ééãããããã€ã³ãé åŸåã§ãã
ååïŒhttps://iret.media/138635
åŸåïŒhttps://iret.media/138658
察象è
DOPïŒAWS Certified DevOps Engineer ïŒãå匷ããŠãã人ã«åããŠãããééãããããã£ãŠãšããããµãŒãã¹ããšã«æ³šèšããŠãããŸãã(2025幎1ææç¹)
çµæ§ãªéã«ãªã£ãã®ã§èšäºã2åå²ãšãã
ååã¯CodeDeployãªã©Codeäžå
åŒãšCloudFormationã«ã€ããŠèšèŒ
åŸåã¯äžèšä»¥å€ã®AutoScalingãALBãªã©ãã®ä»ãµãŒãã¹ã«ã€ããŠèšèŒã
ãŸããæ
å ±ãåèã«ããäžã§ã®æ³šæç¹ãèšäºã®æåŸã«èšèŒããŠããŸãã®ã§ãæ°ã«ãªãæ¹ã¯ãã¡ããã確èªãã ããã
EC2
StatusCheckFailed_System ã¡ããªã¯ã¹
以äžãæ€åºå¯èœ
- ãããã¯ãŒã¯æ¥ç¶ã®åªå€±
- ã·ã¹ãã 黿ºã®åªå€±
- ç©çãã¹ãã®ãœãããŠã§ã¢ã®åé¡
- ãããã¯ãŒã¯å°éå¯èœæ§ã«åœ±é¿ãããç©çãã¹ãäžã®ããŒããŠã§ã¢ã®åé¡
Image Builder
AMIã®ãã£ã¹ããªãã¥ãŒã·ã§ã³ãããããããå€ãããAutoScalingã°ã«ãŒãã®æŽæ°ãå¯èœ
å
·äœçã«ã¯ãEC2 Image Builder ã¯ãæšæºçãªã³ã³ããããŒã¹ã€ã¡ãŒãžãèªåã§æ§ç¯ãæ€èšŒãå
¬éã§ãããµãŒãã¹
Dedicated Instance ãšã¯
EC2ã€ã³ã¹ã¿ã³ã¹ã¯AWSåŽã§ä»»æã®ç©çãµãŒãã®äžã§èµ·åããããã®çºãç©çãµãŒãäžã®ã€ã³ã¹ã¿ã³ã¹ã«ã¯å¥ã¢ã«ãŠã³ãã®ã€ã³ã¹ã¿ã³ã¹ãååšããã
ãããããœãããŠã§ã¢ã®ã©ã€ã»ã³ã¹çã§ç©çãµãŒããå°æãããå Žåãããããã®éã«äœ¿çšããã
å¥ã¢ã«ãŠã³ãã®EC2ã€ã³ã¹ã¿ã³ã¹ãåããµãŒãäžã§èµ·åããªãããšãä¿èšŒãã ã®ã Dedicated Instance ã§ãã
Dedicated Hosts ãšã¯
Dedicated Hosts 㯠Dedicated Instance ã®äžäœçãšãã£ãã€ã¡ãŒãžã§ãã
Dedicated Instance ã§ã¯ãå¥ã¢ã«ãŠã³ãã®EC2ã€ã³ã¹ã¿ã³ã¹ãåããµãŒãäžã§èµ·åããªãããšãä¿èšŒããããåãã¢ã«ãŠã³ãã®ã€ã³ã¹ã¿ã³ã¹ãåãç©çãµãŒãäžã§èµ·åãããããšãã§ããªãã
ããããDedicated Hosts ã§ã¯ ç©çãµãŒãã§ã®ã€ã³ã¹ã¿ã³ã¹ã®é
眮ãå¶åŸ¡ããããšãã§ããŸãã
S3
S3 Object Lambda ã¢ã¯ã»ã¹ãã€ã³ã
- ããŒã¿ãåãåºãæã«
ç»åã®åçãªãµã€ãºå€æŽãæ©å¯ããŒã¿ã®ç·šéãã§ãã
ã¯ãã¹ãªãŒãžã§ã³ã¬ããªã±ãŒã·ã§ã³
æ°æéãããããšãããã
Content-MD5ãã©ã¡ãŒã¿ãšetagã®éãã«ã€ããŠ
Content-MD5
- æŠèŠ:
Content-MD5ããããŒã¯ããªã¯ãšã¹ããã¬ã¹ãã³ã¹ããã£ã®å 容ã«å¯ŸããMD5ããã·ã¥ãæäŸããŸãã - ç®ç:
- ããŒã¿ã®æŽåæ§ãæ€èšŒããããã«äœ¿çšãããŸãã
- ãµãŒããŒãšã¯ã©ã€ã¢ã³ãéã§è»¢éãããããŒã¿ãéäžã§æ¹ãããããŠããªããã確èªããŸãã
- åäœ:
- ãµãŒããŒãŸãã¯ã¯ã©ã€ã¢ã³ãã¯ãããã£ã®å 容ããMD5ããã·ã¥ãèšç®ãããããããããŒã«èšå®ããŸãã
- åä¿¡åŽãåãæ¹æ³ã§ããã·ã¥ãèšç®ããããããŒå€ãšäžèŽãããããã§ãã¯ããŸãã
- äž»ãªç¹åŸŽ:
- èšç®ãããMD5ããã·ã¥å€ã¯ããã£å šäœã«åºã¥ããŠãããããŒã¿ã®å®å šæ§ç¢ºèªãäž»ãªç®çã
- ããŒã¿ã倿ŽãããŠãããšãããã·ã¥ãäžèŽããªããããšã©ãŒãçºçããŸãã
- äŸ:äžèšã¯ããã£å
容ã®MD5ããã·ã¥ãBase64ãšã³ã³ãŒããããã®ã
Content-MD5: Q2hlY2sgSW50ZWdyaXR5IQ==
2. ETag
- æŠèŠ:
ETag(ãšã³ãã£ãã£ã¿ã°) ããããŒã¯ããªãœãŒã¹ã®ããŒãžã§ã³ãç¶æ ã衚ãäžæã®èå¥åã§ãã - ç®ç:
- ãã£ãã·ã¥ã®å¶åŸ¡ãç¶æ ã®è¿œè·¡ãç®çã«äœ¿çšãããŸãã
- ãªãœãŒã¹ã倿ŽãããŠãããã©ãããå¹ççã«ç¢ºèªããŸãã
- åäœ:
- ãµãŒããŒã¯ãªãœãŒã¹ã®ç¶æ ã衚ãèå¥åïŒããã·ã¥ãã¿ã€ã ã¹ã¿ã³ããããŒãžã§ã³IDãªã©ïŒãçæããã¬ã¹ãã³ã¹ã«å«ããŸãã
- ã¯ã©ã€ã¢ã³ãã¯
If-None-MatchããããŒã䜿çšããŠãETagãéä¿¡ãããµãŒããŒã«ãªãœãŒã¹ã®å€æŽã確èªããŸãã
- äž»ãªç¹åŸŽ:
- ããŒã¿ã®å®å šæ§ç¢ºèªã§ã¯ãªãããªãœãŒã¹ã®å€æŽæ€ç¥ãäž»ãªç®çã
- åããªãœãŒã¹ã§ããã°ETagã¯äžèŽãã倿Žãããã°æ°ããETagãçæãããŸãã
- äŸ:äžèšã¯ãªãœãŒã¹ãèå¥ããããã®äžæã®èå¥åã
ETag: "686897696a7c876b7e"
MD5ãšETagã®éã
| ç¹åŸŽ | Content-MD5 | ETag |
|---|---|---|
| ç®ç | ããŒã¿ã®æŽåæ§æ€èšŒ | ãªãœãŒã¹ã®å€æŽæ€ç¥ |
| 察象 | ããã£å šäœã®ããã·ã¥ | ãªãœãŒã¹å šäœïŒç¶æ ãããŒãžã§ã³ïŒ |
| 䜿çšãããå Žé¢ | ããŒã¿ã®æ¹ããæ€ç¥ãå®å šæ§ç¢ºèª | ãã£ãã·ã¥å¶åŸ¡ããªãœãŒã¹ã®ç¶æ ç¢ºèª |
| ã¢ã«ãŽãªãºã | MD5ïŒåºå®ïŒ | ä»»æïŒããã·ã¥ãããŒãžã§ã³IDãªã©ïŒ |
| ã¯ã©ã€ã¢ã³ãåŽã®å©çš | ããã·ã¥ãåèšç®ããŠæ€èšŒ | If-None-Match ããããŒã§ã®äžèŽç¢ºèª |
Object lambda ã¢ã¯ã»ã¹ãã€ã³ã
ããŒã¿ãåç倿ããäŸ¿å©æ©èœ
ãã«ããªãŒãžã§ã³ã¢ã¯ã»ã¹ã³ã³ãããŒã«
S3ã®åæ¹åã¬ããªã±ãŒã·ã§ã³ã«ã¯é¢äžããªã
PIIãšã¯
PIIïŒå人ãç¹å®ã§ããæ
å ±ïŒ
Personally Identifiable Information
Route 53
Route 53 ã®ããã«ã¹ãã§ãã¯ãšãã§ã€ã«ãªãŒããŒã«ãŒã«ã
Route 53 ã®ãèšç®ãã«ã¹ãã§ãã¯ãã§ã¯ãè€æ°ã®ãã«ã¹ãã§ãã¯ãçµã¿åãããŠæ¡ä»¶ïŒATLEAST ãªã©ïŒãèšå®ã§ããŸãã
AWS Config
Config ã³ã³ãã©ãŒãã³ã¹ããã¯ãšã¯ïŒ
æŠèŠïŒ
AWS Configã«ãŒã«ãšä¿®åŸ©ã¢ã¯ã·ã§ã³ã®ã»ãããããã±ãŒãžåãããã®ã
è€æ°ã®AWS Configã«ãŒã«ãã«ã¹ã¿ã ã«ãŒã«ãäžæ¬ã§é©çšã§ããã
äž»ã«ã»ãã¥ãªãã£ãã³ã³ãã©ã€ã¢ã³ã¹åºæºã«åºã¥ããèšå®ãç°¡åã«é©çšããããã«èšèšãããŠããŸãã
修埩ã¢ã¯ã·ã§ã³ã®èšå®ã容æãªã®ã§ããããããã®ã«æ¯éã眮ããšãã¯è¯ã
Config ã³ã³ãã©ãŒãã³ã¹ããã¯ãéžã¶ã¹ãå Žå
- ç°¡åã«æšæºçãªã³ã³ãã©ã€ã¢ã³ã¹åºæºãé©çšãããã
- AWSãæäŸããäºåå®çŸ©ã®ã«ãŒã«ã»ãããå©çšãããã
- ã»ãã¥ãªãã£ãã³ã³ãã©ã€ã¢ã³ã¹ã®åºæºãè¿ éã«æºããå¿ èŠãããã
CloudFormation ã¹ã¿ãã¯ãéžã¶ã¹ãå Žå
- AWS Config以å€ã®ãªãœãŒã¹ïŒIAMãLambdaãS3ãªã©ïŒãåæã«ç®¡çãããã
- é«åºŠãªã«ã¹ã¿ãã€ãºãå¿ èŠïŒã«ã¹ã¿ã ã«ãŒã«ãè€éãªä¿®åŸ©ã¢ã¯ã·ã§ã³ãå®çŸ©ããïŒã
- ã€ã³ãã©å šäœãã³ãŒãããŒã¹ã§ç®¡çããå¿ èŠãããã
AWS CloudFormation ã¹ã¿ãã¯ã®ããªãããæ€åº
AWS Config ã¯ãAWS ãªãœãŒã¹ã®èšå®å€æŽãç£èŠããã³è©äŸ¡ãããµãŒãã¹ã§ãããAWS CloudFormation ã¹ã¿ãã¯ã®ããªãããæ€åºããŠéç¥ããããšãã§ããŸãã
ã¯ãã¹ãªãœãŒã¹åç §äŸïŒ
"Resources" : {
"WebServerInstance": {
"Type": "AWS::EC2::Instance",
"Properties": {
"InstanceType" : "t2.micro",
"NetworkInterfaces" : [{
"SubnetId" : { "Fn::ImportValue" : "SampleSubnet" },
"GroupSet" : [ { "Fn::ImportValue" : "SampleSG" } } ],
:(ç¥)
ãã³ãã¬ãŒãå¶çŽ (Template Constraints) ãš èµ·åå¶çŽ (Launch Constraints) ã®éã
AWS Service Catalogã«ããã ãã³ãã¬ãŒãå¶çŽ (Template Constraints) ãš èµ·åå¶çŽ (Launch Constraints) ã®éãã¯ããããããå¶çŽãã察象ã«ãããŸãã
| å¶çŽã®çš®é¡ | 察象 | ç®ç |
|---|---|---|
| ãã³ãã¬ãŒãå¶çŽ (Template Constraints) | CloudFormation ãã³ãã¬ãŒãã®ãã©ã¡ãŒã¿ | ãŠãŒã¶ãŒãå ¥åã§ãããã©ã¡ãŒã¿å€ãå¶éãã |
| èµ·åå¶çŽ (Launch Constraints) | 補åã®èµ·åæã«äœ¿çšãã IAM ããŒã« | ãšã³ããŠãŒã¶ãŒãã©ã® IAM æš©éã§ãªãœãŒã¹ãäœæã§ããããå¶åŸ¡ãã |
ãã³ãã¬ãŒãå¶çŽäŸ
ãã³ãã¬ãŒãã§èšå®ã§ãããªãã·ã§ã³ãçŸ åããä»çµã¿
Parameters:
InstanceType:
Description: "EC2 Instance Type"
Type: String
AllowedValues:
- t2.micro
- t2.small
- t2.medium
Default: t2.micro
èµ·åå¶çŽäŸ
{
"LaunchRole": "arn:aws:iam::123456789012:role/ServiceCatalogLaunchRole"
}
require-tagsãããŒãžãã«ãŒã«
ãªãœãŒã¹ã«ç¹å®ã®ã¿ã°ãããããæ€åºã§ãããããŒãžãã«ãŒã«
Systems Manager
Systems Manager State Manager
ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®åæ»ãªé©çšãå¯èœ
Systems Manager Compliance
ã³ã³ãããªããžããªã®è匱æ§ãçºèŠããæ©èœã¯ãªãã®ã§ãInspectorãªã©ãé©å
Inspector
Amazon Inspector ã䜿çšãã Amazon EC2 ã€ã³ã¹ã¿ã³ã¹ã®ã¹ãã£ã³
Amazon EC2 ã€ã³ã¹ã¿ã³ã¹ã«å¯ŸããŠè匱æ§ã¹ãã£ã³ãå®è¡ããããã«ãAWS Systems Manager ãšãŒãžã§ã³ã(SSM Agent) ã®ã€ã³ã¹ããŒã«ãšåäœãããŒã 443 ã§ã®ã¢ãŠãããŠã³ãéä¿¡ã®èš±å¯ããã㊠Aws Systems Manager ãšã®éä¿¡ã«å¯Ÿããã¢ã¯ã»ã¹èš±å¯ãå¿
èŠãšãªã
- Amazon Inspector ãã¹ãã£ã³ããŠããªã EC2 ã€ã³ã¹ã¿ã³ã¹ã« AWS Systems Manager ãšãŒãžã§ã³ãïŒSSM Agent) ãã€ã³ã¹ããŒã«ãããŠããããš
- ã¿ãŒã²ãã EC2ã€ã³ã¹ã¿ã³ã¹ã«ãAWs Systems Manager ãµãŒãã¹ã®ãšã³ããã€ã³ããžã®ããŒã 443 ã§ã®ã¢ãŠãããŠã³ãéä¿¡ãèš±å¯ããã»ãã¥ãªãã£ã°ã«ãŒããé¢é£ä»ããããŠããããš
- ã¿ãŒã²ãã EC2 ã€ã³ã¹ã¿ã³ã¹ã«ãAWS Systems Manager ãšéä¿¡ããããã®ã¢ã¯ã»ã¹èš±å¯ãä»äžããã€ã³ã¹ã¿ã³ã¹ãããã¡ã€ã«ãé¢é£ä»ããŠããããš
Systems Manager Document
SSM Automation ããã¥ã¡ã³ã
configããéæºæ ãªãœãŒã¹ã®èªå修埩ãå¯èœ
CloudTrail
ãµãŒãã¹ã®æ€ç¥ã§ãããã«ãŒããŠãŒã¶ãŒã®ãã°ã€ã³ãªã©ãè¡ããµãŒãã¹ã§ã¯ãªã
AWSSSODirectoryAdministratorãšã¯ïŒ
AWS IAM Identity Center (æ§AWS SSO) ã«é¢é£ãã管çè
ããŒã«
䞻㫠AWS IAM Identity Center ã®èšå®ã管çãè¡ãããã®æš©é
AWS Organizations ãå©çšãããã£ã¬ã¯ããªç®¡çã«é¢äžãã
IAM ã®ããªã·ãŒç®¡çãAWSã¢ã«ãŠã³ãã®ç®¡çãç®çãšããããŒã«ã§ã¯ãªã
EventBridge å ¥åãã©ã³ã¹ãã©ãŒããŒ
jsonã®åœ¢ãã¡ãã£ãšããããªã©ã«æå¹ã
å€§èŠæš¡ãªããŒã¿å€æŽã«äœ¿ããã®ã§ã¯ãªã
IAM
iam:passroleãšiam:assumeroleã®éãã¯ïŒ
| ç¹åŸŽ | iam:PassRole | iam:AssumeRole |
|---|---|---|
| çšé | ããŒã«ãAWSãµãŒãã¹ã«æž¡ã | ããŒã«ãåŒãåããŠäœ¿çšãã |
| æäœå¯Ÿè±¡ | æž¡ã察象ã¯AWSãµãŒãã¹ | åŒãåãã察象ã¯IAMãŠãŒã¶ãŒãAWSã¢ã«ãŠã³ã |
| å¿ èŠãªèšå® | IAMããªã·ãŒã ãã§èšå®å¯èœ | ä¿¡é Œããªã·ãŒãå¿ èŠ |
| å žåçãªäœ¿çšäŸ | Lambda颿°ã«ããŒã«ãæž¡ã | ã¯ãã¹ã¢ã«ãŠã³ãã¢ã¯ã»ã¹ãå®çŸãã |
Auto Scaling
AWS Auto Scaling ã®ã¹ãããã€ã³ã¹ã¿ã³ã¹ã®é
åæŠç¥ Capacity Optimized
ã¹ãããäŸ¡æ Œãšäžæçã®äž¡æ¹ãèæ
®ããããå¡©æ¢
ã®æŠç¥
UpdatePolicy 屿§ãWaitOnResourceSignals
AWS CloudFormation ããªãœãŒã¹ã®èšå®ãåŸ
ã€ããã«èšå®ããå¿
èŠããããããã¯WaitOnResourceSignals ãš ãã«ããŒã¹ã¯ãªããã䜿çšããŠè¡ãããšãã§ããã
å
·äœçã«ã¯ãAWS CloudFormation ã¯ãAWS ãªãœãŒã¹ã®ããããžã§ãã³ã°ãšç®¡çãèªååããããã®ãµãŒãã¹ã§ãããããããªãœãŒã¹ãæ£ããèšå®ãããŠãããã©ããã CloudFormation èªäœã倿ããããšã¯ã§ããŸãããããã¯ç¹ã«ããŠãŒã¶ãŒããŒã¿ãçšããŠèšå®ãè¡ã EC2ã€ã³ã¹ã¿ã³ã¹ãªã©ã®ãªãœãŒã¹ã«ãããŠåé¡ãšãªããŸãã
ãã®åé¡ã解決ããããã«ãCloudFormation 㯠WaitOnResourceSignals ãšãããªãã·ã§ã³ãæäŸããŠããŸããããã䜿çšãããšãCloudFormation ã¯ç¹å®ã®ãªãœãŒã¹ã®èšå®ãå®äºããã®ãåŸ
ã€ããšãã§ããŸããèšå®ã®å®äºã¯ããã«ããŒã¹ã¯ãªãã ã䜿çšããŠãªãœãŒã¹ãã CloudFormation ã«éç¥ãããŸãã
DevOps ãšã³ãžãã¢ã¯ ãã«ããŒã¹ã¯ãªããã䜿çšããŠããŠãŒã¶ãŒããŒã¿ã®å®è¡ãæ£åžžã«çµäºãããã©ããã CloudFormation ã«éç¥ã§ããŸããããã«ãWaitOnResourceSignals ã® UpdatePolicy ã䜿çšããŠãCloudFormation ããªãœãŒã¹ã®èšå®ãåŸ ã€ããã«ããããšãã§ããŸãããããã®èšå®ã«ããããŠãŒã¶ãŒããŒã¿ã®å®è¡ãæ£åžžã«çµäºããªãã£ãå Žåã«ãCloudFormation ã®ãããã€ã倱æããããã«ããããšãå¯èœã§ãã
Auto Scalingã®ãŠã©ãŒã ããŒã«
èµ·åæéççž®ã®å
·äœäŸ
éåžžãæ°èŠã€ã³ã¹ã¿ã³ã¹ãèµ·åããå ŽåïŒ
1. EC2ã€ã³ã¹ã¿ã³ã¹ã®ããããžã§ãã³ã°ïŒæ°åïŒ
2. OSãšã¢ããªã±ãŒã·ã§ã³ã®åæåïŒè¿œå ã®æ°åïŒ
3. å¿
èŠãªèšå®ã®é©çšïŒIAMããŒã«ãã»ãã¥ãªãã£ã°ã«ãŒããªã©ïŒ
Stopped ç¶æ
ã®ãŠã©ãŒã ããŒã«ãå©çšããå ŽåïŒ
1. ã€ã³ã¹ã¿ã³ã¹ã®åèµ·åïŒéåžž30ç§ã1åçšåºŠïŒ
2. ççž®ãããåæåïŒã¢ããªã±ãŒã·ã§ã³ã¯æ¢ã«åºæ¬èšå®æžã¿ïŒ
çµè«
Stopped ç¶æ ã®ãŠã©ãŒã ããŒã«ã€ã³ã¹ã¿ã³ã¹ã¯ãå®å šãªæ°èŠã€ã³ã¹ã¿ã³ã¹ã®èµ·åãããå€§å¹ ã«èµ·åæéãççž®ã§ããŸããå®å šã« Running ç¶æ ã§ã¯ãªããã峿å¿çæ§ã¯äœãã§ãããã³ã¹ãå¹çãšããçšåºŠã®ã¹ã±ãŒã«ã¢ãŠãé床ãäž¡ç«ãããå Žåã«ã¯éåžžã«æå¹ãªéžæè¢ã§ãã
çµäºä¿è·ããŠã®èª¿æ»
Amazon EC2 Auto Scaling ã§ã¯ãç°åžžãªã€ã³ã¹ã¿ã³ã¹ããããã°ããéã«ãã€ã³ã¹ã¿ã³ã¹ãã¹ã¿ã³ãã€ç¶æ ã«ããããšãæšå¥šãããŠããŸããã¹ã¿ã³ãã€ç¶æ ã«ããããšã§ãã€ã³ã¹ã¿ã³ã¹ãçµäºããããéçºè ãåé¡ã®åå ãç¹å®ããããã«ãã°ã€ã³ããŠèª¿æ»ããããšãã§ããŸãã
Capacity Optimized vs Diversifiedã®éã
| ç¹åŸŽ | Capacity Optimized | Diversified |
|---|---|---|
| ç®ç | å©çšå¯èœãªãªãœãŒã¹ãæé©åããŠéžæ | è€æ°ã®å Žæã«ãªãœãŒã¹ã忣 |
| äž»ãªå©ç¹ | ãªãœãŒã¹ã®æ¯æžãé¿ããæé©ãªå®¹éã§ã¹ã±ãŒãªã³ã° | é害æã®èé害æ§ãåé·æ§ã®åäž |
| éžæåºæº | æãå©çšå¯èœãªãªãœãŒã¹ãéžæ | ãªãœãŒã¹ãç°ãªããšãªã¢ããŸãŒã³ã«åæ£ |
| 䜿çšäŸ | é«å¯çšæ§ãæ±ããããã¯ãŒã¯ããŒãããªãœãŒã¹ã®æ¯æžåé¿ | é«å¯çšæ§ãåé·æ§ã®ããã®åæ£é 眮 |
Amazon EC2 Auto Scaling ã®ã©ã€ããµã€ã¯ã«ããã¯
ã©ã€ããµã€ã¯ã«ããã¯ãå©çšããŠãæ°ããã€ã³ã¹ã¿ã³ã¹ã PendingïŒWait ç¶æ ã«ä¿æãã
ããã«ãããã«ã¹ã¿ã ã¹ã¯ãªããã«ããç£æ»ãµãŒãã¹ãžã®ç»é²ãæåãŸãã¯å€±æããçµæã Amazon EC2 Auto Scaling ã°ã«ãŒãã«ãã£ãŒãããã¯ããããšãå¯èœãšãªããŸãã
å
·äœçã«ã¯ããã®ãã£ãŒãããã¯ãå©çšããAmazon EC2 Auto Scaling ã°ã«ãŒãã¯æ°ãã Amazon EC2 ã€ã³ã¹ã¿ã³ã¹ãžã®ãã©ãã£ãã¯ã®éä¿¡ãéå§ããããAmazon EC2 ã€ã³ã¹ã¿ã³ã¹ãçµäºãããããŸãã
ã©ã€ããµã€ã¯ã«ããã¯ã¯ãæ°ããã€ã³ã¹ã¿ã³ã¹ã®ç¶æ
ã Pending:Wait ã«ããããšãå¯èœã§ãããã«ãã Amazon EC2 Auto Scaling ã°ã«ãŒãã®æäœãäžæåæ¢ããŸãã
ããã§ã«ã¹ã¿ã ã¹ã¯ãªãããåŒã³åºããŠã€ã³ã¹ã¿ã³ã¹ãäŒç€Ÿã®ç£æ»ãµãŒãã¹ã«ç»é²ããããšãå¯èœãšãªããŸãã
ãã®ã«ã¹ã¿ã ã¹ã¯ãªãããæåããå Žåãã©ã€ããµã€ã¯ã«ã¢ã¯ã·ã§ã³ã¯CONTINUEå€ã§å®äºããæ°ããã€ã³ã¹ã¿ã³ã¹ãžã®ãã©ãã£ãã¯ã®éä¿¡ãéå§ãããŸãã
æ¹ãã¹ã¯ãªããã倱æããå Žåãã©ã€ããµã€ã¯ã«ã¢ã¯ã·ã§ã³ã¯ABANDON å€ã§å®äºãã該åœã® Amazon EC2ã€ã³ã¹ã¿ã³ã¹ã¯çµäºããŸãã
ãã®ãããªæ¹æ³ã§ãAmazon EC2 Auto Scaling ã°ã«ãŒãã¯ã«ã¹ã¿ã ã¹ã¯ãªããã®çµæã«åºã¥ããŠé©åãªã¢ã¯ã·ã§ã³ãåãããšãå¯èœãšãªããŸãã
â»Amazon EC2 Auto Scaling ã®ã©ã€ããµã€ã¯ã«ããã¯
Amazon EC2 Auto Scaling ã¯ãAuto Scaling ã°ã«ãŒãã«ã©ã€ããµã€ã¯ã«ããã¯ã远å ããæ©èœãæäŸããŸãããããã®ããã¯ã«ãããAuto Scaling ã€ã³ã¹ã¿ã³ã¹ã©ã€ããµã€ã¯ã«ã®ã€ãã³ããèªèãã察å¿ããã©ã€ããµã€ã¯ã«ã€ãã³ããçºçãããšãã«ã«ã¹ã¿ã ã¢ã¯ã·ã§ã³ãå®è¡ãããœãªã¥ãŒã·ã§ã³ãäœæã§ããŸããã©ã€ããµã€ã¯ã«ããã¯ã§ã¯ãã€ã³ã¹ã¿ã³ã¹ã次ã®ç¶æ
ã«ç§»è¡ããåã«ãã©ã€ããµã€ã¯ã«ã¢ã¯ã·ã§ã³ã®å®äºãåŸ
ã€æéïŒããã©ã«ãã§ã¯1æéïŒãæå®ãããŸãã
RDS
èªåããã¯ã¢ãã
1æ¥1åè¡ããã
Aurora
Aurora ã¯ã©ã¹ã¿ãŒã®ã«ã¹ã¿ã ANY ãšã³ããã€ã³ã
ã¯ã©ã¹ã¿ãŒé äžã®ç¹å®ã®ã€ã³ã¹ã¿ã³ã¹ãçŽä»ããããšãã§ãããšã³ããã€ã³ã
ãã«ãã¯ã©ã¹ã¿ãŒ
ããã¯åããªãŒãžã§ã³ã«ããå¿
èŠããã
ç°ãªããªãŒãžã§ã³ã§å¯çšæ§ãé«ããããªãã°ããŒãã«ããŒã¿ããŒã¹ã䜿çšããå¿
èŠãããã
ALBã«é¢ããŠãããªãŒãžã§ãã«ãªãœãŒã¹ãšãªãã
Amazon API Gateway
REST API ã®çžäº TLS èªèšŒã®èšå®
ãã©ã€ããŒãèªèšŒå±ïŒCAïŒãå©çšããããšã§å®çŸå¯èœ
ãã©ã€ããŒãCAãS3ã«ããããšã§å®çŸãå¯èœ
ã¯ã©ã€ã¢ã³ãèšŒææžã§ã¯ãªãã
Amazon Detective
äžæ£ãªã¢ã¯ãã£ããã£ã¯æ€åºããªããç¹å®ã®æ€åºçµæã«é¢é£ããåææ å ±ãæäŸãããã®
AWS Config
awsã§ãdesired instance typeã§ç¹å®ã®amiã®ã¿ãæå®ããããšã¯å¯èœïŒ
âå¯èœãèªå修埩ãå¯èœ
CloudWatch è€åã¢ã©ãŒã
CloudWatch è€åã¢ã©ãŒã
è€æ°æ¡ä»¶ã§ã¢ã©ãŒã ã®èšå®ãå¯èœ
èšå®ã¬ã³ãŒããŒ
- èšå®ã¬ã³ãŒããŒã¯ããµããŒãããããªãœãŒã¹ã®èšå®ãèšå®é ç®ãšããŠã¢ã«ãŠã³ãã«ä¿å
- èšé²ãéå§ããåã«ãèšå®ã¬ã³ãŒããŒãäœæããŠèµ·åãã
- ããã©ã«ãã§ã¯AWS Configãå®è¡ãããŠãããªãŒãžã§ã³ã®ãã¹ãŠã®ãµããŒããããŠãããªãœãŒã¹ãèšé²
- æå®ãããªãœãŒã¹ã¿ã€ãã®ã¿ãèšé²ããããšãå¯
CodeGuru
CodeGuru Profiler
ã©ã³ã¿ã€ã ããã©ãŒãã³ã¹ã®æ€èšŒãå¯èœãªãµãŒãã¹
CodeGuru Reviewer
ç§å¿æ å ±ãå ¥ã£ãŠããããªã©ã®æ€åºãå¯èœ
Firewall Manager
Firewall Manager ã«ã¯ã次ã®ãããªå©ç¹ããããŸãã
- ã¢ã«ãŠã³ãéã§ãªãœãŒã¹ãä¿è·ããã®ã«åœ¹ç«ã¡ãŸã
- ãã¹ãŠã® Amazon CloudFront ãã£ã¹ããªãã¥ãŒã·ã§ã³ãªã©ãç¹å®ã®ã¿ã€ãã®ãã¹ãŠã®ãªãœãŒã¹ãä¿è·ããã®ã«åœ¹ç«ã¡ãŸã
- ç¹å®ã®ã¿ã°ã§ãã¹ãŠã®ãªãœãŒã¹ãä¿è·ããã®ã«åœ¹ç«ã¡ãŸã
- ã¢ã«ãŠã³ãã«è¿œå ããããªãœãŒã¹ãžã®ä¿è·ãèªåçã«è¿œå ããŸã
- AWS Organizations çµç¹å ã®ãã¹ãŠã®ã¡ã³ããŒã¢ã«ãŠã³ãã Aws Shield Advanced ã«ç»é²ããããšãã§ããçµç¹ã«åå ããæ°ãã察象ã¢ã«ãŠã³ããèªåçã«ç»é²ããããšãã§ããŸã
- AWS Organizations çµç¹å ã®ãã¹ãŠã®ã¡ã³ããŒã¢ã«ãŠã³ããŸãã¯ã¢ã«ãŠã³ãã®ç¹å®ã®ãµãã»ããã«ã»ãã¥ãªãã£ã°ã«ãŒãã«ãŒã«ãé©çšããçµç¹ã«åå ããæ°ããç¯å²å ã¢ã«ãŠã³ãã«ã«ãŒã«ãèªåçã«é©çšã§ããŸãã
- ç¬èªã®ã«ãŒã«ã䜿çšããããAWS Marketplace ãããããŒãžãã«ãŒã«ãè³Œå ¥ãããã§ããŸã
AWS FirewallManager ã䜿çšããããšã§ãApplication Load Balancer (ALB) ãš Amazon API Gateway APIã«å¯Ÿã㊠AWS WAF ã®ãŠã§ã ACL ãäžå
çã«ç®¡çãã
æ°ããäœæããããªãœãŒã¹ã«èªåçã«ã¢ã¿ããããããšãã§ãã
Organizations 察å¿
AWS FirewallManager 㯠AWS Organizations ã«å¯Ÿå¿ããŠãããã»ãã¥ãªãã£ã¢ã«ãŠã³ããæå®ããŠçµç¹å
šäœã®ã»ãã¥ãªãã£ããªã·ãŒãäžå€®ã§ç®¡çããããšãã§ããŸãã
ãããã£ãŠãã»ãã¥ãªãã£ããŒã 㯠Firewal Manager ã䜿çšããŠãçµç¹å
ã®ãã¹ãŠã®ã¢ã«ãŠã³ãã§ ALB ãš API Gateway API ã« WAF ã®ãŠã§ã ACLãé¢é£ä»ããããšãå¯èœã§ãã
AWS FirewallManager ã䜿çšãããšãALB ã API Gateway API ãªã©ã®æ°ããäœæããããªãœãŒã¹ã«å¯ŸããŠãèªåçã« AWS WAF ã®ãŠã§ã ACL ãã¢ã¿ããããããªã·ãŒãäœæããããšãã§ããŸãã
ããã«ãããæ°ãã«ãªãœãŒã¹ãäœæãããéããèªåçã«é©åãªãŠã§ã ACL ãé¢é£ä»ããããã»ãã¥ãªãã£ç¶æã«åœ¹ç«ã¡ãŸãã
AWS WAF
AWS WAF Web Acl
察象ãªãœãŒã¹ãšã¢ã¯ã·ã§ã³ãšã«ãŒã«ãæå®ããŠãããã¯ãALLOWãããã®
- ãªãœãŒã¹ã¿ã€ã
- ããã©ã«ãã¢ã¯ã·ã§ã³
Application Load Balancer (ALB)
ã¢ã¯ã»ã¹ãã°ã¯åºæ¬S3ã«æžã蟌ã圢ã«ãªãã
CloudWatch ã«æžã蟌ãèšå®ã¯ããããã
NATã²ãŒããŠã§ã€
è€æ°ã®ã¢ãã€ã©ããªãã£ãŸãŒã³ãè·šã圢ã§ã¯äœããªãã®ã§ã1ã¢ãã€ã©ããªãã£ãŸãŒã³ã«å¯ŸããŠ1åäœã
CloudWatch
CloudWatch Logs ãµãã¹ã¯ãªãã·ã§ã³ãã£ã«ã¿ãŒ
ã«ãŒããŠãŒã¶ãŒã®ãã°ã€ã³ã€ãã³ãã«äžèŽãã CloudWatch Logs ãµãã¹ã¯ãªãã·ã§ã³ãã£ã«ã¿ãŒãäœæå¯èœã
ãCloudWatch Logs ãµãã¹ã¯ãªãã·ã§ã³ãã£ã«ã¿ãŒãã¯ãã°ããŒã¿ãä»ã®ãµãŒãã¹ãã¹ããªãŒã ã«ç¶ç¶çã«è»¢éããããã®æ©èœ
OpenID Connect (OIDC)
OpenID Connect ãã§ãã¬ãŒã·ã§ã³çšã®ããŒã«ãäœæããæ¹æ³ïŒã³ã³ãœãŒã«ïŒ
ã»æ¢åã® IdP ãããããã€ã㌠URLã察象ãŠãŒã¶ãŒã眲åã䜿çšã㊠IAM ldP ãäœæããŸãã
âAWS IAM ã§ldP ãèšå®ããããšã§ãæ¢åã®IdPãš AWS IAM ã飿ºãããããšãå¯èœã§ããããã«ãããèªèšŒæ
å ±ã䜿çšã㊠Amazon S3ãžã®ã¢ã¯ã»ã¹ãå¶åŸ¡ããå¿
èŠãªãªãœãŒã¹ã«å¯Ÿããã»ãã¥ãªãã£ã確ä¿ã§ããŸãã
ã»å¿
èŠãªS3 ã¢ã¯ã·ã§ã³ãèš±å¯ããããªã·ãŒãæã€IAM ããŒã«ãäœæããŸããauth.company.com:aud ã³ã³ããã¹ãããŒã appid from idp ã®å ŽåãOIDC IPãããŒã«ãåŒãåããããšãèš±å¯ããããã«ããŒã«ã®ä¿¡é Œããªã·ãŒãæ§æããŸãã
âãAWS IAM ããŒã«ãã®ä¿¡é Œããªã·ãŒãèšå®ããŠãauth.company.com:audã³ã³ããã¹ãããŒãappid_from_idp ã§ããå Žåã«OIDC ldP ãããŒã«ãåŒãåããããšãèš±å¯ããããšã§ãå€éšã®èªèšŒãããã€ããŒãéã㊠AWS ã¢ã«ãŠã³ããžã®ã»ãã¥ã¢ãªã¢ã¯ã»ã¹
ãå®çŸããŸãã
ã» AssumeRolewithwebIdentity API ãªãã¬ãŒã·ã§ã³ã䜿çšããããšã§ãOIDC IP ãå©çšããèªèšŒæ
å ±ãååŸããäžæçãªã¢ã¯ã»ã¹ã Amazon S3 ã«å¯ŸããŠè¡ããŸãã
GetFederationToken API 㯠ãAM ãŠãŒã¶ãŒã®äžæçãªèªèšŒæ
å ±ãååŸããããã®ãã®
AWS Health
AWSãµãŒãã¹å šäœã®å¥å šæ§ãèŠãŠãã
GuardDuty
SNSãšé£æºãããã«ã¯Event bridgeãå¿ èŠ
EFS
EFSã¢ã¯ã»ã¹ããªã·ãŒäŸ
{
"Version": "2012-10-17",
"Id": "efs-policy-wizard-*****-f36e-442b-aea0-3c4988ad3c53",
"Statement": [
{
"Sid": "efs-statement-*****-0404-435e-9abb-2590ea9df0e0",
"Effect": "Allow",
"Principal": {
"AWS": "*"
},
"Action": [
"elasticfilesystem:ClientWrite",
"elasticfilesystem:ClientMount"
],
"Condition": {
"Bool": {
"elasticfilesystem:AccessedViaMountTarget": "true"
}
}
},
{
"Sid": "efs-statement-*****-75bd-4d75-9ec3-ad76c4fd832d",
"Effect": "Deny",
"Principal": {
"AWS": "*"
},
"Action": "*",
"Condition": {
"Bool": {
"aws:SecureTransport": "false"
}
}
},
{
"Sid": "efs-statement-*****-71de-4c1b-8685-783e67f34def",
"Effect": "Allow",
"Principal": {
"AWS": "*"
},
"Action": [
"elasticfilesystem:ClientMount"
]
}
]
}
EFSãã¡ã€ã«ã·ã¹ãã ããªã·ãŒã§ã¢ã«ãŠã³ãBã®ã¢ã¯ã»ã¹ã蚱容ããèšå®ã®äŸ
"Principal": {
"AWS": "arn:aws:iam::ACCOUNT_B_ID:root"
},
Reflesh cache
çŽæ¥S3ã«é 眮ããããªããžã§ã¯ãã«ã察å¿ã§ããããã«ããä»çµã¿
Athena
CloudWatchããããŒã¿ãœãŒã¹ã«ã¯ã§ããªã
S3ãäž»ãªããŒã¿ãœãŒã¹
Redis
Redis ã®ã¯ã©ã¹ã¿ãŒã®ãªãŒãã¬ããªã«ãšã³ããã€ã³ãããã¯ã©ã¹ã¿ãŒã®èšå®ãšã³ããã€ã³ãã䜿çšããããšãæšå¥šãããçç±
Redis ã¯ã©ã¹ã¿ãŒã«ãã㊠ãªãŒãã¬ããªã«ãšã³ããã€ã³ã ã§ã¯ãªã ã¯ã©ã¹ã¿ãŒã®èšå®ãšã³ããã€ã³ã ã䜿çšããããšãæšå¥šãããçç±ã¯ããã€ããããŸãã以äžã«ãã®èæ¯ãšå©ç¹ã説æããŸãã
1. ã¯ã©ã¹ã¿ãŒæ§æå€æŽãžã®èæ§
- ãªãŒãã¬ããªã«ãšã³ããã€ã³ã:
- åã ã®ããŒãã«çŽæ¥æ¥ç¶ããããããã®ããŒãã«é害ãçºçãããšæ¥ç¶ã倱ãããŸãã
- ã¯ã©ã¹ã¿ãŒã®åæ§æããã§ã€ã«ãªãŒããŒãçºçããå Žåãæ°ãããªãŒãã¬ããªã«ãæåã§æ€åºããŠåãæ¿ããå¿ èŠããããŸãã
- ã¯ã©ã¹ã¿ãŒã®èšå®ãšã³ããã€ã³ã:
- ã¯ã©ã¹ã¿ãŒå šäœãæœè±¡åããŠäžã€ã®ãšã³ããã€ã³ããæäŸã
- å éšã§é©åãªããŒãã«ã«ãŒãã£ã³ã°ãè¡ãããããã§ã€ã«ãªãŒããŒããªãŒãã¬ããªã«ã®è¿œå ã»åé€ãééçã«åŠçãããŸãã
- ã¢ããªã±ãŒã·ã§ã³ã¯ã¯ã©ã¹ã¿ãŒã®å éšæ§æã«äŸåãããæ¥ç¶å ãåžžã«å®å®ããŠä¿ã€ããšãã§ããŸãã
2. è² è·åæ£
- ãªãŒãã¬ããªã«ãšã³ããã€ã³ã:
- ç¹å®ã®ãªãŒãã¬ããªã«ã«ããæ¥ç¶ã§ãããè² è·åæ£ãã¢ããªã±ãŒã·ã§ã³ã«äŸåããŸãã
- é«è² è·ã®ã¯ãŒã¯ããŒãã§ã¯ã¹ã±ãŒã©ããªãã£ãå¶éãããå ŽåããããŸãã
- ã¯ã©ã¹ã¿ãŒã®èšå®ãšã³ããã€ã³ã:
- ã¯ã©ã¹ã¿ãŒå ã®è€æ°ã®ãªãŒãã¬ããªã«ã«èªåçã«ãªã¯ãšã¹ãã忣ã
- è² è·ã®ãã©ã³ã¹ãå¹ççã«ä¿ã€ããšãã§ããã¯ã©ã¹ã¿ãŒã®ã¹ã±ãŒã©ããªãã£ãæå€§é掻çšã§ããŸãã
3. ãã§ã€ã«ãªãŒããŒã®èªåå
- ãªãŒãã¬ããªã«ãšã³ããã€ã³ã:
- ç¹å®ã®ããŒããé害ãèµ·ãããšæ¥ç¶ãåãããããã¢ããªã±ãŒã·ã§ã³åŽã§æåã§ãšã³ããã€ã³ããåãæ¿ããå¿ èŠããããŸãã
- ã¯ã©ã¹ã¿ãŒã®èšå®ãšã³ããã€ã³ã:
- ãã§ã€ã«ãªãŒããŒæã«ãèªåçã«æ°ãããã¹ã¿ãŒããªãŒãã¬ããªã«ã«ã«ãŒãã£ã³ã°ã倿ŽãããŸãã
- ã¢ããªã±ãŒã·ã§ã³ã¯ãšã³ããã€ã³ããæ°ã«ãããééçã«æ¥ç¶ãç¶æã§ããŸãã
AWS Lambda
lambdaãªãŒãœã©ã€ã¶ãŒäŸïŒ
token == âabcâ:æ€èšŒãã¿ãŒã³
import json
from logging import getLogger, INFO
logger = getLogger(__name__)
logger.setLevel(INFO)
def lambda_handler(event, context):
print("============ event ã®åºå ============")
logger.info(json.dumps(event))
token = event['authorizationToken']
effect = 'Deny'
if token == 'abc':
effect = 'Allow'
return {
'principalId': '*',
'policyDocument': {
'Version': '2012-10-17',
'Statement': [
{
'Action': 'execute-api:Invoke',
'Effect': effect,
'Resource': event['methodArn']
}
]
}
}
Amazon Kinesis Data Streams
æ¡åŒµãã¡ã³ã¢ãŠãããã³ã·ã£ãŒãæ°ã®é¢ä¿ã€ã¡ãŒãž

ããããµã€ãº
ããããµã€ãºãå¢å ããããšãLambda 颿°ãäžåºŠã«åŠçããã¬ã³ãŒãæ°ãå¢ããŸãããã®çµæãåãããã®åŠçæéãé·ããªããããŒã¿ã®åã蟌ã¿ããåŠçãŸã§ã®ã¬ã€ãã³ã·ãŒãå¢å ãã
SQS
ReportBatchItemFailures ã®æŠèŠ
- ç®ç: Lambda颿°ããããåŠçäžã«å€±æããã¢ã€ãã ã ããå詊è¡å¯Ÿè±¡ãšããŠããŒã¯ããã
- 察象ãµãŒãã¹: äž»ã«SQSãšKinesisã€ãã³ããœãŒã¹ã§å©çšãããŸãã
Lambdaã®ããã¥ãŒå¯èŠæ§ã¿ã€ã ã¢ãŠãïŒVisibility TimeoutïŒãã¯ãAmazon SQSïŒSimple Queue ServiceïŒãšLambdaã®çµ±åã«é¢é£ããéèŠãªæŠå¿µ
å¯èŠæ§ã¿ã€ã ã¢ãŠãã®æŠèŠ
- ç®ç: SQSãã¥ãŒã®ã¡ãã»ãŒãžãæ¶è²»ãããåŸã«ãå床å¥ã®æ¶è²»è ããèŠããããã«ãªããŸã§ã®æéãèšå®ã
- åäœ:
- LambdaãSQSããã¡ãã»ãŒãžãååŸãããšããã®ã¡ãã»ãŒãžã¯ãäžæçã«é衚瀺ãã«ãªããŸãïŒå¯èŠæ§ã¿ã€ã ã¢ãŠãïŒã
- é衚瀺æéå ã«Lambdaãã¡ãã»ãŒãžãåŠçããæåãŸãã¯å€±æãSQSã«éç¥ããŸãã
- æå: ã¡ãã»ãŒãžã¯åé€ãããŸãã
- 倱æ: ã¡ãã»ãŒãžã¯å詊è¡ã®å¯Ÿè±¡ã«ãªããŸãã
- å¯èŠæ§ã¿ã€ã ã¢ãŠãæéãçµéãããšãã¡ãã»ãŒãžã¯åã³ä»ã®æ¶è²»è ããèŠããããã«ãªããŸãã
泚æ
ãã®èšäºã¯AWSã®ãµãŒãã¹ã®é¢ä¿ãå
šäœåãç°¡ç¥ã«çè§£ããããã
å°ããµãŒãã¹åãçç¥è¡šèšããŠãããã®ããããããããŸããããäºæ¿ãã ããã
ãŸããAWSèªäœåžžã«ã¢ããããŒããããã®ããã2025/02ææç¹ã§ã®æ
å ±ãæžããŠããã€ããã§ããã
ææ°ã®æ
å ±ã¯ãããŸã§èªå·±è²¬ä»»ã§ã調ã¹ããã ããã°ãšæããŸãã