁૉ w -BNCEBͷσϓϩΠํ๏ w ʮεςʔδʯ w 4UFQ'VODUJPOT w

    DPOUFYU DELKTPO ͷѻ͍ w ࣗ෼ͷ୲౰ൣғͩͱTMT͕ศརʹײ͡Δ৔߹͕ଟ͍ɺͱ͍͏࿩ ࠓ೔ͷτʔΫ ʢߦ͚Δͱ͜Ζ·Ͱʣ
  6. -BNCEBͷσϓϩΠํ๏ ϓϥάΠϯར༻͕લఏͱͳΔ͕ɺॳֶऀతʹ͸TMTͷํ͕ߟ͑Δ͜ͱ͕গͳ͍ ˞ ࣮ࡍʹ͸Ξοϓϩʔυ͸σϓϩΠ·Ͱ࣮ߦ͠ͳ͍ 
 #VDLFU ,FZΛ֬ఆ͠$MPVE'PSNBUJPOελοΫ΁ͷม׵࣌ʹϦιʔε໊ͷຒΊࠐΈΛߦ͏ͱ͜Ζ·Ͱ [JQσϓϩΠͳ-BNCEBϋϯυϥͷ࣮૷ྫΛோΊͯΈΔ w σϓϩΠલͷ޻ఔ

    CVJMEQBDLBHJOH  w ґଘؔ܎ͷμ΢ϯϩʔυ w [JQόϯυϧͷ࡞੒ w T΁ͷΞοϓϩʔυʢ˞ʣ w σϓϩΠ؀ڥͱ*%&্૒ํͰϞδϡʔϧݕࡧύεΛ௨͍ͨ͠ TMT $%,ͷͲͪΒͰ΋ʮ͍͍ײ͡ʯʹͰ͖Δ ͨͩ͠$%,Ͱָ͢ΔͳΒBMQIB൛ύοέʔδ͕ඞཁ l!BXTDELBXTMBNCEBQZUIPOBMQIBz ΋͘͠͸ϓϨʔϯͳ-BNCEB'VODUJPOͱ"TTFU ։ൃ͠΍͢͞ͷ౎߹ ϓϩδΣΫτϧʔτ͕Ϟδϡʔϧݕࡧύεʹ ؚ·Εͳ͍৔߹͸։ൃ؀ڥͷηοτΞοϓ͕૿͑Δ FH *%&ͷ؀ڥม਺ʹݕࡧύεΛ௥Ճ
  7. "84$%, ʮ͜͏͢Ε͹0,ʯͱ͍͏ڞ௨ݟղ͸ͳͦ͞͏ʁ  $POUFYU w DPOUFYUKTPOʹσϓϩΠઌͷ؀ڥ৘ใΛهड़ w CJOҎԼͷΤϯτϦʔϩδοΫͰύʔε  4UBHFΫϥε

    Ұ൪Πϝʔδʹۙͦ͏ʢQJQFMJOFTͷΠϝʔδ͕ڧ͍ʣ &YBNQMF IUUQTEPDTBXTBNB[PODPNDELBQJWEPDTBXTDELMJC4UBHFIUNMFOW 🤔
  8. 4UFQ'VODUJPOT ݸਓతʹ͸ w ࢹ఺ͷ্ԼҠಈ͕ଟͯ͘ಡΉͷ͕͠ΜͲ͍ w ʮܕ෇͖ͷ΄΅ϓϨʔϯͳ"4-ʯతͳ࢓༷Ͱ͋Δํ͕͋Γ͕͍ͨͱײͨ͡ w -BNCEBλεΫͷఆ͕ٛσϑΥϧτͰʮαʔϏε౷߹ʯํࣜʹͳ͍ͬͯΔ w ৄ͘͠͸<"84$%,>4UFQ'VODUJPOTͷ-BNCEBλεΫΛಉظݺͼग़͢͠Δ৔߹ͷ"4-ͷॻ͖ํʹ͍ͭ

    ͯ঺հɾൺֱ͢Δ ˞  w αʔϏε౷߹ํࣜͰͳ͍΍Γํ͸lQBZMPBE3FTQPOTF0OMZzUSVFΛར༻ɻͪ͜Βͷํ͕"4-͕؆ܿ w αʔϏε౷߹ํࣜͰͳ͍-BNCEBλεΫͷॻ͖ํ͕lQBZMPBE3FTQPOTF0OMZzUSVFͰ͋Δ͜ͱ͸ 
 ·ͣॳݟͰΘ͔Βͳ͍ ˞ʜIUUQT[FOOEFWIBTTBLVBSUJDMFTBF ff GFCGFFG
  9. ॴײ ໨తʹ߹க͢ΔΫϥε΍ϝιουͷଘࡏʹͨͲΓண͘ͷ͕େม w $%,ʹݶΒͣͳ࿩Ͱ͸͋Δ w +BWBͷखश͍ͨ͠ͱ͖ͷײ֮ͱಉͩͬͨ͡ w ΍Γ͍ͨ͜ͱʹରͯ͠ొ৔ਓ෺ DMBTT ͕ଟ͘ͳ͍ʜ

    తͳ w ܦݧ͋Διϑτ΢ΣΞΤϯδχΞͷօ͞·͸Ͳ͏ͯ͠ΔΜͰ͠ΐ͏Ͷʜʁʢ͝ҙݟٻΉʣ w ެࣜϦϑΝϨϯε͸௒༏ल w ͱʹ͔͘·ͣϦϑΝϨϯεͷ&YBNQMFΛݟΔ w TZOUIͷ࣮ߦ݁ՌΛݟͳ͕Βࢼߦࡨޡ
  10. ॴײ ໨తʹ߹க͢ΔΫϥε΍ϝιουͷଘࡏʹͨͲΓண͘ͷ͕େม w "84%PDT GPS$%,W ͷl$PODFQUTz ˞  ΋༗༻ w

    গ͠׳Ε͖ͯͨΒ"QQT 4UBDLT &OWJSPONFOUT $POUFYU͋ͨΓΛಡΜͰΈΔͱྑͦ͞͏ w πʔϧͷઃܭࢥ૝ʹ৮ΕΔ͜ͱͰʮΒ͍͠ʯ࢖͍ํͷૉཆΛ෇͚Δ w$IBU(15ʹαϯϓϧ࣮૷Λฉ͍ͯΈΔ w ࣮ࡏ͢Δ࢓༷ʹجͮ͘ճ౴͸جຊग़ͯ͜ͳ͍΋ͷͱࢥͬͯ෇͖߹͏ w ʮͦΕͬΆ͍ʯαϯϓϧ͸ग़ྗͰ͖ΔͷͰɺͦΕΛݕࡧͷऔֻ͔ͬΓʹ ˞ʜIUUQTEPDTBXTBNB[PODPNDELWHVJEFDPSF@DPODFQUTIUNM
  11. ॴײ ࠓ೔ͷ͍͍ͩͨͷ࿩ͬͯʮ׳Εʯͱʮ޷ΈʯͰ͸ʁ w ࣮ࡍͦΜͳؾ΋͍ͯ͠Δ w ଞπʔϧ TMT ͷ஌͕ࣝ $%, शಘ࣌ͷઌೖ؍ʹͳ͍ͬͯͨ

    w ద౓ͳ6OMFBSOJOHͷҙࣝ΋େࣄ w πʔϧ͕ҧ͑͹ઃܭࢥ૝΋ҟͳΔɺࢥ૝͕มΘΕ͹ਪ঑࡞๏΋มΘΔ
  12. ༨ஊ $%,ʹ৐Γ׵͍͑ͨϞνϕͱ͔ɺ͖͔͚ͬͷิ଍ w ܕఆٛͱ*%&ͷࢧԉ͕ड͚ΒΕΔ*B$ͷੈք؍ w ຊମ΍#-&"౳ͷपล΋ؚΊͨ$%,ք۾ͷ੎͍ w 4FSWFSMFTT'SBNFXPSLͩͱۤ͘͠ͳΔࣄྫ͕ग़͖ͯͨ w *B$ଆͷґଘؔ܎ߋ৽͢ΔࡍͷσάϨݕূͰָ͍ͨ͠

    4OBQTIPUUFTUJOH  w ϦϑΝϨϯεͷॆ࣮౓߹͍͕ҧ͏ w ͲͷΈͪ*B$ઐ༻ͷґଘؔ܎ΛೖΕΔͷͳΒ$%,ͷํ͕Α͘ͳ͍ʁͱࢥͬͨ w σϓϩΠपลͷݖݶઃܭࢥ૝͕लҳ w ࢀߟ  BXTBXTDEL4FDVSJUZ"OE4BGFUZ%FW(VJEF w ࢀߟ  *4*%5FDI#MPH$%,4FDVSJUZ"OE4BGFUZ%FW(VJEFΛಡΜͰΈͨ