Study/Certificate / / 2024. 12. 10. 12:38

[AWS SAA] IAM & AWS CLI ์ •๋ฆฌ

๐Ÿš€ 2024๋…„๋„ ํ•˜๋ฐ˜๊ธฐ AWS SAA-C03 ์ทจ๋“ ๋„์ „๊ธฐ

AWS SAA ๊ฐ•์˜๋ฅผ ๋ณธ๊ฒฉ์ ์œผ๋กœ ์ˆ˜๊ฐ•ํ•˜๋ฉด์„œ ํ•™์Šตํ•œ ๋‚ด์šฉ์„ ์ •๋ฆฌํ•˜๊ณ ์ž ํ•ฉ๋‹ˆ๋‹ค.

๊พธ์ค€ํžˆ ์ง„ํ–‰ํ•ด์„œ ๋‚ด๋…„ 1์›”๋ง ์ž๊ฒฉ์ฆ ์‹œํ—˜ ์‘์‹œ ์˜ˆ์ •์ž…๋‹ˆ๋‹ค.

 

๐Ÿ›ก๏ธ IAM ์‚ฌ์šฉ์ž ๋ฐ ๊ทธ๋ฃน

  • IAM (Identity and Access Management): ๊ธ€๋กœ๋ฒŒ ์„œ๋น„์Šค, ํŠน์ • ๋ฆฌ์ „์— ์ข…์† X
  • Root ์‚ฌ์šฉ์ž: ํšŒ์›๊ฐ€์ž… ๊ณ„์ •, ์‚ฌ์šฉํ•˜๋ฉด ์•ˆ๋˜๊ณ  User ๋งŒ๋“ค์–ด์„œ ์‚ฌ์šฉํ•ด์•ผํ•จ
  • User์™€ Group: N:N ๊ด€๊ณ„
    • User: Group์ด ์—†์„ ์ˆ˜๋„ ์žˆ์Œ
    • Group: Group ์•ˆ์— Group์€ ๋ถˆ๊ฐ€๋Šฅ, ์˜ค์ง User๋งŒ ์ฐธ์—ฌ
    • ๋‹ค์ค‘ ์†Œ์†: ํ•˜๋‚˜์˜ User๋Š” ์—ฌ๋Ÿฌ Group์— ์†Œ์†๋  ์ˆ˜ ์žˆ๋‹ค.
  • ๊ถŒํ•œ ๊ด€๋ฆฌ: User, Group ๋ณ„ ๊ถŒํ•œ ๊ด€๋ฆฌ ๊ฐ€๋Šฅ, ์ตœ์†Œ ๊ถŒํ•œ์˜ ์›์น™

๐Ÿ“œ IAM ์ •์ฑ…

IAM ์ •์ฑ…์€ AWS ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•œ ์ ‘๊ทผ์„ ์ œ์–ดํ•˜๋Š” ๊ทœ์น™ ์ง‘ํ•ฉ

๐Ÿ“‚ Group ์ •์ฑ… vs. Inline ์ •์ฑ…

  • Group ์ •์ฑ…: Group ๋‚ด๋ถ€ User๊ฐ€ ๋ฐ›๋Š” ์ •์ฑ….
  • Inline ์ •์ฑ…: ํŠน์ • ์‚ฌ์šฉ์ž์—๊ฒŒ ์ง์ ‘ ์ ์šฉ๋˜๋Š” ์ •์ฑ….

๐Ÿ“ ์ •์ฑ…์˜ ๊ตฌ์กฐ

IAM ์ •์ฑ…์€ JSON ํ˜•์‹์œผ๋กœ ์ž‘์„ฑ

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "iam:GenerateCredentialReport", 
                "iam:GenerateServiceLastAccessedDetails",
                "iam:Get*",
                "iam:List*",
                "iam:SimulateCustomPolicy",
                "iam:SimulatePrincipalPolicy"
            ],
            "Resource": "*"
        }
    ]
}
  • Version: ์ •์ฑ…์ด ์ƒ์„ฑ๋œ ์ตœ์‹  ๋‚ ์งœ
  • Statement: ์ •์ฑ…์˜ ํ•ต์‹ฌ ๋‚ด์šฉ, Effect, Action, Resource๋ฅผ ํฌํ•จ

 


 

๐Ÿ” IAM Password ์ •์ฑ…๊ณผ MFA

๋ณด์•ˆ ๊ฐ•ํ™”๋ฅผ ์œ„ํ•ด IAM์—์„œ๋Š” ๋‹ค์–‘ํ•œ ์ธ์ฆ ๋ฐฉ๋ฒ•๊ณผ ํŒจ์Šค์›Œ๋“œ ์ •์ฑ…์„ ์ œ๊ณต

๐Ÿ”‘ Password ์ •์ฑ…

  • ์ตœ์†Œ ๋น„๋ฐ€๋ฒˆํ˜ธ ๊ธธ์ด ์„ค์ •
  • ํŠน์ • ๋ฌธ์ž ์œ ํ˜• ์š”๊ตฌ: ๋Œ€๋ฌธ์ž, ์†Œ๋ฌธ์ž, ์ˆซ์ž, ํŠน์ˆ˜๋ฌธ์ž ํ˜ผํ•ฉ
  • ํŒจ์Šค์›Œ๋“œ ๋งŒ๋ฃŒ์ผ์ž ์ œํ•œ
  • ์ค‘๋ณต๋œ ํŒจ์Šค์›Œ๋“œ ์žฌ์‚ฌ์šฉ ๊ธˆ์ง€

๐Ÿ“ฑ MFA (Multi-Factor Authentication)

  • ๊ฐœ๋…: ํŒจ์Šค์›Œ๋“œ์™€ ์†Œ์œ ํ•œ ์žฅ์น˜๋ฅผ ํ˜ผํ•ฉํ•œ ์ธ์ฆ ๋ฐฉ์‹. ํŒจ์Šค์›Œ๋“œ๊ฐ€ ํƒˆ์ทจ๋˜๋”๋ผ๋„ ์†Œ์œ ํ•œ ์žฅ์น˜๊ฐ€ ์—†์œผ๋ฉด ์ ‘๊ทผ์ด ๋ถˆ๊ฐ€๋Šฅํ•˜๋‹ค.
  • MFA ๋””๋ฐ”์ด์Šค ์˜ต์…˜:
    • Authenticator App: Google Authenticator, Authy ๋“ฑ ๊ฐ€์ƒ์˜ ์•ฑ์—์„œ ํ† ํฐ์„ ์ƒ์„ฑ.
    • Security Key: Universal 2Nd Factor (U2F) Security Key ์‚ฌ์šฉ.
    • Hardware TOTP token: Hardware Key Fob MFA Device ๋“ฑ ์‚ฌ์šฉ.

Tip: ์—ฌ๋Ÿฌ MFA ์˜ต์…˜์„ ์ดํ•ดํ•˜๊ณ , ๋น„์ฆˆ๋‹ˆ์Šค ์š”๊ตฌ์— ๋งž๋Š” ๋„๊ตฌ๋ฅผ ์„ ํƒํ•˜๋Š” ๊ฒƒ์ด ์ค‘์š”


๐ŸŽญ IAM Role

IAM Role์€ ์‚ฌ์šฉ์ž์™€ ์œ ์‚ฌํ•˜์ง€๋งŒ, ์‹ค์ œ ์‚ฌ๋žŒ์ด ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ์•„๋‹ˆ๋ผ AWS ์„œ๋น„์Šค๊ฐ€ ์‚ฌ์šฉํ•˜๋„๋ก ๋งŒ๋“ค์–ด์ง„ ๊ฐœ๋…

  • ์‚ฌ์šฉ ๋ชฉ์ : AWS ์„œ๋น„์Šค๊ฐ€ ๋‹ค๋ฅธ AWS API์™€ ์ƒํ˜ธ์ž‘์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•  ๋•Œ ์‚ฌ์šฉ.
  • ์˜ˆ์‹œ: EC2 ์ธ์Šคํ„ด์Šค๊ฐ€ AWS API์™€ ์ƒํ˜ธ์ž‘์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก ๊ถŒํ•œ์ด ํ•„์š”ํ•  ๋•Œ IAM Role์„ ์‚ฌ์šฉ.

๐Ÿ› ๏ธ IAM Security Tools

AWS๋Š” IAM ๋ณด์•ˆ์„ ๊ฐ•ํ™”ํ•˜๊ธฐ ์œ„ํ•ด ๋‹ค์–‘ํ•œ ๋„๊ตฌ๋ฅผ ์ œ๊ณต

  • IAM Credentials Report (Account Level): IAM ์ž๊ฒฉ ์ฆ๋ช… ๋ณด๊ณ ์„œ๋ฅผ ์ƒ์„ฑํ•˜์—ฌ ๊ณ„์ • ๋‚ด ์‚ฌ์šฉ์ž์™€ ์ž๊ฒฉ ์ฆ๋ช… ์ƒํƒœ๋ฅผ ํ™•์ธ. ์˜ˆ: MFA ๋ฏธ์„ค์ • ์ง์›์„ ์ฐพ์•„ ๋ณด์•ˆ ์ •์ฑ…์„ ์ค€์ˆ˜ํ•˜๋„๋ก ํ•จ.
  • IAM Access Advisor (User-Level): ์‚ฌ์šฉ์ž์—๊ฒŒ ๋ถ€์—ฌ๋œ ์„œ๋น„์Šค ๊ถŒํ•œ๊ณผ ๋งˆ์ง€๋ง‰์œผ๋กœ ์•ก์„ธ์Šคํ•œ ์‹œ๊ฐ„์„ ํ™•์ธ. ์˜ˆ: ์‚ฌ์šฉ์ž์˜ ์‚ฌ์šฉ ํŒจํ„ด์„ ๋ถ„์„ํ•˜์—ฌ ๋ถˆํ•„์š”ํ•œ ๊ถŒํ•œ์„ ์ œ๊ฑฐํ•˜๊ณ  ์ตœ์†Œ ๊ถŒํ•œ์˜ ์›์น™์„ ์œ ์ง€.

๐Ÿ–ฅ๏ธ AWS CLI

AWS CLI๋Š” AWS ์„œ๋น„์Šค์™€ ์ƒํ˜ธ ์ž‘์šฉํ•˜๊ธฐ ์œ„ํ•œ ๊ฐ•๋ ฅํ•œ ๋„๊ตฌ

๐Ÿ”‘ AWS Access Key

  • Access Key ID: Username ์ˆ˜์ค€์œผ๋กœ ์ดํ•ด.
  • Secret Access Key: Password ์ˆ˜์ค€์œผ๋กœ ์ดํ•ด.
  • ์ฃผ์˜ ์‚ฌํ•ญ: Access Key๋Š” ์ ˆ๋Œ€ ๊ณต์œ  X

โš–๏ธ AWS SDK์™€ CLI์˜ ์ฐจ์ด์ 

  • AWS CLI: ํ„ฐ๋ฏธ๋„์—์„œ ์ง์ ‘ ์ƒํ˜ธ ์ž‘์šฉํ•˜๋ฉฐ ๋ช…๋ น์–ด ๊ธฐ๋ฐ˜์œผ๋กœ ์ž‘๋™.
  • AWS SDK: ํ”„๋กœ๊ทธ๋ž˜๋ฐ ์–ธ์–ด์— ๋งž๊ฒŒ AWS API์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๋„๋ก ์ง€์›.

๐Ÿ“ ์š”์•ฝ

  • Root ๊ณ„์ • ์‚ฌ์šฉ ์ž์ œ: AWS Account Setup ์™ธ์—๋Š” Root ๊ณ„์ •์„ ์‚ฌ์šฉํ•˜์ง€ ์•Š์•„์•ผ ํ•œ๋‹ค.
  • 1์ธ 1๊ณ„์ • ์›์น™: ํ•œ ๋ช…์˜ ์ง์›์—๊ฒŒ ์—ฌ๋Ÿฌ ์‚ฌ์šฉ์ž๋ฅผ ๋ถ€์—ฌํ•ด์„œ๋Š” ์•ˆ ๋œ๋‹ค.
  • ๊ทธ๋ฃน ๋ ˆ๋ฒจ ๋ณด์•ˆ ์œ ์ง€: ๋ณด์•ˆ ์ˆ˜์ค€์„ ๊ทธ๋ฃน ๋‹จ์œ„๋กœ ๊ด€๋ฆฌ.
  • ๊ฐ•๋ ฅํ•œ ํŒจ์Šค์›Œ๋“œ ์ •์ฑ…: ์ตœ์†Œ ๋น„๋ฐ€๋ฒˆํ˜ธ ๊ธธ์ด ๋ฐ ๋ณต์žก์„ฑ ์œ ์ง€.
  • MFA ์ธ์ฆ ์‚ฌ์šฉ: ์ถ”๊ฐ€ ๋ณด์•ˆ ๊ณ„์ธต์„ ์œ„ํ•ด MFA ์‚ฌ์šฉ.
  • AWS Role ์‚ฌ์šฉ: AWS ์„œ๋น„์Šค์— ๊ถŒํ•œ ๋ถ€์—ฌ ์‹œ Role ์‚ฌ์šฉ.
  • Access Key ๊ด€๋ฆฌ: CLI๋‚˜ SDK ์‚ฌ์šฉ ์‹œ ํ•„์š”ํ•œ Access Key๋Š” ์ ˆ๋Œ€ ํƒ€์ธ๊ณผ ๊ณต์œ ํ•˜์ง€ ์•Š๋Š”๋‹ค.
  • ๊ณ„์ • ๊ถŒํ•œ ๊ฒ€ํ† :
    • Account Level: IAM Credentials Report ํ™œ์šฉ.
    • User Level: IAM Access Advisor ํ™œ์šฉ.

๐Ÿ“š AWS IAM Summary

IAM์˜ ์ฃผ์š” ๊ฐœ๋…๊ณผ ๊ตฌ์„ฑ ์š”์†Œ๋ฅผ ์š”์•ฝํ•ฉ๋‹ˆ๋‹ค.

  • Users: ์‹ค์ œ ๋ฌผ๋ฆฌ์  ์‚ฌ์šฉ์ž์™€ ๋งคํ•‘๋˜์–ด์•ผ ํ•œ๋‹ค.
  • Groups: ์‚ฌ์šฉ์ž๋ฅผ ๊ทธ๋ฃนํ™”ํ•˜์—ฌ ๊ทธ๋ฃน ๋‹จ์œ„๋กœ ๊ด€๋ฆฌ. ์˜ค์ง ์‚ฌ์šฉ์ž๋งŒ ๊ทธ๋ฃน์— ํฌํ•จ๋  ์ˆ˜ ์žˆ๋‹ค.
  • Policies: ๊ทธ๋ฃน์ด๋‚˜ ์‚ฌ์šฉ์ž์— ๋Œ€ํ•œ ๊ถŒํ•œ ์ •์ฑ…์„ JSON์œผ๋กœ ๊ด€๋ฆฌ.
  • Roles: EC2 ์ธ์Šคํ„ด์Šค๋‚˜ AWS ์„œ๋น„์Šค๋ฅผ ์œ„ํ•œ ์ •์ฑ… ๊ฐœ๋….
  • Security: MFA์™€ Password Policy๋ฅผ ์ ๊ทน์ ์œผ๋กœ ์‚ฌ์šฉ.
  • AWS CLI: CLI๋กœ ๋‹ค์–‘ํ•œ AWS ์„œ๋น„์Šค์— ์ ‘๊ทผ ๊ฐ€๋Šฅ.
  • AWS SDK: ํ”„๋กœ๊ทธ๋ž˜๋ฐ ์–ธ์–ด๋ฅผ ํ™œ์šฉํ•ด ์„œ๋น„์Šค ๋‚ด์—์„œ AWS API์— ์ ‘๊ทผ ๊ฐ€๋Šฅ.
  • Access Keys: CLI ๋˜๋Š” SDK ์‚ฌ์šฉ ์‹œ ํ•„์š”ํ•˜๋ฉฐ ์ ˆ๋Œ€ ํƒ€์ธ๊ณผ ๊ณต์œ ํ•˜์ง€ ์•Š๋Š”๋‹ค.
  • Audit: IAM Credential Reports๋‚˜ IAM Access Advisor๋ฅผ ํ†ตํ•ด ๊ณ„์ • ๋ฐ ์‚ฌ์šฉ์ž์˜ ํ˜„ํ™ฉ์„ ํ™•์ธ.

โŒ ์˜ค๋‹ต๋…ธํŠธ

  • ํ•ด๋‹น ์„น์…˜ ๋ฌธ์ œ ํ’€์ด ๊ฒฐ๊ณผ: 8/9
  • Version์€ AWS IAM Policy ๋‚ด Statement์— ํฌํ•จ๋˜์ง€ ์•Š๋Š”๋‹ค. 

๐Ÿ’ก ๊ฒฐ๋ก 

AWS SAA-C03 ์ž๊ฒฉ์ฆ์„ ์ค€๋น„ํ•˜๊ธฐ ์ „์— ๊ทธ๋ƒฅ ๋ฃจํŠธ ๊ณ„์ •์„ ์‚ฌ์šฉํ–ˆ์—ˆ๋Š”๋ฐ, ์ •๋ง ๋ฌธ์ œ๊ฐ€ ์žˆ๋Š” ๋ฐฉ์‹์ด๋ผ๋Š”๊ฑธ ๊นจ๋‹ฌ์•˜๊ณ  ์–ด๋ ดํ’‹์ด ์•Œ๋˜ ๊ถŒํ•œ๊ณผ ์—ญํ•  ๊ทธ๋ฃน์— ๋Œ€ํ•ด์„œ ์ƒ์„ธํ•˜๊ฒŒ ์•Œ ์ˆ˜ ์žˆ์—ˆ๋‹ค. ๋ณด์•ˆ์˜ ํ•ต์‹ฌ์ธ IAM์„ ์ž˜ ํ™œ์šฉํ•˜์ž.


๐Ÿ“š Refference


 

'Study > Certificate' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[AWS SAA] EC2 - SAA Level  (0) 2024.12.12
[AWS SAA] EC2 ๊ธฐ์ดˆ ์ •๋ฆฌ  (0) 2024.12.12
[AWS] AWS Solution Architect Associate(SAA-C03) ์‹œ์ž‘  (3) 2024.10.10
  • ๋„ค์ด๋ฒ„ ๋ธ”๋กœ๊ทธ ๊ณต์œ 
  • ๋„ค์ด๋ฒ„ ๋ฐด๋“œ ๊ณต์œ 
  • ํŽ˜์ด์Šค๋ถ ๊ณต์œ 
  • ์นด์นด์˜ค์Šคํ† ๋ฆฌ ๊ณต์œ