19 幎 2019 æ 106 æ¥ãCapital One ã¯ãçŸä»£ã®ãã¹ãŠã®äŒæ¥ãæããŠãããããŒã¿äŸµå®³ãçºçãããšããã¡ãã»ãŒãžãåãåããŸããã 140å000äžäººä»¥äžã圱é¿ãåããã ç±³åœã®ç€ŸäŒä¿éçªå·ã¯ 80 件ãã«ããã®ç€ŸäŒä¿éçªå·ã¯ 000 äžä»¶ã XNUMX ã®éè¡å£åº§ã äžå¿«ã§ãããããæããŸãããïŒ
æ®å¿µãªããããããã³ã°ã¯ 19 æ XNUMX æ¥ã«çºçããŸããã§ããã çµå±ã®ãšããããã€ãžã»ãã³ããœã³ãå¥åïŒ äžèŠåã22幎23æ2019æ¥ããXNUMXæXNUMXæ¥ãŸã§ã®éã«ç¯ãããŸããã ãã㯠ã»ãŒXNUMXãæåã å®éãCapital One ãäœããèµ·ãã£ãããšãçºèŠã§ããã®ã¯ãå€éšã³ã³ãµã«ã¿ã³ãã®å©ãããã£ãããã§ãã
å
AmazonåŸæ¥å¡ãé®æããã250äžãã«ã®çœ°éãšXNUMX幎ã®æ²åœ¹åãèšãæž¡ãããâŠããããäŸç¶ãšããŠå€ãã®ãã¬ãã£ããªææ
ãæ®ã£ãŠããã ãªãïŒ ãªããªãããããã³ã°è¢«å®³ã«éã£ãå€ãã®äŒæ¥ã¯ããµã€ããŒç¯çœªãå¢å ããäžãèªç€Ÿã®ã€ã³ãã©ãã¢ããªã±ãŒã·ã§ã³ã匷åãã責任ãéããããšããŠããããã ã
ãšã«ããããã®è©±ã¯ç°¡åã«ã°ãŒã°ã«ã§æ€çŽ¢ã§ããŸãã ãã©ãã®è©±ã«ã¯å ¥ããŸãããã次ã®ããšã«ã€ããŠè©±ããŸãã ãã¯ãã«ã« åé¡ã®åŽé¢ã
ãŸããäœãèµ·ãã£ãã®ã§ããããïŒ
Capital One ã§ã¯çŽ 700 åã® S3 ãã±ãããå®è¡ãããŠãããPaige Thompson ããããã³ããŒããŠåžãäžããŸããã
次ã«ãããã S3 ãã±ãã ããªã·ãŒã®èšå®ãééã£ãŠããã±ãŒã¹ãªã®ã§ãããã?
ããããä»åã¯éããŸãã ããã§åœŒå¥³ã¯ããã¡ã€ã¢ãŠã©ãŒã«ãæ£ããæ§æãããŠããªããµãŒããŒã«ã¢ã¯ã»ã¹ããããããæäœå šäœãå®è¡ããŸããã
åŸ ã£ãŠãã©ãããŠãããªããšãã§ããã®?
ããŠã詳现ã¯ããŸããããŸãããããµãŒããŒã«ãã°ã€ã³ããããšããå§ããŸãããã ç§ãã¡ãç¥ããããã®ã¯ããããã誀ã£ãŠèšå®ããããã¡ã€ã¢ãŠã©ãŒã«ããéããŠèµ·ãã£ããšããããšã ãã§ããã ã€ãŸããWeb ã¢ããªã±ãŒã·ã§ã³ ãã¡ã€ã¢ãŠã©ãŒã« (Imperva) ãŸãã¯ãããã¯ãŒã¯ ãã¡ã€ã¢ãŠã©ãŒã« (iptablesãufwãshorewall ãªã©) ã®ã»ãã¥ãªã㣠ã°ã«ãŒãèšå®ãæ§æãééã£ãŠãããšããåçŽãªåé¡ã§ãã ãã£ãã¿ã«ã»ã¯ã³ã¯èªãã®çœªãèªããç©Žãå¡ãã ã ãã ãšè¿°ã¹ãã
ã¹ããŒã³æ°ã¯ãCapital Oneã¯åœåãã¡ã€ã¢ãŠã©ãŒã«ã®è匱æ§ã«æ°ä»ããªãã£ãããèªèãããšããã«è¡åãããšè¿°ã¹ãã ã¹ããŒã³æ°ã¯ãããã«ãŒãéèŠãªå人æ å ±ããããªãã¯ãã¡ã€ã³ã«æ®ãããšèšãããŠãããšããäºå®ã«ãã£ãŠç¢ºå®ã«å©ãããããšè¿°ã¹ãã
ãªããã®éšåã«ã€ããŠè©³ãã説æããªãã®ããšçåã«æãããå Žåã¯ãæ å ±ãéãããŠãããããæšæž¬ããããšããã§ããªãããšããç解ãã ããã ãããã³ã°ãCapital Oneã«ãã£ãŠæ®ãããç©Žã«äŸåããŠããããšãèãããšãããã¯æå³ããããŸããã ãããŠã圌ããããã«è©³ããæããŠãããªãéããCapital One ããµãŒããŒãéãããŸãŸã«ããèãããããã¹ãŠã®æ¹æ³ãšã誰ãããããã®ããŸããŸãªãªãã·ã§ã³ã® XNUMX ã€ã䜿çšããå¯èœæ§ã®ãããã¹ãŠã®æ¹æ³ãçµã¿åãããŠãªã¹ãããŸãã ãããã®æ¬ é¥ãææ³ã¯ãéåžžã«æããªèŠèœãšãããä¿¡ããããªãã»ã©è€éãªãã¿ãŒã³ãŸã§å€å²ã«ããããŸãã ããŸããŸãªå¯èœæ§ãèæ ®ãããšãããã¯æ¬åœã®çµè«ã®ãªãé·ãç©èªã«ãªãã§ãããã ãããã£ãŠãäºå®ãããéšåãéç¹çã«åæããŸãããã
æåã®ãã€ã³ãã¯ããã¡ã€ã¢ãŠã©ãŒã«ã§äœãèš±å¯ãããŠããããç¥ãããšã§ãã
ããªã·ãŒãŸãã¯é©åãªããã»ã¹ã確ç«ããŠãéãå¿ èŠããããã®ã ããéãããããã«ããŸãã ã»ãã¥ãªã㣠ã°ã«ãŒãããããã¯ãŒã¯ ACL ãªã©ã® AWS ãªãœãŒã¹ã䜿çšããŠããå Žåãæããã«ç£æ»ããããã®ãã§ãã¯ãªã¹ãã¯é·ããªãå¯èœæ§ããããŸã...ããããå€ãã®ãªãœãŒã¹ãèªåçã«äœæãããã®ãšåæ§ (ã€ãŸããCloudFormation)ãç£æ»ãèªååããããšãå¯èœã§ãã æ°ãããªããžã§ã¯ãã®æ¬ é¥ãã¹ãã£ã³ããèªå®¶è£œã¹ã¯ãªããã§ãããCI/CD ããã»ã¹ã®ã»ãã¥ãªãã£ç£æ»ã®ãããªãã®ã§ããããããåé¿ããç°¡åãªãªãã·ã§ã³ããããããããŸãã
ãã®è©±ã®ãé¢çœããéšåã¯ããã£ãã¿ã«ã»ã¯ã³ãæåãããã®ç©Žãå¡ãã§ãããâŠäœãèµ·ãããªãã£ãã ãããšããããšã§ãã ã ãããççŽã«èšã£ãŠãäœããå®éã«ã©ã®ããã«èµ·ãã£ãŠããããèŠãã®ã¯ãã€ãè¡æçã§ã ãã®ãããåçŽ äŒæ¥ããããã³ã°ãããå¯äžã®çç±ã«ãªããŸãã ç¹ã«Capital Oneãšåãããã倧ãããã®ã
ããã§ãå éšã®ããã«ãŒ - 次ã«äœãèµ·ãã£ãã§ãããã?
ããŠãEC2 ã€ã³ã¹ã¿ã³ã¹ã«äŸµå ¥ããåŸã¯...å€ãã®åé¡ãçºçããå¯èœæ§ããããŸãã 誰ãããããŸã§è¡ããããšãäºå®äžãã€ãã®åã®äžãæ©ããŠãããããªãã®ã§ãã ããããã©ããã£ãŠ S3 ãã±ããã«äŸµå ¥ããã®ã§ãããã? ãããç解ããããã«ãIAM ããŒã«ã«ã€ããŠèª¬æããŸãã
ãããã£ãŠãAWS ã®ãµãŒãã¹ã«ã¢ã¯ã»ã¹ãã 3 ã€ã®æ¹æ³ã¯ããŠãŒã¶ãŒã«ãªãããšã§ãã ããŠãããã¯éåžžã«æçœã§ãã ããããã¢ããªã±ãŒã·ã§ã³ãµãŒããŒãªã©ã®ä»ã® AWS ãµãŒãã¹ã« SXNUMX ãã±ãããžã®ã¢ã¯ã»ã¹ãèš±å¯ãããå Žåã¯ã©ãããã°ããã§ãããã? ããã IAM ããŒã«ã®ç®çã§ãã ããã㯠XNUMX ã€ã®ã³ã³ããŒãã³ãã§æ§æãããŸãã
- ä¿¡é Œããªã·ãŒ - ãã®ããŒã«ã䜿çšã§ãããµãŒãã¹ãŸãã¯ãŠãŒã¶ãŒã¯äœã§ãã?
- ã¢ã¯ã»ã¹èš±å¯ããªã·ãŒ - ãã®ããŒã«ã§ã¯äœãèš±å¯ãããŸãã?
ããšãã°ãEC2 ã€ã³ã¹ã¿ã³ã¹ã S3 ãã±ããã«ã¢ã¯ã»ã¹ã§ããããã«ãã IAM ããŒã«ãäœæãããšããŸãããŸããEC2 (ãµãŒãã¹å šäœ) ãŸãã¯ç¹å®ã®ã€ã³ã¹ã¿ã³ã¹ãããŒã«ããåŒãç¶ããããšãã§ããä¿¡é Œããªã·ãŒãæã€ããã«ããŒã«ãèšå®ããŸãã ããŒã«ãåãå ¥ãããšããããšã¯ãããŒã«ã®æš©éã䜿çšããŠã¢ã¯ã·ã§ã³ãå®è¡ã§ããããšãæå³ããŸãã 次ã«ãã¢ã¯ã»ã¹èš±å¯ããªã·ãŒã«ãããã圹å²ãåŒãåããããµãŒãã¹/人/ãªãœãŒã¹ã¯ãç¹å®ã® 3 ã€ã®ãã±ããã«ã¢ã¯ã»ã¹ããå Žåã§ããCapital One ã®å Žåã®ããã« 700 以äžã®ãã±ããã«ã¢ã¯ã»ã¹ããå Žåã§ããSXNUMX äžã§ããããæäœãè¡ãããšãã§ããŸãã
IAM ããŒã«ãæ〠EC2 ã€ã³ã¹ã¿ã³ã¹ã«å ¥ã£ãããããã€ãã®æ¹æ³ã§èªèšŒæ å ±ãååŸã§ããŸãã
- ã€ã³ã¹ã¿ã³ã¹ã®ã¡ã¿ããŒã¿ã¯æ¬¡ã®å Žæã§ãªã¯ãšã¹ãã§ããŸãã
http://169.254.169.254/latest/meta-data
ãã®ã¢ãã¬ã¹ã§ã¯ãä»»æã®ã¢ã¯ã»ã¹ ããŒã䜿çšã㊠IAM ããŒã«ãèŠã€ããããšãã§ããŸãã ãã¡ãããã€ã³ã¹ã¿ã³ã¹å ã«ããå Žåã«éããŸãã
- AWS CLIã䜿çšããŠ...
AWS CLI ãã€ã³ã¹ããŒã«ãããŠããå ŽåãIAM ããŒã« (ååšããå Žå) ããã®èªèšŒæ å ±ãããŒããããŸãã æ®ã£ãŠããã®ã¯ãã€ã³ã¹ã¿ã³ã¹ãä»ããŠäœæ¥ããããšã ãã§ãã ãã¡ãããä¿¡é Œããªã·ãŒããªãŒãã³ã§ããã°ããã€ãžã¯ãã¹ãŠãçŽæ¥è¡ãããšãã§ããŸãã
ãããã£ãŠãIAM ããŒã«ã®æ¬è³ªã¯ãäžéšã®ãªãœãŒã¹ãä»ã®ãªãœãŒã¹ã«å¯ŸããŠãŠãŒã¶ãŒã«ä»£ãã£ãŠåäœã§ããããã«ããããšã§ãã
IAM ã®åœ¹å²ãç解ãããšããã§ããã€ãžã»ãã³ããœã³ãäœããããã«ã€ããŠè©±ããŸãããã
- 圌女ã¯ãã¡ã€ã¢ãŠã©ãŒã«ã®ç©Žãéã£ãŠãµãŒã㌠(EC2 ã€ã³ã¹ã¿ã³ã¹) ã«ã¢ã¯ã»ã¹ããŸããã
å ¬åŒèšé²ã«èšèŒãããŠããããã«ããããã»ãã¥ãªã㣠ã°ã«ãŒã/ACL ã§ãã£ãŠããç¬èªã® Web ã¢ããªã±ãŒã·ã§ã³ ãã¡ã€ã¢ãŠã©ãŒã«ã§ãã£ãŠãããã®ç©Žãå¡ãã®ã¯ããããéåžžã«ç°¡åã§ããã
- ãµãŒããŒã«ã¢ã¯ã»ã¹ãããšã圌女ã¯èªåèªèº«ããµãŒããŒã§ãããã®ããã«æ¯ãèãããšãã§ããŸããã
- IAM ãµãŒã㌠ããŒã«ã«ããããããã® 3 以äžã®ãã±ãããžã® S700 ã¢ã¯ã»ã¹ãèš±å¯ãããŠããããããããã®ãã±ããã«ã¢ã¯ã»ã¹ã§ããŸããã
ãã®ç¬éããã圌女ãããªããã°ãªããªãã£ãã®ã¯ãã³ãã³ããå®è¡ããããšã ãã§ãã List Buckets
ãããŠã³ãã³ã Sync
AWS CLI ãã...
ãã®è©±ã®æèš: å®å šã確èªããŠãã ããã å®æçãªç£æ»ãå®æœããŸãã ã»ãã¥ãªã㣠ããªã·ãŒã«å¯Ÿããæå°ç¹æš©ã®ååãå°éããŸãã
(
åºæïŒ habr.com