Upgrade to Pro — share decks privately, control downloads, hide ads and more …

IAM Access Analyzer を活用して最小権限を目指そう

IAM Access Analyzer を活用して最小権限を目指そう

「IAM Access Analyzer を活用して最小権限を目指そう」というタイトルで登壇した際の資料です

Avatar for YukihiroChiba

YukihiroChiba

May 19, 2021
Tweet

More Decks by YukihiroChiba

Other Decks in Technology

Transcript

  1. ࣗݾ঺հ  ઍ༿ ޾޺ • 2020 ΫϥεϝιουδϣΠϯ • 2021 APN

    AWS Top EngineerΑ • ޷͖ͳAWSΞΫγϣϯɿ • sts:AssumeRole
  2. ᶄ8"ϑϨʔϜϫʔΫηΩϡϦςΟͷப  • ΞΠσϯςΟςΟϕʔεϙϦγʔ • ϚωʔδυϙϦγʔ • AWS ؅ཧϙϦγʔ •

    ΧελϚʔ؅ཧϙϦγʔ • ΠϯϥΠϯϙϦγʔ ʮ΄ͱΜͲͷ৔߹ɺ࠷খݖݶͷݪଇʹैͬͯɺ ɹಠࣗͷΧελϚʔ؅ཧϙϦγʔΛ࡞੒͢Δඞཁ͕͋Γ·͢ɻʯ
  3. ᶄ8"ϑϨʔϜϫʔΫηΩϡϦςΟͷப  • ৚݅ɺϦιʔεɺΞΫγϣϯΛ࠷খԽ͢Δ • άϧʔϓ΍ଐੑʹΑΓಈతʹΞΫηεڐՄΛ༩͑Δ ʢݸʑͷϢʔβʔʹ෇༩͠ͳ͍ʣ • Ϧιʔε΍IAMΤϯςΟςΟʹΞλον͢ΔϙϦ γʔʹΑΓΞΫηεΛ੍ޚ͢Δ

    • Permissions boundary΍ABACΛ׆༻͢Δ ʮ͜ͷݪଇʹج͍ͮͯӡ༻͢Δͱɺҙਤ͠ͳ͍ΞΫηε੍͕ݶ͞Εɺ ɹɹ୭͕ͲͷϦιʔεʹΞΫηεͰ͖Δ͔؂ࠪͰ͖ΔΑ͏ʹͳΓ·͢ɻʯ
  4. ͭͷϙϦγʔλΠϓ  • ΞΠσϯςΟςΟϕʔεϙϦγʔ • ϦιʔεϕʔεϙϦγʔ • ΞΫηεڐՄͷڥքʢPermissions boundaryʣ •

    Organizations SCPʢαʔϏείϯτϩʔϧϙϦγʔʣ • ΞΫηείϯτϩʔϧϦετʢACLʣ • ηογϣϯϙϦγʔ ʁ ʁ ʁ ʁ ʁ ʁ ʁ ʁ ʁ
  5. ͭͷϙϦγʔλΠϓ  • ΞΠσϯςΟςΟϕʔεϙϦγʔ • ϦιʔεϕʔεϙϦγʔ • ΞΫηεڐՄͷڥքʢPermissions boundaryʣ •

    Organizations SCPʢαʔϏείϯτϩʔϧϙϦγʔʣ • ΞΫηείϯτϩʔϧϦετʢACLʣ • ηογϣϯϙϦγʔ ʁ ʁ ʁ ʁ ʁ ʁ ʁ ʁ ʁ 71$ΤϯυϙΠϯτϙϦγʔ͸ ͜͜ʹଐ͢Δ͕ɺ ʮͪΐͬͱ܅͕ͪ͘ͳ͍ʁʯͱ ࢥ͍ͬͯΔ
  6. ͭͷϙϦγʔλΠϓ  • ΞΠσϯςΟςΟϕʔεϙϦγʔ • ϦιʔεϕʔεϙϦγʔ • ΞΫηεڐՄͷڥքʢPermissions boundaryʣ •

    Organizations SCPʢαʔϏείϯτϩʔϧϙϦγʔʣ • ΞΫηείϯτϩʔϧϦετʢACLʣ • ηογϣϯϙϦγʔ ͍ΘΏΔʮIAMϙϦγʔʯ όέοτϙϦγʔɺIAMϩʔϧ৴པϙϦγʔͳͲ όέοτACLͳͲ IAMϩʔϧͷҾ͖ड͚࣌ʹઃఆՄೳ
  7. ͭͷϙϦγʔλΠϓ  • ΞΠσϯςΟςΟϕʔεϙϦγʔ • ϦιʔεϕʔεϙϦγʔ • ΞΫηεڐՄͷڥքʢPermissions boundaryʣ •

    Organizations SCPʢαʔϏείϯτϩʔϧϙϦγʔʣ • ΞΫηείϯτϩʔϧϦετʢACLʣ • ηογϣϯϙϦγʔ +40/ +40/ +40/ +40/ +40/
  8. *"."DDFTT"OBMZ[FSͷྺ࢙  • 2019/12 ϦϦʔε • S3ɺIAM ϩʔϧɺKMSɺLambdaɺSQSͷϦιʔεϕʔεϙϦγʔΛ෼ੳ • 2021/01

    ෼ੳର৅͕௥Ճ • Secrets Manager γʔΫϨοτʹରԠ • 2021/03 ʮࣄલݕূʯʹରԠ • ϦιʔεϕʔεϙϦγʔͷมߋલʹ෼ੳ͕Մೳ • ϚωδϝϯτίϯιʔϧͰ͸ S3 όέοτϙϦγʔͷΈ
  9. *"."DDFTT"OBMZ[FSͷྺ࢙  • 2019/12 ϦϦʔε • S3ɺIAM ϩʔϧɺKMSɺLambdaɺSQSͷϦιʔεϕʔεϙϦγʔΛ෼ੳ • 2021/01

    ෼ੳର৅͕௥Ճ • Secrets Manager γʔΫϨοτʹରԠ • 2021/03 ʮࣄલݕূʯʹରԠ • ϦιʔεϕʔεϙϦγʔͷมߋલʹ෼ੳ͕Մೳ • ϚωδϝϯτίϯιʔϧͰ͸ S3 όέοτϙϦγʔͷΈ ٸʹྲྀΕ͕มΘΔ
  10. *"."DDFTT"OBMZ[FSͷྺ࢙  • 2019/12 ϦϦʔε • 2021/01 ෼ੳର৅͕௥Ճ • 2021/03

    ʮࣄલݕূʯʹରԠ • 2021/03 ʮϙϦγʔνΣοΫʯʹରԠ • ϙϦγʔݕূʢValidationʣͱ΋ • ΞΠσϯςΟςΟϕʔεϙϦγʔ͕ϝΠϯ • AWS CLI Ͱ͸ SCP ΍ϦιʔεϕʔεϙϦγʔʹ΋ରԠ
  11. *"."DDFTT"OBMZ[FSͷྺ࢙  • 2019/12 ϦϦʔε • 2021/01 ෼ੳର৅͕௥Ճ • 2021/03

    ʮࣄલݕূʯʹରԠ • 2021/03 ʮϙϦγʔνΣοΫʯʹରԠ • ϙϦγʔݕূʢValidationʣͱ΋ • ΞΠσϯςΟςΟϕʔεϙϦγʔ͕ϝΠϯ • AWS CLI Ͱ͸ SCP ΍ϦιʔεϕʔεϙϦγʔʹ΋ରԠ • 2021/04 ʮϙϦγʔͷੜ੒ʯʹରԠ • ΞΠσϯςΟςΟϕʔεϙϦγʔͷΈ͕ର৅
  12. ΞφϥΠβʔͱΞυόΠβʔ  *"."DDFTT"OBMZ[FS *"."DDFTT"EWJTPS *".ΞΫηεʁ ΞφϥΠβʔʂ ΞυόΠβʔʂ Կ͕Ͱ͖Δ͔ ɾϦιʔεϕʔεϙϦγʔͷ෼ੳ ɾ֤छϙϦγʔͷݕূ

    ɾΞΠσϯςΟςΟϕʔεϙϦγʔͷੜ੒ ɾ*".Ϧιʔε୯ҐͰͷɺ ΞΫηεڐՄͱΞΫηεཤྺͷදࣔ αʔϏε͔Ͳ͏͔ ɾ"84αʔϏεͰ͋Δ ɾϦιʔε΋ଘࡏ͢Δ ɾαʔϏε༻ͷϩʔϧ΋ଘࡏ͢Δ ɾ"84αʔϏεͰ͸ͳ͍ ɾෳ਺ͷ"1*ʹΑΔػೳͷ໊শ ར༻ྉ ແྉͰࠓ͙͓͢࢖͍͍͚ͨͩ·͢ ແྉͰࠓ͙͓͢࢖͍͍͚ͨͩ·͢
  13. ϙϦγʔͷݕূͱ͸  • IAM Access Analyzer ʹΑΔػೳ • ҎԼͷϙϦγʔʹର͍͍ͯ͠ײ͡ͷνΣοΫΛͯ͘͠ΕΔ •

    ΞΠσϯςΟςΟϕʔεϙϦγʔ • SCPʢαʔϏείϯτϩʔϧϙϦγʔʣ※ϚωίϯෆՄ • ϦιʔεϕʔεϙϦγʔɹ※ϚωίϯෆՄ
  14. ஫ҙ఺ͦͷ  •ਫ਼ࠪͯ͘͠ΕΔͷ͸ Action ͷΈ •Resource ΍ Codition ʹ͸աڈͷΞΫςΟϏςΟ͸൓ө͞Ε ͳ͍

    ʮ͜ͷϢʔβʔ͸աڈ೔ؒͰ ಛఆͷ4όέοτʹରͯ͠ͷΈΞΫηεͯ͠Δ͔Β 3FTPVSDFͰ͜ͷ4όέοτ͚ͩʹߜΔͱ͍͍Αʯ ͳΜͯ͜ͱ͸ͯ͘͠Ε·ͤΜɻ
  15. ஫ҙ఺ͦͷ  •͢΂ͯͷαʔϏεͰ Action ϨϕϧͰਫ਼ࠪͯ͘͠ΕΔΘ͚Ͱ͸ͳ͍ ্هҎ֎ͷαʔϏε͸ ʮαʔϏεϨϕϧʯͰͷ ચ͍ग़ͩ͠Α ◦ IAM


    ◦ AWS KMS
 ◦ AWS Lambda
 ◦ AWS RAM
 ◦ Amazon RDS
 ◦ AWS Resource Groups
 ◦ Amazon S3
 ◦ AWS Security Token Service
 ◦ AWS Systems Manager
 ◦ IAM Access Analyzer
 ◦ Amazon CloudWatch
 ◦ Amazon Cognito Identity
 ◦ Amazon Cognito user pools
 ◦ Amazon EC2
 ◦ Amazon ECS
 ◦ Elastic Load Balancing

  16. ࠷ऴΞΫηε৘ใͷར༻ͱ͸  • IAM ΞΫηεΞυόΠβʔ ʹΑΔػೳ • IAMϦιʔεʢϢʔβʔ/άϧʔϓ/ϩʔϧ/ϙϦγʔʣ୯ҐͰҎԼΛ֬ ೝͰ͖Δ •

    ΞΫηεՄೳͳAWSαʔϏε • ࠷ऴΞΫηεཤྺ • ҎԼͷAWSαʔϏεʹରͯ͠͸ΞΫγϣϯϨϕϧͰ֬ೝՄೳ • Amazon S3 • Amazon EC2 • AWS IAM • AWS Lambda