ããã«ã¡ã¯ãG-gen ã®æŠäºã§ããä»å㯠Google Cloud (æ§ç§° GCP) ã§ Cloud Functions ã®é¢æ°ãããŒã«ã«ã§æ€èšŒã§ãã Functions Framework ã®ã€ã³ã¹ããŒã«æ¹æ³ã«ã€ããŠç޹ä»ããããšæããŸãã cloud.google.com åææ¡ä»¶ 1. Linux éçºç°å¢ ãæå¹å 2. gcloud ã³ãã³ãã®ã€ã³ã¹ããŒã«ã»åæå Functions Framework ã®å°å
¥ 1. venvã»pip3 ã®ã€ã³ã¹ããŒã« 2. venv ä»®æ³ç°å¢ã®äœæ 3. Functions Framework ã®ã€ã³ã¹ããŒã« åäœç¢ºèª 1. ãœãŒã¹ã®æºå 2. Functions Framework ã®å®è¡ ä»®æ³é¢æ°ããã® Cloud SDK å®è¡ åææ¡ä»¶ 1. Linux éçºç°å¢ ãæå¹å åœç€Ÿã§ã¯å
šç€Ÿå¡ã Chromebook (Chrome OS) ã䜿ã£ãŠæ¥åãããŠããŸãã ãã®ããæ¬èšäºã§ã¯ãããŒã«ã«ç°å¢ãšã¯ Chromebook ã®ããããããŒåãæ©èœã§ããã Linux éçºç°å¢ããæããŠããŸãã ãã¡ãã Chromebook ã§ãªããŠã Functions Framework ã¯äœ¿çšã§ããã®ã§ã Chromebook ã§ã¯ãªãç°å¢ãž Functions Framework ãã€ã³ã¹ããŒã«ããå Žåã¯ãåœé
ç®ã¯ã¹ãããããŠãã ããã Chromebook ã® Linux éçºç°å¢æ©èœãçšãããš Chromebook å
ã« Linux (Debian) ã®ã³ã³ãããèµ·åããã¿ãŒããã«ã§æäœããããšãã§ããŸãã Linux ç°å¢ãæå¹åããã«ã¯ èšå® > 詳现èšå® > ããããã㌠> Linux éçºç°å¢ ããåæ©èœãæå¹åããŸãã èšå®ç»é¢ (ãã®ã¹ã¯ãªãŒã³ã·ã§ããã§ã¯æ¢ã«æå¹åæžã¿) 2. gcloud ã³ãã³ãã®ã€ã³ã¹ããŒã«ã»åæå â»ãã®æé ã¯éåžžã® gcloud ã³ãã³ããšåãã§ãããŸãã宿œãå¿
èŠãªã®ã¯å§ãã®1åã ãã§ãã ããã¥ã¡ã³ãã Cloud SDK ã®ã€ã³ã¹ããŒã« ãã«åŸã Linux ç°å¢ã« gcloud ã³ãã³ããã€ã³ã¹ããŒã«ããŸãã äžèšãªã³ã¯å
ã® Debian/Ubuntu ã®æé ã«åŸã£ãŠãã ããã ã€ã³ã¹ããŒã«ã§ããã gcloud init ã³ãã³ãã§åæåããŸãã ã¢ã«ãŠã³ãããããžã§ã¯ããæå®ããŸãããã Functions Framework ã®å°å
¥ 1. venvã»pip3 ã®ã€ã³ã¹ããŒã« Chromebook ã® Linux éçºç°å¢ã«ã¯ããããã Python3.x ãã€ã³ã¹ããŒã«ãããŠããŸãã ãã€ããŒããŒãžã§ã³ã¯ Linux éçºç°å¢ãæå¹ã«ããã¿ã€ãã³ã°ã«ãã£ãŠç°ãªãå Žåããããç§ã®å Žå㯠v3.9 ãã€ã³ã¹ããŒã«ãããŠããŸããã ãã ãvenv ã pip ã«ã€ããŠã¯ã€ã³ã¹ããŒã«ãããŠããŸããã§ããã®ã§ã以äžã®ã³ãã³ããå®è¡ããŠã€ã³ã¹ããŒã«ããŸãã sudo apt update && sudo apt install python3-pip 2. venv ä»®æ³ç°å¢ã®äœæ â Functions Framework ãå®è¡ããããã® venv ä»®æ³ç°å¢ãæºåããŠãããã«ããã±ãŒãžé¡ãã€ã³ã¹ããŒã«ããããšæããŸãã â ã»ãããžã§ã¯ãã®äœæ (ãããžã§ã¯ãå㯠âfunctionâ ãšãã) â mkdir function ã»ä»®æ³ç°å¢ã®äœæãšåæå â cd function python3 -m venv venv source venv/bin/activate ä»®æ³ç°å¢ãèµ·åããŠãããšãããã³ããã«ä»®æ³ç°å¢åã衚瀺ãããŸãã venv ä»®æ³ç°å¢ãèµ·åããŠããç¶æ
â 3. Functions Framework ã®ã€ã³ã¹ããŒã« â æºåãã venv ä»®æ³ç°å¢ã« Functions Framework ãã€ã³ã¹ããŒã«ããŸãã â â pip3 install functions-framework åäœç¢ºèª 1. ãœãŒã¹ã®æºå ãã¡ãã® Quickstart ã«ãããã£ãŠç°¡åãªåäœç¢ºèªã宿œããããšæããŸãã github.com venv ä»®æ³ç°å¢äžã«ä»»æã®äœæ¥ãã£ã¬ã¯ããªãäœæããããã«ãœãŒã¹ãã¡ã€ã« (main.py) ãæºåããŸãã Chromebook ã®å Žåã vscode.dev ã䜿ãã°ãã¡ã€ã«ã®äœæãš Linux éçºç°å¢ãžã®é
眮ãç°¡åã«è¡ãªããŸãã vscode.dev ãã Linux ã³ã³ããã®ãã¡ã€ã«ãç·šé vscode.dev ãã Linux ã³ã³ããã®ãã¡ã€ã«ãç·šé 2. Functions Framework ã®å®è¡ ãœãŒã¹ãã¡ã€ã«ãé
眮ãããã£ã¬ã¯ããªäžã§ Functions Framework ããããã°ã¢ãŒãã§å®è¡ããŸãã"hello" ã¯ãœãŒã¹ãã¡ã€ã«äžã§å®çŸ©ãã颿°åã§ãã functions-framework --debug --target hello ã¿ãŒããã«ç»é¢ã«ãããã°ãåºåãããŸãã®ã§ã http://localhost:8080 ã«ã¢ã¯ã»ã¹ããŸãã 颿°ã§å®çŸ©ãããšãã Hello world! ã衚瀺ãããã° Quickstart ã«ãããã£ãåäœç¢ºèªã¯å®äºã§ãã 颿° (Hello world!) ã衚瀺 ä»®æ³é¢æ°ããã® Cloud SDK å®è¡ functions-framework ã§èµ·åããä»®æ³ç㪠function ã®äžãã Cloud SDK ãå®è¡ããå ŽåããããšæããŸãã äŸãã° BigQuery ãžããŒã¿ãæå
¥ããã Cloud Storage ã®ãªããžã§ã¯ããæäœããããªã©ã§ãã Cloud SDK 㯠IAM èªèšŒãå¿
èŠãšããŸãããã®ãšããã©ã®ããã«èªèšŒããã°ããã®ã§ããããã ãããªãšã㯠functions-framework ã®å®è¡ç°å¢ã§ä»¥äžã®ã³ãã³ããå®è¡ããŸãã gcloud auth application-default login ãã®ã³ãã³ããå®è¡ããããšã§ gcloud ã«èšå®ãããŠããèªèšŒæ
å ±ã§ ~/.config/gcloud/application_default_credentials.json ã«èªèšŒæ
å ±ãã¡ã€ã«ãäœæãããããã䜿ã£ãŠ Cloud SDK ãå®è¡ãããããã«ãªããŸãã åè : ãªãã¡ã¬ã³ã¹ æŠäº ç¥ä» (èšäºäžèЧ) 2022幎4æå
¥ç€Ÿ / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš / æè¡2課æå± è¶£å³ã¯ãŽã«ãã«ããŒããã€ã¯ãIaC ã CI/CD åšãã®ãµãŒãã¹ããããã¯ããèå³åéã§ãã Google Cloud èªå®å
šå éæïŒ(2023幎6æ)
G-gen ã®ææã§ããåœèšäºã§ã¯ Google Cloud ã® Virtual Private CloudïŒç¥ç§° VPCïŒã«ã€ããŠåŸ¹åºè§£èª¬ããŸãããªãåœèšäºã¯ VPC ã®åºæ¬æ©èœã«çµã£ãã åºæ¬ç·š ãã§ããã å¿çšç·š ããããããŠãåç
§ãã ããã Virtual Private CloudïŒVPCïŒãšã¯ ãããã¯ãŒã¯ãšãµãããã ãããã¯ãŒã¯ ãµãããã ãµããããã® IP ã¢ãã¬ã¹ ãµããããäœæã¢ãŒã VPC éæ¥ç¶ ãªã³ãã¬ãã¹ãä»ã®ã¯ã©ãŠããšã®æ¥ç¶ ã«ãŒã ãã¡ã€ã¢ãŠã©ãŒã«ïŒCloud NGFWïŒ ã€ã³ã¿ãŒããããšã®ã¢ã¯ã»ã¹ VM ãšã€ã³ã¿ãŒãããéã®éä¿¡ Cloud NAT ã€ã³ã¿ãŒããããšã®éä¿¡ãé²ãæ¹æ³ ãã¬ãã¢ã ãã£ã¢ãšã¹ã¿ã³ããŒããã£ã¢ Google Cloud ãµãŒãã¹ãžã®ãã©ã€ããŒããµãŒãã¹ã¢ã¯ã»ã¹ éçš VPC Flow Logs ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®ãã° VPC ãããã¯ãŒã¯ã®ç£æ»ãã° æé æŠèŠ ãã©ãã£ãã¯éãžã®èª²é IP ã¢ãã¬ã¹ãžã®èª²é ãã®ä»æ©èœãžã®èª²é å¿çšç·šãžã®ãªã³ã¯ Virtual Private CloudïŒVPCïŒãšã¯ Virtual Private Cloud ïŒä»¥äžãVPCïŒãšã¯ Google CloudïŒæ§ç§° GCPïŒã«ä»®æ³ãããã¯ãŒã¯ãæ§ç¯ããããã®ãµãŒãã¹ã§ããæ§ç¯ããã VPC ãããã¯ãŒã¯ã¯ãä»ã® Google Cloud å©çšè
ããã¯å®å
šã«ç¬ç«ãããã©ã€ããŒããããã¯ãŒã¯ãšãªããŸãã VPC ãããã¯ãŒã¯ã¯ ãµãããã ãšåŒã°ããå°åããããããã¯ãŒã¯ã«åå²ããããµããããã«ã¯ãã©ã€ããŒã IP ã¢ãã¬ã¹åž¯ãå²ãåœãŠãããŸãããµããããå
ã«ã¯ Compute Engine ã®ä»®æ³ãã·ã³ïŒVMïŒãé
眮ããããGoogle Kubernetes EngineïŒGKEïŒã®ã¯ã©ã¹ã¿ãé
眮ããããApp EngineïŒFlexibleïŒã®ã¢ããªãé
眮ããããšãã§ããŸãã VPC ãããã¯ãŒã¯ã¯ãIPSec VPNïŒãµãŒãã¹å Cloud VPN ïŒãå°çšç·ïŒãµãŒãã¹å Cloud Interconnect ïŒã䜿ã£ãŠããªã³ãã¬ãã¹ã®ãããã¯ãŒã¯ããä»ã®ãããªãã¯ã¯ã©ãŠãã®ãããã¯ãŒã¯ãšæ¥ç¶ããããšãã§ããŸãã åè : Virtual Private CloudïŒVPCïŒã®æŠèŠ VPC ã¯ãAndromeda ãšãã Google ã®ãããã¯ãŒã¯ä»®æ³åæè¡ã䜿ã£ãŠå®è£
ãããŠããŸããä»®æ³çãªãããã¯ãŒã¯ã®ãããç©çãããã¯ãŒã¯ã§èæ
®ãå¿
èŠãªãã»ã°ã¡ã³ããå°ããåããããšã§ãããŒããã£ã¹ããã¡ã€ã³ãåå²ãããããã¯ãŒã¯ã®èŒ»èŒ³ã軜æžããããšãã£ãèæ
®ã¯ å¿
èŠãããŸãã ããã®ãããç©ççãªãããã¯ãŒã¯ãšã¯ãããã¯ãŒã¯èšèšã®åæãç°ãªãç¹ã«æ³šæãå¿
èŠã§ãã ãããã¯ãŒã¯ãšãµãããã ãããã¯ãŒã¯ãšãµãããã ãããã¯ãŒã¯ VPC ãããã¯ãŒã¯ ãŸãã¯åã« ãããã¯ãŒã¯ ãšã¯ãVPC ã§æ§ç¯ããã1ã€ã®ãããã¯ãŒã¯ã®ããšãæããŠããŸãã ãããã¯ãŒã¯ã¯ ã°ããŒãã«ãªãœãŒã¹ ã§ããããã¯ããããã¯ãŒã¯ã ãªãŒãžã§ã³ããŸããååš ã§ããããšã瀺ããŠããŸãã ä»ã®ãããªãã¯ã¯ã©ãŠãã®ä»£è¡šäŸãšã㊠Amazon Web ServicesïŒAWSïŒãäŸã«åããšãVPC ã¯ãªãŒãžã§ã³ãªãœãŒã¹ã§ããããªãŒãžã§ã³ããšã« VPC ãäœæããå¿
èŠããããŸããããã«å¯Ÿã㊠Google Cloud ã® VPC ã¯ã°ããŒãã«ãªãœãŒã¹ã§ãããããäœææã«ãªãŒãžã§ã³ãæå®ããå¿
èŠããããŸããããããã¯ãŒã¯ã®äžã«ãµãããããäœæããéã«ããªãŒãžã§ã³ãæå®ããŸãã ãŸã VPC ãããã¯ãŒã¯ã¯ IP ã¢ãã¬ã¹åž¯ã æã¡ãŸãã ãGoogle Cloud ã§ã¯ VPC å
ã®ãµãããããã ãµããããããšã« IP ã¢ãã¬ã¹åž¯ãæã¡ãŸã ããã®ããšãããVPC ã¯ããµããããããŸãšããã°ã«ãŒãã³ã°ãªãœãŒã¹ã§ããããšè§£éããããšãã§ããŸãã ãããã¯ãŒã¯ã¯äžã«ãã«ãŒããããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ããªã©ã®åãªãœãŒã¹ãæã¡ãŸããããããã°ããŒãã«ãªãœãŒã¹ã§ãã åè : VPC ãããã¯ãŒã¯ ãµãããã ãµãããã ïŒãããã¯ãµããããã¯ãŒã¯ïŒã¯ãVPC ãããã¯ãŒã¯ã®äžã«ååšãããå°åãããããããã¯ãŒã¯ã§ãã ãµãããã㯠ãªãŒãžã§ã³ãªãœãŒã¹ ã§ãããããäœææã«ãªãŒãžã§ã³ãæå®ããŸãããŸããäœææã« IP ã¢ãã¬ã¹åž¯ ã CIDR åœ¢åŒ ã§æå®ããŸãã ãµãããããäœã£ãŠåããŠããã®äžã« Compute Engine ã® VMïŒä»®æ³ãµãŒããŒïŒãªã©ãé
眮ããããšãã§ããããã«ãªããŸãã åè¿°ããŸããããVPC ãããã¯ãŒã¯ããµããããã¯ä»®æ³çãªååšã®ãããã»ã°ã¡ã³ããå°ããåããããšã§ãããŒããã£ã¹ããã¡ã€ã³ãåå²ãããããã¯ãŒã¯ã®èŒ»èŒ³ã軜æžããããšãã£ãèæ
®ã¯ å¿
èŠãããŸãã ã ãŸããã»ã°ã¡ã³ããåããããšã¯éä¿¡å¶åŸ¡ã«ã¯ãªããŸãããåäž VPC ã«æå±ãããµããããå士ã¯èªåçã«ã«ãŒããçæããã çžäºã«éä¿¡ããããšãã§ããŸã ããµããããå士ã®éä¿¡å¶åŸ¡ãè¡ããããšãã¯ãåŸè¿°ã®ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã«ããè¡ããŸãã ãåäž VPC ã«æå±ãããµããããå士ã¯éä¿¡ã§ããããšããååã¯ããªãŒãžã§ã³ãç°ãªã£ãŠãå€ãããŸãããéããªãŒãžã§ã³ã®ãµããããå士ã§ããåäž VPC ã«æå±ããŠããã°çžäºã«éä¿¡ããããšãã§ããŸãã åè : ãµãããã ãµããããã® IP ã¢ãã¬ã¹ ãµããããã«ã¯ CIDR åœ¢åŒ ã§ IP ã¢ãã¬ã¹ç¯å²ãæå®ããŸãããµããããã«ã¯ IPv4 ãŸã㯠IPv6 ç¯å²ãå²ãåœãŠãããšãå¯èœã§ãã IPv4 ã§ã¯ã 10.0.0.0/8 ã 172.16.0.0/12 ã 192.168.0.0/16 ãããªãã¡ RFC 1918 ã®ãã©ã€ããŒã IP ã¢ãã¬ã¹ç¯å²ã®äžããå²ãåœãŠå¯èœãªã»ãããã®ä»ã®ããã€ãã®ç¯å²ãå©çšå¯èœã§ãã æå°ã®ãµãããããµã€ãºã¯ /29 ïŒIP ã¢ãã¬ã¹æ°ã8åãåŸè¿°ã®äºçŽã¢ãã¬ã¹ãé€ããšå©çšå¯èœã¯4åã®ã¿ïŒã§ãã åè : æå¹ãª IPv4 ç¯å² åè : IPv4 ãµããããç¯å²ã®å¶éäºé
ãªããµããããã® IP ã¢ãã¬ã¹ã®ç¬¬4ãªã¯ãããã®ãã¡ãæåã®2ã€ãšæåŸã®2ã€ã® IP ã¢ãã¬ã¹ã¯ Google Cloud ã«ãã£ãŠäºçŽãããŠããããããŠãŒã¶ãŒã¯å©çšããããšãã§ããŸããã äŸãã° 10.1.2.0/24 ãšãããµããããã§ããã°ã 10.1.2.0 ã 10.1.2.1 ã 10.1.2.254 ã 10.1.2.255 ã¯äºçŽã¢ãã¬ã¹ã§ãããVM ã€ã³ã¹ã¿ã³ã¹çãé
眮ããããšãã§ããªãããšã«ãªããŸãã åè : IPv4 ãµããããç¯å²ã§äœ¿çšã§ããªãã¢ãã¬ã¹ ãã®ä»ã«ãçŠæ¢ãããŠãããµããããç¯å²ãååšããŸããGoogle ã«äºçŽãããŠãã 199.36.153.4/30 ã 199.36.153.8/30 ããªã³ã¯ããŒã«ã«ã¢ãã¬ã¹ã§ãã 169.254.0.0/16 ãªã©ã§ãã詳现ãªãªã¹ãã¯ä»¥äžã®å
¬åŒããã¥ã¡ã³ãã«èšèŒããããŸãã åè : çŠæ¢ãããŠãã IPv4 ãµããããç¯å² ãµããããäœæã¢ãŒã VPC æ§ç¯æã«ãµãããããäœæããéã èªåã¢ãŒã ãš ã«ã¹ã¿ã ã¢ãŒã ããéžæã§ããŸãã èªåã¢ãŒããéžæãããšãå
šãªãŒãžã§ã³ã«1ã€ãã€ãèªåçã«ãµãããããäœæãããŸããåãµããããã® CIDR ãããã¯ã¯ 10.128.0.0/9 ã®ç¯å²ããæ±ºãŸã£ã CIDR ãèªåçã«èšå®ãããŸãããã®ã¢ãŒãã§ã¯ãäžèŠãªãªãŒãžã§ã³ã«ãèªåçã«ãµãããããäœæãããããšããŸã CIDR ãç¹å®ã®ãã®ã«ãªã£ãŠããŸãããšããã æ€èšŒç®çç ã§ã®ã¿äœ¿ãããšãæšå¥šãããŸãã èªåã¢ãŒãã® VPC ã§å²ãåœãŠããã IP ã¢ãã¬ã¹ç¯å²ã¯ã以äžã®ããã¥ã¡ã³ããåç
§ããŠãã ããã åè : èªåã¢ãŒãã® IPv4 ç¯å² äžæ¹ã®ã«ã¹ã¿ã ã¢ãŒãã§ã¯ãèªåçã«ãµãããããäœæãããããšã¯ãªãããµããããäœæå
ã®ãªãŒãžã§ã³ã CIDR ã¯ãŠãŒã¶ãŒãæå®ããŸããVPC ãããã¯ãŒã¯ãäœæãããšããµããããã®ãªã空ã®ãããã¯ãŒã¯ãã§ããããããããæ±äº¬ãªãŒãžã§ã³ã« 192.168.0.0/24 ã§ãµãããããäœæãã®ããã«åå¥ã«ãµãããããäœæããŠãããŸãã æ¬çªçšéçã§ã¯ãã¡ãã®ã«ã¹ã¿ã ã¢ãŒããå©çš ããããšãæšå¥šãããŠããŸãã åè : ãµããããäœæã¢ãŒã VPC éæ¥ç¶ ç°ãªã VPC éå士ã¯ã VPC ãããã¯ãŒã¯ãã¢ãªã³ã° æ©èœã§æ¥ç¶ããããšãã§ããŸããåœæ©èœã§ã¯ãç°ãªã Google Cloud ãããžã§ã¯ãã«ãã VPC ãšãæ¥ç¶ãããããšãå¯èœã§ãã VPC ãããã¯ãŒã¯ãã¢ãªã³ã°ã®äœ¿çšæ¡ä»¶ãšããŠããµããããã® IP ã¢ãã¬ã¹ç¯å²ãéè€ããŠããªãããšããããŸãããŸã VPC ãããã¯ãŒã¯ãã¢ãªã³ã°çµç±ã§ã¯ã æšç§»çãã¢ãªã³ã°ã¯ã§ããªã ãªã©ã®å¶éããããŸããã€ãŸãã VPC A <=> VPC B <=> VPC C ããããããã¢ãªã³ã°ãããŠããå Žåã§ã VPC A ãš VPC C ãçŽæ¥ãã¢ãªã³ã°ãããŠããªãå Žåã VPC A ãš VPC C ã¯éä¿¡ããããšãã§ããŸããïŒéã® VPC B ãçµç±ããŠå察åŽã«å°éããããšã¯ã§ããŸããïŒãããã¯ãããããã2ãããå¶éããšããŠç¥ãããŠããŸãã åè : VPC ãããã¯ãŒã¯ ãã¢ãªã³ã° ãŸã Cloud VPN ã䜿ã£ãŠ VPC éãæ¥ç¶ããããšãå¯èœã§ããCloud VPN ã§ã¯æšç§»çãªæ¥ç¶ãå¯èœã§ãããæéãçºçããç¹ã VPC ãããã¯ãŒã¯ãã¢ãªã³ã°ãšã®éãã§ãã ãããã®ä»æ§ã¯ã å¿çšç·š ã®èšäºã§ç޹ä»ããŸãã ãªã³ãã¬ãã¹ãä»ã®ã¯ã©ãŠããšã®æ¥ç¶ VPC 㯠Cloud VPN ãšåŒã°ãã IPSec VPN ã®ä»çµã¿ãã Cloud Interconnect ãšããå°çšç·ãµãŒãã¹ã䜿ãããšã§ããªã³ãã¬ãã¹ã®æ¢åãããã¯ãŒã¯ããä»ã®ãããªãã¯ã¯ã©ãŠãã®ãããã¯ãŒã¯ãšæ¥ç¶ããããšãå¯èœã§ãã ããã«ããã€ã³ã¿ãŒããããä»ããããã©ã€ããŒã IP ãçšããŠä»ã®ãããã¯ãŒã¯ãã Google Cloud ã® VPC å
ã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããšãã§ããŸãã ä»ã®ãããã¯ãŒã¯ãš VPC ã®æ¥ç¶ã«ãããŠã¯ãååãšããŠæ¥ç¶ãããä»ã®ãããã¯ãŒã¯ãš VPC ãµããããã® IP ã¢ãã¬ã¹åž¯ã éè€ããŠããªãããš ãæ¡ä»¶ã§ããã«ãŒãã£ã³ã°ã®èšå®ã«ãã£ãŠã¯äžéšãéè€ããŠããŠãéä¿¡ãå¯èœã«ãªãå ŽåããããŸãããã·ã³ãã«ãªã«ãŒãèšèšã®ããã«ã¯ã VPC èšèšã®éã«ä»ã®ãããã¯ãŒã¯ãšã®æ¥ç¶ã®å¯èœæ§ã¯ååèæ
®ã«å
¥ãã ããšãæšå¥šãããŸãã åœèšäºã§ã¯ Cloud VPN ã Cloud Interconnect ã«ã€ããŠã¯è©³è¿°ããªãããã以äžã®ããã¥ã¡ã³ãããåç
§ãã ããã åè : Cloud VPN ã®æŠèŠ åè : Cloud Interconnect ã®æŠèŠ ãŸã Cloud VPN ã«ã€ããŠã¯ä»¥äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp ããã«ãGoogle Cloud ã® VPC ãšãAmazon Web ServicesïŒAWSïŒã Microsoft Azure ãªã©ä»ã¯ã©ãŠãã®ãããã¯ãŒã¯ãæ¥ç¶ããããšãã§ãã Cross-Cloud Interconnect ãšåŒã°ããå°çšç·ãµãŒãã¹ãååšããŸãã以äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp ã«ãŒã ã«ãŒã ã¯ãVPC ãããã¯ãŒã¯å
ã®ãã±ãããåŸããã«ãŒãã£ã³ã°ã®ã«ãŒã«ã§ããVPC ãããã¯ãŒã¯åäœã§ã«ãŒãããŒãã«ãååšããŸãã æ³šæãã¹ãç¹ã¯ãVPC ã®ã«ãŒãã¯ãVPC ãããã¯ãŒã¯ã® äžããå€ãž ãã±ãããå°éããããã®çµè·¯ãæå®ãããã«ãŒã«ã§ããããšããç¹ã§ããéæ¹åãã€ãŸã VPC ã® å€ããäžæ¹åãžã® çµè·¯ã¯ èªåçã«çæãããåé€ããããšãã§ããŸãã ã ã«ãŒãã«ã¯ãæåãã Google Cloud ã«ããçæããã ã·ã¹ãã çæã«ãŒã ãšãŠãŒã¶ãŒãèªåã§å®çŸ©ãã ã«ã¹ã¿ã ã«ãŒã ããããŸããã€ã³ã¿ãŒããããžéä¿¡ããããã®ããã©ã«ãã²ãŒããŠã§ã€ã«ãŒãããåäž VPC å
ã®ãµããããå士ã®ã«ãŒãã¯èªåçã«çæãããŸãããªããåè
ã¯åé€ããã眮æãããã§ããŸãããåŸè
ã¯åé€ã倿Žãã§ããŸããã åè : ã«ãŒã åè¿°ã®éããåäž VPC ãããã¯ãŒã¯å
ã®ãµããããå士ã®éä¿¡ã¯èªåçã«ã§ããããã«ãªããŸãã®ã§ãç¹ã«è¿œå ã®èšå®ã¯å¿
èŠãããŸããããŸã VPN ãå°çšç·ã§ VPC ãããã¯ãŒã¯ãä»ã®ãããã¯ãŒã¯ãšæ¥ç¶ããéãã仿§äžãå€ãã®å Žåã§ BGP ã«ããåçã«ãŒã亀æãè¡ããããããVPC ã«ãŒãããŒãã«ã«æåã§ã«ãŒãã远å ããããšã¯çšã§ããã«ãŒãã®è¿œå èšå®ãå¿
èŠã«ãªãã®ã¯ã以äžã®ãããªéãããå Žé¢ã§ãã ç¹å®ãããã¯ãŒã¯ãžã®ãã±ããã VM äžã®ä»®æ³ã¢ãã©ã€ã¢ã³ã¹ãžã«ãŒãã£ã³ã°ãããå Žå Cloud VPN ã® Classic VPN æ©èœã䜿ã£ãŠãããéçã«ãŒãã®è¿œå ãå¿
èŠãªå Žå ãã®ããã«ãGoogle Cloud ã® VPC ã§ã¯ãã«ãŒããæåã§ç·šéããæ©äŒã¯å°ãªããšãããŸããããã VPNãå°çšç·ãVPC Peering çã§ä»ãããã¯ãŒã¯ãžæ¥ç¶ããéã«ãã«ãŒã亀æãæ£åžžã«è¡ãããŠãããã確èªããéãªã©ã«åç
§ããæ¹ãå€ãã§ãã ãã¡ã€ã¢ãŠã©ãŒã«ïŒCloud NGFWïŒ Google Cloud ã® VPC ã«ã¯åãä»ãã®ãã¡ã€ã¢ãŠã©ãŒã«æ©èœããããŸãããã㯠Cloud Next Generation Firewall ïŒä»¥äžãCloud NGFWïŒãšãã Google Cloud ãããã¯ããšããŠãã©ã³ãã£ã³ã°ãããŠããŸãããVPC ãšå¯ã«é£æºããŠããŸãã åè : Cloud NGFW ã®æŠèŠ Cloud NGFW ã¯ãã«ãããŒãžãã®åæ£ã·ã¹ãã ã§ãããäžè¬çãªãã¡ã€ã¢ãŠã©ãŒã«ã¢ãã©ã€ã¢ã³ã¹ã®ãããªã€ã¡ãŒãžã§ã¯ãªããVPC å
ã®éä¿¡ã«å¯ŸããŠééçã«å¶åŸ¡ããããŸãããŠãŒã¶ã¯ãGoogle Cloud ã³ã³ãœãŒã«ã gcloud ã³ãã³ãã©ã€ã³ã§ã«ãŒã«ã远å ããã ãã§ãããã€ã³ãã©ã®ç®¡çãªã©ãèããå¿
èŠããããŸããã åœæ©èœã¯ Amazon Web ServicesïŒAWSïŒã«ããããã»ãã¥ãªãã£ã°ã«ãŒããã«çžåœããŠããŸãã 詳现ã¯ä»¥äžã®èšäºã§è§£èª¬ããŠããŸãã以äžã®èšäºã¯ Cloud NGFW ã®å
šäœåã解説ããŠããŠèªãã®ã«æéããããã®ã§ãåºæ¬çãªçè§£ã ããããã人ã¯ããŸãã¯ä»¥äžèšäºã®ãæŠèŠããVPC ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãã ãããèªã¿ãã ããã blog.g-gen.co.jp ã€ã³ã¿ãŒããããšã®ã¢ã¯ã»ã¹ VM ãšã€ã³ã¿ãŒãããéã®éä¿¡ VPC ãããã¯ãŒã¯ïŒãµããããïŒå
ããã€ã³ã¿ãŒããããžæ¥ç¶ããããšãå¯èœã§ãã VPC ã«ã¯ ããã©ã«ãã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ ïŒdefault-internet-gatewayïŒãååšãããµããããå
ã® VM ã¯ãããéããŠã€ã³ã¿ãŒããããšéä¿¡ããããšãã§ããŸãã VM ãã€ã³ã¿ãŒããããšéä¿¡ããã«ã¯ä»¥äžã®æ¡ä»¶ã å
šãŠ æºãããŠããå¿
èŠããããŸãã VPC ã®ã«ãŒãã«ããã©ã«ãã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãžã®çµè·¯ãååšãã VM ã External IPïŒå€éš IPããããã Public IPïŒã¢ãã¬ã¹ãæã€ VM ãšã€ã³ã¿ãŒãããäžã®ããŒãéã®éä¿¡ã VPC ãã¡ã€ã¢ãŠã©ãŒã«ã§èš±å¯ãããŠãã VPC ãããã¯ãŒã¯ãäœæããããšãããã€ãã®ã«ãŒããã·ã¹ãã ã«ãã£ãŠèªåçæãããŸãããã®äžã«ã¯ 0.0.0.0/0 ãããã©ã«ãã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãžåããã«ãŒããååšããŠãããã 1. ã«é¢ããŠã远å ã®æé ã¯å¿
èŠãããŸããã åè : ã·ã¹ãã çæã®ããã©ã«ã ã«ãŒã 2. ã«ã€ããŠãå
šãŠã® VM 㯠Internal IPïŒå
éš IPãPrivate IPïŒã¢ãã¬ã¹ãæã¡ãŸãããã€ã³ã¿ãŒããããšéä¿¡ããããã® External IPïŒãããã Public IPïŒã¢ãã¬ã¹ã«ã€ããŠã¯ãVM ã®æ§ç¯æã«æããããã©ãããéžæã§ããŸããVM æ§ç¯åŸã§ãã忢æã§ããã° Exnternal IP ã¢ãã¬ã¹ã®æç¡ã倿Žã§ããŸãã åè : å€éš IP ã¢ãã¬ã¹ 3. ã«ã€ããŠã¯ãVPC ã®ãã¡ã€ã¢ãŠã©ãŒã«ïŒCloud NGFWïŒã«ãŠ VM ãšã€ã³ã¿ãŒãããäžã®ããŒãã®éã®éä¿¡ãèš±å¯ãããŠããå¿
èŠããããŸããVM ããå§ãŸã éä¿¡ã§ããã°äžãïŒEgressïŒã«ãŒã«ã§ã å€éšããå§ãŸã éä¿¡ã§ããã°äžãïŒIngressïŒã«ãŒã«ã§èš±å¯ãããŠããå¿
èŠããããŸããVPC ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã§ã¯ãããã©ã«ãã§ã¯äžãïŒEgressïŒã«ãŒã«ã§ 0.0.0.0/0 ã«å¯Ÿããéä¿¡ãèš±å¯ãäžãïŒIngressïŒã«ãŒã«ã§ã¯ 0.0.0.0/0 ããã®éä¿¡ãæåŠããŠããã®ã§ãäžãéä¿¡ãèš±å¯ããã«ã¯æç€ºçã«ã«ãŒã«è¿œå ããå¿
èŠããããŸãã åè : æé»ã®ã«ãŒã« Cloud NAT Cloud NAT ã¯ãã«ãããŒãžã㪠NAT æ©åšã§ããExternal IP ãæã£ãŠããªã VM ã§ããã€ã³ã¿ãŒããããžã®éä¿¡ïŒVM ããéå§ãã€ã³ã¿ãŒããããžå°éããæ¹åã®éä¿¡ïŒãå¯èœã«ãªããŸãã ãã«ãããŒãžã ãšã¯ããã®ãµãŒãã¹ã®åºç€ã Google Cloud ã«ãã£ãŠå®å
šã«ç®¡çãããŠããããšãæå³ããŠããŸããæã
å©çšè
ã¯ãäžåºŠ Cloud NAT ã䜿çšããèšå®ã远å ããã°ãé害察å¿ãããããé©çšããæ§èœç£èŠã»ã¹ã±ãŒãªã³ã°ããªã©ãè¡ãå¿
èŠããããŸãããCloud NAT ã®ããã¯ãšã³ãã¯ä»®æ³åã»åæ£ã¢ãŒããã¯ãã£ã«ãªã£ãŠãããã¹ã±ãŒã©ããªãã£ã»å¯çšæ§ã»ããã©ãŒãã³ã¹ã確ä¿ãããŠããŸãã Cloud NAT ã VPC ãããã¯ãŒã¯ã«è¿œå ããã°ã External IP ãæããªã VM ã§ãã€ã³ã¿ãŒããããžéä¿¡ããããšãã§ããŸããéã«ã€ã³ã¿ãŒãããããéå§ã㊠VM ãžå°éããæ¹åã®éä¿¡ã¯èš±å¯ãããŸãããããã«ããäŸãã°ããããé
ä¿¡ãµãŒãããã®ãã¡ã€ã«ããŠã³ããŒãããã€ã³ã¿ãŒãããäžã®ãœãŒã¹ã³ãŒãã¬ããžããªããã®ãœãŒã¹ã³ãŒãååŸããSaaS ãµãŒãã¹ã® HTTP API åŒã³åºãããªã©ãã»ãã¥ã¢ã«å¯èœã«ãªããŸãã 以äžã®æ¡ä»¶ã å
šãŠ æºãããšãVM 㯠Cloud NAT ãå©çšããŠã€ã³ã¿ãŒããããžåºãŠããããšãã§ããŸãã VM ã®æå±ãããµããããã Cloud NAT ãå©çšããããçŽä»ããããŠãã VM ã« External IPïŒå€éš IPïŒã¢ãã¬ã¹ãå²ãæ¯ãããŠããªã VPC ã®ã«ãŒãã«ãŠ 0.0.0.0/0 ã®ãã¯ã¹ãããããããã©ã«ãã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ã«ãªã£ãŠãã ãã¡ã€ã¢ãŠã©ãŒã«ã®äžãïŒEgressïŒã«ãŒã«ã§éä¿¡ãèš±å¯ãããŠãã Cloud NAT ã¯ãã«ãããŒãžãã§ããããå€ãã®å Žåã§ç°¡åã«å©çšã§ããŸãããæ§ã
ãªæ©èœã仿§ãæã£ãŠããŸãã詳现ã¯ä»¥äžã®å
¬åŒããã¥ã¡ã³ãããåç
§ãã ããã åè : Cloud NAT ã®æŠèŠ ã€ã³ã¿ãŒããããšã®éä¿¡ãé²ãæ¹æ³ ã»ãã¥ãªãã£äžã®çç±ã§ VPC å
ã® VM ãšã€ã³ã¿ãŒãããã®æ¥ç¶ããããªãããã«ããã«ã¯ã以äžã®ãããªæ¹æ³ããããŸãã VPC ã®ã«ãŒããç·šéããŠããã©ã«ãã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãžã®ã«ãŒããåé€ãã VM ã« External IP ã¢ãã¬ã¹ãæãããªã ãã¡ã€ã¢ãŠã©ãŒã«ïŒCloud NGFWïŒã§éä¿¡ãå¶éãã 1. ã®ããã«ã«ãŒããåé€ããŠããŸãã°ã VPC å
ã®å
šãŠã® VM ã¯ã€ã³ã¿ãŒããããšéä¿¡ã§ããªããªããŸãã 圱é¿ç¯å²ã¯ VPC å
šäœ ãšãªãã®ã§ãããåäž VPC å
ã«ã€ã³ã¿ãŒããããšã®éä¿¡èŠä»¶ã®ç°ãªãè€æ°ã® VM ãããå Žåã¯ããã®æ¹æ³ã¯åããŸãããAWS ãäŸã«åããšããããªãã¯ãµãããããããã©ã€ããŒããµãããããã®ããã«éä¿¡èŠä»¶ããšã«ãããã¯ãŒã¯ã»ã°ã¡ã³ããåããã±ãŒã¹ããããŸããã Google Cloud ã«ãããŠã¯ããã¯å®çŸã§ããŸãããå®çŸããå Žå㯠VPC ããšåå²ããããšã«ãªããŸãã 2. ã¯èªãã§åã®ããšãã VM ã« External IP ã¢ãã¬ã¹ãæãããªãããšã§ãã«ãŒãèšå®çã«é¢ä¿ãªãéä¿¡ã§ããªããããŠããŸãæ¹æ³ã§ãããã ãåè¿°ã® Cloud NAT ãèšå®ãããŠãããšãExternal IP ãæããªã VM ã¯ã€ã³ã¿ãŒããããž åºãŠãã ããšã¯å¯èœãšãªã£ãŠããŸããŸãããããé²ãã«ã¯ 3. ã宿œããŸãã åè : å€éš IP ã¢ãã¬ã¹ã䜿çšããªãæ¹æ³ 3. 㯠VPC ã®ãã¡ã€ã¢ãŠã©ãŒã«ã§ãããã¯ããæ¹æ³ã§ããåè¿°ã®ããã« VPC ãåå²ãããšç®¡çé¢ã§ç
©éã«ãªãå ŽåããããããGoogle Cloud ã®å Žåã¯ã ãã¡ã€ã¢ãŠã©ãŒã«ã§ã€ã³ã¿ãŒããããšã®éä¿¡å¯åŠãå¶åŸ¡ããããšãå€ã ãšãããŸãããªãåè¿°ã®éããã¡ã€ã¢ãŠã©ãŒã«ã® äžãïŒIngressïŒã¯ããã©ã«ãã§ æåŠïŒDenyïŒã®ãããã€ã³ã¿ãŒããã ãã VM ãžã®éä¿¡ã¯æç€ºçã«èš±å¯ããªããã°å°éããŸãããéã«äžãéä¿¡ã¯ããã©ã«ãã§èš±å¯ïŒAllowïŒã®ãããæç€ºçã«æåŠã«ãŒã«ã远å ããªããã°ãVM ããå€éšæ¹åãžã®éä¿¡ã¯å¯èœãªãŸãŸã§ãã ãã¬ãã¢ã ãã£ã¢ãšã¹ã¿ã³ããŒããã£ã¢ VPC ãããã¯ãŒã¯å
ã® VM ãšã€ã³ã¿ãŒãããéã®éä¿¡ã§ã¯ãæéã®ç°ãªã ãããã¯ãŒã¯ãã£ã¢ ããVM ãããŒããã©ã³ãµãŒããšã«éžæããããšãã§ããŸãã ãã¬ãã¢ã ãã£ã¢ ãš ã¹ã¿ã³ããŒããã£ã¢ ã®2çš®é¡ããããåè
㯠Google ã®æã€é«å質ãªå°çšããã¯ããŒã³ãããã¯ãŒã¯ãå©çšããåŸè
ã¯ã³ã¹ãããã©ãŒãã³ã¹ã«åªããéåžžã®ã€ã³ã¿ãŒããããå©çšãããã£ã¢ã§ããããã©ã«ãã§ã¯åè
ãå©çšãããããã«ãªã£ãŠããããŸã Google ã®æšå¥šã¯åè
ã§ãã åè
ã¯é«å質ã»é«ããã©ãŒãã³ã¹ã§ãããç¹ã«ã°ããŒãã«ã«å©çšãããã·ã¹ãã ã§ã®å©çšãæšå¥šãããŠããŸããäžæ¹ã§åŸè
ã¯ãåäžã®å°åã§å©çšãããã·ã¹ãã ã§ããã€ã³ã¹ãæé©åãæãŸããå Žåã«å©çšãããŸãã åè : Network Service Tiers ã®æŠèŠ åè¿°ã®ãšãããæé㯠äžãæ¹åã®ãã±ããã®ããŒã¿é ã«å¿ããŠèª²éãããŸããå
·äœçãªæéå䟡ã¯ã以äžã®ããŒãžãã確èªã§ããŸãã åè : Network Service Tiers ã®æé Google Cloud ãµãŒãã¹ãžã®ãã©ã€ããŒããµãŒãã¹ã¢ã¯ã»ã¹ ããã€ãã® Google Cloud ãµãŒãã¹ã¯ããªãœãŒã¹é
眮ã«å°çšã® VPC ãããã¯ãŒã¯ãšãµããããã䜿ããŸããäŸãã°ä»¥äžã®ãããªãµãŒãã¹ã§ãã Cloud SQL Memorystore Cloud Build Vertex AI äžèšã®ãµãŒãã¹ã§ã¯ããªãœãŒã¹ãäœæãããš ãµãŒãã¹ãããã¥ãŒãµãŒã®ãããã¯ãŒã¯ ãšåŒã°ããå°çšã® VPC ãããã¯ãŒã¯ã«é
眮ãããŸããäŸãšã㊠AWS ã® Amazon RDS ã§ã¯ãŠãŒã¶ãŒã® VPCã»ãµããããå
ã«ã€ã³ã¹ã¿ã³ã¹ãé
眮ãããŸãããGoogle Cloud ã® Cloud SQL ã§ã¯ããŠãŒã¶ãŒã® VPC ã§ã¯ãªã ãGoogle ã管çããå°çš VPC ãããã¯ãŒã¯ã®äžã«ã€ã³ã¹ã¿ã³ã¹ãé
眮ãããŸãã ãŠãŒã¶ãŒã® VPC ãããã¯ãŒã¯ãšãµãŒãã¹ãããã¥ãŒãµãŒã®ãããã¯ãŒã¯ã¯ VPC ãããã¯ãŒã¯ãã¢ãªã³ã°ã§æ¥ç¶ ããããŠãŒã¶ãŒã® VM ããã¯ãã¢ãªã³ã°çµç±ã§ãCloud SQL ã€ã³ã¹ã¿ã³ã¹çã«å°éããŸãã ãã®ãµãŒãã¹ãããã¥ãŒãµãŒã®ãããã¯ãŒã¯ã® IP ã¬ã³ãžïŒCIDRïŒã¯ããŠãŒã¶ãŒåŽã§æå®ã§ããŸãããã®éã«ã¯ããŠãŒã¶ãŒã® VPC ãããã¯ãŒã¯ãšéè€ããªã CIDR ãæå®ããå¿
èŠããããŸãã äžåºŠãµãŒãã¹ãããã¥ãŒãµãŒã®ãããã¯ãŒã¯ãäœæããã°ããã®äžã«è€æ°ã® Cloud SQL ã€ã³ã¹ã¿ã³ã¹ã Memorystore ã€ã³ã¹ã¿ã³ã¹ãé
眮ããããšãå¯èœã§ãã ãªãããã®äžé£ã®ä»çµã¿ã¯ ãã©ã€ããŒããµãŒãã¹ã¢ã¯ã»ã¹ ãšåŒã°ããŸãã åè : ãã©ã€ããŒã ãµãŒãã¹ ã¢ã¯ã»ã¹ ãã©ã€ããŒããµãŒãã¹ãžã®ã¢ã¯ã»ã¹ éçš VPC Flow Logs VPC Flow Logs ïŒVPC ãããŒãã°ïŒãšã¯ãVM ã«ãã£ãŠéåä¿¡ããããã©ãã£ãã¯èšé²ã®ãµã³ãã«ããã°ãšããŠä¿åããä»çµã¿ã§ããå©çšç®çãšããŠã¯ä»¥äžãæããããŸãã ãããã¯ãŒã¯ã¢ãã¿ãªã³ã° ãã©ãã«ã·ã¥ãŒãã£ã³ã° è²»çšæé©å ã»ãã¥ãªãã£ïŒãã©ã¬ã³ãžãã¯ããªã¢ã«ã¿ã€ã åæïŒ VPC Flow Logs ã§ã¯å
šãŠã®ãã©ãã£ãã¯ãèšé²å¯Ÿè±¡ãšãªãããã§ã¯ãªããäºåã«æå®ãããµã³ããªã³ã°ã¬ãŒãïŒ%æå®ïŒã«åºã¥ããå²åã®ãã©ãã£ãã¯ã®ãã°ã ããèšé²ãããŸãããŸããç¹å®ã® VM ã®ã¿ããç¹å®éä¿¡å
IP ã®ãã©ãã£ãã¯ã®ã¿ããšãã£ãããã«èšé²ãã察象ãã©ãã£ãã¯ããã£ã«ã¿ããããšãã§ããŸãã ãªã VPC Flow Logs ã¯ãVPC ã®ä»®æ³ååºç€ã«é«åºŠã«çµã¿èŸŒãŸããŠããããšãããæå¹åããŠãããã©ãŒãã³ã¹é
å»¶çã¯çºçããŸããã åè : VPC Flow Logs VPC Flow Logs ã«ã¯ãããã 5 ã¿ãã«ïŒéä¿¡å
IP ã¢ãã¬ã¹ãéä¿¡å
ããŒãçªå·ãéä¿¡å
IP ã¢ãã¬ã¹ãéä¿¡å
ããŒãçªå·ããããã³ã«çªå·) ãå«ãŸããä»ãæå»ããã€ãæ°ã TCP ã® ACK ã®ã¬ã€ãã³ã·ãªã©ãå«ãŸããŸããVPC Flow Logs ã§ã¯ãããã£ã ãã±ããã®é¢é£æ
å ± ãèšé²ãããã®ã§ããã ãã±ãããã®ãã®ããã£ããã£ãããã®ã§ã¯ãããŸãã ã ãªãã·ã§ã³ã§ ã¡ã¿ããŒã¿ã®èšé² ãæå¹åãããšããã°ã®ãµã€ãºã¯å€§ãããªããŸãããéä¿¡ãè¡ã£ã VM ã VPC ãããã¯ãŒã¯ã«é¢ããè¿œå æ
å ±ãèšé²ãããããã«ãªããŸãã åè : VPC Flow Logs ã®ã¬ã³ãŒãã«ã€ã㊠VPC ãããŒãã°ã®æå¹åæç¡ãããµã³ããªã³ã°ã¬ãŒãçã®èšå®ã¯ã ãµããããããš ã«èšå®ã§ããŸãããµããããäœææã«æ±ºå®ããã»ããããšããã§ã倿Žå¯èœã§ãã åè : VPC Flow Logs ãæ§æãã åœæ©èœã§èšé²ããããã°ã¯ãããã©ã«ãã§ã¯ Cloud Logging ã®ãã°ãã±ããã«ä¿ç®¡ãããŸããCloud Logging ã®è©³çްãæéã«ã€ããŠã¯ä»¥äžããåç
§ãã ããã blog.g-gen.co.jp ããã©ã«ãã®ãã°ãã±ããã§ããã°ããã°ã¯30æ¥éä¿åããããã®ç¯å²å
ã§ããã°ä¿åæéã¯ç¡æã§ãããã ãä¿åæéãšã¯å¥ã«ãåã蟌ãã ãã°ã®ãµã€ãºã«å¿ããæéãçºçããŸãã2025幎3æçŸåšã§ã¯ $0.50/GiB/æã§ããããã¯ãCloud Logging ã® Vended Network Logs ã¹ãã¬ãŒãžæéïŒ$0.25/GiB/æïŒãšãVPC ã®ãããã¯ãŒã¯ãã¬ã¡ããªãŒæéïŒ$0.25/GiB/æïŒã䜵ããéé¡ã§ãããããã¯ãŒã¯ãã¬ã¡ããªãŒæéã¯ãåã蟌ã¿éã«å¿ããŠåŸã
ã«å䟡ãå®ããªããŸãã詳现ã¯å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : Cloud Logging ã®æéæŠèŠ åè : ãããã¯ãŒãã³ã°ã®ãã¹ãŠã®æéäœç³» ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®ãã° ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®ãã° ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã®ã«ãŒã«ã®ç£æ»ãæ€èšŒãåæã®ããã«çšãããã°ã§ãã以äžã®ãããªç®çã§å©çšãããŸãã æå³éãã«ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãèš±å¯/æåŠããŠãããç¢ºèª ç¹å®ã®ã«ãŒã«ãäœå°ã® VM ã«åœ±é¿ãäžããŠãããèª¿æ» ãã©ãã«æã«éä¿¡ã«ãã¡ã€ã¢ãŠã©ãŒã«ã圱é¿ããŠãããã®ç¢ºèª ç¹åŸŽãšããŠããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®ãã®ã³ã°ã¯ãã¡ã€ã¢ãŠã©ãŒã«ã® ã«ãŒã«ããš ã«èšå®ããŸããVPC ããšïŒã«ãŒã«ããŒãã«ããšïŒã§ã¯ãããŸããã1è¡ã®ã«ãŒã«ããšã«ããã®ã³ã°ã®æå¹ãç¡å¹ããšãã¡ã¿ããŒã¿ãå«ããåŠãããèšå®ããŸãããã°ã¯ãVPC Flow Logs ãšåæ§ãCloud Logging ã«åºåãããŸãã ãªãåœãã®ã³ã°æ©èœã¯ VPC ãã¡ã€ã¢ãŠã©ãŒã«ãšãã¡ã€ã¢ãŠã©ãŒã«ããªã·ãŒã®äž¡æ¹ã§äœ¿çšå¯èœã§ãã åè : ãã¡ã€ã¢ãŠã©ãŒã« ã«ãŒã«ã®ãã®ã³ã° ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®ãã°ã«ã¯ã以äžã®ãããªå
容ãèšèŒãããŸãã æ¥æ 5ã¿ãã«ïŒéä¿¡å
IP ã¢ãã¬ã¹ãéä¿¡å
ããŒãçªå·ãéä¿¡å
IP ã¢ãã¬ã¹ãéä¿¡å
ããŒãçªå·ããããã³ã«çªå·ïŒ èš±å¯ããããæåŠãããã 該åœãããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®è©³çް ãŸãã ã¡ã¿ããŒã¿ ã®èšé²ãæå¹åãããšãVPC ãããã¯ãŒã¯ã VM ã®è©³çްãªã©è¿œå æ
å ±ãèšé²ãããŸãã åè : ãã¡ã€ã¢ãŠã©ãŒã« ãã°åœ¢åŒ VPC ãããã¯ãŒã¯ã®ç£æ»ãã° ãããã¯ãŒã¯é¢é£èšå®ãäœæã倿Žãåé€ãããå±¥æŽã¯ãç£æ»ãã°ãšããŠèªåçã«èšé²ãããããã«ãªã£ãŠããŸããèšé²ãç¡å¹åããããšã¯ã§ããŸããã ãã㯠Cloud Audit Logs ã®æ©èœã§å®çŸãããŠãããã 誰ãããã€ãã©ãã§ãäœãããã ããèšé²ãããŸããCloud Audit Logs ã«ã€ããŠã¯ã以äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp èšå®ã®äœæã倿Žãåé€ãªã©ãæŽæ°ç³» API ãªã¯ãšã¹ãã«é¢ãããã°ã¯ã 管çã¢ã¯ãã£ããã£ç£æ»ãã° ãšåŒã°ããŸããåè¿°ã® Cloud Audit Logs ã®èšäºã«ããããã«ãããã©ã«ãã§ã¯ãã°ã¯400æ¥éä¿åãããŸããããã©ã«ãã§æå¹åãããŠãã管çã¢ã¯ãã£ããã£ç£æ»ãã°ã«ã€ããŠã¯ãæéã¯çºçããŸããã äžæ¹ã§ãèšå®ã®èªã¿åããäžèŠ§è¡šç€ºãªã©ãèªåç³» API ãªã¯ãšã¹ãã«é¢ããå±¥æŽã¯ã ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã° ãšåŒã°ãããã°ãµã€ãºãèšå€§ã«ãªããã¡ãªããšããããã©ã«ãã§ã¯ç¡å¹åãããŠããŸããåè¿°ã®èšäºã«ããéãããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ã¯æåã®ãããæå¹åã®éã¯æéãæèããå¿
èŠããããŸãã åè : Virtual Private CloudïŒVPCïŒã®ç£æ»ãã®ã³ã° æé æŠèŠ VPC ã®å©çšæéã¯ã以äžã®èŠçŽ ã§æ§æãããŸãã äžãïŒEgressïŒãã©ãã£ãã¯ã®ããŒã¿é 確ä¿ãã External IPïŒå€éš IPïŒã¢ãã¬ã¹ã®å©çšæé ãªããVPC ãäœæããã®ã¿ã§ããã°ç¡åã§ãã åè : ãããã¯ãŒãã³ã°ã®ãã¹ãŠã®æéäœç³» ãã©ãã£ãã¯éãžã®èª²é 1. ã¯ãVPC ãããã¯ãŒã¯å
ãéããã©ãã£ãã¯ã®éã«å¿ãã課éã§ããç¹åŸŽçãªã®ã¯ããã±ããã®éä¿¡æ¹åã«ãã£ãŠèª²éã®æç¡ãç°ãªããŸããVPC ãããã¯ãŒã¯ãäžåŽ / Internal åŽãšã¿ãªããã€ã³ã¿ãŒãããããªã³ãã¬ãã¹åŽãäžåŽ / External åŽãšãããšãã«ãäžãïŒIngressïŒãã±ããã¯èª²é ãããŸãã ãå察ã«ãäžãïŒEgressïŒãã±ãã㯠課éãããŸã ã äŸãã° VPC ãããã¯ãŒã¯å
ã® VM ã« Web ãµãŒããŒãé
眮ããæããŠãŒã¶ãŒããã® HTTP ãªã¯ãšã¹ãããããŒã¿ã®ã¢ããããŒãã«ã¯èª²éãããŸãããå察ã«ãŠãŒã¶ãŒãããŒã¿ãããŠã³ããŒãããéã«ã¯ãããŒã¿éã«å¿ããŠèª²éãããŸããããã¯ä»ã®å€ãã®ãããªãã¯ã¯ã©ãŠãã®ãããã¯ãŒã¯èª²éäœç³»ãšé¡äŒŒããŠããŸãã äŸãšããŠã2025幎3æçŸåšãæ±äº¬ãªãŒãžã§ã³ããæ¥æ¬åœå
ãžã®ã€ã³ã¿ãŒããããžã®éä¿¡ã¯ãGiB ããã$0.12ãã«ã§ãïŒãã¬ãã¢ã ãã£ã¢ã®å ŽåïŒãæã«100GiBã®å€åãéä¿¡ãçºçãããšããŠãæŠãï¿¥1,800åçšåºŠã®èª²éãçºçããããšã«ãªããŸãïŒ1ãã«150åæç®ïŒããªããã®æéã¯éä¿¡å
ã®å°åããæéã®ç·ããŒã¿éã«ãã£ãŠãå€åããŸãã ãŸããã€ã³ã¿ãŒãããã«å¯Ÿããéä¿¡ã ãã§ã¯ãªããVPC å
ã® VM å士ã®éä¿¡ã§ãã£ãŠãã ç°ãªããŸãŒã³ãç°ãªããªãŒãžã§ã³å士 ã®éä¿¡ã«ã¯èª²éã çºçããŸã ããã¡ãããåäžãªãŒãžã§ã³å
ã®ç°ãŸãŒã³ãšã®éä¿¡ãªã®ãããªãŒãžã§ã³éã§ããã°ã©ã®ãªãŒãžã§ã³ãžã®éä¿¡ãªã®ããã«ãã£ãŠæéãå€åããŸãã åè : Google Cloud å
ã® VM éããŒã¿è»¢éã®æé IP ã¢ãã¬ã¹ãžã®èª²é 2. ã¯ãVMïŒCompute Engine ã®ä»®æ³ãã·ã³ïŒã«ä»äžããããã® IP ã¢ãã¬ã¹ã«å¯Ÿãã課éã§ããInternal IP ã¢ãã¬ã¹ïŒå
éš IP ã¢ãã¬ã¹ïŒã«ã¯èª²é ãããŸãã ããã€ã³ã¿ãŒããããšã®éä¿¡ã«å¿
èŠãª External IP ã¢ãã¬ã¹ïŒå€éš IP ã¢ãã¬ã¹ïŒã«ã¯å²ãåœãŠæéã«å¿ãã課éãçºçããŸããExternal IP ã¢ãã¬ã¹ã«ã¯ãVM ã忢ãããšè§£æŸãããŠããŸãäžæç㪠ãšãã§ã¡ã©ã« IP ã¢ãã¬ã¹ ãšãåºå®çã«ç¢ºä¿ã§ãã éç IP ã¢ãã¬ã¹ ããããŸãããã©ã¡ããåæ§ã«èª²éãããŸãã ãã®ä»æ©èœãžã®èª²é Private Service ConnectãPacket Mirroring ãªã©ãä»ã®ããŸããŸãª VPC æ©èœã«é¢ãã課éããå¿
èŠã«å¿ããŠçºçããŸãã 詳现ã¯å
¬åŒã®æéããŒãžããåç
§ãã ããã åè : ãããã¯ãŒãã³ã°ã®ãã¹ãŠã®æéäœç³» å¿çšç·šãžã®ãªã³ã¯ åœèšäºã¯ VPC ã®åºæ¬æ©èœã«çµã£ãåºæ¬ç·šã§ãããå¿çšç·šã®èšäºã§ã¯ä»¥äžã®æ©èœãæ±ã£ãŠããŸãã®ã§ããåç
§ãã ããã VPC éã»ãµããããéã®éä¿¡ VPC ãããã¯ãŒã¯ãã¢ãªã³ã° Cloud VPN ã«ããæšç§»çãªéä¿¡ïŒã«ã¹ã¿ã ã«ãŒãåºå ±ïŒ å
±æ VPC ãµãŒããŒã¬ã¹ VPC ã¢ã¯ã»ã¹ éå®å
¬éã® Google ã¢ã¯ã»ã¹ / Private Service Connect Packet Mirroring blog.g-gen.co.jp ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãX (æ§ Twitter) ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-gen ã®ææã§ããChromebookïŒChrome OSïŒãã Cloud IAP ã®ãã³ããªã³ã°æ©èœã䜿ãã Compute Engine ã® Windows Server ãžãªã¢ãŒããã¹ã¯ãããïŒRDPïŒããæ¹æ³ã«ã€ããŠç޹ä»ããŸãã åæç¥è åæäœæ¥ 1. Linux éçºç°å¢ã®æå¹å 2. gcloud ã³ãã³ãã®ã€ã³ã¹ããŒã«ã»åæå ãã³ãã«ç¢ºç«ãšRDP 1. Linux ã³ã³ããã® IP ã¢ãã¬ã¹ãç¢ºèª 2. 倿°èšå®ãš IAP ãã³ãã«ç¢ºç« 3. ãªã¢ãŒããã¹ã¯ãããæ¥ç¶ ãã©ãã«ã·ã¥ãŒãã£ã³ã° åæç¥è Cloud IAP ïŒCloud Identity-Aware ProxyïŒã¯ãGoogle CloudïŒæ§ç§° GCPïŒãæäŸãããã«ãããŒãžãã®ãªããŒã¹ãããã·ã§ããIAP ã䜿ããšãCompute Engine VM ã«èžã¿å°ãµãŒããŒäžèŠã§ SSH ã RDP ã䜿ã£ãŠãã°ã€ã³ããããšãã§ããŸãã Cloud IAP ã«ãã VM ãžã®æ¥ç¶æ¹æ³èªäœã®è§£èª¬ã«ã€ããŠã¯ã以äžã®èšäºã§è§£èª¬ããŠããŸãã®ã§ãåç
§ãã ããã blog.g-gen.co.jp åæäœæ¥ 1. Linux éçºç°å¢ã®æå¹å æ¬æé ã§ã¯ Chromebook ã®ããããããŒåãæ©èœã Linux éçºç°å¢ãã䜿ããŸãã ãã®æ©èœãçšãããš Chromebook å
ã« Linux (Debian) ã®ã³ã³ãããèµ·åããã¿ãŒããã«ã§æäœããããšãã§ããŸãã ãŸã Linux ç°å¢ãæå¹åããŠããªãå Žå㯠èšå® > 詳现èšå® > ããããã㌠> Linux éçºç°å¢ ããåæ©èœãæå¹åããŸãã èšå®ç»é¢ (ãã®ã¹ã¯ãªãŒã³ã·ã§ããã§ã¯æ¢ã«æå¹åæžã¿) 2. gcloud ã³ãã³ãã®ã€ã³ã¹ããŒã«ã»åæå â»ãã®æé ã¯éåžžã® gcloud ã³ãã³ããšåãã§ãããŸãã宿œãå¿
èŠãªã®ã¯å§ãã®1åã ãã§ãã ããã¥ã¡ã³ãã Cloud SDK ã®ã€ã³ã¹ããŒã« ãã«åŸã Linux ç°å¢ã« gcloud ã³ãã³ããã€ã³ã¹ããŒã«ããŸãã äžèšãªã³ã¯å
ã® Debian/Ubuntu ã®æé ã«åŸã£ãŠãã ããã ã€ã³ã¹ããŒã«ã§ããã gcloud init ã³ãã³ãã§åæåããŸãã 察象ã®ã€ã³ã¹ã¿ã³ã¹ããããããžã§ã¯ããæå®ããŸãããã ãã³ãã«ç¢ºç«ãšRDP 1. Linux ã³ã³ããã® IP ã¢ãã¬ã¹ãç¢ºèª ä»¥äžã®ã³ãã³ãã§èªåã® Chromebook äžã® Linux ã³ã³ããã®å
éš IP ã¢ãã¬ã¹ã確èªããŸãã ip -4 addr åºåã¯ä»¥äžã®äŸã®ããã«ãªããŸãã 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000 inet 127.0.0.1/8 scope host lo valid_lft forever preferred_lft forever 5: eth0@if6: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000 link-netnsid 0 inet 100.115.92.206/28 brd 100.115.92.207 scope global eth0 valid_lft forever preferred_lft forever äžãã2è¡ç®ã eth0 ã® inet 100.115.92.206/28 ãšè¡šèšãããŠããéšåã® 100.115.92.206 ã IP ã¢ãã¬ã¹ã«ãªããŸãã 2. 倿°èšå®ãš IAP ãã³ãã«ç¢ºç« 以äžã®ããã« Linux 倿°ãèšå®ããŸããåŸã®ã³ãã³ãã§äœ¿ãããã§ãã <ã«ãã³> ã®äžèº«ã¯ãèªèº«ã®ç°å¢ã®ãã®ãšçœ®ãæããŠãã ããã ZONE=<察象ã€ã³ã¹ã¿ã³ã¹ã®ãŸãŒã³> INSTANCE_NAME=<察象ã€ã³ã¹ã¿ã³ã¹å> IP_ADDR=<å
ã»ã© ip ã³ãã³ãã§èª¿ã¹ãã³ã³ããã® IP ã¢ãã¬ã¹> ãã®åŸä»¥äžã®ã³ãã³ããå®è¡ããŸãã gcloud compute start-iap-tunnel ${INSTANCE_NAME} 3389 --zone=${ZONE} --local-host-port=${IP_ADDR}:13389 ãªã 13389 ã¯ä»»æã®ããŒãçªå·ã§åé¡ãããŸããã Linux ã³ã³ããäžã§äœ¿ãããŠããªããã®ãéžæããŠãã ããã åºåã以äžã®ããã«åºããããã³ãã«ç¢ºç«ãå®äºã§ãã Testing if tunnel connection works. Listening on port [13389]. ãªãã以äžã®ãã㪠warning ãåºãããšããããŸãããéåžžå©çšã§åé¡ã¯ãããŸããã WARNING: To increase the performance of the tunnel, consider installing NumPy. To install NumPy, see: https://numpy.org/install/. After installing NumPy, run the following command to allow gcloud to access external packages: export CLOUDSDK_PYTHON_SITEPACKAGES=1 3. ãªã¢ãŒããã¹ã¯ãããæ¥ç¶ RD Client ã¢ããªçãä»»æã®ãªã¢ãŒããã¹ã¯ãããã¯ã©ã€ã¢ã³ãã§ä»¥äžã®ã¢ãã¬ã¹ã«æ¥ç¶ããŸãã <å
ã»ã© ip ã³ãã³ãã§èª¿ã¹ãã³ã³ããã® IP ã¢ãã¬ã¹>:13389 ããã§ IAP ãšçµãã ãã³ãã«çµç±ã§ Windows Server ãžãªã¢ãŒããã¹ã¯ãããã§ããŸãã ãã©ãã«ã·ã¥ãŒãã£ã³ã° gcloud init ã gcloud compute start-iap-tunnnel ã³ãã³ããå®è¡ããéãããã³ãããæ°å以äžè¿ã£ãŠããªããããªç¶æ
ã«é¥ãããšããããŸãã ãŸã以äžã®ãããªãšã©ãŒã¡ãã»ãŒãžãçŸããããšããããŸãã ERROR: (gcloud.compute.start-iap-tunnel) While checking if a connection can be made: Unexpected error while connecting. Check logs for more details. ããã¯ã³ã³ãããã API ãšã³ããã€ã³ãã«æ¥ç¶ããéã« ipv6 ã§æ¥ç¶ã詊è¡ããŠããããã«èµ·ãã£ãŠããå¯èœæ§ããããŸãã 察åŠãšã㊠Debian ã® ipv6 ãç¡å¹ã«ãããšæ¹åããå ŽåããããŸãã /etc/sysctl.conf ã vim çã§ç·šéãã以äžã®è¡ã远å ããŸãã net.ipv6.conf.eth0.disable_ipv6 = 1 ãã®åŸ sysctl ã³ãã³ããå®è¡ããŸãã sudo sysctl -p 宿œåŸ ip addr ã³ãã³ããæã¡ã eth0 ãã ipv6 ã¢ãã¬ã¹ã®è¡šèšãç¡ããªã£ãŠããã°å¯ŸåŠå®äºã§ãã ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãX (æ§ Twitter) ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-gen ã®ææã§ãããã€ãŠå
¬éãããŠãã Google CloudïŒGCPïŒèªå®è©Šéšã§ãã Professional Google Workspace Administrator 詊éšïŒæ§ç§° Professional Collaboration EngineerïŒã®åéšã«åããŠã圹ç«ã€å
容ãã玹ä»ããŸãã â» åœè©Šéšã¯2025幎1æã« 廿¢ ãããŸãããããããªããåœèšäºã¯ Google Workspace ã®è£œåç¥èã®ååŸã«åœ¹ç«ãŠãŠãããæå³ã蟌ããŠãå
¬éã®ãŸãŸãšãããŠããã ããŸãã çŸåšã¯åŸç¶è³æ Œã§ãã Associate Google Workspace Administrator 詊éšãååšããŠããŸãã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp ã¯ããã« Professional Google Workspace Administrator ãšã¯ é£æåºŠ åŠç¿æ¹æ³ 泚æç¹ã»åºé¡åŸå ãã£ã¬ã¯ããªèšèšã»ç®¡ç çµç¹éšéèšèš ã«ã¹ã¿ã ãã£ã¬ã¯ã㪠èšå®ã°ã«ãŒã ããŒã¿ãªãŒãžã§ã³ ãã¡ã€ã³åïŒã»ã«ã³ããªãã¡ã€ã³ïŒ ã¢ã«ãŠã³ãä¿è· ã³ã³ããã¹ãã¢ãŠã§ã¢ã¢ã¯ã»ã¹ ã³ã³ãã©ã€ã¢ã³ã¹ïŒGoogle VaultïŒ Google Vault ã®åºæ¬ 泚æç¹ Gmail ã¡ãŒã«ã®ã»ãã¥ãªã㣠迷æã¡ãŒã« ã«ã¬ã³ã㌠äŒè°å®€ãšãªãœãŒã¹ Google Meet é話å質 ãã©ã€ã å
±æãã©ã€ã å
±æãã©ã€ãã«ãããæš©é ã°ã«ãŒã å
±åãã¬ã€ ãã£ã¬ã¯ããªç®¡ç ã¢ã«ãŠã³ãã®äžæåæ¢ãšåé€ ããŒã¿ã®ãšã¯ã¹ããŒã ããã°ã©ããã«ãªãã£ã¬ã¯ããªç®¡ç Google Cloud Directory Sync (GDCS) ããã€ã¹ç®¡ç Workspace ã§å¯èœãªç®¡ç iOS ã¯ããã« Professional Google Workspace Administrator ãšã¯ Professional Google Workspace Administrator 詊éšã¯ã Google ã®æäŸããã°ã«ãŒããŠã§ã¢ã§ãã Google Workspace ã®å°éç¥èãåã詊éšã§ãã äŒæ¥ IT ã®ç®¡çè
ãå°å
¥æ
åœè
ã Google Workspace ã«é¢ããå°éç¥èãåŸãããã«æçšãªè©Šéšãšãªã£ãŠããŸãã ãªããåœè©Šéšã¯ãã€ãŠ Professional Collaboration Engineer ãšåŒç§°ãããŠããŸããã2022幎4æ29æ¥ã«æ¹ç§°ãã Professional Google Workspace Administrator ãšãªããŸãããæ¢ã«è©Šéšã«åæ ŒããŠãã人ã®ä¿æè³æ Œåãèªåçã«æ¹ç§°ãããŸãã åœè©Šéšã§ã¯ Google Workspace ã®ç¥èã®ã¿ãªãããäŒæ¥ IT ã«é¢ããå¹
åºãç¥èãåããããããæ
å ±ã·ã¹ãã éšéã®ãšã³ãžãã¢ã«ãšã£ãŠã¯ç¥èŠãæã£ãŠããããšã瀺ãè¯ã客芳ææãšãªããŸãã åœè©Šéšã¯è±èªã𿥿¬èªã§åéšããããšãã§ããŸããå顿°ã¯ 50 åã§ãè©Šéšæé㯠120 åã§ãã åè : Professional Google Workspace 管çè
é£æåºŠ åœè©Šéšã®é£æåºŠã¯ æ¯èŒçé«ã ãšèšããŸãã åæç¥èãšããŠã IPA ã®åºæ¬æ
å ±åŠçæè¡è
çšåºŠã® IT åºç€ç¥èã«å ãã Active Directory ãªã©ã®ãã£ã¬ã¯ããªãµãŒãã¹ã«é¢ããåºç€ç¥èããE ã¡ãŒã«åºç€ã®åºç€ç¥èãã·ã³ã°ã«ãµã€ã³ãªã³ãSAMLãOAuthãOpenID Connect ãªã©ãèªèšŒã»èªå¯ã ID 飿ºã«é¢ããåºç€ç¥èããããšè¯ãã§ãããã ãããã®äžè¬çãªç¥èãããæ¹ããå
¬åŒ 詊éšã¬ã€ã ãåœèšäºãåèã« Google ãµãŒãã¹ã®ç¥èãã€ããŠããã°ãåæ Œã§ããã§ããããGoogle Workspace 管çã³ã³ãœãŒã«ã®çްããå©çšçµéšãç¡ããšåçãé£ããåé¡ããããããé«é£æåºŠãšããŸããã å顿° 50 åã«å¯ŸããŠè©Šéšæé㯠120 åã®ãã 1 åããã 2.4 åãšããæ°åã¯å³ããããã«ãèŠãããããããŸããããèœã¡çããŠè§£ãã°æéã«ã¯äœè£ããã詊éšã§ãã åŠç¿æ¹æ³ ããããã®åŠç¿æ¹æ³ã¯ã以äžã§ãã äžè¬ç㪠IT ç¥èãšããŠä»¥äžã®ããŒã¯ãŒããçè§£ãã ã·ã³ã°ã«ãµã€ã³ãªã³ (SSO) Active Directory SAML OAuth, OpenID Connect (OIDC) E ã¡ãŒã«ã«é¢ããäžè¬çãªç¥è (SPF/DKIM ãªã©ã®éä¿¡ãã¡ã€ã³èªèšŒã«é¢ããç¥èå«ã) å®éã« Google Workspace ã®åãµãŒãã¹ãšç®¡çç»é¢ã«è§Šã 管çç»é¢ãããçšåºŠèªç±ã«è§Šããã®ãçæ³ èªç±ã«å€æŽã§ããªãç°å¢ã®å Žåã¯ãé²èŠ§æš©éã ãã§ãæã«å
¥ããåçš®èšå®ç»é¢ã確èªãã 詊éšã¬ã€ã ãèªãã§è©Šéšç¯å²ã確èªãã 詊éšç¯å²ã®äžã§çè§£ã§ããªãå
容ãç¥ããªãåèªãæœ°ã æš¡æ¬è©Šéš ãåéšããåãããªãã£ãç¯å²ãã«ããŒå匷ãã æåŸã«ãåœèšäºãèªãã§ç¥ããªãç¯å²ã朰ããŠãã æ³šæç¹ã»åºé¡åŸå åœè©Šéšã®æ³šæç¹ãšããŠä»¥äžã®ãããªãã®ããããŸãã æ¥æ¬èªç詊éšã¯ãè±èªç詊éšã翻蚳ãããã®ã§ãã®ã§ãè¥å¹²ã®éåæãæããæç« ããããŸããç¹ã« Google Workspace ããã¥ã¡ã³ããã³ã³ãœãŒã«ã®æ¥æ¬èªèš³ãšã詊éšã®æ¥æ¬èªèš³ãéãå ŽåããããŸããåæãæ³åããŠèªãå¿
èŠãåºãŠããŸã 管çã³ã³ãœãŒã«ã«ããã现ããæäœïŒèšå®ç®æïŒãåãããå ŽåããããŸã åºé¡åŸåã¯ãåºæ¬çã«ã¯è©Šéšã¬ã€ãã«æ²¿ããã®ã«ãªããŸãããåœèšäºã§ã¯ãã詳现ã«èšèŒããŸãã®ã§ãåŠç¿ã®åèã«ããŠãã ããã åœèšäºã§ã¯ãã以éã詊éšã®åºé¡åŸåããžã£ã³ã«ããšã«æç€ºããŸãã ãã£ã¬ã¯ããªèšèšã»ç®¡ç çµç¹éšéèšèš çµç¹éšé (Organizational Unit = OU) ã®èšèšã«é¢ããåé¡ãåºãŠããŸãããŠãŒã¹ã±ãŒã¹ãæ³åããªããåŠç¿ãããšè¯ãã§ãããã çµç¹éšéãåããããšã§ã Gmail ãã«ã¬ã³ããŒãªã©ã®èšå®ãéšéããšã«åããããšãã§ããŸãã åè : çµç¹æ§é ã®ä»çµã¿ ã«ã¹ã¿ã ãã£ã¬ã¯ã㪠é£çµ¡å
çã®å
±æç¯å²ã现ãèšå®å¯èœãª ã«ã¹ã¿ã ãã£ã¬ã¯ã㪠æ©èœãææ¡ããŠãããŸãããã ããã©ã«ãã§ã¯ãçµç¹å
ã®ãŠãŒã¶ãŒããä»ã®å
šãŠãŒã¶ãŒã®ãããã£ãŒã«æ
å ±ã確èªã§ããŸãããããã«ã¹ã¿ã ãã£ã¬ã¯ããªãèšå®ãããšãé£çµ¡å
ãæ€çŽ¢ã«è¡šç€ºãããŠãŒã¶ãŒãéå®ããããšãã§ããŸãã 瀟å€ã®ã¡ã³ããŒãçµç¹ã®ãã£ã¬ã¯ããªã«è¿œå ãã瀟å
ã®äžéšã¡ã³ããŒãšã ãã³ã©ãã¬ãŒã·ã§ã³ãããããšããªã©ã«æŽ»çšã§ããŸãã åè : ããŒã ãã°ã«ãŒãã®ãã£ã¬ã¯ããªãã«ã¹ã¿ãã€ãºãã èšå®ã°ã«ãŒã èšå®ã°ã«ãŒã ã®æŠå¿µãåé¡ã§ç¹°ãè¿ãåãããŸããèšå®ã°ã«ãŒããšã¯ã管çç»é¢çã§äœæãã Google ã°ã«ãŒãããåçš®èšå®ã®é©çšã®ããã«äœ¿ãå ŽåãæããŸãã èšå®ã°ã«ãŒãã«é©çšããèšå®ã¯ãçµç¹éšéãžã®èšå®ãããåªå
ãããŸãããŸãããŠãŒã¶ãŒã¯è€æ°ã®ã°ã«ãŒãã«æå±ããããšãã§ããŸãïŒçµç¹éšéã«ã¯1ã€ããæå±ã§ããŸããïŒããã®ä»æ§ãæŒãããŠãããŸãããã åè : èšå®ã°ã«ãŒãã䜿çšããŠãµãŒãã¹ã®èšå®ãã«ã¹ã¿ãã€ãºãã ããŒã¿ãªãŒãžã§ã³ ããŒã¿ãªãŒãžã§ã³ èšå®ã«ãããããŒã¿ã®é
眮å
ã®å°åãæå®ããããšãã§ããŸãã ç¹ã«ãšãŒãããã§ã¯ãæ³çèŠå¶ïŒGDPRïŒã«ãã EU å°åå€ã«å人æ
å ±ãåºãããšãèŠå¶ããŠããããšãæåã§ããããŒã¿ãªãŒãžã§ã³èšå®ã§ã¯ããŒã¿ã®é
眮å
ãšããŠç±³åœãããã¯ãšãŒããããæå®ã§ããŸããèšå®åäœã¯ããã¡ã€ã³å
šäœããçµç¹éšéããèšå®ã°ã«ãŒããã®ããããã®ç²åºŠã§ãããã®èšå®ç²åºŠãå«ããŠæŒãããŠãããŠãã ããã åè : ããŒã¿ ãªãŒãžã§ã³: ããŒã¿ã®å°ççãªä¿ç®¡å Žæãéžæãã ãã¡ã€ã³åïŒã»ã«ã³ããªãã¡ã€ã³ïŒ Google Workspace ã®çµç¹ïŒããã³ãïŒã¯ãã¡ã€ã³åïŒäŸ : example.comïŒãå¿
ã1ã€æã¡ãŸãããã ãã2ã€ç®ä»¥éã®ãã¡ã€ã³åãæãããããšãã§ããŸãããã®ãšãã1ã€ç®ã ãã©ã€ããªãã¡ã€ã³ ãšåŒã³ã2ã€ç®ä»¥éã ã»ã«ã³ããªãã¡ã€ã³ ãšåŒã³ãŸãã ãŠãŒã¶ã«ã¯2ã€ã®ãã¡ã€ã³ã®ã¡ãŒã«ã¢ãã¬ã¹ãæãããããšãã§ããŸãããçæ¹ã ãæãããããšãå¯èœã§ãã åè : ãŠãŒã¶ãŒ ãšã€ãªã¢ã¹ ãã¡ã€ã³ãŸãã¯ã»ã«ã³ã㪠ãã¡ã€ã³ã远å ãã ã¢ã«ãŠã³ãä¿è· ã³ã³ããã¹ãã¢ãŠã§ã¢ã¢ã¯ã»ã¹ ã³ã³ããã¹ãã¢ãŠã§ã¢ã¢ã¯ã»ã¹ ãšããã»ãã¥ãªãã£æ©èœãéèŠã§ãã ã³ã³ããã¹ãã¢ãŠã§ã¢ã¯ãã®åã®éãèæ¯æ
å ±ïŒã³ã³ããã¹ãïŒãèæ
®ããŠïŒã¢ãŠã§ã¢ïŒèªèšŒã»èªå¯ã«çµã¿å
¥ããææ³ã§ãããã®æ©èœãå©çšãããšããŠãŒã¶ãŒã® ã¢ã«ãŠã³ããå Žæãããã€ã¹ã®ã»ãã¥ãªãã£ç¶æ
ïŒäŒç€Ÿç«¯æ«ãã©ããïŒãIP ã¢ãã¬ã¹ãªã©ã®å±æ§ã«åºã¥ããŠã¢ã¯ã»ã¹ã®èš±å¯ãè¡ãããšãã§ããŸãã Enterprise Standard ãªã©ç¹å®ã®ãšãã£ã·ã§ã³ã§ãªããšäœ¿ããªãããšã«ã泚æããŠãã ããã ãŸããã°ã€ã³ã§ãã PC 端æ«ãäŒç€Ÿç«¯æ«ã«éãå Žåã Endpoint Verification ãšããããŒã«ïŒChrome ãã©ãŠã¶ã®æ¡åŒµæ©èœïŒãã€ã³ã¹ããŒã«ããå¿
èŠãããããšããç¹ãæŒãããŠãããŠãã ããã åè : ã³ã³ããã¹ãã¢ãŠã§ã¢ ã¢ã¯ã»ã¹ã®æŠèŠ åè : ã³ã³ããã¹ãã¢ãŠã§ã¢ ã¢ã¯ã»ã¹ã§ããžãã¹ãä¿è·ãã ã³ã³ãã©ã€ã¢ã³ã¹ïŒGoogle VaultïŒ Google Vault ã®åºæ¬ ã³ã³ãã©ã€ã¢ã³ã¹æºæ ã®ããã®éèŠãªããŒã«ãšã㊠Google Vault ããããŸãã Gmail ã®ã¡ãŒã«ããã©ã€ãã®ãã¡ã€ã«ã Google Chat ã®ã¡ãã»ãŒãžãªã©ãé·æä¿ç®¡ããã€ã³ã·ãã³ãçºçæã®äºåŸèª¿æ»ã蚎èšã«æŽ»ããããšãã§ããŸãã Google Vault ã«ã¯ æ¡ä»¶ ãšãã管çåäœããããèšé²ä¿æ (ãªãã£ã²ãŒã·ã§ã³ ããŒã«ã) ãæ€çŽ¢ãæžãåºãã管çã§ããŸããäœãèµ·ããéã«ã¯ãVault ã§æ¡ä»¶ãäœæããæ³åéšéã«æš©éãä»äžããããšããã¢ã¯ã·ã§ã³ãå®çªãšãªããŸãã åè : Google Vault åè : æ¡ä»¶ãäœæã管çãã æ³šæç¹ éèŠãã€ã³ããšããŠãåŸæ¥å¡ãéè·ããéã« Google ã¢ã«ãŠã³ããåé€ããŠããŸããš ãã®ãŠãŒã¶ãŒã® Vault ããŒã¿ããã¹ãŠåé€ ãããŸãã ã¢ã«ãŠã³ããåé€ããã®ã§ã¯ãªã ã¢ãŒã«ã€ããŠãŒã¶ãŒã©ã€ã»ã³ã¹ ã®å©çšãæ€èšããŸãããã åè : é¢è·ããåŸæ¥å¡ãšãã®ããŒã¿ã管çãã Google Vault ã«é¢ããŠåºæ¬æ©èœãçè§£ãããã以äžã® FAQ ãèªãã§ãããŸãããã åè : Google Vault ã«é¢ãããããã質å Gmail ã¡ãŒã«ã®ã»ãã¥ãªã㣠Google Workspace ã®ç®¡çè
ã«ãšã£ãŠãã¡ãŒã«ïŒGmailïŒã®ã¹ãã 察çããã«ãŠã§ã¢å¯Ÿçã¯éèŠã§ãã æ€ç« ãšããæ©èœãæŒãããŠãã ãããGoogle ã«ããæ€æ»ã«æµè§Šããäžå¯©ãªã¡ãŒã«ã¯æ€ç«ã®ããéé¢ããã管çè
ãæ¿èªããªããã°é
ä¿¡ãããŸããã ãŸããæ€ç«ã«ããéé¢ãããã¡ãŒã«ãæ¿èª/äžæ¿èªãããšããã¿ã¹ã¯ã¯ãç¹æš©ç®¡çè
ããã¹ãŠå®æœããªããšããå¥ã®äººã«å§ä»»ããããšãã§ããŸãããã®ãšãã¯æå°æš©éã®ååã«åŸãã ã«ã¹ã¿ã ããŒã« ãäœãããšãæãŸããã§ãã åè : ã¡ãŒã«æ€ç«ãèšå®ã管çãã ãŸããã¡ãŒã«ã«æ·»ä»ãããŠããäžå¯©ãªãã¡ã€ã«ããã«ãŠã§ã¢ã§ãªããã©ããã¯ã ã»ãã¥ãªãã£ãµã³ãããã¯ã¹ ãšããä»®æ³ç°å¢ã§æ€æ»ããããšãã§ããŸãã åè : æå®³ãªæ·»ä»ãã¡ã€ã«ãæ€åºããã«ãŒã«ãèšå®ãã ã¡ãŒã«ã®TLS æ¥ç¶ãå¿
é åãã管çè
ãªãã·ã§ã³ããããŸããæå¹åãããšãã«ãé TLS ã§éåä¿¡ãããã¡ãŒã«ãã©ããªããã«ã€ããŠã¯ãããã¥ã¡ã³ãã確èªããŠãã ããã åè : ã¡ãŒã«ã®ã»ãã¥ã¢ãªæ¥ç¶ãå¿
é ã«ãã è¿·æã¡ãŒã« Gmail ã¯åªããè¿·æã¡ãŒã«ãã£ã«ã¿ãæã£ãŠããŸããã誀æ€ç¥ããããŸããè¿·æã¡ãŒã«ãšåé¡ãã¹ãã§ãªãéä¿¡å
ãæç€ºçã«èš±å¯ãããªã¹ãã«ã¯ èš±å¯ãªã¹ã ãš æ¿èªæžã¿éä¿¡è
ãããããã®2ã€ã¯æå³ãç°ãªããŸãããã®éããçè§£ããŠãããŠãã ããã åè : èš±å¯ãªã¹ããæåŠãªã¹ããããã³æ¿èªæžã¿éä¿¡è
ã«ã¬ã³ã㌠äŒè°å®€ãšãªãœãŒã¹ Google ã«ã¬ã³ããŒã«ã¯ ãªãœãŒã¹ç®¡çæ©èœ ããããŸãã äŒè°å®€ããªãœãŒã¹ãšããŠç»é²ããŠãããé©åã«èšå®ããããšã§å©çšè
ãå¿«é©ã«äŒè°å®€ã®äºçŽãè¡ãããšãã§ããŸãã以äžã®ãããªããã¥ã¡ã³ããæŒãããŠãããŠãã ããã åè : Google ã«ã¬ã³ããŒã®äŒè°å®€ã®èªåææ¡æ©èœãèšå®ãã åè : äžèŠãªã«ã¬ã³ããŒã®äŒè°å®€ã®äºçŽãåãæ¶ã Google Meet é話å質 ãªã³ã©ã€ã³äŒè°ããŒã« Google Meet ã§ã¯ã管çè
ã¯åç»ã»é³å£°å質ã«é¢ãããã©ãã«ãžã®å¯ŸåŠãæ±ãããããããããŸããã 以äžã®ããã¥ã¡ã³ããæŒãããŠãããŠãã ããã åè : äŒè°ã®å質ãšçµ±èšæ
å ±ã確èªãã - Meet å質管çããŒã« ãã©ã€ã å
±æãã©ã€ã Google ãã©ã€ã㯠Google Workspace ã®åŒ·åãªã³ã©ãã¬ãŒã·ã§ã³æ©èœã®äžæ žã§ããç¹ã« å
±æãã©ã€ãæ©èœ ãæŒãããŠãããŠãã ããã åè : å
±æãã©ã€ããšã¯ å
±æãã©ã€ãã«ãããæš©é ãŠãŒã¶ãŒã«äžããããæš©éã¯ã管çè
ãã³ã³ãã³ã管çè
ãæçš¿è
ãã³ã¡ã³ãæçš¿è
ãé²èЧè
ãªã©ããããŸããæçš¿è
ã®æš©éã¯ç¹æ®ã§ããã¡ã€ã«ã®è¿œå ãç·šéã¯ã§ããããåé€ã¯ã§ããªããšãããã®ã§ãã åè : å
±æãã©ã€ãã®ãã¡ã€ã«ãžã®ã¢ã¯ã»ã¹ã®ä»çµã¿ ã°ã«ãŒã å
±åãã¬ã€ Google ã°ã«ãŒãã¯ãGoogle ã¢ã«ãŠã³ããäžæ¬ãã®ã°ã«ãŒããšããŠãŸãšããæ©èœã§ãããŸãã¡ãŒãªã³ã°ãªã¹ããšããŠãæ©èœããŸãã ã°ã«ãŒãã«ç¹åŸŽçãªã®ã å
±åãã¬ã€ æ©èœã§ããäŸãã°ã«ã¹ã¿ããŒãµã¯ã»ã¹ããŒã ãã顧客ããã®ãªã¯ãšã¹ããããŒã ãšããŠå¯Ÿå¿ãããå Žåã«ãã®æ©èœã圹ã«ç«ã¡ãŸãã åè : ã°ã«ãŒããå
±åãã¬ã€ãšããŠäœ¿çšãã 以äžã®åœç€Ÿèšäºããåç
§ãã ããã blog.g-gen.co.jp ãã£ã¬ã¯ããªç®¡ç ã¢ã«ãŠã³ãã®äžæåæ¢ãšåé€ Google ã¢ã«ãŠã³ãã¯ãäžåºŠåé€ããŠããŸããšååçã«ã¯ããŒã¿ããã¹ãŠæ¶ããŠããŸããŸãããã ãåé€åŸ20æ¥é以å
ã§ããã°åŸ©å
ã§ããŸãã åè : æè¿åé€ãããŠãŒã¶ãŒã埩å
ãã ãŸããé·æäŒæãªã©ã§åŸæ¥å¡ãé¢ããã埩垰åŸã¯åŸåã©ããå€åããããå Žåãªã©ã¯ãã¢ã«ãŠã³ãã®åé€ã§ã¯ãªãäžæåæ¢ãæ€èšããŸãããã åè : ãŠãŒã¶ãŒãäžæçã«åæ¢ãã ããŒã¿ã®ãšã¯ã¹ããŒã ããçµç¹ã®ã¢ã«ãŠã³ããæã£ãŠããããŒã¿ãå€éšã«æžãåºãããå Žåã ããŒã¿ãšã¯ã¹ããŒãããŒã« ã䜿çšãããšããã¹ãŠã®ãŠãŒã¶ãŒã®ããŒã¿ãæžãåºãããšãã§ããŸãã ãã ããçµç¹ã®ãŠãŒã¶ãŒæ°ã 1,000ãè¶
ããå Žå ã¯ããŒã«å©çšåã« Google Workspace ãµããŒããŸã§é£çµ¡ãå¿
èŠã§ãã åè : çµç¹ã®ãã¹ãŠã®ããŒã¿ãæžãåºã ããã°ã©ããã«ãªãã£ã¬ã¯ããªç®¡ç Directory API ã䜿ãããšã§ãããã°ã©ããã«ã«ãŠãŒã¶ãŒã®ç®¡çãã°ã«ãŒãã®ç®¡çãè¡ãããšãã§ããŸãã äŸãã°äººäºæ
å ±ç®¡çã·ã¹ãã ãããAPI çµç±ã§ããŒã¿ãååŸããŠèªåçã« Google Workspace ã«åæããããã°ã©ã ãæ§æå¯èœã§ãã åè : Directory API ã®æŠèŠ Google Cloud Directory Sync (GDCS) Google Cloud Directory Sync (GDCS) ã¯ãActive Directory ãä»ã® LDAP ãã£ã¬ã¯ããªãã Google Workspace ãžãã£ã¬ã¯ããªæ
å ±ãåæããããã®ããŒã«ã§ãã ãµãŒãã«ã€ã³ã¹ããŒã«ããŠå©çšããããŒã«ã§ãããAD ãš Google Workspace ã®ã¢ã«ãŠã³ãåæãªã©ã«çšããããŸãããªããè€æ°ã®ãã£ã¬ã¯ããªãã1ã€ã® Google Workspace ãžã®åæã¯ã§ããŸããã åè : Google Cloud Directory Sync åè : 2. LDAP ãã£ã¬ã¯ããªã®æºå ããã€ã¹ç®¡ç Workspace ã§å¯èœãªç®¡ç Google Workspace 㯠iOS ã Android ãªã©ã®ã¢ãã€ã«ç«¯æ«ãWindows ã Mac ãªã©ã® PC 端æ«ã管çããããšãã§ããŸãã ãåºæ¬ã®ãšã³ããã€ã³ã管çããé«åºŠãªãšã³ããã€ã³ã管çãããšã³ã¿ãŒãã©ã€ãº ãšã³ããã€ã³ã管çãã®3ãã£ã¢ã«åãããŠããŠããšãã£ã·ã§ã³ããšã«äœ¿ããæ©èœãç°ãªããŸãããããããªã³ã»ãªããå¯èœã§ãã åè : Google ãšã³ããã€ã³ãç®¡çæ©èœã®æ¯èŒ iOS ãšã³ã¿ãŒãã©ã€ãº ãšã³ããã€ã³ã管çã§ã¯ iOS ã«å¯ŸããŠãäŸãšããŠãWorkspace ã®ä»äºçšã®ããŒã¿ããå人㮠Gmail ã¢ã«ãŠã³ãããµãŒãããŒãã£ã¢ããªã«ã³ããŒããããšãçŠæ¢ããããšãã£ãå¶åŸ¡ãå¯èœã§ãã ããã¯ãããã€ã¹ > ã¢ãã€ã«ãšãšã³ããã€ã³ã > iOS èšå® > ããŒã¿å
±æãããè¡ããŸãã åè : iOS ããã€ã¹ã®ç®¡çã«ã€ã㊠åè : iOS ããã€ã¹ã«èšå®ãé©çšãã ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãX (æ§ Twitter) ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-gen ã®ææã§ããåœèšäºã¯ãBigQuery Reservation (Flat-rate pricing)ãã«ã€ããŠèª¬æããèšäºã§ãã æ³šæ : BigQuery ã®æéäœç³»ã«ã€ã㊠BigQuery Reservations ãšã¯ çšèª ã³ãããã¡ã³ã (Commitment) äºçŽ (Reservation) å²ãåœãŠ (Assignment) æé BigQuery Reservation ã®æé 賌å
¥æ¯éã®å€æ å®ããªãã®ãïŒ å¶é å¿çš 管çãããžã§ã¯ã ã¹ãããã¹ã±ãžã¥ãŒãªã³ã°ãšã¢ã€ãã«ã¹ããã ã¢ãã¿ãªã³ã° 泚æ : BigQuery ã®æéäœç³»ã«ã€ã㊠åœèšäºã§è§£èª¬ãããŠãããBigQuery Reservation (Flat-rate pricing)ã㯠2023/07/05 ã§è²©å£²ãçµäº ãã以åŸã¯ BigQuery Editions ã Flat-rate pricing ã«ä»£ããä»çµã¿ãšãªããŸãã 以éã®åœèšäºã®èšèŒã¯ãå€ãå¶åºŠã®ãã®ã§ãã®ã§ã泚æãã ãã (ã¢ãŒã«ã€ãã®æå³åãã§æ®ããŠããŸã)ã çŸåšã® BigQuery ã®æéäœç³»ã¯ã以äžã®èšäºãåèã«ããŠãã ããã blog.g-gen.co.jp BigQuery Reservations ãšã¯ BigQuery Reservations ãšã¯äºåã« BigQuery ã®ã¯ãšãªåŠç容éã賌å
¥ããããšã§ BigQuery ã®ã¯ãšãªæéãå®é¡ (flat-rate) åã§ããæ©èœã§ãã ãªã³ããã³ã課éã§ã¯ BigQuery ãåŠçãããã€ãæ°ã«å¿ããŠåŸéã§èª²éãæ±ºãŸãã®ã«å¯Ÿã㊠flat-rate 課éã§ã¯ äºåã«ã¯ãšãªåŠç容éã賌å
¥ ããããšã«ãªããŸãã ãªã BigQuery Reservations ãšããèšèãš Flat-rate pricing ãšããèšèããããŸãã BigQuery Reservations ã¯æ©èœåã§ããããã®æ©èœã䜿ãããšã§ Flat-rate pricing ã«æéäœç³»ãåãæ¿ããããããšçè§£ããã°ããã§ãããã Flat-rate pricing (å®é¡èª²é) ã®å¯ŸçŸ©èªã¯ On-demand pricing (åŸé課é) ã§ãã ãªã BigQuery Reservations ã§äºçŽã§ããã®ã¯ ã¯ãšãªåŠçã®èª²éã«å¯ŸããŠã®ã¿ ã§ãã ã¹ãã¬ãŒãžã®èª²éã¯å¥éãåŸé課éã§çºçããŸã ã®ã§ã泚æãã ããã çšèª ã³ãããã¡ã³ããäºçŽãå²ãåœãŠ ã³ãããã¡ã³ã (Commitment) ã³ãããã¡ã³ã (Commitment) ãšã¯ BigQuery ã®åŠç容éã®è³Œå
¥åäœã§ãã BigQuery ã§ã¯ ã¹ããã ãšããæŠå¿µããããŸããã¹ãããã¯åçŽã«èšããš BigQuery ã§äœ¿çšãããä»®æ³ CPU ã§ããã BigQuery ã®ã¯ãšãªãåŠçããé è³ãã¡ã§ãããã®ã¹ããããäºå賌å
¥ããããšããã³ãããã¡ã³ããäœæ (賌å
¥) ãããã®ããã«è¡šããŸãã ã³ãããã¡ã³ããã©ã³ã¯ä»¥äžã® 3 ã€ãååšããŸãã å¹Žé ææ¬¡ Flex 幎éã§ã¯ 365 æ¥éãæéã§ã¯ 30 æ¥éã Flex ã§ã¯ 60 ç§éã賌å
¥ã® æå°åäœ ãšãªããŸãã ãã®æå°åäœã®æéãéããã°ãã³ãããã¡ã³ãããã£ã³ã»ã«ããããã©ã³å€æŽããããšãã§ããŸãã ã³ãããæéãé·ãã»ã©ãã¹ããããããã®æéãå®ããªããŸãã ãªãæå°æéãéããŠããã£ã³ã»ã«ã«ãªãããã§ã¯ãªããã¹ãããã¯ä¿æãããŠèª²éãããŸã ( åç
§ )ã Flex 㯠60 ç§åäœã§è³Œå
¥å¯èœãªãããã¯ãŒã¯ããŒã管çã®ãã¹ãçšã«ã¹ããã賌å
¥ãããå Žåããçšåç³åãªã©å£ç¯æ§ã»çæã®åŠçå¢å ãžã®å¯Ÿå¿ãªã©ã«é©ããŠããŸãããŸãå¿çšçãªäœ¿ãæ¹ãšããŠãéããããåŠçã®çŽåã« Flex ã¹ãããã賌å
¥ããŠå²ãåœãŠãããããåŠçãçµãã£ããã¹ãããããã£ã³ã»ã«ãã (ã¹ãããã®è³Œå
¥ã»ãã£ã³ã»ã«ã¯ã¯ãŒã¯ãããŒããŒã«ã§èªåçã«è¡ã) ãããšãã£ãäœ¿ãæ¹ãå¯èœã§ãã äºçŽ (Reservation) äºçŽ (Reservation) ãšã¯è³Œå
¥ããã³ãããã¡ã³ãããããžã§ã¯ãã«å²ãåœãŠãããã®ç®¡çåäœã§ãã äŸãã°ããªã¥ãŒã ã®ç°ãªãã³ãããã¡ã³ãã 2 ã€è³Œå
¥ããŠãããã prod ãš test ãšããäºçŽã«å²ãåœãŠã prod ã¯æ¬çªç°å¢çšãããžã§ã¯ãã«ã test ã¯ãã¹ãç°å¢çšãããžã§ã¯ãã«å²ãåœãŠãããšãã£ãããšãå¯èœã§ãã ãªãã³ãããã¡ã³ãã賌å
¥ãããšæåã« default ãšããååã®äºçŽã«å²ãåœãŠãããŸãã å²ãåœãŠ (Assignment) å²ãåœãŠ (Assignment) ãšã¯äºçŽ (Reservation) ãããããžã§ã¯ããããã©ã«ãããçµç¹ãã®ããããã«å²ãåœãŠãããšãæå³ããŸãã äžã€ã®äºçŽãè€æ°ã®ããããžã§ã¯ããããã©ã«ãããçµç¹ãã«å²ãåœãŠãããšãå¯èœã§ãã å²ãåœãŠã«ã¯ ç¶æ¿ ã®æŠå¿µããããäŸãã°ãããããžã§ã¯ãã«äºçŽã®å²ãåœãŠãååšããªãå Žåãäžäœã®ãã©ã«ããçµç¹ã®å²ãåœãŠãé©çšãããŸãã æç€ºçã«å²ãåœãŠã None ã«æå®ããããšãã§ããŸããäŸãã°çµç¹å
šäœã«äºçŽãå²ãåœãŠãŠããããäžéšãããžã§ã¯ãã ã None ã«èšå®ããã°ããã®ãããžã§ã¯ãã ãã¯è³Œå
¥ããã¹ãããã䜿ãããªã³ããã³ã課éã䜿ãããããšãã£ãããšãå¯èœã§ãã ã³ãããã¡ã³ããäºçŽãå²ãåœãŠ (åãå³ãåæ²) æé BigQuery Reservation ã®æé 幎éãæéã Flex ã®é ã§ãã³ãããæéãé·ãã»ã©ã¹ããããããã®æéãå®ããªããŸãã 2022 幎 4 æçŸåšã®éé¡ã§ã¯ 100 ã¹ããããããã®éé¡ã¯ä»¥äžã§ãã Plan Price åäœ å¹Žé $2,040 100 ã¹ããã / æé¡ æé $2,400 100 ã¹ããã / æé¡ Flex $3,504 100 ã¹ããã / æé¡ ææ°ã®æéã¯å
¬åŒããŒãžããåç
§ãã ããã cloud.google.com 賌å
¥æ¯éã®å€æ BigQuery Reservations (Flat-rate pricing) ã¯ã©ã®ãããªãšãã«äœ¿ãã¹ããªã®ã§ããããã 以äžã®ããããã«åœãŠã¯ãŸããšãã ãšèšããŸãã BigQuery ã®æéãå®é¡ã»äºæž¬å¯èœã«ããããšã å€éå®è¡ããããžã§ã (ã¯ãšãª) ãéåžžã«å€ãããªã³ããã³ããã©ã³ã®ã¹ãããäžéã§ãã 2,000 ã¹ããããå®åžžçã«è¶
ãããšã 1ã€ç®ã®ãæéãå®é¡ã»äºæž¬å¯èœã«ããããšããã®æå³ã¯èªãã§åã®ããšãã§ããBigQuery ã®ç¹åŸŽã¯åŸé課éã§ããããããäŒç€Ÿã®æ¯æãã®ä»çµã¿ã財åäžã®çç±ã§æãŸãããªãå Žå㯠Flat-rate pricing ãéžæè¢ã«ãªããŸãã ãŸãã瀟å
ã® BigQuery å©çšè
ãå€ããã¯ãšãªã®ããªã¥ãŒã ãäºæž¬å°é£ã§ããå Žåã«å®å
šæµãšããŠã¹ãããå©çšæãåºå®åããããšããäœ¿ãæ¹ãèãããããããããŸããã 2 ã€ç®ã®ããªã³ããã³ããã©ã³ã®ã¹ãããäžéã§ãã 2,000 ã¹ããããå®åžžçã«è¶
ãããšããã¯æ§èœäžã®çç±ã§ãã ã¹ãããã® ã¹ã±ãžã¥ãŒãªã³ã° 㯠BigQuery ã«ãã£ãŠèªåçã«è¡ãããŠããŸããå¿
ãããå€ãã®ã¹ãããããããšåŠçãæ©ããªãããšããããã§ã¯ãªããè€æ°ã¯ãšãªãå¹ççã«å®è¡ãããããã«æé©åãããŸãããŸãã¹ããããäžæçè¶³ããªãå Žåã¯ãå®è¡ã§ããªãã¯ãšãªã¯ãšã©ãŒã«ãªãããã§ã¯ãªããã¥ãŒã§åŸ
ããããŠãæçµçã«ã¯å®è¡ãããŸãããªããªã³ããã³ãã¢ãŒãã§ã®æå€§ã¹ãããã¯ãããžã§ã¯ãããšã« 2,000 ã§ãããã¹ããšãã©ãŒãã§äžæçã« ããŒã¹ã ããŸãã ãªã³ããã³ãã¢ãŒãã®äžéã§ãã 2,000 ã¹ãããã¯çžå¿ã«å€§ãããã®ã§ãããŸããåè¿°ã®ããã«ã Flat-rate ã賌å
¥ããã°éããªããããã§ã¯ãããŸãããåŸè¿°ã®ããã«ã Flat-rate ã賌å
¥ããã°å¿
ãå®ããªããããã§ããããŸããã çŸåšã®ã¹ãããå©çšç¶æ³ãç¢ºèª ããäžã§ æ¬åœã« Flat-rate ã®å°å
¥ãå¿
èŠãã©ãããé©åã«å€æ ããã¹ãã§ãã çŸåšã®ã¯ãšãªã¯ãŒã¯ããŒãã«ãããŠã©ã®ãããã®ã¹ããããæ¶è²»ãããŠããã®ãã確èªããã«ã¯ã以äžã®ãããªæ¹æ³ããããŸãã ã¹ãããèŠç©ããããŒã« ãå©çšãã Cloud Monitoring ã® slots/allocated_for_project ã¡ããªã¯ã¹ã§ç¢ºèª INFORMATION_SCHEMA ãã¥ãŒã§ç¢ºèª ( åè ) ãŸãã以äžã®ããŒã« "Slot Recommender" ã§è³Œå
¥ãã¹ãã¹ãããæ°ã®ãªã³ã¡ã³ããŒã·ã§ã³ãåããããšãã§ããŸãã ã¹ãããã®æšå¥šäºé
ãšåææ
å ±ã®è¡šç€º å®ããªãã®ãïŒ Flat-rate ã賌å
¥ããã°å¿
ãå®ããªãããšããããã§ã¯ãããŸããããã®ç¹ããäŸãã° Compute Engine 㮠確çŽå©çšå²åŒ (Committed Use Discounts) ãªã©ã®ãªãœãŒã¹äºçŽè³Œå
¥å¶åºŠãšã¯ç°ãªãç¹ã§ãã BigQuery ã®éåžžã¢ãŒãã§ãããªã³ããã³ã課éã§ã¯ãã¯ãšãªã§ã¹ãã£ã³ããããŒã¿ã®ãµã€ãºããšãã¹ãã¬ãŒãžã®æéãã® 2 軞ã§èª²éãããŸãããã®ãã¡ BigQuery Reservation (Flat-rate) ãšé¢ä¿ãããã®ã¯åè
ã§ã (2022 幎 4 æçŸåšã®æ±äº¬ãªãŒãžã§ã³ã§ã¯ 1 TB ããã $6) ã ãã®äžæ¹ã§ Flat-rate æéã¯ãã¹ãããã®äºçŽã賌å
¥ããããšããæŠå¿µã§ããããªã³ããã³ãæéã®ãã¹ãã£ã³ããããŒã¿éããšã¯èšæž¬ã®å¯Ÿè±¡ãç°ãªããŸãããã®ãããã©ã¡ãã®ã»ããã³ã¹ãããã©ãŒãã³ã¹ããããªãã㯠ã¯ãšãªã®å©çšç¶æ³ã«ãã£ãŠç°ãªã ã®ã§ããåŸåãšããŠã¯ã å®åžžçã«ã¯ãšãªãçºè¡ãããŠããã¹ãããã®äœ¿çšç¶æ³ãäžå®ã§ããã»ã© Flat-rate ã®ã³ã¹ãã¡ãªãããåºãŠãã ãšèšããŸãã ãŸã Flat-rate ãšãªã³ããã³ã課éã¯çµã¿åãããŠäœ¿ãããšãã§ããŸããæé©ãªå©ç𿹿³ãæ€èšããããšãéèŠã§ãã å¶é 賌å
¥ããã¹ããããäºçŽã¯ ä»ã®ãçµç¹ããšã¯å
±æã§ããŸãã ã çµç¹ããšã«ã¹ããã賌å
¥ãäºçŽã®ç®¡çãæ€èšããå¿
èŠããããŸãã ãŸãã³ãããã¡ã³ã (ã¹ããã賌å
¥) 㯠ãªãŒãžã§ã³ãªãœãŒã¹ ã§ãã äŸãã°æ±äº¬ãªãŒãžã§ã³ã§è³Œå
¥ããã¹ããããå¥ã®ãªãŒãžã§ã³ã§äœ¿ã£ããããããã¯ç§»åããããšã¯ã§ããŸããã å¿çš 管çãããžã§ã¯ã BigQuery ã®ã³ãããã¡ã³ããäºçŽ (Reservation) ãšãã£ããªãœãŒã¹ã¯ãäžã€ã® 管çãããžã§ã¯ã ã§éçŽç®¡çããããšã æšå¥š ãããŠããŸãã ãã®ç®¡çãããžã§ã¯ãã§ã³ãããã¡ã³ã賌å
¥ãäºçŽã®äœæãè¡ãã BigQuery ãžã§ããå®è¡ãããåãããžã§ã¯ãã«äºçŽãå²ãåœãŠãŠããããšãæãŸãããšãããŸãã ããã«ããè«æ±ã®ç®¡çãã¹ãããå²ãåœãŠã®ç®¡çãäžå€®éçŽãããã·ã³ãã«ã«ãªããŸãã ãã ã 1 ã€ã®çµç¹ã®äžã§æš©éãè€æ°éšéã«ç§»è²ããŠããã BigQuery Reservations æ©èœã®å©çšãåéšéã«ä»»ããè«æ±è² æ
ãæç¢ºã«ãããå Žåã¯ãã®éãã§ã¯ãããŸãããèªåã®çµç¹ã®éçšåœ¢æ
ã«å¿ããŠãé©åãªç®¡çæ¹æ³ãéžã¶ã®ãè¯ãã§ãããã ã¹ãããã¹ã±ãžã¥ãŒãªã³ã°ãšã¢ã€ãã«ã¹ããã ããäžã€ã®äºçŽ (Reservation) ãè€æ°ãããžã§ã¯ãã«å²ãåœãŠãããŠãããšããŸãã ãããšããã®äºçŽã®ã¹ãããã¯ãŸããããžã§ã¯ãéã§åçã«åé
ãããŸãã æ¬¡ã«ãããžã§ã¯ãå
ã§å®è¡ãããŠãããžã§ã (ã¯ãšãªç) ã«åé
ãããŸãã BigQuery å
éšã®ã¹ã±ãžã¥ãŒã©ãåé
ãããŸãã³ã³ãããŒã«ããäžåè¡¡ãç¡é§ã眮ããªãããã«èª¿æŽããŠãããŸãã ãããæ°ã«ãªãã®ã¯ããã®ãããªã±ãŒã¹ã§ã¯ãªãã§ããããã äŸ: 10,000 ã¹ãããã 賌å
¥ã㊠2 ã€ã®äºçŽ ( batch , analyst ) ã«ãããã 7,000 ã 3,000 ã§å²ãåœãŠã ãã®äºçŽ batch , analyst ããããããããžã§ã¯ã project-batch ãš project-bi ã«å²ãåœãŠã ããæéã§ã¯ project-batch ã¯ã¯ãšãªãããªãåã£ãŠããŠã¹ããããè¶³ããªãäžæ¹ãã¿ã€ãã³ã°çã« project-bi ã¯ã¯ãšãªãåã£ãŠãããã¹ããããäœã£ãŠãã ãã®ãããªç¶æ
ã§ã¯ãã£ãã賌å
¥ããã¹ããããæå¹æŽ»çšãããªãã®ã§ã¯ããšèãããããããŸããã ãããå®ã¯ã BigQuery ã¯ãã®ãããªç¶æ³ãè³¢ããã³ããªã³ã°ããŠãããŸãã äºçŽã«å²ãåœãŠãããŠããã䜿çšãããŠããªããéãã§ãããã¹ãããããããããäºçŽã«å²ãåœãŠãããŠããªãã¹ããã㯠ã¢ã€ãã«ã¹ããã ãšããæ±ãã«ãªããŸãã BigQuery ã§ã¯äºçŽçµç±ã§ã¯ãšãªãå®è¡ããããš èªåçã«ãããã®ã¢ã€ãã«ã¹ããããäœ¿çš ããŸãã ãã®ããã«å¥ã®äºçŽã«äœ¿ãããŠããã¹ãããããå
ã®æå±ããŠããäºçŽã§ã¯ãšãªãå®è¡ãããŠå¿
èŠãšãããç¶æ
ã«ãªããšãå
ã®äºçŽã®ã¯ãšãªã§åªå
çã«äœ¿ãããããã«æ»ããŸãã ãã®ããã«èªåçã«ããŸãã¹ããããæŽ»çšãããããã«ãªã£ãŠããŸãã ãªãäºçŽã® ignore_idle_slots ãšãããã©ã¡ãŒã¿ã true ã«èšå®ããããšã§ä»ã®äºçŽã®ã¢ã€ãã«ã¹ãããã«æãåºããªãããã«èšå®ããããšãå¯èœã§ãã ã¢ãã¿ãªã³ã° BigQuery Reservations ã賌å
¥ããåŸããå²ãåœãŠãé©åããç¡é§ã§ã¯ãªããããªã©å®åžžçã«ã¢ãã¿ãªã³ã°ããããšãæãŸããã§ãã åè¿°ã®ããã« Cloud Monitoring ã®ã¡ããªã¯ã¹ã確èªããæ¹æ³ã INFORMATION_SCHEMA ãã¥ãŒããæ
å ±ãåŸãããã»ã 管çãªãœãŒã¹ã°ã©ã ãå©çšå¯èœã§ãã 管çãªãœãŒã¹ã°ã©ãã§ã¯éå» 30 æ¥éã«é¡ã£ãŠã¹ãããã®å©çšçããžã§ãã®ããã©ãŒãã³ã¹æšç§»ãªã©ãã°ã©ãã£ã«ã«ã«ç¢ºèªå¯èœã§ãããããŒã¿ã¯ INFORMATION_SCHEMA ã«åºã¥ãããã®ã§ãã Google Cloud ã³ã³ãœãŒã«ã® BigQuery > ã¢ãã¿ãªã³ã° ãã確èªããããšãã§ããŸãã ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãX (æ§ Twitter) ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-gen ã®ææã§ãã Google CloudïŒæ§ç§° GCPïŒã«ãããã¢ããªã±ãŒã·ã§ã³éçºè
åãã®èªå®è³æ Œã§ãã Professional Cloud Developer 詊éšã®ååŒ·æ¹æ³ãåºé¡åŸåãªã©ãåæ Œã«åã圹ç«ã€æ
å ±ãã玹ä»ããŸãã è©Šéšæ
å ± Professional Cloud Developer 詊éšãšã¯ Professional Cloud Developer 詊éšã®é£æåºŠ Professional Cloud Developer 詊éšã®ååŒ·æ¹æ³ åºé¡ç¯å²ãšåŸå ãã€ã¯ããµãŒãã¹ã¢ãŒããã¯ã㣠Identity and Access ManagementïŒIAMïŒ Google Kubernetes EngineïŒGKEïŒ Workload Identity èªèšŒæ
å ±ã®ç®¡ç ãµãŒãã¹ã¡ãã·ã¥ ãããã€æŠç¥ ãµãŒãã¹ééä¿¡ ã¯ã©ã¹ã¿å€ããã®éä¿¡ Network Policy / Authorization Policy Pod ã®ã©ã€ããµã€ã¯ã« Cloud Run Cloud Run ã®åºç€ Cloud Run ãžã®ããã〠Dockerfile ãªãã§ã®ããã〠Cloud Run functions App Engine Cloud Storage Firestore Compute Engine åºæ¬ ã¢ãã¿ãªã³ã°ãšãã®ã³ã° ããŒã¿ããŒã¹éžå® Cloud SQL Pub/Sub éçºç°å¢ CI/CD Cloud Build Cloud Build ã®ãã©ã€ããŒãããŒã« è匱æ§ã®ç®¡ç ç£èŠããªãã¶ãŒãããªã㣠Cloud Endpoints Google Cloud ã® API åŒã³åºã ã¯ãŒã¯ãããŒç®¡çïŒãžã§ãã®èªååïŒ Apigee Apigee ãšã¯ Apigee Analytics ãã©ãã£ãã¯ç®¡çãšã¬ãŒãå¶é ããã¯ãšã³ããµãŒããŒãžã®è² è·åæ£ è©Šéšæ
å ± Professional Cloud Developer 詊éšãšã¯ Professional Cloud Developer 詊éšã¯ãã¯ã©ãŠããã€ãã£ããªã¢ããªã±ãŒã·ã§ã³éçºãè¡ãããã®ç¥èãåã Google Cloud èªå®è³æ Œã§ãã Google Cloud äžã§ã¢ããªã±ãŒã·ã§ã³ã®é«å¯çšæ§ãã¹ã±ãŒã©ããªãã£ãã»ãã¥ãªãã£ã確ä¿ãããããŒãžããµãŒãã¹ã®æŽ»çšããµãŒããŒã¬ã¹ã®æŽ»çšã«ããéçšæ§ã®é«ãã¢ãŒããã¯ãã£ãèšèšããç¥èŠãæ±ããããŸããCI/CD ãéçºããŒã«ã«é¢ããç¥èããèªèšŒã»èªå¯ã«é¢ããç¥èã詊éšç¯å²ã«å«ãŸããŸãã è©Šéšæéã¯120åãå顿°ã¯50ã60åã§ãã1å1åã¯ãããŸã§å顿ãé·ãããã§ã¯ãªãããŸãåœèšäºããèªã¿ã®ã»ãšãã©ã®æ¹ã®ç¬¬äžèšèªã§ãããæ¥æ¬èªã§åéšã§ãããããè©Šéšæéãè¶³ããªããŠèŠããå°è±¡ã¯æããªãã¯ãã§ãã 詊éšã¯æ¥æ¬èªãšè±èªã§æäŸãããŠãããç³ãèŸŒã¿æã«éžæããŸãã åè : Professional Cloud Developer Professional Cloud Developer 詊éšã®é£æåºŠ Professional Cloud Developer 詊éšã®é£æåºŠã¯ äžçšåºŠ ã§ãããšãããŸãã IPA ã®ãå¿çšæ
å ±æè¡è
詊éšãçžåœã® ITãã·ã¹ãã éçºã«é¢ããåºç€ç¥èã«å ããŠãGoogle Cloud ã®åçš®ãµãŒãã¹ã«é¢ããç¥èŠãæ±ããããŸãã詊éšã§ã¯ Google Cloud ã®ç¥èã®ã¿ãªãããã¢ããªã±ãŒã·ã§ã³éçºãã³ã³ããã«é¢ããäžè¬çãªç¥èãæ±ãããã®ããããŸãããã®ããåŠç¿ã®é㯠Google Cloud ã«éãããšãªããåºæ¬ç㪠IT ç¥èããåºæ¬çãªã¢ããªã±ãŒã·ã§ã³éçºã«é¢ããç¥èããæŒãããã¹ããšãããŸãã å
¬åŒã¬ã€ãã§ã¯ã3幎以äžã®æ¥ççµéšãã1幎以äžã® Google Cloud ã䜿çšãããœãªã¥ãŒã·ã§ã³ã®èšèšãšç®¡çã®çµéšããæ±ããããã¬ãã«ã§ãããšèšèŒãããŠããŸãããå®éã«ã¯ãããŸã§ã®çµéšããªããŠãããã€ã³ããæŒãããåŠç¿ãããã°ãåæ Œã¯é£ãããããŸããã Professional Cloud Developer 詊éšã®ååŒ·æ¹æ³ 以äžã®ãããªååŒ·æ¹æ³ãæšå¥šã§ããããããªãã以äžã«ãã ããããšãªããåèªã®çŸåšã®ç¥èéãåŸæé åã«å¿ããåŠç¿ãããããšãæšå¥šãããŸãã ã¢ãã³ãªéçºææ³ã«é¢ããç¥èãå¥éãåŠç¿ãã Associate Cloud Engineer è©Šéš ãåŠç¿ããååŸããããšã§ Google Cloud ã®åºæ¬ãçè§£ 詊éšã¬ã€ã ã確èªããŠè©Šéšç¯å²ãçè§£ãã å
¬åŒããã¥ã¡ã³ããäžå¿ã«è©Šéšç¯å²ãåŠç¿ãã åœèšäºãèªã¿ã詊éšç¯å²ã®è©³çŽ°ãææ¡ããç¥ããªãç¥èãè£å¡«ãã æš¡æ¬è©Šéš ãåããåºé¡ãããåé¡ã®åœ¢åŒãšå
容ãããçè§£ãã Associate Cloud Engineer 詊éšã«ã€ããŠã¯ã以äžã®èšäºãåèã«ããŠãã ããã blog.g-gen.co.jp åè¿°ã® 1. ã¯ãã¢ãã³ãªéçºææ³ããšãããããŸããªã¯ãŒãã§è¡šçŸãããŠããŸããå
·äœçã«ã¯ã以äžã®ãããªçšèªã®çè§£ãæ·±ãããšè¯ãã§ããããããã㯠Google Cloud ã«éãããéçºã«é¢ããäžè¬çãªç¥èãšããŠãéèŠã§ããå
·äœçã«ãããã®çšèªã詊éšã§åãããããã§ã¯ãªããããããããããããã®çšèªã®ãšãã»ã³ã¹ãçè§£ããããšã§åçãéžæããéã®å€æåºæºã«ãªããŸãã CI/CDïŒç¶ç¶çã€ã³ãã°ã¬ãŒã·ã§ã³ / ç¶ç¶çããªããªïŒ DevOps / DevSecOps ãã¹ãé§åéçº ãªãã¶ãŒãããªã㣠ã€ãã³ãããªãã³ã¢ãŒããã¯ã㣠ãµãŒããŒã¬ã¹ã¢ãŒããã¯ã㣠ççµåã¢ãŒããã¯ã㣠ãã€ã¯ããµãŒãã¹ã¢ãŒããã¯ã㣠ã¹ããŒãã¬ã¹ãªã¢ããªã±ãŒã·ã§ã³ãã¹ããŒããã«ãªã¢ããªã±ãŒã·ã§ã³ åºé¡ç¯å²ãšåŸå åœèšäºã§ã¯ã䞻㫠Google Cloud ã®ãµãŒãã¹ã«ããã§ãåºé¡ç¯å²ãåŸåãã玹ä»ããŸãããŸããç¥ã£ãŠããã¹ãç¥èãã§ããã ãå
¬åŒããã¥ã¡ã³ãçãžã®ãªã³ã¯ä»ãã§ã玹ä»ããŸãããã²åŠç¿ã«åœ¹ç«ãŠãŠããã ããåæ Œãç®æããŠãã ããã ãã®èšäºã§å
šãŠã®æè¡èŠçŽ ã®è§£èª¬ãããããã§ã¯ãããŸãããèšèŒããã£ãããªã³ã¯ã貌ä»ãããŠããå Žåã¯ããã®ãããã詊éšã«ãããéèŠãã€ã³ãã ãšãèªèãã ããã ãã€ã¯ããµãŒãã¹ã¢ãŒããã¯ã㣠ãã€ã¯ããµãŒãã¹ã¢ãŒããã¯ã㣠ã«é¢ããç¥èŠãåãããåé¡ãåºé¡ãããŸãã 以äžã®å
¬åŒããã¥ã¡ã³ã㯠App Engine ã®ããã¥ã¡ã³ãã§ããããã€ã¯ããµãŒãã¹ã® RESTful API èšèšã«ãããåºæ¬çãªèãæ¹ã瀺ããŠãããåèã«ãªããŸãã ã API ã³ã³ãã©ã¯ã ãã API ããŒãžã§ã³ã瀺ã URL ãã äºææ§ãæãªã倿Žãšäºææ§ãæãªããªãå€æŽ ããªã©ã«ã€ããŠãçšèªã®æå³ãæŒãããŠãããŸãããã åè : ãã€ã¯ããµãŒãã¹ã®ã³ã³ãã©ã¯ããã¢ãã¬ã¹æå®ãAPI Identity and Access ManagementïŒIAMïŒ ã»ãŒãã¹ãŠã® Google Cloud èªå®è©Šéšã§å
±éããŠèšããããšãšããŠã Cloud IAM ã«é¢ããæ£ããçè§£ãå¿
é ã§ãã 以äžã®èšäºãèªã¿ã IAM Policy ã ãªãœãŒã¹ã«çŽã¥ãæŠå¿µã§ãã ããšãæ£ããçè§£ããŠãã ããã blog.g-gen.co.jp ãŸãããã®ããã§ ãµãŒãã¹ã¢ã«ãŠã³ã ãæ£ããçè§£ããŠãã ããã äŸãã° Compute Engine ã Cloud Run functions ã§çšŒåããããã°ã©ã ããGoogle Cloud ã®ä»ã®ãµãŒãã¹ã® API ãåŒã³åºãéã«ã¯ãèªèšŒæ
å ±ïŒãµãŒãã¹ã¢ã«ãŠã³ãããŒïŒãããã¹ããšããŠä¿åããŠããåŒã³åºãã®ã§ã¯ãªãããµãŒãã¹ã¢ã«ãŠã³ããã€ã³ã¹ã¿ã³ã¹ã颿°ã«ã¢ã¿ããããŠäœ¿ãã®ãæé©ã§ãã Google Kubernetes EngineïŒGKEïŒ Workload Identity Google Kubernetes Engine ïŒGKEïŒã§çšŒåããã¢ããªã±ãŒã·ã§ã³ã Google Cloud ã® API ãžã¢ã¯ã»ã¹ããéã®èªèšŒã»èªå¯ã«ã¯ Workload Identity ã䜿ãããšã 第äžéžæè¢ãšããŠæšå¥š ãããŠããŸãã åè : Authenticate to Google Cloud APIs from GKE workloads Workload Identity ã䜿ããš Cloud IAM ã§äœæãã "Google Cloud ã®" ãµãŒãã¹ã¢ã«ãŠã³ããšãKubernetes ãªãœãŒã¹ãšããŠäœæãã "Kubernetes ã®" ãµãŒãã¹ ã¢ã«ãŠã³ãã çŽã¥ã ããããšãã§ããŸãã ããã«ãã Kubernetes äžã§ã®æš©é管çãš Google Cloud äžã§ã®æš©é管çãççµåã«ããããšãã§ããã»ãã¥ãªãã£ãéçšæ§ãåäžããŸãã ãã®ååãåãåé¡ãè€æ°åºé¡ãããŸãã®ã§ã確å®ã«æŒãããŠãããŸãããã èªèšŒæ
å ±ã®ç®¡ç Workload Identity ã䜿ã Google Cloud ãµãŒãã¹ãžã®èªèšŒã管çããæ¹æ³ã¯åè¿°ã®éãã§ããããªã³ãã¬ãã¹ã«ååšããããŒã¿ããŒã¹ãžã®èªèšŒãªã©ã®ããã« IDã»ãã¹ã¯ãŒããå¿
èŠãšãããå Žé¢ããããŸãã ã³ã³ããå
ãã¹ãã¬ãŒãžã«ãããã£ãèªèšŒæ
å ±ãæ°žç¶åããããããGoogle Cloud ãµãŒãã¹ã§ãã Secret Manager ã«èªèšŒæ
å ±ãä¿ç®¡ããã°ãã»ãã¥ã¢ãªä¿ç®¡ãããŒããŒã·ã§ã³ã®ç®¡çãªã©ã容æã«ãªããŸãã èªèšŒæ
å ±èªäœã¯ Secret Manager ã«ä¿åããŸãããGKE ãã Secret Manager ã«ã¢ã¯ã»ã¹ããã«ã¯ãã¯ãåè¿°ã®éã Workload Identity ã䜿ãããŸãã åè : Using Secret Manager with other products ãµãŒãã¹ã¡ãã·ã¥ Istio on Google Kubernetes Engine ã¯ã2024幎6æçŸåšã§ã¯éæšå¥šãšãªã Cloud Service Mesh ã®å©çšãæšå¥šãããŠããŸãã2024幎6æçŸåšã®åœè©Šéšã§ã¯ Istio ã«é¢ããŠåãããŸããã詳现ãªä»æ§ãŸã§åãããããã§ã¯ãããŸããããåºæ¬çãªèãæ¹ã¯ Cloud Service Mesh ãšåãã§ãã ãµãŒãã¹ã¡ãã·ã¥ã®èãæ¹ãã mTLS ã«ãããµãŒãã¹ééä¿¡ã®æå·å ã«ã€ããŠãæŠèŠã ãã§ãçè§£ããŠãããŸããããéèŠãªã®ã¯ãIstio ã Cloud Service Mesh ãå°å
¥ããããšã«ããããµãŒãã¹ééä¿¡ãå°ãªãåŽåã§æå·åããããšãã§ããŸãã ãããã€æŠç¥ Blue/Green ããã〠ã ããŒãªã³ã°ã¢ããããŒã ã ã«ããªã¢ãªãªãŒã¹ ã A/B ãã¹ã ãšãã£ããããã€æŠç¥ãçè§£ããŠãã ããã ãããããã©ã®ãããªæ¹æ³ãªã®ãããã¡ãªãããšãã¡ãªããããããŒã«ããã¯ã®è¿
éãããªã©ã«çç®ããŸãããããããã®ãããã€æŠç¥ã¯ Google Cloud ã GKE ã«ç¹æã®ãã®ã§ã¯ãªããçŸä»£ã®ãããã€æŠç¥ã®èãæ¹ãšããŠå
±éã®ãã®ã§ãã 以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : ã¢ããªã±ãŒã·ã§ã³ã®ãããã€ãšãã¹ãã®æŠç¥ åè : GKE ã§ã®ãããã€ãšãã¹ãã®æŠç¥ã®å®è£
ãµãŒãã¹ééä¿¡ Kubernetes ãªãœãŒã¹ã§ãã Service ã«ã¯ ClusterIP ã NordPort ã LoadBalancer ãªã©ããããŸãã ãããã®ãã¡ã¯ã©ã¹ã¿ "å
" ã®ãµãŒãã¹ééä¿¡ãæ
ãã®ã¯ ClusterIP ã§ãã¯ã©ã¹ã¿ "å€" ããã®éä¿¡ãåãä»ããã®ã NodePort ã LoadBalancer ã§ãã ãŸããGKE ã¯ã©ã¹ã¿å
ã§ãã€ã¯ããµãŒãã¹éã®éä¿¡ãå®çŸããã«ã¯ã©ã®ãããªãªãœãŒã¹æ§æãšããã¹ãããçè§£ããŠãããŸãããã ãããã«ã€ããŠãåœããŒãžã§ã¯è©³çްã«è§£èª¬ããŸãããåèãšããŠã以äžã®æžç±ã§ Kubernetes ãªãœãŒã¹ã®è©³çްãªè§£èª¬ããããŠããŸãã åè : ãã³ãºãªã³ã§åãããããåŠã¹ã Google Cloudå®è·µæŽ»çšè¡ ããŒã¿åæã»ã·ã¹ãã åºç€ç·š ã¯ã©ã¹ã¿å€ããã®éä¿¡ Ingress ã«é¢ããç¥èŠãåãããŸããããšãã° External HTTPS Load Balancer ã«è€æ°ã®ãã¹ãåçšã® SSl/TLS èšŒææžãèšå®ããæ¹æ³ã«ã€ããŠæŒãããŠããŸãããã åè : Using multiple SSL certificates in HTTPS load balancing with Ingress Network Policy / Authorization Policy Network Policy ã Authorization Policy ãæŠèŠã¬ãã«ã§ãæ§ããŸããã®ã§ãæŒãããŠãããŸãããã ãããã¯ã¯ã©ã¹ã¿å
ã® Pod éããµãŒãã¹éã®éä¿¡ãå¶åŸ¡ããä»çµã¿ã§ãã åè : Control communication between Pods and Services using network policies åè : Authorization policy overview Pod ã®ã©ã€ããµã€ã¯ã« Pod ã忢ãããéãããŒã¿ããŒã¹ãšã®ã»ãã·ã§ã³ãæ£ããåæããŠããçµäºãããªã©ãPod çµäºåã®ã¢ã¯ã·ã§ã³ãèšå®ãããå Žåã PreStop ãå©çšããŸãã åè : ã³ã³ããã©ã€ããµã€ã¯ã«ãã㯠Cloud Run Cloud Run ã®åºç€ Cloud Run ã®åºæ¬ã¯ã以äžã®èšäºãèªãã§çè§£ããŠãããŸããããCloud Run ã¯ãã«ãããŒãžãã»ãµãŒããŒã¬ã¹ã®ã³ã³ããå®è¡ãã©ãããã©ãŒã ã§ãã blog.g-gen.co.jp Cloud Load Balancing ã®èåŸã«çœ®ã㊠Web ã¢ã㪠ãšããŠåäœãããããšãã Pub/Sub ã® push/pull ãµãã¹ã¯ãªãã·ã§ã³ã®èåŸã«çœ®ã㊠ã€ãã³ãããªãã³ãªããã°ã©ã ãåäœãããããšãã Cloud Scheduler ã«ãã£ãŠå®æçãªãžã§ããšããŠåŒã³åºãããšãã§ããŸãã Cloud Run ãžã®ããã〠Cloud Run ãžã®ã¢ããªã±ãŒã·ã§ã³ãããã€ã®åºæ¬çãªæµããæŒãããŠãã ããã ãœãŒã¹ã³ãŒããš Dockerfile ãæ ŒçŽãããŠãããã£ã¬ã¯ããªã§ docker build ãå®è¡ïŒã³ã³ããã€ã¡ãŒãžã®ãã«ãïŒ Docker ã€ã¡ãŒãžãã³ã³ããã€ã¡ãŒãžã¬ããžããªãž PushïŒã¬ããžããªãžã®æ ŒçŽïŒ ã€ã¡ãŒãžã® URL ãæå®ã㊠gcloud run deploy ïŒCloud Run ãžã®ãããã€ïŒ ãŸããäžèšã®ã»ãã«ã以äžã®ããã« Cloud Build ãå©çšããæ¹æ³ããããŸãã ãœãŒã¹ã³ãŒããš Dockerfile ãæ ŒçŽãããŠãããã£ã¬ã¯ããªã§ gcloud builds submit ãå®è¡ïŒã³ã³ããã€ã¡ãŒãžã®ãã«ããšã¬ããžããªãžã®æ ŒçŽïŒ ã€ã¡ãŒãžã® URL ãæå®ã㊠gcloud run deploy ïŒCloud Run ãžã®ãããã€ïŒ ãã®ãããªåºæ¬çãªæµããçè§£ããŠãåãã«çããããããã«ããŠãããŠãã ããã åè : Cloud Run ãžã®ããã〠åè : ã³ã³ãã ã€ã¡ãŒãžããã«ãããŸã Dockerfile ãªãã§ã®ããã〠Cloud Run ãžã®ã¢ããªã±ãŒã·ã§ã³ã®ãããã€ã¯ãã¬ããžããªã«æ ŒçŽããã³ã³ããã€ã¡ãŒãžã® URL ãæå®ããŠè¡ãããšãåºæ¬ã§ããããœãŒã¹ã³ãŒãã®ååšãããã£ã¬ã¯ããªãããããã€ã³ãã³ããå®è¡ããããšã§ãå®çŸã§ããŸãããã®å Žåãèªåçã«ã³ã³ããã€ã¡ãŒãžã®ãã«ããã€ã¡ãŒãžã® Artifact Registry ã¬ããžããªãžã®æ ŒçŽããããã€ãè¡ãããDockerfile ã®å®çŸ©ãå¿
èŠãããŸããã åè : ãœãŒã¹ã³ãŒããããããã€ãã Cloud Run functions Cloud Run functions ã¯ãã«ãããŒãžãã®ãµãŒããŒã¬ã¹ãµãŒãã¹ã§ãä»»æã®ã³ãŒããåããããšãã§ãããµãŒãã¹ã§ããFunction as a ServiceïŒFaaSïŒãšåé¡ãããããšããããŸããCloud Run functions 㯠Node.jsãPythonãGoãJavaã.NETãRubyãPHP ãªã©ã®ããã°ã©ãã³ã°èšèªã«å¯Ÿå¿ããŠããŸãã ãã®éã«æŒãããŠãããã»ããè¯ãç¥èãšããŠãã»ãã¥ã¢ã³ãŒãã£ã³ã°ã¯å¿
é ã§ããã»ãã¥ã¢ãªã³ãŒãã£ã³ã°ã«ã€ããŠã¯ã以äžã®ãããªæžç±ã圹ã«ç«ã¡ãŸãã åè : äœç³»çã«åŠã¶ å®å
šãªWebã¢ããªã±ãŒã·ã§ã³ã®äœãæ¹ äŸãã° CORS ïŒCross-Origin Resource SharingïŒãšããæŠå¿µãæŒãããŠãããŸãããã㯠Google Cloud ç¹æã§ã¯ãªããäžè¬çãªçšèªã§ãã詳现ã¯åœèšäºã§ã¯è§£èª¬ããªããããå¿
ããèªèº«ã§èª¿ã¹ãçè§£ããŠãã ããã äŸãã°ããã³ããšã³ãã® Web ãµã€ãã®ãã¡ã€ã³åãšãCloud Run functions ã«èšå®ããã«ã¹ã¿ã ãã¡ã€ã³åãç°ãªãå Žåã¯ã Access-Control-Allow-Origin: ${åŒã³åºãå
ãã¡ã€ã³å} ãã¬ã¹ãã³ã¹ãããã«å«ãŸããå¿
èŠããããŸãã 以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp App Engine App Engine ã¯ãããŒãžã㪠Web ã¢ããªã±ãŒã·ã§ã³ãã©ãããã©ãŒã ã§ãããé«åºŠã«ã¹ã±ãŒã©ãã«ãªæ§æãç°¡åã«æ§ç¯ã§ããŸããéçºè
ã¯ãã€ã³ãã©ã®æ§ç¯ã»éçšã®å·¥æ°ãçããã¢ããªã±ãŒã·ã§ã³éçºã«éäžããããšãã§ããŸãã App Engine ã«éããæ§ã
ãªãããŒãžããã©ãããã©ãŒã ãã³ã³ããã¢ãŒããã¯ãã£ã«å
±éããŠèšããããšã§ãããã¢ããªã±ãŒã·ã§ã³ã¯ã¹ããŒãã¬ã¹ã§ããå¿
èŠããããŸãããã®ããã»ãã·ã§ã³ç®¡çã«ã¯ Redis ã Memcached ãšãã£ãã€ã³ã¡ã¢ãªããŒã¿ããŒã¹ãå©çšãããšããã¢ãŒããã¯ãã£ããå顿ã®åæãšããŠèšå®ãããããšãå€ããªã£ãŠããŸãã ãã㊠Google Cloud ã§ã¯ Redis / Memcached ã®ãããŒãžããµãŒãã¹ã§ãã Memorystore ãããããããã»ããã§åºé¡ãããŸãã 现ãããšããã§ããäŸãã° Memorystore ã App Engine ããå©çšããå Žåã®ã¢ã¯ã»ã¹æ¹æ³ãçè§£ããŠãããŸãã App EngineïŒStandardïŒãã Memorystore ãžæ¥ç¶ããã«ã¯ããµãŒãã¬ã¹ VPC ã¢ã¯ã»ã¹ãå¿
èŠ App EngineïŒFlexibleïŒãã Memorystore ãžæ¥ç¶ããã«ã¯ãApp Engine ã authorized network å
ã«ããå¿
èŠããã App Engine ã®è©³çްã«ã€ããŠã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp Cloud Storage Cloud Storage ã¯å
ç¢ã§å®äŸ¡ãªãªããžã§ã¯ãã¹ãã¬ãŒãžã§ããCloud Storage ã«ã€ããŠã¯åœç€Ÿèšäºã§è©³çްã«è§£èª¬ããŠããŸãã®ã§ã以äžãåç
§ããŠãã ããã blog.g-gen.co.jp ã©ã€ããµã€ã¯ã«ãããžã¡ã³ãæ©èœ ã 眲åä»ã URL ãªã©ã䟿å©ãªæ©èœããã£ãããšæŒãããŠãããŠãã ãããã眲åä»ã URL ã§å¶éæéä»ãã®å°çš URL ãçºè¡ããèªèšŒæžã¿ã®å©çšè
ã ãã Cloud Storage äžã®ãªããžã§ã¯ããããŠã³ããŒãå¯èœã«ããããªã©ã®ãŠãŒã¹ã±ãŒã¹ãé »åºã§ãã åè : 眲åä»ã URL ãŸãèšäºã§ã説æãããŠããéçãŠã§ããµã€ããã¹ãã£ã³ã°æ©èœã«ãã Cloud Load Balancing ãšçµã¿åãããŠããŠã§ããµã€ãã®ãã¹ãã£ã³ã°ã«äœ¿ãããšãã§ããŸãã ãã«ããªãŒãžã§ã³ã® Cloud Storage + å€éš HTTP ããŒããã©ã³ãµãŒ + Cloud CDN æå¹å ã®ãããªã¢ãŒããã¯ãã£ã«ããããšã§ãå®äŸ¡ãã€ãã«ãããŒãžããªåœ¢ã§ãäžçäžã®å©çšè
ãã¿ãŒã²ãããšãããŠã§ããµã€ããç°¡åã«æ§ç¯ããããšãã§ããŸãããã®ãããªæ§æããé ã®äžã§æããããã«ããŠãããŠãã ããã Firestore Firestore ã¯ãã¢ãã€ã«ã¢ããªã Web ã¢ããªã®ããã¯ãšã³ãããŒã¿ããŒã¹ãšããŠå©çšã§ããããã«ãããŒãžã㪠NoSQL ããŒã¿ããŒã¹ã§ãã æ§ç§° Datastore ããçºå±ãããFirestoreïŒDatastore ã¢ãŒãïŒããšãWeb ã¢ããªã»ã¢ãã€ã«ã¢ããªã«æé©ãªãFirestoreïŒãã€ãã£ãã¢ãŒãïŒããååšãããããã¯ã»ãšãã©å¥ã
ã®è£œåã§ãããšèããããšãã§ããŸãã åè : Feature comparison 詊éšã«åããŠã¯ãç¹ã«ãã€ãã£ãã¢ãŒãã® Firestore ã«ã€ããŠéç¹çã«çè§£ããã»ããè¯ãã§ãããã Firestore ãã€ãã£ãã¢ãŒãã¯ããã¥ã¡ã³ãå¿åããŒã¿ããŒã¹ã§ããããšãããããŒãã«ãã«ã©ã ãã¬ã³ãŒããšãã£ãæŠå¿µã¯ãããŸããããã®ä»£ããã«ã ããã¥ã¡ã³ã ãã ã³ã¬ã¯ã·ã§ã³ ããšããæŠå¿µãååšããŸãã åè : Cloud Firestore ããŒã¿ã¢ãã« ãŸã Firestore ãã€ãã£ãã¢ãŒãã¯ã¢ãã€ã«ã¢ããªãæ³å®ããŠãããã¢ãã€ã«æ©åšã®ããŒã«ã«åŽãš Firestore ã®éä¿¡ãåããŠããããŒã«ã«åŽã§ããŒã¿ãä¿æããŠã¢ã¯ã»ã¹ã§ããããã«ããŠããã éä¿¡ãå埩ããéã«åæ ããããã«ã§ããŸãããŸãéçºæ
åœè
ã® PC ã®ããŒã«ã«äžã§çšŒåãããšãã¥ã¬ãŒã¿ãŒãçšæãããŠããŸãã Compute Engine åºæ¬ ä»®æ³ãµãŒããŒã®ãµãŒãã¹ã§ãã Compute Engine ãåºé¡ç¯å²ã§ããCompute Engine ã®ã€ã³ãã©å¯ãã®å
容ããããã¢ããªã±ãŒã·ã§ã³ã®ãããã€ã«é¢ããç¹ãéèŠãããŸãã ããšãã°ã VM ã¡ã¿ããŒã¿ ãïŒã€ã³ã¹ã¿ã³ã¹ããšã« Key/Value ã§æ
å ±ãæãããããæ©èœïŒã«ããããã€å
ã®ç°å¢ããšã«ç°ãªãæ
å ±ãæ ŒçŽããŠããããããã€ã®éã®åæååŠçæã«å©çšããããšãã£ããŠãŒã¹ã±ãŒã¹ãåºé¡ãããŸãã åè : About VM metadata ãŸãã¡ã¿ããŒã¿ã«ã¯ããããžã§ã¯ãã¬ãã«ã®ã¡ã¿ããŒã¿ããšãã€ã³ã¹ã¿ã³ã¹ã¬ãã«ã®ã¡ã¿ããŒã¿ãããããŸãããããžã§ã¯ãã¬ãã«ã§èšå®ããã¡ã¿ããŒã¿ã¯å
šãŠã®ã€ã³ã¹ã¿ã³ã¹ããååŸã§ããã€ã³ã¹ã¿ã³ã¹ã¬ãã«ã®ã¡ã¿ããŒã¿ã¯ãã®ã€ã³ã¹ã¿ã³ã¹ããã®ã¿ååŸã§ããŸãã Compute Engine ã®è©³çްã¯ã以äžã®èšäºãåç
§ããŠãã ããã åè : Compute Engineã培åºè§£èª¬ïŒïŒåºæ¬ç·šïŒ åè : Compute Engineã培åºè§£èª¬ïŒïŒå¿çšç·šïŒ ã¢ãã¿ãªã³ã°ãšãã®ã³ã° ã¢ããªã±ãŒã·ã§ã³ã®ãã°ã Cloud Logging ãžãªã¢ã«ã¿ã€ã ã«éä»ãããå Žåã Ops Agent ãã€ã³ã¹ããŒã«ããããšã§ä»»æã®ãã°ã Cloud Logging ãžéåºã§ããŸãã以äžã®èšäºãåèã«ããŠãã ããã åè : Cloud Loggingã®æŠå¿µãšä»çµã¿ããã£ãã解説 - G-gen Tech Blog åè : Google Cloud (GCP) Windows VM ã® Ops ãšãŒãžã§ã³ã ã§ Cloud Logging ã«ä»»æã®ãã°ãã¡ã€ã«ãåéããæ¹æ³ - G-gen Tech Blog ããŒã¿ããŒã¹éžå® Cloud SQLãBigtableãCloud SpannerãFirestore ãšãã£ã Google Cloud ã®ããŒã¿ããŒã¹ã®éããããã£ããææ¡ããŠãããŸãããã以äžã®èšäºã®ããã®ä»ã®ããŒã¿ããŒã¹ãã®é
ãåç
§ããŠãã ããã blog.g-gen.co.jp æŽåæ§ã®åŒ·åŒ±ããã©ã³ã¶ã¯ã·ã§ã³ã®æç¡ãSQL ã®å©çšå¯åŠãªã©ããããŒã¿ã®ã¢ã¯ã»ã¹ãã¿ãŒã³ãšç
§ãããŠéžå®ããå¿
èŠããããŸãã Cloud SQL Cloud SQL ãšã¯ãGoogle Cloud ã®ãããŒãžããªãªã¬ãŒã·ã§ãã«ããŒã¿ããŒã¹ãµãŒãã¹ã§ãã blog.g-gen.co.jp 詊éšã«åããŠã¯ããµãŒãã¹æŠèŠã«å ããCloud Run ã Comptue Engine ãã Cloud SQL ã€ã³ã¹ã¿ã³ã¹ãžããã©ããŒã IP ã¢ãã¬ã¹ã§æ¥ç¶ãããéã®æ¹æ³ã«ã€ããŠã以äžèšäºãåèã«ã€ã¡ãŒãžã確èªããŠãããšè¯ãã§ãããããµãŒããŒã¬ã¹ VPC ã¢ã¯ã»ã¹ã³ãã¯ã¿ããCloud SQL Auth Proxy ã䜿ã£ãæ¥ç¶æ¹æ³ãçè§£ããŠãããŠãã ããã blog.g-gen.co.jp Pub/Sub Pub/Sub ã¯ãã«ãããŒãžããªã¡ãã»ãŒãžãã¥ãŒã€ã³ã°ãµãŒãã¹ã§ãã ã·ã¹ãã ã³ã³ããŒãã³ãå士ã ççµåã«ãã ããã«éèŠãªãµãŒãã¹ã§ãããã¯ã©ãŠããããã¢ãŒããã¯ãã£ã®èŠãšãªããŸãã Pull ãµãã¹ã¯ãªãã·ã§ã³ ãš Push ãµãã¹ã¯ãªãã·ã§ã³ã® 2çš®é¡ããã ç¹ããŸãã¹ããªãŒãã³ã°ããŒã¿ã®åãå£ãšããŠã䜿ãããç¹ãªã©ãããAmazon Web Services (AWS) ã§ãã Amazon SQSãAmazon SNSãAmazon Kinesis Streams ãçµã¿åããããããªäœçœ®ä»ãã®ãµãŒãã¹ã§ãã ãŸãããŒã«ã«ã§åäœãã ãååšããŠããããããåé¡ã§åãããããšããããŸãã åè : Testing apps locally with the emulator éçºç°å¢ Cloud Code ãšããããŒã«ã®ååšãæŒãããŠãããŸãããã VSCodeãIntelliJ ãªã©ã® IDE åãã®ãã©ã°ã€ã³ã§ãããGoogle Cloud ã«ãããéçºã䟿å©ã«ããŠãããŸãã åè : Cloud Code and Gemini Code Assist IDE Plugins ãŸã Cloud Shell 㯠Google Cloud ãå®éã«å©çšã»éçšããŠãã人ã¯ã»ãŒäœ¿ã£ãããšãããã¯ãã§ããããäžåºŠã䜿ã£ãããšããªãå Žåãå€å°ã¯è§Šã£ãŠãããŸããããCloud Shell ã«ã¯ 5 GB ã®æ°žç¶ãã£ã¹ã¯ãå²ãåœãŠãããŸããã120æ¥éã¢ã¯ã»ã¹ããªãå Žåãäžèº«ãåé€ãããŸãã åè : Cloud Shell: ã¢ã¯ãã£ããã£ã®ãªãç¶æ
CI/CD Cloud Build Google Cloud ã§ CI/CD ãã€ãã©ã€ã³ãæ§ç¯ããéã«èŠã«ãªãã®ã¯ Cloud Build ã§ãã Cloud Build ã¯ãã®åã®éãããœãããŠã§ã¢ã®ãã«ãã®ããã®ãµãŒãã¹ã§ããã Google Cloud äžã®åãã©ãããã©ãŒã ãžã®ãããã€ã«ãçšããããšãå¯èœã§ãããœãŒã¹ã³ãŒãã¬ããžããªãžã® Push ãæ€ç¥ã㊠Code Build ãåãããã«ãã»ãã¹ãã»ãããã€ã宿œãããããšãã§ããŸãã ãã«ãããŒãžãã® Git ã¬ããžããªãµãŒãã¹ã§ãã Cloud Source Repositories ãšãCloud Build ã飿ºãããŠäžèšã®ãã㪠CI/CD ãã€ãã©ã€ã³ãå®çŸããããšãã§ããŸãïŒãã ãã2024幎6æä»¥éãCloud Source Repositories ã®æ°èŠå©çšåãä»ãã¯çµäºããŸããïŒã åè : Cloud Build ã䜿çšãããã«ãã®èªåå ãªã Cloud Build ã«ã¯ ãã«ãã¹ããã ïŒãŸãã¯åã«ã¹ãããïŒãšããæŠå¿µããããŸããã¹ãããã¯ãã®åã®éããã«ãã®åã¹ããããåŠçããåäœã§ããã¹ãããããšã«ãããŒãžããªã³ã³ãããèµ·åããŠåŠçãè¡ããŸããYAML ãŸã㯠JSON ã§èšè¿°ããæ§æãã¡ã€ã«ã«ãäžã€ä»¥äžã®ã¹ããããå®çŸ©ããå®è¡ããããšã§ãã«ãããããã€ãå®è¡ããã€ã¡ãŒãžã§ãã åãã«ãã¹ãããã¯å¥ã
ã®ã³ã³ããã§å®è¡ãããŸããã /workspace ãã£ã¬ã¯ããªé
äžã«é
眮ãããã¡ã€ã«ã¯ ã¹ãããéã§åŒãç¶ãã ãŸãã åè : ãã«ãã¹ããã Cloud Build ã®ãã©ã€ããŒãããŒã« ãã©ã€ããŒãããŒã« ã䜿çšãããšããã«ãããã»ã¹ãVPCãããã¯ãŒã¯å
ã«éå®ããããŒã¿ãå€éšã«æŒæŽ©ãããªã¹ã¯ã軜æžããããšãã§ããŸããVPC Service Contorls ã䜵ããŠå©çšããããšã§ãããã»ãã¥ã¢ãªãã«ãç°å¢ãå®çŸã§ããŸãã åè : ãã©ã€ããŒã ããŒã«ã®æŠèŠ åè : VPC Service Controlsãåããããã解説 - G-gen Tech Blog è匱æ§ã®ç®¡ç CI/CD ã«ã»ãã¥ãªãã£ã®æŠå¿µãåã蟌ã¿ãéçºã»éçšã«ã»ãã¥ãªãã£æ
ä¿ã®ä»çµã¿ãç¶ç¶çã«åã蟌ãäœå¶ã¯ãDevSecOps ãšãåŒã°ããŸãã ã³ã³ããã€ã¡ãŒãžã®æ ŒçŽã¬ãžã¹ããªã§ãã Artifact Registry ã§ã¯ã è匱æ§ã¹ãã£ã³ ãæå¹åããããšãã§ããŸãã åè : Artifact Analysis ãšè匱æ§ã¹ãã£ã³ ãŸãã¹ãã£ã³ã§åé¡ããªãã£ãã³ã³ããã€ã¡ãŒãžã«ã®ã¿ 眲å ïŒattestationïŒãä»äžãã Binary Authorization ã«ãã眲åããªãã€ã¡ãŒãžã®ãããã€ãçŠæ¢ããããšã§ãã»ãã¥ãªãã£ãåäžããããšãã§ããŸããBinary Authorization ã®èšå®æã¯ ããªã·ãŒ ïŒã³ã³ããã€ã¡ãŒãžã®ãããã€ãèŠå®ããã«ãŒã«ïŒãš èªèšŒè
ïŒïŒãšãã2ã€ã®ãªããžã§ã¯ãã®äœæãå¿
é ã§ãã åè : Binary Authorization ã®ã³ã³ã»ãã åè : Cloud Build ãã€ãã©ã€ã³ã§ Binary Authorization èšŒææžãäœæãã 眲åãš Binary Authorization ã䜿ã£ãã³ã³ããã€ã¡ãŒãžã®ã»ãã¥ã¢åã¯ãProfessional Cloud Security Engineer 詊éšã§ãåããããäžçš®ã®å®ç³ã§ãã以äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp ç£èŠããªãã¶ãŒãããªã㣠Google Cloud ã«ãããç£èŠã»éçšãšããã° Cloud Monitoring ã§ãã blog.g-gen.co.jp äžèšã®åºæ¬ã¯æŒããã€ã€ã Cloud Trace ã Cloud Profiler ãæŒãããŠãããŸãã Cloud Trace ã¯ãã¢ããªã±ãŒã·ã§ã³ã® 忣ãã¬ãŒã¹ ãå®çŸããä»çµã¿ã§ããã¢ããªã±ãŒã·ã§ã³ããŠãŒã¶ã®ãªã¯ãšã¹ããåŠçããã®ã«ãããæéãèšæž¬ãããããã€ã¯ããµãŒãã¹éã®ã¬ã€ãã³ã·ãç¶ç¶ã§ããã®ã§ã SLI/SLO ã®èšæž¬ ã«ãå©çšã§ããŸããã¢ããªã±ãŒã·ã§ã³ã«å¿
èŠãªã¯ã©ã€ã¢ã³ãã©ã€ãã©ãªã远å ããå¿
èŠãªã³ãŒãã远å ããããšã§å©çšå¯èœã«ãªããŸãã Cloud Profiler ã¯ã¢ããªã±ãŒã·ã§ã³ã® CPU ãã¡ã¢ãªãªã© ãªãœãŒã¹äœ¿çšç¶æ³ ãç¶ç¶åéããããã®ä»çµã¿ã§ããã¢ããªã±ãŒã·ã§ã³ã«ãããŠã ãœãŒã¹ã³ãŒãã®ã©ã®éšåã æããªãœãŒã¹ãæ¶è²»ããŠããã®ãããªã©ãç¹å®ã§ããã®ã§ãéå¹çãªã¢ããªã±ãŒã·ã§ã³ã® ãªãŒããŒãããã®ç¹å® ã«å©çšã§ããŸãã Cloud Endpoints Cloud Endpoints ã¯å
¬é API ãå®è£
ããããã®ãµãŒãã¹ã§ããCloud Endpoints ãä»ã㊠API ãå
¬éããããšã§ ã¢ãã¿ãªã³ã°ãã»ãã¥ã¢åãåæãã¯ã©ãŒã¿ã®èšå® ãªã©ãå®çŸã§ããŸãã Cloud Endpoints ã§ã¯ Nginx ããŒã¹ã® Extensible Service Proxy ïŒESPïŒãšåŒã°ãããããã·æ©èœã«ãããããŸããŸãªæ©èœãå®çŸããŸããESP ã¯ãCloud Load Balancing ã®åŸããVM / GKE ãªã©ããã¯ãšã³ãã¢ããªã±ãŒã·ã§ã³ã®åãã«é
眮ãããŸãã 以äžã®ããã¥ã¡ã³ãã®æ§æå³ãããèŠããŠãããŠãã ããããã®æ§æå³ã®äžã§ ESP ãã©ãã«é
眮ãããŠããã = Cloud Endpoints ã®é
çœ®å Žæãåãã£ãŠããã ãã§ãåçã«åœ¹ç«ã¡ãŸãã åè : Cloud Endpoints ã®ã¢ãŒããã¯ãã£ã®æŠèŠ Google Cloud ã® API åŒã³åºã Google Cloud ã®åçš®ãµãŒãã¹ã® API ãåŒã³åºãéãGoogle Cloud åŽã®äžæçãªé害ãªã©ã«ããã5xx ç³»ã®ãšã©ãŒãçºçããå¯èœæ§ããããŸãã ãã®ãããåŒã³åºãåŽã®ã¢ããªã±ãŒã·ã§ã³ã§ã¯ ãšã¯ã¹ããã³ã·ã£ã«ããã¯ãªã ïŒææ°ããã¯ãªãïŒãå®è£
ããããšãæšå¥šãããŠããŸããããã¯ãå詊è¡ã®éã«ãåŸã
ã«å®è¡ééãåºããªãããæå€§è©Šè¡åæ°ã«éãããŸã§åãªã¯ãšã¹ããç¹°ãè¿ãæŠç¥ã®ããšã§ãã åè : Exponential backoff Google Cloud APIs ã®è©³çްã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp ã¯ãŒã¯ãããŒç®¡çïŒãžã§ãã®èªååïŒ Google Cloud ã«ãããŠã¯ãŒã¯ãããŒç®¡çïŒãžã§ãã®èªååïŒãå®è£
ããå Žåã Workflows ã Cloud Composer ãæ€èšããŸããäž¡è
ãšããžã§ãã®ã¯ãŒã¯ãããŒç®¡çã®ããã®ãããŒãžããµãŒãã¹ã§ãããããããç°ãªãç¹åŸŽãšãŠãŒã¹ã±ãŒã¹ãæã£ãŠããŸãã ç¹åŸŽ Workflows Cloud Composer åºç€æè¡ ç¬èª Apache Airflow ãžã§ãå®çŸ© YAML ãŸã㯠JSON Python ã¹ã±ãžã¥ãŒãªã³ã° Cloud Scheduler Airflow ã¹ã±ãžã¥ãŒã©ïŒå
èµïŒ è€éæ§ æ¯èŒçã·ã³ãã«ãªã¯ãŒã¯ãããŒã«é©ãã é«åºŠãªã¯ãŒã¯ãããŒå¶åŸ¡ãå¯èœ åŠç¿ã³ã¹ã æ¯èŒçäœã æ¯èŒçé«ã äž»ãªçšé API ãªãŒã±ã¹ãã¬ãŒã·ã§ã³ãã·ã³ãã«ãªèªåå è€éãªããŒã¿ãã€ãã©ã€ã³ããããåŠç 以äžã®èšäºãåèã«ããŠãã ããã åè : Cloud Workflowsã培åºè§£èª¬ - G-gen Tech Blog åè : Cloud Composer (ã¡ãžã£ãŒããŒãžã§ã³2)ã培åºè§£èª¬ïŒ - G-gen Tech Blog 詊éšã§ã¯äžèšã®ãã€ã³ããæŒãããå顿ã«ããèŠä»¶ããã©ã¡ããããããããã€ã¡ãŒãžãããšè¯ãã§ãã Apigee Apigee ãšã¯ Apigee ãšã¯ãGoogle Cloud ãæäŸãã API 管çãã©ãããã©ãŒã ã§ããAPI ã®èšèšãã»ãã¥ãªãã£ä¿è·ãå
¬éãåæãªã©ã SaaS 圢åŒã§äžå
管çããããšãã§ããŸããApigee ã§ API ãããã·ãäœæããããšã§ãããã¯ãšã³ããµãŒãã¹ãæœè±¡åããã»ãã¥ãªãã£ããã©ãã£ãã¯å¶åŸ¡ãªã©ã®ããªã·ãŒãé©çšããããšã§ãéçºè
ã¯APIã®ã©ã€ããµã€ã¯ã«å
šäœãå¹ççã«ç®¡çããããšãã§ããŸãã åè : Apigee ã«ã€ã㊠以äžã®æ©èœã®ç޹ä»ãããã¯ã¢ããããŸãã Apigee Analytics Apigee Analytics ã¯ãAPI ãããã·ãä»ããŠæµãããªã¯ãšã¹ããã¬ã¹ãã³ã¹ããšã©ãŒãªã©ã®å€§éã®æ
å ±ãåéã»åæããå¯èŠåãããµãŒãã¹ã§ãã API ã®ããã©ãŒãã³ã¹ããã«ããã¯ããšã©ãŒã®åå ãç¹å®ããæ¹åã«åœ¹ç«ãŠãããšãã§ããŸããé¡äŒŒã®åœ¹å²ãæã€ãµãŒãã¹ãšã㊠Cloud Monitoring ããããŸãããã€ã³ãã©ã¹ãã©ã¯ãã£ãã¢ããªã±ãŒã·ã§ã³å
šäœã®ããã©ãŒãã³ã¹ç£èŠã§ã¯ãªããAPI ããã°ã©ã ã®å©çšç¶æ³ã API åºæã®èª²é¡ã«ç¹åããåæããããå Žåã¯ãApigee Analytics ãå©çšããæ¹ãé©ããŠããŸãã åè : Apigee API Analytics ã®æŠèŠ ãã©ãã£ãã¯ç®¡çãšã¬ãŒãå¶é ãŠãŒã¶ãŒã¢ã¯ã»ã¹ã®å€ãå€éšã¢ããªã±ãŒã·ã§ã³ãªã©ã§ãããã¯ãšã³ã API ãžã®éå°ãªãªã¯ãšã¹ãã«ããããã©ãŒãã³ã¹ãç¶æãããããApigee ã§ã¬ãŒãå¶éãèšå®ããããšãã§ããŸãã SpikeArrest ããªã·ãŒã Quota ããªã·ãŒã«ã€ããŠæŠèŠã¬ãã«ã§æŒãããŠãããŸãããã åè : ã¬ãŒãå¶é ããã¯ãšã³ããµãŒããŒãžã®è² è·åæ£ API ã¢ã¯ã»ã¹ã®å¯çšæ§ãé«ãããããTarget Servers ãæ§æããããšã«ãããããã¯ãšã³ããµãŒããŒã®è² è·åæ£ãå®çŸã§ããŸããååããã¹ãããããã³ã«ãããŒããäºåèšå®ããŠãAPI ãããã·ãæ§æããŸãã åè : ããã¯ãšã³ã ãµãŒããŒéã®ããŒã ãã©ã³ã·ã³ã° ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãX (æ§ Twitter) ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-gen ã®æŠäºã§ãããã£ããã§ããããã®åºŠã¯ãããŠåŒç€Ÿ Tech Blog ã«æçš¿ãããŠãããããšã«ãªããŸãããã¯ãããŠã®æçš¿ãšããããšãããããŸãã¯ãGoogle Cloud åºæ¬ã®ããã·ãªãŒãºã®1ã€ãšããŠãGoogle Compute Engine (GCE) çã® IaaS ãµãŒãã¹ãå©çšããäžã§ã¯æ¬ ãããªã Virtual Private Cloud (ä»®æ³ãããã¯ãŒã¯ãä»¥äž VPC) ã®æ§ç¯æé ã«ã€ããŠè§ŠããŠãããããšæããŸãã VPC ã®æŠèŠ VPC ã®åºæ¬ ãªãŒããµããããã¢ãŒã ã°ããŒãã«ãªãœãŒã¹ VPC ã®äœæ Google Cloud ã³ã³ãœãŒã«ãžã®ãã°ã€ã³ VPC åã®èšå® ãµããããã®èšå® ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã« (IPv4 / IPv6) ãã®ä»èšå®äºé
VPC ã®äœæåŸ ãµãããã éç IP ã¢ãã¬ã¹ ãã¡ã€ã¢ãŠã©ãŒã«ããªã·ãŒããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã« ã«ãŒã VPC ãããã¯ãŒã¯ãã¢ãªã³ã° ãã©ã€ããŒããµãŒãã¹æ¥ç¶ VPC ã®æŠèŠ VPC ã®åºæ¬ VPC ã®åºæ¬çãªç¥èã«ã€ããŠã¯éå»ã®æçš¿ããããŸãã®ã§ç®ãéããŠããã ãããšå¹žãã§ãã ã«ãžã¥ã¢ã«ã« VPC ã®æŠèŠãç¥ãããæ¹ blog.g-gen.co.jp ããå°ã现ãã VPC ãç¥ãããæ¹ blog.g-gen.co.jp ãªãŒããµããããã¢ãŒã 話ã®é çªãå°ãé転ããŠããŸããããããŸãããã解説ã®äŸ¿å®äžããŸãã¯ãµããããã«ã€ããŠèª¬æããŸãã ãªãŒããµããããã¢ãŒãã«ãã£ãŠ VPC å
ã«äœæããããµããããäžèЧ èŠãŠããã ããšãç»é¢äžå€®ãåãªãŒãžã§ã³ã«å¯ŸããŠãããã /20 ã®ãã¬ãã£ãã¯ã¹ã§åããããµããããã®äžèЧã衚瀺ãããŠããããšæããŸããããã¯äœããšèšããŸããšãããªãŒããµããããã¢ãŒãããå©çšããå Žåã«ãããããäœæãã VPC ã®äžã«æãåºããããµããããã®äžèЧã«ãªããŸãã ãªãŒããµããããã¢ãŒããšã¯ãµããããäœæãèªååãã Google Cloud ç¬èªã®æ©èœã®ããšã§ããã®ã¢ãŒããéžæã㊠VPC ãäœæãããšããã®æç¹ã§å©çšå¯èœãªãªãŒãžã§ã³ã«èªåçã«ãµãããããäœæãããŸããäŸãã°ãããã¹ãç°å¢çã§ãµã¯ããšäœããæ€èšŒããŠã¿ãããšãã«ãããã¯ãŒã¯ã®æ€èšãŸã§ã¯ããããªãïŒããªããŠãšãã«äŸ¿å©ãªæ©èœã«ãªãããšæããŸãã 詊ãã«ãyutakei-test-vpcããšãããªãœãŒã¹åã§ VPC ãæãåºããéã®ç»é¢ã以äžãšãªããŸãããäžèšç»é¢ã§äžèŠ§è¡šç€ºãããŠãããã®ãšåã IP ã¢ãã¬ã¹ããã¬ãã£ãã¯ã¹ã§åãªãŒãžã§ã³ã«ãµãããããäœæãããŠããã®ããåããããã ããããšæããŸãã ãªãŒããµããããã¢ãŒãã§å®éã«æãåºããããµãããã ãªããåŸæ¥ã©ãã管çè
ããµãããããš IP ç¯å²ãå®çŸ©ãããã«ã¹ã¿ã ãµããããã¢ãŒãããšããã¢ãŒããçšæãããŠãããæ¬çªç°å¢çã§ã䜿ãé ãå Žåããã¡ãã®ã«ã¹ã¿ã ãµããããã¢ãŒãã®å©çšããã¹ããã©ã¯ãã£ã¹ãšãªããŸããã¢ãŒãã®éžæã«ã€ããŠã¯ãVPC ãäœæããéã®ç»é¢ããéžæããã ããŸãã ãµããããäœæã¢ãŒãã®éžæ ã°ããŒãã«ãªãœãŒã¹ ããŠããããŸã§ã®ã話ã®äžã§éåæãæããããæ¹ãå€ãããã£ããããããããŸãããç¹ã« AWS ãå©çšãããçµéšã®ããæ¹ã¯ããã ãšæããã§ãããå®ã¯ Google Cloud ã® VPC ã§ã¯ããªãŒãžã§ã³ããŸãããããã«ã㊠VPC ãæ§æããããšãã§ãããã§ãã äžè¬çã«ãä»ã®ãããªãã¯ã¯ã©ãŠãã§ã¯ VPC ã¯ãªãŒãžã§ãã«ãªãœãŒã¹ãšããŠå®çŸ©ãããŠããŸãã®ã§ãæãåºããã VPC ã¯ç¹å®ã®ãªãŒãžã§ã³ã«çŽã¥ã圢ã§ç®¡çãããŸãã ããã Google Cloud ã®å ŽåãVPC ã¯ã°ããŒãã«ãªãœãŒã¹ãšããŠå®çŸ©ãããŠããŸãã®ã§ãäŸãã°æ±äº¬ãªãŒãžã§ã³ (asia-northeast1) ãšå€§éªãªãŒãžã§ã³ (asia-northeast2) ã䜿ã£ãŠ2ã€ã®ãªãŒãžã§ã³ã«ãŸããããããªåœ¢ã§1ã€ã® VPC ã圢æããããšãã§ããŸãããŸããåãªãŒãžã§ã³ã«ã¯éåžž3ã€ã®ãŸãŒã³ (AWS ã§èšã AZ) ããããŸãã®ã§ããµãŒãã¹ã®ç¹æ§ã«å¿ã㊠VPC ã ãµãããããæè»ã«èšèšã»æ§ç¯ããããšãå¯èœãšãªããŸãã äŸãã°ãããšåããããªæ§æã AWS ã§å®çŸãããå Žåãããããã®ãªãŒãžã§ã³ã« VPC ãæãåºããVPC éã®éä¿¡ãå¯èœã«ãªããããVPC éããã¢ãªã³ã°ã§æ¥ç¶ããã«ãŒãæ
å ±ãåæ¹ã® VPC ã§è¿œå ãããããå¿
èŠãåºãŠããã®ã§ãèšå®ã管çé¢ã§ã®æéãçãããšãã§ããŸãã VPCããµãããããæè»ã«æ§æã§ãã VPC ã®äœæ Google Cloud ã³ã³ãœãŒã«ãžã®ãã°ã€ã³ ä»åã¯ãGoogle Cloud åºæ¬ã®ããã·ãªãŒãºãšããããšããããŸãã®ã§ããããã㊠Cloud ã³ã³ãœãŒã«ã«ãã°ã€ã³ãããšãããã説æããããšæããŸãã 以äžã Google Cloud ã管çããããã® GUI ã³ã³ãœãŒã« (Cloud ã³ã³ãœãŒã«) ã«ãªããŸãã Cloud ã³ã³ãœãŒã«ã«ãŠçµç¹ãªãœãŒã¹ãéžæ ãŸã㯠Google ã¢ã«ãŠã³ãã§ Cloud ã³ã³ãœãŒã«ã«ãã°ã€ã³ãããã®åŸ VPC ãæãåºããŠããæµãã«ãªããŸãããVPC ãã¯ãããåçš® Google Cloud ãªãœãŒã¹ãå©çšããäžã§æåã«ãããªããã°ãããªãããšãšããŠãç»é¢ã®èµ€æ å
ã«ãŠãçµç¹ããã©ã«ãããããžã§ã¯ããšãã£ãçµç¹ãªãœãŒã¹ (ãªãœãŒã¹éå±€) ãæ£ããéžæããå¿
èŠããããŸãã çµç¹ãªãœãŒã¹ãšã¯ãGoogle Cloud ãå©çšããçµç¹ã®éå±€æ§é ã管çãããä»ã®ãããªãã¯ã¯ã©ãŠãã«ã¯ãªãç¬èªã®æŠå¿µã«ãªããŸãããVPC çã®åçš®ãªãœãŒã¹ã¯ãã®ãªãœãŒã¹éå±€ã®æãäžäœã«äœçœ®ã¥ãããããããäžäœã«ãããåçš®çµç¹ãªãœãŒã¹ã¯ééããªãããæ³šæãå¿
èŠã§ãã ãªããçµç¹ãªãœãŒã¹ããªãœãŒã¹éå±€ã«ã€ããŠã¯ä»åã®æ¬é¡ããå€ããŠããŸãããã詳现ã«ã€ããŠã¯å¥éãã¡ãã®èšäºãåç
§ããã ããšçè§£ãæ·±ãŸãããšæããŸãã blog.g-gen.co.jp VPC åã®èšå® åè¿°ã®éããç»é¢äžãããVPC ãããã¯ãŒã¯ã®äœæããã¯ãªãã¯ããé·ç§»å
ã®ç»é¢ã§è©³çްãèšå®ããŠãããŸãã ãŸãå§ãã« VPC åã説æ (ä»»æ) ãèšå®ããŸãã VPCèšå® ãµããããã®èšå® 次ã«ãµãããããèšå®ããŸãããµããããã¢ãŒãã¯ãã«ã¹ã¿ã ãããèªåããéžæããŸãããåè¿°ã®éããèªå (ãªãŒããµããããã¢ãŒã) ã¯ãã¹ãç°å¢çäžæçãªå Žé¢ã§ã®å©çšã«ãšã©ããæ¬çªç°å¢çãæ³å®ããŠå©çšããå Žåã¯ã«ã¹ã¿ã ã¢ãŒãã®éžæããã¹ããã©ã¯ãã£ã¹ã«ãªããŸããã«ã¹ã¿ã ã¢ãŒããéžæãããšã远å ã§ä»¥äžã®é
ç®ã«ã€ããŠèšå®ããŸãã ãµããããå 説æ ãªãŒãžã§ã³ IP ã¢ãã¬ã¹ç¯å² ãã¬ãã£ãã¯ã¹é·ã§èšå® ã»ã«ã³ã㪠IP ç¯å² (ä»»æ) Google ã¢ã¯ã»ã¹ (ä»»æ) ä»ã®ãªãœãŒã¹ã® API ã¢ã¯ã»ã¹ã«å€éš IP ã䜿ããªããAWS ã§èšã VPC ãšã³ããã€ã³ãã«çžåœããæ©èœ ãããŒãã° (ä»»æ) VPC ãžã®ã€ã³ããŠã³ã (äžã)ãã¢ãŠãããŠã³ã (äžã) ãã©ãã£ãã¯ã«é¢ãããã°ãçæãä¿ç®¡ããæ©èœ è¿œå ã®ãµããããèšå® (ä»»æ) èšå®é
ç®ã¯äžèšåæ§ ãµããããèšå®-1 ãµããããèšå®-2 ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã« (IPv4 / IPv6) VPC ãžã®ã€ã³ããŠã³ããã¢ãŠãããŠã³ããã©ãã£ãã¯ãå¶åŸ¡ããæ©èœã§ãAWS ã§èšãã»ãã¥ãªãã£ã°ã«ãŒãããããã¯ãŒã¯ ACL ã«çžåœããŸãã 以äžã®ããã«ãããã©ã«ãã«ãŒã«ã VPC äœæã®æ®µéã§é©çšããããšãã§ããŸãããããšããå¥éãã¡ã€ã¢ãŠã©ãŒã«ã®ã¡ãã¥ãŒã§å
·äœçã«å®çŸ©ããããšãå¯èœã§ãã ã»ãã¥ãªãã£ã®èгç¹ãããããšãäŸãã° RDP ã SSH ã®ã€ã³ããŠã³ãã«ãŒã«ã以äžã®ç»é¢ã§ã¯æ¥ç¶å
ã any ãšããŠããŸãã®ã§ãå¿
èŠæå°éã«çµã蟌ãã ã«ãŒã«ãå¥éäœæããã»ããæãŸããã§ãããã ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«èšå® ãã®ä»èšå®äºé
ãã®ä»ã®èšå®äºé
ãšããŠã¯ä»¥äžãæããããŸãããããããªã³ãã¬ãã¹ç°å¢ãšã® VPN æ¥ç¶ãæ³å®ããé
ç®ãšãªããŸãã åçã«ãŒãã£ã³ã°ã¢ãŒã ãªã³ãã¬ãã¹ãš VPN æ¥ç¶ããéãã°ããŒãã«ãéžæããããšã§ VPC åŽã®ã«ãŒãæ
å ±ããªã³ãã¬ãã¹åŽã«åºå ±ãããŸã DNS ãµãŒããŒããªã·ãŒ ãªã³ãã¬ãã¹ãš VPN æ¥ç¶ããéããªã³ãã¬ãã¹åŽã® DNS ãåç
§ãããããšãã§ããŸã æå€§äŒéåäœ (MTU) ãªã³ãã¬ãã¹ãš VPN æ¥ç¶ããéã1460 ã«èšå®ããããšãæšå¥šããŸã (VPN ãã³ãã«å
ã§ã¯ãªãªãžãã«ãã±ããããã³ãã«ãããã§ã«ãã»ã«åããããã) ãã®ä»èšå®äºé
ãããŸã§èšå®ãçµããããæåŸã«äœæãã¯ãªãã¯ã㊠VPC ãäœæããŸãã VPC ã®äœæåŸ VPC äœæåŸã¯èŠä»¶éãäœæã§ããã®ãã確èªããå¿
èŠã«å¿ããŠä¿®æ£ã远å ã®ç·šéãå ããããšãã§ããŸãã VPC ãããã¯ãŒã¯äžèЧã«äœæãã VPC ã衚瀺ãããããšæããŸãã®ã§ããã¡ããã¯ãªãã¯ããããšã§è©³çŽ°ç¢ºèªãšç·šéãå¯èœãªç»é¢ã«é·ç§»ããŸããä»åç§ã¯æ±äº¬ãªãŒãžã§ã³ãšå€§éªãªãŒãžã§ã³ããŸããããããªåœ¢ã§ VPC ãäœæããŸããã äœæããã VPC VPC 詳现ç»é¢ ãµãããã ååäœæåŸããµããããã¿ããããµããããã®åé€ã远å ãå¯èœã§ãã ãµããããã®ç·šéç»é¢ éç IP ã¢ãã¬ã¹ ä»åã¯äœæããŠããŸããããäŸãã° Compute Engine ãäœæãããšãèªåçã« å
éš IP ã¢ãã¬ã¹ãå²ãåœãŠãããŸãããå
éš IP ãã¹ã¿ãã£ãã¯ã«å²ãåœãŠãããšãã£ãèŠæãããå Žåã«ã¯ãã¡ãã®ã¿ããã管çããããšãã§ããŸãã éç IP ã¢ãã¬ã¹ã®ç·šéç»é¢ ãã¡ã€ã¢ãŠã©ãŒã«ããªã·ãŒããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã« 圹å²ãç®çã¯åããªãã§ãããå
ã«ãè¿°ã¹ããšãã Google Cloud ã«ã¯ãªãœãŒã¹éå±€ãšããæŠå¿µããããŸãããã®ãããåè
ã§ããã°çµç¹ãªãœãŒã¹ããã©ã«ããªãœãŒã¹ã«ã¢ã¿ããããããšã§ãé
äžã®ãªãœãŒã¹ã«ãåãããªã·ãŒãé©çšããããšãã§ããåŸè
ã§ããã°ãäŸãã°ç¹å®ã®ãããžã§ã¯ãã®ç¹å®ã® VPC ã«ã®ã¿ãŠããŒã¯ãªã«ãŒã«ãé©çšãããå Žåãªã©ã«å©çšããããšãã§ããŸãã ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã¯ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã¿ãããç·šéã§ããŸã ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®ç·šéç»é¢ ãã¡ã€ã¢ãŠã©ãŒã«ããªã·ãŒã«ã€ããŠã¯ Google ã®å
¬åŒãµã€ããã確èªãã ããã cloud.google.com ã«ãŒã VPC å
å€ãžéä¿¡ããããã®ã«ãŒãæ
å ±ã管çããŸããããã©ã«ãã§ã¯ãã€ã³ã¿ãŒããããžã®ããã©ã«ãã«ãŒãããVPC å
ã®ãµãããããå®å
ãšããã«ãŒãã¯ç»é²ããã仿§ãšãªã£ãŠããŸãããã®ããã㯠AWS ãåã仿§ããšæããŸãã ã«ãŒãã®ç·šéç»é¢ VPC ãããã¯ãŒã¯ãã¢ãªã³ã° åäžãããžã§ã¯ãå
ã®ä»ã® VPC ããå¥ã®ãããžã§ã¯ãã® VPC ã«å¯ŸããŠéä¿¡ãè¡ãããå ŽåãVPC ãããã¯ãŒã¯ãã¢ãªã³ã°ãèšå®ããŸããèšå®ãããšãå®å
ãšãªã VPC (ãµãããã) ãžã®ã«ãŒãæ
å ±ãèªåçã«ç»é²ãããŸãã ãŸããããŒã«ã« VPC ãŸã㯠æ¥ç¶å
VPC ããªã³ãã¬ãã¹ãš VPN æ¥ç¶ããŠããå Žåããªã³ãã¬ãã¹åŽã®ã«ãŒãæ
å ±ãã€ã³ããŒããããããŸãããªã³ãã¬ãã¹åŽãž VPC åŽã®ã«ãŒãã®ãšã¯ã¹ããŒããè¡ããŸãã VPC ãããã¯ãŒã¯ãã¢ãªã³ã°ã®ç·šéç»é¢ ãã©ã€ããŒããµãŒãã¹æ¥ç¶ ãã¡ããä»åã¯å©çšããŠããŸããããäŸãã° Cloud SQL ã§äœæãã DB ã€ã³ã¹ã¿ã³ã¹ã«ãã©ã€ããŒã IP æ¥ç¶ãèšå®ããå Žåãªã©ãä»ã®ãªãœãŒã¹ãšã®æ¥ç¶ã«ãã©ã€ããŒããµãŒãã¹æ¥ç¶ãå©çšããå Žåã«ç®¡çããé
ç®ã«ãªããŸãã ãã©ã€ããŒããµãŒãã¹æ¥ç¶ã®ç·šéç»é¢ æŠäº ç¥ä» (èšäºäžèЧ) 2022幎4æå
¥ç€Ÿ / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš / æè¡2課æå± è¶£å³ã¯ãŽã«ãã«ããŒããã€ã¯ãIaC ã CI/CD åšãã®ãµãŒãã¹ããããã¯ããèå³åéã§ãã Google Cloud èªå®å
šå éæïŒ(2023幎6æ)
G-gen ã®ææã§ãã BigQuery ã® Search Index æ©èœã 2022幎4æ7æ¥ã«ãã¬ãã¥ãŒå
¬éã2022幎10æ27æ¥ã« GA ãããŸãããBigQuery ã«å¯Ÿããç¹å®æååã®æ€çŽ¢ãé«éåããåœæ©èœã解説ããŸãã BigQuery Search Index ã®åºæ¬ BigQuery Search Index ãšã¯ ãŠãŒã¹ã±ãŒã¹ æé å¶é 察å¿ããŠããã«ã©ã ã¿ã€ã ãã®ä»ã®å¶é ã€ã³ããã¯ã¹ã®äœæãšå©çš åºæ¬çãªäœ¿ãæ¹ å
šã«ã©ã ãžã®ã€ã³ããã¯ã¹äœæã»æ€çŽ¢ ã€ã³ããã¯ã¹ã䜿ããããã©ããã®ç¢ºèª ãã®ä»ã®ã¯ãšãªæ¹æ³ ã€ã³ããã¯ã¹ã®åé€ BigQuery Search Index ã®åºæ¬ BigQuery Search Index ãšã¯ BigQuery ã® Search Index ãšã¯ã BigQuery ã®ããŒãã«ããç¹å®æååãæ€çŽ¢ã»æœåºãããããªã¯ãšãªã髿§èœåããããã®ã€ã³ããã¯ã¹æ©èœã§ãã ããŒãã«ã«ãã«ã©ã ãæå®ããŠäºãã€ã³ããã¯ã¹ãäœæããŠãããSELECT æã® WHERE å¥ã« SEARCH() 颿°ã = ã IN ã LIKE ãªã©ã®æŒç®åãçšããããšã§ãã€ã³ããã¯ã¹ãå©çšããé«éãªã¯ãšãªãå®è¡ã§ããããã«ãªããŸãã ã€ã³ããã¯ã¹ã®æŽæ°ã¯ èªåçã« è¡ãããŸãã®ã§ãäžåºŠã€ã³ããã¯ã¹ãäœæããŠããŸãã°ãã¡ã³ããã³ã¹ã¯å¿
èŠãããŸããã ãŸãã€ã³ããã¯ã¹ãçšããã¯ãšãªã§ã¯ãã«ã¹ãã£ã³ãåé¿ã§ããŸãã®ã§ãã¹ãã£ã³æéã®ç¯çŽã«ããªããŸããã¯ãšãªã«ãã£ãŠã¯åçãªæéç¯çŽã«ãªãå¯èœæ§ããããŸãã ãªãåœæ©èœã¯ 10GB 以äžã®ãµã€ãºãæã€ããŒãã«ã«ã®ã¿æå¹ ã§ããããã以äžã®ãµã€ãºã®ããŒãã«ã«ã€ã³ããã¯ã¹ãäœæããŠããæå¹ã«ãªããŸããã åè : Introduction to search in BigQuery åè : Search indexed text åè : Manage search indexes ãŠãŒã¹ã±ãŒã¹ åœæ©èœã¯ã以äžã®ãããªãŠãŒã¹ã±ãŒã¹ãæ³å®ãããŸãã ãã°ããŒã¿ã®æ€çŽ¢ïŒã·ã¹ãã ãã°ããããã¯ãŒã¯ãã°ãã¢ããªã®ãã°çïŒ æ³çèŠå¶ãªã©ã«å¯Ÿå¿ããããã®ãç¹å®ããŒã¿ãæ€çŽ¢ãããåé€ããã¯ãšãª ã»ãã¥ãªãã£ç£æ» ãã©ãã«ã·ã¥ãŒãã£ã³ã° çãç¯å²ã®ç¹å®æååãæœåºããããã·ã¥ããŒãäœæ SEARCH() 颿°ã䜿ãå Žåã¯è€æ°ã«ã©ã ãæšªæããŠæååãæ°å€ã®æ€çŽ¢ãå¯èœã§ãããåŸè¿°ã®ããã«ãã€ãã£ã JSON åã®ã«ã©ã ã«ã察å¿ããŠããŸããCloud Logging ã§åéãã Google Cloud ãµãŒãã¹ã®ãã°ã«å¯Ÿããæ€çŽ¢ãªã©ã«ã圹ç«ã€ã§ãããã BigQuery ã«ã¯åŸæ¥ãã€ã³ããã¯ã¹ã®æŠå¿µããªããã€ã³ããã¯ã¹èšèšãèæ
®ããè² æ
ãç¡ãããšã BigQuery ã®ã¡ãªããã®äžã€ã§ããããã®åºæ¬å§¿å¢ãå€ããå¿
èŠã¯ãªããç¹å®æååãæœåºããã¯ãšãªã®ãŠãŒã¹ã±ãŒã¹ãããéã®éžæè¢ãå¢ããããšæããã°ããã§ãããã æé ã€ã³ããã¯ã¹ãä¿åããããã® BigQuery ã¹ãã¬ãŒãžæéãçºçããŸã ( æéããŒãž ) ã ã€ã³ããã¯ã¹ã䜿çšããŠããã¹ãã¬ãŒãžã®é㯠INFORMATION_SCHEMA.SEARCH_INDEXES ãã¥ãŒ ã§ç¢ºèªããããšãã§ããŸãã ã€ã³ããã¯ã¹äœæã»æŽæ°åŠçã®ã³ã³ãã¥ãŒãã£ã³ã°æéã«ã€ããŠã¯ããªãŒãžã§ã³ããšã«èŠå®ãããç¯å²å
ã§ããã°èª²éãããŸãããããããè¶
ããå Žå㯠Reservation ã賌å
¥ããå¿
èŠããããŸãã詳现ã¯ä»¥äžã®ããã¥ã¡ã³ãããåç
§ãã ããã åè : Introduction to search in BigQuery - Pricing åè : Quotas and limits - Indexes å¶é 察å¿ããŠããã«ã©ã ã¿ã€ã 以äžã®åã®ã«ã©ã ã«å¯ŸããŠãã€ã³ããã¯ã¹ãäœæã§ããŸãã STRING INT64 TIMESTAMP ARRAY STRUCT JSON åè : CREATE SEARCH INDEX statement ãã®ä»ã®å¶é ãã®ä»ã«ã¯ä»¥äžã®å¶éããããŸãã ã€ã³ããã¯ã¹ã䜿ãããã®ã¯ SEARCH() 颿°ããã㯠WHERE å¥ã§ = ã IN ã LIKE ãªã©ç¹å®ã®æŒç®åïŒoperatorïŒã䜿ã£ãã¯ãšãªã®ã¿ 10 GB 以äžã®ãµã€ãºã®ããŒãã«ã§ã¯ã€ã³ããã¯ã¹ãç¡å¹ ãã¥ãŒããããªã¢ã©ã€ãºãã»ãã¥ãŒã«ã¯ã€ã³ããã¯ã¹äœæäžå¯ ãã ããã¥ãŒããããªã¢ã©ã€ãºãã»ãã¥ãŒã®å
ããŒãã«ã«ã€ã³ããã¯ã¹ã匵ã£ãŠããã°ããã¥ãŒã«å¯Ÿãã SEARCH 颿°ã®å©çšã§ãã€ã³ããã¯ã¹ãå©çšããã ããŒãã«ããªããŒã ããããšã€ã³ããã¯ã¹ãç¡å¹ã«ãªã ã€ã³ããã¯ã¹ã®äœæãšå©çš åºæ¬çãªäœ¿ãæ¹ ã€ã³ããã¯ã¹ã¯ä»¥äžã®ãã㪠CREATE æã§äœæã§ããŸãã CREATE SEARCH INDEX my_index ON my_dataset.my_table(column_a, column_c); äœæããã€ã³ããã¯ã¹ãå©çšããŠé«éãªã¯ãšãªãå®è¡ããã«ã¯ã以äžã®ãã㪠SELECT æãçšããŸãã SELECT * FROM my_dataset.my_table WHERE SEARCH(column_a, ' hogehoge ' ); ãªããã¯ãšãªå®è¡çµæã® EXECUTION DETAIL (æ¥æ¬èªã³ã³ãœãŒã«ã§ã¯ å®è¡ã®è©³çް ) ã確èªããããšã§ãã¯ãšãªã«ã€ã³ããã¯ã¹ã䜿ããããã©ããã確èªããããšãã§ããŸãã å
šã«ã©ã ãžã®ã€ã³ããã¯ã¹äœæã»æ€çŽ¢ 以äžã®ãã㪠CREATE æã§ã察象ããŒãã«ã®å
šãŠã®ã«ã©ã (察å¿ã¿ã€ãã®ã«ã©ã ã®ã¿) ã«ã€ã³ããã¯ã¹ãäœæã§ããŸãã CREATE SEARCH INDEX my_index ON my_dataset.my_table( ALL COLUMNS); ãŸãã以äžã®ãã㪠SELECT æã§ããŒãã«å
šäœã«å¯ŸããŠã¯ãšãªãå®è¡ã§ããŸãã SELECT * FROM my_dataset.my_table WHERE SEARCH(my_table, ' hogehoge ' ); ã€ã³ããã¯ã¹ã䜿ããããã©ããã®ç¢ºèª ã¯ãšãªãå®è¡ããããšããã®ã¯ãšãªã§ã€ã³ããã¯ã¹ã䜿ããããã©ããã確èªããã«ã¯ãã¯ãšãªå®è¡åŸã«åœè©²ãžã§ãã® ãžã§ãæ
å ± ïŒJob InformationïŒã確èªããŸãã ã³ã³ãœãŒã«ç»é¢çã§ãžã§ãæ
å ±ã®è©³çްç»é¢ã衚瀺ãã ã€ã³ããã¯ã¹äœ¿çšã®ã¢ãŒã ïŒIndex Usage ModeïŒã®é
ç®ã確èªããããšã§ã€ã³ããã¯ã¹ã䜿çšããããã©ãããããããŸãã UNUSED : ã€ã³ããã¯ã¹ã䜿çšãããªãã£ã PARTIALLY_USED : ã¯ãšãªã®äžéšã§ã€ã³ããã¯ã¹ã䜿çšããã FULLY_USED : ã¯ãšãªã®å
šéšåã§ã€ã³ããã¯ã¹ã䜿çšããã åè : Search index usage ãžã§ãæ
å ± ãã®ä»ã®ã¯ãšãªæ¹æ³ ã€ã³ããã¯ã¹ã䜿ã£ãããŸããŸãªã¯ãšãªæ¹æ³ããå®è¡çµæã®èãæ¹ã«ã€ããŠã¯ä»¥äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : Search indexed data SEARCH 颿°ã®æ³šæç¹ãšããŠãäŸãã° 192.168.10.1 ã®ãããªããªãªãåºåãã®æååã¯ãããŒã¹ãã㊠192 168 10 1 ãšããããããã®æååãå«ãå ŽåãšããŠæ€çŽ¢ãããŠããŸããŸãã IP ã¢ãã¬ã¹ãæ€çŽ¢ãããšããªã©ã¯ `192.168.10.1` ã®ããã«ããã¯ã¯ã©ãŒãã§å²ãããšã§ãäžé£ã®æååãšããŠèªèãããå¿
èŠããããŸãã SELECT * FROM my_dataset.my_access_log WHERE SEARCH(ip_addr, ' `192.168.10.1` ' ); SEARCH 颿°ã®äœ¿ãæ¹ã«ã€ããŠã¯ä»¥äžããåç
§ãã ããã åè : Search functions ã€ã³ããã¯ã¹ã®åé€ ã€ã³ããã¯ã¹ã®åé€ã«ã¯ DROP æãçšããŸãã DROP SEARCH INDEX my_index ON my_dataset.my_table; ãªãããŒãã«ãåé€ããããšã€ã³ããã¯ã¹ãèªåçã«åé€ãããŸãã®ã§ãåé€å¿ãã«ããç¡é§ãªã¹ãã¬ãŒãžèª²éã®å¿é
ã¯ãããŸããã ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãX (æ§ Twitter) ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-gen ã®æž¡é@norry ã§ããGoogle CloudïŒæ§ç§° GCPïŒã® é«å¯çšæ§ Cloud VPN ã¯ãIPsec VPN ã«ãããªã³ãã¬ãã¹ãããã¯ãŒã¯ãš VPC ãããã¯ãŒã¯ããã©ã€ããŒãã«æ¥ç¶ãããµãŒãã¹ã§ãã HA VPN æŠèŠ HA VPN ãšã¯ ãŠãŒã¹ã±ãŒã¹ HA VPN ã®æé ãªã³ãã¬ãã¹åŽã«ãŒã¿ãŒã®ä»æ§ HA VPN ãæ§æããèŠçŽ HA VPN çšèªã®ãããã Cloud HA VPN ã²ãŒããŠã§ã€ VPN ã²ãŒããŠã§ã€ ã®æ§æèŠçŽ VPN ãã³ãã« VPN ãã³ãã« ã®æ§æèŠçŽ Cloud Router BGP ã»ãã·ã§ã³ ã®æ§æèŠçŽ æ§æ HA VPN æ§æ é«å¯çšæ§ã®ç¢ºèª ã¢ã¯ãã£ã / ã¢ã¯ãã£ã ãŸã㯠ã¢ã¯ãã£ã / ããã·ã éçšã»ãã®ã³ã° ãã°ã®ä¿åå Žæ ã¢ã©ãŒã HA VPN æŠèŠ HA VPN ãšã¯ é«å¯çšæ§ Cloud VPN ïŒä»¥äžã HA VPN ïŒãšã¯ãã€ã³ã¿ãŒãããåç·äžã§ IPsec VPN ãçšããŠããªã³ãã¬ãã¹ãš VPC ãããã¯ãŒã¯ããŸãã¯ãVPC ãããã¯ãŒã¯ å士ããããã¯ãGoogle Cloud ã® VPC ãš Amazon VPC ã Azure VNet çããšå®å
šã«æ¥ç¶ãã§ãããµãŒãã¹ã§ãã HA VPN ã¯ã€ã³ã¿ãŒãããåç·ã䜿çšããŠãã©ã€ããŒãæ¥ç¶ãå®çŸã§ããããšã«å ããVPN ãã³ãã«ãåé·åããäºã§å¯çšæ§ã垯åãæ¡åŒµã§ãããããå°çšç·ã«æ¯èŒããŠã³ã¹ãã¡ãªããã«åªããŠããŸãã èªçµç¹ã§æ¢ã«ã€ã³ã¿ãŒããã VPN ãå©çšããŠæ ç¹éæ¥ç¶ãè¡ã£ãŠããå ŽåãGoogle Cloud ãèªç€Ÿã®äžæ ç¹ãšããŠè¿œå ãããããªã€ã¡ãŒãžã§æããŠãã ããã ãªããã¯ã©ã€ã¢ã³ã端æ«ããã® VPN æ¥ç¶ã SSL ãå©çšãã VPN æ¥ç¶ã¯ãµããŒããããŠããŸããã®ã§ã泚æãã ããã åè : Cloud VPN ã®æŠèŠ æ§ç¯æé ã®äŸã¯ä»¥äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp ãŸããCloud VPN ã®ãã1ã€ã®æ©èœãšã㊠Classic VPN ããããŸãããæ©èœãšããŠã¯ HA VPN ã§ã«ããŒå¯èœãªããšããŸã ç¹å®ã®æ©èœãéæšå¥š ãšãªãçºãæ¬èšäºã§ã¯åãæ±ããŸããã ãŠãŒã¹ã±ãŒã¹ HA VPN ã®ãŠãŒã¹ã±ãŒã¹ãšããŠã¯æ¬¡ã®éãã§ãã Google Cloud ã®ä»®æ³ãã·ã³ã« ãã©ã€ããŒãæ¥ç¶ ããã ããŒã¿éä¿¡ã«å¿
èŠãªåž¯åã 12Gbps (çè«å€) ããå°ãªã ãã³ãã«äžæ¬ãããäžãäžãã®åèšã§ 3Gbps ããµããŒã HA VPN ã§ã¯ãã³ãã«2æ¬ä»¥äžãæšå¥š éä¿¡é床㯠ãã¹ããšãã©ãŒã ã§è¯ã ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®æå·åã§ã¯ç¡ãã éä¿¡ã¬ãã« ã®æå·åãå©çšãã äœã³ã¹ããªãããæå€§ 99.99% ã®å¯çšæ§ãæ
ä¿ãéçšããã å©çšç¶æ³ã«ãããŸãããäžè¬çãªå°äžèŠæš¡ã®ç°å¢ã§ããã°ãåèŽããã®ã§ã¯ãªãã§ããããã éä¿¡ã«å¯ŸããŠåž¯åä¿èšŒãå¿
èŠãªå Žåã 10 GBps 以äžã®é床ãå¿
èŠãªå Žåã¯å°çšç·æ¥ç¶ã® Dedicated InterconnectãPartner Interconnect ããæ€èšãã ããã Google Cloud ã®ãããã¯ãŒã¯æ¥ç¶ã«ãããŠã©ã®ãµãŒãã¹ãéžæãããã¯ã以äžã®ãããŒãã£ãŒãããå©çšãã ãããâ» å
¬åŒ ã®æèš³ã«ãªããŸãã Google Cloud æ¥ç¶æ¹åŒã®éžæ HA VPN ã®æé HA VPN ã®æéã¯å€§ããåã㊠å©çšæé ãš éä¿¡é ã®2軞ã§èšç®ãããŸãã "å©çšæé"ã¯ãã²ãŒããŠã§ã€å©çš 1æé ããšã ãã³ãã«ã®æ° ãš å Žæ ãå å³ãããæéãçºçããŸãã "éä¿¡é"ã¯ãIPsecã®éä¿¡éã«å¿ã㊠æé¡ ã§æéãçºçããŸãã 2022幎4æçŸåšã®æéã¯ä»¥äžã§ãã â» æ±äº¬ãªãŒãžã§ã³å
ã§ã®éä¿¡ãæ³å® 1ãã³ãã« 1ã¶æããã $54.75 Google Cloud ããå€åãã®éä¿¡æ $0.14/GB èšç®äŸã§ããäŸãã°ãã³ãã«ã 2 æ¬æ¥ç¶ã 2 TB ã®ããŒã¿ããªã³ãã¬ãã¹åŽã«åä¿¡ããå Žåã«ã¯ VPN: $0.075 * 720 * 2æ¬ = $108 â 115 * 108 = Â¥12,420/æ Premium Tier to APAC: $0.14 * 2,048 GB = $286.72 â 115 * 286.72 = Â¥32,973/æ çŽ Â¥45,400/æ çšåºŠã®è²»çšã«ãªããŸã ($1 = 115åæç®) ã â»ã€ã³ã¿ãŒãããåç·ããµãŒãã¹ãããã€ãæéããªã³ãã¬ãã¹åŽã®åºå®ãããªãã¯IPæéã¯å¥éå¥çŽãå¿
èŠã§ãã ãŸã Google Cloud ãžå
¥ãããŒã¿ (å
åã) ã«é¢ããŠã¯éä¿¡æéãçºçããŸããã ææ°ã®æéã¯ä»¥äžãåç
§ãã ããã Cloud VPN ã®æé衚 ãªã³ãã¬ãã¹åŽã«ãŒã¿ãŒã®ä»æ§ HA VPN æ¥ç¶å¯èœãªãªã³ãã¬ãã¹åŽã«ãŒã¿ãŒã®ä»æ§ã¯æ¬¡ã®éãã§ãã é
ç® å
容 VPN åœ¢åŒ IPsec VPN ãããã³ã« ESP (IPsec)ã(IKE) UDP 500ãUDP 4500 â» ãã³ãã«ã¢ãŒãã® ESP ããµããŒãããŠããäº â» IKEv1 ãŸã㯠IKEv2 ããµããŒãããŠããäº NAT-T ãå©çšããå Žå 1:1 NAT çŸåšåžå Žã«æµéããŠããæ³äººåãã®äžè¬çãªã«ãŒã¿ãŒã§ããã°ãã»ãŒå¯Ÿå¿ããŠãããšæãããŸãã詳ããã¯åã¡ãŒã«ãŒã«ãåãåãããã ããã HA VPN ãæ§æããèŠçŽ HA VPN ã§ã¯å€§ããåããŠä»¥äžã®ïŒã€ã®ãªãœãŒã¹ããæãç«ã£ãŠããŸãã Cloud HA VPN ã²ãŒããŠã§ã€ Cloud Router æ€èšãã¹ãèŠçŽ ãäºé
ããèšè¿°ããŸããèšèšã®éã«ãåèãã ããã HA VPN çšèªã®ãããã Cloud VPN ã§ HA VPN æ§æãçµãå Žåã«è¯ãåºãŠããèšèãäžèšã«ãŸãšããŠãããŸããããã£ãšç¢ºèªããŠãããŠããã ããæ¹ãå
šäœã®çè§£ãæ·±ãŸãããšæããŸãã çšèª ç°¡åãªè§£èª¬ 1 AS çªå· (Autonomous System number) ISP ãªã©å€§ããªãããã¯ãŒã¯ã«å²ãåœãŠãããäžæã®èå¥çªå· 2 BGP (Border Gateway Protocol) AS ãä»ã®AS ã«åºåãããã«ãŒãã£ã³ã°ãããããããã®ãããã³ã« 3 Cloud VPN ã²ãŒããŠã§ã€ïŒIPïŒ Google Cloud ã®å€åŽ (WAN) IP ã¢ãã¬ã¹ 4 ã㢠VPN ã²ãŒããŠã§ã€ïŒIPïŒ ãªã³ãã¬ãã¹ã® å€åŽ (WAN) IP ã¢ãã¬ã¹ 5 Cloud Router ã® BGP IP IPsec VPN ã§ãã³ãã«ã匵ãæã® Google Cloud åŽ BGP çš IP ã¢ãã¬ã¹ 6 BGP ã㢠IP IPsec VPN ã§ãã³ãã«ã匵ãæã®ãªã³ãã¬ãã¹åŽã® BGPçš IP ã¢ãã¬ã¹ 7 MED å€ BGP éä¿¡ãããéã«ã©ã®ãã¹ãåªå
ãããã®éã¿ä»ã Cloud HA VPN ã²ãŒããŠã§ã€ VPN ã²ãŒããŠã§ã€ã¯ Google Cloud ã® VPC ãªãœãŒã¹ ãš ãªã³ãã¬ãã¹ãããã¯ãŒã¯ãä»ã® VPC ãªãœãŒã¹ãšæ¥ç¶ããä»®æ³çãªåºå
¥ãå£ã§ãã ã€ã³ã¿ãŒããããªã©ã®å
¬è¡ãããã¯ãŒã¯ãå©çšããä»®æ³çãªå°çšãããã¯ãŒã¯ãæ§ç¯ããããšãå¯èœãšãªã£ãŠããŸãã æ¥ç¶ãèªèšŒãæå·åã埩å·ãªã©ãæ
åœããŠããŸãã Google Cloud ã® Virtual Private Cloud (VPC) 㯠ã°ããŒãã« ã§ããäºããè€æ°ã®ãªãŒãžã§ã³ãã«ããŒããŠããŸãã ãããã£ãŠHA VPN ãå©çšããã VPC ãšåããªãŒãžã§ã³ã«ã²ãŒããŠã§ã€ãé
眮ããå¿
èŠã¯ãªããæ¥ç¶æ ç¹ããè¿ããªãŒãžã§ã³ãéžæããäºã§ GCP ã«å°éãããŸã§ã®ãããæ°ãå°ãªãããäºãåºæ¥ãŸãã VPN ã²ãŒããŠã§ã€ ã®æ§æèŠçŽ VPC: ã©ã®VPC ãšæ¥ç¶ããã ãªãŒãžã§ã³: ã©ã®ãªãŒãžã§ã³ã«é
眮ããããéžæåŸã« 倿Žãåºæ¥ãªã çºæ³šæ VPN ã²ãŒããŠã§ã€ã®ãããªã㯠IP ã¢ãã¬ã¹: Google åŽã§å²ãåœãŠããã IP VPN ãã³ãã« VPN ãã³ãã«ã§ã¯æ¥ç¶å
ã® ãããªã㯠IPã¢ãã¬ã¹ãASNãåºå ±ã«ãŒããªã©äž»ã«ãã³ããªã³ã°ã«å¿
èŠãªæ
å ±ãæå·åã«é¢ããèšå®ãè¡ããŸãã VPN ãã³ãã« ã®æ§æèŠçŽ ã㢠(æ¥ç¶å
) VPN ã²ãŒããŠã§ã€ ãªã³ãã¬ãã¹ãŸãã¯é Google Cloud Google Cloud Cloud Router Google ASN ã¢ããã¿ã€ãºã«ãŒã ã㢠VPN ã²ãŒããŠã§ã€ ã€ã³ã¿ãŒãã§ãŒã¹ 1-4ã€ã®ã€ã³ã¿ãŒãã§ãŒã¹ã®æå®ãå¯èœ IKE ã®ããŒãžã§ã³éžæãšäºåå
±æã㌠Cloud Router Cloud Router ã§ã¯ãªã³ãã¬ãã¹ãšã® BGP ã»ãã·ã§ã³ã®ç¢ºçãè¡ããŸãã ãŸãã Google Cloud ã® VPC å
ã®æ°ãããããã¯ãŒã¯ãèªåçã«åŠç¿ããªã³ãã¬ãã¹ãããã¯ãŒã¯ãžåºå ±ããŸãã BGP ã»ãã·ã§ã³ ã®æ§æèŠçŽ ã㢠ASN ãã©ã€ããŒã ASN: 64512ïœ65534 ã®å€ãèšå®ããŸãã MED Cloud Router ã® BGP IP BGP ã㢠IP 察æåŽã§èšå®ããããŒã«ã«ãªã³ã¯ã¢ãã¬ã¹ãæå®ããŸãã æ§æ HA VPN æ§æ HA VPN ã§ã¯é©åã«ã€ã³ã¿ãŒãã§ãŒã¹ãè€æ°ã®ãã³ãã«ããã¢ãªã³ã°ããäºã§ 99.99% ã®å¯çšæ§ SLA ã享åããããšãã§ããŸãã HA VPN ã§ã¯ãã³ãã«ïŒæ¬ã®éçšãå¯èœã§ããããã®å Žåã«ã¯ SLA ãåŸãäºãåºæ¥ãŸããã ãªããã® SLA é©çšæã«å®éã®çšŒåããããäžåããš Financial Credits ãåãåãããšãã§ããŸã ( åè ) ã SLA é©çšã¯ãã³ãã«ã ã㢠(ã¢ã¯ãã£ã / ã¢ã¯ãã£ã ãŸã㯠ã¢ã¯ãã£ã / ããã·ã) ã§æ§ç¯ããäºã«ããåããããšãã§ããŸãã ãããã£ãŠã以äžã®ãããªãã³ãã«1æ¬ã®ãã¿ãŒã³ã§ã¯ SLA é©çšå€ãšãªããŸãã ãã³ãã«1æ¬ã®æ§æ äžæ¹ã§ããã³ãã«ãã¢ã®æ§æã§ã¯ SLA é©çšå¯Ÿè±¡ãšãªããŸãã ãã®å Žåã®ãªã³ãã¬ãã¹åŽã®ã²ãŒããŠã§ã€è£
眮ã§ã¯1å°ã§ã2å°ã§ãããããã³ãã«ã ã㢠ã§äœæãããäºããã€ã³ãã§ä»¥äžã®ãããªæ§æã®å Žåã¯é©çšå¯Ÿè±¡ãšãªããŸãã ãã ãããªã³ãã¬ãã¹åŽã«ãŒã¿ãŒã®é害æã®å®çšçãªå¯çšæ§ãèæ
®ã«å
¥ãããšã2å°äœå¶ãæãŸãããšèšããŸãã ãã³ãã«ãã¢ã®æ§æ é«å¯çšæ§ã®ç¢ºèª HA VPN ãæ§æããã SLA 察象ãšãªã£ãŠãããã確èªããäºãåºæ¥ãŸãã 管çã³ã³ãœãŒã« ïŒ ãã€ããªããæ¥ç¶ ïŒ VPN ïŒ CLOUD VPN ã²ãŒããŠã§ã€ ïŒ ã²ãŒããŠã§ã€ã®ååãéžæ HA VPN é«å¯çšæ§ã®ç¢ºèª é«å¯çšæ§ã ⯠ã«ãªã£ãŠããã°é©çšãããŠããŸãã ã¢ã¯ãã£ã / ã¢ã¯ãã£ã ãŸã㯠ã¢ã¯ãã£ã / ããã·ã ãªã³ãã¬ãã¹ã§ IPsec VPN ãçµãã äºããã人ã§ããã°ãéåžžã¢ã¯ãã£ã / ããã·ã (ã¢ã¯ãã£ã / ã¹ã¿ã³ãã€) 㯠åç· ã®äºãã€ã¡ãŒãžããããããããŸããã Google Cloud HA VPN ã§ã¯ãã®å¶åŸ¡ã BGP ã«ãŒãã£ã³ã°ã® VPN ãã³ãã«ã® ã«ãŒãåªå
床 (MED) ãèšå®ããäºã«ãã£ãŠæ§æããŸãã ã¢ããã¿ã€ãºãããåªå
床 (MED) MED ã®å€ã¯ 0 ãã 65535 ã®æŽæ°ã§èšå®ãå€ã 0 ã«è¿ãã»ã©åªå
床ãé«ããªããŸãã ããã©ã«ãã®åºæ¬åªå
床㯠100 ãšãªã£ãŠãããäžèšã®ããã«æå®ããªãå Žåã¯ããã©ã«ãã®å€ãé©çšãããŸãã ãã³ãã«ã®çåŽã®MEDåªå
床ã倿Žããäºã«ããã¢ã¯ãã£ã / ããã·ãã®ç¶æ
ã«ãªããŸãã ãã ãããã³ãã«ã®ã¹ããŒã¿ã¹ã¯ ã¢ã¯ãã£ã ç¶æ
ã®ãŸãŸã§ããããããŸã§ãã±ãããã«ãŒããããéã®åªå
床ã®é«äœå·®ã§ãã¢ã¯ãã£ã / ããã·ãããå®çŸããŠããŸãã ã¢ã¯ãã£ã / ããã·ã deno HA VPN ã®é«å¯çšæ§ã«ã€ããŠè©³ããç¥ãããæ¹ã¯ä»¥äžãåç
§ãã ããã cloud.google.com éçšã»ãã®ã³ã° ãã°ã®ä¿åå Žæ VPN ã®ãã°ã¯ããã©ã«ãã§ç¹å®ã®ãã°ã Cloud Logging ã«éä¿¡ãããŸãã ããã©ã«ãã®ä¿åæé㯠30 æ¥éã§ãããããããé·ãæéãã°ãä¿æããã«ã¯ã _default ãã°ãã±ããã®ä¿åæéã倿Žãããããã°ãå¥ã®ã¹ãã¬ãŒãžã«è»¢éããå¿
èŠããããŸãã 転éå
ãšã㊠Pub/Sub ã BigQuery ã Cloud Storage ã ä»ã®ãã°ãã±ãããå©çšå¯èœã§ãã Cloud Logging ã®è©³çްã«ã€ããŠã¯ä»¥äžãã芧ãã ããã blog.g-gen.co.jp ã¢ã©ãŒã Cloud Monitoring ãå©çšããŠVPN ãã³ãã«ã«é¢é£ããææšã衚瀺ããã¢ã©ãŒããäœæããäºãåºæ¥ãŸãã äŸãã°ãã³ãã«ãå©çšãã垯åãäžå®ã®ãããå€ããªãŒããŒãããéç¥ãã...ãšãã£ãäºãå¯èœã§ãã äž»ãªææšãšããŠã¯æ¬¡ã®ãããªç©ããããŸãã çš®é¡ èª¬æ gateway/connections æ¥ç¶æ° VPN ã²ãŒããŠã§ã€ãããã® HA æ¥ç¶ã®æ°ã瀺ããŸãã network/dropped_received_packets_count ç Žæ£ãããåä¿¡ãã±ãã ãã³ãã«ã§ç Žæ£ãããäžãïŒå
åããã㢠VPN ããã®åä¿¡ïŒãã±ããã60 ç§ããšã«ãµã³ããªã³ã°ãããŸãããµã³ããªã³ã°åŸãããŒã¿ã¯æé· 180 ç§é衚瀺ãããŸããã network/dropped_sent_packets_count ç Žæ£ãããéä¿¡ãã±ãã ãã³ãã«ã§ç Žæ£ãããäžãïŒå€åããã㢠VPN ãžã®è»¢éïŒãã±ããã60 ç§ããšã«ãµã³ããªã³ã°ãããŸãããµã³ããªã³ã°åŸãããŒã¿ã¯æé· 180 ç§é衚瀺ãããŸããã network/received_bytes_count åä¿¡ãã€ãæ° ãã³ãã«ã®äžãïŒå
åããã㢠VPN ããã®åä¿¡ïŒãã€ãã60 ç§ããšã«ãµã³ããªã³ã°ãããŸãããµã³ããªã³ã°åŸãããŒã¿ã¯æé· 180 ç§é衚瀺ãããŸããã network/received_packets_count åä¿¡ãã±ããæ° ãã³ãã«ã®äžãïŒå
åããã㢠VPN ããã®åä¿¡ïŒãã±ããã60 ç§ããšã«ãµã³ããªã³ã°ãããŸãããµã³ããªã³ã°åŸãããŒã¿ã¯æé· 60 ç§é衚瀺ãããŸããã network/sent_bytes_count éä¿¡ãã€ãæ° ãã³ãã«ã®äžãïŒå€åããã㢠VPN ãžã®è»¢éïŒãã€ãã60 ç§ããšã«ãµã³ããªã³ã°ãããŸãããµã³ããªã³ã°åŸãããŒã¿ã¯æé· 180 ç§é衚瀺ãããŸããã network/sent_packets_count éä¿¡ãã±ãã ãã³ãã«ã®äžãïŒå€åããã㢠VPN ãžã®è»¢éïŒãã±ããã60 ç§ããšã«ãµã³ããªã³ã°ãããŸãããµã³ããªã³ã°åŸãããŒã¿ã¯æé· 60 ç§é衚瀺ãããŸããã tunnel_established 確ç«ãããã³ãã« > 0 ã®å Žåãæåãããã³ãã«ç¢ºç«ã瀺ããŠããŸãã60 ç§ããšã«ãµã³ããªã³ã°ãããŸãããµã³ããªã³ã°åŸãããŒã¿ã¯æé· 180 ç§é衚瀺ãããŸããã æž¡é å®£ä¹ (èšäºäžèЧ) ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš AI/MLãã¢ããªã±ãŒã·ã§ã³ã¢ããã€ãŒãŒã·ã§ã³ãããŒã¿åæåºç€ã®æ§ç¯ãã¯ã©ãŠã管çéçšããããã¯ãŒã¯ãªã©ã€ã³ãã©ç³»ã¯äœã§ããGoogle Workspace 掻çšãæšé²äž 鱿«ãã©ãã°ã©ãã¡ãŒã§ãèŠ³èæ€ç©ã塿 ¹æ€ç©ã«ããã£ãŠããŠçš®ããè²ãŠãŠãŸãã
ããã«ã¡ã¯ãG-gen ã®æž¡éã§ãã åäººçš Gmail ã ãã§ç¡ã Google Workspace ã®äŒæ¥çš Gmail ã§ã Google Workspace ã§å©çšããŠãããã¡ã€ã³ä»¥å€ã®ã¡ãŒã«ãåä¿¡ããäºãã§ããŸãã Google Workspace ã®ãŠãŒã¶ãŒã¢ã«ãŠã³ããšã¯å¥ã«ä»ã®ã¡ãŒã«ãµãŒããŒã§å©çšããŠããã¡ãŒã«ãäŸãã°ãããã€ãã®ã¡ãŒã«ã¢ãã¬ã¹ããå人åãã® gmail.com ã¢ã«ãŠã³ããªã©ã§ãã ãã®èšäºã§ã¯ãã®èšå®æ¹æ³ããæ¡å
ããŸãã ãŸããGoogle Workspace ã®ãŠãŒã¶ãŒã¢ã«ãŠã³ãã§å©çšããŠãããã¡ã€ã³ã®å ŽåããŠãŒã¶ãŒãšã€ãªã¢ã¹ãšããŠ30åãŸã§å¯èœã§ãã Gmail ã®èšå® Gmail ã®èšå® gmail.com ã®å Žå åäººçš Gmail ã®èšå® Google Workspace äŒæ¥çš Gmail ã®èšå® 泚æäºé
Google Workspaceãå°å
¥ãããªãæ ªåŒäŒç€ŸG-genã«ãçžè«ãã ããã Gmail ã®èšå® Google Workspace ã® Gmail ç»é¢ã«å
¥ããŸãã Gmail ã®èšå® å³äžéšã®ã®ã¢ããŒã¯ ïŒ ãã¹ãŠã®èšå®ã衚瀺 ãã¯ãªãã¯ã ã¢ã«ãŠã³ã ã¿ã ïŒ ã¡ãŒã«ã¢ã«ãŠã³ãã远å ãã 远å ãããã¡ãŒã«ã¢ãã¬ã¹ãå
¥åã 以äžã®é
ç®ãå
¥åããŸãã å
容ã«ã€ããŠã¯é©å®è¿œå ãããã¡ãŒã«ã¢ãã¬ã¹ã®èšå®æ
å ±ã«åºã¥ããŠãã ããã â» SSL ã®å©çšãå¯èœãšãªã£ãŠããŸãã â ãŠãŒã¶ãŒå â ãã¹ã¯ãŒã â POP ãµãŒã㌠â¡ããŒãçªå·ã®æå® â¢SSL ãå©çšããå Žåã¯ãã§ã㯠å
¥ååŸãã¢ã«ãŠã³ãã远å ãéžæ ã¡ãŒã«ãåä¿¡ããã ãã§ãªããGmail ããéä¿¡ããããå Žåã«ã¯ããã¯ããâ¯â¯â¯ãšããŠã¡ãŒã«ãéä¿¡ã§ãããã«ããŸãããããªã³ã«ã㊠次㞠ãã¯ãªãã¯ããŸãã ã¡ãŒã«ã®ååãå
¥åã㊠次ã®ã¹ããã ãã¯ãªã㯠ãŠã£ã³ããŠãéãã ã§èšå®ãçµäº 远å ããã¡ãŒã«ã¢ãã¬ã¹ã«ãã¹ãã¡ãŒã«ãéä¿¡ãããšä»¥äžã®ããã«åä¿¡ãããŸããã ã¡ãŒã«ã¢ã«ãŠã³ãã远å ããéã«ã©ãã«ãã€ããŠãããšãã©ã®ã¡ãŒã«ã¢ãã¬ã¹ã§åä¿¡ããããåãããããã®ã§ããããã§ãã gmail.com ã®å Žå åäººçš Gmail ã®èšå® å人çšã® gmail.com ãåãæé ã§è¿œå ããäºãå¯èœã§ãã ãã ããPOP ã§ã®åä¿¡ã«ãªããŸãã®ã§äºåã« åäººçš Gmail ã®èšå®ã§ POP ãæå¹åããŠããå¿
èŠããããŸãã åäººçš Gmail ã®èšå®ç»é¢ Google Workspace äŒæ¥çš Gmail ã®èšå® ãã¡ãã®èšå®ã¯åè¿°ãšåãæäœã«ãªããŸãã å人çšã® gmail ã¢ãã¬ã¹ãå
¥åã ãã°ã€ã³ã«å¿
èŠãªæ
å ±ãå
¥åããŸããPOP ãµãŒããŒãããŒãçªå·ãªã©ã¯èªåçã«èšå®ãããŸãã æ³šæäºé
ãã®èšå®ã«ãã£ãŠGmail ã«è€æ°ã®ã¡ãŒã«ã¢ãã¬ã¹ãéçŽãã¡ãŒã«ã¯ã©ã€ã¢ã³ããšããŠå©çšããäºãå¯èœã§ããã以äžã®äºã«ã泚æãã ããã 宿çã«Gmail â ã¡ãŒã«ãµãŒã㌠ã«ã¡ãŒã«ååŸã宿œããŠããé¢ä¿äžã¿ã€ã ãã¹ãçºçããŸãã 峿æ§ãå¿
èŠãªå Žåã¯ãšã€ãªã¢ã¹ (äŸ: test@ãã¡ã€ã³å.test-google-a.com) ã«å¯Ÿãä»ã®ã¡ãŒã«ã¢ã«ãŠã³ãããã¡ãŒã«ã転éãã圢ã§ãå©çšãã ããã ã¡ãŒã«åä¿¡å±¥æŽ Google Workspaceãå°å
¥ãããªãæ ªåŒäŒç€ŸG-genã«ãçžè«ãã ããã æ ªåŒäŒç€ŸG-genã§ã¯Google Workspace / Google CloudïŒGCPïŒã5%å²åŒã§ãæäŸããŠãããŸãã g-gen.co.jp ãŸããGoogle Workspace / Google CloudïŒGCPïŒ/ Chrome book ã®å°å
¥ããéçšãŸã§ã®ãæ¯æŽãè¡ã£ãŠããŸãã®ã§ãæ€èšã®éã«ã¯ãã²ã声ãããã ããã ãåãåããã¯ãã¡ããã docs.google.com æž¡é å®£ä¹ (èšäºäžèЧ) ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš ããŒã¿åæåºç€ã®æ§ç¯ãã¯ã©ãŠã管çéçšããããã¯ãŒã¯ãå®åç¯å²ãGoogle Workspace æŽ»çšæšé²äžãGoogle Cloud èªå®è³æ Œã¯4è³æ Œä¿æ 鱿«ãã©ãã°ã©ãã¡ãŒã§ãèŠ³èæ€ç©ã塿 ¹æ€ç©ã«ããã£ãŠãŸãã
G-genã®ææã§ãã BigQueryã§ã¯ã åã¬ãã«ã®ã¢ã¯ã»ã¹å¶åŸ¡ ã è¡ã¬ãã«ã®ã»ãã¥ãªã㣠ãšãã£ãæ©èœã䜿ãããã现ããã¢ã¯ã»ã¹å¶åŸ¡ãè¡ãããšãã§ããŸãã åã¬ãã«ã®ã¢ã¯ã»ã¹å¶åŸ¡ åã¬ãã«ã®ã¢ã¯ã»ã¹å¶åŸ¡ åé¡ãšããªã·ãŒã¿ã° å¶é è¡ã¬ãã«ã®ã»ãã¥ãªã㣠è¡ã¬ãã«ã®ã»ãã¥ãªãã£ãšã¯ è¡ã¬ãã«ã®ã¢ã¯ã»ã¹ããªã·ãŒ å¶é åã¬ãã«ã®ã¢ã¯ã»ã¹å¶åŸ¡ vs è¡ã¬ãã«ã®ã»ãã¥ãªã㣠åã¬ãã«ã®ã¢ã¯ã»ã¹å¶åŸ¡ åã¬ãã«ã®ã¢ã¯ã»ã¹å¶åŸ¡ BigQuery ã® åã¬ãã«ã®ã¢ã¯ã»ã¹å¶åŸ¡ ïŒcolumn-level access controlïŒæ©èœã¯ãäºåå®çŸ©ãã ããªã·ãŒã¿ã° ãåã«ä»äžããããšã§ãç¹å®ã® Google ã¢ã«ãŠã³ããã°ã«ãŒãã ããåã«ã¢ã¯ã»ã¹ã§ããããã«ããä»çµã¿ã§ããåœæ©èœã¯åŸæ¥ãåã¬ãã«ã®ã»ãã¥ãªãã£ïŒcolumn-level securityïŒãšãåŒã°ããŠããŸããã äŸãšããŠã BigQuery ããŒãã«ã®å人æ
å ±ãå«ãåã« security-level : high ã®ãããªã¿ã°ãä»äžããŠããã®ã¿ã°ãã€ããŠããåã«ã¯ manager@example.com ã°ã«ãŒãã®ã¡ã³ããŒããã¢ã¯ã»ã¹ã§ããªãããã«ããããšãã£ãå¶åŸ¡ãå¯èœã§ãã ã¢ã¯ã»ã¹ããªã·ãŒã¯ SQL ãå®è¡ããéã«è©äŸ¡ãããèš±å¯ãããŠããªãã¡ã³ããŒããã®ã¯ãšãªã¯ Access Denied ãšããŠæåŠãããŸãã åè : åã¬ãã«ã®ã¢ã¯ã»ã¹å¶åŸ¡ åã¬ãã«ã®ã¢ã¯ã»ã¹å¶åŸ¡ åé¡ãšããªã·ãŒã¿ã° åã¬ãã«ã®ã¢ã¯ã»ã¹å¶åŸ¡ã§ã¯ãäºåã« åé¡ ïŒTaxonomyïŒãäœæããŸããåé¡ã®äžã«ã¯è€æ°ã® ããªã·ãŒã¿ã° ãå容ã§ããŸãã äœæããããªã·ãŒã¿ã°ã«ã¯ãIAM ããŒã«ãçŽã¥ããããšãã§ããŸããããªã·ãŒã¿ã°ã«ãããŠãGoogle ã¢ã«ãŠã³ããã°ã«ãŒããããã现ããèªã¿åãïŒ roles/datacatalog.categoryFineGrainedReader ïŒããŒã«ãçãšçŽã¥ããããšã§ããã®ããªã·ãŒã¿ã°ãã¢ã¿ãããããåãžã®ã¢ã¯ã»ã¹ãèš±å¯ããããšãå¯èœã§ãã åé¡ãšããªã·ãŒã¿ã° ãã®ããªã·ãŒã¿ã°ãããŒãã«ã®åãã¢ã¿ããããããšã§ãIAM ã§èš±å¯ãããã¢ã«ãŠã³ããã°ã«ãŒãã®ã¿ããåãžã¢ã¯ã»ã¹ã§ããããã«ãªããŸãã åãžããªã·ãŒã¿ã°ãã¢ã¿ãã åè : åã¬ãã«ã®ã¢ã¯ã»ã¹å¶åŸ¡ã«ããã¢ã¯ã»ã¹å¶é åè : BigQuery ã§ããªã·ãŒã¿ã°ã䜿çšããéã®ãã¹ã ãã©ã¯ãã£ã¹ ãªããããªã·ãŒã¿ã°ã«ã¯ãåããªã·ãŒã¿ã°ïŒãµãã¿ã°ïŒããäœãããšãã§ãã5段éãŸã§ãã¹ãã§ããŸãã芪ããªã·ãŒã¿ã°ãžã®ã¢ã¯ã»ã¹æš©éãæã£ãŠããã°ãæš©éã¯åãžç¶æ¿ãããåããªã·ãŒã¿ã°ãžã®ã¢ã¯ã»ã¹ãå¯èœã§ãã åè : Google Cloudã®IAMã培åºè§£èª¬ïŒ - G-gen Tech Blog - ç¶æ¿ å¶é åã¬ãã«ã®ã¢ã¯ã»ã¹å¶åŸ¡ã«ã¯ã以äžã®ãããªå¶éããããŸãã BigQuery Editions ã® Standard ãšãã£ã·ã§ã³ã§ã¯å©çšã§ããªãïŒãªã³ããã³ããEnterpriseãEnterprise Plus ã§ã¯å©çšå¯èœïŒ 1ã€ã®åã«ã¢ã¿ããã§ããããªã·ãŒã¿ã°ã¯1ã€ã ã 1ã€ã®ããŒãã«ã«ã¢ã¿ããå¯èœãªããªã·ãŒã¿ã°ã®çš®é¡ã¯æå€§1,000åãŸã§ ããªã·ãŒã¿ã°ã1ã€ã§ãã€ããŠãããšãã®ããŒãã«ã§ã¯ Legacy SQL ã䜿ããªã ãããåã«ã¯ããªã·ãŒã¿ã°ã1ã€ããã¢ã¿ããã§ããªãããšããå¶éããããããã¢ã¯ã»ã¹å¶åŸ¡ãè€éã«ãªããããªãããã«ãåé¡ãšããªã·ãŒã¿ã°äœæã«ã¯å·¥å€«ãå¿
èŠã§ãã åè : åã¬ãã«ã®ã¢ã¯ã»ã¹å¶åŸ¡ã®æŠèŠ - å¶éäºé
è¡ã¬ãã«ã®ã»ãã¥ãªã㣠è¡ã¬ãã«ã®ã»ãã¥ãªãã£ãšã¯ è¡ã¬ãã«ã®ã»ãã¥ãªã㣠ïŒrow-level securityïŒã¯ãããŒãã«ã« è¡ã¬ãã«ã®ã¢ã¯ã»ã¹ããªã·ãŒ ãèšå®ããããšã§ãGoogle ã¢ã«ãŠã³ããã°ã«ãŒãã«å¯ŸããŠã ç¹å®ã®å€ãæã£ãè¡ã«ã ã ã¢ã¯ã»ã¹ã§ããããã«å¶åŸ¡ããæ©èœã§ãã äŸãšããŠã顧客æ
å ±ããŒãã«ã«ãããŠãå°åæ
å ±ãæ ŒçŽãããŠãã region åã®å€ã Kanto ãªã颿±å°åæ
åœã®ã»ãŒã«ã¹ããŒã ã«ã ãè¡ãèŠããããã«ããé¢è¥¿æ
åœããŒã ããã¯èŠããªãããã«ããããšãã£ãããšãå¯èœã§ãã ã¢ã¯ã»ã¹ããªã·ãŒã¯ SQL ãå®è¡ããéã«è©äŸ¡ãããèš±å¯ãããŠããªãè¡ã¯ã¯ãšãªçµæããåãé€ãããŸãã åè : BigQuery ã®è¡ã¬ãã«ã®ã»ãã¥ãªãã£ã®æŠèŠ è¡ã¬ãã«ã®ã»ãã¥ãªã㣠è¡ã¬ãã«ã®ã¢ã¯ã»ã¹ããªã·ãŒ è¡ã¬ãã«ã®ã¢ã¯ã»ã¹ããªã·ãŒ ã¯ã CREATE ROW ACCESS POLICY æãå®è¡ããŠäœæããŸãã åè : è¡ã¬ãã«ã®ã»ãã¥ãªãã£ã䜿çšãã 以äžã¯ãè¡ã¬ãã«ã®ã¢ã¯ã»ã¹ããªã·ãŒãäœæããããã®æ§æã®äŸã§ãã CREATE ROW ACCESS POLICY region ON `myproject.mydataset.user_table` GRANT TO ( " group:team-kanto@example.com " ) FILTER USING (region = " Kanto " ); ãŸã以äžã®ãããªæå®ãå¯èœã§ãã CREATE ROW ACCESS POLICY region ON `myproject.mydataset.employee_table` GRANT TO ( " domain:example.com " ) FILTER USING ( emp_email = SESSION_USER() ); äžã®äŸã§ã¯ãFILTER å¥ã§æå®ãã emp_email åã®å€ã SESSION_USER() ãšããŠããŸãããã㯠BigQuery ã® SESSION_USER 颿°ã§ããããã«ãããSQL ãå®è¡ããã¡ãŒã«ã¢ãã¬ã¹ãååŸããŠããŸãããã®äŸã§ã¯ãåŸæ¥å¡ãèªåã®ããŒã¿ã ããã瀟å¡äžèЧããŒãã«ããåŸãããããã«ãªããŸãã åè : Security functions - SESSION_USER å¶é è¡ã¬ãã«ã®ã»ãã¥ãªãã£ã«ã¯ã以äžã®ãããªå¶éããããŸãã BigQuery Editions ã® Standard ãšãã£ã·ã§ã³ã§ã¯å©çšã§ããªãïŒãªã³ããã³ããEnterpriseãEnterprise Plus ã§ã¯å©çšå¯èœïŒ ã¯ãšãªããã©ãŒãã³ã¹ãè¥å¹²äœäžãã è¡ã¬ãã«ã®ã»ãã¥ãªãã£ã¯ãJSON åã®åã«ã¯äœ¿ããªã è¡ã¬ãã«ã®ã»ãã¥ãªãã£ãé©çšãããŠãããšãã¯ã€ã«ãã«ãŒãããŒãã«ã¯ãšãªã䜿ããªã ãã¹ãŠã®å¶éäºé
ã®äžèЧã¯ã以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : BigQuery ã®è¡ã¬ãã«ã®ã»ãã¥ãªãã£ã®æŠèŠ - å¶éäºé
åã¬ãã«ã®ã¢ã¯ã»ã¹å¶åŸ¡ vs è¡ã¬ãã«ã®ã»ãã¥ãªã㣠åã¬ãã«ã®ã¢ã¯ã»ã¹å¶åŸ¡ãšãè¡ã¬ãã«ã®ã»ãã¥ãªãã£ã¯äžèŠäŒŒãŠããŸããããŠãŒã¹ã±ãŒã¹ã®éãã¯æçœã§ãã ç¹å®ã® Google ã¢ã«ãŠã³ããã°ã«ãŒãã«ã¯ãç¹å®ã®åããåããšèŠããããªããšãã«ã¯ãåã¬ãã«ã®ã¢ã¯ã»ã¹å¶åŸ¡ã䜿ããŸããäŸãšããŠãå人æ
å ±ãæ ŒçŽãããŠããåãæ©å¯æ
å ±ãæ ŒçŽãããŠããåãªã©ã§ãã äžæ¹ã§ãåå
šäœã§ã¯ãªããåã®å€ã«ãã£ãŠèŠããè¡ãåããããšãã«ãè¡ã¬ãã«ã®ã»ãã¥ãªãã£ã䜿ããŸããäŸãã°ãã»ãŒã«ã¹ããŒã ã®ã°ã«ãŒãã«ã¯ãéšçœ²ãåã« sales ãšããå€ãå
¥ã£ãŠããè¡ã ããèŠãããæãªã©ã§ãã ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãX (æ§ Twitter) ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-gen ã®ææã§ãã ãããªãã¯ã¯ã©ãŠããšããŠæäŸããããªããžã§ã¯ãã¹ãã¬ãŒãžã®äºå€§å·šé ã Cloud Storage (Google Cloud) ãš Amazon S3 (AWS) ãæ¯èŒããŠã¿ãŸããã éåžžã«ãã䌌ãŠãããµãŒãã¹ã§ãããã©ã®ãããªéããããã®ã§ããããã Cloud Storage vs Amazon S3 Cloud Storage / Amazon S3 ãšã¯ å
±éç¹ åºæ¬ã¹ããã¯ ç®¡çæ©èœã»ä»å æ©èœ ã¹ãã¬ãŒãžã¯ã©ã¹ãšæéã®éã ã¹ãã¬ãŒãžã¯ã©ã¹ã®éã ã¹ãã¬ãŒãžã¯ã©ã¹ããšã®æé æšæºã¹ãã¬ãŒãž Nearline / Infrequent Access Coldline / Glacier Instant Retrieval / Glacier Flexible Retrieval Archive / Glacier Deep Archive ãããã¯ãŒã¯æé æå·åã®éã ãã±ããã®ãªãŒãžã§ã³ ããŒã¿é£æº AWS ã®å Žå Google Cloud ã®å Žå Amazon S3 vs Cloud Storage Cloud Storage / Amazon S3 ãšã¯ Cloud Storage ãšã¯ Google Cloud (æ§ç§° GCP) ãæäŸãããªããžã§ã¯ãã¹ãã¬ãŒãžãµãŒãã¹ã§ãã äžæ¹ã§ Amazon S3 㯠Amazon Web Services (AWS) ãæäŸãããªããžã§ã¯ãã¹ãã¬ãŒãžãµãŒãã¹ã§ãã ããã2ã€ã®ãµãŒãã¹ã¯ãã䌌ãŠãããæ¯èŒå¯Ÿè±¡ã«ããªããŸãã ãªããžã§ã¯ãã¹ãã¬ãŒãžãäœãããŸã Cloud Storage ã®è©³çްã«ã€ããŠã¯ä»¥äžã®èšäºã«ãŠè§£èª¬ããŠããŸãã®ã§ãåç
§ãã ããã å
±éç¹ åºæ¬ã¹ãã㯠Cloud Storage ãš Amazon S3 ã¯ãšãã«ãªããžã§ã¯ãã¹ãã¬ãŒãž (ããŒã»ããªã¥ãŒã¹ãã¢) ã§ãã ãã±ãã ã ãªããžã§ã¯ã ãšããæŠå¿µã ãã©ãããªæ§æ ã Web API ã«ãã I/O ãªã©ã®å
±éç¹ããããŸãã ãŸãã以äžã®ãããªåºæ¬æ§èœãå
±éããŠããŸãã 容éç¡å¶é 99.999999999% (ã€ã¬ãã³ãã€ã³) ã®èä¹
æ§ è€æ°ã®ããŒã¿ã»ã³ã¿ãŒã«åé·å 1 ãªããžã§ã¯ãã®æå€§ãµã€ãºã¯ 5 TiB IAM ããªããžã§ã¯ãã¬ãã« ACL ã«ããã¢ã¯ã»ã¹å¶åŸ¡ ããŒã¿ä¿ç®¡æéã«å ããªã¯ãšã¹ãåæ°ã«å¯Ÿããæéããããã¯ãŒã¯å©çšæéãããããªã©ã®èª²éäœç³» Read-after-Write ã®åŒ·ãæŽåæ§ ãããã®ããšããããŠãŒã¹ã±ãŒã¹ãã»ãŒåãã§ãããåºæ¬çãªæ§èœã§ã¯ã©ã¡ããåŒããåããªããã®ã ãšããããšãåãããŸãã ç®¡çæ©èœã»ä»å æ©èœ 以äžã®ãããªç®¡çæ©èœãå
±éã§ãã ç£æ»ãã° ã©ã€ããµã€ã¯ã«ç®¡ç (èªåã§ã¹ãã¬ãŒãžã¯ã©ã¹ã倿Žãããå€ããã¡ã€ã«ãåé€) ãªããžã§ã¯ããžã®ã¡ã¿ããŒã¿ä»äž ã¡ããªã¯ã¹ã®ã¢ãã¿ãªã³ã° èŠå¶/æ³ä»€å¯Ÿå¿ã®ããã®åé€ãã㯠ãã®ä»ã«ã以äžã®ãããªæ©èœãå
±éããŠããŸãã éçãŠã§ããµã€ããã¹ãã£ã³ã°æ©èœ ãªããžã§ã¯ã倿Žãããªã¬ãšããã¡ãã»ãŒãžãã¥ãŒã€ã³ã°ãµãŒãã¹ãžã®éç¥ ã¹ãã¬ãŒãžã¯ã©ã¹ãšæéã®éã ã¹ãã¬ãŒãžã¯ã©ã¹ã®éã Cloud Storage ãš Amazon S3 ã¯ãšãã« ã¹ãã¬ãŒãžã¯ã©ã¹ ã®æŠå¿µãæã£ãŠãããä¿ç®¡æéãã¢ã¯ã»ã¹é »åºŠã«ãã䜿ãåããŸãã é »ç¹ã«ã¢ã¯ã»ã¹ããããªããžã§ã¯ããé
眮ããæšæºçãªã¹ãã¬ãŒãžã®ã»ããã¢ã¯ã»ã¹é »åºŠãäœããã¡ã€ã«ãé
眮ããã¹ãã¬ãŒãžããã£ãã«ã¢ã¯ã»ã¹ãããªãã¢ãŒã«ã€ãçšã®ã¹ãã¬ãŒãžãªã©ããããŸãã ã¢ãŒã«ã€ãå¯ãã®ã¯ã©ã¹ã»ã©ãä¿åããŒã¿ãµã€ãºã«å¯Ÿããæéã¯å®ãåé¢ãæžã蟌ã¿ã»èªã¿åããªã¯ãšã¹ãåæ°ãåãåºãããŒã¿éã«å¯Ÿããæéãé«ãããšã§ãã©ã³ã¹ãåãããŠããŸãã Cloud Storage ãš Amazon S3 ã®ã¹ãã¬ãŒãžã¯ã©ã¹ãæ¯èŒãããšä»¥äžã®ããã«ãªããŸãã (ããããæ±äº¬ãªãŒãžã§ã³ã 2022 幎 3 æçŸåš) Cloud Storage ( æéããŒãž ) ( ã¹ãã¬ãŒãžã¯ã©ã¹ã«é¢ããããã¥ã¡ã³ã ) ã¹ãã¬ãŒãžã¯ã©ã¹ ä¿ç®¡æé (GB/æ) æäœä¿ç®¡æé ã¬ã€ãã³ã· Standard Storage $0.023 ãªã ããªç§ã¬ãã« Nearline Storage $0.016 30 days ããªç§ã¬ãã« Coldline Storage $0.006 90 days ããªç§ã¬ãã« Archive Storage $0.0025 365 days ããªç§ã¬ãã« Amazon S3 ( æéããŒãž ) ( ã¹ãã¬ãŒãžã¯ã©ã¹ã«é¢ããããã¥ã¡ã³ã ) ã¹ãã¬ãŒãžã¯ã©ã¹ ä¿ç®¡æé (GB/æ) æäœä¿ç®¡æé ã¬ã€ãã³ã· S3 Standard $0.025 (æåã® 50 TB) $0.024 (次㮠450 TB) $0.023 (500 TB 以äž) ãªã ããªç§ã¬ãã« S3 Standard - Infrequent Access $0.0138 30 days ããªç§ã¬ãã« S3 One Zone - Infrequent Access $0.011 30 days ããªç§ã¬ãã« S3 Glacier Instant Retrieval $0.005 90 days ããªç§ã¬ãã« S3 Glacier Flexible Retrieval $0.0045 90 days æ°åããæ°æé S3 Glacier Deep Archive $0.002 180 days æ°æé S3 Intelligent - Tiering (æéããŒãžåç
§) - - 现ããªéãã¯ãããŸãããæŠããæšæºã¹ãã¬ãŒãžãã30æ¥çšåºŠä¿ç®¡ã»æ1åçšåºŠã®ã¢ã¯ã»ã¹åãã®ã¹ãã¬ãŒãžãã90æ¥çšåºŠä¿ç®¡ã»ååæã«äžåºŠçšåºŠã®ã¢ã¯ã»ã¹åãã®ã¹ãã¬ãŒãžãã幎åäœã®é·æä¿ç®¡åãã®æãå®äŸ¡ãªã¹ãã¬ãŒãžããã©ã¡ãã«ãçšæãããŠããããšãåãããŸãã äžæ¹ã§ Amazon S3 ã®ã»ããéžæã§ããã¹ãã¬ãŒãžã¯ã©ã¹ãå€ãããŠãŒã¹ã±ãŒã¹ã«å¿ããŠããæè»ã«éžæããããšãã§ããŸãã ãŸã S3 Intelligent - Tiering ãšããã¯ã©ã¹ãååšããããã¯ãªããžã§ã¯ãã®ã¢ã¯ã»ã¹é »åºŠã«ãã£ãŠèªåçã«æé©ãªã¹ãã¬ãŒãžã¯ã©ã¹ã«æ¯ãåããŠãããæ©èœã§ã (ãããæ±ããšããŠã¯ S3 Intelligent - Tiering èªäœãã¹ãã¬ãŒãžã¯ã©ã¹ã®äžçš®ã«äœçœ®ã¥ããããŠããŸã) ã ãªããæäœä¿ç®¡æéãã®æå³ã«ã€ããŠã¯ã Cloud Storage / Amazon S3 ãšãã«ããªããžã§ã¯ããçæããŠãããã®æ¥æ°ãè¶
ããªããã¡ã«ãªããžã§ã¯ããåé€çãããšããã®æ¥æ°åã®ä¿ç®¡æéããããããšããä»çµã¿ã«ãªã£ãŠããŸãã ãŸã倧ããªéããšããŠã¯ Cloud Storage ã® Archive Storage ã§ã¯ããªããžã§ã¯ãååŸã«ãããæéã ããªç§åäœ ãšãããŠããããšã§ãã äžæ¹ã§ Amazon S3 ã® Glacier ã§ã¯ Flexible Retrieval ã§ æ°åããæ°æéåäœ ã Glacier Deep Archive ã§ æ°æéåäœ ã§ã (å©çšãããªãã·ã§ã³ã«ãã£ãŠãå€ãããŸã) ã ã¹ãã¬ãŒãžã¯ã©ã¹ããšã®æé åè¿°ã®è¡šã§ã¯ããŒã¿ãµã€ãºã«å¯ŸããŠãããä¿ç®¡æéã®ã¿ãèšèŒããŸããã ããã Cloud Storage / Amazon S3 ã®äž¡æ¹ã§ãã»ãã«ãããªã¯ãšã¹ãåæ°ã«å¯Ÿãã課éããããŒã¿åãåºãéã«å¯Ÿãã課éãããããã¯ãŒã¯å©çšã«å¯Ÿãã課éããååšããŸãã ãããã«ã€ããŠãæ¯èŒããŠã¿ãŸãããããã 2022 幎 3 æçŸåšã®æ±äº¬ãªãŒãžã§ã³ã®æéãèšèŒããŠãããŸãã æšæºã¹ãã¬ãŒãž ãŸãã¯ æšæºã¹ãã¬ãŒãž ã®æéã§ãã ã¹ãã¬ãŒãžã¯ã©ã¹ ä¿ç®¡æé(GB/æ) æžèŸŒ(/1,000å) èªå(/ 1,000å) ããŒã¿ååºãªã¯ãšã¹ã(/ 1,000å) ããŒã¿ååºé (GB) æäœä¿ç®¡æé Cloud Storage - Standard $0.023 $0.005 $0.0004 ãªã ãªã ãªã Amazon S3 - Standard ã» $0.025 (æåã® 50 TB) ã» $0.024 (次㮠450 TB) ã» $0.023 (500 TB 以äž) $0.0047 $0.00037 ãªã ãªã ãªã ããŒã¿ä¿åæéãæžèŸŒ/èªåãªã¯ãšã¹ãæ°ã«å¯Ÿããæéã«è¥å¹²ã®éãã¯ãããŸãããã»ãŒåçã¯ã©ã¹ãšãããŸãã ãŸã Amazon S3 ã§ã¯ããŒã¿ä¿ç®¡éã倧ãããªãã«ã€ããåäœãããã®æéãå®ããªã£ãŠããŸãã Nearline / Infrequent Access 次㫠Cloud Storage ã® Nearline Storage ãš Amazon S3 ã® Infrequent Access (Standard ãš One Zone ã®2çš®é¡) ã®éãã§ãã ãããã®ã¹ãã¬ãŒãžã¯ã©ã¹ã¯ãæšæºã¹ãã¬ãŒãžããã¯ã¢ã¯ã»ã¹é »åºŠãäœããããŸã£ããã¢ã¯ã»ã¹ãç¡ãããã§ããªã... æŠãæã«1ãæ°åçšåºŠã®ã¢ã¯ã»ã¹ããããªããžã§ã¯ããå
¥ããããã®ã¯ã©ã¹ã§ãã ããã¯ã¢ããçšéãçœå®³å¯Ÿççšéããã°ã®é·æä¿åãªã©ã«é©ããŠããŸãã ã¹ãã¬ãŒãžã¯ã©ã¹ ä¿ç®¡æé(GB/æ) æžèŸŒ(/1,000å) èªå(/ 1,000å) ããŒã¿ååºãªã¯ãšã¹ã(/ 1,000å) ããŒã¿ååºé (GB) æäœä¿ç®¡æé Cloud Storage - Nearline $0.016 $0.01 $0.001 ãªã $0.01 30 days Amazon S3 - Standard - Infrequent Access $0.0138 $0.01 $0.001 ãªã $0.01 30 days Amazon S3 - One Zone - Infrequent Access $0.011 $0.01 $0.001 ãªã $0.01 30 days ãã¡ãã¯ãè¥å¹² Amazon S3 ã®ã»ããå®ããªã£ãŠããŸãã ãªã Amazon S3 ã® Standard - Infrequent Access ãš One Zone - Infrequent Access ã®éãã§ãããåŸè
ã¯åé·æ§ã 1 ãŸãŒã³ã«éããŠãããããŒã¿ã®å¯çšæ§ã»å
ç¢æ§ãäžãã代ããã«ããå®ãæéã§æäŸãããŠããŸãã Coldline / Glacier Instant Retrieval / Glacier Flexible Retrieval 次㫠Cloud Storage ã® Coldline Storage ãš Amazon S3 ã® Glacier Instant Retrieval ããã³ Glacier Flexible Retrieval ãæ¯èŒããŸãã ãããã®ã¹ãã¬ãŒãžã¯ã©ã¹ã¯ãæŠã3ã¶æã«äžåºŠä»¥äžçšåºŠã®ã¢ã¯ã»ã¹é »åºŠã®ãªããžã§ã¯ããé
眮ããããã®ã¯ã©ã¹ã§ãã ã¹ãã¬ãŒãžã¯ã©ã¹ ä¿ç®¡æé(GB/æ) æžèŸŒ(/1,000å) èªå(/ 1,000å) ããŒã¿ååºãªã¯ãšã¹ã(/ 1,000å) ããŒã¿ååºé (GB) æäœä¿ç®¡æé ååŸã«ãããæé Cloud Storage - Coldline $0.006 $0.01 $0.005 ãªã $0.02 90 days ããªç§ã¬ãã« Amazon S3 - Glacier Instant Retrieval $0.005 $0.02 $0.01 ãªã $0.03 90 days ããªç§ã¬ãã« Amazon S3 - Glacier Flexible Retrieval $0.0045 $0.03426 $0.00037 $11.00 (Expedited) $0.033 (Expedited) 90 days 1ã5 å以å
(Expedited) Cloud Storage ã® Coldline ãš Amazon S3 ã® Glacier Instant Retrieval ãåæ Œã ãšèããŠè¯ãã§ãããã ããŒã¿ãµã€ãºã«å¯Ÿããæéã¯è¥å¹² Glacier Instant Retrieval ã®æ¹ãå®ããªã£ãŠããŸãããåãåºãã«ãããæéç㯠Cloud Storage - Coldline Storage ã®ã»ããå®ãã§ãã Amazon S3 ã® Glacier Flexible Retrieval ã¯åãåºãã®ããã®ãªãã·ã§ã³ãè€æ°ãããŸãããä»å㯠Cloud Storage ã«åãããŠçŽ æ©ãåãåºããå¯èœãª Expedited ã¢ãŒãã®æéãèšèŒããŸããã ã»ãã«ã 3ã5 æéåäœã§åãåºãå¯èœãª Standard ã¢ãŒãã 3ã12 æéçšåºŠ ããããäžæ¬åãåºãã«é©ãã Bulk ã¢ãŒããªã©ããããŸã ( ããã¥ã¡ã³ã ) ã Archive / Glacier Deep Archive æåŸã« Cloud Storage ã® Archive Storage ãš Amazon S3 ã® Glacier Deep Archive ãæ¯èŒããŸãã ãããã®ã¹ãã¬ãŒãžã¯ã©ã¹ã¯ãæŠã幎åäœã«äžåºŠä»¥äžã®ã¢ã¯ã»ã¹é »åºŠã®ãªããžã§ã¯ããé
眮ããããã®ã¯ã©ã¹ã§ãã ã¹ãã¬ãŒãžã¯ã©ã¹ ä¿ç®¡æé(GB/æ) æžèŸŒ(/1,000å) èªå(/ 1,000å) ããŒã¿ååºãªã¯ãšã¹ã(/ 1,000å) ããŒã¿ååºé (GB) æäœä¿ç®¡æé ååŸã«ãããæé Cloud Storage - Archive $0.0025 $0.50 $0.50 ãªã $0.05 365 days ããªç§ã¬ãã« Amazon S3 - Glacier Deep Archive $0.002 $0.065 $0.00037 $0.1142 (Standard) $0.022 180 days 3ã5 æé (Standard) ããã§ãæéã«ã¯å
ããªéãããããããŒã¿ä¿ç®¡æé㯠Glacier ã®æ¹ãè¥å¹²å®ãã§ãããåãåºãã«ãããéé¡ã¯ Cloud Storage ã®æ¹ãå®ããªã£ãŠããŸãã ãã®ä»ã®å€§ããªéã㯠Cloud Storage - Archive Storage 㯠ããªç§ã¬ãã«ã®ã¬ã€ãã³ã· ã§ããã®ã«å¯Ÿãã Amazon S3 - Glacier Deep Archive ã¯ æ°æéãå¿
èŠ ãªç¹ã§ãã åè¿°ã®éã Glacier ã«ã¯è€æ°ã®åãåºãã¿ã€ãããããŸããã Deep Archive ã§ã¯ Expedited ã¢ãŒãã¯äœ¿ãã Standard ã Bulk ã«ãªããŸãã ãããŸã§èšèŒããããã«ã Cloud Storage ãš Amazon S3 ã§ã¯æéé¢ã§è¥å¹²ã®å·®ããããŸãã åŸåãšããŠã¯ããŒã¿ãµã€ãºã«å¯Ÿããæé㯠Amazon S3 ã®æ¹ãè¥å¹²å®ãããªã¯ãšã¹ãæ°ã«å¯Ÿããæé㯠Cloud Storage ã®æ¹ãè¥å¹²å®ãã§ãã å·®ãå°ãããšã¯ãã ããŒã¿ä¿ç®¡ããªã¥ãŒã ãããªã巚倧ãªå Žå ããã¢ããªã±ãŒã·ã§ã³ããã® ã¢ã¯ã»ã¹é »åºŠãããªãå€ãå Žå ã¯ãå·®ãåºãŠããããšã«ãªããŸãã ãããã¯ãŒã¯æé Cloud Storage / Amazon S3 ã®äž¡æ¹ã§ãã¹ãã¬ãŒãžãžã®ããŒã¿ã®ã¢ããããŒããç¡æãªäžæ¹ã ã¹ãã¬ãŒãžããã®ããŠã³ããŒã ã®ããªã¥ãŒã ã«å¿ããŠæéãçºçããŸãã Cloud Storage ãã£ã¢ æé 0 - 1 TB $0.12 1 - 10 TB $0.11 10 TB - $0.08 Amazon S3 ãã£ã¢ æé 0 - 10 TB $0.114 per GB 10 - 50 TB $0.089 per GB 50 - 150 TB $0.086 per GB 150 TB - $0.084 per GB ããããæ¯ã¹ããšã倧ããªéãã¯ãªããããŒã¿è»¢éããªã¥ãŒã ãããªã巚倧ã«ãªã£ããšãã«å·®ãåºãŠããŸãã ãªããã€ã³ããšããŠãAmazon S3 ã«ã¯ æ 100 GB ãŸã§ã®ããŒã¿è»¢ééã®ç¡ææ ããããŸãã (ãã®å©çšæ 㯠Amazon S3 ã ãã§ãªã Amazon EC2 ãªã©ä»ã®ãµãŒãã¹ãšãå
±æãããŸãã) å°ãäžèŠæš¡ã®å©çšã§ããã°ããã®ç¡ææ ã§å€§åãè³ããã§ãããã äžæ¹ã§ Google Cloud Storage ã§ã¯ ãæã« 1 GB ã®ããŒã¿è»¢ééããæ 5 GB ã®ããŒã¿ä¿ç®¡éããæ 5,000 åã®æžã蟌ã¿ãªã¯ãšã¹ãããæ 50,000 åã®èªã¿èŸŒã¿ãªã¯ãšã¹ããã®ç¡ææ ããããã®ã®ãããé©çšãããã®ã¯ us-east1, us-west1, us-central1 ã® 3 ãªãŒãžã§ã³ã ã ã§ããæ¥æ¬ã®ãŠãŒã¶ãŒãæã䜿ãã§ãããæ±äº¬ã»å€§éªãªãŒãžã§ã³ã§ã¯é©çšãããŸãã (2022 幎 3 æçŸåš) ã æå·åã®éã Cloud Storage ã§ã¯ å
šãŠã®ããŒã¿ãããã©ã«ãã§ãµãŒããµã€ãã§æå·å ãããŸãã ãã®æå·å㯠ç¡å¹åããããšãã§ããŸãã ã®ã§ Cloud Storage ã§ã¯å¿
ãä¿åæã®ããŒã¿ãæå·åãããããšã«ãªããŸãã ããã©ã«ãã§ã¯ Google ã管çããæå·åéµãå©çšãããŸããããŠãŒã¶æã¡èŸŒã¿ã®éµãå©çšããããšãå¯èœã§ãã äžæ¹ã§ Amazon S3 ã§ã¯æå·åã¯ãªãã·ã§ã³ã§ãã ãªãã«ããããšãã§ããŸã ã ãã±ããããšã®èšå®ãšããŠæå·åãããã©ã«ããšããéžæãå¯èœãªã»ãããªããžã§ã¯ãããšã«æå·åã®æç¡ãéžæã§ããŸãã Amazon S3 ã§ã Amazon ã管çããæå·åéµãå©çšãããããŠãŒã¶æã¡èŸŒã¿ã®éµãå©çšããããšãå¯èœã§ãã æå·åã®éããšããç¹ã§ã¯ Cloud Storage ã§ã¯æå·åããããããªãã«ã§ããªããããèšå®æŒãçãæªç¶ã«é²ãããšãã§ãããšãããŸãã ãã±ããã®ãªãŒãžã§ã³ Cloud Storage ã Amazon S3 ãšãã«ãã±ããäœææã«ãªãŒãžã§ã³ãæå®ããŸãã Amazon S3 ã§ã¯åäžã®ãªãŒãžã§ã³ãæå®ããäžæ¹ã Cloud Storage ã§ã¯ åäžãªãŒãžã§ã³ã®ä»ã«ã ãã¥ã¢ã«ãªãŒãžã§ã³ ãã ãã«ããªãŒãžã§ã³ ããéžæã§ããŸãã ãã¥ã¢ã«ãªãŒãžã§ã³ããã«ããªãŒãžã§ã³ãæå®ãããšãããŒã¿ã¯è€æ°ã®ãªãŒãžã§ã³ã«éåæã§èªåçã«ã¬ããªã±ãŒã·ã§ã³ãããŸãã ãªãŒãžã§ã³éã§ããŒã¿ãã³ããŒããç®çãšããŠã¯ã DR ç®çã§ã®å
ç¢æ§ã»å¯çšæ§ã®åäžããåœãè·šãã§å©çšãããã¢ããªã±ãŒã·ã§ã³ããŠã§ããµã€ãã®ããã«ã¬ã€ãã³ã·ãå°ããããããšãæããããŸãã Amazon S3 ã§ãæç€ºçã« ã¯ãã¹ãªãŒãžã§ã³ã¬ããªã±ãŒã·ã§ã³ ãèšå®ããã°åæ§ã®ããšãå¯èœã§ãã Cloud Storage ã®æ¹ããåã«ãã±ããã®èšå®ããã«ããªãŒãžã§ã³/ã¯ãã¹ãªãŒãžã§ã³ãšããã ãã§ãªãŒãžã§ã³éã³ããŒãå¯èœã§ããããã€ã¢ããªã±ãŒã·ã§ã³ãå©çšè
åŽããã¯ééçã«äžã€ã®ãã±ããã»äžã€ã®ãªããžã§ã¯ããæå®ããã ãã§æžãããããã å®è£
ãã·ã³ãã« ã«ãªããšãããŸãã ããŒã¿é£æº AWS ã®å Žå Amazon S3 㯠ãããŒãžãã® RDB ãµãŒãã¹ã§ãã Amazon RDS ã Amazon Aurora ãããŒã¿ãŠã§ã¢ããŠã¹ã§ãã Amazon Redshift ãšã®ããŒã¿é£æºãå¯èœã§ãã ãŸã Amazon Kinesis Data Firehose ãªã©ãåçš® AWS ãµãŒãã¹ãšã®é£æºã容æã«ã§ããã»ãã AWS ãµãŒãã¹ã«ãã£ãŠã¯ãã°ãã¡ã€ã«ã®åºåå
ã Amazon S3 ã«ãªã£ãŠãããªã©ã AWS ããã«æŽ»çšããŠããå Žå㯠Amazon S3 ãèªç¶ã«æŽ»çšããããšã«ãªããŸãã AWS ãå©çšããŠããå Žå㯠Amazon S3 ãããŒã¿ä¿ç®¡ã®èŠ ãšãªããŸãã ãã®ãã AWS ã«ãããããŒã¿æŽ»çšåºç€ã§ã¯ Amazon S3 ãããŒã¿ã¬ã€ã¯ãšããŠäœ¿ããã ã±ãŒã¹ãæšæºçã§ãã â» RA3 ããŒãã¿ã€ãã®ãããŒãžãã¹ãã¬ãŒãžã¯ Amazon S3 çžåœã®ããå®äŸ¡ã§ãããæ§é åããŒã¿ã¯å§ãããããã«é
眮ããå ŽåããããŸãã AWS ã«ãããããŒã¿æŽ»çšåºç€ã®ã¹ãã¬ãŒãž Google Cloud ã®å Žå åæ§ã« Cloud Storage ã§ã¯ ãããŒãžãã® RDB ãµãŒãã¹ã§ãã Cloud SQL ããäžççã«éåžžã«äººæ°ã®é«ãããŒã¿ãŠã§ã¢ããŠã¹ã§ãã BigQuery ãšã®ããŒã¿é£æºãå¯èœã§ãã BigQuery ã®ã¹ãã¬ãŒãžã¯éåžžã«å®äŸ¡ã§ãã BigQuery ã§ã¯éåžžã®ã¹ãã¬ãŒãžã $0.023 /GB ã 90 æ¥é倿Žããªãã£ãããŒã¿ã¯ Long-term Storage ãšãã $0.016 /GB ã«ãªããŸãã ãã㯠Cloud Storage ã® Standard ($0.023 /GB) ãš Nearline ($0.016 /GB) ã®ä¿ç®¡éé¡ãšåãã§ãã åæå¯Ÿè±¡ãšãªãåŸãããŒã¿ã§ãã BigQuery ã®ããŒãã«ã«å
¥ããããæ§é åããŒã¿ã§ããã°ã Cloud Storage ã§ãªãå§ããã BigQuery ã«å
¥ãã ãšããéžæè¢ãåºãŠããŸãã ãã®ãã Google Cloud ã«ãããããŒã¿æŽ»çšåºç€ã§ã¯ã ããŒã¿ã¬ã€ã¯ãšããŠæ§é åããŒã¿ã¯ BigQuery ã« ã éæ§é åããŒã¿ã¯ Cloud Storage ã« å
¥ãããšããã±ãŒã¹ããããããŸãã Google Cloud ã«ãããããŒã¿æŽ»çšåºç€ã®ã¹ãã¬ãŒãž Amazon S3 vs Cloud Storage ã¯ã©ãŠããµãŒãã¹ãæ¯èŒæ€èšããŠããæ¹ã®äžã«ã¯ã Amazon S3 ãš Cloud Storage ã¯ã©ã¡ãã®ã»ãã è¯ã ã®ãïŒããšããçåãæã€æ¹ãããã£ããããããããŸããã äžã€ã®èãæ¹ãšããŠã¯ãããã®ãµãŒãã¹ã åçŽã«ã¹ãã¬ãŒãžãµãŒãã¹ãšããŠã®èгç¹ã ãã§èŠãŠããŸã ãš Amazon S3 vs Cloud Storage ãšããåçŽæ¯èŒã«ã¯ ããŸãæå³ããªã ãšèšããŸãã ãããŸã§ã«æ¯èŒããããã«ãããã 2 ãµãŒãã¹ã¯æ©èœãå
ç¢æ§ãæéãªã©ã«ãããŠã»ãšãã©åçã¬ãã«ãéæããŠããŸãã ãããªã£ããšãã«æ¯èŒæ€èšã®åºæºãšãªãããã®ã¯ã ä»ã®ã¯ã©ãŠããµãŒãã¹ãšã®çµã¿åãã ã§ãã "ããŒã¿é£æº" ã®é
ã§æžããããã« Amazon S3 㯠AWS ã®ã Cloud Storage 㯠Google Cloud ã®ããŒã¿åæç³»ãµãŒãã¹ãšã®èŠªåæ§ãé«ãã§ãã äŸãã°æ¥åã·ã¹ãã ã AWS äžã«é
眮ãããŠãããåæåºç€ã AWS ã® Amazon Redshift çã§æ§æãããŠããå Žåã¯ãããŒã¿ã¬ã€ã¯ã®ã¹ãã¬ãŒãžã¯ Amazon S3 ãå¯äžã®éžæè¢ãšãªããŸãã äžæ¹ã§æ¥åã·ã¹ãã ã AWS ã«ãããšããŠãã髿§èœã»å®äŸ¡ãª BigQuery ãããŒã¿ãŠã§ã¢ããŠã¹ãšããŠå©çšãããå Žåãéæ§é åããŒã¿ã¯ Cloud Storage ã«ãæ§é åããŒã¿ã¯ BigQuery ã«éä¿¡ã»ä¿åãããšããéžæè¢ã¯ååããããŸãã ããŒã¿ã®æµããäžæµããäžæµãŸã§èŠããšãã«ãããŒã¿é£æºã«ãã㊠ãæéã»æ§èœã»å®è£
ãéçšã®å®¹æããã®èгç¹ã§ã©ãã«ããŒã¿ãé
眮ããã®ãæãå¹çãè¯ãã ããšããç¹ã«çç®ããŠã¹ãã¬ãŒãžãéžæããã¹ãã§ãã ãã®ãã Amazon S3 ã Cloud Storage ã®æ©èœã®ã¿ãªãããããŒã¿ã®äžæµã§ãã Amazon Redshift, BigQuery, Snowflake ãªã©ã®ããŒã¿ãŠã§ã¢ããŠã¹ãµãŒãã¹ã BI ããŒã«ãªã©ã®ä»æ§ã確èªããŠããªããžã§ã¯ãã¹ãã¬ãŒãžãšã®é£æºæ¹æ³ãææ¡ããããšãæãŸããã§ãããã ãªãåèãšã㊠Google Cloud ã® BigQuery ã§ã¯ Cloud Storage ãšã¯å®¹æã«ããŒã¿ã飿ºã§ããããšã«å ã BigQuery Omni æ©èœã«ãã£ãŠ Amazon S3 ã®ãªããžã§ã¯ããå€éšããŒãã«ãšããŠå®çŸ©ããçŽæ¥ã¯ãšãªãæããããšãå¯èœã§ãã(2022 幎 3 æçŸåšãæ±äº¬ãªãŒãžã§ã³æªå¯Ÿå¿) ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãTwitter ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-genã®ææã§ããåœèšäºã§ã¯ãGoogle Cloud ã®å®¹éç¡å¶éã»äœäŸ¡æ Œã»å
ç¢ãªãªããžã§ã¯ãã¹ãã¬ãŒãžãµãŒãã¹ã§ãã Cloud Storage ã解説ããŸããåçšèªã®æå³ãæéãã»ãã¥ãªãã£ã«é¢ãã仿§ã«ã€ããŠè§£èª¬ããŸãã æŠèŠ Cloud Storage ãšã¯ ãªããžã§ã¯ãã¹ãã¬ãŒãžãšã¯ äœ¿ãæ¹ ãŠãŒã¹ã±ãŒã¹ æé Cloud Storage ã®æéã®æŠèŠ æéäœç³» ã¹ãã¬ãŒãžã¯ã©ã¹ çšèª ãã±ãã ãªããžã§ã¯ã ã¡ã¿ããŒã¿ ãã¹ ãã©ã«ã ãã±ãŒã·ã§ã³ïŒãªãŒãžã§ã³ïŒ æŠèŠ éžæåºæº ã¿ãŒãã¬ããªã±ãŒã·ã§ã³ ãªãŒãžã§ã³ãšã³ããã€ã³ã ã©ã€ããµã€ã¯ã«ãããžã¡ã³ã Autoclass Autoclass ãšã¯ ãã±ããäœæåŸã®æå¹å å¶çŽ ãŠãŒã¹ã±ãŒã¹ Autoclass ã®æé ãªããžã§ã¯ãã®ä¿è· Soft delete ããªã·ãŒ ããŒãžã§ãã³ã° ä¿æããªã·ãŒïŒBucket LockïŒ ãªããžã§ã¯ãä¿æä¿æïŒObject Retention LockïŒ éçãŠã§ããµã€ããã¹ãã£ã³ã° ã¢ã¯ã»ã¹ãã° 2ã€ã®ãã°ååŸææ³ ããŒã¿ã¢ã¯ã»ã¹ç£æ»ã㰠䜿çšç¶æ³ãã°ãšã¹ãã¬ãŒãžãã° ã»ãã¥ãªã㣠ã¢ã¯ã»ã¹å¶åŸ¡ïŒIAM ãš ACLïŒ ãããªãã¯å
¬é ãããªãã¯å
¬éã®çŠæ¢ IP ã¢ãã¬ã¹å¶é 2ã€ã®ææ³ VPC Service Controls ãã±ãã IP ãã£ã«ã¿ãªã³ã° ãããŒãžããã©ã«ã æå·å 眲åä»ã URL çµç¹ã®ããªã·ãŒ ããã©ãŒãã³ã¹ãšæŽåæ§ åºæ¬çãªä»æ§ Rapid Cache ãªããžã§ã¯ãã®åœå æŽåæ§ éå±€åå空é ããŒã¿ã¬ã€ã¯ ããŒã¿ã¬ã€ã¯ãšããŠã® Cloud Storage BigQuery ãä»ãµãŒãã¹é£æº ãªããžã§ã¯ãã³ã³ããã¹ã ããŒã¿ã®è»¢é Storage Transfer Service ã¯ãã¹ãã±ãã ã¬ããªã±ãŒã·ã§ã³ ä»ãµãŒãã¹ãšã®é£æº ã€ãã³ãããªãã³ã»ã¢ãŒããã¯ã㣠VM ã Cloud Run ããã®ããŠã³ã æŠèŠ Cloud Storage ãšã¯ Cloud Storage ã¯ãGoogle CloudïŒæ§ç§° GCPïŒã®å®¹éç¡å¶éã»äœäŸ¡æ Œã»å
ç¢ãªãªããžã§ã¯ãã¹ãã¬ãŒãžãµãŒãã¹ã§ããGoogle Cloud Storage ãç¥ã㊠GCS ãšãåŒç§°ãããå ŽåããããŸãã ããŒã¿ã¯å°ãªããšã 2 ã€ä»¥äžã®ãŸãŒã³ïŒãŸãŒã³ã¯1ã€ä»¥äžã®ããŒã¿ã»ã³ã¿ãŒã§æ§æïŒã«ããã£ãŠåé·åãããŠããã 99.999999999%ïŒã€ã¬ãã³ãã€ã³ïŒ ã®å
ç¢æ§ãä¿ã€ããèšèšãããŠããŸãã Cloud Storage ã§ã¯ãã¹ãã¬ãŒãžã¯ã©ã¹ãšåŒã°ããäŸ¡æ Œåž¯ã®éã4çš®é¡ã®ä¿ç®¡ã¿ã€ããå©çšã§ããã¢ã¯ã»ã¹é »åºŠã«ãã£ãŠäœ¿ãåããŸãã åè : Cloud Storage ã®ãããã¯ãæŠèŠ åè : ããŒã¿ã®å¯çšæ§ãšèä¹
æ§ åè : Cloud Storage ãã€ã¬ãã³ãã€ã³ã®èä¹
æ§ãå®çŸããä»çµã¿ãšããã®å¹æãé«ããæ¹æ³ ãªããžã§ã¯ãã¹ãã¬ãŒãžãšã¯ Cloud Storage 㯠ãªããžã§ã¯ãã¹ãã¬ãŒãž ãšåŒã°ããã¿ã€ãã®ã¹ãã¬ãŒãžãµãŒãã¹ã§ããä»ç€Ÿã®ä»£è¡šçãªãªããžã§ã¯ãã¹ãã¬ãŒãžãšããŠãAmazon S3 ãæããããŸãã ãªããžã§ã¯ãã¹ãã¬ãŒãžã¯ããœã³ã³ããµãŒããã䜿ããããããªããã¡ã€ã«ã·ã¹ãã çµç±ã§èªã¿æžããããã¹ãã¬ãŒãžãšã¯ç°ãªããŸããããŒã¿ã¯ããªããžã§ã¯ãããšããåäœã§ç®¡çããããããéåžžã®ãã¡ã€ã«ã·ã¹ãã ã§ããããã¡ã€ã«ãã«çžåœããŸãã Cluod Storage ã«ãããŠã¯ããªããžã§ã¯ã㯠Web API çµç±ã§èªã¿æžã ãããŸãã Cloud Storage API äœ¿ãæ¹ å©çšè
ã¯ä»¥äžã®ããããã®æ¹æ³ã§ Cloud Storage ãå©çšã§ããŸãã Google Cloud ã³ã³ãœãŒã« CLI ããŒã« (gcloud / gsutil) Cloud SDK ã¯ã©ã€ã¢ã³ãã©ã€ãã©ãª Google Cloud ã³ã³ãœãŒã«ã§ã¯ãWeb ãã©ãŠã¶äžã§å®¹æã« Cloud Storage ã®æäœãå¯èœã§ãã æšæºã®ã³ã³ãœãŒã«ç»é¢ 倧éã®ãªããžã§ã¯ãã®åŠçãããããèªååãè¡ãã«ã¯ CLI ããŒã«ãå©çšãããšäŸ¿å©ã§ããCLI ããŒã«ã«ã¯ gcloud ãš gsutil ã®2çš®é¡ããããŸãã gcloud 㯠Google Cloud ãµãŒãã¹å
šè¬ãæäœããããšãã§ããã³ãã³ãã©ã€ã³ããŒã«ã§ãããåŸè¿°ã® gsutil ãããåŠçãé«éãšãããŠããŸãã åè : Introducing gcloud storage: up to 94% faster data transfers for Cloud Storage äžæ¹ã® gsutil ã¯ãgcloud ã³ãã³ãã Cloud Storage ã«å¯Ÿå¿ãã以åãããã£ãã³ãã³ãã©ã€ã³ããŒã«ã§ããéå»ã«ã¯ Cloud Storage ãæäœããããã®å¯äžã® CLI ããŒã«ã§ãããä»åŸã¯ãgsutil ã§å©çšã§ãããã¹ãŠã®æ©èœã gcloud ã³ãã³ãã«ç§»è¡ãããgcloud ãæšå¥šãšãªããŸãã gcloud ã³ãã³ãã©ã€ã³ã®å©ç𿹿³ã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp ãŠãŒã¹ã±ãŒã¹ Cloud Storage ã¯ä»¥äžã®ãããªçšéããŠãŒã¹ã±ãŒã¹ãšãªããŸãã ç»åãã¡ã€ã«ã»åç»ãã¡ã€ã«ãªã©ã倿Žããªããµã€ãºã倧ãããã¡ã€ã«ã®ä¿å é »ç¹ã«ã¢ã¯ã»ã¹ãããªããã¡ã€ã«ã®ããã¯ã¢ãã ããŒã¿ã¬ã€ã¯ïŒããŒã¿åæåºç€ïŒ ã·ã¹ãã éã®ããŒã¿ã®åãæž¡ã ãªã Cloud Storage ã¯ãéå®çãªçšéã§ããã°ããµãŒããŒçããããŠã³ãããŠæ¬äŒŒçãªãã¡ã€ã«ã·ã¹ãã ãšããŠèªã¿æžãããããšãå¯èœã§ãããVM ã Cloud Run ããã®ããŠã³ããã®é
ãåç
§ããŠãã ããã æé Cloud Storage ã®æéã®æŠèŠ Cloud Storage ã®ç¹åŸŽã¯ãå®äŸ¡ã§ããããšã§ããæ±äº¬ãªãŒãžã§ã³ã® Standard Storage ã®ããŒã¿ä¿ç®¡æéã¯2025幎12æçŸåšã $0.023ïŒGB/æïŒ ã§ããæŠãã1TB ã§3,500åçšåºŠãšèªèããã°è¯ãã§ãããã ææ°ã®æéã¯ãå
¬åŒã®æéããŒãžãåç
§ããããå
¬åŒã® Google Cloud æé詊ç®ããŒã«ããå©çšãã ããã åè : Cloud Storage pricing åè : Google Cloud's pricing calculator ãã ã Cloud Storage ã®æéã¯ããŒã¿ä¿ç®¡ã®ããªã¥ãŒã ã ãã§ãªãã API ãªã¯ãšã¹ãã®åæ°ãªã©ãè€æ°ã®è»žã§èª²éãããŸãã ãŸã Cloud Storage ã®æéã«ã¯ ã¹ãã¬ãŒãžã¯ã©ã¹ ãšããéèŠãªèæ
®äºé
ããããéžæããã¯ã©ã¹ã«ãã£ãŠæéå䟡ãç°ãªããŸãã æéäœç³» Cloud Storage ã§ã¯ãä¿ç®¡ããããŒã¿ã®ãµã€ãºã«å ããŠãè€æ°ã®è»žã§åŸé課éãçºçããŸãã ä¿ç®¡ããããŒã¿ã®ãµã€ãºïŒGB/æïŒ æžã蟌ã¿ãªãã¬ãŒã·ã§ã³åæ° èªã¿åããªãã¬ãŒã·ã§ã³åæ° ãããã¯ãŒã¯å©çš (ããŠã³ããŒãæ¹åã®ã¿ã GB) åãåºãæé (GB) ãããã®æéå䟡ã¯ãåŸè¿°ã®ã¹ãã¬ãŒãžã¯ã©ã¹ããšã«ç°ãªããŸãã ã¹ãã¬ãŒãžã¯ã©ã¹ Cloud Storage ã«ã¯ã Standard / Nearline / Coldline / Archive ãšãã4ã€ã® ã¹ãã¬ãŒãžã¯ã©ã¹ ãååšããŸããå³ã«è¡ãã»ã©é·æä¿åããã€åãåºãé »åºŠãå°ãªãããŒã¿ã«é©ããŠããŸãã åè : ã¹ãã¬ãŒãž ã¯ã©ã¹ å³ã®ã¹ãã¬ãŒãžã¯ã©ã¹ã»ã© GB ãããã®ããŒã¿ä¿ç®¡æéãå®ããªããŸããããªãã¬ãŒã·ã§ã³åæ°ãããã®æéãåãåºã GB ãããã®æéãé«ããªããŸããæéå䟡ã¯ä»¥äžã®ãšããã§ãïŒ2025幎12æçŸåšãæ±äº¬ãªãŒãžã§ã³ïŒã ã¹ãã¬ãŒãžã¯ã©ã¹ ä¿ç®¡æé (GB/æ) æžã蟌ã¿ãªãã¬ãŒã·ã§ã³ (10,000åããã) èªã¿åããªãã¬ãŒã·ã§ã³ (10,000åããã) ããŒã¿åãåºãé (GB) æå°ä¿åæé Standard Storage $0.023 $0.05 $0.004 $0 ãªã Nearline Storage $0.016 $0.10 $0.01 $0.01 30 æ¥ Coldline Storage $0.006 $0.10 $0.05 $0.02 90 æ¥ Archive Storage $0.0025 $0.50 $0.50 $0.05 365 æ¥ é·æä¿ç®¡çšã®ã¹ãã¬ãŒãžã¯ã©ã¹ã»ã©ãããŒã¿ãµã€ãºãããã®æéã¯å®ã代ããã«ãåãåºãã«ãéããããããšãåãããŸãã æå°ä¿åæé ïŒMinimum storage durationïŒãåã¹ãã¬ãŒãžã¯ã©ã¹ããšã«å®ããããŠãããä¿ç®¡ãããªããžã§ã¯ãããã®æ¥æ°ä»¥å
ã«åé€ã»çœ®æã»ç§»åãããå Žåããã®æ¥æ°åã®ä¿ç®¡æéãçºçããŠããŸããŸãïŒåé€ã§ããªãèš³ã§ã¯ãããŸããïŒã ã¹ãã¬ãŒãžã¯ã©ã¹ã¯ãã±ããäœææã« ããã©ã«ãã¹ãã¬ãŒãžã¯ã©ã¹ ãšããŠæå®ã§ããŸãããã±ããã«ãªããžã§ã¯ããäœæããããšããã©ã«ãã¹ãã¬ãŒãžã¯ã©ã¹ã«åŸã£ãŠã¹ãã¬ãŒãžã¯ã©ã¹ãèšå®ãããŸããããªããžã§ã¯ãããšã«åå¥ã«ã¯ã©ã¹ãæå®ããããšãã§ããŸãããåŸãã倿Žãå¯èœã§ãããŸããåŸè¿°ã® Autoclass æ©èœã«ãããå©çšç¶æ³ã«ããããŠèªåã§ã¯ã©ã¹ãç§»è¡ãããŠããããã«èšå®ããããšãã§ããŸãã ãªãå
šãŠã®ã¹ãã¬ãŒãžã¯ã©ã¹ã§ãããŒã¿åãåºãæã®ã¬ã€ãã³ã·ã¯ãæåã®ãã€ã転ééå§ãŸã§æ°åããªç§çšåºŠããšãããŠããŸããAWS ã® Amazon S3 çã§ã¯ã¢ãŒã«ã€ãã¬ãã«ã®ã¹ãã¬ãŒãžã®åãåºãã«ã¯æéããããå ŽåããããŸãããCloud Storage ã«ãããŠã¯ã©ã®ã¹ãã¬ãŒãžã¯ã©ã¹ã§ãè¿
éã«ããŒã¿ãåãåºãããšãã§ããŸãã çšèª ãã±ãã Cloud Storage ã«ããã ãã±ãã ãšã¯ãããŒã¿ãå
¥ããããã®ç®±ã§ãããåã
ã®ãªããžã§ã¯ãïŒãã¡ã€ã«ïŒãå
¥ããããã®ã°ã«ãŒãã³ã°ãªããžã§ã¯ãã§ãããã±ããã®åäœã§ã¢ã¯ã»ã¹å¶åŸ¡ãããããã©ã®ãªãŒãžã§ã³ã«é
眮ããããæ±ºããããšãã§ããŸãã ãã±ããã«ã¯å
šäžçã§äžæãšãªãååãä»ããå¿
èŠããããŸãã ãªã bucket ãšã¯è±èªã§ããã±ãããæå³ããŸãã åè : Cloud Storage ãã±ããã«ã€ã㊠ãªããžã§ã¯ã ãªããžã§ã¯ã ãšã¯ããã±ããã«å
¥ããããåã
ã®ãã¡ã€ã«ãæããŸãã Cloud Storage ã®ãããªãªããžã§ã¯ãã¹ãã¬ãŒãžã§ã¯åºæ¬çã«ããªããžã§ã¯ããäžåºŠæžã蟌ããš ã倿ŽããšããæŠå¿µã¯ãããŸãã ãåé€ãããååã®ãªããžã§ã¯ãã§äžæžãããããšã«ãªããŸããæ¢ã«ååšãããªããžã§ã¯ããéããŠç·šéãã1è¡è¶³ãããšãã£ãããšã¯ã§ããŸããããããè¡ãããå Žåã1è¡ãè¶³ããæ°ãããã¡ã€ã«ã§æ¢åãªããžã§ã¯ããäžæžãããããšã«ãªããŸãã 1ã€ã®ãªããžã§ã¯ãã®æå€§ãµã€ãºã¯ 5 TiB ã§ãããã±ããå
ã«æ ŒçŽã§ãããªããžã§ã¯ãã®æ°ã«å¶éã¯ãããŸããã åè : Cloud Storage ãªããžã§ã¯ãã«ã€ã㊠ã¡ã¿ããŒã¿ ãªããžã§ã¯ãã«ã¯ ã¡ã¿ããŒã¿ ãšããä»å æ
å ±ãä»äžã§ããŸããã¡ã¿ããŒã¿ã¯ããŒã»ããªã¥ãŒã®ãã¢ã®æååã§ãã äŸãšããŠãªããžã§ã¯ãã« Cache-Control:no-store ã®ããã«ã¡ã¿ããŒã¿ãä»äžããã°ããªããžã§ã¯ããäžè¬å
¬éããéã«ã HTTP ã¬ã¹ãã³ã¹ããããŒã« Cache-Control:no-store ãä»äžãããã£ãã·ã¥å¯åŠãã³ã³ãããŒã«ã§ããŸãã Content-Type ãªã©ãåæ§ã®äœ¿ãæ¹ãã§ããŸãã äžèšã®ãã㪠HTTP ããããŒã«é¢é£ããã¡ã¿ããŒã¿ã®ã¿ãªããããŠãŒã¶ãŒãä»»æã®ããŒã»ããªã¥ãŒãæååãšããŠä¿åããŠããããšãã§ããŸãã ã¡ã¿ããŒã¿ã«ã¯ åºå®ããŒã¡ã¿ããŒã¿ ïŒFixed-key metadataïŒãš ã«ã¹ã¿ã ã¡ã¿ããŒã¿ ïŒCustom metadataïŒããããŸãã以äžã«ãã®æŠèŠã瀺ããŸãã åç§° æå³ äŸ åºå®ããŒã¡ã¿ããŒã¿ ããã©ã«ãã§ããŒãèšå®ãããŠããã¡ã¿ããŒã¿ãããªã¥ãŒã¯èªç±ã«æå® Cache-ControlãContent-TypeãContent-Language ç ã«ã¹ã¿ã ã¡ã¿ããŒã¿ ããŒãšããªã¥ãŒã®äž¡æ¹ãä»»æã«èšå®ã§ããã¡ã¿ããŒã¿ ä»»æ åè : ãªããžã§ã¯ãã®ã¡ã¿ããŒã¿ ãã¹ ãã¹ ãšã¯ç¹å®ã®ãªããžã§ã¯ããæã瀺ãæååã§ããèŠãç®ã¯ Linux ã®ãã¹ãšäŒŒãŠããŸãã Cloud Storage ãªããžã§ã¯ãã®ãã¹ã¯ã gs://my-bucket/my-folder/myobject ã®ããã«è¡šãããŸããå
é ã® gs:// 㯠Cloud Storage ã®ãªããžã§ã¯ãã®ãã¹ã§ããããšãç€ºãæ¥é èŸã§ãã ãã©ã«ã ãã©ã«ã ãšã¯ããã±ããã®äžãåºåãããã®ã°ã«ãŒãã³ã°ãªããžã§ã¯ãã§ãããããœã³ã³ã®ãã©ã«ããšåããããªæå³ãæã¡ãŸãã ãŠãŒã¶ãŒç®ç·ã§ã¯ããŸãæèããå¿
èŠã¯ãããŸããããCloud Storage ã®å
éšçã«ã¯ããã©ã«ãã¯å®äœãšããŠã¯ååšããŠããŸãããCloud Storage ã¯ãå
éšæ§é ãšããŠã¯ããŒããªã¥ãŒã¹ãã¢ã§ãããå¹³åŠãªæ§æã«ãªã£ãŠããŸãã gs://my-bucket/my-folder/my-object ãšãããªããžã§ã¯ãããããšãã my-folder ã«ã¯ãã©ã«ããšããå®äœã¯ãªããåã« my-object ãšãããªããžã§ã¯ãã®ååïŒãã¹ïŒã®äžéšã§ããWeb ã³ã³ãœãŒã«ã CLI ããŒã«ã§ç©ºã®ãã©ã«ããäœãããšãã§ããŸãããå®éã«ã¯ 0 ãã€ãã®ãªããžã§ã¯ããäœæããããšããæåãããŠããŸãã åè : Cloud Storage ãªããžã§ã¯ãã«ã€ã㊠- ãªããžã§ã¯ãã®åå空é ãã©ã«ãåããããŠããããã«èŠãããå®éã«ã¯ãã©ãããªæ§æ ãªããåŸè¿°ã®ãããŒãžããã©ã«ãæ©èœã䜿ããšãéåžžã®ãã©ã«ããšã¯ç°ãªãããã现ããæš©é管çãè¡ãããšãã§ããŸãããããŒãžããã©ã«ãã«å¯ŸããŠãéåžžã®ãã©ã«ãã®ããšãã·ãã¥ã¬ãŒãããããã©ã«ãïŒSimulated foldersïŒãšåŒã³ãŸãã ãã±ãŒã·ã§ã³ïŒãªãŒãžã§ã³ïŒ æŠèŠ Cloud Storage ã§ã¯ããã±ããäœææã« ãã±ãŒã·ã§ã³ ãéžæããŸããããŒã¿ã¯ç©ççã«ãéžæãããã±ãŒã·ã§ã³ã«ä¿ç®¡ãããŸãã ãã±ãŒã·ã§ã³ã¯ã åäžãªãŒãžã§ã³ ãã ãã¥ã¢ã«ãªãŒãžã§ã³ ãã ãã«ããªãŒãžã§ã³ ãã®ã¿ã€ãããããããããã®ã¿ã€ãã§ãªãŒãžã§ã³ãéžæå¯èœã§ãã äŸãšããŠåäžãªãŒãžã§ã³ã«ã¯ãasia-northeast1ïŒæ±äº¬ïŒãããasia-northeast2ïŒå€§éªïŒããããã¥ã¢ã«ãªãŒãžã§ã³ã«ã¯ãasia1ïŒæ±äº¬ã»å€§éªïŒããããã«ããªãŒãžã§ã³ã«ã¯ãasiaïŒã¢ãžã¢åè€æ°ãªãŒãžã§ã³ïŒããååšããŸãã åè : ãã±ããã®ãã±ãŒã·ã§ã³ éžæåºæº ããšãåäžãªãŒãžã§ã³ãéžãã å Žåã§ãããªãŒãžã§ã³å
ã®è€æ°ã®ãŸãŒã³ã«ããŒã¿ã¯åé·åãããŠããã99.999999999%ïŒã€ã¬ãã³ãã€ã³ïŒã®å¹Žéèä¹
æ§ãå®çŸããŸããããããã¥ã¢ã«ãªãŒãžã§ã³ãŸãã¯ãã«ããªãŒãžã§ã³ãéžã¶ããšã§ããªãŒãžã§ã³ã¬ãã«ã®é害ãçœå®³ãäºæ
ãæ¿å€ãªã©ã®ãªã¹ã¯ã«ã察å¿ããå¯çšæ§ãšåé·æ§ãåäžãããããšãã§ããŸãããã±ãŒã·ã§ã³ã¯ã以äžã®ãããªåºæºã§éžã¶ãšè¯ãã§ãããã ã³ã¹ãå¹çãšäœãã¬ã€ãã³ã·ãæ±ããå Žå㯠åäžãªãŒãžã§ã³ ã¬ã€ãã³ã·ãæãã€ã€ãåäžãªãŒãžã§ã³ããé«ãå°ççåé·æ§ãšå¯çšæ§ïŒãå¿
èŠãªå Žå㯠ãã¥ã¢ã«ãªãŒãžã§ã³ è€æ°å°åããã®ã¢ã¯ã»ã¹ãæ³å®ãããããè€æ°ãªãŒãžã§ã³ã§ã®åé·æ§ã確ä¿ãããå Žå㯠ãã«ããªãŒãžã§ã³ ãã¥ã¢ã«ãªãŒãžã§ã³ã¯ããã«ããªãŒãžã§ã³ãããã¹ãã¬ãŒãžæéãé«ãã§ãããããåºã垯åå¹
ïŒãªãŒãžã§ã³ããš 200 GbpsïŒã確ä¿ã§ããããšã«å ããåäžãªãŒãžã§ã³ããã®ããŠã³ããŒãã«ã¯ã¢ãŠãããŠã³ãæéãçºçããŸããããã«ããªãŒãžã§ã³ã¯ãã®å察ã«ãä¿ç®¡æéãå®ã代ããã«åž¯åå¹
ãããçãïŒãªãŒãžã§ã³ããš 50 GbpsïŒãããŒã¿èªã¿åãã«ã¯å¿
ãã¢ãŠãããŠã³ãæéãçºçããŸãããã®ãããªãã¬ãŒããªããçè§£ããŠéžæããŸãã詳现ã¯ä»¥äžã®ããã¥ã¡ã³ããåç
§ããŠãã ããã åè : ãã±ããã®ãã±ãŒã·ã§ã³ - ãã±ãŒã·ã§ã³ã«é¢ããçæäºé
ã¿ãŒãã¬ããªã±ãŒã·ã§ã³ ãã¥ã¢ã«ãªãŒãžã§ã³ããã«ããªãŒãžã§ã³ãã±ããã«ãããŠããªãŒãžã§ã³éã®ã¬ããªã±ãŒã·ã§ã³ã¯ããªããžã§ã¯ãã®æžã蟌ã¿ãå®äºããŠãã éåæ ã§è¡ãããŸããåæã«ã¯æ°åãããã以äžã®æéããããããšããããŸããããã©ã«ãã®éåæã¬ããªã±ãŒã·ã§ã³ã§ã¯ã1æé以å
ã«99.9%ã®ãªããžã§ã¯ããè€è£œããã12æé以å
ã«100%ã«éããŸãã ããã§ã¯ RPOïŒRecovery Point ObjectiveïŒèŠä»¶ãæºãããªãå Žåã ã¿ãŒãã¬ããªã±ãŒã·ã§ã³ ïŒTurbo replicationïŒãæå¹åããããšã§ã15å以å
ã«100%ã®ããŒã¿ãè€è£œã§ããŸãã ã¿ãŒãã¬ããªã±ãŒã·ã§ã³ã«ã¯è¿œå æéãçºçããŸãããŸããã¿ãŒãã¬ããªã±ãŒã·ã§ã³ã¯ãã¥ã¢ã«ãªãŒãžã§ã³ã®ãã±ããã§ã®ã¿å©çšå¯èœã§ãã åè : ããŒã¿ã®å¯çšæ§ãšèä¹
æ§ åè : ã¯ã©ãŠã ã€ã³ãã©ã¹ãã©ã¯ãã£ã®åæ¢ã«å¯Ÿããé害埩æ§ã®èšèš - Google Cloudã§ã¢ããªã±ãŒã·ã§ã³ã®é害埩æ§ãèšèšããããã®èšå®ã¬ã€ã ãªãŒãžã§ã³ãšã³ããã€ã³ã ãªãŒãžã§ã³ãšã³ããã€ã³ã ïŒRegional endpointsïŒã¯ãç¹å®ã®ãªãŒãžã§ã³ã«ããã Cloud Storage ãã±ããå°çšã®ãšã³ããã€ã³ã URL ã§ãããªãŒãžã§ã³ãšã³ããã€ã³ãã䜿ããšãããŒã¿ã転éäžãšä¿ç®¡äžã®äž¡æ¹ã§ãç¹å®ã®å°åå
ã«çãŸãããšãä¿èšŒã§ããããŒã¿ã¬ãžãã³ã·ãŒïŒdata residencyïŒãããŒã¿äž»æš©ïŒdata sovereigntyïŒãæ
ä¿ããããšãã§ããŸãã ãªãŒãžã§ã³ãšã³ããã€ã³ã㯠https://storage.europe-west3.rep.googleapis.com ã®ãããªåœ¢åŒã§ãããã® URL ã®å ŽåãããŒã¿ã europe-west3 ãªãŒãžã§ã³ïŒãã€ãã®ãã©ã³ã¯ãã«ããªãŒãžã§ã³ïŒãåºãªãããšãä¿èšŒãããŸãã ãã®ãšã³ããã€ã³ãã䜿ããšãèªã¿æžãçã®ãªãã¬ãŒã·ã§ã³å¯Ÿè±¡ãšãªããã±ãããã察象ãªãŒãžã§ã³å€ã«ããå Žåããªãã¬ãŒã·ã§ã³ã¯ãšã©ãŒãšãªããŸãã å©çšããã«ã¯ãgcloud ã³ãã³ãã®å Žåã¯ç°å¢å€æ°ã«ãšã³ããã€ã³ããèšå®ããŸããREST API ã®å Žåã¯ããªã¯ãšã¹ãå
ã®ãšã³ããã€ã³ã URL ããªãŒãžã§ãã«ãšã³ããã€ã³ãã«ããŸãã åè : ãªãŒãžã§ã³ ãšã³ããã€ã³ã ã©ã€ããµã€ã¯ã«ãããžã¡ã³ã ã©ã€ããµã€ã¯ã«ãããžã¡ã³ã æ©èœã¯ããªããžã§ã¯ãäœæåŸã®çµéæ¥æ°ãªã©ã«åŸãèªåçã«ã¹ãã¬ãŒãžã¯ã©ã¹ã倿Žããããåé€ãããã§ããæ©èœã§ãã äŸãã°ãããã©ã«ãã¹ãã¬ãŒãžã¯ã©ã¹ã¯ Standard Storage ã ãã 120 æ¥çµéãããªããžã§ã¯ãã¯èªåçã« Coldline Storage ã«ç§»åããã360 æ¥çµéãããªããžã§ã¯ãã¯åé€ããããšãã£ãæå®ãå¯èœã§ãã ã«ãŒã«ãèšå®ããã ãã§èªåé©çšããããããããŠã¹ããŒãã³ã°ã®ããã®ããã°ã©ã ãæžãå¿
èŠããããŸããããã®æ©èœãè³¢ã䜿ãããšã§ãæéãç¯çŽããããšã«ãç¹ãããŸãã ã«ãŒã«ãé©çšããæ¡ä»¶ãšããŠããªããžã§ã¯ãäœæåŸã®çµéæ¥æ° ( Age )ããçµ¶å¯Ÿæ¥æä»¥åã«äœæããããªããžã§ã¯ã ( CreatedBefore )ããããŒãžã§ãã³ã°ã§éå»çã«ãªã£ãŠããã®æ¥æ° ( DaysSinceNoncurrentTime )ããç¹å®ã®æ¥é èŸ/æ¥å°ŸèŸãæã€ãªããžã§ã¯ã ( MatchesPrefix / MatchesSuffix )ããªã©æ§ã
ãªæ¡ä»¶ãéžæã§ããŸãã ã©ã€ããµã€ã¯ã«ã«ãŒã«ã¯ãã±ããåäœã§äœæããŸããã«ãŒã«ã¯ãã±ããå
ã®å
šãŠã®ãªããžã§ã¯ãã«é©çšãããŸãã MatchesPrefix / MatchesSuffix ã«ãŒã«ãšçµã¿åãããããšã§ãç¹å®ã®ãã©ã«ãé
äžã®ã¿ããç¹å®ã®æ¡åŒµåã®ãªããžã§ã¯ãã®ã¿ãã«é©çšããããšãªã©ãå¯èœã§ãã åè : ãªããžã§ã¯ãã®ã©ã€ããµã€ã¯ã«ç®¡ç Autoclass Autoclass ãšã¯ Autoclass ã¯ããã±ããå
ã®ãªããžã§ã¯ãã®ã¢ã¯ã»ã¹ãã¿ãŒã³ã«å¿ããŠãã¹ãã¬ãŒãžã¯ã©ã¹ãèªåã§æ¯ãåããæ©èœã§ããAWS ã® Amazon S3 ã«ããããIntelligent-Tieringããšé¡äŒŒããæ©èœãšãããŸãã Autoclass ãã±ããã®ãããã©ã«ãã®ã¹ãã¬ãŒãž ã¯ã©ã¹ãã Autoclass ã«èšå®ããããšã§ããã±ããåäœã§æå¹åããŸããæå¹åããããã±ããã§ã¯ã以äžã®ã«ãŒã«ã§ãªããžã§ã¯ãã®ã¹ãã¬ãŒãžã¯ã©ã¹ãèªåçã«ç®¡çãããŸãã æ°èŠã«æžã蟌ãŸãããªããžã§ã¯ã㯠Standard storage ã«ãªã ãªããžã§ã¯ããäžæžãããããš Standard storage ã«å€æŽããã äžåºŠã§ãã¢ã¯ã»ã¹ïŒèªã¿èŸŒã¿ïŒããããªããžã§ã¯ã㯠Standard storage ã«å€æŽããã 30æ¥éã¢ã¯ã»ã¹ããªããªããžã§ã¯ã㯠Nearline storage ã«å€æŽããã 90æ¥éã¢ã¯ã»ã¹ããªããªããžã§ã¯ã㯠Coldline storage ã«å€æŽããã 365æ¥éã¢ã¯ã»ã¹ããªããªããžã§ã¯ã㯠Archive storage ã«å€æŽããã ã€ãŸããã¢ã¯ã»ã¹é »åºŠãå°ãããªããžã§ã¯ãã»ã©ãããå®ãã¹ãã¬ãŒãžã«èªåçã«ç§»è¡ããŠãããŸããAutoclass æå¹åæã¯ãããã©ã«ãã ãš Nearline ãžã®ç§»è¡ã®ã¿ãè¡ãèšå®ã«ãªã£ãŠãããColdline ã Archive ãžã®èªåç§»è¡ã¯æç€ºçã«æå¹åããå¿
èŠããããŸãã åè : Autoclass ãã±ããäœæåŸã®æå¹å 以åã¯å¶çŽãšããŠããã±ããäœææã«ã®ã¿ Autoclass ãæå¹åã§ãããã±ããäœæåŸã®æå¹åã¯ã§ããŸããã§ãããã2023幎11æ3æ¥ã®ã¢ããããŒãã§ããã±ããã§ãã€ã§ã Autoclass ãæå¹åã§ããããã«ãªããŸããã ãã ã æå¹åæã«æéãçºçãã ããšã«ã泚æãã ãããAutoclass æå¹åæã« Standard 以å€ã®ã¹ãã¬ãŒãžã«å
¥ã£ãŠãããªããžã§ã¯ãã«ã¯ãæ©æå逿éããããŒã¿åãåºãæéããçºçããã»ããå
šãªããžã§ã¯ãã«å¯Ÿã㊠Class A ãªãã¬ãŒã·ã§ã³ã® API ã³ãŒã«æéãçºçããŸãã®ã§ãååãæ³šæãã ããã åè : Cloud Storage pricing - Autoclass charges å¶çŽ Autoclass æ©èœã«ã¯ã以äžã®å¶çŽãé©çšãããŸãã 128KBæªæºã®å°ãããã¡ã€ã«ã«ã¯ã¹ãã¬ãŒãžã¯ã©ã¹å€æŽãããããStandard ã®ãŸãŸãšãªã ãã ã128KBæªæºã®å°ãããã¡ã€ã«ã«ã¯ç®¡çè²»çšïŒåŸè¿°ïŒãé©çšãããªã ãŠãŒã¹ã±ãŒã¹ ãããã±ããã§ãã¢ã¯ã»ã¹é »åºŠããªããžã§ã¯ãã«ãããŸã¡ãŸã¡ã§ãããäºæž¬ãé£ããå Žåã«ã¯ãAutoclass ã䜿ãããšã§ã³ã¹ãæé©åãå¯èœãªå ŽåããããŸãã éã«ããªããžã§ã¯ãã®ã¢ã¯ã»ã¹é »åºŠãããçšåºŠäºæž¬ããããã£ããããããã¯ã»ãšãã©ã®ãªããžã§ã¯ãã®ãµã€ãºã128KB以äžã§ããå Žåãç¡å¹åã®ãŸãŸã®ã»ããã³ã¹ãå¹çãè¯ãå¯èœæ§ããããŸãã ãŸãåŸè¿°ã®ããã«ãAutoclass ã§ã¯æ¬æ¥ NearlineãColdlineãArchive storage ã§çºçãããæ©æå逿éãããããŒã¿åãåºãæéããçºçããŸããããããã®ã¡ãªããã享åãããå Žåã¯ãAutoclass ãé©ããŠããŸãã Autoclass ã®æé Autoclass ãæå¹åãããšã 管çè²»çš ãšã㊠1,000 ãªããžã§ã¯ãããšã«æããã $0.0025 ã®è²»çšãçºçããŸãã ãã ãç¹çãã¹ãç¹ãšããŠãAutoclass ãæå¹åãããã±ããã§ã¯ NearlineãColdlineãArchive storage ã®ãªããžã§ã¯ããåé€ããŠã æå°ä¿åæéã®æéãçºçããŸãã ããŸããNearlineãColdlineãArchive storage ã§æ¬æ¥çºçãã ããŒã¿åãåºãæéãçºçããŸãã ã ãŸã Autoclass ã«ããèªåçã«è¡ãããããã cold ãªã¹ãã¬ãŒãžã¯ã©ã¹ã®ç§»åã«ã¯ããªãã¬ãŒã·ã§ã³æéãçºçããŸãããéã« hot ãªã¹ãã¬ãŒãžãžã®ç§»åã«ã€ããŠã¯ãNearline -> Standard ã§ã¯æéãçºçããŸããããColdline -> Standard ã Archive -> Standard ã§ã¯ Class A ãªãã¬ãŒã·ã§ã³ãšããŠã®èª²éãçºçããŸãããã ãããªãã¬ãŒã·ã§ã³æéã®å䟡ã¯ãStandard ã®ãã®ãé©çšãããŸãã åè : Autoclass - Pricing åè : Cloud Storage pricing - Autoclass charges ãªã2023幎10æ16æ¥ä»¥åã¯ããªãã¬ãŒã·ã§ã³èª²éã«é¢é£ãã課éäœç³»ã¯çŸåšãšç°ãªã£ãŠããŸããã詳现ã¯ä»¥äžãåèã«ããŠãã ããã åè : Cloud Storage release notes - July 17, 2023 ãªããžã§ã¯ãã®ä¿è· Soft delete ããªã·ãŒ Soft delete ããªã·ãŒ ãšã¯ãåé€ããã Cloud Storage ãªããžã§ã¯ãããåé€åŸãäžå®ã®æéä¿æãããæéå
ã§ããã°åŸ©å
å¯èœãšãªãèšå®ã§ããæ¥æ¬èªã³ã³ãœãŒã«ãæ¥æ¬èªããã¥ã¡ã³ãã§ã¯ãåé€ïŒåŸ©å
å¯èœïŒããªã·ãŒããšè¡šèšãããŸãããåœèšäºã§ã¯ãããããããã Soft delete ãšããçšèªã䜿çšããŸãã Soft delete ããªã·ãŒã¯ãã±ããåäœã§èšå®ã§ããããã©ã«ãã§ã¯7æ¥éã«èšå®ãããŠããŸãããã®æéã®ãã¡ã¯ããªããžã§ã¯ãã誀ã£ãŠåé€ããŠã埩æ§å¯èœã§ããæé·90æ¥éãæçã¯0æ¥éïŒãªãïŒã§ãã åè : åé€ïŒåŸ©å
å¯èœïŒ Soft delete ããããªããžã§ã¯ãã埩æ§ããã«ã¯ã gcloud storage restore ã³ãã³ãã䜿ãããGoogle Cloud ã³ã³ãœãŒã«ã䜿ã£ãŠãªã¹ãã¢æäœãè¡ããŸãã åè : åé€ïŒåŸ©å
å¯èœïŒãªããžã§ã¯ãã䜿çšãã ããŒãžã§ãã³ã° ãªããžã§ã¯ãã«ã¯ã ããŒãžã§ãã³ã° ãèšå®å¯èœã§ãããã±ããããšã«æå¹åã§ããŸãã ããŒãžã§ãã³ã°ãæå¹åãããŠããå Žåããªããžã§ã¯ããäžæžããããšãéå»ã®ããŒãžã§ã³ãšããŠæå®ããäžä»£æ°ã ãä¿ç®¡ãããŸããåé€ãåæ§ã§ããªããžã§ã¯ããåé€ããŠããéå»ã®ããŒãžã§ã³ãšããŠããŒã¿ãæ®ããŸããææ°ã®ããŒãžã§ã³ã®ãªããžã§ã¯ãã¯ã çŸè¡ã®ããŒãžã§ã³ ããéå»ã®ããŒãžã§ã³ã¯ã éçŸè¡ã®ããŒãžã§ã³ ããšåŒã°ããŸãã éçŸè¡ã®ããŒãžã§ã³ã¯ çŸè¡ã®ããŒãžã§ã³ãšåæ§ã«èª²éããã ã®ã§ã泚æãå¿
èŠã§ãã åè : ãªããžã§ã¯ãã®ããŒãžã§ãã³ã° éçŸè¡ã®ããŒãžã§ã³ãšãªã£ããªããžã§ã¯ããåé€ããã«ã¯ãå
ã«èšè¿°ãããªããžã§ã¯ãã©ã€ããµã€ã¯ã«æ©èœã䜿ã£ãŠãéçŸè¡ããŒãžã§ã³ã«ãªã£ãŠãã 14 æ¥çµéåŸã«å®å
šã«åé€ãããã®ããã«èšå®ããŸããããŒãžã§ãã³ã°ãšã©ã€ããµã€ã¯ã«ãçµã¿åãããŠå©çšããæ¹æ³ã«ã€ããŠã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp ä¿æããªã·ãŒïŒBucket LockïŒ åçš®èŠå¶ãã³ã³ãã©ã€ã¢ã³ã¹èŠä»¶ãžã®å¯Ÿå¿ã®ãã ä¿æããªã·ãŒ ïŒBucket LockïŒãèšå®ããããšãã§ããŸãã ãä¿æããªã·ãŒãããã±ããã«èšå®ãããšãèšå®ããæéäžããªããžã§ã¯ããåé€ãããæŽæ° ã§ããªã ãªããŸããããã«ãããã°ããŒã¿çã®æ¹ããã»æ¶å»ãäžå¯èœã«ãªããŸãããã®ããã«ãæžã蟌ã¿ïŒæ°èŠè¿œå ïŒã¯ã§ãããåé€ãããæ¹ããã§ããªãããèªã¿åãã¯å¯èœããšããç¶æ
ããwrite once, read manyïŒWORMïŒããšåŒã³ãç£æ»ãã°çã®ä¿ææœçã®ååã§ãã ãŸããä¿æããªã·ãŒã®ããã¯ããèšå®ãããšä¿æããªã·ãŒã æ°žä¹
ã« è§£é€ã§ããªãããããšãã§ããŸããããã¯ãããšä¿ææéã® å»¶é·ã¯ã§ããŸã ããéã«æéãççž®ããããããªã·ãŒãåé€ã§ããªããªããŸãã æ³çèŠå¶ã§ä¿ç®¡ã矩åä»ããããŠãããã°ããŒã¿çã®ä¿ç®¡ã«åœ¹ç«ã€äžæ¹ãä¿ææéãæºäºãããŸã§ãªããžã§ã¯ãã®åé€ã倿Žã¯äžåã§ããªããªããŸãã®ã§ååãæ³šæãã ããã åè : ãã±ãããã㯠ãªããžã§ã¯ãä¿æä¿æïŒObject Retention LockïŒ åè¿°ã®ä¿æããªã·ãŒããã±ããåäœã§ã®èšå®ã§ããã®ã«å¯Ÿãããªããžã§ã¯ãåäœã§ã®èšå®ã§ãã ãªããžã§ã¯ãä¿æä¿æ ïŒObject Retention LockïŒãèšå®ããããšãå¯èœã§ãã ããªããžã§ã¯ãä¿æãããªããžã§ã¯ãã«å¯ŸããŠã«èšå®ãããšãèšå®ããæéãŸã§ããªããžã§ã¯ããåé€ãããæŽæ°ã§ããªããªããŸããä¿æããªã·ãŒãã现ããç²åºŠã§ãã°ããŒã¿çã®æ¹ããã»æ¶å»ãé²ããæ³çèŠå¶ãžã®å¯Ÿå¿ãå¯èœã«ããŸãã ããã«èšå®ãããªããžã§ã¯ãä¿ææéã«å¯Ÿãã倿Žãé²ãããããã¯ç¶æ
ïŒLockedïŒã«ããããšãå¯èœã§ããããã¯ç¶æ
ã«ãããšãä¿ææéãå»¶é·ããããšã¯ã§ããŸãããèšå®ãåé€ãããççž®ããããšã¯äºåºŠãšã§ããªããªããŸãã ãã±ããåäœã®ä¿æããªã·ãŒãšã®äœµçšãå¯èœã§ã䜵çšããå Žåã¯äž¡æ¹ã®æéãæºäºãããŸã§ãªããžã§ã¯ããä¿æãããŸãã åè : ãªããžã§ã¯ãä¿æãã㯠éçãŠã§ããµã€ããã¹ãã£ã³ã° Cloud Storage ã«é
眮ãã HTML ãã¡ã€ã«çãã€ã³ã¿ãŒãããå
¬éããããšã§ããŠã§ããµã€ãã®ãã¹ãã£ã³ã°ãããããšãã§ããŸãã HTML ãã¡ã€ã«ãé
眮ããå
ã«èšè¿°ãããããªãã¯å
¬éã«ããããšã§ https://storage.googleapis.com/(BUCKET_NAME)/(OBJECT_NAME) ãšãã URL ãæãåºãããŸãã ãŸã Cloud Load Balancing ã®å€éšã¢ããªã±ãŒã·ã§ã³ããŒããã©ã³ãµãŒãšçµã¿åãããããšã§ãã«ã¹ã¿ã ãã¡ã€ã³å + TLS èšŒææžã§ãµã€ããå
¬éããããšãå¯èœã§ãã è©³çŽ°ãªæé ã¯ã以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : éçãŠã§ããµã€ãããã¹ããã éçãŠã§ããµã€ããã¹ãã£ã³ã° ã¢ã¯ã»ã¹ãã° 2ã€ã®ãã°ååŸææ³ Cloud Storage ãã±ãããžã®ã¢ã¯ã»ã¹ãã°ãååŸãããå Žåã以äžã®2ã€ã®æ¹æ³ãèããããŸãã Cloud Audit Logs ã®ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ãæå¹åãã 䜿çšç¶æ³ãã°ãšã¹ãã¬ãŒãžãã°ãæå¹åãã ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã° Cloud Audit Logs ã® ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã° ã¯ãGoogle Cloud ã®ç£æ»ãã°ã远å ã§æå¹åããæ¹æ³ã§ããã¢ã¯ã»ã¹æå»ãããªã³ã·ãã«ïŒã¢ã¯ã»ã¹ãããŠãŒã¶ãŒïŒããªã¯ãšã¹ãã®è©³çްãªã©ãèšé²ãããŸãããã°ã¯ Cloud Logging ã«åºåããããã°ãšã¯ã¹ãããŒã©ã§é²èЧå¯èœã§ãã 詳现ã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp 䜿çšç¶æ³ãã°ãšã¹ãã¬ãŒãžã㰠䜿çšç¶æ³ãã°ãšã¹ãã¬ãŒãžãã° ã¯ãCloud Storage ç¬èªã®ãã°ããã±ããããšã«æå¹åã§ããæ©èœã§ããç£æ»ãã°ãšæ¯èŒããŠãã€ã³ã¿ãŒãããå
¬éã®ãªããžã§ã¯ãã®ã¢ã¯ã»ã¹ãã°ã远ããããšãã¬ã€ãã³ã·ã«é¢ããæ
å ±ããªã¯ãšã¹ããã¬ã¹ãã³ã¹ã®ãµã€ãºã®æ
å ±ãªã©ãèšé²ãããŸãã ãã°ã¯ CSV 圢åŒã§ããã®ã³ã°å¯Ÿè±¡ã®ãã±ãããšã¯å¥ã® Cloud Storage ãã±ããã«åºåãããŸãã詳现ãªå©çšç¶æ³ãèšé²ãããå Žåã«ã¯ããã¡ããéžæããŸãã åè : 䜿çšç¶æ³ãã°ãšã¹ãã¬ãŒãžãã° ã»ãã¥ãªã㣠ã¢ã¯ã»ã¹å¶åŸ¡ïŒIAM ãš ACLïŒ Cloud Storage ã®ã»ãã¥ãªãã£ã«ãããŠãæãéèŠãªã®ã¯ã¢ã¯ã»ã¹å¶åŸ¡ã®ä»çµã¿ã§ãã åè : ã¢ã¯ã»ã¹å¶åŸ¡ã®æŠèŠ ãã±ããã®ã¢ã¯ã»ã¹å¶åŸ¡èšå®ã«ã¯ããåäžïŒUniformïŒããšããã现ãã管çïŒFine-grainedïŒããããããã±ããããšã«éžæã§ããŸããå¯èœãªéãåè
ã®åäžïŒUniformïŒãå©çšããããšãæšå¥šãããŠããŸããåè
ã®åäžïŒUniformïŒã¯ãã±ããã¬ãã«ã§ IAM ïŒIdentity and Access ManagementïŒã䜿ã£ãŠå¶åŸ¡ããŸããåŸè
ã®ãã现ãã管çïŒFine-grainedïŒã¯ãªããžã§ã¯ãããšã« ACL ã䜿ã£ãŠå¶åŸ¡ããŸãã ãã现ãã管çïŒFine-grainedïŒã¯ Amazon S3 ãšã®çžäºéçšæ§ã®ããã«çšæãããæ©èœã§ããã现ãããªããžã§ã¯ãããšã®æš©é管çã¯ç
©éã§ãããéçšå·¥æ°ãé«ããªããããããããŸããããããåè
ã®åäžïŒUniformïŒç®¡çãæšå¥šãããçç±ã§ãã ãã®ããšããããã±ããã¯ãã¢ã¯ã»ã¹æš©éã®ãŠãŒã¹ã±ãŒã¹ããšãã«äœæãããã®ããã§ãã±ããããšã«æš©é管çãããããšãæãŸãããšãããŸãã ãŸã Google Cloud ã® IAM ã®åºæ¬çãªä»çµã¿ã«ã€ããŠã¯ä»¥äžã®èšäºã§è©³çްã«è§£èª¬ããŠããŸãã®ã§ããåç
§ãã ããã blog.g-gen.co.jp ãããªãã¯å
¬é Cloud Storage ã®ãªããžã§ã¯ãã¯ããããªãã¯å
¬éèšå®ã«ããããšã§ã€ã³ã¿ãŒãããã®ã©ãããã§ãã¢ã¯ã»ã¹ã§ããããã«èšå®ã§ããŸãã ãããªãã¯å
¬éãããããŒã¿ãžã¢ã¯ã»ã¹ããæ¹æ³ã¯ä»¥äžã®ãããªãã®ããããŸãã URIïŒ https://storage.googleapis.com/(BUCKET_NAME)/(OBJECT_NAME) ïŒ Google Cloud ã³ã³ãœãŒã« Google Cloud CLIïŒgsutilãgcloudïŒ ãããªãã¯å
¬éã®çŠæ¢ æå³ããªããã±ããããªããžã§ã¯ãã«ã誀ã£ãŠãããªãã¯å
¬éèšå®ãããªãããã«æ³šæãå¿
èŠã§ãã Cloud Storage ã§ã¯ããã±ããåäœã§ ãããªãã¯å
¬éã®çŠæ¢ ïŒpublic access preventionïŒãèšå®ããããšãã§ããŸããèšå®ãããšããªããžã§ã¯ãåå¥ã®èšå®ã«é¢ãããããªããžã§ã¯ããžã®ã¢ã¯ã»ã¹ã«ã¯ Google ã¢ã«ãŠã³ãã«ããèªèšŒãå¿
é ã«ãªããŸããã€ãŸãããªããžã§ã¯ãã®ã€ã³ã¿ãŒãããå
¬éãé²ãããšãã§ããŸãã åè : å
¬éã¢ã¯ã»ã¹ã鲿¢ãã Cloud Storage ã§æå³ããªãããŒã¿æŒæŽ©ãé²ãã«ã¯ã以äžã®ããã«ãã±ããã䜿çšããŸãã ãã€ã³ã¿ãŒãããã«å
¬éãããªããžã§ã¯ãããšãå
¬éããªããªããžã§ã¯ããããåããã±ããã«æ··åšãããªã ã€ã³ã¿ãŒãããå
¬éã®å¯èœæ§ããªããã±ããã§ã¯ããããªãã¯å
¬éã®çŠæ¢èšå®ãæå¹åãã IP ã¢ãã¬ã¹å¶é 2ã€ã®ææ³ åºæ¬çã«ãCloud Storage ãã¯ãããšãããããªãã¯ã¯ã©ãŠããµãŒãã¹ã¯ãAPI ãšã³ããã€ã³ããã€ã³ã¿ãŒãããã«å
¬éãããŠããç¶æ
ã§ãããåŸæ¥åã® IP ã¢ãã¬ã¹å¶åŸ¡çïŒå¢çåã»ãã¥ãªãã£ïŒ ã§ã¯ãªã ãIAM ãªã©ã®èªèšŒã»èªå¯ã®ä»çµã¿ã§ã»ãã¥ãªãã£ãæ
ä¿ããã®ãååã§ãã æ¥ç¶å
IP ã¢ãã¬ã¹å¶éãèšå®ãããšãéçšã®ç
©éåãã¢ã¯ã»ã¹æš©é管çã®è»œèŠã«ã€ãªããããããããããšããã æ¬åœã«æ¥ç¶å
IP ã¢ãã¬ã¹å¶éãå¿
èŠãã©ããæ
éã«æ€èš ããããšãæšå¥šãããŸãã ããããªãããCloud Storage ã§ã¯ä»¥äžã®2ã€ã®æ¹æ³ã®ããããã§ãæ¥ç¶å
IP ã¢ãã¬ã¹å¶éãå®çŸã§ããŸãã VPC Service Controls ãã±ãã IP ãã£ã«ã¿ãªã³ã° VPC Service Controls åè
ã® VPC Service Controls ã¯ãGoogle Cloud API å
šè¬ã«å¯ŸããŠãæ¥ç¶å
IP ã¢ãã¬ã¹ãæ¥ç¶å
VPC ãããã€ã¹ããªã·ãŒãªã©ã«åºã¥ããã¢ã¯ã»ã¹å¶åŸ¡ãèšå®ããããã® Google Cloud ãµãŒãã¹ã§ãã詳现ã¯ä»¥äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp ãã±ãã IP ãã£ã«ã¿ãªã³ã° åŸè
ã® ãã±ãã IP ãã£ã«ã¿ãªã³ã° ïŒBucket IP filteringïŒã¯ãCloud Storage ã«åãä»ãã®æ¥ç¶å
IP å¶éã®ä»çµã¿ã§ããVPC Service Controls ãšåæ§ã«ãæ¥ç¶å
IP ã¢ãã¬ã¹ãæ¥ç¶å
VPC ãå¶éã§ããŸããçžéç¹ã¯ããã±ããåäœã§ã®èšå®ãå¯èœãªç¹ããŸãããã€ã¹ããªã·ãŒã«åºã¥ããå¶åŸ¡æ©èœã¯ååšããŠããªãç¹ã§ãã æ³šæç¹ãšããŠããã±ããã§ IP ãã£ã«ã¿ãªã³ã°ãæå¹åãããšãCloud Storage ãã BigQuery ãžã®ããŒã¿ããŒããå€éšããŒãã«ã®èªã¿èŸŒã¿ãªã©ãäžéšã®æ©èœã䜿çšã§ããªããªããŸãããã®ãããªæ©èœã䜿ã£ãŠããå Žåã§æ¥ç¶å
ã®å¶åŸ¡ãããããšãã¯ãVPC Service Controls ã®äœ¿çšãæ€èšããŠãã ããã詳现ã¯ä»¥äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : ãã±ãã IP ãã£ã«ã¿ãªã³ã° ãããŒãžããã©ã«ã Cloud Storage ãã±ããã®å
éšã«ã¯ãã©ã«ããäœæããããšãã§ããŸããéåžžã®æé ã§ãã©ã«ããäœæãããšããã®ãã©ã«ã㯠ã·ãã¥ã¬ãŒãããããã©ã«ã ïŒSimulated foldersïŒãšããçš®é¡ã«ãªããŸããã·ãã¥ã¬ãŒãããããã©ã«ãã¯ã ãããŒãžããã©ã«ã ã«ã¢ããããŒãããããšãå¯èœã§ãã ãããŒãžããã©ã«ãã§ã¯ããã©ã«ãåäœã§ã® IAM æš©é管çãã§ãããããã现ããæš©é管çãå¯èœã§ãããã詳现ãªå
容ã¯ã以äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp æå·å Cloud Storage ã«ä¿ç®¡ãããããŒã¿ã¯ãããã©ã«ãã§ãèªåçã«æå·åãããŸãã åè : ããŒã¿æå·åãªãã·ã§ã³ ããã©ã«ãã®èªåçãªæå·åã¯ã¹ãã¬ãŒãžã¬ãã«ã®æå·åã§ãããå©çšè
ããã¯ééçã«è¡ããããããæèãããããšã¯ãããŸããã ééçãªæå·åã¯ãGoogle ã®å
éšç¯è¡ãç©ççãªçé£ãªã©ã«å¹æãçºæ®ãããã®ã§ããã äžæ£ã¢ã¯ã»ã¹ã«å¯Ÿæã§ãããã®ã§ã¯ãªã ããšã«æ³šæãå¿
èŠã§ãã ãã®æå·å㯠Google ã管çããéµã§è¡ãããŸãããåçš®èŠå®ãç£æ»ãžã®å¯Ÿå¿ã®ããå¿
èŠã§ããã°å©çšè
åŽã®æäŸããéµã§æå·åãããããšãã§ããŸãã ãã®å Žåã Cloud KMS ãçšããŠéµã管çãã Customer-managed encryption key ãšããæ¹æ³ã®ã»ããCloud Storage API ãžã®ãªã¯ãšã¹ãã®åºŠã«éµãæå®ãã Customer-supplied encryption key ãšããæ¹æ³ããããŸãã ããããå©çšè
åŽã§ æå·åéµãéçšãããšããéçšè² è· ãçºçããŸãã®ã§ãæ¬åœã«å¿
èŠãªãšãã«ã®ã¿æ€èšããã¹ãã§ãã 眲åä»ã URL 眲åä»ã URL ïŒsigned URLïŒæ©èœã䜿ãããšã§ãè±æ°åã®çœ²åããŒã¯ã³ä»ãã® URL ãç¥ã£ãŠãã人ãã¢ã¯ã»ã¹ã§ãããæéå¶éä»ãã® URL ãçºè¡ããããšãã§ããŸãã ã¯ãšãªæååå
ã«èªèšŒæ
å ±ãå
¥ã£ãŠãããããå¶éæéå
ã§ããã°ã URL ãç¥ã£ãŠãã人ã§ããã°èª°ã§ã ã¢ã¯ã»ã¹ã§ããŸãã Google ã¢ã«ãŠã³ãããµãŒãã¹ã¢ã«ãŠã³ãã«ããèªèšŒã䜿ããªãå Žé¢ã§ãéå®çãªã¢ã¯ã»ã¹ïŒãªããžã§ã¯ãã®ã¢ããããŒããããŠã³ããŒãïŒãæäŸããããšãã«å©çšããŸãã 眲åä»ã URL ã¯ã以äžã®ãããªãã©ãŒãããã«ãªããŸãã https://storage.googleapis.com/example-bucket/cat.jpeg?X-Goog-Algorithm=GOOG4-RSA-SHA256&X-Goog-Credential=example%40example-project.iam.gserviceaccount.com%2F20181026%2Fus-central1%2Fstorage%2Fgoog4_request&X-Goog-Date=20181026T181309Z&X-Goog-Expires=900&X-Goog-SignedHeaders=host&X-Goog-Signature=247a2aa45f169edf4d187d54e7cc46e4731b1e6 (äžç¥) c56c5ca81ff3447032ea7abedc098d2eb14a7 眲åä»ã URL 㯠gsutil ã³ãã³ã ãåããã°ã©ãã³ã°èšèªã® Google authentication library ãªã©ãçšããŠçæããããšãã§ããŸããçæããéã¯ãGoogle ã¢ã«ãŠã³ãçã«ããèªèšŒãå¿
èŠã§ãã åè : 眲åä»ã URL çµç¹ã®ããªã·ãŒ çµç¹ã®ããªã·ãŒ æ©èœã䜿ãããšã§ãåã çµç¹ ïŒOrganizationïŒã«æå±ããŠããå
šãŠã® Google Cloud ãããžã§ã¯ãã§ Cloud Storage ã®èšå®ã匷å¶ããããšãã§ããŸãã äŸãã°ããããªãã¯ã¢ã¯ã»ã¹ãçµç¹é
äžã®å
šãŠã® Cloud Storage ãã±ããã§çŠæ¢ããããªã©ã®çµ±å¶ãå¯èœã§ãã Cloud Storage ã«å¯ŸããŠäœ¿ããçµç¹ã®ããªã·ãŒã¯ä»ã«ãè€æ°ããã以äžã®å
¬åŒããã¥ã¡ã³ãã«ãªã¹ããããŠããŸãã åè : Cloud Storage ã®çµç¹ã®ããªã·ãŒã«é¢ããå¶çŽ çµç¹ã®ããªã·ãŒæ©èœã®è©³çްã«ã€ããŠã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp ããã©ãŒãã³ã¹ãšæŽåæ§ åºæ¬çãªä»æ§ Cloud Storage ã¯ãã«ãããŒãžããªãµãŒããŒã¬ã¹ãµãŒãã¹ã§ããååãšããŠãä»ã®ãŠãŒã¶ãŒãšç©çãªãœãŒã¹ãå
±çšãããã«ãããã³ãã®ãµãŒãã¹ã§ãã ç¹å®ã®ãã±ããã®ã¢ã¯ã»ã¹è² è·ãäžæãããšãCloud Storage ã¯èªåã¹ã±ãŒãªã³ã°ãè¡ããè€æ°ãµãŒããŒã«ãªã¯ãšã¹ãã忣ããŸãã 詳现ãªä»æ§ã¯ã以äžã®ããã¥ã¡ã³ããåç
§ããŠãã ããã åè : ãªã¯ãšã¹ã ã¬ãŒããšã¢ã¯ã»ã¹åæ£ã®ã¬ã€ãã©ã€ã³ Rapid Cache Rapid Cache ïŒæ§ç§° Anywhere CacheïŒã¯ãCloud Storage ãã±ããã«ä»äžã§ããããŸãŒã³ããŒã¹ã®ãã£ãã·ã¥æ©æ§ã§ãããŸãŒã³ã«ãã£ãã·ã¥ãäœæããããšã§ãã¬ã€ãã³ã·ã®ççž®ãããã«ããªãŒãžã§ã³ãã±ããã®å Žåã®ãªãŒãžã§ã³éããŒã¿è»¢éæéã®ç¯çŽã«åœ¹ç«ã¡ãŸãã ãã ãããã£ãã·ã¥ã䜿ããã®ã¯ããã£ãã·ã¥ãšåããŸãŒã³ã® Compute Engine VM ã®ã¿ã§ããCompute Engine VM ãã Cloud Storage ãã±ãããžã®é »ç¹ãªã¢ã¯ã»ã¹ãããå Žåã«ãRapid Cache ã®å©çšãæ€èšããŸããç¹ã«ãæ©æ¢°åŠç¿ã¢ãã«ã®ãã¬ãŒãã³ã°ãããŒã¿åæãªã©ãããŒã¿ã®æŽæ°ã¯å°ãªãèªã¿åããå€ãã¯ãŒã¯ããŒãã«é©ããŠããŸãã Rapid Cache ã®è©³çްãªä»æ§ã¯ã以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : Rapid Cache ãªããžã§ã¯ãã®åœå Cloud Storage ã¯åæ£ã¢ãŒããã¯ãã£ã§ãããããã¯ãšã³ãã«ã¯è€æ°ã®ãµãŒããŒããããŸãããŸããªããžã§ã¯ãåãªã©ã管çããã€ã³ããã¯ã¹ã¯èŸæžé ã«äžŠã³æ¿ããããŠãããåæ£ç®¡çãããŠããŸãããã®ã€ã³ããã¯ã¹ã®èªã¿æžãæã®è² è·åæ£ã«ã¯ããªããžã§ã¯ãåïŒãã¹ïŒã䜿ãããŸãã ããããªããžã§ã¯ãåã以äžã®ããã«é£ç¶çã ãšãè² è·åæ£ããããã«åäžã®ã€ã³ããã¯ã¹ç¯å²ãã¢ã¯ã»ã¹ããç¶ããŠããŸããè² è·åæ£ãã§ããªãããã åæå€§éãªã¯ãšã¹ãã®éã«ããã©ãŒãã³ã¹ãäœäž ããŸãã /2022-03-18-19-24-00/access_log.txt /2022-03-18-19-24-01/access_log.txt /2022-03-18-19-24-02/access_log.txt åæå€§éãªã¯ãšã¹ããããããå Žåã¯ã以äžã®ããã« ãªããžã§ã¯ãåã®æåã«ã©ã³ãã ãªæååãä»äž ããããšã§ãããã©ãŒãã³ã¹ãåäžã§ããŸããäŸãšããŠãMD5 ã§ãªããžã§ã¯ãåãããã·ã¥åããŠæåã®6æåãåãæ¹æ³ãªã©ããããŸãã /q84ic3-f2022-03-18-19-24-00/access_log.txt /zbfg9t-2022-03-18-19-24-01/access_log.txt /2w99uk-2022-03-18-19-24-02/access_log.txt åè : ãªã¯ãšã¹ã ã¬ãŒããšã¢ã¯ã»ã¹åæ£ã®ã¬ã€ãã©ã€ã³ - åœåèŠåã䜿ã£ãŠè² è·ãããŒã®ç¯å²ã«åçã«åæ£ãã æŽåæ§ Cloud Storage ã¯åæ£ã¢ãŒããã¯ãã£ã®ã¹ãã¬ãŒãžã§ãããæžã蟌ã¿ãåé€ã®åŸã®èªã¿åããªãã¬ãŒã·ã§ã³ã¯ 匷æŽåæ§ ã§å®çŸãããŠããŸãã æŽåæ§ ãšã¯ãã¹ãã¬ãŒãžãããŒã¿ããŒã¹ã«ãããŠãæžã蟌ã¿åŠçãå®äºãããåŸã«èªã¿åããããå Žåã«ããã€ã®æç¹ã®ããŒã¿ãèªã¿åãããããç€ºãæŠå¿µã§ãã 忣ã¢ãŒããã¯ãã£ã®ã¹ãã¬ãŒãžã§ã¯ãæžã蟌ã¿ãªãã¬ãŒã·ã§ã³ãå®äºããåŸã§ãããã®æžã蟌ã¿å
容ãå
šãŠã®åæ£ããŒãã«è€è£œããããŸã§ã®éãæžã蟌ã¿ãªãã¬ãŒã·ã§ã³å®è¡åã®å€ãæ
å ±ãèªã¿åãããå¯èœæ§ããããäžå®ã®æéãçµã£ãŠããæŽåæ§ãåãããå¯èœæ§ããããŸãããã®ãããªæŽåæ§ã®æ§è³ªã¯ã çµææŽåæ§ ãšåŒã°ããŸãã äžæ¹ã§ãããæžã蟌ã¿ãªãã¬ãŒã·ã§ã³ãå®äºããåŸã«èªã¿åããªãã¬ãŒã·ã§ã³ãå®è¡ããå Žåã«ããã®æžã蟌ã¿å
容ãå¿
ãèªã¿åãããå Žåããã®æ§è³ªã¯ 匷æŽåæ§ ãšãããŸããCloud Storage ã¯ããªããžã§ã¯ãã®æžã蟌ã¿åŸã®èªã¿åããåé€åŸã®èªã¿åããªã©ãã»ãšãã©ã®ãªãã¬ãŒã·ã§ã³ã§ã°ããŒãã«ãªåŒ·æŽåæ§ãå®çŸããŠããŸãã ãã ããã¢ã¯ã»ã¹å¶åŸ¡èšå®ã®å€æŽãªã©äžéšã®ãªãã¬ãŒã·ã§ã³ã¯ãçµææŽåæ§ã§ããèšå®å€æŽåŸãé©çšããããŸã§1åãæ°åçšåºŠã®æéããããå ŽåããããŸãã åè : Cloud Storage ã®æŽåæ§ éå±€åå空é éå±€åå空é ïŒHierarchical namespaceïŒã¯ãCloud Storage ã§ãã¡ã€ã«ã·ã¹ãã ã©ã€ã¯ãªéå±€æ§é ãããªãã¡ãã©ã«ãã«ãããªããžã§ã¯ãæŽçãå®çŸ©ããããšã§ãããã©ãŒãã³ã¹åäžãå³ãæ©èœã§ããäž»ã«ä»¥äžã®ãããªãŠãŒã¹ã±ãŒã¹ã§èšå®ããŸãã HadoopãSpark ãã Cloud Storage ã³ãã¯ã¿çã§æ¥ç¶ããŠãªããžã§ã¯ããžã¢ã¯ã»ã¹ãããšã ãããåæåŠçãHPC ãªã©ãããªããžã§ã¯ããžã¢ã¯ã»ã¹ãããšã TensorFlowãPandasãPyTorch ãªã©ã® AI/ML ãã¬ãŒã ã¯ãŒã¯ãããªããžã§ã¯ããžã¢ã¯ã»ã¹ãããšã äžèšã®ãããªã¯ãŒã¯ããŒãã«ãããŠã¯ãéå±€åå空éã䜿çšããããšã§ããªããžã§ã¯ãã®ç®¡çãæ€çŽ¢ãæé©åããããããã¡ã€ã«ããã©ã«ãã®åå倿Žã®ãããªãã¡ã€ã«ã·ã¹ãã ã©ã€ã¯ãªåŠçãæé©åãããããšã§ãããã©ãŒãã³ã¹ãåäžããå¯èœæ§ããããŸãã éå±€åå空éã®æå¹åã¯ããã±ããäœææã«æå®ããå¿
èŠããããŸãããªãæå¹åãããšãä¿æããªã·ãŒïŒBucket LockïŒãã¯ãã¹ãã±ãã ã¬ããªã±ãŒã·ã§ã³ãããŒãžã§ãã³ã°ãªã©å€ãã®æ©èœã䜿çšã§ããªããªãç¹ã«çæããŠãã ããã詳现ã¯ä»¥äžã®ããã¥ã¡ã³ãã確èªããŠãã ããã åè : éå±€åå空é ããŒã¿ã¬ã€ã¯ ããŒã¿ã¬ã€ã¯ãšããŠã® Cloud Storage æ±äº¬ãªãŒãžã§ã³ã® BigQuery ã®ã¹ãã¬ãŒãžæéã¯ãActive ã¹ãã¬ãŒãžã $0.023/GB ãLong-term ã¹ãã¬ãŒãžã $0.016 ã§ããããã¯æ±äº¬ãªãŒãžã§ã³ã® Cloud Storage ã®ã¹ãã¬ãŒãžäŸ¡æ ŒããStandard ã§ $0.023ãNearline ã§ $0.016 ã§ããã®ãšäžèŽããŠããŸãïŒãããã 2025幎12æçŸåšïŒã åè : BigQuery pricing åè : Cloud Storage pricing ãã®ããšãã Google Cloud ã§ã¯ ããŒã¿ã¬ã€ã¯çšã®ã¹ãã¬ãŒãž ãšã㊠ïŒåïŒæ§é åããŒã¿ã¯ BigQuery ã«ä¿ç®¡ ã éæ§é åããŒã¿ã¯ Cloud Storage ã«ä¿ç®¡ ããšãã䜿ãåããããããšãå€ããšãããŸãã ãã㯠AWS ã«ãããŠãããŒã¿ã¬ã€ã¯ã¯ Amazon S3 ãããŒã¿ãŠã§ã¢ããŠã¹ã« Amazon Redshiftããšããäœ¿ãæ¹ãããã®ãšã¯ãå°ãç°ãªã£ãŠããŸããå§ãããæ§é åããŒã¿ãããŒã¿ãŠã§ã¢ããŠã¹ã§ãã BigQuery ã«å
¥ããŠããããšã§ãããŒã¿ã®ç§»éãäžèŠã«ãªããŸãã BigQuery ãä»ãµãŒãã¹é£æº Cloud Storage 㯠BigQuery ãšã®é£æºã®é¢ã§ãåªããŠããŸãã Cloud Storage ãªããžã§ã¯ããšããŠé
眮ãã CSVãJSONãAvroãORCãParque çã®ãã¡ã€ã«ãã BigQuery ã®ããŒãã«ã«ããŒãïŒèªã¿èŸŒã¿ïŒããããšãã§ããŸããäŸãšããŠä»¥äžã®ãããªæ¹æ³ããããŸãã BigQuery ã®æ¢åããŒãã«ã« Cloud Storage ãªããžã§ã¯ããããŒã BigQuery ã®ããŒãã«äœææã«å
ãã¡ã€ã«ãšã㊠Cloud Storage ãªããžã§ã¯ããæå® BigQuery Data Transfer Service ã§èªåãžã§ããäœæ ãŸã BigQuery ãã å€éšããŒãã«å®çŸ© ãè¡ãããšã§ãçŽæ¥ Cloud Storage ãªããžã§ã¯ãã«å¯ŸããŠã¯ãšãªããããããšãå¯èœã§ãã ãªããžã§ã¯ãã³ã³ããã¹ã ãªããžã§ã¯ãã³ã³ããã¹ã ïŒObject contextsïŒã¯ããªããžã§ã¯ãã«ã³ã³ããã¹ãæ
å ±ïŒèæ¯æ
å ±ïŒãæ·»ä»ããŠãããŒã¿ã®ç®¡çãæ€åºã«åœ¹ç«ãŠãæ©èœã§ãããªããžã§ã¯ãã³ã³ããã¹ãã§ã¯ãCloud Storage ãªããžã§ã¯ãã«æååãããŒã»ããªã¥ãŒã®ãã¢ãšããŠä»äžã§ããŸãã åè : ãªããžã§ã¯ã ã³ã³ããã¹ã æååãããŒã»ããªã¥ãŒã§ä¿åã§ããç¹ã§ã¯ãªããžã§ã¯ãã¡ã¿ããŒã¿ãšåæ§ã§ããããªããžã§ã¯ãã³ã³ããã¹ãã®å Žåã¯ãã³ã³ããã¹ãæ
å ±ã®è¿œå ã倿Žãåé€ã«å¯Ÿããç¬èªã® IAM æš©éãååšããŠããç¹ãç°ãªããŸãããªããžã§ã¯ãã¡ã¿ããŒã¿ã®èªã¿åãã»æžãèŸŒã¿æš©éã¯ããªããžã§ã¯ããã®ãã®ã®æš©éãšåäžã§ããäžæ¹ã®ãªããžã§ã¯ãã³ã³ããã¹ãã«ã¯ãå°çšã® IAM æš©éãçšæãããŠããŸããããã«ããããªããžã§ã¯ãã®ããŒã¿ãã®ãã®ãšããªããžã§ã¯ãã³ã³ããã¹ãã§ãããããå¥ã
ã®ç®¡çè
ãåœãŠãããããšã«ãªããŸãã ãªããžã§ã¯ãã³ã³ããã¹ãã®ãŠãŒã¹ã±ãŒã¹ãšããŠã以äžã®ãããªãã®ãæããããŸãã å人è奿
å ±ïŒPIIïŒãå«ããªããžã§ã¯ãã®æç€º ã¯ãŒã¯ãããŒã®ç¶æ
ã®è¿œè·¡ïŒ ã¬ãã¥ãŒåŸ
ã¡ ã æ¿èªæžã¿ çïŒ ã¢ããªã±ãŒã·ã§ã³ãã䜿çšããä»å æ
å ± ããŒã¿ã®è»¢é Storage Transfer Service Cloud Storage ã®é¢é£ãµãŒãã¹ãšããŠã Storage Transfer Service ããããŸããStorage Transfer Service ã䜿ããšãAmazon S3 ããã¡ã€ã«ã·ã¹ãã ãªã©ã®æ§ã
ãªããŒã¿ãœãŒã¹ããããã¡ã€ã«ã Cloud Storage ã«å¯ŸããŠè»¢éã§ããŸãã ãžã§ããèšå®ããããšã§ããã¡ã€ã«æ°ãããŒã¿éã倧éã®å Žåã«ãå¹ççãªããŒã¿è»¢éãè¡ãããšãã§ããŸãã åè : Storage Transfer Service ãŸã Amazon S3 ããã®è»¢éã®éã«ãªãã·ã§ã³ã§ Google ã管çãããã©ã€ããŒã ãããã¯ãŒã¯ ãæå¹åãããšãAWS ããã®ãããã¯ãŒã¯è»¢éæéãçºçããã«ã代ããã« Google Cloud åŽã®æéãçºçããŸããããã«ãããå®äŸ¡ãªè»¢éæéã§ Amazon S3 ãã Cloud Storage ãžã®ããŒã¿è»¢éãå®çŸã§ããŸãã åè : Amazon S3 ãã Cloud Storage ãžã®è»¢é - äžãïŒå€åãïŒãªãã·ã§ã³ ã¯ãã¹ãã±ãã ã¬ããªã±ãŒã·ã§ã³ ã¯ãã¹ãã±ãã ã¬ããªã±ãŒã·ã§ã³ ïŒcross-bucket replicationïŒæ©èœã䜿ããšããããã±ããã«äœæãããæ°ãããªããžã§ã¯ããæŽæ°ããããªããžã§ã¯ãããéåæã«å¥ã®ãã±ããã«è€è£œã§ããŸãã ãã®æ©èœã®ããã¯ãšã³ãã§ã¯ãStorage Transfer Service ã䜿ãããŠããŸãã åè : ããŒã¿ã®å¯çšæ§ãšèä¹
æ§ - ã¯ãã¹ãã±ãã ã¬ããªã±ãŒã·ã§ã³ ä»ãµãŒãã¹ãšã®é£æº ã€ãã³ãããªãã³ã»ã¢ãŒããã¯ã㣠æ°ãããªããžã§ã¯ããäœæããããšããåé€ããããšããªã©ã察å¿ããŠããã€ãã³ããçºçããéã«ã Cloud Pub/Sub ã«éç¥ãããã Cloud Run functions ãèµ·åããããšãã§ããŸãã åè : Cloud Storage ã® Pub/Sub éç¥ ããã«ãããäŸãã°ä»¥äžã®ãããªåŠçãå¯èœã«ãªããŸãã ãŠãŒã¶ãŒãã¢ããªã±ãŒã·ã§ã³ãéããŠç»åãã¡ã€ã«ã Cloud Storage ã«ã¢ããããŒãïŒ= ãªããžã§ã¯ãäœæïŒ ãªããžã§ã¯ãäœæãããªã¬ãŒã«ã㊠Eventarc ãèµ·åãPub/Sub ã«ã¡ãã»ãŒãžãæå
¥ããã Cloud Run ã Pub/Sub ã¡ãã»ãŒãžãèªã¿åããç»åããµã ãã€ã«åããŠå¥ã® Cloud Storage ãã±ããã«é
眮 ãã®ããã«ããªããžã§ã¯ãã®äœæãªã©äœããã®ã€ãã³ããããªã¬ã«åŠçãèµ°ãæ§æãã ã€ãã³ãããªãã³ã»ã¢ãŒããã¯ã㣠ãšåŒã³ãŸãã ãã®ã€ãã³ãããªãã³ã®èãæ¹ã¯ããµãŒããŒã¬ã¹ãåŸé課éãççµåãšãã£ãå©ç¹ã掻çšã§ãããããã¯ã©ãŠãã®ã¡ãªãããæå€§é享åã§ããæ¹æ³ã®1ã€ã§ãã ã€ãã³ãããªãã³ãªåŠç VM ã Cloud Run ããã®ããŠã³ã Cloud Storage FUSE ã䜿ããšãLinux ã macOS ãž Cloud Storage ãã±ãããããŠã³ãããããšãã§ããŸãã Cloud Storage ã¯ãæ¬æ¥ã¯ Web API ã§èªã¿æžããããä»çµã¿ã§ããCloud Storage FUSE ã¯ãOS ãããã¡ã€ã«ã·ã¹ãã ã©ã€ã¯ã«ãã±ããã«ã¢ã¯ã»ã¹ã§ãããããã·ã¹ãã ã³ãŒã«ã Cloud Storage ãžã® API ãªã¯ãšã¹ããžæžãæããŠãªã¯ãšã¹ãããŸãããã£ãŠ Cloud Storage FUSE ãé©ããŠããã®ã¯ãã¬ã€ãã³ã·ãæ¯èŒç倧ãããŠãæ§ããªãããã€ã¢ã¯ã»ã¹é »åºŠãå€ãããªããšããéå®çãªæ¡ä»¶ã®å Žåã§ãããå©çšã«åœãã£ãŠã¯ååãªæ€èšŒãå¿
èŠã§ãã åè : Cloud Storage FUSE ãŸãåãä»çµã¿ãçšããŠãCloud Run ã® services ã jobs ã§ãããªã¥ãŒã ãšã㊠Cloud Storage ãã±ãããããŠã³ãããããšãã§ããŸãããã¡ã€ã«ã®èªã¿æžãã®éãã¹ããŒãžã³ã°é åãšããŠã¡ã¢ãªãå©çšãããããã³ã³ããã€ã³ã¹ã¿ã³ã¹ã®ã¡ã¢ãªéçã«æ³šæãå¿
èŠã§ãã åè : Cloud Run ãµãŒãã¹ã«å¯Ÿã㊠Cloud Storage ã®ããªã¥ãŒã ããŠã³ããæ§æãã åè : ãžã§ãã® Cloud Storage ããªã¥ãŒã ã®ããŠã³ããæ§æãã Cloud Run ããã® Cloud Storage ãã±ããã®ããŠã³ãã«ã€ããŠã¯ã以äžã®èšäºãåç
§ããŠäžããã blog.g-gen.co.jp ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO å
èŠå¯å®ãšããçµæŽãæã€ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS èªå®è³æ Œããã³ Google Cloud èªå®è³æ Œã¯ãã¹ãŠååŸãXïŒæ§ TwitterïŒã§ã¯ Google Cloud ã Google Workspace ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-genã®ãããã€ã§ãã åœèšäºã§ã¯ãGoogle Workspaceã®å©çšãã°ãéèšããããã«BigQuery Exportãå©çšããããšãããšããããã£ãŠããŸã£ãä»¶ã«ã€ããŠè§£èª¬ããããŸãã Google Workspaceã®BigQuery Exportãšã¯ Google Workspaceã®BigQuery Exportã®èšå®æ¹æ³ ããŒã¿ã»ããäœæ BigQuery Exportæå¹å Exportãããªã Exportããããªãçç±ãšå¯Ÿå¿æ¹æ³ Google Workspaceã®BigQuery Exportãšã¯ ãŸãã¯Google Workspaceã«ãããBigQuery Exportã¯ã©ã®ãããªæ©èœãªã®ã§ããããïŒ ãã¡ãã¯ãäžèšã§ãããšGoogle Workspaceã®æ¥ã
ã®ãã°ããŒã¿ããã¹ãŠGoogle Cloudã®BigQuery ã«Exportããå¯èŠåãåæã§ãããããªé£æºã®ããã®æ©èœã«ãªããŸãã å©çšçšéãšããŠã¯ä»¥äžã®ããã«è§£èª¬èšäºããããŸãã®ã§ããã²åèã«ããŠã¿ãŠãã ããã japan.zdnet.com Google Workspaceãå©çšäžã®ç€Ÿå¡ãã©ã®ãããªåãæ¹ã宿œããŠããã®ãããå¯èŠåããããã«ã¯äŸ¿å©ãªæ©èœã§ãããšèããŸãã äŸãã°ããŸã®ææã§ããšã瀟å¡ãã©ã®ãããMeetãå©çšããŠããããããã©ãããåããŠããã®ãããªã©ããã°æ
å ±ãããšã«ãããã£ãæ
å ±ãéèšãåæããããšãå¯èœãšãªããŸãã ããŠä»åããã£ãããªã®ã§G-genã§ã宿œããŠã¿ããããšããããšã§ãå®éã«æ¬æ©èœãå©çšããŠã¿ãããšãããšããããã£ãŠããŸã£ãããšããç¹ã«é¢ããŠãç°¡åã«èª¬æããŠãããããšæ³ããŸãã Google Workspaceã®BigQuery Exportã®èšå®æ¹æ³ ãŸãã¯ç°¡åã«èšå®æ¹æ³ã«é¢ããŠèª¬æããããŸããBigQuery Exportã®èšå®ã«é¢ããŠã¯ããã£ãŠã·ã³ãã«ã§ãã (1)Google Cloud BigQueryã«å
¥ãç©ãšãªãããŒã¿ã»ãããçšæããã (2)Google Workspaceã®ç®¡çè
èšå®ã«ãããŠãäžèš(1)ã§äœæããããŒã¿ã»ããã«å¯ŸããŠExportãæå¹åããã ãã®2ç¹ã«ãªããŸããè³ã£ãŠã·ã³ãã«ã§ãããããŸã®ãšãããã©ãã«ããããèŠçŽ ã¯ãªãã§ããã ããŒã¿ã»ããäœæ 詳现ã®èª¬æã¯çããŸããããŸãã¯Google Cloudã®BigQueryã®ç»é¢ã«ãŠããŒã¿ã»ãããäœæããããŸãã 以äžã®ãããªåœ¢ã§äœæãå®äºããŠãããŸãã ããŒã¿ã»ããã®äœæ BigQuery Exportæå¹å ãã¡ããå®éã®èšå®ã¯ãã®ãããã·ã³ãã«ã§ã管çè
ãŠãŒã¶ãŒã§ãã°ã€ã³åŸã®ç»é¢ã«ãŠ ãã¬ããŒãïŒBigQuery Exportãã«ãŠãBigQueryã®ãããžã§ã¯ãIDããã³ããŒã¿ã»ããã®ååãæå®ããŠçµäºã Google Workspace 管çè
èšå®ç»é¢ ããã§Googleããã®æ£åŒåçã«ãããšã以äžãšã®ããšãªã®ã§æ°æ¥åŸ
ãŠã°ç¢ºå®ã«ExportãããŠããããšã§ãããã äžè¬çãªãæ¡å
ãšããŸããŠç®¡çã³ã³ãœãŒã«äžã§ã®èšå®ãåæ ããããŸã§æå€§ 24 æéãããå ŽåãããããŸãããŸããããŒã¿ãçæãããã®ã¯å€ªå¹³æŽæéã®æ¥æãšãªãããšããããšã¯ã¹ããŒãã«ãæéãããã£ãŠããå¯èœæ§ãããããŸãã Exportãããªã çæéã«æ€èšŒããŠããŸã£ãŠããããšããã®ãããã®ã§ãããåŸ
ãŠã©ãåŸ
ãŠã©ãExportãããªãããã°ãã¿ããªãããšããç¶æ³ã«ãªã£ãŠããŸããŸããã ãšããããšã§äžæŠGoogleã®ãµããŒãã«åãåããã宿œãæ§ã
ãªãããšãã®çµæã»ã»ã»(äºé
ã«ç¶ã) Exportããããªãçç±ãšå¯Ÿå¿æ¹æ³ ããã€ãã®ãããšãã®çµæã以äžã®Google Cloudã®BigQueryã«ãã㊠ããŒã¿ã»ãããâasia-northeast1âã«æå®ããŠããŸã£ãŠããããšãåå ã ãšããããšãããããŸããã ããŒã¿ã»ããã®ãã±ãŒã·ã§ã³ æ¥æ¬äººã ãšãããã¡ãªæ°ãããŸãããæ£åŒåçãšããŠã¯ ãã±ãŒã·ã§ã³ã EUãUS ãšãã£ãããã«ããªãŒãžã§ã³ãæå®ããã ãå¿
èŠããã ãšããããšã®ããã§ãã©ããã§åŸ
ã£ãŠãåŸ
ã£ãŠãExportãããªãããããšããç¶æ³ã ã£ãããã§ãã ããã€ãGoogleãµããŒãããæçãªURLãããã ããŸããã®ã§å
±æããããŸãã â»ãšã¯ããEUãUSãšããèšèŒã¯ã©ãã«ãç¡ãæ°ãããŸããããã ãã±ããã®ç§»åãšååå€æŽ | Cloud Storage | Google Cloud https://cloud.google.com/storage/docs/moving-buckets ããŒã¿ã®ä¿åå Žæã§ãããªãŒãžã§ã³ã«ã€ããŸããŠã¯ãäžèšããŒãžããåèããã ããŸãã ãã±ããã®ä¿åå Žæ | Cloud Storage | Google Cloud https://cloud.google.com/storage/docs/locations#available-locations ãªããæ¬ä»¶ã® BigQuery Export ã«é¢ããŠãåèããã ãããã«ãèšäºã¯äžèšãšãªããŸãã BigQuery ãããžã§ã¯ãããã°ã¬ããŒãçšã«èšå®ãã - Google Workspace 管çè
ãã«ã https://support.google.com/a/answer/9082756?hl=ja ãµãŒãã¹ãã°ã® BigQuery ãžã®æžãåºããèšå®ãã - Google Workspace 管çè
ãã«ã https://support.google.com/a/answer/9079365?hl=ja BigQueryåŽã®ããŒã¿ã»ãããäœæãçŽãããšãã以äžã®ããã«æ£ããExportãããããã§ããããåæå¯èœãšãªããŸããã æ£ããExportãããããšã®ç»é¢ ä»åã¯æ£ããExportã§ããããšãããšãããŸã§ã«ããŸããã以äžã®ããã«Google Workspaceã§ã¯æ§ã
ãªæ¹æ³ã§ãã°ã®è§£æãå¯èœã§ãã®ã§ããã²è©ŠããŠã¿ãŠã¯ãããã§ããããã blog.g-gen.co.jp éŽæš éæ (èšäºäžèЧ) å·è¡åœ¹å¡ COO ããžãã¹æšé²éš éšé· åºæ¬ããªãã§ãå±ãäž»ã«ããžãã¹ã®ç«ã¡äžããä»çµã¿ã¥ãããå¥œã æ¥ã
ãåªåãæ¥ã
ãæ¥œããããšã倧äºã« ã Professional Cloud Architect / Professional Workspace Administratorã®ã¿ä¿æããŠããŸãããããã倱å¹ããŠããŸããããªäºæã
G-gen ã®ææã§ããProfessional Cloud Network Engineer 㯠Google Cloud ã®ãããã§ãã·ã§ãã«ã¬ãã«ã®èªå®è³æ Œã®1ã€ã§ããGoogle Cloud ã®ãããã¯ãŒã¯ç³»ãµãŒãã¹ã«é¢ããé«åºŠãªç¥èã確èªããé£é¢è©Šéšã§ããåœèšäºã§ã¯ã詊éšã®åæ Œã«åœ¹ç«ã€ TipsãååŒ·æ¹æ³ãåºé¡åŸåçã玹ä»ããŸãã æŠèŠ Professional Cloud Network Engineer 詊éšã«ã€ããŠ é£æåºŠ ååŒ·æ¹æ³ ãããã¯ãŒã¯åºç€ç¥è Google Cloud ç¥è ã«ãŒãã£ã³ã° 仿§ã«é¢ããåèèšäº ã«ã¹ã¿ã ã«ãŒãåºå ±ãšãã¢ãªã³ã° VPC éã®æšç§»çãã¢ãªã³ã° Cloud NAT éå®å
¬éã® Google ã¢ã¯ã»ã¹ãš Private Service Connect ããªã·ãŒããŒã¹ã®ã«ãŒã Network Connectivity Center åºæ¬çãªç¥è ã¹ã¿ãŒããããžãšã¡ãã·ã¥ããããž çµè·¯äº€æã®ä»æ§ Cloud NGFW åºæ¬çãªç¥è FQDN ãªããžã§ã¯ã è©äŸ¡é ã¿ãŒã²ãã VM ã®æå® å
±æ VPC æŠå¿µãšãŠãŒã¹ã±ãŒã¹ IAM Cloud Load Balancing ããŒããã©ã³ãµãŒã®éžæ ã¢ããªã±ãŒã·ã§ã³ããŒããã©ã³ãµãŒ Cloud Router Cloud Router ã®åºæ¬ BGP ã»ãã·ã§ã³ Cloud Interconnect Dedicated Interconnect Partner Interconnect Direct Peering / Carrier Peering Cross-Cloud Interconnect æå·å Cloud DNS 転éãŸãŒã³ åä¿¡ãµãŒããŒããªã·ãŒ ã¹ããªãããã©ã€ãºã³ DNS ãã¢ãªã³ã° DNSSEC ãããã¯ãŒã¯ã»ãã¥ãªã㣠Secure Web Proxy VPC Service Controls Cloud Armor Cloud CDN åºæ¬çãªç¥è ãã£ãã·ã¥ç¡å¹å Google Kubernetes EngineïŒGKEïŒ GKE ã«é¢ããåºé¡ IP ãã¹ã«ã¬ãŒããšãŒãžã§ã³ã ã¢ãã¿ãªã³ã° Packet Mirroring ãš VPC ãããŒãã° ãã¡ã€ã¢ãŠã©ãŒã«ã®ãã° å°çšç·ã VPN ã®ã¢ãã¿ãªã³ã° Network Intelligent Center æŠèŠ Professional Cloud Network Engineer 詊éšã«ã€ã㊠Professional Cloud Network Engineer 詊éšã¯ãGoogle Cloud ã®ãããã¯ãŒã¯ç³»ãµãŒãã¹ãå°çšç·ãVPN çã«é¢ããç¥èãåããããGoogle Cloud ã®èªå®è©Šéšã§ãã 詊éšåé¡ã¯50ã60åãè©Šéšæéã¯120åã§ããè±èªçãšæ¥æ¬èªçãæäŸãããŠããŸãã åœè©Šéšã§ã¯å顿ãé·ããè€éãªãããã¯ãŒã¯æ§æãæç« ã§èª¬æãããããããããã¯ãŒã¯èšèšã«æ
£ããŠããªããšèªã¿è§£ãã«æéããããããšãæ³å®ãããŸããæ§æå³ã§èª¬æããŠããããããªåé¡ã¯ç¡ããå顿ããã£ããèªã¿è§£ãå¿
èŠããããŸãã åè : Professional Cloud Network Engineer é£æåºŠ Professional Cloud Network Engineer 詊éšã®é£æåºŠã¯ã äžãé«çšåºŠ ã ãšèšããŸãã åœè©Šéšã§ã¯ãVPC ãå°çšç·ãNetwork Connectivity Center ãªã©ãäžå¿ã«ãGoogle Cloud ã®ãããã¯ãŒã¯ã®ä»æ§ã«é¢ããæ·±ãç¥èãåãããŸãããŸããCloud DNS ãè€æ°ã® VPC ãããã¯ãŒã¯ããããããã¯ãªã³ãã¬ãã¹ããå©çšãããªã©ã®ç¹å¥ãªãŠãŒã¹ã±ãŒã¹ã«é¢ããåé¡ãåãããŸãã å
¬åŒã®è©ŠéšèŠé
ã«ã¯ãæ¥ççµéšã 3 幎以äžïŒGoogle Cloud ã䜿çšãããœãªã¥ãŒã·ã§ã³ã®èšèšãšç®¡çã®çµéš 1 幎以äžãå«ãïŒãããšããèŠä»¶ãèšèŒãããŠããŸãããå¿
ããããããŸã§ã®çµéšã¯å¿
èŠãããŸããã Google Cloud ã«é¢ãã Professional Cloud Architect çšåºŠã®ç¥èŠã«å ããŠãäžè¬çãªãããã¯ãŒã¯æè¡ã®ç¥èŠãç¹ã«ã«ãŒãã£ã³ã°ããã¡ã€ã¢ãŠã©ãŒã«ãªã©ã«é¢ããç¥èãæã£ãŠããããšãæãŸããã§ãããšã¯ãããGoogle Cloud ã® VPC ã¯ç¬ç¹ã®ä»æ§ãæã£ãŠããŸãã®ã§ãäžè¬çãªç¥èã«å ããŠãGoogle Cloud ç¹æã®ãããã¯ãŒã¯ä»æ§ããã£ãããšåŠãã§ããå¿
èŠããããŸãã ååŒ·æ¹æ³ æšå¥šã®ååŒ·æ¹æ³ã¯ã以äžãšãªããŸãã 詊éšã¬ã€ã ãèªã 詊éšã¬ã€ãã§ææ¡ãã詊éšç¯å²ã«ã€ããŠå匷ãã ãã®é Google Cloud ã«éããªãäžè¬çãªãããã¯ãŒã¯ç¥èã«ã€ããŠã穎åãããã æš¡æ¬è©Šéš ãåãã åœèšäºãèªã¿ãåºé¡åŸåãææ¡ããç¥ããªãç¥èã穎åããã ç¹ã« VPC ãããã¯ãŒã¯ã Cloud VPN ãªã©ã«ã€ããŠãå®éã«æ€èšŒç°å¢ãæ§ç¯ããŠã¿ãããšããå§ãããŸããã³ã³ãœãŒã«ã®æ§ç¯ç»é¢ã CLI ã®ã³ãã³ãæ§é ãèŠãããšã§ãGoogle Cloud ã®ãªãœãŒã¹æ§æãçŽæçã«çè§£ã§ãããããçè§£ãé£èºçã«é²ã¿ãŸãã ã«ãŒãã£ã³ã°ã Cloud DNSãCloud Interconnect ãªã©ã«ã€ããŠã¯ã以äžã®æžç±ãèšèšèŠçŽ ãªã©ã«ã€ããŠè©³ãã解説ããŠããããªã¹ã¹ã¡ã§ãã åè : ãšã³ã¿ãŒãã©ã€ãºã®ããã®Google Cloud ã ã¯ã©ãŠããæŽ»çšããã·ã¹ãã ã®æ§ç¯ãšéçš ãããã¯ãŒã¯åºç€ç¥è åœè©Šéšã®åºé¡å
容ãé©åã«çè§£ããã«ã¯ãGoogle Cloud ã®ç¥è以åã«ãäžè¬çãªãããã¯ãŒã¯çšèªïŒç¹ã« L3 ã L4 ã¬ã€ã€ïŒãçè§£ããŠããå¿
èŠããããŸãããã以äžã®ãããªçšèªã®æŠèŠãçè§£ããŠããªãå ŽåããŸãã¯ããããåŠç¿ããããšãåŒ·ãæšå¥šããŸãã TCP/IP åç
§ã¢ãã«ãOSI åç
§ã¢ãã«ãTCPãUDPãIPããã±ããããã¬ãŒã ã«ãŒã¿ãŒãã«ãŒãã£ã³ã°ãã«ãŒãïŒçµè·¯ïŒãã«ãŒãåºå ±ïŒAdvertisementïŒããã¯ã¹ãããã ãããã¯ãŒã¯ããµãããããVLAN ã«ãŒãã£ã³ã°ãããã³ã«ãBGPãAS çªå·ïŒASNïŒ ãã¡ã€ã¢ãŠã©ãŒã«ãã¹ããŒããã«ã€ã³ã¹ãã¯ã·ã§ã³ãã¹ããŒãã¬ã¹ã€ã³ã¹ãã¯ã·ã§ã³ãL3/L4 ã¬ã€ã€ãããã¯ãŒã¯ã»ãã¥ãªã㣠Web Application FirewallïŒWAFïŒãIPS/IDSãL7 ã¬ã€ã€ãããã¯ãŒã¯ã»ãã¥ãªã㣠NATïŒNetwork Address TranslationïŒ ããŒããã©ã³ã·ã³ã° HTTPãHTTPSãSSL/TLSãèšŒææžãé察称æå·å å°çšç·ãã€ã³ã¿ãŒããã VPNãIPSec DNSããã¡ã€ã³ããªãŒãæš©åš DNS ãµãŒããŒããŸãŒã³ããŸãŒã³ãã©ã¯ãŒãã£ã³ã° Google Cloud ç¥è VPC ã®ã«ãŒãã£ã³ã°ãå°çšç·ãNetwork Connectivity CenterãCloud DNS ã«é¢ããåé¡ãéåžžã«å€ãåºé¡ãããŸãããGoogle Cloud ã®ãããã¯ãŒã¯èšèšã®éã«ãé©åãªããããžãéžæã§ãããããå¯çšæ§ãšã»ãã¥ãªãã£ãèæ
®ããèšèšãã§ãããããå®éçšæã®ãã©ãã«ã«å¯ŸåŠã§ãããããšãã£ã芳ç¹ã®åºé¡ãå€ãã§ãã åºé¡ç¯å²ã¯ã以äžã®ãã㪠Google Cloud ãµãŒãã¹ã§ãã VPC Cloud NGFW Packet Mirroring Cloud Router Cloud NAT Cloud Load Balancing VPC Service Controls Dedicated / Partner Interconnect Cloud VPN Cloud DNS Cloud Armor Network Connectivity Center Network Intelligence Center Google Kubernetes EngineïŒGKEïŒ æ¬èšäºã§ã¯ãã以éã詊éšåæ Œã®ããã«ãå
·äœçã«äœãç¥ã£ãŠããã¹ãããã«ã€ããŠçްããèšè¿°ããŸãã詊éšã®å©çšèŠçŽã®é¢ä¿äžãå
·äœçãªåºé¡å
容ã¯ã玹ä»ã§ããŸããããåœèšäºã詊éšåæ Œã®ããã®åèã«ãªãã°å¹žãã§ãã ã«ãŒãã£ã³ã° 仿§ã«é¢ããåèèšäº Google Cloud ã®ã«ãŒãã£ã³ã°ã®ä»æ§ã«é¢ããåèèšäºãšããŠã以äžãåç
§ããŠãã ããã medium.com blog.g-gen.co.jp ã«ã¹ã¿ã ã«ãŒãåºå ±ãšãã¢ãªã³ã° VPC Peering ã Cloud VPN ãé§äœ¿ããè€éãªãããã¯ãŒã¯æ§æã«ã€ããŠåãããåé¡ãå€ãåºé¡ãããŸãã ãªãã§ã Hub-and-Spoke å (ã¹ã¿ãŒåãšãåŒã°ãã) ã®ãããã¯ãŒã¯ããããžã«é¢ããåé¡ãé »åºã§ãã以äžã«äŸãæããŸãã Hub-VPC ãäžå¿ãšãããããã¯ãŒã¯ ãã®ãããã¯ãŒã¯ã¯ VPC (A) ããããšããŠããªã³ãã¬ãã¹ãµã€ãã VPC (B) ã VPC (C) ãšæ¥ç¶ãããŠããŸããVPC (A) ãš ãªã³ãã¬ãã¹ã¯ Cloud VPN (IPSec VPN) ã§æ¥ç¶ãããŠããã VPC é㯠VPC Peering ã§æ¥ç¶ãããŠããŸãã ãã®ãšããCloud Router ã VPC Peering ãããã©ã«ãã®èšå®ã®ãŸãŸã ãšãããªã³ãã¬ãã¹ãã VPC (B) ãžããšãã£ããã VPC ãçµç±ããé信㯠ã§ãã ãçŽæ¥æ¥ç¶ãããŠãããããã¯ãŒã¯éã®ã¿ã§ããéä¿¡ã§ããŸããã ããããé©åã«èšå®ãããããã°ãå³å³äžã®è¡šã®ããã«çžäºã«ãããã¯ãŒã¯ééä¿¡ãå®çŸã§ããŸããèšå®å
容ã¯ã以äžã®ãšããã§ãã Cloud Router ã«ãŠãªã³ãã¬ãã¹ã®å¯Ÿåã«ãŒã¿ãŒã«åºå ±ããã«ãŒãã æç€ºçã«èšå® ãã ããã©ã«ãã ãš Cloud Router ãçŽã¥ããŠãã VPC (A) ã®ãµããããã® CIDR ããåºå ±ãããªã Peering ã§ç¹ãã£ãŠãã VPC (B) ãš (C) ã®ã«ãŒãã远å ã§åºå ±ãããããæç€ºçã«èšå® VPC (A) åŽã® 2 ã€ãã Peering èšå®ã«ãŠã«ã¹ã¿ã ã«ãŒãã ãšã¯ã¹ããŒãããããèšå® ãã ããã«ãã察åã§ãã VPC (B) ããã³ (C) ã«ã«ã¹ã¿ã ã«ãŒã (ãªã³ãã¬ããåãåã£ã 10.0.0.0/8 ã®ã«ãŒã) ãæž¡ãã VPC (B) ããã³ (C) ã® Peering èšå®ã«ãŠå¯Ÿåã§ãã VPC (A) ããã«ã¹ã¿ã ã«ãŒãã ã€ã³ããŒãããããèšå® ãã ããã«ãã察åã§ãã VPC (A) ããã«ã¹ã¿ã ã«ãŒã (ãªã³ãã¬ããåãåã£ã 10.0.0.0/8 ã®ã«ãŒã) ãåãåãã 1 ã€ç®ã®èšå®ãããªããšããªã³ãã¬ãã¹ã«ãŒã¿ãŒã¯ VPC (B) ãš (C) ãžã®çµè·¯ãç¥ãããšãã§ããŸãããCloud Router ã¯ããã©ã«ãã ãšãèªåãçŽä»ããŠãã VPC ã®ã«ãŒãã®ã¿ãã察åã«ãŒã¿ãŒãžåºå ±ããããã§ããVPC (B) ãš (C) ã®çµè·¯ã察åã«ãŒã¿ãŒãžåºå ±ãããããæç€ºçã«èšå®ããŠãããå¿
èŠããããŸããããã ã«ã¹ã¿ã ã«ãŒãåºå ± ãšãããŸãã 2 ã€ç®ãš 3 ã€ç®ã®èšå®ãããªããšã VPC (B) ãš (C) ã¯ãªã³ãã¬ãã¹ãžã®çµè·¯ãç¥ãããšãã§ããŸãããã«ã¹ã¿ã ã«ãŒãã®ã€ã³ããŒãã»ãšã¯ã¹ããŒãã®èšå®ãããŠãããããšã§ã VPC (A) ããªã³ãã¬ãã¹ããåãåã£ã 10.0.0.0/8 ãšããã«ãŒãã VPC (B) ãš (C) ã«æããŠãããããšãã§ããŸãããªãããã§ãã ã«ã¹ã¿ã ã«ãŒã ãšã¯ Google Cloud ã«ãã£ãŠèªåçã«çæãããã«ãŒã (ããã©ã«ãã«ãŒãããµããããéã®ã«ãŒã) ä»¥å€ ã®åçã»éçãªã«ãŒããæããŠããŸãããã®å³ã§ããã°ããªã³ãã¬ãã¹ãã BGP ã§åãåã£ã 10.0.0.0/8 ãžã®ã«ãŒããã«ã¹ã¿ã ã«ãŒãã«ãªããŸãã è€éã§ãããäžèšã®ãããªäžéãã®èšå®ãè¡ããšã VPC (A) ããããšããçžäºéä¿¡ãå¯èœã«ãªãã®ã§ãã VPC éã®æšç§»çãã¢ãªã³ã° VPC (B) ãš (C) å士ã®éä¿¡ã§ããããã㯠VPC Peering ã§ç¹ãã£ã VPC ãçµç±ããŠéä¿¡ããã æšç§»çãã¢ãªã³ã° ãšåŒã°ãã圢ã«ãªãã VPC ã§ã¯ãã®éä¿¡ã ã§ããªã仿§ ã«ãªã£ãŠããŸãããã㯠AWS ã® VPC Peering ã§ãåæ§ã§ãã2 ãããå¶éããšãåŒã°ããŠããŸãã VPC Peering ã§ã¯ çŽæ¥ç¹ãã£ãŠãã VPC éã§ããéä¿¡ã§ããªã ãšèŠããŠãããŸãããã VPC (B) ãš (C) ãéä¿¡ããããå Žåã¯ããããã çŽæ¥ãVPC Peering ã§ç¹ã å¿
èŠããããŸããã€ãŸã VPC Peering ã§è€æ°ã® VPC ééä¿¡ãå®çŸãããå Žåãæ¥ç¶ã¯ ãã«ã¡ãã·ã¥ ã«ãªããŸãããã«ã¡ãã·ã¥æ§æã§ã¯ãããã¯ãŒã¯ã®æ°ã n ãšãããš n * (n-1) / 2 ã®æ°ã® Peering ãäœæããããšã«ãªããŸãã ãããããã®ãããªãã«ã¡ãã·ã¥æ§æã¯è€éæ§ãé«ããéçšæ§ãäžããããããããé¿ããæ¹æ³ããããŸãããã㯠VPC éã Peering ã§ã¯ãªãã Cloud VPN ã§æ¥ç¶ãã ããšã§ãã Cloud VPN ã§ç¹ãã£ãŠããã°ãå
çšã®å³ã§ãªã³ãã¬ãã¹ãšè¡ã£ãã®ãšåãããã«çµè·¯ã®äº€æãã§ããŸãã®ã§ããã VPC ãäžå¿ãšããããããžã§ VPC ééä¿¡ããããããšãã§ããŸãã Cloud VPN ã«ã¯ å©çšæé ãããã£ãŠããŸããããå®éã®èšèšã§ã¯ã³ã¹ããšéçšæ§ã®ãã¬ãŒããªããæ€èšããããšã«ãªããŸãã Cloud NAT ã»ãã¥ãªãã£äžãVM ã«å€éš IP ã¢ãã¬ã¹ãæãããããšã¯ã§ããã°é¿ããããã®ã§ãã Cloud NAT ã䜿ãã°ãå€éš IP ã¢ãã¬ã¹ãæããªã VM ãã€ã³ã¿ãŒããããžåºãŠããããšãã§ããŸãã Cloud NAT ã VM ã®ãã±ããã NAT ããã®ã¯ãã±ããã 0.0.0.0/0 â default internet gateway ã®ã«ãŒãã䜿ããšãã ãã§ããããã¯ã¹ããããã default internet gateway 以å€ïŒCloud VPN çïŒã§ãã£ããã 0.0.0.0/0 ããçãã¿ãŒã²ãããæå®ãããŠããå Žåã¯ãCloud NAT ã¯äœ¿ãããŸããã åè : Cloud NAT ãããã¯ãã®çžäºäœçš éå®å
¬éã® Google ã¢ã¯ã»ã¹ãš Private Service Connect éå®å
¬éã® Google ã¢ã¯ã»ã¹ ãŸã㯠Private Service Connect ãæ§æããŠããã©ã€ããŒããããã¯ãŒã¯ãã Google Cloud APIs ã«ã¢ã¯ã»ã¹ããæ¹æ³ãææ¡ããŠãã ãããDNS ããã³ã«ãŒãã£ã³ã°ã®èšå®æé ãã€ã¡ãŒãžã§ããããã«ããŠãããŠãã ããã ãªãéå®å
¬éã® Google ã¢ã¯ã»ã¹ã®æå¹åã¯ã ãµããããã®ã¬ãã« ã§è¡ãèšå®ã§ãã åè : éå®å
¬éã® Google ã¢ã¯ã»ã¹ã®ä»çµã¿ãšæé ããã£ã¡ã解説 - G-gen Tech Blog åè : Private Service Connectæ©èœè§£èª¬ãGoogle Cloud APIã«ãã©ã€ããŒãæ¥ç¶ - G-gen Tech Blog ããªã·ãŒããŒã¹ã®ã«ãŒã VPC ãããã¯ãŒã¯ã®ã«ãŒãããŒãã«ã«ã¯ã ããªã·ãŒããŒã¹ã®ã«ãŒã ã远å ã§ããŸããããªã·ãŒããŒã¹ã®ã«ãŒããšã¯ããã±ããã®éä¿¡å
VM ã®ãããã¯ãŒã¯ã¿ã°ãªã©ã«å¿ããŠããã¯ã¹ããããã å
éšãã¹ã¹ã«ãŒããŒããã©ã³ãµãŒ ã«åããããã«ãŒãã§ãã ãã±ãããä»®æ³ãããã¯ãŒã¯ã¢ãã©ã€ã¢ã³ã¹ã«åããŠããã±ããã®æ€æ»çãã§ããããã«ãããŠãŒã¹ã±ãŒã¹ã§äœ¿çšãããŸãããŠãŒã¹ã±ãŒã¹ãèšå®æ¹æ³ãçè§£ããŠãããŠãã ããã åè : ããªã·ãŒããŒã¹ã®ã«ãŒã Network Connectivity Center åºæ¬çãªç¥è Network Connectivity Center ã¯ãGoogle Cloud ã§ããã¢ã³ãã¹ããŒã¯ã®ãããã¯ãŒã¯æ§æãå®çŸããããã®ãã«ãããŒãžããµãŒãã¹ã§ããåœè©Šéšã§ã¯é »åºã§ãã®ã§ãåºæ¬çãªç¥èã以äžã®èšäºã§åŠãã§ãã ããã åè : Network Connectivity Centerã培åºè§£èª¬ïŒ - G-gen Tech Blog ã¹ã¿ãŒããããžãšã¡ãã·ã¥ããããž ã¡ãã·ã¥ããããž ãš ã¹ã¿ãŒããããž ã®æ§æãçè§£ããŠãã ããã ã»ã³ã¿ãŒã¹ããŒã¯ã°ã«ãŒã ãš ãšããžã¹ããŒã¯ã°ã«ãŒã ã®ããããã«ã¹ããŒã¯ãç»é²ããããšã«ãªããŸããã©ã¡ãã«ã¹ããŒã¯ãç»é²ãããšãã©ãã«éä¿¡ã§ããããã«ãªãã®ããææ¡ããŠãã ããã åè : Network Connectivity Centerã培åºè§£èª¬ïŒ - G-gen Tech Blog - ã¡ãã·ã¥ããããžãšã¹ã¿ãŒããããž çµè·¯äº€æã®ä»æ§ ããã«ããã exclude-export-ranges ãã©ã°ãããã€ããªããã¹ã³ãŒãã«ããã include-import-ranges èšå®ãªã©ãNetwork Connectivity Center ã«ãããçµè·¯äº€æãã³ã³ãããŒã«ããèšå®ã«ã€ããŠæŠèŠãææ¡ããŠãã ããã åè : ããã®ç®¡çã®æŠèŠ - ãã ã«ãŒãããŒãã« åè : Network Connectivity Center ã®æŠèŠ - ãã€ããªãã ã¹ããŒã¯ã®ãããµããããã®ã€ã³ããŒã Cloud NGFW åºæ¬çãªç¥è Cloud NGFW ã VPC ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã« ã®ä»çµã¿ãåãåé¡ãåºé¡ãããŸããã¹ããŒããã«ã€ã³ã¹ãã¯ã·ã§ã³ã IngressãEgressãã¿ãŒã²ããããããã¯ãŒã¯ã¿ã°ããµãŒãã¹ã¢ã«ãŠã³ãã®æŠå¿µãæŒãããŠãããŸãã 以äžã®èšäºãèªã¿ã VPC ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã« ãš ãã¡ã€ã¢ãŠã©ãŒã«ããªã·ãŒ ã®éãããããŠããããã§ã©ã®ãããªå¶åŸ¡ãã§ããããçè§£ããŠãã ããã åè : Cloud Next Generation Firewall(Cloud NGFW)ã培åºè§£èª¬ïŒ - G-gen Tech Blog FQDN ãªããžã§ã¯ã ãã¡ã€ã¢ãŠã©ãŒã«ããªã·ãŒïŒéå±€åãã°ããŒãã«ããªãŒãžã§ã³ïŒã§ã¯ã FQDN ãªããžã§ã¯ã ãäœçœ®æ
å ±ãªããžã§ã¯ããªã©ã䜿ã£ãŠãé«åºŠãªãã±ããã®å¶åŸ¡ãã§ããŸãããããã®ã¢ã¯ã»ã¹å¶åŸ¡ã¯ VPC ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã§ã¯äœ¿ããªãããšã«æ³šæããŠãã ããã åè : Cloud NGFW Standardã®éä¿¡å¶åŸ¡ãªããžã§ã¯ããè§£èª¬ïŒ - G-gen Tech Blog è©äŸ¡é ããã©ã«ãã§ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãšãã¡ã€ã¢ãŠã©ãŒã«ããªã·ãŒã®è©äŸ¡é ã¯ä»¥äžã®ããã«ãªã£ãŠããŸãã ã«ãŒã«ã®è©äŸ¡é åº ããããVPC ãããã¯ãŒã¯ã®èšå®ã BEFORE_CLASSIC_FIREWALL ã«å€æŽããããšã§ããã®è©äŸ¡é ã倿Žã§ããããšã«æ³šæããŠãã ããã ãŸãã«ãŒã«ã®ã¢ã¯ã·ã§ã³ã« goto_next ãæå®ãããŠãããšã©ã®ãããªæåã«ãªããããªã©ã«ã€ããŠã確å®ã«ææ¡ããŠãã ããã åè : ãã¡ã€ã¢ãŠã©ãŒã« ããªã·ãŒ - ãããã¯ãŒã¯ ãã¡ã€ã¢ãŠã©ãŒã« ããªã·ãŒã®é©çšé åº ã¿ãŒã²ãã VM ã®æå® Google Cloud ã®ãã¹ããã©ã¯ãã£ã¹ãšããŠã VPC ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãé©çšãã VM ãæå®ããéã¯ããããã¯ãŒã¯ã¿ã°ããããµãŒãã¹ã¢ã«ãŠã³ããå©çšããããšãæšå¥šãããŠããŸãããã®ãããªãã¹ããã©ã¯ãã£ã¹ãæŒãããŠããå¿
èŠããããŸãã åè : VPC èšèšã®ããã®ããããã®æ¹æ³ãšãªãã¡ã¬ã³ã¹ ã¢ãŒããã¯ã㣠- ã¿ãŒã²ãã ãã£ã«ã¿ãªã³ã° ãããã¯ãŒã¯ã¿ã°ã¯ VM ã«å¯Ÿããç®¡çæš©é ( Compute Instance Admin ããŒã«ç ) ãæã£ãŠããã°ç·šéãã§ããŠããŸãã®ã«å¯ŸãããµãŒãã¹ã¢ã«ãŠã³ãã¯ãµãŒãã¹ã¢ã«ãŠã³ãããšåå¥ã« IAM ã§ã¢ã¯ã»ã¹å¶åŸ¡ãã§ãããããã€ã³ã¹ã¿ã³ã¹ç®¡çè
ããããã¯ãŒã¯ç®¡çè
ã®èš±å¯ãªããçŠæ¢ãããŠããéä¿¡ãå¯èœã«ããŠããŸãããšããããšãææ¢ããããšãã§ããŸããããããã€ã³ããšãããåé¡ãåºé¡ãããŸãã å
±æ VPC æŠå¿µãšãŠãŒã¹ã±ãŒã¹ å
±æ VPC ïŒShared VPCïŒã䜿ããŠãŒã¹ã±ãŒã¹ãå€ãåºé¡ãããŸãã ãã¹ããããžã§ã¯ã ã ãµãŒãã¹ãããžã§ã¯ã ãšãã£ãçšèªãªã©ãåºæ¬çãªæŠå¿µãçè§£ããŠãã ããã å
±æ VPC ã䜿ãããšã§ãäžå€®ã®ãããã¯ãŒã¯ç®¡çè
ããããã¯ãŒã¯èšå®ãéäžç®¡çããéçºè
åŽã¯ãã®ãããã¯ãŒã¯ãå©çšããã ãããšãã£ãéçšãå¯èœã«ãªããŸãã åè : å
±æ VPC IAM å
±æ VPC ã«é¢é£ãã IAM ããŒã«ã«ã€ããŠãææ¡ããŠãã ãããå
±æ VPC ã®ç®¡çè
ãããµããããã«ãããŠå©çšè
ã« Compute ãããã¯ãŒã¯ ãŠãŒã¶ãŒïŒ roles/compute.networkUser ïŒããŒã«ãä»äžããããšã§ãå©çšè
åŽã¯èªåã® VM çãå
±æããããµããããã«é
眮ããããšãã§ããããã«ãªããŸãã åè : å
±æVPCã®èšå®ãå©çšã«å¿
èŠãªIAMæš©é - G-gen Tech Blog Cloud Load Balancing ããŒããã©ã³ãµãŒã®éžæ åçš®çšéã®ããã«ãé©åãªããŒããã©ã³ãµãŒãéžæã§ããããã«ããŠãããŸãããã åè : ããŒããã©ã³ãµãéžæãã ããŒããã©ã³ãµãŒã¯çš®é¡ãå€ãäžèŠå€§å€ã«æããŸããã軞ãèŠããŠããŸãã°ãããŸã§å€§å€ã§ã¯ãããŸããã以äžã®è»žã®çµã¿åããã§ã10çš®é¡ã®ããŒããã©ã³ãµãŒãååšããŸãã 軞 éžæè¢ ãã©ãã£ãã¯ã®çš®é¡ HTTPïŒSïŒããTCP/UDP ã å
¬é å€éšããå
éšã ã¹ã³ãŒã ã°ããŒãã«ãããªãŒãžã§ã³ããã¯ãã¹ãªãŒãžã§ã³ã ãã±ããçµç«¯ ãããã·åãããã¹ã¹ã«ãŒåã äŸãã°ã瀟å
ã®ã¿ã«å
¬éããã·ã¹ãã ã§ããã¹ã¹ã«ãŒåã®ïŒãªã¯ãšã¹ãã®æ¥ç¶å
IP ã¢ãã¬ã¹ãæžãæããªãïŒããŒããã©ã³ãµãŒãå¿
èŠã§ããããšããç¶æ³ã§ããã°ããªãŒãžã§ã³å
éšãã¹ã¹ã«ãŒãããã¯ãŒã¯ããŒããã©ã³ãµãŒããéžæããããšã«ãªããŸãããã€ã³ã¿ãŒãããå
¬éããã·ã¹ãã ããŠãŒã¶ãŒã¯äžçäžã«ããããããã³ã«ã¯ HTTPSãã§ããã°ãã°ããŒãã«å€éšã¢ããªã±ãŒã·ã§ã³ããŒããã©ã³ãµãŒããéžæããŸãã ãŸãã以äžã®ãããªã¢ãŒããã¯ãã£ã®ã·ã¹ãã ããããšããŸãã [Web ãµãŒããŒ] -> [AP ãµãŒããŒ] -> [DB ãµãŒããŒ] Web ãµãŒããŒã®è² è·åæ£ã®ããã«ã¯ãWeb ãµãŒããŒã®æåã«ãã°ããŒãã«å€éšã¢ããªã±ãŒã·ã§ã³ããŒããã©ã³ãµãŒããé
眮ããŠãWeb ãµãŒããŒãã AP ãµãŒããŒãžã®ãã©ãã£ãã¯ã®è² è·åæ£ã®ããã«ããªãŒãžã§ã³å
éšãã¹ã¹ã«ãŒãããã¯ãŒã¯ããŒããã©ã³ãµãŒããé
眮ãããšããããã«ã1ã€ã®ã·ã¹ãã ã§è€æ°ã®ããŒããã©ã³ãµãŒã䜿çšããå ŽåãããããŸãã ã¢ããªã±ãŒã·ã§ã³ããŒããã©ã³ãµãŒ æãäžè¬çãªãŠãŒã¹ã±ãŒã¹ã§äœ¿ãããã®ãã ã°ããŒãã«å€éšã¢ããªã±ãŒã·ã§ã³ããŒããã©ã³ãµãŒ ã§ããã°ããŒãã«å€éšã¢ããªã±ãŒã·ã§ã³ããŒããã©ã³ãµãŒã¯ãåäžã®ãšããŒãã£ã¹ã IP ã¢ãã¬ã¹ã䜿çšããŠãäžçäžã®ãŠãŒã¶ãŒããã®ãªã¯ãšã¹ããåãä»ãããªãŒãžã§ã³ã®ããã¯ãšã³ãã«ãã©ãã£ãã¯ãã«ãŒãã£ã³ã°ããŠãããŸããããã«ãããã°ããŒãã«ã¬ãã«ã®å¯çšæ§ã確ä¿ãããŸãã ãã®éãã°ããŒãã«å€éšã¢ããªã±ãŒã·ã§ã³ããŒããã©ã³ãµãŒã¯1ã€ã ãæ§ç¯ããããã«çŽã¥ãã ããã¯ãšã³ããµãŒãã¹ ïŒã°ããŒãã«ãªãœãŒã¹ïŒã1ã€ã§ãããã®ããã¯ãšã³ããµãŒãã¹ã®èåŸã«ããªãŒãžã§ã³ããšã®ã€ã³ã¹ã¿ã³ã¹ã°ã«ãŒããçŽã¥ããŸãã Cloud Router Cloud Router ã®åºæ¬ Cloud Router ã®ä»¥äžã®ãããªä»æ§ãç¥ã£ãŠããå¿
èŠããããŸãã Cloud Router ã¯ç¹å®ã®ãªãŒãžã§ã³ã«çŽã¥ããªãŒãžã§ã³ãªãœãŒã¹ã§ãã Cloud Router ã¯ç¹å®ã® VPC ãããã¯ãŒã¯ã«çŽã¥ã Cloud Router 㯠AS çªå·ïŒASNïŒãæã€ Cloud Router ã¯ããã©ã«ãã§ã¯ãçŽã¥ã VPC ãããã¯ãŒã¯ã®ãã¹ãŠã®ãµãããããžã®çµè·¯ã察åã«ãŒã¿ãŒã«åºå ±ãã Cloud Router ãåŠç¿ããã«ãŒããã©ã®ãªãŒãžã§ã³ã«åºå ±ããããã¯ãåçã«ãŒãã£ã³ã°ã¢ãŒããããªãŒãžã§ã³ãã°ããŒãã«ãã«ãã£ãŠæåãç°ãªã åçã«ãŒãã£ã³ã°ã¢ãŒãããªãŒãžã§ã³ã®å ŽåãCloud Router ãšåããªãŒãžã§ã³ã«åçã«ãŒããäœæãã åçã«ãŒãã£ã³ã°ã¢ãŒããã°ããŒãã«ã®å Žåããã¹ãŠã®ãªãŒãžã§ã³ã«åçã«ãŒããäœæãã ç¹ã«æåŸã®åçã«ãŒãã£ã³ã°ã¢ãŒãã«ã€ããŠã¯ãèšå®ããªãŒãžã§ã³ã«ãããã°ããŒãã«ã«ãããã«ãã£ãŠãCloud Router ã®ãããªãŒãžã§ã³ïŒVPN ã Cloud Interconnect ãæ¥ç¶ãããªãŒãžã§ã³ïŒãšã¯éããªãŒãžã§ã³ã®ãµããããã«ãã VM çãããªã³ãã¬ãã¹ãšéä¿¡ã§ãããã©ãããæ±ºãŸã£ãŠããŸãããã®ä»æ§ãããçšåºŠçè§£ããŠãããŸãããã åè : åŠç¿ããã«ãŒã - åçã«ãŒãã£ã³ã° ã¢ãŒã BGP ã»ãã·ã§ã³ Cloud VPN ã«ããã BGP ã»ãã·ã§ã³ã®èšå®æ¹æ³ ã¯ãå®éã«äžåºŠæ€èšŒããŠã¿ãããšãæãŸããã§ããGoogle Cloud ã§ã¯ VPC ãããã¯ãŒã¯éã§ VPN æ¥ç¶ãè¡ãããšãå¯èœã§ãããããGoogle Cloud æ€èšŒç°å¢ãããã°è©ŠããŠã¿ãããšãã§ããŸãã BGP IP ã¢ãã¬ã¹ã¯ 169.254.x.x ãšãããªã³ã¯ããŒã«ã«ã¢ãã¬ã¹ã§ããããŸã ASN ã Private ASN ïŒ64512-65535 ãŸã㯠4200000000 - 4294967294ïŒã§ããå¿
èŠããããŸãã åè : ã㢠VPN ã²ãŒããŠã§ã€ã«å¯Ÿãã HA VPN ã²ãŒããŠã§ã€ãäœæãã - BGP ã»ãã·ã§ã³ãäœæãã ãªã Cloud VPN ã®èšå®ã«ãããŠã¯ããããŒã«ã«ããšããèšè㯠Google åŽãæããããã¢ããšããèšèã¯å¯ŸååŽãæããŠããããšã«çæããŠãã ããã Cloud Interconnect Dedicated Interconnect Cloud Interconnect ã¯å°çšç·ãµãŒãã¹ã§ãããããæ€èšŒããã®ãé£ãããµãŒãã¹ã§ããããã¥ã¡ã³ããäžå¿ã«çè§£ãæ·±ããŸãããã äŸãã° Dedicated Interconnect ã®å©çšéå§æé ã¯ä»¥äžã®ããã¥ã¡ã³ãã«èšèŒãããŠãããããæµããææ¡ããŠãããŸãã åè : Dedicated Interconnect ã®ããããžã§ãã³ã°ã®æŠèŠ Partner Interconnect Partner Interconnect ã§ Google ãæšå¥šããããããžãŒã¯ã©ã®ãããªãã®ããã«ã€ããŠãææ¡ããŠãããŸãããã åè : Partner Interconnect ã®æŠèŠ - 99.99% ã®å¯çšæ§ã®ããããž 99.99% ã®å¯çšæ§ã確ä¿ããã«ã¯äžèšã®ããã¥ã¡ã³ãã®ãããªæ§æã«ããå¿
èŠããããŸããCloud Router ã®ã«ãŒãã£ã³ã°ã¢ãŒãã Global ã«ããããšã§çæ¹ã®åç·ãããŠã³ããŠãåé·æ§ã確ä¿ãããããšããç¹ã«æ³šæããŠãã ããã å¥ã
ã® 2ã€ã®ãªãŒãžã§ã³ã«ãããã Cloud Router ãé
眮 å Cloud Router ããã¯éããŸãŒã³ã«åãã2ã€ãã€ã® VLAN ã¢ã¿ããã¡ã³ã ãäœæãã Cloud Router ã® åçã«ãŒãã£ã³ã°ã¢ãŒã ã Global ã«ãã ãŸã Partner Interconnect ã«ã¯ Layer 2 ãš Layer 3 ã®2çš®é¡ãååšããŠããç¹ã«ãçæããŠãã ãããL2 ã ãšèªç€Ÿã«ãŒã¿ãŒãš Cloud Router éã§ BGP ã»ãã·ã§ã³ã®ç¢ºç«ãå¿
é ã§ããL3 ã ãšãCloud Router ãšãªã³ãã¬ãã¹ã®éã§ BGP ã»ãã·ã§ã³ã確ç«ããã®ã¯ããããã¯ãŒã¯æ¥è
ã®ã«ãŒã¿ãŒã§ãã åè : Partner Interconnect ã®æŠèŠ - ã¬ã€ã€ 2 ãšã¬ã€ã€ 3 ã®æ¥ç¶ Direct Peering / Carrier Peering Direct Peering ã Carrier Peering ã¯ãGoogle Workspace çã®ãããªãã¯ãª Google ãµãŒãã¹ãšæ¥ç¶ããããã®ãµãŒãã¹ã§ããæ·±ãçè§£ããå¿
èŠã¯ãããŸãããããã®ååšãšæŠèŠã¯ææ¡ããŠãããŸãããã åè : ãã€ã¬ã¯ã ãã¢ãªã³ã°ã®æŠèŠ åè : ãã£ãªã¢ ãã¢ãªã³ã°ã®æŠèŠ Cross-Cloud Interconnect Cross-Cloud Interconnect ã¯ãGoogle Cloud ãšãAmazon Web ServicesïŒAWSïŒãªã©ã®ä»ã¯ã©ãŠãããåºåž¯åãé«ä¿¡é Œæ§ã®å°çšç·ã§æ¥ç¶ãããµãŒãã¹ã§ããä»ã¯ã©ãŠããšå€§èŠæš¡ãªãããã¯ãŒã¯ãæ¥ç¶ããéã«ã¯ããã®éžæè¢ãããããšãçè§£ããŠãã ããã åè : Cross-Cloud Interconnectã培åºè§£èª¬ïŒ æå·å ã¬ã€ã€3ã§ã®æå·åã確ä¿ãããããCloud Interconnect ã® å°çšç·äžã§ HA VPN ãç¢ºç« ããããšãã§ããŸããå°çšç·ã®äžã«æå·åãã³ãã«ãéãããšã§ããã匷åºãªçèŽé²æ¢ãšãªããŸãã åè : Cloud Interconnect ãä»ãã HA VPN ãæ§æãã ãªããCloud Interconnect ã§ã¯ MACsec ãæ§æã§ããŸããMACsec 㯠ã¬ã€ã€2 ã®æå·åæ¹åŒã§ããã©ã®ææ³ãã©ã®ã¬ã€ã€ã§æå·åããããã®ãªã®ããææ¡ããŠãã ããã åè : Cloud Interconnect ã® MACsec ã®æŠèŠ Cloud DNS 転éãŸãŒã³ Cloud DNS 㧠転éãŸãŒã³ ãäœæããããšã§ãã¯ã©ãŠãäžã® VM çãããäžéšã®ãã¡ã€ã³åããªã³ãã¬ãã¹ã® DNS ãµãŒããŒã«ãã©ã¯ãŒãããããšãã§ããŸãããã©ã¯ãŒãããã¯ãšãªã¯ãCloud Interconnect ã Cloud VPN ãéããŠãªã³ãã¬ãã¹ã«å°éã§ããŸãã åè : DNS ãŸãŒã³ã®æŠèŠ - 転éãŸãŒã³ 泚æç¹ãšããŠã転éãåããæ¹ã® DNS ãµãŒãããèŠãã¯ãšãªã®æ¥ç¶å
IP ã¢ãã¬ã¹ã¯ 35.199.192.0/19 ãšãªããŸãããã©ã€ããŒããããã¯ãŒã¯çµç±ã§ã¯ãšãªã転éãããŠããŠããæ¥ç¶å
IP ã¢ãã¬ã¹ã RFC 1918 ã®ãã©ã€ããŒãã¢ãã¬ã¹ã§ã¯ãªãããäžèªç¶ã«èŠããŸããããã®ãããªä»æ§ã§ãã ããã¯ãCloud DNS ãããªã³ãã¬ãã¹ DNS ãžã®ãã©ã¯ãŒãã£ã³ã°ãå®çŸããããã«ã¯ã以äžã®ãããªè¿œå ã®èšå®ãå¿
èŠã§ããããšãæå³ããŸãã ãªã³ãã¬ãã¹åŽãã¡ã€ã¢ãŠã©ãŒã«èšå®ã§ 35.199.192.0/19 ããã® TCP/UDP 53 çªããŒããèš±å¯ãã ãªã³ãã¬ãã¹åŽ DNS ã®èšå®ã§ãã® IP ã¢ãã¬ã¹åž¯ããã® DNS ã¯ãšãªãèš±å¯ãã ãªã³ãã¬ãã¹ãã Google Cloud åŽã«ãã±ãããè¿ããããã«çµè·¯ãèšå®ããïŒBGP ã§ Cloud Router ããåºå ±ããçïŒ åä¿¡ãµãŒããŒããªã·ãŒ åä¿¡ãµãŒããŒããªã·ãŒ ãå®çŸ©ããããšã§ããªã³ãã¬ãã¹ã®ã¯ã©ã€ã¢ã³ããã Cloud DNS ãžãšåå解決ã¯ãšãªãæå
¥ããããããªã³ãã¬ãã¹ã® DNS ãµãŒãããäžéšã®ãªã¯ãšã¹ãã Cloud DNS ãžãã©ã¯ãŒãã£ã³ã°ããããšãã§ããŸãã åä¿¡ãµãŒããŒããªã·ãŒãäœæã㊠VPC ã«é©çšãããšããªã³ãã¬ãã¹ã®ã¯ã©ã€ã¢ã³ãã DNS ãµãŒããã Cloud DNS ã«ãªãŒãããããã®ãã©ã€ããŒã IP ã¢ãã¬ã¹ãæã£ããšã³ããã€ã³ããçæãããŸãã åè : DNS ãµãŒããŒã®ããªã·ãŒ ã¹ããªãããã©ã€ãºã³ äŸãã° example.com ãšãããããªãã¯ãŸãŒã³ãšãååã® example.com ãšãããã©ã€ããŒããŸãŒã³ãäž¡æ¹äœæãããšãã€ã³ã¿ãŒãããããã®åå解決ã¯ãããªãã¯ãŸãŒã³ãè¿ããVPC å
ããã®åå解決ã¯ãã©ã€ããŒããŸãŒã³ãè¿ãããã«ãªããŸãããããã£ãèšå®ãã ã¹ããªãããã©ã€ãºã³ ãšåŒã³ãŸãã åè : DNS ãŸãŒã³ã®æŠèŠ - ã¹ããªãã ãã©ã€ãºã³ DNS ã®äŸ DNS ãã¢ãªã³ã° DNS ãã¢ãªã³ã° ã¯ãç¹å®ãã¡ã€ã³ã®åå解決ãç°ãªããããžã§ã¯ãããŸãã¯ç°ãªã VPC ãããã¯ãŒã¯ã® Cloud DNS ã«ãã©ã¯ãŒãããããã®èšå®ã§ãã åè : DNS ãŸãŒã³ã®æŠèŠ - ãã¢ãªã³ã° ãŸãŒã³ äŸãã°ä»¥äžã®ãããªã±ãŒã¹ã§äœ¿ãããšãã§ããŸãã VPC (A) ã¯ãªã³ãã¬ãã¹ãµã€ããš Cloud Interconnect ã§æ¥ç¶ãããŠãã VPC (A) ã® Cloud DNS ã§ã¯ onpremiss.local ã®ãã¡ã€ã³åããªã³ãã¬ãã¹ã® DNS ãµãŒããŒã«ãã©ã¯ãŒãããããèšå®ãããŠãã VPC (B) 㯠VPC (A) ãš VPC Peering ã§æ¥ç¶ãããŠãã VPC (B) ã§ onpremiss.local ãåå解決ããã DNS 転éãš DNS ãã¢ãªã³ã° ãã®ãããªãšãã« VPC (B) ãã VPC (A) ãžã® DNS ãã¢ãªã³ã°ãèšå®ããããšã§èŠä»¶ãæºãããŸããVPC (B) ã®äžã«ãã VM 㯠Cloud DNS ã«å¯Ÿã㊠onpremiss.local ã®åå解決ã¯ãšãªãæãããšã DNS Peering ã«åŸã VPC (A) ã«åå解決ããã©ã¯ãŒãããŸããVPC (A) 㯠forwarding zone ã«åŸããªã³ãã¬ãã¹ DNS ã«åå解決ããã©ã¯ãŒãããŸããã¯ãšãªãžã®è¿çã¯ãVPC (B) ã«è¿ããŸãã DNSSEC DNSSEC ïŒDNS Security ExtensionsïŒã¯ãDNS ãã£ãã·ã¥ãã€ãºãã³ã°ã DNS ã¹ããŒãã£ã³ã°ãšãã£ãè
åšã«å¯Ÿæããããã®ãDNS ã®ã»ãã¥ãªãã£æ©èœã§ããIETF ã§å®çŸ©ãããŠããŸãã Cloud DNS ã§ã¯ DNSSEC ãæ§æã§ããŸããDNSSEC ã®åºæ¬çãªä»çµã¿ã®æŠèŠããèšå®æé ã¯ç°¡åã«æŒãããŠãããŠãã ããã åè : DNS Security ExtensionsïŒDNSSECïŒã®æŠèŠ ãããã¯ãŒã¯ã»ãã¥ãªã㣠Secure Web Proxy Secure Web Proxy ã¯ãVM ããã€ã³ã¿ãŒããããž HTTPïŒSïŒã¢ã¯ã»ã¹ããéã®ã¢ã¯ã»ã¹å¶åŸ¡ïŒåºå£ç®¡çïŒãã§ãããã«ãããŒãžããµãŒãã¹ã§ãã Secure Web Proxy ã«ã¯ããããã·ã¢ãŒããããã¯ã¹ããããã¢ãŒãããPrivate Service Connect ã¢ãŒããã®3çš®é¡ã®ãããã€æ¹æ³ãããããšã«çæããŠãã ããã åè : Secure Web Proxy ã®æŠèŠ åè¿°ã®ãã¡ã€ã¢ãŠã©ãŒã«ããªã·ãŒã® FQDN ãªããžã§ã¯ãã§ããå®å
ãã¡ã€ã³ã«å¿ããã¢ã¯ã»ã¹å¶åŸ¡ïŒèš±å¯ãããã¡ã€ã³äžèЧã«ã®ã¿ã¢ã¯ã»ã¹ãããçïŒã¯ã§ããŸãããFQDN ãªããžã§ã¯ãã®å Žåã¯ãã®åã®éãã ãã¡ã€ã³åãŸã§ ããæ€æ»ãããŸãããSecure Web Proxy ã§ã¯ããã¡ã€ã³åéšåã ãã§ã¯ãªãã ãã¹ã®éšåãŸã§ æ€æ»ã§ããŸãã åè : UrlList ã®æ§æãªãã¡ã¬ã³ã¹ VPC Service Controls VPC Service Controls ãš éå®å
¬éã® Google ã¢ã¯ã»ã¹ ïŒPrivate Google AccessïŒãçµã¿åãããæ¹æ³ã«ã€ããŠãçè§£ããŠãã ããã ãªã³ãã¬ãã¹ãš VPC ã Cloud Interconnect ã VPN ã§æ¥ç¶ãããŠããããªã³ãã¬ãã¹ã®ã¯ã©ã€ã¢ã³ããã Google API ããéå®å
¬éã® Google ã¢ã¯ã»ã¹ãçµç±ã§ã¢ã¯ã»ã¹ããããæ§æãããŠãããããã¯ãŒã¯ã«ãããŠãVPC Service Controls ã䜿ã£ã API ãä¿è·å®çŸãããã±ãŒã¹ãåºé¡ãããŸãã ãã®ãããªã±ãŒã¹ã§ãéå®å
¬éã® Google ã¢ã¯ã»ã¹ã®ããã®ãã¡ã€ã³åãšã㊠restricted.googleapis.com ã䜿ãã®ã private.googleapis.com ã䜿ãã®ããçããããããã«ããŠãããŸãããã ãŸã VPC Service Controls ã«å¯ŸããŠçŽã¡ã«èšå®ã倿Žãããšæ¬çªç°å¢ãžã®äºæãã¬åœ±é¿ãæžå¿µããããããäºåã®æ€èšŒãè¡ãããã® ãã©ã€ã©ã³æ§æ ãå¯èœã§ãã VPC Service Controls ãéå®å
¬éã® Google ã¢ã¯ã»ã¹ã«ã€ããŠã¯ã以äžã®èšäºãåç
§ããŠãã ããããéå®å
¬éã® Google ã¢ã¯ã»ã¹ãã¯é£è§£ãªã®ã§ãå®éã«æ€èšŒç°å¢ã§æ§ç¯ããŠã¿ããšçè§£ãæ·±ãŸããŸãã åè : VPC Service Controlsãåããããã解説 - G-gen Tech Blog åè : éå®å
¬éã® Google ã¢ã¯ã»ã¹ã®ä»çµã¿ãšæé ããã£ã¡ã解説 - G-gen Tech Blog Cloud Armor WAF ãµãŒãã¹ã§ãã Cloud Armor ãåºé¡ç¯å²ã§ãã æŠèŠãçè§£ããããšã«å ãã现ãããšããã§ã¯ã Cloud WAF ã§åœéœæ§ãªã©ãçºçããéã«ãã©ã®ãã°ãèŠãŠèª¿æ»ããã°è¯ããããªã©ã¯ææ¡ããŠãããŸããããCloud Armor ã®æ€ç¥ã«é¢ãããã°ã¯ Cloud Armor ã® Cloud Audit Log ã§ã¯ãªã ã Cloud Load Balancing ã®ã¢ã¯ã»ã¹ãã° ã«åºåãããŸãã 以äžã®èšäºãåç
§ããŠãã ããã åè : Cloud Armorã培åºè§£èª¬ãGoogleã®ãã«ãããŒãžãWAF - G-gen Tech Blog Cloud CDN åºæ¬çãªç¥è Cloud CDN ã¯ãGoogle Cloud ãã€ãã£ããªã³ã³ãã³ãããªããªãŒãããã¯ãŒã¯ãµãŒãã¹ã§ããæå€§ã®æ³šæç¹ã¯ãCloud CDN 㯠å€éšã¢ããªã±ãŒã·ã§ã³ããŒããã©ã³ãµãŒ ã® ããã¯ãšã³ããµãŒãã¹ ãŸã㯠ããã¯ãšã³ããã±ãã ã§ã®ã¿ãæå¹åã§ãããšããç¹ã§ãã åè : Cloud CDN ã®æŠèŠ ãã£ãã·ã¥ç¡å¹å Cloud CDN ã§ã¯ãæç€ºçãªãã£ãã·ã¥ã®ç¡å¹åïŒinvalidationïŒãå¯èœã§ãã以äžã®ãããªã³ãã³ããå®è¡ããŠããã¹ãæç€ºãããã£ãã·ã¥ã®ç¡å¹åãã§ããŸããããã«ãããå€ãã³ã³ãã³ããé
ä¿¡ãããŠããŸãããšãé²ããŸãã gcloud compute url-maps invalidate-cdn-cache ${URL_MAP_NAME} \ --path " /images/file.jpg " åè : ãã£ãã·ã¥ç¡å¹åã®æŠèŠ Google Kubernetes EngineïŒGKEïŒ GKE ã«é¢ããåºé¡ Google Kubernetes Engine ïŒGKEïŒã«é¢ããåºé¡ããããŸããGKE ã¯ã©ã¹ã¿ã VPC ãã€ãã£ãã¯ã©ã¹ã¿ ãšããŠèµ·åããŠã ãšã€ãªã¢ã¹ IP ã¢ãã¬ã¹ç¯å² ã䜿çšããããšã§ IP ã¢ãã¬ã¹ãªãœãŒã¹ãå¹ççã«äœ¿çšã§ããŸãã ãŸãã¯ã©ã¹ã¿ã ããŒãããŒã« ã®ä»çµã¿ãªã©ãGKE ã®åºæ¬ã¯æŒãããŠãããŠãã ããã åè : Google Kubernetes EngineïŒGKEïŒã培åºè§£èª¬ - G-gen Tech Blog IP ãã¹ã«ã¬ãŒããšãŒãžã§ã³ã IP ãã¹ã«ã¬ãŒããšãŒãžã§ã³ã ã«ãã£ãŠ Pod ããã®ãã©ãã£ãã¯ã®éä¿¡å
IP ã¢ãã¬ã¹ã SNAT ããããšãã£ãæŠå¿µã«ã€ããŠçè§£ããŠãããŠãã ããã åè : IP ãã¹ã«ã¬ãŒã ãšãŒãžã§ã³ã ã¢ãã¿ãªã³ã° Packet Mirroring ãš VPC ãããŒãã° äŸãã°ãVM ãã Egress ããå
šãŠã®ãã©ãã£ãã¯ãæ€æ»ããªããã°ãªããªãããšãã£ãã»ãã¥ãªãã£èŠä»¶ãããéã«æŽ»èºããã®ã Packet Mirroring ã§ãã åè : Packet Mirroring Packet Mirroring ã¯ãVM ã®ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ãããã±ããããã©ãŒããŠã å
éšããŒããã©ã³ãµã®èåŸ ã«ãã ã¢ãã¿ãªã³ã°çšã® VM ãž æž¡ãæ©èœã§ããããã«ããã¢ãã¿ãªã³ã°çšã® VM äžã§ãã±ããã®è§£æãè¡ãããšãã§ããŸããVPC ãæµããå
šãŠã®ãã±ããããã©ãŒã§ããèš³ã§ã¯ãªããVM ã®ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ãŒã¹ãåºå
¥ããããã±ããã®ã¿ã察象ã§ãã 䌌ããããªå Žåã§ããã±ããã® ã¡ã¿ããŒã¿ã®ã¿ ïŒæ¥ç¶å
/å
IP ã¢ãã¬ã¹ãæ¥ç¶å
/å
ããŒãçªå·ããããã³ã«ããã±ããã®ãµã€ãºãªã©ïŒãè§£æãããã±ãŒã¹ããããŸãããã®å Žåã¯ããã±ããã®äžèº«ãŸã§èŠãå¿
èŠã¯ãªãã®ã§ã VPC ãããŒãã° ãæå¹åããããšãæ€èšããŸãã åè : VPC ãããŒãã° ãã±ããã®äžèº«ãè§£æãããã®ãããã±ããã®ã¡ã¿ããŒã¿ãè§£æãããã®ããå顿ããã確èªããŸãã ãã¡ã€ã¢ãŠã©ãŒã«ã®ãã° ãã¡ã€ã¢ãŠã©ãŒã«ã®ãã°ã®åºæ¬ãæŒãããŠãããŸãããããã¡ã€ã¢ãŠã©ãŒã«ã®ãã°ã¯ã ã«ãŒã«ããš ã«æå¹åããå¿
èŠããããŸãããã¡ãããååŸã§ããã®ã¯ãã®ã«ãŒã«ã«è©äŸ¡ããããã±ããã ãã§ããåé¡æã«æžãããŠããèŠä»¶ã« Firewall Logging ãæ¬åœã«åèŽããŠãããã«ã¯æ³šæããŠåçãå¿
èŠã§ãã åè : VPC ãã¡ã€ã¢ãŠã©ãŒã« ã«ãŒã«ã®ãã®ã³ã° åè : ãã¡ã€ã¢ãŠã©ãŒã« ããªã·ãŒ ã«ãŒã«ã®ãã®ã³ã°ã䜿çšãã å°çšç·ã VPN ã®ã¢ãã¿ãªã³ã° å°çšç·ã VPN ãã¢ãã¿ãªã³ã°ããã«ãããã Cloud Monitoring ã® ææš ïŒmetricsïŒãç£èŠããããšãã§ããŸãã BGP ãã¢ãªã³ã°ã®æ»æŽ»ç¶æ³ããå
ãã¡ã€ããŒåç·ã®å
ä¿¡å·ã®åŒ·ãïŒTx ãã¯ãŒãš Rx ãã¯ãŒã®å
ã¬ãã«ïŒã確èªããææšãçšæãããŠããŸãã åè : æ¥ç¶ãã¢ãã¿ãªã³ã°ãã - Google Cloud ã³ã³ãœãŒã«ã§ææšã確èªãã åè : ãã°ãšææšã®è¡šç€º Network Intelligent Center Google Cloud ã®ãããã¯ãŒã¯ç®¡çè£å©ããŒã«ã§ãã Network Intelligent Center ã«ã¯ããã±ããã®å°éæ§ããã§ãã¯ãã æ¥ç¶ãã¹ã ïŒConnectivity TestïŒæ©èœãçšæãããŠããŸããæ¥ç¶ãã¹ãã¯ãNetwork Connectivity Center ã®çµè·¯ã®ç¢ºèªã«ã察å¿ããŠããŸãã ãã ãæ³šæããªããŠã¯ãããªãã®ã¯ãæ¥ç¶ãã¹ãæ©èœã¯ãããŸã§ããããã¯ãŒã¯èšå®ãæ£ãããã確èªããããã®æ©èœã§ããã ãããã¯ãŒã¯ã®ã¢ãã¿ãªã³ã°ãæ³å®ãããã®ã§ã¯ãªã ç¹ã§ããå®åžžçãªã¢ãã¿ãªã³ã°ã«ã¯ãåè¿°ã® Cloud Monitoring ææšã䜿ããŸãã ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO å
èŠå¯å®ãšããçµæŽãæã€ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS èªå®è³æ Œããã³ Google Cloud èªå®è³æ Œã¯ãã¹ãŠååŸãXïŒæ§ TwitterïŒã§ã¯ Google Cloud ã Google Workspace ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-genã®ææã§ããGoogle CloudïŒæ§ç§° GCPïŒã® Identity and Access Management ïŒIAMïŒã«ããã æåŠããªã·ãŒ ïŒDeny policiesïŒã«ã€ããŠè§£èª¬ããŸãã ã¯ããã« IAM ãšã¯ æåŠããªã·ãŒãšã¯ IAM ããªã·ãŒã®è©äŸ¡é ä»çµã¿ æåŠããªã·ãŒã®æ§è³ª æåŠããªã·ãŒã管çããããã® IAM æš©é æåŠããªã·ãŒã®ç®¡ç æåŠããªã·ãŒã®æ§æèŠçŽ ç¶æ¿ IAM ããªã·ãŒã®äŸ æåŠããªã·ãŒå©çšã®æ³šæç¹ äœ¿ãæ æåŠã§ããã¢ã¯ã·ã§ã³ ã¯ããã« IAM ãšã¯ Google CloudïŒæ§ç§° GCPïŒã® Identity and Access Management ïŒä»¥äžãIAMïŒã¯ Google Cloud ãªãœãŒã¹ã®æäœæš©éã管çããä»çµã¿ã§ããIAM ã¯ãèªèšŒããã Google ã¢ã«ãŠã³ãçã«å¯ŸããŠãã©ããªæš©éãäžãããïŒèªå¯ïŒãåžããŸãã IAM ã®åºæ¬çãªè§£èª¬ã«ã€ããŠã¯ä»¥äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp æåŠããªã·ãŒãšã¯ æåŠããªã·ãŒ ïŒDeny policiesïŒãšã¯ããªãœãŒã¹ãžã®æäœãæç€ºçã«æåŠãã IAM èšå®ã®ããšã§ãã Google Cloud ã® IAM ã§ã¯ãäœãèšå®ããªãããã©ã«ãç¶æ
ã ãšããã¹ãŠã®æäœãæåŠãããŸããåãªãœãŒã¹ãæã£ãŠãã IAM ããªã·ãŒã«ãããŠããªã³ã·ãã«ïŒGoogle ã¢ã«ãŠã³ããã°ã«ãŒãçïŒã IAM ããŒã«ãšçŽã¥ãããšãæäœãèš±å¯ãããŸãïŒæç€ºç㪠AllowïŒã æåŠããªã·ãŒã¯ãæã匷ãåªå
床ãæã¡ãŸããIAM ããªã·ãŒã§æç€ºç㪠Allow ãäžããããŠããæåŠããªã·ãŒãæãåªå
ãããæäœã¯æåŠãããŸãã åè : æåŠããªã·ãŒ IAM ããªã·ãŒã®è©äŸ¡é IAM ã®ããªã·ãŒãè©äŸ¡ãããéã以äžã®ãããªé çªã§è©äŸ¡ãããŸãã æç€ºç㪠Deny > æç€ºç㪠Allow > æé»ã® Deny IAM ã§ã¯ãæš©éããªãœãŒã¹éå±€ã®èŠªããåãžïŒäžããäžãžïŒ ç¶æ¿ ãããŸããéå±€ã®ã©ããã§ Deny ã«ãŒã«ãååšãããšããããæãåªå
ãããããšã«ãªããŸããå³ç€ºãããšã以äžã®ããã«ãªããŸãã IAM Policy è©äŸ¡ãã㌠ä»çµã¿ æåŠããªã·ãŒã®æ§è³ª æåŠããªã·ãŒã¯ãéåžžã® IAM ããªã·ãŒãšã¯ç¬ç«ãããªããžã§ã¯ã ã§ãã ãã®ãã gcloud projects get-iam-policy ãªã©ã§ãªãœãŒã¹ã® IAM ããªã·ãŒãé²èЧããŠããæåŠããªã·ãŒã¯è¡šç€ºãããŸããã äŸãšããŠããããããžã§ã¯ãã®éåžžã® IAM ããªã·ãŒãååŸããããã® gcloud ã³ãã³ãã瀺ããŸãã gcloud projects get-iam-policy your-project-name äžèšã®ã³ãã³ããå®è¡ãããšãæç€ºçãªèš±å¯ã瀺ã IAM bindings ã衚瀺ãããã®ã¿ã§ãæåŠããªã·ãŒã¯è¡šç€º ãããŸãã ã æåŠããªã·ãŒã衚瀺ããã«ã¯ã以äžã®ãããªã³ãã³ããå®è¡ããŸãã gcloud iam policies get my-deny-policy \ --attachment-point=cloudresourcemanager.googleapis.com/projects/your-project-name \ --kind=denypolicies ãŸãã以äžã®ãããªã³ãã³ããå®è¡ããŸãã gcloud projects get-ancestors-iam-policy sugimura --include-deny æåŠããªã·ãŒã®äœæã¯ã以äžã®ãããªã³ãã³ããå®è¡ããŸãã gcloud iam policies create my-deny-policy \ --attachment-point=cloudresourcemanager.googleapis.com/projects/your-project-name \ --kind=denypolicies --policy-file=policy.json ããããããæåŠããªã·ãŒã¯éåžžã® IAM ããªã·ãŒãšã¯ç°ãªããªããžã§ã¯ã ã§ããããšãåãããŸãã æåŠããªã·ãŒã管çããããã® IAM æš©é æåŠããªã·ãŒã®é²èЧã»äœæã»ç·šéã»åé€ã«ã¯ã Deny AdminïŒroles/iam.denyAdminïŒ ãªã©ã®ããŒã«ãå¿
èŠã§ãã ããšããããžã§ã¯ãã¬ãã«ã§ãªãŒããŒïŒroles/ownerïŒããŒã«ãæã£ãŠããŠããæåŠããªã·ãŒã®äœæã»ç·šéã»åé€ã¯ã§ãããé²èЧãã§ããã®ã¿ã§ãã åè : Required roles æåŠããªã·ãŒã®ç®¡ç æåŠããªã·ãŒã¯ãWeb ã³ã³ãœãŒã«ãgcloud ã³ãã³ãã©ã€ã³ãREST API çµç±ã§ç®¡çã§ããŸãã æåŠããªã·ãŒã«é¢ããåçš®æé ã«ã€ããŠã¯ã以äžã®ããã¥ã¡ã³ããåç
§ããŠãã ããã åè : ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãæåŠãã æåŠããªã·ãŒã®æ§æèŠçŽ æåŠããªã·ãŒã¯ã以äžã®ãããªèŠçŽ ã§æ§æãããŠããŸãã æåŠå¯Ÿè±¡ã®ããªã³ã·ãã« é€å€ããããªã³ã·ãã«ïŒãªãã·ã§ã³ïŒ æåŠããããŒããã·ã§ã³ æåŠããæ¡ä»¶ïŒãªãã·ã§ã³ïŒ ã¯ããã«ã 1. ã®ãæåŠå¯Ÿè±¡ã®ããªã³ã·ãã«ããšã¯ãæäœãæåŠãã察象ã®ããªã³ã·ãã«ãæå®ããŸããããªã³ã·ãã«ãšã¯ãGoogle ã¢ã«ãŠã³ãã Google ã°ã«ãŒãããµãŒãã¹ã¢ã«ãŠã³ãçãGoogle Cloud API ãå®è¡ããäž»äœãæããŸããããã§ã¯ãè€æ°ã®ããªã³ã·ãã«ãæå®ããããšãã§ããŸãã 2. ã®ãé€å€ããããªã³ã·ãã«ãã¯ã 1. ã§æå®ããããªã³ã·ãã«ã®ãã¡ã察象å€ãšããããªã³ã·ãã«ãæããŸããäŸãã° 1. ã§æåŠå¯Ÿè±¡ã®ããªã³ã·ãã«ãšã㊠hogehoge@example.com ãšãã Google ã°ã«ãŒããæå®ãããšããŸãã 2. ã«ãŠ john@example.com ãšããããªã³ã·ãã«ãé€å€å¯Ÿè±¡ãšããŠæå®ããã°ã john ã hogehoge ã°ã«ãŒãã«æå±ããŠããŠããæåŠå¯Ÿè±¡ã«ã¯ãªããŸããã 3. ã®ãæåŠããããŒããã·ã§ã³ãã¯äŸãšã㊠cloudresourcemanager.googleapis.com/projects.delete ãªã©ã®ãããŒããã·ã§ã³ãæå®ããŸããéåžžã® IAM ããªã·ãŒã§ã¯æš©éã®æå®æ¹æ³ãšã㊠IAM Role ãæå® ããã®ã«å¯ŸããŠãæåŠããªã·ãŒã§ã¯ ããŒããã·ã§ã³ãæå® ããããšã«æ³šæãå¿
èŠã§ãã 4. ã®ãæåŠããæ¡ä»¶ãã¯ãã¢ã¯ã·ã§ã³ãæåŠããæ¡ä»¶ãæå®ããŸãããã®æ¡ä»¶ã«äžèŽãããšãã ããã¢ã¯ã·ã§ã³ãæåŠãããŸããäŸãã°ãç¹å®ã®ãªãœãŒã¹ã¿ã°ãä»äžãããªãœãŒã¹ã«å¯Ÿããæäœã ããæåŠã§ããŸãã ç¶æ¿ éåžžã® IAM ããªã·ãŒãšåæ§ã«ãæåŠããªã·ãŒãäžäœãªãœãŒã¹ããäžäœãªãœãŒã¹ã«ç¶æ¿ãããŸãã çµç¹ã¬ãã«ã§ä»äžããããªã·ãŒã¯äžäœã®ãã©ã«ããŒããããžã§ã¯ãã«ç¶æ¿ãããŸãããŸãããã©ã«ããŒã¬ãã«ã§ä»äžããããªã·ãŒã¯äžäœã®ãããžã§ã¯ãã«ç¶æ¿ãããŸãããããžã§ã¯ãã«ä»äžããããªã·ãŒã¯ããããžã§ã¯ãå
ã®å
šãŠã®ãªãœãŒã¹ã«ç¶æ¿ãããŸãã æåŠããªã·ãŒã¯æãåªå
ããããããäžäœãªãœãŒã¹ã® IAM ããªã·ãŒã§æç€ºçã«èš±å¯ãããæš©éããäžäœãªãœãŒã¹ã«è¿œå ããæåŠããªã·ãŒã§æåŠããããšãã£ãããšãå¯èœã§ãã IAM ããªã·ãŒã®äŸ 以äžã¯ãå
¬åŒããã¥ã¡ã³ãããåŒçšããæåŠããªã·ãŒã§ãã åè : Structure of a deny policy { "name": "policies/cloudresourcemanager.googleapis.com%2Fprojects%2F253519172624/denypolicies/limit-project-deletion", "uid": "06ccd2eb-d2a5-5dd1-a746-eaf4c6g3f816", "kind": "DenyPolicy", "displayName": "Only project admins can delete projects.", "etag": "MTc1MTkzMjY0MjUyMTExODMxMDQ=", "createTime": "2021-09-07T23:15:35.258319Z", "updateTime": "2021-09-07T23:15:35.258319Z", "rules": [ { "denyRule": { "deniedPrincipals": [ "principalSet://goog/public:all" ], "exceptionPrincipals": [ "principalSet://goog/group/project-admins@example.com" ], "deniedPermissions": [ "cloudresourcemanager.googleapis.com/projects.delete" ], "denialCondition": { "title": "Only for non-test projects", "expression": "!resource.matchTag('12345678/env', 'test')" } } } ] } ãã® Deny ã«ãŒã«ã§ã¯ deniedPrincipals ã«ãŠããã¹ãŠã® Google ãŠãŒã¶ãŒã察象ãšãªã£ãŠããŸãã ããã exceptionPrincipals ã«ãŠ project-admins@example.com ãæå®ãããŠããããããã®ã°ã«ãŒãã ãã¯ãã®æåŠããªã·ãŒã®å¯Ÿè±¡å€ã§ãããšã¯ãããæç€ºçãªæåŠã®å¯Ÿè±¡å€ãšãªãã ãã§ãã®ã§ããã®ã°ã«ãŒãããªãœãŒã¹ã«å¯ŸããŠæäœãè¡ãã«ã¯ãIAM ããªã·ãŒã§ æç€ºçãªèš±å¯ãå¿
èŠ ã§ãã deniedPermissions ã«ãŠããã®æåŠã«ãŒã«ã®å¯Ÿè±¡ã cloudresourcemanager.googleapis.com/projects.delete ãããªãã¡ãããžã§ã¯ããåé€ããæš©éã§ããããšãåãããŸãã denialCondition ã«ãŠã env : test ãšãããªãœãŒã¹ã¿ã°ãã€ããŠãããããžã§ã¯ãã«éãããŠããããšãåãããŸãã æåŠããªã·ãŒå©çšã®æ³šæç¹ äœ¿ãæ ããªã·ãŒã®è©äŸ¡é 㯠æç€ºç㪠Deny > æç€ºç㪠Allow > æé»ã® Deny ã§ãããæç€ºç㪠Deny ãæã匷ãã§ãã ãã®ãã IAM æš©éäœç³»ã®èšèšæã¯ããŸãæåŠããªã·ãŒã䜿ããã«ãéåžžã® IAM ããªã·ãŒïŒæç€ºç㪠AllowïŒãä»äžãããããªãããã§ç®¡çããããšãååãšããã©ãããŠãåŒ·ãæš©éã§æåŠãããïŒæš©éã«ãã¿ããããïŒãšãã ãæç€ºç㪠Deny ã䜿ãããšããæ¹éã«ããããšãæãŸããã§ããæåŠããªã·ãŒïŒæç€ºç㪠DenyïŒã¯åŒ·åãããããã宿ã«äœ¿ããšåŸããä¿®æ£ãé£ãããªãå Žåãããããã§ãã æåŠã§ããã¢ã¯ã·ã§ã³ æåŠããªã·ãŒã§ã¯ããã¹ãŠã®ã¢ã¯ã·ã§ã³ãæåŠå¯Ÿè±¡ã«ã§ããããã§ã¯ãããŸãããæåŠã§ããã¢ã¯ã·ã§ã³ã®äžèЧãå
¬éãããŠããããµããŒãå¯Ÿè±¡ã®æš©éïŒã¢ã¯ã·ã§ã³ïŒä»¥å€ã¯ãæåŠã§ããŸããã ææ°ã®å¯Ÿè±¡æš©éïŒã¢ã¯ã·ã§ã³ïŒã¯ã以äžã®ããã¥ã¡ã³ãããåç
§ãã ããã åè : Permissions supported in deny policies ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãX (æ§ Twitter) ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
ããã«ã¡ã¯ãG-genã®èäºïŒ@arapoteïŒã§ãã åç·šã§ã¯Google Cloud (GCP) ã®å©çšéå§ã«åããŠã説æãæºåãé²ããŸããã ä»åã®åŸç·šã§ã¯å®éã«Google Cloud ãéå§ããæé ããéå§åŸã®ãã€ã³ãã解説ããŸãã åç·šã®ããã°ã¯ã³ãã©ã«ãªããŸããå¿
èŠãªãã®ãçšæããŠå©çšæç¶ããå§ããŸãããã blog.g-gen.co.jp Google Cloud å©çšéå§ åæã»ããã¢ãã Google Cloud ã³ã³ãœãŒã«ç»é¢ã«ã€ã㊠ã³ã³ãœãŒã«ç»é¢ã®èŠæ¹ã«ã€ã㊠Google Cloud ãå§ããéã®ãã€ã³ã äºç®ã¢ã©ãŒã ç¡æãã©ã€ã¢ã«æ ã®ç¢ºèª åçš®ãããã¯ãã®å§ãæ¹ åçš®æ©èœã®åŠç¿ Google Cloud ããã¥ã¡ã³ã ãããã« â»æ¬èšäºã®å
容ã¯2022幎3æ6æ¥æç¹ã®æ
å ±ãšãªããŸãã Google Cloud å©çšéå§ åæã»ããã¢ãã ã§ã¯æ©éGoogle Cloud ãå§ããŸãããïŒ ãŸã Google Cloud ãžã¢ã¯ã»ã¹ããŸãã â»ç»é¢ã€ã¡ãŒãžã¯2022幎3æ6æ¥ã®ãã®ã§ããç»é¢ã¯äºåãªã倿Žãšãªãå ŽåãããããŸãã ä»åã¯ç¡æã§å©çšãããããç¡æã§äœ¿ã£ãŠã¿ãããã¯ãªãã¯ããŠé²ã¿ãŸãã ãã°ã€ã³ãæ±ããããŸããåç·šã§æºåããGoogleã¢ã«ãŠã³ããå©çšããã°ã€ã³ããŸãã äœæããGoogleã¢ã«ãŠã³ãã®ãã¹ã¯ãŒããå
¥åãæ¬¡ã«é²ã¿ãŸãã Google Cloud ãå©çšããããã®ã»ããã¢ããç»é¢ã衚瀺ãããŸãã åœãšçµç¹ã®ã¿ã€ããå©çšèŠçŽã確èªã次ã«é²ã¿ãŸãã SMSãåä¿¡ã§ããæºåž¯é»è©±ãçšæããé»è©±çªå·ãå
¥åããŸãããã SMSã§åä¿¡ããã³ãŒããå
¥åããŸãã ã¢ã«ãŠã³ãã®çš®é¡ãšãæ¯ææ
å ±ãå
¥åããç¡æãã©ã€ã¢ã«ãéå§ããã¯ãªãã¯ããŸãã Google Cloud ã®ã³ã³ãœãŒã«ç»é¢ãéããå©çšã§ããç¶æ
ãšãªããŸããã ãããã§ããã§ãããããã¯ã©ãŠãã§ãµãŒããŒãæ§ç¯ããæºåããªã©ãšèšã£ãŠããŸããšå€§å±€ãªæºåãå¿
èŠãšæã£ãŠããŸããã¡ã§ããããããã®éããããªã容æã«å§ããããšãã§ããŸãã ããŠïŒããã§Google Cloud ãå©çšã§ããããã«ãªã£ãã®ã§ãããäœããå§ãããè¯ããããããªãæ¹ã®ããã«å°ããã€ã³ããã説æããããŸãã Google Cloud ã³ã³ãœãŒã«ç»é¢ã«ã€ã㊠ã³ã³ãœãŒã«ç»é¢ã®èŠæ¹ã«ã€ã㊠ãŸãæåã«Google CLoud ã®ã³ã³ãœãŒã«ç»é¢ã«ã€ããŠãã³ã³ãœãŒã«ç»é¢ã§ã¯ã©ããªããšãã§ããã解説ããŸãã â ãããžã§ã¯ã ã©ã®ãããžã§ã¯ãã§äœæ¥ãããŠããã確èªããããšãã§ããŸãããŸããããžã§ã¯ãã®åãæ¿ããå¯èœã§ãã â¡æ€çŽ¢ããã¯ã¹ ãããã¯ããæ€çŽ¢ããããšãã§ããŸããGoogle Cloud ã¯ãããã¯ããéåžžã«å€ããããæ€çŽ¢ã¯ããå©çšããŸãã â¢Cloud Shell ã³ãã³ãã©ã€ã³ã§ Google Cloud ãæäœã§ããããŒã« Cloud Shell ãèµ·åããããšãã§ããŸãã â£åºå®ïŒã·ã§ãŒãã«ããïŒ åºå®ãããããã¯ãã«çŽ æ©ãã¢ã¯ã»ã¹ããããšãã§ããŸãã â€ããã²ãŒã·ã§ã³ã¡ãã¥ãŒ å©çšããããããã¯ããéžæãã詳现ç»é¢ã«å
¥ããŸãããŸãããå©çšãããããã¯ãã®ç»é²ããŒã¯ãã¯ãªãã¯ããããšã§ãäžéšã«åºå®ããããšãã§ããŸãã Google Cloud ãå§ããéã®ãã€ã³ã Google Cloud ãéå§ããäžã§ãæåã«èšå®ïŒç¢ºèªïŒãããŠãããªããã°ãªããªãç¹ãããã€ããããŸãã é
ç®ããã§ãã¯ãªã¹ãã¯äžèšã®ããã°ã«èŠç¹ããŸãšãŸã£ãŠããŸãã®ã§ããã¡ãããåç
§ãã ããã blog.g-gen.co.jp äºç®ã¢ã©ãŒã ãã¯ãæ°ã«ãªã£ãŠããŸãæéã§ãããåå解説ããéã 課éã®æå¹å ãè¡ããªãéã課éã¯çºçããŸããã ãšã¯ããç¡æãã©ã€ã¢ã«æ ã®$300ãè¶
ãããå©çšãã§ããªããªã£ãŠããŸããããæéã¯æ°ã«ããŠãããªããã°ãªããŸããã ãã®ããå©çšæéã®éŸå€ãèšå®ããã¢ã©ãŒããéç¥ãããããèšå®ãè¡ããŸãããã ä»åã¯æã«æå®ããéé¡ïŒï¿¥30,000ïŒã«å¯ŸããŠ50%/90%/100%ã«å°éããéã¡ãŒã«éç¥ããããèšå®ãè¡ããŸãã ã³ã³ãœãŒã«ç»é¢ã§ãäºç®ãšã¢ã©ãŒãããæ€çŽ¢ããŸãã ãäºç®ãäœæããã¯ãªãã¯ããŸãã ãæé 1ïŒç¯å²ãã§æéã察象ãããžã§ã¯ãã»ãµãŒãã¹ãèšå®ããŸãã é
ç® å
容 åå ïŒä»»æèšå®ïŒ æé æå¥ ãããžã§ã¯ã ãã¹ãŠã®ãããžã§ã¯ã ãµãŒãã¹ ãã¹ãŠã®ãµãŒãã¹ ã¯ã¬ãžãã æå¹ïŒå²åŒãããã¢ãŒã·ã§ã³ãªã© ãæé 2ïŒéé¡ãã§äºç®ã¿ã€ããéé¡ãèšå®ããŸãã é
ç® å
容 äºç®ã¿ã€ã æå®é¡ ç®æšéé¡ ï¿¥30000 ãæé 3ïŒæäœãã§ã¢ã©ãŒãã®éŸå€ãšã¢ã©ãŒãæ¹æ³ãèšå®ããŸãã No äºç®ã®å²å éé¡ ããªã¬ãŒå¯Ÿè±¡ 1 50% ï¿¥15000 å®å€ 2 90% ï¿¥27000 å®å€ 3 100% ï¿¥30000 å®å€ ç¡æãã©ã€ã¢ã«æ ã®ç¢ºèª ç¡æãã©ã€ã¢ã«æ ã®$300ãš90æ¥ã§ããããªã¢ã«ã¿ã€ã ã§ã®æ®é¡ã𿥿°ã確èªãããå Žåäžèšã®ç»é¢ã§ç¢ºèªããããšãã§ããŸãã æ®ãã¯ã¬ãžãããšçµäºæ¥ã«ã¯æ³šæããŠãããŸãããã å·Šäžã®ããã²ãŒã·ã§ã³ã¡ãã¥ãŒãã¿ã³ããããã²ãŒã·ã§ã³ã¡ãã¥ãŒãå±éãããæ¯æãããã¯ãªãã¯ããŸãã ç»é¢å³ã«æ®ãã¯ã¬ãžãããšçµäºæ¥ã®è¡šç€ºããããŸãã â»ã¢ããã°ã¬ãŒããã¿ã³ã«ã¯æ³šæããŸãããïŒïŒ è«æ±ã«é¢ããä»çµã¿ã«ã€ããŠã¯ãæ¬ããã°ã®å¥èšäºã§è©³çްå
容ãèšèŒãããŠããŸãã ãã Google Cloud ãæ¬æ ŒæŽ»çšãããéã«ã¯åèã«ããŠããã ããã°ãšæããŸãã blog.g-gen.co.jp åçš®ãããã¯ãã®å§ãæ¹ è«žã
ã®æºåãæŽã£ãã®ã§æ¬¡ã¯èå¿ã®ããããã¯ãå©çšã§ãã Google Cloud ã§ã¯åããŠå©çšããããåãã«ãã¥ãŒããªã¢ã«ããããŸãããã¥ãŒããªã¢ã«ãã Google Cloud åçš®ãããã¯ãã®å©ç𿹿³ãåŠç¿ããŸãããã ããã«ããããããã¥ãŒããªã¢ã«ãéå§ããã¯ãªãã¯ããŸãã ãã¥ãŒããªã¢ã«ãéå§ããããããã¯ããã¯ãªãã¯ããŸãã å
容ã確èªããéå§ããã¯ãªãã¯ãããã¥ãŒããªã¢ã«ãéå§ããŸãã åçš®æ©èœã®åŠç¿ ãã¥ãŒããªã¢ã«ã¯ç¹å®ã®ãããã¯ãã®ã¿ã察象ãšããŠããŸããããã以å€ã® Google Cloud ãµãŒãã¹ã®ä»çµã¿ãæ©èœãåŠç¿ãããéã«ã¯ãåŠã¶ããæå¹ã§ãã ããŒãžå³äžã«ãåŠã¶ãã衚瀺ãããŠããå ŽåãåŠã¶ããã¯ãªãã¯ãããšãé¢é£ããããã¥ã¡ã³ããåç»ã確èªããããšãã§ããŸãã ãåŠã¶ããã¯ãªãã¯ããŸãã é¢é£ããããã¥ã¡ã³ããåç»ã衚瀺ãããŸãã Google Cloud ããã¥ã¡ã³ã æåŸã« Google Cloud ã«é¢ããããã¥ã¡ã³ãã®ãªã³ã¯ãã玹ä»ããŸããåçš®ãããã¯ãã®æŠèŠãæè¡æ
å ±ãæ²èŒããããŠããŸããåå¿è
ããäžçŽè
ãŸã§é »ç¹ã«ç¢ºèªããããšãå€ããšæããŸãã googlecloudcheatsheet.withgoogle.com ãŸãã以äžã®ãªã³ã¯éã§ã¯åãããã¯ãããããããã解説ããåœç€ŸèšäºããŸãšãŸã£ãŠããŸããããã¯ããŒã¯å¿
é ã§ãïŒïŒ blog.g-gen.co.jp ãããã« ãç²ãããŸã§ããã以äžã§ Google Cloud ãç¡æã§æ¥œããããšãã§ããŸãïŒ Google Cloud ãç¡æã§ãå©çšããã ããç¶ç¶ããŠäœ¿ã£ãŠã¿ããããšæã£ãæ¹ã¯ãæ¯éG-genã«ãçžè«ãã ããã Google Cloud ã3%OFFã ã§ãåŸã«ãå©çšããã ããŸãïŒïŒ ããã§ã¯ãå¿«é©ãªã¯ã©ãŠãã©ã€ãããæ¥œãã¿ãã ããïŒïŒ èäº éåº (èšäºäžèЧ) ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš ã¯ã©ãŠããµããŒã課 ãªã³ãã¬ç°å¢ã®ãããã¯ãŒã¯ã»ãµãŒããŒã·ã¹ãã ãäž»æŠå ŽãšããŠããããã¯ã©ãŠãé åã«ã·ãããçŸåšã¯ Google Workspace ãäžå¿ã«äŒæ¥ã® DX æšé²ããµããŒãã ã» Google Cloud Partner Top Engineer 2025 ã»Google Cloud èªå®è³æ Œ 7å æè¿ããã£ãŠããããšã¯ãæ¯åãšã®ãã±ã¢ã³ã«ãŒã Follow @arapote_tweet
G-gen ã®ææã§ããåœèšäºã§ã¯ãGoogle Cloud ã®ä»®æ³ãµãŒããŒãµãŒãã¹ã§ãã Compute Engine ã®å²åŒå¶åºŠã®1ã€ã§ãã ç¶ç¶å©çšå²åŒ ïŒSustained use discountsïŒã«ã€ããŠè§£èª¬ããŸãã ã¯ããã« ç¶ç¶å©çšå²åŒãšã¯ ä»ã®å²åŒå¶åºŠ å²åŒå¯Ÿè±¡ å²åŒç èšç®äŸ åææ¡ä»¶ è©Šç® è£è¶³ ã¯ããã« ç¶ç¶å©çšå²åŒãšã¯ ç¶ç¶å©çšå²åŒ ïŒSustained use discountsïŒã¯ãGoogle Cloud ã®ä»®æ³ãµãŒããŒãµãŒãã¹ã§ãã Compute Engine ã®å²åŒå¶åºŠã®1ã€ã§ããã€ã³ã¹ã¿ã³ã¹ã忢ããã«èµ·åãããŸãŸã«ããã ãã§ãå²åŒã¡ãªãããåŸãããšãã§ããŸãã ç¶ç¶å©çšå²åŒã§ã¯ã1ã¶æã®ãã¡25%以äžã®æéïŒäŸãã°3æã§ããã°ã31 æ¥é = 744 æéã§ãã®ã§ã25%ã¯186æéã«ãªããŸãïŒãVM ãèµ·åãããŸãŸã«ããŠãããšèªåçã«é©çšããããã以éã¯æ®µéçã«å²åŒé¡ãäžãã£ãŠãããç·é¡ãšããŠæå€§20%ã30%ã®å²åŒãé©çšãããŸãã åè : ç¶ç¶å©çšå²åŒ ä»ã®å²åŒå¶åºŠ 䌌ãåç§°ã®å²åŒå¶åºŠãšã㊠確çŽå©çšå²åŒ ïŒCommitted use discountsïŒãååšããŸãã確çŽå©çšå²åŒã«ã€ããŠã¯ä»¥äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp å²åŒå¯Ÿè±¡ ç¶ç¶å©çšå²åŒã¯ã Compute Engine ãš Google Kubernetes Engine ïŒGKEïŒã§èµ·åããã VM ã察象ã«ãªããŸãã 以äžã¯å¯Ÿè±¡å€ã§ãããããæ³šæãå¿
èŠã§ãã App EngineïŒã¹ã¿ã³ããŒãããã¬ãã·ãã«ïŒã§èµ·åããã VM Dataflow ã«ããèµ·åããã VM 確çŽå©çšå²åŒã®å¯Ÿè±¡ãšãªã£ãŠãã VMïŒäœ¿çšéïŒ E2ãA2ãT2D ãã·ã³ã¿ã€ããªã©ã察象ãšãªã£ãŠãããã·ã³ã¿ã€ã以å€ã®ãã·ã³ã¿ã€ã æãå®ãæ±çšçã«äœ¿ããããåºçªã®å€ã E2 ãã·ã³ã¿ã€ãã§ãããE2 ã«ã¯ç¶ç¶å©çšå²åŒãé©çšãããŸããããŸãææ°ã®ãã·ã³ã¿ã€ãã«ã¯é©çšãããªãå ŽåããããŸããè©³çŽ°ãææ°æ
å ±ã¯ä»¥äžã®ããã¥ã¡ã³ãã®è±èªçãåç
§ããŠãã ããã åè : Sustained use discounts - Limitations ãŸã泚æç¹ãšããŠãç¶ç¶å©çšå²åŒãé©çšãããã®ã¯ vCPU ã³ã¢ãšã¡ã¢ãªã«å¯ŸããŠã§ããã æ°žç¶ãã£ã¹ã¯ã«ã¯é©çšãããªã ç¹ã«æ³šæããŠãã ããã å²åŒç ç¶ç¶å©çšå²åŒã¯ãVM ãèµ·åããŠããæéã«å¿ããŠã段éçã«å²åŒé¡ãå¢ããŸãã以äžã«ãäŸãèšèŒããŸãã æå
ã§èµ·åããŠããæé 課éé¡ c2-standard-4 ã€ã³ã¹ã¿ã³ã¹ã®å Žåã®äŸ¡æ Œ 0%â25% å®äŸ¡ã® 100% $0.2088 /h 25%â50% å®äŸ¡ã® 86.78% $0.1811 /h 50%â75% å®äŸ¡ã® 73.3% $0.1530 /h 75%â100% å®äŸ¡ã® 60% $0.1252 /h ãã®ããã«ãé·æéèµ·åãããŸãŸã§ããã°ã èµ·åããŠããæéåã®èª²éã«å¯ŸããŠæå®ã®å²åã®å²åŒ ãé©çšãããŸãã 倧äºãªãã€ã³ããšããŠã èµ·åããŠããåã«å¯ŸããŠã®å²åŒé¡ ã倧ãããªã£ãŠããã®ã§ãã忢ããã«ããšâ¯æéèµ·åããŠããã°ã忢ãããšããããå®ããªãããšãã£ãããšã¯çºçããŸããã èšç®äŸ 以äžã«ãç¶ç¶å©çšå²åŒã®èšç®äŸã瀺ããŸãã åææ¡ä»¶ ãã·ã³ã¿ã€ã : c2-standard-4 å®äŸ¡ : $0.2088 /h ææ : ãã幎ã®3æ äžèšã®æ¡ä»¶ã§ãVM ãæäžã«589æéèµ·åããŠãããšä»®å®ããŠãç¶ç¶å©çšå²åŒã®èšç®äŸã瀺ããŸããããã¯ãæ¯æ¥æ·±å€1æããæ6æãŸã§ VM ã忢ããŠããå Žåãæ³å®ããŠããŸãã è©Šç® 589æé ãåè§£ãããšã以äžã®éãã 186æéïŒ0%-25%ïŒ+ 186æéïŒ25%-50%ïŒ+ 186æéïŒ50%-75%ïŒ+ 31æéïŒ75%-100%ïŒ ããããã®èª²éé¡ã®èšç®ã¯ã以äžã®éãã $0.2088 * 186h = $38.8368 $0.1811 * 186h = $33.6846 $0.1530 * 186h = $28.458 $0.1252 * 31h = $3.8812 äžèšãåèšãããšã以äžã®éãã $38.8368 + $33.6846 + $28.458 + $3.8812 = $104.8606 èš $104.8606 ããã¯ãå®äŸ¡ã§ãã $0.2088 à 589 æéãšèšç®ãã $122.9832 ãšæ¯ã¹ããšã ç·é¡ã§ã¯çŽ15%å®äŸ¡ ã«ãªã£ãŠããããšãåãããŸãã ãªããæ°žç¶ãã£ã¹ã¯ã®æéã¯äžèšã®èšç®ããã¯å€ããŠãããŸããåè¿°ã®ããã«ãæ°žç¶ãã£ã¹ã¯ã¯ç¶ç¶å©çšå²åŒã®å¯Ÿè±¡å€ã§ãã®ã§ããæ³šæãã ããã å³ã«ãã説æ è£è¶³ ç¶ç¶å©çšå²åŒã¯èªåçã«èšç®ããã課éé¡ã«åæ ãããŸãã®ã§ããŠãŒã¶ãŒåŽã§èšç®ãããå¿
èŠã¯ãããŸããã ãŸããäºåã«æéãèŠç©ããããå Žåã¯ãå
¬åŒã®å©çšæèšç®ããŒã«ã§ãã Google Cloud's pricing calculator ãå©çšããããšã§ãç¶ç¶å©çšå²åŒãèæ
®ã«å
¥ããéé¡ãèŠç©ããããšãã§ããŸãã åè : Google Cloud's pricing calculator ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO å
èŠå¯å®ãšããçµæŽãæã€ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS èªå®è³æ Œããã³ Google Cloud èªå®è³æ Œã¯ãã¹ãŠååŸãXïŒæ§ TwitterïŒã§ã¯ Google Cloud ã Google Workspace ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
ããã«ã¡ã¯ãG-genã®æž¡é @norry ã§ãã æšä»ã¯ã©ãŠããã€ãã£ããšããã¯ãŒããåœããåã®ããã«è³ã«ããããã«ãªããŸããã èªåã¯ã¯ã©ãŠãã®å©ç¹ã培åºçã«æŽ»çšããïŒãšãããããªæå³åãã§æãããŠããŸããã·ã¹ãã ãæ§ç¯ã»éçšããéã«ãŸãã¯ã©ãŠããããŒã¹ã«ããŠäœ¿ãåããŠããæãã§ããããã åŒç€Ÿã¯ãã«ãªã¢ãŒãã§åããã³ãã£ãŒäŒæ¥ã§ããäºãããã瀟å
ã«ãªã³ãã¬ãã¹ã®ãµãŒããŒãä¿æããŠããããVPNç°å¢ãå©çšããŠããŸããã ãšã¯ãããæ¥æ¬ã®å€ãã®äŒæ¥ã§ã¯ç€Ÿå
ã«ãµãŒããŒããããããããã¯ã©ãŠããžç§»è¡ãããŸãã¯ãªã³ãã¬ãã¹ãšã¯ã©ãŠãã®ãã€ããªããã§ã®éçšããã€ã³ã¿ãŒãããåŽã«ã¯å
¬éãã瀟å
ã·ã¹ãã ãå©çšããããšèšãäºããããšæããŸãã æ¬çªç°å¢ãªãå°çšç·ãµãŒãã¹ã§ããCloud Interconnect ãå©çšããŠéåç¶²ã§æ¥ç¶ããäºãããããããŸãããäºç®ã®é¢ä¿ãæ°è»œã«éå§ãããæ¹ã
ãžåããŠç€Ÿå
LAN ãã Google Cloud (æ§GCP ) ã§ç°¡åã« VPNæ¥ç¶ããæé ããæ¡å
ããããŸãã Cloud VPN ãšã¯ ã¢ãŒããã¯ãã£ æ§æå³ Cloud VPN ã®ã¿ã€ã HA (High Availability) VPN ãšã¯ VPN æ¥ç¶ã§çè§£ããŠããã¹ãçšèª Google Cloud åŽã®èšå® VPC ã®èšå® Google Cloud Engine (GCE) ã€ã³ã¹ã¿ã³ã¹ã®äœæ ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®èšå® Cloud VPN ãäœæ 瀟å
ãªã³ãã¬ãã¹ã«ãŒã¿ãŒ (RTX1210) ã®èšå® IPsecãã³ãã«ã®èšå®1 IPsecãã³ãã«ã®èšå®2 IPsecãã³ãã« å
±éèšå® BGPã®èšå® BGPã®èšå® æå¹å æ¥ç¶ç¢ºèª Ping ãš RDP æ¥ç¶ç¢ºèª Cloud VPN ãšã¯ Cloud VPN ãšã¯ IPsec VPN æ¥ç¶ã䜿çšããŠããªã³ãã¬ãã¹ ãããã¯ãŒã¯ ãš VPC ãããã¯ãŒã¯ããã©ã€ããŒãã«æ¥ç¶ãããµãŒãã¹ã§ãã 詳现ã¯ä»¥äžã®èšäºã§è§£èª¬ããŠããŸãã®ã§ããåç
§ãã ããã blog.g-gen.co.jp ã¢ãŒããã¯ãã£ æ§æå³ ä»åã¯ã·ã³ãã«ãªäžå³ã®ãããªæ§æã§æ§ç¯ããŸãã æ§æå³ ãªã³ãã¬ãã¹åŽã§å©çšããã«ãŒã¿ãŒã¯ RTX1210 ã«ãªããŸãã(å°ãå€ãæ©çš®ã§ããããŒã¹ã®éšåã¯çŸè¡ã¢ãã«ãšã»ãŒå€ãããªãã¯ãããã) Cloud VPN ã®ã¿ã€ã å
¬åŒããã¥ã¡ã³ã ã®åŒçšã«ãªããŸãã Google Cloud ã«ã¯ãHA VPN ãš Classic VPN ã® 2 çš®é¡ã® Cloud VPN ã²ãŒããŠã§ã€ããããŸãããã ããClassic VPN ã®ç¹å®ã®æ©èœã 2022 幎 3 æ 31 æ¥ã«éæšå¥šãšãªããŸãã ãšãããŸãã®ã§ä»å㯠HA VPN æ§æã§èšå®ããŠãããŸãã HA (High Availability) VPN ãšã¯ åäžãªãŒãžã§ã³å
ã® IPsec VPN æ¥ç¶ã䜿çšããŠããªã³ãã¬ãã¹ ãããã¯ãŒã¯ã VPC ãããã¯ãŒã¯ã«å®å
šã«æ¥ç¶ã§ãããé«å¯çšæ§ïŒHigh AvailabilityïŒCloud VPN ãœãªã¥ãŒã·ã§ã³ã§ãã ãªã³ãã¬ãã¹ ãããã¯ãŒã¯ãšããŠããŸãããå®éã«ã¯ IPsec VPN æ¥ç¶å¯èœãª AWS ã Microsoft Azure ãšãæ¥ç¶åºæ¥ãŸãã HA VPN ã¯2 ã€ã®ã€ã³ã¿ãŒãã§ãŒã¹ã«1ã€ãã€ã2 ã€ã®å€éš IP ã¢ãã¬ã¹ãèªåçã«éžæãã99.99% ã®ãµãŒãã¹å¯çšæ§ã® SLA ãæäŸããŸãã ã¢ã¯ãã£ãã€ã³ã¿ãŒãã§ã€ã¹ãïŒã€ãå€éšã¢ãã¬ã¹ïŒã€ã§ãå®ã¯éä¿¡å¯èœã§ãããã®å Žå SLA ã¯99.99% ãšãªããŸããã VPN æ¥ç¶ã§çè§£ããŠããã¹ãçšèª Cloud VPN ã§ HA VPN æ§æãçµãå Žåã«è¯ãåºãŠããèšèãäžèšã«ãŸãšããŠãããŸããããã£ãšç¢ºèªããŠãããŠããã ããæ¹ãå
šäœã®çè§£ãæ·±ãŸãããšæããŸãã çšèª ç°¡åãªè§£èª¬ 1 AS çªå· (Autonomous System number) ISP ãªã©å€§ããªãããã¯ãŒã¯ã«å²ãåœãŠãããäžæã®èå¥çªå· 2 BGP (Border Gateway Protocol) AS ãä»ã®AS ã«åºåãããã«ãŒãã£ã³ã°ãããããããã®ãããã³ã« 3 Cloud VPN ã²ãŒããŠã§ã€ïŒIPïŒ Google Cloud ã®å€åŽ (WAN) IP ã¢ãã¬ã¹ 4 ã㢠VPN ã²ãŒããŠã§ã€ïŒIPïŒ ãªã³ãã¬ãã¹ã® å€åŽ (WAN) IP ã¢ãã¬ã¹ 5 Cloud Router ã® BGP IP IPsec VPN ã§ãã³ãã«ã匵ãæã® Google Cloud åŽ BGP çš IP ã¢ãã¬ã¹ 6 BGP ã㢠IP IPsec VPN ã§ãã³ãã«ã匵ãæã®ãªã³ãã¬ãã¹åŽã® BGPçš IP ã¢ãã¬ã¹ Google Cloud åŽã®èšå® VPC ã®èšå® ãŸã㯠VPC (Virtual Private Cloud) ãèšå®ããŸããVPCã£ãŠäœïŒ ãšããæ¹ã¯ä»¥äžãåç
§ãã ããã blog.g-gen.co.jp 管çã³ã³ãœãŒã« ïŒ VPCãããã¯ãŒã¯ ïŒ VPC ãããã¯ãŒã¯ã®äœæ ãã以äžã®ããã«äœæããŸããã VPC ãµããããäœæ ãŸããåãããŠçµç¹ããªã·ãŒã§ä»¥äžã®èšå®ã宿œããŠããäºãããããããŸãã ããªã·ãŒID ããªã·ãŒæŠèŠ çç±ãšèª¬æ constraints/compute.skipDefaultNetworkCreation ããã©ã«ã ãããã¯ãŒã¯ã®äœæãã¹ããã ããã©ã«ããããã¯ãŒã¯ã¯é垞䜿ããªããããèªåäœæãããªãããèšå®ãã constraints/iam.automaticIamGrantsForDefaultServiceAccounts ããã©ã«ãã®ãµãŒãã¹ ã¢ã«ãŠã³ãã«å¯Ÿãã IAM ããŒã«ã®èªåä»äžã®ç¡å¹å æå¹ã«ããããšã§ VM ãæåã«äœæããæã«äœæãããããã©ã«ãã® Compute Engine ãµãŒãã¹ã¢ã«ãŠã³ãã« Owner æš©éãä»äžãããããšãé²ã Google Cloud Engine (GCE) ã€ã³ã¹ã¿ã³ã¹ã®äœæ 管çã³ã³ãœãŒã« ïŒ Compute Engine ïŒ VM ã€ã³ã¹ã¿ã³ã¹ ïŒ + ã€ã³ã¹ã¿ã³ã¹ãäœæ èšå®å
å®¹ã¯æ¬¡ã®ãšããã§ããä»åã¯å€éš IP ãæãããã€ã³ã¿ãŒãããåŽããçŽæ¥ã¢ã¯ã»ã¹åºæ¥ãªã圢ã«ããŠããŸãããã ã VM åŽãã㯠Cloud NAT ãéããŠã€ã³ã¿ãŒãããæ¥ç¶ãå¯èœã§ãã é
ç® èšå®å€ åå windows-1 ãŸãŒã³ asia-northeast2-a ãã·ã³ã¿ã€ã e2-medium OS windows-server-2019 ãããã¯ãŒã¯ norry-vpc ãµããããã¯ãŒã¯ private ãã©ã€ããªå
éš IP 10.0.1.2 å€éš IP ãªã ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®èšå® 管çã³ã³ãœãŒã« ïŒ VPCãããã¯ãŒã¯ ïŒ ãã¡ã€ã¢ãŠã©ãŒã« ïŒ + ãã¡ã€ã¢ãŠã©ãŒã«ãäœæ äœæãã VPC ã«å¯Ÿããã¡ã€ã¢ãŠã©ãŒã«ã®èšå®ãè¡ããŸããä»å㯠VM 㫠瀟å
LAN (192.168.100.0/24) ããã® RDP ãš Ping ãéãçºã® icmp ãèš±å¯ããŸããã ãã¡ã€ã¢ãŠã©ãŒã«èšå® Cloud VPN ãäœæ VPC ã®äœæãVMã®äœæããã¡ã€ã¢ãŠã©ãŒã«ã®èšå®ãå®äºããŸããã®ã§å®éã« Cloud VPN ã®èšå®ã«å
¥ã£ãŠãããŸãã HA VPN ã§ã¯ Cloud VPN ã²ãŒããŠã§ã€ã§ IP ã2ã€ããã³ãã«ã2æ¬åŒµãæ§æã«ããŠããŸãã ASN ã¯ãã©ã€ããŒã ASN ãå©çšããŠããŸãã èšå®ãããã©ã¡ãŒã¿ã¯æ¬¡ã®éãã§ãã é
ç® èšå®å€ åå norry-ha-vpn ãããã¯ãŒã¯ norry-vpc ãªãŒãžã§ã³ asia-northeast2 Cloud VPN ã²ãŒããŠã§ã€ïŒIP) â 34.xxx.xxx.xxx Cloud VPN ã²ãŒããŠã§ã€ïŒIP) â¡ 35.xxx.xxx.xxx ãã³ãã«å â norry-inhouse-tn ãã³ãã«å â¡ norry-inhouse-tn2 ã㢠VPN ã²ãŒããŠã§ã€ïŒIPïŒ 118.xxx.xxx.xxx Cloud Router ASN 65001 ãã¢ã«ãŒã¿ãŒ ASN 65002 Cloud Router ã® BGP IP â 169.254.0.1 Cloud Router ã® BGP IP â¡ 169.254.1.1 BGP ã㢠IP â 169.254.0.2 BGP ã㢠IP â¡ 169.254.1.2 IKEããŒãžã§ã³ IKEv2 å
±æã·ãŒã¯ã¬ãã ä»»æ ã«ãŒãã£ã³ã°ãªãã·ã§ã³ ããªã·ãŒããŒã¹ ãªã¢ãŒããããã¯ãŒã¯IPã®ç¯å² 192.168.100.0/24 ããŒã«ã«IPç¯å² 10.0.1.0/24 ã§ã¯ Google Cloud åŽã®èšå®ã«å
¥ã£ãŠãããŸãããã 管çã³ã³ãœãŒã« ïŒ ãã€ããªããæ¥ç¶ ïŒ VPN ïŒ + VPN èšå®ãŠã£ã¶ãŒã ãã é«å¯çšæ§ (HA) VPN ãéžæããŸãã VPN èšå®ãŠã£ã¶ãŒã - VPN ã®äœæ ãVPN ã²ãŒããŠã§ã€ã®ååãããããã¯ãŒã¯ãããªãŒãžã§ã³ããéžæããäœæããŠå®è¡ ã㢠VPN ã²ãŒããŠã§ã€ã¯ãªã³ãã¬ãã¹ãŸãã¯é Google Cloud ãéžæãããæ°ãã VPN ã²ãŒããŠã§ã€ãäœæããã ãååããšã€ã³ã¿ãŒãã§ãŒã¹ 1 ã€ã®ã€ã³ã¿ãŒãã§ãŒã¹ ãéžæããRTX1210 ã®ã°ããŒãã« IP ãèšå®ããŸããã°ããŒãã« IP ãè€æ°ãæã¡ã®å Žåã¯ã€ã³ã¿ãŒãã§ãŒã¹ãå¢ããäºãå¯èœã§ãã æ¬¡ã«æ°ããã«ãŒã¿ãŒãäœæããŸã ãååããšãASNããèšå®ãäœæããŸãã ç¶ã㊠IKE ãŸããã®èšå®ãããŸãããååãã IKE ããŒãžã§ã³ãã IKE äºåå
±æããŒããå
¥åã BGP ã»ãã·ã§ã³ã®äœæããååããã㢠ASNããCloud Router ã® BGP IPããBGP ã㢠IPããå
¥åãBGP IP ã¯ãªã³ã¯ããŒã«ã«ã¢ãã¬ã¹ã䜿çšããŸããã 1ã€ç®ã®ãã³ãã«äœæãŸã§çµãããŸããã®ã§ ã VPN ãã³ãã«äœæãã§ 2 æ¬ç®ã®ãã³ãã«ãäœæããŠãã ããã 瀟å
ãªã³ãã¬ãã¹ã«ãŒã¿ãŒ (RTX1210) ã®èšå® Config 㯠Yamaha å
¬åŒããŒãž ãåç
§ããŠä»¥äžã®èšå®ãããŠããŸãã IPsecãã³ãã«ã®èšå®1 tunnel select 1 ipsec tunnel 1 ipsec sa policy 1 1 esp aes-cbc sha-hmac ipsec ike version 1 2 ipsec ike always-on 1 on ipsec ike encryption 1 aes-cbc ipsec ike group 1 modp1024 ipsec ike hash 1 sha ipsec ike keepalive log 1 on ipsec ike keepalive use 1 on rfc4306 ipsec ike local address 1 192.168.100.1 ipsec ike local name 1 118.xxx.xxx.xxx ipv4-addr ipsec ike nat-traversal 1 on ipsec ike pfs 1 on ipsec ike pre-shared-key 1 text (äºåå
±æéµ) ipsec ike remote address 1 34.xxx.xxx.xxx ipsec ike remote name 1 34.xxx.xxx.xxx ipv4-addr ip tunnel address 169.254.0.2 ip tunnel remote address 169.254.0.1 ip tunnel tcp mss limit auto tunnel enable 1 IPsecãã³ãã«ã®èšå®2 tunnel select 2 ipsec tunnel 2 ipsec sa policy 2 2 esp aes-cbc sha-hmac ipsec ike version 2 2 ipsec ike always-on 2 on ipsec ike encryption 2 aes-cbc ipsec ike group 2 modp1024 ipsec ike hash 2 sha ipsec ike keepalive log 2 on ipsec ike keepalive use 2 on rfc4306 ipsec ike local address 2 192.168.100.1 ipsec ike local name 2 118.xxx.xxx.xxx ipv4-addr ipsec ike nat-traversal 2 on ipsec ike pfs 2 on ipsec ike pre-shared-key 2 text (äºåå
±æéµ) ipsec ike remote address 2 35.xxx.xxx.xxx ipsec ike remote name 2 35.xxx.xxx.xxx ipv4-addr ip tunnel address 169.254.1.2 ip tunnel remote address 169.254.1.1 ip tunnel tcp mss limit auto tunnel enable 2 IPsecãã³ãã« å
±éèšå® ipsec auto refresh on BGPã®èšå® bgp use on bgp autonomous-system 65002 bgp neighbor 1 65001 169.254.0.1 local-address=169.254.0.2 bgp neighbor 2 65001 169.254.1.1 local-address=169.254.1.2 bgp import filter 1 equal 192.168.100.0/24 bgp import 65001 static filter 1 BGPã®èšå® æå¹å bgp configure refresh æ¥ç¶ç¢ºèª Ping ãš RDP æ¥ç¶ç¢ºèª 以äžã§èšå®å®äºã§ãã瀟å
PC ãã Ping ã®ãã¹ããããŠã¿ãŸãã norry@penguin:~$ ping 10.0.1.2 PING 10.0.1.2 (10.0.1.2) 56(84) bytes of data. 64 bytes from 10.0.1.2: icmp_seq=1 ttl=124 time=30.1 ms 64 bytes from 10.0.1.2: icmp_seq=2 ttl=124 time=29.6 ms 64 bytes from 10.0.1.2: icmp_seq=3 ttl=124 time=27.5 ms 64 bytes from 10.0.1.2: icmp_seq=4 ttl=124 time=26.6 ms 64 bytes from 10.0.1.2: icmp_seq=5 ttl=124 time=25.6 ms 64 bytes from 10.0.1.2: icmp_seq=6 ttl=124 time=29.2 ms 64 bytes from 10.0.1.2: icmp_seq=7 ttl=124 time=44.0 ms ^C --- 10.0.1.2 ping statistics --- 7 packets transmitted, 7 received, 0% packet loss, time 16ms rtt min/avg/max/mdev = 25.586/30.368/43.999/5.770 ms RDP ãæ¥ç¶åºæ¥ãŸããã æž¡é å®£ä¹ (èšäºäžèЧ) ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš ããŒã¿åæåºç€ã®æ§ç¯ãã¯ã©ãŠã管çéçšããããã¯ãŒã¯ãå®åç¯å²ãGoogle Workspace æŽ»çšæšé²äžãGoogle Cloud èªå®è³æ Œã¯4è³æ Œä¿æ 鱿«ãã©ãã°ã©ãã¡ãŒã§ãèŠ³èæ€ç©ã塿 ¹æ€ç©ã«ããã£ãŠãŸãã
G-gen ã®ææã§ããGoogle CloudïŒæ§ç§° GCPïŒã®ä»®æ³ãµãŒããŒãµãŒãã¹ã§ãã Compute EngineïŒGCEïŒçã«ã¯ã 確çŽå©çšå²åŒ ïŒCommitted use discountsïŒãšããå²åŒã®ä»çµã¿ããããŸããæ¬èšäºã§ã¯ç¢ºçŽå©çšå²åŒã®ä»çµã¿ãåããããã解説ããŸãããŸããAmazon Web ServicesïŒAWSïŒã®é¡äŒŒå¶åºŠã§ãã Reserved Instance ã Savings Plans ãšã®éãã«ã€ããŠãèšåããŸãã 確çŽå©çšå²åŒã®åºæ¬ 確çŽå©çšå²åŒãšã¯ æé éé¡ã®äŸ 2çš®é¡ã®ç¢ºçŽå©çšå²åŒ ãªãœãŒã¹ããŒã¹ã® CUD ä»çµã¿ 賌å
¥ã»é©ç𿹿³ ãã¬ãã·ãã« CUD ä»çµã¿ 賌å
¥ã»é©ç𿹿³ GKE ã Cloud Run ãžã®é©çš ã©ããªãšãã«è³Œå
¥ãã¹ãã 賌å
¥ãã¹ããšã 賌å
¥ãã¹ãã§ã¯ãªããšã ã³ãããã¡ã³ãã®æŽæ°ã»å»¶é· ã³ãããã¡ã³ãã®æŽæ° ã³ãããã¡ã³ãã®å»¶é· ã³ãããã¡ã³ãæéã®ã¢ããã°ã¬ãŒã ãŸãŒã³ãªãœãŒã¹ã®äºçŽïŒreservationïŒ ç¢ºçŽå©çšå²åŒã®å¿çš æšå¥šã®ç¢ºèª ãããžã§ã¯ãéã§ç¢ºçŽå©çšå²åŒãå
±æãã ãªãœãŒã¹ããŒã¹ã® CUD ã®å Žå ãã¬ãã·ãã« CUD ã®å Žå ã³ãããã¡ã³ãã®çµåã»åå² æ³šæç¹ 確çŽã®å€æŽããã£ã³ã»ã«ã¯ã§ããªã 確çŽå©çšå²åŒã®é©çšç¯å² å²ãåœãŠïŒã¯ã©ãŒã¿ïŒã®ç¢ºèª åžžæèµ·åããŠããªãã€ã³ã¹ã¿ã³ã¹ãžã¯é©çšãããªãå Žåããã 確çŽå©çšå²åŒãé©çšã§ããªãã±ãŒã¹ ãªãœãŒã¹ããŒã¹ã® CUD ãã¬ãã·ãã« CUD AWS ãšã®éã 確çŽå©çšå²åŒã®åºæ¬ 確çŽå©çšå²åŒãšã¯ 確çŽå©çšå²åŒ ãšã¯ãäžå®ã®å©çšã Google ã«ã³ãããïŒç¢ºçŽïŒããããšãšåŒãæãã«ãéåžžãããå²åŒãããæéã§ Google Cloud ãªãœãŒã¹ãå©çšã§ããå²åŒãã©ã³ã®ããšã§ããè±èªã§ Committed Use Discounts ãšè¡šèšãããããã CUD ãšç¥ç§°ãããããšããããŸãã ãã€ã³ãããŸãšãããšã以äžã®éãã§ãã 1幎éãŸãã¯3幎é ã®å©çšã確çŽããããšã§ å²åŒ ãåŸããã åæãã¯ãªãã æ¯æãã¯æ¯æ Google Compute Engine ã Cloud SQLãGoogle Kubernetes Engine ã§å©çšã§ãã ãã ãããããã®ç¢ºçŽå©çšå²åŒã®éã§èéã¯ã§ããªãïŒå¥ã
ã§è³Œå
¥ããå¿
èŠãããïŒ åœèšäºã§ã¯ãCompute Engine ã® CUD ã«ã€ããŠè§£èª¬ããŸããCompute Engine ã® CUD ã¯ã2çš®é¡ååšããŸãã 1ã€ç®ã¯ã ãªãœãŒã¹ããŒã¹ã® CUD ã§ããå¥åãšããŠã ãªãœãŒã¹ããŒã¹ã®ã³ãããã¡ã³ã ãšãåŒã°ããŸããäžå®ã® Compute Engine ãªãœãŒã¹ã1幎éãŸãã¯3幎é䜿çšããããšã®ç¢ºçŽãšåŒãæãã«ãæå€§57%ã®å²åŒæéãé©çšãããŸãããªãœãŒã¹ããŒã¹ã® CUDã¯ã ãããžã§ã¯ãåäœ ã§è³Œå
¥ããŸãã åè : ãªãœãŒã¹ããŒã¹ã®ã³ãããã¡ã³ã 2ã€ç®ã¯ã ãã¬ãã·ãã« CUD ã§ããå¥åãšããŠã è²»çšããŒã¹ã®ã³ãããã¡ã³ã ãšãåŒã°ããŸãããã¬ãã·ãã« CUD ã¯ãªãœãŒã¹ããŒã¹ã® CUD ãšã¯ç°ãªããããããéé¡ã䜿ããããã³ãããããããšã§ãæå€§46%ã®å²åŒãåããããšãã§ããŸãããã¬ãã·ãã« CUD ã¯ããã®åã®éããªãŒãžã§ã³ããã·ã³ã·ãªãŒãºã«çžãããªãæè»æ§ããããŸãããã¬ãã·ãã« CUD ã¯ã è«æ±å
ã¢ã«ãŠã³ãåäœ ã§è³Œå
¥ããŸãã åè : è²»çšããŒã¹ã®ã³ãããã¡ã³ã åè : Compute ã®ãã¬ãã·ãã« CUD æé 確çŽå©çšå²åŒã®æéã¯ãå
¬åŒããŒãžã«èšèŒããããŸãã åè : Compute Engine pricing 確çŽå©çšå²åŒã®æéã¯ãªã³ããã³ãæéïŒéåžžæéïŒãããªãšã³ããã£ãã«æéïŒãå£²ãæ®ãã€ã³ã¹ã¿ã³ã¹ãã®å®å£²ãæéïŒãšãšãã«äœµèšãããŠããŸãããŸãå
¬åŒã®æéèšç®ããŒã«ã§ãããGoogle Cloud's pricing calculatorãã§ãç®åºããããšãã§ããŸãã åè : Google Cloud's pricing calculator 確çŽå©çšå²åŒã賌å
¥ãããšã æåäœã§æéã®æ¯æããçºç ããŸããAWS ã® Reserved Instance ã Savings Plans ãšã¯ç°ãªããGoogle Cloud ã®ç¢ºçŽå©çšå²åŒã«ã¯ åæãã¯ãããŸãã ã éé¡ã®äŸ e2-standard-2ïŒvCPU 2 coresã8 GB RAM) ã§ãªãœãŒã¹ããŒã¹ã® CUD ã賌å
¥ããå ŽåãäŸã«åããŸãã ãã®ãã·ã³ã¿ã€ãã®ãªã³ããã³ãïŒéåžžæéïŒã®æé¡ã¯ãæ±äº¬ãªãŒãžã§ã³ã§ã¯ $62.75372 / æã§ãïŒ2024幎9æçŸåšãã¹ãã¬ãŒãžæéã¯èšç®ã«å
¥ããŠããŸããïŒã 1幎ã³ãããã¡ã³ãã®å Žåãããã $33.8876872 ãšãªãã çŽ37%ãªã ã«ãªããŸãã 2çš®é¡ã®ç¢ºçŽå©çšå²åŒ ãªãœãŒã¹ããŒã¹ã® CUD ä»çµã¿ 2çš®é¡ãã確çŽå©çšå²åŒã®ãã¡ã®1ã€ç®ã¯ã ãªãœãŒã¹ããŒã¹ã® CUD ã§ããvCPUãã¡ã¢ãªãGPUããã£ã¹ã¯ãªã©ã«å¯ŸããŠãããã確çŽå©çšå²åŒã賌å
¥ã§ããŸãããªãœãŒã¹ããŒã¹ã® CUDã¯ã ãããžã§ã¯ãåäœ ã§è³Œå
¥ãããã®ãããžã§ã¯ãã®äžã§é©çšãããŸãïŒåŸè¿°ããŸãããå¥ã®ãããžã§ã¯ãã«å
±æããããšãã§ããŸãïŒã åè : ãªãœãŒã¹ããŒã¹ã®ã³ãããã¡ã³ã ãªã賌å
¥ã¯ã ã³ãããã¡ã³ã ïŒcommitmentïŒããã äœæãã ïŒcreateïŒããšè¡šçŸããããšããããŸãã ã³ãããã¡ã³ãã®äœæã¯ã³ã³ãœãŒã«ã CLIã API çµç±ã§å¯èœã§ããã³ã³ãœãŒã«ã®å Žåã¯ãCompute Engine ã³ã³ãœãŒã«ïŒç¢ºçŽå©çšå²åŒããã賌å
¥ããŸãã 以äžã®äŸã§ã¯ Google Cloud ã³ã³ãœãŒã«ã§ã æ±äº¬ãªãŒãžã§ã³ ã« E2ã¿ã€ã ã§ vCPU ã4ã³ã¢ ã RAM ã 8 GB 賌å
¥ãããæéã¯1幎éã®ã³ããããããšãã£ãæå®ã®ä»æ¹ãããŠããŸãã ãªãœãŒã¹ããŒã¹ã® CUD ã®è³Œå
¥ç»é¢ 賌å
¥ã»é©ç𿹿³ ã³ã³ãœãŒã«ã®å Žåã¯ãCompute Engine ã³ã³ãœãŒã«ïŒç¢ºçŽå©çšå²åŒããã賌å
¥ããŸãã 賌å
¥æã«ã¯ã å©çšãããªãœãŒã¹ã®éã»æéã®ç¢ºçŽ ããæå®ããŸãã賌å
¥ãããšããªãŒãžã§ã³å
ã«ååšããŠãã ãã®ã¹ããã¯ãæã€ããããã® VM ã«ãèªåçã«å²åŒãé©çšãããŸãã ãã®ãããåœåã«å²åŒå¯Ÿè±¡ãšããŠæ³å®ããŠãã VM ã®èšå®ã倿ŽããŠãå¥ã®ã€ã³ã¹ã¿ã³ã¹ã¿ã€ãã«å€ãããšããŠããåãã¿ã€ãã®ã€ã³ã¹ã¿ã³ã¹ãä»ã«ååšããŠããã°ãèªåçã«ãã¡ãã«å²åŒãé©çšãããŸãã ãŸãã確çŽå©çšå²åŒã§ã¯ãã«ã¹ã¿ã ãã·ã³ã¿ã€ãããšãäºåå®çŸ©ã®ãã·ã³ã¿ã€ããã¯åºå¥ãããŸããã 賌å
¥æ¹æ³ã®äŸãšããŠãå
¬åŒããã¥ã¡ã³ãã®èšè¿°ãåŒçšããŸãã åè : 確çŽå©çšå²åŒã®ä»çµã¿ äŸãšã㊠8 ã³ã¢ã®ã³ãããã¡ã³ãã賌å
¥ãããã®æã« 24 ã³ã¢ãå®è¡ããå Žåã8 ã³ã¢åã®ã¿ç¢ºçŽå©çšå²åŒãé©çšãããŸãã æ®ãã® 16 ã³ã¢ã¯æšæºæé (確çŽå©çšã§ãªãæé) ã§èª²éãããŸãã 8ã³ã¢ã®ç¢ºçŽã賌å
¥ãå®é䜿ã£ãã®ã¯24ã³ã¢ ãã®ããã«ã賌å
¥ããã³ã¢æ°ãè¶
ããåã«ã€ããŠã¯ã èªåçã«æšæºæéã§è«æ± ãããããã«ãªããŸãã éã«ã賌å
¥ããã³ãããã¡ã³ãã«å¯ŸããŠã¯ã ããšã䜿çšããŠããªããŠãæ¯æè«æ±ããããŸã ã8ã³ã¢ã®ã³ãããã¡ã³ãã賌å
¥ãããšããŠãå®éã«ã¯ Compute Engine ã4ã³ã¢åãã䜿ã£ãŠããªããŠããå¿
ã8ã³ã¢åãè«æ±ãããŸãã ç¡é§ã«ãªããã¿ãŒã³ ãã¬ãã·ãã« CUD ä»çµã¿ 2çš®é¡ç®ã® ãã¬ãã·ãã« CUD ïŒè²»çšããŒã¹ã®ã³ãããã¡ã³ãïŒã¯ã è«æ±å
ã¢ã«ãŠã³ãåäœ ã§è³Œå
¥ããåãè«æ±å
ã¢ã«ãŠã³ããå
±æãããããžã§ã¯ãéã§å
±æãããŸãã åè : è²»çšããŒã¹ã®ã³ãããã¡ã³ã åè : Compute ã®ãã¬ãã·ãã« CUD ã1幎ãŸãã¯3幎ã®é·æå©çšãã³ãããããŠå²åŒã享åããããåæããªãã§æ¯ææ¯æãããšããç¹ã¯ãªãœãŒã¹ããŒã¹ã® CUD ãšåæ§ã§ããããããã¬ãã·ãã« CUD ã®å Žåã¯ã以äžã®ç¹åŸŽããããŸãã vCPU æ°ãã¡ã¢ãªéã§ã¯ãªããè²»çšããŒã¹ïŒãããåãå©çšãããïŒã§ã³ããããã è²»çšãã³ããããããããªãŒãžã§ã³ããããžã§ã¯ãããã·ã³ã·ãªãŒãºã«é¢ä¿ãªãé©çšããã 1幎ã³ãããã¡ã³ãã¯28%å²åŒã3幎ã³ãããã¡ã³ãã¯46%å²åŒããã äŸãã°ãã¬ãã·ãã« CUD ã以äžã®æ¡ä»¶ã§è³Œå
¥ãããšããŸãã ãªã³ããã³ãè²»çš $100 / æéã§ã³ããã 3幎ã³ãããã¡ã³ã 3幎ã³ãããã§ã¯ 46% ã®å²åŒãé©çšãããŸããæ¯æã® vCPU/Memory ã®å©çšæéã®ãã¡ãéåžžæéã§ $100 æ¶è²»ããåãŸã§ãã$54 ã®æ¯æãã§æžã¿ãŸãã ããæå»ã®å©çšã $100 ãè¶
ããªãã£ãå Žåã§ããæäœ $54 ã®æ¯æããçºçããŸããéã« $100 ãè¶
ã㊠$150 䜿ã£ãå Žåã$100 ãŸã§ã CUD ã§ã«ããŒãã $54 ã«ãªããæ®ãã® $50 ã¯å®äŸ¡ã§æ¯æãããšã«ãªããŸãã ãªããæ®ã£ã $50 ã¯ãç¶ç¶å©çšå²åŒãã®å¯Ÿè±¡ã«ã¯ãªããŸããç¶ç¶å©çšå²åŒã¯ãèªåçã«é©çšããã Compute Engine ã®å²åŒã®ä»çµã¿ã§ãã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp 賌å
¥ã»é©ç𿹿³ ãã¬ãã·ãã« CUD ã¯è«æ±å
ã¢ã«ãŠã³ãåäœã§è³Œå
¥ããŸããã³ã³ãœãŒã«ã§ã¯ããæ¯æãïŒç¢ºçŽå©çšå²åŒãã®ç»é¢ãã賌å
¥ããããšãã§ããŸãã åãè«æ±å
ã¢ã«ãŠã³ãå
ã§ããã°ãªãŒãžã§ã³ããããžã§ã¯ãããã·ã³ã·ãªãŒãºã«é¢ä¿ãªãé©çšãããŸãã ãã ãããã¬ãã·ãã« CUD ãé©çšã§ãããã·ã³ã¿ã€ãã¯ä»¥äžã®ã¿ã§ãã General purpose : C3ãC3DãC4ãE2ãN1ãN2ãN2DãN4 Compute-optimized : C2ãC2D Storage-optimized : Z3 ãªãäžèšã®ãªã¹ãã¯2024幎9æçŸåšã®ãã®ã§ããææ°ã®å¯Ÿå¿ãªã¹ãã¯ä»¥äžããåç
§ãã ããã åè : Eligible resources ãã¬ãã·ãã« CUD ãã©ã®ãªãœãŒã¹ã«é©çšããããã¯ãŠãŒã¶ãŒåŽã§éžæã§ãããèªåã§é©çšãããŸããèªåé©çšã®ããžãã¯ã¯ä»¥äžã®éãã§ãã ãŸããªãœãŒã¹ããŒã¹ã® CUDïŒéåžžã® CUDïŒãåãªãœãŒã¹ã«é©çšããã æ®ãã®ãªãœãŒã¹ã«ããã¬ãã·ãã« CUD ãé©çšããã æ®ãã®ãªãœãŒã¹ã«ç¶ç¶å©çšå²åŒãé©çšããã GKE ã Cloud Run ãžã®é©çš ãã¬ãã·ãã« CUD ã¯ã2024幎7æã®ã¢ããããŒãã«ãããGoogle Kubernetes EngineïŒGKEïŒã® Autopilot ã¢ãŒãã Cloud RunïŒCPU always allocated ã® Cloud Run services ãš Cloud Run JobsïŒã«ãé©çšãããããã«ãªããŸããã GKE Standard ã¯ã€ã³ãã©ãšã㊠Compute Engine ã䜿ã£ãŠãããããåŸæ¥ãã Compute Engine ã® CUD ã§å²åŒã®é©çšãå¯èœã§ãããããã®ã¢ããããŒãã«ãã GKE Autopilot ã Compute Engine ã®ãã¬ãã·ãã« CUD ã§ã«ããŒãããããã«ãªããŸããããã«äŒŽããããšããšååšããŠãã GKE Autopilot çšã® CUD ã¯å»æ¢ã«ãªããŸãã 詳现ã¯ä»¥äžã®å
¬åŒããã¥ã¡ã³ãããåç
§ãã ããã åè : Google Kubernetes Engine (GKE) - Committed use discounts åè : Cloud Run - Committed use discounts ã©ããªãšãã«è³Œå
¥ãã¹ãã 賌å
¥ãã¹ããšã 確çŽå©çšå²åŒã¯ãæäœéå¿
èŠãªãªãœãŒã¹éããé·æã«æž¡ã£ãŠããçšåºŠäºæž¬ã§ããã·ã¹ãã ãã«ãããŠè³Œå
¥ãã¹ãã§ãã äŸãã°ã åºæ¬çã«24æé皌å ã§ããã å©çšè
æ°ãæŠã決ãŸã£ãŠ ããŠã皌åéå§ãã 3ã¶æçšåºŠçµé ããŠã¯ãŒã¯ããŒããå®å®åãã瀟å
ã·ã¹ãã ããªã©ãæãåãããããã§ãããã 賌å
¥ãã¹ãã§ã¯ãªããšã éã«ã以äžã®ãããªã±ãŒã¹ã§ã¯è³Œå
¥ ãã¹ãã§ã¯ãããŸãã ã ç«ã¡äžããã°ããã®ããžãã¹ã§ããå
è¡ããäžæãªå Žå 皌åããã°ããã®ã·ã¹ãã ã§ããæ¬çªå©çšã®è² è·ã®æ§åãèŠããå Žå å¹³æ¥æŒéãã皌åãããªãéçºçš VM ãªã©ç¹å®æéã ãèµ·åãã VM ã®å Žå 確çŽå©çšå²åŒã¯1幎ãŸãã¯3幎ã®å©çšã確çŽããå¿
èŠãããã éäžã§è§£çŽã倿Žã¯ã§ããŸãã ã äŸ 1. ã¯ãããžãã¹ã確çŽããæéããçãã¹ãã³ã§æ€éã«ãªã£ãããçž®å°ã«ãªãå¯èœæ§ãããã±ãŒã¹ã§ãã賌å
¥ãã確çŽå©çšå²åŒãç¡é§ã«ãªã£ãŠããŸããããããŸããã äŸ 2. ã¯ãæ€éã¯èããããªããŸã§ããæ°èš/ç§»è¡ããã«ãããªãŒããŒããã°ããã§æ¬çªå©çšããŠéããªãã±ãŒã¹ã§ããããããããæã£ãŠãããããå°ããã€ã³ã¹ã¿ã³ã¹ã¿ã€ãã§ååãããããŸãããæ¬çªçšŒåéå§ãã 3 ã 6 ã¶æçšåºŠã¯æ§åèŠã®æéãèšããã®ãå®ç³ã§ãã äŸ 3. ã¯ãããŸãã«åæ¢ã»èµ·åããã»ããå®ããªããã¿ãŒã³ã§ãã確çŽå©çšå²åŒã賌å
¥ããå Žåã®è²»çšãšãããŸãã«åæ¢ããå Žåã®è²»çšãæ¯ã¹ãŠãã©ã¡ããå®ããªãããæ£ããèŠå®ããŸããããå
¬åŒã®æéèšç®ããŒã«ãæéããŒãžãèŠãããšã§ãèªåã§èšç®ã§ããŸãã åè : Compute Engine pricing åè : Google Cloud's pricing calculator ãŸãäžè¬çã«ã¯ã3幎éã®ç¢ºçŽã®è³Œå
¥ã«ã¯æ
éã«ãªãã¹ãã§ãã3幎ãçµã€ãšãããå®äŸ¡ã§é«æ§èœãªãã·ã³ã¿ã€ããçºè¡šãããå¯èœæ§ããããŸãããã¯ãŒã¯ããŒãïŒå©çšã®ããªã¥ãŒã ãæ§è³ªïŒãå€åããå¯èœæ§ãé«ããªãããã§ãã ã³ãããã¡ã³ãã®æŽæ°ã»å»¶é· ã³ãããã¡ã³ãã®æŽæ° ã³ãããã¡ã³ãã¯1幎ãŸãã¯3幎ã§äœæããŸãããæéãåãããšå²åŒãçµäºãããã®æ¥ãã㯠éåžžæéã§ã®è«æ± ãšãªããŸãã åŒãç¶ã CUD ãå©çšãããå Žåããã¬ãã·ãã« CUD ã®å Žåã¯ãæåã§å賌å
¥ããå¿
èŠããããŸãããªãœãŒã¹ããŒã¹ã® CUD ã¯ãå床æåã§è³Œå
¥ããããšãã§ããŸããã ã³ãããã¡ã³ãã®èªåæŽæ° æ©èœãå©çšããããšãã§ããŸãã åè : ã³ãããã¡ã³ããèªåçã«æŽæ°ãã ã³ãããã¡ã³ãã®èªåæŽæ°ãèšå®ãããšãæŽæ°åŸã®ã³ãããã¡ã³ãã®æéã¯ãå
ã®ã³ãããã¡ã³ããšåãã«ãªããŸãã èªåæŽæ°ããªã³ã«ãããšãèªåæŽæ°ããã£ã³ã»ã«ããªãéããã³ãããã¡ã³ãã®çµäºæ¥ã«èªåçã«æŽæ°ãããŸãããªããã£ã³ã»ã«ã¯ãæŽæ°æ¥ã®ååŸ12æïŒå€ªå¹³æŽæšæºæé = PSTïŒãŸã§ã«è¡ãå¿
èŠããããŸãã ã³ãããã¡ã³ãã®å»¶é· ãªãœãŒã¹ããŒã¹ã® CUD ã§ã¯ã ã³ãããã¡ã³ãã®å»¶é· æ©èœã«ããã1幎ãŸãã¯3幎ãè¶
ããŠããã¿ã£ãšãããšæéãå»¶é·ããããšãã§ããŸãã 1幎ã³ãããã¡ã³ãã¯ã1幎ã3å¹Žæªæºã®ã«ã¹ã¿ã æéãæå®ã§ããŸãã 3幎ã³ãããã¡ã³ãã¯ã3幎ã6å¹Žæªæºã®ã«ã¹ã¿ã æéãæå®ã§ããŸãã æéãå»¶é·ããŠããå²åŒçã¯å€æŽãããŸããã1幎ã³ãããã¡ã³ããå©çšäžã®å Žåã§ãããä»ããé«ãå²åŒçãåãããå Žåã¯ã1幎â3幎ãžãã³ãããã¡ã³ãæéã®ã¢ããã°ã¬ãŒãããæ€èšããŠãã ããã åè : 確çŽå©çšæéãå»¶é·ãã ã³ãããã¡ã³ãæéã®ã¢ããã°ã¬ãŒã 1幎ã³ãããã¡ã³ããå©çšäžã®å Žåã ã³ãããã¡ã³ãæéã®ã¢ããã°ã¬ãŒã ãè¡ã£ãŠ3幎ã³ãããã¡ã³ãã«å€æŽããããšã§ãããé«ãå²åŒæéãé©çšãããŸãã ã¢ããã°ã¬ãŒããããšãé©çšæéã2幎éå»¶é·ãããŸãã åè : ã³ãããã¡ã³ãæéãã¢ããã°ã¬ãŒããã ãŸãŒã³ãªãœãŒã¹ã®äºçŽïŒreservationïŒ ç¢ºçŽå©çšå²åŒã賌å
¥ãããšããŠããããã¯ãã£ãã·ãã£ãå¿
ã確ä¿ãããããšã æå³ããŸãã ããŸãã§ã¯ãããŸãããGoogle åŽã®ã³ã³ãã¥ãŒããªãœãŒã¹ãç©ççã«è¶³ããªãå Žåãå¿
èŠãªãšãã« VM ãèµ·åããããã¹ãã¬ãŒãžã远å ãããã§ããªãããšããããŸãããã®ãããªç¶æ
ã ãã£ãã·ãã£äžè¶³ ãšèšããŸãã 確çŽå©çšå²åŒãšã¯å¥ã®æŠå¿µãšããŠã ãŸãŒã³ãªãœãŒã¹ã®äºçŽ ïŒreservation of zonal resourcesïŒãè¡ãããšã§ãäºããã£ãã·ãã£ãäºçŽããããšãã§ããŸããäºçŽæã¯ããŸãŒã³ããã·ã³ã¿ã€ããªã©ãæå®ããŸãã ãªãœãŒã¹ã®äºçŽãè¡ããšããã®åã®ãªãœãŒã¹ãå©çšã§ããããšã確å®ããŸãããäºçŽããã ãã§ å®éã«ã¯äœ¿ã£ãŠããªããŠããæéãçºçããŸã ããªãœãŒã¹ã®äºçŽã¯ã確çŽå©çšå²åŒãšçµã¿åãããããšã§ããã£ãã·ãã£ã確ä¿ãã€ã€å²åŒæéã®é©çšãåŸãããŸãã ç¹å®ã® VM ã«é¢ããŠèšãã°ãVM ãåžžæèµ·åãããŸãŸã«ããŠããã°ååçã«ãªãœãŒã¹ã®äºçŽã¯å¿
èŠãããŸããããäœãã®æ©äŒã« VM ãäžæçã«åæ¢ãããšãã«ãåã³èµ·åããéã«ãã£ãã·ãã£äžè¶³ã®ç¶æ
ã§ãããèµ·åã§ããªããšããå¯èœæ§ã¯ãŒãã§ã¯ãããŸããã åžžæèµ·åã¯ç¢ºçŽå©çšå²åŒã®å²åŒãæå€§é掻ãããäœ¿ãæ¹ã§ãããããå¿
ãããäºçŽã¯å¿
èŠãããŸãããããããªãããGPU ãããŒã«ã« SSD ã®å Žåã確çŽå©çšå²åŒã®è³Œå
¥æã« ãªãœãŒã¹äºçŽãå¿
é ãšãã仿§ã«ãªã£ãŠããŸããGPU ãšããŒã«ã« SSD ã®ç¢ºçŽå©çšå²åŒã®è³Œå
¥ã®éã¯ãåæã«ãªãœãŒã¹äºçŽãäœæããå¿
èŠããããŸãã åè : Compute Engine ãŸãŒã³ãªãœãŒã¹ã®äºçŽ ãŸãã å°æ¥ã®äºçŽãªã¯ãšã¹ã ïŒfuture reservation requestsïŒã«ãã£ãŠãæé·ã§1幎å
ãŸã§ã®äºçŽãäºããªã¯ãšã¹ãã§ããŸãããªã¯ãšã¹ãã Google Cloud ã«ãã£ãŠå¯©æ»ãããæ¿èªããããšãå°æ¥ã®ç¹å®æ¥ä»ä»¥éã«ãæå®ãã容éã確ä¿ãããŸãã倿°ã® VM ãç§»è¡ããéããæ°èŠã·ã¹ãã ã®éçºã¹ã±ãžã¥ãŒã«ã«åããéãªã©ã«å©çšã§ããŸãã åè : å°æ¥ã®äºçŽãªã¯ãšã¹ãã«ã€ã㊠確çŽå©çšå²åŒã®å¿çš æšå¥šã®ç¢ºèª Google Cloud ã³ã³ãœãŒã«ã®ããæ¯æã > è²»çšã®æé©å > CUD åæããªã©ãããã©ããããã®ç¢ºçŽå©çšå²åŒã賌å
¥ããã¹ããããªã©ã® æšå¥šäºé
ãèŠãããšãã§ããŸãã ãã㯠Google Cloud ã®ãµãŒãã¹ã§ãã Recommender API ã«ãããæ©æ¢°åŠç¿çãçšããŠçæãããæšå¥šäºé
ã§ããåèã«ããããã§ã賌å
¥ã®å€æã«æŽ»çšããŸãããã åè : 確çŽå©çšå²åŒã®æšå¥šäºé
ãé©çšãã ãããžã§ã¯ãéã§ç¢ºçŽå©çšå²åŒãå
±æãã ãªãœãŒã¹ããŒã¹ã® CUD ã®å Žå ãªãœãŒã¹ããŒã¹ã® CUD ã¯ãããžã§ã¯ãåäœã®è³Œå
¥ã§ãããã®ã®ãæç€ºçã«æå®ããããšã§åã è«æ±å
ã¢ã«ãŠã³ã ãå
±æããè€æ°ã®ãããžã§ã¯ãéã§ã賌å
¥ãã確çŽå©çšå²åŒãå
±æã§ããŸãã åè : ãããžã§ã¯ãéã§ç¢ºçŽå©çšå²åŒãå
±æãã è«æ±å
ã¢ã«ãŠã³ãã«ã€ããŠã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp ããã«ãããäŸãã°å€§èŠæš¡ã« Google Cloud ãå©çšããŠããäŒç€Ÿçã§ã¯ãçµç¹ãšããŠç¢ºçŽå©çšå²åŒã賌å
¥ããŠãããå©çšè
ã®æèããªããšããã§å²åŒãé©çšãè²»çšã®å
šäœæé©ãå³ãããšãã§ããŸãããã¬ãã·ãã« CUD ã§ãåæ§ã®ããšãç°¡åã«å®çŸã§ããŸãããå²åŒçã¯ãªãœãŒã¹ããŒã¹ã®ã»ãã倧ãããªããŸãã ãŸã ã¢ããªãã¥ãŒã·ã§ã³ ãšããä»çµã¿ã§ã確çŽå©çšå²åŒãã©ã®ãããžã§ã¯ãã«å²ãåœãŠãããããå¶åŸ¡ããããšãã§ããŸãã ããã©ã«ãã§ã¯ æ¯äŸã¢ããªãã¥ãŒã·ã§ã³ ã¢ãŒããšãªã£ãŠãããåãããžã§ã¯ãã§æ¶è²»ããã察象ãªãœãŒã¹ã®åèšäœ¿çšéã«å¿ããå²åã§ã確çŽå©çšå²åŒããããžã§ã¯ãã«é
åãããŸãã äžæ¹ã® åªå
ã¢ããªãã¥ãŒã·ã§ã³ ã§ã¯ãæç€ºçã«å²åœã®åªå
é äœãæå®ã§ããŸãã åè : 確çŽå©çšå²åŒã®æéãšã¯ã¬ãžããã®ã¢ããªãã¥ãŒã·ã§ã³ ãã¬ãã·ãã« CUD ã®å Žå ãã¬ãã·ãã« CUD ã«ãããŠã¯åãè«æ±å
ã¢ã«ãŠã³ãå
ã§ã³ãããã¡ã³ããå
±æã»åé
ãããŸãã ãã®ããããããžã§ã¯ãéã§å
±æãããããšã¯ããããèããå¿
èŠããããŸããã ã³ãããã¡ã³ãã®çµåã»åå² ãªãœãŒã¹ããŒã¹ã® CUD ã¯è³Œå
¥åŸã« çµåã»åå² ãå¯èœã§ãã ã³ãããã¡ã³ããçµåããã¡ãªããã¯ãè€æ°ã®ã³ãããã¡ã³ããçµåããããšã§æéåãã«ãªãæéã調æŽããããšãã§ããç¹ã§ããçµåãããã³ãããã¡ã³ã矀ã®ãã¡æãé
ãæå¹æéããçµååŸã®æå¹æéã«ãªããŸãã ãã ãçµåããã³ãããã¡ã³ãå士ã¯ãåããããžã§ã¯ãã»ãªãŒãžã§ã³ã»æéïŒ1 or 3 yearsïŒã»ãã·ã³ã¿ã€ãçã¯åçã§ããå¿
èŠããããŸãã ã³ãããã¡ã³ããåå²ããã¡ãªãããåæ§ã«ãçµäºæéã管çãããããªãç¹ã§ãã倧ããªã³ãããã¡ã³ããåå²ããäžéšã¯æéãæ¥ããçµäºããæ®ãã¯èªåæŽæ°ãããããšãã£ãããšãã§ããŸãã åè : ã³ãããã¡ã³ããçµ±åããŠåå²ãã æ³šæç¹ 確çŽã®å€æŽããã£ã³ã»ã«ã¯ã§ããªã 確çŽå©çšå²åŒã¯äžåºŠè³Œå
¥ãããšã倿Žããã£ã³ã»ã«ã¯ã§ããŸããã賌å
¥æã«ã¯ã賌å
¥ééãããäžå¿
èŠãªåãŸã§è³Œå
¥ããŠããŸãããªã©ã«ååæ³šæããå¿
èŠããããŸãã åŸããè¶³ããªããªã£ãåã«ã€ããŠã¯è¿œå 賌å
¥ãå¯èœã§ãããæžãããããã£ã³ã»ã«ããããšã¯ã§ããªãç¹ã«ãååæ³šæã§ãã ãªãã2023幎2æã®ã¢ããããŒãã§1幎ã³ãããã3幎ã³ãããã« [ã¢ããã°ã¬ãŒãã§ãã ããã«ãªããŸãããã³ãããæéã䌞ã°ãããšã§ããæ·±ãå²åŒãåŸãããšãã§ããŸãã åè : ã³ãããã¡ã³ãæéãã¢ããã°ã¬ãŒããã 確çŽå©çšå²åŒã®é©çšç¯å² ãªãœãŒã¹ããŒã¹ã®ç¢ºçŽå©çšå²åŒã¯ãªãŒãžã§ã³åäœã§ã®è³Œå
¥ãšãªããŸãããã®ãããªãŒãžã§ã³ããŸããã§ãªãœãŒã¹ãå©çšããŠããå²åŒãé©çšãããªãç¹ã«æ³šæãå¿
èŠã§ãã äžæ¹ã®ãã¬ãã·ãã« CUD ã¯ãããžã§ã¯ãããªãŒãžã§ã³ããã·ã³ã·ãªãŒãºããŸããã§é©çšãããŸãã å²ãåœãŠïŒã¯ã©ãŒã¿ïŒã®ç¢ºèª Google Cloud ã«ã¯ å²ãåœãŠïŒã¯ã©ãŒã¿ïŒ ãšããæŠå¿µããããŸãã åè : Compute Engine ã®å²ãåœãŠãšäžéã®æŠèŠ ãããžã§ã¯ãããšããªãŒãžã§ã³ããšã«ã䜿çšå¯èœãªãªãœãŒã¹ã®æå€§å€ã決ãŸã£ãŠããã誀ã£ãŠå€§éæ¶è²»ããŠããŸãããšãé²ãã§ããŸãã 確çŽå©çšå²åŒã§ããªãŒãžã§ã³ããšã«è³Œå
¥å¯èœãªç¢ºçŽå©çšå²åŒã®å²ãåœãŠ (ã¯ã©ãŒã¿) ãæ±ºãŸã£ãŠããŸããã³ã³ãœãŒã«ã®ãå²ãåœãŠãç»é¢çãããäžéç·©åãããããšãå¯èœã§ãã åžžæèµ·åããŠããªãã€ã³ã¹ã¿ã³ã¹ãžã¯é©çšãããªãå Žåããã VM ãæã®äžã§é·æé忢ããŠãããããããã¯1æ¥ã®äžã§é »ç¹ã«èµ·åã»åæ¢ããŠãããããªå Žåããã®ã€ã³ã¹ã¿ã³ã¹ã«ã¯ç¢ºçŽå©çšå²åŒãé©çšãããªãå ŽåããããŸãã確çŽå©çšå²åŒã¯åžžæèµ·åããŠãã VM ã察象ãšããŠæ³å®ããŠããŸããå
¬åŒããã¥ã¡ã³ãã§ã¯ä»¥äžã®ããã«è¡šçŸãããŠããŸãã ã³ãããã¡ã³ãã¯ããŒã¹ã ã·ããªãªçšã«ã¹ã¿ãã¯ããããšã¯ã§ããŸãããããšãã°ãããæã« 10 ã³ã¢åã賌å
¥ããåŸããã®æã®ååã®æéã§ 20 ã³ã¢ã皌åãããå Žåã䜿çšéãååã«ãªã£ããšããçç±ã ãã§ã¯ã20 ã³ã¢å
šäœã«å¯Ÿããã³ãããã¡ã³ãã¯é©çšãããŸããã åè : ã³ãããã¡ã³ãã®å¹ççãªäœ¿çš 確çŽå©çšå²åŒãé©çšã§ããªãã±ãŒã¹ ãªãœãŒã¹ããŒã¹ã® CUD ã€ã³ã¹ã¿ã³ã¹ã¿ã€ãã®å¶éãšããŠã¯ãf1-micro ããã³ g1-small ãã·ã³ã¿ã€ã (N1 å
±æã³ã¢ãã·ã³) ã¯ãªãœãŒã¹ããŒã¹ã®ç¢ºçŽå©çšå²åŒã®å¯Ÿè±¡ã«ãªããŸããã ãŸããSpot VM ãããªãšã³ããã£ãã«ã€ã³ã¹ã¿ã³ã¹ãVM ã«ã¢ã¿ããããæ¡åŒµã¡ã¢ãªã«ãé©çšãããŸããã ããã«ã確çŽå©çšå²åŒã¯ããã¯ãšã³ãã§ Compute Engine ã䜿ã Google Kubernetes EngineãDataprocãCloud Composer 1 ã® VM ã«ã¯é©çšãããŸãããäžæ¹ã§ App EngineãDataflowãCloud Composer 2 ã«ã¯é©çšãããŸããã åè : å¶éäºé
ãã¬ãã·ãã« CUD 察象ãšãªããã·ã³ã¿ã€ãã¯ä»¥äžã®ã¿ã§ããããã以å€ã«ã¯é©çšãããŸããã General purpose : C3ãC3DãC4ãE2ãN1ãN2ãN2DãN4 Compute-optimized : C2ãC2D Storage-optimized : Z3 ãªãäžèšã®ãªã¹ãã¯2024幎9æçŸåšã®ãã®ã§ããææ°ã®å¯Ÿå¿ãªã¹ãã¯ä»¥äžããåç
§ãã ããã åè : Eligible resources AWS ãšã®éã Amazon Web ServicesïŒAWSïŒã«ã Reserved Instance ã Savings Plans ãšãã£ããé¡äŒŒã®å²åŒãã©ã³ãååšããŠããŸãã ãããããä»®æ³ãµãŒãçã³ã³ãã¥ãŒãã£ã³ã°ãªãœãŒã¹ã®å©çšã 1 幎ãŸã㯠3 幎ã§ã³ãããããå
šé¡åæã / äžéšåæã / åæããªãã ã®ããããããéžæããŠå²åŒæéã®é©çšãåŸããããã®ã§ãã Reserved Instance ãš Savings Plans ã®éãã¯ããµãŒããŒã¯ãŒã¯ã¹ç€Ÿã®ä»¥äžã®ããã°ã§éåžžã«åããããã解説ãããŠããŸãã blog.serverworks.co.jp AWS ã® Reserved Instance / Savings Plans ã¯ã Google Cloud ã®ç¢ºçŽå©çšå²åŒãšãã䌌ãå¶åºŠã§ããã以äžã®ãããªéãããããŸãã åæããªãã·ã§ã³ (å
šé¡åæã / äžéšåæã / åæããªã) ãããããš ïŒSavings PlansïŒã€ã³ã¹ã¿ã³ã¹ãã¡ããªãŒïŒGoogle Cloud ã§ãããã·ã³ã·ãªãŒãºïŒããŸããã§æè»ã«é©çšããã ïŒReserved InstanceïŒè³Œå
¥ãã Reserved Instance ã Marketplace ã§å£²åŽã§ãã ãã®ä»ã«ã Reserved Instance ã§ã¯ã¢ãã€ã©ããªãã£ãŸãŒã³æå®ã®è³Œå
¥ãªãã·ã§ã³ãããããªã©çްããéãã¯å€æ°ãããŸãã æã倧ããªéãã¯ãAWS ã«ã¯ åæããªãã·ã§ã³ãååšããåæãé¡ã倧ããã»ã©å²åŒé¡ã倧ãããªã ãšããç¹ã§ãã Google Cloud ã®ç¢ºçŽå©çšå²åŒã§ã¯åæããªãã·ã§ã³ããªããæé¡ã§ã®æ¯æããšãªãã®ã§ããã®ç¹ã倧ããªéãã ãšèšããŸãã ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãX (æ§ Twitter) ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it