èšäºã®å 容
AWS ã®ã¢ãŒããã¯ãã£ãèšèšããäžã§ãå°ãããã¢ãã¯ã ã£ããã§çè§£ãææ§ã ã£ãå
容ããã€ã³ããŸãšãããããã®
AWSã¢ãŒããã¯ãã£ã«ããããã£ãããšãã匱ç¹ã®çºèŠã«ããæŽ»çšãã ãã
察象è
SAP ã«åºããµãŒãã¹ããã£ããã©ããªãã®ãç¥ããã人
ã§
ã©ã®ãããèªåã®ãµãŒãã¹ç¥èãè¶³ããŠãã
ãã£ããææ¡ããã人
泚æ
çéãã€ã³ãæžãå
Œçµæ§ãªæç« éã§ã¢ããããŒããæ¿ããåéãªã®ã§ã
çŸæç¹ãšã®éãã誀èšãæ°ã«ãªã£ãå Žåã¯ããçšåºŠèš±å®¹ãã
ããããã§èª¿æ»ããé¡ãããŸãã
ãããŸã§çè§£ãçããšãããçºèŠããèªåã§è©³çްã確èªããåæã®èšäº
ä»¥äžæ¬æ
Amazon EC2é¢é£
RI
ãã¹ã¿ãŒã¢ã«ãŠã³ããå
±æããªãã«ããããšãã§ãã
ãªã¶ãŒãã ã€ã³ã¹ã¿ã³ã¹ (RI) å
±æããã©ã€ããŒãã«èšå®ããããšã¯ã§ããªã
ã¹ãããã€ã³ã¹ã¿ã³ã¹é¢é£
diversified æŠç¥
ã¹ãããã€ã³ã¹ã¿ã³ã¹
èªåãã¬ã€ã³
åæã«ä»ã®ã€ã³ã¹ã¿ã³ã¹ã«å€ããŠãããã·ã¹ãã
ã¹ãããã€ã³ã¹ã¿ã³ã¹ã¯åæ¢ã®2ååã«äžæéç¥ãè¡ã
倿§ãªå²ãåœãŠæŠç¥
æéãšãã£ãã·ãã£ã®äž¡é¢ã§ã®æé©æŠç¥ãè¡ãã
æè¿èãããã¡
ããªãŒããšã¯
EC2ã®ã°ã«ãŒãèšå®ããªã³ããã³ã2å²ãã¹ãããã€ã³ã¹ã¿ã³ã¹8å²ãªã©ã®èšå®ãã§ãã
åºå®ããªãŒã
æç¢ºã«ã¯ãããªåèªã¯ãªãããããšãã°ãªã³ããã³ãã®æ¹ãå¢ãããšãåºå®ããªãŒããå€ããªã©ãšãã£ã衚çŸãã§ããã
ãªã¶ãŒããã€ã³ã¹ã¿ã³ã¹
è²·ã£ãã¢ãã€ã©ããªãã£ãŸãŒã³ãšäœ¿ãã¢ãã€ã©ããªãã£ãŸãŒã³ã¯äžèŽããŠããå¿ èŠããã
EC2Rescue ããŒã«
EC2ã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ãã§ããããŒã«
AWS Systems Manager
Patch Manager
ãããŒãžã ã€ã³ã¹ã¿ã³ã¹ã«ã»ãã¥ãªãã£é¢é£ã®ã¢ããããŒããé©çšããããã»ã¹ãèªååãã
Linux ããŒã¹ã®ã€ã³ã¹ã¿ã³ã¹ã®å Žåã¯ãã»ãã¥ãªãã£ä»¥å€ã®æŽæ°ã®ããããã€ã³ã¹ããŒã«ããããšãã§ãã
Automation
AWS Systems Manager Automation ã¯ãAmazon EC2 ã€ã³ã¹ã¿ã³ã¹ããã®ä»ã® AWS ãªãœãŒã¹ã®äžè¬çãªã¡ã³ããã³ã¹ããã³å°å
¥ã¿ã¹ã¯ãç°¡çŽ åãã
èªååã«ãããæ¬¡ã®ããšãå¯èœã«ãªã
1 ã€ä»¥äžã® EC2 ã€ã³ã¹ã¿ã³ã¹ã®åèµ·åã Amazon Machine Image (AMI) ã®äœæãªã©ã®äžè¬çãªã¿ã¹ã¯ãå®è¡ããããã«äœ¿çšã§ãããäºåå®çŸ©ãããã¹ããããå«ãããã€ãã® Runbook ãçšæãããŠãã
State Manager
State Manager ã¯äž»ã«ãAmazon EC2 ããã³ãã€ããªãã ã€ã³ãã©ã¹ãã©ã¯ãã£ãå®çŸ©ããç¶æ
ã«ç¶æããããã»ã¹ãèªååãããå®å
šã§ã¹ã±ãŒã©ãã«ãªæ§æç®¡çãµãŒãã¹ãšããŠäœ¿çšãããããEC2 ã€ã³ã¹ã¿ã³ã¹ã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã«ã¯åœ¹ç«ããªã
ã€ã³ã¹ã¿ã³ã¹ãèµ·åãããã¿ã€ãã³ã°ã«ç¹å®ã®ã¢ã¯ã·ã§ã³ãå®è¡ãããå Žåã«ã¯ ã¹ããŒããããŒãžã£ãé©ããŠãã
ã¡ã³ããã³ã¹ãŠã€ã³ããŠã§ãããããå³å¯ã«å
šãŠã®çšŒåããŠããã€ã³ã¹ã¿ã³ã¹ã«ãããåœãŠãè¡ãå Žåãªã©ã¯ããã䜿ãã®ããã
Systems Manager ã¯ããŒã®ããŒããŒã·ã§ã³ãã§ããªã
AWS CloudFormation ã«ã¯ Systems Manager ãã©ã¡ãŒã¿ ã¹ã㢠RotationSchedule ãªãœãŒã¹ããªã
ãã¡ã€ã«ã·ã¹ãã é¢é£
Amazon S3
ãªã¯ãšã¹ã¿æ¯æãããªã³ã«ããŠãããšã宿œè ã«è«æ±ããã
Glacier
æšæºååŸã䜿çšãããšéåžž3ïœ5æéããã
S3 Glacier volt
æ€çŽ¢ã¯äœ¿ããªã
S3 Transfer Acceleration
ã¢ããããŒããé«éåã§ãã
S3眲åä»ãURL
IAM User ã¢ã«ãŠã³ããæã£ãŠããªã人ã«å¯ŸããŠäžæçã«ãã¡ã€ã«ã®ããŠã³ããŒãïŒã¢ããããŒãããããå Žåãªã©ã«äœ¿çšãã
S3 ã®ããŒãžã§ã³ç®¡ç
ããŒãžã§ã³ç®¡çããªã³ã«ããå㯠nullããã以éã¯ã1ã2ãšå¢ããŠããã
S3 ã«ã¯ãã¹ãªãŒãžã§ã³ã¬ããªã±ãŒã·ã§ã³ã¯ããïŒ
ãã
NFS å ±æ
ãããã¯ãŒã¯ãã¡ã€ã«ãµãŒããŒã®ç¥
Amazon EFS
ããããžã§ã³ãã¹ã«ãŒããã
ããããããªãããã¬ã€ãã³ã·ãŒãæå€§åãããããªãã®ã§ã¯ãªããäžå®ã®é床ãä¿èšŒãããã®
EFS Lustre
EFS ã®å
±æãã¡ã€ã«ã·ã¹ãã ã匷åãããã®
ã¹ã±ãŒã«ã¢ããåãªã®ã§ãããã©ãŒãã³ã¹ãäžãããã
Amazon FSx for Lustre
EFS ã®ãããçãå ±æã¹ãã¬ãŒãžã®ã¯ãªãã£ã«ã«ãã€ã³ãã®å¹çãäžããããªããã
EFS ããããžã§ã³ã ã¹ã«ãŒããã ã¢ãŒã
ããããžã§ã³ã ã¹ã«ãŒããã ã¢ãŒãã䜿çšãããšãä¿åãããŠããããŒã¿ã®éã«é¢ä¿ãªãããã¡ã€ã« ã·ã¹ãã ã®ã¹ã«ãŒããããæå®ã§ãã
èªèšŒç³»
enableDnsHostnamesãšenableDNSsupport
enableDnsHostnames
VPC å
ã®ã€ã³ã¹ã¿ã³ã¹ããããªã㯠IP ãæã€ãšãã«ã
ãã®ã€ã³ã¹ã¿ã³ã¹ã«ãããªã㯠DNS ãã¹ãåãèªåã§ã¢ã¿ããããããå¶åŸ¡ãã屿§ã
enableDNSsupport
AWS Provided DNS ããVPC å
ã€ã³ã¹ã¿ã³ã¹ã®åå解決ããµããŒãããããå¶åŸ¡ãã屿§ã§ãã
åèïŒhttps://walk0204.hatenablog.com/entry/tech/aws/vpc/DNS-attribute
x-amz-server-side-encryption
x-amz-server-side-encryptionâ:âAES256â³ããããŒãèšå®ããŠå©çšãã
âx-amz-server-side-encryptionâ:âaws:kmsâããããŒãèšå®ããŠå©çšãã
SCP
SCP ã¯ãµãŒãã¹ã«ãªã³ã¯ãããããŒã«ã«ã¯åœ±é¿ããªã
AWS ããããŒãžãã§èªåã§æ€åºããŠäœæããŠããã
ããã©ã«ãã§ã¯å
šãŠèš±å¯ãããŠãã
SCP ã®ããã©ã«ã
ããã©ã«ãã§ã¯ãã¹ãŠã®ã«ãŒããOUãã¢ã«ãŠã³ãã« FullAWSAccess ãšãã ããªã·ãŒãã¢ã¿ãããããŠãã
ACM é¢é£
ACM ããã®åã SSL èšŒææžãè€æ°ã® AWS ãªãŒãžã§ã³ã§äœ¿çšã§ããã®ã¯ãApplication Load Balancer ã§ã¯ãªããCloudFront ãã£ã¹ããªãã¥ãŒã·ã§ã³ã«ã®ã¿ã¢ã¿ããããŠããå Žåã®ã¿
Amazon Cognito
æ°çŸäžã®federationãŠãŒã¶ãŒããã©ããŒãã
Amazon Cognito ã¯æ°çŸäžã®ãŠãŒã¶ãŒã«æ¡åŒµã§ããFacebookãGoogleãAmazon ãªã©ã®ãœãŒã·ã£ã« ã¢ã€ãã³ãã£ã㣠ãããã€ãããSAML 2.0 ãä»ãããšã³ã¿ãŒãã©ã€ãº ã¢ã€ãã³ãã£ã㣠ãããã€ãã«ãããµã€ã³ã€ã³ããµããŒããã
SAML2.0
SAML 2.0 ããŒã¹ã®ãã§ãã¬ãŒã·ã§ã³ã§ã¯ãœãŒã·ã£ã« ã¡ãã£ã¢ ãã°ã€ã³ã䜿çšããããéçã³ã³ãã³ãã®é åžã«ã¯ S3 ãã±ããããã CloudFront ã䜿çšããæ¹ãé©åã§ãã
AWS Control Tower
çµç¹å ã® AWS ã¢ã«ãŠã³ããç£èŠããããã« CloudWatch ããã³ CloudTrail ã«ãã°ãéä¿¡ã§ãã
AWS Certificate ManagerïŒACMïŒ
ãªãŒãžã§ã³ããšã« SSL/TLS èšŒææžãå¿ èŠ
ACMã«ãããå ¬éèšŒææžãšãã©ã€ããŒãèšŒææžã®éããšã¯
ãããªãã¯ãªèªèšŒæ©é¢ã§èšŒæããããŠãããã®ãå
¬éããããªãã¯èšŒææž
ãã©ã€ããŒãèšŒææžã¯ CA ã ACM ã§ç«ãŠãŠãå©çšãããã®ã§ããã©ãŠã¶åŽã§ã®èªèšŒèšå®ãå¿
èŠ
RAM
enable-sharing-with-aws-organizations
ã¯ãã¹ã¢ã«ãŠã³ãã®å¿
èŠã¯ãªã
Amazon Route53
DNSSEC 眲åããµããŒãããŠãã
Route53 ãšã€ãªã¢ã¹ã¬ã³ãŒã
CNAME ã¬ã³ãŒãã¯äžåAã¬ã³ãŒããçµç±ããã®ã§ããšã€ãªã¢ã¹ã¬ã³ãŒãã®æ¹ãå¹çãè¯ã
ãšã€ãªã¢ã¹ã¬ã³ãŒããš C ã¬ã³ãŒãã®éã
ãšã€ãªã¢ã¹ã¬ã³ãŒãïŒAWS ç¬ç¹ã®ãã® C ã¬ã³ãŒããããæ€çŽ¢å¹çãé«ã
C ã¬ã³ãŒãã¯äžåºŠãA ã¬ã³ãŒããèŠã«ãããªããšã¢ãã¬ã¹ãããããªãã®ã§ãå°ãå¹çãæªã
100G ã®ããŒãã¹ããŒãã§æå€§2ã€ã®æ¥ç¶ããŸãã¯100 G æªæºã§æå€§4ã€ã®æ¥ç¶ã䜿çšã§ãã
SAML2.0
ãããã£ãèªèšŒã·ã¹ãã ãAWS ã§ã¯ federation ã SAML ããCognito ããšãã£ãå ·åã§åããããã
AWS IAM Identity Center
AWS IAM Identity Center ã¯ãWeb ãã©ãŠã¶ãä»ããããžãã¹ ã¢ããªã±ãŒã·ã§ã³ãžã®ã·ã³ã°ã« ãµã€ã³ãªã³ã®ã¿ããµããŒããã
ã§ããããšïŒè€æ°ã®AWSã¢ã«ãŠã³ããžã®ã·ã³ã°ã«ãµã€ã³ãªã³
AWS Direct Connect
Direct Connect + AWS Site-to-Site VPN ãå©çšãããå ŽåãPrivate VIF ã§ã¯ãªã Public VIF ãå©çšããå¿
èŠããããŸãã
Direct Connect ã®ç©ççãªåç·ã connection ã§ããããè«ççã«åãããã®ããVIFãšãªãã
conncetion ããšã®èª²éã®ãããåå²ããŠãæéã¯å€§ããã¯å€ãããªã
ãã®å Žå㯠VLAN500ãVLAN400ãšãã£ã圢ã§åãã
ãã ã10åããããªãããããããã100åãšããªããšããã®å VIF ãåãã®ã¯ããã©ãã®ã§ããã©ã³ãžããã²ãŒããŠã§ã€ã®åºçªã«ãªã
ãã©ã€ããŒã VIF çµç±ã§ãVPCå€ã®ãªãœãŒã¹ã«è§Šãããå Žåã¯ãã€ã³ã¿ãŒãã§ãŒã¹åã®ãšã³ããã€ã³ãïŒprivate LinkïŒãæå¹
ã²ãŒããŠã§ã€åã®ãšã³ããã€ã³ãã§ã¯ããªã³ãã¬ãã¹ãµãŒããŒããééçã«ãµãŒãã¹ã«ã¢ã¯ã»ã¹ã§ããªã
ãããªãã¯VIF
Direct Connect ã®è«çåºåãã®äžã€
VP Cå€ã®ãµãŒãã¹ã«ã¢ã¯ã»ã¹ããããã®ãã®ã§ããããªã㯠IP ã§ã€ãªãããã®
S3 ã DynamoDB ã察象
AWS æäŸã®ãããªã㯠IP ã¢ãã¬ã¹å士ãç¹ãã
Direct Connect ãªã³ã¯ã¢ã°ãªã²ãŒã·ã§ã³ã°ã«ãŒã
Direct Connect ã®åç·ã匷åãã
Link Aggregation Group
è€æ°ã®æ¥ç¶ãéçŽãããããã 1 ã€ã®ãããŒãžã忥ç¶ãšããŠæ±ãããšãå¯èœã«ããè«çã€ã³ã¿ãŒãã§ã€ã¹
VPC ã«ã€ã Direct Connect æ¥ç¶ããªãã匟ããïŒ
1ããŸã§ã²ãããVPG ã VPC ã«ã€ãäžåã¥ã€ãdirectConnect ã¯äžã€ã§è¯ã
1DirectConnect ã«è€æ°ã® VPC ããã£ã€ãããããã
1VPC ã«è€æ°ã® Direct Connect ã¯ãã£ã€ããããªã
External id
ã¯ãã¹ã¢ã«ãŠã³ãããŒã«ã§çšãããã®
èªç±ã«èšå®ã§ãã
ããŒã«ã®äœææã«èšå®ãããã®
WebSocket ã®ãããã³ã«
WSSãSSL ã§ã¯ããããHTTPS ãšã¯å¥ç©
AWS STS
Security Token Service
ãã®ãŸãŸ
VPC ãšã³ããã€ã³ãããªã·ãŒ
VPCãšã³ããã€ã³ãã«ä»ããããªã·ãŒ
ãã±ãã:Bucket-AAAA ãžã®ã¢ã¯ã»ã¹èš±å¯ãªã©èšå®ã§ãã
AWS PrivateLink
VPC ãã¢ãªã³ã°ãšäŒŒãŠããããVPC ãšã³ããã€ã³ãã2ã€äœæãããã©ã€ããŒãæ¥ç¶ãã§ãããµãŒãã¹
aws:SecureTransport
ãããtrueã«ããããšã§ãhttpséä¿¡ããã¹ãã«ããèšå®
SSE-**
管çãç°¡åé ã§èšããšãSSE-S3ãSSE-KMSã
SSE-S3 ã§ã¯ãAmazon S3 ãããŒã¿ãšæå·åããŒã管çããå¿
èŠããã
SSE-C ã§ã¯ãæå·åããŒã管çããå¿
èŠããã
SSE-KMS ã§ã¯ãAWS ãããŒã¿ããŒã管çããå¿
èŠãããããã«ã¹ã¿ããŒãã¹ã¿ãŒã㌠(CMK) 㯠AWS KMS ã§ç®¡çãã
Server Name Indication
ããŒãã®äžã® PC ã«æ¯ãåããããä»çµã¿
äžã€ã®ã°ããŒãã«ã¢ãã¬ã¹ã§ãããŒããæ¯ãåããããšã§å®çŸãå¯èœ
IP ã¢ãã¬ã¹ã®æ¯æžåé¡ã«ãäžåœ¹è²·ã£ãŠãã
AWS Lake formation
AWS ã§ããŒã¿ã¬ã€ã¯ãæ§ç¯ã»éçšããããã®ãããŒãžããµãŒãã¹
å®äœã¯ãã»ãŒ AWS ã®åçš®ãµãŒãã¹ãã©ãããããã®(Glue, IAM, S3, etc.ïŒ
LDAPãµãŒããŒ
LDAP ã®èªèšŒãµãŒãã¹ãSAML èªèšŒã®äžç°ãªã©ã§äœ¿çšããã
AWS Config
EC2 ã€ã³ã¹ã¿ã³ã¹ã®ã»ãã¥ãªã㣠ã³ã³ãã©ã€ã¢ã³ã¹
MFA Delete
S3 ã®ããŒãžã§ãã³ã°æ©èœã®ãªãã·ã§ã³
ãªããžã§ã¯ãã®ããŒãžã§ã³ãåé€ãããšãã« AWS ã¢ã«ãŠã³ãã® MFA ããã€ã¹ã«è¡šç€ºããã6æ¡ã®ã³ãŒãå
¥åãå¿
é ã«ãªã
ã·ã¹ãã 管çè ïŒSystemAdministratorïŒ
éçºã»éçšãªãœãŒã¹ã®ã»ããã¢ãããã¡ã³ããã³ã¹ãè¡ããŠãŒã¶ãŒçšã®ããªã·ãŒ
ååçã«åŒ·æš©éã®ããã«èŠããããEC2ã LambdaãRDS ãšãã£ããAWS ã®åºæ¬çãªãµãŒãã¹ã®äœæã»ã¡ã³ããã³ã¹ãèš±å¯ããããªã·ãŒãªã®ã§ãPowerUserAccess ããæš©éã¯åŒ±ã
éçºè ãã¯ãŒãŠãŒã¶ãŒïŒPowerUserAccessïŒ
Admin æš©éã«äžŠã¶åŒ·æš©éãªããªã·ãŒ
IAM ãš Organization ãš Account 以å€ã® Action ãå
šãŠèš±å¯ããéçºè
åãã®ããªã·ãŒ
VPN CloudHub
åäžã®ä»®æ³ãã©ã€ããŒãã²ãŒããŠã§ã€ãäœæããè€æ°ã®ã«ã¹ã¿ããŒã²ãŒããŠã§ã€ãåçã« AWS Site-to-Site VPN æ¥ç¶ãäœæããæµãã§æ¥ç¶ãã
AWS VPN CloudHub ã¯ãVPC ã®æç¡ã«ããããã䜿çšã§ããã·ã³ãã«ãªããã¢ã³ãã¹ããŒã¯ã¢ãã«ã§åäœãã
ã¢ã¯ã»ã¹èš±å¯ããªã·ãŒãšä¿¡é Œããªã·ãŒã®éã
ãã«ã¡ããã被ãããšãã§ããããªã·ãŒãä¿¡é Œããªã·ãŒ
ãã©ã¬ã¹ãä¿¡é Œé¢ä¿
Windows ã§ãã¡ã€ã³ãä¿¡é Œã§ããã®ã ãã芪å士ãçµã¶ãšããã®åäŸãå
šéšä¿¡é Œé¢ä¿ãçµã°ãããã®
3è
éã§ã¯ã§ããªã
AssumeRoleWithSAMLãšAssumeRoleAPIãšAssumeRoleWithFederationãAssumeRoleWithWebIdentityã®éãã調ã¹ã
AssumeRoleWithSAMLïŒ
SAML ãçšããããŒã«ä»äžã®åœ¢ãåºæ¬å¥éã«ã¹ã¿ã idpãçšæã䜿çšããã€ã¡ãŒãž
AssumeRoleAPIïŒ
ãŠãŒã¶ãŒãããŒã«ã䜿çšããŠã¢ã¯ã»ã¹ãã§ããããã«ããä»çµã¿ãã¯ãã¹ã¢ã«ãŠã³ããªã©ã§æš©éãæž¡ããšãã«ãã䜿ããã
AssumeRoleWithFederationïŒ
Google ãªã© Web ã¢ããªèªèšŒãçšããŠãç¹å®ã®ããŒã«ã®æš©éãä»äžã§ããããã«ããä»çµã¿
AssumeRoleWithWebIdentityïŒ
ã«ã¹ã¿ã IDãããã€ããŒ
Lambda ãªã©ã§æ§ç¯ã§ãã
AWS Transfer Family ã®äžæ©èœ
Secrets Manager ãšçµã¿åãããŠäœ¿ãã®ãäžè¬ç
ã»ãã¥ãªãã£é¢é£
IPsec
ãããªãã¯ã€ã³ã¿ãŒãããã«åºãŠãããã®
æå·åã¯ãããŠãã
ããŒãã¹ãã£ã³
éä¿¡å¯èœãªããŒããäžã€äžã€ç¢ºããã
ã»ãã¥ãªãã£æ»æãšããŠã䜿ããã
ãªãœãŒã¹ããŒã¹ã®ããªã·ãŒã䜿çšããã¯ãã¹ã¢ã«ãŠã³ã ã¢ã¯ã»ã¹ã®å©ç¹
ãªãœãŒã¹èªäœã«ã¢ã¿ãããããã®ã§ãæš©éã® json ã« Resource ã®èšèŒã¯å¿
èŠãªã
ãªãœãŒã¹ããšã«èšå®ããå¿
èŠããªãã®ã§ãECR ã®ãªããžããªãããããããå Žåãªã©ã¯ããªãœãŒã¹ããŒã¹ã«ãããšãŸãšããŠäžåã«ã§ãã
Fraud Detector
S3 ã® csv ãªã©ã察象ã«ãæ å ±æµå€±ã«ç¹ãããããªå人æ å ±ãªã©ãæ€ç¥ããŠããã
SYN ãã©ãã
éå°ãªæ°ã® SYN ãªã¯ãšã¹ããéä¿¡ãããµãŒããŒæ»æïŒTCP éä¿¡ã®ãã³ãã·ã§ã€ã¯ã®ç¬¬äžæ©ïŒ
UDP ãªãã¬ã¯ã·ã§ã³
UDP ã«ãŠãéä¿¡å ãåœè£ ããéä¿¡ãè¡ãã倧éã®è¿ä¿¡ãã±ããã§å¯Ÿè±¡ã®IPã«æ»æãããããããš
Security Token Service
STSã®ããš
ãã¹ã«ã¬ãŒãæ»æ
ãããããªãããŸãæ»æ
ãã¹ã«ã¬ãŒãæ»æã¯ãçãŸãããã¹ã¯ãŒããšãã°ãªã³ã䜿çšããŠãããã°ã©ã ã®ã®ã£ãããç¹å®ããããèªèšŒããã»ã¹ã®åé¿æ¹æ³ãèŠã€ããããšã«ãã£ãŠå®è¡ã§ãã
X.509èšŒææž
TLSãªã©ã§äœ¿çšãããèšŒææž
å
¬ééµèšŒææžã®æšæºãã©ãŒããã
ãããªãã¯èšŒææž
ãããªãã¯èšŒææžã¯ãããªãã¯èªèšŒå±ããçºè¡ããããããã®ãããªãã¯èªèšŒå±ã¯ç£æ»æ³äººããå³ãã審æ»ããã¹ããŠãã
ãã®ãããã©ãŠã¶ããããã©ã«ãã§ä¿¡é Œããã
äžæ¹ãã©ã€ããŒãèšŒææžã¯å¯©æ»ãåããŠããªããã©ã€ããŒãèªèšŒå±ããçºè¡ããã
ãã©ã€ããŒãèšŒææžã¯ãã®æå¹æéã屿§ãªã©ãèªç±ã«èšå®ã§ãããããã®èšŒææžããã©ãŠã¶ãä¿¡é Œããããã«èšå®ããå¿
èŠãã
ã©ãããçµç¹å
ãªã©ã®ãã©ã€ããŒããããã¯ãŒã¯ãªã©ã§äœ¿ãããæã«äœ¿ãããããã
AWS CloudTrail
ã°ããŒãã«ãµãŒãã¹ãªãã·ã§ã³
以äžãã°ããŒãã«ãµãŒãã¹
AWS Identity and Access Management (IAM)ãAWS STSãAmazon CloudFrontãRoute 53
CloudFrontã®å°åå¶éæ©èœ
[åœ] ã§ãèš±å¯ãŸãã¯ãããã¯ããåœãéžæãããšå®çŸã§ãã
IAM ãããã¡ã€ã«
ããŒã«ã EC2 ã«çŽã¥ããããã«å¿
èŠ
ãããã¡ã€ã«ãããŒã«ãšçŽä»ããEC2ãšãããã¡ã€ã«ãçŽã¥ãããšã§éæã§ãã
SSL èšŒææžã IAMã«å ¥ããããïŒ
å
¥ãããã
æ ACM ããªããšãã¯ããããŠããïŒCLI ãããªããšå
¥ãã¥ããïŒ
AWS Network Firewall
ã¹ããŒãã¬ã¹ãªãã±ãããã£ã«ã¿ãªã³ã°ãã¹ããŒããã«ãªãã±ãããã£ã«ã¿ãªã³ã°ãå¯èœ
ãã©ã³ãžããã²ãŒããŠã§ã€ãšçŽä»ããããšã§ãã¢ãŠãããŠã³ãã®å
±éãããããã¯ãŒã¯å¶åŸ¡ãå¯èœ
ãã©ã³ãžããã²ãŒããŠã§ã€ã®äœ¿çšã€ã¡ãŒãž
å¥ã¢ã«ãŠã³ããªã RAM ã䜿çšããŠãªãœãŒã¹ã®å
±æããã
ã¢ã¿ããã¡ã³ããäœæãã(VPC ãš TGW ãçŽä»ããïŒ
ã«ãŒãããŒãã«ã«çµè·¯ã远å ãããã©ã³ãžããã²ãŒããŠã§ã€ã«åããããã«ãã
AWS Control Tower
ãã¬ãŒãã¬ãŒã«ããã©ã³ãã£ã³ã°ãŸãŒã³ããããã·ã¥ããŒããã®æŠå¿µãããªã
ã»ãã¥ãªãã£çµ±å¶ã®åŸ¹åºããã°ã®äžå
管çãã€ã³ã·ãã³ãçºçæã®èšŒè·¡ãç®çãšãããµãŒãã¹
ãã¹ããã©ã¯ãã£ã¹çãªãã°éçŽã¢ã«ãŠã³ããç£æ»ã¢ã«ãŠã³ããèªåæ§ç¯ããŠããã
ãããã¯ãŒã¯ ACL
ãããã¯ãŒã¯ ACL ã¯ã¹ããŒãã¬ã¹ãå ¥ãå£ã§èš±å¯ãããããšãã£ãŠåºå£ã§èªåééããèš³ã§ã¯ãªã
DevOps é¢é£
AWS App Runner
ããçšåºŠé èœãããã³ã³ãããã¹ãã£ã³ã°ãµãŒãã¹
App Runner ã¯æãç°¡åãªæ§æã§ããã°ãœãŒã¹ã³ãŒããªããžããªããèšå®ããã°ãããã€ãå¯èœ
AWS Elastic Beanstalk
AWS ã®çšæããç°å¢ã§å®æœã§ãã
ãœãŒã¹ã³ãŒãã®ã¢ãããå¯èœ
ããã«ãŒã³ã³ããããã®ãŸãŸãšããããã§ã¯ãªã
AWS OpsWorks
EC2ã€ã³ã¹ã¿ã³ã¹ããªã³ãã¬ã®ç°å¢ã§ã®ãµãŒãèšå®ããããã€ã管çãèªååã§ãã
CloudFormation ã¯ã»ãŒãã¹ãŠã®ãªãœãŒã¹ãäœæå¯èœ
OpsWorks ã¯ã¢ããªã±ãŒã·ã§ã³åšãã®ãªãœãŒã¹äœæã«éããã
Amazon CloudSearch
CloudSearch ã Elasticsearch ã Lucene ããŒã¹
ãŠã§ãããŒãžãããã¥ã¡ã³ããã¡ã€ã«ãªã©ã®å€§èŠæš¡ãªããŒã¿ããã®æ€çŽ¢ãå¯èœãšãããã«ãããŒãžãåãµãŒãã¹
AWS OpsWork
ã¬ã€ã€ãŒãšã¯
ã¬ã€ã€ãŒã¯ãã¢ããªã±ãŒã·ã§ã³ãžã®ãµãŒãã¹æäŸãããŒã¿ããŒã¹ãµãŒããŒã®ãã¹ãã®ãããªç¹å®ã®ç®çãæããäžé£ã® EC2ã€ã³ã¹ã¿ã³ã¹
ã¬ã·ããšã¯
Chef ã¬ã·ããå®è¡ããŠãã¢ããªã±ãŒã·ã§ã³ã®èšå®ãã¢ããªã±ãŒã·ã§ã³ã®ãããã€ãã¹ã¯ãªããã®å®è¡ãªã©ãè¡ã
äŸïŒPHPã®ãŠã§ããµãŒããŒäŸ
package "vim-enhanced" do
action :install
end
%w{php mysql-server httpd}.each do |p|
package p do
action :install
end
end
service "httpd" do
action [:start, :enable]
end
AWS CloudFormation
StackSet
StackSet ã䜿ãããšã§ãOrganization ã«ç°¡åã«åæ ã§ãã
CloudFormation ã®ãªãŒãžã§ã³ãã©ã¡ãŒã¿ïŒ
ãããªãäžè¬çã«ã¯ãªã
CloudFormation:Deletionããªã·ãŒ
snapshot ãš retain ããã
snapshot ã¯ãã®æ
å ±ãä¿åãã€ã³ã¹ã¿ã³ã¹ã¯åæ¢ãããRDS ãªã©ã«åããŠãã
CloudFormation:Serviceã«ã¿ãã°
CloudFormation ã®ãã³ãã¬ãŒããæµçšããããšãã§ãããµãŒãã¹
é¢é£ãŠãŒã¶ãŒã« Service ã«ã¿ãã°ã ãäœããæš©éãäžãããªã©ãããéçš
Cloud formation ã®ã¢ãŒãã£ãã¡ã¯ããšã¯
ãã³ãã¬ãŒãããã®å±¥æŽæ å ±
CloudFormation ãªãœãŒã¹ãã¿ã°ãããããã£
ããã§è«æ±ããŸãšããããšãã§ãã
CloudFormation:update-stack APIïŒ
CloudFormation ã®å€æŽå·®åãæŽæ°ããAPI
CloudFormation:ãªãŒãžã§ã³éã®VPCã¹ã¿ãã¯äœæ
Stack Setsãè¯ãã
Stack Sets
CloudFormation ã®ããŒãžã§[StackSets]ã«å
¥ããæ°ãã StackSetsãäœæã§ãã
åæ§ã®ãã³ãã¬ãŒããè€æ°ãªãŒãžã§ã³ã«æ¡åŒµããä»çµã¿
CloudFront Function ãš Lambda@Edgeã®éã
ã¯ããããã«ãããã
AWS CodeArtifact
AWS CodeArtifact ã¯ããã±ãŒãžãããŒãžã£ããŒã«(MavenãGradleãnpmãYarnãTwineãpipãNuGetãªã©)ã§ããŠã³ããŒãããããã±ãŒãžã管çãããµãŒãã¹
OutPosts
ãŠãŒã¶ãŒç°å¢ã§ AWS ã宿œã§ããããã«ãããã®
Elastic BeansTalk ãš OpsWork ã®éã
OpsWork 㯠chef ã䜿ã£ããµãŒããŒæ§ç¯ã®ä»çµã¿ãElastic Beans Talk ã¯ããã±ãŒãžåãããã³ã³ããæäŸãµãŒãã¹
Amazon WorkDocs
Amazon WorkDocs ã¯ããã«ãããŒãžãåã®å®å
šãªã³ã³ãã³ãäœæãã¹ãã¬ãŒãžãããã³ã³ã©ãã¬ãŒã·ã§ã³ ãµãŒãã¹
Microsoft ADãæŽ»çšããããã¡ã€ã«å
±æã·ã¹ãã ããã¡ã€ã³ãæ¿èªãã圢ã§ãã¡ã€ã«ãªã©ãå
±æã§ãã
AWS CodeDeploy
æåå°ãã ããã©ãã£ãã¯ãæ°ããŒãžã§ã³ç°å¢ã«æµã
æ¬¡ã«æŽã«æ°ããŒãžã§ã³ç°å¢ã«ãã©ãã£ãã¯ãæµãããšèšãããšãç¹°ãè¿ãåŸã
ã«åŸã
ã«æ°ããŒãžã§ã³ç°å¢ãžãã©ãã£ãã¯ãæµããæçµçã«ãã¹ãŠã®ãã©ãã£ãã¯ãæ°ããŒãžã§ã³ç°å¢ãžæµã
âãããªãã¢ã
æåå°ãã ããã©ãã£ãã¯ãæ°ããŒãžã§ã³ç°å¢ã«æµã
åé¡ãªããã°ãåçç¡çšã§ãã¹ãŠã®ãã©ãã£ãã¯ãæ°ããŒãžã§ã³ç°å¢ã«æµã
âããCanaryïŒã«ããªã¢ïŒã
AWS Outposts
AWS Outposts ã¯ãAWS ã€ã³ãã©ã¹ãã©ã¯ãã£ããµãŒãã¹ãAPIãããŒã«ãé¡§å®¢ã®æœèšã«æ¡åŒµãããµãŒãã¹
ããã«ããã顧客㯠AWS ãªãŒãžã§ã³ãšåãããã°ã©ãã³ã° ã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããŠããªã³ãã¬ãã¹ã§ã¢ããªã±ãŒã·ã§ã³ãæ§ç¯ããã³å®è¡å¯èœ
ç§»è¡ãµãŒãã¹ã§ã¯ãªã
æå°æªåŠçã«ãŒãã£ã³ã°ã¢ã«ãŽãªãºã
æå°æªåŠçãªã¯ãšã¹ã (LOR) ã¢ã«ãŽãªãºã ã¯æ°ãããªã¯ãšã¹ããå°çãããšãããŒã ãã©ã³ãµãŒã¯æªåŠçã®ãªã¯ãšã¹ãã®æ°ãæãå°ãªãã¿ãŒã²ããã«ãªã¯ãšã¹ããéä¿¡ãã
ã©ãŠã³ãããã³ã¢ã«ãŽãªãºã
ã³ã³ãã¥ãŒã¿ ã·ã¹ãã ãæã€ãªãœãŒã¹ããé çªã«å©çšããææ³ã®1ã€
Immutable
All at once ã¯äžåºŠã€ã³ã¹ã¿ã³ã¹ã忢ãã
Immutable ã¯äžåãããã€ããŠãåé¡ãªããã°ããšããããã€ããã®ã§ãå°ãããã©ãŒãã³ã¹ã¯äœäžããããã ããæå¹ãªéžæè¢
light sail
Amazon Lightsailã¯ã³ã³ãã¥ãŒãã£ã³ã°ãã¹ãã¬ãŒãžãããŒã¿è»¢éãªã©ãWebãµã€ããWebãµãŒãã¹ãªã©ã«äœ¿ããµãŒããŒãšããŠå¿
èŠãªæ©èœãçµã¿åããã1ã€ã«ãŸãšããããã±ãŒãžã§æäŸãããŠãã
Amazon Lightsailã«ã¯ãã³ã³ãã¥ãŒãã£ã³ã°ç°å¢ã ãã§ãªããã¹ãã¬ãŒãžãã¹ãããã·ã§ãããããŒããã©ã³ãµãŒæ©èœããã¡ã€ã¢ãŠã©ãŒã«ãDNSæ©èœãªã©ãããã€ãã®æ©èœãæã£ãŠãã
äžæ¹ãAmazon EC2 ã§æäŸããŠããã®ã¯ãã³ã³ãã¥ãŒãã£ã³ã°ç°å¢ã ã
Amazon LightSail
ããã±ãŒãžã³ã°ããããµãŒãã¹å
Ž
OS ã CMS ãããããããŠæäŸãããŠãããã¯ãŒããã¬ã¹ãªã©ããã
AIé¢é£
Amazon Macie
Macieã¯S3ã«å¯ŸããŠã®ãã®ãcodecommit ã«ã¯é©å¿ã§ããªã
Amazon Lex
Amazon Lex ã¯ãé³å£°ãšããã¹ãã䜿çšããŠä»»æã®ã¢ããªã±ãŒã·ã§ã³ã«äŒè©±åã€ã³ã¿ãŒãã§ã€ã¹ãæ§ç¯ããããã®ãµãŒãã¹
Amazon Lex ã¯ãé³å£°ãããã¹ãã«å€æããããã®èªåé³å£°èªè (ASR) ãšããã¹ãã®æå³ãèªèããããã®èªç¶èšèªçè§£ (NLU) ãšããé«åºŠãªæ·±å±€åŠç¿æ©èœãæäŸããéåžžã«é
åçãªãŠãŒã¶ãŒãšã¯ã¹ããªãšã³ã¹ãšæ¬ç©ã®ãããªäŒè©±ã®å¯Ÿè©±ãåããã¢ããªã±ãŒã·ã§ã³ãæ§ç¯ã§ããããã«ãã
Amazon Transcribe
é³å£°ãããã¹ãã«å€æããæ©èœ
Amazon Translate
è³æã翻蚳ããŠããããã®ãå€ãã®è³æã翻蚳ãããå Žåã¯äœ¿ã£ãŠããããã
Amazon Textract
ã¹ãã£ã³ããããã¥ã¡ã³ãããããã¹ããææžãæåãã¬ã€ã¢ãŠãèŠçŽ ãããŒã¿ãèªåçã«æœåºããæ©æ¢°åŠç¿ (ML) ãµãŒãã¹
Amazon Comprehend
é²é³ã®æåèµ·ãããååŸããé話ã«é³å£°åææ©æ¢°åŠç¿ãé©çšããŠãææ ãããŒã¯ãŒããäŒç€Ÿããªã·ãŒã®é å®ãªã©ãç¹å®ãã
Amazon Polly
ãã¹ãŠã®åãåãããããŒã§ããã¹ãèªã¿äžããæäŸãã
DBé¢é£
åæ§é åããŒã¿
jsonãªã©
Amazon DynamoDB
Auto Scaling for DynamoDB ãšãããããããžã§ãã³ã°ã¢ãŒãã§ãã¹ã±ãŒãªã³ã°æ©èœããã
Fine-Grained Access Control for DynamoDB
DynamoDB Accelerator ã¯éåžžã«é«äŸ¡ãããããã€ã¯ãç§ã§ã®è¿ä¿¡ãå¯èœ
Redshift snapshot copy grant
Red shift ã®ã³ããŒãããä»çµã¿ã®ããš
Amazon RDS
ã·ã£ãŒãã£ã³ã°
ãã£ã±ãã§ããã£ãœã
RDSã£ãŠãã«ãAZå¯èœïŒ
å¯èœ
Amazon RDS ãããã·
Amazon RDS ãããã·ã¯ã Amazon Relational Database Service (RDS) çšã®ãã«ãããŒãžãåã®é«å¯çšæ§ããŒã¿ããŒã¹ ãããã·ã§ãããã¢ããªã±ãŒã·ã§ã³ã®ã¹ã±ãŒã©ããªãã£ãããŒã¿ããŒã¹é害ã«å¯Ÿããå埩åãªã©ãé«ãã
Amazon Neptune
Amazon Neptune ã¯AWS(ã¯ã©ãŠã)ã®ã°ã©ãåããŒã¿ããŒã¹ãµãŒãã¹
Amazon Keyspaces
Amazon Keyspaces (Apache Cassandra åã) ã¯ãã¹ã±ãŒã©ãã«ã§å¯çšæ§ã®é«ããApache Cassandra äºæã®ãããŒãžãããŒã¿ããŒã¹ãµãŒãã¹
ã¡ãã»ãŒãžã³ã°ãµãŒãã¹
Amazon SQS
ãªãã©ã€ãèš±å¯ããªã·ãŒ
Amazon MQ
MQéä¿¡ãªã©ãå¯èœã«ããä»çµã¿
AWS AppSync
GraphQL ãšããAPI 仿§ãçšããŠãæè»ãªAPIããæäŸãã AWS ã®ãããžã¡ã³ããµãŒãã¹
ç§»è¡ãµãŒãã¹
AWS DataSync
ãããã¯ãŒã¯ ãã¡ã€ã« ã·ã¹ãã (NFS) å
±æããµãŒã㌠ã¡ãã»ãŒãž ããã㯠(SMB) å
±æãèªå·±ç®¡çåãªããžã§ã¯ã ã¹ãã¬ãŒãžãAWS SnowconeãAmazon Simple Storage Service (Amazon S3) ãã±ãããAmazon Elastic File System (Amazon EFS) éã§ããŒã¿ãã³ããŒããããã«èšèšãããŠãã
ãã¡ã€ã« ã·ã¹ãã ãããã³ Amazon FSx for Windows ãã¡ã€ã« ãµãŒã㌠ãã¡ã€ã« ã·ã¹ãã ãç©çãµãŒããŒã AWS ã«ç§»è¡ããããã«èšèšãããŠããªã
AWS Database Migration Service
ãªã³ãã¬ãã¹ïœAWS éããªã³ãã¬ãã¹ïœãªã³ãã¬ãã¹éã®ããŒã¿ç§»è¡ãæ¯æŽããä»çµã¿
AWS Schema Conversion Tool
Database Migration Service ã«çµ±åãããŠãããµãŒãã¹
Application Discovery Service ãš Migration hub ã®éã
ADS 㯠Migration Hub ã«çµ±åãããŠãã
ããäžå®ä»¥äžã®èŠæš¡ã®å°æ°ããããªã³ãã¬ããAWSã®ç§»è¡èšç»ãç«æ¡ãããšãã«æŽ»çšã§ãã
ãšãŒãžã§ã³ããå
¥ããŠãããã©ãŒãã³ã¹æ
å ±ãªã©åéã§ãã
AWS Application Discovery Service
AWS Application Discovery Service ã¯ãç§»è¡ã®ããã®ããŒã¿ã®ã¿ãåéãã
AgentLess Discovery ã³ãã¯ã¿
ADS ãå©çšããããšã§ãªã³ãã¬ãã¹ã§çšŒåããŠãããµãŒããŒã®åçš®æ
å ±ãååŸããã¢ã»ã¹ã¡ã³ãã»åæãè¡ãããã®æ¯æŽãããŠããã
numCores ã OSType ãªã©ãç¥ãããšãã§ãã
Application Migration Service
ãªã³ãã¬ãã¹ã® VM ã AWS ã¯ã©ãŠãã«è€è£œãŸãã¯ãã©ãŒãªã³ã°ããããã«äœ¿çšãã
Application Migration Serviceãš Migration Hub ã®éã
ãªã³ãã¬ãªã©ã®ãµãŒããŒã AWS ãžç§»è¡ããããã®ãµãŒãã¹ãApplication Migration Service
ãã®ä»
Amazon API Gateway
Amazon API Gateway ã§ã¯ãªãã·ã§ã³ã§ãã£ãã·ã¥æ©èœã䜿ãããšãåºæ¥ã
Amazon ECS
ECS Anywhere
ãããŒãžã ã€ã³ã¹ã¿ã³ã¹ã«ã»ãã¥ãªãã£é¢é£ã®ã¢ããããŒããé©çšããããã»ã¹ãèªååãã
Linux ããŒã¹ã®ã€ã³ã¹ã¿ã³ã¹ã®å Žåã¯ãã»ãã¥ãªãã£ä»¥å€ã®æŽæ°ã®ããããã€ã³ã¹ããŒã«ããããšãã§ããŸãã
AWS Batch
AWS ã® Batch æ§ç¯ãµãŒãã¹
MAM
ïŒã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ç®¡çïŒ
CRM ã¢ããªã±ãŒã·ã§ã³
ãCustomer Relationship Managementãã®ç¥ã§ãæ¥æ¬èªã§ã¯ã顧客é¢ä¿ç®¡çã
以äžã