ããã«ã¡ã¯ã@norryã§ããèªåã¯ä¹å·ã¯çæ¬ãããã«ãªã¢ãŒãã§æ±äº¬æ¬ç€Ÿã®æ ªåŒäŒç€ŸG-genã«ãžã§ã€ã³ããŠããŸãã G-genã¯Google Cloudã®å°æ¥ãã³ããŒã§ããäºãããèªãã®å®ååäžã®çºGoogle Cloudã®èªå®è³æ ŒååŸã«åãçµãã§ããŸãã Googleã®èªå®è³æ Œã¯ KRYTERION ã§åéšå¯èœãªã®ã§ãããåœå
ã§ã¯ããŸã察å¿ããŠãã詊éšäŒå Žããªãä»åã¯çŠå²¡ã®è©ŠéšäŒå Žã§åéšããŸããã ãã®éã«åéšäŒå ŽåšèŸºã§å°ãè¿·ã£ãã®ã§ä¹å·ã§å¯äžã®äŒå Žã§ãã®ã§åéšããã人ã®åèã«ãªãã°å¹žãã§ããã¡ãªã¿ã«èªå®
ãããªã³ã©ã€ã³ã§ã®åéšãå¯èœãªã®ã§ããæ°å転æãå
ŒããŠä»åã¯äŒå Žã§åéšããŠããŸãã Google Cloudèªå®è³æ Œãšã¯ 詊éšäŒå Žãžã®ã¢ã¯ã»ã¹ Google Cloudèªå®è³æ Œãšã¯ Google Cloudã®èªå®è³æ Œãšã¯ Google Cloud ã®è·åããŒã¹ã®èªå®è³æ Œã¯ãGoogle Cloud ãã¯ãããžãŒã䜿çšããç¹å®ã®è·åã®éè¡èœåãè©äŸ¡ãããã®ã§ãã峿£ã«éçºãããæ¥çæšæºã®ææ³ã䜿çšããŠãåè·åã®ç¥èãã¹ãã«ãèœåã®è©äŸ¡ãè¡ãããŸããGoogle Cloud èªå®è³æ Œã¯ãå人ã®ãã£ãªã¢éçºã®ä¿é²ãšãé«ãã¹ãã«ãšå®è·µåãåããããŒã ã®æ§ç¯ã«åœ¹ç«ã¡ãŸãã ãšãããŸãã èªåã¯ä»å㯠Professional Cloud Architect 詊éšãåéšããŸãããAWSã§èšããšããã® Solutions Architect - Professionalã«ãããã§ãããããGoogle Cloudã®ãµãŒãã¹å
šè¬çãªå
容ãåãããŸãã Google Cloud èªå®è³æ Œã«ã€ããŠã¯ã以äžã®åœç€Ÿèšäºããåç
§ãã ããã blog.g-gen.co.jp 詊éšäŒå Žãžã®ã¢ã¯ã»ã¹ é»è»ã§è¡ãå Žåã¯å°äžéèµ€åé§
ã§äžè»ããŠãã ãããåŸæ©ïŒåã»ã©ã«ãªããŸãã 詊éšäŒå Žãžã¯15ååãžã®å
¥å Žã«ãªããŸãã®ã§äœè£ãæã£ãŠè©ŠéšäŒå Žã®è¿ããžè¡ããŸãããã 幞ãã«ãäŒå Žã®è¿ãã«ã¯ã«ãã§ãå«è¶åºã倿°ãããŸãã®ã§è©Šéšå匷ã®ä»äžãã«æã£ãŠããã§ãã æéã«ãªããŸãããäŒå Žãžåããã®ã§ãããã¡ãã®å»ºç©ãå°ãè€éã§å°å³ã§æžããŸããšãã®å Žæã«ãªããŸãã èªåã¯ééã£ãŠãã®åšèŸºãã°ã«ã°ã«ããŠããŸããŸããã äžã®åçã®ã©ãŒã¡ã³å±ããããå·Šæ ãããå
¥ãå£ã§ãã å
¥ãå£å
¥ã£ãŠãå·ŠåŽãã®ãšã¬ããŒã¿ãŒã§12FãŸã§äžãã£ãŠãã ããããããééã£ãŠå³åŽã«ä¹ããš12Fã§ããã£ãšé åãããäºã«ãªããŸãã ãšã¬ããŒã¿ãŒãããã峿ã«äŒå Žå
¥å£ããããŸãã å
¥ã£ãŠåä»ãæžãŸã詊éšã§ããåºé¡æ°50åã®å¶éæé120åã§ããã60åã»ã©ã§çµäºãäœãšãåæ ŒããŸãããã¯ã©ãŠãç³»è³æ Œå
šè¬ãããªã®ã§ãããåæ Œããäžåæ Œãã®è¡šç€ºãåããã«ãããŠããããããŸãã ããŠè©Šéšãçµãã£ãããè€çŸã«èŠçå±±ãã«ãŒã倧çŠãé£ã¹ãŸãããã â»ãåºã«æ®åœ±èš±å¯ãããã ããŠããŸã 倧çŠãé£ã¹ãåŸã¯è
¹ããªããšã瀌åãã«çŠå²¡çž£è·åœç¥ç€Ÿãž 以äžçŠå²¡åéšæ¥èšã§ãããçãããè¯ã詊éšã©ã€ããïŒ æž¡é å®£ä¹ (èšäºäžèЧ) ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš ããŒã¿åæåºç€ã®æ§ç¯ãã¯ã©ãŠã管çéçšããããã¯ãŒã¯ãå®åç¯å²ãGoogle Workspace æŽ»çšæšé²äžãGoogle Cloud èªå®è³æ Œã¯4è³æ Œä¿æ 鱿«ãã©ãã°ã©ãã¡ãŒã§ãèŠ³èæ€ç©ã塿 ¹æ€ç©ã«ããã£ãŠãŸãã
G-genã®ææã§ããGoogle CloudïŒæ§ç§° GCPïŒã®ãã«ãããŒãžãã®ããŒã¿ãŠã§ã¢ããŠã¹ã§ãã BigQuery ã«ã¯ãããã©ãŒãã³ã¹åäžãã³ã¹ãåæžã«åœããã ããŒãã£ã·ã§ã³ ãš ã¯ã©ã¹ã¿ãªã³ã° ãšããéèŠãªæŠå¿µããããŸããããããã®ä»çµã¿ã䜿ãåãã解説ããŠãããŸãã ããã©ãŒãã³ã¹ã®ããã®ããŒãã«èšèš ããŒãã£ã·ã§ã³ ããŒãã£ã·ã§ã³ãšã¯ äœ¿çšæ¹æ³ ããŒãã£ã·ã§ã³ãã£ã«ã¿èŠä»¶ ã¡ãªãã ããŒãã£ã·ã§ã³ã®åå²åºæº æéã®å åãèŸŒã¿æé æŽæ°ç¯å²ã®å ããŒãã£ã·ã§ã³ã®ç®¡ç ããŒãã£ã·ã§ã³ã®äžéãšæ³šæç¹ ã¯ã©ã¹ã¿ãªã³ã° ã¯ã©ã¹ã¿ãªã³ã°ãšã¯ äœ¿çšæ¹æ³ ã¯ã©ã¹ã¿åã«æå®ããå èªååã¯ã©ã¹ã¿ãªã³ã° ããŒãã£ã·ã§ã³ vs ã¯ã©ã¹ã¿ãªã³ã° ããŒãã£ã·ã§ã³ãšã¯ã©ã¹ã¿ãªã³ã°ã®éã ããŒãã£ã·ã§ã³ãšã¯ã©ã¹ã¿ãªã³ã°ã®äœ¿ãåããšäœµçš ããŒãã£ã·ã§ã³ã»ã¯ã©ã¹ã¿ãŒã®ã¬ã³ã¡ã³ããŒã·ã§ã³ åèæ
å ± ããã©ãŒãã³ã¹ã®ããã®ããŒãã«èšèš BigQuery ã«ãããŠãæé©ãªããã©ãŒãã³ã¹ãåºãããã®ããŒãã«èšèšãšããŠãæãéèŠãªã®ã ããŒãã£ã·ã§ãã³ã° ãš ã¯ã©ã¹ã¿ãªã³ã° ã§ãã äžè¬ç㪠RDBMSïŒãªã¬ãŒã·ã§ãã«ããŒã¿ããŒã¹ãããžã¡ã³ãã·ã¹ãã ïŒã§ã¯ãããŒãã«ã«å¯ŸããŠã€ã³ããã¯ã¹ãäœæããããšã§ãæ€çŽ¢ããã©ãŒãã³ã¹ãåäžãããŸããBigQuery ã«ã¯æ€çŽ¢ã€ã³ããã¯ã¹ïŒsearch indexïŒæ©èœããããã®ã®ãããã¯äž»ã«ç¹å®ã®æååãç¹å®ã®ãã£ãŒã«ãããé«éã«æ€çŽ¢ããããã«äœ¿çšããæ©èœã§ãããåºæ¬çã«ã¯åæãå¯èŠåã®ããã©ãŒãã³ã¹åäžã«å¯äžãããã®ã§ã¯ãããŸããã blog.g-gen.co.jp æ€çŽ¢ã€ã³ããã¯ã¹ã¯ãã·ã¹ãã ãã°ã®æ€çŽ¢ãã»ãã¥ãªãã£ç£æ»ãªã©ã®æååæ€çŽ¢ã®ããã©ãŒãã³ã¹ãåäžãããããã«äœ¿ããŸããäžæ¹ã§ãåœèšäºã§ç޹ä»ããããŒãã£ã·ã§ãã³ã°ãã¯ã©ã¹ã¿ãªã³ã°ã¯ãã¹ãã£ã³å¹çãé床ãã³ã¹ãããã©ãŒãã³ã¹ãåäžãããããã«æçšã§ãããã®ããå€ãã®æ©äŒã§ãããŒãã£ã·ã§ãã³ã°ãã¯ã©ã¹ã¿ãªã³ã°ã¯ãBigQuery ã®ããŒãã«èšèšã«ãããåºæ¬çãªèãã§ãããšãããŸãã ããŒãã£ã·ã§ã³ ããŒãã£ã·ã§ã³ãšã¯ ããŒãã£ã·ã§ã³ ãšã¯ã BigQuery ã®äžã€ã®ããŒãã«ããç¹å®ã®åã®å€ãåºæºã«ããŠå
éšçã«è€æ°ã®éšäœã«åå²ããæ©èœã§ããããã«ããã¯ãšãªæã«ã¹ãã£ã³ããç¯å²ãçããããã©ãŒãã³ã¹åäžãšã¹ãã£ã³æéã®ç¯çŽãã§ããŸãã åè : ããŒãã£ã·ã§ã³åå²ããŒãã«ã®æŠèŠ åå²åºæºãšããŠäœ¿ãåãããŒãã«äœææã«æå®ããããšã§ãããŒãã£ã·ã§ã³åå²ãããããŒãã«ãäœæããããšãã§ããŸãã1ã€ã®ããŒãã«ã«ã¯ãããŒãã£ã·ã§ã³åã¯1ã€ããæå®ã§ããŸããã ããŒãã£ã·ã§ã³ã§åå²ãããããŒãã« äœ¿çšæ¹æ³ ããŒãã«äœææ¹æ³ã¯ä»¥äžã®ããã¥ã¡ã³ãã®éãã§ãã åè : ããŒãã£ã·ã§ã³åå²ããŒãã«ã®äœæ äŸãšããŠã以äžã®ãã㪠DDL ã§ãããŒãã£ã·ã§ã³åå²ãããããŒãã«ãäœæããããšãã§ããŸãã CREATE TABLE mydataset.purchase_tran ( purchase_dt DATE , prod_id STRING, prod_name STRING, store_id INT64, store_name STRING ) PARTITION BY purchase_dt ãã®ããã«äœæãããããŒãã«ã§ä»¥äžã®ããã«ã¯ãšãªãå®è¡ãããšã BigQuery ã¯åœè©²ã®å€ãå«ãã ããŒãã£ã·ã§ã³ã ããã¹ãã£ã³ããŸãã SELECT * FROM mydataset.purchase_tran WHERE purchase_dt = " 2025-04-01 " ããŒãã£ã·ã§ã³ãã£ã«ã¿èŠä»¶ ããŒãã£ã·ã§ã³åå²ããŒãã«ã®äœææã«ã ããŒãã£ã·ã§ã³ãã£ã«ã¿èŠä»¶ ïŒPartition filter requirementsïŒãæå¹åããããšã§ãWHERE å¥ã§ããŒãã£ã·ã§ã³åãæå®ãããŠããªãã¯ãšãªãããšã©ãŒãšããŠæåŠããããšãã§ããŸãã ãããèšå®ããããšã§ãããŒãã«ã®å©çšè
ã¯ãããŒãã£ã·ã§ã³ã«ããã¹ãã£ã³ç¯å²ãæå®ããã¯ãšãªããæããããªããªããŸãã®ã§ãããŒãã«ã«å¯Ÿããäžçšæãªãã«ã¹ãã£ã³ãäºé²ããããšãã§ããŸãã ã¡ãªãã ããŒãã£ã·ã§ã³ãç¡ãå ŽåãBigQuery ã¯ããŒãã«å
šäœããã«ã¹ãã£ã³ããŸããããŒãã£ã·ã§ã³ã«ããç¯å²ã¹ãã£ã³ã¯ããã«ã¹ãã£ã³ã«æ¯ã¹ãŠå€§å¹
ã«ã¹ãã£ã³ç¯å²ãç¯çŽã§ããæéãšæéã®ç¯çŽãšãªããŸãã ãŸãåè¿°ã®ããŒãã£ã·ã§ã³ãã£ã«ã¿èŠä»¶ã䜿ãã°ããŠãŒã¶ãŒãå€§èŠæš¡ãªããŒãã«å
šäœã«å¯ŸããŠèª€ã£ãŠã¯ãšãªãå®è¡ããçã®ãè²»çšã®æ¥å¢ãé²ã广ããããŸãã ããŒãã£ã·ã§ã³ã®åå²åºæº æéã®å TIMESTAMP å ã DATE å ã DATETIME å ã®ããããã®åãããŒãã£ã·ã§ã³åãšããŠæå®å¯èœã§ãã TIMESTAMP åãš DATETIME åã§ã¯ãããŒãã£ã·ã§ã³ãæéåäœãæ¥åäœãæåäœã幎åäœã®ããããã§äœæã§ããŸãã DATE åã®å ŽåãããŒãã£ã·ã§ã³ã¯æ¥åäœãæåäœã幎åäœã§äœæã§ããŸãã ãããããåå²åäœãæå®ããªãå Žåãããã©ã«ãã¯æ¥åäœãšãªããŸãã 以äžã¯ãDDL ã®äŸã§ããDATE åã®åãããŒãã£ã·ã§ã³åã«æå®ãããšãããã©ã«ãã§ã¯æ¥åäœã§ã®åå²ã«ãªããŸããã以äžã®äŸã®ããã« DATE_TRUNC 颿°ã䜿ã£ãŠæåäœã§åãæšãŠãããšã§ãæåäœã®åå²ã«ãªããŸãã CREATE TABLE mydataset.newtable ( transaction_id INT64, transaction_date DATE ) PARTITION BY DATE_TRUNC(transaction_date, MONTH) OPTIONS ( require_partition_filter = TRUE ); åãèŸŒã¿æé åãèŸŒã¿æéãããŒãã£ã·ã§ã³åºæºãšããŠéžæãããšãBigQuery ãããŒã¿ãåã蟌ãã ã¿ã€ã ã¹ã¿ã³ãã«åºã¥ããŠããŒãã«ãåå²ãããŸãã åå²ç²åºŠã¯ãæéåäœãæ¥åäœãæåäœã幎åäœããéžæã§ããŸããããã©ã«ãã¯æ¥åäœã§ãã ããŒãã«äœææã«ã¯ã _PARTITIONTIME ãšããç䌌åïŒä»®æ³åïŒãããŒãã£ã·ã§ã³åãšããŠæå®ããŸãã 以äžã¯ãDDL ã®äŸã§ãã CREATE TABLE mydataset.newtable ( transaction_id INT64 ) PARTITION BY _PARTITIONDATE æŽæ°ç¯å²ã®å ããŒãã£ã·ã§ã³åå²ã®åºæºåãšããŠãINTEGER åã®åãæå®å¯èœã§ãããŸããã®å Žåãåå²ã®éå§å€ã»çµäºå€ãšåå²ã®ééãæå®ã§ããŸãã 以äžã¯ãDDL ã®äŸã§ãã CREATE TABLE mydataset.newtable ( customer_id INT64, date1 DATE ) PARTITION BY RANGE_BUCKET( customer_id, GENERATE_ARRAY( 0 , 100 , 10 ) ); ãã®äŸã§ã¯ customer_id åã§ããŒãã£ã·ã§ãã³ã°ããéå§å€ 0ãçµäºå€ 100ãéé 10 ãšããŠããŸãã ãã®ããã«èšå®ããå Žåãcustomer_id ã 0 ãã 9 ã®è¡ãæåã® ããŒãã£ã·ã§ã³ã«å
¥ãã10 ãã 19 ãæ¬¡ã®ããŒãã£ã·ã§ã³ã«å
¥ããŸãããã®åŠçã 99 ãŸã§ç¶ããŸãããã®ç¯å²å€ã®å€ã¯ã __UNPARTITIONED__ ãšããååã®ããŒãã£ã·ã§ã³ã«å
¥ããŸããcustomer_id ã NULL ã®è¡ã¯ã __NULL__ ãšããååã®ããŒãã£ã·ã§ã³ã«å
¥ããŸãã ããŒãã«ã«ã©ããªããŒãã£ã·ã§ã³ãååšããŠãããã¯ãããŒãã«ã®ã¡ã¿ããŒã¿ãã確èªã§ããŸãã åè : ããŒãã£ã·ã§ã³åå²ããŒãã«ã®ç®¡ç - ããŒãã£ã·ã§ã³ ã¡ã¿ããŒã¿ã®ååŸ ããŒãã£ã·ã§ã³ã®ç®¡ç æéåäœãŸãã¯åãèŸŒã¿æéã§åå²ããããŒãã«ã®å ŽåãããŒãã£ã·ã§ã³ã® æå¹æé ãèšå®ã§ããŸãã æå®ããæå¹æéãéãããããŒã¿ã¯èªåçã«åé€ãããŸãããã®ãšã BigQuery ã®ãŠãŒã¶ãŒã«å²ãåœãŠãããªãœãŒã¹ã¯æ¶è²»ãããŸãããæå¹æéãããŸã䜿ãããšã§ãããŠã¹ããŒãã³ã°çšã®ãžã§ãããŠãŒã¶ãŒãäœæããå¿
èŠããªããªããŸãã åè : ããŒãã£ã·ã§ã³åå²ããŒãã«ã®ç®¡ç - ããŒãã£ã·ã§ã³ã®æå¹æéãèšå®ãã ããã©ã«ãã®ããŒãã£ã·ã§ã³æå¹æéãããŒã¿ã»ããã§èšå®ã§ããã»ããããŒãã«åäœã§æå¹æéãèšå®ããããšãã§ããŸããããŒãã«ã§æå¹æéãèšå®ãããŠããå Žåã¯ãããŒãã«ã®æå¹æéãåªå
ãããŸãã ããŒãã£ã·ã§ã³ã®æå¹æéã¯ããŒãã«äœææã«æå®ããã»ããäœæåŸã«ã倿Žã§ããŸãã ããŒãã£ã·ã§ã³ã®äžéãšæ³šæç¹ 1ããŒãã«ãæãŠãããŒãã£ã·ã§ã³æ°ã«ã¯äžéãããã 1ããŒãã«ã«ã€ã10,000ããŒãã£ã·ã§ã³ãŸã§ ã§ããåŸæ¥ã¯4,000ãæå€§å€ã§ãããã2024幎5æ29æ¥ã®ã¢ããããŒãã§10,000ã«å€æŽãããŸããã ããã¯ãæéåäœã§ããã° 10,000 æé = çŽ416æ¥ = çŽ13ã¶æéã§ãããæ¥åäœã§ã®åå²ã§ããã° 10,000æ¥ = çŽ322ã¶æ = çŽ27幎ã§ãã ããŒãã£ã·ã§ã³æ°ã®äžéã«éãããšã ãžã§ãããšã©ãŒãšãªããŸã ãããŒãã£ã·ã§ã³ã®ããŒã¿ã®ããã¯ã¢ãããååŸããä»çµã¿ãçšæããããã§ãããŒãã£ã·ã§ã³ã«æå¹æéãèšããŠããŒã¿ãèªååé€ãããããã«ããçãéçšäžã®èæ
®ãæ€èšããå¿
èŠããããŸãã ãŸãã1 ã€ã®ãžã§ãã§å€æŽãããããŒãã£ã·ã§ã³ã®æ°ããã1 æ¥ã®åãèŸŒã¿æéããŒãã£ã·ã§ã³åå²ããŒãã«ãããã®ããŒãã£ã·ã§ã³ã®å€æŽåæ°ãã1 æ¥ã®åããŒãã£ã·ã§ã³åå²ããŒãã«ãããã®ããŒãã£ã·ã§ã³å€æŽæ°ããªã©ã«ãäžéããããŸãããããåŠçãããã«æµè§ŠããŠããªããã¯ãååæ³šæããå¿
èŠããããŸãã åè : å²ãåœãŠãšäžé - ããŒãã£ã·ã§ã³åå²ããŒã㫠以äžã¯ã10,001 åç®ã®ããŒãã£ã·ã§ã³ã远å ããããšããå Žåã®ãšã©ãŒã¡ãã»ãŒãžã§ãã Resources exceeded during query execution: Table my-project:my_dataset.my_table will have 10001 partitions when the job finishes, exceeding limit 10000. If partitions were recently expired, it may take some time to be reflected unless explicitly deleted. ããŒãã£ã·ã§ã³äžéãè¶
ããéã®ãšã©ãŒã¡ãã»ãŒãž ãŸãã1åã®ãžã§ãã§å€æŽå¯èœãªããŒãã£ã·ã§ã³æ°ã¯4,000ã§ãããããè¶
ãããããªã¯ãšãªãçºè¡ããå Žåã以äžã®ãããªã¡ãã»ãŒãžã衚瀺ãããŸãã Too many partitions produced by query, allowed 4000, query produces at least 10000 partitions ã¯ã©ã¹ã¿ãªã³ã° ã¯ã©ã¹ã¿ãªã³ã°ãšã¯ ã¯ã©ã¹ã¿ãªã³ã° ãšã¯ã BigQuery ã®ããŒãã«ã®ç¹å®ã®åã®å€ã«åºã¥ããŠããŒãã«ã®ããŒã¿ããœãŒãããå
éšçã«è¿ãäœçœ®ã«é
眮ãããããšã§ããã£ã«ã¿ãéèšã¯ãšãªãé«éåããæ©èœã§ãã ããŒãã«äœææã«ãåãã¯ã©ã¹ã¿ååãšããŠæå®ããŸãã ã¯ã©ã¹ã¿ãªã³ã°ãå©çšãããšãæå®ããåã®å€ã«åºã¥ããŠè¡ããœãŒããããããã WHERE å¥ã§ãã®åã«åºã¥ããŠãã£ã«ã¿ããã¯ãšãªãæããéãäžèŠãªããŒã¿ã®ã¹ãã£ã³ãã¹ãããããããšãã§ããŸãããŸããã¯ã©ã¹ã¿åããåã§ GROUP BY ããŠéèšããã¯ãšãªã®å Žåãè¡ããœãŒãããè¿ãäœçœ®ã«é
眮ãããŠããã®ã§ãããã©ãŒãã³ã¹ãåäžããŸãã åè : ã¯ã©ã¹ã¿åããŒãã«ã®æŠèŠ ã¯ã©ã¹ã¿ã¯ ããŒãã£ã·ã§ã³ãšäœµçšãã ããšãå¯èœã§ããã¯ã©ã¹ã¿ãªã³ã°ãšããŒãã£ã·ã§ãã³ã°ã䜵çšãããšãããŒã¿ã¯ããŒãã£ã·ã§ã³åå²ãããåŸã«ãã¯ã©ã¹ã¿åãããŸãã ãŸãã¯ã©ã¹ã¿ååã¯ã1ã€ã®ããŒãã«ã§è€æ°ïŒæå€§ 4 åãŸã§ïŒæå®å¯èœã§ããè€æ°æå®ããå Žåãæå®ã®é çªãéèŠã«ãªããŸãããŸãæåã«æå®ããåã§è¡ããœãŒããããæ¬¡ã«ãã®äžã§2çªãã«æå®ããåã§ãœãŒããæ¬¡ã«3çªç®... ãšããããã«ãé çªã«ãœãŒããããŸãã ã¯ã©ã¹ã¿åãããããŒãã« äœ¿çšæ¹æ³ ã¯ã©ã¹ã¿ãªã³ã°ãããããŒãã«ãäœæããæ¹æ³ã¯ã以äžã®ããã¥ã¡ã³ãã®ãšããã§ãã åè : ã¯ã©ã¹ã¿åããŒãã«ã®äœæãšäœ¿çš äŸãšããŠä»¥äžã®ãã㪠DDL ã§ãã¯ã©ã¹ã¿ãªã³ã°ãããããŒãã«ãäœæã§ããŸããäŸã§ã¯ãããŒãã£ã·ã§ãã³ã°ã䜵çšããŠããŸãã CREATE TABLE mydataset.purchase_tran_cls ( purchase_dt DATE , prod_id STRING, prod_name STRING, store_id INT64, store_name STRING ) PARTITION BY purchase_dt CLUSTER BY prod_id ãŸããæ¢åã®ããŒãã«ãã¯ã©ã¹ã¿ãªã³ã°ããããåã®æå®ã倿Žããããšãå¯èœã§ãã åè : ã¯ã©ã¹ã¿åããŒãã«ã®äœæãšäœ¿çš - ã¯ã©ã¹ã¿ãªã³ã°ä»æ§ã倿Žãã ã¯ã©ã¹ã¿åã«æå®ããå ã¯ã©ã¹ã¿åã«æå®ããåã¯ãäžæã®å€ãå€ãå«ãïŒã«ãŒãã£ããªãã£ã®é«ãïŒåãæšå¥šãããŸãããã®ã»ããããœãŒãã«ããã¹ãã£ã³ç¯å²ã®ã¹ãããã®å¹æãé«ãæåŸ
ãããããã§ãã ãŸããçµã¿åãããŠäœ¿ãããããšã®å€ãè€æ°ã®åãã¯ã©ã¹ã¿åãããšå¹æãæåŸ
ã§ããŸããå
ã®èšè¿°ã®éããé çªã«æ³šæããŠãé »ç¹ã« WHERE ã§æå®ããã㯠GROUP BY ãããè€æ°åãã¯ã©ã¹ã¿ååãšããŠæå®ãããšã广ã倧ãããªããŸãã åè : BigQuery ç¹é: ã¹ãã¬ãŒãžã®æŠèŠ åè : BigQuery ã®ã¯ã©ã¹ã¿ãªã³ã°ã§ ã¡ã³ããã³ã¹ã®æéãçã㊠ã¯ãšãªãé«éå èªååã¯ã©ã¹ã¿ãªã³ã° ã¯ã©ã¹ã¿ãªã³ã°ã®ã¡ã³ããã³ã¹ã¯èªåã§è¡ãããŸããããŒã¿ãæ°èŠã§è¿œå ããããã倿Žããããããå Žåã§ããèªåã§åã¯ã©ã¹ã¿ãªã³ã°ãè¡ãããŸããäžè¬çãªããŒã¿ããŒã¹è£œåã§å¿
èŠãšããã VACUUM ãšãã£ãåŠçã¯äžèŠã§ãã åã¯ã©ã¹ã¿ãªã³ã°ã¯ãã¹ããããªã©ã®ãªãœãŒã¹ãæ¶è²»ãããããšããªããèªåçãã€ééçã«è¡ãããããããŠãŒã¶ãŒãæèããå¿
èŠã¯ãããŸããã ããŒãã£ã·ã§ã³ vs ã¯ã©ã¹ã¿ãªã³ã° ããŒãã£ã·ã§ã³ãšã¯ã©ã¹ã¿ãªã³ã°ã®éã ããŒãã£ã·ã§ã³ãšã¯ã©ã¹ã¿ãªã³ã°ã¯äœµçšã§ããŸãããã©ã®ãããªã±ãŒã¹ã§ã©ã¡ãã䜿ãã°ããã®ãããŸãã©ã®ãããªåãæå®ããã°ããã®ãã䜿ãåãã«è¿·ããšãããããŸãã ããŒãã£ã·ã§ã³ãšã¯ã©ã¹ã¿ãªã³ã°ã®éãã¯ã以äžã®ãããªç¹ã«ãããŸãã ããŒãã£ã·ã§ãã³ã°ã§ã¯å®éã®ã¯ãšãªå®è¡åã« ãã©ã€ã©ã³ ã§ã¹ãã£ã³éã®è©Šç®ãã§ããïŒæé詊ç®ãå¯èœïŒãäžæ¹ã®ã¯ã©ã¹ã¿ãªã³ã°ã§ã¯ã詊ç®ã¯ããŒãã«åäœãããŒãã£ã·ã§ã³åäœã§è¡ããããããã©ã€ã©ã³ã«åæ ããããå®éã®ã¹ãã£ã³éã¯èŠç©ããããå°ãããªãå¯èœæ§ããã åè : ã¯ãšãªã®å®è¡ - ãã©ã€ã©ã³ ããŒãã£ã·ã§ãã³ã°ã§ã¯æå¹æéã®èšå®ãã§ãã ããŒãã£ã·ã§ãã³ã°ã§ã¯åå²ç²åºŠïŒæéã»æ¥ã»æã»å¹Žã»æŽæ°ç¯å²ïŒã®éžæãã§ãã ããŒãã£ã·ã§ãã³ã°ã§ã¯1ã€ã®åããæå®ã§ããªããã¯ã©ã¹ã¿ãªã³ã°ã§ã¯4åãŸã§æå®ã§ãã ããŒãã£ã·ã§ãã³ã°ã§ã¯ç¹å®ã®åã®åããæå®ã§ããªãããã¯ã©ã¹ã¿ãªã³ã°ã«ã¯åã®å¶éã¯ãªã ããŒãã£ã·ã§ã³ãšã¯ã©ã¹ã¿ãªã³ã°ã®äœ¿ãåããšäœµçš ãŸãã¯ããŒãã£ã·ã§ã³ãé©çšã§ããåããããã©ãããæ€èšããŸãã以äžã®ãããªå ŽåãããŒãã£ã·ã§ã³ã®å©çšãæ€èšããŸãã æ¥ä»ãŸãã¯æé ã®åã®åãããã ãããã®åã§ãã£ã«ã¿ ããã¯ãšãªããã ããŒãã£ã·ã§ã³ã® æå¹æéèšå® ã䜿ã£ãŠããŒãã«ã®ã¡ã³ããã³ã¹ãããã ãã©ã€ã©ã³ ã§ã¹ãã£ã³éïŒè²»çšïŒã®èŠç©ãããè¡ããã 1åã®ããŒãã£ã·ã§ã³ãããã®ããŒã¿éã ããã 10 GB ä»¥äž ã«ãªãèŠèŸŒã¿ïŒããæªæºã®å Žåã¯ãªãŒããŒãããã«ãã éã«éå¹ç ã«ãªãå¯èœæ§ãããããã¯ã©ã¹ã¿ãªã³ã°ã®äœ¿çšãæ€èšããïŒ äžèšã®èгç¹ã§ããŒãã£ã·ã§ãã³ã°ãé©çšããåãæ€èšãããåŸã以äžã®ããã«ã¯ã©ã¹ã¿ãªã³ã°ãé©çšããåãæ€èšããŸãã ãããã£ã«ã¿å¯Ÿè±¡ã«ãªãåã ããããŒãã£ã·ã§ãã³ã°ã¯æ¢ã«å¥ã®åã«é©çšããŠãã ãããã£ã«ã¿å¯Ÿè±¡ã«ãªãåã ããããŒã¿ãµã€ãºã 10 GB æªæº ã«ãªãèŠèŸŒã¿ ãããã£ã«ã¿å¯Ÿè±¡ã«ãªãåã§ãããå€ã® ã«ãŒãã£ããªãã£ã倧ãã ïŒã¯ã©ã¹ã¿åã«ããé床æ¹åã®å¯èœæ§ããïŒ ãããã£ã«ã¿å¯Ÿè±¡ã«ãªãåã ããããŒãã£ã·ã§ã³ã䜿ããšåå²ç²åºŠãå°ãããªãããã1ããŒãã«ã® äžéã§ãã 10,000 ããŒãã£ã·ã§ã³ ãè¶
ããŠããŸã ããŒãã«å
ã®å€§éšåã®ããŒãã£ã·ã§ã³ãé »ç¹ã«ïŒããšãã°ãæ°åããšã«ïŒå€æŽããããªãã¬ãŒã·ã§ã³ãããããã®å ŽåãããŒãã£ã·ã§ã³ã¯é¿ããŠã¯ã©ã¹ã¿ãªã³ã°ãå©çšããã1æ¥ãããã®ããŒãã£ã·ã§ã³å€æŽæ°ã®äžéããããã çµåã«äœ¿ãããŠããåãã¯ã©ã¹ã¿åã«ãã£ãŠ çµåãé«éå ããå¯èœæ§ãããïŒããŒã¿ãåãã«ã©ã ããã¡ã€ã«ã«èšé²ããã¹ãããéã®ããŒã¿ç§»åãæŒãããããïŒ ãã ã 64 MB æªæºã®ããŒãã«ãããŒãã£ã·ã§ã³ã§ã¯ã¯ã©ã¹ã¿åã®ã¡ãªããã¯å°ãã ãµã€ãºãããçšåºŠå€§ããããŒãã«ã®å Žåã¯äžèšã®ããã«æ€èšããããŒãã£ã·ã§ã³ãšã¯ã©ã¹ã¿ãªã³ã°ã䜵çšããããšã§ãã¹ãã£ã³æãç¯æžããŠããã©ãŒãã³ã¹ãšã³ã¹ãå¹çãåäžãããããå¯èœæ§ããããŸãã 以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : ããŒãã£ã·ã§ã³åå²ããŒãã«ã®æŠèŠ - ã¯ã©ã¹ã¿åããŒãã«ãšããŒãã£ã·ã§ã³åå²ããŒãã«ãçµã¿åããã åè : ã¯ã©ã¹ã¿åããŒãã«ã®æŠèŠ - ã¯ã©ã¹ã¿ãªã³ã°ã䜿çšããå Žå åè : ã¯ã©ã¹ã¿åããŒãã«ã®æŠèŠ - ã¯ã©ã¹ã¿åããŒãã«ãšããŒãã£ã·ã§ã³åå²ããŒãã«ãçµã¿åããã ããŒãã£ã·ã§ã³ã»ã¯ã©ã¹ã¿ãŒã®ã¬ã³ã¡ã³ããŒã·ã§ã³ BigQuery ã«ã¯ãéå»ã®ã¯ãŒã¯ããŒãã«åºã¥ããŠããŒãã«ã®é©åãªããŒãã£ã·ã§ãã³ã°ãã¯ã©ã¹ã¿ãªã³ã°ãæšå¥šããæ©èœããããŸãã Recommender API ãéå»30æ¥éã®å®çžŸãæ©æ¢°åŠç¿ã§åæããããŒãã«ã®é©åãªããŒãã£ã·ã§ãã³ã°ã»ã¯ã©ã¹ã¿ãªã³ã°èšå®ãæç€ºããŸãã察象ããŒãã«ã察象åããŸãã©ã®ãããã®ã¹ãããæéãç¯çŽã§ãããã®èŠèŸŒã¿ã衚瀺ãããŸãã æšå¥šã®å¯Ÿè±¡ãšãªãããŒãã«ã¯ãããŒãã£ã·ã§ãã³ã°ç¡ãã»ã¯ã©ã¹ã¿ãªã³ã°ç¡ãããããŒãã£ã·ã§ãã³ã°æãã»ã¯ã©ã¹ã¿ãªã³ã°ç¡ããã®ããŒãã«ã§ãã äžæ¹ã§ 10 GB 以äžã®ããŒãã«ãæ¢ã«ããŒãã£ã·ã§ã³ãšã¯ã©ã¹ã¿ãŒãäž¡æ¹èšå®æžã¿ã®ããŒãã«ããŸãéå»30æ¥ä»¥å
ã«èªã¿åããããŠããªãããŒãã«ãªã©ã¯å¯Ÿè±¡å€ãšãªããŸãã æšå¥šã¯ã³ã³ãœãŒã«ãgcloudãREST API ã§ç¢ºèªå¯èœã§ããã³ã³ãœãŒã«ã§ã¯ãç»é¢å³äžã®é»çããŒã¯ãã確èªã§ããŸãã åè : ããŒãã£ã·ã§ã³ãšã¯ã©ã¹ã¿ã®æšå¥šäºé
ã管çãã åèæ
å ± 以äžã®å
¬åŒèšäºã§ã¯ãããŒãã£ã·ã§ã³ãã¯ã©ã¹ã¿ãªã³ã°ã®ä»çµã¿ã詳现ã«è§£èª¬ãããŠããŸãã®ã§ãæ¯éåèã«ããŠãã ããã åè : BigQuery ç¹é: ã¹ãã¬ãŒãžã®æŠèŠ åè : BigQuery ã®ã¯ã©ã¹ã¿ãªã³ã°ã§ ã¡ã³ããã³ã¹ã®æéãçã㊠ã¯ãšãªãé«éå ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO å
èŠå¯å®ãšããçµæŽãæã€ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS èªå®è³æ Œããã³ Google Cloud èªå®è³æ Œã¯ãã¹ãŠååŸãXïŒæ§ TwitterïŒã§ã¯ Google Cloud ã Google Workspace ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
ã¿ãªããããã«ã¡ã¯ãG-genã®éŽæšããšãããã€ã§ãã Google Workspaceã«ãããŠãªãŒããŒæš©éãšããã®ããåç¥ã§ããããïŒ ãã®åã®éãããã¡ã€ã«ããã©ã«ãã®ãªãŒããŒæš©éã«ãªãã®ã§ãããäŸãã°ãã®ãªãŒããŒãGoogle Workspaceããåé€ãããå Žåãªã©ããªãŒããŒãäœæããããã¥ã¡ã³ããäžç·ã«åé€ãããŠããŸããŸãããŸãããã¡ã€ã«ã®å€æŽå±¥æŽãªã©ãæ¶ããŠããŸãããšãããã®ã§ã確å®ã«å®æœããæ¹æ³ãšããŠã¯âãªãŒããŒæš©éãå¥ã®ãŠãŒã¶ãŒã«ç§»ãâãšããäœæ¥ãå¿
èŠã«ãªããŸãã äŸãã° éè·è
ãåºãå Žå çã«ã¯å¿
èŠã«ãªãã®ã§ããæŽ»çšãã ããã ããã§ã¯ãã®æ¹æ³ãç°¡åã«èª¬æããŠãããŸãã ãŠãŒã¶ãŒãæäœå¯èœãªå Žå(éè·åãªã©) äžæ¬ã§ãªãŒããŒæš©éãä»ãæ¿ããæ¹æ³(éè·åŸãªã©) ãŠãŒã¶ãŒãæäœå¯èœãªå Žå(éè·åãªã©) ãŸã ãŠãŒã¶ãŒãéè·ããŠãããããŸããã¡ã€ã«æ°ãå°ãªãå Žåã«ã¯ä»¥äžã®æé ã§ç°¡åã«å®æœå¯èœã§ãã ãã¡ã€ã«ãå³ã¯ãªãã¯ïŒå
±æã®ã¡ãã¥ãŒããç·šéè
ã®ãã«ããŠã³ã«ãŠ ãªãŒããŒæš©éã®è²æž¡ ã«ãŠæäœå¯èœã§ãã ãã¡ã€ã«åäœã®è²æž¡æ¹æ³ ãã ãã¡ããäžåäžå宿œããã®ã¯çžåœããã©ãããã§ããããéè·è
ãã§ãããšããããšã¯ãããããã¡ã€ã«ãå€ãååšãããšæããŸããã ã§ã¯æ¬¡é
ã«ãŠ äžæ¬ã§è²æž¡ããæ¹æ³ ãã詊ããã ããã äžæ¬ã§ãªãŒããŒæš©éãä»ãæ¿ããæ¹æ³(éè·åŸãªã©) ãã¡ãã®æ¹æ³ã¯ç®¡çè
ã®ã¿ãå®è¡ã§ããæ¹æ³ã«ãªãã®ã§ããã管çã¡ãã¥ãŒãã以äžã®ããã«éžæããããŸãã ãã¢ããªãïŒãGoogle WorkspaceãïŒããã©ã€ããšããã¥ã¡ã³ããïŒããªãŒããŒæš©éã®è²æž¡ã ãªãŒããŒæš©éã®è²æž¡ ããã§è²æž¡åã®ãŠãŒã¶ãŒãåã³è²æž¡åŸã®ãŠãŒã¶ãŒãå
¥åããããšã§ãç°¡åã«äžæ¬ã§ãªãŒããŒæš©éãè²æž¡ããããšãå¯èœã§ãã ä»åã¯äœè€ããããéŽæšããã«è²æž¡ããŠã¿ãŸãããã ãªãŒããŒæš©éã®è²æž¡æäœ(1) ãªãŒããŒæš©éã®è²æž¡æäœ(2) äžèšæäœã宿œãããšã以äžã®ç»é¢ã®ããã«ãäœè€ãããä¿æããŠãããªãŒããŒæš©éããéŽæšã«è²æž¡ãããŠããããšããããšããããããšæããŸãã è²æž¡åŸã®ãªãŒããŒæš©é ãã ãããã§æ³šæãªã®ãæ¬æäœãå¯èœãªã®ã¯ åãçµç¹å
ã§ç®¡çãããŠãããŠãŒã¶ãŒã®ã¿ ã«ãªããŸãã®ã§ãå¥çµç¹çã«å
±æããŠãããã®ã«é¢ããŠã¯ãªãŒããŒæš©éãäžæ¬ã§å€æŽããããšã¯ã§ããŸããã ãã¡ãã«é¢ããŠã¯åŒãç¶ãGoogleãµããŒããå©çšãã€ã€èª¿æ»ããŠãããããšæããŸãã ä»åã®èšäºã¯ã©ã€ãã«ãããŸã§ãšãããŠããã ãããšæããŸãã 远䌞ïŒ11æ29æ¥ã«Google Cloud - Professional Collaboration EngineerãååŸãããŠããã ããŸããããã®ä»¶ã«é¢ããŠã¯ãŸãäœãã®æ©äŒã§ã Professional Collaboration Engineer éŽæš éæ (èšäºäžèЧ) å·è¡åœ¹å¡ COO ããžãã¹æšé²éš éšé· åºæ¬ããªãã§ãå±ãäž»ã«ããžãã¹ã®ç«ã¡äžããä»çµã¿ã¥ãããå¥œã æ¥ã
ãåªåãæ¥ã
ãæ¥œããããšã倧äºã« ã Professional Cloud Architect / Professional Workspace Administratorã®ã¿ä¿æããŠããŸãããããã倱å¹ããŠããŸããããªäºæã
G-gen ã®ææã§ããGoogle Cloud (æ§ç§° GCP) ã®ã»ãã¥ãªãã£ãµãŒãã¹ã§ãã Cloud IDS ã«ã€ããŠè§£èª¬ããŠãããŸãã Cloud IDS ãšã¯ ã¢ãŒããã¯ãã£ æ§æå³ IDS ãšã³ããã€ã³ã Packet mirroring policy è
åšæ€ç¥ Application-ID ã·ã°ããã£ãŒã»ãã éèŠåºŠ ã·ã°ããã£ãŒã®æŽæ°é »åºŠ æé äžé ã»ããã¢ãã ã»ããã¢ããæé åäœç¢ºèª Cloud IDS Cloud IDS ãšã¯ Cloud IDS ãšã¯ Google Cloud (æ§ç§° GCP) ã®ã»ãã¥ãªãã£ãµãŒãã¹ã§ãããGoogle Cloud äžã®ãããã¯ãŒã¯ã«ããã䟵å
¥ããã«ãŠã§ã¢ã«ããéä¿¡ãã³ãã³ã&ã³ã³ãããŒã«éä¿¡çãæ€ç¥ããä»çµã¿ã§ãã IDS ãšã¯ Intrusion Detection System ã®ç¥èªã§ãã 䟵å
¥æ€ç¥ã·ã¹ãã ã®ããšã§ããäž»ã«ãããã¯ãŒã¯ãã©ãã£ãã¯ãæ€æ»ããããšã§æå®³ãªã¢ã¯ã»ã¹ãæ€ç¥ããããšãç®çãšããä»çµã¿ãæããŸãããã°ãã° IPS/IDS ã®ããã«äŸµå
¥ 鲿¢ ã·ã¹ãã ãšã»ããã§èªãããããšãå€ããã®ã§ãã ãã®ãã Cloud IDS ã§æäŸãããã®ã¯äŸµå
¥ã® æ€ç¥ã ã ã§ãã䟵å
¥ã é²ãæ©èœã¯ãããŸãã ã Cloud IDS ã¯ãVPC ãããã©ãã£ãã¯ããã©ãŒãªã³ã° (è€è£œ) ã Palo Alto Networks ã®è
åšæ€ç¥æè¡ ã§æ€æ»ããŸãã ãŸããå©çšæéãšåŠçããŒã¿éã«å¿ããŠæéãçºçããŸããå
šãã©ãã£ãã¯ãæ€æ»ããããšãããµããããåäœãªã€ã³ã¹ã¿ã³ã¹åäœã§æ€æ»å¯Ÿè±¡ãã±ãããæå®ããããšãå¯èœã§ãã åè : Cloud IDS ã®æŠèŠ ã¢ãŒããã¯ãã£ æ§æå³ Cloud IDS ã®ã¢ãŒããã¯ãã£ã¯ã以äžã®ããã«å³ç€ºãããŸãã Cloud IDS ã®ã¢ãŒããã¯ã㣠IDS ãšã³ããã€ã³ã Cloud IDS ã§ã¯ IDS ãšã³ããã€ã³ã ãšãããªãœãŒã¹ãäœæããŸãã IDS ãšã³ããã€ã³ãèªäœã¯ãŸãŒã³ãªãœãŒã¹ã§ããã1ã€äœãã°åããªãŒãžã§ã³å
ã®å
šãŸãŒã³ã®ãã©ãã£ãã¯ãæ€æ»ã§ããŸãã IDS ãšã³ããã€ã³ã㯠Private services access ã®æ©èœã䜿ã£ãŠããŠãŒã¶ã® VM ãš Google ã管çããæ€æ»çš VM ã®éãæ¥ç¶ããŸãã ãã©ã¡ãŒã¿ãšããŠä»¥äžãæã¡ãŸãã æå°ã®ã¢ã©ãŒã (ã¢ã©ãŒããšããŠæ±ãæå°ã®éèŠåºŠã Critical > High > Medium > Low > Informational) ãã©ãã£ãã¯ãã° (ON or OFF) ãã©ãã£ãã¯ãã° ã¯ãæ€ç¥ãããè
åšãšã¯å¥ã«ããã©ãŒãªã³ã°ãããã©ãã£ãã¯ã®ãã°ã JSON ã§çæããŸãã 倧éã®ãã°ã Cloud Logging ãžéä¿¡ããå©çšæéã倧ãããªãããšãæ³å®ãããŸãã®ã§ãç¹ã«å¿
èŠãªçç±ãããå Žåãé€ããŠããªããšããããšãæãŸããã§ãããã Packet mirroring policy IDS ãšã³ããã€ã³ããäœæãããš Packet mirroring policy ãã¢ã¿ããããå¿
èŠããããŸãã ãã®ããªã·ãŒããã©ã®ãã©ãã£ãã¯ãæ€æ»å¯Ÿè±¡ãšããããæ±ºå®ããŸãã Packet mirroring policy ã§ã¯ä»¥äžã®ãã©ã¡ãŒã¿ãæã£ãŠããŸãã ããªã·ãŒã®ç¶æ
(æå¹ or ç¡å¹) ãã©ãŒãªã³ã°ã®å¯Ÿè±¡ (ãµããããåäœ or ãããã¯ãŒã¯ã¿ã°åäœ or ã€ã³ã¹ã¿ã³ã¹åäœ) ãã©ãŒãªã³ã°ã®ãã£ã«ã¿ (ãããã³ã« / IP ã¬ã³ãž / ãã©ãã£ãã¯ã®æ¹å) è
åšæ€ç¥ Application-ID æ€æ»ããããããã¯ãŒã¯ãã©ãã£ãã¯ã¯ Palo Alto Networks ãã¡ã³ããã³ã¹ãã Application-ID (App-ID) ãšãã ID ã«ãããã©ã®ã¢ããªã®ãã©ãã£ãã¯ã§ãããã倿ãããŸãã è
åšæ€ç¥ãããéããã®ãã©ãã£ãã¯ãäœã®ã¢ããªã±ãŒã·ã§ã³ã«ããçæããããã®ãªã®ããããã® App-ID ã«ãã£ãŠåé¡ãããŸãã App-ID ã¯é±æ¬¡çšåºŠã®é »åºŠã§æŽæ°ãããŠããã Cloud IDS ã®ãŠãŒã¶ãŒãæèããªããšããèªåã§ã¢ããããŒããããŠãããŸãã ã·ã°ããã£ãŒã»ãã Cloud IDS 㯠ã·ã°ããã£ãŒ ã«ãããã©ãã£ãã¯ãæ€æ»ããŸãã äŸãšããŠã以äžã®ãããªæåãšãªããŸãã ãããã¡ãªãŒããŒãããŒãã³ãŒãã®äžæ£å®è¡ããã®ä»ã®è匱æ§ãçªããã¢ã¯ã»ã¹ãªã©ãæ€ç¥ ã¹ãã€ãŠã§ã¢ããã³ãã³ã & ã³ã³ãããŒã« (C&C) ãµãŒããžã®éä¿¡ãæ€ç¥ éèŠåºŠ æ€ç¥ãããè
åšã¯ 5段éã«åé¡ ãããŸãã IDS ãšã³ããã€ã³ãã®èšå®ã§ã©ã®ã¬ãã«ãŸã§ãæ€ç¥å¯Ÿè±¡ãšããããæå®ã§ããŸãã éèŠåºŠ 説æ Critical æ·±å»ã ãµãŒãã«æ·±å»ãªãã¡ãŒãžãäžãããã®ããŸããšã¯ã¹ããã€ãã³ãŒããåºãç¥ãããŠãããæ»æè
ãæ»æå¯Ÿè±¡ã«é¢ããŠèªèšŒæ
å ±ãæ·±ãæ
å ±ãå¿
èŠãšããªããªã©ãå±éºåºŠãé«ãè
åš High é«ãå±éºã§ã¯ãããã®ã®ããšã¯ã¹ããã€ãã®é£æåºŠãé«ããç¹æš©ææ Œã«ç¹ãããªããæ»æå¯Ÿè±¡ãšãªãåŸãç¯å²ãçããªã©ã®çç±ã§ "æ·±å»" ã«ã¯åé¡ãããªãè
åš Medium äžãã€ã³ãã¯ãã¯äžçšåºŠã§ãæ»æè
ãåãããŒã«ã«ãããã¯ãŒã¯ã«ããå¿
èŠããã£ãããæšæºçã§ãªãèšå®ã«å¯ŸããŠã®ã¿å±éºã§ãã£ãããéå®çãªå¯Ÿè±¡ã«å¯ŸããŠã®ã¿å±éºãªè
åš Low äœãã€ã³ãã¯ããå°ãããããŒã«ã«ãããã¯ãŒã¯ãããã¯ç©ççãªã¢ã¯ã»ã¹ãå¯èœãªå Žåã®ã¿å±éºãšãªããããªã©ã®çç±ã§ãèŠåã¬ãã«ãšãããè
åš Informational æ
å ±ã¬ãã«ãçŽã¡ã«è
åšã«ã¯ãªãåŸãªããæœåšçã«å±éºãªãçãããæåãªã© ã·ã°ããã£ãŒã®æŽæ°é »åºŠ App-ID ãã·ã°ããã£ãŒã¯ããŠãŒã¶ãŒãæèããå¿
èŠãªãã èªåçã«ã¢ããããŒã ãããŸãã Palo Alto Networks ã«ããã¢ããããŒãã¯ãæ¥æ¬¡ã§ Cloud IDS ã«åæ ãããŸããåæ ã®é
ãã¯ãæå€§ã§ã 48 æéãšãããŠããŸãã æé Cloud IDS ã®æé㯠ãšã³ããã€ã³ãã®ååšããæé åäœã®èª²é + åŠçãããã©ãã£ãã¯ã® GB åäœã®èª²é ã®2軞ãšãªã£ãŠããŸãã 2021/11æç¹ã§æéã¯ä»¥äžã®ããã«ãªã£ãŠããŸãã ãšã³ããã€ã³ãæéããã: $1.50 / hour åŠçããŒã¿éããã: $0.07 / GB ææ°ã®æéã¯å¿
ã以äžã®ããã¥ã¡ã³ããåç
§ããŠãã ããã åè: Pricing äžé Cloud IDS ã«ã¯ä»¥äžã®äžé (Quotas) ãèšå®ãããŠããŸãã ã³ã³ãœãŒã«ã® å²ãåœãŠ ç»é¢ããç·©åãªã¯ãšã¹ããéä¿¡ããããšãå¯èœã§ãã ãŸãŒã³ãããã® IDS ãšã³ããã€ã³ãæ°: ããã©ã«ã 10 åãããã® API ãªã¯ãšã¹ãæ°: ããã©ã«ã 1,200 ã»ããã¢ãã ã»ããã¢ããæé ã»ããã¢ããæ¹æ³ã¯ä»¥äžã®ããã¥ã¡ã³ããåèã«ããŠãã ããã cloud.google.com 倧ãŸããªæµãã¯ä»¥äžã®ãšããã§ãã IDS ãšã³ããã€ã³ãã®äœææã«åŸ
ã¡æéã 10 åã»ã©ãããŸãããå
šäœãšããŠã¯ 30 åçšåºŠã§æ§ç¯ããããšãã§ããŸãã Private service access ãäœæ (Cloud SQL ãªã©ã§æ¢åã®ãã®ãããã°å©çšå¯èœ) IDS ãšã³ããã€ã³ããäœæ Packet mirroring policy ãäœæ åäœç¢ºèª Google Compute Engine (GCE) ã®ã³ã³ãœãŒã«ã§å¯Ÿè±¡ VM ãéžæã ãªãã¶ãŒãããªã㣠ã¿ããéžæãããšå¯Ÿè±¡ VM ã® Cloud Monitoring ã¡ããªã¯ã¹ (ææš) ãèŠãããšãã§ããŸãã ãã®äžã« Packet Monitoring ãšããé
ç®ããããŸãã ãããèŠããšã察象 VM ãããã±ããã IDS ãšã³ããã€ã³ããéããŠãã©ãŒãªã³ã°ãããŠããããšãåãããŸãã ãã±ãããã©ãŒãªã³ã°ãæå¹åãããŠãã ãŸããè
åšã確å®ã«æ€ç¥ãããããšã確ãããããã以äžã®ã³ãã³ãã VM äžã§å®è¡ããŸãããã curl http://example.com/cgi-bin/../../../..//bin/cat%%20/etc/passwd ãã°ãããããš Cloud IDS ã®ã³ã³ãœãŒã«ç»é¢ã§æ€ç¥ã High ãšããŠè
åšãããŠããããšã衚瀺ãããŸãã 察象ã¢ã©ãŒããã¯ãªãã¯ãããšã詳现ã衚瀺ããããšãã§ããŸãã ãã¹ãã§å®è¡ãã curl ãæ€ç¥ããã åè: Troubleshooting ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãTwitter ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
ããã«ã¡ã¯æ ªåŒäŒç€ŸG-genã®æž¡éïŒ@norryïŒã§ãã Google Workspace (以äžãGWS)ãå©çšããã«ããã£ãŠçµç¹ã®ç«¯æ«ã«å¯ŸããŠã»ãã¥ãªãã£ãŒãã©ãæ
ä¿ããŠããã®ãïŒæ°ã«ãããã®ã§ã¯ãªãã§ããããããã®æã«GWSã ãã§ã©ã®çšåºŠç®¡çå¯èœãªã®ããæ°ã«ãªãéšåããšæããŸãã ä»åã¯å©çšäººæ°1ã300åãŸã§ã®Businessãšãã£ã·ã§ã³ã®åãã©ã³ã§ããããããã®ç®¡çãããããããã®ãã©ã³ãå¿
èŠããšå€æããæã«ã圹ã«ç«ãŠãã°å¹žãã§ãã åãã©ã³ã®ãããŸããªå
šäœæ¯èŒã¯ãã¡ããåèã«ããŠãã ãã blog.g-gen.co.jp ã©ã®ãã©ã³ããªã¹ã¹ã¡ã Business Starteråã³Business Standardããªã¹ã¹ã¡ãªã±ãŒã¹ Business Plusããªã¹ã¹ã¡ãªã±ãŒã¹ äžèšã ãã§ã¯èŠä»¶ãæºãããªãã±ãŒã¹ æ··åããã¡ãªããŒã¯ãŒã GWSäžã®ããã€ã¹ç®¡çã®ã³ã³ãœãŒã«ã§è¯ãç®ã«ããããŒã¯ãŒã Businessãšãã£ã·ã§ã³ãããã€ã¹ç®¡çã®åãã©ã³æ©èœæ¯èŒ æ©èœæ¯èŒã®è£è¶³ åºæ¬ã®ãšã³ããã€ã³ã管ç ã»ãã¥ãªãã£èšå® ããã€ã¹ã®ç®¡ç ã¢ããªã®ç®¡ç ããã€ã¹ã®è©³çް é«åºŠãªãšã³ããã€ã³ã管ç ã»ãã¥ãªãã£èšå® ããã€ã¹ã®ç®¡ç ã¢ããªã®ç®¡ç ããã€ã¹ã®è©³çް Google Workspaceãå°å
¥ãããªãæ ªåŒäŒç€ŸG-genã«ãçžè«ãã ããã ã©ã®ãã©ã³ããªã¹ã¹ã¡ã ããã€ã¹ç®¡çã®Businessãšãã£ã·ã§ã³ã§ã®åãã©ã³æ©èœæ¯èŒã¯ãã¡ãã®ããã«ãªããŸãã Business Starter Business Standard Business Plus åºæ¬ã®ãšã³ããã€ã³ã管ç â â â Android ã¢ããªã®ç®¡ç â é«åºŠãªãšã³ããã€ã³ã管ç â ãšã³ã¿ãŒãã©ã€ãº ãšã³ããã€ã³ã管ç ã¢ãã€ã«ã¢ããªãåå¥ã«é
åžãã â ããã€ã¹ç£æ»ãã° â 䜿ãããŠããªãäŒç€Ÿææããã€ã¹ã«é¢ããã¬ããŒã â äŒç€Ÿææã® Android ããã€ã¹ â äžèšãåèã«ããªããæåã«ãªã¹ã¹ã¡ã®ãã©ã³ãã玹ä»ããããŸãã Business Starter åã³ Business Standard ããªã¹ã¹ã¡ãªã±ãŒã¹ ããã€ã¹ç®¡çãããªãããŸãã¯æäœéã®ç®¡çã ããèããŠããæ¹ã«ããããã§ãã åŸè¿°ããŸããããã€ã¹ç®¡çã ããèæ
®ããå ŽåããBusiness StarterããBusiness Standardãã«ã¯å·®ç°ããããŸããã åºæ¬çãªã¢ãã€ã«ããã€ã¹ç®¡ç ãå©çšå¯èœã§ã äž»ãªæ©èœãšããŠãã¹ã³ãŒã䜿çšã®å¿
é åãããã€ã¹ã®äžèЧååŸãGoogle ã¢ã«ãŠã³ãã®ãªã¢ãŒã ã¯ã€ããAndroid ããã€ã¹ãžã®ã¢ããªã±ãŒã·ã§ã³ã®ãªã¢ãŒã ã€ã³ã¹ããŒã«ãå¯èœã§ãã åºæ¬çãªç®¡çã®ããã€ã¹æ
å ±ç»é¢ ãŸãããŠãŒã¶ãŒã WindowsãMacãChromeãLinux ããã€ã¹ã®ã©ã®ãã©ãŠã¶ã䜿çšã㊠GWSã«ãã°ã€ã³ããå Žåã§ãããã®ããã€ã¹ããšã³ããã€ã³ã管çã«èªåç»é²ãããŸãã çšåºŠãšããŠããŠãŒã¶ãŒã«å¶éããããããªããã©ããªã¢ãã€ã«ããã€ã¹ãã¢ã¯ã»ã¹ããã®ããªïŒããããç¥ãããšãåºæ¥ãã°OKã§ãããããã¡ããéžæãã ããã Business Plus ããªã¹ã¹ã¡ãªã±ãŒã¹ AndoroidãiOSã®BYODããã€ã¹ã«å¯ŸããŠãã现ããå¶åŸ¡ãWindows端æ«ã管ç察象ã«ãããå Žåã«Business Plusãã©ã³ãããããã§ãã Business Plusãã©ã³ã§ã¯ é«åºŠãªã¢ãã€ã«ããã€ã¹ç®¡ç ãå©çšå¯èœã«ãªããŸãã Android ã§ã¯ä»äºçšãããã¡ã€ã«ã§å人ããŒã¿ãä»äºçšããŒã¿ããåé¢ããŠããã©ã€ãã·ãŒãå®ãããšãã§ããŸããiOS ããã€ã¹ãš Android ããã€ã¹ã§ä»äºçšã¢ããªã®äœ¿çšãèš±å¯ã管çããäºãå¯èœã§ãã Windows ããã€ã¹ç®¡çã§ã¯GWSã¢ã«ãŠã³ãã§ã®Windowsãã°ã€ã³ãããã€ã¹ããã®ããŒã¿ã®ã¯ã€ãïŒæ¶å»ïŒãããã€ã¹ã®è©³çްæ
å ±ã衚瀺ãããäºãå¯èœãšãªã£ãŠããŸãã äžèšã ãã§ã¯èŠä»¶ãæºãããªãã±ãŒã¹ ããããèš±å¯ããã端æ«ä»¥å€ã¯GWSã«ã¢ã¯ã»ã¹ãããããªãå Žåã¯ä»ã®æ¹æ³ããæ€èšãã ããã äŒç€Ÿææä»¥å€ã®ç«¯æ«ããã¢ã¯ã»ã¹ããæã«ç®¡çè
ã®æ¿èªãå¿
é ã«ããå ŽåãEnterpriseãšãã£ã·ã§ã³ããã®ä»ã®MDMããŒã«ããæ€èšãã ããã åºæ¬çãé«åºŠãªã¢ãã€ã«ããã€ã¹ã§ã¯ãŠãŒã¶ãŒã¯ç«¯æ«ã§äžåºŠã¯GWSã«ãã°ã€ã³ããäºãåºæ¥ãŠããŸããŸããããã°ã€ã³åŸã«ç®¡çã³ã³ãœãŒã«ããç¶æ³ã®ç¢ºèªãã¯ã€ãã®æäœã¯å¯èœã§ãã æ··åããã¡ãªããŒã¯ãŒã GWSäžã®ããã€ã¹ç®¡çã®ã³ã³ãœãŒã«ã§è¯ãç®ã«ããããŒã¯ãŒã GWS管çã³ã³ãœãŒã« ãã©ã³ã«ãã£ãŠã¢ãã€ã«ããã€ã¹ã«ã¯ããªã·ãŒé©çšåºæ¥ãããšã³ããã€ã³ãã«ã¯åºæ¥ãªãã¿ãããªäºããããŸããæ€èšããŠãããã¡ã«ã©ã®çš®é¡ã®ç«¯æ«ãªã®ãåãããªããªã£ãŠããã®ã§ãã䜿ãã¯ãŒãã ããŸãšããŠãããŸãã ã¢ãã€ã«ããã€ã¹ AndroidãiOSãGoogle sync ããã€ã¹ïŒæè¬æºåž¯ç«¯æ«ïŒ ãšã³ããã€ã³ã 管çã³ã³ãœãŒã«äžã§ã¯ããœã³ã³(WindowsãMacãLinux)ãšã¹ããŒãããŒã ããã€ã¹ããã©ã³èª¬æã®æã«ã¯ç«¯æ«å
šè¬ãæãäºãå€ã Chromeããã€ã¹ Chromebook ãšãã®ä»ã® Chrome OS æèŒããã€ã¹ 管ç察象ãã©ãŠã¶ åOSïŒWindowsãMacãLinuxïŒããç»é²ããŒã¯ã³ã䜿çšããŠç»é²ããã Chromeãã©ãŠã¶ ã®ããš ãŸãGoogleãšã³ããã€ã³ã管çã®ããã€ã¹èŠä»¶ã¯ ãã¡ã ã«ãªããŸã Businessãšãã£ã·ã§ã³ãããã€ã¹ç®¡çã®åãã©ã³æ©èœæ¯èŒ æ©èœæ¯èŒã®è£è¶³ å
ã«ãªã¹ã¹ã¡ãã©ã³ã®çµè«ã¯ãäŒãããŸããããããå°ãæ©èœã«ã€ããŠè©³ããç¥ãããæ¹åãã«è£è¶³ããããŠããã ããŸãã å床ã«ãªããŸãããããã€ã¹ç®¡çã®Businessãšãã£ã·ã§ã³ã§ã®åãã©ã³æ©èœæ¯èŒã¯ãã¡ãã®ããã«ãªããŸãã Business Starter Business Standard Business Plus åºæ¬ã®ãšã³ããã€ã³ã管ç â â â Android ã¢ããªã®ç®¡ç â é«åºŠãªãšã³ããã€ã³ã管ç â ãšã³ã¿ãŒãã©ã€ãº ãšã³ããã€ã³ã管ç ã¢ãã€ã«ã¢ããªãåå¥ã«é
åžãã â ããã€ã¹ç£æ»ãã° â 䜿ãããŠããªãäŒç€Ÿææããã€ã¹ã«é¢ããã¬ããŒã â äŒç€Ÿææã® Android ããã€ã¹ â äºé
ããè£è¶³ããŠãããŸãã åºæ¬ã®ãšã³ããã€ã³ã管ç åºæ¬ã®ãšã³ããã€ã³ã管ç ã¯GWSã®Business Starterãã©ã³ããBusiness PlusãŸã§å
šãŠã®ãã©ã³ã§å©çšå¯èœã§ãã ãŸããåºæ¬ã®ãšã³ããã€ã³ã管çã«ã¯ä»¥äžã®æ©èœãå«ãŸããŸãã ã»ãã¥ãªãã£èšå® ã»ãã¥ãªãã£èšå®ã§ã¯ã¢ãã€ã«ããã€ã¹ã«å¯ŸããŠãã¹ã³ãŒãã®äœ¿çšãå¿
é åããWindowsPCã«ãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ããäºã«ãã£ãŠGWSã®ã¢ã«ãŠã³ãã§ãã°ã€ã³ããäºãå¯èœã«ãªããŸãã åºæ¬çãªãã¹ã³ãŒãã®é©çšïŒã¢ãã€ã«ïŒ Windows çš Google èªèšŒæ
å ±ãããã€ã ããã€ã¹ã®ç®¡ç ããã€ã¹ã®ç®¡çã§ã¯ã¢ãã€ã« ããã€ã¹ãããŠãŒã¶ãŒã®ã¢ã«ãŠã³ããã¯ã€ãããèªçµç¹ã®Chromeãå©çšããŠãããŠãŒã¶ãŒããªã¢ãŒãã§ãã°ã¢ãŠããããã€ã¹äžã®ããœã³ã³çãã©ã€ãã«é¢ããæ
å ±ã確èªãªã©ãå¯èœã§ãã åºæ¬çãªã¢ãã€ã« ããã€ã¹ç®¡ç ããœã³ã³ã®åºæ¬ç®¡ç ãšã³ããã€ã³ãã®ç¢ºèª ããœã³ã³çãã©ã€ã ããã€ã¹ã®ããã㯠ã¢ã«ãŠã³ãã®ãªã¢ãŒãã¯ã€ãïŒã¢ãã€ã«ïŒ ãªã¢ãŒã ãã°ã¢ãŠãïŒããœã³ã³ïŒ ã¢ããªã®ç®¡ç ã¢ããªã®ç®¡çã§ã¯ç®¡çè
ãèšå®ããã¢ããªããŠãŒã¶ãŒãèŠã€ããŠã€ã³ã¹ããŒã«ããäºãã§ããä»äºçšãŸãã¯åŠæ ¡çšãšããŠã¢ããªç®¡çã§ããŸãã ãã ãBusiness Starterã§ã¯ç®¡ç察象ã¢ããªãèªåã€ã³ã¹ããŒã«ããããããã¯ãããããæ©èœã¯ãããŸããã äžè¬å
¬éããã³éå®å
¬éã® Android ã¢ããªã®éžæ ããã€ã¹ã®è©³çް ããã€ã¹ã®è©³çްã§ã¯ã¢ãã€ã«ããã€ã¹ããšã³ããã€ã³ãã®åºæ¬çãªæ
å ±ïŒçš®é¡ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãããã€ã¹IDïŒã管ç察象ããã€ã¹ã®æ°ã®æšç§»ãªã©ã確èªåºæ¥ãŸãã åºæ¬ç㪠ã¢ãã€ã« ããã€ã¹ ãš ãšã³ããã€ã³ã ã®è©³çް ããã€ã¹ ã¬ããŒã äŒç€Ÿææã®ããœã³ã³ã®ã€ã³ãã³ã㪠é«åºŠãªãšã³ããã€ã³ã管ç é«åºŠãªãšã³ããã€ã³ã管ç ã¯Business Plus以äžã®ãã©ã³ã§å©çšå¯èœã§ãã é«åºŠãªãšã³ããã€ã³ã管çã§ã¯ç«¯æ«ã®ç£èŠã ãã§ãªãå¶åŸ¡ãããMobile Device Management (MDM)ã®èŠçŽ ãå ãã£ãŠããŸãã æ©èœãšããŠã¯ä»¥äžã®ããã«ãªããŸãã ã»ãã¥ãªãã£èšå® ã»ãã¥ãªãã£ãŒããªã·ãŒã«ããã«ã¡ã©ã®äœ¿çšèš±å¯ã®å¶åŸ¡ããAndroidã§BYODã宿œããå Žåã«äŒç€Ÿå©çšã®ã¢ããªã±ãŒã·ã§ã³ãå¥ãã ä»äºçšãããã¡ã€ã« ãå©çšå¯èœã§ãã æšæºåãšåŒ·ååã®ãã¹ã³ãŒãã®é©çš ã¢ãã€ã« ããã€ã¹ã®ã»ãã¥ãªã㣠ããªã·ãŒ Android ã®ä»äºçšãããã¡ã€ã« ãããã¯ãŒã¯ç®¡ç ïŒã¢ãã€ã«ïŒ ããã€ã¹ã®ç®¡ç 詳现管çã«ãããããã¯ç»é¢éç¥ãªã©ã®ã¢ãã€ã« ããã€ã¹æ©èœã®å¶éãããã€ã¹ã®æå·åã®åŒ·å¶ãAndroid ããã€ã¹ / iPhone / iPad äžã®ã¢ããªã®ç®¡çãããã€ã¹ããã®ããŒã¿ã¯ã€ããè¡ããŸãã iPhone / iPadã詳现管çããã«ã¯ Apple ããã·ã¥èšŒææž ãèšå®ããŸãããã ã¢ãã€ã«ã®è©³çŽ°ç®¡ç Windows ããã€ã¹ç®¡ç * ããã€ã¹ã®æ¿èª ããã€ã¹ã®ãªã¢ãŒãã¯ã€ã ã¢ããªã®ç®¡ç äžéšã® Android ã¢ããªã§ã¯ 管ç察象ã¢ã㪠ãšããŠèšå®ãä¿åããäºãå¯èœã§ãäŸãã°Wi-Fi ã«æ¥ç¶ãããŠãããšãã«ã®ã¿ããŒã¿ãåæãããã©ããã®å¶åŸ¡ãå¯èœã§ãã iOS ã¢ããªã®ç®¡ç éå®å
¬éã® Android ãŠã§ãã¢ã㪠ã¢ãã€ã«ã¢ããªãåå¥ã«é
åžãã â Android ã¢ããªã®èšå® ããã€ã¹ã®è©³çް ããã€ã¹ã®ããã€ã¹IDã ãã§ãªãã·ãªã¢ã«çªå·ãªã©ã®ååŸãªã©ãã现ããéšåã®æ
å ±ãååŸããäºãå¯èœã§ãã äŒç€Ÿææã®ã¢ãã€ã« ããã€ã¹ã®ã€ã³ãã³ã㪠ã¢ãã€ã« ããã€ã¹ã®è©³çްã¬ããŒã ããã€ã¹ç®¡çã«ã€ããŠã¯æ©èœãå€ããã©ã³ã«ãã£ãŠã®éããåããã«ããéšåããããããããŸãã ãããªæã¯åŒç€Ÿã«ãæ°è»œã«ã声ãããã ãããã Google Workspaceãå°å
¥ãããªãæ ªåŒäŒç€ŸG-genã«ãçžè«ãã ããã æ ªåŒäŒç€ŸG-genã§ã¯Google Workspace / Google CloudïŒGCPïŒã5%å²åŒã§ãæäŸããŠãããŸãã g-gen.co.jp ãŸããGoogle Workspace / Google CloudïŒGCPïŒ/ Chrome book ã®å°å
¥ããéçšãŸã§ã®ãæ¯æŽãè¡ã£ãŠããŸãã®ã§ãæ€èšã®éã«ã¯ãã²ã声ãããã ããã ãåãåããã¯ãã¡ããã docs.google.com
G-gen ã®ææã§ããGoogle Cloud (æ§ç§° GCP) ã®ãããŒãžã㪠DNS ãµãŒãã¹ã§ãã Cloud DNS ã§ãå
æ¥å°ã£ãããšãçºçããŸãããåãããšãèµ·ãããšãã«èª°ãã®å©ãã«ãªãããã顿«ãšè§£æ±ºæ³ãèšèŒããŸãã ããããã£ãããš ãšã©ãŒã¡ãã»ãŒãž è§£æ±ºæ¹æ³ 泚æç¹ ããããã£ãããš Google Cloud (æ§ç§° GCP) ã®ãã«ãããŒãžã㪠DNS ãµãŒãã¹ã§ãã Cloud DNS ã§ããããã¡ã€ã³ã管çããŠããŸããããã仮㫠example.com ãšããŸãã ããæ¥ããšããçç±ãããããªãã¯ãŸãŒã³ã§ãã example.com ãå¥ã® Google Cloud ãããžã§ã¯ãã® Cloud DNS ã«ç§»åããå¿
èŠæ§ãåºãŠããŸããã åœåèããç§»è¡æ¹æ³ã¯ã以äžã®éãã§ãã ç§»è¡å
ãããžã§ã¯ãã«ãããªãã¯ãŸãŒã³ example.com ãäœæãã ç§»è¡å
ãŸãŒã³ãã gcloud ã³ãã³ãã«ããã¬ã³ãŒãã®å
容ã ãšã¯ã¹ããŒã ããç§»è¡å
ãŸãŒã³ã« ã€ã³ããŒã ãã ãååãããã³ã åŽã«ãç§»è¡å
ãŸãŒã³ã®æ°ãã NS ã¬ã³ãŒããç»é²ãã ãšã©ãŒã¡ãã»ãŒãž ããããªãããå
ã»ã©ã®æé 1. ã§ç§»è¡å
ãããžã§ã¯ãã«ãããªãã¯ãŸãŒã³ãäœæããããšãããšããã以äžã®ãããªãšã©ãŒã¡ãã»ãŒãžãåºãŠããŸããŸããã http://www.google.com/webmasters/verification/ ã§ã(ãã¡ã€ã³å)ããã¡ã€ã³ïŒãŸãã¯èŠªïŒã®æææš©ã確èªããŠãããããäžåºŠã詊ããã ãã ãšã©ãŒã¡ãã»ãŒãž ãã®ãšã©ãŒã§ããã以äžã®ãããªæ¡ä»¶ã®ãšãã«åºãŠããŸãããã§ãã æ¢ã« Cloud DNS ããã㯠Google Domains ã§ãã¡ã€ã³åã® DNS ã管çããŠãã ãã®ç¶æ
ã§ Cloud DNS ã«åããã¡ã€ã³åã®ãããªãã¯ãŸãŒã³ãäœæãã ãã£ããè±èªçã®ãšã©ãŒã¡ãã»ãŒãžãåãããšã倱念ããŠããã®ã§ããã ãã®å
¬åŒããã¥ã¡ã³ã ã«èšèŒãããŠãã Verify ownership of the example.com domain (or a parent), and then try again. ã«è©²åœããŠããããã§ãã è§£æ±ºæ¹æ³ ãã®ãšã©ãŒã¡ãã»ãŒãžã¯ããã¡ã€ã³åã®æªçšã鲿¢ããããã« Google ã® DNS ã§æ¢ã«ç®¡çäžã®ãã¡ã€ã³åã«ã€ããŠããããªãã¯ãŸãŒã³ãäœæããããšãã« Google åŽããã¡ã€ã³ã®æææš©ã確èªããããã«åºãã¡ãã»ãŒãžã§ãã ãšã©ãŒã¡ãã»ãŒãžã«ãã http://www.google.com/webmasters/verification/ ã«ã¢ã¯ã»ã¹ã Google ã® ãŠã§ããã¹ã¿ãŒ ã»ã³ãã©ã« ã«ãŠãã¡ã€ã³åãç»é²ããŸãã ãŠã§ããã¹ã¿ãŒ ã»ã³ãã©ã« 㯠Google æ€çŽ¢çµæã®é äœã®ç£èŠã管çãæ¹åãªã©ã®ããã« Google ã«ãã£ãŠæäŸãããŠãã Google Search Console ã®äžéšã§ãã ãŠã§ããã¹ã¿ãŒã»ã³ãã©ã« ããããã£ã远å ãæŒäžããŠãã¡ã€ã³åã®ç»é²ãé²ããŸãã ãã¡ã€ã³ã®æææš©ã®ç¢ºèªã«ã¯ã Google ã®æå®ãã HTML ãã¡ã€ã«ãåãã¡ã€ã³ãæã€ãŠã§ããµã€ãã«ã¢ããããŒããããªã©ã®æ¹æ³ããããŸããããã¡ã€ã³ã®ãŸãŒã³ã« TXT ã¬ã³ãŒãã CNAME ã¬ã³ãŒãã远å ããæ¹æ³ãéžæã§ããŸãã ãã¡ã€ã³åã®æææš©ã®ç¢ºèª æç€ºããã TXT ã¬ã³ãŒããç§»è¡å
ãŸãŒã³ã«ç»é²ããŠæææš©ã確èªãããšããããã以éã¯ç§»è¡å
ãããžã§ã¯ãã«åããã¡ã€ã³åã§ãããªãã¯ãŸãŒã³ãäœæããããšãå¯èœã«ãªããç¡äº DNS ãŸãŒã³ãç§»è¡ããããšãã§ããŸããã æ³šæç¹ äžé£ã®äœæ¥ã¯ãåãäœæ¥è
ã® Google ã¢ã«ãŠã³ãã§å®æœããå¿
èŠããããŸãã ãã¡ã€ã³åã®æææš©ã®ç¢ºèªã¯ Google ã¢ã«ãŠã³ãã«çŽä»ããŠããããã§ãã®ã§ãæææš©ã確èªããã Google ã¢ã«ãŠã³ãã§ãŸãŒã³ã®äœæçãè¡ãå¿
èŠããããŸãã ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãTwitter ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
ä»åã¯çãããåç¥Google Workspace(æ§G Suite)ã®ãªã¹ã¹ã¡ãã©ã³æ¯èŒã«ãªããŸãã å人ã§Gmailã¯äœ¿ã£ãŠããã©äŒç€ŸãããŒã ã§å©çšããäºã¯ç¡ããæ€èšããŠãããã©ã©ã®ãã©ã³ãéžã¹ã°ããã®ããªïŒBusinessãEnterpriseã£ãŠãããã©åãšãã£ã·ã§ã³ã®éãã£ãŠäœã ããïŒããããæ¹ãžãåèã«ãªãã°å¹žãã§ãã Google Workspace æŠèŠ ãšãã£ã·ã§ã³ Business ãš Enterprise ã®æ¯èŒ ã¢ã«ãŠã³ãæ°äžé äž»èŠãªæ©èœæ¯èŒ Business ãšãã£ã·ã§ã³å
ã®æ¯èŒ æ¯èŒè¡š Businessãã©ã³ã®éžã³æ¹ Business Starter ãéžæããã±ãŒã¹ Business Standard ãéžæããå Žå Business Plus ãéžæããå Žå Google Workspace ã®å°å
¥ æŠèŠ Google Workspace ã® å
¬åŒãµã€ã ã«ã¯ãããããåãæ¹ã«å¯Ÿå¿ããçç£æ§åäžãšã³ã©ãã¬ãŒã·ã§ã³ã®ããŒã«ãããšããããŸãåŸæ¥å¡ã®çç£æ§ = ããŒã x äŒç€Ÿã®æå = ã³ãã¥ãã±ãŒã·ã§ã³ + ã³ã©ãã¬ãŒã·ã§ã³ãšèšãæããäºãåºæ¥ãŸãã ãã®çµç¹ã®ã³ãã¥ãã±ãŒã·ã§ã³ãšã³ã©ãã¬ãŒã·ã§ã³ãäžæ¯ããä¿é²ããããŒã«ã Google Workspace ã§ãã Google Workspace ã®ç¹åŸŽãšããŠåããŒã«ãç¬ç«ããŠååšããã®ã§ã¯ç¡ããããŒã ã®åãæå€§åããçºã«åã
ã®ããŒã«ãå¯ã«é£æºããŠããäºã«ãããŸãã äŸãã°éåžžã¯ãã£ãããšããã¥ã¡ã³ãäœæã¯å¥ã
ã®äŒç€Ÿã®ããŒã«ãå©çšããŠããå Žåãããã§ããããGoogle Workspaceã§ã¯ãã£ããããããªäŒè°ãªã©ã§ã³ãã¥ãã±ãŒã·ã§ã³ãåããªããã·ãŒã ã¬ã¹ã«è³æäœæãããäºãå¯èœã§ãã G-gen 瀟ã¯ãå
šå¡ãã«ãªã¢ãŒãã§å€åããŠããŸããPC 端æ«ã¯ ChromebookãããŒã«ãšã㊠Google Workspace ã䜿ã£ãŠä»äºãããŠããŸãããªã¯ã«ãŒãã®é¢ã«ãããŠããããã£ãåãæ¹ãã¢ããŒã«åºæ¥ããšããã®ã¯äŒæ¥ã«ãšã£ãŠå€§ããªã¢ããã³ããŒãžã«ãªãã®ã§ã¯ãªãã§ããããã Google Workspace ã®è©³çްã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp ãšãã£ã·ã§ã³ 以äžã¯ãå
¬åŒã®ãã©ã³ã»æéããŒãžã§ãã workspace.google.co.jp ãšãã£ã·ã§ã³ã倧ããåãããš Business ãš Enterprise ã«åãããŸããEnterprise ãšãã£ã·ã§ã³ã¯ Business ãšãã£ã·ã§ã³ã®äžäœãšãã£ã·ã§ã³ã§ãã Business ãš Enterprise ã®æ¯èŒ ã¢ã«ãŠã³ãæ°äžé ãŸã㯠Businessã®æäžäœãšãã£ã·ã§ã³ã§ãã Business Plus ãš Enterprise ãæ¯èŒããŠã¿ãŸãããŸãã¯äžçªåãããããç¹ãšããŠãã¢ã«ãŠã³ãæ°ã®äžéããããŸãã ã Business Plus Enterprise å©çšå¯èœäººæ° 300人ãŸã§ ç¡å¶é äžèšã§ã¯ Enterprise ãšãã£ã·ã§ã³ã¯ã²ãšæ¬ãã«ãªã£ãŠããŸãããå®éã«ã¯ Enterprise Essentials ã Enterprise Standard ãEnterprise Plus** ã«åãããŠããŸãã Google Workspace ãå©çšãã人æ°ã 300å以äžã§ãããEnterpriseãå©çš ããããšã«ãªããŸãã ãŸã300å以äžã®å Žåã§ããPC 端æ«ãã¹ããŒããã©ã³ã管çäžã«çœ®ããŠç£èŠãå¶éãããããå Žåã«ã Enterprise ãæ€èšå¯Ÿè±¡ã«ãªããŸãã äž»èŠãªæ©èœæ¯èŒ åèãšã㊠Business ãšãã£ã·ã§ã³ã®æäžäœãã©ã³ã§ãã Business Plus ãš Enterprise ã®åãã©ã³ã§ã®ãäž»ãªæ©èœæ¯èŒãèšèŒããŸãã 2011幎11æçŸåšã®æ
å ±ã§ãã®ã§ãææ°æ
å ±ã¯ä»¥äžã®å
¬åŒããã¥ã¡ã³ãããåç
§ãã ããã åè : Google Workspace ã®åãšãã£ã·ã§ã³ã®æ¯èŒ Business Plus Enterprise Essentials Enterprise Standard Enterprise Plus åºæ¬æ
å ± æé¡æéïŒ1ãŠãŒã¶ãŒãããâ»çšå¥ïŒ 2,040å ãåãåãã ãåãåãã ãåãåãã ãŠãŒã¶ãŒäžéæ° 300人 æå®ãªã æå®ãªã æå®ãªã ã¹ãã¬ãŒãžã®å®¹é 5 TB *5人以äžã®ãŠãŒã¶ãŒãå¿
èŠ ïŒ4人以äžã®å Žåã¯ïŒTBïŒ 1TB å¿
èŠã«å¿ããŠæ¡åŒµå¯èœ å¿
èŠã«å¿ããŠæ¡åŒµå¯èœ ã¡ãŒã« Gmail â â â IMAP ã¯ã©ã€ã¢ã³ããš POP ã¯ã©ã€ã¢ã³ã â â â Google Meet äŒè°ãããã®åå è
æ°ã®äžé 250 150 250 250 ãã¡ã€ã³å
ããã³ä¿¡é Œã§ãããã¡ã€ã³ã®ã©ã€ã ã¹ããªãŒãã³ã° 1äžäºº 10äžäºº Google Chat Chat ã§ã®ãã¡ã€ã«ã®å
±æã管çãã â â â Chat ãšãµãŒãããŒãã£è£œã¢ãŒã«ã€ã ãœãªã¥ãŒã·ã§ã³ãšã®é£æº â â Google ã°ã«ãŒã ã°ã«ãŒã ã¡ã³ããŒã粟æ»ãã â â ã°ã«ãŒã ã¡ã³ããŒãå¶éãã â â åçã°ã«ãŒãïŒã¡ã³ããŒã·ãããèªåçã«ç®¡çïŒ â â ãã¹ãããã°ã«ãŒãã®ã¡ã³ããŒã確èªïŒéæ¥çãªã¡ã³ããŒïŒ â â ã»ãã¥ãªãã£ãš ããŒã¿ä¿è· ä¿¡é Œã§ããå€éšãã¡ã€ã³ãšã®é£æº â â â ããŒã¿æå€±é²æ¢ïŒDLPïŒ â â ãŠãŒã¶ãŒãšããã€ã¹ã®ç¶æ³ã«åºã¥ãã¢ã¯ã»ã¹å¶åŸ¡ â â Google ãµãŒãã¹ã®ã»ãã·ã§ã³ç¶ç¶æéãèšå®ãã â â â Cloud Identity Premium â â ã»ãã¥ãªã㣠ã»ã³ã¿ãŒ: ã»ãã¥ãªã㣠ããã·ã¥ããŒã â â ã»ãã¥ãªã㣠ã»ã³ã¿ãŒ: ã»ãã¥ãªãã£èª¿æ»ããŒã« â â ã»ãã¥ãªã㣠ã»ã³ã¿ãŒ: ã»ãã¥ãªãã£ã®ç¶æ³ããŒãž â â Fundamental ããŒã¿ ãªãŒãžã§ã³ â â Enterprise ããŒã¿ ãªãŒãžã§ã³ â ã¯ã©ã€ã¢ã³ããµã€ãæå·åïŒããŒã¿çïŒ â ç§»è¡ãããã¯ã HCL Notes ããç§»è¡ãã â â â ã¬ããŒããšç£æ»ãã° ãã©ã€ãã®è©³çްãªç£æ»ãšã¬ããŒã â â â BigQuery ãžã®ã¬ããŒãã®ãšã¯ã¹ããŒã â â 管çã¢ã¯ãã£ããã£ã®ã¢ã¯ã»ã¹ã®éææ§ãã° â ãŠãŒã¶ãŒã«é¢ããã¯ãŒã¯ ã€ã³ãµã€ã ã¬ããŒã â ãµãŒãããŒãã£è£œ ã¢ããªãšã®é£æº ã»ãã¥ã¢ LDAP: LDAP ããŒã¹ã®ã¢ããªããµãŒãã¹ãæ¥ç¶ãã â â â ãã¹ã¯ãŒããä¿ç®¡ãããã¢ããªãžã®ã¢ã¯ã»ã¹ã管çãã â â ããã€ã¹ç®¡ç ã¢ãã€ã«ã¢ããªãåå¥ã«é
åžãã â â â ããã€ã¹ç£æ»ãã° â â â 䜿ãããŠããªãäŒç€Ÿææããã€ã¹ã«é¢ããã¬ããŒã â â â äŒç€Ÿææã® Android ããã€ã¹ â â â äŒç€Ÿææã® iOS ããã€ã¹ â â Windows ããã€ã¹ç®¡ç â â iOS ããŒã¿ã®ä¿è· â â ããã€ã¹ã®ãªã¢ãŒãã¯ã€ãïŒWindowsïŒ â â ã¢ãã€ã« ããã€ã¹ã®èšŒææž â â 管çã«ãŒã« â â ãã©ã€ã ããã¥ã¡ã³ããšãã£ã¿ ã³ãã¯ããã ã·ãŒã â â â çµç¹ã®ãã©ã³ãã£ã³ã°ïŒã«ã¹ã¿ã ãã³ãã¬ãŒãïŒ â â â Chrome ãã©ãŠã¶ã§ãã©ã€ãã®ãã¡ã€ã«åè£ã®äœ¿çšãèš±å¯ãã â åè¿°ã®ãšãã Business Plus ã§ãäž»èŠãªæ©èœã¯ãµããŒããããŠããŸãããã©ã€ãã¹ããªãŒãã³ã°ãããã€ã¹å¶åŸ¡ã管çãã¬ããŒãã£ã³ã°ãšèšã£ãæ©èœã¯å©çšåºæ¥ãŸããã ãŸã Enterprise Essentials ã¯ã300å以äžã§ Google Workspace ãå©çšãããããã¡ãŒã«ã·ã¹ãã ã¯ä»ã«æã£ãŠããããçŽã¡ã«ç§»è¡ããããšã¯é£ãããããŸãã¯ã³ãã¥ãã±ãŒã·ã§ã³ïŒGoogle ChatïŒãã³ã©ãã¬ãŒã·ã§ã³ïŒãã©ã€ããããã¥ã¡ã³ããšãã£ã¿ïŒã ãå©çšãããããšãã£ããŠãŒã¹ã±ãŒã¹ã§ããããã§ããHCL Notes ããã®ç§»è¡ãå«ãŸããŠããã®ã Enterprise ãªãã§ã¯ãšèšããã§ãããã Enterprise ã®ãšãã£ã·ã§ã³ã«é¢ããŠã¯æ€èšãã¹ãèŠä»¶ãå€ãããããã²åœç€ŸãŸã§ãçžè«ãã ããã g-gen.co.jp Business ãšãã£ã·ã§ã³å
ã®æ¯èŒ æ¯èŒè¡š 次㫠Business ã«åé¡ããã3ã€ã®ãšãã£ã·ã§ã³ Business Starter ã Business Standard ã Business Plus ãæ¯èŒããŸãã Business Starter Business Standard Business Plus åºæ¬æ
å ± æé¡æéïŒ1ãŠãŒã¶ãŒãããâ»çšå¥ïŒ 680å 1,360å 2,040å å©çšå¯èœäººæ° 1ã300å 1ã300å 1ã300å ã¹ãã¬ãŒãžå®¹é 30GB 2TB 5TB 24æé365æ¥ã®é»è©±ãµããŒã â â â ã³ã¢ãµãŒãã¹ Gmailãšã«ã¬ã³ã㌠â â â Cloud Searchã«ãããã¡ã€ã³å
æ€çŽ¢ â â Google Vault â Google Chat â â â ãã©ã€ããš ããã¥ã¡ã³ã ããã¥ã¡ã³ãã®äœæ â â â ããŒã åãå
±æãã©ã€ã â â â Google Meet äŒè°ãããã®åå è
æ°ã®äžé 100å 150å 250å äŒè°ã®é²ç»ãšãã©ã€ããžã®ä¿å â â ãã€ãº ãã£ã³ã»ã« â â ãã¬ã€ã¯ã¢ãŠã ã«ãŒã â â ã»ãã¥ãªãã£ãš ããŒã¿ä¿è· ä¿¡é Œã§ããå€éšãã¡ã€ã³ãšã®é£æº â â ããŒã¿ãªãŒãžã§ã³ã®éžæ â â ããã€ã¹ç®¡ç åºæ¬ã®ãšã³ããã€ã³ã管ç â â â é«åºŠãªãšã³ããã€ã³ã管ç â ã¢ãã€ã«ã¢ããªã®åå¥é
åž â Businessãã©ã³ã®éžã³æ¹ Business Starter ãéžæããã±ãŒã¹ ãŸãã¯å°äººæ°ïŒ10å以äžïŒã§ã³ã¹ããæã㊠Google Workspace ã䜿ã£ãåãæ¹ã«ãã£ã¬ã³ãžãããå Žåã«ãªã¹ã¹ã¡ããŸãã äž»èŠãªæ©èœã§ããããã¥ã¡ã³ãäœæãã¡ãŒã«ãã«ã¬ã³ããŒããããªäŒè°ããã£ãããªã©ãå©çšããäºãåºæ¥ãŸãã äŸãã°å
šç€Ÿã«å°å
¥ããåã«å°äººæ°ã§ãã¹ãçã«å©çšããŠã¿ãã®ãè¯ãã§ãããã Business Standard ãéžæããå Žå ããå
±åäœæ¥ïŒã³ã©ãã¬ãŒã·ã§ã³ïŒãä¿é²ããçç£æ§åäžãã¯ããããå Žåã«ãªã¹ã¹ã¡ããŸãã Business Standard ããã¯ã¹ãã¬ãŒãžã®å®¹éãäžæ°ã«1ãŠãŒã¶ãŒãããïŒTBãŸã§å¢ããŸãã ãŸããããªäŒè°ã§ã¯ãäŒè°ã®é²ç»ãããã€ãºãã£ã³ã»ã«ãããã¬ã€ã¯ã¢ãŠãã«ãŒã ããªã©ããªã³ã©ã€ã³äŒè°ã ããããã®ã³ã©ãã¬ãŒã·ã§ã³æ©èœã匷åãããŸãã ãŸãåäžãã¡ã€ã³å
ã® Gmailããã©ã€ããããã¥ã¡ã³ããã«ã¬ã³ããŒãªã©ã«å«ãŸããããŒã¿ãå
æ¬çã«æ€çŽ¢ãææ¡ãããCloud Searchããå©çšããäºãå¯èœãšãªããŸãã Business Plus ãéžæããå Žå 倧容éã®ã¹ãã¬ãŒãžãšæŽã«ã»ãã¥ãªãã£ãé«ãããå Žåã«ãªã¹ã¹ã¡ããŸãã Business Plus ã§ã¯ã¹ãã¬ãŒãžã®å®¹éã1ãŠãŒã¶ãŒãããïŒTBã«ãªããŸãã ããã« Business Standard ã®æ©èœã«å ã㊠Google Workspace ã®ããããããŒã¿ã®ä¿æãæ€çŽ¢ãæžãåºããè¡ãããšãã§ããæ
å ±é瀺ã»ã¬ããã³ã¹ã®çºã®ãGoogle Vaultãããšã³ããã€ã³ã管çãªã©ããã»ãã¥ãªãã£ã«éç¹ã眮ããæ©èœã匷åãããŸãã å®å
šã« Google ãµãŒãã¹ã掻çšãããå Žåã«ã¯ãã²æŽ»çšãã ããã Google Workspace ã®å°å
¥ Google Workspace ãå°å
¥ãããªãæ ªåŒäŒç€ŸG-genã«ãçžè«ãã ãããGoogle Workspace ã䜿ã£ãåãæ¹ã«å€ãããšæ¬åœã«çµç¹ã®ã³ãã¥ãã±ãŒã·ã§ã³ãšã³ã©ãã¬ãŒã·ã§ã³ã®ããæ¹ãå€ãã£ãŠãé©ãã¯ãã§ãã ãã®æåãããå€ãã®äººã«äœæããŠãããããã§ããã æ ªåŒäŒç€Ÿ G-gen ã§ã¯ Google Workspace / Google Cloud (æ§ç§° GCP) ã5%å²åŒã§ãæäŸããŠãããŸãã g-gen.co.jp ãŸã Google Workspace / Google Cloud / Chromebook ã®å°å
¥ããéçšãŸã§ã®ãæ¯æŽãè¡ã£ãŠããŸãã®ã§ãæ€èšã®éã«ã¯ãã²ã声ãããã ããã æž¡é å®£ä¹ (èšäºäžèЧ) ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš ããŒã¿åæåºç€ã®æ§ç¯ãã¯ã©ãŠã管çéçšããããã¯ãŒã¯ãå®åç¯å²ãGoogle Workspace æŽ»çšæšé²äžãGoogle Cloud èªå®è³æ Œã¯4è³æ Œä¿æ 鱿«ãã©ãã°ã©ãã¡ãŒã§ãèŠ³èæ€ç©ã塿 ¹æ€ç©ã«ããã£ãŠãŸãã
G-genã®ææã§ãã Cloud Logging 㯠Google CloudïŒæ§ç§° GCPïŒäžã®ã·ã¹ãã çãçæãããã°ãåéã»ä¿ç®¡ã»ç®¡çããä»çµã¿ã§ããåºæ¬çãªæŠå¿µãä»çµã¿ã解説ããŠãããŸãã Cloud Logging æŠèŠ Cloud Logging ãšã¯ 察象ã®ãã° ãã°ã®ä¿åå
Cloud Logging ãæ±ããã° ãã©ãããã©ãŒã ãã°ãã³ã³ããŒãã³ã ãã° ç£æ»ãã° ãŠãŒã¶ãŒäœæã®ãã° ãã«ãã¯ã©ãŠããšãã€ããªãã ã¯ã©ãŠãã®ãã° æé Cloud Logging ã®æé æåããååšãããã°ãã±ããã®æé åãèŸŒã¿æéã®ç¯çŽ ãã°ã®é²èЧ é²èŠ§æ¹æ³ ã¯ãšãªèšèª ã€ã³ããã¯ã¹ ãã°ã®é²èЧå¯èœç¯å²ãå®çŸ©ãã ãã°ãã¥ãŒ ãã°ã¹ã³ãŒã ãã°ã«ãŒãã£ã³ã°ãšãã°ã®ä¿å ãã°ã«ãŒãã£ã³ã°ãšã¯ ã·ã³ã¯ãšã¯ åæèšå®ã§ååšããã·ã³ã¯ãšãã°ãã±ãã æžã蟌㿠ID ãããžã§ã¯ãããŸããã ãã°ã®éçŽ å¥ãããžã§ã¯ãã®ã¹ãã¬ãŒãžã«ãã°ãéã çµç¹å
šäœã§ãã°ãéçŽãã éçŽã·ã³ã¯ã®çš®é¡ ãã°ç£èŠ ãã°ããŒã¹ã®ææš ãã°ããŒã¹ã®ã¢ã©ãŒã Log Analytics Log Analytics ãšã¯ å©ç𿹿³ BigQuery ããŒã¿ã»ãããšã®ãªã³ã¯ ãŠãŒã¹ã±ãŒã¹ å¶é Log Analytics ã®æé ãµãŒãã¹é飿º Cloud Run functions ã®ãã° Compute Engine VMïŒWindowsïŒã®ãã° Tips Cloud Logging æŠèŠ Cloud Logging ãšã¯ Cloud Logging ïŒæ§ç§° Stackdriver LoggingïŒã¯ Google Cloud äžã®ã·ã¹ãã çãçæãããã°ãåéã»ä¿ç®¡ã»ç®¡çããä»çµã¿ã§ãã å Google Cloud ãµãŒãã¹ãåºåãããã°ã¯èªåçã« Cloud Logging ã«éçŽãããŸãããŸããCloud Logging ã® Web API ããšãŒãžã§ã³ããœãããŠã§ã¢ãéããŠãä»»æã®ãã°ãåéããããšãã§ããŸãã åéããããã°ã¯ ãã°ãã±ãã ãšåŒã°ããã¹ãã¬ãŒãžã§ä¿ç®¡ãããæéãéããã廿£ããçã®èšå®ãç°¡åã«è¡ãããšãã§ããŸãããã°ãã±ããã®ä»ã«ããCloud Logging ã BigQuery ãªã©ä»ã®ã¹ãã¬ãŒãžã«ãã°ã転éããããšã容æã§ãã ãã°ã¯ Web ã³ã³ãœãŒã«ã§ãã ãã°ãšã¯ã¹ãããŒã© ã§é²èЧã»ã¯ãšãªããããšãã§ããŸããããã«ãæå®ã®æååããã°ã«åºåãããéã«ã¢ã©ãŒããçºå ±ããèšå®ãå¯èœã§ãã 察象ã®ãã° Cloud Logging ã§åéã»ç®¡çå¯èœãªãã°ã«ã¯ã以äžã®çš®é¡ããããŸãã åè : Cloud Logging ã®æŠèŠ - ãã°ã®ã«ããŽãª çš®å¥å 説æ ãã©ãããã©ãŒã ãã° BigQuery ã Cloud Run çãã»ãšãã©ã® Google Cloud ãµãŒãã¹ã®ãã° ã³ã³ããŒãã³ããã° Google ãæäŸãããœãããŠã§ã¢ ã³ã³ããŒãã³ããçæãããã°ãGoogle Kubernetes EngineïŒGKEïŒã®ç®¡çæ©æ§ãåºåãããã°ãªã© ç£æ»ãã° Cloud Audit Logs ãã¢ã¯ã»ã¹ã®éææ§ãã°ïŒGoogle ãµããŒãçããŠãŒã¶ã®ã³ã³ãã³ãã«ã¢ã¯ã»ã¹ããéã«åºããã°ïŒ ãŠãŒã¶ãŒäœæã®ãã° ãŠãŒã¶ãŒã®ã¢ããªã±ãŒã·ã§ã³ãªã©ã«ãã£ãŠåºåãããã°ããšãŒãžã§ã³ãã API çµç±ã§åé ãã«ãã¯ã©ãŠããšãã€ããªãã ã¯ã©ãŠãã®ãã° Microsoft Azure ã Amazon Web ServicesïŒAWSïŒããåã蟌ãã ãã°ããªã³ãã¬ãã¹ããåã蟌ãã ãã° ãã°ã®ä¿åå
Cloud Logging ã®ä¿åå
ã¹ãã¬ãŒãžã¯ä»¥äžããéžæã§ããŸãã ãã°ãã±ãã Cloud Storage ãã±ãã BigQuery ããŒã¿ã»ãã Pub/Sub ããã㯠Splunk ä»ã® Google Cloud ãããžã§ã¯ã ãã°ãã±ãã 㯠Cloud Logging ç¬èªã®å°çšã¹ãã¬ãŒãžã§ããCloud Storage ãã±ãããšåç§°ã䌌ãŠããŸããã å
šãå¥ã®ãã® ã§ãããã°ãã±ããã«ä¿ç®¡ãããŠãããã°ã ããã Cloud Logging ã³ã³ãœãŒã«ã®ãã°ãšã¯ã¹ãããŒã©ããé²èЧã§ããŸãã ãã°ãã±ãããžã®ãã°ä¿ç®¡æéã¯ã以äžã®å
¬åŒããã¥ã¡ã³ããGoogle Cloud Observability ã®æéãã®ãCloud Logging ã®æéæŠèŠãéšåã«èšèŒãããŠããããã®ã³ã°ä¿æããããã«ãããã$0.01/GiBïŒ2025幎2æçŸåšïŒã§ãããCloud Storage ãã±ããã® Standard Storage ã Nearline Storage ãããå°ãå®ãäŸ¡æ Œèšå®ã§ãã åè : Google Cloud Observability ã®æé - Cloud Logging ã®æéæŠèŠ åè : Cloud Storage ã®æé - æé衚 Cloud Logging ãæ±ããã° ãã©ãããã©ãŒã ãã°ãã³ã³ããŒãã³ã ãã° ãŠãŒã¶ãŒãæèããªããšããæ§ã
㪠Google Cloud ãµãŒãã¹ã Cloud Logging ã«ãã°ãåºåããŠããŸãã ããã«ãããå©çšè
㯠Web ã³ã³ãœãŒã«ç»é¢ã§ãã¡ãã¡å Google Cloud ãµãŒãã¹ã®ç»é¢ãžé·ç§»ããªããŠããCloud Logging ã§éäžçã«ãã°ã管çã»é²èЧããããšãã§ããŸãã Cloud Run ã Cloud Run functions çã® Google Cloud ãµãŒãã¹ã§çšŒåããããã°ã©ã ã¯ãäœãèšå®ããªããŠããæšæºåºåã Cloud Logging ã«ãã°ãšã³ããªãšããŠé£æºãããŸãããã ããé©åãªãã©ãŒãããã§åºåããããšã§ SeverityïŒéèŠåºŠïŒãªã©ã®å±æ§å€ããé²èЧãããã圢ã§åºåã§ããŸãã以äžã®èšäºãåèã«ããŠãã ããã blog.g-gen.co.jp ç£æ»ãã° Cloud Audit Logs ãµãŒãã¹ã«ãã£ãŠçæããããã°ã§ãã Cloud Audit Logs ã«ã€ããŠã¯ä»¥äžã®æçš¿ã§è§£èª¬ããŠããŸãã®ã§ããã¡ããåç
§ããŠãã ããã blog.g-gen.co.jp ãŠãŒã¶ãŒäœæã®ãã° ãŠãŒã¶ãŒãæç€ºçã« Cloud Logging ã«æå
¥ãããã°ã§ãã Google Compute EngineïŒGCEïŒã® VM çãã Ops ãšãŒãžã§ã³ã ãªã©ãéããŠæå
¥ããããšãã§ããŸãã Cloud Logging ã«ãã°ãæå
¥ããããšã§ä»¥äžã®ãããªã¡ãªããã享åã§ããŸãã ãã°é²èЧã®éã«ãµãŒãã«ãã°ã€ã³ããå¿
èŠããªã ãµãŒãé害ãã¹ã±ãŒã«ã€ã³ããéã«ããã°ã倱ãããªã åæç®çã§ãã°ã BigQuery ã«æå
¥ã§ãã ãã°ã®ä¿ç®¡ãšä¿ç®¡æéã®ç®¡çïŒããŠã¹ããŒãã³ã°ïŒã容æã«å®è£
ã§ãã VM ã« Ops ãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ãããšããã©ã«ãã§ãLinux ã§ã¯ /var/log/messages ã /var/log/syslog ãã Windows ã§ã¯ System ã Application ã Security ã®ã€ãã³ããã°ãåéãããŸãã ããã©ã«ãã§åéããããã°ä»¥å€ã«ããèšå®ãã¡ã€ã«ã倿Žããããšã§ãä»»æã®ã¢ããªã±ãŒã·ã§ã³ã®ãã°ãåéããããšãã§ããŸãã 詳现ã¯å
¬åŒ ããã¥ã¡ã³ã ãåç
§ãã ããã Compute Engine ã® VM ãã Cloud Logging ã«ãã°ãéåºããæ¹æ³ã«ã€ããŠã¯ã以äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp ãã«ãã¯ã©ãŠããšãã€ããªãã ã¯ã©ãŠãã®ãã° Microsoft Azure ã Amazon Web ServicesïŒAWSïŒããåã蟌ãã ãã°ããªã³ãã¬ãã¹ããåã蟌ãã ãã°ã§ãã Ops ãšãŒãžã§ã³ãçãéããŠãGoogle Cloud 以å€ã®ãã©ãããã©ãŒã ããããã°ãåéãã管çããããšãã§ããŸãã æé Cloud Logging ã®æé Cloud Logging ã®æéã¯ãã°ã® åã蟌ã¿åŠçé ãš ã¹ãã¬ãŒãžä¿ç®¡é ã®2軞ã§ã®åŸé課éã§ãã ãåã蟌ã¿åŠçéããžã®èª²éã¯ãCloud Logging ãã°ãã±ããã«åã蟌ããã°ã®ãµã€ãºã«å¿ããŠãã¯ã³ã·ã§ããã®æéãçºçããŸãã ãã¹ãã¬ãŒãžä¿ç®¡éããžã®èª²éã¯ããã°ãã±ããã§ä¿ç®¡ããŠãããã°ã®ãµã€ãºã«å¿ããŠãç¶ç¶çã«çºçããæéã§ãã 2025幎2æçŸåšã®æéå䟡ã¯ã以äžã®ãšããã§ãã æéå å䟡 説æ åã蟌ã¿åŠçé $0.50 / GiB ã»Cloud Logging ãã°ãã±ããã«æå
¥ããããã°ã®ããŒã¿ãµã€ãºã«å¿ããŠäžåºŠã ã課é ã»æ¯æããããžã§ã¯ãããšã«æåã® 50 GiB ã¯ç¡æ ã¹ãã¬ãŒãžä¿ç®¡é $0.01 / GiB ã»ãã°ãã±ããäžã«30æ¥é以äžä¿ç®¡ããããã°ã«ã®ã¿é©çšïŒ30æ¥é以å
ã¯ç¡æïŒ ã»ãã°ã BigQuery ã Cloud Storage çãä»ãµãŒãã¹ã«è»¢éããå Žåã¯ãã¡ãã®æéãçºç ææ°ã®æéå䟡ã¯ä»¥äžã®ããŒãžãåç
§ããŠãã ããããªã以äžã®ããã¥ã¡ã³ãã§ã¯ãåè
ã®ãåã蟌ã¿åŠçéãã¯ãLogging ã¹ãã¬ãŒãžããåŸè
ã®ãã¹ãã¬ãŒãžä¿ç®¡éãã¯ããã®ã³ã°ä¿æããšè¡šçŸãããŠããŸãã åè : Google Cloud Observability ã®æé - Cloud Logging ã®æéæŠèŠ æåããååšãããã°ãã±ããã®æé Google Cloud ãããžã§ã¯ããäœæãããšãããã©ã«ãã§ _Required ãš _Default ãšãã2ã€ã®ãã°ãã±ãããååšããŠããŸãã _Required ã¯ãGoogle Cloud ãå¿
é ã§ååŸããç£æ»ç³»ã®ãã°ãæå
¥ãããç¹æ®ãªãã°ãã±ããã§ããããã«ä¿åããããã°ã¯ãåãèŸŒã¿æéãã¹ãã¬ãŒãžæéãçºçããŸããã _Default ã¯ã _Required ã«ä¿åãããã㰠以å€ã®ãã° ããã¹ãŠä¿åããããã°ãã±ããã§ãããã®ãã°ãã±ããã¯ãåæèšå®ã§ä¿ææéã30æ¥ã§ãã®ã§ãä¿ææéã倿Žããªããã°ã¹ãã¬ãŒãžæéã¯çºçããŸããããã ããåã蟌ã¿åŠçæéã¯çºçããããšã«æ³šæããŠãã ããã åãèŸŒã¿æéã«ã¯ããããžã§ã¯ãããšã«æåã®50GiBãŸã§ãç¡ææ ãšããŠçšæãããŠããŸãã®ã§ãçžåœã®ãµã€ãºãŸã§ã¯ç¡æã§åã蟌ãããšãã§ããŸãã åãèŸŒã¿æéã®ç¯çŽ ãã°ã®ããªã¥ãŒã ã倧ãããªããšã$0.50 / GiB ã®åãèŸŒã¿æéã¯ã³ã¹ããšããŠéãã®ãããã£ãŠããŸãã ãã®åãèŸŒã¿æé㯠Cloud Logging ãã°ãã±ããã«å¯ŸããŠåã蟌ããã°ãµã€ãºã«å¯ŸããŠã®ã¿ çºçããŸããã€ãŸãã以äžã®ãã°ã«å¯ŸããŠã¯æéãçºçããŸããã ã·ã³ã¯ïŒåŸè¿°ïŒã«ãã Cloud Storage ãã±ãããBigQuery ããŒã¿ã»ãããPub/Sub ãããã¯çã«ã«ãŒãã£ã³ã°ããããã° ã·ã³ã¯ã®é€å€ãã£ã«ã¿ã§é€å€ãããã° ãã°éãè«å€§ã«ãªããåãèŸŒã¿æéãå€ãçºçããŠããå Žåãé€å€ãã£ã«ã¿ã§åã蟌ããã°ããã£ã«ã¿ãªã³ã°ããããCloud Storage ã BigQuery ã«éããããšã§ãåãèŸŒã¿æéãç¯çŽã§ããŸãããã ããã«ãŒãã£ã³ã°å
ã®åãèŸŒã¿æéã¯çºçããŸãã®ã§ããã¡ãã確èªããå¿
èŠã¯ãããŸãã åè : ã¯ã©ãŠã管çè
åãã® Cloud Logging ã®æé: ãã®ã¢ãããŒããšè²»çšãåæžããæ¹æ³ äŸãšã㊠Cloud Logging ãã°ãã±ãããžã®åã蟌ã¿ãš BigQuery ãžã®ãšã¯ã¹ããŒãã§æéãæ¯èŒãããšã以äžã®éãã§ãã Cloud Logging ( åãèŸŒã¿æé ) : $0.5 /GB (2023幎5ææç¹) BigQuery ( Streaming inserts æé ) : $0.06 /GB ($0.012 per 200 MBãšè¡šèšãæ±äº¬ãªãŒãžã§ã³ã2023幎5ææç¹) BigQuery ãžãã°ããšã¯ã¹ããŒããããš Streaming inserts æéãçºçããŸãããCloud Logging ãã°ãã±ãããžã®åãèŸŒã¿æéãšæ¯èŒããŠã10åã®1è¿ãã®æéèšå®ãšãªã£ãŠããŸãã ãã°ã®é²èЧ é²èŠ§æ¹æ³ Cloud Logging ã®ãã°ãã±ããã«ä¿åããããã°ã¯ãGoogle Cloud ã® Web ã³ã³ãœãŒã«å
ã«ååšãã ãã°ãšã¯ã¹ãããŒã© ãšåŒã°ããç»é¢ã§é²èЧããããšãã§ããŸãã ãã°ãšã¯ã¹ãããŒã© ãŸãä»ã«ããgcloud ã³ãã³ãã©ã€ã³ããŒã«çãçšããŠãã°ãååŸããããšãå¯èœã§ãã åè : ãã° ãšã¯ã¹ãããŒã©ã䜿çšããŠãã°ã衚瀺ãã åè : gcloud CLI ã䜿çšããŠãã°ãšã³ããªããªã¹ã衚瀺ãã ã¯ãšãªèšèª ãã°ãšã¯ã¹ãããŒã©ã gcloud ã³ãã³ãã§ã¯ãç¬èªã®ã¯ãšãªèšèªã§ãã Logging query language ãçšããŠããã°ããã£ã«ã¿ããŠè¡šç€ºãããããšãã§ããŸãã Logging query language ã¯ããã°ãšã¯ã¹ãããŒã©ããçŽæçã«çæããããšãã§ããŸãã®ã§ããŒãããæéããããŠåŠç¿ããå¿
èŠæ§ã¯ãããŸãããå
¬åŒã®ãªãã¡ã¬ã³ã¹ã¯ä»¥äžã®ãªã³ã¯ããåç
§ã§ããŸãã åè : Logging ã®ã¯ãšãªèšèª 以äžã¯ãã¯ãšãªã®äŸã§ãã my-project ãšãããããžã§ã¯ãã«ããã Cloud KMS é¢é£ã®ãã°ã ããæœåºããŠããŸãã protoPayload.serviceName="cloudkms.googleapis.com" resource.labels.project_id="my-project" 以äžã®åœç€Ÿèšäºã§ã¯ãLogging query language ã«ã€ããŠè©³çްã«è§£èª¬ããŠããŸãã blog.g-gen.co.jp ã€ã³ããã¯ã¹ Cloud Logging ã«ã¯ ã€ã³ããã¯ã¹ ã®æŠå¿µããããŸãã 以äžã®ãã£ãŒã«ãã«ã¯ããã©ã«ãã§ã€ã³ããã¯ã¹ãäœæãããŠãããã¯ãšãªã«å«ããããšã§ããã°æœåºãé«éåã§ããŸãã resource.type resource.labels.* logName severity timestamp insertId operation.id trace httpRequest.status labels.* split.uid ãŸããã°ãã±ããããšã«ããã£ãŒã«ãã«å¯Ÿã㊠ã«ã¹ã¿ã ã€ã³ããã¯ã¹ ãæç€ºçã«æå®ããããšãã§ããŸãã åè : Configure custom indexing ãã°ã®é²èЧå¯èœç¯å²ãå®çŸ©ãã ãã°ãã¥ãŒ ãã°ãã¥ãŒ ãšã¯ããã°ãã±ããã«ä¿åãããŠãããã°ã®äžéšã®ã¿ïŒãã°ã®ãµãã»ããããšè¡šçŸããŸãïŒãå©çšè
ã«é²èЧããããå Žåã«ãäºåã«å®çŸ©ãããã°ç¯å²ã®ã¿ã®é²èŠ§æš©éãä»äžã§ããæ©èœã§ãã ãã°ãã¥ãŒã§ã¯ã察象ã®ãã°ãã±ãããšãLogging query language ã§èšè¿°ãããã£ã«ã¿ãå®çŸ©ããŸãã管çè
ã¯ãã°é²èЧè
ã®ããã«ããã®ãã°ãã¥ãŒã«å¯Ÿããé²èŠ§æš©éãä»äžããŸããããã«ãããé²èЧè
ã¯å®çŸ©ããããã°ãã±ããå
ã®ãã£ã«ã¿ããããã°ã ããé²èЧã§ããããã«ãªããŸãã 詳现ãšå
·äœçãªæé ã¯ä»¥äžã®ããã¥ã¡ã³ããåç
§ããŠãã ããã åè : ãã°ãã±ããã®ãã°ãã¥ãŒãæ§æãã ãã°ã¹ã³ãŒã ãã°ã¹ã³ãŒã ãšã¯ãè€æ°ã® Google Cloud ãããžã§ã¯ãã® Cloud Logging ãã°ããæšªæããŠé²èЧããããã®æ©èœã§ãã éåžžããã°ãšã¯ã¹ãããŒã©ã§ã¯ãåäžã®ãããžã§ã¯ãã®ãã°ãã±ããã察象ãšãããã°ã®ã¯ãšãªã»é²èЧããã§ããŸããã ãã°ã¹ã³ãŒãã䜿ããšãè€æ°ã®ãããžã§ã¯ãããã°ãã¥ãŒãã°ã«ãŒãã³ã°ããããšãã§ããŸãããã°ãšã¯ã¹ãããŒã©äžã§ãã°ã¹ã³ãŒãã察象ã«ããŠã¯ãšãªãæå
¥ãããšãè€æ°ã®ãããžã§ã¯ãããã°ãã¥ãŒã暪æããŠãã°ãæ€çŽ¢ãããŸãã ãã°ã¹ã³ãŒãèªäœã¯ããããžã§ã¯ãã¬ãã«ã®ãªãœãŒã¹ãšããŠãããžã§ã¯ãå
ã«äœæããŸãã åœæ©èœã䜿ã£ãŠåãããžã§ã¯ãã®ãã°ãé²èЧããã«ã¯ãé²èЧè
ã察象ã®ãããžã§ã¯ãã«ãã°ã®é²èŠ§æš©éãæã£ãŠããå¿
èŠããããŸãã åè : Create and manage log scopes ãã°ã¹ã³ãŒãæ©èœã¯2025幎2æçŸåšãPreview 段éã§ãã ãã°ã«ãŒãã£ã³ã°ãšãã°ã®ä¿å ãã°ã«ãŒãã£ã³ã°ãšã¯ Cloud Logging ã§ç¹ã«éèŠãªæŠå¿µã ãã°ã«ãŒãã£ã³ã° ããã³ ã·ã³ã¯ ïŒsinkïŒã§ãããããŸããªæŠå¿µã以äžã«å³ç€ºããŸãã åè : 転éãšã¹ãã¬ãŒãžã®æŠèŠ åè : ãµããŒããããŠããå®å
ã«ãã°ãã«ãŒãã£ã³ã°ãã ãã°ã«ãŒãã£ã³ã°ã®æŠå¿µ å³ã®æäžéšã¯ããã°ã®çºçå
ã衚ããŠããŸãããããããã°ã Cloud Logging API ã«åããŠæå
¥ãããŸãã æå
¥ããããã°ã¯ ãã°ã«ãŒã¿ãŒ ãšãã Cloud Logging ã®å
éšæ©æ§ã«ãããæ¯ãåãå
ãæ±ºå®ãããŸãããã°ã«ãŒã¿ãŒã¯ ã·ã³ã¯ ãšããåå¥èšå®ãæã£ãŠããããã°ã¯ã·ã³ã¯ã«å®çŸ©ãããèšå®ã«å¿ããŠä¿åå
ã«æ¯ãåããããŸãã ãã°ã®æ¯ãåãå
ãšããŠãã°ãã±ãã ãCloud Storage ãã±ãããBigQuery ããŒã¿ã»ãããPub/Sub ãããã¯ãä»ã® Google Cloud ãããžã§ã¯ããSplunk ãæå®ããããšãã§ããŸãã ã·ã³ã¯ãšã¯ ã·ã³ã¯ 㯠Cloud Logging ã«å
¥ã£ãŠãããã°ã®æ¯ãåããããã³ã³ããŒãã³ãã§ãã API ãéã㊠Cloud Logging ã«å
¥ã£ãŠãããã°ã¯ãã·ã³ã¯ã«ãã£ãŠå®å
ã§ãããã°ãã±ããã BigQuery ãªã©ã«æ¯ãåããããŸãã ã·ã³ã¯ã¯èšå®å€ãšã㊠1. ãã°ã®ä¿åå
ã2. å
å«ãã£ã«ã¿ ã3. é€å€ãã£ã«ã¿ ãæã¡ãŸãã ãŸã 1. ãã°ã®ä¿åå
ã¯åè¿°ã®éãããã°ãã±ãããããCloud Storage ãã±ãããããBigQuery ããŒã¿ã»ãããããPub/Sub ãããã¯ãçãããããããæå®ããŸãã ãã㊠2. å
å«ãã£ã«ã¿ ãš 3. é€å€ãã£ã«ã¿ ã¯ããã®ã·ã³ã¯ãã©ã®ãã°ã ãã°ã®ä¿åå
ã«æ¯ãåããããæ±ºå®ããããã®ãã£ã«ã¿ã§ããã Logging query language ã§å®çŸ©ããŸãã以äžã®ãããªãã®ã§ãã resource.type="bigquery_dataset" AND LOG_ID("cloudaudit.googleapis.com/activity") AND protoPayload.methodName="google.cloud.bigquery.v2.DatasetService.UpdateDataset" äžèšã¯ãBigQuery ããŒã¿ã»ããã UpdateDataset ã«ããæŽæ°ããããšãã«çºçããã¢ã¯ãã£ããã£ãã°ããã£ããããããšããæå³ã§ãã åè : ãã£ã«ã¿ã®äŸ ãªããè€æ°ã®ã·ã³ã¯ã§ãã£ã«ã¿ã®èšå®ãéè€ããŠããŠãåããã°ããã£ããããããã«ãªã£ãŠããå Žåããããå
šãŠã®ã·ã³ã¯ã«ãã°ã è€è£œãããŠæ¯ãåããã ãŸãã ããšãã°ã·ã³ã¯ A ã¯ãããã°ããããã°ãã±ããã«è»¢éããèšå®ã«ãªã£ãŠãããã·ã³ã¯ B ã¯åããã°ã BigQuery ã«æå
¥ããèšå®ã«ãªã£ãŠãããšããŸãããã®å Žåã¯ããã°ãã±ãããš BigQuery ã®äž¡æ¹ã«ãåããã°ãæå
¥ãããŸãã åæèšå®ã§ååšããã·ã³ã¯ãšãã°ãã±ãã åæèšå®ã§ _Required ãš _Default ãšããã·ã³ã¯ãååšããŠããŸããããããã®ã·ã³ã¯ã¯ _Required ãš _Default ãšãããã°ãã±ããã«ãã°ãã«ãŒãã£ã³ã°ããèšå®ã«ãªã£ãŠããŸãã _Required ãã°ãã±ããã«ã¯ã管çã¢ã¯ãã£ããã£ç£æ»ãã°ããã·ã¹ãã ã€ãã³ãç£æ»ãã°ããã¢ã¯ã»ã¹ã®éææ§ãã°ããä¿åããã400æ¥éä¿åãããŸãããªãã管çã¢ã¯ãã£ããã£ç£æ»ãã°ããã·ã¹ãã ã€ãã³ãç£æ»ãã°ã㯠Cloud Audit Logs ãšããç£æ»ãã°ã®ä»çµã¿ã«ãã£ãŠååŸããããã°ã§ãã _Default ãã°ãã±ããã«ã¯ã _Required ã«å
¥ããªãå
šãŠã®ãã°ãå
¥ãããã«åæèšå®ãããŠããŸãããã®èšå®ã¯å€æŽå¯èœã§ãã ãããã®ãã±ããã«çºçããæéã¯åè¿°ã® æåããååšãããã°ãã±ããã®æé ããåç
§ãã ããã åè : ãã°ãã±ãã æžã蟌㿠ID ã·ã³ã¯ãäœæããéããã°ã®æ¯ãåãå
ãããã®ã·ã³ã¯ãæå±ãããããžã§ã¯ãã®ãã°ãã±ãã ä»¥å€ ãã§ããå Žåã æžã蟌㿠ID ïŒWriter IdentityïŒãšåŒã°ãããµãŒãã¹ã¢ã«ãŠã³ããçæãããŸãã ãã°ãã«ãŒãã£ã³ã°ããã«ã¯ããã®æžã蟌㿠ID ã«å¯ŸããŠãæžã蟌ã¿å
ãžã®æš©éãä»äžããå¿
èŠããããŸãã æžã蟌㿠ID ã®åç§°ã¯ã³ã³ãœãŒã«ã§ãã°ã·ã³ã¯ãéžæããã·ã³ã¯ã®è©³çްã衚瀺ããããæŒäžããããgcloud ã§ gcloud logging sinks describe ${SINK_NAME} ãå®è¡ããããšã§ç¢ºèªã§ããŸãã æžã蟌㿠ID ã®ç¢ºèª äŸãã°æžã蟌ã¿å
ã BigQuery ããŒã¿ã»ããã®å Žåãåœè©²ã®ãããžã§ã¯ãã BigQuery ããŒã¿ã»ããã«ãããŠãæžã蟌㿠ID ã« BigQuery ããŒã¿ç·šéè
æš©éãä»äžããå¿
èŠããããŸãã åè : ãšã¯ã¹ããŒãå
ã®æš©éãèšå®ãã ãªãã·ã³ã¯ãšåããããžã§ã¯ãå
ã®ãã°ãã±ãããžãã°ãéãéã¯ãæžã蟌㿠ID ã¯äžèŠã§ãããäœæãããŸããã æžã蟌㿠ID ã¯ã·ã³ã¯ãäœæããããšã«äžæã«çæãããŸããåŸè¿°ããéçŽã·ã³ã¯ãäœæããéã«ã¯çµç¹ã¬ãã«ããã©ã«ãã¬ãã«ã§ã·ã³ã¯ãäœæããŸãããã·ã³ã¯ãäœæãããã¬ãã«ã«ãã£ãŠæžã蟌㿠ID ã®åœåèŠåãç°ãªããŸãã No ã·ã³ã¯ã®ã¬ãã« æžã蟌㿠ID ã®åç§° 1 ãããžã§ã¯ãã«äœæãããã·ã³ã¯ã®æžã蟌㿠ID p(ãããžã§ã¯ãçªå·)-(6æ¡æ°å)@gcp-sa-logging.iam.gserviceaccount.com 2 ãã©ã«ãã¬ãã«ã§äœæãããã·ã³ã¯ã®æžã蟌㿠ID f(ãã©ã«ãçªå·)-(6æ¡æ°å)@gcp-sa-logging.iam.gserviceaccount.com 3 çµç¹ã¬ãã«ã§äœæãããã·ã³ã¯ã®æžã蟌㿠ID o(çµç¹çªå·)-(6æ¡æ°å)@gcp-sa-logging.iam.gserviceaccount.com ãããžã§ã¯ãããŸããã ãã°ã®éçŽ å¥ãããžã§ã¯ãã®ã¹ãã¬ãŒãžã«ãã°ãéã Cloud Logging ã®ã·ã³ã¯ã䜿ããå¥ã®ãããžã§ã¯ãã®ãã°ãã±ããã BigQuery ããŒã¿ã»ããã«ãã°ãã«ãŒãã£ã³ã°ããããšãã§ããŸãã ãã®å Žåãã·ã³ã¯ã®æžã蟌㿠ID ãå®å
ã®ã¹ãã¬ãŒãžã«å¯ŸããŠæžãèŸŒã¿æš©éãæã£ãŠããå¿
èŠããããŸãã ãŸãã·ã³ã¯ã®å®å
ããä»ã® Google Cloud ãããžã§ã¯ããã«ããå Žåãå®å
ãããžã§ã¯ãå
ã®ãã°ã·ã³ã¯ã«åŠçãå§ä»»ããããšãã§ããŸããæ¬¡ã®é
ã§èª¬æãããããªçµç¹æ§æã䜿ããªãå Žåã§ãããã®æ¹æ³ã§ãã°ã®åŠçã1ãããžã§ã¯ãã«éçŽããããšãå¯èœã§ãã çµç¹å
šäœã§ãã°ãéçŽãã 以äžã®ãããªçç±ã§ãçµç¹å
šäœã§ãã°ãäžã€ã®ãããžã§ã¯ãã®ãã°ãã±ããã BigQuery ã«éçŽãããèŠä»¶ãåºãŠãããããããŸããã è€æ°ãããžã§ã¯ãã®ãã°ãéçŽã㊠SIEM çã§åæããã ç£æ»ãªã©ã®çç±ã§ç£æ»ãã°ã第äžè
ã«æåºããå¿
èŠããã è€æ°ãããžã§ã¯ãã§ã¢ããªã±ãŒã·ã§ã³ã皌åããŠãããã°ã暪æããŠç¢ºèªããã ãã®éã¯ãã·ã³ã¯ãçµç¹ããã©ã«ãã®ã¬ãã«ã§äœæããé
äžã®å
šãŠã®ãããžã§ã¯ãã®ãã°ãåéããããšãå¯èœã§ãããã®ããã«è€æ°ãããžã§ã¯ãã®ãã°ãéçŽããããã®ã·ã³ã¯ã éçŽã·ã³ã¯ ïŒAggregated sinksïŒãšãããŸãã åè : çµç¹ã¬ãã«ãšãã©ã«ãã¬ãã«ã®ãã°ããµããŒããããŠããå®å
ã«ç
§åããŠè»¢éãã ã·ã³ã¯ãäœæããéã«ã ãã®ãªãœãŒã¹ãšãã¹ãŠã®åãªãœãŒã¹ã«ãã£ãŠåã蟌ãŸãããã°ãå«ãã ããªãã·ã§ã³ãæå¹åããããšã§ããã®çµç¹/ãã©ã«ãé
äžã®å
šãŠã®ãããžã§ã¯ãã«å¯ŸããŠã·ã³ã¯ãæå¹ã«ãªãããã°éçŽçšã®ãããžã§ã¯ãã«ãã°ãåéã§ããŸãã è©³çŽ°ãªæé ã¯ã以äžãåèã«ããŠãã ããã åè : çµç¹ã®ãã°ããã°ãã±ããã«ä¿åãã ã·ã³ã¯ã«ãããã°ã®éçŽ ãªããåçŽã«è€æ°ã®ãããžã§ã¯ããæšªæããŠãã°ã確èªãããå Žåãåè¿°ã®ãã°ã¹ã³ãŒãæ©èœã䜿ãããšãã§ããŸãã éçŽã·ã³ã¯ã®çš®é¡ éçŽã·ã³ã¯ã®äœææã éã€ã³ã¿ãŒã»ããåéçŽã·ã³ã¯ ïŒnon-intercepting aggregated sinkïŒãš ã€ã³ã¿ãŒã»ããåéçŽã·ã³ã¯ ïŒintercepting aggregated sinkïŒã®2çš®é¡ããéžæå¯èœã§ãã åè¿°ã®éããçµç¹ã®äžæµïŒçµç¹ã®ã«ãŒãããã©ã«ãïŒã§éçŽã·ã³ã¯ã䜿çšããã°ãäžæµã®åãªãœãŒã¹ïŒãããžã§ã¯ãçïŒã§çºçãããã°ãéçŽããããšãå¯èœã§ãããéã€ã³ã¿ãŒã»ããåéçŽã·ã³ã¯ã®å Žåã¯ã芪ãªãœãŒã¹ã®éåååéçŽã·ã³ã¯ã§åéãããã°ã¯ãåãªãœãŒã¹ã§ãåéããããšãã§ããŸããäžæ¹ã®ã€ã³ã¿ãŒã»ããåéçŽã·ã³ã¯ã®å Žåãäžæµã®ã·ã³ã¯ã§åéãããã°ã¯ããããäžæµã®åãªãœãŒã¹ã§ã¯åéã§ããŸããã ã€ã³ã¿ãŒã»ããåã·ã³ã¯ã䜿ãã°ãåãªãœãŒã¹ã§ãã°ãéè€ããŠåéãããã°åéã³ã¹ããè¥å€§åããããšãé¿ããããšãã§ããŸããéã«ãåãªãœãŒã¹ã§ããã°ãèªç±ã«åéã§ããããã«ãããå Žåã¯ãéã€ã³ã¿ãŒã»ããåã®ã·ã³ã¯ãå©çšããŸãã ãªãã€ã³ã¿ãŒã»ããåã·ã³ã¯ã¯åãªãœãŒã¹ïŒãããžã§ã¯ãïŒãããé²èЧã§ããŸãïŒã³ã³ãœãŒã«ã®ãã°ã«ãŒã¿ãŒç»é¢ã«è¡šç€ºãããŸãïŒã åè : Overview ãã°ç£èŠ ãã°ããŒã¹ã®ææš Cloud Logging ã§ãã°ã®ç¹å®æååãæ£èŠè¡šçŸã§æ€ç¥ãããã®æ€ç¥æ°ã Cloud Monitoring ã«ææšïŒã¡ããªã¯ã¹ïŒãšããŠéä¿¡ããããšãã§ããŸããããã ãã°ããŒã¹ã®ææš ãšåŒã³ãŸãã ãã®ææšã Cloud Monitoring ã®ã¢ã©ãŒãããªã·ãŒæ©èœã«ããæ€ç¥ã»çºå ±ããããšã§ãXXãã°ã§ Error ãšããæååã5åéã§3åä»¥äžæ€ç¥ãããã¡ãŒã«éç¥ãããã®ãããªãã°ç£èŠãå¯èœã«ãªããŸãã æé ã¯ä»¥äžããåç
§ãã ããã åè : ãã°ããŒã¹ã®ææšã®æŠèŠ åè : ææšããŒã¹ã®ã¢ã©ãŒã ããªã·ãŒãäœæãã ã¢ã©ãŒãããªã·ãŒã«ã€ããŠã¯ã以äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp ãã°ããŒã¹ã®ã¢ã©ãŒã ãã°ããŒã¹ã®ã¢ã©ãŒã ã¯ãCloud Logging ã«åºåããããã°ãšã³ããªã®æååãæ€ç¥ããŠãE ã¡ãŒã«ã Slack çã«å¯ŸããŠéç¥ãçºå ±ããæ©èœã§ãã æ€ç¥å¯Ÿè±¡ã®æååãæå®ããŠãã°ããŒã¹ã®ã¢ã©ãŒããèšå®ããããšã§ãã¢ããªã±ãŒã·ã§ã³ã Google Cloud ãµãŒãã¹ã®ãšã©ãŒçãæ€ç¥ããŠãéçšè
ã管çè
ã«å¯ŸããŠã¢ã©ãŒããçºå ±ããããšãã§ããŸãã åè¿°ã®ãã°ããŒã¹ã®ææšã«ããçºå ±æ¹æ³ã¯ããã£ãããã°æååã®æ€ç¥æ°ã Cloud Monitoring ã®ææšãšããŠã«ãŠã³ãããŸããããã®ããã°ããŒã¹ã®ã¢ã©ãŒããã§ã¯ç¹å®ã®æååãæ€ç¥ãããšçŽæ¥ãã¢ã©ãŒããçºå ±ã§ããŸãã ãã®ããã°ããŒã¹ã®ã¢ã©ãŒããã¯åè¿°ã®ããã°ããŒã¹ã®ææš + ã¢ã©ãŒãããªã·ãŒããšã»ãšãã©åãããšãå¯èœã§ã¯ãããŸãããããã°ããŒã¹ã®ã¢ã©ãŒããã§ã¯æååæ€ç¥æ°ãææšåããªããããæ°å€ãšããŠåŸããçµ±èšãåããªã代ããã«ãããå°ãªãã¹ãããã§èšå®å¯èœã§ãããåŸããèŠãŠãèšå®ããããããããšããéãããããŸãã åè : ãã°ããŒã¹ã®ã¢ã©ãŒããæ§æãã Log Analytics Log Analytics ãšã¯ Log Analytics ïŒãã°åæïŒã¯ãCloud Logging ãã°ãã±ããã«æ ŒçŽãããŠãããã°ã«å¯Ÿã㊠SQL ã§ã¯ãšãªããããšãã§ããæ©èœã§ãã åœæ©èœãªãªãŒã¹ä»¥åã¯ããã°ã«å¯Ÿã㊠SQL ã§ã¯ãšãªããããã«ã¯ãã°ã«ãŒã¿ãŒ (ã·ã³ã¯) ã䜿ã£ãŠ BigQuery ãžãã°ããšã¯ã¹ããŒãããå¿
èŠããããŸããã2023幎1æã«åœæ©èœã GA ãããŠä»¥éã¯ãåœæ©èœã«ãã Cloud Logging ãã°ãã±ããã«çŽæ¥ SQL ãå®è¡ããããšãå¯èœã«ãªããŸããã ãŸãããäžã€ã®æ©èœãšããŠãã°ãã±ããã BigQuery ããŒã¿ã»ãããšãªã³ã¯ ããããšãã§ããŸãã BigQuery ããŒã¿ã»ãããšãªã³ã¯ããããã°ãã±ãã㯠BigQuery åŽãããã¥ãŒãšããŠäœ¿ãããšãã§ããŸããããã«ãã BigQuery ã®ä»ã®ããŒã¿ãšçµåããŠã®åæãå¯èœã«ãªããŸãã åè : ãã°åæ å©ç𿹿³ ãã°ã« SQL ãå®è¡ããã«ã¯ããã°ãã±ããããšã« Log Analytics ã æå¹å ããå¿
èŠããããŸãã æå¹åããããã°ãã±ããã«å¯Ÿã㊠Google Cloud ã³ã³ãœãŒã«ã® Log Analytics ããŒãžãã BigQuery æšæº SQL ãå®è¡ããããšãã§ããŸãã ã³ã³ãœãŒã«ç»é¢ BigQuery ããŒã¿ã»ãããšã®ãªã³ã¯ ãã°ãã±ããããšã« BigQuery ããŒã¿ã»ãããšã®ãªã³ã¯ ãè¡ãããšãã§ããŸãã ãªã³ã¯ãããš BigQuery ã«æ°èŠããŒã¿ã»ãããäœæããããã®äžã« _AllLogs ãšãããã¥ãŒãçæãããŸãããã®ãã¥ãŒã«å¯ŸããŠã¯ãšãªãå®è¡ããããšã§ãã°ãæœåºã§ããŸãã BigQuery ã䜿ã£ãŠ _AllLogs ãã¥ãŒã«å¯ŸããŠã¯ãšãªãå®è¡ãããšãã¹ãã£ã³ããããŒã¿éã«å¿ã㊠BigQuery ã®ã¯ãšãªæéãçºçããŸããäžæ¹ã§ Log Analytics ç»é¢ããã®ã¯ãšãªã¯ç¡æã§ãã ãŠãŒã¹ã±ãŒã¹ Log Analytic ã¯ãã¢ããªã±ãŒã·ã§ã³ã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ããã¢ããªãã°ã BigQuery ã®èªç€ŸããŒã¿ããããªãã¯ããŒã¿ã»ããçãšçµåããçã®çšéãæ³å®ãããŸãã åŸæ¥ããããã£ãåæãããããã«ãã°ã«ãŒã¿ãŒïŒã·ã³ã¯ïŒã䜿ã£ãŠ BigQuery ã«ãã°ããšã¯ã¹ããŒãããŠé·æä¿åããããšããããŸãããããã Log Analytics ç»å ŽåŸã¯ãäºæ
ãå€ãããŸãã Cloud Logging ã®ãã°ãã±ããã®ä¿åæéã¯ã BigQuery ã®ã¹ãã¬ãŒãžæéïŒã¢ã¯ãã£ã/é·æä¿åïŒãšåçãããã¯å®äŸ¡ãªããã§ããæçµçã« Cloud Logging ãã°ãã±ããã«ä¿åããã»ããå®äŸ¡ã«ãªãã®ããããã㯠BigQuery ã®æ¹ãå®äŸ¡ã«ãªãã®ããã«ã€ããŠã¯åŸè¿°ããŸãã åè : Cloud Logging pricing summary åè : BigQuery - Storage pricing å¶é 代衚çãªå¶éã®ã¿ãèšèŒããŸãã ã¯ãšãªã§ããã®ã¯ Log Analytics æå¹ååŸã«çºçãããã°ã®ã¿ ãã°ãã±ããã CMEK æå·åãããŠããªã ãã°ãã±ãããããã¯ãããŠããªã ãã®ä»ã®å¶éãææ°æ
å ±ã¯ä»¥äžã®å
¬åŒããã¥ã¡ã³ãããåç
§ãã ããã åè : å¶éäºé
Log Analytics ã®æé Log Analytics ã§ã¯éåžžã® Cloud Logging 以å€ã«çºçããè¿œå æéã¯ãããŸãããLog Analytics ç»é¢ããã¯ãšãªããå Žåãã¯ãšãªæéãç¡æã§ãã äžæ¹ã§ãã°ãã±ããã BigQuery ããŒã¿ã»ãããšãªã³ã¯ã㊠BigQuery ããã¯ãšãªããå Žå BigQuery ã®ã¯ãšãªæéãçºçããŸãã ãã°ããã°ãã±ããã«ä¿åããã®ãšãBigQuery ã«ãšã¯ã¹ããŒãããã®ã§ã¯ãæçµçã«ã©ã¡ããå®äŸ¡ã«ãªãã®ã§ãããããããã«ã¯ã以äžã®èŠçŽ ãé¢ãã£ãŠããŸãã ãã°åãèŸŒã¿æã®æé Cloud Logging ( åãèŸŒã¿æé ) : $0.5 /GB (2023幎5ææç¹) BigQuery ( Streaming inserts æé ) : $0.06 /GB ($0.012 per 200 MBãšè¡šèšãæ±äº¬ãªãŒãžã§ã³ã2023幎5ææç¹) ã¯ãšãªæã®æé Cloud Logging (Log Analytics ç»é¢) ã§ã®ã¯ãšãª : ç¡æ BigQuery ã§ã®ã¯ãšãª ( ãªã³ããã³ãæé ) : $6 /TB (æåã® 1TB ã¯ç¡æ) (æ±äº¬ãªãŒãžã§ã³ã2023幎5ææç¹) ã€ãŸãããã°åã蟌ã¿ã®æé㯠BigQuery ã®æ¹ãå®äŸ¡ã§ãããã¯ãšãªæã®æé㯠Cloud LoggingïŒLog Analytics ç»é¢ïŒã®ã»ããå®äŸ¡ïŒç¡æïŒãšããããšã§ãäžé·äžçã§ããå©çšå®çžŸã確èªããã©ã¡ãã®ã»ããå®äŸ¡ã«ãªããã倿ããŠããæ±ºå®ããããšã«ãªããŸãã ãµãŒãã¹é飿º Cloud Run functions ã®ã㰠以äžã¯ãCloud Run functions ãã Cloud Logging ãžãã°ãæå
¥ããæ¹æ³ã«ã€ããŠè§£èª¬ããèšäºã§ããCloud Run functions ã§ã¯ãæšæºåºåã«æååãåºåããã ãã§ Cloud Logging ãžãã°ãšããŠæå
¥ãããŸãããç¹å®ã®èšå®ãããããšã§ éèŠåºŠïŒSeverityïŒçãèšå®ããããšãã§ããŸãã blog.g-gen.co.jp Compute Engine VMïŒWindowsïŒã®ã㰠以äžã®èšäºã§ã¯ãCompute Engine VM ãã Cloud Logging ãžä»»æã®ãã°ãã¡ã€ã«ãåã蟌ãããã®æ¹æ³ã玹ä»ããŠããŸããOps Agent ãšãã Cloud Monitoring ã®ãšãŒãžã§ã³ããœãããŠã§ã¢ãã€ã³ã¹ããŒã«ããããšã§å®çŸã§ããŸãã blog.g-gen.co.jp Tips 以äžã®èšäºã§ã¯ãCloud Logging ã®éçšäžã® Tips ã玹ä»ãããŠããŸãã blog.g-gen.co.jp ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãX (æ§ Twitter) ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
ã¿ãªããããã«ã¡ã¯ãG-genã®éŽæšããšãããã€ã§ãã ã¿ãªããŸã®äŒç€Ÿããã³ãã¥ããã£ã§ã¯ã¿ã¹ã¯ç®¡çãã©ã®ããã«è¡ã£ãŠããŸãã§ããããïŒ åå㯠å
±åã¿ã¹ã¯ãå©çšããã¿ã¹ã¯ç®¡ç ã玹ä»ããŸããã å
±åã¿ã¹ã¯ã®å©çšã¯ã䞻㫠ã客æ§ãšã®ããåããå¿
èŠãªå Žå ãã€ãŸãGoogle Workspaceãå©çšããŠããªããããã㯠å¥ã®çµç¹ã®æ¹ã
ãšã®ããåããå¿
èŠãªå Žå ã«æ¬é ãçºæ®ããŸãã ã§ã¯ãçµç¹å
ã®æ¹ã
ãšã¿ã¹ã¯ç®¡çããå Žåã¯ãªã«ããªããã®ã§ããããïŒ ããã§ä»åã¯Google Keepãå©çšããã¿ã¹ã¯ç®¡çã«ã€ããŠèª¬æããŠãããããšæããŸãã Google Keepãšã¯ Google Keepã®åºæ¬æäœ ã©ãã«ã®äœæ è²ã®å€æŽãšãªãã€ã³ããŒã®èšå® æ
åœè
ã®å²ãåœãŠ Googleã«ã¬ã³ããŒãšã®é£æº Google Keepãšã¯ Google Keep Google Keepãšã¯ãGoogle Workspace(æ§ G Suite)ã«ç¡æã§å«ãŸããŠãã 倿©èœã¡ã¢ã¢ããªã±ãŒã·ã§ã³ ã«ãªããŸããæºåž¯çšã®ã¢ããªã±ãŒã·ã§ã³ãæäŸãããŠããŸãã®ã§ãå€åºå
ãããªã«ãå¿ããŠã¯ãããªãããšãã¡ã¢ãããããããšãã§ããŸãã ã§ã¯ä»åã¯ãããªGoogle Keepãå©çšã㊠çµç¹ã®ã¡ã³ããŒãšã¿ã¹ã¯ç®¡ç ããæ¹æ³ã玹ä»ããããŸããããããã¯ããã® çæ¿ç®¡ç ã§ã Google Keepã®åºæ¬æäœ ã¯ããã«ãGoogle Keepã®åºæ¬æäœãã¿ãŠãããŸããããåæç»é¢ã¯ã以äžã®ãããªç»é¢ã«ãªããŸãã Google Keepã®åæç»é¢ ç»é¢äžå€®ã®å·Šãã以äžã®ãããªã€ã¡ãŒãžãªããŸãã ã»åçŽãªãªã¹ã ã»ãã¯ã€ãããŒãã®ãããªæç»å
¥ã ã»åçå
¥ã Google Keepã®åºæ¬çãªäœ¿ãæ¹ ããã§ã¯æ¬¡ã®é
ç®ãã以äžã説æããããŸãã ã»ã¿ã¹ã¯ãèå¥ããã©ãã«ã®äœæ ã»è²ã®å€æŽãšãªãã€ã³ããŒã®èšå® ã»æ
åœè
ã®å²ãåœãŠ ã»Google ã«ã¬ã³ããŒãšã®é£æº ã©ãã«ã®äœæ ã§ã¯ã¯ããã«æºåãšããŠãã¿ã¹ã¯ãããããããèå¥ããããã«ãå·ŠåŽã®ãã€ã³ã® ã©ãã«ã®ç·šé ããã©ãã«ãäœæããŠãããŸãããã ä»åã¯ãæ°èŠéçºãããžã§ã¯ãããšããã©ãã«ãäœæããŠã¿ãŸãã ã©ãã«ã®äœæ ãããšãäžèšç»åã®ããã«ããŸãŸã§ãã£ãã¿ã¹ã¯ããªããªããŸãããããã¯æåã«äœæãã3ã€ã®ã¿ã¹ã¯ã«ãæ°èŠéçºãããžã§ã¯ãããšãã©ãã«ã貌ãããŠããªãããã§ãã ãã®ããã«ãã©ãã«ã䜿ã£ãŠãããžã§ã¯ãããšãæ¥åçš®å¥ããšããªã©ãããŸããŸãªè§åºŠããã¿ã¹ã¯ãã°ã«ãŒãã³ã°ããããšãã§ããŸãã è²ã®å€æŽãšãªãã€ã³ããŒã®èšå® ãã¹ãŠã®ã¿ã¹ã¯ãçœã ãšããããã«ããã§ãããããããªãšãã¯åçæ¿ã® ãã¬ãã ã®çµµãã¯ãªãã¯ããŠã以äžã®ããã«è²ãå€ããŠã¿ãŸãããã è²ã®å€æŽ ãŸããåã¿ã¹ã¯ã«å¯ŸããŠãªãã€ã³ããŒãèšå®ããããšãå¯èœã§ãã以äžã®ããã«ããã«ã®ããŒã¯ãããªãã€ã³ããèšå®ããŠã¿ãŸãããã ãªãã€ã³ããŒã®èšå® ãã®ããã«èšå®ããããšã§ãåã¿ã¹ã¯ãäžèЧã§ã¿ãããšãã§ãããã€ãçŽæç®¡çãã§ããããã«ãªããŸããã æ
åœè
ã®å²ãåœãŠ å®éã®ãããžã§ã¯ããšãªããšãäžäººã§é²ããããšã¯ããŸããªãããšæããŸããä»ã®ã¡ã³ããŒãšã¿ã¹ã¯ãå
±æããªããé²ããããšãäžè¬çã§ãã ãã®å Žåã«ã¯åã¿ã¹ã¯ã«æ
åœè
ãå²ãåœãŠãŠã¿ãŸãããã 以äžã®ãã㫠人ã®ããŒã¯ ããçµç¹å
ã®å¥ã®ã¡ã³ããŒãå²ãåœãŠãããšãå¯èœã§ãã æ
åœè
ã®å²ãåœãŠ(1) æ
åœè
ã®å²ãåœãŠ(2) ããã§ä»ã®ã¡ã³ããŒãšã¿ã¹ã¯ãå
±æããããšãã§ããŸããã Googleã«ã¬ã³ããŒãšã®é£æº Google Workspaceã¯æ§ã
ãªæ©èœãèªåçã«é£æºããŠããŸãããã®ããäœããããšãä»ã®ã¢ããªã±ãŒã·ã§ã³ã§ç¶æ³ã確èªããããšãå¯èœã§ãã ã§ã¯å®éã« Googleã«ã¬ã³ããŒããã¿ã¹ã¯ãèŠãæ¹æ³ ã説æããããŸãã ããã¯ç°¡åã以äžã®ããã«Googleã«ã¬ã³ããŒã®ãã€ã«ã¬ã³ããŒããããªãã€ã³ããŒããéžæããããšã§ã¿ã¹ã¯ã§èšå®ãããªãã€ã³ãã®æ¥ã«è¡šç€ºããããšãå¯èœã§ãã Google ã«ã¬ã³ããŒãšã®é£æº ãšã£ãŠãç°¡åã§ãããå
šäœçã«ç®¡çãããšä»¥äžã®ãããªã€ã¡ãŒãžã«ãªããŸãã Google Keepå©çšã€ã¡ãŒãž ãã®ããã«ãGoogle KeepãããŸãå©çšããããšã§ã¿ã¹ã¯ãçæ¿ç®¡çããããšãå¯èœã«ãªããŸãããã²ããå©çšãã ããïŒ Google Cloud(旧GCP) / Google Workspace導入に関するお問い合わせ Google Workspace éŽæš éæ (èšäºäžèЧ) å·è¡åœ¹å¡ COO ããžãã¹æšé²éš éšé· åºæ¬ããªãã§ãå±ãäž»ã«ããžãã¹ã®ç«ã¡äžããä»çµã¿ã¥ãããå¥œã æ¥ã
ãåªåãæ¥ã
ãæ¥œããããšã倧äºã« ã Professional Cloud Architect / Professional Workspace Administratorã®ã¿ä¿æããŠããŸãããããã倱å¹ããŠããŸããããªäºæã
G-gen ã®ææã§ããGoogle Cloud ã®ãªãœãŒã¹ã¢ãã¿ãªã³ã°ã®ããã®ãããã¯ãã§ããã Cloud Monitoring ã解説ããŸãã Cloud Monitoring ã®æŠèŠ Cloud Monitoring ãšã¯ Cloud Monitoring ã®æé ãªãœãŒã¹ã¢ãã¿ãªã³ã° Google Cloud ã®ææš ã«ã¹ã¿ã ææš è€æ°ã®ãããžã§ã¯ãã®ææšã衚瀺ãã Ops ãšãŒãžã§ã³ã Ops ãšãŒãžã§ã³ãã®ææš Ops ãšãŒãžã§ã³ãã®ã»ããã¢ãã VM ã®èŠä»¶ ãã©ãã«ã·ã¥ãŒãã£ã³ã° ããã·ã¥ããŒã ã¢ã©ãŒã æŠèŠ éç¥ãã£ãã« èšå®æ¹æ³ 皌åæéãã§ã㯠皌åæéãã§ãã¯ãšã¯ å
¬éã®çšŒåæéãã§ã㯠éå
¬éã®çšŒåæéãã§ã㯠Prometheus Query LanguageïŒPromQLïŒ Cloud Monitoring ã®æŠèŠ Cloud Monitoring ãšã¯ Cloud Monitoring 㯠Google CloudïŒæ§ç§° GCPïŒã® Google Cloud Observability ãšåŒã°ãããµãŒãã¹çŸ€ã®1ã€ã§ãåçš® Google Cloud ãµãŒãã¹ããããã©ãŒãã³ã¹ããŒã¿çãåéããŠä¿åã»é²èЧå¯èœã«ãããµãŒãã¹ã§ããããŒã¿åéå
ãšããŠãGoogle Cloud ã®åçš®ãµãŒãã¹ã®ã»ãããªã³ãã¬ãã¹ã Amazon Web Services ïŒAWSïŒäžã®ä»®æ³ãµãŒããªã©ã察象ã«ããããšãã§ããŸãã åè : Cloud Monitoring ã®æŠèŠ Cloud Monitoring ã§ã¯ãããã©ã«ãã§åéããããŒã¿ïŒåŸè¿°ã®ãGoogle Cloud ã®ææšããªã©ïŒã«å¯ŸããŠã¯èª²éããããåºæ¬æ©èœã¯ç¡æã§äœ¿çšããããšãã§ããŸãã ãªã Google Cloud Observability ã¯ãã€ãŠã¯ãªãã¬ãŒã·ã§ã³ã¹ã€ãŒãããã®å㯠Google Stackdriver ãšåŒç§°ãããŠããŸããããæ¹ç§°ãããŸããã åè : Google Cloud ã®ãªãã¶ãŒãããªã㣠Cloud Monitoring ã®æé Cloud Monitoring ã¯ãå€ãã®å Žåã§ç¡æã§å©çšããããšãã§ããŸãã Google Cloud ãããã©ã«ãã§åéããææšïŒã¡ããªã¯ã¹ïŒã«ã€ããŠã¯ã課éã¯çºçããŸããããŠãŒã¶ãŒã Ops Agent ã§åéããè¿œå ææšãã«ã¹ã¿ã ææšã¯ãåéãããã€ãæ°ãããã¯ãµã³ãã«æ°ã«å¿ããŠèª²éãããŸãã 課é察象ã¡ããªã¯ã¹ããæåã® 150 MB ã¯æ¯æç¡æã§ãããããç§»è¡ã¯ $0.2580/MB ãçºçããŸãïŒ2025幎4æçŸåšã®å䟡ïŒãæ°å°ãåæ°å°ã® VM ã® Ops Agent è¿œå ææšçšåºŠã§ããã°ãç¡æç¯å²å
ã«åãŸãå¯èœæ§ããããŸãã ãŸããCloud Monitoring API ã«ãªã¯ãšã¹ãããéæ°ãã皌åæéãã§ãã¯æ©èœãªã©ã«ããæéãèšå®ãããŠããŸãã ææ°ã®æéã¯ã以äžã®ããã¥ã¡ã³ããåç
§ããŠãã ããã åè : Google Cloud Observability ã®æé ãªãœãŒã¹ã¢ãã¿ãªã³ã° Google Cloud ã®ææš Cloud Moniitoring ã¯ãCompute Engine ã Cloud SQLã Cloud Storage ã®ãã±ãããªã©ããããã Google Cloud ãªãœãŒã¹ãã ææš ïŒã¡ããªã¯ã¹ïŒãåéããŸãã ååŸã§ããææšã¯ãCompute Engine ã Cloud SQL ã®å ŽåãCPU 䜿çšçããããã¯ãŒã¯ I/OãCloud Storage ãªãã° API ãªã¯ãšã¹ãæ°ãç·äœ¿çšãã€ãæ°ãªã©ã§ãã æšæºçãªææšã¯ãå©çšè
ãäœãèšå®ããªããŠãã èªåçã«åé ãããŸããèªåçã«åéãããææšã«ã€ããŠã¯ã課éã¯çºçããŸããããã®ãããªèªåçã«åéãããææšãã Google Cloud ã®ææš ãšãããŸãã åéãããææšã¯ãCloud Monitoring ã³ã³ãœãŒã«ç»é¢ã® Metrics Explorer ç»é¢ããåãµãŒãã¹åŽã®ãªãœãŒã¹ã®ç»é¢çã§é²èЧããããšãã§ããŸãã åè : Metrics Explorer ã§ã°ã©ããäœæãã Metrics Explorer ç»é¢ Google Cloud ã®ææšã®äžèЧã¯ã以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : Google Cloud metrics ã«ã¹ã¿ã ææš ãŠãŒã¶ãŒç¬èªã®ææšãšã㊠ã«ã¹ã¿ã ææš ãåéããŠãCloud Monitoring API ã«éä¿¡ããããšãã§ããŸãã Google Cloudã®ææšã Ops ãšãŒãžã§ã³ãã®ææšã¯ç»äžçãªãã®ã§ãããã¢ããªã±ãŒã·ã§ã³ã®è² è·ããŠãŒã¶ãŒäœéšã®ç¶æ³ãæ£ç¢ºã«åæ ããŠããªãå¯èœæ§ããããŸãã CPU 䜿çšçãã¡ã¢ãªäœ¿çšçãäžãã£ãŠãããããšãã£ãŠããŠãŒã¶ãŒãåŠçãåŸ
ããããŠããããšã確å®ã«ç€ºããŠããããã§ã¯ãªãã§ãããéã« CPU 䜿çšçãã¡ã¢ãªäœ¿çšçã«äœè£ããã£ãŠãéã®ããšãããããŸããã·ã¹ãã ã®ããã©ãŒãã³ã¹å®æ
ã瀺ãç¬èªã®ææšãããã°ãæ£ç¢ºã«ç¶æ³ãåæ ããã¹ã±ãŒã«ã¢ã¯ã·ã§ã³ãªã©ã«ç¹ããããšãã§ããŸãã ã«ã¹ã¿ã ææšãåéããã«ã¯ãCloud Monitoring ã® Web API ã«çŽæ¥ããŒã¿ãéä¿¡ããæ¹æ³ãšããªãŒãã³ãœãŒã¹ã®ã©ã€ãã©ãªã§ãã OpenCensus ã䜿ã£ãŠ Cloud Monitoring ã«éä¿¡ããæ¹æ³ããããŸãã詳现ã¯ä»¥äžã®ããã¥ã¡ã³ãããåç
§ãã ããã åè : ãŠãŒã¶ãŒå®çŸ©ææšã®æŠèŠ è€æ°ã®ãããžã§ã¯ãã®ææšã衚瀺ãã ææšã¹ã³ãŒã ãæ§æããããšã§ãè€æ°ã®ãããžã§ã¯ãã®ææšãåäžã®ç»é¢ã§è¡šç€ºããããšãã§ããŸãã ãã Google Cloud ãããžã§ã¯ãããè€æ°ãããžã§ã¯ãã® Cloud Monitoring ææšãæšªæããŠè¡šç€ºããããã®ãããšããŠæ±ºããŠããã®ãããžã§ã¯ãã®ææšã¹ã³ãŒãã«ãç£èŠå¯Ÿè±¡ã®ãããžã§ã¯ãã远å ããããšã§ãè€æ°ãããžã§ã¯ãã®ææšã暪æããŠé²èЧã§ããŸãããã®ãšãããããšãªããããžã§ã¯ãã ã¹ã³ãŒãã³ã°ãããžã§ã¯ã ãšåŒã³ãŸãããŸããç£èŠå¯Ÿè±¡ãšãªãåã
ã®ãããžã§ã¯ãã ãªãœãŒã¹ã³ã³ãã ãšåŒã³ãŸãã åè : ææšã¹ã³ãŒãã®æŠèŠ ææšãé²èЧãã Google ã¢ã«ãŠã³ãïŒã°ã«ãŒãïŒã¯ãã¹ã³ãŒãã³ã°ãããžã§ã¯ãã«å¯ŸããŠã®ã¿ãã¢ãã¿ãªã³ã°é²èЧè
ïŒ roles/monitoring.viewer ïŒããŒã«çã® IAM ããŒã«ãæã€ããšã§ãç£èŠå¯Ÿè±¡ãšãªããã¹ãŠã®ãããžã§ã¯ãã®ææšãé²èЧã§ããããã«ãªããŸããåã
ã®ç£èŠå¯Ÿè±¡ãããžã§ã¯ãã«å¯Ÿãã IAM æš©éã¯å¿
èŠãããŸããã åè : ææšã¹ã³ãŒãã®æŠèŠ - Cloud Monitoring ãžã®ã¢ã¯ã»ã¹æš©ãä»äžãã ã¹ã³ãŒãã³ã°ãããžã§ã¯ããšæš©é å
¬åŒããã¥ã¡ã³ãã§ã¯ãã¹ã³ãŒãã³ã°ãããžã§ã¯ããšããŠå°çšã®ãããžã§ã¯ããäœæããããã«ã¯ãªãœãŒã¹ãäœãäœæããªãããšãæšå¥šããŠããŸãããã®ã»ããæš©é管çäžãã·ã³ãã«ã§ãããã¹ã³ãŒãã³ã°ãããžã§ã¯ãèªäœã§ææšãçæãããªãããã管çã容æã«ãªãããã§ãã åè : ææšã¹ã³ãŒãã®æŠèŠ - ãã¹ã ãã©ã¯ãã£ã¹ Ops ãšãŒãžã§ã³ã Ops ãšãŒãžã§ã³ãã®ææš Compute Engine VM ã«ã Ops ãšãŒãžã§ã³ã ãã€ã³ã¹ããŒã«ãããšãGoogle Cloud ã®ææšã®ä»ã«ã远å ã®ææšãåéã§ããŸãã åè : Ops ãšãŒãžã§ã³ãã®æŠèŠ Compute Engine ã®å ŽåãGoogle Cloud ã®ææšã§ã¯ãã¡ã¢ãªäœ¿çšçããã£ã¹ã¯äœ¿çšçãã¹ã¯ããå©çšçãªã©ã®éèŠãªææšã¯åéãããŸãããããã¯ãGoogle Cloud ã®ææšã¯ã VM ã®ãã€ããŒãã€ã¶ããååŸã§ããæ
å ± ãããšã«æ§æãããŠããããã ãšèããããŸãã Ops ãšãŒãžã§ã³ãã¯ãVM ã®ã²ã¹ã OS äžã§çšŒåããæ
å ±ãåéããŠãCloud Monitoring ã® API ãšã³ããã€ã³ãã«å¯ŸããŠãã®æ
å ±ãéä¿¡ããŸããããã«ããã ã¡ã¢ãªäœ¿çšç ã ãã£ã¹ã¯äœ¿çšç ã ã¹ã¯ããå©çšç ãªã©ã®ææšãååŸã§ããŸãã Ops ãšãŒãžã§ã³ãã«ãã£ãŠåéãããææšã®äžèЧã¯ã以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : Ops ãšãŒãžã§ã³ãã®ææš ãªããOps ãšãŒãžã§ã³ãã®ææšã¯åã蟌ã¿ããªã¥ãŒã ã«å¿ããŠæéãçºçããŸããã€ã³ã¹ã¿ã³ã¹æ°ãæ°å°ãåæ°å°ãšãã£ãã¬ãã«ã§ã¯ç¡ææ ã«åãŸãããå®äŸ¡ã«ãªãå¯èœæ§ãé«ãã§ãããæ°çŸå°ã®ã€ã³ã¹ã¿ã³ã¹ã管çããå Žåã¯ãã³ã¹ãã«é¢ãã詊ç®ãéèŠã«ãªããŸãã Ops ãšãŒãžã§ã³ãã®ã»ããã¢ãã ãšãŒãžã§ã³ãã®ã€ã³ã¹ããŒã«æé ã¯ã以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : Ops ãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ãã VM ã®èŠä»¶ Ops ãšãŒãžã§ã³ãã皌åãã VM ã§ã¯ã以äžã®æ¡ä»¶1ã3ããã¹ãŠæºãããŠããå¿
èŠãããããšã«æ³šæããŠãã ãããã©ãã1ã€ã§ãæºãããŠããªãç¶æ
ã ãšãOps ãšãŒãžã§ã³ãã¯ææšã®éä¿¡ã«å€±æããŸãããšãŒãžã§ã³ãã皌åããŠããæ°åãçµã€ãšãMemory UtilizationïŒ agent.googleapis.com/memory/percent_used ïŒãšãã£ã Ops ãšãŒãžã§ã³ãã®ææšã VM ã®è©³çްç»é¢çã§ç¢ºèªã§ããŸãããšãŒãžã§ã³ãã®ã€ã³ã¹ããŒã«åŸã«ã¯ãæ£ããææšãåéã§ããŠãããã確èªããŸãããã æ¡ä»¶1 : VM ã Cloud Monitoring ã® API ãšã³ããã€ã³ãã«å°éã§ãã äŸ1 ãã¡ã€ã¢ãŠã©ãŒã«ã§ 443/tcp ã 0.0.0.0/0 (â») ã«å¯ŸããŠç©ºããŠãã VPC ã®ã«ãŒãèšå®ã§ 0.0.0.0/0 (â») ãããã©ã«ãã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ã«åããŠãã VM ãå€éš IP ã¢ãã¬ã¹ãæã£ãŠãã äŸ2 ãã¡ã€ã¢ãŠã©ãŒã«ã§ 443/tcp ã 0.0.0.0/0 (â») ã«å¯ŸããŠç©ºããŠãã VPC ã®ã«ãŒãèšå®ã§ 0.0.0.0/0 (â») ãããã©ã«ãã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ã«åããŠãã VM ã Cloud NAT ã§ã€ã³ã¿ãŒããããžã¢ã¯ã»ã¹ã§ãã äŸ3 ãµããããã§éå®å
¬éã® Google ã¢ã¯ã»ã¹ãæå¹ã«ãªã£ãŠãã VM ãéå®å
¬éã® Google ã¢ã¯ã»ã¹çµç±ã§ Google Cloud API ã«ã¢ã¯ã»ã¹ã§ããèšå®ãã§ããŠãã éå®å
¬éã® Google ã¢ã¯ã»ã¹ã«ã€ããŠã¯ã以äžã®èšäºãåç
§ããŠãã ããã åè : éå®å
¬éã® Google ã¢ã¯ã»ã¹ã®ä»çµã¿ãšæé ããã£ã¡ã解説 - G-gen Tech Blog æ¡ä»¶2 : VM ã«ã¢ã¿ãããããŠãããµãŒãã¹ã¢ã«ãŠã³ãããããžã§ã¯ãã¬ãã«ã§ä»¥äžã®ããŒã«ãä»äžãããŠãã ã¢ãã¿ãªã³ã°ææšã®æžã蟌ã¿ïŒ roles/monitoring.metricWriter ïŒããŒã« æ¡ä»¶3 : VM ã®ã¢ã¯ã»ã¹ã¹ã³ãŒãèšå®ã§ Cloud Monitoring ãžã®æžã蟌ã¿ãèš±å¯ãããŠãã "ããã©ã«ã" ããã㯠"å
šãŠèš±å¯" ã«ãªã£ãŠããã°åé¡ãªã ã¢ã¯ã»ã¹ã¹ã³ãŒãã«ã€ããŠã¯ã以äžã®å
¬åŒããã¥ã¡ã³ãããåœç€Ÿèšäºãåç
§ããŠãã ããã åè : ãµãŒãã¹ ã¢ã«ãŠã³ã - ã¢ã¯ã»ã¹ ã¹ã³ãŒã åè : æ¹ããŠãµãŒãã¹ã¢ã«ãŠã³ããšVMã®ã¢ã¯ã»ã¹ã¹ã³ãŒããçè§£ãã - G-gen Tech Blog ãã©ãã«ã·ã¥ãŒãã£ã³ã° ææšã衚瀺ãããªãå Žåã¯ãäœããã®ãšã©ãŒãåºåãããŠããå¯èœæ§ããããŸããLinux ã€ã³ã¹ã¿ã³ã¹ã§ããã°ã以äžã®ãããªãã¹ã«ãšãŒãžã§ã³ãã®ãã°ãåºåãããŠããã®ã§ããã°ã確èªããŠåå ã調æ»ããŸãã /var/log/google-cloud-ops-agent/subagents/logging-module.log 以äžã¯ãšã©ãŒã®äŸã§ãããã®äŸã§ã¯ãVPC ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã§ã€ã³ã¿ãŒããããžã®ã¢ãŠãããŠã³ãã® 443/TCP éä¿¡ãæåŠãããŠããããããšãŒãžã§ã³ã㯠API ãšã³ããã€ã³ãã«ãªãŒãã§ããããšã©ãŒã«ãªã£ãŠããŸããã [2021/10/14 10:07:46] [error] [upstream] connection #272 to logging.googleapis.com:443 timed out after 10 seconds ãªãäžèšã®ãšã©ãŒã¡ãã»ãŒãžã§ logging.googleapis.com ãšåºãŠããããšããããããããã«ãOps ãšãŒãžã§ã³ã㯠Cloud Logging ã«ãã°ãéä¿¡ãããšãŒãžã§ã³ãã®åœ¹å²ãå
ŒåããŠããŸãããã€ãŠã¯ Monitoring ãšãŒãžã§ã³ããš Logging ãšãŒãžã§ã³ãã®2ã€ã®ç°ãªã圹å²ã®ãšãŒãžã§ã³ããœãããŠã§ã¢ããããŸããããçŸåšã§ã¯ Ops ãšãŒãžã§ã³ãã«çµ±åãããŠããŸãã ããã·ã¥ããŒã Cloud Monitoring ææšãé²èЧããã«ã¯ãMetrics Explorer ã®ä»ã ããã·ã¥ããŒã æ©èœã䜿ãããšãã§ããŸããããã·ã¥ããŒãã¯ã«ã¹ã¿ãã€ãºå¯èœã§ãããŸããŸãªãã£ãŒãïŒã°ã©ãïŒãé
眮ããŠãéçšäžå¿
èŠãªãªãœãŒã¹ã®ææšãé²èЧããããšãã§ããŸãã ããã·ã¥ããŒãã¯éçšã®èŠä»¶ã«åãããŠèªåšã«äœæãå¯èœã§ããããšã«å ããŠãGoogle Cloud ãããã¯ãããšã«ããªã»ããã§çšæãããŠããããã·ã¥ããŒãããã®ãŸãŸå©çšããããè€è£œããŠã«ã¹ã¿ãã€ãºããŠå©çšããããšãã§ããŸãããŸããããã·ã¥ããŒãå®çŸ©ã¯ JSON 圢åŒã§ãšã¯ã¹ããŒãããããã€ã³ããŒãããããšãã§ããŸãã åè : ããã·ã¥ããŒãã®æŠèŠ åè : ã«ã¹ã¿ã ããã·ã¥ããŒãã®äœæãšç®¡ç ããªã»ããã®VMçšããã·ã¥ããŒã ã¢ã©ãŒã æŠèŠ Cloud Monitoring ã§ã¯ãææšã«ãããå€ãèšå®ããŠããããå€ãè¶
éããéã«ã¡ãŒã«ãçºä¿¡ãããªã©ã ã¢ã©ãŒã ã®èšå®ãå¯èœã§ããã¢ã©ãŒãæ©èœã§äœæãããåã
ã®èšå®ãã ã¢ã©ãŒãããªã·ãŒ ãšåŒã³ãŸãã åè : ã¢ã©ãŒãã®æŠèŠ äŸãã°ã以äžã®ãããªã¢ã©ãŒãããªã·ãŒãäœæå¯èœã§ãã ææš : CPU䜿çšç 察象 : ããã€ã³ã¹ã¿ã³ã¹ã°ã«ãŒãå
šäœ æé : 5åé ãããå€ : 80%ãè¶
é ã¢ã¯ã·ã§ã³ : E ã¡ãŒã«ãéä¿¡ ã¢ã©ãŒãã®èšå®ç»é¢ éç¥ãã£ãã« Cloud Monitoring ã®ã¢ã©ãŒãã§ã¯ã以äžã®éç¥å
ãžã®éç¥ãå¯èœã§ãããããã®ãããªéç¥å
ã®ããšã éç¥ãã£ã³ãã« ïŒnotification channelsïŒãšåŒã³ãŸãã Eã¡ãŒã« Google Cloud ã®ã¢ãã€ã«ã¢ã㪠Google ãã£ãã PagerDuty Services PagerDuty Sync Slack WebhookïŒHTTP ãšã³ããã€ã³ãïŒ SMS Pub/Sub éç¥å
ãã£ã³ãã«ã䜿ã£ãéçšã®äŸãšããŠãææšã®ãããå€è¶
éãããªã¬ãŒã«ã㊠Pub/Sub ã«ã¡ãã»ãŒãžãéä¿¡ããPub/Sub ããªã¬ã® Cloud Run functions ãèµ·åããŠã察åŠã¢ã¯ã·ã§ã³ãèªåå®è¡ãããšãã£ãããšãå®çŸå¯èœã§ãã åè : éç¥ãã£ã³ãã«ãäœæããŠç®¡çãã èšå®æ¹æ³ ã¢ã©ãŒãããªã·ãŒã¯ããããå€è¶
éæã®çºå ±ã®ã»ããææšãåéã§ããªããªã£ãæããææšãããæ°å€ã«å°éããããšäºæž¬ãããéã«çºå ±ãããããšãã§ããŸããã¢ã©ãŒãããªã·ãŒã®èšå®æ¹æ³ã¯ã以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : ææšãããå€ã®ã¢ã©ãŒã ããªã·ãŒãäœæãã åè : ææšãªãã®ã¢ã©ãŒã ããªã·ãŒãäœæãã åè : äºæž¬ææšå€ã®ã¢ã©ãŒã ããªã·ãŒãäœæãã ãŸãã以äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp 皌åæéãã§ã㯠皌åæéãã§ãã¯ãšã¯ 皌åæéãã§ã㯠ïŒuptime checksïŒãšã¯ãäžè¬çã« URL ç£èŠããããã¯å€åœ¢ç£èŠçãšåŒã°ããç£èŠãèšå®ã§ããæ©èœã§ãã HTTPãHTTPSãTCPïŒä»»æã®ããŒãïŒã®ããããã®ãã©ãã£ãã¯ã Google ãã察象ãªãœãŒã¹ã«éä¿¡ãããã®ã¬ã¹ãã³ã¹ãæ³å®ç¶æ
ãšç°ãªã£ãŠããã°ã¢ã©ãŒããçºå ±ããããšãã§ããŸãã ã€ã³ã¿ãŒãããããã¢ã¯ã»ã¹å¯èœãªãšã³ããã€ã³ãã察象ãšãã å
¬éã®çšŒåæéãã§ã㯠ïŒPublic uptime checksïŒãšãVPC ãããã¯ãŒã¯å
ã®ãã©ã€ããŒããªãšã³ããã€ã³ãã察象ãšãã éå
¬éã®çšŒåæéãã§ã㯠ïŒPrivate uptime checksïŒã®2çš®é¡ããããŸãã ãã§ãã¯ã倱æããéã®éç¥å
ãšããŠãCloud Monitoring ã®éç¥ãã£ã³ãã«ãéžæã§ããŸãã åè : å
¬éã®çšŒåæéãã§ãã¯ãäœæãã åè : éå
¬é皌åæéãã§ãã¯ãäœæãã 皌åæéãã§ãã¯ã«ã¯ããã§ãã¯å®è¡åæ°ãããã®æéãçºçããŸããæéå䟡ã¯ã1,000 åã®å®è¡ããšã« $0.30 ã§ãïŒ2025幎4æçŸåšïŒããŸããGoogle Cloud ãããžã§ã¯ãããããæã«100äžåãŸã§ãç¡æã§ãã åè : Google Cloud Observability ã®æé å
¬éã®çšŒåæéãã§ã㯠å
¬éã®çšŒåæéãã§ã㯠ïŒPublic uptime checksïŒã¯ãã€ã³ã¿ãŒãããããã¢ã¯ã»ã¹ã§ãããšã³ããã€ã³ãã察象ãšãã皌åæéãã§ãã¯ã§ãã 以äžãç£èŠå¯Ÿè±¡ãšããŠèšå®ã§ããŸãã URL Compute Engine VM App Engine ã¢ããªã±ãŒã·ã§ã³ Kubernetes ãµãŒãã¹ Amazon EC2 ã€ã³ã¹ã¿ã³ã¹ Amazon Elastic Load Balancers Cloud Run ãªããžã§ã³ ç£èŠå¯Ÿè±¡ã Google Cloud ã® VPC ãããã¯ãŒã¯å
ã®ãªãœãŒã¹ã®å Žåã皌åæéãã§ãã¯ãæ£ãããšã³ããã€ã³ãã«å°éã§ããããã«ããããã«ã¯ãVPC ãããã¯ãŒã¯ã®ãã¡ã€ã¢ãŠã©ãŒã«çãé©åã«èšå®ããå¿
èŠããããŸãã 0.0.0.0/0 ããã®ãã©ãã£ãã¯ãèš±å¯ãããŠããã°åé¡ãããŸãããã皌åæéãã§ãã¯ãå©çšããæ¥ç¶å
IP ã¢ãã¬ã¹ã ããèš±å¯ããããšãã§ããŸããIP ã¢ãã¬ã¹ã®ãªã¹ãã¯ãGoogle Cloud ã³ã³ãœãŒã«ããããŠã³ããŒãããããAPI çµç±ã§ååŸããããšãã§ããŸãã åè : 皌åæéãã§ã㯠ãµãŒããŒã® IP ã¢ãã¬ã¹ãäžèŠ§è¡šç€ºãã äžèšã§ååŸããæ¥ç¶å
IP ã¢ãã¬ã¹ã®ç¯å²ã ãã VPC ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã§èš±å¯ããããšãå¯èœã§ãããã¯ã©ãŠããµãŒãã¹ã® IP ã¢ãã¬ã¹ç¯å²ã¯å€æŽãããå¯èœæ§ãããããã倿Žã宿çã«æ€ç¥ããŠãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã«åæ ãããããªä»çµã¿ãçšæããããšãæãŸããã§ãããã å
¬éã®çšŒåæéãã§ãã¯ã®èšå®æé ã®è©³çްã¯ã以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : å
¬éã®çšŒåæéãã§ãã¯ãäœæãã éå
¬éã®çšŒåæéãã§ã㯠éå
¬éã®çšŒåæéãã§ã㯠ïŒPrivate uptime checksïŒã¯ãã€ã³ã¿ãŒãããã«å
¬éãããŠããªãã VPC ãããã¯ãŒã¯å
éšã®ãªãœãŒã¹ã®ãšã³ããã€ã³ãã察象ãšãã 皌åæéãã§ãã¯ã§ãã 瀟å
åãã·ã¹ãã ããã¹ããã Compute Engine VM ããèªçµç¹ã®å
éšãããã¯ãŒã¯åãã® API ãšã³ããã€ã³ãçãç£èŠããç®çã§å©çšã§ããŸãã éå
¬é皌åæéãã§ãã¯ã§ã¯ãã¿ãŒã²ãããšã㊠Service Directory ãªãœãŒã¹ ãšåŒã°ãããªãœãŒã¹ãäœæããå¿
èŠããããŸããService Directory ãªãœãŒã¹ã«ã¯ããšã³ããã€ã³ãããµãŒãã¹ãåå空éãšãã£ããªãœãŒã¹ãå«ãŸããŸãããããã®ãªãœãŒã¹ã«ãããCompute Engine VM ããCloud Load Balancing ã® IP ã¢ãã¬ã¹ãæœè±¡åãã皌åæéãã§ãã¯ã¯ããã«å¯ŸããŠãã§ãã¯ãè¡ããŸãã 詳现ãªèšå®æé ã¯ã以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : éå
¬é皌åæéãã§ãã¯ãäœæãã Prometheus Query LanguageïŒPromQLïŒ Cloud Monitoring ã§ã¯ã Prometheus Query Language ïŒPromQLïŒãšããèšèªã§ãææšãã¯ãšãªããããã°ã©ããäœæããããšãã§ããŸãã PromQL ã¯ã䞻㫠Kubernetes åãã®ãªãŒãã³ãœãŒã¹ã®ç£èŠããŒã«ã§ãã Prometheus ã§çšãããããæç³»åããŒã¿ã«å¯Ÿããã¯ãšãªèšèªã§ãã Prometheus ãå©çšããŠãããéçšãå
±éåãããå Žåã¯ãCloud Monitoring ã§ã PromQL ã䜿ãããšãã§ããŸããMetrics Explorer ããã«ã¹ã¿ã ããã·ã¥ããŒããžã®ã°ã©ãè¿œå æã«ãPromQL ãå©çšã§ããŸãã åè : Cloud Monitoring ã® PromQL ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãX (æ§ Twitter) ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-genã®ææã§ãã2021幎10æ26æ¥ãããžã¿ã«åºãå
¬åããŠãã ããžã¿ã«åºã«ãããã¬ãã¡ã³ãã»ã¯ã©ãŠãæŽåã®ããã®ã¯ã©ãŠããµãŒãã¹ã®æäŸ ã®å
¬åçµæãå
¬éãããŸããã çµæãšã㊠Amazon Web Services (AWS) ãš Google Cloud (æ§ç§° GCP) ã察象ãšã㊠çºè¡š ãããŸããã ããã«é¢é£ããŠæ¬æçš¿ã§ã¯ã Google ãå
¬éããŠããæµ·å€ã®æ¿åºã»èªæ²»äœã«ãã Google Cloud å©çšäºäŸãç°¡åã«ã玹ä»ããŸãã æ¥æ¬ã§ãè¡æ¿ã«ããã¯ã©ãŠãå©çšãé²ã¿ãåœæ°ããã䟿å©ã«ãå¹ççã«è¡æ¿ãµãŒãã¹ãåããããããã«ãªãããšãé¡ããŸãã ããžã¿ã«åºã«ãããã¬ãã¡ã³ãã»ã¯ã©ãŠãæŽåã®ããã®ã¯ã©ãŠããµãŒãã¹ã®æäŸ æ¿åºããã³è¡æ¿æ©é¢åã Google Cloud æŠèŠ Google Cloud ã®ã³ã³ãã©ã€ã¢ã³ã¹æ
å ± è¡æ¿åãã®äºäŸ 1. ã¢ã¡ãªã«åœç«èåç ç©¶æ: ããŒãã³ãœã³ç
察çãå é 2. NYC Cyber Command: ãã¥ãŒãšãŒã¯åžã®å€§èŠæš¡ããžã¿ã« ãµãŒãã¹ã®å®å
šãå®ã 3. ããµã³ãŒã«ã¹åž: Google Map ã§åžæ°ãžã®æ
å ±å
¬éãšå©äŸ¿æ§ã®åäžãå®çŸ 4. ã€ã¿ãªã¢ã»ãããå·: 500äžäººåãã®å°æ¹èªæ²»äœãµãŒãã¹ã®å€é© 5. ããª: å»çã±ã¢ã®ã¢ããã€ãŒãŒã·ã§ã³ 6. ã¢ãªãŸãå·: ã¯ã©ãŠãã³ã©ãã¬ãŒã·ã§ã³ã§çç£æ§ãšã»ãã¥ãªãã£ãåäž ããžã¿ã«åºã«ãããã¬ãã¡ã³ãã»ã¯ã©ãŠãæŽåã®ããã®ã¯ã©ãŠããµãŒãã¹ã®æäŸ 2021幎10æ4æ¥ãæ¥æ¬ã®ããžã¿ã«åºã¯ ããžã¿ã«åºã«ãããã¬ãã¡ã³ãã»ã¯ã©ãŠãæŽåã®ããã®ã¯ã©ãŠããµãŒãã¹ã®æäŸïŒä»€å3å¹ŽåºŠå°æ¹å
Œ
±å£äœã«ããå
è¡äºæ¥åã³ããžã¿ã«åºWEBãµã€ãæ§ç¯æ¥åïŒ ãšé¡ããå
¬åãçºåºããã ããžã¿ã«åºã«ãããã¬ãã¡ã³ãã»ã¯ã©ãŠãæŽåã®ããã®ã¯ã©ãŠããµãŒãã¹ã®æäŸïŒä»€å3å¹ŽåºŠå°æ¹å
Œ
±å£äœã«ããå
è¡äºæ¥åã³ããžã¿ã«åºWEBãµã€ãæ§ç¯æ¥åïŒ (ããžã¿ã«åº) å
¬åã®ç®çã¯ä»¥äžã®ããã«èšèŒãããŠããã æ¬å
¬åã¯ã¯ã©ãŠããµãŒãã¹ã®é©æ£ãã€ç¢ºå®ãªæäŸã確ä¿ãããããå
¬ååå è
ã«å¯Ÿãã ãã®ç¢ºå®ãªãµãŒãã¹ã®æäŸã蚌æããæžé¡çã®æåºãæ±ãããã®ã§ãããããžã¿ã«åºã åœè©²æåºãããæžé¡çã®å¯©æ»ã«ãããŠã¯ã©ãŠããµãŒãã¹ã®æäŸãå¯èœãšå€æããè
ãã¹ ãŠãšå¥çŽã®ç· çµãè¡ããã®ã§ããã ãŸãå¿åèŠé
ã®äºæ¥æŠèŠã®é
ã«èšèŒãããŠããããã«ãä»åŸããžã¿ã«åºã® Web ãµãŒãã¹åºç€ã¯ãããã®ãããªãã¯ã¯ã©ãŠãäžã«æ§ç¯ãããä»çåºãèªæ²»äœã®ã·ã¹ãã ãããã«ç¶ãããšãæ³å®ãããã (1) å°æ¹å
Œ
±å£äœã«ããå
è¡äºæ¥ã«åããã¯ã©ãŠããµãŒãã¹ã®æŽå (äžç¥) (2) ããžã¿ã«åº WEB ãµã€ãã«åããã¯ã©ãŠããµãŒãã¹ã®æŽå (äžç¥) æ¬ä»¶ã¯ãäžèšïŒ1ïŒãïŒ2ïŒã宿œããããã«ããã®åºç€ãšãªãã¯ã©ãŠããµãŒãã¹ã®æ äŸãå
¬åãããã®ã§ããã 2021幎10æ26æ¥ã«ã¯ã Amazon Web Services (AWS) ãš Google Cloud (æ§ç§° GCP) ãéžå®ãããããšãçºè¡šãããã å
¬åçµæã«ã€ã㊠(ããžã¿ã«åº) æ¿åºããã³è¡æ¿æ©é¢åã Google Cloud æŠèŠ Google Cloud ã®å
¬åŒ Web ãµã€ãã«ã¯ãæ¿åºã»è¡æ¿æ©é¢ã«ãã Google Cloud å©çšäºäŸãå
¬éãããŠããã æ¿åºããã³è¡æ¿æ©é¢åã Google Cloud (Google) åããŒãžã§ã¯Google Cloud ã® IaaS ç³»ãœãªã¥ãŒã·ã§ã³ã®ä»ã AI/ML (人工ç¥èœã»æ©æ¢°åŠç¿) ç³»ãœãªã¥ãŒã·ã§ã³ã Google Workspace ã«ããæ¥åå¹çåããœãªã¥ãŒã·ã§ã³ãšããŠç޹ä»ããããŸãããã€ãã®äºäŸãå
¬éãããŠããã ãã ã2021幎10ææ«çŸåšã®ãšãããåããŒãžã§ç޹ä»ãããŠããäºäŸã¯ããããã¢ã¡ãªã«åè¡åœãåç±³ãªã©ãæµ·å€ã®äºäŸã«çãŸã£ãŠããã åããŒãžã§ç޹ä»ãããæµ·å€äºäŸã¯äžéšãæ¥æ¬èªèš³ãããŠãããã®ã®ãè±èªçããå
¬éãããŠããªãäºäŸãããããšãããããããæèš³ããŠããç°¡åã«ç޹ä»ãããã Google Cloud ã®ã³ã³ãã©ã€ã¢ã³ã¹æ
å ± äºäŸã玹ä»ããåã«ãåããŒãžã§ç޹ä»ãããŠãã Google Cloud ã®ã³ã³ãã©ã€ã¢ã³ã¹æ
å ±ã«é¢ããŠã®èšè¿°ã«è§Šãããã è¡æ¿ã»èªæ²»äœã«éããäžè¬äŒæ¥ã§ã泚ç®ãã¹ããã€ã³ãã¯ã Google Cloud ãåããŠãã第äžè
èªèšŒã ã 以äžã®ããŒãžã§ã¯ã Google Cloud ãåããèªèšŒã«é¢ããè³æã«å ããååœã®å
¬çèªèšŒãã¬ã€ãã©ã€ã³ãžã®æºæ ã«åããè£å©è³æãé
眮ãããŠããã ã³ã³ãã©ã€ã¢ã³ã¹ ãªãœãŒã¹ ã»ã³ã¿ãŒ æ¥æ¬ã§ãç¥å床ãé«ã ISO/IEC 27001 ã SOC ãPCIDSS ã¯ãã¡ãããæ¥æ¬ã®éç§°ã3ç2ã¬ã€ãã©ã€ã³ (åçåŽåçãçµæžç£æ¥çãç·åçã®3çãçºè¡ããå»çæ©é¢åãã®æ
å ±ã·ã¹ãã ã¬ã€ãã©ã€ã³ã®ç·ç§°)ãã«æºæ ããããã®ãã¯ã€ãããŒããŒçãå
¬éãããŠããç¹ãè峿·±ãã ããŠããããã¯ãåããŒãžã§ç޹ä»ãããŠããæµ·å€ã§ã®è¡æ¿ã»èªæ²»äœã«ããã Google Cloud ã Google Workspace ã®æŽ»çšäºäŸã玹ä»ããã è¡æ¿åãã®äºäŸ 1. ã¢ã¡ãªã«åœç«èåç ç©¶æ: ããŒãã³ãœã³ç
察çãå é cloud.google.com ã¢ã¡ãªã«åœç«èåç ç©¶æ (National Institute on Aging) ã«ãã㊠Google Cloud ãå©çšãããäºäŸã玹ä»ãããŠããã Cloud Life Sciences (æ§ Google Genomics: çç©å»åŠããŒã¿åŠçã®ããã®ã³ã³ãã¥ãŒãã£ã³ã°ãªãœãŒã¹ç®¡çãã©ãããã©ãŒã ) ã®å©çš ãªã³ãã¬åºç€ã§ã¯æ°ã¶æããã200 TB ã®ãšã¯ãœãŒã ããŒã¿ã®åŠçã 3.5 é±éã§å®çŸ äžçäžã®50ãè¶
ããæ©é¢ã®ç ç©¶è
ã«ããŒã¿ãå
±æ (ã¢ã¯ã»ã¹ã³ã³ãããŒã«ã«ããã»ãã¥ãªãã£ãæ
ä¿) Cloud Life Sciences (æ§ Google Genomics) ã䜿ãããšã§å€§éã®ã³ã³ãã¥ãŒãã£ã³ã°ãªãœãŒã¹ãå¹ççã«ç®¡çããŠèšå€§ãªéºäŒåè§£æãå®çŸããäºäŸã ã ãŸã Google Cloud ã®ãã现ãããªã¢ã¯ã»ã¹å¶åŸ¡ã®ç¹æ§ãå©çšããŠãç±³åœå
ãæ¬§å·ã®åæ©é¢ã«æ£ãã°ãç ç©¶è
ãã¡ã«ããŒã¿ãéããã«å
±æã§ããããšã玹ä»ããŠããã 2. NYC Cyber Command: ãã¥ãŒãšãŒã¯åžã®å€§èŠæš¡ããžã¿ã« ãµãŒãã¹ã®å®å
šãå®ã cloud.google.com NYC Cyber Command ã¯ç±³åœã»ãã¥ãŒãšãŒã¯åžã®å
¬çæ©é¢ã§ãåžã®ãµã€ããŒãã£ãã§ã³ã¹ãä»»åãšããæ©é¢ã ã Google ã¯ãã®äºäŸã以äžã®ããã«èŠçŽããŠããã é«ããã©ãŒãã³ã¹ã®ã¯ã©ãŠã ãµãŒãã¹ã§ããè¿
éã«è
åšãæ€ç¥ 100 以äžã®ãã¹ãŠã®éœåžæ©é¢ã®ãªã³ããŒãã£ã³ã°ã«ãããæéãççž® å°èŠæš¡ãªããŒã ã§ã¯ã©ãŠã ã€ã³ãã©ã¹ãã©ã¯ãã£ãå®å
šã«ç®¡ç ãã¿ãã€ãèŠæš¡ã®ããŒã¿ãåæã§ãããã»ãŒç¡éã®ã¹ã±ãŒã©ããªã㣠éœåžæ©é¢ãåžæ°ã«æå€§ã®äŸ¡å€ãæäŸ æ¬äºäŸã§ã¯ãåžã®è·å¡ã BeyondCorp ã»ãã¥ãªãã£ã¢ãã«ã«ããã·ã¹ãã å©çšãããŠããããšãè¿°ã¹ãããŠããã Google Workspace ã«ãã ID 管çãããŒã¹ã« Cloud IAM ã«ããèªå¯å¶åŸ¡ããã Cloud Identity-Aware Proxy (IAP) ãå©çšããŠé VPN ã«ãã Google Cloud ã¢ã¯ã»ã¹ãå®çŸããããã ã ãŸãåè¡æ¿ã·ã¹ãã ããããŒã¿åéãè¡ãããŒã¿ãã€ãã©ã€ã³ã以äžã®ãããªã¢ãŒããã¯ãã£ã§æ§ç¯ããããšãèšèŒãããŠããã ããŒã¿ã®åãå£ãšã㊠Cloud Pub/Sub ãå©çš Cloud Dataflow ãŸã㯠Cloud Functions ããã®ããŒã¿ãåŠçãã BigQuery çã®ããŠã³ã¹ããªãŒã ã§ããŒã¿ãåæ ãããã®ãµãŒãã¹ãå©çšããçç±ãšããŠããµãŒãã¬ã¹ããã«é«ãåŠçèœåã容æã«èª¿éã»å®è£
ã§ããããšãçç±ãšããŠæããããŠããã ãŸãã¢ããªã±ãŒã·ã§ã³åºç€ãšããŠã¯ Google Kubernetes Engine (GKE) ãæ¡çšãã¢ãã¿ãªã³ã°ã« ãªãã¬ãŒã·ã§ã³ ã¹ã€ãŒã (æ§ç§° Stackdriver) ãå©çšããŠããããšãæããã«ããŠããã 3. ããµã³ãŒã«ã¹åž: Google Map ã§åžæ°ãžã®æ
å ±å
¬éãšå©äŸ¿æ§ã®åäžãå®çŸ workspace.google.com åäºäŸã§ã¯ Google Cloud ã«ãã以äžã®ææãèšèŒãããŠããã ç·æ¥æã«éèŠãšãªãæ
å ±ã䜿ãæ
£ãã Google Map ã®ã€ã³ã¿ãŒãã§ã€ã¹ã§æäŸ Google Map ã§ã®æ
å ±æäŸã1æé以å
ã« ã»ãã¥ãªãã£ãããæ©èœéçºãžæ³šåã§ããããã« ããµã³ãŒã«ã¹åžæ
å ±æè¡å± (ITA, Information Technology Agency) 㯠2016 幎ãŸã§ãç·æ¥æ
å ±æäŸããŠã§ããµã€ãäžã§ã®ããã¹ãã«ããè¡ãããå°å³æ
å ±ãå¿
èŠãªéã«ã¯æåã§äœãããå°å³ãPDFé
åžãããŠããã 2016 幎ååããšã«ã»ããŒãã§çŸè±¡ã«ãã£ãŠåŒãèµ·ããããç°åžžæ°è±¡ã®éã Google Map ã䜿ã£ãæ°ã·ã¹ãã ãæŽ»çšãããã Google Map ãæŽ»çšããŠåžã®å°å³ãšæ°è±¡æ
å ±ãã¬ã€ã€ã§éãããšã«ã»ããŒãã§ã»ãŠã©ããã»ããŒãžãå
¬éãããã ãã®ããŒãžã§ã¯èŠå ±æ
å ±ãæµžæ°Žããåžè¡å°ãå°æ»ããåé»ãæžæ»æ
å ±ãé¿é£ã·ã§ã«ã¿ãŒãªã©ã®æ
å ±ãæäŸããããšããã ãã®ãšã«ã»ããŒãã§ã»ãŠã©ããã»ããŒãžã§ã¯ Google Map ã®æäŸããå°çæ
å ±ã®ä»ãå°åã®ããŒã ã»ã³ã¿ãŒçã®æ
å ±ãæŽ»çšãããäœæ°ããã®æ
å ±ãæŽ»ãããŠã倧éšã«åããæºåãã§ããããã«ããã®ã ã ãŸã ITA ã¯ã«ãªãã©ã«ãã¢å·ã§é »çºããå±±ç«äºã®å¯Ÿå¿ã«ã Google Map ãæŽ»çšããŠããã ç«äºã®çºçå Žæãé¿é£å Žæçã衚瀺ããããã«ããã®ã ã ãŸãããµã³ãŒã«ã¹åžã¯ Google Workspace (æ§ GSuite) ãå©çšããŠããã 2009 幎ãã Gmail ãšã«ã¬ã³ããŒã䜿ã£ãŠãããããã¯ç±³åœå
ã®èªæ²»äœã§ãæãæ©ãéšé¡ã ã£ããšããã çŸåšã§ã¯ Google Drive ã Google Meet ã®å©çšãå«ã 30,000 ãŠãŒã¶ãŒãå©çšããŠããã ããµã³ãŒã«ã¹åžã¯æ±äº¬23åºã®ããã2åã®é¢ç© (1214.7 å¹³æ¹ km) ã§ãããããç¹åšããè·å¡ã®ã³ãã¥ãã±ãŒã·ã§ã³ã« Google Drive çãå©çšãããŠããã ããµã³ãŒã«ã¹åžã§ã¯ 2028 幎ã®ãªãªã³ããã¯éå¬ã«åããããã«ããŒãã£ã«ã¢ã·ã¹ã¿ã³ã (Google Assistant) ã®æŽ»çšã 5G 掻çšãªã©ã暡玢ããŠããã 4. ã€ã¿ãªã¢ã»ãããå·: 500äžäººåãã®å°æ¹èªæ²»äœãµãŒãã¹ã®å€é© cloud.google.com ãŽã§ããã¢åžãæããã€ã¿ãªã¢ã»ãããå·ã®å°æ¹å
Œ
±ãµãŒãã¹ã§ã¯ä»¥äžã®ææãå ±åãããŠããã 85,000 人ã®åŸæ¥å¡ã Google Workspace ã§ç®¡çã人ã®ç§»åã®å¿
èŠæ§ã 60% åæž ãªã³ãã¬ãœãªã¥ãŒã·ã§ã³ã«æ¯ã¹ä¿å¥å»çåœå±ã®éçšã³ã¹ãã 90% åæž å°æ¹èªæ²»äœãè·šãã çµ±åããžã¿ã«ãšã³ã·ã¹ãã ãæ§ç¯ãæ©æ¢°åŠç¿ã掻çšãã驿°çãªç®¡çããŒã«ãå©çš åå·ã§ã¯ããžã¿ã«æŠç¥ã®äžç°ãšããŠããã«ã¹ã±ã¢ã·ã¹ãã ã®ICTã€ã³ãã©ã®æŽæ¹ã決å®ããã åå·ã«ã¯ 13 ã®å°æ¹å»çåœå±ãååšããããããã«ããŒã¿ã»ã³ã¿ãŒãEã¡ãŒã«ãããã€ããŒãæã£ãŠããã å
¥æãçµãŠãæ§ç¯ããŒãããŒã®åãåããããã§ã 50 ãè¶
ããå»çæ©é¢ã® 70,000 人ã®åŸæ¥å¡ã Google Workspace ã«ç§»è¡ããã Google Workspace ã®ãµãŒãã¹ã§ãã Drive, Document, Spreadsheet, Meet ã®å©çšã«ãããè·å¡ã®å°åéã®ç§»åãåå以äžã«åæžã§ãããšããã ãŸãååžã¯ Vertex AI (æ§ Cloud Machine Learning Engine), Cloud Natural Language ããã³ Cloud Storage ãæŽ»çšããæ©æ¢°åŠç¿åãã©ã€ãã©ãªã§ãã TensorFlow ã䜿ã£ãæ©æ¢°åŠç¿ã掻çšããŠããããªã TensorFlow ã Google ãéçºãããªãŒãã³ãœãŒã¹ã ã å»çæ©é¢ã®èšºææžã®ç®¡çã®ããã«æ©æ¢°åŠç¿ã掻çšãããŠãããè§£æã«ããæ£ç¢ºãªèšºæã«æŽ»çšãããšãããŠããã ãŸã Apigee API Management Platform ãå©çšãããŠãããããã«ããåå°ã® 4,000 人以äžã®éæ¥å»ã®èšºå¯äºçŽæ
å ±ãåéãããŠããã Google Cloud ãš Google Workspace ã®æŽ»çšã«ãããããŒã¿ã»ã³ã¿ãŒã®ç®¡çéçšã«æ¯ã¹ãŠ 90% ã®éçšã³ã¹ãåæžã«ãªã£ãããšãåœå± CIO ãæããã«ããŠããã 5. ããª: å»çã±ã¢ã®ã¢ããã€ãŒãŒã·ã§ã³ www.youtube.com ããªåççã®ãã«ã¹ã±ã¢ã·ã¹ãã ã«é¢ããäºäŸãåç»ã§ç޹ä»ãããŠããã åçã§ã¯ãæ£è
ã®å»çæ
å ±ã®çµ±åã«èª²é¡ããã£ããšããã æ³çã¬ã®ã¥ã¬ãŒã·ã§ã³ã®ããšããããªãã¯ãªæ
å ±ãšãã©ã€ããŒããªæ
å ±ã API ã¬ããã³ã¹ã®ããšã§çµ±åããèšåºçŸå Žã§å©çšã§ããããã«ãããã Apigee ãå©çšããã åçã Apigee ãæ¡æããçç±ãšããŠãã·ã³ãã«ãªã¢ãŒããã¯ãã£ããã¹ããŒã¯ãã«ãã«æ
å ±ãå
±æããéã®ã»ãã¥ãªãã£ãã®2ã€ãäžããŠããã Apigee ã«ãã 2017 幎ãäœæ°ç¥šãšæ£è
æ
å ±ã®ç
§åããã¯ã¯ãã³æ
å ±ã®å
±æããããªãã¯ãšãã©ã€ããŒããªã»ã¯ã¿ãŒãè·šãã å»çæ
å ±ã®å
±æãªã©ã«åœ¹ç«ãŠããšããã ãããã£ãæ
å ±ã®çžäºéçšããå
¬çãªåºæºã«æºæ ããããã§å®çŸããããã« Apigee ãæŽ»çšããã ä»åŸããã¯ãããžãŒãããŒã¹ãšããŠãåœæ°ãèªãäºé²çãªå¥åº·ç¶æãã§ãããããªæœçã宿œããããšãä»åŸã®èª²é¡ã ãšããŠããã 6. ã¢ãªãŸãå·: ã¯ã©ãŠãã³ã©ãã¬ãŒã·ã§ã³ã§çç£æ§ãšã»ãã¥ãªãã£ãåäž workspace.google.com ç±³åœã¢ãªãŸãå·ã§ã Google Workspace ã䜿ã£ãŠçç£æ§åäžãå³ã£ãäºäŸãå
¬éãããŠããã ãªã¢ã«ã¿ã€ã ãªã³ã©ãã¬ãŒã·ã§ã³ã§çç£æ§ãåäž æããã10äž7åä»¶ãã£ãæå®³ãªã¡ãŒã«ãæé€ããã»ãã¥ãªãã£ãåäž 3å¹Žã§æ°çŸäžãã«ã®ã¹ãã¬ãŒãžãã©ã€ã»ã³ã¹ã管çã³ã¹ããç¯çŽ ã¢ãªãŸãå·ã®ã¯ã©ãŠããã¡ãŒã¹ãããªã·ãŒãå®çŸ ç±³åœã®å·ã®äžã§ IT æè¡ã®ãªãŒããŒçããžã·ã§ã³ã«äœçœ®ããã¢ãªãŸãå·ã¯ã 2018 幎ã«ã¯ã©ãŠããã¡ãŒã¹ãæ¹éãæ±ºå®ã ã»ãã¥ãªãã£ã®èгç¹ãã Google Workspace ãéžæããã åå·ã¯æ¢ã« Microsoft 365 ãå©çšããŠããããåœæã¯åå·ãæ±ããŠãããªã¢ã«ã¿ã€ã ã®ã³ã©ãã¬ãŒã·ã§ã³ããããªé話ã®èŠä»¶ãæºãããã代ããã« Google Workspace ã®æ¡çšã決å®ããã Okta ã«ãã Active Directory ãš Google Workspace ãçµ±åããŠã·ã³ã°ã«ãµã€ã³ãªã³ (SSO) ãå®çŸããããšã玹ä»ãããŠããã ãã©ãŠã¶ãšã㊠Chrome ãæ¡çšããŠããã»ãã Vault ã®æ©èœã䜿ã£ãŠé»åæ
å ±é瀺 (eDiscovery) ã«å¯Ÿå¿ããŠããã Vault ãšã¯ã Google Workspace ã® Business / Enterprise ãã©ã³ã«çµã¿èŸŒãŸããŠããæ©èœã§ã Gmail ã Drive ãšãã£ãåãµãŒãã¹ã®ããŒã¿ãä¿æãæ€çŽ¢ãæžãåºããè¡ãããšãã§ããæ©èœã ã åå·ã§ã¯1幎以å
ã« 22,000 人ã®è·å¡ã Google Workspace ãžç§»è¡ããæçµçã«ã¯ 36,000 ã®è·å¡ãé¢ä¿è
ãå©çšããããšã«ãªããšããã å°å
¥ã«ã¯ããŒãããŒã®ä»ã Google ã®ãããã§ãã·ã§ãã«ãµãŒãã¹ãååããã Gmail ã§ã¯ããã¢ã¯ãã£ããªä¿è·ã«ãããæ¯æ1åäžãè¶
ããã¹ãã ã¡ãŒã«ãæé€ããŠãããåå·ã®åŸæ¥åã®ãªã³ãã¬ãã¹ã®ä»çµã¿ã§ã¯æ€ç¥ã§ããªãã£ã10äžä»¶ä»¥äžã®æå®³ã¡ãŒã«ãã Gmail ã¯èªåæ€ç¥ããŠæé€ãããšããã åå·ã§ã¯ã»ãšãã©ã®ãã¡ã€ã«ãµãŒãã廿¢ã㊠Google Drive ã«ç§»è¡ããããŸã Google Meet ãåçš®ãµãŒãã¹ã䜿ã£ãé éã»ãªã¢ã«ã¿ã€ã ã®åãæ¹ã«ãæ
£ãã匷ãåµã«ãã£ãŠããŒã¿ã»ã³ã¿ãŒãæ©èœåæ¢ã«é¥ã£ãéããè·å¡ã¯èªå®
ããåãããšãã§ãããšããã ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãTwitter ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-genã®ææã§ããBigQuery ãžã®èªèšŒã»èªå¯ã¯ Cloud IAM ã«ãã£ãŠå¶åŸ¡ãããŸããããã®ä»çµã¿ã¯è€éã§ããåœèšäºã§ã¯ãä»çµã¿ã詳现ã«è§£èª¬ããŸãã ã¯ããã« BigQuery ãšèªèšŒã»èªå¯ IAM ã®åºæ¬æŠå¿µ BigQuery é¢é£ã® IAM æš©éã®çè§£ ãžã§ãå®è¡ãšããŒã¿ã¢ã¯ã»ã¹ ãžã§ãå®è¡æš©é ããŒã¿ãžã®ã¢ã¯ã»ã¹æš©é èªã¿åãæš©é èªã¿åãæš©éã®æ€èšŒ æžãèŸŒã¿æš©é ã¡ã¿ããŒã¿ãžã®ã¢ã¯ã»ã¹æš©é ããŒã«ãæã€ IAM æš©é ãŠãŒã¹ã±ãŒã¹å¥ IAM èšå® ãããžã§ã¯ãã®ãã¹ãŠã®ããŒã¿ã»ããã«å¯Ÿããé²èŠ§æš©éãäžããã èšå® 説æ ç¹å®ã®ããŒã¿ã»ããã«ã ãé²èЧã»ç·šéæš©éãäžããã èšå® 説æ ç¹å®ã®ãããžã§ã¯ãã® BigQuery å
šäœç®¡çè
èšå® 説æ BigQuery ã®ããŒã¿ãå«ããããžã§ã¯ãå
ã®å
šãªãœãŒã¹ã®é²èŠ§æš©éãäžããã èšå® 説æ é²èЧè
ããŒã«ã«é¢ããèå¯ ãã®ä»ã®ãŠãŒã¹ã±ãŒã¹ ã¯ããã« BigQuery ãšèªèšŒã»èªå¯ Google CloudïŒæ§ç§° GCPïŒã®ããŒã¿ãŠã§ã¢ããŠã¹ãµãŒãã¹ã§ãã BigQuery ã§ã¯ãèªèšŒã»èªå¯ã Identity and Access ManagementïŒIAMïŒã«ãã£ãŠå¶åŸ¡ãããŸãã Google Cloud ã® IAM ã®ä»çµã¿èªäœãé£ããããšã«å ããŠãBigQuery ã§ã¯ ãžã§ãå®è¡æš©é ãš ããŒã¿ååŸã»ç·šéæš©é ãå¥ããŠãããããåºæ¬ããŒã«ãã«ã¯ ç¹æ®ãªä»çµã¿ã§ æš©éãäžããããŠãããããšé£è§£ã§ãã åœèšäºã§ã¯ãå®ç°å¢ã§ã®æ€èšŒçµæã亀ããŠè§£èª¬ããŸãã IAM ã®åºæ¬æŠå¿µ ãŸã㯠Google Cloud ã® IAM ã®åºæ¬çãªä»çµã¿ãçè§£ããå¿
èŠããããŸããæ¬æçš¿ã§ã¯ä»¥äžã®èšäºã®å
容ãçè§£ãããŠããåæã§èšèŒããŠãããŸãã®ã§ãå
ã«ãåç
§ãã ããã ç¹ã«ããªãœãŒã¹ã®æã€èš±å¯ããªã·ãŒããããŒã«ããç¶æ¿ããªã©ã®çšèªçè§£ãå¿
é ã§ãã blog.g-gen.co.jp BigQuery é¢é£ã® IAM æš©éã®çè§£ ãžã§ãå®è¡ãšããŒã¿ã¢ã¯ã»ã¹ BigQuery ã® ãžã§ã ãšã¯ãBigQuery ã®ã³ã³ãã¥ãŒãã£ã³ã°ãªãœãŒã¹ã䜿ã£ãŠè¡ããã以äžã®ãããªæäœãæããŸãã ã¯ãšãªïŒããŒãã«ã®èªã¿åããæžã蟌ã¿ïŒ ããŒãïŒããŒãã«ãžã®ããŒã¿æå
¥ïŒ ãšã¯ã¹ããŒãïŒCloud Storage ãã±ãããªã©ã«ããŒã¿ãåºåïŒ ã³ããŒïŒããŒãã«ãè€è£œããïŒ ãããã®æäœããŠãŒã¶ãŒãããã°ã©ã ã«ããè¡ããããšããžã§ããäœæãããããã¯ã°ã©ãŠã³ãã§åŠçãè¡ãããŸããäŸãšããŠãã³ã³ãœãŒã«ã« SQL ãå
¥åããŠå®è¡ããããbq ã³ãã³ãã«ãã£ãŠ Cloud Storage ããã®ããŒã¿ããŒããªã©ãè¡ãéã«ããžã§ããå®è¡ãããŸãã åè : ãžã§ãã管çãã BigQuery ã§ã¯ããã®ã ãžã§ããå®è¡ããæš©é ããšã ããŒãã«ã®ããŒã¿ã«ã¢ã¯ã»ã¹ããæš©é ããåºå¥ãããŠããŸãã æ®æ®µä»äºã§äœ¿ãããœã³ã³ã«äŸãããšãããœã³ã³ã«ãã°ã€ã³ãããæš©éãšããã¡ã€ã«ãµãŒããžã®ã¢ã¯ã»ã¹æš©éãšã¯å¥ã«ãªã£ãŠããããšãããããªã€ã¡ãŒãžã§ãã ãžã§ãå®è¡æš©éãšããŒã¿ãžã®ã¢ã¯ã»ã¹æš©é å¥ããŠããçç±ã¯ã以äžã®äŸãèãããšçè§£ãããããªããŸãã Google ãå
¬éããŠãããããªãã¯ããŒã¿ã»ããã䜿ã£ãŠåæãè¡ãã±ãŒã¹ãèããŸããããŒã¿ã»ãããžã®ã¢ã¯ã»ã¹æš©éã¯å
šäžçã«å
¬éãããŠãããããŒã¿ã®ä¿ç®¡æéã¯ãããŒã¿ãä¿æããŠããäŒç€ŸïŒãããžã§ã¯ãïŒã«èª²éãããŠããŸãããããã¯ãšãªãžã§ãã¯ããŒã¿å©çšè
åŽã® Google Cloud ãããžã§ã¯ãã«æå
¥ããå¿
èŠããããã³ã³ãã¥ãŒãæéãããŒã¿ãå©çšããåŽãè² æ
ããŸãã ä»ãããžã§ã¯ãã®ããŒã¿ã䜿ãå Žå ãã®ããã«ããŒã¿ãä¿ç®¡ãããŠãŒã¶ãŒãšãã¯ãšãªãå®è¡ãããŠãŒã¶ãŒãããããŠãããšããIAM æš©éãå¥ã
ã«ç®¡çãããŠããããã«ã責任ç¯å²ãè²»çšè² æ
ãåå²ããããšãã§ããŸãã ãžã§ãå®è¡æš©é ãžã§ãå®è¡é¢é£ã® IAM æš©éã«ã¯ bigquery.jobs.create ã bigquery.jobs.get ã bigquery.jobs.list ãšãã£ããã®ããããŸãã ãžã§ããå®è¡ããã«ã¯ bigquery.jobs.create ã®æš©éãå¿
èŠã§ãããã®æš©éã¯ã以äžã®ãããªäºåå®çŸ©ããŒã«ã«å«ãŸããŠããŸãã BigQuery 管çè
ïŒ roles/bigquery.admin ïŒ BigQuery ãžã§ããŠãŒã¶ãŒ ïŒ roles/bigquery.jobUser ïŒ BigQuery ãŠãŒã¶ãŒ ïŒ roles/bigquery.user ïŒ BigQuery Studio ãŠãŒã¶ãŒ ïŒ roles/bigquery.studioUser ïŒ ãããã®ããŒã«ã¯ã ãããžã§ã¯ã ã¬ãã«ä»¥äžïŒçµç¹ããã©ã«ãããããžã§ã¯ãïŒã§ä»äžããå¿
èŠããããŸãããžã§ãã¯ãããžã§ã¯ãã® API ã«å¯ŸããŠæå
¥ãããã®ãªã®ã§ããããã®ããŒã«ãããŒã¿ã»ããã®ã¬ãã«ã«ä»äžããŠã广ããªãããããŒã«ã«ãã£ãŠã¯ä»äžã§ããªã仿§ã«ãªã£ãŠããŸãã ãã ãããžã§ãã®å®è¡æš©éã ããæã£ãŠããŠããããŒã¿ã«ã¢ã¯ã»ã¹ããããšã¯ã§ããŸãããæ¬¡ã«èšèŒããããŒã¿ãžã®ã¢ã¯ã»ã¹æš©éãå¿
èŠã§ãã ããŒã¿ãžã®ã¢ã¯ã»ã¹æš©é èªã¿åãæš©é BigQuery ã®ããŒãã«ãžã¯ãšãªçãè¡ãã«ã¯ããžã§ãå®è¡æš©éã«å ããŠã ããŒã¿ãžã®ã¢ã¯ã»ã¹æš©é ãå¿
èŠã§ããå
ã»ã©ã®ä»äºçšããœã³ã³ã®äŸãã䜿ããšããã¡ãã¯ãã¡ã€ã«ãµãŒããžã®ã¢ã¯ã»ã¹æš©éã§ãã ããŒãã«å
ã®ããŒã¿ã«èªã¿åãã¢ã¯ã»ã¹ããã«ã¯ã bigquery.tables.getData ã®æš©éãå¿
èŠã§ãããã®æš©éã¯ã以äžã®ãããªäºåå®çŸ©ããŒã«ã«å«ãŸããŠããŸãã BigQuery 管çè
ïŒ roles/bigquery.admin ïŒ BigQuery ããŒã¿ãªãŒããŒ ïŒ roles/bigquery.dataOwner ïŒ BigQuery ããŒã¿ç·šéè
ïŒ roles/bigquery.dataEditor ïŒ BigQuery ããŒã¿é²èЧè
ïŒ roles/bigquery.dataViewer ïŒ ãããã®ããŒã«ã¯ ãããžã§ã¯ã ã¬ãã«ã ããŒã¿ã»ãã ã¬ãã«ãããã㯠ããŒãã« ã¬ãã«ã§ä»äžããããšãã§ããŸãã芪ãªãœãŒã¹ã«ããŒã«ãä»äžããã°ããã®é
äžã«ããåãªãœãŒã¹ãã¹ãŠã«æš©éãç¶æ¿ãããŸãã äŸãã°ããããŒã¿ã»ããå
ã®ããŒã¿ã«èªã¿åãã¯ãšãªãå®è¡ãããå Žåããã®ãŠãŒã¶ãŒã®ã¢ã«ãŠã³ãã«ã ãããžã§ã¯ã ã¬ãã«ã§ BigQuery ãžã§ããŠãŒã¶ãŒ ïŒ roles/bigquery.jobUser ïŒãä»äžããã®ã«å ããŠã該åœã®ããŒã¿ã»ããã¬ãã«ã§ BigQuery ããŒã¿é²èЧè
ïŒ roles/bigquery.dataViewer ïŒãä»äžããŸããããã«ããããã®ãŠãŒã¶ãŒã¯ãããžã§ã¯ãã¬ãã«ã§ã®ãžã§ãå®è¡æš©éãšãããŒã¿ã»ããã¬ãã«ã§ã®ããŒã¿èªã¿åãæš©éãåŸãããšã«ãªããSELECT æçãå®è¡ããããšãã§ããŸãã èªã¿åãæš©éã®æ€èšŒ ããžã§ãå®è¡æš©éã¯ãããžã§ã¯ãã¬ãã«ã§ä»äžããå¿
èŠãããããããŠãããŒã¿ãžã®ã¢ã¯ã»ã¹æš©éã¯ããŒã¿ã»ããã¬ãã«ãããã¯ããŒãã«ã¬ãã«ã§ä»äžããããšèšèŒããããšã«ã€ããŠãæ€èšŒããŸãã BigQueryã®æš©éã®ãã£ã·ãžã§ã³ããŒãã« BigQuery ãžã§ããŠãŒã¶ãŒïŒ roles/bigquery.jobUser ïŒããŒã«ã¯ããŒã¿ã»ããåäœã§ã¯ä»äžã§ããªã仿§ã®ãããäžèšã®è¡šã§ã¯ N/A ãšãªã£ãŠããŸãã 衚ã®ãšããããããžã§ã¯ãã¬ãã«ã«ãžã§ãå®è¡æš©éããªãå Žåã«ã¯ã¯ãšãªãå®è¡äžå¯ïŒNïŒãšããçµæã«ãªããŸããã ãŸããžã§ãå®è¡æš©éããããã°ãããŒã¿èªã¿åãæš©éã¯ããŒã¿ã»ããã¬ãã«ã§ä»äžããããšã§ããŒã¿ãèªã¿åããããšããçµæã確ãããããŸããããªããããŒã¿ã»ããã¬ãã«ã§ãªããããŒãã«ã¬ãã«ã§æš©éãä»äžããããšã§ããããŒã¿ãèªã¿åãããšãã§ããŸãã æžãèŸŒã¿æš©é æžãèŸŒã¿æš©éã«ã€ããŠãåºæ¬çãªèãæ¹ã¯èªã¿åãæš©éãšåæ§ã§ãã æžã蟌ã¿ã¢ã¯ã»ã¹ã«å¿
èŠãªæš©é㯠bigquery.tables.updateData ã§ãããã®æš©éã¯ã以äžã®ãããªäºåå®çŸ©ããŒã«ã«å«ãŸããŠããŸãã BigQuery 管çè
ïŒ roles/bigquery.admin ïŒ BigQuery ããŒã¿ãªãŒããŒ ïŒ roles/bigquery.dataOwner ïŒ BigQuery ããŒã¿ç·šéè
ïŒ roles/bigquery.dataEditor ïŒ ã¡ã¿ããŒã¿ãžã®ã¢ã¯ã»ã¹æš©é ã¡ã¿ããŒã¿ã¯ããŒã¿ã»ãããããŒãã«ã®æã€ä»éçãªå±æ§æ
å ±ã§ããããŒãã«ã®ã¹ããŒãæ
å ±ãªã©ãããã«åœãããŸãã ä»äºå Žã®ããœã³ã³ã®äŸãã䜿ããšããã¡ã€ã«ãµãŒãã®ããŒã¿å®¹éã®äœ¿çšç¶æ³ããã£ã¹ã¯ã®ãã©ã€ãåããŸããã¡ã€ã«ã·ã¹ãã ã®èšå®å€ãªã©ãåœãããŸãã ããŒã¿ã»ããã®ã¡ã¿ããŒã¿ã«å¯Ÿããæš©éãšã㊠bigquery.datasets.get ã bigquery.datasets.update ããããããŒãã«ã®ã¡ã¿ããŒã¿ã«å¯Ÿããæš©éãšã㊠bigquery.tables.get ã bigquery.tables.update ãªã©ããããŸãã ã¡ã¿ããŒã¿ã®é²èЧã»ç·šéæš©éãããã°ãããŒãã«åãã«ã©ã æ
å ±ãåŸãããšãã§ããŸãããããŒãã«å
ã®ããŒã¿ïŒã¬ã³ãŒãïŒãé²èЧããããç·šéããããšã¯ã§ããŸããã äºåå®çŸ©ããŒã«ã§ãã BigQuery ããŒã¿ç·šéè
ïŒ roles/bigquery.dataEditor ïŒã BigQuery ããŒã¿é²èЧè
ïŒ roles/bigquery.dataViewer ïŒãªã©ã¯ãããŒã¿ã«å¯Ÿããæš©éã«å ããŠãã¡ã¿ããŒã¿ã«å¯Ÿããæš©éãæã£ãŠããŸãã äžæ¹ã§ã BigQuery ã¡ã¿ããŒã¿é²èЧè
ïŒ roles/bigquery.metadataViewer ïŒããŒã«ã¯ã¡ã¿ããŒã¿ã«å¯Ÿããèªã¿åãæš©éãæã£ãŠããŸããããŒã¿èªäœãžã®æš©éã¯ãªãã®ã§ã BigQuery åºç€ã®ç®¡çè
ã»éçšè
ãªã©ã䜿ãããšãæ³å®ãããŸãã ããŒã«ãæã€ IAM æš©é ã©ã® IAM ããŒã«ãã©ã®ãããªæš©éãæã£ãŠãããã確èªãããå Žåã以äžã®ããã¥ã¡ã³ããåç
§ããŸãã ããã¹ãããã¯ã¹ã«æš©éåãå
¥åããŠæ€çŽ¢ããããšã§ãããæš©éãæã€ããŒã«ã®äžèЧã確èªã§ããŸãããŸãéã«ãããŒã«åãæ€çŽ¢ããããšã§ããã®ããŒã«ãæã€æš©éã®äžèЧã確èªã§ããŸãã åè : IAM roles and permissions index ãŠãŒã¹ã±ãŒã¹å¥ IAM èšå® ãããžã§ã¯ãã®ãã¹ãŠã®ããŒã¿ã»ããã«å¯Ÿããé²èŠ§æš©éãäžããã èšå® ä»äžå¯Ÿè±¡ãªãœãŒã¹ ãããžã§ã¯ã ä»äžãã IAM ããŒã« BigQuery Studio ãŠãŒã¶ãŒ ïŒ roles/bigquery.studioUser ïŒ BigQuery ããŒã¿é²èЧè
ïŒ roles/bigquery.dataViewer ïŒ èª¬æ ãããžã§ã¯ãã¬ãã«ã§ãGoogle ã¢ã«ãŠã³ãã«å¯ŸããŠäžèšã®2ã€ã®ããŒã«ãä»äžããããšã§ããã®ã¢ã«ãŠã³ãã¯ãããžã§ã¯ãå
ã®ãã¹ãŠã®ããŒã¿ã»ããã»ããŒãã«ã«å¯ŸããŠèªã¿åãã¯ãšãªãå®è¡ããããšãã§ããããã«ãªããŸãã BigQuery Studio ãŠãŒã¶ãŒïŒ roles/bigquery.studioUser ïŒããŒã«ããããžã§ã¯ãã¬ãã«ã§èšå®ããããšã«ãããã¢ã«ãŠã³ã㯠BigQuery ãžã§ããå®è¡ããæš©éãåŸãŸãã BigQuery Studio ãŠãŒã¶ãŒããŒã«ã®ä»£ããã« BigQuery ãžã§ããŠãŒã¶ãŒïŒ roles/bigquery.jobUser ïŒããŒã«ã§ãæ§ããŸããããBigQuery Studio ãŠãŒã¶ãŒããŒã«ãä»äžããããšã§ Gemini in BigQuery ãå«ããBigQuery StudioïŒBigQuery ã® Web ã³ã³ãœãŒã«ïŒã®ã»ãšãã©ãã¹ãŠã®æ©èœãå©çšããããšãã§ããŸããGemini in BigQuery ã¯çæ AI ã SQL ã³ãŒãã£ã³ã°ã®è£å©çãããŠãããæ©èœã§ãããå¶éä»ããªããç¡åã§å©çšã§ããŸãã ããããŒã«ã®ä»äžå¯Ÿè±¡ã人éã®ãŠãŒã¶ãŒã§ã¯ãªããµãŒãã¹ã¢ã«ãŠã³ãã§ããå ŽåãBigQuery Studio ãŠãŒã¶ãŒããŒã«ããã BigQuery ãžã§ããŠãŒã¶ãŒããŒã«ã®æ¹ãé©ããŠããŸãã äžèšã«å ããBigQuery ããŒã¿é²èЧè
ïŒ roles/bigquery.dataViewer ïŒããããžã§ã¯ãã¬ãã«ã«èšå®ããããšã§ãã¢ã«ãŠã³ãã¯ãããžã§ã¯ãå
ã®å
šãŠã®ããŒã¿ã»ãããšããŒãã«ã«å¯ŸããŠé²èŠ§æš©éãæã¡ãŸãã ç¹å®ã®ããŒã¿ã»ããã«ã ãé²èЧã»ç·šéæš©éãäžããã èšå® IAM èšå® 1 ä»äžå¯Ÿè±¡ãªãœãŒã¹ ãããžã§ã¯ã ä»äžãã IAM ããŒã« BigQuery Studio ãŠãŒã¶ãŒ ïŒ roles/bigquery.studioUser ïŒ IAM èšå® 2 ä»äžå¯Ÿè±¡ãªãœãŒã¹ ããŒã¿ã»ãã ä»äžãã IAM ããŒã« BigQuery ããŒã¿ç·šéè
ïŒ roles/bigquery.dataEditor ïŒ èª¬æ äžèšã® IAM èšå® 1 ãš 2 ã®äž¡æ¹ãããªãã¡ãããžã§ã¯ãã¬ãã«ãšããŒã¿ã»ããã¬ãã«ã®äž¡æ¹ã§ãã¢ã«ãŠã³ãã«å¯ŸããŠããŒã«ãä»äžããããšã§ãç¹å®ã®ããŒã¿ã»ããã«å¯ŸããŠã®ã¿ãINSERT ã UPDATEãSELECT ã®å®è¡ãªã©ããŒã¿ã®èªã¿åãã»ç·šéæš©éãåŸãããšãã§ããŸãã BigQuery Studio ãŠãŒã¶ãŒïŒ roles/bigquery.studioUser ïŒããŒã«ãªã©ããããžã§ã¯ãã¬ãã«ã§ä»äžããããšã§ãã¢ã«ãŠã³ãã¯ãžã§ããå®è¡ã§ããããã«ãªããŸãããªãåããŒã«ã¯ããŒã¿ã»ããã¬ãã«ã«ã¯ä»äžã§ããªã仿§ã§ãããå¿
ããããžã§ã¯ãã¬ãã«ä»¥äžã«ããä»äžã§ããŸããã ãŸã BigQuery ããŒã¿ç·šéè
ïŒ roles/bigquery.dataEditor ïŒãããŒã¿ã»ããã¬ãã«ã§ä»äžããããšã§ããã®ããŒã¿ã»ããã«å¯ŸããŠã®ã¿ãããŒã¿ã®ç·šéæš©éãæã€ããšãã§ããŸããäžæ¹ã§ãããžã§ã¯ãã¬ãã«ã«èšå®ãããšããããžã§ã¯ãå
ã®å
šãŠã®ããŒã¿ã»ãããšããŒãã«ã«å¯ŸããŠç·šéæš©éãæã€ããšãã§ããŸãã ç¹å®ã®ãããžã§ã¯ãã® BigQuery å
šäœç®¡çè
èšå® ä»äžå¯Ÿè±¡ãªãœãŒã¹ ãããžã§ã¯ã ä»äžãã IAM ããŒã« BigQuery 管çè
ïŒ roles/bigquery.admin ïŒ èª¬æ ãããžã§ã¯ãã¬ãã«ã§ BigQuery 管çè
ïŒ roles/bigquery.admin ïŒããŒã«ãä»äžããã°ããã®ã¢ã«ãŠã³ãã¯ãžã§ãã®å®è¡ãããŒã¿ãžã®ã¢ã¯ã»ã¹ãããŒã¿ã»ãããããŒãã«ã®äœæããªã© BigQuery ã«é¢ããå
šãŠã®æäœãè¡ãããšãã§ããŸãã BigQuery ã®ããŒã¿ãå«ããããžã§ã¯ãå
ã®å
šãªãœãŒã¹ã®é²èŠ§æš©éãäžããã èšå® ä»äžå¯Ÿè±¡ãªãœãŒã¹ ãããžã§ã¯ã ä»äžãã IAM ããŒã« é²èЧè
ïŒ roles/viewer ïŒ èª¬æ ãã Google ã¢ã«ãŠã³ãã é²èЧè
ïŒ roles/viewer ïŒããŒã«ããããžã§ã¯ãã¬ãã«ã§æã£ãŠãããšãBigQuery ã®å
šããŒã¿ã»ããã»ããŒãã«ã®ããŒã¿ãšã¡ã¿ããŒã¿ãé²èЧããããšãã§ããŸãã é²èЧè
ã¯ãBigQuery 以å€ã®ã»ãšãã©ãã¹ãŠã®æ
å ±ã«å¯Ÿããé²èŠ§æš©éãæã€ãããæ³šæãå¿
èŠã§ãã é²èЧè
ããŒã«ã«é¢ããèå¯ é²èЧè
ïŒ roles/viewer ïŒããŒã«ãš BigQuery ã®é¢ä¿æ§ã«ã€ããŠã詳现ã«è§£èª¬ããŸãã é²èЧè
ïŒ roles/viewer ïŒããŒã«ã®æã€ BigQuery é¢ä¿ã®æš©éãäžèЧåãããšã以äžã®ããã«ãªããŸãã sugimura@cloudshell:~ ( gcp-dev-yuma-sugimura ) $ gcloud iam roles describe roles/viewer | grep bigquery - bigquery.bireservations.get - bigquery.capacityCommitments.get - bigquery.capacityCommitments.list - bigquery.config.get - bigquery.connections.get - bigquery.connections.getIamPolicy - bigquery.connections.list - bigquery.connections.use - bigquery.datasets.get - bigquery.datasets.getIamPolicy - bigquery. jobs .create - bigquery. jobs .get - bigquery. jobs .list - bigquery.models. export - bigquery.models.getData - bigquery.models.getMetadata - bigquery.models.list - bigquery.readsessions.create - bigquery.readsessions.getData - bigquery.readsessions.update - bigquery.reservationAssignments.list - bigquery.reservationAssignments.search - bigquery.reservations.get - bigquery.reservations.list - bigquery.routines.get - bigquery.routines.list - bigquery.rowAccessPolicies.getIamPolicy - bigquery.rowAccessPolicies.list - bigquery.savedqueries.get - bigquery.savedqueries.list - bigquery.tables.createSnapshot - bigquery.tables.getIamPolicy - bigquery.transfers.get äžèšããæç²ãããšãBigQuery ã®ããŒãã«ã«é¢ããæš©éã¯ä»¥äžã®2ã€ã ãã§ãã - bigquery.tables.createSnapshot - bigquery.tables.getIamPolicy ããã§ã¯ãé²èЧè
ããŒã«ã¯ããŒãã«ã®ã¡ã¿ããŒã¿ãããŒã¿ã«å¯Ÿããã¢ã¯ã»ã¹æš©éã¯æããªãã¯ãã§ããåè¿°ã®éããããŒã¿ã«ã¢ã¯ã»ã¹ããã«ã¯ bigquery.tables.getData ã®æš©éãå¿
èŠã§ãã bigquery.jobs.create æš©éã¯ããã®ã§ãžã§ãå®è¡ã¯ã§ããŸãããããŒãã«ã®ããŒã¿ã¯èªã¿åãããAccess Denied ãšã©ãŒã«ãªãã¯ãã§ãã ãããå®éã«ã¯ãããŒãã«ã®ããŒã¿ãååŸããããšãã§ããŸããããã¯ãBigQuery ãæ°èŠããŒã¿ã»ããã«å¯ŸããŠããã©ã«ãã§ä»äžããã以äžã®èšå®ãé¢ä¿ããŠããŸãã é²èЧè
ããŒã«ãæã€ããšã¯ BigQuery ããŒã¿é²èЧè
ããŒã«ãæã€ããšãšå矩 äžã®ã¹ã¯ãªãŒã³ã·ã§ããã®éãããããžã§ã¯ãã¬ãã«ã§é²èЧè
ïŒ roles/viewer ïŒããŒã«ãä»äžãããŠãã人ã¯ãããŒã¿ã»ããã«å¯Ÿã㊠BigQuery ããŒã¿é²èЧè
ïŒ roles/bigquery.dataViewer ïŒçžåœã®æš©éãæã€ããã«èšå®ãããŠããŸãããã㯠IAM ã®ä»çµã¿ãšã¯ç°ãªããã¬ã¬ã·ãŒãªã¢ã¯ã»ã¹æš©éã®ä»çµã¿ã«èµ·å ããŠããŸãã ããã¯ãããŒã¿ã»ãããæ°èŠäœæãããšãã«èªåã§èšå®ããããBigQuery ç¹æã®èšå®ã§ããããã«ãããé²èЧè
ïŒ roles/viewer ïŒããŒã«èªäœã¯ bigquery.tables.getData æš©éãæã£ãŠããªããããæ¬æ¥ã¯ããŒã¿ã«ã¢ã¯ã»ã¹ã§ããªãã¯ãã§ãããããŒã¿ã»ããåŽã®åå¥èšå®ã§ BigQuery ããŒã¿é²èЧè
ïŒ roles/bigquery.dataViewer ïŒçžåœã®æš©éãäžããããŠããããã¢ã¯ã»ã¹ãã§ããããã«ãªã£ãŠããŸãã åè : Basic roles and permissions åæ§ã«ãããžã§ã¯ãã¬ãã«ã® ãªãŒããŒ ïŒ roles/owner ïŒã«ã¯ BigQuery ããŒã¿ãªãŒããŒ ïŒ roles/bigquery.dataOwner ïŒçžåœã®æš©éãããããžã§ã¯ãã¬ãã«ã® ç·šéè
ïŒ roles/editor ïŒã«ã¯ BigQuery ããŒã¿ç·šéè
ïŒ roles/bigquery.dataEditor ïŒæš©éãå²ãåœãŠãããŸãã ãããã®èªåã§å²ãåœãŠãããæš©éã¯ãåé€ããããšãå¯èœã§ãã ãã®ä»ã®ãŠãŒã¹ã±ãŒã¹ 以äžã®å
¬åŒããã¥ã¡ã³ãã«ãBigQuery é¢é£ã®äºåå®çŸ©ããŒã«ãã©ã®ãããªæš©éãæã£ãŠããŠãã©ã®ãªãœãŒã¹ã«ä»äžå¯èœãªã®ããäžèЧåãããŠããŸãã åœèšäºã®å
容ãçè§£ããããšã¯ã以äžã®ããŒãžãåç
§ãããã现ããæš©éèšå®ãæ€èšããŠãã ããã åè : BigQuery ã® IAM ããŒã«ãšæš©é ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãX (æ§ Twitter) ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-gen ã®ææã§ããGoogle CloudïŒæ§ç§° GCPïŒã®èšŒè·¡ç®¡çã®ä»çµã¿ã§ãã Cloud Audit Logs ïŒCloud Audit LoggingïŒã«ã€ããŠè§£èª¬ããŸãã Cloud Audit Logs ã®åºæ¬ Cloud Audit Logs ãšã¯ API ãªã¯ãšã¹ããšã¯ Cloud Audit Logs ã§èšé²ã§ãããã° ãã°ã®åºåå
æé èãæ¹ ç£æ»ãã°ã®æé ç£æ»ãã°ã®çš®é¡ 4 ã€ã®ç£æ»ãã° No 1. 管çã¢ã¯ãã£ããã£ç£æ»ãã° No 2. ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã° No 3. ã·ã¹ãã ã€ãã³ãç£æ»ãã° No 4. ããªã·ãŒæåŠç£æ»ãã° ãã°ã®ä¿åæé ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ã®æå¹å æå¹åæé 3ã€ã®çš®é¡ é€å€ããããªã³ã·ãã« ç£æ»ãã°ã®éçŽ éçŽã®å¿
èŠæ§ èšå®æé ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ãš Cloud Storage ã®èªèšŒæžã¿ URL Cloud Audit Logs ã®åºæ¬ Cloud Audit Logs ãšã¯ Cloud Audit Logs ãšã¯ãGoogle CloudïŒæ§ç§° GCPïŒã® API ãªã¯ãšã¹ãå±¥æŽãèšé²ããä»çµã¿ã§ãã ç£æ»å¯Ÿå¿ããã©ãã«ã·ã¥ãŒãã£ã³ã°ã«æŽ»çšããããšãã§ããŸãããã®ä»çµã¿ã«ãã Google Cloud ã§ããã€ã誰ããã©ããããäœããããããèªåçã«èšé²ãããŸãã äžéšã®èšé²ã¯ããã©ã«ãã§ãªã³ã«ãªã£ãŠãããèšå®å€æŽã«ãã£ãŠããã«åºãç¯å²ã®ãã°ãèšé²ãããããã«ãªããŸãã åè : Cloud Audit Logs overview API ãªã¯ãšã¹ããšã¯ ãŸããå¿
èŠãªåæç¥èã確èªããŸããCloud Audit Logs ã¯ã Google Cloud ã«å¯Ÿãã API ãªã¯ãšã¹ãã蚌跡管çã®ç®çã§èšé²ãããµãŒãã¹ã§ããã§ã¯ãããã§ãããAPI ãªã¯ãšã¹ãããšã¯äœã§ããããïŒ Amazon Web ServicesïŒAWSïŒãå§ããå€ãã®ãããªãã¯ã¯ã©ãŠãã¯ãã€ã³ã¿ãŒãããã«å
¬éããã Web API ã§æäœãããŸããGoogle Cloud ãã»ãŒå
šãŠã®ãªãœãŒã¹ã Web API çµç±ã§æäœ ïŒé²èЧãäœæãæŽæ°ãåé€ïŒãããŸããäŸãã°ã以äžã®ãããªæäœã¯å
šãŠ Web API ãªã¯ãšã¹ãã§è¡ãããŸãã VM ã®é²èЧãäœæãèµ·åã忢 Cloud Storage ãžã®ãªããžã§ã¯ãã®ListãGetãPutãDelete BigQuery ãžã®ã¯ãšãªãã¡ã¿ããŒã¿ã®é²èŠ§ãæŽæ° API ãªã¯ãšã¹ããšå±¥æŽã®èšé² AWS ã Google Cloud ã Web ã³ã³ãœãŒã«ç»é¢ã§æäœãããšããŠãããã® Web ç»é¢ã®ããã¯ãšã³ãã§ã¯ã Web API ãªã¯ãšã¹ããçºè¡ãããŠãã ãšèããŠãã ããã ãããªãã¯ã¯ã©ãŠãã® Web API ã¯ã€ã³ã¿ãŒãããã«å
¬éãããŠããŸããã誰ã§ã API ãå®è¡ã§ããããã§ã¯ãªããIAM ã®ä»çµã¿çã§èªèšŒã»èªå¯ãããŠããŸãã®ã§ãã»ãã¥ãªãã£ãä¿ãããŸãã Google Cloud ã§ã¯ãåãµãŒãã¹ããšã« Web API ã®ãšã³ããã€ã³ããçšæãããŠããŸãããªããããã® API ãç·ç§°ã㊠Google Cloud APIs ãšåŒã³ãŸãã äžæ¹ã§ã以äžã®ãããªã¢ã¯ã»ã¹ã¯ Web API ãªã¯ãšã¹ããšã¯å¥ã§ãã VM ãžã® SSH ã¢ã¯ã»ã¹ VM ã§ãã¹ãããã Web ãµã€ããžã® HTTPïŒSïŒãªã¯ãšã¹ã ããã㯠Virtual Private CloudïŒVPCïŒãšããä»®æ³ãããã¯ãŒã¯å
ã® VM ã«å¯ŸããŠãTCP/IP çã«ãªãŒãããã¢ã¯ã»ã¹ã§ãã®ã§ãã¯ã©ãŠãã® Web API ãšã¯å¥ã®çµè·¯ã§ã¢ã¯ã»ã¹ããããšã«ãªããŸãã Google Cloud APIs ã®è©³çްã«ã€ããŠã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp Cloud Audit Logs ã§èšé²ã§ãããã° Cloud Audit Logs ã«ããããã€èª°ã Google Cloud ãµãŒãã¹ã«å¯Ÿã㊠Web API ãªã¯ãšã¹ããè¡ãããªãœãŒã¹ã®é²èЧãäœæãç·šéãåé€çãè¡ã£ãããèšé²ãããŸãã ãããã®èšé²ã¯ãç£æ»èšŒè·¡ãšããŠãããªãã¬ãŒã·ã§ã³ãã¹ãã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®äºåŸèª¿æ»ããå
éšçã®ææ¢ããå©çšç¶æ³ã®åæããªã©ã«çšããããŸãã Cloud Audit Logs ã«èšé²ãããã®ã¯ã Google Cloud APIs ã«å¯Ÿãããªã¯ãšã¹ã ã§ããäžæ¹ã§ãåã®å°èŠåºãã§æåŸã«ç€ºããã VPC ãžã® TCP/IP çãªã¢ã¯ã»ã¹ã¯èšé²ãããŸãã ã åŸè
ã®å±¥æŽãèšé²ããã®ã¯ãVPC ã®æ©èœã§ãã VPC Flow Logs ããã¡ã€ã¢ãŠã©ãŒã«ãã°ããããã¯ã¢ããªã±ãŒã·ã§ã³åŽã®ãã®ã³ã°ã®åœ¹å²ã§ãã ãªããCloud Audit Logs ã«å¯Ÿå¿ããŠãã Google Cloud ãµãŒãã¹ã®äžèЧã¯ã以äžã®ããã¥ã¡ã³ãã«ç€ºãããŠããŸãã åè : ç£æ»ãã°ã䜿çšãã Google Cloud ãµãŒãã¹ ã»ãšãã©ãã¹ãŠã® Google Cloud ãµãŒãã¹ã Cloud Audit Logs ã§ã«ããŒãããŠããäžæ¹ãGoogle AI StudioïŒ generativelanguage.googleapis.com ïŒãªã©ãGoogle Cloud ã§ã¯ãªããµãŒãã¹ã¯å¯Ÿè±¡ã«ãªã£ãŠããŸããã ãã°ã®åºåå
Cloud Audit Logs ã«ããèšé²ããããã°ã¯ã Google Cloud ã®ãã°ç®¡çãµãŒãã¹ã§ãã Cloud Logging ã«ä¿åãããŸãã Cloud Logging ã«ã€ããŠã¯ä»¥äžã®èšäºã§è©³çްã«è§£èª¬ããŠããŸãã®ã§ããåç
§ãã ããã blog.g-gen.co.jp æé èãæ¹ Cloud Audit Logs èªäœã«æéã¯çºçããŸããããããããã°ã® ä¿åå
ã§ãã Cloud Logging ã®æé ãçºçããŸãã Cloud Logging ã®æéã¯ãããã°ã®åã蟌ã¿éãããã°ã®ä¿ç®¡éãã®ããããã«å¯ŸããåŸé課éã§ããåè
ã¯ãæã« 50 GiB ãŸã§ç¡æã§ããããè¶
ããéã«å¯ŸããŠæéãçºçããŸããåŸè
ã¯ãããã©ã«ãã®ä¿ç®¡æéã§ããã°ç¡æã§ããããã°ã®ä¿ç®¡æéãé·ãããå Žåã«çºçããŸãã åè : Google Cloud Observability ã®æé - Cloud Logging ã®æéæŠèŠ åè : Cloud Loggingã®æŠå¿µãšä»çµã¿ããã£ãã解説 - G-gen Tech Blog - æé ç£æ»ãã°ã®æé ããã©ã«ãã§åºåãããç£æ»ãã°ïŒç®¡çã¢ã¯ãã£ããã£ç£æ»ãã°ãªã©ïŒã«ã€ããŠã¯ãããã©ã«ãã§ Cloud Logging ãã°ãã±ããã§ãã _Required ãã°ãã±ããã«ä¿ç®¡ãããŸããç¹ã«èšå®ã倿Žããªããã°ããã°ã®ä¿ç®¡éãã«å¯Ÿãã課éã¯çºçãããç¡æã§ä¿ç®¡ã§ããŸãããŸãããããžã§ã¯ãå
šäœã®ãã°ã®åã蟌ã¿ããªã¥ãŒã ã®åèšãç¡ææ ã§ãã 50 GiB ãè¶
ããªããã¡ã¯ãããã°ã®åã蟌ã¿éãã«å¯ŸããæéãçºçããŸããã åè : 転éãšã¹ãã¬ãŒãžã®æŠèŠ - _Required ãã°ãã±ãã ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ãæç€ºçã«æå¹åããå Žåã VPC Service Controls ãæå¹åããŠããªã·ãŒæåŠç£æ»ãã°ãçºçããå Žåãç¹ã«èšå®ã倿Žããªããã°ãããã®ãã°ã¯ _Default ãã°ãã±ããã«åºåãããããã©ã«ãã®ä¿ç®¡æéã§ããã30æ¥éãã倿Žããªãéããããã°ã®ä¿ç®¡éãã«å¯Ÿãã課éã¯çºçããŸããããŸãããããžã§ã¯ãå
šäœã®ãã°ã®åã蟌ã¿ããªã¥ãŒã ã®åèšã 50 GiB ãè¶
ããªããã°ãããã°ã®åã蟌ã¿éãã«å¯ŸããæéãçºçããŸããããã ãã䜿çšç¶æ³ãèšå®å
容ã«ããããŸãããããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ã¯å€§éã«çºçããåŸåããããŸãããã°ã®çºçéã«ã¯æ³šæãå¿
èŠã§ãã åè : 転éãšã¹ãã¬ãŒãžã®æŠèŠ - _Default ãã°ãã±ãã ç£æ»ãã°ã®çš®é¡ 4 ã€ã®ç£æ»ãã° Cloud Audit Logs ã§ã¯åè¿°ã®éãã Google Cloud ãµãŒãã¹ã«å¯Ÿãã Web API ãªã¯ãšã¹ãã®å±¥æŽãèšé²ãããŸãããèšé²ããããã°ã«ã¯ããã€ãã®çš®é¡ããããŸãããããã®ãã¡ã«ã¯ãããã©ã«ãã§æå¹åãããŠãããã°ãããã°ãä»»æã§å©çšè
ãæå¹åããå¿
èŠããããã®ããããŸãã No åç§° èª¬æ æé ããã©ã«ã 1 管çã¢ã¯ãã£ããã£ç£æ»ãã° (Admin Activity audit logs) ãªãœãŒã¹ã«å¯Ÿãã管ççãªæŽæ°ç³»ã® API ãªã¯ãšã¹ããèšé²ããã ç¡æ æå¹ (ç¡å¹åã§ããªã) 2 ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã° (Data Access audit logs) ãªãœãŒã¹ãããŒã¿ã«å¯ŸããæŽæ°ç³»ã»èªã¿åã系㮠API ãªã¯ãšã¹ããèšé²ããããæå¹åãããšãã°å®¹éã倧ãããªãå¯èœæ§ãããããæ³šæ ææ ç¡å¹ (BigQueryã®ã¿ããã©ã«ãæå¹) 3 ã·ã¹ãã ã€ãã³ãç£æ»ãã° (System Event audit logs) ãŠãŒã¶ã§ã¯ãªãGoogle CloudãµãŒãã¹ã«ãã£ãŠè¡ããããªãœãŒã¹æ§æå€æŽãèšé²ããã ç¡æ æå¹ (ç¡å¹åã§ããªã) 4 ããªã·ãŒæåŠç£æ»ãã° (Policy Denied audit logs) VPC Service Controls æ©èœã§æåŠããã API ãªã¯ãšã¹ããèšé²ããã ææ æå¹ (é€å€ãã£ã«ã¿èšå®å¯èœ) åè: ç£æ»ãã°ã®çš®é¡ No 1. 管çã¢ã¯ãã£ããã£ç£æ»ã㰠管çã¢ã¯ãã£ããã£ç£æ»ãã° ã¯ã æŽæ°ç³» ã® API ãªã¯ãšã¹ãã®ããšã§ããçµç¹ããããžã§ã¯ãã§ãããã©ã«ãã§æå¹åãããŠããŸãã Compute Engine VM ãäœæãããããCloud Storage ã®ãã±ãããäœæã»åé€ããããããéã«ããã®ãã°ãåºåãããŸãã æŽæ°ç³»æäœã¯èšŒè·¡ç®¡çäžã®éèŠåºŠãé«ããããããã©ã«ãã§æå¹ãšãªã£ãŠããã400æ¥éä¿åãããŸããç¡å¹åã¯ã§ããŸããããæéãçºçããŸããã No 2. ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã° ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã° ã¯ã ããŒã¿ã«å¯Ÿããèªã¿åãç³»ããã³æŽæ°ç³»ã®ãã° ãèšé²ãããŸããBigQuery ãé€ããããã©ã«ãã§ã¯ãªãã«ãªã£ãŠããŸããäžè¬çã«ãããŒã¿ã®æŽæ°ã»èªã¿åãã¢ã¯ã»ã¹ã¯æžã蟌ã¿ã«æ¯ã¹ãŠé »åºŠãå€ãããšãããããŒã¿éã倧ãããªããå©çšããªã¥ãŒã ã«ãã£ãŠã¯æéãé«é¡ã«ãªãå¯èœæ§ããããŸãã BigQuery ã®ã¿ãããã©ã«ãã§ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ãæå¹åãããŠãããç¡å¹åã¯ã§ããŸããã ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ãšããŠèšé²ããããªãã¬ãŒã·ã§ã³ã®äŸãšããŠãCloud Storage ã®ãªããžã§ã¯ãã®äœæãåé€ããªããžã§ã¯ãã®äžèŠ§è¡šç€ºããªããžã§ã¯ãã®ååŸãªã©ããããŸããã©ã®ãªãã¬ãŒã·ã§ã³ãããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ã«åœãããã¯ããµãŒãã¹ããšã®ããã¥ã¡ã³ãã«èšèŒãããŠããŸãã åè : Cloud Storage ã§ã® Cloud Audit Logs ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ã¯ Google Cloud ãµãŒãã¹åäœã§æå¹åããããšãã§ããŸããæå¹åãããšããã°ã®åã蟌ã¿éãä¿åéãä¿åæéã«å¿ã㊠Cloud Logging ã®æéãçºçããŸãã ããŒã¿ã®èªã¿åããæŽæ°ã®é »åºŠãå€ããšãããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ã«å¯ŸããŠå€é¡ã®å©çšæéãçºçããå¯èœæ§ããããããç¹ã«éèŠãªããŒã¿ãæ±ãå¯èœæ§ããããµãŒãã¹ãéžå®ããå¿
èŠæ§ãšã³ã¹ãã®ãã¬ãŒããªããæ€èšããŠããæå¹åããŠãã ããã äŸãšããŠãå人æ
å ±ãæ ŒçŽããŠãã Cloud Storage ãã±ãããååšãããããžã§ã¯ããªã©ã§ãããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ãæå¹åããããšãæ€èšããŸãã ãŸããCloud Logging ã®é€å€ãã£ã«ã¿èšå®ã«ãããèšé²ããããã°ããã£ã«ã¿ããããšã§æéãç¯çŽããããšãã§ããŸãã åè : é€å€ãã£ã«ã¿ No 3. ã·ã¹ãã ã€ãã³ãç£æ»ãã° ã·ã¹ãã ã€ãã³ãç£æ»ãã° ã¯ã人éã®ãŠãŒã¶ãŒã«ãã API ãªã¯ãšã¹ãã§ã¯ãªãã Google Cloud ãµãŒãã¹åŽã®ãªã¯ãšã¹ãã«ãããªãœãŒã¹ã«å€æŽããã£ãéã«èšé²ãããŸãã ã·ã¹ãã ã€ãã³ãç£æ»ãã°ã¯ããã©ã«ãã§æå¹åãããŠãããç¡å¹åã¯ã§ããŸããããŸããæéãçºçããŸããã No 4. ããªã·ãŒæåŠç£æ»ãã° ããªã·ãŒæåŠç£æ»ãã° ã¯ãVPC Service Controls ã®ããªã·ãŒãéåããããšãã«èšé²ããããã°ã§ãã ããªã·ãŒæåŠç£æ»ãã°ã®èšé²ãšä¿åã«ã¯ Cloud Logging æéãçºçããŸããæéãç¯çŽãããå ŽåãCloud Logging ã®é€å€ãã£ã«ã¿èšå®ã«ãããã£ã«ã¿ãæ€èšããŠãã ããã VPC Service Controls ã«ã€ããŠã¯ã以äžããåç
§ãã ããã blog.g-gen.co.jp ãã°ã®ä¿åæé ããã©ã«ãã§æå¹åãããŠããç£æ»ãã°ã¯ãçµç¹ãåãã©ã«ããåãããžã§ã¯ãã«ããã©ã«ãã§ååšãããã°ãã±ãã _Required ã«ä¿åããã 400æ¥é ä¿æãããŸãã ãã°ãã±ãã ãšã¯ããã°ãä¿åããããã® Cloud Logging å°çšã¹ãã¬ãŒãžã§ãããCloud Storage ãã±ãããšã¯ååã䌌ãŠããŸãããå¥ç©ã§ãã _Required ãã°ãã±ããã®ä¿åæéã¯å€æŽããããšãã§ããªãããã400æ¥é以äžãã°ãä¿æãããå ŽåãCloud Logging ã§ã·ã³ã¯ïŒãã°ãéžå¥ããŠä¿åå
ãžã«ãŒãã£ã³ã°ããããã®ä»çµã¿ïŒãäœæããŠãããé·ãä¿åæéãèšå®ããå¥ã®ãã°ãã±ããã Cloud Storage ãã±ãããBigQuery çã«ãã°ãä¿åããŸãã ãŸããããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ãæå¹åãããš _Default ãã°ãã±ããã«ä¿åãããŸãã _Default ãã°ãã±ããã®ä¿ææé㯠30æ¥é ã§ãã _Default ãã°ãã±ããã®ä¿åæéã¯å€æŽã§ãããããããé·ãä¿åæéãæ±ããããå Žåã¯ä¿åæéã倿Žããããã·ã³ã¯ãäœæããŠå¥ã®ã¹ãã¬ãŒãžã«ãã°ãä¿åããŸãã ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ã®æå¹å æå¹åæé ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ãæå¹åããã«ã¯ãGoogle Cloud ã® Web ã³ã³ãœãŒã«ãgcloud ã³ãã³ãã©ã€ã³ãREST API ãªã©ãå©çšããŸããè©³çŽ°ãªæé ã¯ä»¥äžã®èšäºãåç
§ããŠãã ããã åè : ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ãæå¹ã«ãã 3ã€ã®çš®é¡ ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ã«ã¯ã3çš®é¡ã®æå¹åãªãã·ã§ã³ããããŸãã åç§° 説æ ADMIN_READ ã¡ã¿ããŒã¿ãæ§ææ
å ±ã«å¯Ÿããèªã¿åããªãã¬ãŒã·ã§ã³ãèšé² DATA_READ ãŠãŒã¶ãŒæäŸã®ããŒã¿ã«å¯Ÿããèªã¿åããªãã¬ãŒã·ã§ã³ãèšé² DATA_WRITE ãŠãŒã¶ãŒæäŸã®ããŒã¿ã«å¯Ÿããæžã蟌ã¿ãªãã¬ãŒã·ã§ã³ãèšé² Cloud Storage ãäŸã«åããšããªããžã§ã¯ãã®ã¡ã¿ããŒã¿ïŒä¿åæ¥æãããŒã¿ãµã€ãºãåç§°ã®ååŸçïŒãååŸãããªã¯ãšã¹ã㯠ADMIN_READ ã«åé¡ãããŸããããŒã¿èªäœãããŠã³ããŒããããªã¯ãšã¹ã㯠DATA_READ ã«åé¡ãããŸãã Google Cloud ãããžã§ã¯ãã«ãããŠãå Google Cloud ãµãŒãã¹ããšã«ãäžèšã®ãã¡æå¹åãããã°ãéžæããŠæå¹åããŸãããã¹ãŠæå¹åããããšãã§ããŸãããäžéšã®ã¿ãæå¹åããããšãã§ããŸãããŸããå
šãµãŒãã¹ã®ãã¹ãŠã®ãã°ãååŸããããã«èšå®ããããšãã§ããŸãã åè : æ§æã®æŠèŠ é€å€ããããªã³ã·ãã« ç¹å®ã® ããªã³ã·ãã« ïŒGoogle ã¢ã«ãŠã³ãããµãŒãã¹ã¢ã«ãŠã³ããªã©ïŒãæå®ããŠããã®ããªã³ã·ãã«ã ãã¯ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ãçæããªãããã«èšå®ã§ããŸãã äŸãã°ãã€ãã³ãããªãã³ã§é »ç¹ã«èµ·åãã Cloud Run functions ããããšããŸãããã®é¢æ°ã¯ãæ°ç§ã«1床ããªããžã§ã¯ãããã±ããã«ã¢ããããŒãããããã³ã«èµ·åããŠããµãŒãã¹ã¢ã«ãŠã³ãã®æš©éã䜿ã£ãŠãªããžã§ã¯ããååŸããçãåŠçãè¡ã£ãŠããçµäºããããšããŸãããã®é¢æ°ã¯é »ç¹ã«èµ·åã㊠Cloud Storage ãªããžã§ã¯ãã«ã¢ã¯ã»ã¹ãããããããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ãèšå€§ã«ãªãããšãæ³å®ãããŸãããã®ãããªå Žåã«ã颿°ã䜿ããµãŒãã¹ã¢ã«ãŠã³ãã Cloud Storage ã®ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ã®é€å€ããªã³ã·ãã«ãšããŠèšå®ããã°ã颿°ããã®ã¢ã¯ã»ã¹ã¯ãã°ã«èšé²ãããŸããã é€å€ããããªã³ã·ãã«ã¯ãGoogle Cloud ãµãŒãã¹ããšã«æå®ã§ããŸãã åè : é€å€ãèšå®ãã ç£æ»ãã°ã®éçŽ éçŽã®å¿
èŠæ§ åè¿°ã®éããããã©ã«ãã§ã¯ç£æ»ãã°ã¯çµç¹ãåãã©ã«ããåãããžã§ã¯ãã®ãã°ãã±ãã _Required ã«ä¿åãããŸãã ãããã以äžã®ãããªèŠä»¶ãããå Žåã ãã°éçŽçšã®ãããžã§ã¯ã ãäœæãããã®äžã«ãã°éçŽçšãã°ãã±ãããäœæããããšãçµç¹ã¬ãã«ã§ éçŽã·ã³ã¯ ãäœæããããšã§ãçµç¹é
äžã®å
šãŠã®ç£æ»ãã°ã1ãæã«éçŽããããšãã§ããŸãã è€æ°ãããžã§ã¯ãã®ãã°ãéçŽã㊠SIEM ã§åæããã ç£æ»ã®ããã«ç£æ»ãã°ããšã¯ã¹ããŒãããŠç¬¬3è
ã«æåºããå¿
èŠããã è€æ°ãããžã§ã¯ããæšªæããŠç£æ»ãã°ãã¯ãšãªããã éçŽã·ã³ã¯ã䜿ã£ãŠãã°ãéçŽããå Žåããã°ãã±ãããžã®ããŒã¿åã蟌ã¿ã«å¯ŸããŠããã°ã®åã蟌ã¿éãä¿åéãä¿åæéã«å¿ããŠæéãçºçããç¹ã«çæããŸãããã ã·ã³ã¯ã«ãããã°ã®éçŽ ãªããåçŽã«è€æ°ãããžã§ã¯ããæšªæããŠç£æ»ãã°ãã¯ãšãªãããã ãã§ããã°ãCloud Logging ã®ãã°ã¹ã³ãŒãæ©èœã䜿ãããšã§å®çŸã§ããŸããããã®æ©èœã䜿ã£ãŠãã°ãé²èЧããã«ã¯ãã°ãä¿æããåãããžã§ã¯ãã«å¯ŸããŠãã°ã®é²èŠ§æš©éãå¿
èŠã§ãããã°ããã°éçŽãããžã§ã¯ãã«éçŽããããšã§ããã°ã®é²èЧè
ãåãããžã§ã¯ãåŽã«æš©éãæã€å¿
èŠããªããªããŸãã åè : Cloud Loggingã®æŠå¿µãšä»çµã¿ããã£ãã解説 - ãã°ã¹ã³ãŒã èšå®æé çµç¹ã§ç£æ»ãã°ãéçŽããã«ã¯ã以äžã®ãããªæµãã§èšå®äœæ¥ãè¡ããŸãã ãã°éçŽçšã® Google Cloud ãããžã§ã¯ããçšæ ãã°ãä¿åããããã®ãã°ãã±ãããŸã㯠BigQuery ããŒãã«çãçšæ çµç¹ã¬ãã«ïŒãã©ã«ãã¬ãã«ïŒã§éçŽã·ã³ã¯ãäœæ ã·ã³ã¯ã®ãµãŒãã¹ã¢ã«ãŠã³ãã«ããã°ä¿åå
ã«æžã蟌ãããã® IAM æš©éãä»äž å Žåã«ãã£ãŠã¯ãã°ã®ããªã¥ãŒã ãèšå€§ã«ãªãå©çšæéãããããããå¿
èŠã«å¿ããŠæå°éã®ãã°ãåéããããããé€å€ãã£ã«ã¿èšå®ãæ€èšããŠãã ããã æé ã®è©³çްã¯ã以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : çµç¹ã®ãã°ããã°ãã±ããã«ä¿åãã ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ãš Cloud Storage ã®èªèšŒæžã¿ URL ãããžã§ã¯ãã§ Cloud Storage ã«å¯ŸããŠããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ãæå¹åãããšãCloud Storage ãªããžã§ã¯ãã®èªèšŒæžã¿ URL ã䜿çšã§ããªããªããŸãã ãã®äºè±¡ãåé¿ããã«ã¯ãCloud Storage ã®ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ã®ãã¡ãããŒã¿èªã¿åãããã°ãç¡å¹åããããURL ãå©çšããã¢ã«ãŠã³ããé€å€ããªã³ã·ãã«ãšããŠèšå®ããŸãã åè : èªèšŒã«ãããã©ãŠã¶ã§ã®ããŠã³ããŒã åè : ãã©ãã«ã·ã¥ãŒãã£ã³ã° - 403: Forbidden ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã®äºäŸãšããŠã以äžããåç
§ãã ããã blog.g-gen.co.jp ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãX (æ§ Twitter) ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-genã®ææã§ãã éå®å
¬éã® Google ã¢ã¯ã»ã¹ ïŒPrivate Google AccessïŒæ©èœã䜿ããšãExternal IP ã¢ãã¬ã¹ãæã£ãŠããªã VM ãããGoogle Cloud ãµãŒãã¹ã® API ã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸãã éå®å
¬éã® Google ã¢ã¯ã»ã¹ãšã¯ 仿§ å©çšãããã¡ã€ã³å åæç¥è ããã©ã«ãã®ãã¡ã€ã³åãå©çšãã ç¹æ®ãªãã¡ã€ã³ãå©çšãã private ãš restricted ã®éã 2ã€ã®ãã¡ã€ã³åã®éã private.googleapis.com restricted.googleapis.com éžæãããŒãã£ãŒã æå¹åã®æé æŠèŠ ããã©ã«ãã®ãã¡ã€ã³ã®å Žå private.googleapis.com restricted.googleapis.com ãªã³ãã¬ãã¹ããå©çšãã éå®å
¬éã® Google ã¢ã¯ã»ã¹ vs Private Service Connect éå®å
¬éã® Google ã¢ã¯ã»ã¹ãšã¯ éå®å
¬éã® Google ã¢ã¯ã»ã¹ ïŒPrivate Google AccessïŒãšã¯ãGoogle CloudïŒæ§ç§°GCPïŒã® API ã«å¯ŸããŠãExternal IPïŒPublic IPïŒã¢ãã¬ã¹ãæããªã VM ãããªã³ãã¬ãã¹ã®ã¯ã©ã€ã¢ã³ãããããã©ã€ããŒããããã¯ãŒã¯ã®ã¿ã§ã¢ã¯ã»ã¹ã§ããããã«ããä»çµã¿ã§ãã Google Cloud ã® API ã¯ãéåžžã¯ã€ã³ã¿ãŒãããçµç±ã§ã¢ã¯ã»ã¹ãããããšãæ³å®ããŠããŸããããããã€ã³ã¿ãŒããããä»ããããã©ã€ããŒããããã¯ãŒã¯ã§ã®ã¢ã¯ã»ã¹ãå¯èœã«ããã®ãåœæ©èœã§ãã åè : éå®å
¬éã® Google ã¢ã¯ã»ã¹ ãªããé¡äŒŒã®æ©èœãšã㊠Private Service Connect ããããŸããã©ã¡ãã®æ©èœãå©çšãããè¯ãã®ãã«ã€ããŠã¯ãPrivate Service Connect ã«ã€ããŠè§£èª¬ãã以äžã®èšäºã§èª¬æããŠããŸãã®ã§ããåç
§ãã ããã blog.g-gen.co.jp 仿§ ã€ã¡ãŒãž éå®å
¬éã® Google ã¢ã¯ã»ã¹ã®ä»æ§ãšç¹åŸŽã¯ã以äžã®ãšããã§ãã ãµããããåäœã§æå¹å ãã æå¹åãããšã External IP ãæããªã VM ããªã³ãã¬ãã¹ã®ããŒãã Google ã® API ãžã¢ã¯ã»ã¹ã§ããããã« ãªã Cloud Storage ã BigQuery ãªã©ã® Google Cloud ãµãŒãã¹ã«å ããGoogle MapãGoogle åºåãªã©ã察象 å©çšãããã¡ã€ã³åã®éžæè¢ ãšããŠä»¥äžã®3ã€ããããã¢ã¯ã»ã¹å¯èœãª APIãå¿
èŠãªãã¡ã€ã¢ãŠã©ãŒã«èšå®ãDNS èšå®ãªã©ãç°ãªã ããã©ã«ãã®ãã¡ã€ã³åãå©çšãã private.googleapis.com ãå©çšãã restricted.googleapis.com ãå©çšãã å©çšãããã¡ã€ã³å åæç¥è éå®å
¬éã® Google ã¢ã¯ã»ã¹ãçè§£ããã«ã¯ãåæãšããŠã Google Cloud ãµãŒãã¹ã¯ API ã«ãã£ãŠæäœãã ããã®ã§ããããšããããšã®çè§£ãå¿
èŠã§ãã ããã¯ãAmazon Web ServicesïŒAWSïŒãªã©ã®ä»ã®ãããªãã¯ã¯ã©ãŠãã§ãåæ§ã§ããVM ã®èµ·åã»åæ¢ãã BigQuery ã®ããŒãã«ãžã®ã¯ãšãªãªã©ã¯ã Web API ãéããŠè¡ãããŸããWeb ãã©ãŠã¶ã§ Google Cloud ã³ã³ãœãŒã«ç»é¢ãæäœããéããgcloud ã³ãã³ãã©ã€ã³ãå®è¡ããéããå
éšçã«ã¯ HTTPS ãããã³ã«ã«ãã Web API ãžã®ãªã¯ãšã¹ããå®è¡ãããŠããŸãã Google Cloud API ãšã¯ã©ã€ã¢ã³ã ããã«ã€ããŠã¯ã以äžã®èšäºã§è©³çްã«è§£èª¬ããŠããŸãã åè : Google Cloudã®æ ¹å¹¹ãæãGoogle Cloud APIsãšã¯äœã - G-gen Tech Blog åè : Cloud Audit Logsã解説ãGoogle Cloudã®èšŒè·¡ç®¡ç - G-gen Tech Blog - API ãªã¯ãšã¹ããšã¯ äŸãã°ãCloud Storage API ã®ãšã³ããã€ã³ã㯠https://storage.googleapis.com/ ã§ãããBigQuery API ã®ãšã³ããã€ã³ã㯠https://bigquery.googleapis.com/ ã§ãããããã® API ãšã³ããã€ã³ãã¯ãã€ã³ã¿ãŒãããã«å
¬éãããŠããŸãããã®ãããCompute Engine VM ãã Cloud Storage ã BigQuery ãå©çšããå Žåãæ¬æ¥ã¯ External IP ã¢ãã¬ã¹ã䜿ã£ãŠãã€ã³ã¿ãŒãããçµç±ã§ã¢ã¯ã»ã¹ããå¿
èŠããããŸãã ããã©ã«ãã®ãã¡ã€ã³åãå©çšãã éå®å
¬éã® Google ã¢ã¯ã»ã¹ã§å©çšãããã¡ã€ã³åãšããŠã以äžã®3çš®é¡ããéžæã§ããŸãã ããã©ã«ãã®ãã¡ã€ã³åãå©çšãã private.googleapis.com ãå©çšãã restricted.googleapis.com ãå©çšãã éžæè¢ 1. ããã©ã«ãã®ãã¡ã€ã³åãå©çšãã ã¯ãããšããšã® Web API ãšã³ããã€ã³ãããã®ãŸãŸå©çšããéžæè¢ã§ãããµããããã§éå®å
¬éã® Google ã¢ã¯ã»ã¹ãæå¹åããå Žåããã®ç¶æ
ã«ãªããããã«å©çšããããšãã§ããŸãã ãã®æ¹æ³ã§ VM ãã Google Cloud APIs ãžã¢ã¯ã»ã¹ããã«ã¯ãVPC ã«ãŒãã§ 0.0.0.0/0 ãããã©ã«ãã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ã«åããå¿
èŠããã ãŸããããã«ã ãã¡ã€ã¢ãŠã©ãŒã«ã®äžãïŒEgressïŒã«ãŒã«ã§ 0.0.0.0/0 ã«å¯Ÿãã HTTPSïŒ443/TCPïŒãèš±å¯ããå¿
èŠããã ãŸãã äžèšã®ãããªèšå®ããããšããã©ãã£ãã¯ãã€ã³ã¿ãŒãããã«åºãŠããããã«ãæããŸããããã®èšå®ã«ãã External IP ã¢ãã¬ã¹ãæã£ãŠããªã VM ã§ããGoogle Cloud APIs ãžã®ã¢ã¯ã»ã¹ãã§ããããã«ãªããŸãããŸããé信㯠Google ã®ãããã¯ãŒã¯å
ã«éãããã®ã«ãªããŸãã åè : éå®å
¬éã® Google ã¢ã¯ã»ã¹ãæ§æãã - æ§æãªãã·ã§ã³ã®æŠèŠ ãã®èšå®ã§ã¯ãVPC ãããã¯ãŒã¯åäœã§ããã©ã«ãã«ãŒãã 0.0.0.0/0 ã«åããå¿
èŠããããŸããããã¡ã€ã¢ãŠã©ãŒã«èšå®ã空ããå¿
èŠããããŸããèšå®ãã¹çã«ãããæå³ãã VM ã External IP ã¢ãã¬ã¹ãæã£ãŠããŸã£ãéãªã©ã«ãVM ããã¯ã€ã³ã¿ãŒããããžã®ã¢ãŠãããŠã³ãéä¿¡ãå¯èœãªç°å¢ã«ãªã£ãŠããŸããŸãã ãããé²ãããå Žåã¯ãä»ã®éžæè¢ãæ€èšãããŸãã ç¹æ®ãªãã¡ã€ã³ãå©çšãã éžæè¢ 2. private.googleapis.com ãå©çšãã ãšã 3. restricted.googleapis.com ãå©çšãã ã¯ããããã®ãã¡ã€ã³åãã ããã©ã«ãã®ãã¡ã€ã³åã® CNAME ãšããŠç»é²ããããšã§ãããã Web API ãšã³ããã€ã³ããšããŠå©çš ããã¢ã¯ã»ã¹å
IP ã¢ãã¬ã¹ãå€ããæ¹æ³ã§ãã ãããã®éžæè¢ã§ã¯ãVPC ãããã¯ãŒã¯ã«ã 199.36.153.8/30 ã 199.36.153.4/30 ãšãã£ãIP ã¢ãã¬ã¹åž¯ã«å¯ŸããŠã®éä¿¡ãèš±å¯ãããã¡ã€ã¢ãŠã©ãŒã«ãã«ãŒããèšå®ããŸãã çè§£ããããããããã restricted.googleapis.com ã®å ŽåãäŸã«ãšã£ãŠãèšå®ã®æµãã以äžã«èšèŒããŸãã ãµããããã§ éå®å
¬éã® Google ã¢ã¯ã»ã¹ãæå¹å 199.36.153.4/30 ã®ãã¯ã¹ããããã ããã©ã«ãã®ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãžåããŠãã ããšã確èªïŒããã©ã«ãã§ã¯ 0.0.0.0/0 ã®ãã¯ã¹ãããããã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ã«ãªã£ãŠãããããæ¡ä»¶ãæºãããŠããïŒ VPC ãã¡ã€ã¢ãŠã©ãŒã«ã§ã 199.36.153.4/30 ãžã® 443/TCP ã® äžãïŒEgressïŒéä¿¡ãæåŠãããŠããªãããšã確èªïŒããã©ã«ãã§ã¯èš±å¯ïŒ Cloud DNS ã« googleapis.com ãšããéå®å
¬é DNS ãŸãŒã³ãäœæ åãŸãŒã³ã«ä»¥äžã远å DNSå : restricted.googleapis.com ã¿ã€ã : A IPv4ã¢ãã¬ã¹ : 199.36.153.4 199.36.153.5 199.36.153.6 199.36.153.7 åãŸãŒã³ã«ä»¥äžã远å DNSå : *.googleapis.com ã¿ã€ã : CNAME æ£èŠå : restricted.googleapis.com äžèšã®æé ã§ Cloud DNS ãèšå®ãããç¶æ
äžèšãèšå®ãããšæåãã©ãå€ããã®ã§ãããããäŸãšããŠãCompute Engine VM å
ãã gcloud storage ã³ãã³ããå®è¡ããŠãCloud Storage ãžã®ã¢ã¯ã»ã¹ãçºçãããšãã®å
éšçãªåäœãèããŸããgcloud storage ã³ãã³ãã¯ãCloud Storage API ãžãªã¯ãšã¹ãããããã«ã storage.googleapis.com ãž HTTPS ã§ã¢ã¯ã»ã¹ããããšããŸãããããš VM 㯠Cloud DNS ãåç
§ããŸãã®ã§ãéå®å
¬éãŸãŒã³ãåªå
çã«äœ¿ã£ãŠåå解決ããŸããå
éšçã«ã¯ã以äžã®ãããªåŠçãè¡ãããŸãã VM ã storage.googleapis.com ãåå解決ãããããCloud DNS ãžã¯ãšãªãã ã¯ãšãªã¯ *.googleapis.com ã«äžèŽããŠããã®ã§ãCNAME ã§ restricted.googleapis.com ãžè§£æ±ºããã restricted.googleapis.com 㯠A ã¬ã³ãŒãã«ãã 199.36.153.4 ã 199.36.153.5 ã 199.36.153.6 ã 199.36.153.7 ã®ã©ãããžè§£æ±ºããã VM ãã¯ãšãªãžã®ã¬ã¹ãã³ã¹ãåãåã gcloud ã³ãã³ãã¯ã 199.36.153.4 ã 199.36.153.5 ã 199.36.153.6 ã 199.36.153.7 ã®ãããããžã¢ã¯ã»ã¹ VPC ãããã¯ãŒã¯ã®èšå®ã§ããããã® IP ã¢ãã¬ã¹ãžã®ã«ãŒããããã©ã«ãã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãžåããŠããããã€ãã¡ã€ã¢ãŠã©ãŒã«ã§ 443/TCP ãèš±å¯ãããŠããã°ãäžèšã®åŠçã®çµæãšããŠãGoogle ã®å
éšãããã¯ãŒã¯ãéã£ãŠ API ãªã¯ãšã¹ããã§ããŸãã 解決å
ã® IP ã¢ãã¬ã¹ãšããŠã private.googleapis.com ã§ã¯ 199.36.153.8/30 ãïŒäžèšã®4ã€ã® IP ã¢ãã¬ã¹ïŒã restricted.googleapis.com ã§ã¯ 199.36.153.4/30 ã䜿ãå¿
èŠããããŸãã ãããã® IP ã¢ãã¬ã¹ã¯ãã€ã³ã¿ãŒãããã«åºå ±ãããŠããªããéå®å
¬éã® Google ã¢ã¯ã»ã¹å°çšã® IP ã¢ãã¬ã¹ã§ãã åè : åå解決ã®çµæ private ãš restricted ã®éã 2ã€ã®ãã¡ã€ã³åã®éã éå®å
¬éã® Google ã¢ã¯ã»ã¹ã§ããã©ã«ãã®ãã¡ã€ã³åã䜿ããªããã¿ãŒã³ã«ã¯ã private.googleapis.com ãå©çšãããã¿ãŒã³ãšã restricted.googleapis.com ãå©çšãããã¿ãŒã³ã®2çš®é¡ããããŸãããããã®å Žåããåºæ¬çãªä»çµã¿ã¯åæ§ã§ããçžéç¹ã¯ã ã¢ã¯ã»ã¹ã§ãã API ã®çš®é¡ ãšã å©çšãã IP ã¢ãã¬ã¹ ã§ãã ãã®çžéç¹ã«ã€ããŠã¯ãGoogle Cloud èªå®è³æ Œã§ãã Professional Cloud Network Engineer 詊éšã Professional Cloud Security Engineer詊éšã§ãåãããŸãã®ã§ãåéšäºå®ãããæ¹ã¯ restricted.googleapis.com ãš private.googleapis.com ã®éãã«ã€ããŠãæ£ããçè§£ããããšãæšå¥šãããŸãã åè : Professional Cloud Network Engineer詊éšå¯Ÿçããã¥ã¢ã« - G-gen Tech Blog åè : Professional Cloud Security Engineer詊éšå¯Ÿçããã¥ã¢ã«ãåºé¡åŸåã»ååŒ·æ¹æ³ - G-gen Tech Blog private.googleapis.com private.googleapis.com ã䜿ããã¿ãŒã³ã§ã¯ãã»ãšãã©ã® Google API ãžã®ã¢ã¯ã»ã¹ãå¯èœã§ãã æ¬¡ã«èª¬æãã restricted.googleapis.com ã§ã¯ã VPC Service Controls ã§ãµããŒããããŠãã API ã«ã ãããã¢ã¯ã»ã¹ã§ããŸãããã private.googleapis.com ã§ã¯ãVPC Service Controls ã®ãµããŒãæç¡ã¯é¢ä¿ãããŸããã åè : VPC Service Controlsãåããããã解説 - G-gen Tech Blog private.googleapis.com ã䜿ããšãå€ãã® API ã«ã¢ã¯ã»ã¹å¯èœãªäžæ¹ã§ãVPC Service Controls ã§ VM ããã® API ã¢ã¯ã»ã¹ãå³å¯ã«ã³ã³ãããŒã«ãããå Žåã«ã¯é©ããŠããŸããã VPC Service Controls ã䜿çšãŠãããã䜿çšããäºå®ããªãå ŽåããVPC Service Controls ã䜿çšãããã®ã®ããµããŒã察象ã§ãªã API ãžã®ã¢ã¯ã»ã¹ãèš±å¯ããå Žåã«ã private.googleapis.com ãéžæããããšã«ãªããŸãã ãµããŒããããŠããã¢ã¯ã»ã¹å
ã®äžèЧã¯ã以äžã®ããã¥ã¡ã³ããåç
§ããŠãã ããã åè : éå®å
¬éã® Google ã¢ã¯ã»ã¹ãæ§æãã - ãã¡ã€ã³ ãªãã·ã§ã³ DNS ã«ç»é²ããå°çš IP ã¢ãã¬ã¹ã¯ã 199.36.153.8/30 ã§ãïŒ 199.36.153.8 ã 199.36.153.9 ã 199.36.153.10 ã 199.36.153.11 ïŒã restricted.googleapis.com restricted.googleapis.com ã䜿ããã¿ãŒã³ã§ã¯ãVPC Service Controls ã§ãµããŒããããŠãã Google API ã« ã®ã¿ ãã¢ã¯ã»ã¹ã§ããããã«ãªããŸãããã以å€ã® API ãžã®ã¢ã¯ã»ã¹ã¯æåŠãããŸãã VPC Service Controls ãå©çšããŠããããŸãã¯å©çšããäºå®ããããã〠VM ãã㯠VPC Service Controls ã§ãµããŒããããŠããªã API ãžã®ã¢ã¯ã»ã¹ãçŠæ¢ãããå Žåã¯ããã¡ããéžæããŸãã ãµããŒããããŠããã¢ã¯ã»ã¹å
ã®äžèЧã¯ã以äžã®ããã¥ã¡ã³ããåç
§ããŠãã ããã åè : VPC Service Controls - ãµããŒããããŠãããããã¯ããšå¶éäºé
DNS ã«ç»é²ããå°çš IP ã¢ãã¬ã¹ã¯ 199.36.153.4/30 ïŒ 199.36.153.4 ã 199.36.153.5 ã 199.36.153.6 ã 199.36.153.7 ïŒã§ãã éžæãããŒãã£ãŒã ã©ã®ãã¡ã€ã³ãéžæããã°ããããç°¡åãªãããŒãã£ãŒãã§èŠãŠã¿ãŸãããã ãã¡ã€ã³å決å®ãããŒãã£ãŒã äžçªå·Šã®ãããã©ã«ãã®ãã¡ã€ã³åãéžæãããšãå³äžã«ããããã« VM ã External IP ã¢ãã¬ã¹æã£ãŠãããšãã€ã³ã¿ãŒããããžã¢ã¯ã»ã¹ã§ããŠããŸã ãªã©ã®ãªã¹ã¯ããããŸãããããååçè§£ããŠéžæããŸãããã æå¹åã®æé æŠèŠ åœèšäºã§ã¯ãèšå®æé ã®æŠèŠã ããèšèŒããŠããŸãã詳现ãªèšå®æé ã¯ã以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : éå®å
¬éã® Google ã¢ã¯ã»ã¹ãæ§æãã ããã©ã«ãã®ãã¡ã€ã³ã®å Žå 察象ã®ãµããããã§ éå®å
¬éã® Google ã¢ã¯ã»ã¹ãæå¹å VPC ãããã¯ãŒã¯ã®ã«ãŒãèšå®ã§ã 0.0.0.0/0 ã®ãã¯ã¹ããããã ããã©ã«ãã®ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãžåããŠãã ããšã確èªïŒããã©ã«ãã§ã¯èšå®æžã¿ïŒ VPC ãã¡ã€ã¢ãŠã©ãŒã«ã§ã 0.0.0.0/0 ãžã® 443/TCP ã®äžãïŒEgressïŒéä¿¡ãæåŠãããŠããªã ããšã確èªïŒããã©ã«ãã§ã¯æé»çã«èš±å¯ïŒ private.googleapis.com 察象ã®ãµããããã§ éå®å
¬éã® Google ã¢ã¯ã»ã¹ãæå¹å VPC ãããã¯ãŒã¯ã®ã«ãŒãèšå®ã§ã 199.36.153.8/30 ã®ãã¯ã¹ããããã ããã©ã«ãã®ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãžåããŠãã ããšã確èªïŒ 0.0.0.0/0 ãããã©ã«ãã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ã«åããŠããèšå®ã§ãåé¡ãªãïŒ VPC ãã¡ã€ã¢ãŠã©ãŒã«ã§ã 199.36.153.8/30 ãžã® 443/TCP ã® äžãïŒEgressïŒéä¿¡ãæåŠãããŠããªã ããšã確èªïŒããã©ã«ãã§ã¯æé»çã«èš±å¯ïŒ Cloud DNS ã« googleapis.com ãšããéå®å
¬é DNS ãŸãŒã³ãäœæ åãŸãŒã³ã«ä»¥äžã远å DNSå : private.googleapis.com ã¿ã€ã : A IPv4ã¢ãã¬ã¹ : 199.36.153.8 199.36.153.9 199.36.153.10 199.36.153.11 åãŸãŒã³ã«ä»¥äžã远å DNSå : *.googleapis.com ã¿ã€ã : CNAME æ£èŠå : private.googleapis.com restricted.googleapis.com 察象ã®ãµããããã§ éå®å
¬éã® Google ã¢ã¯ã»ã¹ãæå¹å VPC ãããã¯ãŒã¯ã®ã«ãŒãèšå®ã§ã 199.36.153.4/30 ã®ãã¯ã¹ããããã ããã©ã«ãã®ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãžåããŠãã ããšã確èªïŒ 0.0.0.0/0 ãããã©ã«ãã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ã«åããŠããèšå®ã§ãåé¡ãªãïŒ VPC ãã¡ã€ã¢ãŠã©ãŒã«ã§ã 199.36.153.4/30 ãžã® 443/TCP ã® äžãïŒEgressïŒéä¿¡ãæåŠãããŠããªã ããšã確èªïŒããã©ã«ãã§ã¯æé»çã«èš±å¯ïŒ Cloud DNS ã« googleapis.com ãšããéå®å
¬é DNS ãŸãŒã³ãäœæ åãŸãŒã³ã«ä»¥äžã远å DNSå : restricted.googleapis.com ã¿ã€ã : A IPv4ã¢ãã¬ã¹ : 199.36.153.4 199.36.153.5 199.36.153.6 199.36.153.7 åãŸãŒã³ã«ä»¥äžã远å DNSå : *.googleapis.com ã¿ã€ã : CNAME æ£èŠå : restricted.googleapis.com ãªã³ãã¬ãã¹ããå©çšãã Cloud Interconnect ã Cloud DNS ã§ Google Cloud ã«æ¥ç¶ããããªã³ãã¬ãã¹ç°å¢ãããéå®å
¬éã® Google ã¢ã¯ã»ã¹ãå©çšããã«ã¯ã以äžã®èšå®ãå¿
èŠã§ãã éå®å
¬éã® Google ã¢ã¯ã»ã¹ã® IP ã¢ãã¬ã¹ïŒ 199.36.153.8/30 çïŒã Cloud Router ãããªã³ãã¬ãã¹åŽã«åºå ±ãã ãªã³ãã¬ãã¹ããŒããåç
§ãã DNS ã«ããã©ã¯ãŒããŒèšå®ã远å ããŠã Google Cloud APIs ã®åå解決ã Cloud DNS ã®éå®å
¬éãŸãŒã³ã«è»¢éãã 1ã€ç®ã¯ãCloud Router ã® ã«ã¹ã¿ã ã«ãŒãã¢ããã¿ã€ãº ã䜿ãããšã§å®çŸå¯èœã§ãã2ã€ç®ã¯ãCloud DNS ã® åä¿¡ãµãŒããŒããªã·ãŒ ã§å®çŸå¯èœã§ãã 2ã€ç®ã«ã€ããŠã¯ããªã³ãã¬ãã¹ã®ã¯ã©ã€ã¢ã³ãããéå®å
¬éã® Google ã¢ã¯ã»ã¹ã® IP ã¢ãã¬ã¹ïŒ 199.36.153.8/30 ã 199.36.153.4/30 ïŒãåãããããã°è¯ãã®ã§ããªã³ãã¬ãã¹ã® DNS ã« Cloud DNS ãšåãã¬ã³ãŒãã远å ããŠãæ§ããŸããã ãã詳现ãªèšå®æé ã¯ã以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : ãªã³ãã¬ãã¹ ãã¹ãã®éå®å
¬éã® Google ã¢ã¯ã»ã¹ãæ§æãã éå®å
¬éã® Google ã¢ã¯ã»ã¹ vs Private Service Connect é¡äŒŒã®æ©èœãšããŠã Private Service Connect ããããŸãã ã©ã¡ãã®æ©èœãå©çšãããè¯ãã®ãã«ã€ããŠä»¥äžã®èšäºã§èª¬æããŠããŸãã®ã§ããåç
§ãã ããã blog.g-gen.co.jp ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO å
èŠå¯å®ãšããçµæŽãæã€ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS èªå®è³æ Œããã³ Google Cloud èªå®è³æ Œã¯ãã¹ãŠååŸãXïŒæ§ TwitterïŒã§ã¯ Google Cloud ã Google Workspace ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-genã®ææã§ããåœèšäºã§ã¯ Google Cloud APIs ã«ãã©ã€ããŒããããã¯ãŒã¯çµç±ã§ã¢ã¯ã»ã¹ããããã®æ©èœã§ãã Private Service Connect ã«ã€ããŠè§£èª¬ããŸãã æŠèŠ Private Service Connect ãšã¯ Google Cloud APIs ãšã¯ Private Service Connect ã®ãŠãŒã¹ã±ãŒã¹ å¿
èŠæ§ æ©èœã®ãã€ã³ã Private Service Connect ã§ãããŒãžããµãŒãã¹ãå
¬éãã Private Service Connect vs éå®å
¬éã® Google ã¢ã¯ã»ã¹ æ©èœã®éã ã©ã¡ãã䜿ãã°ããã®ãïŒ èšèšã®ãã€ã³ã ãšã³ããã€ã³ãã®çš®é¡ ãšã³ããã€ã³ãã® IP ã¢ãã¬ã¹ DNS èšå® èšå®æé ã¯ããã« èšå®æé ã®æŠèŠ DNS èšå®ã®æå³ ãªã³ãã¬ãã¹ããå©çšãã æŠèŠ Private Service Connect ãšã¯ Private Service Connect ãšã¯ã External IPïŒPublic IPïŒã¢ãã¬ã¹ãæããªã VM ãããªã³ãã¬ãã¹ã®ã¯ã©ã€ã¢ã³ãããããã©ã€ããŒããããã¯ãŒã¯çµç±ã§ Google Cloud ã® API 矀ãããŠãŒã¶ãŒã®ç¬èªãµãŒãã¹ãžã¢ã¯ã»ã¹ã§ããããã«ããããã®ä»çµã¿ã§ãã ãã®æ©èœã§ã¯ãVPC ãããã¯ãŒã¯å
ã« Internal IPïŒPrivate IPïŒã¢ãã¬ã¹ãæã€ãšã³ããã€ã³ããäœæããããã®ãšã³ããã€ã³ãçµç±ã§ Google Cloud APIs ãç¬èªãµãŒãã¹ã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸãã åè : Private Service Connect åè : ãšã³ããã€ã³ããä»ãã Google API ãžã®ã¢ã¯ã»ã¹ã«ã€ã㊠åœèšäºã§ã¯ãPrivate Service Connect ã§ Google Cloud API ã«ã¢ã¯ã»ã¹ããæ¹æ³ã«ã€ããŠç޹ä»ããŸãã Google Cloud ããã¥ã¡ã³ã ããåŒçš Google Cloud APIs ãšã¯ åæç¥èãšããŠãGoogle Cloud APIs ãšã¯äœãã«ã€ããŠããããããŸãã ã»ãšãã©ã® Google Cloud ãªãœãŒã¹ã«å¯Ÿããé²èЧãäœæãæŽæ°ãåé€ãªã©ã¯ããã¹ãŠ Web API ã«ãã£ãŠæäœãã ãŸããããã¯ãAmazon Web ServicesïŒAWSïŒãªã©ã®ä»ã®ãããªãã¯ã¯ã©ãŠãã§ãåæ§ã§ãã ããã«ã€ããŠã¯ã以äžã®èšäºã§è©³çްã«è§£èª¬ããŠããŸãã åè : Google Cloudã®æ ¹å¹¹ãæãGoogle Cloud APIsãšã¯äœã - G-gen Tech Blog åè : Cloud Audit Logsã解説ãGoogle Cloud(GCP)ã®èšŒè·¡ç®¡ç - G-gen Tech Blog - API ãªã¯ãšã¹ããšã¯ Private Service Connect ã®ãŠãŒã¹ã±ãŒã¹ ã»ãã¥ãªãã£äžã®çç±ãããGoogle Cloud APIs ãžã®ã¢ã¯ã»ã¹ããã€ã³ã¿ãŒãããçµç±ã§ãªããã©ã€ããŒããããã¯ãŒã¯å
ã§è¡ããããšããã±ãŒã¹ããããŸãã éå®å
¬éã® Google ã¢ã¯ã»ã¹ æ©èœã䜿ãããšã§ãExternal IP ã¢ãã¬ã¹ãæããªã VM ããªã³ãã¬ãã¹ã®ããŒããããGoogle Cloud APIs ã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸãã åè : éå®å
¬éã® Google ã¢ã¯ã»ã¹ã®ä»çµã¿ãšæé ããã£ã¡ã解説 ããããéå®å
¬éã® Google ã¢ã¯ã»ã¹ã§ã¯ã 199.36.153.4/30 ã 199.36.153.8/30 ãšãã£ããRFC 1918 ç¯å²ïŒâ»ïŒã§ã¯ãªã IP ã¢ãã¬ã¹ã䜿ãå¿
èŠãããããã Cloud Interconnect ã Cloud VPN çµç±ã§ãªã³ãã¬ãã¹ç°å¢ããå©çšããéãªã©ã«ãã«ãŒãã£ã³ã°ãè€éåãããªã©ã®åŒå®³ãåºãå¯èœæ§ããããŸãã â» 10.0.0.0/8 ã 172.16.0.0/12 ã 192.168.0.0/16 äžæ¹ã§åœèšäºã§è§£èª¬ãã Private Service Connect ãå©çšããã°ã VPC ãããã¯ãŒã¯å
ã« Internal IP ã¢ãã¬ã¹ãæã€ãšã³ããã€ã³ããäœæãããã®ãšã³ããã€ã³ãçµç±ã§ Google Cloud APIs ã«ã¢ã¯ã»ã¹ã§ããŸãã ãã®ãšã³ããã€ã³ãã«ã¯ä»»æã® IP ã¢ãã¬ã¹ãå²ãåœãŠãããšãã§ããRFC 1918 ã§å®çŸ©ããã IP ã¢ãã¬ã¹ã§ããããã§ãªããŠãæ§ããŸããã å¿
èŠæ§ Google Cloud APIs ã¯ã€ã³ã¿ãŒãããçµç±ã§ã¢ã¯ã»ã¹ããå¿
èŠãããããããããã»ãã¥ã¢ã§ãªããšèããæ¹ããããããããŸãããããããAPI ãªã¯ãšã¹ã㯠HTTPSïŒSSL/TLSïŒã§æå·å ãããŸãããã®ããã鵿
å ±ã®æŒæŽ©ããªããã°ããã±ãããçèŽãããŠãå
容ã¯è§£èªãããŸãããGoogle ãã SSL/TLS èšŒææžã®éµæ
å ±ãæŒæŽ©ããããã«ãã±ãããçèŽã»åŸ©å·ãããŠæ
å ±ãæŒæŽ©ããå¯èœæ§ã¯ãäžè¬çã«ã¯äœããšèããããŸãã ãã®ãããPrivate Service Connect ãéå®å
¬éã® Google ã¢ã¯ã»ã¹ãçšããäž»ããçç±ã¯ãã€ã³ã¿ãŒããããžã®ã«ãŒãã£ã³ã°ãã§ããªãã¯ã©ã€ã¢ã³ãããGoogle Cloud APIs ãžã¢ã¯ã»ã¹ã§ããããã«ããããããããã¯ãäŒç€ŸïŒçµç¹ïŒã®ã»ãã¥ãªãã£ããªã·ãŒã«æºæ ãããããã§ãããšããããŸãã æ©èœã®ãã€ã³ã Private Service Connect æ©èœã®ãã€ã³ãã¯ä»¥äžã®éãã§ãã Private Service Connect ãšã³ããã€ã³ãïŒInternal IP ã¢ãã¬ã¹ãå²ãåœãŠãããïŒãäœæãããªã³ãã¬ãã¹ã®ããŒãã VPC ãããã¯ãŒã¯å
ã® VM ã¯ããã®ãšã³ããã€ã³ãçµç±ã§ Google Cloud APIs ãžã¢ã¯ã»ã¹ã§ãã ãšã³ããã€ã³ãäœææã«ã以äžã®çš®é¡ã®ãããããéžæ all-apis vpc-sc ãšã³ããã€ã³ãã¯æéããšã«æéãçºçïŒ$7.44/æçšåºŠïŒ ã€ã¡ãŒãž Private Service Connect ãšã³ããã€ã³ãã®æéã¯ã以äžã®å
¬åŒã®å䟡衚ãåç
§ããŠãã ããã åè : Virtual Private Cloud ã®æé - Private Service Connect Private Service Connect ã§ãããŒãžããµãŒãã¹ãå
¬éãã åœèšäºã§ã¯è©³ãã玹ä»ããŸãããããã1ã€ã® Private Service Connect ã®æ©èœãšããŠãèªç°å¢ã§ãã¹ããããµãŒãã¹ãä»ã® Google Cloud ãŠãŒã¶ãŒåãã«å
¬éããæ©èœããããŸããããã¯ã ãããŒãžããµãŒãã¹ã®å
¬é ãšåŒã°ããŸãããªããAmazon Web ServicesïŒAWSïŒã® AWS PrivateLink ã§ãé¡äŒŒã®ããšãå®çŸå¯èœã§ãã 以äžã®èšäºã§ã玹ä»ããŠããŸãã®ã§ããåç
§ãã ããã blog.g-gen.co.jp Private Service Connect vs éå®å
¬éã® Google ã¢ã¯ã»ã¹ æ©èœã®éã Private Service Connect ã«äŒŒãæ©èœãšããŠã éå®å
¬éã® Google ã¢ã¯ã»ã¹ ããããŸãã ããã2ã€ã®æ©èœã¯ã以äžã®ãããªéãããããŸãã éå®å
¬éã® Google ã¢ã¯ã»ã¹æ©èœã§ã¯ API ãšã³ããã€ã³ããšããŠå©çšããä»®æ³ IP ã¢ãã¬ã¹ãšã㊠199.36.153.4/30 ã 199.36.153.8/30 ãšãã£ã RFC 1918 å®çŸ©å€ã® IP ã¢ãã¬ã¹ã䜿ãå¿
èŠããã éå®å
¬éã® Google ã¢ã¯ã»ã¹æ©èœã§ã¯ãããã©ã«ãã®ãã¡ã€ã³åã䜿ãå Žåã«éããDNS ã®è¿œå èšå®ãäžèŠã§æè»œã«å©çšã§ãã ããããã®ãã¿ãŒã³ã§ã¯ 0.0.0.0/0 ãžã®ããã©ã«ãã«ãŒããšããã¡ã€ã¢ãŠã©ãŒã«èš±å¯èšå®ã远å ããå¿
èŠããã éå®å
¬éã® Google ã¢ã¯ã»ã¹æ©èœã§ã¯æéãçºçããªã ãªããPrivate Service Connect ãèšå®ããéã«ã¯ãéå®å
¬éã® Google ã¢ã¯ã»ã¹ãæå¹åããå¿
èŠããããŸãã®ã§ãPrivate Service Connect æ©èœã¯éå®å
¬éã® Google ã¢ã¯ã»ã¹ã®æ¡åŒµçãšèããããšãã§ããŸãã ã©ã¡ãã䜿ãã°ããã®ãïŒ Private Service Connect vs éå®å
¬éã® Google ã¢ã¯ã»ã¹ ãèããæãã©ã®ããã«å€æãããããã§ããããã以äžã®ãããªèгç¹ã§æ€èšããŸãã 以äžã®å
šãŠã«åœãŠã¯ãŸãå Žåã¯ã Private Service Connect ãéžæãã ãªã³ãã¬ãã¹ããã®ãã©ã€ããŒããããã¯ãŒã¯çµç±ã§ã® Google Cloud APIs å©çšããã éå®å
¬éã® Google ã¢ã¯ã»ã¹ã§äœ¿ããã 199.36.153.4/30 ãŸã㯠199.36.153.8/30 ã䜿ãã«ããããçµè·¯äº€æãçµè·¯å¶åŸ¡ã§äžéœåããã äŸ: ãªã³ãã¬ãã¹åŽã®ã¯ã©ã€ã¢ã³ãã«ãã£ãŠç°ãªãéä¿¡å
VPC ãããã¯ãŒã¯ã䜿çšããåç·ãå€ãããããè€æ°ã®ãšã³ããã€ã³ãã䜿çšããã äŸ: RFC 1918 以å€ã® IP ã¢ãã¬ã¹ãåºå ±ãããŠããããšãæãŸãããªã ãã以å€ã®å Žåãç¡æã§äœ¿ãã éå®å
¬éã® Google ã¢ã¯ã»ã¹ ãéžæãã å©çšãã IP ã¢ãã¬ã¹ãšããŠã 199.36.153.4/30 ãŸã㯠199.36.153.8/30 ã蚱容ã§ããå Žåã¯ãç¡åã§å©çšã§ããéå®å
¬éã® Google ã¢ã¯ã»ã¹ãéžæããã®ãããã§ãããã éå®å
¬éã® Google ã¢ã¯ã»ã¹æ©èœã«ã€ããŠã¯ã以äžã®è§£èª¬èšäºã§ç޹ä»ããŠããŸãã®ã§ããã²ãåç
§ãã ããã blog.g-gen.co.jp èšèšã®ãã€ã³ã ãšã³ããã€ã³ãã®çš®é¡ ãšã³ããã€ã³ãã®çš®é¡ã«ãã£ãŠãã¢ã¯ã»ã¹å¯èœãª API ãç°ãªããŸãã all-apis ã®å Žåã Google Cloud ã®ã»ãšãã©ã®ãµãŒãã¹ããGoogle MapãGoogle åºåãªã©ãå€ãã®ãµãŒãã¹ãžæ¥ç¶ããããšãã§ããŸãã vpc-sc ã®å Žåãæ¥ç¶ã§ããã®ã¯ VPC Service Controls ã§ãµããŒããããŠãããµãŒãã¹ã ãã§ãã VPC Service Controls ã䜿çšããŠããããå°æ¥çã«äœ¿çšããäºå®ãå
šãç¡ãå Žåã¯åè
ãéžæããŸããäžæ¹ã§ VPC Service Controls ã䜿çšããŠããããŸãã¯äœ¿çšããäºå®ãããå Žåã§ãã〠VPC Service Controls ããµããŒãããŠããªããµãŒãã¹ãžã®ã¢ã¯ã»ã¹ãäžèŠãªå Žåã¯ãåŸè
ãå©çšãããšããã§ãããã ãšã³ããã€ã³ãããµããŒãããŠããæ¥ç¶å
ã® API ã«ã€ããŠã¯ã以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : ãšã³ããã€ã³ããä»ãã Google API ãžã®ã¢ã¯ã»ã¹ã«ã€ã㊠- ãµããŒããããŠãã API ãšã³ããã€ã³ãã® IP ã¢ãã¬ã¹ Private Service Connect ãšã³ããã€ã³ãäœææã«ã¯ã1ã€ã® Internal IP ã¢ãã¬ã¹ãå²ãåœãŠãŸããIP ã¢ãã¬ã¹ã¯ãRFC 1918 ã¢ãã¬ã¹ïŒ10.0.0.0/8ã172.16.0.0/12ã192.168.0.0/16ïŒã§ãããã§ãªããŠãæ§ããŸãããã IPv6 ã¢ãã¬ã¹ã¯äœ¿ããŸããã ãšã³ããã€ã³ãã® IP ã¢ãã¬ã¹ã¯ã ãµããããã® IP ã¢ãã¬ã¹ãšã¯éè€ã§ããŸãã ããŸããVPC ãããã¯ãŒã¯ãšããããã¯ãŒã¯ãã¢ãªã³ã°ã Cloud InterconnectãCloud VPN çã§æ¥ç¶ãããŠãããããã¯ãŒã¯ãšéè€ããŠããããŸããã å°æ¥ç㪠VPC ãããã¯ãŒã¯ããµããããã®æ¡åŒµãªã©ãèæ
®ããŠã éè€ãèµ·ããªããã〠IP ãªãœãŒã¹ã®ç¡é§äœ¿ãã«ãªããªã ãã㪠IP ã¢ãã¬ã¹ãæå®ããŸãããã ãŸãããããªã³ãã¬ãã¹ç°å¢ãã Cloud Interconnect ã Cloud VPN çµç±ã§ Private Service Connect ãšã³ããã€ã³ããå©çšãããå ŽåãGoogle Cloud ããåºå ±ããã«ãŒãã®éçŽæ§ãèæ
®ããŠãVPC ãµããããã® IP ã¢ãã¬ã¹åž¯ãšé£ãåã£ã IP ã¢ãã¬ã¹ã«ããã®ãæãŸããã§ãããã åè : ãšã³ããã€ã³ããä»ãã Google API ãžã®ã¢ã¯ã»ã¹ã«ã€ã㊠- IP ã¢ãã¬ã¹ã®èŠä»¶ DNS èšå® äŸãšããŠãCloud Storage API ã®ãšã³ããã€ã³ã㯠https://storage.googleapis.com/ ã§ãããBigQuery API ã®ãšã³ããã€ã³ã㯠https://bigquery.googleapis.com/ ã§ãããããã®ãã¡ã€ã³åã® IP ã¢ãã¬ã¹ãåå解決ãããšããããªã㯠IP ãè¿ããŸãã storage.googleapis.comã®åå解決ã®çµæ Private Service Connect ãšã³ããã€ã³ããäœæããŠãããã®ãŸãŸã§ã¯ãgcloud ã³ãã³ããªã©ã®ã¯ã©ã€ã¢ã³ãã¯ããããã®ãããªã㯠IP ã¢ãã¬ã¹ãç®æããŠãã±ãããçºéããŠããŸããŸãã ããã§ã以äžã®ããããã®æ¹æ³ã§ãã¯ã©ã€ã¢ã³ãã Private Service Connect ãšã³ããã€ã³ãã®ãã©ã€ããŒã IP ã¢ãã¬ã¹ãåãããã«ããå¿
èŠããããŸãã ã¯ã©ã€ã¢ã³ãïŒSDKïŒåŽã®èšå®ã§ãPrivate Service Connect ãšã³ããã€ã³ããåç
§ããããæç€ºçã«èšå®ãã ãã©ã€ããŒã㪠DNS åå解決ã«ãããã¯ã©ã€ã¢ã³ãã Private Service Connect ãšã³ããã€ã³ããåãããã«èšå®ãã 1.ã¯ãã¯ã©ã€ã¢ã³ããžã®æç€ºçãªèšå®ã«ãããåãå
ãå€ããæ¹æ³ã§ããPrivate Service Connect ãšã³ããã€ã³ããäœæãããšããããžã§ã¯ãã® Cloud DNS ã« <ãµãŒãã¹å>.<ãšã³ããã€ã³ãå>.p.googleapis.com ãšãã DNS ãŸãŒã³ãèªåçã«äœæãããŸããgcloud ã Python SDK ãªã©ãã¯ã©ã€ã¢ã³ãåŽã§ã¯ãåãå
ã® API ãšã³ããã€ã³ã URL ãæç€ºçã«æå®ããããšãã§ããŸãããã®æ¹æ³ã§ã¯ãDNS èšå®ã倿Žããããšãªã Private Service Connect ãšã³ããã€ã³ãã䜿ãããšãã§ããŸãã åè : p.googleapis.com DNS åã䜿çšãã 2.ã¯ãVM ããªã³ãã¬ãã¹ã®ã¯ã©ã€ã¢ã³ã PC çãåç
§ãã DNS ãµãŒããŒãããã㯠Cloud DNS ã®ãã©ã€ããŒããŸãŒã³ã§ã *.googleapis.com ã«å¯Ÿãã CNAME ã¬ã³ãŒããäœæããããã Private Service Connect ãšã³ããã€ã³ãã® IP ã¢ãã¬ã¹ãžè§£æ±ºãããæ¹æ³ã§ãããã®æ¹æ³ã§ã¯ãã¯ã©ã€ã¢ã³ãåŽã®èšå®ãããã°ã©ã ã®ãœãŒã¹ã³ãŒãã倿ŽããããšãªããPrivate Service Connect ãšã³ããã€ã³ãã䜿ãããšãã§ããŸãã åè : ããã©ã«ãã® DNS åã䜿çšã㊠DNS ã¬ã³ãŒããäœæãã åœèšäºã§ã¯ç¶ããŠã2. ã®èšå®æé ã玹ä»ããŸãã èšå®æé ã¯ããã« åœèšäºã§ã¯ãèšå®æé ã®æŠèŠã®ã¿ãèšèŒããŠããŸãããã詳现ãªèšå®æé ã¯ã以äžã®å
¬åŒããã¥ã¡ã³ãããåç
§ãã ããã åè : ãšã³ããã€ã³ããã Google API ã«ã¢ã¯ã»ã¹ãã èšå®æé ã®æŠèŠ Private Service Connect ã®èšå®æé ã®ãããŸããªæµãã以äžã«èšèŒããŸãã å¿
èŠãª API ãæå¹å Compute Engine API Service Directory API Cloud DNS API Private Service Connect ãšã³ããã€ã³ããäœæ 察象ã®ãµããããã§éå®å
¬éã® Google ã¢ã¯ã»ã¹ãæå¹å VPC ãã¡ã€ã¢ãŠã©ãŒã«ã§ããšã³ããã€ã³ã IP ã¢ãã¬ã¹ãžã® 443/TCP ã® äžãïŒEgressïŒéä¿¡ãæåŠãããŠããªãããšã確èªïŒããã©ã«ãã§ã¯èš±å¯ïŒ Cloud DNS ã« googleapis.com ãšããéå®å
¬é DNS ãŸãŒã³ãäœæ åãŸãŒã³ã«ä»¥äžã远å DNSå : googleapis.com ã¿ã€ã : A IPv4ã¢ãã¬ã¹ : (ãšã³ããã€ã³ãã® IP ã¢ãã¬ã¹) åãŸãŒã³ã«ä»¥äžã远å DNSå : *.googleapis.com ã¿ã€ã : CNAME æ£èŠå : googleapis.com DNS èšå®ã®æå³ äžèšã®ãã¡ã5. 以éã® DNS èšå®ã«ã€ããŠè§£èª¬ããŸãã äŸãã°ãVM ã®äžã§ gcloud storage ã³ãã³ããå®è¡ããŠãCloud Storage ãžã®ã¢ã¯ã»ã¹ãçºçãããšããŸããgcloud ã³ãã³ã㯠Cloud Storage API ãžãªã¯ãšã¹ããããããã«ã storage.googleapis.com ãž HTTPS ãããã³ã«ã§ã¢ã¯ã»ã¹ããããšããŸããVM ã¯ããã©ã«ãã§ã¯ Cloud DNS ãåç
§ããã®ã§ãéå®å
¬éãŸãŒã³ãåªå
çã«äœ¿ã£ãŠåå解決ãããŸãã ã¯ã©ã€ã¢ã³ãã®åäœã®æµãã¯ã以äžã®ãšããã§ãã VM ã storage.googleapis.com ãåå解決ãããã Cloud DNS ãžã¯ãšãªãã ã¯ãšãªã¯ *.googleapis.com ã«äžèŽããŠããã®ã§ãCNAME ã§ googleapis.com ãžè§£æ±ºããã googleapis.com 㯠A ã¬ã³ãŒãã«ãã Private Service Connect ãšã³ããã€ã³ãã® IP ã¢ãã¬ã¹ã«è§£æ±ºããã VM 㯠åå解決ã®çµæãåãåã gcloud ã³ãã³ã㯠Private Service Connect ãšã³ããã€ã³ãã® IP ã¢ãã¬ã¹ãž API ãªã¯ãšã¹ããå®è¡ãã åèãšããŠãCloud DNS ã§ã®ã¬ã³ãŒãè¿œå æžã¿ã®ç»é¢ã®ã¹ã¯ãªãŒã³ã·ã§ãããšãå®éã« VM ã®äžããåå解決ã詊ã¿ãçµæã以äžã«è²Œä»ããŸãã Cloud DNSã§ã¬ã³ãŒããèšå®ãããŠãã VMããCloud Storageãåå解決ãããšãšã³ããã€ã³ãURLãè¿ã ãªã³ãã¬ãã¹ããå©çšãã ãããŸã§ãCompute Engine VM ãã Private Service Connect ãšã³ããã€ã³ããå©çšããããã®èšå®æé ã説æããŸããã äžæ¹ãCloud Interconnect ã Cloud DNS ã§æ¥ç¶ããããªã³ãã¬ãã¹ãããã¯ãŒã¯ãã Private Service Connect ãšã³ããã€ã³ããå©çšããã«ã¯ã以äžã®èšå®ã远å ã§å¿
èŠã§ãã Private Service Connect ãšã³ããã€ã³ãã® IP ã¢ãã¬ã¹ããCloud Router ãããªã³ãã¬ãã¹åŽã«åºå ±ãã ãªã³ãã¬ãã¹ããŒããåç
§ãã DNS ã«ãã©ã¯ãŒããŒèšå®ã远å ããŠãGoogle Cloud APIs ã®åå解決ã Cloud DNS ãã©ã€ããŒããŸãŒã³ã«è»¢éãã 1ã€ç®ã¯ãCloud Router ã® ã«ã¹ã¿ã ã«ãŒã ã¢ããã¿ã€ãº ã§å®çŸå¯èœã§ãã2ã€ç®ã¯ãCloud DNS ã® åä¿¡ãµãŒã㌠ããªã·ãŒ ã§å®çŸå¯èœã§ãã 2ã€ç®ã«ã€ããŠã¯ããªã³ãã¬ãã¹ã®ã¯ã©ã€ã¢ã³ãã Private Service Connect ãšã³ããã€ã³ãã«åãã°è¯ãã®ã§ããªã³ãã¬ãã¹ããŒããåç
§ãã DNS ã«çŽæ¥ Cloud DNS ãšåãã¬ã³ãŒãã远å ããŠãæ§ããŸããã 詳现ãªèšå®æé ã¯ã以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : ãšã³ããã€ã³ããã Google API ã«ã¢ã¯ã»ã¹ãã - ãªã³ãã¬ãã¹ ãã¹ããããšã³ããã€ã³ãã«ã¢ã¯ã»ã¹ãã ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãX (æ§ Twitter) ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-genã®ææã§ããGoogle CloudïŒæ§ç§° GCPïŒã® è«æ±ãã®ä»çµã¿ ã è«æ±å
ã¢ã«ãŠã³ã ã«ã€ããŠè§£èª¬ããŸãã åºæ¬çãªæŠå¿µ æŠå¿µãšçšèª è«æ±å
ã¢ã«ãŠã³ããšã¯ ãæ¯æããããã¡ã€ã« è€æ°ã®ãããžã§ã¯ããšè«æ± ç¡ææ ãããžã§ã¯ããšã®çŽã¥ã çŽã¥ãã®åºæ¬ å¿
èŠãª IAM æš©é Google Cloud ããŒãããŒã«ããè«æ±ä»£è¡ïŒè«æ±ä»£è¡ïŒ è«æ±ä»£è¡ã®ä»çµã¿ Marketplace ã«é¢ããæ³šæç¹ 課éã¬ããŒã 課éã¬ããŒããšã¯ ã¬ããŒãã®ã³ã Tips ç®¡çæ©èœ äºç®ã¢ã©ãŒã ç°åžžæ€ç¥ïŒAnomaly DetectionïŒ èª²éããŒã¿ã® BigQuery ãšã¯ã¹ããŒã ãããžã§ã¯ããšè«æ±å
ã¢ã«ãŠã³ãã®ãªã³ã¯ãä¿è· AWS ãšã®éã åºæ¬çãªæŠå¿µ æŠå¿µãšçšèª åœèšäºã§ã¯ Google CloudïŒæ§ç§° GCPïŒã® è«æ±ã®ä»çµã¿ ããŸã è«æ±å
ã¢ã«ãŠã³ã ãšããèšèããAmazon Web ServicesïŒä»¥äžãAWSïŒãšæ¯èŒãã€ã€è§£èª¬ããŸãã ãŸãã¯è«æ±å
ã¢ã«ãŠã³ãã®ä»çµã¿ãæŠå¿µãå³ç€ºããŸãã è«æ±ã®æŠå¿µ å³ã®äžã«ããã3ã€ã®çšèªãç°¡åã«èª¬æãããšã以äžã®ãšããã§ãã çšèª 説æ è«æ±å
ã¢ã«ãŠã³ã è«æ±å
æ
å ±ãå®çŸ©ããèšå®ãªããžã§ã¯ãããããžã§ã¯ããšçŽã¥ãã ãæ¯æããããã¡ã€ã« ã¯ã¬ãžããã«ãŒãçªå·ãªã©ãæ¯æãæ
å ±ãå®çŸ©ããèšå®ãªããžã§ã¯ããè«æ±å
ã¢ã«ãŠã³ããšçŽã¥ãã ãããžã§ã¯ã Google Cloud ã®ãªãœãŒã¹ãå容ããããããããããã³ãã åè : Cloud Billing ã«ã€ããŠ è«æ±å
ã¢ã«ãŠã³ããšã¯ Google Cloud ãå©çšããããã«ã¯ ãããžã§ã¯ã ã®äœæãå¿
èŠã§ããããããžã§ã¯ãããšã«è«æ±å
ãèšå®ããå¿
èŠããããŸãããã®è«æ±å
ãå®çŸ©ããèšå®ãªããžã§ã¯ããã è«æ±å
ã¢ã«ãŠã³ã ã§ããè«æ±å
ã¢ã«ãŠã³ãã§ã¯ã以äžã®ãããªæ
å ±ãèšå®ããããæ
å ±ãé²èЧãããã§ããŸãã è«æ±å
ïŒãæ¯æããããã¡ã€ã«ïŒ è«æ±æžã®è¡šç€ºãããŠã³ããŒã 課éã®åæ äºç®ã¢ã©ãŒãïŒå©çšæéãäžå®å€ãè¶
ãããšèŠåã¡ãŒã«ãçºä¿¡ããïŒ äžåºŠãè«æ±å
ã¢ã«ãŠã³ããäœããšããã®è«æ±å
ã¢ã«ãŠã³ãã¯åå©çšãã§ããè€æ°ã®ãããžã§ã¯ããšçŽã¥ããããšãã§ããŸããã€ãŸããè«æ±å
ã¢ã«ãŠã³ããšãããžã§ã¯ã㯠1:n ã®é¢ä¿ã§ãã ãæ¯æããããã¡ã€ã« ãæ¯æããããã¡ã€ã« ã«ã¯ãã¯ã¬ãžããã«ãŒãæ
å ±ãè«æ±æžéä»å
ãªã©ãå
·äœçãªæ¯æãæ
å ±ãå«ãŸããŠããŸãã ãªãããæ¯æããããã¡ã€ã«ã衚瀺ãããç·šéãããããæš©éã¯ãè«æ±å
ã¢ã«ãŠã³ãã®æš©éãšã¯ç¬ç«ããŠèšå®å¯èœã§ãããæ¯æããããã¡ã€ã«ã¯äžåºŠèšå®ãããšãç·šéãããé²èЧãããããé »åºŠã¯äœãã¯ãã§ãã®ã§ãæš©éãæã€ã¹ã人ã¯è«æ±å
ã¢ã«ãŠã³ããããããå°ãªããªãã¯ãã§ããã¯ã¬ãžããã«ãŒãçªå·ãªã©ã®æ
å ±ãå
¥ã£ãŠããŸãã®ã§ãããå³å¯ã«æš©é管çããŸãããã è€æ°ã®ãããžã§ã¯ããšè«æ± 以äžã®ããã«ãGoogle Cloud çµç¹ã®äžã«ã¯è€æ°ã®è«æ±å
ã¢ã«ãŠã³ããäœæããããšãã§ããŸãã ãŸãããããžã§ã¯ãããšã«éãè«æ±å
ã¢ã«ãŠã³ããèšå®ã§ããŸãã è«æ±ã®æŠå¿µ (è€æ°è«æ±å
ã¢ã«ãŠã³ã) è«æ±å
ã¢ã«ãŠã³ããè€æ°äœæãããšã管çãç
©éã«ãªããŸãããå©çšå
èš³ãåããã ãã§ã¯ãã¡ã§ãè«æ±æžãå®å
šã«åå²ããããããããžã§ã¯ãããšã«ã¯ã¬ãžããã«ãŒããåãããããªã©ãç¹å¥ãªçç±ããªããã°è€æ°ã®è«æ±å
ã¢ã«ãŠã³ããäœæããå¿
èŠã¯ãããŸããã 1ã€ã®è«æ±å
ã¢ã«ãŠã³ãã«è€æ°ã®ãããžã§ã¯ããçŽã¥ããŠããŠããã³ã³ãœãŒã«ã®è²»çšå
èš³ç»é¢ã§ããããžã§ã¯ãããšãããµãŒãã¹ããšãããã©ã«ãããšããªã© 詳现ã«èª²éã®å
èš³ãé²èЧããããšãå¯èœ ã§ãã éšçœ²ããšãã·ã¹ãã ããšã®èª²éå
èš³ãç¥ããããšãã¯ããŸãã¯ãã®æ¹æ³ãæ€èšããŸãã ç¡ææ Google Cloud ã«ã¯ããµãŒãã¹ããšã«ç¡ææ ãååšããŠããŸããäŸãã° BigQuery ã¯ã1ã¶æãããã10 GiB ã®ããŒã¿ä¿åãã1 TiB ã®ã¹ãã£ã³ããŸã§ãç¡æã§å©çšã§ããŸãã ãã ãããããã® Google Cloud ç¡ææ ã¯ãç¹èšããªãå Žåã¯ãè«æ±å
ã¢ã«ãŠã³ããã®åäœã§ã«ãŠã³ããããŸããGoogle Cloud ãããžã§ã¯ããè€æ°ãã£ãŠãããããã®ãããžã§ã¯ãã åãè«æ±å
ã¢ã«ãŠã³ãã«çŽã¥ããŠããã°ã1ã€ã®ç¡ææ ãå
±æãã ããšã«ãªããŸãã åè : ç¡ææ ãããžã§ã¯ããšã®çŽã¥ã çŽã¥ãã®åºæ¬ Google Cloud ãããžã§ã¯ããè«æ±å
ã¢ã«ãŠã³ããšçŽã¥ãããšããã®ãããžã§ã¯ãã®ã¯ã©ãŠãå©çšæã¯ããã®è«æ±å
ã¢ã«ãŠã³ãã«å¯ŸããŠèª²éãããŸãã åŸè¿°ãã Google Cloud ããŒãããŒã«ããè«æ±ä»£è¡ãµãŒãã¹ãå©çšããçã®çç±ã§ããã§ã«å©çšäžã® Google Cloud ç°å¢ã«ãããŠãããè«æ±å
ã¢ã«ãŠã³ãããå¥ã®è«æ±å
ã¢ã«ãŠã³ãã«çŽã¥ãã倿Žããããšãå¯èœã§ãã ãã®å ŽåãçŽã¥ã倿Žã® 宿œä»¥é ã«çºçããã¯ã©ãŠãå©çšæéã ãããæ°ããçŽã¥ããè«æ±å
ã¢ã«ãŠã³ãã«èª²éãããããã«ãªããŸããã€ãŸããçŽã¥ããè¡ã£ãç¿æã®è«æ±ã¯ã2ã€ã®è«æ±å
ã¢ã«ãŠã³ãã«åãããŠçºçããããšã«çæããŠãã ããã å¿
èŠãª IAM æš©é Google Cloud ãããžã§ã¯ããšè«æ±å
ã¢ã«ãŠã³ããšã®çŽã¥ãæäœãè¡ãã«ã¯ãæäœè
ã® Google ã¢ã«ãŠã³ãã«ã以äžã® äž¡æ¹ã®æš©é ãå¿
èŠã§ãã ãããžã§ã¯ãã«å¯Ÿãã resourcemanager.projects.createBillingAssignment æš©é è«æ±å
ã¢ã«ãŠã³ãã«å¯Ÿãã billing.resourceAssociations.create æš©é äžèšã®ãã¡ 1. ãæºããã«ã¯ããããžã§ã¯ãã«å¯ŸããŠä»¥äžã®ããããã®ããŒã«ãå¿
èŠã§ãïŒäŸç€ºã§ãããä»ã«ãå¿
èŠãªæš©éãå«ãã ããŒã«ã¯ååšããŸãïŒã ãªãŒããŒïŒ roles/owner ïŒ ãããžã§ã¯ãè«æ±ç®¡çè
ïŒ roles/billing.projectManager ïŒ ãŸããäžèšã®ãã¡2. ãæºããã«ã¯ãè«æ±å
ã¢ã«ãŠã³ãã«å¯ŸããŠä»¥äžã®ããããã®ããŒã«ãå¿
èŠã§ãïŒåæ§ã«ãäŸç€ºã§ãïŒãïœ è«æ±å
ã¢ã«ãŠã³ã管çè
ïŒ roles/billing.admin ïŒ è«æ±å
ã¢ã«ãŠã³ã ãŠãŒã¶ãŒ ïŒ roles/billing.user ïŒ ã¢ã¯ã»ã¹å¶åŸ¡ã«é¢ãã詳现ãè«æ±å
ã¢ã«ãŠã³ãã«å¯Ÿã㊠IAM ããŒã«ãä»äžããæ¹æ³ã«ã€ããŠã¯ã以äžã®å
¬åŒããã¥ã¡ã³ãããåç
§ãã ãããïœ åè : Cloud Billing のアクセス制御と権限 | Google Cloud Documentation åè : Cloud 請求先アカウントへのアクセスを管理する | Cloud Billing | Google Cloud Documentation Google Cloud ããŒãããŒã«ããè«æ±ä»£è¡ïŒè«æ±ä»£è¡ïŒ è«æ±ä»£è¡ã®ä»çµã¿ Google Cloud ããŒãããŒã«ããè«æ±ä»£è¡ãµãŒãã¹ïŒèª²é代è¡ãµãŒãã¹ïŒãå©çšããããšã§ã Google Cloud ãå²åŒæéã§å©çšã§ãããªã©ã®ã¡ãªããããããŸãã ããŒãããŒçµç±ã§ Google Cloud ãå©çšããå Žåã®è«æ±ã®ä»çµã¿ã¯ããŒãããŒããšã«æ§ã
ã§ãããããã§ã¯ Google Cloud å°æ¥ããŒãããŒã§ãã G-gen ïŒãžãŒãžã§ã³ïŒç€Ÿã®ã±ãŒã¹ãã玹ä»ããŸãã åè : æ ªåŒäŒç€ŸG-gen - Google Cloud è«æ±ä»£è¡ G-gen è«æ±ä»£è¡ãµãŒãã¹ã®ä»çµã¿ G-gen ã®è«æ±ä»£è¡ãµãŒãã¹ã«ç³ã蟌ããšã G-gen ããå©çšè
ã«å¯ŸããŠ è«æ±å
ã¢ã«ãŠã³ããæãåºãã ãŸããå©çšè
ã¯ããã®è«æ±å
ã¢ã«ãŠã³ããèªç±ã«ãããžã§ã¯ãã«çŽã¥ããŠäœ¿çšããããšãã§ããŸãã ãã®è«æ±å
ã¢ã«ãŠã³ãããããžã§ã¯ãã«çŽã¥ããæç¹ãããGoogle Cloud ã®å©çšæé㯠Google ãã G-gen ã«è«æ±ãããŸããG-gen ã¯å©çšè
ã®ä»£ããã« Google ã«æéãæ¯æãããã®åŸã§ãG-gen ããå©çšè
ã«å¯ŸããŠå²åŒæéã§è«æ±ãããŸãã ãã®ãããªä»çµã¿ã§ãããããã§ã« Google Cloud ãèªç€Ÿã®ã¯ã¬ãžããã«ãŒãçã§å©çšããŠããŠãããããžã§ã¯ãã®çŽã¥ãå
ã G-gen ã®è«æ±å
ã¢ã«ãŠã³ãã«åãæ¿ããã ãã§ãè«æ±ä»£è¡ãµãŒãã¹ãå©çšããããšãã§ããŸãããã®ãšããååçã« ã·ã¹ãã ã®äžæãå©çšå¯èœãªæ©èœå·®ãªã©ã¯ãªã ãG-gen çµç±ã®æ¯æãã«åãæ¿ããŠã å²åŒã®æ©æµãåãã ããšãã§ããŸãã ãŸã G-gen ã®è«æ±ä»£è¡ãµãŒãã¹ã§ã¯ãåœèšäºã§ç޹ä»ãã課éã¬ããŒããäºç®ã¢ã©ãŒããªã©ãè«æ±å
ã¢ã«ãŠã³ãã®ç®¡çæ©èœããå¶éãªãå©çšã§ããŸãã åœèšäºã§ã¯ G-gen 瀟ã®ã±ãŒã¹ã玹ä»ããŸããããããŒãããŒã«ãã£ãŠä»çµã¿ãç°ãªããŸãã®ã§ã詳现ã¯ããŒãããŒã®å¶æ¥æ
åœè
ã«ãåãåãããã ããã G-gen 瀟ã®è«æ±ä»£è¡ãµãŒãã¹ã®è©³çްã¯ã以äžããåç
§ãã ããã g-gen.co.jp Marketplace ã«é¢ããæ³šæç¹ Google Cloud Marketplace çµç±ã§è³Œå
¥ãããµãŒãããŒãã£è£œåã¯ãå販ã®èŠå®ã®é¢ä¿ã§ããŒãããŒçµç±ã§ã®è²©å£²ãã§ããªãå ŽåããããŸãã ãŸã Google 補åã®äžã§ã Google Maps Platform ã Firebase ãªã©å販èŠå®ãå°ãç¹æ®ãªãµãŒãã¹ããããŸãããããã®ãµãŒãã¹ãå©çšããŠããå Žåã¯ãããŒãããŒã®å¶æ¥æ
åœè
ã«ãåãåãããã ããã äžæ¹ã§ãæ ªåŒäŒç€Ÿ G-gen ã®å Žå㯠MCPOïŒMarketplace Channel Private OfferïŒãšããä»çµã¿ã«ããããµãŒãããŒãã£è£œåã Google Cloud Marketplace çµç±ã§è³Œå
¥ããéã«å²åŒã®æ©æµãåŸãããå ŽåããããŸãã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp 課éã¬ããŒã 課éã¬ããŒããšã¯ Google Cloud ã®èª²éæ
å ±ãé²èЧã§ãã 課éã¬ããŒã æ©èœããããŸããGoogle Cloud ã³ã³ãœãŒã«ã§ ãæ¯æã > ã¬ããŒã ãžé·ç§»ããããšã§ãè«æ±å
ã¢ã«ãŠã³ãããšã«è©³çްã«èª²éå
容ãå¯èŠåã§ããŸãããªããG-gen ã®è«æ±ä»£è¡ãµãŒãã¹ã§ã¯ãã客æ§ã¯èªç±ã«èª²éã¬ããŒããé²èЧã§ããŸãã åè : Cloud Billing ã¬ããŒã 課éã¬ããŒã ãã®ã¬ããŒãç»é¢ã§ã¯ã以äžã®ãããªåãå£ã§èª²éé¡ãã°ã©ãã£ã«ã«ã«è¡šç€ºã§ããŸãã ãããžã§ã¯ãããš ãµãŒãã¹ããš SKUïŒèª²éåäœïŒããš ãªãœãŒã¹ã«ä»äžããã©ãã«ããš ãªãŒãžã§ã³ããš äžèšã®æãåãã ã¬ããŒãã®ã³ã Google Cloud ã³ã³ãœãŒã«ç»é¢ã§ ãæ¯æã > ã¬ããŒã ã«é·ç§»ããŠèª²éã¬ããŒãã衚瀺ããéãåæç¶æ
ã§ã¯ã°ã©ãäžéšã®ãã°ã«ãŒãæ¡ä»¶ããã£ã«ã¿ã§ããµãŒãã¹ããéžæãããŠããå ŽåããããŸãã ããµãŒãã¹ãã§ã°ã«ãŒãã³ã°ãããŠãã ãã®ç¶æ
ã§ã¯ã課éé¡ããµãŒãã¹ããšïŒVertex AIãBigQueryãCompute Engine ãªã©ïŒã«è¡šç€ºãããŸãããã®è¡šç€ºæ¹æ³ã ãšãããããã®ãµãŒãã¹ã§ããªãã課éãçºçããŠããã®ããçè§£ããããšãã§ããŸãããBigQuery ã®æéãç¯çŽããããšèããæãã¹ãã£ã³éã«å¯Ÿãã課éãçºçããŠããã®ããã¹ãã¬ãŒãžæéã«å¯Ÿãã課éãçºçããŠããã®ãã確èªããªããã°ãé©åãªå¯ŸåŠãæã€ããšãã§ããŸããã ãã°ã«ãŒãæ¡ä»¶ããã£ã«ã¿ ã§ãSKUããéžæããããšã§ããã现ãã軞ã§èª²éé¡ã衚瀺ã§ããŸãã ãã°ã«ãŒãæ¡ä»¶ããã£ã«ã¿ SKU ãšã¯ãGoogle Cloud ã®æå°ã®èª²éåäœã§ããäŸãã° BigQuery ã§ããã°ã Analysis (asia-northeast1) ãšãã SKU ã¯æ±äº¬ãªãŒãžã§ã³ã«ããããªã³ããã³ã課éã¢ãŒãã§ã®ã¹ãã£ã³æéã瀺ããŠãããäžæ¹ã§ Active Logical Storage (asia-northeast1) ã¯æ±äº¬ãªãŒãžã§ã³ã«ãããã¹ãã¬ãŒãžæéã瀺ããŠããŸãã åè : SKU Groups - BigQuery åè : SKU Groups ãSKUãã§ã°ã«ãŒãã³ã°ãã衚瀺 ã¬ããŒãã SKU åäœã§è¡šç€ºããããšã§ãã³ã¹ãåæžãªã©ã«ãããé©åãªæã¡æãæ€èšããããšãã§ããŸãã ãŸããã°ã«ãŒãæ¡ä»¶ã§ã¯ä»ã«ãããããžã§ã¯ããããããžã§ã¯ãéå±€ïŒçµç¹ããã©ã«ãçïŒããã±ãŒã·ã§ã³ïŒãªãŒãžã§ã³ïŒãã®åäœã§ã®ã°ã«ãŒãã³ã°ãæå®ã§ããããã«ãªã£ãŠããŸãããŸã衚瀺察象㮠SKU ããããžã§ã¯ããæå®ããŠè¡šç€ºå¯Ÿè±¡ãçµãããšãã§ãããªã©ã詳现ã«è¡šç€ºãã³ã³ãããŒã«ã§ããŸãã 課éã¬ããŒããããŸã䜿ããšã以äžã®ãããªæµãã§ãGoogle Cloud ã®ã³ã¹ãåæžæœçãæ€èšããããšãã§ããŸãã ã°ã«ãŒãæ¡ä»¶ããSKUãã«ããŠèª²éã¬ããŒãã衚瀺 ç¹ã«æéã®ããã£ãŠãã SKU ãç¹å® SKU ãã£ã«ã¿ã§ãç¹å®ãã SKU ã ãã«æé衚瀺ãçµã ã°ã«ãŒãæ¡ä»¶ãããããžã§ã¯ããã«ããŠèª²éã¬ããŒããå衚瀺 ããã«ããããã® SKU ã§ã®èª²éãç¹ã«å€ãçºçããŠãããããžã§ã¯ããç¹å® ãããžã§ã¯ãã®æ
åœè
ã«å¯Ÿçãæç€º Tips 課éã¬ããŒãã«é¢ãã Tips ãšããŠã以äžã®èšäºãåèã«ããŠãã ããã blog.g-gen.co.jp ç®¡çæ©èœ äºç®ã¢ã©ãŒã è«æ±å
ã¢ã«ãŠã³ãã«å¯Ÿã㊠äºç® ãèšå®ãããã®éé¡ã® n % ã«éãããã¡ãŒã«éç¥ããããªã©ã®ã¢ã©ãŒãèšå®ãå¯èœã§ãã äºç®ã®ç²åºŠããæããšãååæããšã幎éãªã©ä»»æã®æéã«ã§ããŸãããäºç®ã®é©çšç¯å²ãããžã§ã¯ãããµãŒãã¹ã现ããéžæã§ããŸãã äŸãã° ã1ã¶æã§XXXãããžã§ã¯ããšYYYãããžã§ã¯ãã®åèšäºç®ã ï¿¥2,000,000 ãšããããã®äºç®ã«å¯Ÿã 50% ã«éãããšããš 75% ã«éãããšãã«ã¡ãŒã«ãçºå ±ããã ãªã©ã®èšå®ãå¯èœã§ãã åè : äºç®ãšäºç®ã¢ã©ãŒããäœæãç·šéãåé€ãã äºç®ã¢ã©ãŒãã®èšå®æ¹æ³ã«ã€ããŠã¯ã以äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp ç°åžžæ€ç¥ïŒAnomaly DetectionïŒ è«æ±å
ã¢ã«ãŠã³ãã«ã¯ã ç°åžžæ€ç¥ ïŒAnomaly DetectionïŒæ©èœããããŸãã ç°åžžæ€ç¥ã¯ãGoogle Cloud ã®çªçºèª²éãæ€ç¥ã§ããæ©èœã§ããè«æ±å
ã¢ã«ãŠã³ãåäœã§ãéå»ã®äœ¿çšåŸåãæ©æ¢°åŠç¿ã«ããåŠç¿ãããéåžžãã¿ãŒã³ãšç°ãªã課éãçºçãããšç°åžžïŒanomalyïŒãšããŠæ€ç¥ãããŸãã åè : View and manage cost anomalies åœæ©èœã®è©³çްã«ã€ããŠã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp 課éããŒã¿ã® BigQuery ãšã¯ã¹ããŒã è«æ±å
ã¢ã«ãŠã³ãã®èª²éå±¥æŽãã BigQuery ãžèªåãšã¯ã¹ããŒã ããããšãã§ããŸããBigQuery ã«ãã課éããŒã¿ã®è©³çްãªåæãè¡ããããšãã«æŽ»çšã§ããŸãã ãšã¯ã¹ããŒãããå
容ã¯ä»¥äžã®3ã€ããéžæã§ããããããåºåãããããŒã¿ã®ç²åºŠãéããŸãã æšæºã®äœ¿çšæéïŒStandard usage cost dataïŒ è©³çŽ°ãªäœ¿çšæéïŒDetailed usage cost dataïŒ æéïŒPricing dataïŒ ãæšæºã®äœ¿çšæéïŒStandard usage cost dataïŒãã«ã¯ãè«æ±æããµãŒãã¹ã SKU ããããžã§ã¯ããã©ãã«ããªãŒãžã§ã³ãè²»çšã䜿çšéãã¯ã¬ãžããïŒå²åŒïŒãªã©ã®æ
å ±ãå«ãŸããŸãã ã詳现ãªäœ¿çšæéïŒDetailed usage cost dataïŒãã«ã¯ãæšæºã®äœ¿çšæéãã«å«ãŸããæ
å ±ã«å ããŠããã®æéãçºçããããªãœãŒã¹åãªã©åå¥ãªãœãŒã¹ã®æ
å ±ãå«ãŸããŸãããªãœãŒã¹ã¬ãã«ã§ã®åæãå¿
èŠãªå Žåã«å©çšã§ããŸãã ãæéïŒPricing dataïŒãããšã¯ã¹ããŒããããšãGoogle Cloud ã®ææ°ã®æéå䟡ããšã¯ã¹ããŒããããŸããGoogle Cloud ã®å©çšæéå䟡ã¯å€æŽãããããšãããã®ã§ãããããææ°ã®æéå䟡ãååŸããããšã§ãåæã«æŽ»çšã§ããŸãã 詳现ãªä»æ§ã«ã€ããŠã¯ã以äžã®ããã¥ã¡ã³ãããåç
§ãã ããã åè : Cloud Billing ããŒã¿ã BigQuery ã«ãšã¯ã¹ããŒããã åè : BigQuery å
ã® Cloud Billing ããŒã¿ããŒãã«ã«ã€ã㊠ãªãããããã®æ©èœã«ãã£ãŠçæãããããŒãã«ã¯èªåçã«ãåãèŸŒã¿æ¥ä»ã«ããããŒãã£ã·ã§ã³ããèšå®ãããŸããBigQuery ã§ã¯ããŒãã«ãããã®ããŒãã£ã·ã§ã³ã®æå€§æ°ã¯ 10,000 ã§ãããããã¯æ¥åäœã§ã®ããŒãã£ã·ã§ã³ã§ã¯ ããã27å¹Žã§æ¯æž ããããšãæå³ããŠããŸãããããè¶
ããå Žåããšã¯ã¹ããŒãããšã©ãŒãšãªãããšãèããããŸãã®ã§ãé·æå©çšãæ³å®ãããå Žåã¯ããŒãã£ã·ã§ã³ã«27幎çšåºŠã®æéãèšå®ããããŒã¿ãèªååé€ãããããã«èšå®ããããšãæãŸããã§ãããããã®å Žåã¯ãããŒã¿ã®ããã¯ã¢ãããªã©ã¯å¥éãæ€èšããå¿
èŠããããŸãã ãããžã§ã¯ããšè«æ±å
ã¢ã«ãŠã³ãã®ãªã³ã¯ãä¿è· ãããžã§ã¯ããšè«æ±å
ã¢ã«ãŠã³ãéã®ãªã³ã¯ã誀ã£ãŠè§£é€ãããªããããããã¯ããããšãã§ããŸãã ãããžã§ã¯ããšè«æ±å
ã¢ã«ãŠã³ãã®çŽã¥ããè§£é€ããããããžã§ã¯ãã«è«æ±å
ã¢ã«ãŠã³ããçŽã¥ããããŠããªãç¶æ
ã«ãªããšãäžéšã® Google Cloud ãªãœãŒã¹ãåé€ããã埩å
äžèœã«ãªãå¯èœæ§ããããŸããããã«äŒŽãããããžã§ã¯ãå
ã®ããŒã¿ãæ¶å€±ãããããããããŸãã åè : ãããžã§ã¯ãã®èª²éãç¡å¹ã«ãã 誀æäœçã§çŽã¥ããè§£é€ãããŠããŸã£ãããç°ãªãè«æ±å
ã¢ã«ãŠã³ãã«çŽã¥ããå€ããããšãé²ãããããªã³ã¯ãããã¯ããããšãå¯èœã§ããããã¯ããã«ã¯ Google Cloud ã³ã³ãœãŒã«ã®ã課éãç»é¢ã§ããã€ãããžã§ã¯ããã¿ããžé·ç§»ãã察象ãããžã§ã¯ãã®äžç¹ãªãŒããŒãããè«æ±ãããã¯ããéžæããŸãã åè : ãããžã§ã¯ããšè«æ±å
ã¢ã«ãŠã³ãéã®ãªã³ã¯ãä¿è·ãã è«æ±å
ã¢ã«ãŠã³ãã®ãã㯠AWS ãšã®éã Google Cloud ãš Amazon Web ServicesïŒAWSïŒã®è«æ±ã®ä»çµã¿ãšã®éãããç°¡åã«ã玹ä»ããŸãã AWS ã§ã¯ãã¯ã¬ãžããã«ãŒãçã®è«æ±å
æ
å ±ã¯ AWS ã¢ã«ãŠã³ãããšã«å®çŸ© ããŸãããAWS ã¢ã«ãŠã³ãããšã¯ãããããããã³ãããšèšãæããããšãã§ãã Google Cloud ã§ããã«æãè¿ãæŠå¿µã¯ããããžã§ã¯ããã§ãã AWS ã§ã¯ AWS ã¢ã«ãŠã³ãããš ã«è«æ±æ
å ±ãèšå®ããã®ãåºæ¬ã§ããè€æ°ã® AWS ã¢ã«ãŠã³ãã®è«æ±ããŸãšããã«ã¯ Consolidated Billing ãšããæ©èœãå©çšããŸãããã AWS ã¢ã«ãŠã³ãã 管çã¢ã«ãŠã³ã ïŒæ§ç§°ãã¹ã¿ãŒã¢ã«ãŠã³ãïŒãšããããšã§ã管çã¢ã«ãŠã³ãã«è«æ±ããŸãšããããšãã§ããŸãã AWSã®è«æ±ã®æŠå¿µ äžæ¹ã§ãGoogle Cloud ã¯è«æ±å
æ
å ±ã®èšå®ã è«æ±å
ã¢ã«ãŠã³ã ãšããŠç¬ç«ããŠããŠåå©çšå¯èœã§ãã Google Cloudã®è«æ±ã®æŠå¿µ ãŸãšãããšãAWS ã§ã¯ãè«æ±å
æ
å ±ã®èšå®ã¯ AWS ã¢ã«ãŠã³ãã®æã€å±æ§ãã§ãããGoogle Cloud ã§ã¯ãè«æ±å
æ
å ±ã®èšå®ã¯ãããžã§ã¯ããšã¯ç¬ç«ããŠããããšããããšãã§ããŸããããããããã2ã€ã®ã¯ã©ãŠãã®è«æ±ã®ä»çµã¿ã«ãããã倧ããªéãã§ãã ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO å
èŠå¯å®ãšããçµæŽãæã€ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS èªå®è³æ Œããã³ Google Cloud èªå®è³æ Œã¯ãã¹ãŠååŸãXïŒæ§ TwitterïŒã§ã¯ Google Cloud ã Google Workspace ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
ã¿ãªããããã«ã¡ã¯ãG-genã®éŽæšããšãããã€ã§ãã ã¿ãªããŸã®äŒç€Ÿããã³ãã¥ããã£ã§ã¯ã¿ã¹ã¯ç®¡çãã©ã®ããã«è¡ã£ãŠããŸãã§ããããïŒ äººã«ãã£ãŠã¯ãªã«ãç¬èªã®ãœãããŠã§ã¢/ã¯ã©ãŠããµãŒãã¹ãå°å
¥ããŠç®¡çããŠã人ãããããšæããŸãã ãããïŒ Google Workspaceã«ã¯ãã§ã«ãã®æ©èœããã ã®ã§ãä»åã¯ãã¡ãã解説ããŠãããŸãããã ãã®æ©èœãå©çšããããšã§ãäŸãã°ã客æ§ãµããŒãã§ãã£ããã瀟å
ã®ãããžã§ã¯ãã®ã¿ã¹ã¯ç®¡çãªã©ãå¿ããããã¿ã¹ã¯ã管çå¯èœïŒ å
±åã¿ã¹ã¯ãšã¯ïŒ å
±åã¿ã¹ã¯ã®å©ç𿹿³ å
±åã¿ã¹ã¯ã®å®éã®å©çš äœæ¥ãå²ãåœãŠã äœæ¥ãã©ãã«ã§ç®¡çãã äœæ¥ãå®äºããã å
±åã¿ã¹ã¯ãšã¯ïŒ ãŸãã¯ããã«ãå
±åã¿ã¹ã¯ã«é¢ããŠç°¡åã«èª¬æããŸããšã以äžã®ããã«ã¡ãŒãªã³ã°ãªã¹ãã§åä¿¡ããã¡ãŒã«ããã¡ãŒã«ãšããŠåŠçããã®ã§ã¯ãªãã äžã€ã®ã¿ã¹ã¯ãšããŠåä¿¡ ããæ©èœã§ãã åä¿¡ããã¿ã¹ã¯ã¯ãã¡ã³ããŒã«ãã£ãŠåå人ã«å²ãåœãŠãããšãå¯èœã§ããã®ã¿ã¹ã¯ã®é²æç®¡çããããšã§ã¬ãããã鲿¢ããããšãã§ããæ©èœã§ãã æ¬æ©èœã¯Google Groupã®æ©èœãå¿çšãããã®ã«ãªããŸããGoogle Groupãšããã®ã¯ä»¥äžã®ããã«äžèšã§ãããš ã¡ãŒãªã³ã°ãªã¹ãã®ãããªãã® ã§ãã Google Groupãšã¯ å
±åã¿ã¹ã¯ã®å©ç𿹿³ å®éã«å
±åã¿ã¹ã¯ãå©çšããå Žåãåæèšå®ãå¿
èŠã«ãªããŸãã以äžã®ã°ã«ãŒãèšå®ããã远å ã® Google ã°ã«ãŒãã®æ©èœãæå¹ã«ãããã§ å
±åãã¬ã€ãæå¹ã« ããŸãããã ã€ãã§ã«ãã®ããäžã«ãã å
±æã©ãã« ãæå¹ã«ããŠãããšäŸ¿å©ã§ãã®ã§ããã®ã¿ã€ãã³ã°ã§ONã«ããŠããŸããŸãããã å
±åã¿ã¹ã¯ã®èšå®æ¹æ³(1) å
±åã¿ã¹ã¯ã®èšå®æ¹æ³(2) ãã£ãããã ãã§å
±åã¿ã¹ã¯ã®èšå®æ¹æ³ã¯çµããã§ãã å
±åã¿ã¹ã¯ã®å®éã®å©çš ããã§ã¯æ©éå©çšããŠãããŸãããïŒ å€§ãŸããªäœæ¥ãšããŠã¯ä»¥äžã«ãªããŸãã ã»äœæ¥ãå²ãåœãŠã ã»äœæ¥ãã©ãã«ã§ç®¡çãã ã»äœæ¥ãå®äºããã ãã®åã«ãã§ã¯ã©ããã£ãããã®ã°ã«ãŒãã«äœæ¥ãšããŠè¿œå ã§ããã®ãïŒ ããã¯ç°¡åïŒãã® ã°ã«ãŒãã«ã¡ãŒã«ãéä¿¡ããã ã ã§ããä»åã®å Žåã¯task-mgmt@suzutatsu.onlineãã¡ãŒã«ã¢ãã¬ã¹ã«æå®ããŠãŸãã®ã§ãããã«ã¡ãŒã«ãéä¿¡ããããšã§æ°ããã¿ã¹ã¯ã远å ãããŸãã ãããå¿çšããããšã§äŸãã°ã客æ§ããã®ã質åããµããŒããªã©ããã£ã¡ããšã¿ã¹ã¯ãšããŠç®¡çå¯èœãªããã ã¬ããã鲿¢ã«ç¹ãããã²ããŠã¯ã客æ§ã®ä¿¡é Œç²åŸãžïŒ äœæ¥ãå²ãåœãŠã ãŸãã¯ããã«åä¿¡ããã¿ã¹ã¯ã«é¢ããŠæ
åœãå²ãåœãŠãŠã¿ãŸãããã 以äžã®ããã«ã¿ã¹ã¯ãã¯ãªãã¯ããå³äžã®ã¢ã€ã³ã³ããæ
åœè
ãæåããããšãå¯èœã§ãã ããã§ã¿ã¹ã¯ãå人ã«å²ãåœãŠãããŸããã ã¿ã¹ã¯ã®å²ãåœãŠ äœæ¥ãã©ãã«ã§ç®¡çãã ã¿ã¹ã¯ãå€ããªã£ãŠãããšãã«ã éèŠåºŠã§ç®¡ç ããããã©ã® éšéã§å¯Ÿå¿ãã¹ãäºé
ããªã©ãæ§ã
ãªã©ãã«ãå¿
èŠã«ãªãå ŽåãããããšæããŸãã ãã®å Žåã«åœ¹ã«ç«ã€ã®ãæåã«æå¹åããŠãããå
±æã©ãã«ã«ãªããŸãããã¡ããå©çšããããšã§åã¿ã¹ã¯ãäžç®çç¶ïŒ ä»åã¯ç·æ¥å¯Ÿå¿ãå¿
èŠãšããæ³å®ã§èšå®ããŠã¿ãŸãããã å
±æã©ãã«ã®èšå®(1) å
±æã©ãã«ã®èšå®(2) 以äžã®ããã« ç·æ¥å¯Ÿå¿ãå¿
èŠ ã ãšããããšãäžç®çç¶ã§ããã å
±æã©ãã«ã®èšå®(3) äœæ¥ãå®äºããã åé ããã¿ã¹ã¯ã®å®æœäºé
ãå®äºãããšãã«ã¿ã¹ã¯ã®ç¶æ
ãå®äºã«ããããäœãããããšããªãããšãæããã«ããŸãããã ãŸãããã®ãšãã«å
±æã©ãã«ãå¯Ÿå¿æžã¿ããªã©ã«ããŠãããšããããããããã§ããã ã¿ã¹ã¯ã®å®äº(1) ã¿ã¹ã¯ã®å®äº(2) ããã§å
±åã¿ã¹ã¯ã®äžé£ã®å©ç𿹿³ã®è§£èª¬ã¯çµããã«ãªããŸããæã£ããããç°¡åã ã£ãã®ã§ã¯ãªãã§ããããïŒ Google Workspaceã«ã¯ãã®ããã«å®ã¯ç°¡åã«äœ¿ããã®ã ãã©ãç¥ãããŠãªãæ©èœã沢山ãããŸãã åŒç€Ÿã§ã¯Google Workspaceã®äœ¿ãæ¹ãããµããŒããããŠããã ããŸãã®ã§ããæ°è»œã«ã声ãããã ããïŒ Google Cloud(旧GCP) / Google Workspace導入に関するお問い合わせ Google Workspace éŽæš éæ (èšäºäžèЧ) å·è¡åœ¹å¡ COO ããžãã¹æšé²éš éšé· åºæ¬ããªãã§ãå±ãäž»ã«ããžãã¹ã®ç«ã¡äžããä»çµã¿ã¥ãããå¥œã æ¥ã
ãåªåãæ¥ã
ãæ¥œããããšã倧äºã« ã Professional Cloud Architect / Professional Workspace Administratorã®ã¿ä¿æããŠããŸãããããã倱å¹ããŠããŸããããªäºæã
G-genã®ææã§ãã管ç察象㮠Compute Engine ã€ã³ã¹ã¿ã³ã¹ïŒVMïŒãå€ããšã課é¡ã«ãªãã®ããã°ã€ã³ãŠãŒã¶ãŒã®ç®¡çã§ããGoogle CloudïŒæ§ç§° GCPïŒã®ãµãŒãã¹ Google Compute EngineïŒGCEïŒã«ã¯ OS Login æ©èœ ããããSSH ãã°ã€ã³ãŠãŒã¶ãŒãå¹ççã«ç®¡çã§ããŸãã OS Login ã«ã€ã㊠OS Login ãšã¯ ãã€ã³ã ã¡ãªãã èšå®æé Step 1. OS Login æå¹åïŒã¡ã¿ããŒã¿èšå®ïŒ Step 2. IAM ããŒã«ã®ä»äž ãã°ã€ã³æé OS Login ã«ã€ã㊠OS Login ãšã¯ OS Login 㯠Compute Engine ã® SSH ãã°ã€ã³æã®èªèšŒã IAM ã§ç®¡çããããã®ä»çµã¿ã§ãã OS Login æ©èœã§ã¯ã VM ãž SSH ãã°ã€ã³ãããŠãŒã¶ã Google ã¢ã«ãŠã³ããšé£åããŠç®¡ç ã§ããŸãããªããåœæ©èœã§ç®¡çã§ããã®ã¯ SSH ãã°ã€ã³ã§ããããã察象㯠Linux VM ã®ã¿ã§ãããWindows Server ã¯å¯Ÿè±¡å€ã§ãã OS Login æ©èœããããžã§ã¯ãããšã«ããŸãã¯ã€ã³ã¹ã¿ã³ã¹ããšã«æå¹åãããšãSSH ãŠãŒã¶ãŒã Google ã¢ã«ãŠã³ããã°ã«ãŒããšçŽã¥ããŠç®¡çã§ããŸããGoogle ã¢ã«ãŠã³ãïŒã°ã«ãŒãïŒã«ä»äžãã IAM ããŒã«ã«ãã£ãŠã VM ãžã®ãã°ã€ã³å¯åŠ ãšã sudo å¯åŠ ãæå®ã§ããŸãã ãªã OS Login ã¯ãç¡æã§äœ¿çšã§ããŸãã åè : OS Login ã®æŠèŠ OS Loginæ©èœã®æŠå¿µ ãã€ã³ã æå¹å / ç¡å¹å㯠Compute Engine ã®ã¡ã¿ããŒã¿ïŒã€ã³ã¹ã¿ã³ã¹åäœ / ãããžã§ã¯ãåäœïŒã§æå®ãã å
¬ééµ / ç§å¯éµã¯èªåçæããã€ã³ã¹ã¿ã³ã¹ã®äžã«é£æºããã OS Login ã§ã¯ OS ãŠãŒã¶ãŒã <ã¢ã«ãŠã³ãå>_<ãã¡ã€ã³å> ãšããåç§°ã§èªåäœæããã äŸ: john@g-gen.co.jp â john_g_gen_co_jp 2段éèªèšŒãèšå®å¯èœ ã¡ãªãã VM ã«ãã°ã€ã³ã§ããå©çšè
ã Google ã¢ã«ãŠã³ãïŒã°ã«ãŒãïŒã§ç®¡çã§ããããã OS ãŠãŒã¶ãŒçµ±å¶ã®æ¹å ã 管çã»éçšã®å·¥æ°åæž ãæåŸ
ã§ããŸãã ãã°ã€ã³æã®2段éèªèšŒãç°¡åã«èšå®ã§ããã®ã§ãã»ãã¥ãªãã£ã¬ãã«ã®åäžãèŠèŸŒããŸãã å察㫠OS Login æ©èœãå©çšããªãã§ SSH ãŠãŒã¶ãŒã管çããæ¹æ³ã«ã¯ã ã¡ã¿ããŒã¿ãããŒãžã SSH æ¥ç¶ ããããŸãããã¡ãã®å ŽåãäŸãã° gcloud compute ssh ã§ãã°ã€ã³ãè¡ããããšãæäœãã PC ç°å¢ã®ããŒã«ã«ãŠãŒã¶ãŒã®åç§°ã§ãOS ãŠãŒã¶ãŒã VM äžã«èªåäœæãããŸãããã®æ¹æ³ã§ã¯ãVM ã« OS ãŠãŒã¶ãŒãä¹±ç«ããŠããŸããããããããŸãã åè : ã¡ã¿ããŒã¿ ãããŒãžã SSH æ¥ç¶ èšå®æé åè : OS Login ãèšå®ãã Step 1. OS Login æå¹åïŒã¡ã¿ããŒã¿èšå®ïŒ ãŸããOS Login æ©èœã ãããžã§ã¯ãåäœ ã§æå¹åããã®ããããã㯠ã€ã³ã¹ã¿ã³ã¹åäœ ã§æå¹åããã®ããæ±ºå®ããŸãã OS Login ãæå¹åããã«ã¯ãæå®ã®ããŒã»ããªã¥ãŒãã¡ã¿ããŒã¿ã«èšå®ããå¿
èŠããããŸããCompute Engine ã¡ã¿ããŒã¿ã¯ããããžã§ã¯ãåäœã®ã¡ã¿ããŒã¿ãšã€ã³ã¹ã¿ã³ã¹åäœã®ã¡ã¿ããŒã¿ãããŸãã ãããžã§ã¯ãå
šäœã§æå¹åããã«ã¯ããããžã§ã¯ãã® Compute Engine ã¡ã¿ããŒã¿ã« enable-oslogin = TRUE ãèšå®ããŸãã ãããžã§ã¯ãã¬ãã«ã®ã¡ã¿ããŒã¿ äžæ¹ã§ã€ã³ã¹ã¿ã³ã¹åäœã§æå¹åããã«ã¯ãåã
ã®ã€ã³ã¹ã¿ã³ã¹ã® ç·šé ç»é¢ãããã¡ã¿ããŒã¿ã« enable-oslogin = TRUE ãèšå®ããŸãã ã€ã³ã¹ã¿ã³ã¹ã¬ãã«ã®ã¡ã¿ããŒã¿ 2段éèªèšŒãæå¹åãããå Žåã¯ããã®æç¹ã§ã¡ã¿ããŒã¿ã« enable-oslogin-2fa = TRUE ã䜵ããŠèšå®ããŠãã ããã OS Login æ©èœã®2段éèªèšŒã¯ã Google ã¢ã«ãŠã³ãã«èšå®ãããäºæ®µéèªèšŒã®èŠçŽ ãå©çšããŸããããšãã°ãGoogle Authenticator ã® OTP å
¥åãä¿ãããããã¹ããã® Google ã¢ããªã®æ¿èªãã¿ã³ãæŒãããšãä¿ãããããããªã©ã§ãã Step 2. IAM ããŒã«ã®ä»äž OS ã«ãã°ã€ã³ãããã Google ã¢ã«ãŠã³ããŸã㯠Google ã°ã«ãŒãã«ãIAM ããŒã«ãä»äžããŸãã ãªã IAM ã®ãã¹ããã©ã¯ãã£ã¹ãšããŠãIAM ããŒã«ã¯ã¢ã«ãŠã³ãã«çŽæ¥ä»äžããã®ã§ã¯ãªããã°ã«ãŒãã«ä»äžããããšãæšå¥šãããŠããŸãã OS Login ã䜿ãã«ã¯ã以äžã® ãããã ã® IAM ããŒã«ãä»äžããŸãã sudo æš©éãªãã®å Žå roles/compute.osLogin ïŒæ¥æ¬èªå: Compute OS ãã°ã€ã³ ïŒ sudo æš©éããã®å Žå roles/compute.osAdminLogin ïŒæ¥æ¬èªå: Compute OS 管çè
ãã°ã€ã³ ïŒ IAM ããŒã«ã¯ çµç¹ã¬ãã« ãããžã§ã¯ãã¬ãã« åå¥ã€ã³ã¹ã¿ã³ã¹ã¬ãã« ã®ããããã§ä»äžããããšã§ããã® Google ã¢ã«ãŠã³ãïŒã°ã«ãŒãïŒãã©ã®ã€ã³ã¹ã¿ã³ã¹ã«ãã°ã€ã³ã§ãããããæ±ºãŸããŸãã çµç¹ã¬ãã«ã§ä»äžããã°çµç¹é
äžã®å
šãŠã®ã€ã³ã¹ã¿ã³ã¹ã«ããããžã§ã¯ãã¬ãã«ã§ä»äžããã°ãããžã§ã¯ãå
ã®å
šãŠã®ã€ã³ã¹ã¿ã³ã¹ã«ãã€ã³ã¹ã¿ã³ã¹ã¬ãã«ã§ä»äžããã°ãã®ã€ã³ã¹ã¿ã³ã¹ã ãã«ãSSH ãã°ã€ã³ã§ããããã«ãªããŸãã IAM ã®åºæ¬çãªä»çµã¿ã«ã€ããŠã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp ãã°ã€ã³æé OS Login ãæå¹åãããšãã³ã³ãœãŒã«ãã SSH ãã¿ã³ãæŒäžããããgcloud ã³ãã³ãã䜿ã£ãŠ VM ã«ãã°ã€ã³ããéã«ãèªåçã« OS Login ã«ããèªèšŒãè¡ããããã°ã€ã³ã§ããããã«ãªããŸãã ã³ã³ãœãŒã«ããã®SSHãã°ã€ã³ gcloud ã³ãã³ãã§ããã°ãéåžžã® SSH ãã°ã€ã³æãšåãããã«ã以äžã®ããã«å®è¡ããã ãã§ãã gcloud compute ssh --project=${PROJECT_ID} --zone=${ZONE} ${VM_NAME} ããã¡ã¿ããŒã¿ã« enable-oslogin-2fa = TRUE ãèšå®ãããŠããã°ããã®ã¿ã€ãã³ã°ã§2段éèªèšŒãæ±ããããŸãã ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãX (æ§ Twitter) ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
ããã«ã¡ã¯ïŒG-genã®å°æã§ããã¿ãªããGoogle Cloudã¯ãå©çšãããŠãŸãã§ããããïŒã客æ§ãšã話ãããŠããäžã§Google Cloudã䜿ã£ãŠã¿ãŠãããã©ãæåã«äœãèšå®ããŠããã¹ããªã®ãåãããªããŠå°ã£ãŠããããšãã声ããã䌺ããŸããåœèšäºã§ã¯ãGoogle Cloudãã»ãã¥ã¢ã«äœ¿ãããã«ã¯ã©ãããã¹ããªã®ãã«ã€ããŠèª¬æããŸãã ã¯ããã« æåã«å¯Ÿå¿ãã¹ããã§ãã¯ãªã¹ãã®ç¢ºèªæ¹æ³ çµç¹ãš ID ãŠãŒã¶ãŒãšã°ã«ãŒã 管çè
ã¢ã¯ã»ã¹ ãæ¯æã ãªãœãŒã¹éå±€ ãªãœãŒã¹ã®ã¢ã¯ã»ã¹ ãããã¯ãŒãã³ã° ã¢ãã¿ãªã³ã°ãšãã®ã³ã° ã»ãã¥ãªã㣠ãµããŒãïŒã«ã¹ã¿ããŒã±ã¢ïŒ ã¯ããã« åœèšäºã§ã¯ãGoogle Cloudãå©çšéå§ããã°ããã®æ¹ããã»ãã¥ã¢ã«å©çšããããã«å¿
èŠãªããšã説æããŸãã ãGoogle Cloudã瀟å
ã§äœ¿ã£ãŠã¿ãããšããŠãããã©ãå¿
èŠæäœéã®èšå®ãããç¶æ
ã§ãŠãŒã¶ãŒã«äœ¿ããããããæ¬çªå©çšããå Žåã®ããã ãã¯èšå®ããŠããã¹ãé
ç®ãææ¡ããŠããããããšèããŠããã¯ã©ãŠã管çè
ã®æ¹åãã®å
容ã§ãã ãªããåœèšäºã§ç޹ä»ãã Google Cloud ã³ã³ãœãŒã«ç»é¢ã¯2021幎10æçŸåšã®ãã®ã§ããææ°ã®ç¶æ
ãšã¯ç°ãªãå Žåãããç¹ã«ãçæãã ããã æåã«å¯Ÿå¿ãã¹ããã§ãã¯ãªã¹ãã®ç¢ºèªæ¹æ³ Web ãã©ãŠã¶ã§ Google Cloud ã«ãã°ã€ã³ãã[IAMãšç®¡ç] -> [IDãšçµç¹] ã«ã¢ã¯ã»ã¹ããŸããç»é¢äžéšã®ãããžã§ã¯ãã»ã¬ã¯ã¿ã§çµç¹ãéžæãããšã以äžã®è¡šç€ºã«ãªããŸãã ãã®ç»é¢ã§ã¯ãGoogle Cloudãå©çšããéã®æšå¥šèšå®ãæ¡å
ãããŸãã[ãã§ãã¯ãªã¹ãã«ç§»å] ãã¯ãªãã¯ãããšã以äžã®ç»é¢ã«ãªããŸãã ããã«èšèŒãããŠããé
ç®ã1ã€ãã€å¯Ÿå¿ããããšã§ãGoogle ãæšå¥šããæ¬çªã¯ãŒã¯ããŒãã«é©ããç°å¢èšå®ãè¡ãããšãã§ããŸãã ãªããèŠãŠããã ããšåããéãéåžžã«å€ãã®å¯Ÿå¿é
ç®ããããŸããGoogle CloudãåããŠå©çšãã人ã«ãšã£ãŠã¯åãããªãçšèªãçè§£ã«æéããããé
ç®ãã¡ãã»ã...ã ãã®ããã以éã®æ¬æçš¿ã§ã¯å
·äœçã«ã©ã®ãããªèšå®ãå¿
èŠãç°¡åãã€ãããããã解説ããããšæããŸãã çµç¹ãš ID Google Cloud ã管çããããGoogle Cloud äžã§éçºããããã人ã®ã¢ã«ãŠã³ãã¯ãCloud Identity ããã㯠Google Workspace ã§ç®¡çãããŸãã Google Workspace ããã§ã«å©çšããŠããçµç¹ã®æ¹ã¯ããã®ã¢ã«ãŠã³ãã䜿ã£ãŠ Google Cloud ãå©çšããããšãå¯èœã§ããGoogle Workspace ãå©çšããŠããªãçµç¹ã®æ¹ã¯ãCloud Identity ã®æ°ããçµç¹ïŒããã³ãïŒãéèšããå¿
èŠããããŸããCloud Identity Free edition ã¯ã50ã¢ã«ãŠã³ããŸã§ç¡æã§å©çšããããšãã§ããŸãã 宿œå
容 Cloud Identity ããã㯠Google Workspace ãå©çšããŠããå Žå ãã¡ã€ã³ã®æææš©ã®èšŒæãå®äºããŠããããã§ã㯠Cloud Identity ããã㯠Google Workspace ããŸã å©çšããŠããªãå Žå Cloud Identity ã®æ°èŠç»é² ãã¡ã€ã³ã®æææš©ã®èšŒæãå®äºããŠããããã§ã㯠çµç¹ã«ã€ããŠã®è©³çްã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp ãŠãŒã¶ãŒãšã°ã«ãŒã ãŠãŒã¶ãŒãã°ã«ãŒããäœæããŸãã Google Cloud ã§äœ¿çšãããŠãŒã¶ãŒã¢ã«ãŠã³ããã°ã«ãŒãã¯ãGoogle Cloud ã³ã³ãœãŒã«ã§äœæããã®ã§ã¯ãããŸãããåè¿°ã®ãšãããCloud Identity ããã㯠Google Workspace ã®ç®¡çã³ã³ãœãŒã«ã§äœæããŸããGoogle Workspace ã§äœæãããŠãŒã¶ãŒã¢ã«ãŠã³ããã°ã«ãŒããããã®ãŸãŸGoogle Cloud ã§ã䜿çšããã€ã¡ãŒãžã§ãã 宿œå
容 ãŠãŒã¶ãŒã®è¿œå ã°ã«ãŒãã®äœæ ãŠãŒã¶ãŒãã°ã«ãŒãã«è¿œå ãã®ãšããGoogle Cloud ã®çµç¹ç®¡çè
ãè«æ±ç®¡çè
ããããžã§ã¯ãããšã®ç®¡çè
ãªã©ã圹å²ããšã«ã°ã«ãŒããäœãããšãæšå¥šãããŸãã 管çè
ã¢ã¯ã»ã¹ ãã®é
ç®ã§ã¯ã1ã€åã®é
ç®ã§äœæããã°ã«ãŒãã«å¯Ÿã㊠IAM ããŒã«ãå²ãåœãŠãŸãã ãªãããã®äœæ¥ã¯ Cloud Identity ãŸã㯠Google Workspace ã®ç¹æš©ç®¡çè
ãè¡ãå¿
èŠããããŸããCloud Identity ãŸã㯠Google Workspace ã¢ã«ãŠã³ãã®ç¹æš©ç®¡çè
ã¯ãæåãã Google Cloud ã®ãçµç¹ã®ç®¡çè
ãããŒã«ã®æš©éãæã£ãŠããŸãã 宿œå
容 ã°ã«ãŒããžã® IAM ããŒã«ã®å²ãåœãŠ IAM ã®ä»çµã¿ã«ã€ããŠã¯ã以äžã®èšäºãåç
§ããŠãã ãããç¹ã«ãã¯ã©ãŠãã管çãã圹å²ã®æ¹ã¯ IAM ã®ä»çµã¿ãæ£ç¢ºã«çè§£ããããšãåŒ·ãæšå¥šãããŸãã blog.g-gen.co.jp ãæ¯æã ãã®é
ç®ã§ã¯ Google Cloud ã®æ¯æããè¡ãè«æ±å
ã¢ã«ãŠã³ãã®äœæãããŸããGoogle Cloud ã¯æ¯æãã®èšå®ããªããŠãäžéšã®æ©èœãå©çšã§ããŸããããã¹ãŠã®æ©èœãå©çšããã«ã¯ Google Cloud ãããžã§ã¯ãã«å¯ŸããŠ è«æ±å
ã¢ã«ãŠã³ã ã®çŽä»ããå¿
é ã«ãªããŸãã 宿œå
容 è«æ±å
ã¢ã«ãŠã³ãã®äœæ è«æ±å
ã¢ã«ãŠã³ãããŠãŒã¶ãŒãèªãäœæãããšãGoogle ãšçŽæ¥å¥çŽããããšã«ãªããŸããG-gen ã®ãããªãªã»ã©ãŒïŒä»£çåºïŒãšå¥çŽããè«æ±å
ã¢ã«ãŠã³ããçºè¡ããŠãããããšãå¯èœã§ãããªã»ã©ãŒçµç±ã§è«æ±å
ã¢ã«ãŠã³ããçºè¡ããŠããããšã å²åŒ ã ç¡æã®æè¡ãµããŒãçªå£ ãæ¥æ¬åã»è«æ±æžæããã§ãããªã©ããªã»ã©ãŒç¬èªã®ãµãŒãã¹ãåããããšãã§ããŸãã è«æ±å
ã¢ã«ãŠã³ãã«ã€ããŠã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp ãªãœãŒã¹éå±€ Google Cloudã¯ä»¥äžã®ãããªãªãœãŒã¹éå±€ã§æãç«ã£ãŠããŸãã ãã®é
ç®ã§ã¯ããã©ã«ããšãããžã§ã¯ããäœæããŸãã Google Cloud ãããžã§ã¯ã ã¯æäžå±€ã®ç®¡çåäœã§ãããCompute Engine VM ã BigQuery ããŒãã«ãªã©åã
ã®ãªãœãŒã¹ãé
眮ãã管çãªããžã§ã¯ãã§ããAmazon Web ServicesïŒAWSïŒã§ãããšããã®ãAWS ã¢ã«ãŠã³ãããšãããŸãã ãã©ã«ã ã¯ããããžã§ã¯ããã°ã«ãŒããã³ã°ããããã®ç®¡çãªããžã§ã¯ãã§ãã Google Cloud ã®ãã©ã«ãããããžã§ã¯ãã®è©³çްã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp 宿œå
容 ãªãœãŒã¹éå±€ã®èšç» ãã©ã«ãã®äœæ ãããžã§ã¯ãã®äœæ ãããžã§ã¯ãäœææã«ãçŽã¥ããè«æ±å
ã¢ã«ãŠã³ããéžæããŸãããã®ãããžã§ã¯ãã§çºçãã課éã¯ãçŽã¥ããè«æ±å
ã¢ã«ãŠã³ãã«å¯ŸããŠçºçããŸãã1ã€ã®è«æ±å
ã¢ã«ãŠã³ãã«ã¯è€æ°ã®ãããžã§ã¯ããçŽã¥ããããšãã§ããŸããã©ã®ãããžã§ã¯ãã§ã©ã®ãããªèª²éãçºçãããã¯ãè«æ±å
ã¢ã«ãŠã³ãã®èª²éã¬ããŒãã§è©³çްã«ç¢ºèªã§ããŸãã ãªãœãŒã¹ã®ã¢ã¯ã»ã¹ Google Cloud ã§ã¯ãåã
ã®ãªãœãŒã¹ãæã€ IAM èšå®å€ïŒãã®ãªãœãŒã¹ã«å¯ŸããŠã誰ãã©ã®ãããªæš©éãæã£ãŠãããïŒã®ããšã IAM ããªã·ãŒ ãšåŒã³ãŸããäŸãã°ããã Compute Engine VM ã® IAM ããªã·ãŒã«ã¯ã user01@example.com ã管çè
æš©éãæã€ãã®ããã«å®çŸ©ã§ããŸãã ãã®é
ç®ã§ã¯äžèšã®ãã㪠IAM ããªã·ãŒã®èšå®ã宿œããŸããIAM ããªã·ãŒãªã©ã®æŠå¿µã«ã€ããŠã¯ã以äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp 宿œå
容 çµç¹ã¬ãã«ã® IAM ããªã·ãŒèšå® ãã©ã«ãã¬ãã«ã® IAM ããªã·ãŒèšå® ãããžã§ã¯ãã¬ãã«ã® IAM ããªã·ãŒèšå® ãããã¯ãŒãã³ã° VPC ãããã¯ãŒã¯ãCloud VPNãCloud NATãVPC ãã¡ã€ã¢ãŠã©ãŒã«çãäž»ã«ãããã¯ãŒã¯ã«é¢é£ããåæèšå®ãè¡ãé
ç®ã§ãã ããã«ã¯èšå®ãäžèŠãªé
ç®ãããã¯ãã§ãã®ã§ãå¿
èŠã«å¿ããŠäœæ¥ãè¡ã£ãŠãã ããã 宿œå
容 VPC èšå® å
±æ VPC èšå® IPSec VPN èšå® Cloud NAT èšå® ãã¡ã€ã¢ãŠã©ãŒã«èšå® Cloud Load Balancing èšå® Google Cloud ã®ãããã¯ãŒã¯ã®åºæ¬çãªç¥èã«ã€ããŠã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp ã¢ãã¿ãªã³ã°ãšãã®ã³ã° ãã®é
ç®ã§ã¯ã¢ãã¿ãªã³ã°ãšãã®ã³ã°ã®èšå®ãè¡ããŸããã¢ãã¿ãªã³ã°ã¯ Cloud Monitoringããã®ã³ã°ã«ã¯ Cloud Logging ãå©çšããŸãã Cloud Monitoring 㯠Google Cloud ãµãŒãã¹ããããã©ãŒãã³ã¹ææšãååŸãä¿ç®¡ãé²èЧãããµãŒãã¹ã§ãããã®é
ç®ã§ã¯ãã¢ãã¿ãªã³ã°çšã®ãããžã§ã¯ããäœæãããã®ãããžã§ã¯ãã§ããã©ãŒãã³ã¹ææšãäžæ¬ç®¡çããããã«ãä»ã®ãããžã§ã¯ããç»é²ããããã®èšå®ãè¡ããŸãã Cloud Logging 㯠Google Cloud ãµãŒãã¹ãããã°ãåéãä¿ç®¡ãé²èЧãããµãŒãã¹ã§ãããã®é
ç®ã§ã¯ããã°éçŽçšã®ãããžã§ã¯ããäœæããè€æ°ã®ãããžã§ã¯ãããååŸããããã°ããã®ã³ã°çšãããžã§ã¯ãã® BigQuery ã«äžæ¬åéããèšå®ãè¡ããŸãã 宿œå
容 ã¢ãã¿ãªã³ã°ã®èšå® ãã®ã³ã°ã®èšå® Cloud Monitoring ã Cloud Logging ã«ã€ããŠã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp blog.g-gen.co.jp ã»ãã¥ãªã㣠ãããžã§ã¯ãã®ä¿è·ã«åœ¹ç«ã€ã»ãã¥ãªãã£èšå®ãè¡ããŸãã Security Command Center ãšã¯ãGoogle Cloud ãµãŒãã¹ã®æ§æãã¹ãè匱ãªèšå®ããªãããã§ãã¯ããè
åšæ€åºãµãŒãã¹ã§ããã¹ã¿ã³ããŒããã£ã¢ã¯ç¡æã§å©çšã§ããŸãã çµç¹ããªã·ãŒ ã¯ãçµç¹å
ã§å©çšå¯èœãªãµãŒãã¹ã宿œå¯èœãªæäœãé©çšå¯èœãªèšå®ãªã©ãå¶éãã匷å¶çãªã«ãŒã«ãå®çŸ©ã§ããä»çµã¿ã§ããäŸãã°ãç¹å®ã®ãªãŒãžã§ã³ä»¥å€ã®äœ¿çšãå¶éããããšããå©çšå¯èœãª Google Cloud APIs ãå¶éããããšãå¯èœã§ãã 宿œå
容 Security Command Center ã®èšå® çµç¹ããªã·ãŒã®èšå® Security Command Center ãçµç¹ããªã·ãŒã«ã€ããŠã®è©³çްã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp blog.g-gen.co.jp ãµããŒãïŒã«ã¹ã¿ããŒã±ã¢ïŒ é害æçã«åããŠãå
¬åŒã®æè¡ãµããŒããå©çšããããšæãããšãããã¯ãã§ããGoogle Cloud ã«ã¯ ã«ã¹ã¿ããŒã±ã¢ ãšåŒã°ãããµããŒããµãŒãã¹ããããç¡åã®ãã©ã³ãšæåã®ãã©ã³ããããŸãã ç¡åãã©ã³ïŒããŒã·ãã¯ïŒã®å Žåã課éã«é¢ãã質åã®ã¿ãåãåãããããšãã§ããŸããæè¡çãªè³ªåãå¯èœãªæåãã©ã³ã«ã¯è€æ°ããããã©ã³ã«ãã£ãŠæ¥æ¬èªå¯Ÿå¿ã®æç¡ããåçæéã®å·®ç°ããããŸãã 宿œå
容 ã«ã¹ã¿ããŒã±ã¢ã®ç³ã蟌㿠ãã®ãšãã«ã¹ã¿ããŒã±ã¢ãç³ã蟌ãæäœè
ã¯ãçµç¹ã¬ãã«ã§ãçµç¹ã®ç®¡çè
ïŒ roles/resourcemanager.organizationAdmin ïŒããŒã«ããšããµããŒã ã¢ã«ãŠã³ã管çè
ïŒ roles/cloudsupport.admin ïŒããŒã«ããå¿
èŠã§ããããã«ãè«æ±å
ã¢ã«ãŠã³ãã«å¯Ÿãããè«æ±å
ã¢ã«ãŠã³ã管çè
ïŒ roles/billing.admin ïŒããŒã«ããªã©ãå¿
èŠã§ãã ã«ã¹ã¿ããŒã±ã¢ã®ãã©ã³ã«ã€ããŠã¯ã以äžã®å
¬åŒããŒãžãåç
§ããŠãã ããã åè : Google Cloud ã«ã¹ã¿ããŒã±ã¢ å°æ ããã¿ (èšäºäžèЧ) ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš å¶æ¥ããŒã AWSãšã³ãžãã¢ããGoogle Cloudå¶æ¥ã«è»¢å çŠäºãããªã¢ãŒãã¯ãŒã¯äž è¶£å³ã¯Monkey125ã§ããŒãªã³ã°ãNetflixéè³ãæ
è¡
G-gen ã®ææã§ãã Google Cloud Next '21 ã® What's new with BigQuery ã»ãã·ã§ã³ã§çºè¡šãããæ°æ©èœããéå ±ãšããŠã玹ä»ããŸãã BigQuery ã¯ããã« BigQuery Omni (GA) BigQuery Security & Governance for Data Lakes (Coming soon) BigQuery External Functions Analytics Hub (Preview) BigQuery Migration Service (Preview) BigQuery 管çç³»æ©èœ Admin hub & Resource charts (GA) Slot estimator (Preview) BigQuery Slots Autoscaling (Coming soon) Table Snaphosts and Clones BigQuery Storage Write API (GA) Search Indexes with BigQuery (Preview) BigQuery ML é¢é£ Explainable AI Integration with Vertex (Coming soon) Advanced Models & Techniques BigQuery BI Engine (GA) ã¯ããã« 2021幎10æ12æ¥ããã14æ¥ã®æ¥çšã§ Google Cloud Next '21 ãéå¬ãããŠããŸãã What's new with BigQuery ãšããã»ãã·ã§ã³ã®äžã§ã Google Cloud ã®ããŒã¿ãŠã§ã¢ããŠã¹ãµãŒãã¹ã§ãã BigQuery ã®æ°æ©èœã®æ°ã
ãçºè¡šãããŸããã ç¹ã« BigQuery Migration Service ãšããç§»è¡ã«æŽ»çšã§ããæ©èœãã Table Snaphosts and Clones , Search Indexes with BigQuery ãšãã£ã BigQuery ã®ãŠãŒã¹ã±ãŒã¹ãå€ããŠããŸãå¯èœæ§ããããæ©èœã¯æ³šç®ã§ãã æ¬æçš¿ã§ã¯ãåœè©²ã»ãã·ã§ã³ã§çºè¡šãããæ°æ©èœãã玹ä»ããŸãããªãèšèŒã®å
容㯠ã»ãã·ã§ã³ã®çºè¡šããã£ã 2021幎10æ13æ¥çŸåšã®å
容ãšãªã£ãŠãããŸã ã ãªãªãŒã¹ç¶æ
ãæ©èœã®å
容ã¯åžžã«å€åããŠãããŸãã®ã§ãæ¬æçš¿ã¯ãããŸã§éå ±èšäºã§ããããšããçè§£ãã ããã BigQuery Omni (GA) AWS, Azure, Google ã«åæ£ãããŠããããŒã¿ãSQLã§æšªæã¯ãšãªã§ããæ©èœã Google Cloud (GCP) äžã®ãããŸã§ãšåã BigQuery ã®ã€ã³ã¿ãŒãã§ãŒã¹ã§ãGoogle Cloud ã AWSãAzure ã«ä¿åããããŒã¿ããã¯ã©ãŠãéãç§»åãããã³ããŒãããããããšãªãã¯ãšãªãå¯èœãšãªãã Anthos ã®æè¡ãããã¯ãšã³ããšããŠäœ¿ããäŸãã° AWS äžã§ BigQuery ã®ã¯ãšãªãšã³ãžã³ã皌åãã Amazon S3 çã«ä¿åãããŠããããŒã¿ã«ã¯ãšãªãå®è¡ããã åè: BigQuery Omni - ãã«ãã¯ã©ãŠã ã®åæã§ããŒã¿ãæŽ»çš BigQuery Security & Governance for Data Lakes (Coming soon) BigQuery ã§ã¯ Cloud Storage ã Spanner ãªã© BigQuery ã®å€éšã«ååšããããŒã¿ãå€éšããŒãã«ãšããŠå®çŸ©ããããšãã§ãããããã®å€éšããŒãã«ã«å¯Ÿããæš©éèšå®ããã现ããã§ããããã«ãªãæš¡æ§ã ããŒã¿ã¬ã€ã¯ã®ã»ãã¥ãªãã£åäžãèŠèŸŒããã¯ãã ã â»åæ©èœã¯ BigLake ãšã㊠2022/01/25 ã« GA ãšãªããŸããã BigQuery External Functions UDF (ãŠãŒã¶å®çŸ©ã®é¢æ°) ã BigQuery ã®å€éšã§å®çŸ©ã§ããããã«ãªã£ãã ãããŸã§ã BigQuery ã§ã¯ UDF ãå®çŸ©ããããšã¯ã§ããããæšæº SQL ã Javascript ã§èšè¿°ããå¿
èŠãããã颿°ã¯ BigQuery ã®å
éšã«å®çŸ©ãããã ä»åã®ã¢ããããŒãã§ã¯ UDF ã BigQuery ã®å€éšã«å®çŸ©ã§ããããã«ãªãããã®ã©ã³ã¿ã€ã ã«ã¯ãåç¥ Cloud Functions ãå©çšããŠããã®ã§ node.js / Python / Go / Java / .net / PHP ãªã©ã§èšè¿°ã§ããã åè : ãªã¢ãŒã颿°ã®æäœ Analytics Hub (Preview) çµç¹ (Organization) ããŸããã§ããŒã¿ããããšãã§ããä»çµã¿ã Publisher (ããŒã¿å
¬éåŽ) 㯠Analytics Hub ãéããŠããŒã¿ã»ãããå
¬éã§ãã Subscriber (ããŒã¿å©çšè
åŽ) ããããå©çšã§ããã å
¬éããŒã¿ããã¥ã¬ãŒã·ã§ã³ãããæ€çŽ¢ããä»çµã¿ãæäŸãããæš¡æ§ã Publisher ãããŒã¿ã®å©çšç¶æ³ãåæã§ãããããªä»çµã¿ãååšããŠããããã ã åè : Analytics Hub ã®ãçŽ¹ä» -- ç°¡åãå®å
šãã¹ã±ãŒã©ãã«ã«ããŒã¿åæãå
±æ â» Analytics Hub 㯠2022/10/11 ã«GA ãšãªããŸããã BigQuery Migration Service (Preview) ä»ã®ããŒã¿ãŠã§ã¢ããŠã¹è£œåãã BigQuery ãžã®ç§»è¡ãæ¯æŽããããŒã«ã§ããã® Preview ãçºè¡šãããã ãœãŒã¹ DB ãžã®ã¢ã»ã¹ã¡ã³ãã SQL (DDL, DML, BTEQ ã§æžããã PL) ã®å€æã ç§»è¡å
BigQuery ãžã®ããªããŒã·ã§ã³ãè¡ãã Walmart ã Mercado Libre ãªã©ã§æ¢ã« SQL 倿ã«ãããå©çšããå®çžŸããããšããã çŸåšã®ãšããã Teradata ããµããŒã察象ãšãªãããšã倿ããŠããããä»ã®ç§»è¡å
ã Coming soon ãšããŠããã åè : BigQuery Migration Service ã®æŠèŠ BigQuery 管çç³»æ©èœ Admin hub & Resource charts (GA) BigQuery ç°å¢ã®è©³çްãªã¢ãã¿ãªã³ã°ã管çããã©ãã«ã·ã¥ãŒããããã«ããã¯ç¹å®ãªã©ã«æŽ»çšã§ããæ°ãã管çã³ã³ãœãŒã«ã䜿ããããã«ãªã£ãã Slot Reservation (ã³ã³ãã¥ãŒãã£ã³ã°å®¹éã®äºå賌å
¥ãå®é¡ã»å€§å®¹éã§ BigQuery ãå©çšã§ããããã«ãªã) ã䜿çšããŠã¯ãŒã¯ããŒã管çãè¡ã£ãŠãããŠãŒã¶ãŒã«ãšã£ãŠã匷åãªæ©èœãšãªãã ããã Slot estimator (Preview) ãã¡ãã Slot Reservation ã䜿ã£ãŠãããŠãŒã¶ãŒåãã®æ©èœã ã çµç¹å
ã§ãããžã§ã¯ããæšªæããŠã¹ãããã®å©çšç¶æ³ã確èªã§ããä»ãã¹ãããã远å 賌å
¥ãã¹ããã©ããã®å€æã®å©ãã«ãªãæ
å ±ãæäŸããã â» Slot estimator 㯠2022/11/14 ã«GA ãšãªããŸããã BigQuery Slots Autoscaling (Coming soon) äºåã«å®çŸ©ããäºç®ã«åºã¥ããŠã¹ããããèªåã§ã¹ã±ãŒãªã³ã°ããæ©èœã ã åŸæ¥ã®ãªã³ããã³ãã¢ãŒãã ãšãåºæ¬çã«ã¹ããã㯠2,000 ãäžéã§ããããã¹ããšãã©ãŒãã§ã®ããŒã¹ããæåŸ
ããããšãã§ããã åœè©²æ©èœããªãªãŒã¹ãããã°ãããçšåºŠã®äºæž¬ãé£ããã¯ãŒã¯ããŒãã§ãã³ã¹ãã®ç¡é§ãã·ã§é«ãããã©ãŒãã³ã¹ãç¶æã§ããã ããã â»åœæ©èœã¯ BigQuery Editions ã®äžæ©èœãšã㊠2023/03/29 ã«GA ãšãªããŸããã Table Snaphosts and Clones BigQuery ã§ã®ããŒã¿ã®æã¡æ¹ã倧ããå€ãããããããªãæ©èœãçºè¡šãããã Snapshots (ã¹ãããã·ã§ãã) ã¯èªã¿åãå°çšã®ããŒã¿ã³ããŒã§ãããè«çããã¯ã¢ããç®çãã¿ã€ã ãã©ãã«æ©èœ (7æ¥éããä¿æãããªã) 以äžã®ä¿ææéã§ç¹å®æå»ã®ããŒãã«ç¶æ
ãä¿æãããå Žåã«å©çšã§ããããããããŒã¿ã¯ããªãªãžãã«ããŒãã«ããå³åº§ã«ã³ããŒããã®ã§ã¯ãªããåºæ¬çã«ã¯ãªãªãžãã«ããŒãã«ãåç
§ãããŸãŸã倿Žãåé€ãããå Žåã®ã¿ããŒã¿ãè€è£œããã (ããããã³ããŒã»ãªã³ã»ã©ã€ã) ã®ããã³ã¹ããæããããšãå¯èœã ã â» Snapshot æ©èœã¯ 2021/10/28 ã« GA ãšãªããŸããã Clone (ã¯ããŒã³) 㯠Snapshots ã®ããŒã¿å€æŽãå¯èœãªããŒãžã§ã³ãšèããã°ããã ãããåããã³ããŒã»ãªã³ã»ã©ã€ãã§ããŒãã«ã®ã¯ããŒã³ãäœæãããçºè¡šã§ã¯ã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿãã倿Žããã¹ãããç°å¢ãšããŠå©çšãããŠãŒã¹ã±ãŒã¹ãæããããã â» Clone æ©èœã¯ 2022/02/15 ã« Preview å
¬é ããããã®åŸ 2023/05/03 ã« GA ãšãªããŸããã BigQuery Storage Write API (GA) BigQuery ã®ã¹ãã¬ãŒãžã«çŽæ¥ API ãçºè¡ããé«ã¹ã«ãŒãããã§ã®ããŒã¿ã®æžã蟌ã¿çãå¯èœã«ãªãã è²»çšãéåžžã® INSERT ããäœãæŒãããããããã倧éããŒã¿ã®æå
¥ã§ã¯æ€èšãã¹ãéžæè¢ã ã åè : BigQuery Storage Write API ã®äœ¿çš Search Indexes with BigQuery (Preview) ãªããšã BigQuery ã§ã€ã³ããã¯ã¹ã䜿ããããã«ãªã£ã ( Preview å
¬éã®äºå®ã®çºè¡šã§ãã 2022 幎 1 æçŸåšã§ãŸã å©çšå¯èœã«ãªã£ãŠããªã â 2022/04/07 ã« Preview å
¬éãã 2022/10/27 ã« GA ãšãªã£ã) ã 2022/04/11 æŽæ° : 以äžã®åœããã°èšäºã«ãŠè©³çްã解説ããŠããã blog.g-gen.co.jp åŸæ¥ã§ã¯ BigQuery ã«ãããŠã¯ã€ã³ããã¯ã¹ã¯äœ¿ããªãã£ããããã BigQuery ã®ã¡ã³ããã³ã¹å·¥æ°ãæžããå©ç¹ã§ããã£ãã ãšã¯ãããã㯠BigQuery ãããŒãã«åäœã»ããŒãã£ã·ã§ã³åäœã§ã®ãã«ã¹ãã£ã³ãè¡ãããšãæå³ããŠãããæ°ãã¿ãã€ãã«ããã¶ããŒã¿ã®äžããç¹å®ã®ããŒã§ããŒã¿ãæãåºããããªã¯ãŒã¯ããŒãã«å¯ŸããŠå€§éã®ã¹ãã£ã³ãçºçããŠããŸããããééçã»æéçã³ã¹ããããã£ãŠããŸãããšãæå³ããŠããã æ¬æ©èœã§ã¯ããŒãã«ã«ããã¹ãã€ã³ããã¯ã¹ãäœæããç¹å®ã®æååãæ€çŽ¢ããæ§èœãåäžãããããšãã§ããã ã€ã³ããã¯ã¹ã¯èªåçã«æŽæ°ãããããããããã VACUUM ã®ãããªã¡ã³ããã³ã¹ã¯äŸç¶ãšããŠäžèŠã ã åãããã¬ãã¥ãŒçºè¡šããããã€ãã£ãJSONã¿ã€ãã«ã䜿çšã§ããã 以äžã®ãããªãŠãŒã¹ã±ãŒã¹ãæããããã éžæç¯å²ãéåžžã«çããã£ã«ã¿ã䜿ã£ãããã·ã¥ããŒã (ã¹ã©ã€ã·ã³ã°/ãã€ã·ã³ã°ãå¿
èŠ) ç®çãšãªãããŒã¿ã®ãµãã»ããã倧ããªããŒã¿ã»ããããèŠã€ãåºã (ç¹å®ã®æ
å ±ãæã£ãæ£è
矀ãæãåºã) GDPRæºæ ã®ããç¹å®ãŠãŒã¶ã®ããŒã¿ã ããæãåºããŠåé€ãã ãã°ããç¹å® IP ã¢ãã¬ã¹ãæãåºã BigQuery ML é¢é£ Explainable AI AI/ML é¢é£ã§ãã話é¡ã«ãªãã説æå¯èœãªAIããå®çŸããããã®æ©èœã ã åŠç¿ããŒã¿ã®ãã¡ã©ã®ãããªèŠçŽ ãçµæã«åœ±é¿ããã®ããçè§£ããããšãå©ããã Integration with Vertex (Coming soon) BigQuery ML ã Vertex AI ãšé£æºããã Vertex AI ã®ãã€ãã©ã€ã³ãšé£æºããããšã§ BigQuery ML ã®ã¢ãã«ã®åŠç¿ããããã€ã匷åãããæš¡æ§ã ã Advanced Models & Techniques XGBoost, Wide & Deep DNN (ãã£ãŒããã¥ãŒã©ã«ãããã¯ãŒã¯), AutoML Tables ãªã©ããµããŒãããã匷åãããã BigQuery BI Engine (GA) ãã¬ãã¥ãŒçã§çšæãããŠããæ©èœã GA ãšãªã£ãã ããŒã¿ããŒã¿ã«çã® BI ããŒã«ããå©çšå¯èœãªãã£ãã·ã¥æ©æ§ã§ãå©çšã«ã¯è¿œå æéãçºçããã ã€ã³ã¡ã¢ãªãã£ãã·ã¥æ©æ§ã§ãããæå¹åããã ãã§å¹æãçºæ®ããã åè : BI Engine ãšã¯ ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãTwitter ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it