Upgrade to Pro — share decks privately, control downloads, hide ads and more …

JAWSUG初心者支部 IAMの「あ」の話

Takuro SASAKI
January 19, 2021

JAWSUG初心者支部 IAMの「あ」の話

JAWS-UG初心者支部 第35回の登壇資料です
IAMの「あ」ということで、基本的なところの解説です

Takuro SASAKI

January 19, 2021
Tweet

More Decks by Takuro SASAKI

Other Decks in Technology

Transcript

  1. "84ͱηΩϡϦςΟ #jawsug_bgnr "84ͷηΩϡϦςΟ͸ͭͷ࣠Ͱߟ͑Δ ᶃ"84಺ʹߏஙͨ͠ωοτϫʔΫͱαʔόʔͷηΩϡϦςΟ ᶄ"84ͷαʔϏε܈ͷઃܭɾઃఆ ᶅ"84ૢ࡞ʹؔ͢Δݖݶʢ*".ʣ ᶆηΩϡϦςΟΛҡ࣋؅ཧ͢ΔͨΊͷ"84αʔϏε AWS Management Console

    Role VPC AWS Cloud Subnet Internet gateway Amazon Simple Storage Service (S3) VPN gateway Endpoints User ૢ࡞ݖݶ Instance Instance Instance AWS Lambda Role ᶅ ᶄ ᶃ AWS Command Line Interface AWS Config AWS Systems Manager AWS Service Catalog AWS Trusted Advisor AWS CloudTrail ᶆ ηΩϡϦςΟΛҡ࣋ ؅ཧ͢ΔαʔϏε
  2. *".ͷجຊػೳ #jawsug_bgnr *".͸୭ʹԿΛ࢖͑Δͷ͔؅ཧ͢Δػೳ *".Ϣʔβʔ ʜ ར༻ऀͷೝূ *".άϧʔϓ ʜ *".ϢʔβʔͷάϧʔϓԽ *".ϩʔϧ

     ʜ ਓؒҎ֎ʹ΋Ұ࣌తͳૢ࡞ݖݶΛ෇༩͢Δ࢓૊Έ *".ϙϦγʔ  ʜ ෇༩͢ΔݖݶΛهड़ͨ͠΋ͷ ར༻ऀ ֎෦ Ϧιʔε "84 Ϧιʔε *".άϧʔϓ *".Ϣʔβʔ *".ϩʔϧ *". ϙϦγʔ "84 Ϧιʔε ୭ʹʁ ԿΛڐՄېࢭ͢Δ
  3. *".ϩʔϧ #jawsug_bgnr *".ϩʔϧͱ͸ʁ ʢར༻ऀ͕ҙࣝͤͣʹʣҰ࣌తͳݖݶΛऔಘ͢Δ࢓૊Έ "84Ϧιʔε΍֎෦Ϧιʔε͔Β"84ϦιʔεΛར༻͢Δ৔߹ʹ࢖༻ "84440Ͱ*".Ϣʔβʔͷ୅ସ͢Δ৔߹ʹ΋*".ϩʔϧΛ࢖༻ Role AWS STS ΫϨσϯγϟϧ

    ϓϩάϥϜ *".Ϣʔβʔͷ৔߹ *".ϩʔϧͷ৔߹ EC2 Πϯελϯε ϓϩάϥϜ EC2 Πϯελϯε Πϯελϯε಺ʹΞΫη εΩʔɾγʔΫϨοτΞ ΫηεΩʔΛຒΊࠐΉඞ ཁ͕͋Δ *".ϩʔϧ͕Ұ࣌తͳೝ ূ৘ใΛऔಘ͢Δɻ
  4. ڞ௨Ͱར༻͢ΔϙϦγʔͰ·ͣݕ౼͢Δͷ͸͜ͷͭ .'"ඞਢԽ͸ඞͣ͢Δ͜ͱ *1੍ݶ͸ɺӡ༻ϙϦγʔͱ૬ஊɻ࡞ۀ৔ॴΛ੍ݶͰ͖Δͱ͍͏ޮՌ͕͋Δ #jawsug_bgnr .'"ඞਢԽͱ*1੍ݶ \ &⒎FDU%FOZ  "DUJPO 

     $POEJUJPO\ /PU*Q"EESFTT\ BXT4PVSDF*Q<  > ^ ^  3FTPVSDF  ^ \ &⒎FDU%FOZ  /PU"DUJPO< JBN  >  3FTPVSDF   $POEJUJPO\ #PPM*G&YJTUT\ BXT.VMUJ'BDUPS"VUI1SFTFOUGBMTF ^ ^ ^
  5. 1SJODJQBMΛߜΒͳ͍ͱɺશϢʔβʔ͕εΠονͰ͖Δ σϑΥϧτςϯϓϨʔτͷઃఆ͸ɺΞΧ΢ϯτ಺ͷϢʔβʔʹରͯ͠ ߜΔඞཁ͕͋ΓɺϢʔβʔࢦఆͰߜΔʢάϧʔϓ͸Ͱ͖ͳ͍ʣ ผղͱͯ͠"TTVNF3PMFͷݖݶΛ͢΂ͯണୣͷ͏͑ͰɺඞཁͳϢʔβʔʹ ෇༩͢Δͱ͍͏ํ๏΋͋Δ #jawsug_bgnr εΠονϩʔϧͷ஫ҙ఺ \ 7FSTJPO 

    4UBUFNFOU< \ &⒎FDU"MMPX  1SJODJQBM\ "84 BSOBXTJBNSPPU ^  "DUJPOTUT"TTVNF3PMF  $POEJUJPO\^ ^ > ^ \ 7FSTJPO  4UBUFNFOU< \ &⒎FDU"MMPX  1SJODJQBM\ "84BSOBXTJBNVTFSUFTU VTFS ^  "DUJPOTUT"TTVNF3PMF  $POEJUJPO\^ ^ > ^