AWS IAM

YeJi Kimยท2023๋…„ 3์›” 24์ผ
0

SAA

๋ชฉ๋ก ๋ณด๊ธฐ
1/4

๐Ÿ“ SAA ๋„์ „ 1์ผ์ฐจ
๐Ÿ“ Udemy-AWS Certified Solutions Architect Associate ์„น์…˜ 4


IAM: Users & Groups

  • IAM = Identity and Access Management, Global service
  • IAM์—์„œ๋Š” ์‚ฌ์šฉ์ž๋ฅผ ์ƒ์„ฑํ•˜๊ณ  ๊ทธ๋ฃน์— ๋ฐฐ์น˜ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ๊ธ€๋กœ๋ฒŒ ์„œ๋น„์Šค์— ํ•ด๋‹นํ•œ๋‹ค.
  • ๋ฃจํŠธ ๊ณ„์ •์€ ์ž๋™์œผ๋กœ ์ƒ์„ฑ๋œ๋‹ค. ๋ฃจํŠธ ๊ณ„์ •์€ ์‚ฌ์šฉ๋˜๊ฑฐ๋‚˜ ๊ณต์œ ๋˜์–ด์„œ๋Š” ์•ˆ๋œ๋‹ค. ์˜ค์ง ๊ณ„์ •์„ ์ƒ์„ฑํ•  ๋•Œ๋งŒ ์‚ฌ์šฉ๋˜์–ด์•ผ ํ•œ๋‹ค.
  • ํ•˜๋‚˜์˜ ์‚ฌ์šฉ์ž๋Š” ์กฐ์ง ๋‚ด์˜ ํ•œ ์‚ฌ๋žŒ์— ํ•ด๋‹น๋œ๋‹ค. ํ•„์š”ํ•˜๋‹ค๋ฉด ์—ฌ๋Ÿฌ ๋ช…์˜ ์‚ฌ์šฉ์ž๋“ค์„ ๊ทธ๋ฃน์œผ๋กœ ๋ฌถ์„ ์ˆ˜ ์žˆ๋‹ค.
  • ๊ทธ๋ฃน์€ ์‚ฌ์šฉ์ž๋งŒ ํฌํ•จํ•  ์ˆ˜ ์žˆ๋‹ค. ๊ทธ๋ฃน์— ๋‹ค๋ฅธ ๊ทธ๋ฃน์„ ํฌํ•จ์‹œํ‚ฌ ์ˆ˜๋Š” ์—†๋‹ค.
  • ๊ทธ๋ฃน์— ํฌํ•จ๋˜์ง€ ์•Š์€ ์‚ฌ์šฉ์ž๋„ ์žˆ์„ ์ˆ˜ ์žˆ๋‹ค.



IAM: Permissions

  • ์‚ฌ์šฉ์ž ๋˜๋Š” ๊ทธ๋ฃน์—๊ฒŒ IAM ์ •์ฑ…์ด๋ผ๊ณ  ๋ถˆ๋ฆฌ๋Š” JSON ๋ฌธ์„œ๋ฅผ ์ง€์ •ํ•  ์ˆ˜ ์žˆ๋‹ค. ์ •์ฑ…๋“ค์„ ์‚ฌ์šฉํ•ด์„œ ์‚ฌ์šฉ์ž๋“ค์˜ ๊ถŒํ•œ์„ ์ •์˜ํ•  ์ˆ˜ ์žˆ๋‹ค.
  • AWS์—์„œ๋Š” ๋ชจ๋“  ์‚ฌ์šฉ์ž์—๊ฒŒ ๋ชจ๋“  ๊ฒƒ์„ ํ—ˆ์šฉํ•˜์ง€ ์•Š๋Š”๋‹ค. ์ƒˆ๋กœ์šด ์‚ฌ์šฉ์ž๊ฐ€ ๋„ˆ๋ฌด ๋งŽ์€ ์„œ๋น„์Šค๋ฅผ ์‹คํ–‰ํ•˜์—ฌ ํฐ ๋น„์šฉ์ด ๋ฐœ์ƒํ•˜๊ฑฐ๋‚˜, ๋ณด์•ˆ ๋ฌธ์ œ๋ฅผ ์•ผ๊ธฐํ•  ์ˆ˜ ์žˆ๊ธฐ ๋•Œ๋ฌธ์ด๋‹ค.
  • ๋”ฐ๋ผ์„œ AWS์—์„œ๋Š” ์ตœ์†Œ ๊ถŒํ•œ์˜ ์›์น™์„ ์ ์šฉํ•œ๋‹ค.
  • ๊ทธ๋ฃน์— ๋ฐฐ์น˜๋œ ์‚ฌ์šฉ์ž๋Š” ๋ถ€์—ฌ๋œ ๊ถŒํ•œ์„ ์Šน๊ณ„ํ•˜๊ฒŒ ๋œ๋‹ค.
  • Permission์„ ์„ค์ •ํ•˜๋Š” 3๊ฐ€์ง€ ๋ฐฉ์‹



IAM Policies Structure

  • version: ์ •์ฑ… ์–ธ์–ด ๋ฒ„์ „
  • ID: ์ •์ฑ… ์‹๋ณ„ ๋ฒˆํ˜ธ (optional)
  • Statement: ํ•˜๋‚˜ ์ด์ƒ์˜ ๋…๋ฆฝ์ ์ธ ๊ตฌ๋ฌธ๋“ค๋กœ ์ด๋ฃจ์–ด์ง
    • Sid: statement์˜ ์‹๋ณ„ ๋ฒˆํ˜ธ (optional)
    • Effect: ์ ‘๊ทผ์„ ํ—ˆ์šฉํ•˜๋Š”์ง€ ๋˜๋Š” ๊ฑฐ์ ˆํ•˜๋Š”์ง€ (Allow, Deny)
    • Principle: ์ •์ฑ…์ด ์ ์šฉ๋  ๊ณ„์ •/์‚ฌ์šฉ์ž/์—ญํ• 
    • Action: Effect์— ๊ธฐ๋ฐ˜ํ•ด์„œ ํ—ˆ์šฉ ๋˜๋Š” ๊ฑฐ๋ถ€๋˜๋Š” API ํ˜ธ์ถœ์˜ ๋ชฉ๋ก
    • Resource: Action์ด ์ ์šฉ๋  ๋ฆฌ์†Œ์Šค ๋ชฉ๋ก
    • Condition: Statement๊ฐ€ ์–ธ์ œ ์ ์šฉ๋ ์ง€๋ฅผ ๊ฒฐ์ •ํ•˜๋Š” ์กฐ๊ฑด (optional)



IAM: Password Policy

  • ๋น„๋ฐ€๋ฒˆํ˜ธ๊ฐ€ ๊ฐ•๋ ฅํ• ์ˆ˜๋ก ๊ณ„์ •์˜ ๋ณด์•ˆ์ด ์ฒ ์ €ํ•ด์ง„๋‹ค.
  • ๋‹ค์–‘ํ•œ password policy๋ฅผ ์„ธํŒ…ํ•  ์ˆ˜ ์žˆ๋‹ค.
    • ๋น„๋ฐ€๋ฒˆํ˜ธ์˜ ์ตœ์†Œ ๊ธธ์ด
    • ํŠน์ • ์œ ํ˜•์˜ ๊ธ€์ž ์‚ฌ์šฉ
    • ๋ชจ๋“  IAM ์‚ฌ์šฉ์ž๋“ค์ด ๊ฐ๊ฐ ๊ทธ๋“ค๋งŒ์˜ ๋น„๋ฐ€๋ฒˆํ˜ธ๋กœ ๋ฐ”๊พธ๋„๋ก ํ—ˆ์šฉ
    • ์ผ์ •ํ•œ ๊ธฐ๊ฐ„๋งˆ๋‹ค ๋น„๋ฐ€๋ฒˆํ˜ธ ๋งŒ๋ฃŒ์‹œํ‚ค๊ธฐ
    • ๋น„๋ฐ€๋ฒˆํ˜ธ ์žฌ์‚ฌ์šฉ ๋ง‰๊ธฐ



MFA(Multi Factor Authentication)

  • AWS์—์„œ๋Š” ์ด ๋ฉ”์ปค๋‹ˆ์ฆ˜์„ ํ•„์ˆ˜์ ์œผ๋กœ ์‚ฌ์šฉํ•˜๋„๋ก ๊ถŒ์žฅ๋œ๋‹ค.
  • ์‚ฌ์šฉ์ž๋“ค์€ ๊ณ„์ •์— ์ ‘๊ทผ ๊ถŒํ•œ์ด ์žˆ๊ณ  ๋งŽ์€ ์ž‘์—…์„ ํ•  ์ˆ˜ ์žˆ๋‹ค.
  • MFA = ๋น„๋ฐ€๋ฒˆํ˜ธ + ์†Œ์œ ํ•˜๊ณ  ์žˆ๋Š” ๋ณด์•ˆ ์žฅ์น˜
  • MFA ์žฅ์น˜์˜ ์ข…๋ฅ˜
    • Virtual MFA device
      • Google Authenticator: ํ•˜๋‚˜์˜ ํ•ธ๋“œํฐ๋งŒ ์‚ฌ์šฉ ๊ฐ€๋Šฅ
      • Authy: ์—ฌ๋Ÿฌ ์žฅ์น˜์—์„œ ์‚ฌ์šฉ ๊ฐ€๋Šฅ. ํ•˜๋‚˜์˜ ์žฅ์น˜์—์„œ ์—ฌ๋Ÿฌ๊ฐœ์˜ ํ† ํฐ๋“ค์„ ์ œ๊ณตํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์—ฌ๋Ÿฌ ๊ฐœ์˜ ๊ณ„์ •์— ๋Œ€ํ•ด ํ† ํฐ์„ ๋ฐœ๊ธ‰๋ฐ›์„ ์ˆ˜ ์žˆ๋‹ค.
    • U2F(Universal 2nd Factor Security Key)
      - YubiKey by Yubico: ๋ฌผ๋ฆฌ์  ์žฅ์น˜์ด๋‹ค. ํ•˜๋‚˜์˜ ๋ณด์•ˆ ํ‚ค์—์„œ ์—ฌ๋Ÿฌ ๋ฃจํŠธ ๊ณ„์ •๊ณผ IAM ์‚ฌ์šฉ์ž๋ฅผ ์ง€์›ํ•œ๋‹ค.



AWS CLI

AWS CLI ์„ค์น˜ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ๋‹ค์Œ ๋ฌธ์„œ๋ฅผ ๋”ฐ๋ผํ•˜๋ฉด ๋œ๋‹ค.
AWS CLI

๋‚ด ๋งฅ๋ถ์— aws CLI๊ฐ€ ์„ค์น˜๋œ ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

AWS access key๋ฅผ ํ†ตํ•ด IAM์„ ์„ค์ •ํ•  ์ˆ˜ ์žˆ๋‹ค.

๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด user list๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.



IAM Roles for Services

  • ๋ช‡๋ช‡ AWS ์„œ๋น„์Šค๋Š” ๋™์ž‘๋“ค์„ ์ˆ˜ํ–‰ํ•  ํ•„์š”๊ฐ€ ์žˆ๋‹ค.
  • ๊ทธ๋ ‡๊ฒŒ ํ•˜๊ธฐ ์œ„ํ•ด์„œ, AWS ์„œ๋น„์Šค๋“ค์— ๋Œ€ํ•œ ๊ถŒํ•œ์„ IAM Role์„ ํ†ตํ•ด ๋ถ€์—ฌํ•ด์•ผ ํ•œ๋‹ค.
  • common roles:
    • EC2 Instance Roles
    • Lambda Function ROles
    • Roles for CloudFormation



IAM Security Tools

  • IAM Credentials Report(account-level): ๊ณ„์ •์˜ ์‚ฌ์šฉ์ž์™€ ๋‹ค์–‘ํ•œ ์ž๊ฒฉ์ฆ๋ช…๋“ค์˜ ์ƒํƒœ๋ฅผ ํฌํ•จํ•œ ๋ฆฌํฌํŠธ
  • IAM Access Advisor(user-level): ์‚ฌ์šฉ์ž์—๊ฒŒ ๋ถ€์—ฌ๋œ ์„œ๋น„์Šค์˜ ๊ถŒํ•œ๊ณผ ํ•ด๋‹น ์„œ๋น„์Šค์— ๋งˆ์ง€๋ง‰์œผ๋กœ ์ ‘๊ทผํ•œ ์‹œ๊ฐ„์ด ๋ณด์ธ๋‹ค.



IAM Section - Summary

profile
์ด์ „์˜ ๊ธฐ๋ก๋“ค ๐Ÿ‘‰ https://blog.naver.com/reviewerkyj

4๊ฐœ์˜ ๋Œ“๊ธ€

comment-user-thumbnail
2023๋…„ 3์›” 27์ผ

S3 bucket์— ์—…๋กœ๋“œ ๋•Œ๋ฌธ์— IAM ์‚ฌ์šฉ์ž๋ฅผ ์ƒ์„ฑํ–ˆ๋˜ ๊ฒฝํ—˜์ด ์žˆ๋Š”๋ฐ password policy๊ฐ€ ์žˆ๋Š”๊ฑด ๋˜ ์ฒจ ์•Œ์•˜๋„ค์š”..
์•„ ๊ทธ๋ฆฌ๊ณ  MFA๋Š” ๋ถ„์‹คํ•˜์‹œ๋ฉด ๊ณจ์น˜ ์•„ํŒŒ ์ง€๋”๋ผ๊ณ ์š”๐Ÿ˜‚๐Ÿ˜‚
AWS์— ์˜์–ด๋กœ ์ „ํ™”ํ•ด์„œ ํ•ด๊ฒฐํ•ด์•ผ ํ•˜๋‹ˆ๊นŒ MFA ์‚ฌ์šฉํ•˜์‹œ๋ฉด ์‚ญ์ œ ์กฐ์‹ฌํ•˜์„ธ์š”!!

1๊ฐœ์˜ ๋‹ต๊ธ€
comment-user-thumbnail
2023๋…„ 3์›” 27์ผ

์ƒˆ๋กœ์šด ์ž๊ฒฉ์ฆ์— ์‹œ์ž‘์„ ์•Œ๋ฆฌ๋Š” ๊ธ€ ์ด์‹œ๊ตฐ์š”.
๊ณ„์†ํ•ด์„œ ๋„์ „ํ•ด๋‚˜๊ฐ€์‹œ๋Š” ๋ชจ์Šต ๋ฉ‹์žˆ์Šต๋‹ˆ๋‹ค ํ™”์ดํŒ…์ž…๋‹ˆ๋‹ค!!

๋‹ต๊ธ€ ๋‹ฌ๊ธฐ
comment-user-thumbnail
2023๋…„ 3์›” 27์ผ

๋ณต์žกํ•˜๋„ค์š” ์—ญ์‹œ cloud๋Š” ์ƒˆ๋กญ๊ธฐ๋„ ํ•˜๋ฉด์„œ ์–ด๋ ต๋„ค์š”

๋‹ต๊ธ€ ๋‹ฌ๊ธฐ