ð°ã»ãã·ã§ã³ãããŒãžã£ãŒãšãã©ã€ããŒããµããããã®èœãšã穎
ä»åã¯ã€ã³ãã©åå¿è
ð°ã®ç§ãAWSã³ã³ãœãŒã«ç»é¢ã«ãŠç°å¢æ§ç¯ãããŠãããšãããã»ãã·ã§ã³ãããŒãžã£ãŒãžã®æ¥ç¶ã§æããããèŠæŠããçµéšãå
±æããŸãã
åããããªå£ã«ã¶ã€ãã£ãæ¹ã®å©ãã«ãªãã°å¬ããã§ãïŒð
ã»ãã·ã§ã³ãããŒãžã£ãŒãšã¯
ã»ãã·ã§ã³ãããŒãžã£ãŒãšã¯AWS Systems Managerã®æ©èœã®ã²ãšã€ã§ãEC2ã€ã³ã¹ã¿ã³ã¹ããªã³ãã¬ãã¹ãµãŒããŒãžã®å®å šãªã¢ã¯ã»ã¹ã管çããããã®ãµãŒãã¹ã§ãã
ã»ãã·ã§ã³ãããŒãžã£ãŒã䜿çšããããšã«ãã£ãŠã以äžã®ã¡ãªãããåŸãããŸãã
- ã»ãã¥ãªãã£ã®åäž
ã€ã³ããŠã³ãããŒããéããããèžã¿å°ãã¹ããç¶æããããSSHããŒã管çãããããå¿ èŠããããŸããã - ç°¡åãªæäœ
AWSã³ã³ãœãŒã«ç»é¢ããã¯ã³ã¯ãªãã¯ã§æ¥ç¶ããããšãã§ããŸãã - äžå
管ç
IAMããªã·ãŒã«ãã£ãŠããããŒãžãããŒã(管ç察象ã®ã€ã³ã¹ã¿ã³ã¹)ãžã®æ¥ç¶æš©éãäžå 管çããããšãã§ããŸãã - ç£æ»
AWS CloudTrailãªã©ã®ãµãŒãã¹ãšé£æºããããšã§ããããŒãžãããŒããžã®æ¥ç¶å±¥æŽãèšé²ãç£æ»ããããšãã§ããŸãã
èµ·ãããšã©ãŒãšè§£æ±ºãŸã§ã®éã®ã
EC2ã®æ§ç¯ãå®äºããåŸãã»ãã·ã§ã³ãããŒãžã£ãŒã«ãã£ãŠæ¥ç¶ã確èªããããšãããšããããSSM ãšãŒãžã§ã³ãã¯ãªã³ã©ã€ã³ã§ã¯ãããŸããããšãããšã©ãŒã衚瀺ãããæ¥ç¶ã§ããªããšããåé¡ãèµ·ããŸããã
以äžã®æé ã§ç¶æ³ã確èªãã€ã€ãäºè±¡ãè§£æ¶ããŠãããŸããã
- EC2ã€ã³ã¹ã¿ã³ã¹ã«ããŒã«ãã¢ã¿ãã
EC2ã€ã³ã¹ã¿ã³ã¹ã«AmazonSSMManagedInstanceCoreããªã·ãŒãã¢ã¿ãããããIAMããŒã«ã远å ããŸããã - SSMãšãŒãžã§ã³ãã®ç¢ºèª
EC2ã«ã»ãã·ã§ã³ãããŒãžã£ãŒã§æ¥ç¶ããã«ã¯ãEC2ã«AWS Systems Managerã®SSMãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ãããŠããå¿ èŠããããŸãã
ä»åäœæããEC2ã®AMIã¯Amazon Linux 2023 AMIã ã£ããããããã©ã«ãã§ã€ã³ã¹ããŒã«ãããŠããããã§ããã - NATã²ãŒããŠã§ã€ã®è¿œå
ä»åEC2ã¯ãã©ã€ããŒããµããããã«èšçœ®ããŠãããNATã²ãŒããŠã§ã€ãèšçœ®ããŠããŸããã§ããã
ãããåå ã§SSMãšãŒãžã§ã³ãããªãã©ã€ã³ç¶æ ã«ãªã£ãŠããããã§ããã
以äžã®æé ã§ãã©ã€ããŒããµããããããã€ã³ã¿ãŒããããžã®æ¥ç¶ãå¯èœã«ããŸããã- ãããªãã¯ãµããããã«NATã²ãŒããŠã§ã€ãèšçœ®
- ãã©ã€ããŒããµããããã®ã«ãŒãããŒãã«ã®
0.0.0.0/0
ã®ã¿ãŒã²ããã«ãäœæããNATã²ãŒããŠã§ã€ãèšå®
ã»ãã·ã§ã³ãããŒãžã£ãŒã®ä»çµã¿ïŒãªãNATã²ãŒããŠã§ã€ãå¿ èŠã ã£ãã®ãïŒ
ãªãNATã²ãŒããŠã§ã€ããªããšã»ãã·ã§ã³ãããŒãžã£ãŒã§EC2ã«æ¥ç¶ã§ããªãã£ãã®ããã»ãã·ã§ã³ãããŒãžã£ãŒã®ä»çµã¿ãèžãŸããŠè§£èª¬ããŸãã
ã»ãã·ã§ã³ãããŒãžã£ãŒã®æ¥ç¶ã¯ãEC2ã€ã³ã¹ã¿ã³ã¹ãAWS Systems ManagerãµãŒãã¹ã®ãšã³ããã€ã³ããšæ¥ç¶ããããšã§ç¢ºç«ãããŸãã
å
·äœçãªæ¥ç¶ãããŒã¯ä»¥äžã§ãã
- ãŠãŒã¶ãŒãAWSã³ã³ãœãŒã«ç»é¢ã®ã»ãã·ã§ã³ãããŒãžã£ãŒã®ãæ¥ç¶ããæŒäž
- ã»ãã·ã§ã³ãããŒãžã£ãŒã¯EC2å ã®SSMãšãŒãžã§ã³ãã«ã»ãã·ã§ã³éå§ãæç€º
- EC2ã®AWSSystemManagerSSMãšãŒãžã§ã³ããã»ãã·ã§ã³ãããŒãžã£ãŒã«æ¥ç¶ãã
3ã®æé ã«ãŠãEC2å
ã®AWSSystemManagerSSMãšãŒãžã§ã³ããAWS Systems Managerãšã³ããã€ã³ã(ã€ã³ã¿ãŒããã)ã«å¯ŸããŠæ¥ç¶ã詊ã¿ãŸãã
EC2ããã©ã€ããŒããµããããã«èšçœ®ãããŠããå ŽåãNATã²ãŒããŠã§ã€ãç¡ããšã€ã³ã¿ãŒãããã«æ¥ç¶ãã§ããªãããããšã©ãŒã«ãªã£ãŠããŸã£ãããã§ããã
ç¥ã£ãŠãããããããã¯ãŒã¯çšèª
ä»åã®çµéšã§çè§£ãæ·±ãŸã£ãããããã¯ãŒã¯çšèªããŸãšããŸããã
- NATã²ãŒããŠã§ã€ãšã¯
ãã©ã€ããŒããµããããå ã®ãªãœãŒã¹ãã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ããããšãå¯èœã«ããŸãã
ãã©ã€ããŒããµããããã®ã€ã³ã¹ã¿ã³ã¹ãããã©ãã£ãã¯ãåãåããã€ã³ã¿ãŒãããã«è»¢éããŸãã
ã¢ãŠãããŠã³ãéä¿¡ãèš±å¯ããã€ã³ããŠã³ãéä¿¡ã¯èš±å¯ããŸããã - ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãšã¯
VPCãã€ã³ã¿ãŒãããã«æ¥ç¶ããããã®ãµãŒãã¹ã
ã¢ãŠãããŠã³ãéä¿¡/ã€ã³ããŠã³ãéä¿¡åæ¹ãèš±å¯ããŸãã - ã«ãŒãããŒãã«ãšã¯
ãµããããéã®éä¿¡çµè·¯ãå®çŸ©ããããã®èšå®ã
ç¹å®ã®IPã¢ãã¬ã¹ç¯å²ã®ãã©ãã£ãã¯ãã©ã®ã²ãŒããŠã§ã€ã«éãããæ±ºå®ããŸãã - ã»ãã¥ãªãã£ã°ã«ãŒã
ä»®æ³ãã¡ã€ã¢ãŠã©ãŒã«æ©èœã
ãã©ãã£ãã¯ã®èš±å¯/æåŠãå¶åŸ¡ããŸãã
ããã§0.0.0.0/0
ã®ã¢ãŠãããŠã³ããèš±å¯ããŠããŠããã©ã®ã²ãŒããŠã§ã€ã«æ¥ç¶ãããã®ãçµè·¯ããå®çŸ©ãããŠããªããšãã€ã³ã¿ãŒãããã«æ¥ç¶ããããšã¯ã§ããŸããã
ææ³
åèã«ããŠããæé ãšå°ãå€ããªããæ§ç¯ããŠããã®ã§ããããã®æ¹ãããŸããããªãããšãå€ããçµæãšããŠå€ãã®åŠã³ããããŸããã
æé éãã«ãã£ãŠãçè§£ããæ°ã«ãªã£ãŠãã人ããããããŠæé ããå€ããŠå€±æããŠã¿ãã®ãè¯ãçµéšã«ãªãã®ã§ããããã§ãð
åè
- https://docs.aws.amazon.com/ja_jp/systems-manager/latest/userguide/session-manager.html
- https://docs.aws.amazon.com/ja_jp/prescriptive-guidance/latest/patterns/connect-to-an-amazon-ec2-instance-by-using-session-manager.html
- https://www.stylez.co.jp/aws_columns/understand_the_basics_of_aws_networking/understanding_aws_public_subnets_and_private_subnets/#NAT-2
Discussion