ããã«ã¡ã¯ãGlobal Solutionsäºæ¥éšã§ãã
ã¯ã©ãŠãã€ã³ãã©ã«ã«ãŒã«ãèšå®ããŠãã誰ãå®ã£ãŠãããªããšæããããšã¯ãããŸãããïŒãã¡ãããšã«ãŒã«ãå®ãããã«ã§ãããããã®ã«âŠããšæã£ãããšããããããããŸãããAWSã䜿ãã°ãããã«è¿ããã®ããããŸãããã®ããã°ã§ã¯ããPolicy as CodeïŒã³ãŒãã«ããããªã·ãŒç®¡çïŒãã«ã€ããŠèª¬æããç¹ã«AWS ConfigãšããAWSã®ãµãŒãã¹ã«çŠç¹ãåœãŠãŸãã
Policy as Codeãšã¯ïŒ
åºæ¬çã«ãPolicy as Codeãšã¯ãã€ã³ãã©ã«ãããã«ãŒã«ãæç¢ºã«å®çŸ©ããèªååããããšã§ãæé©ã§æè»ãªæ¹æ³ã§ã¬ããã³ã¹ãå®çŸããæè¡ã§ããããŒãã£ãŒãéãåã«ã«ãŒã«ãèšå®ãããã¹ãããã£ãšæ³šæããããšãªããå šå¡ããã®ã«ãŒã«ãå®ãããã«ãããããªãã®ã§ãã
AWS Config
AWS Configã¯ããã®ããã°ã®äž»åœ¹ã§ãèšå®ãããã«ãŒã«ãç£èŠããéåãããã°éç¥ããå¿ èŠã«å¿ããŠæ¯æ£æªçœ®ãåããé Œãããååšã§ããã§ã¯ããã®åœ¹å²ãèŠãŠãããŸãããã
- ç¶ç¶çãªç£èŠïŒAWS Configã¯ãç ããªãã»ãã¥ãªãã£ã¬ãŒãã®ããã«ãèšå®ãããªã·ãŒã«æºæ ããŠããããåžžã«ç£èŠããŠããŸãã
- ã¹ãããã·ã§ãããšå€æŽéç¥ïŒ éå»ã®è¡åãæ¯ãè¿ããã¿ã€ã ãã·ã³ãããã£ãããããšæã£ãããšã¯ãããŸãããïŒAWS Configã¯ãªãœãŒã¹ã®ç¶æ ãèšé²ãããã€ã§ãéå»ã®èšå®ã確èªã§ããæ©èœãæäŸããŸãããŸãã倿Žãããã°éç¥ãå±ããŸãã
- éæºæ ã®æ¯æ£ïŒ ç¹°ãè¿ãã®èšå®ãã¹ãäžæ£ãªèšå®ã«æ©ãã ããšã¯ãããŸãããïŒAWS Configã¯éæºæ ãªæŽ»åãç£èŠããã ãã§ãªããæ¯æ£æªçœ®ãæäŸããŸããããã«ãããäœæ¥è² æ ã軜æžãããããéèŠãªã¿ã¹ã¯ã«éäžããããšãã§ããŸãã
AWS IAM
ããŒãã£ãŒã«å šå¡ãæåŸ ããåã«ãã²ã¹ããªã¹ããäœãå¿ èŠããããŸãããïŒIAMã¯ãã®ãå ¥å Žç®¡çãã§ãã誰ãå ¥ãããããããŠå ¥å ŽåŸã«äœãã§ããããèšå®ããŸãã
- ãŠãŒã¶ãŒç®¡çïŒåœ¹å²ãå®çŸ©ããŸããAWSã®äžçã§ã¯ããããŠãŒã¶ãŒã¯èªã¿åãå°çšã®ã¢ã¯ã»ã¹æš©ãæã¡ãä»ã®ãŠãŒã¶ãŒã«ã¯ç®¡çè
æš©éãäžãããããšãã£ãå
·åã«ãã¢ã¯ã»ã¹æš©ã现ãã調æŽã§ããŸãã
- ããªã·ãŒã®å²ãåœãŠïŒããã§ãPolicy as CodeããæŽ»èºããŸãããŠãŒã¶ãŒãããŒã«ãã°ã«ãŒãã«ããªã·ãŒãå²ãåœãŠãŸããããã¯ã€ãã³ãã§ãªã¹ããã³ããé
åžããè²ã«ãã£ãŠç°ãªãã¢ã¯ã»ã¹æš©ã瀺ããããªãã®ã§ãã
AWS CloudFormationã«ããæè»ã§å ç¢ãªç®¡ç
ãã¹ãŠããŸãšããããã«ãå šäœã®æµããã¹ã ãŒãºã«ãããã¹ããŒãžãããŒãžã£ãŒããå¿ èŠã§ãããããAWS CloudFormationã§ãã
- ãã³ãã¬ãŒãäœæïŒãªã³ã©ã€ã³ãªãœãŒã¹ãåèã«ããªãããã³ãã¬ãŒããäœæããŸãã
- ãããã€ãšç®¡çïŒãã³ãã¬ãŒãã宿ãããããã¹ããè¡ãããã®åŸCloudFormationããªãœãŒã¹ã®èšå®ãIAMããŒã«ã®ãªã³ã¯ãªã©ãåŒãç¶ããããªã·ãŒã®å®è£
ã確å®ã«ããŸãã
Policy as Codeã®ã¡ãªãã
- äžè²«æ§ïŒäžè²«ããããªã·ãŒã®é©çšã«ãããäºæãã¬ãã©ãã«ãçºçãã«ãããªããèªååã«ããæå°éã®ä»å ¥ã§åé¡ã解決ãããŸãã
- è¿ éãªãªã³ããŒãã£ã³ã°ïŒAWSã®åå¿è ãããŒã ã®æ¡å€§æã«ããPolicy as Codeãå°å ¥ããããšã§ãã¹ã ãŒãºãªãªã³ããŒãã£ã³ã°ãå¯èœã«ãªããŸãããŸãã§æ°ããã¡ã³ããŒã«ã«ãŒã«ããã¯ãæž¡ããããªãã®ã§ãããã ããå®å šã«èªååãããããã§ã¯ãªããããçšåºŠã®ã¬ã€ãã¯å¿ èŠãªã®ã§ãéåºŠãªæåŸ ã¯çŠç©ã§ãã
- ç£æ»ã®å®¹æãïŒAWS Configã®å±¥æŽããŒã¿ããAWS CloudTrailã§IAMãªãœãŒã¹ã«é¢é£ããã¢ã¯ãã£ããã£ã確èªã§ãããããç£æ»æºåãåžžã«æŽã£ãŠããç¶æ
ãç¶æã§ããŸãã責任ãæã£ãŠç°å¢ã管çããŠããããšã蚌æããããã®éææ§ã確ä¿ãããŸãã
çµããã«
AWSã«ããããPolicy as Codeãã¯å¿ é ã§ã¯ãããŸããããã¬ããã³ã¹ãšã»ãã¥ãªãã£ã粟å¯ã«å®è¡ããããšãéèŠã§ããã°ãæ¬ ãããªãèŠçŽ ã§ããããžã¿ã«ç°å¢ã®æé·ã«ã¯ãç§©åºãèŠåŸããããŠå°ãã®å·¥å€«ãå¿ èŠã§ãããã®ããã°ãçããã®åèã«ãªãã°å¹žãã§ãããŸã次åãäŒãããŸãããã
ã¢ã€ã¬ããæ ªåŒäŒç€Ÿã®Global Solutionsäºæ¥éšã§ã¯ãã客æ§ã®ããžãã¹å€é©ãå®çŸããªãããææ°ã®ããŒã¿ãœãªã¥ãŒã·ã§ã³ã®å°å ¥ãå éã§ããããã«èšèšãããããŒã¿åæãœãªã¥ãŒã·ã§ã³ãšããŒã¿ãµãŒãã¹ã®å¹ åºãããŒããã©ãªãªãæäŸããŠããŸããããžãã¹ã®æåãããç§ãã¡ã远æ±ãããã®ã§ãããå°ãã®éã¯ãã²äžåºŠãæ°è»œã«ãåãåãããã ããã