ç®æ¬¡
- å°å ¥ïŒãªãOffice on EC2ãSSMã§å®å šã«ç®¡çããããšæã£ãã®ã
- ãã®èšäºã§ç»å Žããäž»èŠãµãŒãã¹
- æåã®å£: SSMã«ç¹ãããªãïŒ IAMããŒã«ãšã»ãã¥ãªãã£ã°ã«ãŒããšã®æ Œé
- èŠããªãå£: ãããã¯ãŒã¯ã¯æ£ããã¯ããªã®ã«âŠVPCãšã³ããã€ã³ãã®çœ
- æå€§ã®è¬: ãªãã©ã€ã»ã³ã¹ä»ãAMIã ããçµäºããã®ãïŒ DHCPãªãã·ã§ã³ã»ãããæ ¹æ¬åå ã ã£ã話
- è£è¶³ïŒèŠèœãšããã¡ãªã©ã€ã»ã³ã¹ãããŒãžã£ãŒã®ãŠãŒã¶ãŒç»é²
- ãŸãšã
å°å ¥ïŒãªãOffice on EC2ãSSMã§å®å šã«ç®¡çããããšæã£ãã®ã
ãMicrosoft Officeä»ãEC2ã€ã³ã¹ã¿ã³ã¹ããèµ·åããŠã¿ããšããããªããæ°åã§åæã«çµäºããŠããŸãããããããªäžå¯è§£ãªåé¡ã«çŽé¢ããããšã¯ãããŸãããïŒ
ã¯ã©ãŠãã§ã®ãµãŒããŒç®¡çãšããã°ãèžã¿å°ãµãŒããŒããæ§ç¯ããŠã¢ã¯ã»ã¹ããã®ãäžè¬çã§ãããããããã®æ¹æ³ã¯ãç¶æã³ã¹ããåžžæå
¬éã«ããã»ãã¥ãªãã£ãªã¹ã¯ã課é¡ã§ãã
ããã§çŸåšã®AWSãæšå¥šããŠããã®ã AWS Systems Manager (SSM) ã䜿ã£ãç®¡çæ¹åŒã§ããSSMãå©çšããã°ããã¹ãŠã®ã»ãã¥ãªãã£ããŒããéãããŸãŸãå®å
šãã€å¹ççã«ã€ã³ã¹ã¿ã³ã¹ãžã¢ã¯ã»ã¹ã§ããŸãã
æ¬èšäºã§ã¯ããã®SSMæ¹åŒã§Officeä»ãEC2ãæ§ç¯ããããšããéã«ééãããã€ã³ã¹ã¿ã³ã¹å³çµäºåé¡ããšããã®è§£æ±ºãŸã§ã®éã®ãããŸãšããŸãããåé¡ã®åå ã¯åãªãèšå®ãã¹ã§ã¯ãªããSSMãLicense ManagerãActive DirectoryããããŠVPCã®DNSèšå®ãªã©ãããã€ãã®ä»çµã¿ã圱é¿ãåã£ãŠããŸããïŒ
ãã®èšäºããåããããªãã©ãã«ã«æ©ãæ¹ã®å©ãã«ãªãã°å¹žãã§ãïŒ
ä»åã®èšäºã§æ±ãOffice on EC2ã®æ§æã§ãã
å³1ïŒæ§æå³
ãã®ç°å¢ã§ã¯ã
- èžã¿å°ãµãŒããŒã眮ãããSSM Session ManagerãšVPCãšã³ããã€ã³ããå©çšããŠãã©ã€ããŒããµããããå ã®ãµãŒããŒãžå®å šã«æ¥ç¶ã§ãã
- åã³ã³ããŒãã³ãããã¹ãŠãã©ã€ããŒããµããããã«é 眮ããã€ã³ã¿ãŒãããã«çŽæ¥å ¬éããªãèšèš
ãšãã£ãç¹ãç¹åŸŽã«ãªã£ãŠããŸãã
ãã®èšäºã§ã¯ãOfficeä»ãEC2ã€ã³ã¹ã¿ã³ã¹ãå®å®çšŒåããããŸã§ã«çµéšãããã©ãã«ãšè§£æ±ºã®æµãããŸãšããŠããŸããæåã«ãä»åã®ã«ã®ãšãªã£ãAWSã®äž»èŠãµãŒãã¹ããã£ãã玹ä»ããŸãïŒ
ãã®èšäºã§ç»å Žããäž»èŠãµãŒãã¹
AWS Systems Manager (SSM)ãšã¯ïŒ
AWS Systems ManagerïŒä»¥äžSSMïŒã¯ãEC2ã€ã³ã¹ã¿ã³ã¹ãã¯ãããšãããµãŒããŒçŸ€ããå®å šãã€å¹ççã«ç®¡çããããã®ãµãŒãã¹ã§ããåŸæ¥ã¯ãªã¢ãŒãæäœã®ããã«ç¹å®ã®éä¿¡ããŒããéæŸããå¿ èŠããããŸããããSSMã§ã¯ãã®å¿ èŠããããŸããã
ãµãŒããŒå éšã§åäœãããSSM AgentãããAWSã®ç®¡çãµãŒãã¹ã«å¯ŸããŠå åŽããéä¿¡ãéå§ããä»çµã¿ã«ãªã£ãŠããããã§ããããã«ãããå€éšããã®ããŒãããã¹ãŠéããç¶æ ã§ããAWSã³ã³ãœãŒã«ãCLIãéããŠå®å šã«ãµãŒããŒãžã¢ã¯ã»ã¹ã§ããŸãã

å³2ïŒSSMã®åœ¹å²
Â
AWS License Managerãšã¯ïŒ
AWS License Managerã¯ãWindows ServerãMicrosoft Officeãªã©ã®ãœãããŠã§ã¢ã©ã€ã»ã³ã¹ãAWSäžã§äžå 管çãããµãŒãã¹ã§ããç¹ã«AWS Marketplaceçµç±ã§æäŸãããäžéšãœãããŠã§ã¢ã§ã¯ãã©ã€ã»ã³ã¹ããµãŒããŒåäœã§ã¯ãªã Active DirectoryãŠãŒã¶ãŒã«çŽã¥ãããŠãŒã¶ãŒããŒã¹ã®ãµãã¹ã¯ãªãã·ã§ã³ã ãšãã圢æ ãæ¡çšãããŠããŸãã
License Managerã¯Active Directoryãšé£æºãããŠãŒã¶ãŒããšã®å©çšæš©éãéäžç®¡çããŸããEC2ã€ã³ã¹ã¿ã³ã¹ã¯ãã°ã€ã³æã«License Managerãžåãåãããè¡ãã察象ãŠãŒã¶ãŒãæ£ããã©ã€ã»ã³ã¹ãæã£ãŠãããã©ãããæ€èšŒããŸãã

Â
DHCPãªãã·ã§ã³ã»ãããšã¯ïŒ
DHCPãªãã·ã§ã³ã»ããã¯ãVPCã«èšå®ããããšã§ããã®äžã§èµ·åããEC2ã€ã³ã¹ã¿ã³ã¹ã«å¯Ÿããåºæ¬çãªãããã¯ãŒã¯èšå®ãèªåçã«é åžããä»çµã¿ã§ãã
ã€ã³ã¹ã¿ã³ã¹ã¯ãã®èšå®ãéããŠãå©çšããDNSãµãŒããŒãããæå±ãããã¡ã€ã³åããšãã£ãæ å ±ãåãåããŸãã管çè ã¯ãªãã·ã§ã³ã»ãããã«ã¹ã¿ãã€ãºããããšã§ãVPCå šäœã®DNS解決ããã¡ã€ã³é¢é£ã®æåãçµ±äžçã«å¶åŸ¡ã§ããŸãã

å³4ïŒDHCPãªãã·ã§ã³ã»ããã®åœ¹å²
Â
æåã®å£: SSMã«ç¹ãããªãïŒ IAMããŒã«ãšã»ãã¥ãªãã£ã°ã«ãŒããšã®æ Œé
SSMã§ãµãŒããŒã«æ¥ç¶ããããšããŠããŸãçŽé¢ããã®ããããããSSMã®ç®¡çç»é¢ã«ã€ã³ã¹ã¿ã³ã¹ã衚瀺ãããªãããšããæåã®å£ã§ãããã®åå ã®ã»ãšãã©ã¯ãEC2ã€ã³ã¹ã¿ã³ã¹èªèº«ãæã€ã¹ãIAMããŒã«ãšã»ãã¥ãªãã£ã°ã«ãŒããšããã2ã€ã®åºæ¬çãªèšå®ã«ãããŸãã
EC2ã€ã³ã¹ã¿ã³ã¹ãSSMãšéä¿¡ããã«ã¯ãIAMããŒã«ããã€ã³ã¹ã¿ã³ã¹èµ·åæã«èº«ã«ã€ããŠããå¿ èŠããããŸããAmazonSSMManagedInstanceCore ãšããããªã·ãŒãã¢ã¿ããããããã®èš±å¯èšŒããªããã°ãSSM Agentã¯AWSãšå¯Ÿè©±ããæš©éããæãŠãŸããã
ããã«ãããšãIAMããŒã«ãæã£ãŠããŠããã€ã³ã¹ã¿ã³ã¹ã®ãã¡ã€ã¢ãŠã©ãŒã«ã§ããã»ãã¥ãªãã£ã°ã«ãŒããå€éšãžã®éä¿¡ããããã¯ããŠããŠã¯æå³ããããŸãããã¢ãŠãããŠã³ãã«ãŒã«ã§HTTPS(443)ã®éä¿¡ãèš±å¯ãããŠãããããšãã確èªãå¿ é ã§ãã
èŠããªãå£: ãããã¯ãŒã¯ã¯æ£ããã¯ããªã®ã«âŠVPCãšã³ããã€ã³ãã®çœ
SSMãã€ã³ã¹ã¿ã³ã¹ãèªèããªãåå ïŒVPCãšã³ããã€ã³ãã®äžè¶³
IAMããŒã«ãã»ãã¥ãªãã£ã°ã«ãŒãã®èšå®ãæ£ãããŠããEC2ã€ã³ã¹ã¿ã³ã¹ãSSMã®ç®¡çç»é¢ã«è¡šç€ºãããªãããšããããŸããããããåå ã®ã²ãšã€ããVPCãšã³ããã€ã³ãã®æªèšå®ãèšå®äžåã§ãã
ãã©ã€ããŒããµããããã«ããEC2ã€ã³ã¹ã¿ã³ã¹ã¯ãã€ã³ã¿ãŒããããçµç±ããã«AWSãµãŒãã¹ãšéä¿¡ããå¿ èŠããããŸãããã®ããã«ã¯ã以äž3ã€ã®VPCãšã³ããã€ã³ããäœæããªããã°ãªããŸããã
- com.amazonaws.
.ssm : Run Commandãããã管çãªã©ãSSMã®åçš®æäœã«å¿ èŠ - com.amazonaws.
.ec2messages : ã€ã³ã¹ã¿ã³ã¹ãSSMãšç¶æ ãããåãããããã«å¿ èŠ - com.amazonaws.
.ssmmessages : Session Managerã«ããã·ã§ã«æ¥ç¶ã«å¿ èŠ
ã»ãã¥ãªãã£ã°ã«ãŒãèšå®ã®èŠèœãšã
ãšã³ããã€ã³ããäœæããã ãã§ã¯éä¿¡ã§ããªãå ŽåããããŸãããã®å€ãã¯ãVPCãšã³ããã€ã³ãã«é¢é£ä»ããã»ãã¥ãªãã£ã°ã«ãŒãã®èšå®äžè¶³ãåå ã§ãã
å ·äœçã«ã¯ããšã³ããã€ã³ãåŽã®ã»ãã¥ãªãã£ã°ã«ãŒãã« HTTPS (443) ã®ã€ã³ããŠã³ãéä¿¡èš±å¯ ã远å ããå¿ èŠããããŸããã€ã³ã¹ã¿ã³ã¹åŽã®ã¢ãŠãããŠã³ãèš±å¯ã ãã§ã¯äžååã§ããšã³ããã€ã³ãããªã¯ãšã¹ããåãä»ããããªãããã§ãã
ãã®èšå®ãè¡ãããšã§ãSSM Agent ãAWSãµãŒãã¹ãšæ£ããéä¿¡ã§ããããã«ãªãã管çç»é¢ã«ã€ã³ã¹ã¿ã³ã¹ã衚瀺ãããããã«ãªããŸãã
ç§èªèº«ããã®ã»ãã¥ãªãã£ã°ã«ãŒãã®èšå®ãèŠèœãšããŠãããåå ãåãããé·ãæéãè²»ãããŠããŸããŸããããã
æå€§ã®è¬: ãªãã©ã€ã»ã³ã¹ä»ãAMIã ããçµäºããã®ãïŒ DHCPãªãã·ã§ã³ã»ãããæ ¹æ¬åå ã ã£ã話
åé¡
åè¿°ã®ã»ãã¥ãªãã£ã°ã«ãŒãèšå®ãä¿®æ£ããããšã§ãSSMã®ç®¡çäžã«ã€ã³ã¹ã¿ã³ã¹ã衚瀺ã§ããããã«ãªããŸãããããããå¥ã®ç°å¢ã§ã¯ããã«åä»ãªåé¡ã«çŽé¢ããŸãããOfficeã©ã€ã»ã³ã¹ä»ãã®AMIãå©çšããå Žåã«ã®ã¿ãEC2ã€ã³ã¹ã¿ã³ã¹ãèµ·åçŽåŸã«èªåçµäºããŠããŸãããšããåé¡ã§ãã
IAMããŒã«ãVPCãšã³ããã€ã³ããã»ãã¥ãªãã£ã°ã«ãŒãã®èšå®ã¯ããããåé¡ãªããReachability Analyzerã«ãããããã¯ãŒã¯çµè·¯ãæ£åžžã§ããã
調æ»éçš
åœåã¯ã©ã€ã»ã³ã¹èªèšŒçšã®éä¿¡çµè·¯ã«åé¡ããããšèãããããã¯ãŒã¯çéã確èªããŸãããã察象ãã¹ããžã®æ¥ç¶ã¯ããããæåããŠãããçµè·¯èªäœã«ã¯åé¡ããããŸããã§ããã
ããã«ããããããèªèšŒã倱æããã€ã³ã¹ã¿ã³ã¹ãçµäºããç¶æ³ãããDNS解決ã«é¢é£ããèšå®ã確èªããŸããã
åå
æ ¹æ¬åå ã¯DHCPãªãã·ã§ã³ã»ããã«ãããŸããïŒ
ã€ã³ã¹ã¿ã³ã¹ã¯èµ·åæã«DHCPãªãã·ã§ã³ã»ããã§æå®ãããDNSãµãŒããŒãå©çšããŸããVPCã®ããã©ã«ãã§ã¯AmazonProvidedDNS (10.0.0.2ãªã©)ãå²ãåœãŠãããŸãããä»åã®AMIãèŠæ±ããã®ã¯ä»¥äžã®2çš®é¡ã®åå解決ã§ãã
- Active Directory ãã¡ã€ã³(1)
- AWS License Manager(2)
AmazonProvidedDNSã¯(2)ã解決ã§ããŸããã(1)ã®å éšãã¡ã€ã³ã¯è§£æ±ºã§ããŸããããã®ããèªèšŒåŠçã®åææ®µéã§å€±æããã€ã³ã¹ã¿ã³ã¹ã匷å¶çµäºããŠããŸããã
解決ç
æ°ããDHCPãªãã·ã§ã³ã»ãããäœæãããã©ã€ããªã®DNSãµãŒããŒãšããŠADãã¡ã€ã³ã³ã³ãããŒã©ãŒãæå®ããŸãããADã®DNSãµãŒããŒã¯(1)ãçŽæ¥è§£æ±ºã§ããæªè§£æ±ºã®ã¯ãšãªãAmazonProvidedDNSãžãã©ã¯ãŒãããèšå®ã«ãªã£ãŠããããã(2)ãåæ§ã«è§£æ±ºå¯èœã§ãã
ãã®å€æŽã«ãããOfficeã©ã€ã»ã³ã¹ä»ãAMIã®èªèšŒåŠçãæ£åžžã«å®äºããã€ã³ã¹ã¿ã³ã¹ãçµäºãã皌åãç¶ããããšã確èªã§ããŸããïŒ
è£è¶³ïŒèŠèœãšããã¡ãªã©ã€ã»ã³ã¹ãããŒãžã£ãŒã®ãŠãŒã¶ãŒç»é²
DHCPãªãã·ã§ã³ã»ããã«ããDNSèšå®ãæŽããŠããã©ã€ã»ã³ã¹èªèšŒã倱æããå ŽåããããŸãã
ãã®åå ã®ã²ãšã€ããAWS License Managerã«ããããŠãŒã¶ãŒç»é²ã®äžè¶³ã§ããOfficeã®ã©ã€ã»ã³ã¹ããŠãŒã¶ãŒããŒã¹ã§ç®¡çããŠããå ŽåãèªèšŒæã«ããã°ã€ã³ããŠãããŠãŒã¶ãŒããµãã¹ã¯ãªãã·ã§ã³ã«å«ãŸããŠãããããæ€èšŒãããŸãã
ãã®ãããAWSãããžã¡ã³ãã³ã³ãœãŒã«ã® License Manager â ãŠãŒã¶ãŒããŒã¹ã®ãµãã¹ã¯ãªãã·ã§ã³ ç»é¢ããã察象ã®ADãŠãŒã¶ãŒã远å ããå¿ èŠããããŸãã
ãããã®èšå®ãå¿ããŠãããšãDNSããããã¯ãŒã¯ãæ£ãããŠãã©ã€ã»ã³ã¹èªèšŒã¯å€±æããŸãã確èªããéã¯ã察象ãŠãŒã¶ãŒããµãã¹ã¯ãªãªãã·ã§ã³ã«ç»é²ãããŠããããå¿ ããã§ãã¯ããŸãããïŒ
ãŸãšã
Officeã©ã€ã»ã³ã¹ä»ãAMIãèµ·åãããšãã€ã³ã¹ã¿ã³ã¹ãæ°åã§çµäºããŠããŸãããããããªåé¡ã«çŽé¢ããŸããã
åå ãæ¢ãããã«ãIAMããŒã«ãã»ãã¥ãªãã£ã°ã«ãŒããVPCãšã³ããã€ã³ãããããã¯ãŒã¯ACLãªã©ãèããããèšå®ãäžéã確èªããŸããããã©ããåé¡ã¯èŠã€ãããã解決ã®ç³žå£ãã€ãããªããŸãŸèŠæŠã匷ããããŸããã
ãããæçµçã«ãæ ¹æ¬åå ã¯DHCPãªãã·ã§ã³ã»ããã«ããããšã倿ããŸããã
ã©ã€ã»ã³ã¹ä»ãAMIã¯ãèµ·åçŽåŸã«Active Directoryã®DNSãæ£ããåç §ã§ããããšãåæãšããŠããŸãããšããããããã©ã«ãã®AmazonProvidedDNSã®ãŸãŸã§ã¯è§£æ±ºã§ããªããã¡ã€ã³ãååšãããããã©ã€ã»ã³ã¹èªèšŒå€±æã®çŽæ¥çãªèŠå ãšãªã£ãŠããŸããã
ä»åã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ãéããŠå®æããã®ã¯ããä»çµã¿ãæ£ããçè§£ããããšãã®å€§åãã§ããVPCå ã§ã®DNS解決ã®ä»çµã¿ããã¡ããšææ¡ããŠããã°ããã£ãšæ©ãåé¡ã«ãã©ãçãããããããŸããã
åããŠèšäºã«ãŸãšããŸãããããã®èšé²ãåããããªåé¡ã§æ©ãæ¹ã®å©ãã«ãªãã°å¹žãã§ãïŒ