G-genã®èäºã§ããåœèšäºã§ã¯ Google Cloud èªå®è³æ Œ ã®äžèЧããå詊éšã®æŠèŠãã玹ä»ããŸããGoogle Cloud ãä»äºã§åãæ±ãæ¹ããèå³ããã£ãŠèª¿ã¹ãŠããæ¹åãã«è³æ Œã®æŠèŠãã玹ä»ããŸãã®ã§ãã©ããªè³æ Œãèªåã«å¿
èŠãèŠå®ããŠè³æ ŒååŸãç®æããŠããã ããã°ãšæããŸãã ã¯ããã« Google Cloud èªå®è³æ Œãšã¯ è³æ Œã®çš®é¡ èªå®è³æ Œã®ã¡ãªãã ã«ãŒã«ã»åéšæ¹æ³ èšèªã»è©Šéšæéã»æé åéšå Žæ æå¹æéãšåèªå® è³æ ŒååŸã®é çª åè©Šéš Google Cloud èªå®è³æ Œã®è©³çް Foundational ã¬ãã« Cloud Digital Leader Generative AI Leader Associate ã¬ãã« Associate Cloud Engineer Associate Google Workspace Administrator Associate Data Practitioner Professional ã¬ãã« Professional Cloud Architect Professional Cloud Database Engineer Professional Cloud Developer Professional Data Engineer Professional Cloud DevOps Engineer Professional Cloud Security Engineer Professional Cloud Network Engineer Professional Machine Learning Engineer Professional Security Operations Engineer çªå€ç·š Professional ChromeOS Administrator 廿¢ãããè©Šéš Looker LookML Developer Looker Business Analyst Professional Google Workspace Administrator ã¯ããã« Google Cloud èªå®è³æ Œãšã¯ Google Cloud èªå®è³æ Œãšã¯ãGoogle Cloud ã«é¢ããå
¬åŒã®èªå®è³æ Œã§ããGoogle Cloud ã«é¢ããç¥èãã¹ãã«ãè©äŸ¡ãããŸãã 2025幎11æçŸåšãGoogle Cloud èªå®è³æ Œã¯ 14å ãããŸãããã¯ãããžãŒåéããšã«è³æ ŒãçšæãããŠãããããè³æ ŒãååŸããããšã§ãã®åéã«ãããç¥èã»ã¹ãã«ãä¿æããŠããããšã蚌æã§ããŸãã 以äžã¯ãGoogle Cloud èªå®è³æ Œã®å
¬åŒæ¡å
ããŒãžãšã詳现ãªãã«ãããã¥ã¡ã³ãã§ããæ¥æ¬èªã®ããŒãžã¯ææ°æ
å ±ã«æŽæ°ãããŠããªãå ŽåããããŸãã®ã§ãææ°æ
å ±ãåŸãããã«ã¯ãããŒãžæäžéšå³åŽã®ã»ã¬ã¯ã¿ã§è±èªçã«åãæ¿ããŠãã ããã åè : èªå®è³æ Œ | Google Cloud åè : Google Cloud èªå®è³æ Œ ãã«ã è³æ Œã®çš®é¡ Google Cloud èªå®è³æ Œã«ã¯ãã©ã®ãããªãã®ãããã確èªããŠã¿ãŸãããã Google Cloud èªå®è³æ Œã¯ãFoundationalïŒåºç€ïŒãAssociateïŒã¢ãœã·ãšã€ãïŒãProfessionalïŒãããã§ãã·ã§ãã«ïŒã®3段éã«å¥ããŠããŸãã Foundational ã¬ãã« Associate ã¬ãã« Professional ã¬ãã« Foundational ã¬ãã« Cloud Digital Leader Generative AI Leader Associate ã¬ãã« Associate Cloud Engineer Associate Google Workspace Administrator Associate Data Practitioner Professional ã¬ãã« Professional Cloud Architect Professional Cloud Database Engineer Professional Cloud Developer Professional Data Engineer Professional Cloud DevOps Engineer Professional Cloud Security Engineer Professional Cloud Network Engineer Professional Machine Learning Engineer Professional Security Operations Engineer èªå®è³æ Œã®ã¡ãªãã Google Cloud èªå®è³æ ŒãååŸãããšã以äžã®ãããªã¡ãªããããããŸãããã¡ããäžçªã¯èªèº«ã®ç¥èã»ã¹ãã«åäžã§ããããã®ä»ã«ãããããã®ç¹å
žããããŸãïŒ åŠç¿ã® ãã£ãã ã«ãªã ç¥è㮠客芳ç ãªèšŒæã«ãªã Google Cloud Next ãªã©ã®ã€ãã³ãã§ æè³æ Œè
ç¹å
ž ãåŸããã Google ã® éå®ã°ã㺠ãæã«å
¥ã ã«ãŒã«ã»åéšæ¹æ³ èšèªã»è©Šéšæéã»æé â» åéšæã®èšèŒã¯çšå¥ã§ã è³æ Œå è©Šéšæé åéšæ èšèª Cloud Digital Leader 90å $99 æ¥æ¬èª/è±èª/ã¹ãã€ã³èª/ãã«ãã¬ã«èª/ãã©ã³ã¹èª Generative AI Leader 90å $99 æ¥æ¬èª/è±èª Associate Cloud Engineer 2æé $125 æ¥æ¬èª/è±èª/ã¹ãã€ã³èª/ãã«ãã¬ã«èª Associate Google Workspace Administrator 2æé $125 æ¥æ¬èª/è±èª Associate Data Practitioner 2æé $125 æ¥æ¬èª/è±èª Professional Cloud Architect 2æé $200 æ¥æ¬èª/è±èª Professional Cloud Database Engineer 2æé $200 æ¥æ¬èª/è±èª Professional Cloud Developer 2æé $200 æ¥æ¬èª/è±èª Professional Data Engineer 2æé $200 æ¥æ¬èª/è±èª Professional Cloud DevOps Engineer 2æé $200 æ¥æ¬èª/è±èª Professional Cloud Security Engineer 2æé $200 æ¥æ¬èª/è±èª Professional Cloud Network Engineer 2æé $200 æ¥æ¬èª/è±èª Professional Machine Learning Engineer 2æé $200 æ¥æ¬èª/è±èª Professional Security Operations Engineer 2æé $200 æ¥æ¬èª/è±èª åéšå Žæ Google Cloud èªå®è³æ Œã¯ããã¹ãã»ã³ã¿ãŒã§ã®çŸå°åéšã®ã»ãããªã³ã©ã€ã³ã§ã®åéšãå¯èœã§ãã ãã¹ãã»ã³ã¿ãŒã§ã®çŸå°åéšã®å Žåãæ¥æ¬å
šåœã«ææºè©ŠéšäŒå ŽïŒãã¹ãã»ã³ã¿ãŒïŒããããäŒå Žã«èšçœ®ãããããœã³ã³ã䜿ã£ãŠåéšããŸãã çŠå²¡çè¿èŸºã®æ¹åãã§ããããã¹ãã»ã³ã¿ãŒãžã®è¡ãæ¹ã«ã€ããŠã®èšäºãåèã«ããŠãã ããã åè : ãGoogle Cloudèªå®è©ŠéšãçŠå²¡äŒå Žãžã®è¡ãæ¹ - G-gen Tech Blog ãªã³ã©ã€ã³ã§ã®åéšã«ã€ããŠã¯ãåœç€Ÿã®ã¡ã³ããŒã«ããèšäºãåèã«ããŠãã ããã åè : Google Cloud èªå®è³æ Œãªã³ã©ã€ã³åéšã®æºåãšæ³šæç¹ - G-gen Tech Blog åè : 3ã¶æåãŸã§Google Cloud(æ§GCP)ã®çŽ äººã ã£ãç§ãGoogle Cloudã®è©Šéšãé é(ãªã³ã©ã€ã³)ã§åéšãã話 - G-gen Tech Blog æå¹æéãšåèªå® Google Cloud èªå®è³æ Œã«ã¯ãæå¹æéãèšå®ãããŠããŸãã Foundational ã¬ãã«ãš Associate ã¬ãã«ã®è©Šéšã®æå¹æé㯠3幎é ãProfessional ã¬ãã«ã®è©Šéšã®æå¹æé㯠2幎é ã§ãã Foundational ã¬ãã«ãš Associate ã¬ãã«ã®è©Šéšã§ã¯ãæå¹æéæ¥ã® 180 æ¥å以éã«å床ã詊éšã«åæ Œããããšã§ãè³æ ŒãæŽæ°ããïŒåèªå®ãããïŒããšãã§ããŸããProfessional ã¬ãã«ã®è©Šéšã§ã¯ã60æ¥å以éã«ååºŠåæ Œããå¿
èŠããããŸãã åè : Google Cloud èªå®è³æ Œè©Šéšã®ããªã·ãŒãšè©Šéšã®å©çšèŠçŽ ãŸããAssociate Cloud Engineer ãš Professional Cloud Architect ã®ã¿ã æŽæ°è©Šéš ãçšæãããŠããŸããæŽæ°è©Šéšã¯æšæºè©Šéšããå顿°ãåéšè²»çšãè©Šéšæéãªã©ãäœãèšå®ãããŠãããå°ããè² æ
ã§è³æ ŒãæŽæ°ããããšãã§ããŸãã è³æ ŒååŸã®é çª Google Cloud èªå®è³æ Œã§ã¯ãAã®è³æ ŒãååŸããªããšãBã®è³æ ŒãååŸã§ããªãããšãã£ããããªè³æ ŒååŸã®é çªæå®ã¯ãããŸããããããªã Professional ã¬ãã«ã®è©ŠéšãåéšããŠãæ§ããŸããã ãšã¯ããã Google Cloud ã®ç¥èãé åœã«èº«ã«ã€ããŠããããã«ã¯ãããããã®é çªããããŸãã ãšã³ãžãã¢ã§ããã°ã Cloud Digital Leader ããã㯠Associate Cloud Engineer ããå§ããã®ãæšå¥šãããŸããCloud Digital Leader â Associate Cloud Engineer â Professional Cloud Architect â ãã®ä»ã® Professional 詊éšããšããé çªã§åéšããããšã§ãé ã远ã£ãŠ Google Cloud 掻çšã®ç¥èŠã身ã«ã€ããããŸãã äžæ¹ããšã³ãžãã¢ãšããŠã§ã¯ãªãã çµå¶ç®ç·ãããã¯ãªãã£ã¹ç®ç· ã§ Google Cloud ãæããå¿
èŠã®ããæ¹ã¯ã Cloud Digital Leader ã«ææŠ ããããšãæãŸããã§ãããã åè©Šéš ããGoogle Cloud èªå®è©Šéšã«äžåæ Œãšãªã£ãŠããŸã£ãããå詊éšããªã·ãŒã«åã£ãŠå床åéšããããšãã§ããŸãã Cloud Digital Leader 詊éšã¯ã1幎éã«10åãŸã§åéšã§ããŸãããã詊éšã«äžåæ Œãšãªã£ãå ŽåãååéšãŸã§14æ¥ã®ã€ã³ã¿ãŒãã«ã空ããå¿
èŠããããŸãã Associate ã¬ãã«ãš Professional ã¬ãã«ã®è©Šéšã«ã¯ã以äžã®ããã«ã€ã³ã¿ãŒãã«ãèšå®ãããŠããŸãã åéšåæ° ååéšãŸã§ã®ã€ã³ã¿ãŒãã« 1å 2åç®ã®å詊éšãŸã§ã«14æ¥éã®ã€ã³ã¿ãŒãã«ãå¿
èŠ 2å 3åç®ã®å詊éšãŸã§ã«60æ¥éã®ã€ã³ã¿ãŒãã«ãå¿
èŠ 3å 4åç®ã®å詊éšãŸã§ã«365æ¥éã®ã€ã³ã¿ãŒãã«ãå¿
èŠ Associate ã¬ãã«ãš Professional ã¬ãã«ã®è©Šéšã®å Žåãåéšåæ°ã¯2幎éã§æå€§4åãŸã§ããšããå¶éããããŸããåéšããªã³ãµã€ãããªã³ã©ã€ã³ãã«ããããããåéšåæ°ã«ã«ãŠã³ããããŸãã åè : ååéšããªã·ãŒ Google Cloud èªå®è³æ Œã®è©³çް Foundational ã¬ãã« Cloud Digital Leader Cloud Digital Leader 詊éšã¯ãGoogle Cloud ã«é¢ããæãåºç€çãªè³æ Œã§ããæšå¥šã®å®åçµéšæéãªã©ã¯ãããŸããã Google Cloud ãçè§£ããããã®æåã®ã¹ããããšããŠæé©ãªè³æ Œã§ããã ãšã³ãžãã¢ã§ãªãæ¹ãååŸãç®æã ãŸãã 以äžã®èšäºã§ãé£æåºŠã詊éšå¯Ÿçæ¹æ³ã«ã€ããŠè©³çްã«è§£èª¬ããŠããŸãã®ã§ããã²ãåç
§ãã ããã blog.g-gen.co.jp ãŸãã以äžã¯ G-gen 瀟ã®ã»ãŒã«ã¹ã¡ã³ããŒãåœè©Šéšãåéšããäœéšèšã§ããéãšã³ãžãã¢ãåœè©Šéšãå匷ããããã®ãã³ãã«ããŠãã ããã blog.g-gen.co.jp G-gen ã®ãšã³ãžãã¢ãå·çããæžç±ãåæ Œå¯Ÿç Google Cloudèªå®è³æ ŒCloud Digital Leader ããã¹ãïŒæŒç¿åé¡ãã¯ãCloud Digital Leader 詊éšã®åèæžã§ãããã¡ãããåèã«ããŠãã ããã åæ Œå¯Ÿç Google Cloudèªå®è³æ ŒCloud Digital Leader ããã¹ãïŒæŒç¿åé¡ äœè
: ææ å銬 , åå äœæš¹ ãªãã¯ãã¬ã³ã Amazon Generative AI Leader Generative AI Leader 詊éšã¯ã çæ AI ã«é¢ããåºç€çãªç¥è ãã Google Cloud ã Google Workspace ã®çæ AI é¢é£ãµãŒãã¹ã»æ©èœã®ç¥è ãåãããŸããéæè¡ç³»ã®ããžãã¹ããŒãœã³ã察象ãšããŠãã詊éšã§ããåœè©Šéšã¯ã2025幎5æ14æ¥ïŒç±³åœæéïŒã«äžè¬å
¬éãããŸããã ãã®è©ŠéšååŸã«åããŠãGoogle ã¯ç¡æã®ãªã³ã©ã€ã³ãã¬ãŒãã³ã°ã³ãŒã¹ãæäŸããŠããŸããåœè©Šéšã®åæ Œã«åããŠæçšãªã»ããããžãã¹ã«ãããçæ AI 掻çšã®ããã«éèŠãªç¥èãåŠã¶ããšãã§ããŸãã 詊éšå¯Ÿçæ¹æ³ã«ã€ããŠã¯ã以äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp Associate ã¬ãã« Associate Cloud Engineer Associate Cloud Engineer 詊éšã§ã¯ãGoogle Cloud ã®åºç€ã¹ãã«ãè©äŸ¡ãããŸãã ã¯ã©ãŠããšã³ãžãã¢ã®åºçºç¹ ãšãªãè³æ Œã§ãã å
¬åŒã¬ã€ãã«ã¯ãGoogle Cloud ã§ã®æ§ç¯çµéš 6 ãæä»¥äžãæšå¥šããšèšèŒãããŠããŸãããå¿
ããããããæºãããŠããªããŠããã£ã¬ã³ãžã§ããè³æ Œã§ãã 詊éšå¯Ÿçæ¹æ³ã¯ä»¥äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp G-gen ã®ãšã³ãžãã¢ãã詊éšå¯Ÿçæžç±ã§ãããåæ Œå¯Ÿç Google Cloudèªå®è³æ ŒAssociate Cloud Engineer ããã¹ãïŒæŒç¿åé¡ ããå·çããŠããŸãããã¡ããåŠç¿ã«ããããåç
§ãã ããã åæ Œå¯Ÿç Google Cloudèªå®è³æ ŒAssociate Cloud Engineer ããã¹ãïŒæŒç¿åé¡ äœè
: ææ å銬 , äœã
æš é§¿å€ª , è€å²¡ éçŸ ãªãã¯ãã¬ã³ã Amazon Associate Google Workspace Administrator Associate Google Workspace Administrator 詊éšã¯ãGoogle Workspace ã®åºç€çãªç®¡çæ¥åã«é¢ããã¹ãã«ãè©äŸ¡ãããŸããäŒæ¥ã®æ
å ±ã·ã¹ãã éšå¡ãªã©ã«ããããã®è³æ Œã§ãã2024幎10ææ«ã« Beta çãšããŠå
¬éããã2025幎1æã« GAïŒäžè¬å
¬éïŒãããŸããã åºæ¬æ
å ±æè¡è
詊éšã¬ãã«ã® IT åºç€ç¥èïŒDNSãE ã¡ãŒã«åºç€ãç¹æš©ç®¡çãªã©ïŒã«å ããŠãGoogle Workspace ã®ç®¡çç»é¢ã«æ¥åžžçã«è§ŠããŠããæ¹ã§ããã°ã远å ã®åŠç¿ãæ°æ¥ã1ã¶æçšåºŠè¡ãããšã§ååã«åæ ŒãçããŸãã 詊éšå¯Ÿçæ¹æ³ã¯ä»¥äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp Associate Data Practitioner Associate Data Practitioner 詊éšã¯ãGoogle Cloud äžã®ããŒã¿ã®ä¿è·ã管çã®ããã®ã¹ãã«ãè©äŸ¡ããã詊éšã§ããããŒã¿ãã€ãã©ã€ã³ã®ç®¡çãåæãå¯èŠåãæ©æ¢°åŠç¿ãªã©ã®ã¿ã¹ã¯ã Google Cloud äžã§è¡ã£ãçµéšãåãããŸãã2024幎10ææ«ã« Beta çãšããŠå
¬éããã2025幎1æã« GAïŒäžè¬å
¬éïŒãããŸããã Google Cloud äžã§ã®ããŒã¿åã蟌ã¿ã倿ããã€ãã©ã€ã³ç®¡çãåæãæ©æ¢°åŠç¿ãããã³å¯èŠåçã«é¢ããç¥èãæèœãåãããŸãã 詊éšå¯Ÿçæ¹æ³ã¯ä»¥äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp Professional ã¬ãã« Professional Cloud Architect Professional Cloud Architect 詊éšã¯ãGoogle Cloud ãé¢é£ãã¯ãããžãŒã«é¢ãããèšèšãå®è£
ã管çã«å¿
èŠãªé«åºŠãªã¹ãã«ãä¿æããŠããããšã瀺ãè³æ Œã§ãã IT ã€ã³ãã©ãšã¢ããªã±ãŒã·ã§ã³éçºã«å¯Ÿããããã©ã³ã¹ã®åããç¥è ãæ±ããããŸãã 詊éšå¯Ÿçæ¹æ³ã¯ä»¥äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp Professional Cloud Database Engineer Professional Cloud Database Engineer 詊éšã¯ãGoogle Cloud ã«ããã ããŒã¿ããŒã¹ç³»ãµãŒãã¹ã®ç¥èŠ ãåã詊éšã§ããProfessional Data Engineer 詊éšãããŒã¿ãšã³ãžãã¢ãªã³ã°ã«é¢ããç¥èãåã詊éšã§ããã®ã«å¯Ÿããåœè©Šéšã¯éçšããŒã¿ããŒã¹ã«é¢ããç¥èãåããŸãã ã¢ããªã±ãŒã·ã§ã³ããã®ããŒã¿ãžã®ã¢ã¯ã»ã¹ãŠãŒã¹ã±ãŒã¹ã«å¿ããŠé©åãªããŒã¿ããŒã¹ãµãŒãã¹ãéžå®ã»èšèšãã管çã»ãã©ãã«ã·ã¥ãŒãã£ã³ã°ãªã©ãè¡ãããšãã§ããããšã瀺ãè³æ Œã§ãã Cloud SQLãFirestoreãBigtableãSpanner çã«é¢ããç¥èŠãæ±ããããŸããå察㫠BigQuery ãªã©åæç³»ããŒã¿ããŒã¹ã«é¢ããåºé¡ã¯ãããŸããã 詊éšå¯Ÿçæ¹æ³ã¯ä»¥äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp Professional Cloud Developer Professional Cloud Developer 詊éšã¯ãGoogle æšå¥šã®ææ³ãçè§£ããŠãã¹ã±ãŒã©ãã«ã§é«å¯çšãª ã¢ããªã±ãŒã·ã§ã³ãéçº ã§ãããšã³ãžãã¢ã§ããããšã瀺ãè³æ Œã§ãã ã¯ã©ãŠããã€ãã£ããªã¢ããªãéçºè
ããŒã«ããããŒãžããµãŒãã¹ã次äžä»£ããŒã¿ããŒã¹ã®äœ¿çšçµéšãæ±ããããŸãã 詊éšå¯Ÿçæ¹æ³ã¯ä»¥äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp Professional Data Engineer Professional Data Engineer 詊éšã¯ãããŒã¿ã®åéã倿ãå¯èŠåãªã©ã ããŒã¿ãšã³ãžãã¢ãªã³ã°ã«é¢ããæèœ ãæã€ãšã³ãžãã¢ã§ããããšã瀺ãè³æ Œã§ãã ããŒã¿åŠçã·ã¹ãã ã®èšèšãæ§ç¯ãéçšãã»ãã¥ãªãã£ä¿è·ãç£èŠã«å ããæ©æ¢°åŠç¿ã«é¢ããåé¡ãåºé¡ç¯å²ã§ãã 詊éšå¯Ÿçæ¹æ³ã¯ä»¥äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp Professional Cloud DevOps Engineer Professional Cloud DevOps Engineer 詊éšã¯ãGoogle Cloud ã§ã¢ããªéçºãè¡ã£ããã CI/CD ãã€ãã©ã€ã³ãæ§ç¯ãããããµãŒãã¹ç£èŠã»ã€ã³ã·ãã³ã管çãªã©ã IT ãµãŒãã¹ãå®å®çšŒå ãããããã«ã¯ã©ãããã°ããããšãã£ãç¥èŠãæ±ããããŸãã Google ã®æå±ãã SRE ïŒãµã€ãã»ãªã©ã€ã¢ããªãã£ã»ãšã³ãžãã¢ãªã³ã°ïŒããã®æ ¹åºã«ãããŸãã 詊éšå¯Ÿçæ¹æ³ã¯ä»¥äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp Professional Cloud Security Engineer Professional Cloud Security Engineer 詊éšã¯ãGoogle Cloud äžã§å®å
šãªã€ã³ãã©ãèšèšãå®è£
ããã§ãããšã³ãžãã¢ã§ããããšã瀺ãã ã»ãã¥ãªãã£ã«ç¹å ããèªå®è³æ Œã§ãã ãããã¯ãŒã¯ã»ãã¥ãªãã£ãã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãèªèšŒèªå¯ãç£æ»èšŒè·¡çã«é¢ããç¥èãæ±ããããŸãã 詊éšå¯Ÿçæ¹æ³ã¯ä»¥äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp Professional Cloud Network Engineer Professional Cloud Network Engineer 詊éšã¯ãGoogle Cloud ã® ãããã¯ãŒã¯ã¢ãŒããã¯ãã£ã«é¢ããæ·±ãç¥èŠ ãæ±ããããè³æ Œã§ãã Google Cloud ã®ãããã¯ãŒã¯ç³»ãµãŒãã¹ãã³ã³ããïŒGKEïŒã«é¢ãããããã¯ãŒã¯ãã³ã°ããã€ããªããã¯ã©ãŠãçã«é¢ããç¥èŠãæ±ããããŸãã 詊éšå¯Ÿçæ¹æ³ã¯ä»¥äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp Professional Machine Learning Engineer Professional Machine Learning Engineer 詊éšã¯ã Google Cloud ã® AI/ML ç³»ãµãŒãã¹ ãæŽ»çšããŠãããžãã¹èª²é¡ã解決ããããã®æ©æ¢°åŠç¿ã¢ãã«ã®èšèšãæ§ç¯ãå©çšãæšé²ã§ãã æ©æ¢°åŠç¿ãšã³ãžã㢠ã§ããããšã瀺ãè³æ Œã§ãã æ©æ¢°åŠç¿ã¢ãã«ã®ã¢ãŒããã¯ãã£ãããŒã¿ãã€ãã©ã€ã³ã®çžäºäœçšãããã³ã¡ããªãã¯ã®è§£éã«çéããŠããå¿
èŠããããŸãã Google Cloud ã®è©Šéšã§ã¯ãããŸãããGoogle Cloud ã®ç¥èã«å ããŠãæ©æ¢°åŠç¿ã«é¢ããç¥èŠãæ·±ãæ±ãããã詊éšã§ããæºäžã®çè«ã ãã§ãªãæ¯èŒçå®è·µçãªç¥èãæ±ãããããããé£æåºŠã¯é«ããã®ãšãªã£ãŠããŸãã 詊éšå¯Ÿçæ¹æ³ã¯ä»¥äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp Professional Security Operations Engineer Professional Security Operations Engineer 詊éšã¯ãGoogle Cloud ãããã¯ããäžå¿ãšãã ã»ãã¥ãªãã£ãªãã¬ãŒã·ã§ã³æ
åœè
åã ã®èªå®è³æ Œã§ãã æ»æã®æ€ç¥ãé²è¡ã»å¯Ÿå¿ã«é¢ããæè¡çãªç¥èããã€ã³ã·ãã³ã管çã®äœå¶ã«é¢ãããã®ãŸã§ãå
æ¬çã«åãããŸãã ç¹ã«ãGoogle Security OperationsïŒç¥ç§° Google SecOpsïŒãš Security Command Center ãäžå¿ãšãªããŸãã 詊éšå¯Ÿçæ¹æ³ã¯ä»¥äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp çªå€ç·š Professional ChromeOS Administrator Professional ChromeOS Administrator 詊éšã¯ãGoogle ã®æäŸããã³ã©ãã¬ãŒã·ã§ã³ããŒã«ã§ãã Google Workspace ã ChromeOS ããã€ã¹ã®éçšã管çã«é¢ããç¥èãåã詊éšã§ãã Google Cloud ã®å
¬åŒããã° ã§ç޹ä»ãããŠãããã®ã®ã Google Cloud èªå®è©ŠéšäžèЧ ã®å
¬åŒããŒãžã«ã¯èšèŒãããŠããããGoogle é¢é£è©Šéšã§ã¯ããã Google Cloud èªå®è©Šéšã®æ±ãã«ã¯ãªã£ãŠããŸããã 以äžã®èšäºã§è©³çްã«è§£èª¬ããŠããŸãã®ã§ããåç
§ãã ããã blog.g-gen.co.jp 廿¢ãããè©Šéš Looker LookML Developer Google ã®æäŸããããŒã¿ãã©ãããã©ãŒã ããŒã«ã§ãã Looker ã«ãããéçº (LookML) ã«é¢ããç¥èŠ ãåãèªå®è³æ Œã§ãã åœè©Šéšã¯2022幎4æ1æ¥ããã£ãŠçµäºããŸãããåèãŸã§ã«ã以äžã®èšäºã§ãã©ããªè©Šéšã ã£ãã®ãã確èªããããšãã§ããŸãã blog.g-gen.co.jp Looker Business Analyst Google ã®æäŸããããŒã¿ãã©ãããã©ãŒã ããŒã«ã§ãã Looker ã®ããžãã¹ãŠãŒã¹ã«é¢ããç¥èŠ ãåãèªå®è³æ Œã§ãã åœè©Šéšã¯2021幎12æ31æ¥ã§å»æ¢ãšãªããŸããã Professional Google Workspace Administrator Professional Google Workspace Administrator 詊éšã¯ã Google Workspace ïŒæ§ç§° GSuiteïŒ ã®å°å
¥ãéçšã«é¢ããç¥èŠ ãæ±ããããèªå®è³æ Œã§ããActive Directory ãšé£æºããèªèšŒã»èªå¯ãã·ã³ã°ã«ãµã€ã³ãªã³ãªã©ãäŒæ¥ IT ã®åšèŸºç¥èãæ±ããããŸãã åœè©Šéšã¯ã2022幎4æ29æ¥ãã以å㯠Professional Collaboration Engineer è©Šéš ãšåŒç§°ãããŠããŸããããåç§°å€æŽãããŸããããŸãã2025幎1æã«åŸç¶ã®èªå®è³æ Œã§ãã Associate Google Workspace Administrator 詊éšã GAïŒäžè¬å
¬éïŒã«ãªããåœè©Šéšã¯å»æ¢ãããŸãããåèãŸã§ã«ã以äžã®èšäºã§ã詊éšã®å
容ã確èªããããšãã§ããŸãã blog.g-gen.co.jp èäº éåº (èšäºäžèЧ) ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš ã¯ã©ãŠããµããŒã課 ãªã³ãã¬ç°å¢ã®ãããã¯ãŒã¯ã»ãµãŒããŒã·ã¹ãã ãäž»æŠå ŽãšããŠããããã¯ã©ãŠãé åã«ã·ãããçŸåšã¯ Google Workspace ãäžå¿ã«äŒæ¥ã® DX æšé²ããµããŒãã ã» Google Cloud Partner Top Engineer 2025 ã»Google Cloud èªå®è³æ Œ 7å æè¿ããã£ãŠããããšã¯ãæ¯åãšã®ãã±ã¢ã³ã«ãŒã Follow @arapote_tweet
G-gen ã®ææã§ãã BigQuery ã® Scheduled Query (ã¹ã±ãžã¥ãŒã«ãããã¯ãšãª) ã§èªåå®è¡ããã¯ãšãªã®ããžã§ã倱æéç¥ãè¡ãæ¹æ³ã«ã€ããŠè§£èª¬ããŸãã ã¯ããã« 3ã€ã®æ¹æ³ 1. ã¡ãŒã«éç¥æ©èœ 2. Pub/Sub 3. ãã°ããŒã¹ã®ææš ãã°ããŒã¹ã®ææšãšã¢ã©ãŒãã®äœææé ãã°ããŒã¹ã®ææšãšã¯ æé 1: ãã°ããŒã¹ã®ææšäœæ æé 2: ã¢ã©ãŒãã®äœæ ã¡ãŒã«éç¥ã®äŸãšèª²é¡ Scheduled Query ã®éç Cloud Monitoring ãš Cloud Logging ã¯ããã« Google Cloud (æ§ç§° GCP) ã®ããŒã¿ãŠã§ã¢ããŠã¹ãµãŒãã¹ã§ãã BigQuery ã«ã¯ Scheduled Query ãšããæ©èœãååšããŸããå¥åãã¹ã±ãžã¥ãŒã«ãããã¯ãšãªããããã¯ã¯ãšãªã®ã¹ã±ãžã¥ãŒãªã³ã°ãšèšããŸãããã®æ©èœã§ã¯å®æçã« BigQuery äžã§ SQL ãå®è¡ããããšãã§ãããã®æ©èœã®å©çšèªäœã«æéã¯çºçããŸãã (éåžžéãã® BigQuery æéã®ã¿ãçºçããŸã)ã ãã®æ©èœã§ã¯ãååŸé¢ä¿ãåå²ã®ããè€éãªãžã§ã管çã¯ã§ããªããã®ã®ãæ¥æãæå®ããŠå®æçã« SQL ãå®è¡ã§ãããããç°¡æç㪠ELT åŠçãããŒã¿ããŒãããŒãã«äœæãªã©ãè¡ãããããšãã§ããŸãã ããããã®æ©èœã䜿ãã«åœãã£ãŠèª²é¡ãšãªãã®ãããžã§ãã倱æãããšãã®éç¥ã§ããåœèšäºã§ã¯ã Scheduled Query ã䜿ã£ãéã®å€±æéç¥ã«ã€ããŠè§£èª¬ããŸãã åè : ã¯ãšãªã®ã¹ã±ãžã¥ãŒãªã³ã° 3ã€ã®æ¹æ³ 1. ã¡ãŒã«éç¥æ©èœ Scheduled Query ã«ã¯ããžã§ãã倱æããéã«ã¡ãŒã«ãéä¿¡ããæ©èœãåãã£ãŠããŸãã ããã©ã«ãã®ã¡ãŒã«éç¥æ©èœ å€ãã®æ¹ããããã第äžã®éžæè¢ãšããŠèããã¯ãã§ãã ããããªããããã®æ©èœã¯ ãžã§ãäœæè
ã® Google ã¢ã«ãŠã³ãã®ã¡ãŒã«ã«ããã¡ãŒã«ãéä¿¡ã§ããªã ãšãã仿§ããããŸãã ããã¥ã¡ã³ãã§ã¯ã¯ãŒã¯ã¢ã©ãŠã³ããšããŠã¡ãŒã«ãèªå転éããæ¹æ³ãèšèŒãããŠããŸãããããã ãšãžã§ãäœæè
ã®ã¢ã«ãŠã³ããéè·çã§åé€ããããšãã«éç¥ãã§ããªããªã£ãŠããŸããŸãã ã¡ãŒã«éç¥ (ãã®ãªã³ã¯ã¯ BigQuery Data Transfer Service ã®ããã¥ã¡ã³ãã§ããã Scheduled Query ã¯åãµãŒãã¹ã®äžéšã§ã) ãžã§ãã®å€±æéç¥ã¯ãç£èŠããŒã ã®ã¡ãŒãªã³ã°ãªã¹ãã§ãã£ãããã€ã³ã·ãã³ã管çããŒã«ããã£ããããŒã«ãžã®éç¥ãå¿
èŠã«ãªã£ãŠããã§ãããã ãã®ãããªããŒãºã«ããã®ããã©ã«ãéç¥æ©èœã§ã¯çããããšãã§ããŸããã 2. Pub/Sub ããäžã€ã®æ¹æ³ãšããŠã Pub/Sub ãžã®éç¥ãæããããŸãã åæ²ã®ã¹ã¯ãªãŒã³ã·ã§ããã«ããããã«ããžã§ãã®æå/倱æéç¥ã¯ Cloud Pub/Sub ã«éç¥ããããšãã§ããŸãã ããããªãã Pub/Sub ããã¡ãã»ãŒãžãèªã¿åºãã«ã¯ã Cloud SDK çãçšããå¿
èŠããããåºæ¬çã«ã¯ããŒã³ãŒãã§å®çŸã§ããŸããã Pub/Sub ãã Push åã§çŽæ¥ã¡ãŒã«éç¥ãçºåºããæ¹æ³ã¯ 2022 幎 1 æçŸåšã§ã¯ååšããªããããäŸãã° Pub/Sub ããªã¬ã® Cloud Functions ãäœæããŠã¡ãŒã«/ãã£ãããžé£æºãããªã©ãéç¥ã®ä»çµã¿ãå¥éäœæããå¿
èŠããããŸãã Scheduled Query ããããããæè»œã«ããŒã¿å€æãè¡ãããã«å©çšããŠããã®ã ãšããã°ããã®ãããªæéã®ãããå®è£
ã¯éžæè¢ãšããŠã¯éžã³ã¥ãããããããŸããã ãã®å Žåã¯æ¬¡ã«æããä»£æ¿æ¡ãæ€èšããŸãã 3. ãã°ããŒã¹ã®ææš æ¬¡ã®æ¹æ³ã¯ããã°ããŒã¹ã®ææšãšã¢ã©ãŒããçšããããšã§ãã Scheduled Query (BigQuery Data Transfer Service) ã¯ãžã§ãå®è¡ã®çµæã Cloud Logging ãžåºåããŠããŸãã æåæã»å€±ææãšãã«ãã°ãåºåããŸãããšã©ãŒæã®ãã°ã¯ä»¥äžã®ãããªãã®ã§ãã Scheduled Queryã®ãšã©ãŒãã° ãã®ãšã©ãŒãã°ãæ€ç¥ããŠéç¥ããããšãäžã€ã®ã¯ãŒã¯ã¢ã©ãŠã³ãã«ãªãããã§ãã ãã®æ¹æ³ã¯ç°¡åã«å®è£
ã§ããããã以éåœèšäºã§ã¯ããã°ããŒã¹ã®ææšãšã¢ã©ãŒããçšããéç¥ã®å®è£
æ¹æ³ã玹ä»ããŠãããŸãã â»ãªãç¹å®ãã°ãæ€ç¥ããŠã¢ã©ãŒããçºå ±ããæ¹æ³ãšããŠã¯ãä»åã玹ä»ããããã°ããŒã¹ã®ææš + ã¢ã©ãŒãããããããã«ç°¡åã«å®è£
ã§ãã ãã°ããŒã¹ã®ã¢ã©ãŒã æ©èœããããŸãããã¡ãã¯å·çåœæã® 2021 幎 12 æçŸåšã§ã¯ãã¬ãã¥ãŒæ©èœã ã£ãããæ¡çšããŸããã§ããããçŸåšã¯ GA ãããŠããŸãã ãã°ããŒã¹ã®ã¢ã©ãŒããæ§æãã ãã°ããŒã¹ã®ææšãšã¢ã©ãŒãã®äœææé ãã°ããŒã¹ã®ææšãšã¯ ãã°ããŒã¹ã®ææšãšã¯ã Cloud Logging ã«åºåããããã°ã«ãã£ã«ã¿ããããŠããã®æ€åºæ°ã Cloud Monitoring ã®ææš (ã¡ããªã¯ã¹) ãšããŠå©çšããæ©èœã§ãã ä»å㯠Cloud Logging ã«åºåããããšã©ãŒãã°ãã以äžã®ãããªãã£ã«ã¿ã§æ€ç¥ããŠã¿ãŸãã resource.type="bigquery_dts_config" AND severity = "ERROR" äžèšã®ãã£ã«ã¿ã¯éèŠåºŠã ERROR ã§ãã Scheduled Query (BigQuery Data Transfer Service) ãã°ãæœåºãããã®ã§ãã ãã®ãã£ã«ã¿ã䜿ã£ãŠãã°ããŒã¹ã®ææšãäœæãããšã 該åœãããã°ã¬ã³ãŒãã®æ°ã Cloud Monitoring ã«æ°å€ã¡ããªã¯ã¹ãšããŠéã ããšãã§ããŸãã ãã®ã¡ããªã¯ã¹ããããå€ãè¶
ãããšãã«ã¢ã©ãŒããçºå ±ããããèšå®ããã°ããšã©ãŒãã°åºåã奿©ã«ã¡ãŒã«éç¥ã Slack éç¥ãªã©ãè¡ãããšãã§ããŸãã ããããã¯ããã°ããŒã¹ã®ææšãšããããå
ã«éç¥ãçºå ±ããã¢ã©ãŒãã Google Cloud ã³ã³ãœãŒã«ã§äœæããæé ãã玹ä»ããŸãã æé 1: ãã°ããŒã¹ã®ææšäœæ Google Cloud ã³ã³ãœãŒã«ã§ ãã®ã³ã° > ãã°ããŒã¹ã®ææš ç»é¢ãžé·ç§»ããŸãã ãã¿ã³ ææšãäœæ ãæŒäžããŸãã ææšãäœæãæŒäž ææšã®èšå®å€ã¯ä»¥äžã®ããã«ããŸãã ææšã¿ã€ã: Counter ãã°ææšã®åå: (ä»»æ) 説æ: (ä»»æ) åäœ: ç©ºçœ ãã£ã«ã¿ã®äœæ: 以äžã®éã resource.type="bigquery_dts_config" AND severity = "ERROR" ææšã®æ
å ±ãå
¥å å
¥ååŸããã¿ã³ ææšã®äœæ ãæŒäžãããšææšãäœæãããŸãã 以åŸã¯ Cloud Monitoring ã® Metrics Explorer ã§ãæ€åºæ°ãã¡ããªã¯ã¹ (ææš) ãšããŠç¢ºèªã§ããŸãã ã¡ããªã¯ã¹å㯠logging/user/(æå®ããææšå) ãšãªããŸãã æé 2: ã¢ã©ãŒãã®äœæ ææšäœæåŸã«çŸãã以äžã®ç»é¢ãããææšã«åºã¥ãã¢ã©ãŒããäœæããããæŒäžããŸãã ææšäœæåŸã®ç»é¢ ãã®ç»é¢ãéããŠããŸã£ãŠããå Žåã¯ã Google Cloud ã³ã³ãœãŒã«ã§ Monitoring > ã¢ã©ãŒã ç»é¢ãžé·ç§»ããŠãã¿ã³ + CREATE POLICY ãæŒäžããŸãã æ¬¡ã®ç»é¢ã§ ADD CONDITION ãæŒäžãã Target ãšã㊠logging/user/(æå®ããææšå) ãæå®ããŸãã (ææšäœæåŸã®ç»é¢ããé·ç§»ããå Žåã¯ããããŸã§ã¯èªåã§å
¥åãããŸã) ã¢ã©ãŒãäœæç»é¢ Period ãšããŠãã¡ããªã¯ã¹ãéèšããæéåäœãæå®ããŸãã Configuration ã®ãããã¯ã§ãçºå ±ã®æ¡ä»¶ãæå®ããŸãã Configurationããã㯠äŸãã° Period ã 10 minutes ã§ Aggregator ã Sum ã Configuration ã«ãŠ is above 10 for most recent value ã®ããã«èšå®ããå Žåã 10 åéã§æ€ç¥ããããã°æ°ã®åèšã 10 ãè¶
ããå Žåã«çºå ±ãããªã¬ãŒãããŸãã is above 0 ãšããŠããã°ã 1 åã§ããšã©ãŒãåºãã°çºå ±ãããããã«ãªããŸãã ãã¿ã³ ADD ãæŒäžããŠãããå€èšå®ç»é¢ãéããã æ¬¡ãž ãæŒäžããŠãéç¥å
èšå®ãžé·ç§»ããŸãã éç¥å
èšå® éç¥å
㯠Cloud Monitoring ã® Notification Channel ãšããèšå®å€ãšããŠç®¡çããããšãã§ããŸãã ã¡ãŒã«ã Slack ã®ä»ã Webhook ã§å€éš API ãåŒã³åºãããã Pub/Sub ãžã¡ãã»ãŒãžã Publish ããããšãã§ããŸãã Notification Channel ãäºåã«äœã£ãŠããªãå Žåããã®ç»é¢ã§æ°èŠäœæãå¯èœã§ãã ãªãã¢ã©ãŒããçºçãããš Cloud Monitoring å
ã§ãã€ã³ã·ãã³ããã起祚ãããŸãããã€ã³ã·ãã³ãã®èªåã¯ããŒãºæéãªã©ãããã§èšå®ã§ããŸãã ãã¿ã³ NEXT ãæŒäžããŠãæåŸã«ã¢ã©ãŒãåãèšå®ãããã¿ã³ SAVE ãæŒäžããŸãã ã¢ã©ãŒãåã®èšå® ãããŸã§èšå®ãããšããããå€ãè¶
ããéã« Notification Channel ãžéç¥ãè¡ãããŸãã ã¡ãŒã«éç¥ã®äŸãšèª²é¡ éç¥å
ãã¡ãŒã«ãšããå Žåã以äžã®ãããªã¡ãŒã«ãå±ããŸãã ã¡ãŒã«ã®äŸ 課é¡ãšããŠãã¡ãŒã«æ¬æãã㯠ãã©ã®ãžã§ããã³ã±ããããã©ã®ããã«ã³ã±ãããã¯åãããªã ç¹ããããŸãã ãã®ä»£ããã¡ãŒã«å
ã® VIEW LOGS ãã¿ã³ãæŒäžã㊠Google Cloud ã³ã³ãœãŒã«ãžãã°ã€ã³ããŠè©²åœãããã°ãé²èЧããã°ããšã©ãŒæ¬æã該åœãã Scheduled Query ãžã§ãã® ID ã確èªã§ããŸãã ãããããã§ã¯ã Google Cloud ã³ã³ãœãŒã«ãžãã°ã€ã³ããæš©éãæããªãã¡ã³ããŒãã¡ãŒã«ãåãåãå Žåã察åŠãåããŸããã ã¡ãŒã«æ¬æããã©ã®ãžã§ãããããããææ¡ããã«ã¯ãäŸãã°ãã£ã«ã¿ã以äžã®ããã«ããŠããžã§ãããšã«ãã°ããŒã¹ææšãšã¢ã©ãŒããäœæããæ¹æ³ãæããããŸãã resource.type="bigquery_dts_config" AND severity = "ERROR" AND resource.labels.config_id="xxxxxxxx-0000-0xxx-0000-xxxxxxxxxxxx" resource.labels.config_id ãšããŠæå®ããŠãã xxxxxxxx-0000-0xxx-0000-xxxxxxxxxxxx ã®éšåã¯ãå Scheduled Query ã®è©³çްç»é¢ã® æ§æ ã¿ãã§ç¢ºèªã§ããããªãœãŒã¹åãã®æ«å°Ÿéšåã®è±æ°åã§ãã config_id ããããŠãžã§ãããšã«ãã°ããŒã¹ææšãšã¢ã©ãŒããäœæããã°ãã¡ãŒã«æ¬æã«ã¯ã¢ã©ãŒãåãææšåãèšèŒããããããã¡ãŒã«æ¬æãããã©ã®ãžã§ããã³ã±ããããŸã§ã¯ææ¡ããããšãã§ããŸãã ãã ããäŸç¶ãšããŠãã©ã®ããã«ã³ã±ããããŸã§ã¯åãããªãããããžã§ãæ° (Scheduled Query æ°) ãå€ããªããšããžã§ãããšã«ææšãšã¢ã©ãŒããäœæããªããã°ãªãããçŸå®çã§ã¯ãããŸããã ã¡ãŒã«ã«ããéç¥ã¯ãããŸã§ç°¡æçãªéç¥ã«çã ãå®éã®å¯ŸåŠã¯ã³ã³ãœãŒã«ã«ãã°ã€ã³ããŠãã°ã確èªããããšãããªãã¬ãŒã·ã§ã³ãçŸå®çã§ãããã Scheduled Query ã®éç Scheduled Query ã§ã¯ãåè¿°ã®éç¥ã®èª²é¡ã«å ããŠãååŸé¢ä¿ãåå²ã®ãããžã§ãããããçµãããšã«éçããããŸãã ãžã§ã倱ææã®ãªãã©ã€åŠçãªã©ããããŸã管çããããšãé£ããã§ãããã äžå®ä»¥äžè€éãªãžã§ãã®å Žå㯠Scheduled Query ã ãã§ãžã§ããæ§æããããšã諊ããŠã ã¯ãŒã¯ãããŒç®¡çããŒã«ãå°å
¥ããããšãæ€èš ããŸãããã 3rd party 補åã®æ€èšã¯ãã¡ããã Google Cloud ãµãŒãã¹ã§ããã° Cloud Composer ãªã©ã該åœããŸãã ãŸã Cloud Data Fusion ã Dataprep ãšãã£ãããŒã«ãæ€èšå¯Ÿè±¡ã§ãã Cloud Monitoring ãš Cloud Logging åœèšäºã§ã玹ä»ãã Cloud Logging ã®äœ¿ãæ¹ãã Cloud Monitoring ã®ææšãã¢ã©ãŒãã®æŠå¿µã«ã€ããŠã¯ä»¥äžã®èšäºã§ç޹ä»ããŠããŸãã®ã§ããåèã«ãé¡ãããããŸãã blog.g-gen.co.jp blog.g-gen.co.jp ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãX (æ§ Twitter) ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
ããã«ã¡ã¯æ ªåŒäŒç€ŸG-genã®æž¡é@norryã§ãã çããã³ã©ãã¬ãŒã·ã§ã³ããŒã«ã®Google Workspaceã¯å©çšãããŠããŸããïŒ ä»çŸåšäŒæ¥ã§å©çšãããŠããGoogle Workspaceã®ãšãã£ã·ã§ã³ãšããŠã¯Google Workspace BusinessãEnterpriseãšãã£ã·ã§ã³ãå©çšãããŠããæ¹ãå€ãã®ã§ã¯ç¡ãããšæããŸãã å
šç€Ÿã§Gmailãå
šå¡å©çšããããã©ãçŸå Žã¹ã¿ããå
šå¡ã«ã©ã€ã»ã³ã¹ãå²ãåœãŠãã«ã¯æéã...å©çšãã端æ«ã©ãããã...ã©ããã£ãŠå¥çŽããã°ããã®...ãªã©ãšãã£ãäºã¯ãããŸãããïŒ ãããã£ãæ¹ã«åããŠGoogle Workspace Frontline ã®ã玹ä»ã«ãªããŸãã Google Workspaceãšã¯ïŒ Frontlineãšãã£ã·ã§ã³ã«ã€ã㊠Frontlineãšãã£ã·ã§ã³ãšã¯ çŸå Žã¹ã¿ããã®å®çŸ© å©çšå¯èœãªãµãŒãã¹ ä»æ§ã«ã€ããŠã®æ³šæç¹ å¥çŽã«éããŠã®æ³šæç¹ ãŠãŒã¹ã±ãŒã¹å¯©æ» ãšãã£ã·ã§ã³æ··åšã®ã¿ã§å©çšå¯èœ å¥çŽæéãšæ¯æã ç³èŸŒã¿æ¹æ³ æåŸã« Google Workspaceãšã¯ïŒ Google Workspaceã® å
¬åŒãµã€ã ã«ã¯ãããããåãæ¹ã«å¯Ÿå¿ããçç£æ§åäžãšã³ã©ãã¬ãŒã·ã§ã³ã®ããŒã«ãããšããããŸãåŸæ¥å¡ã®çç£æ§ïŒããŒã xäŒç€Ÿã®æåïŒã³ãã¥ãã±ãŒã·ã§ã³ïŒã³ã©ãã¬ãŒã·ã§ã³ãšèšãæããäºãåºæ¥ãŸãã ãã®çµç¹ã®ã³ãã¥ãã±ãŒã·ã§ã³ãšã³ã©ãã¬ãŒã·ã§ã³ãäžæ¯ããä¿é²ããããŒã«ãGoogle WorkspaceãšãªããŸãã Google Workspace ã«ã¯è²»çšã®ç°ãªãè€æ°ã®ãšãã£ã·ã§ã³ãååšããŸãã詳ããã¯ãã¡ãã®èšäºãåç
§ãã ããã blog.g-gen.co.jp Frontlineãšãã£ã·ã§ã³ã«ã€ã㊠Frontlineãšãã£ã·ã§ã³ãšã¯ Google Workspace ã® Frontline ãšãã£ã·ã§ã³ãšã¯ã 第äžç·ã§æŽ»èºããçŸå Žã¹ã¿ããåã ã®ãšãã£ã·ã§ã³ã§ãã çµ±å¶ãåããäžã§ãšè¡šçŸããã®ã¯ãçŸå Žã¹ã¿ããã¯æ¥åãéè¡ããäžã§ç¥ãããæ
å ±ãåŸãã®ã«èªåãã¡ã®å人ããã€ã¹ãã¢ããªã䜿ãã»ããªãç¶æ³ãæšæž¬ãããããã§ãã ãããã£ãç¶æ³ã¯ã·ã£ããŒITãšãç¹ããäŒæ¥ã«ãšã£ãŠã¯æãŸãããªãç¶æ³ã§ãããããã¡ããšç®¡çäžã«çœ®ããäžã§é©åãªæ
å ±ãçŽ æ©ãåŸãããç¶æ
ãæãŸããã¯ãã§ãã çŸå Žã¹ã¿ããã®å®çŸ© Google Workspace Frontlineãå©çšå¯èœãªçŸå Žã¹ã¿ããã®å®çŸ©ã¯ä»¥äžã«ãªããŸãã äžç¹å®å€æ°ã®äººã«çŽæ¥å¯Ÿå¿ããŠããµãŒãã¹ããµããŒããåå販売ãè¡ã 補åããµãŒãã¹ã®è£œé ãé
éã«çŽæ¥æºãã æŠåã®å€§éšåãæ§æããæ¥åéè¡ã«ã¯ã¹ããŒããšå
±åäœæ¥ãéèŠã§ãã 該åœããå
·äœçãªçŸå Žã¹ã¿ããã®äŸ: è£œé æ¥ã®çµã¿ç«ãŠäœæ¥å¡ ã¬ã¹ãã©ã³ãæ¥å®¢æ¥ãå°å£²æ¥ã®ã¹ã¿ãã 蟲æ¥ãæŒæ¥ãææ¥ã®åŸäºè
建èšäœæ¥å¡ äž»ã«å±å€ã§äœæ¥ããã¹ã¿ãã ã³ãŒã«ã»ã³ã¿ãŒãäº€éæ©é¢ã®ãªãã¬ãŒã¿ãŒ å©çšå¯èœãªãµãŒãã¹ äŸ¡æ Œãå©çšäººæ°ã®å¶éãªã©ã¯äžèšã®ããã«ãªã£ãŠããŸãã Frontline Business Starter Business Standard Business Plus åºæ¬æ
å ± æé¡æéïŒ1ãŠãŒã¶ãŒãããâ»çšå¥ïŒ 520å 680å 1,360å 2,040å å©çšå¯èœäººæ° ç¡å¶é 1ã300å 1ã300å 1ã300å ã¹ãã¬ãŒãžå®¹é 2G 30GB 2TB 5TB 24æé365æ¥ã®é»è©±ãµããŒã â â â â å©çšå¯èœãªã³ã¢ãµãŒãã¹ã¯äžèšã®éãã§ãã Frontline Business Starter Business Standard Business Plus ã³ã¢ãµãŒãã¹ Gmailãšã«ã¬ã³ã㌠â â â â ããžãã¹åã Google ã°ã«ãŒã â â â â ChatãšChatã¹ããŒã¹ â â â â ãã©ã€ã ã¹ãã¬ãŒãžãšããã¥ã¡ã³ã ãšãã£ã¿ â â â â Meet ã«ãããããªäŒè° â â â â ãã£ã¬ã¯ããªç®¡ç â â â â Cloud Searchã«ãããã¡ã€ã³å
æ€çŽ¢ â â Google Vault â* â åºæ¬çãªæ©èœã¯ã»ãŒå©çšåºæ¥ããšèšã£ãŠè¯ãã§ãããããŸãäžèšã«å ããŠFrontlineã§ã¯ããã€ã¹ç®¡çã«ãããŠãåºæ¬ã®ãšã³ããã€ã³ã管çããé«åºŠãªãšã³ããã€ã³ã管çããå©çšå¯èœãšãªã£ãŠãããçŸå Žã¹ã¿ãããå©çšããã«ããã£ãŠäŒæ¥ã®ã¬ããã³ã¹ãå¹ãããäºãå¯èœã§ãã â» Vault 㯠Frontline ã§ã¯ææã¢ããªã³ãšããŠãå©çšããã ããŸãã 仿§ã«ã€ããŠã®æ³šæç¹ ãå
±æãã©ã€ããã®äœææ©èœã¯ç¡ããããã§ã«äœæãããŠããå
±æãã©ã€ãã«åå ããäºã¯å¯èœ Frontline ãŠãŒã¶ãŒã¯ãå
±æãã©ã€ããã®ãã©ã«ã㯠ãé²èЧã ããã§ããªã ãã ããã¡ã€ã«åäœã§æš©éãä»äžããã°ç·šéå¯èœïŒãã©ã«ãåäœã»ãã©ã€ãåäœã§ã¯ç·šéæš©éãä»äžã§ããªãã åè ïŒ 1ãŠãŒã¶ãŒãããã®ã¡ãŒã«ãããã¥ã¡ã³ããåçã®ä¿å容éãå«ããŠ2GBãšãªã£ãŠãã Cloud Searchã䜿ã£ã暪æçãªæ€çŽ¢ãã§ããªã ãšèšã£ãäºãäžããããŸããç¹ã«ãå
±æãã©ã€ããã®ãã©ã€ãã®ã«ãŒãããã©ã«ãã«ã¯ é²èŠ§æš©é ããäžããããªãäºã«æ³šæããŠãã ãã (ãã¡ã€ã«åäœã§ç·šéæš©éãä»äžããããšã¯ã§ããŸã) ããã®äºãããçŸå Žã¹ã¿ããã«ç¹åãããã©ã³ãšèšããŸãã å¥çŽã«éããŠã®æ³šæç¹ ãŠãŒã¹ã±ãŒã¹å¯©æ» ãã®ç¹æ§äžãFrontlineãå¥çŽããå Žåã«ã¯ Google 瀟ã®èŠä»¶ã«æ²¿ã£ãŠãããïŒ ã Google ã«ãã£ãŠå¯©æ»ãããŸãã Google Cloud 瀟ãšçŽæ¥å¥çŽã®å Žåã«ã¯ Google Cloud 瀟ãçŽæ¥å¯©æ»ã宿œããŸãã ããŒãããŒçµç±ã§å©çšããŠããå Žåã«ã¯ããŒãããŒã Google Cloud 瀟ãšåè°ããããŸãã Frontline ã®ãŠãŒã¹ã±ãŒã¹ã«åèŽããŠãããšå€æãããå Žåã®ã¿ãå¥çŽãå¯èœãšãªããŸãã ãšãã£ã·ã§ã³æ··åšã®ã¿ã§å©çšå¯èœ Frontline ãšãã£ã·ã§ã³ åäœã§ã®å¥çŽã¯äžå¯ ã§ãã Frontline + å¥ãšãã£ã·ã§ã³ ã®ããã«æ··åšãã圢ã§ã®ã¿å¥çŽãå¯èœã§ãã äŸãã° Business Standard + Frontline ãªã©ã§ãã ãã ã Frontline 以å€ã®ãã©ã³ã«é¢ããŠã¯ãäŸãã° Business StandardãšBusiness Starter çã®ããã«è€æ°ã®ãšãã£ã·ã§ã³ããã©ã³ãæ··åšãããŠå¥çŽããäºã¯ åºæ¥ãŸãã ã®ã§ã泚æãã ããã å¥çŽæéãšæ¯æã Frontline ãå¥çŽããã«ããã£ãŠãå¥çŽæéãšæ¯æãã¯ä»¥äžã®éãã§ãã æ··åšããŠå¥çŽãã Frontline 以å€ã®ãšãã£ã·ã§ã³ãããããŠä»¥äžã«ãªããŸãã®ã§ã泚æãã ããã ã©ã€ã»ã³ã¹æ°ãå®ãã幎éå¥çŽ (12ã¶æé) å¥çŽç· çµç¿æã®æåã«è«æ±æžçºè¡ã»ç¿ææ«ã« 12 ã¶æåããŸãšããŠæ¯æ 幎éäžã§ãŠãŒã¶ãŒã远å ããå Žåã¯ãæ®æåãåæã çŸåšã®å¥çŽæ¬¡ç¬¬ã§ã¯æç¶ãã« 2ã3 é±éãããå Žåããã ç³èŸŒã¿æ¹æ³ äžèšã®æ³šæç¹ãèŠãŠãåãããŸãéããçŸåšã®ç°å¢ãå¥çŽåœ¢æ
ã«ãã£ãŠæ€èšããéšåãå€ãçºãåŒç€Ÿæ ªåŒäŒç€ŸG-genã«ãæ°è»œã«ãçžè«ãã ããã docs.google.com æåŸã« Frontlineãäžæãçµã¿åãããäºã§å
šç€Ÿäžäžžãšãªã£ãåãæ¹å€é©ãã³ãã¥ãã±ãŒã·ã§ã³ãã³ã©ãã¬ãŒã·ã§ã³ã®ä¿é²ã«ã圹ç«ã¡åºæ¥ãäºããšæããŸãã åŒç€Ÿæ ªåŒäŒç€ŸG-genã§ã¯Google Workspace / Google CloudïŒGCPïŒ/ Chrome book ã®å°å
¥ããéçšãŸã§ã®ãæ¯æŽãè¡ã£ãŠããŸãã®ã§ãæ€èšã®éã«ã¯ãã²ã声ãããã ããã ãŸã Google Workspace / Google Cloud (GCP) ã5%å²åŒã§ãæäŸããŠãããŸãã æ¢ã« Google Cloud ããå©çšäžã®æ¹ããæ°èŠã«ãå©çšéå§ãæ€èšãããŠããæ¹ãããæ°è»œã«ãé£çµ¡ãã ããã g-gen.co.jp æž¡é å®£ä¹ (èšäºäžèЧ) ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš ããŒã¿åæåºç€ã®æ§ç¯ãã¯ã©ãŠã管çéçšããããã¯ãŒã¯ãå®åç¯å²ãGoogle Workspace æŽ»çšæšé²äžãGoogle Cloud èªå®è³æ Œã¯4è³æ Œä¿æ 鱿«ãã©ãã°ã©ãã¡ãŒã§ãèŠ³èæ€ç©ã塿 ¹æ€ç©ã«ããã£ãŠãŸãã
G-genã®æž¡é@norryã§ããåœèšäºã§ã¯ãçŸå Žã¹ã¿ããã«ãªãŒãºããã«ãªäŸ¡æ Œã§ Google Workspace ã©ã€ã»ã³ã¹ãå²ãåœãŠãããã® Google Workspace Frontline ãšãã£ã·ã§ã³ã玹ä»ããŸãã æŠèŠ Frontline ãšãã£ã·ã§ã³ãšã¯ çŸå Žã¹ã¿ããã®å®çŸ©ãšå¯©æ» 仿§ å©çšå¯èœãªæ©èœ æ©èœã®å¶é 人æ°ã容éã®äžé StarterãStandardãPlus ã®æ¯èŒ 泚æç¹ äž»ãªæ©èœå¶é ãšãã£ã·ã§ã³æ··åšã®ã¿ã§å©çšå¯èœ å¥çŽæéãšæ¯æã 賌å
¥ã«ããã æŠèŠ Frontline ãšãã£ã·ã§ã³ãšã¯ Google Workspace ã® Frontline ãšãã£ã·ã§ã³ ãšã¯ã第äžç·ã§æŽ»èºãã çŸå Žã¹ã¿ããåãã®ãšãã£ã·ã§ã³ ã§ãããªã FrontlineïŒããã³ãã©ã€ã³ïŒãšã¯ããåç·ããæå³ããè±åèªã§ãã Frontline ãšãã£ã·ã§ã³ã¯ãä»ã®ãšãã£ã·ã§ã³ãšæ¯èŒããŠæ©èœå¶éã¯ãããã®ã®ãæ¯èŒçå®äŸ¡ã«ã©ã€ã»ã³ã¹ã賌å
¥ããããšãã§ããŸãã Frontline ãšãã£ã·ã§ã³ã«ã¯ Frontline Starter ã Frontline Standard ã Frontline Plus ã®3çš®é¡ãååšããŸããäžäœãšãã£ã·ã§ã³ã«ãªãã»ã©ãã»ãã¥ãªãã£ç®¡çæ©èœã匷åãããŸãã åè : Frontline ãšãã£ã·ã§ã³ çŸå Žã¹ã¿ããã®å®çŸ©ãšå¯©æ» Frontline ãšãã£ã·ã§ã³ãå©çšå¯èœãªãçŸå Žã¹ã¿ãããã®å®çŸ©ã¯ã以äžã®ãšããã§ãã äžç¹å®å€æ°ã®äººã«çŽæ¥å¯Ÿå¿ããŠããµãŒãã¹ããµããŒããåå販売ãè¡ã 補åããµãŒãã¹ã®è£œé ãé
éã«çŽæ¥æºãã æŠåã®å€§éšåãæ§æããæ¥åéè¡ã«ã¯ã¹ããŒããšå
±åäœæ¥ãéèŠã§ãã å
·äœçã«ã¯ã以äžã®ãããªåŸæ¥å¡ã該åœããŸãã è£œé æ¥ã®çµã¿ç«ãŠäœæ¥å¡ ã¬ã¹ãã©ã³ãæ¥å®¢æ¥ãå°å£²æ¥ã®ã¹ã¿ãã 蟲æ¥ãæŒæ¥ãææ¥ã®åŸäºè
建èšäœæ¥å¡ äž»ã«å±å€ã§äœæ¥ããã¹ã¿ãã ã³ãŒã«ã»ã³ã¿ãŒãäº€éæ©é¢ã®ãªãã¬ãŒã¿ãŒ Frontline ãšãã£ã·ã§ã³ã®ã©ã€ã»ã³ã¹ã賌å
¥ããã«ã¯ãå©çšããåŸæ¥å¡ãäžèšã®èŠä»¶ã«æ²¿ã£ãŠãããã Google ã«ãã£ãŠå¯©æ» ãè¡ãããŸãã Google Cloud ãšçŽæ¥å¥çŽãããå Žåã«ã¯ãGoogle Cloud 瀟ãçŽæ¥ã審æ»ã宿œããŸããG-gen ã®ãããªè²©å£²ããŒãããŒçµç±ã§å¥çŽããå ŽåãããŒãããŒã Google Cloud 瀟ãšåè°ããããšãå¯èœã§ãã Frontline ã®ãŠãŒã¹ã±ãŒã¹ã«åèŽããŠãããšå€æããã審æ»ãã¯ãªã¢ããå Žåã®ã¿ã賌å
¥ãå¯èœãšãªããŸãã 仿§ å©çšå¯èœãªæ©èœ Frontline ãšãã£ã·ã§ã³ã§ã¯ã以äžã®ãããªæ©èœãå©çšå¯èœã§ããBusiness ãšãã£ã·ã§ã³ä»¥äžã§äœ¿ãã Google Workspace ã®ã»ãšãã©ã®æ©èœããFrontline ãšãã£ã·ã§ã³ã§ãå©çšã§ããããšãããããŸãã Gmail ãšã«ã¬ã³ã㌠ããžãã¹åã Google ã°ã«ãŒã Chat ãšãã£ããã«ãŒã ãã©ã€ã ã¹ãã¬ãŒãžãšããã¥ã¡ã³ã ãšãã£ã¿ïŒGoogle ããã¥ã¡ã³ããã¹ãã¬ããã·ãŒããã¹ã©ã€ãããã©ãŒã ããµã€ããå«ãïŒ Meet ã«ãããããªäŒè° ãã£ã¬ã¯ããªç®¡ç ãµã€ã ãã®ä»ã® Google ãµãŒãã¹ Colab: ããŒã¿ ãµã€ãšã³ã¹ã𿩿¢°åŠç¿ã¢ãã«ãå
±åã§éçºã§ããŸãïŒãã®ä»ã® Google ãµãŒãã¹ãšããŠããŠãŒã¶ãŒ ã©ã€ã»ã³ã¹ã¯äžèŠïŒã Colab Pro ãš Colab Pro+ïŒã¢ããªã³ïŒ ãšã³ã¿ãŒãã©ã€ãºçŽã®ããŒã¿ä¿è·ãåãã Gemini ã¢ã㪠AppSheet Core NotebookLM Cloud SearchïŒFrontline Plus ã®ã¿ïŒ AppSheet Core äžèšã¯ãäžéšæç²ã§ããå©çšå¯èœãªæ©èœã®äžèЧã詳现ã¯ã以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : Frontline ãšãã£ã·ã§ã³ã®æ¯èŒ æ©èœã®å¶é Frontline ãšãã£ã·ã§ã³ã§ã¯ãBusiness 以äžã®ãšãã£ã·ã§ã³ãšæ¯èŒããŠã以äžã®ãããªæ©èœå¶éããããŸãã Google ãã©ã€ãã®å
±æãã©ã€ãã«ã¯ã é²èЧè
æš©é ããä»äžã§ããªãïŒãã¡ã€ã«ã«çŽæ¥æš©éãä»äžããå Žåã¯ãç·šéãå¯èœïŒ Google Vids ã¯èŠèŽã®ã¿ïŒç·šéãã§ããªãïŒ Gemini ãŠã§ãã¢ããªã¯å©çšå¯èœã ããGemini Advanced ã§ã¯ãªãïŒé«åºŠãªæ©èœãå©çšã§ããªãïŒ äººæ°ã容éã®äžé Google Workspace ã®åãšãã£ã·ã§ã³ã«ã¯ãã©ã€ã»ã³ã¹æ°ã®äžéããã¹ãã¬ãŒãžå®¹éã«äžéãèšããããŠããŸãã以äžã®è¡šã§ã¯ã3çš®é¡ã® Frontline ãšãã£ã·ã§ã³ãšãæ¯èŒã®ããã« Business Starter ããã³ Plus ãšãã£ã·ã§ã³ã®äžéãèšèŒããŠããŸãã ãšãã£ã·ã§ã³ ãŠãŒã¶ãŒæ° ã¹ãã¬ãŒãžå®¹é Frontline Starter ç¡å¶é 5 GB/ãŠãŒã¶ãŒ Frontline Standard ç¡å¶é 5 GB/ãŠãŒã¶ãŒ Frontline Plus ç¡å¶é 5 GB/ãŠãŒã¶ãŒ Business Starter 300 30 GB/ãŠãŒã¶ãŒ Business Standard 300 2 TB/ãŠãŒã¶ãŒ Business Plus 300 5 TB/ãŠãŒã¶ãŒ StarterãStandardãPlus ã®æ¯èŒ Frontline Starter ã§ã¯ãããã€ã¹ç®¡çã«ãããŠãåºæ¬ã®ãšã³ããã€ã³ã管çããé«åºŠãªãšã³ããã€ã³ã管çããå©çšã§ããŸããäžæ¹ãFrontline Standard ã Plus ã§ã¯ãã ãšã³ã¿ãŒãã©ã€ãºãšã³ããã€ã³ã管ç ããå©çšå¯èœãšãªã£ãŠãããçŸå Žã¹ã¿ãããå©çšããã«ããã£ãŠãããé«åºŠãªçµ±å¶ãšã»ãã¥ãªãã£ãçºæ®ããäºãå¯èœã§ãã æäžäœã® Plus ãšãã£ã·ã§ã³ã§ã¯ãé«åºŠãªããŒã¿ãšã¯ã¹ããŒãããã¯ã©ã€ã¢ã³ããµã€ãæå·åãããŒã¿ãªãŒãžã§ã³ã®æå®ãç£æ»æ
å ±ã® BigQuery ãžã®ãšã¯ã¹ããŒãããã°ã€ãã³ãã® Google SecOps ãžã®ãšã¯ã¹ããŒããªã©ãããé«åºŠãªã»ãã¥ãªãã£æ©èœãå©çšã§ããŸãã 詳现ãªäžèЧã¯ã以äžã®ããã¥ã¡ã³ããåç
§ããŠãã ããã åè : Frontline ãšãã£ã·ã§ã³ã®æ¯èŒ 泚æç¹ äž»ãªæ©èœå¶é Frontline ãšãã£ã·ã§ã³ã§ã¯ã以äžã®å¶éã«ç¹ã«æ³šæãå¿
èŠã§ãã ãå
±æãã©ã€ããã®äœææ©èœã¯ç¡ããããã§ã«äœæãããŠããå
±æãã©ã€ãã«åå ããäºã¯å¯èœ Frontline ãŠãŒã¶ãŒã¯çµç¹å
ã®å
±æãã©ã€ãã«ã é²èЧè
æš©éã®ã¿ãä»äžå¯èœ ãã©ã«ãåäœã»ãã©ã€ãåäœã§ã¯ç·šéè
æš©éãä»äžã§ããªã ãã ããã¡ã€ã«åäœã§ã¯ãç·šéè
æš©éãä»äžã§ãã åè : å
±æãã©ã€ããäœæãã çµç¹å€ã®å
±æãã©ã€ãã®ã¡ã³ããŒãšããŠè¿œå ãããå Žåã¯ã 管çè
ãªã©ã®ä»»æã®ã¢ã¯ã»ã¹ã¬ãã«ãä»äžã§ãã åè : çµç¹ã®å
±æãã©ã€ããèšå®ãã 1ãŠãŒã¶ãŒãããã®ã¡ãŒã«ãããã¥ã¡ã³ããåçã®ä¿å容é㯠5 GB ç¹ã«ãçµç¹å
ã®å
±æãã©ã€ãã«ã¯é²èŠ§æš©éããä»äžã§ããªãç¹ã«ã¯æ³šæãå¿
èŠã§ããFrontline ãšãã£ã·ã§ã³ã¯ããããŸã§çŸå Žã¹ã¿ããã«ç¹åããã©ã€ã»ã³ã¹ã®ããããã©ã€ãäžã®ãã¡ã€ã«ã®äž»èŠãªç®¡çè
ãšããŠã¯æ³å®ãããŠããªããšèããããŸãã ãšãã£ã·ã§ã³æ··åšã®ã¿ã§å©çšå¯èœ Frontline ãšãã£ã·ã§ã³ã¯ãåäœã§ã®å¥çŽã¯äžå¯ã§ããã Business 以äžã®å¥ã®ãšãã£ã·ã§ã³ãšã®çµã¿åããã 圢ã§ã®ã¿ã賌å
¥ãå¯èœã§ããäŸãã°ã Business Standard + Frontline Starter ã®ããã«ããšãã£ã·ã§ã³ãæ··åšãããå Žåã§è³Œå
¥ãã§ããŸãã ãã ããFrontline 以å€ã®ãã©ã³ã«é¢ããŠã¯ãäŸãã° Business Standard + Business Starter ã®ããã«ãè€æ°ã®ãšãã£ã·ã§ã³ããã©ã³ãæ··åšãããŠå¥çŽããäºã¯ã§ããªãç¹ã«æ³šæããŠãã ããã å¥çŽæéãšæ¯æã Frontline ãå¥çŽããã«ããã£ãŠãå¥çŽæéãšæ¯æãã¯ä»¥äžã®ãšããã§ããæ··åšããŠå¥çŽãã Frontline 以å€ã®ãšãã£ã·ã§ã³ããããããŠä»¥äžãé©çšãããŸãã®ã§ã泚æãã ããã ã©ã€ã»ã³ã¹æ°ãå®ãã幎éå¥çŽïŒ12ã¶æéïŒ å¥çŽç· çµç¿æã®æåã«è«æ±æžçºè¡ã»ç¿ææ«ã« 12 ã¶æåããŸãšããŠæ¯æ 幎éäžã§ãŠãŒã¶ãŒã远å ããå Žåã¯ãæ®æåãåæã çŸåšã®å¥çŽæ¬¡ç¬¬ã§ã¯æç¶ãã« 2ã3 é±éãããå Žåããã ãªãããã®æ
å ±ã¯ G-gen 瀟ã®éå»å®çžŸã«åºã¥ããŠããŸããææ°æ
å ±ã¯ãGoogle Cloud 瀟ã販売ããŒãããŒã«ã確èªãã ããã 賌å
¥ã«ããã äžèšã®æ³šæç¹ãèŠãŠãããããšãããçŸåšã®ç°å¢ãå¥çŽåœ¢æ
ã«ãã£ãŠèæ
®ãã¹ãèŠçŽ ãå€ããããFrontline ãšãã£ã·ã§ã³ã®è³Œå
¥ã¯ãçµéšãã販売ããŒãããŒã«çžè«ããããšãæšå¥šãããŸãã åœèšäºãå·çããæ ªåŒäŒç€Ÿ G-gen ã®ãåãåãããã©ãŒã ããããæ°è»œã«ãçžè«ãã ããã åè : ãçžè«ã»ãåãåãããã©ãŒã - æ ªåŒäŒç€ŸG-gen G-gen ã§ã¯ Google Workspace ã Google CloudïŒæ§ç§° GCPïŒãå²åŒäŸ¡æ Œã§æäŸããŠããŸããæ¢ã« Google Cloud ã Google Workspace ããå©çšäžã®æ¹ããæ°èŠã«å©çšéå§ãæ€èšããŠããæ¹ãããæ°è»œã«ãé£çµ¡ãã ããã åè : Google Cloud è«æ±ä»£è¡ - æ ªåŒäŒç€ŸG-gen æž¡é å®£ä¹ (èšäºäžèЧ) ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš AI/MLãã¢ããªã±ãŒã·ã§ã³ã¢ããã€ãŒãŒã·ã§ã³ãããŒã¿åæåºç€ã®æ§ç¯ãã¯ã©ãŠã管çéçšããããã¯ãŒã¯ãªã©ã€ã³ãã©ç³»ã¯äœã§ããGoogle Workspace 掻çšãæšé²äž 鱿«ãã©ãã°ã©ãã¡ãŒã§ãèŠ³èæ€ç©ã塿 ¹æ€ç©ã«ããã£ãŠããŠçš®ããè²ãŠãŠãŸãã
Google ãæäŸãããŒããã©ã¹ãã»ãœãªã¥ãŒã·ã§ã³ã§ãã Chrome Enterprise Premium ïŒæ§ç§° BeyondCorp EnterpriseïŒã玹ä»ããŸãã Chrome Enterprise Premium ã®æŠèŠ Chrome Enterprise Premium ãšã¯ å®çŸã§ããããš ãŒããã©ã¹ãã»ãã¥ãªãã£ãšã¯ æ§æèŠçŽ éçš IDïŒãŠãŒã¶ãŒã¢ã«ãŠã³ãïŒ å€éš ID 飿º ç£æ»ãã° æé Chrome Enterprise Premium ã®æé ãã®ä»ã®èª²é ç¡æç¯å² æè¡çãªè©³çް 01. Identity-Aware ProxyïŒIAPïŒ Identity-Aware ProxyïŒIAPïŒ ãšã¯ ä»ã®ãã©ãããã©ãŒã ãžã®äžç¶ 02. Identity and Access ManagementïŒIAMïŒ 03. Access Context Manager Access Context Manager ãšã¯ [A] IP ã¢ãã¬ã¹ã¬ã³ãž [B] å°å [C] ããªã³ã·ãã«ïŒäž»äœïŒ [D] ããã€ã¹ããªã·ãŒ 04. Endpoint Verification ãã®ä»ã®æ©èœ Threat and Data Protection Cloud Console / Google Cloud API ãžã®ã¢ã¯ã»ã¹å¶åŸ¡ Chrome Enterprise Premium ã®æŠèŠ Chrome Enterprise Premium ãšã¯ Chrome Enterprise Premium ïŒæ§ç§° BeyondCorp EnterpriseïŒã¯ããšãŒãžã§ã³ãã¬ã¹ã»VPN ã¬ã¹ã§ç€Ÿå
IT ãµãŒãã¹ãžã®ã¢ã¯ã»ã¹ãå®çŸããã Google ã®ãŒããã©ã¹ãã»ã»ãã¥ãªãã£ãµãŒãã¹ã§ããChrome ãã©ãŠã¶ã®å©çšãåæãšããŠãããç¹ã« Google Workspace ã Chromebook ã瀟å
IT ã®äžå¿ã«çœ®ããŠããçµç¹ã«ãšã£ãŠãæå¹ãªã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ãšãããŸãã Chrome Enterprise Premium ãçšãããšãã€ã³ã¿ãŒããã VPN ã䜿ãããšãªããã€ã³ã¿ãŒãããçµç±ã§å®å
šã«ç€Ÿå
ã·ã¹ãã ã SaaS ãªã©ãžã¢ã¯ã»ã¹ããããšãã§ããŸãããŸããããŒã¿æå€±é²æ¢ïŒDLPïŒæ©èœããã£ãã·ã³ã°å¯Ÿçãªã©ãå€ãã®ã»ãã¥ãªãã£æ©èœãå
·åããŠããŸãã éèŠãªããŒã¯ãŒããšããŠã ã³ã³ããã¹ãã¢ãŠã§ã¢ ã¢ã¯ã»ã¹ ããããŸããäŸãšããŠãäŒç€Ÿæ¿èªã®ããã€ã¹ã§ããããšããäŒç€Ÿã® Google ã¢ã«ãŠã³ãã§ãã°ã€ã³ããŠããããšããšããæ¡ä»¶ãæºãããŠããã°ç€Ÿå
ã®é¡§å®¢æ
å ±ã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ãèš±å¯ããããšãã£ãèšå®ãå¯èœã§ãããªããã€ã IT 管çè
㯠VPN ã«ãŒã¿ãŒãã²ãŒããŠã§ã€ïŒãããã·ïŒã®ç®¡çãããå¿
èŠããããŸããã ãªãæ§ç§°ã§ãã BeyondCorp Enterprise ã® BeyondCorp ã¯ãåŸè¿°ã®ãŒããã©ã¹ãã»ãã¥ãªãã£ãå®çŸããããã« Google ãéçºããå®è£
ã¢ãã«ãæããŠããŸããBeyondCorp ãäžè¬ã®çµç¹åãã«è²©å£²ãããããã¯ãã Chrome Enterprise Premium ã§ãã åè : Chrome Enterprise Premium åè : Chrome Enterprise Premium overview å®çŸã§ããããš Chrome Enterprise Premium ã§ã¯ã以äžã®ãããªããšãå®çŸã§ããŸãã VPN ãªãã§ Google Cloud ä»ã®ãã©ãããã©ãŒã äžã® Web ã¢ããªã±ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ã§ããããã«ãã 瀟å
ã·ã¹ãã ã«ã¢ã¯ã»ã¹ã§ãã端æ«ãã瀟çšç«¯æ«ã ãã«å¶éãã ã¢ãã€ã« ããã€ã¹ãã瀟å
ããŒã¿ã«ã¢ã¯ã»ã¹ã§ããããã«ãã åŸæ¥å¡ãæ©å¯ããŒã¿ãã³ããŒããŠæã¡åºããªãããã«ãã Chrome Enterprise Premium ãå©çšãããšã以äžã®ãããªæ
å ±ãããšã«ããã¢ã¯ã»ã¹å¶åŸ¡ãå¯èœã«ãªããŸãã æ¥ç¶å
IP ã¢ãã¬ã¹ ããã€ã¹æ
å ± Google ã¢ã«ãŠã³ãã Google ã°ã«ãŒã ãµããŒããããŠãããµãŒãããŒãã£è£œåïŒCrowdStrike çïŒããã®æ
å ± ãŒããã©ã¹ãã»ãã¥ãªãã£ãšã¯ åè¿°ã®ããã«ãŠãŒã¶ãŒã®ãªã¯ãšã¹ãã®ã³ã³ããã¹ãïŒããã€ã¹ç¶æ
ãã¢ã¯ã»ã¹ç¶æ³çã ID ãšãã¹ã¯ãŒãã ãã«é Œããªãåçš®èæ¯æ
å ±ïŒã倿ã«äœ¿ã£ãŠã¢ã¯ã»ã¹å¶åŸ¡ãè¡ãæ¹åŒã¯ ãŒããã©ã¹ãã»ãã¥ãªã㣠ãšåŒã°ããŸããGoogle 瀟ã§ã¯å®éã«ãBeyondCorp ã®ä»çµã¿ã瀟å
ã§å©çšãã VPN ã¬ã¹ãªãŒããã©ã¹ãã»ãã¥ãªãã£ãå®çŸããŠãããšããããŠããŸãã ãŒããã©ã¹ãã»ãã¥ãªãã£ã¯ãåŸæ¥åã®ã瀟å
ãšç€Ÿå€ãå¢çç·ã®ãã¡ã€ã¢ãŠã©ãŒã«ã UTM ã§åºåããã瀟å
ãããã¯ãŒã¯ããã®ã¢ã¯ã»ã¹ã§ããã°å®å
šãšã¿ãªããŠãå
šãŠèš±å¯ããããšãã å¢çåãããã¯ãŒã¯ ãšã¯ãèãæ¹ãç°ãªããŸãã å¢çåã»ãã¥ãªã㣠vs ãŒããã©ã¹ã 2010 幎代以éã«äžè¬çã«ãªã£ãæšçåæ»æçã«ããã瀟å
ãããã¯ãŒã¯ã«ãã«ãŠã§ã¢ãå
¥ã蟌ãã ãããããã¯äŸµå
¥è
ã«ã²ãšãã³ç€Ÿå
ãããã¯ãŒã¯ã«å
¥ã蟌ãŸãããšãå¢çåã»ãã¥ãªãã£ã¯æå³ããªããŸãããããããè¿å¹ŽãŒããã©ã¹ãã»ã»ãã¥ãªãã£ã泚ç®ãããŠããçç±ã§ãã Chrome Enterprise Premium 㯠Google ãèªç€Ÿã§å®çŸãããŒããã©ã¹ãããµãŒãã¹åãããã®ã§ããã倿°ã®å®çžŸã®ãããœãªã¥ãŒã·ã§ã³ã ãšãããŸãã æ§æèŠçŽ Chrome Enterprise Premium ã¯æ¬¡ã® 4 ã€ã®ã³ã³ããŒãã³ãã§æ§æãããŸãã No åç§° æŠèŠ èª¬æ 01 Identity-Aware ProxyïŒIAPïŒ ãããŒãžãã®ãªããŒã¹ããã㷠瀟å
ãµãŒããªã©ãžã®æ¥ç¶ãäžç¶ããŠããã Google Cloud äžã®ä»çµã¿ 02 Identity and Access ManagementïŒIAMïŒ Google Cloud ã®æš©éç®¡çæ©æ§ Google ã¢ã«ãŠã³ããšæš©éãçŽã¥ããä»çµã¿ 03 Access Context Manager ã«ãŒã«ãšã³ãžã³ ããã€ã¹æ
å ±ãã¢ã«ãŠã³ãæ
å ±ãæ¥ç¶ç¶æ³ãªã©åçš®èæ¯æ
å ±ããã¢ã¯ã»ã¹å¯åŠã倿ããä»çµã¿ 04 Endpoint Verification ãšã³ããã€ã³ã ãšãŒãžã§ã³ã ãŠãŒã¶ãŒã®ããã€ã¹æ
å ±ãåéãã Google Chrome æ¡åŒµæ©èœ åã³ã³ããŒãã³ãã®æ©èœãå³ã§è¡šããšã以äžã®ããã«ãªããŸãã åã³ã³ããŒãã³ãã®æ©èœ ãã®å³ã§ã¯ IAP ãåäžé害ç¹ïŒSPOFïŒã«èŠããŠããŸããããããŸããããIAP 㯠Google ã®é«åºŠã«ã¹ã±ãŒã©ãã«ãªã€ã³ãã©ã§çšŒåããŠãããããç©ççã«ã¯åäžé害ç¹ã«ã¯ãªãããé«ãå¯çšæ§ãæã£ãŠããŸããIAP ã®ç©ççãªæ§æèŠçŽ ã®äžã€ã§ãã Cloud Load Balancing ã¯æåäœã§ 99.99% ã® SLA ãå®çŸ©ãããŠããŸãã åè : Compute Engine Service Level Agreement (SLA) ãŸãããã®ä»ã®æ©èœãšã㊠Threat and Data Protection ããããŸããThreat and Data Protection ã¯ãChrome ãã©ãŠã¶ã®è¿œå æ©èœãšããŠæäŸããããã«ãŠã§ã¢ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ãªã©ã®ãŠã§ãäžã®è
åšã«å¯Ÿããä¿è·ããData Loss PreventionïŒDLPïŒã«ãŒã«ãã»ãã¥ãªãã£ã¢ã©ãŒããã¬ããŒãããŒã«ãæäŸããŸãã éçš IDïŒãŠãŒã¶ãŒã¢ã«ãŠã³ãïŒ èªèšŒã«çšãããã IDïŒãŠãŒã¶ãŒã¢ã«ãŠã³ãïŒã¯ãåå Google ã¢ã«ãŠã³ãã§ãã Google ã¢ã«ãŠã³ã㯠Google Workspace ãŸã㯠Cloud Identity ã§ç®¡çãããŸãã1人ã®å人ã«å¯ŸããŠã1ã€ã® Google ã¢ã«ãŠã³ããçºè¡ãããŸãã詳现ã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp å€éš ID 飿º å€éš ID 飿º ãçšããããšã§ã以äžã®ãããªå€éš ID ã Google ã¢ã«ãŠã³ããšé£æºããŠèªèšŒããããšãã§ããŸãã ã¡ãŒã«ã¢ãã¬ã¹ãšãã¹ã¯ãŒã OAuthïŒFacebookãXãGitHubãMicrosoft ãªã©ïŒ SAML OIDC é»è©±çªå· ã«ã¹ã¿ã å¿å åè : External identities ç£æ»ãã° ããã©ã«ãã§ã¯ãã¢ã¯ã»ã¹ããªã·ãŒéåããããã°ã¯ãå
šãŠ Cloud Audit Logs ã«ããèšé²ãããŸãã 远å ã®æé ãå®è¡ããããšã§ãéåãã°ã ãã§ãªãããã¹ãŠã®ãªã¯ãšã¹ãã詳现ã«ãã°ã«åºåããããšãå¯èœã§ãã åè : Identity-Aware Proxy audit logging ãã°ã¯ãCloud Logging ã® Log Explorer ã䜿ãããšãªã©ã«ãã£ãŠé²èЧã§ããŸãããã°ã Cloud Logging ãã BigQuery ãžãšã¯ã¹ããŒãããããšã§ãããæ·±ãåæãå¯èœã§ããCloud Audit Logs ã Cloud Logging ã®è©³çްã«ã€ããŠã¯ã以äžã®èšäºãã確èªãã ããã blog.g-gen.co.jp blog.g-gen.co.jp æé Chrome Enterprise Premium ã®æé Chrome Enterprise Premium ã®æéã¯ã1ãŠãŒã¶ãŒãããæé¡ $6 ã§ãã Chrome Enterprise Premium ã®è³Œå
¥ã¯ãWeb ã³ã³ãœãŒã«çããã¯è¡ãããšã¯ã§ããŸãããGoogle ãããã¯è²©å£²ããŒãããŒã®æ
åœå¶æ¥ãžãåãåãããã ããããã®éã«å©çšäººæ°ãç³è«ããŸããããã®ç³è«ã¢ã«ãŠã³ãæ°ããŒã¹ã§èª²éãè¡ãããŸãã åè : Chrome Enterprise Premium ãã®ä»ã®èª²é å©çšäººæ°ããŒã¹ã®èª²éã®ã»ããChrome Enterprise Premium ã®äœ¿çšã«äŒŽããããã€ããã Cloud Load Balancing ãªã©ã«æéãçºçããŸãã ãŸã ID 管çã®ããã® Google Workspace ã Cloud IdentityïŒPremium ã®å ŽåïŒã®ã¢ã«ãŠã³ãæéããå¥éçºçããããšã«æ³šæãå¿
èŠã§ãã ç¡æç¯å² Google Cloud ã§ã¯ Cloud IAP ãç¡æã§å©çšã§ããŸãã Chrome Enterprise Premium ã賌å
¥ããªããšããCloud IAP ãæŽ»çšããããšã§ãGoogle Cloud äžã§çšŒåãã Web ã¢ããªã±ãŒã·ã§ã³ãžã®ã¢ã¯ã»ã¹å¶åŸ¡ããèžã¿å°ãµãŒãç¡ãã§ã® VM ãžã®ãã°ã€ã³ãªã©ãå®çŸã§ããŸãã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp æè¡çãªè©³çް ãããŸã§ã¯ãChrome Enterprise Premium ã®åºæ¬çãªæŠå¿µã解説ããŸãããããããã¯æè¡çãªèгç¹ã§ã Chrome Enterprise Premium ã®æ§æèŠçŽ ã解説ããŸãã 01. Identity-Aware ProxyïŒIAPïŒ Identity-Aware ProxyïŒIAPïŒ ãšã¯ Identity-Aware ProxyïŒIAPïŒ ã¯ã ãã«ãããŒãžãã®ãªããŒã¹ãããã· ã§ããç°¡åã«èšããšã瀟å
ã·ã¹ãã ãžã®æ¥ç¶ãäžç¶ããŠãããã Google Cloud äžã®ä»çµã¿ã§ãã ããã«ãããŒãžãããšããã®ã¯ã ãã®ä»çµã¿ã Google ã®ç®¡çããã€ã³ãã©ã®äžã§åããŠããããã ã€ã³ãã©ç®¡çã»éçšãããå¿
èŠããªã ãšããããšãæå³ããŠããŸãã IAP ãäžç¶ããã®ã¯åºæ¬çã«ã¯ HTTPïŒSïŒãã©ãã£ãã¯ã§ãã®ã§ã Web ã¢ããªã±ãŒã·ã§ã³ãå©çšå¯Ÿè±¡ãšãªããŸããIAP ãäžç¶ãèš±å¯ãããã©ããã¯ãåŸè¿°ã® IAM ã Access Context Manager ã§å®çŸ©ããã«ãŒã«ã«åºã¥ããŠå€æãããŸããã€ãŸãã€ã³ã¿ãŒããããã瀟å
ã·ã¹ãã ãžã¢ã¯ã»ã¹ããéããŠãŒã¶ãŒæ
å ±ãããã€ã¹æ
å ±ã«åºã¥ããŠã¢ã¯ã»ã¹å¯åŠã倿ãããããã瀟å
ã·ã¹ãã ãå®å
šã«å©çšããããšãã§ããŸãã ãã®ä»çµã¿ã«ãããã€ã³ã¿ãŒããã VPN ã«é Œããªããã»ãã¥ã¢ãªã¢ã¯ã»ã¹ãæ§ç¯ã§ããŸãã åè : Securing resources with IAP ä»ã®ãã©ãããã©ãŒã ãžã®äžç¶ Cloud IAP ã¯ãGoogle Cloud äžã« Google Compute EngineïŒGCEïŒã Google Kubernetes EngineïŒGKEïŒã§æ§ç¯ããã Web ã¢ããªã±ãŒã·ã§ã³ã«å ããAmazon Web ServicesïŒAWSïŒã Microsoft Azureããªã³ãã¬ãã¹ãªã©ãä»ã®ãã©ãããã©ãŒã äžã§çšŒåãã Web ã¢ããªã±ãŒã·ã§ã³ã«ã察å¿ããŠããŸãã åè: Securing resources with IAP åè: ãªã³ãã¬ãã¹ ã¢ããªã® IAP ã®æŠèŠ ä»ã®ãã©ãããã©ãŒã äžã® Web ã¢ããªãäžç¶ããå Žåã ã³ãã¯ã¿ ããããã€ããå¿
èŠããããŸããã³ãã¯ã¿ã®å®äœã¯ãCloud Load Balancing ã®å€éšã¢ããªã±ãŒã·ã§ã³ããŒããã©ã³ãµãŒãšãGoogle Kubernetes EngineïŒGKEïŒã§ãã¹ããããã¢ããªã±ãŒã·ã§ã³ã§ãã IAPçµç±ã§ãªã³ãã¬ãã¹ã¢ããªãžã¢ã¯ã»ã¹ãã ã³ãã¯ã¿ãã Web ã¢ããªã±ãŒã·ã§ã³ãžã®éä¿¡ã¯ãHTTPS ãªã©ã®æå·åãããã³ã«ã§ããã°ã€ã³ã¿ãŒãããçµç±ã§ããªã¹ã¯ã¯äœããšãããŸãã HTTP ãªã©ã®éæå·åãããã³ã«ã®å Žåã¯ãGoogle Cloud ã® VPC ãšãªã³ãã¬ãã¹ç°å¢ã Cloud InterconnectïŒå°çšç·ïŒãã€ã³ã¿ãŒããã VPN ã§æ¥ç¶ãããŠããã¹ãã§ãã 02. Identity and Access ManagementïŒIAMïŒ Identity and Access Management ã¯ç¥ç§°ã IAM ãšãããGoogle Cloud ã®èªèšŒã»èªå¯ã®ç®¡çæ©æ§ã§ããç¹ã«ã¯ã©ãŠããµãŒãã¹ã§ã¯äžè¬çãªçšèªã§ãã åè: Applying IAM conditions IAM ã¯ã 誰 ïŒããªã³ã·ãã«ãäž»äœïŒããã©ããã£ã æ¡ä»¶ ïŒã³ã³ãã£ã·ã§ã³ïŒã®ããšã§ã äœã«å¯Ÿã㊠ïŒå¯Ÿè±¡ãªãœãŒã¹ïŒã äœãã§ãã ïŒããŒã«ãæš©éïŒãããšããã«ãŒã«ã»ããã管çããŸãã Google Cloud ã® IAM ã®ç¹åŸŽãšããŠã誰ïŒããªã³ã·ãã«ãäž»äœïŒãããã©ãããæ¡ä»¶ïŒã³ã³ãã£ã·ã§ã³ïŒã®ããšã§ããäœãã§ããïŒããŒã«ãæš©éïŒããšããæ
å ±ãã æäœå¯Ÿè±¡ã®ãªãœãŒã¹ã«èšå®ãã 圢ã«ãªã£ãŠããç¹ãæããããŸãããã®çŽä»ãã ãã€ã³ãã£ã³ã°ïŒbindingïŒ ãšåŒã³ãŸãããã€ã³ãã£ã³ã°ã¯ IAM policy ãšåŒã°ãããåãªãœãŒã¹ã®å±æ§ãšããŠä¿æãããŸãã Chrome Enterprise Premium ã§ã¯ãã¢ã¯ã»ã¹å¶åŸ¡å¯Ÿè±¡ã® Web ã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿã㊠Cloud IAP äžã§ IAM policy ãèšå®ããã誰ïŒããªã³ã·ãã«ãäž»äœïŒãããã©ãããæ¡ä»¶ïŒã³ã³ãã£ã·ã§ã³ïŒã®ããšã§ããäœãã§ããïŒããŒã«ãæš©éïŒ= ã©ã®ãµãŒãã¹ã«å¯ŸããŠæ¥ç¶ã§ããããšãã现ããã¢ã¯ã»ã¹å¶åŸ¡ãå®çŸå¯èœã§ãã Google Cloud ã® IAM ã®ä»çµã¿ã«ã€ããŠã¯ã以äžã®èšäºã§è©³çްã«ç޹ä»ããŠããŸããããã«æ·±å ãããŠçè§£ãããæ¹ã¯ãåç
§ãã ããã blog.g-gen.co.jp 03. Access Context Manager Access Context Manager ãšã¯ Access Context Manager ã¯ãããã€ã¹æ
å ±ãã¢ã«ãŠã³ãæ
å ±ãæ¥ç¶ç¶æ³ãªã©ããªã¯ãšã¹ãã®èæ¯æ
å ±ããã¢ã¯ã»ã¹å¯åŠã倿ããä»çµã¿ã§ãã åè : Limiting access Access Context Manager 㯠IAM ãšã»ããã§äœ¿ãããŸãã IAM ã®ãæ¡ä»¶ïŒã³ã³ãã£ã·ã§ã³ïŒããšã㊠Access Context Manager ã䜿ãããã€ã¡ãŒãžã§ãã åã
ã®æ¡ä»¶èšå®ãªããžã§ã¯ãã ã¢ã¯ã»ã¹ã¬ãã« ãšåŒã³ãŸããã¢ã¯ã»ã¹ã¬ãã«ã§ã¯ã以äžã®èŠçŽ ãæ¡ä»¶ãšããŠå©çšã§ããŸãã [A] IP ã¢ãã¬ã¹ã¬ã³ãž [B] å°å [C] ããªã³ã·ãã« (äž»äœ) [D] ããã€ã¹ããªã·ãŒ åè : Access level attributes [A] IP ã¢ãã¬ã¹ã¬ã³ãž èš±å¯ããæ¥ç¶å
IP ã¢ãã¬ã¹ããCIDR 圢åŒïŒ x.x.x.x/x ïŒã§æå®ã§ããŸãã IPv4 ãš IPv6 ã®äž¡æ¹ã«å¯Ÿå¿ããŠããããããªã㯠IP ã®ã¿ãæå®ã§ããŸãã [B] å°å ã¢ã¯ã»ã¹å
IP ã¢ãã¬ã¹ããå°çæ
å ±ã倿ãããæå®ããå°åããã®ã¢ã¯ã»ã¹ã®ã¿ãèš±å¯ãããŸãã æ¡ä»¶ã«è€æ°å°åãæå®ãããšãOR ã§å€å®ãããŸãã ãªããããªã㯠IP ã¢ãã¬ã¹ããå€å®ããããããå°åãæ¡ä»¶ã«æå®ãããšãPrivate Google AccessïŒéå®å
¬éã® Google ã¢ã¯ã»ã¹ïŒçã䜿ã£ããã©ã€ããŒã IP ã¢ãã¬ã¹ããã®ã¢ã¯ã»ã¹ã¯æåŠãããŸãã [C] ããªã³ã·ãã«ïŒäž»äœïŒ ã¢ã¯ã»ã¹ã«äœ¿ãããããªã³ã·ãã«ïŒGoogle ã¢ã«ãŠã³ãããµãŒãã¹ã¢ã«ãŠã³ãïŒã§ãã ãããã IAM policy 㯠Google ã¢ã«ãŠã³ãã Google ã°ã«ãŒãããµãŒãã¹ã¢ã«ãŠã³ããšçŽä»ããããŠäœæãããã®ã§ãæ¡ä»¶ã®äžã§ããªã³ã·ãã«ãæå®ããããšã¯éå®çãããããŸãããåãã°ã«ãŒãã«çŽä»ããŠãã IAM policy ã§ãããªã³ã·ãã«ã«ãã£ãŠæ¡ä»¶ãå°ãå€ãããããšãããšãã«å©çšããŸãã [äŸ] Google ã°ã«ãŒã ops-grp@example.com ã«å¯ŸããŠãã·ã¹ãã A ãžã® IAP ã¢ã¯ã»ã¹ãèš±å¯ãã IAM policy ããã ãã® IAM policy ã®æ¡ä»¶ãšããŠä»¥äžãèšå® tom@example.com 㯠9:00-18:00 ã®æé垯ã§ã¢ã¯ã»ã¹ãèš±å¯ mary@example.com 㯠18:00-09:00 ã®æé垯ã§ã¢ã¯ã»ã¹ãèš±å¯ [D] ããã€ã¹ããªã·ãŒ åŸè¿°ã® Endpoint Verification ã§ååŸãããããã€ã¹ããªã·ãŒãšåèŽããŠãããã©ãããæ¡ä»¶ãšããŠèšå®ã§ããŸããããã«ãããäŒç€Ÿæå®ã®ç«¯æ«ä»¥å€ããµãŒãã¹ã«æ¥ç¶ããããšãé²ãã ããã»ãã¥ã¢ã§ãªãèšå®ã®ç«¯æ«ããWeb ãµãŒãã¹ã«æ¥ç¶ããããšãé²ãäºãã§ããŸãã 以äžã®èŠçŽ ãæ¡ä»¶ãšããŠãã§ãã¯ã§ããŸãã ã¹ã¯ãªãŒã³ããã¯ã®åŒ·å¶ ã¹ãã¬ãŒãžæå·å ããã€ã¹ã管çè
ã«æ¿èªãããŠããããš äŒç€Ÿæå®ã®ããã€ã¹ã§ããããš äŒç€Ÿæå®ã® OS ã§ããããš 04. Endpoint Verification Endpoint Verification ïŒãšã³ããã€ã³ãã»ããªãã£ã±ãŒã·ã§ã³ïŒã¯ Chrome ãã©ãŠã¶ã®æ¡åŒµæ©èœïŒChrome ExtentionïŒã䜿ãããŠãŒã¶ãŒæ
å ±ã端æ«ã®æ
å ±ãåéããŸãã ã€ãŸãå PC ã® Chrome ãã©ãŠã¶ã«æ¡åŒµæ©èœãã€ã³ã¹ããŒã«ããå¿
èŠããããŸããGoogle Workspace ãå©çšããŠããå Žå㯠Endpoint Verification Chrome extension ã管çã³ã³ãœãŒã«ããäžæé
åžã»èªåå±éãå¯èœã§ãã åè : Endpoint Verification overview åè : Gathering device information ãã®ä»ã®æ©èœ Threat and Data Protection åè¿°ã®äž»èŠãª4ã€ã®æ§æèŠçŽ ã«å ããŠã Threat and Data Protection æ©èœãå©çšã§ããŸãã ãã㯠Chrome ãã©ãŠã¶ã®è¿œå æ©èœãšããŠæäŸããããã«ãŠã§ã¢ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ãªã©ã®ãŠã§ãäžã®è
åšã«å¯Ÿããä¿è·ãã Data Loss PreventionïŒDLPãããŒã¿æå€±é²æ¢ïŒã«ãŒã« ã ã»ãã¥ãªãã£ã¢ã©ãŒã ã ã¬ããŒãããŒã« ãå©çšã§ããããã«ãªããŸãã DLP æ©èœ ã§ã¯ã Chrome äžã§æ©å¯ããŒã¿ã®å
±æã«é¢ããŠèŠåãåºããããããã¯ãããããŸãã ãã¡ã€ã«ã®ã¢ããããŒãã»ããŠã³ããŒãããã³ããŒ&ããŒã¹ãã®äžã«ãã¯ã¬ãžããã«ãŒãçªå·ã倧éã®ã¡ãŒã«ã¢ãã¬ã¹ãå«ãŸããŠããå Žåãªã©ã«åœæ©èœãåãããããã¯ãã¢ã©ãŒãçºå ±ãªã©ãè¡ãããšãã§ããŸãããã ããã®æ©èœã¯ WindowsãMacãLinuxãChrome OS ã® Chrome ãã©ãŠã¶ã§ã®ã¿æ©èœãã ããšã«æ³šæãå¿
èŠã§ãã ãŸãã ç£æ»ãã° ã ã»ãã¥ãªã㣠ããã·ã¥ããŒã ã ã¬ããŒãã£ã³ã° æ©èœãå
å®ããŠããŸãã ãChrome ã®è
åšå¯Ÿçã«é¢ããæŠèŠããChrome ã®ããŒã¿ä¿è·ã«é¢ããæŠèŠãããªã¹ã¯ã®é«ã Chrome ãŠãŒã¶ãŒãããªã¹ã¯ã®é«ã Chrome ãã¡ã€ã³ããªã©ã®ã¬ããŒãã衚瀺ããããšãã§ãããã«ãŠã§ã¢ã®è»¢éãå±éºãªãµã€ããžã®ã¢ã¯ã»ã¹ããã¹ã¯ãŒãã®åå©çšãæ©åŸ®ãªããŒã¿ã®è»¢éãªã©ã®ã¢ã¯ãã£ããã£ãå¯èŠåã§ããŸãã åŸæ¥å¡ã®æŽ»åã Chrome ãã©ãŠã¶ã«éçŽã»å¶éããããã§ Threat and Data Protection ãããŸã掻çšããããšã§ãæ
å ±æŒæŽ©ã®ãªã¹ã¯ãäžããäºãå¯èœã§ãã åè : Chrome Enterprise Premium ã§ Chrome ãŠãŒã¶ãŒãä¿è·ãã Cloud Console / Google Cloud API ãžã®ã¢ã¯ã»ã¹å¶åŸ¡ Google Cloud ã® Web ã³ã³ãœãŒã«ããgcloud ã³ãã³ãã©ã€ã³ãSDK ã䜿ã£ã Google Cloud API ãžã®ã¢ã¯ã»ã¹å¶åŸ¡ãè¡ãããšãã§ããŸãã ãã®æ©èœã䜿ã£ãŠãGoogle Cloud ç°å¢ã®éçšè
ãéçºè
ã«å¯Ÿããæ¥ç¶å
IP ã¢ãã¬ã¹ãããã€ã¹ããªã·ãŒã«åºã¥ããã¢ã¯ã»ã¹å¶åŸ¡ããããããšãã§ããŸãã ã¢ã¯ã»ã¹ã¬ãã«ã®å®çŸ©ã«éåããéçšè
ã¯ãã³ã³ãœãŒã«ç»é¢ã«ã¢ã¯ã»ã¹ã§ããªãã»ããCLI ã SDK ã䜿ã£ãç°å¢æäœãã§ããªããªããŸãã blog.g-gen.co.jp åè : Secure the Google Cloud console and the Google Cloud APIs ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãX (æ§ Twitter) ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-gen ã®ææã§ãã Google 㯠The Google Cloud Adoption Framework ãšãããã¬ãŒã ã¯ãŒã¯ (èãæ¹ãæœçã®æ çµã¿) ãå
¬è¡šããŠããŸãã ãã®ãã¬ãŒã ã¯ãŒã¯ã§ã¯ãçµç¹ãã¯ã©ãŠããå°å
¥ãããšãã«ã©ã®ããã«èããæœçã«åãçµãã¹ããã«ã€ããŠã®æéã瀺ããŠããŸãã æè¡çãªèŠç¹ã«ãšã©ãŸããã çµç¹ã¥ãããçµå¶å±€ã®é¢ããæ¹ãå«ãããå
æ¬çãªãã¬ãŒã ã¯ãŒã¯ ãšãªã£ãŠããŸãã 以äžã®ããŒãžããç¡æã§ãã¯ã€ãããŒããŒãé²èЧããããšãã§ããŸãã cloud.google.com ãã ããããã¥ã¡ã³ãã¯æ®å¿µãªããè±èªã§ããå
¬éãããŠããŸããã åœèšäºã§ã¯ The Google Cloud Adoption Framework ãæèš³ (éèªèš³ã§ã¯ãªãèŠçŽãã€ã€ç¿»èš³) ãã玹ä»ããããšæããŸãã åœèšäºã®å
容ã¯ãå³ãå«ããåè¿°ã® The Google Cloud Adoption Framework ãã¯ã€ãããŒããŒããæç²ã»ç¿»èš³ãããã®ãšãªããŸãããäžéšã«ç¿»èš³è
(ææ) ã®è§£éã解説ãå«ãããšããäºæ¿ãã ããã ãŸã (â») ã§æ¿å
¥ãããæ³šéã¯ç¿»èš³è
ã«ãããã®ã§ãã 第äžéš: ãšã°ãŒã¯ãã£ãã»ãµããªãŒ 1-1. åã€ã®ããŒããäžã€ã®ãã§ã€ãº 1-2. ã¯ã©ãŠãæç床 1-3. ãšãã㯠1-4. The Google Cloud Adoption Framework ãšã¯ 1-5. ã¯ãããã 1-5-1. ã¯ã©ãŠãæçåºŠã®æž¬å® 1-5-2. ãŽãŒã«ã決ãã 1-5-3. ã¯ã©ãŠãå°å
¥ããã°ã©ã ãèšç»ãã 1-5-4. ã¡ããã©ããã¯ãŒã¯ããŒããèŠã€ãã 第äºéš: ãã¯ãã«ã«ã»ãã£ãŒããã€ã 2-1. ã¯ã©ãŠãæç床ã®å段éã«ã€ã㊠2-1-1. Tactical (æŠè¡) 段é 2-1-2. Strategic (æŠç¥) 段é 2-1-3. Transformational (æè») 段é 2-2. åããŒãããšã®ã¯ã©ãŠãæç床 2-2-1. Learn (åŠç¿) Tactical (æŠè¡æ®µé) Strategic (æŠç¥æ®µé) Transformational (æè»æ®µé) 2-2-2. Lead (ãªãŒã) Tactical (æŠè¡æ®µé) Strategic (æŠç¥æ®µé) Transformational (æè»æ®µé) 2-2-3. Scale (ã¹ã±ãŒã«) Tactical (æŠè¡æ®µé) Strategic (æŠç¥æ®µé) Transformational (æè»æ®µé) 2-2-4. Secure (ã»ãã¥ã¢) Tactical (æŠè¡æ®µé) Strategic (æŠç¥æ®µé) Transformational (æè»æ®µé) 2-3. ãšãã㯠2-3-1. ã¢ã¯ã»ã¹ç®¡ç 2-3-2. ã¢ãŒããã¯ã㣠2-3-3. æ¯ãèã 2-3-4. CI/CD (Continuous integration and delivery) 2-3-5. ã³ã¹ãã³ã³ãããŒã« 2-3-6. ã³ãã¥ãã±ãŒã·ã§ã³ 2-3-7. ããŒã¿ãããžã¡ã³ã 2-3-8. å€éšã®ç¥èŠ 2-3-9. ID (ã¢ã€ãã³ãã£ãã£) 管ç 2-3-10. ã€ã³ã·ãã³ã管ç 2-3-11. Infrastructure as Code (IaC, ã€ã³ãã©ã®ã³ãŒãå) 2-3-12. èšæž¬ 2-3-13. ãããã¯ãŒãã³ã° 2-3-14. 人çãªãã¬ãŒã·ã§ã³ 2-3-15. ãªãœãŒã¹ç®¡ç 2-3-16. ã¹ãã³ãµãŒã·ãã 2-3-17. ããŒã ã¯ãŒã¯ 2-3-18. ã¹ãã«åäž ä»é²: ã¯ã©ãŠãæç床ã¢ã»ã¹ã¡ã³ã 第äžéš: ãšã°ãŒã¯ãã£ãã»ãµããªãŒ 1-1. åã€ã®ããŒããäžã€ã®ãã§ã€ãº The Google Cloud Adoption Framework ã«ã¯4ã€ã®ããŒããšã3ã€ã®ãã§ã€ãºããããŸãã 4ã€ã®ããŒãã¯ä»¥äžã§ãã The Google Cloud Adoption Framework ããåŒçšããå³ã翻蚳ãããã® Learn (åŠç¿) Lead (ãªãŒã) Scale (ã¹ã±ãŒã«) Secure (ã»ãã¥ã¢) Learn (åŠç¿) ã¯ãæè¡éšéã®ã¡ã³ããŒãã¹ãã«ã¢ããããããããããã¯æè¡ã®ããããŒãããŒäŒæ¥ãšã®é£æºãè¡ãããšãæ±ãããŒãã§ãã Lead (ãªãŒã) ã¯ãã¯ã©ãŠãç§»è¡ã«ãããçµå¶å±€ããªãŒããŒå±€ã®æ¯æŽãåŸãããŠããããããã«ããéšçœ²é飿ºãåããŠããããã¢ãããŒã·ã§ã³ã¯ååããã©ã®ãããªããŒã ç·šæãšãªã£ãŠãããããšãã£ãå
å®¹ãæ±ãããŒãã§ãã Scale (ã¹ã±ãŒã« â») ã¯ãé©åãªã¯ã©ãŠããµãŒãã¹ã®å©çšãèªååãé§äœ¿ããããšã§ãã€ã³ãã©ã«é¢ããéçšè² è·ãæžãããããã¢ããªã±ãŒã·ã§ã³ã®ã¢ããããŒãã®è² è·ãæžããããããããã®ããŒãã§ãã â»ã¹ã±ãŒã« = ã³ã³ãã¥ãŒãã£ã³ã°ãªãœãŒã¹ãã¹ãã¬ãŒãžãã䜿çšç¶æ³ã«å¿ããŠæ¡åŒµãããçž®å°ãããããããšãã¹ã±ãŒãªã³ã°ãšèšããåè©çã«ãã¹ã±ãŒã«ãããã®ããã«çšãã Secure (ã»ãã¥ã¢) ã¯ãã»ãã¥ãªãã£ã«é¢ããããŒãã§ããå€å±€ã»ãã¥ãªãã£ãIDããŒã¹ã®ã»ãã¥ãªãã£ãåºæ¬ãšããŸãã ããã4ã€ã®ããŒãããšã«ããããã3ã€ã®ãã§ã€ãº (é²æåºŠ) ããããŸãã The Google Cloud Adoption Framework ããåŒçšããå³ã翻蚳ãããã® Tactical (ãæŠè¡ã段é) Strategic (ãæŠç¥ã段é) Transformational (ãæè»ã段é) Tactical (ãæŠè¡ã段é) ã¯ãåå¥ã®åãçµã¿ãååšããŠãããã®ã®ãçµç¹ãšããŠäžè²«ããç¶æ
ã«ã¯ãªãããšããç¶æ
ã§ãããã®ç¶æ
ã§ã®é¢å¿ã¯ãåã
ã®ã·ã¹ãã ã®ã³ã¹ãåæžããæ³¢é¢šã®å°ãªãç§»è¡ãªã©ã«çãŸã£ãŠãããå°æ¥ã®æ¡åŒµãªã©ã«ã¯ãŸã é¢å¿ããããŸããããããçæçãªãŽãŒã«ã«ãªããŸãã Strategic (ãæŠç¥ã段é) ã¯ãå°æ¥ã«æž¡ã芳ç¹ãååšããåã
ã®åãçµã¿ã管çãããŠããç¶æ
ã§ãããŸãå¿
èŠãªé¢ä¿è
ã®å·»ã蟌ã¿ã¯ã§ããŠãã IT ããŒã ã¯ææãåºãå§ããŠããŸãããããäžæçãªãŽãŒã«ãšããŠæããããŸãã Transformational (ãæè»ã段é) ã¯ãã¯ã©ãŠãéçšãã¹ã ãŒãºã«å®çŸããŠãããé¢å¿ã¯ã¯ã©ãŠãäžã«ããããŒã¿ãããããåŸãããæŽå¯ã«ããããšããç¶æ
ã§ãã IT éšéããããã¯çžåœããããŒã ãã€ãããŒã·ã§ã³ã®ãšã³ãžã³ã«ãªã£ãŠããããããé·æçãªãŽãŒã«ãšãããŸãã 1-2. ã¯ã©ãŠãæç床 åè¿°ã®4ããŒãã3ãã§ã€ãºã®ãã¡ãçµç¹ãçŸæ®µéã§ã©ãã«ãããã確ãããéã¯ã ã¯ã©ãŠãæç床 ããã§ãã¯ããŸãã 以äžã®å³ã®ããã«ãçµç¹ã¯åããŒãããšã«ãäžããäžãžæçããŠãããŸãã The Cloud Maturity Scale - The Google Cloud Adoption Framework ããåŒçšããå³ã翻蚳ãããã® 1-3. ãšãã㯠ã¯ã©ãŠãæç床ã¹ã±ãŒã«ã䜿ã£ãŠèªçµç¹ã®çŸåšå°ãåãã£ãããæ¬¡ã¯åãžé²ãããã®æ¹æ³ãèããŸãã ã¯ã©ãŠãå°å
¥ã®ããã®ããããã®åçµã¿ã®ããšããããã§ã¯ ãšãã㯠(â»åäºè©©ã®ããš) ãšåŒã³ãŸãã åãšããã¯ã¯ãäºãã«éè€ããªãããå®çŸ©ãããŠããŸãããŸããåå人ã®ã¹ããŒãªãŒã«ãã¬ã€ã¯ããŠã³ã§ããŸãã äžã®å³ã¯ããšããã¯ã People (人) ã Technology (æè¡) ã Process (ããã»ã¹) ã«åé¡ãããã®ã§ãã è²ãã€ããéšåã¯ãåããŒãã«å¯Ÿå¿ããŠããŸããLearn (åŠç¿) = ç·ã Lead (ãªãŒã) = é»ã Scale (ã¹ã±ãŒã«) = éã Secure (ã»ãã¥ã¢) = èµ€ã§ãã å
šãŠã®ãšããã¯ã宿œã§ããªãå Žå㯠è²ä»ãã®éšåã«ãŸãåãçµã ããšããæåãžã®è¿éã§ãã Fine-tuning your direction with epics - The Google Cloud Adoption Framework ããåŒçšããå³ã翻蚳ãããã® 1-4. The Google Cloud Adoption Framework ãšã¯ å
ã«ç޹ä»ãããã¯ã©ãŠãæç床枬å®ãã§èªçµç¹ã®çŸåšäœçœ®ã確èªããããšããšããã¯ã䜿ã£ãŠãŽãŒã«ãžã®æœçãæ±ºããŸãã ãªã The Google Cloud Adoption Framework 㯠Google Cloud (æ§ç§° GCP) ã ãã§ãªã ã©ã®ã¯ã©ãŠãã«å¯ŸããŠãé©çšã§ãã æ¹æ³è«ã§ãã Google Cloud ã® Technical Account Manager (TAM) ã®æ¯æŽãä»°ãããšã§ãè¶
äžæµã®ã¢ã»ã¹ã¡ã³ããè¡ãããšãã§ããŸãã ããã«ããã¯ã©ãŠãæçåºŠãæž¬å®ããããããã«äŒŽããã¬ãŒãã³ã°ã®åªå
床決å®ãããã§ã³ãžã»ãããžã¡ã³ã (â») ã®ä»çµã¿ã®çå®ãããŒãããŒãšã®é¢ããæ¹ãã¯ã©ãŠãéçšäœå¶ãã¢ã«ãŠã³ãç®¡çææ³ãªã©ãæ€èšã§ããŸãã â» ãã§ã³ãžã»ãããžã¡ã³ã = çµå¶åŠçšèªãçµå¶æŠç¥ãçµç¹ã®å€é©ãã¹ã ãŒãºã«è¡ãããããã«ãããžã¡ã³ãããããšããŸããã®ææ³ TAM ã¯ãã¯ã©ãŠãåã®æåã®ãããžã§ã¯ãããããã®çµç¹ãã¯ã©ãŠããã¡ãŒã¹ããªçµç¹ã«ãªããŸã§ã䌎走ããããšãã§ããŸãã The Google Cloud Adoption Framework ããåŒçšããå³ã翻蚳ãããã® 1-5. ã¯ãããã 1-5-1. ã¯ã©ãŠãæçåºŠã®æž¬å® ã¹ãã€ã¯ãã«ã㌠(é¢ä¿è
) ã«4ã€ã®ããŒããããªãã¡ Learn (åŠç¿) ã Lead (ãªãŒã) ã Scale (ã¹ã±ãŒã«) ã Secure (ã»ãã¥ã¢) ã説æããã¢ã»ã¹ããŠããããŸãã åŸè¿°ã®ãã¯ãã«ã«ã»ãã£ãŒããã€ãã§ãåããŒãããšã®ãµããªãŒè¡šã瀺ãããã®ã§ããããå
ã«è°è«ãå§ããŸãã 1-5-2. ãŽãŒã«ã決ãã ã¯ã©ãŠãæç床ã®ãã¡ãã©ã®æ®µéããŽãŒã«ãšããããæ±ºããŸãã ãã®æ®µéã§ã IT çµç¹ã®äžã§ãæèŠãåããªãããšãå€ãã§ãããã ãã®äººãçµç¹ã®äžã®ã©ã®éå±€ã«ãããã«ãã£ãŠãã¯ã©ãŠãåã«ãã£ãŠåŸãããå©ç vs ãªã¹ã¯ã«å¯Ÿããèãæ¹ãç°ãªãããã§ãã ãŸãã¯è¶³ããããšããŠãçææŠè¡çãªç®æšã«ãã©ãŒã«ã¹ããŠè°è«ããããšãæ€èšããŸãããã 1-5-3. ã¯ã©ãŠãå°å
¥ããã°ã©ã ãèšç»ãã ãŽãŒã«ãšã®ã®ã£ããããããšããã¯ã«ã€ããŠãæœçã宿œããŸãã ãããã®æœçããæçµçã«ä»¥äžã®4ã€ã®ããããã«è¡ãçãããã«ããŠãã ããã ãã¬ãŒãã³ã°ããã°ã©ã ã®çå® ãã§ã³ãžã»ãããžã¡ã³ãããã°ã©ã ã®çå® ã¯ã©ãŠãéçšã¢ãã«ã®èšèš ã¯ã©ãŠãã¢ã«ãŠã³ãã®ã»ããã¢ãã Getting Started - The Google Cloud Adoption Framework ããåŒçšããå³ã翻蚳ãããã® 1-5-4. ã¡ããã©ããã¯ãŒã¯ããŒããèŠã€ãã â»ã¯ãŒã¯ããŒã = å
ã¯ä»äºéãåŠçéãšããæå³ãããã§ã¯ã·ã¹ãã ãåŠçããæ¥åããã®æ§è³ªããããã¯ã·ã¹ãã èªäœãæã åãã«ã¯ã©ãŠãåããã®ã¯ã ã·ã³ãã«ã§ããžãã¹ã¯ãªãã£ã«ã«ã§ã¯ãªãã·ã¹ãã ããæé©ã§ãã ãããã£ãã·ã¹ãã ãæåã«ã¯ã©ãŠãåããããšã§ãçµç¹ã®ã¯ã©ãŠãèœåãéããèªä¿¡ãã€ããããšã«ç¹ãããŸãã èœåãé«ãŸã£ãŠããã°ãå°æ¥ã¯ããè€éã§ã¯ãªãã£ã«ã«ãªã·ã¹ãã ã®ã¯ã©ãŠãåã«ã察å¿ã§ããŸãã æåã®ãããžã§ã¯ãã¯ã¯ãŒã¯ããŒãäž»äœã§èããã¹ããããããã¯éçšæ¹æ³äž»äœã§èããã¹ãããæ©ãããšãããã§ãããã ã¹ã¿ãŒãã¢ããäŒæ¥ã§ã¯ãè¿
éã«åçšç°å¢ãžãããã€ããããšãåªå
ããéçšè² è·ã¯çãããŠåããããšãããã§ãããã ãããããŠã³ã§ã¯ã©ãŠãå°å
¥ãé²ããå€§äŒæ¥ã§ããã°ãã¯ã©ãŠããæ¬çªå°å
¥ããåã«ãŸãã¯éçšäœå¶ããã£ãã確ç«ããããšããããšæãããŸãã ãããã®æ€èšã«æ£è§£ã¯ç¡ããçµç¹ããšã«ç°ãªããã®ã§ãã 第äºéš: ãã¯ãã«ã«ã»ãã£ãŒããã€ã â»ãã£ãŒããã€ã = æè¡èŠçŽ ãªã©ã«å¯ŸããŠãæ·±å ãããŠç޹ä»ãããèå¯ããããšã IT çéã§ãã°ãã°äœ¿ãããèšè 2-1. ã¯ã©ãŠãæç床ã®å段éã«ã€ã㊠2-1-1. Tactical (æŠè¡) 段é Tactical (æŠè¡) 段éã¯ãæ¢å IT ã® ã³ã¹ãæé©å ãšããçæçãªç®æšãšããããŸãã ã¯ã©ãŠãåã«ãã£ãŠããŸã䜿ãããŠããªãã³ã³ãã¥ãŒããªãœãŒã¹ (â»äž»ã« CPU ) ãã¹ãã¬ãŒãžãæé©åããããéçšè² è·ãäžãããã調éãã»ããã¢ããã®å·¥æ°ãäžãããããããšã該åœããŸãã ãã®æ®µéã§ã¯ã IT ããŒã (人ç) ãã¢ããªã±ãŒã·ã§ã³ãããŒã« (æè¡ç) ãéçšäœå¶ (ããã»ã¹ç) ã«å€§ããªå€æŽã¯èµ·ãããªãããšãå€ãã§ãããã ãšã¯ããããããã¯ã©ãŠãå°å
¥ã«ãããŠéèŠãªãã§ã€ãºã§ãã Tactical (æŠè¡) 段éã§ã¯ãæåŸ
ããææã¯ TCO (â») åæãžã®åœ±é¿åºŠåãã§å€æããŸãã åæã®çµæãšããŠåŸãããå©çãå°ãªãå Žåãããã« Strategic (æŠç¥) 段éãžè¡ããããšèããããç¥ããŸããããåçšç°å¢ã§ã¯ã©ãŠãã䜿ã£ãçµéšããªãå Žåã¯ååã«æ°ãã€ããŠãã ããããã®æ®µéã§åŸãããçµéšãããŒã ã«æåäœéšãšããŠæ®ãã°ããã®çµéšèªäœãã®ã¡ã®ãã§ã€ãºã®ããã®éèŠãªåºç€ãšãªãã§ãããã â» TCO = Total Cost of Ownership, ç·ææã³ã¹ããè³ç£ã調éããŠãã廿£ãããŸã§ã«çºçãããééçã»äººççã®ã³ã¹ãã®ç·é¡ 2-1-2. Strategic (æŠç¥) 段é Strategic (æŠç¥) 段é㯠ITçµç¹ããããã䟡å€ã®å¢å€§ ãšããäžæçãªç®æšã§ãã ãã®æ®µéãéæããã«ã¯ã IT ããŒã ã®éçºã»éçšã«é¢ãã广ãå¹çãé£èºçã«åäžããªããã°ãªããŸããã ããã«ã¯ãã¢ãŒããã¯ãã£ã®ã¢ããã€ãŒãŒã·ã§ã³ (è¿ä»£å) ã«ããã¯ã©ãŠããã€ãã£ã (â») ãªãµãŒãã¹ã掻çšããããšãå«ãŸããŸãã â»ã¯ã©ãŠããã€ãã£ã = ãã¯ã©ãŠãããããã ã£ãããã¯ã©ãŠãã®ã¡ãªãããååã«æŽ»çšããŠããç¶æ
ãæãããµãŒãã¹ãã·ã¹ãã ã«å¯ŸããŠäœ¿ãããšãããã°ãçµç¹ãå人ã«å¯ŸããŠäœ¿ãèšèã§ããã ãã®æ®µéã§ã¯ã IT ããŒã (人ç) ãã¢ããªã±ãŒã·ã§ã³ãããŒã« (æè¡ç) ãéçšäœå¶ (ããã»ã¹ç) ãªå€åããäžå®ã®ç¯å²ã§å¿
èŠã§ãã å€å㯠IT çµç¹ã®äžéšã«çãŸããããããŸããããçµç¹ã®å°æ¥å (éåç) ã瀺ããããæåäœéšãšããŠæ®ããšããæå³ã§ãæçµæ®µéã§ãã Transformational (æè») 段éãžã®åžç³ãšããŠéèŠã§ãã 2-1-3. Transformational (æè») 段é Transformational (æè») 段éã¯ã ITãã€ãããŒã·ã§ã³ã®ãšã³ãžã³ã§ããç¶æ
ãç®æããšããé·æçãªç®æšã«åœãããŸãã ãã®æ®µéã§ã¯ IT ãããžãã¹å€é©ãæšãé²ããåååãšãªã£ãŠããããã¯ãã³ã¹ãã»ã³ã¿ãŒã§ã¯ãªãããžãã¹ã«äžå¯æ¬ ãªååšã§ãã 以äžã®ãããªèŠçŽ ãããŒãšãªããŸãã æ¢åããŒã¿ããæŽå¯ãåŸãããš æ°ããããŒã¿ãåéã»åæããããš (ææ
ãç»åãé³å£°ãªã©) æ©æ¢°åŠç¿ã§ Predictive Analytics (äºæž¬çåæ â») ã Prescriptive Analytics (åŠæ¹çåæ â») ãè¡ãããš â» Predictive Analytics = äºæž¬çåæãæ©æ¢°åŠç¿ã«ãããå°æ¥èµ·ããåŸãäºè±¡ãæ°å€ãäºæž¬ããããš â» Prescriptive Analytics = åŠæ¹çåæãæ©æ¢°åŠç¿ã«ãããæææ±ºå®ã®èªååããããã¯ãµããŒããè¡ãããš ãŸã IT çµç¹èªäœãã¹ããŒãæãæã£ãŠã€ãããŒã·ã§ã³ãæäŸã§ãããããäžèšã®ãããªããŒã¿ããªãã³ãª (ããŒã¿èµ·å ã®) ã¢ãããŒããåãå¿
èŠããããŸãã çµç¹ãšããŠã SLO ã®åæã»èšæž¬ãé©åã«è¡ããç¥èŠã®æšªå±éããå人ãããŒã ãäž»äœçã«æææ±ºå®ã§ããããšãä¿é²ããããã«ããŸãã ãŸãã¯ã©ãŠããµãŒãã¹ãã¯ã©ãŠãæµã®ãã¹ããã©ã¯ãã£ã¹ããçµç¹ã®æ°ããåžžèã«ãªãå¿
èŠããããŸãã çµç¹ã¯ã倱æãé害ãå«ããŠå®éšçãªåãçµã¿ãæ£ããè©äŸ¡ããææãšã³ã¹ããé©åã«ç®å®ããããšã§ããã®æ°ããåžžèãäžæ¯ãã§ããã§ãããã 2-2. åããŒãããšã®ã¯ã©ãŠãæç床 é¢é£ãšããã¯: ã¹ãã«åäž ã å€éšã®ç¥èŠ 2-2-1. Learn (åŠç¿) Tactical (æŠè¡æ®µé) èªå·±åæ©ã¥ãã«é Œã£ããå人åäœã§ã®ã¹ãã«åäž ãªã³ã©ã€ã³ããã¥ã¡ã³ãã YouTube ããŒãããŒãå
šäœçãªç¥èŠãã«ã㌠ããŒãããŒãã¯ã©ãŠãç°å¢ãžã® admin æš©éãæã€ ã¹ãã«åäžã¯å人ã®ãã¹ããšãã©ãŒãã«ä»»ãããŠããããªã³ã©ã€ã³ããã¥ã¡ã³ãã YouTube ãšãã£ãç¡æã®ææã䜿ã£ãŠããŸãã ãã®æ®µéã§ã¯ãµãŒãããŒãã£ã®ããŒãããŒãå®å
šã«é ŒãããŠãããã¯ã©ãŠãè³ç£ãžã®ç¹æš©ã¢ã¯ã»ã¹ãå¯èœã§ãã æè¡çãªè³ªåããæäºã®éã®ãšã¹ã«ã¬ãŒã·ã§ã³ãããŒãããŒãäžæã«åŒãåããŠããç¶æ
ã§ãã ãã®æ®µéã«è³ãããã«ãã¯ã©ãŠãèŠå¡ãéãå¿
èŠã¯ãªããæ¢åã®ã¡ã³ããŒã§å°éã§ããã§ãããã Strategic (æŠç¥æ®µé) ãã¬ãŒãã³ã°éå¬ãã è³æ Œè©Šéšãžã®æ¯æŽãã ã¯ã©ãŠãé¢é£æ¥åã§ã®äººæåéãã ããŒãããŒãç·æ¥æã®ã¿çºåããã¯ã©ãŠãç°å¢ãžã® admin æš©éãæã€ (Break-glass admin access â») â» Break-glass ã = ç·æ¥æã«çšŒåãããã®ãæå³ãããç«çœå ±ç¥åšã®ã¢ã©ãŒã ã鳎ããããã«ã¬ã©ã¹ãå²ãããšãã 宿çãªã¹ãã«åäžããã°ã©ã ã IT èŠå¡ã«å¯ŸããŠæäŸãããŠããç¶æ
ã§ãã è³æ Œè©ŠéšååŸãæšå¥šãããäºç®ã確ä¿ãããŠããŸãã ãµãŒãããŒãã£ã®ããŒãããŒã¯ã瀟å
ã® IT èŠå¡ããŸã æã£ãŠããªãã¹ãã«ããå
補ã§å°éããã«ã¯çãæ·±ãããé åã®ç¥èŠãã«ããŒããŸãã æè¡çãªè³ªåãæäºã®éã®ãšã¹ã«ã¬ãŒã·ã§ã³ã«ã€ããŠã¯ãäžæ¬¡åãã¯å
éšã® IT ã¡ã³ããŒãåããŸãã ããã§è§£æ±ºã§ããªãå Žåã®ç¬¬2å±€ãšããŠããµãŒãããŒãã£ã®ããŒãããŒããšã¹ã«ã¬ãŒã·ã§ã³ãåããŸãã ãã®ãããããŒãããŒã¯æ®æ®µã¯å¶éä»ãã®ã¢ã¯ã»ã¹æš©éããæã£ãŠããããæäºã®éã«å¿
èŠãªæš©éãžææ Œããä»çµã¿ãšãªããŸãã ãã®æ®µéã§ã¯ã¯ã©ãŠãçšã®æ°ããããžã·ã§ã³ãçšæãããæ¡çšæœçãå§ãŸã£ãŠããŸãã ãŸãå IT ã¡ã³ããŒã«ã¯ãã¹ãçšã®ã¯ã©ãŠãç°å¢ (ãµã³ãããã¯ã¹) ãçšæãããæ€èšŒäœæ¥ãæ°ããã¢ã€ãã¢ã®ãã¹ããè¡ãããšãã§ããŸãã Transformational (æè»æ®µé) å人å士ãçžäºã«åŠã³ããæåãã wiki, ããã¯ããŒã¯(â»), ããã«ãœã³ IT èŠå¡ã®åœ¹å²ã責任ç¯å²ãå·æ°ãããŠãã ããŒãããŒã¯è£åŒ·çãªåœ¹å²ã®ã¿ã§ãããç¹æš©ãæããªã â»ããã¯ããŒã¯ = æè¡ã«é¢ããæèŠäº€æäŒãç¥èŠå
±æäŒãªã© ãã®æ®µéã§ã¯ãã¹ãã«åäžã¯ç¶ç¶çã§ãçžäºçã«è¡ãããŸãã 宿çãªãã¬ãŒãã³ã°ã«å ããŠã IT ããŒã ãåã
ã®åŸæ¥å¡ã¯ã宿çã«ããã«ãœã³ãããã¯ããŒã¯ãéããç¥èŠãå
±æããŸãã IT ã¡ã³ããŒã¯ããã°èšäºãè¬æŒãéããŠãæ¥çããªãŒãããç«ã¡æ¯èããããããšãæšå¥šãããŸãã ãã㯠IT ã¡ã³ããŒã®æé·ã®æå³ããããŸãããæ°ããªæ¡çšã«ç¹ãããšããç¹ã§äžç³äºé³¥ã§ãã ã¯ã©ãŠããã¡ãŒã¹ã㪠IT çµç¹ãšããŠã IT éšéã®åœ¹å²ãšè·è²¬ã¯ãå¿
èŠãªåå®çŸ©ãå®äºããŠããç¶æ
ã§ãã ãµãŒãããŒãã£ã®ããŒãããŒã¯ãè£å©çãªåœ¹å²ã®ã¿ãæ
ããŸãã ç¹æš©ç®¡çæš©éã¯æã¡ãŸãããã»ãšãã©ã®ãšã¹ã«ã¬ãŒã·ã§ã³ã¯å
éšã§è§£æ±ºããå
šãŠã®ã€ã³ã·ãã³ãå¯Ÿå¿æé ãå
éšã§å®çµããŸãã 2-2-2. Lead (ãªãŒã) é¢é£ãšããã¯: ã¹ãã³ãµãŒã·ãã ã ããŒã ã¯ãŒã¯ Tactical (æŠè¡æ®µé) ããç¹å®ãããžã§ã¯ãã®ç¹å®å人ã«ããã¯ã©ãŠãå°å
¥ãè¡ããã IT éšéå
ã®å¥éšçœ²ãšã®é£æºã¯é£ãã äžé·ããã®æ¿èªã¯ãããã®ã®ãäºç®ã¯éãããŠãã ãã®æ®µéã§ã¯ãã¹ãã³ãµãŒã·ãã (äžé·ã»å¹¹éšããã®æ¯æŽ) ã¯åäžéšéã®äžçŽç®¡çè·ããã®ãã®ã«éãããŠããç¶æ
ã§ãã ãšãã£ãŠãããã®äžé·ã¯ã¯ã©ãŠãå°å
¥ãæ¿èªãã鲿ãè³ãããªããšãã®ãšã¹ã«ã¬ãŒã·ã§ã³å
ã§ããã«éããŸããã ã¯ã©ãŠãå°å
¥ã¯å人çãªã¯ã©ãŠããžã®èå³ãæã£ãŠããäžéšã®ã¡ã³ããŒã«ãã£ãŠã®ã¿ãè¡ãããŸãã ä»ã® IT ã¡ã³ããŒãšã®é£æºã¯ãæ¢åçµç¹ã®æ§é 次第ã§å¶éãããŠããŸããŸãããªããªãã IT éšéå¡ã®è·è²¬ã®ç¯å²ã¯ãå²ãåœãŠããããããžã§ã¯ããããžãã¹éšéã®ç®¡èœå
ã»äºç®å
ã«éãããŠããŸã£ãŠããããã§ãã ãŸã圌ãã®ææã¯æ«ç«¯ã§å©çšããã IT ã ãã«çŸããŠãããçµç¹ã®äžå€®ã® IT ã«éå
ãããããšã¯ãããŸããã çµæãšããŠããããããŠçåããŠããã¯ã©ãŠããããã¯ã©ãŠãã»ã·ã£ããŒIT (â»)ãã®ããã«ãªã£ãŠããŸããŸãã â»ã·ã£ã㌠IT : äžå€®ã® IT éšéã«ãã£ãŠæ¿èªãããŠããªã IT ããŒã«çãäºæ¥éšéãã¡ã³ããŒãåæã«äœ¿ã£ãŠããããšãæããäžè¬çã«ã»ãã¥ãªãã£ãªã¹ã¯ã§ãã Strategic (æŠç¥æ®µé) ãããžã§ã¯ã暪æã§éãŸã£ãå°æ°ã®ã¯ã©ãŠãæšé²æŽŸã°ã«ãŒãã«ããã¯ã©ãŠãå°å
¥ãé²ã ãã®ã°ã«ãŒãå€ãšã®é£æºã¯é£ãã CxO ã¬ãã«ã®å¹¹éšããã®æ¿èªããããäºç®ãã€ããŠãã ãã®æ®µéã§ã¯ C ã¬ãã«ã®å¹¹éš (â») ããã®ã¹ãã³ãµãŒã·ãããåããããããã«ãªã£ãŠããŸãã ã¬ããŒãã©ã€ã³äžã®åãããŒãžã£ã¯ãã¯ã©ãŠãå°å
¥ã«ãããç®æšã KPI ãæç¢ºã«å®ããããŠããŸãã äžé·ããã®æ¯æŽã«ãããä»ã® IT éšéãããžãã¹éšéãšã®æ°Žå¹³é£æºãå¯èœã«ãªã£ãŠããŸãã â» Cã¬ãã« = CIO, CTO ãªã© C ããå§ãŸãå¹¹éšè· ããŸã åŸæ¥åã® SLO (Service Level Objectives, ãµãŒãã¹ã¬ãã«ç®æš) ããæ€èšŒã®ã¹ããŒããã€ãããŒã·ã§ã³ãé害ããã®å埩ãããåªå
ãããŠããŸãã ãã®æ®µéã§ã¯ãã¯ã©ãŠãå°å
¥ã¯å°æ°ç²Ÿéã®æ©èœæšªæã»ãããžã§ã¯ã暪æã®ããŒã (Center of Excellence, CoE) ã«ããé²ããããŠããŸãã ãã® CoE ããŒã ã«ã¯ã¢ããªã±ãŒã·ã§ã³ã¢ãŒããã¯ãããœãããŠã§ã¢ãšã³ãžãã¢ãããŒã¿ãšã³ãžãã¢ããããã¯ãŒã¯ãšã³ãžãã¢ã ID / ãã£ã¬ã¯ããªç®¡çè
ãéçšæ
åœè
ãã»ãã¥ãªãã£æ
åœè
ã財åæ
åœè
ãªã©ãã³ã¢ãšãªã圹è·ãæã£ãŠããç¶æ
ã§ãã ããŒã ã®ã¡ã³ããŒã¯ãå°åã®å Žåãå
Œåã®å ŽåããããŸããã圹è·åãè©äŸ¡è»žã¯æ°ãã圹å²ã«å¿ããŠå·æ°ãããŠããŸãã IT çµç¹ãªã©ã®é¢ä¿è
ãšæè¡æ¥çç¥èã«æãããå°ä»»ã®æè¡ãããŒãžã£ãŒãããããšãæãŸããã§ãããã Transformational (æè»æ®µé) èªäž»çãªãããã¯ãéçºããŒã ãè€æ°ãã ãšã©ãŒããžã§ãã (â») ãš "æ¹å€ãªã" ã®ãã¹ãã¢ãŒãã (â») ã CxO ã¬ãã«å¹¹éšã«èªèãããŠãã çµç¹å
šäœã§å®æçã«é²æãæŽæ°ããã â»ãšã©ãŒããžã§ãã = äºåã«å®ããé害ã«å¯Ÿããäºç®ã§ãã SLO ã«åºã¥ãç®åºãããããããæ®ã£ãŠãããã¡ã¯æ°ãããªãªãŒã¹ãå¯èœããªã©ã®ããã«äœ¿ããã â»ãã¹ãã¢ãŒãã = èªæºã¯ãæ€æ»ããã€ã³ã·ãã³ããšãã®å¯Ÿå¿ãå®äºããåŸã«ãäºè±¡ã»å¯Ÿå¿ã»åå ã»æ ¹æ¬å¯Ÿçãªã©ããŸãšããåçºé²æ¢ç®çã®ããã¥ã¡ã³ããéå®³å ±åæžãšäŒŒãŠãããå ±åã§ã¯ãªãæ¹åãç®çã§ããç¹ã§ãã¥ã¢ã³ã¹ãç°ãªã â»ãããã®çšèªããªã©ã€ãªãŒç€Ÿã«ããåºçã®ãSRE ãµã€ããªã©ã€ã¢ããªãã£ãšã³ãžãã¢ãªã³ã°ãã«è©³ãããåæžã¯ Google ã®ã¡ã³ããŒã«ããå·çãã SRE ãšããçšèªãåºãæ®åããã ã¹ãã³ãµãŒã·ããã¯ãããŒã±ãã£ã³ã°ã財åããªãã¬ãŒã·ã§ã³ã人äºãªã©ããå«ã CxO ã¬ãã«å¹¹éšå
šäœããåããããããã«ãªã£ãŠããããã®äžäœã®ãããŒãžã£é£ã«ãè¡ãæž¡ã£ãŠããç¶æ
ã§ãã ãã®ãããã§ãå®éšãšã€ãããŒã·ã§ã³ã倧äºã§ãããšããæåãå
šäœã«è¡ãæž¡ã£ãŠããŸãã ãšã©ãŒããžã§ããã®æŠå¿µã CEO ãŸã§çè§£ãããŠãããæ¹å€ã䌎ããªããã¹ãã¢ãŒãã ã®æåã IT çµç¹ã«æµžéããŠããŸãã ããŒã ã¯ãéææ§ããããªãŒãã³ãªæ
å ±å
±æãå¯èœãªç°å¢ã§åãããšãã§ããŠãããåçš®æ±ºå®æš©éãæã£ãŠããŸãã ã¢ãããã¯ãªæ€èšŒãè¡ãããã«ãæ¿èªãåŸãããªãœãŒã¹ã®æºåãåŸ
ã€å¿
èŠã¯ãããŸããã ããŒã¿ã¬ããã³ã¹ãã³ã¹ãã³ã³ãããŒã«ã¯èªååãããŠããŸãã é害ãããåŸé²ã®ããã®è²ŽéãªæèšãšããŠæè¿ãããŸããå人ã«ãã倱æã¯å人ã«åž°ãããšã¯ãããçµç¹ãšããŠã®æ¬ é¥ãšè§£éãããå±è²¬ã¯ãããŸããã 2-2-3. Scale (ã¹ã±ãŒã«) é¢é£ãšããã¯: ã¢ãŒããã¯ã㣠ã CI/CD (â») ã IaC (â») â» CI/CD = Continuous Integration / Continuous Delivery ãç¶ç¶çã€ã³ãã°ã¬ãŒã·ã§ã³ã»ç¶ç¶çããªããªãŒãšèš³ããããåè
ã¯èªååã«ãããœãããŠã§ã¢ã®ãã«ãã»ãã¹ãã®ã¹ããŒãã»å¹çãåäžãããææ³ãåŸè
ã¯èªååãé§äœ¿ããŠãµãŒãã¹ã®ãªãªãŒã¹ã®ã¹ããŒãã»å¹çãåäžãããææ³ â» IaC = Infrastructure as Code ãIT ã€ã³ãã©ãã³ãŒããªããå®çŸ©ãã¡ã€ã«ã§å®çŸ©ããŠåçŸæ§ç¢ºä¿ã»èªååã»ããŒãžã§ã³ç®¡çãå¯èœã«ããææ³ Tactical (æŠè¡æ®µé) ã¯ã©ãŠããªãœãŒã¹ã¯æåã§å±éããã ã¢ããªã¯é·æéçšã® VM ã«å±éã OS ã®ä¿å®ãå¿
èŠ ç°å¢å€æŽã®ã¬ãã¥ãŒã¯æäœæ¥ ç°å¢å€æŽã®ãªã¹ã¯ã¯é«ããé »åºŠã¯äœããæäœæ¥ ãã®æ®µéã§ã¯ããããŒãžããµãŒãã¹ (â») ããµãŒãã¬ã¹ (â») ã®å©çšã¯éå®çã§ãã èªãéçšããå¿
èŠããã ä»®æ³ãã·ã³ (VM â») ã«é Œã£ãŠããŸãã ãããããã¯ã管ç察象ãå¢ããã«é£ãã察象ããšã«æå³ããªãèšå®ã®ãºã¬ãèµ·ãããªã©ã®åå ãšãªãã管çéçšã®å·¥æ°ãå¢ãç¶ããŸãã ãµãŒãã®æ°ãå¢ããã°å¢ããã»ã©ã管çã»éçšã®å¯Ÿè±¡ã¯å¢ããç£èŠå¯Ÿè±¡ãå¢ããããã©ãŒãã³ã¹æ
å ±ã®åé察象ãå¢ããŠãããŸãã â»ãããŒãžããµãŒãã¹ = ã¯ã©ãŠããµãŒãã¹åŽã§ã€ã³ãã©ã管çããããµãŒãã¹ãç©çå±€ã OS å±€ãæèãããœãããŠã§ã¢ã¬ãã«ã§å©çšããããšãã§ãããäŸãšã㊠Google Cloud (GCP) ã® Cloud SQL ã Amazon Web Services (AWS) ã® Amazon RDS ã¯ãªã¬ãŒã·ã§ãã«ããŒã¿ããŒã¹ã®ãããŒãžããµãŒãã¹ã§ãã â»ãµãŒãã¬ã¹ = ãããŒãžããµãŒãã¹ã®ãã¡ããµãŒãã®æŠå¿µããªã (ãŠãŒã¶ããèŠãŠé èœãããŠãã) ãµãŒãã¹ã®ããšãå©çšåã«ã€ã³ã¹ã¿ã³ã¹ã®å±éçãå¿
èŠãªããå³åº§ã«å©çšã§ããã Google Cloud (GCP) ã® BigQuery ã Amazon Web Services (AWS) ã® AWS Lambda ãªã©ãè©²åœ â»ä»®æ³ãã·ã³ (VM) = Google Cloud (GCP) ã§ããã° Google Compute Engine (GCE) ã§ããã Amazon Web Services (AWS) ã§ããã° Amazon EC2 ã§ãã ã¢ããªã±ãŒã·ã§ã³ã®ã³ãŒããã€ã³ãã©èšå®ã®å€æŽã¯äººã®ç®ã«ããã¬ãã¥ãŒãããæåã§å®æœãããŸãã ç°å¢ã«å¯Ÿãã倿Žã¯é«ãªã¹ã¯ãšã¿ãªãããæ°é±éã«äžåºŠããããã¯æ°ã¶æã«äžåºŠã®é »åºŠã§ãã ãã®æ®µéã§ã¯ãã¯ã©ãŠããªãœãŒã¹ã®å±éã¯æåã§è¡ãããŸãã Google Cloud (GCP) ã® Deployment Manager ã Hashicorp 瀟㮠Terraform ãšãã£ãã€ã³ãã©èªååããŒã«ã¯çšããããŸãã (â») ã â» Amazon Web Services (AWS) ã®å Žå㯠Terraform ã AWS CloudFormation ã該åœãã Strategic (æŠç¥æ®µé) ã¯ã©ãŠããªãœãŒã¹ã¯ãã³ãã¬ãŒãããå±éãã ã¢ããªã¯ã€ãã¥ãŒã¿ãã« (â») 㪠VM ãã³ã³ããã«å±éã OS ãžã®æ¥ç¶ã¯äžå¯ (äžèŠ) ç°å¢å€æŽã®ãã¹ãã¯èªå ç°å¢å€æŽã®ãªã¹ã¯ã¯äžçšåºŠ ç°å¢å€æŽã¯æå â»ã€ãã¥ãŒã¿ãã« = ãäžå€ã®ããæå³ããè±åèªãã³ãŒãå®çŸ©ã®ä»®æ³ãµãŒããŸãã¯ã³ã³ããã®å©çšã«ãããã€ã³ãã© (ãµãŒã) ãäžå€ã§ãã代ããã«ãã€ã§ãæšãŠãããããšãæå³ããŠãããåŸæ¥ã¯ãµãŒããæ§ç¯ãããšãå
éšã«é
眮ãããèšå®ãã¡ã€ã«ã«ããèšå®ã管çãããã¢ããªã±ãŒã·ã§ã³ã®ããŒã¿ãå
éšã«æã€ããããµãŒãã®äžèº«ã¯ãå¯å€ãã§ãã£ããããããããµãŒãã®ããã¯ã¢ãããåããé害ã®éã¯äžèº«ã®åŸ©æ§ãå¿
èŠãšãªãã察ããŠã€ãã¥ãŒã¿ãã«ãªã€ã³ãã©ã§ã¯ããµãŒãã®äžèº«ã¯å€ãããªããããŒã¿ã¯å€éšã®ããŒã¿ã¹ãã¢ã«æ°žç¶åãããèšå®å€ã¯ã³ãŒãã§ããŒãžã§ã³ç®¡çãããããã§ãããé害ã®éã¯ãé害ãèµ·ãããµãŒã/ã³ã³ããã¯å»æ£ããæ°ãããµãŒã/ã³ã³ãããã€ã¡ãŒãžãã埩æ§ããããã®ã€ãã¥ãŒã¿ãã«ãªã€ã³ãã©ã«ãã管çå·¥æ°ã¯å€§å¹
ã«æžããæ°Žå¹³ã¹ã±ãŒã«ã容æã«ãªã ãã®æ®µéã§ã¯ VM ã¯ã€ãã¥ãŒã¿ãã«ãªèšèšã«ãªã£ãŠããŸãããã®ããã·ã¹ãã 倿Žã«ãããã¹ã³ãŒããå°ããããããšã«æåããŠããŸãã ç°å¢èšå®ã¯ãã¡ã€ã«ã§ã¯ãªãã VM ã€ã¡ãŒãžãšããŠä¿æãã (ã€ã¡ãŒãžã "çŒããŠãã" ãšè¡šçŸããããšããããŸã) ããŒãžã§ã³ç®¡çãããŠããŸãã ã¹ããŒããã« (â») ãªã¯ãŒã¯ããŒããšã¹ã±ãŒãã¬ã¹ (â») ãªã¯ãŒã¯ããŒãã¯åºå¥ãããŠããããã®ããæè»ãªæ°Žå¹³ã¹ã±ãŒã« (â») ãã§ããããã«ãªã£ãŠããŸãã â» ã¹ããŒããã« = ã¢ããªã±ãŒã·ã§ã³ããµãŒããç¶æ
ãä¿æããããšãåæã®ã¢ãŒããã¯ãã£ããããŒã¿è
¹ã«æã€ããã®ã該åœãäŸãã°ããã¢ããªã±ãŒã·ã§ã³ãµãŒããããŒã«ã«ãã£ã¹ã¯ã«ã»ãã·ã§ã³ãã¡ã€ã«ãä¿åããä»çµã¿ã®å Žåããã®ã¢ãŒããã¯ãã£ã¯ã¹ããŒããã«ã§ãã â» ã¹ããŒãã¬ã¹ = ã¢ããªã±ãŒã·ã§ã³ããµãŒããç¶æ
ãä¿æ "ããªã" ããšãåæã®ã¢ãŒããã¯ãã£ããããŒã¿ãè
¹ã«æããªãããã®ã該åœãä¿åããã¹ãããŒã¿ã¯å
šãŠãµãŒã/ã³ã³ããå€éšã®ããŒã¿ããŒã¹çã®ã¹ãã¬ãŒãžã«ä¿åãã â» æ°Žå¹³ã¹ã±ãŒã« = ã¹ã±ãŒã«ã¢ãŠããšã¹ã±ãŒã«ã€ã³ã1ã€ã®ãµãŒãã®ã¹ããã¯ãäžãããäžãããããã¹ã±ãŒã«ã¢ãããã¹ã±ãŒã«ããŠã³ãšã¯å¯Ÿè±¡çã«ããµãŒããã³ã³ããã®æ°ãå¢ããããæžããããããŠããã©ãŒãã³ã¹ã調æŽããæ¹æ³ãã¢ããªã±ãŒã·ã§ã³ãã¹ããŒãã¬ã¹ã§ããã°ãããŒã¿ãè€è£œãããæŽåæ§ãåãå¿
èŠããªããããæ°Žå¹³ã¹ã±ãŒã«ã容æã§ãã ç°å¢å€æŽã®ãªã¹ã¯ã¯äžçšåºŠã§ãããšèªèãããŠããç¶æ
ã§ãã æ¬çªç°å¢ãžã®ãããã€ã¯ããã°ã©ã ã«ããè¡ãããŸããããã®åŠçã¯äººæã«ãã£ãŠèµ·åãããŸãã å¿
èŠãªå Žåãããã«ããŒã«ããã¯ããŠå
ã®ç¶æ
ã«æ»ãããšãã§ããŸãã ã¢ããªã±ãŒã·ã§ã³ããŒã ã¯åºç€çãªã¢ãã¿ãªã³ã°ãã忥ãã Application Performance Monitoring (APM) ãå®çŸããŠããŸãã 24 æéã» 365 æ¥ ã§ã¢ããªã±ãŒã·ã§ã³ã®ããã©ãŒãã³ã¹ã«é¢ããæŽå¯ãããã¢ãªã¢ã«ã¿ã€ã ã§åŸãããšãã§ããŠããŸãã Google Cloud (GCP) ãããžã§ã¯ã (ããã㯠AWS ã§ãã "AWS ã¢ã«ãŠã³ã" ç) ã VPC ã» ID ãªã©é¢é£ãªãœãŒã¹ã®å±é㯠Deployment Manager (Google Cloud), Terraform (Hashicorp) ãªã©ãçšããŠããã°ã©ã ã§è¡ãããŸãã ã³ã¹ãæçްã¿ã°ãããŒã¿æ©å¯ã¬ãã«ãä¿æããŒã ãªã©ã€ã³ããããã¹ã倿°ãå
¥åããã°ãèªåçã«å±éã§ããããã«ãªã£ãŠããç¶æ
ã§ãã Transformational (æè»æ®µé) å
šã¯ã©ãŠããªãœãŒã¹ã¯ãã¿ã³äžã€ã§ãæ°åå
ã«åæ§ç¯å¯èœ ã¢ããªã¯ãµãŒãã¬ã¹ãªã¯ã©ãŠããµãŒãã¹ã«å±é ç°å¢å€æŽã¯å®åžžçã§äœãªã¹ã¯ ç°å¢å€æŽã¯ããã°ã©ããã«ã«è¡ããã æ¬çªç°å¢ VM ã«ã¯ç·æ¥æã®ãããã°ç®ç以å€ã§ã¯ã¢ã¯ã»ã¹ã§ããªãããã«ãªããŸãã ã»ã«ããããŒãžããªãµãŒãã¹ (IaaS) ã¯å
šãŠããããŒãžããµãŒãã¹ããµãŒãã¬ã¹ã SaaS ãªã©ã«çœ®ãæãã£ãŠãããéçšè² è·ã¯æå°åãããŠããŸãã ç°å¢å€æŽã®ãªã¹ã¯ã¯å°ãããšã¿ãªãããæ¬çªç°å¢ãžã®ãããã€ã¯ããã°ã©ã ã«ããèªåçã«è¡ãããŸãã ã«ããªã¢ãªãªãŒã¹ (â») ããã«ãŒã°ãªãŒã³ããã〠(â») ãªã©ã®ãã§ã€ãºå¥ãããã€æŠç¥ã宿œãããŠããŸãã â»ã«ããªã¢ãªãªãŒã¹, ãã«ãŒã°ãªãŒã³ããã〠= ããããã¢ããªã±ãŒã·ã§ã³ã®ãããã€æŠç¥ã®åç§°ã§ãæ°ããŒãžã§ã³ãžã®åãæ¿ããšåé¡ããã£ãéã®æ§ããŒãžã§ã³ãžã®åãæ»ãã广çã«è¡ãããã®æŠç¥ã Amazon Web Services Japan å
¬éã® AWS Black Belt Online Seminar AWS CodeDeploy ã®è³æã«è©³ãã ãã®ã³ã°ãšã¢ãã¿ãªã³ã°ã¯å
æ¬çã§ããå SLO ã®ããšã«ãªãå
šãŠã® SLI ãã«ããŒããŠããŸãã å
šãŠã®ã¯ã©ãŠããªãœãŒã¹ã¯ Deployment Manager (Google Cloud), Terraform (Hashicorp) ãªã©ãçšããŠããã°ã©ã ã§è¡ãããŸãã æ¬çªç°å¢å
šäœããæ°å以å
ã§å¥ãŸãŒã³ãå¥ãªãŒãžã§ã³ã«åæ§ç¯ã§ããããã«ãªã£ãŠããŸãã 2-2-4. Secure (ã»ãã¥ã¢) é¢é£ãšããã¯: ã¢ã¯ã»ã¹ç®¡ç , ããŒã¿ãããžã¡ã³ã , ID (ã¢ã€ãã³ãã£ãã£) 管ç Tactical (æŠè¡æ®µé) ID 㯠Google ã«ãã£ãŠã®ã¿çºè¡ Owner, Editor, Viewer ãšãã£ãåºæ¬ããŒã«ã®ã¿å©çš (Google Cloud ã®å Žå) å¢çåã»ãã¥ãªãã£ã«äŸåãããã©ã€ããŒããããã¯ãŒã¯å
ãæé»çã«ä¿¡çšããŠã ãã®æ®µéã§ã¯ãå©çšè
ã® ID 㯠Cloud Identity (â») ã«ãã£ãŠç®¡çãããŠãããããã Google Analytics ã Adwords, YouTube ãªã©ã®ä»ã® Google ãµãŒãã¹ã®ã¢ã«ãŠã³ãã«ããªããŸãã ã¢ã«ãŠã³ããäŒæ¥ã«ãã£ãŠç®¡çãããŠããç¶æ
ã§ãã ããããªããããŸã Microsoft Active Directory ãªã©ã®äŒæ¥ã®äžå€®ãã£ã¬ã¯ããªãšã¯åæãããŠããŸããã â» Cloud Identity = Google Cloud (GCP) ã® ID ã管çããããã®ä»çµã¿ã Amazon Web Services (AWS) ã®å Žåã¯ãããã IAM User ãšèªã¿æ¿ããŠå·®ãæ¯ããªãã Cloud IAM ã§ã¯ Owner, Editor, Viewer (â») ãšãã£ããéåžžã«åŒ·ãæš©éãæã£ãåºæ¬ããŒã«ã®å©çšãã»ãšãã©ã§ãã ããã¯ãæå°æš©éã®ååãå®ã£ãŠããªãç¶æ
ãšãããŸãã æš©éèšå®ãããã©ã«ãã®ãŸãŸãªã®ã§ã Google Cloud (GCP) ãŠãŒã¶ãŒã¯å¥œãã«ãããžã§ã¯ããè«æ±å
ã¢ã«ãŠã³ããäœæã§ããŠããŸãç¶æ
ã§ãã IAM æš©é㯠Forseti Security ã®ãããªããŒã«ã䜿ã£ãŠã¢ãã¿ãªã³ã°ãããŠããŸããã Cloud Audit Logs (â») ã®ç®¡çã¢ã¯ãã£ããã£ç£æ»ãã°ãããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ã¯ã·ã¹ãããã£ãã¯ã«ãã§ãã¯ãããŠããŸããã ãµãŒãã¹ã¢ã«ãŠã³ã (â») ã®äœæãå¶éãªãã§èªç±ã«äœæã§ããç§å¯éµãèªåããŒããŒã·ã§ã³ãããŸããã â» Owner, Editor, Viewer = 管çè
çšãç·šéè
çšãé²èЧè
çšã®åŒ·ãæš©éãæã€ããŒã«ã§ããããžã§ã¯ãå
ã®å
šãŠã®ãªãœãŒã¹ã«å¯ŸããŠåŒ·ãæäœæš©éãæã€ã AWS ã§ããã° Administrator ã ReadOnlyAccess ãšãã£ã AWS å®çŸ©ã® IAM ããªã·ãŒãè©²åœ â» Cloud Audit Logs = ç£æ»ãã°ãä¿åããä»çµã¿ã åœç€Ÿããã° ã«è©³ããã AWS ã§ããã° AWS CloudTrail ãè©²åœ â» ãµãŒãã¹ã¢ã«ãŠã³ã = ã¢ããªã±ãŒã·ã§ã³ãªã©äººé以å€ã Google Cloud API çãã³ãŒã«ãããšãã«çšããã¢ã«ãŠã³ããåœæã®èšè¿°ã¯ AWS ã§ããã° Amazon EC2 çšã® IAM Role ã§ãã£ããããã°ã©ã çšã® IAM User ããçºè¡ããã Credentials ãèªç±ã«çºè¡ã§ããç¶æ
ãæå³ããŠãã ãããã¯ãŒã¯ã»ãã¥ãªã㣠(å¢çåã»ãã¥ãªãã£) ãéä¿¡ãããŠããããã¡ã€ã¢ãŠã©ãŒã«ãéèŠãªã»ãã¥ãªãã£ã³ã³ããŒãã³ãã§ãã IP ã¢ãã¬ã¹ãããŒãçªå·ãšãã£ãæ
å ±ã«åºã¥ããŠã¢ã¯ã»ã¹ãå¶éãããŸãã ã¯ã©ãŠããšãªã³ãã¬ãã¹éã®é信㯠VPN ãã³ãã«ãªã©ã«ããæå·åã¯ãªãããŠãããã®ã® TLS ã«ãããšã³ãããŒãšã³ãã®æå·åã«ã¯ããŸãé¢å¿ãæãããŠããŸããã VPC Service Controls (â») 㯠Cloud Storage ã BigQuery ãšãã£ããã«ãããŒãžããµãŒãã¹ã«å¯ŸããŠé©çšãããŠããŸãããããŒã¿ã®æ©å¯æ§ã«å¿ããŠã«ãŒã«ãèšèšãããŠããç¶æ
ã«ã¯éããŠããŸããã â» VPC Service Controls = Google Cloud (GCP) ã® API ãã³ã³ããã¹ãæ
å ±ã«å¿ããŠä¿è·ããããã®ä»çµã¿ã åœç€Ÿããã° ã«è©³ããã Strategic (æŠç¥æ®µé) ID ã¯äŒæ¥ã®ãã£ã¬ã¯ããªããåæããã æå°æš©éã®ååã«åºã¥ããŠå®çŸ©æžã¿ IAM Role ãå©çšããã (Google Cloud ã®å Žå) ãããã¯ãŒã¯ã¬ã€ã€ãšã¢ããªã±ãŒã·ã§ã³ã¬ã€ã€ã®ãã€ããªããã»ãã¥ãªãã£ã¢ãã« ã¯ã©ãŠããŠãŒã¶ãŒã® ID 㯠Active Directory ã OpenLDAP ãšãã£ãäŒæ¥ã®ãã£ã¬ã¯ããªãµãŒãã¹ãã Google Cloud Identity ã«åæãããŠãããããæŽåæ§ããããéçšãã·ã³ãã«ã§ãã ãŠãŒã¶ãŒã¯åæããããã¹ã¯ãŒãã§èªèšŒãããããããã¯ãµãŒãããŒãã£ã® SSO (Single-Sign On) ãµãŒãã¹ã§èªèšŒãããŸãã 100% ã®ãŠãŒã¶ãŒã¯ SMS (ã·ã§ãŒãã¡ãã»ãŒãž) ãã¯ã³ã¿ã€ã ã³ãŒãçæã¢ããªã䜿ã£ãäºæ®µéèªèšŒã䜿ã£ãŠããããã£ãã·ã³ã°æ»æãªã©ã®å¯Ÿçãšãªã£ãŠããŸãã Cloud IAM ããªã·ãŒã«ãããŠã¯ããããã£ã±ãªåºæ¬ããŒã«ã®å©çšã¯ãããŠããã现ããæš©éå®çŸ©ãããŠããäºåå®çŸ©ããŒã« (â») ãå©çšããŠããŸãã Google Cloud (GCP) ã§ããã©ã«ãã§ä»äžãããŠãã ãããžã§ã¯ãäœæè
( Project Creator ) ããŒã«ãš è«æ±å
ã¢ã«ãŠã³ãäœæè
( Billing Account Creator ) ããŒã«ã¯ Google Cloud çµç¹ã¬ãã«ããã¯åé€ãããŠããåºæ¬çãªã¯ã©ãŠããªãœãŒã¹ã®ã¬ããã³ã¹ã確ä¿ãããŠããŸãã â»äºåå®çŸ©ããŒã« = åºæ¬ããŒã«ä»¥å€ã®ããªã»ããã® IAM ããŒã«ãäŸãšããŠã BigQuery 管çè
ãã®ããã«çšéå¥ã«æš©éãäºãå®çŸ©ãããŠããã®ã§å©çšè
ã¯çްããæš©éãèšå®ããå¿
èŠããªãã AWS ã§ã¯ AWS IAM ã®ãAWS 管çããªã·ãŒããè©²åœ VPC ã®å¢çã»ãã¥ãªãã£ã¯ãã¡ã€ã¢ãŠã©ãŒã«ã ãã§ãªã Cloud Load Balancing (TLS æå¹å) ã Cloud Identity-Aware Proxy (IAP) ã Cloud Armor ãªã©ã§åŒ·åãããŠããŸãã ãããã¯ãããªãã¯ãªã€ã³ã¿ãŒãããã«ãµãŒãã¹ãæãããšã«ããããªã¹ã¯ãäœæžåãããã®ã§ãã Transformational (æè»æ®µé) å
šãŠã®ã¢ããªéã¢ã¯ã»ã¹ã«å¯ŸããŠèªèšŒã»èªå¯ãè¡ããã IAM ããªã·ãŒãç¶ç¶çã«ã¢ãã¿ãªã³ã°ããä¿®æ£ããã ã€ã³ã¿ãŒããããã VPC ã«è³ããŸã§ã®å€å±€ãããã¯ãŒã¯ã»ãã¥ãªã㣠å
šãŠã®ãµãŒãã¹ééä¿¡ã¯èªèšŒã»èªå¯ãããŸããåäž VPC ãåããã©ã€ããŒããããã¯ãŒã¯ã«ããããŒãå士ã§ããä¿¡é Œã¯ããŸããã VPC ã®ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãã IP ã¢ãã¬ã¹ã¬ã³ãžã«ãã£ãŠã§ã¯ãªãããµãŒãã¹ã¢ã«ãŠã³ãã«ãã£ãŠèš±å¯ãããŸã (â») ã â»ãµãŒãã¹ã¢ã«ãŠã³ãã«ãããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã« = Google Cloud (GCP) ã®ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã§ã¯ã IP ã¢ãã¬ã¹ãããŒãçªå·ã«ããèš±å¯ / ãããã¯ãšããäžè¬çãªã«ãŒã«ã䜿ãããšãã§ãããã VM ã«ä»äžãããããã¯ãŒã¯ã¿ã°ã«ããã«ãŒã«ãã VM ã«ä»äžãããµãŒãã¹ã¢ã«ãŠã³ãã«ããã«ãŒã«ãå©çšããããšãã§ãã ã©ã®ããŒã¿ã¹ãã¢ã«ã©ã®ãããªããŒã¿ãå
¥ã£ãŠãããããšããããšãå
šäœçã«çè§£ãããŠãããããããã«èªèšŒãããæããã¢ã¯ã»ã¹ãäžé©åãªã¢ã¯ã»ã¹ã«å¯Ÿå¿ããã»ãã¥ãªãã£ã¢ãã«ã»ããŒã¿ã¬ããã³ã¹ã¢ãã«ãé©åã«èšèšããããšãã§ããŸãã 100% ã®ã¯ã©ãŠãå©çšè
ãããŒããŠã§ã¢ã»ãã¥ãªãã£ããŒãäºæ®µéèªèšŒã«äœ¿ã£ãŠããããããã£ãã·ã³ã°æ»æãžã®å¯Ÿçã¯ååã§ãã SMS (ã·ã§ãŒãã¡ãã»ãŒãž) ãã¯ã³ã¿ã€ã ã³ãŒãçæã¢ããªãååã«å®å
šã§ã¯ãªããšèªèãããŠããŸãã Cloud Audit Logs ã®ç®¡çã¢ã¯ãã£ããã£ç£æ»ãã°ãããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ã¯å®æçã«ç£æ»ãããäºåã«å®çŸ©ããè
åšãã¿ãŒã³ã«äžèŽããå Žåã¯ã¢ã©ãŒããèªåçºå ±ãããããã«èšå®ãããŠããŸãã Cloud IAM ã®æš©éããã¡ã€ã¢ãŠã©ãŒã«ã®ã«ãŒã«ã¯ç¶ç¶çã«ã¢ãã¿ãŒããã Forseti Security ã®ãããªããŒã«ã§ä¿®æ£ãããŸãã 2-3. ãšãã㯠ã¯ã©ãŠãæçåºŠãæž¬å®ã§ããããæ¬¡ã¯å
·äœçãªã¢ã¯ã·ã§ã³ã§ããããã§ãšããã¯ã䜿ããŸãã ãšããã¯ã¯ã人 (People) ããããã»ã¹ (Process) ããæè¡ (Technology) ãã«åé¡ãããŠããŸãã Fine-tuning your direction with epics - The Google Cloud Adoption Framework ããåŒçšããå³ã翻蚳ãããã® â»åæã§ã¯ä»¥éãåãšããã¯ã¯ã¢ã«ãã¡ãããé ã§èšèŒãããŠãããåœèšäºã§ã¯æ¥æ¬èªã«ç¿»èš³ããŠãããããã®ãŸãŸã®é çªã§èšèŒããã 2-3-1. ã¢ã¯ã»ã¹ç®¡ç ç®ç: é©åãªäºº/ãµãŒãã¹ã ããèªèšŒã»èªå¯ããé©åãªãªãœãŒã¹ã«å¯Ÿããé©åãªæäœãè¡ããããã«ããããš é©åãªã¢ã¯ã»ã¹ç®¡çãã§ããŠããã°ãäžäŸ¿ããæããããããšãªããæå°æš©éã®ååã§ã人/ãµãŒãã¹ãæ¥åã«å¿
èŠãªãªãœãŒã¹ãžã¢ã¯ã»ã¹ã§ããŸãã Google Cloud (GCP) ã§ã¯ Cloud Identity ãš Resource Manager ã®çµã¿åããã§ãããå®çŸã§ããŸãã 2-3-2. ã¢ãŒããã¯ã㣠ç®ç: ãã¹ããã©ã¯ãã£ã¹ãé©åã«æšå¥šããããå°æ¥ãèŠéã«å
¥ããã¯ã©ãŠãã³ã³ãã¥ãŒãã£ã³ã°ãã¹ãã¬ãŒãžã®éžæã«åœ¹ç«ã€èŠéãæäŸããããš ã¢ããªã±ãŒã·ã§ã³ãã¯ã©ãŠããã©ãããã©ãŒã ããã«æŽ»çšã§ããããã«ã¯ã³ã³ãã¥ãŒããã¹ãã¬ãŒãžã®é©åãªéžæãå¿
èŠã§ãããããã«å¯äžããã®ãã¯ã©ãŠãã¢ãŒããã¯ãã£ã§ãã äŸãšããŠãæè»ãªã¹ã±ãŒã©ããªãã£ãåŸãããã«ã¯ãã¢ããªã±ãŒã·ã§ã³ã¯ã¹ããŒãã¬ã¹ãªãã€ã¯ããµãŒãã¹æ§æãšããæ°žç¶ã¹ãã¬ãŒãžãšã¯åé¢ããããåçŸæ§ãšã»ãã¥ãªãã£ã確ä¿ããããã«ãæäœæ¥ã§ã®ãããåœãŠãã¡ã³ããã³ã¹ãæé€ããããã®ããã€ã³ãã©ã¯ã³ãŒãå®çŸ©ãšããã€ãã¥ãŒã¿ãã«ãªãã®ã«ããããšãã£ããã®ã§ãã ã¢ããªã±ãŒã·ã§ã³ãããŒã¿ãŠã§ã¢ããŠã¹ããã€ãã©ã€ã³ãªã©ã®ã¹ã±ãŒã©ããªãã£ã»å¯çšæ§ã»è²»çšè² æ
ãæ®µéçã«å€ããŠããããšããŸãéçºã¹ããŒããåäžãããŠããããšã¯ãã©ã®ãããªããžãã¹ã§ãå¿
é ã ãšèããããŸãã 2-3-3. æ¯ãèã ç®ç: ããããŒã ãšããŠåããããããããåãæã®æ°æã¡ãèããã³ãã¥ãã±ãŒã·ã§ã³ãåããããã«ããããã¹ãã«åäžããã°ã©ã ããããå€ããåŸããããããã®ãæ¯ãèãããå©é·ãããã·ã¹ãããã£ãã¯ãªæ¹æ³ãéçºããããš äººã®æ¯ãèãã® 90% 以äžã¯ç¡æèã®ã¢ãããŒã·ã§ã³ã䟡å€èгã信念ãç¿æ
£ããèµ·ããã®ã ãšãããŸãã æåããã¯ã©ãŠãå°å
¥ã«ã¯ãæèçãªè¡åã ãã§ãªãããã€ã³ãã»ããã䟡å€èгã«ãçç®ããå¿
èŠããããŸãã Learn (åŠç¿) ã Lead (ãªãŒã) ãããŸããããã©ããã¯ã人ã
ãæ¬¡ã®ãããªæ°ããæ¯ãèããåãå
¥ãããããã©ããã«ããã£ãŠããŸãã äŸ: ã³ã©ãã¬ãŒã·ã§ã³ãæ¹å€ããªãæåãå¿ççå®å
šæ§ããããã¿ã€ãã³ã°ãããŒã¿ããªãã³ãªæææ±ºå® çµç¹ã®ãçŸåšã®æ¯ãèãããšãç®æãã¹ãæ¯ãèããã®äž¡æ¹ãçè§£ããŠããç®æãã¹ãæ¯ãèããã«è¡ãçãããã®è¡çšãèšèšããããšãæçµãŽãŒã«ã§ãã 2-3-4. CI/CD (Continuous integration and delivery) ç®ç: CI/CD ãã€ãã©ã€ã³ã«ããã·ã¹ãã ãžã®å€æŽãèªååããæå°ã®äžææéã§å
šãŠã®å€æŽããã¹ããããç£æ»ããããããã€ãããããã«ããã㚠巚倧ãªåæ£ã·ã¹ãã ã§ã¯äžæç¹ãäŸåé¢ä¿ãéšåã«ãã£ãŠè²¬ä»»éšçœ²ãéããªã©ãã³ãŒããžã®å€æŽãæå³éãã«åããªãå¯èœæ§ã«ç¹ããäžç¢ºå®èŠçŽ ãå€ããªããã¡ã§ãã ããžãã¹ã«ãšã£ãŠãäžç¢ºå®èŠçŽ ã¯ãªã¹ã¯ããœãããŠã§ã¢ããªããªãŒã®é
å»¶ã«ç¹ãããŸãã CI/CD (Continuous integration and delivery) ã«ãã£ãŠç¶ç¶çã«ãªãªãŒã¹ããã»ã¹ãæ€èšŒããããšã§ãã©ããªã³ãŒã倿Žã§ãæå³éãã«åããšããèªä¿¡ã«ç¹ãããŸãã 2-3-5. ã³ã¹ãã³ã³ãããŒã« ç®ç: ã³ã¹ãããã¢ãªã¢ã«ã¿ã€ã ã§å¯èŠåããããšã§ãéçºè
ãã¢ãŒããã¯ãã«ã³ã¹ãæèãæãããããš ã¯ã©ãŠãã§ã¯åæããå¿
èŠãªèª¿éããªããè³ç£åã«ããæžäŸ¡ååŽã«åºã¥ãè€æ°å¹Žã®ãã£ãã·ãã£èšç»ããããŸããããã®ãããã³ã¹ãã³ã³ãããŒã«ã¯äžäººã®ãœãããŠã§ã¢ãšã³ãžãã¢ããå§ãŸãããšããããŸãã ãªã³ãã¬ã§ã¯ç©ççãªå¶çŽããããŸããããã¯ã©ãŠãã§ã¯ä»£ããã«ãªãœãŒã¹ã¯ã©ãŒã¿ (ãœãããŠã§ã¢çãªäžé) ããªãŒãã¹ã±ãŒãªã³ã°ã®èšå®ãããã®ã¿ã§ãã é©åãªããã·ã¥ããŒãã»ã¢ã©ãŒãèšå®ã»ããã»ã¹ã®ç¢ºç«ããªããã°ãè€æ°ãããžã§ã¯ãã»è€æ°ããŒã ã»è€æ°äºæ¥éšéã«ããã¯ã©ãŠãæ¯åºã管çããããšã¯ãé£æåºŠãé«ãæéãããããã®ãšãªã£ãŠããŸããŸãã ç©ççå¶çŽããªããããã¢ããªã±ãŒã·ã§ã³ã®ææéšéã¯ã次ã®3ã€ã®æŠç¥ã®ãã¡ã©ãããéžã³ãå®è¡ããå¿
èŠããããŸãã ç¡å¶éã®ã¹ã±ãŒãªã³ã° (äŸ: E ã³ããŒã¹ãµã€ã) åŸã
ã«åæžãã (äŸ: 瀟å
ã®ããŒã¿åæ) äžéãèšãã (äŸ: éçºçšãµã³ãããã¯ã¹) 2-3-6. ã³ãã¥ãã±ãŒã·ã§ã³ ç®ç: ã倱æããªãŒãã³ã«å
±æããããšãæšå¥šãããã¹ã¯æ¹åã®æ©äŒãšããŠæè¿ãããããšãã£ã颚朮ã®åå°ãšãªãããã«ãæ¹å€ãããªãæåããªãŒãã³ã³ãã¥ãã±ãŒã·ã§ã³ã®æåãçè§£ããŠãéžæããããš ããã«ã¡ã§ã¯ãœãããŠã§ã¢ã®ããªããªãŒã¯é床ãéããè€éã§ãããã®ãããªäžã§çµç¹ã¯ã倱æãé害ã¯äžå¯é¿ã§ããããã¹ã¯æ¹åã®è¯ãæ©äŒã§ããããšããããšãçè§£ããå¿
èŠããããŸãã å¿ççå®å
šæ§ãäœãåºããæ¹å€ã®ãªãè·å Žãéžæãããªã¹ã¯åãããšã奚å±ããããã¹ã®è²¬ä»»ã¯å人ã§ã¯ãªãä»çµã¿ãããã»ã¹ã«ãããšããæåã§ããããšã¯ããã¯ãå¿
é ã§ãã ãŸããã¹ãã¢ãŒãã (åè¿°) ã¯ãæ¹å€ããªãæåã»åŠã³ç¶ããæåã»ä»çµã¿ã®æ¹åã®æåãéžæãã倧äºãªããŒã«ãšãªããŸãã 2-3-7. ããŒã¿ãããžã¡ã³ã ç®ç: ã©ããªããŒã¿ãä¿ç®¡ãããŠãããåºèªã¯ã©ãã§ãã©ããããæ©å¯æ§ãããã誰ãã¢ã¯ã»ã¹å¯èœãªã®ãããšãã£ãããšãçè§£ããŠç®¡çããããšã§ãããŒã¿ã®å®å
šãå®ããæ€çŽ¢å¯èœã§ãå©çšå¯èœã«ããããš ããŒã¿ãããžã¡ã³ãã匱ããšãããŒã¿æŒæŽ©ãããã«ããä¿¡é Œå€±å¢ãèŠå¶åœå±ã«ããå¶è£ãªã©ã®çµæã«ç¹ãããŸãã æå·åãåé¡ãæŒæŽ©å¯Ÿçãã³ã³ãã©ã€ã¢ã³ã¹èŠæ Œã®é å®ãªã©ã¯ãã¡ããã®ããšãããŒã¿ãããžã¡ã³ãã§ã¯ä»ã«ãå€ãã®äºé
ãæ€èšããå¿
èŠããããŸãã 2-3-8. å€éšã®ç¥èŠ ç®ç: ãšãã¹ããŒãã®æ¯æŽã«ããããã¹ããã©ã¯ãã£ã¹ãé©çšããä»çµç¹ã®ã¯ã©ãŠãå°å
¥æã®æèšãåŠã¶ããšã§ãã¯ã©ãŠãå°å
¥ãå éããããš ç¥èã¯ãã¬ãŒãã³ã°ãªã©ããåŸãããšãã§ããŸãããããçµéšã¯ããããããŸããã ãããã£ãçµéšãããã°ãåé¡ãæ©æ¥ã«è§£æ±ºããããäºæž¬äžå¯èœãªãªã¹ã¯ã«å¯ŸåŠããããç¹å®ã®ããžãã¹ããŒãºã«ãã£ãããããœãªã¥ãŒã·ã§ã³ãå¹ççã«éçºããããšãã§ããŸãã ã¯ã©ãŠãå°å
¥ã®åææ®µéã§ã¯ãçµç¹ã®å€éšã«æ¯æŽãæ±ããããšãæå¹ãªçãšãªãåŸãŸãã Google ã®ããŒãããŒããããã§ãã·ã§ãã«ãµãŒãã¹ (â») ã Office of the CTO (â») ããœãªã¥ãŒã·ã§ã³ã¢ãŒããã¯ã (â») ãªã©ãæ¯æŽå¯èœã§ãã â»ãããã§ãã·ã§ãã«ãµãŒãã¹ã Office of the CTO = ãããã Google Cloud ã®ã³ã³ãµã«ã¿ã³ããµãŒãã¹ â»ãœãªã¥ãŒã·ã§ã³ã¢ãŒããã¯ã = ã¯ã©ãŠãã§ã®ã¢ãŒããã¯ãã£èšèšã«ç²Ÿéãããšã³ãžã㢠2-3-9. ID (ã¢ã€ãã³ãã£ãã£) 管ç ç®ç: 人ãããã¯ãµãŒãã¹ãžã®ä¿¡é ŒããèªèšŒãæäŸããããšãããã³èªèšŒæ
å ±ã®æŒæŽ©ããªãããŸãã«å¯Ÿçããã㚠人ãããã€ã¹ã®ã¢ã€ãã³ãã£ãã£ç®¡çã«ä¿¡é Œããããããšã¯ãçŸä»£çãªã»ãã¥ãªãã£ã¢ãã«ã§ã¯å¿
é ã§ãã çŸä»£çãªã»ãã¥ãªãã£ã¢ãã«ã«ãããŠã¯ãåäžèŠçŽ ã ããä¿¡é Œããããšã¯ãããŸããã ãã¹ã¯ãŒããèšŒææžã IP ã¢ãã¬ã¹ãšãã£ãèŠçŽ ã¯åäžã§ã¯ä¿¡é Œã®å¯Ÿè±¡ã«ã¯ãªãåŸãŸããã 代ããã«è€æ°èŠçŽ ãçµã¿åãããããšã§ãã©ããªãããã¯ãŒã¯ããã®ã¢ã¯ã»ã¹ãå¯èœã«ããŸãã 2-3-10. ã€ã³ã·ãã³ã管ç ç®ç: å
補ããã³ Google ã®ãµããŒãã®ããšã§ãäºå®å€ã®ãµãŒãã¹äœäžããç§©åºæ£ããè¿
éã«ãã¢ã©ãŒãçºå ±ã»ããªã¢ãŒãžã»æŽçããããš ã·ã¹ãã éçšã§ã¯å¹ççã§å¹æçãªãµããŒãæäŸããè¿
éãªãµãŒãã¹åŸ©æ§ãæ±ããããŸãã ã¯ã©ãŠãå°å
¥ã«ãããŠã¯ãã¹ãã«ã®ã®ã£ãããéçšããã»ã¹ã®ã®ã£ãããçºçãåŸãŸãã ãœãªã¥ãŒã·ã§ã³ã®æé©åã皌åçåäžãããžãã¹äŸ¡å€ã確ä¿ããããã«ã¯ããããã®ã®ã£ããã¯æ£ãå¿
èŠããããŸãã é©åãªãµããŒãäœå¶ãæ§ç¯ããããšã§ããµãŒãã¹äžæã®ãªã¹ã¯ãäžããããäžæãèµ·ãã£ããšãã§ã圱é¿ç¯å²ãæå°åãããããããšãã§ããŸãã ããŒã«ããµãŒãã¹æ§ç¯ã«äœ¿ã£ãŠãããã©ãããã©ãŒã ãæå€§éå©çšããããšãéèŠã§ãã 2-3-11. Infrastructure as Code (IaC, ã€ã³ãã©ã®ã³ãŒãå) ç®ç: èšå®å€ãæ§ç¯ãã³ãŒãåããããšã§èªååãã人çãã¹ãæ²æ»
ããæéãç¯çŽããå
šã¹ããããããã¥ã¡ã³ãåããããš ã€ã³ãã©ãããã°ã©ã åããããšã«ããèšå®å€ãšãªãœãŒã¹ã®å±éãèªååããã°ãæ°Žå¹³ã¹ã±ãŒã«ã»èªåã¹ã±ãŒã«ãå¯èœã«ãªããŸãã ãŸããµãŒããžã® admin/root æš©éã¢ã¯ã»ã¹ãçŠæ¢ããããéçºç°å¢ãæ°åã§å±éããããæ¬çªç°å¢ããå®å®ããŒãžã§ã³ãšæ°ããŒãžã§ã³ã®éãããŠã³ã¿ã€ã ãªãã§åãæ¿ããããšãå¯èœã«ãªããŸãã 2-3-12. èšæž¬ ç®ç: ãªãœãŒã¹ã®çšŒåç¶æ³ããã°ã€ãã³ããèšæž¬ããã¢ããªã±ãŒã·ã§ã³ããã¬ãŒã¹ã»ãããã¡ã€ãªã³ã°ã»ãããã°ããããšã§ãæ§ã
ãªç¶æ³äžã§ã®ã·ã¹ãã ã®æåãç£èŠãã SLO ãå®éåããããš å
æ¬çãªèšæž¬ãè¡ãããšã¯ãã¯ã©ãŠãã§ã¯äžå±€éèŠã«ãªããŸãã èšæž¬ãããã¡ããªã¯ã¹ (ææš) ã«ãã£ãŠãã¯ã©ãŠããªãœãŒã¹ããã€ãã©ã®ããã«ã¹ã±ãŒã«ããããæ±ºãŸããŸãããé害æãããã©ãŒãã³ã¹äœäžæã«ã¯ãåå ãã¯ã©ãŠããµãŒãã¹åŽãªã®ãã¢ããªã±ãŒã·ã§ã³åŽãªã®ãã倿ããéèŠãªèŠçŽ ã«ãªããŸãã ãŸããã¯ã©ãŠãã«ãããå
šãŠã®æäœã¯ API ã³ãŒã«ãªã®ã§ã誰ããã©ã®ãªãœãŒã¹ã«å¯ŸããŠãã©ã®ãããªæäœãè¡ã£ãããšããç£æ»ãã°ãå
æ¬çãã€å€æŽäžå¯èœãªåœ¢ã§æ®ãããšã§ãã¯ã©ãŠãéçšãæ¬è³ªçã«ã»ãã¥ã¢ã«ããããšãã§ããŸãã 2-3-13. ãããã¯ãŒãã³ã° ç®ç: èªèšŒã»èªå¯ã®æç¡ãšã¯å¥è»žã§ããµãŒãã¹ãããŒã¿ã®æµããè«ççå¢çã«ããæ¥ç¶ã»ä¿è·ããããš ãããã¯ãŒã¯ã¯ã©ã®ãããªããžãã¹ã«ãšã£ãŠãéèŠãªã€ã³ãã©ã§ãããããã¯ãŒã¯ã¯é¡§å®¢ãšãµãŒãã¹ãç¹ãããšã³ããŠãŒã¶ãŒãšããžãã¹ãç¹ããåŸæ¥å¡ã®ä»äºãå¯èœã«ããŸãã ããã«ã¡ã®ããžãã¹ã¯ãæ¥ç¶æ§ãªãã«ã¯æãç«ã¡ãŸããããããŠæ¥ç¶æ§ã¯ãçµç¹ (äŒç€Ÿ) ã®å¢çå
ã ãã«ãšã©ãŸããã顧客ãããŒãããŒäŒæ¥ãã€ã³ã¿ãŒãããã«ãåºããå¿
èŠããããŸãã ããã¯ã©ã®ãããªèŠæš¡ã»åœ¢åŒã®ããžãã¹ã§ãåæ§ã§ããããªã³ãã¬ãã¹ã»ã¯ã©ãŠãã»ãã€ããªããã®å¥ãåããŸããã 2-3-14. 人çãªãã¬ãŒã·ã§ã³ ç®ç: å¿
èŠãªçµç¹æ§æãå®çŸ©ããã¯ã©ãŠãå°å
¥æ
åœè
ãã¡ãé©åãªåœ¹è·ã»ã¹ãã«ã»å€åè©å®ææ³ã«åœãŠã¯ããã¯ã©ãŠãå°å
¥ã®åæ»ãå³ãããš çµç¹æ§æã»äººå¡é
眮ã»å€åè©å®ææ³ã調æŽããããšã§ãããŒã ã倿Žãåãå
¥ããŠæ°ãã圹å²ãããªãããšãä¿é²ã§ããŸãã éã«ã IT éšéãéçšéšéãé¢é£ããžãã¹éšéãã©ã®ããã«åãã¹ãããçè§£ãããæåŸ
ãããŠããããšãåãããªãç¶æ
ã ãšæ··ä¹±ãçºçãããã£ããã®ã¯ã©ãŠãç§»è¡ã®ããã®æè³ãžã®æªåœ±é¿ãšãªã£ãŠããŸããŸãã ãŸããã¯ã©ãŠãå°å
¥æ
åœè
ãã¡ãæ°ãã圹å²ãæ°ããæ¯ãèã (ã³ã©ãã¬ãŒã·ã§ã³ãéææ§ã倱æã®èš±å®¹ãä¿¡é Œ) ãåãå
¥ããããšãžã®åæ©ä»ããéèŠã§ãã ãã®ããã®å€åè©å®ææ³ãã€ã³ã»ã³ãã£ãæ§æãå¿
èŠãšãªã£ãŠããŸãã æåŸã«ã枬å®å¯èœã§ãããã€ã¯ã©ãŠãå°å
¥è¡çšãšé£æºãããçµç¹ãšããŠã®ãŽãŒã«ããå®çŸ©ããããšãéåžžã«éèŠã§ãã ãŽãŒã«ãæ¹åä»ãããã¬ããšãã¯ã©ãŠãå°å
¥ã®æåã¯é ã®ããŸãã 2-3-15. ãªãœãŒã¹ç®¡ç ç®ç: ã¯ã©ãŠãç°å¢ã®æŽé ã»äžè²«æ§ç¢ºä¿ã»å¶åŸ¡ã®ãããã¯ã©ãŠããªãœãŒã¹ã®ã¯ã©ãŒã¿ (å²åœãŠäžé) ãæŽçã»æç€ºã»èšå®ããããš ã¯ã©ãŠãã§ã¯èª°ã§ãä»®æ³çã«ãªãœãŒã¹ãçæããããšãã§ããŸããã代ããã«èŠéããæªããªã£ãããåæãªè¡åããããããããåºãŠããŸãã æçšã§åãããããã«ãŒã«ãäœããçµç¹ã®éå±€æ§é ãšåãããŠãã©ã«ããŒã»ãããžã§ã¯ãã®éå±€æ§é (â») ãæ§ç¯ããã°ãã¬ããã³ã¹ãç¶æããç¡ç§©åºç¶æ
ãåé¿ããããšãã§ããŸãã â»ãã©ã«ããŒã»ãããžã§ã¯ãã®éå±€æ§é = Google Cloud (GCP) ã§ã¯ã¯ã©ãŠãç°å¢ã®1ããã³ãã "ãããžã§ã¯ã" ãšåŒã³ãè€æ°ãããžã§ã¯ããã°ã«ãŒãã³ã°ããŠæŽçããåäœã "ãã©ã«ããŒ" ãšåŒã¶ããã©ã«ããŒããããžã§ã¯ãã¯éå±€æ§é ã«ããŠç®¡çããªã·ãŒã IAM æš©éãé©çšã§ãã 2-3-16. ã¹ãã³ãµãŒã·ãã ç®ç: å¹¹éšå±€ããã®ç±å¿ãã€ç¶ç¶çãªæ¯æŽã«ãããã¯ã©ãŠãå°å
¥æ
åœè
ãå€é©ãå§ä»»ãããŠããããšãåºãèªèãããããš ã¹ãã³ãµãŒã·ãããšã¯ãå¹¹éšããªãŒããŒãã¯ã©ãŠãå°å
¥ããŒã ããããžã§ã¯ãã«å¯ŸããŠãèœåçã§ç®ã«èŠããåœ¢ã®æ¯æŽãè¡ãããšããããŸãã çµç¹ã§ã®ã¯ã©ãŠãå°å
¥ã¯è€éã§ããããžãã¹äŸ¡å€ã®å¢å€§ãã³ã©ãã¬ãŒã·ã§ã³æšé²ãé床åäžã®ããã«ãçµç¹èŠæš¡ã§ã¯ã©ãŠãå©çšã決æããã«ããã£ãŠã 匷åãªã¹ãã³ãµãŒã·ããã¯å¿
èŠäžå¯æ¬ ã§ãã å¹¹éšå±€ã¯çµç¹ã§æã圱é¿åãããç«ã¡äœçœ®ã ãã«ãã¯ã©ãŠãå°å
¥æŠç¥ã«å¯ŸããŠç±å¿ãã€ç¶ç¶çãªæ¯æŽãè¡ãããšã§ãã¯ã©ãŠãå°å
¥æ
åœè
ãã¡ãå€é©ãå§ä»»ãããŠããã®ã ãšããããšãåºãèªèãããå¿
èŠããããŸãã 2-3-17. ããŒã ã¯ãŒã¯ ç®ç: ã¯ã©ãŠãæè¡ãæé«å¹çã§æŽ»çšããããããã³ã©ãã¬ãŒã·ã§ã³ãšä¿¡é Œã«åºã¥ãæ¯ãèãã»æåãäœçŸããããŒã ãæ§ç¯ããããš ããŒã ã¯ãŒã¯ã¯ãåã
äººã®æ
åœè
ã«ããããã ã¢ããã®ç念ãªãŒããŒã·ãã (Thought leadership) ããå§ãŸããŸãã ç念ãªãŒããŒã·ãã㯠Center of Excellence (CoE â») ãå°ä»»ãšãã³ãžã§ãªã¹ããéå
¬åŒã®ã¯ã©ãŠã掟ãªã©æ§ã
ãªåœ¢ãåãããŸãå€ãã®ç¥èŠå
±æã®åãçµã¿ãšãªã£ãŠããå ŽåããããŸãã â» Center of Excellence (CoE) = çµç¹ã®äžã§ç¹å®æè¡ãåéã«ãããŠãç ç©¶ã»éçºã»å°å
¥ãªã©ã®ãªãŒããŒã·ãããåãããŒã ã®ããšãç¹ã«ã¯ã©ãŠãã«ãããŠã¯ Cloud Center of Excellence (CCoE) ãšåŒã°ãè¿å¹Žè©±é¡ã«ãªã£ãŠãã ãããã£ãäž»å°è
ãã¡ããã»ãã¥ãªãã£ãã¢ãŒããã¯ãã£ããããã¯ãŒã¯ãéçšãããŒã¿ããŒã¹ç®¡çãªã©ã®èŠåŸã圢äœã£ãŠãããŸãã 圌ãã«å
±éããŠããã®ã¯ãååãã§ããããšãšãã¯ã©ãŠãå°å
¥ã®ãã¹ããã©ã¯ãã£ã¹ã«èªçºçã«é¢å¿ãæã£ãŠããããšã§ãã ãããã£ãäž»å°è
ãããªãå Žåãã¯ã©ãŠãå°å
¥ã¯å¹¹éšå±€ã®ã¹ãã³ãµãŒã·ããã«äŸåããŠããŸããŸã (ã¹ãã³ãµãŒã·ããã®é
ãåç
§)ãããããã®ãããªäžæ¹çãã€ãããããŠã³ã®æ¹çã¯ã¹ã±ãŒã«ãé
ãããŸãã¯ã©ãŠãã®å©ç¹ã§ãã IT ãªãœãŒã¹ã®æ¬è³ªçãªæ°äž»åãšããå©ç¹ã掻çšã§ããªãçµæã«ã話ããå¯èœæ§ããããŸãã 2-3-18. ã¹ãã«åäž ç®ç: çŸè·ã¡ã³ããŒãæã€æ¥åç¥èãæ¢å IT è³ç£ã«é¢ããç¥èŠãšãæ°èŠã«åŠãã ãã¹ããã©ã¯ãã£ã¹ãèåãããããåŠç¿ã«å¯ŸããŠæè³ãããããš ã¯ã©ãŠãã³ã³ãã¥ãŒãã£ã³ã°ã¯ãä»®æ³åã®åºçŸä»¥æ¥ãé¡ãèŠãªããã©ãã€ã ã·ãããšãªã£ãŠããŸãã ãããã®æ°ããèãæ¹ããã¹ããã©ã¯ãã£ã¹ã¯ãããŒã ã®åã
人ã®ã¹ã¿ã€ã«ã«ããããã«ãæ§ã
ãªæ¹æ³ã§åŠç¿ããããšãã§ããŸããå
çãæããã¿ã€ãã®ç ä¿®ãã coursera.com ã qwiklabs.com ã®ããã«ã€ã³ã¿ã©ã¯ãã£ããªèªå·±åŠç¿ã¿ã€ãã®ãã®ã§ãããã§ãããã ã¹ãã«åäžãšã¯ãæè¡çãªçè«ãåŠã¶ããšã ããæãã®ã§ã¯ãããŸãããåŠãã ããšãæ¥åã«æŽ»ãããããèªåã§åé¡è§£æ±ºãã§ããããã«ãããã Google ãµããŒããå©çšããããååãšæèšãå
±æãããããããšã§ãç¶ç¶çã«åŠã¶æåãéžæããããã«ããçµç¹å
šäœã®ç¥èŠãè²ãŠãããšãããéèŠã§ãã ä»é²: ã¯ã©ãŠãæç床ã¢ã»ã¹ã¡ã³ã ãã¯ã€ãããŒããŒã®æèš³ã¯ã以äžã§çµäºã§ãã ãããã㯠Google ã«ããç¡åå
¬éãããŠãããã¯ã©ãŠãæç床ã¢ã»ã¹ã¡ã³ãããŒã«ãã玹ä»ããŸãã 以äžã®ãµã€ãã§å
¬éãããŠãã Web ããŒã«ãçšãããšããã¯ã€ãããŒããŒå
ã§ã玹ä»ãããŠããã¯ã©ãŠãæçåºŠãæž¬å®ããããšãã§ããŸãã digitalmaturitybenchmark.withgoogle.com ç»é¢ã«è¡šç€ºããã質åã«é ã«çããŠãããšãçµç¹ã®çŸåšã®ã¯ã©ãŠãæç床ã4ã€ã®ããŒãã«æ²¿ã£ãŠæž¬å®ããããšãã§ããŸãã 質åã®å
çšãåå³ãããšãä»ã®çµç¹ã«è¶³ããªããã®ãäœããèŠããŠããã¯ãã§ãã 質åã¯è±èªã§ãã®ã§ãèŠæãªæ¹ã¯ Chrome ãã©ãŠã¶ã®ç¿»è𳿩èœãªã©ãé§äœ¿ããŠã掻çšãã ããã ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãTwitter ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-gen ã®ææã§ããGoogle Cloud èªå®è³æ Œã®1ã€ã§ãã Professional Data Engineer èªå®è³æ Œã¯ãGoogle Cloud ã§ã®ããŒã¿ãšã³ãžãã¢ãªã³ã°ãããŒã¿åæã«é¢ããé£é¢è³æ Œã§ããåœèšäºã§ã¯ã詊éšã®åŠç¿ã«åœ¹ç«ã€æ
å ±ãèšèŒããŸãã ã¯ããã« åœèšäºã®å
容 æ³å®èªè
詊éšã®é£æåºŠ æšå¥šã®ååŒ·æ³ åºé¡åŸå ã»ãã¥ãªãã£ãšã¬ããã³ã¹ çµç¹ãIAM å人æ
å ±ã®æ±ã VPC Service Controls BigQuery åºæ¬çãªç¥è é¢é£èšäº å€éšããŒãã«ãš BigLake ããŒãã« ããŒã¿ã®å
±æ Cloud Storage åºæ¬çãªç¥è è€æ°ãªãŒãžã§ã³ãšã¿ãŒãã¬ããªã±ãŒã·ã§ã³ Bigtable åºæ¬çãªç¥è ããŒãã«èšèš éçš é©åãªããŒã¿ããŒã¹ã®éžæ Dataplex Dataplex ã«ããæš©é管ç Dataplex Universal Catalog Dataflow æŠèŠ ãŠã€ã³ã㊠exactly-once èåïŒfusionïŒ ãããã¯ãŒã¯ãšãã¡ã€ã¢ãŠã©ãŒã« ããŒã¿ãã€ãã©ã€ã³ Dataform Pub/Sub Cloud Composer Dataproc DataprepãCloud Data Fusion ããŒã¿ç§»è¡ ãªã³ãã¬ãã¹ããã®ããŒã¿ç§»è¡ ããŒã¿ããŒã¹éã®ããŒã¿ç§»è¡ æ©æ¢°åŠç¿ïŒAI/MLïŒ ãªãã¬ãŒã·ã§ã³ã¹ã€ãŒã åºæ¬ 泚ç®ãã¹ãã¡ããªã¯ã¹ ãã®ä» åéšç°å¢ ã¯ããã« åœèšäºã®å
容 åœèšäºã§ã¯ãGoogle CloudïŒæ§ç§° GCPïŒèªå®è³æ Œã®1ã€ã§ãã Professional Data Engineer èªå®è³æ Œã®åŠç¿ã«åœ¹ç«ã€æ
å ±ã玹ä»ããŸããProfessional Data Engineer èªå®è³æ Œã¯ãGoogle Cloud ã§ã®ããŒã¿ãšã³ãžãã¢ãªã³ã°ãããŒã¿åæã«é¢ããé£é¢è³æ Œã§ãã åè : Professional Data Engineer èªå®è³æ Œ 詊éšã®å©çšèŠçŽã«ãããŠã詊éšã®å
容ãå
¬éããããšã¯çŠããããŠããŸãããã®ããåœèšäºã§ã¯è©Šéšåé¡ãã®ãã®ãæžãããšçã¯ãããäž»ã«ãµãŒãã¹ã«ããã§ã åæ Œããããã«ã¯äœãç¥ã£ãŠããã¹ãã ãšãã芳ç¹ã§æ
å ±ããæäŸããŸãã ãªããåœèšäºã§è©Šéšç¯å²ãå
šãŠã«ããŒã§ããŠããããã§ã¯ãããŸãããå
¬åŒã®è©Šéšã¬ã€ããæš¡æ¬è©Šéšãªã©ãé§äœ¿ããŠãåŠç¿ãé²ããŠãã ããã æ³å®èªè
åœèšäºã¯ä»¥äžã®ãããªæ¹åãã§ãã Professional Data Engineer 詊éšã®åºé¡åŸåãç¥ããã Google Cloud ãµãŒãã¹ãããŒã¿ãšã³ãžãã¢ãªã³ã°ã®åºæ¬çãªç¥èã¯ææ¡æžã¿ã§ãã è¿æ¥äžã«è©Šéšãåããããšæã£ãŠããã®ã§ãç¥èã®ç¢ºèªãããã ãŸãåæç¥èãšã㊠Google Cloud ã®åºç€ç¥èãå¿
èŠã§ãã Associate Cloud Engineer è©Šéš çžåœã®ç¥èŠã¯æã£ãŠããããšãæšå¥šãããŸãã以äžã®èšäºãåèã«ããŠãã ããã blog.g-gen.co.jp 詊éšã®é£æåºŠ Professional Data Engineer 詊éšã®é£æåºŠã¯ã æ¯èŒçé«ã ãšèšããŸãã IPA ã®ãå¿çšæ
å ±æè¡è
詊éšãçšåºŠã®åºæ¬ç㪠IT ã®ç¥èããããã〠Google Cloud ãããçšåºŠæ¥åã§äœ¿çšããçµéšãããããšãæãŸããã§ããããã«å ããŠãããŒã¿ã¢ããªã³ã°ã ETL / ELT ã忣ã¢ãŒããã¯ãã£ã®ããŒã¿åŠçåºç€ã RDBMSãNoSQL ããŒã¿ããŒã¹ãªã©ã®ããŒã¿é¢é£æè¡èŠçŽ ã«é¢ããåºç€ç¥èãå¿
èŠã§ãã ãããã®æ
å ±æè¡ã«é¢ããåºç€ç¥èã®ããã«ãGoogle Cloud ã®ããŒã¿ããŒã¹ãããŒã¿åŠçã«é¢ãããµãŒãã¹ãããµãŒãã¹ã®çµã¿åãããªã©ã«ã€ããŠãæžç±ãå
¬åŒããã¥ã¡ã³ãã§çè§£ããŠããããšå¿
èŠããããŸãã ãŸããæ®æ®µãã Google Cloud ã®å
¬åŒããã°ãããã¥ã¡ã³ãã®ãã¹ããã©ã¯ãã£ã¹ã«ç®ãéããGoogle ã®èãããã¯ã©ãŠããããã¯ã©ãŠãã®äœ¿ãæ¹ããšããäžçš®ã®å²åŠããé ã«ã€ã³ãããããŠããããšãéèŠã§ãã ãããã«å ããŠãåœèšäºã§è¿œå ã®åŠç¿ãããã°ãåæ Œã¯é£ãããªããšèšããŸãã æšå¥šã®ååŒ·æ³ Associate Cloud Engineer ãå
ã«ååŸãã æžç±ãå瀟ã®ããã°çã§ Google Cloud ã®ããŒã¿é¢ä¿ãµãŒãã¹ã®æŠèŠãçè§£ãããç¹ã«ä»¥äžã®ãµãŒãã¹ã«çç®ãã BigQueryãDataplexãDataplex Universal CatalogãCloud StorageãDataflowãPub/SubãCloud ComposerãBigtableãDataprocãBigQuery ML 詊éšã¬ã€ããèªã¿ãåºé¡ç¯å²ãçè§£ãã åœèšäºãèªã¿ãåºé¡åŸåãçè§£ãã ææ¡ãã詊éšç¯å²ã»åºé¡åŸåãããšã«å匷ãã æš¡æ¬è©Šéšãåããè¶³ããªãç¥èãèªèããŠãã®ã£ãããåããå匷ããã 詊éšã¬ã€ããæš¡æ¬è©Šéšãžã®ãªã³ã¯ã¯ã以äžã®å
¬åŒããŒãžãã確èªã§ããŸãã åè : Professional Data Engineer èªå®è³æ Œ åºé¡åŸå åœèšäºã§ã¯ãã以éãåºé¡åŸåãå¿
èŠãªç¥èã解説ããŸããåãããªãèšèãç¥ããªãçšèªãããã°ãå
¬åŒããã¥ã¡ã³ããªã©ã蟿ããååç¥èãã€ããŠãã ããã ãã®ããã«å匷ããã°ã詊éšã«åæ Œã§ããã®ã«å ããå®è·µçãªç¥èãšãªãã§ãããã ã»ãã¥ãªãã£ãšã¬ããã³ã¹ çµç¹ãIAM Identity and Access Management ïŒIAMïŒã® ç¶æ¿ ã®æŠå¿µãããªãœãŒã¹ãšã®çŽã¥ãããŸããªãœãŒã¹éå±€ïŒçµç¹ããã©ã«ãããããžã§ã¯ããåãªãœãŒã¹...ïŒã®æŠå¿µã«ã€ããŠã¯ç¢ºå®ã«çè§£ããŠãã ããã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp ãŸã IAM ãš BigQuery ã®çµã¿åããã®å¿çšãšããŠã æ¿èªããããã¥ãŒ ã®äœ¿ç𿹿³ãåãããŸãããã®æ©èœã«ã€ããŠã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp å人æ
å ±ã®æ±ã å人è奿
å ± ïŒPIIïŒã®æ±ãã«ã€ããŠã¯ãé »åºã§ãã PII ãä¿åããŠå¿
èŠãªãšãã«ã¯åç
§ã§ããããã«ããŠããããããé©åãªæš©éãæã£ãŠãã人以å€ã¯é²èЧã§ããªãããã«ãããããšããå Žåã Sensitive Data Protection ïŒæ§ç§° Cloud Data Loss Preventionã Cloud DLP ïŒã掻èºããŸãã å
ããŒã¿ã«å¯ŸããŠãåé€ããããã¹ãã³ã°ããè¡ã£ãŠäžæžããããšåœç¶ãå
ã®ããŒã¿ã倱ãããŠããŸããŸããäžæ¹ã§ æå·ããŒã¹ã®ããŒã¯ã³å倿 ãšããææ³ã®ãã¡ ãã©ãŒãããä¿ææå·å ã 確å®çæå·å ã䜿ããšãæå·éµãžã®æš©éããããã°å床ãå
ã®å€ã埩å
ã§ããŸããå察㫠æå·ããã·ã¥å ãããŠããŸããšå
ã®å€ã«æ»ããªãïŒäžå¯éïŒã§ããç¹ã«æ³šæããŠãã ããã åè : æå·ããŒã¹ã®ããŒã¯ã³å倿 VPC Service Controls VPC Service Controls ã¯ãGoogle Cloud ã® API ãšããŒã¿ãä¿è·ããããã®ä»çµã¿ã§ãã以äžã®èšäºãèªãã§ãæŠèŠãææ¡ããŠãã ããã blog.g-gen.co.jp VPC Service Controls ã®å¢çïŒperimeterïŒã«ã¯ããããžã§ã¯ããŸã㯠VPC ãããã¯ãŒã¯ã远å ããããšãã§ããŸããVPC ãããã¯ãŒã¯ã ãã远å ããŠãããããžã§ã¯ãã® API ã¯ä¿è·ãããªãç¹ã«æ³šæããŠãã ããã BigQuery åºæ¬çãªç¥è Google Cloud ã®èªããã«ãããŒãžããªããŒã¿ãŠã§ã¢ããŠã¹ã§ãã BigQuery ã¯ãåœè©Šéšã§æãåºé¡ããããããã¯ãã§ãããŸãã¯ä»¥äžã®èšäºã§ãBigQuery ã®æ©èœãçšèªãäžéãçè§£ããŠãã ããã blog.g-gen.co.jp blog.g-gen.co.jp BigQuery 以äžã®ãããªæŠå¿µãçè§£ããŠããã°ãå€ãã®åé¡ã«çããããšãã§ããŸããçšèªãããã¥ã¡ã³ãã®æèšã§ã¯ãªããæŠå¿µãšããŠè
¹èœã¡ãããŸã§çè§£ããããã«ããŠãã ããã BigQuery ã®ç¹è³ª åå¿åã¹ãã¬ãŒãž 忣ã¢ãŒããã¯ã㣠ã¹ããããšäºçŽïŒReservationïŒ ããŒãã£ã·ã§ãã³ã°ãšã¯ã©ã¹ã¿ãªã³ã° æš©é管ç IAM æ¿èªæžã¿ãã¥ãŒãæ¿èªæžã¿ããŒã¿ã»ãã BigQuery SharingïŒæ§ç§° Analytics HubïŒ åã¬ãã«ã®ã¢ã¯ã»ã¹å¶åŸ¡ãè¡ã¬ãã«ã®ã»ãã¥ãªã㣠ããã¯ã¢ãããšã¿ã€ã ãã©ãã« ãã±ãŒã·ã§ã³éžæã«ãŠãã«ããªãŒãžã§ã³ãéžæããæå³ ã¹ããªãŒãã³ã°ã€ã³ãµãŒãïŒã¡ãªãããšãã¡ãªããïŒ é¢é£èšäº äžèšã®åŠç¿ã«ããã£ãŠã¯ã以äžã®èšäºãåèã«ããŠãã ããã blog.g-gen.co.jp blog.g-gen.co.jp blog.g-gen.co.jp blog.g-gen.co.jp blog.g-gen.co.jp å€éšããŒãã«ãš BigLake ããŒãã« BigQuery ã§ã¯ã å€éšããŒãã« ãå®çŸ©ããããšã§ãCloud Storage äžã® CSV ã Parquet ãšãã£ã圢åŒã®ãã¡ã€ã«ã«å¯ŸããŠããªã¢ã«ã¿ã€ã ã«ã¯ãšãªãå®è¡ããããšãã§ããŸãããŸããå€éšããŒãã«ã®çºå±çã§ãã BigLake ããŒãã« ãžã®çè§£ãå¿
èŠã§ãã åè : BigQueryã培åºè§£èª¬ïŒ(å¿çšç·š) - BigLake BigLake ããŒãã«ã«ã¯ ã¡ã¿ããŒã¿ãã£ãã·ã¥ æ©èœããããããã©ãŒãã³ã¹åäžã«ã€ãªãããŸãã åè : å€éšããŒãã«ã®ã¡ã¿ããŒã¿ã®ãã£ãã·ã¥ä¿å ããŒã¿ã®å
±æ BigQuery SharingïŒæ§ç§° Analytics HubïŒã䜿ããšãå°ãªãåŽåã§ä»ã®çµç¹ã« BigQuery ããŒã¿ã»ãããå®å
šã«å
±æã§ããŸããã¢ã¯ã»ã¹å¶åŸ¡ãé©åã«è¡ãªã£ãããã§å
±æã§ããããŒã¿ã®ã³ããŒã¯å¿
èŠãããŸããã åè : BigQuery Sharing ã®æŠèŠ BigQuery SharingïŒAnalytics HubïŒã¯ã éå®å
¬éãªã¹ãã£ã³ã° ã䜿ãããšã§åãçµç¹å
ã§ã®å
±æã«å©çšããããšãã§ããŸãã Cloud Storage åºæ¬çãªç¥è Cloud Storage ã«é¢ããåé¡ãé »åºã§ãã以äžã®èšäºã§ãäžéãã®æ©èœãææ¡ããŠãã ããã blog.g-gen.co.jp è€æ°ãªãŒãžã§ã³ãšã¿ãŒãã¬ããªã±ãŒã·ã§ã³ Cloud Storage ãã±ããã®äœææã«ããã±ãããé
眮ãããªãŒãžã§ã³ãåäžãªãŒãžã§ã³ããã¥ã¢ã«ãªãŒãžã§ã³ããã«ããªãŒãžã§ã³ã®3çš®é¡ã®äžããéžæå¯èœã§ããããã«ãããããŒã¿ã®å¯çšæ§ãå
ç¢æ§ãåäžããŸãããã ãããªãŒãžã§ã³éã®ããŒã¿ã¬ããªã±ãŒã·ã§ã³ã¯éåæã§è¡ããã60å以äžã®é
å»¶ãçºçããå ŽåããããŸãã ããŒã¿ã® RTO ãççž®ããã«ã¯ã ã¿ãŒãã¬ããªã±ãŒã·ã§ã³ ã®æå¹åã广çã§ããæå¹åãããšãè¿œå æéãšåŒãæãã«15å以å
ã§ããŒã¿ã®è€è£œãå®äºããŸãã åè : ããŒã¿ã®å¯çšæ§ãšèä¹
æ§ - ã¿ãŒã ã¬ããªã±ãŒã·ã§ã³ Bigtable åºæ¬çãªç¥è Bigtable ã¯ãGoogle Cloud ã®ãã«ãããŒãžãã® NoSQL ããŒã¿ããŒã¹ã§ããã©ã®ãããªã¢ã¯ã»ã¹ãŠãŒã¹ã±ãŒã¹ã§ Bigtable ãå©çšããã®ãæãŸããã®ãããŠãŒã¹ã±ãŒã¹ãæŒãããŠãããŠãã ããã 以äžã®èšäºãåèã«ããŠäžããã blog.g-gen.co.jp ããŒãã«èšèš ã¹ããŒãèšèšã«ã€ããŠã¯ããã¥ã¡ã³ããããèªã¿èŸŒãã§ãããç¹ã«å€§äºãªè¡ããŒã®èšèšã¯ããçè§£ããŠãããŸããããŒãã«ãåãã¡ããªãŒãåãè¡ãã»ã«ãè¡ããŒãšãã£ãæŠå¿µãçè§£ããŠãã ããã åºæ¬çã«ãè¡ããŒã«ã¿ã€ã ã¹ã¿ã³ãã䜿ãã®ã¯ããããã©ã¯ãã£ã¹ã§ããã¿ã€ã ã¹ã¿ã³ãã¯é£ç¶ããå€ã«ãªã£ãŠããŸãã®ã§ãããŒã¿æ ŒçŽå
ã®ã¹ãã¬ãŒãžäœçœ®ãéäžããŠããŸãã ãããã¹ããã ã®åå ãšãªããŸãã machine_4223421#1425330757685 ã®ããã«å
é ã«ã«ãŒãã£ããªãã£ã®é«ã ID ãªã©ãšçµã¿åãããŠããŒãšããææ³ã䜿ãããŸãã åè : ã¹ããŒãèšèšã®ãã¹ã ãã©ã¯ãã£ã¹ åè : æç³»åããŒã¿çšã®ã¹ããŒãèšèš éçš ã¢ãã¿ãªã³ã°ãæ¬çªçšã¯ãŒã¯ããŒããšåæçšã¯ãŒã¯ããŒãã®åé¢ïŒ ã¢ããªãããã¡ã€ã« ïŒãã¯ã©ã¹ã¿æ¡åŒµã Key Visualizer ãªã©ã管çéçšé¢ãææ¡ããŠãããŸãããã åè : ã¢ã㪠ãããã¡ã€ã«ã®æŠèŠ é©åãªããŒã¿ããŒã¹ã®éžæ Cloud SQLãFirestoreïŒæ§ DatastoreïŒãSpannerãBigtableãBigQuery ãªã©ãGoogle Cloud ã«ã¯å€çšãªããŒã¿ããŒã¹ãµãŒãã¹ãååšããŠããŸããããããã®ãŠãŒã¹ã±ãŒã¹ããã§ããããšãã§ããªãããšãææ¡ããŠãããŸããããã©ããã£ããŠãŒã¹ã±ãŒã¹ã§ã©ã®ããŒã¿ããŒã¹ãéžã¶ã®ããåçã§ããããã«ããå¿
èŠããããŸãã 以äžã®è¡šãåèã«ããŠãã ããã åç§° Cloud SQL Firestore Spanner Bigtable BigQuery æŠèŠ ãããŒãžãRDBãMySQL / PostgreSQL / SQL Server ãå©çšå¯èœ NoSQL ããŒã¿ããŒã¹ãã¢ãã€ã«ã¢ããªãããããå©çšããã ç¡å¶éã®ã¹ã±ãŒãªã³ã°ãã°ããŒãã«å©çšãå¯èœãªãªã¬ãŒã·ã§ãã«ããŒã¿ããŒã¹ NoSQL ããŒã¿ããŒã¹ãé«ã¹ã«ãŒããããé«ã¹ã±ãŒã©ããªã㣠ããŒã¿ãŠã§ã¢ããŠã¹ãåæç®çã®åæå DB ãŠãŒã¹ã±ãŒã¹ äžè¬çãªã¢ããªãRDB Webãã¢ãã€ã«ãã²ãŒã çã§ KVS ããããããå Žå éèããã«ã¹ã±ã¢ãã²ãŒã çã§ã°ããŒãã«ãªãã©ã³ã¶ã¯ã·ã§ã³ æç³»åããŒã¿ã賌å
¥å±¥æŽãIoT çãé«ã¹ã«ãŒããããé«ã¹ã±ãŒã©ããªãã£ãæ±ãããã SQL ã§ã®åæã ELT çš®é¡ RDB NoSQLïŒããã¥ã¡ã³ã DBïŒ RDB ãã€åæ£ã¢ãŒã NoSQLïŒã¯ã€ãã«ã©ã ïŒ ããŒã¿ãŠã§ã¢ããŠã¹ïŒè¡šåœ¢åŒã»åæåïŒ ã¯ãšãªæ¹æ³ SQL API ããã㯠SQL ã©ã€ã¯èšèª SQL API SQL ãã©ã³ã¶ã¯ã·ã§ã³ â â³ (â») â â (1è¡ã®ã¿å¯) â (â») Firestore ãš Datastore ã§ä»æ§ãéã Dataplex Dataplex ã«ããæš©é管ç Dataplex ã¯ã忣ãããããŒã¿ã®çµ±åã»ç®¡çãèªååããããã®ãµãŒãã¹ã§ããããŒã¿ã®æš©é管çãç°¡çŽ åãã ããŒã¿ã¡ãã·ã¥ ã®æ§ç¯ãåŸæŒãããŸãããããã¯ãã®è©³çްã¯ã以äžã®èšäºã§ææ¡ããŠãã ããã blog.g-gen.co.jp Dataplex ã§ã¯ãBigQuery ã Cloud Storage ã®ããŒã¿ãžã®ã¢ã¯ã»ã¹æš©éã®ç®¡çãè¡ãããšãã§ããŸããå
·äœçãªã¢ãŒããã¯ãã£çã«ã€ããŠã¯ã以äžã®èšäºãåèã«ããŠãã ããã blog.g-gen.co.jp Dataplex Universal Catalog Dataplex Universal Catalog ã¯ãã¡ã¿ããŒã¿ç®¡çã®ããã®ãã«ãããŒãžããµãŒãã¹ã§ããBigQuery ã Cloud Storage ã®ããŒã¿ã®ããã®ã¡ã¿ããŒã¿ã管çããããŒã¿ã«ã¿ãã°ãæ§ç¯ã§ããŸãããã€ãŠååšããŠãã Data Catalog ãšãããããã¯ãã®åŸç¶ãããã¯ãã§ãã 以äžã®èšäºãåèã«ããŠãæŠèŠãææ¡ããŠãã ããã blog.g-gen.co.jp Dataflow æŠèŠ Dataflow 㯠Apache Beam ã®ãããŒãžããµãŒãã¹ã§ãããªã¢ã«ã¿ã€ã åŠçãšãããåŠçã® äž¡æ¹ã æ±ãããšãã§ããç¹ãç¹åŸŽã§ããDataflow ã¯ãããŒãžããµãŒãã¹ã§ãããããèªåçãªã¹ã±ãŒã«ã€ã³ã»ã¹ã±ãŒã«ã¢ãŠããªã©ã«ãããå°ããéçšè² è·ã§ããŒã¿å€æåŠçãå®çŸã§ããŸããåœè©Šéšã«ãããŠã¯ãDataflow 㯠BigQuery ã«æ¬¡ãã§æãåºé¡æ°ãå€ããããã¯ããšãããŸãã 以äžã®èšäºãèªãã§ãDataflow ã®æŠèŠãçè§£ããŠãã ããã blog.g-gen.co.jp ãŸã以äžã®ããã¥ã¡ã³ãã確èªããApache Beam ã®ããã°ã©ãã³ã°ã¢ãã«ã«ã€ããŠæŠèŠãææ¡ããŠãã ããã åè : Programming model for Apache Beam ãŠã€ã³ã㊠Dataflow ãã¹ããªãŒãã³ã°ããŒã¿ãæ±ãéã«ãããŒã¿ãåå²ããŠã°ã«ãŒãã³ã°ããç²åºŠãšããŠã ãŠã€ã³ã㊠ãšããèšå®ã䜿çšã§ããŸãã ã¿ã³ããªã³ã°ãŠã€ã³ã㊠ã ãããã³ã°ãŠã€ã³ã㊠ïŒ= ã¹ã©ã€ãã£ã³ã°ãŠã€ã³ããŠïŒã ã»ãã·ã§ã³ãŠã€ã³ã㊠ã®çšèªã¯æŒãããŠãããŸãããã åè : Streaming pipelines - Windows and windowing functions exactly-once äŸãã° Pub/Sub ãã BigQuery ãžã®ããŒã¿é£æºãªã©ã§ã¯ãå°ãªããšã1åïŒ at-least-once ïŒãååã§ãã Pub/Sub ããããŒã¿ãåãåã£ãŠã1åéãïŒ exactly-once ïŒã®åŠçãå®çŸã§ããããšãç¹åŸŽã§ãã åè : Exactly-once in Dataflow èåïŒfusionïŒ Dataflow ã¯è€æ°ã®ã¯ãŒã«ãŒã䜿ã£ãŠäžŠååŠçãè¡ããŸããããªãã¬ãŒã·ã§ã³ã®å
容ã«ãã£ãŠã¯èªåçã«ãžã§ããæé©åãã㊠èå ïŒfusionïŒãçºçãããžã§ããå°ãªãããŒãã§å®è¡ãããããšããããŸããå Žåã«ãã£ãŠã¯ãããéå¹çã§ãããå®è¡æéãå»¶ã³ãŠããŸãããšããããŸãã reshuffle ã䜿ãããšã§ãèåãåé¿ãããããªãã¯ããã¯ããããŸãã åè : Dataflow pipeline best practices - Identify performance issues caused by fused steps ãããã¯ãŒã¯ãšãã¡ã€ã¢ãŠã©ãŒã« Dataflow ã® VM ããŒãå士ãéä¿¡ããã«ã¯ãVPC ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã§ããŒãå士ã®éä¿¡ãèš±å¯ããå¿
èŠããããŸãã èš±å¯ããããŒãã¯ã¹ããªãŒãã³ã°ãžã§ãã®å Žå㯠12345/tcp ãããããžã§ãã®å Žå㯠12346/tcp Dataflow VM ããŒã ã«ä»äžããããããã¯ãŒã¯ã¿ã°ã§ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãäœæãã ãããã¯ãŒã¯ã¿ã°ã¯ããã©ã«ãã§ dataflow ãä»äžããããã«ã¹ã¿ã ãããã¯ãŒã¯ã¿ã°ã®ä»äžãå¯èœ Dataflow ã®åŠç¿ã«ãããŠã¯ãäžèšã®ãããªããããã¯ãŒã¯ãšãã¡ã€ã¢ãŠã©ãŒã«ã«é¢ããç¥èãææ¡ããŠãããŠãã ããã詳现ã¯ä»¥äžã®ããã¥ã¡ã³ãã«èšèŒãããŠããŸãã åè : Configure internet access and firewall rules ããŒã¿ãã€ãã©ã€ã³ Dataform Dataform ã¯ãBigQuery çšã®ãã«ãããŒãžãã®ããŒã¿ãã€ãã©ã€ã³ãµãŒãã¹ã§ããBigQuery ã«å®è¡ãã SQL ãã¯ãŒã¯ãããŒç®¡çã§ããã¹ã±ãžã¥ãŒã«å®è¡ããGit ãªããžããªãšã®é£æºãå¯èœã§ããã¯ãŒã¯ãããŒã¯ SQLX ãšåŒã°ãã SQL ããŒã¹ã®èšèªã§èšè¿°ãããããSQL ã®ç¥èãããã°åŠç¿ã³ã¹ããå°ããæžã¿ãŸãã 以äžã®èšäºãåèã«ããŠäžããã blog.g-gen.co.jp ãªã Dataform ã§ã¯ ã¢ãµãŒã·ã§ã³ ãšåŒã°ãããã¹ãã³ãŒããèšè¿°ããããšã§ãããŒã¿åè³ªãæ€èšŒã§ããŸããã¢ãµãŒã·ã§ã³ã§ã¯ãnull å€ã®ãã§ãã¯ãäžæå¶çŽã®ãã§ãã¯ãªã©ãå¯èœã§ãã åè : ããŒã¿å質ã®ãã¹ã Pub/Sub å€ãã®å顿ããŸãã¯éžæè¢ã«ãããŠãDataflow ãšã»ããã§ Pub/Sub ãæ±ãããŸããApache Kafka ã Pub/Sub ã§çœ®ãæãããšããå®çªãã¿ãŒã³ãåºé¡ãããŸãã Pub/Sub ã®åºæ¬æŠå¿µïŒãããã¯ãšãµãã¹ã¯ãªãã·ã§ã³ïŒã ãããã¬ã¿ãŒããã㯠ãPush ãµãã¹ã¯ãªãã·ã§ã³ã® å詊è¡ããªã·ãŒ ãªã©ã«ã€ããŠçè§£ãæ·±ããŠãã ããã åè : Pub/Sub ãµãŒãã¹ã®æŠèŠ åè : ãããã¬ã¿ãŒ ããã㯠åè : ãµãã¹ã¯ãªãã·ã§ã³ ãããã㣠- å詊è¡ããªã·ãŒ Cloud Composer Google Cloud ã®ãµãŒãã¹ã掻çšããŠãžã§ããªãŒã±ã¹ãã¬ãŒã·ã§ã³ãè¡ãã«ã¯ Cloud Composer ãæçšãªéžæè¢ã§ãã ãžã§ãå®è¡ããŒã«ãšããŠã¯ä»ã«ã Cloud Scheduler ãšãµãŒããŒã¬ã¹ãµãŒãã¹ãçµã¿åãããæ¹æ³ãªã©ããããŸãããCloud Composer 㯠DAG ïŒæåéå·¡åã°ã©ãïŒã«ãããžã§ãã®ååŸé¢ä¿ã®ç®¡çããã¢ãã¿ãªã³ã°çã®é¢ã§åŒ·ã¿ããããŸãã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp blog.g-gen.co.jp Dataproc Hadoop/Spark ã®ãããŒãžããµãŒãã¹ã§ãã Dataproc ãé »åºã§ããå
¬åŒããã¥ã¡ã³ãã確èªããã¯ã©ã¹ã¿æ§æã管çéçšæ¹æ³ã«ã€ããŠææ¡ããŠãããŸãããã åè : Dataproc ã®æŠèŠ Dataproc ã§ã¯åºç€ãšã㊠Compute Engine VM ã䜿ãããŸãããã®ããããã©ãŒãã³ã¹åäžãã³ã¹ãåæžã«ããã£ãŠã¯ãCompute Engine ãšåãç¥èã䜿ããŸããäŸãã°ãããŒã«ã« SSD ã¯æ°žç¶ãã£ã¹ã¯ïŒ=ãããã¯ãŒã¯ã¹ãã¬ãŒãžïŒãããã¬ã€ãã³ã·ãäœããã§ãã£ããããã³ã¹ãå¹çãè¯ãããããã«ãã»ã«ã³ããªã¯ãŒã«ãŒãšã㊠Spot VMïŒããªãšã³ããã£ãã« VMïŒã䜿çšã§ããããªã©ã§ãã ãŸãããªã³ãã¬ãã¹ã® Spark / Hive ç°å¢ãã¯ã©ãŠãã«ç§»è¡ããéã®ç§»è¡å
ãšããŠãDataproc ã第1éžæè¢ã«ãªããŸãã åè : Apache Spark ãžã§ãã® Dataproc ãžã®ç§»è¡ åè : Dataproc ã§ã® Apache Hive ã®äœ¿çš DataprepãCloud Data Fusion Dataprep ãš Cloud Data Fusion ã¯ãããããããŒã¿æœåºã»å€æãã€ãã©ã€ã³ãããŒã³ãŒãã§å®è£
ã§ãããããŒãžããµãŒãã¹ã§ããGUI äžã§ã¯ãŒã¯ãããŒãæ§ç¯ããã¹ã±ãžã¥ãŒã«å®è¡ã§ããŸããBigQuery ãªã©ãžã®ããŒã¿æ¿å
¥ããããŒã¿å€æãå¯èœã§ãããœãŒã¹ã³ãŒããæžããã«ããŒã¿ãã€ãã©ã€ã³ãå®è£
ãããå Žåã®ãŠãŒã¹ã±ãŒã¹ã«é©ããŠããŸãã åè : Google Cloud Dataprep by Trifacta ã¯ã€ã㯠ãªãã¡ã¬ã³ã¹ åè : Cloud Data Fusion ã®æŠèŠ ããŒã¿ç§»è¡ ãªã³ãã¬ãã¹ããã®ããŒã¿ç§»è¡ ããŒã¿ç§»è¡ãšããããŒããæ±ãããŸãããªã³ãã¬ãã¹ãã Google Cloud ãžã®å€§èŠæš¡ãªããŒã¿ç§»è¡ã«ã¯ã Transfer Appliance ãšããéžæè¢ããããŸããTransfer Appliance ã¯ç©ççãªã¹ãã¬ãŒãžããã€ã¹ã§ããTransfer Appliance ã«ããŒã¿ã転éããŠãGoogle ã«è¿éããã°ãGoogle Cloud ã® Cloud Storage ã«éããã«ããŒã¿ãç§»è¡ããããšãã§ããŸããã©ã®ãããªã·ãã¥ãšãŒã·ã§ã³ãã©ã®ãããã®èŠæš¡ã®ããŒã¿ã«ãã®ãµãŒãã¹ãé©ããŠããã®ãã¯é ã®çé
ã«å
¥ããŠãããŸãã åè : Transfer Appliance ãŸã gcloud storage rsync ïŒ gsutil rsync ïŒã³ãã³ãã䜿ã£ãŠæäœæ¥ã§ Cloud Storage ã«ããŒã¿ç§»è¡ãè¡ãããšããããŸãããStorage Transfer Service ã䜿ãã° Cloud Storage ãžã®ããŒã¿ç§»è¡ããžã§ãåã»èªååã§ããŸãã åè : Cloud Storage ãšããã°ããŒã¿ã®äœ¿çš åè : Storage Transfer Service ãšã¯ BigQuery Data Transfer Service ãš Storage Transfer Service ã®éãã«ã¯æ³šæããŠãã ãããåè
ã¯å€éšãã BigQuery ãž ããŒã¿ã転éããä»çµã¿ã§ãããåŸè
㯠Cloud Storage ãž ããŒã¿ã転éããä»çµã¿ã§ãã ããŒã¿ããŒã¹éã®ããŒã¿ç§»è¡ Datastream ã¯ããã«ãããŒãžãã®ããŒã¿è»¢éãµãŒãã¹ã§ããããŒã¿ãœãŒã¹ãšã㊠MySQLãPostgreSQLãOracle ãªã©ã® RDBMS ã«å¯Ÿå¿ããŠãããå®å
ãšããŠã¯ BigQueryãCloud Storage ã«å¯Ÿå¿ããŠããŸããCDCïŒChange data captureïŒã«ãããããŒã¿ã®æŽæ°ããªã¢ã«ã¿ã€ã ã«ãã£ããããŠããŒã¿è»¢éãè¡ãããšãã§ããŸãã åè : Datastream ã®æŠèŠ Datastream ã䜿ãããªã³ãã¬ãã¹ã®ããŒã¿ããŒã¹ããå°çšç·çµç±ã§ BigQuery ã«ããŒã¿ã転éããããšãã§ããŸããããŒã¿ãœãŒã¹ã¯ Compute Engine VM ã§ããããäŸãã° VM ã«ã€ã³ã¹ããŒã«ãããŠãã Oracle Database ãã CDC ã§ãªã¢ã«ã¿ã€ã ã« BigQuery ã«ããŒã¿ã転éããããšãå¯èœã§ãã æ©æ¢°åŠç¿ïŒAI/MLïŒ åœè©Šéšã§ã¯ãæ©æ¢°åŠç¿ç³»ã®åºé¡ããããŸãããŸã Google Cloud ç¹æã®ç¥èãšããããããæ©æ¢°åŠç¿ã®äžè¬çãªçšèªãåºç€ç¥èã«ã€ããŠãããçšåºŠã®çè§£ãå¿
èŠã§ãã ã©ããªã³ã°ããã¬ãŒãã³ã°ãã¢ãã«ãæšè«ãååž°ãåé¡ïŒClassificationïŒãã¯ã©ã¹ã¿ãªã³ã°ããªã³ã¡ã³ããŒã·ã§ã³ãæåž«ããåŠç¿ãæåž«ãªãåŠç¿ãæ··åè¡åãéåŠç¿ãšã®ãã®å¯Ÿçããªã©åºç€çãªçšèªãæŒãããŸãããããã®çšèªã®æå³ãããããªãå Žåã¯ãWeb æ€çŽ¢ã Gemini ãæŽ»çšããŠãæµ
ãã§ãããã®ã§çè§£ããŠãããŸãããã ãŸã BigQuery ML ãåºé¡ç¯å²ã§ããäœ¿ãæ¹ãããçšåºŠã®ä»çµã¿ã¯çè§£ããŠããå¿
èŠããããŸãã åè : BigQuery ã® AI ãš ML ã®æŠèŠ ãªãã¬ãŒã·ã§ã³ã¹ã€ãŒã åºæ¬ Cloud Monitoring ã®åºæ¬æ©èœããã£ããçè§£ããŠãããŸãããã blog.g-gen.co.jp ãGoogle ã®ææšãã®ãªãã¡ã¬ã³ã¹ããŒãžã§ãCompute Engine ã Pub/SubãCloud Storage ãªã©ãããŒã¿ãšã³ãžãã¢ãªã³ã°ã«ãããŠéèŠãªãµãŒãã¹çŸ€ã®ã¡ããªã¯ã¹ã¯ãç°¡åã§ããã®ã§çºããŠããããšãæãŸããã§ãã åè : Google Cloud metrics overview 泚ç®ãã¹ãã¡ããªã¯ã¹ ãPub/Sub ããããŒã¿ãèªã¿åã£ãŠãCloud Storage ã«ããŒã¿ãæžã蟌ãããŒã¿ãã€ãã©ã€ã³ãããããšããŠãããã Cloud Monitoring ã§ç£èŠãããšãã«ã©ããããããªã©ã®ã·ãã¥ãšãŒã·ã§ã³ãæ³åããŠãã ããã Pub/Sub ã®ã¡ããªã¯ã¹ã®ãã¡ subscription/num_undelivered_messages ãäžæããŠãããšãåŠçã®é
å»¶çãèµ·ããŠããããšã¿ãªããã¯ãã§ãã ãŸã BigQuery ã«ã¯ slots/allocated_for_project ãšãã£ãã¡ããªã¯ã¹ããããŸãããããžã§ã¯ãããšã«å²ãåœãŠãããã¹ãããæ°ã確èªã§ãããããè€æ°ã®éšçœ²ã§ BigQuery ã䜿ã£ãŠãããšãã«ã©ã®éšçœ²ãã¹ããããå€ãæ¶è²»ããŠããã®ãããªã©ã確èªã§ããŸãã ãã®ä» åéšç°å¢ åœç€Ÿã¡ã³ããŒã®åéšç°å¢ã«é¢ããå®äœéšã以äžã®èšäºã§ç޹ä»ãããŠããŸãããã²ãåç
§ãã ããã blog.g-gen.co.jp blog.g-gen.co.jp ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO å
èŠå¯å®ãšããçµæŽãæã€ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS èªå®è³æ Œããã³ Google Cloud èªå®è³æ Œã¯ãã¹ãŠååŸãXïŒæ§ TwitterïŒã§ã¯ Google Cloud ã Google Workspace ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
ã¿ãªããããã«ã¡ã¯ãG-genã®éŽæšããšãããã€ã§ãã ç§ã¯G-genã«9æã«JoinããŠãæ¥ã
åªç§ãªæè¡è
ãšãšãã«åŠã°ããŠããã ããŠã11æ2æ¥ã«Professional Cloud Architectã®è©Šéšã«åæ ŒãããŠããã ããŸããã â»Associate Cloud Engineerã«é¢ããŠã¯10æã®é ã«åæ ŒãããŠããã ããã®ã§ããã®è©±ã¯ãŸãå¥ã®æ©äŒã«ã§ãããã°æžããŠã¿ãããšæããŸãã ä»åã¯ãåéšèšã§ã¯ãªãããŸãã®ã³ããã®ææã ããããæå¹æŽ»çšãããé é詊éšã«é¢ããŠå°ã話ããŠã¿ãããšæããŸãã Google Cloudã®é é詊éšãšã¯ïŒ é é詊éšã®èŠä»¶ãšå®éã®ç°å¢ æåã«åéšããããšããŠããç°å¢ å®éã®åéšç°å¢ äºåã®äºçŽ åœæ¥ã®æµã ãã®ä» çŒé¡ å€ä»ãã®Webã«ã¡ã© åŸæ¥ãProfessional Collaboration EngineerãåéšããŸããã Google Cloudã®é é詊éšãšã¯ïŒ Google Cloudã§ã¯ä»¥äžã«ãããŸãããã«ãæ§ã
ãªè©ŠéšãæäŸããŠããŸãã Google Cloud 認定資格 ãããŠããã®è©Šéšããªããš å®¶ããåéšã§ããŠããŸã ã®ã§ãïŒ çŸæç¹(2021幎11æ4æ¥æç¹)ã§ã¯ãæ¥æ¬èªå¯Ÿå¿ããŠãã以äžã®ãã¹ãŠã®è©Šéšã é éã§ã®åéšãå¯èœ ã§ãã Google Cloud Certified - Cloud Digital Leader (Japanese) Google Cloud Certified - Associate Cloud Engineer (Japanese) Google Cloud Certified - Professional Cloud Architect (Japanese) Google Cloud Certified - Professional Cloud Developer (Japanese) Google Cloud Certified - Professional Collaboration Engineer (Japanese) Google Cloud Certified - Professional Data Engineer (Japanese) ã³ãããèœã¡çããŠãããšã¯ããããªã¢ãŒãã§åéšã§ããã®ã¯ãšãŠã䟿å©ã§ãã®ã§ããã²æŽ»çšããŸãããã é é詊éšã®èŠä»¶ãšå®éã®ç°å¢ å®éã«å
¬åŒã«ã¢ããŠã³ã¹ãããŠããèŠä»¶ã¯ä»¥äžã®éãã«ãªããŸãã Exam Procedures ç§ã®å Žåã¯ãããŸãå®¶ã倧ãããªãã®ã§ãããã©ãã§åéšãããããšãå®ã¯è©Šéšéå§30ååãŸã§æ©ã¿ãæåŸã®æåŸã§å€æŽããŸãã(æ±) æåã«åéšããããšããŠããç°å¢ æåã¯ãæºã®äžã«äœãç¡ããã°ããã ããïŒãšèãããªãã³ã°ã®ããŒãã«ã§åããããšèããŠãããŸããã â»ç°¡åãªç°å¢ã¯ä»¥äžã®çµµãåèã«ããŠãã ããã å®¶ã®éåããšåéšããããšããŠããå Žæ ãã ããããã³ã«ã¯ãã®ããã£ãããè¿ãã«ãã¬ãããã£ãããšãããã¯ã€ã£ããŸãããïŒïŒãšæãã詊éš30ååã«åäŸéšå±ãå©çšããããšã決æã(å®ã¯ãã®æå€ã®23æ30å) å®éã®åéšç°å¢ çµæãšããŠä»¥äžã®ç°å¢ã§åéšã決æïŒ æçµçã«åéšããå Žæ çµæãããããšãã®å Žæã§åäŸã®ããã¡ããã¡ã«èŠå®ãããªããåéšããŠäºãªããåŸãŸãããããã§ã¯æ¬¡ãããäºåæºå(äºçŽ)ãåœæ¥ã®æµãã説æããŠãããŸãã ã¡ãªã¿ã«PCã¯æ®éã®Windowsã®ãã©ã€ããŒã端æ«ã«å€ä»ãã«ã¡ã©ãã»ãããããã®ã«ãªããŸãã äºåã®äºçŽ åºæ¬çã«ãäºçŽã¯éåžžã®æ¹æ³ãšäœã代ãããããŸããã以äžã®Kryterionã®ãµã€ãããéåžžéãç³èŸŒã¿ããŸãããã 準備ができたら ãã ãæ³šæãªã®ãæ¥æãšæéã§ããProfessional Cloud Architectã¯äººæ°ã®è©Šéšãªã®ããçµæ§åãããæ¥ã®æ ã空ããŠããããæ©ã¿ã«æ©ãã æ«ã« 11æ2æ¥00:00AM ã§ã®åéšã決æã ã¿ãªããŸã00:00AMã£ãŠãçã£æŒéãªã®ããå€äžãªã®ãããã«ããããŸããïŒ éŽæšã¯å®ã¯æšå¹ŽãåäŸã®éåäŒãçµãã£ãããšã®ããæŒã«ãã¯ããã«ããæ¥ãããã«äºçŽããŠãããå€äžã«æ¥ãŠããŸã£ãããšããäœéšãããããäžç¬ã§å€å¥å¯èœã§ããã(ã©ãã§ã©ãããçµéšã掻ãããããããŸããã)ã ããã11æ2æ¥00:00AMãšããã®ã¯11æ1æ¥ã®ãä»äºãçµãã£ãŠãå€é£¯é£ã¹ããã£ãŠãã颚åã«å
¥ã£ãããšã®å€äžã§ãïŒãééããªãããïŒ ä»ã«ããæµ·å€ããç£èŠã ãããªã®ã3:00AMãšããæ¥æ¬ã ãšæ®é㯠å¯ãŠããæéã§ãåéšãå¯èœ ãªã®ã§ãäºçŽæéã¯ééããªãããã«æ³šæããŸãããã äºçŽãå®äºããŸãããã以äžã®ç»é¢ã®å³åŽã«Sentinelã®ã€ã³ã¹ããŒã«ããšãããã¿ã³ãšãçäœèªèšŒçšã®é¡åçç»é²ããšãããã¿ã³ãã§ãŸãã®ã§ã2ã€ãšã詊éšåãŸã§ã«æžãŸããŠãããŸãããã Kryterionã®ç»é¢ åœæ¥ã®æµã åœæ¥ã¯10ååã«ãªã£ãæç¹ã§ãäºçŽç»é¢ã®ïŒã®å°ãâåéšããâãšãããã¿ã³ã«å€ãããŸãããã¿ã³ãã¯ãªãã¯ãããšSentinelãèªåçã«ç«ã¡äžãããŸãã ãã ãã®æãã©ããããã§ãã¯ããåŽã®æ¹ãæ··éããŠãã£ãœããæ°åéåŸ
ã€ããšã«ã ç»é¢ã¯ããã®ç»é¢ãåããªãã§ãã ããããæ··éããŠãã®ã§æå€§15ååŸ
ã£ãŠããããããããŸããããã®ãããªã¡ãã»ãŒãžãç»é¢ã«è¡šç€ºãããŠããŸããã ãã£ãšã®ããšã§æ¥ç¶ããããšãã¯ããã¯ç°¡åãªèª¬æããã£ãäžã§ããã¹ããŒãçãã«ã¡ã©ã«è¿ã¥ããŠããèŠããããã«æ ããŠãã ããããšããæç€ºããããOKã ãšãã£ããããã¯ã¹ãç«ã¡äžãããŸãã ã©ãã©ãããªããè±èªã®ãŽãªãŽãªã®å€äººã®æ¹ããžããŒïŒãšãèšã£ãŠããã®ããšæã£ãããç»é¢å·Šã«ãã£ãããå³åŽã«ã«ã¡ã©ããšãããŠã£ã³ããŠãç«ã¡äžããããã£ããããã¯ã¹ã«ãã§ã¯ãã§ãã¯ãéå§ããŸãããŸãã¯å£åé¢ã倩äºãåºãã«ã¡ã©ã§æ ããŠãã ãããåéšå5ç§çšåºŠéæ¢ããŠãã ãããã®ãã㪠ã¡ãã»ãŒãžãæ¥æ¬èªã§è¡šç€º ãããããã«åŸã£ãŠæ ããããªåœ¢ã«ãªããŸãã ãã ãããã§æ³šæãªã®ãã ãªã¢ã«ã¿ã€ã ã§ããã«ãªã«ããªã¢ã¯ã·ã§ã³ããŠãããããã§ã¯ãªã ãå
šéšç¢ºèªããŠOKã ã£ããæ¬¡ã®æç€ºãã®ãããªåœ¢ãªã®ã§ãäœããªã¢ã¯ã·ã§ã³ãç¡ããŸãŸã§ãå³ã®å£5ç§ãå·Šã®å£5ç§ãåãåŸãã倩äºãè¶³å
ãããæåŸã«èªåãããããã§ãã£ãŠãã®ããªïŒããšããç¶æ³ã§ãæ°ç§ãã€ãšããã§ã¯æ¬¡ã«ãæºã®äžãæ ããŠãã ãããããæ¬¡ã¯æºåž¯ã®ã«ã¡ã©ããããã¯æé¡ãã€ãã£ãŠãPCã®ãã£ã¹ãã¬ã€ãæ ããŠãã ããããããããããšãããããŸãïŒãã¹ããŒããæºåž¯ãã©ããã«ãããŠãã ããïŒããšæ¥ãŠã(ã©ãã«ããã°ã»ã»ã»)ããšæãã€ã€ãéšå±ã®é
ã£ãã®ããã¡ããã¡ã®äžãžãœãã£ããšã ãããã£ãäžé£ã®æµããçµãããšãããã§OKã§ãïŒããã§ã¯è©Šéšãéå§ããŸãïŒãã®æéã¯è©Šéšæéã«å«ãŸããŸããã®ã§ãå®å¿ãã ããïŒããšããã¡ãã»ãŒãžã衚瀺ããã詊éšãéå§ãããŸãã ãã ãæ°åç§(äœæçã«ã¯1åãããïŒ)ã®ããã 詊éšéå§ãã¿ã³ã衚瀺ãããªãã£ããããããïŒïŒã©ããã£ãŠè©Šéšéå§ããã®ïŒïŒïŒããšæã£ãŠããŸããŸããããç¡äºã«ãã¿ã³ãåºçŸã詊éšéå§ãšãªããŸããã ããšã¯ãã€ãã®è©Šéšãšåãã§ãåæã®ç»é¢ããã£ãŠã詊éšããããã¢ã³ã±ãŒããããçµæããšããæµãã§é²ã¿ãŸãã (詊éšçµäºããæç¹ã§å€äžã®1æ30åããã§ããã»ã»ã») åæ Œãããã§ãããå®ã¯å§ããŠã®é éäœéšã ã£ãããã30ååã«å Žæãå€ãããããã¿ãã¿ãããã§ãªãã ãæ¥çšããåãã°è¡ã£ãæ¹ãè¯ãã£ãããããªãããšãå°ãæã£ãŠããŸããŸãããããã ä»åŸã®ããã«ãããçµéšãã§ããŸããã ãã®ä» çŒé¡ çäœèªèšŒ(èªåã®é¡åçãæ®ã£ãŠéä»)ã®ãšãããå®éã®ãšããèªåã®é¡ãéä»ããšããã®ã¯ããããšã¯ããã£ãŠãã®ã§ããããã®ãšãã®ã€ã³ã¹ãã©ã¯ã·ã§ã³ã§ ã¡ã¬ããå€ããŠãã ãã ãšãã説æããããã¡ã¬ããå€ããš0.01ã¬ãã«ã®éŽæšã¯ æ®åœ±ãã¿ã³ãèŠããªãïŒ ãšããç¶æ³ã ã£ãã®ã§ãçŒé¡ãããã¯èš±ããŠã»ãããªããããšæããŸããã å€ä»ãã®Webã«ã¡ã© ç§ã¯å¹žãã«ãUSBã®å€ä»ãã®Webã«ã¡ã©ãæã£ãŠããããããã¡ããåœæ¥ã¯å©çšããŸããããã§ãã¯ãªã¹ãçã«ã¯å
èµã®ã«ã¡ã©ã§ãOKãªã®ã§ãããæºã®äžãæ ãããããã¡ãã¡æ ãããããã®ã§ãå
èµã ãšæ£çŽå³ããã®ã§ã¯ãªããããããšæã£ãŠãããŸãã åŸæ¥ãProfessional Collaboration EngineerãåéšããŸããã åŸæ¥è«ã§ãããProfessional Collaboration EngineerãåéšããŸããã(çµæã¯å¥ã®ããã°ã§ã»ã»ã») 2床ç®ã®ãªã¢ãŒãåéšãªã®ã§ãèœã¡çããŠãããæå³ãã£ã¬ã³ãžãããšæãã以äžã®ãããªç°å¢ã§åéšããŸããã çµè«ãããããšåé¡ãªãã詊éšç£ã«ããã€ãææãããŸãããã æã®å±ããšããã«ãã®ããªã ãšããã®ãæ¡ä»¶ã®ããã§ããæã®å±ããšããã«ãããããããããªããïŒãšããããã³ãã¯ã容赊ãã ããã â»è©Šéšã«å¿
èŠãªãã¹ããŒãããããã«çœ®ããŠããèµ€ãããŒããçä»ããªããïŒãšçªã£èŸŒãŸãããšãã¯ã»ã»ã»ãšæããŸããããããã ãã¹ã¯ãŸããã®åç ããããå¯ãææã«ããªããŸãããé éåéšãããŸã掻çšããŠãããGoogle Cloudã©ã€ããéããŸãããïŒ Professional Cloud Architect éŽæš éæ (èšäºäžèЧ) å·è¡åœ¹å¡ COO ããžãã¹æšé²éš éšé· åºæ¬ããªãã§ãå±ãäž»ã«ããžãã¹ã®ç«ã¡äžããä»çµã¿ã¥ãããå¥œã æ¥ã
ãåªåãæ¥ã
ãæ¥œããããšã倧äºã« ã Professional Cloud Architect / Professional Workspace Administratorã®ã¿ä¿æããŠããŸãããããã倱å¹ããŠããŸããããªäºæã
G-gen ã®ææã§ãã Professional Cloud Architect è©Šéš ã¯ã Associate Cloud Engineer 詊éšã®äžäœã«äœçœ®ãã Google Cloud (æ§ç§° GCP) ã®é£é¢èªå®è³æ Œã§ããæ¬æçš¿ã§ã¯è©Šéšã®åæ Œã«åœ¹ç«ã€ãååŒ·æ¹æ³ãåºé¡åŸåãªã©ã«ã€ããŠè§£èª¬ããŸãã ã¯ããã« Professional Cloud Architect è©Šéš ãšã¯ é£æåºŠ æšå¥šã®ååŒ·æ³ ã±ãŒã¹ã¹ã¿ã㣠åºé¡åŸå æŽæ°è©Šéš çµç¹ãš IAM çµç¹ã®ããªã·ãŒ IAM ã®åºæ¬æŠå¿µ ãªãã¬ãŒã·ã§ã³ã¹ã€ãŒã Cloud Monitoring Cloud Logging ã»ãã¥ãªãã£ã»çµ±å¶ Network Intelligence Center Sensitive Data Protection Google Kubernetes EngineïŒGKEïŒ åºæ¬æŠå¿µ ã¢ãã¿ãªã³ã° å®å
šãªããã〠GKE ããã® Google API ãžã®èªèšŒ ããŒã¿ããŒã¹ã»åæ ããŒã¿åæãã©ãããã©ãŒã ã®éžæ Cloud SQL Cloud Storage ã³ã³ãã¥ãŒããµãŒãã¹ æŠèŠ App Engine CI/CD æŠèŠ ã³ã³ããã»ãã¥ãªã㣠VPC / ãããã¯ãŒã¯ VPC ã®åºæ¬ ãããã¯ãŒã¯ã»ãã¥ãªã㣠æ¥ç¶æ§ æŠèŠ VPC éã®æšç§»çéä¿¡ ãã€ããªãããããã¯ãŒã¯ å¯çšæ§ SLA Compute Engine Compute Engine ã®åºæ¬ ãããŒãžãã€ã³ã¹ã¿ã³ã¹ã°ã«ãŒã ãªãŒãžã§ã³æ°žç¶ãã£ã¹ã¯ãå©çšããå¯çšæ§åäž ã©ã€ã»ã³ã¹ã®æã¡èŸŒã¿ ãã®ä» ãã®ä»ã®ãããã¯ã ã¯ããã« Professional Cloud Architect è©Šéš ãšã¯ Professional Cloud Architect ã¯ãAssociate Cloud Engineer 詊éšã®äžäœã«äœçœ®ãã Google Cloud ã®èªå®è³æ Œã§ãã IT ã€ã³ãã©ãã¢ããªã±ãŒã·ã§ã³éçºã«é¢ä¿ãã Google Cloud ãµãŒãã¹ã®ç¥èã®ã¿ãªãããããŒã¿åæãã»ãã¥ãªãã£ãã¢ãã¿ãªã³ã°ãªã©å¹
åºãç¥èãæ±ããããŸãããã®è©Šéšã«åæ ŒããŠããããšã¯ãGoogle Cloud ãå¹
åºãçè§£ããŠãããäžäººåã® Google Cloud æè¡è
ã§ãã蚌巊ã ãšãã£ãŠãéèšã§ã¯ãªãã§ãããã è©Šéšæé㯠120 åã詊éšå顿°ã¯ 50ã60 åã§ãã詊éšã¯æ¥æ¬èªãšè±èªã§æäŸãããŠããŸãã åè : Professional Cloud Architect â Google Cloud å¯èœã§ããã°ãåœè©Šéšããå
ã« Associate Cloud Engineer 詊éšã«åæ ŒããŠããããšãæãŸããã§ãããåéšã«ãããå¿
é èŠä»¶ã§ã¯ãããŸãããAssociate Cloud Engineer 詊éšã«ã€ããŠã¯ä»¥äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp é£æåºŠ åœè©Šéšã®é£æåºŠãšããŠã¯ äžçšåºŠ ã ãšèšããŸãã IPA ã®ãå¿çšæ
å ±æè¡è
詊éšãçšåºŠã®åºæ¬ç㪠IT ç¥èããããã〠Google Cloud ãããçšåºŠæ¥åã§äœ¿çšããçµéšããããšããã®ãåæç¥èãšããŠçæ³çã§ãã詊éšã¬ã€ãã§ã¯ã3幎以äžã®æ¥çã§ã®çµéšãšã1幎以äžã® Google Cloud ã«ãããçµéšããæšå¥šã ãšèšèŒãããŠããŸãããå¿
ããããããæºãããŠããªããŠãåååæ Œãçããè³æ Œã§ãã ãããæ®æ®µãã Google Cloud ã®å
¬åŒããã°ãããã¥ã¡ã³ãã®ãã¹ããã©ã¯ãã£ã¹ã«ç®ãéããGoogle ã®èããã¯ã©ãŠããããã¯ã©ãŠãã®äœ¿ãæ¹ãäœãããšããäžçš®ã® ã¯ã©ãŠãã®å²åŠ ãé ã«ã€ã³ãããããŠããããšãéèŠã§ããéžæè¢ã«è¿·ã£ãæã«ã æãã¯ã©ãŠããããéžæè¢ã¯ã©ãã ãšããæèãå©ãã«ãªããŸãã ãããã«å ããŠãåœèšäºã§è¿œå ã®åŠç¿ãããã°ãåæ Œã¯é£ãããªããšèšããŸãã ç¹ã« Amazon Web ServicesïŒAWSïŒã®è©Šéšãåããããšããã人ã§ããã°æ°ãä»ããŸãããå顿ã®é·ããè€éã㯠AWS Certified Solutions Architect - Professional èªå®ã®ãããšæ¯èŒãããšãçããŠã·ã³ãã«ã§ãããšæããããŸããäœæçæ¡é£æåºŠã¯ AWS ã® Professional 詊éšããäœããããããŸããã æšå¥šã®ååŒ·æ³ Associate Cloud Engineer ãå
ã«ååŸãã 詊éšã¬ã€ã ãèªãã§åºé¡ç¯å²ãçè§£ãã åœèšäºãèªã¿ãåºé¡åŸåãçè§£ãã ææ¡ãã詊éšç¯å²ã»åºé¡åŸåãããšã«å匷ãã æš¡æ¬è©Šéš ãåããè¶³ããªãç¥èãèªèããŠãã®ã£ãããåããå匷ããã ã±ãŒã¹ã¹ã¿ã㣠ãçŽåã«ç¢ºèªãã ããã¥ã¡ã³ããèªãã ãã§ã¯çè§£ãé²ãŸãªããµãŒãã¹ãåºãŠããŸãããããã£ããšãã¯ãæžç±ãèªãããããã°èšäºãæ€çŽ¢ããŠèªãããã³ã³ãœãŒã«ç»é¢ã gcloud ã§å®éã«è§Šã£ãŠã¿ããã®3ã€ãç¹ã亀ããŠåŠç¿ãé²ããã®ãããããã§ãã ç¹ã«3ã€ãã®ã å®éã«è§Šãã ãã¯éèŠã§ããã³ã³ãœãŒã«ãã³ãã³ãã©ã€ã³ãè§ŠããšãGoogle Cloud ãããã¯ãã® ãªãœãŒã¹æ§æ ãæã«ãšãããã«åãããçè§£ãé²ã¿ãŸãããªãœãŒã¹æ§æãææ¡ããŠããããã¥ã¡ã³ãã«æ»ããšãç解床ãå
šãéãããšããããŸãã ã±ãŒã¹ã¹ã¿ã㣠Professional 詊éšã§ã¯ ã±ãŒã¹ã¹ã¿ã㣠ãšåŒã°ãããæ¶ç©ºã®äŒç€ŸãããŒãã«ããã¯ã©ãŠãå°å
¥äºäŸãåŒçšãããŸãã åè : Professional Cloud Architect Exam Guide | Japanese 詊éšäžã¯ç»é¢ã®å³ååã«ã±ãŒã¹ã¹ã¿ãã£ã®å
容ã衚瀺ããããããå
容ãèŠããŠããå¿
èŠã¯ãããŸããããäºåã«ç®ãéããŠãããŸããããã©ããªæ¬çªç°å¢ã§ãèŠæ±ããããããªåºæ¬çãªèŠä»¶ãå€ãæžãããŠããŸããããã®ã±ãŒã¹ã§å€§äºã«ããŠããïŒåªå
ãã¹ãïŒèŠä»¶ã«æ³šæããŸããããäŸãã°ãã³ã¹ã vs å
šäžçããã®ã¬ã€ãã³ã·ããšãããã¬ãŒããªãããã©ã¡ãããéžæããªããŠã¯ãããªãå Žåãã±ãŒã¹ã¹ã¿ãã£ã«æžãããŠããããžãã¹èŠä»¶ãæè¡èŠä»¶ããã³ãã«ãªããŸãã åºé¡åŸå åºé¡ç¯å²ã®ãµãŒãã¹ã¯ãAssociate Cloud Engineer 詊éšå¯Ÿçèšäºã«èšèŒãããŠãããã®ãšã倧åãéè€ããŠããŸãã®ã§ããã¡ãã®èšäºããåç
§ãã ããã åè : Associate Cloud Engineer詊éšå¯Ÿçããã¥ã¢ã«ãåºé¡åŸåã»ååŒ·æ¹æ³ - G-gen Tech Blog åºé¡ç¯å²ã¯å¹
åºãã倿§ãªãµãŒãã¹ãåºãçè§£ããŠããå¿
èŠããããŸãã åœèšäºã§ã¯ãã以éãã©ã®ãããªè©Šéšåé¡ãåºãããåºé¡åŸåãšãã®å
容ã解説ããŠãããŸããå
¬åŒããã¥ã¡ã³ããžã®ãªã³ã¯çãã§ããã ãä»èšããŠããŸãã®ã§ãç¥ããªãçšèªãçè§£ã®æµ
ãæŠå¿µãããã°ãããã¥ã¡ã³ããèªãã ããå®éã«ãµãŒãã¹ã«è§Šããçã®å¯Ÿçãè¡ã£ãŠãã ããã æŽæ°è©Šéš Professional Cloud Architect 詊éšã«ã¯ãäžåºŠåæ ŒããŠæŽæ°ææãè¿ãã人åãã® æŽæ°è©Šéš ãçšæãããŠããŸãã æŽæ°è©Šéšã¯è±èªã𿥿¬èªã§æäŸãããŠãããå顿°ã¯é垞詊éšã®çŽååã®25åãè©Šéšæéã¯ååã®1æéã§ãããŸãåéšè²»çšã¯ãéåžžæéã®åé¡ã® $100 ã§ãã æŽæ°è©Šéšã¯é垞詊éšãšã¯åºé¡ç¯å²ãç°ãªã£ãŠãããã±ãŒã¹ã¹ã¿ãã£ã®å
容ããçæ AI ãœãªã¥ãŒã·ã§ã³ãããŒããšãããã®ã«ãªã£ãŠããŸããã±ãŒã¹ã¹ã¿ãã£ã«é¢ããåé¡ãå
šäœã®90%ã100%ãå ããŠãããšãããŠãããã»ãšãã©ãçæ AI é¢é£ã®åé¡ãšèããããŸããææ°æ
å ±ã¯ãå
¬åŒã®æŽæ°èªå®è©Šéšã¬ã€ããåç
§ããŠãã ããã åè : Professional Cloud Architect æŽæ°èªå®è©Šéšã¬ã€ã çµç¹ãš IAM çµç¹ã®ããªã·ãŒ çµç¹ã®ããªã·ãŒã§ã¯ãããŸããŸãªå¶çŽãçµç¹å
šäœã«èª²ãããšãã§ããŸãã ããã§ã®èšå®ã¯ IAM ã§ã®èš±å¯ãããåªå
ãããŸããçµç¹ã®ããªã·ãŒã§ã©ããªããšãã§ããã®ãããã¡ãããã¹ãŠèŠããå¿
èŠã¯ãããŸããããçµç¹ã«çµ±å¶ãå¹ãããéã«ã©ã®ãããªããªã·ãŒã䜿ãããã ããããšæ³åããªãã以äžã®ããã¥ã¡ã³ãã確èªãããšããã§ãããã åè : çµç¹ã®ããªã·ãŒã®å¶çŽ äŸãã°ä»¥äžã®ãããªããªã·ãŒã«æ³šç®ããŠãæçŸ©ãäœ¿ãæ¹ïŒãã©ã¡ãŒã¿ã«äœãèšå®ãããïŒãäºåã«çè§£ããŠãããŠãã ããã ç¹å®ãªãŒãžã§ã³ãã䜿ããªãããã«ãã ( constraints/gcp.resourceLocations ) å€éš IP ã¢ãã¬ã¹ãæã€ããšãã§ãã Compute Engine VM ããã¯ã€ããªã¹ãåŒã§å¶éãã ( constraints/compute.vmExternalIpAccess ) å€éšçµç¹ã® Google ã¢ã«ãŠã³ãã IAM æš©éãæãŠãªãããã«ãã ( constraints/iam.allowedPolicyMemberDomains ) 以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp IAM ã®åºæ¬æŠå¿µ Google Cloud ã® Identity and Access Management ïŒIAMïŒã¯ã ãªãœãŒã¹ãæã€ããªã·ãŒãäžå¿ ã®æŠå¿µã§ããããšããŸã ç¶æ¿ ãèµ·ãããšããããšãæ£ããçè§£ããŠãã ãããIAM ã®æŠå¿µã«ã€ããŠã¯ã以äžã®èšäºãåèã«ããŠãã ããã blog.g-gen.co.jp Associate 詊éšãšåæ§ã«åºæ¬çãªæŠå¿µããã£ããçè§£ããŠããã°è§£ããåé¡ã°ããã§ãã ãŸã詊éšåé¡ã§ãããããã·ãã¥ãšãŒã·ã§ã³ãæ¹åããã«ã¯ã©ããããããšåããããšãã æå°æš©éã®åå ãæèããŠæ¹åçãèããŠãã ããããªãŒããŒãªã©ã®åŒ·ãããŒã«ã¯æ¥µå䜿ããªãæ¹åã«ããã¹ãã§ããã䜿ãå Žåã¯çµç¹å
šäœã«å¯ŸããŠä»äžããã®ã§ã¯ãªãããã©ã«ããªã©ã䜿ã£ãŠé©çšç¯å²ãå¶éããŸãã ãŸãã ãµãŒãã¹ã¢ã«ãŠã³ã ã®äœ¿ãæ¹ã¯çè§£ããŠãããŠãã ããããµãŒãã¹ã¢ã«ãŠã³ãã¯ã人éã§ã¯ãªã ããã°ã©ã ã Google Cloud ãµãŒãã¹ã䜿ãã¢ã«ãŠã³ã ã§ãããµãŒãã¹ã¢ã«ãŠã³ãã«æš©éãäžããéã¯ã人ã®ã¢ã«ãŠã³ããšåæ§ã«ãæå°æš©éã®ååã«åŸãã¹ãã§ãã éžæè¢ã«å®æã«ãçµç¹ã®ç®¡çè
ãä»äžãããããªãŒããŒæš©éãä»äžããããªã©ãããã°ã誀ã£ãéžæè¢ã§ããå¯èœæ§ãé«ããšèšããŸãã ãŸãå人ã®ã¢ã«ãŠã³ãã«åå¥ã« IAM æš©éãä»äžããããšãªããã°ã«ãŒãã«å¯ŸããŠä»äžããããšã§ãéçšå·¥æ°ãåæžããããšãã§ããŸãã åè : IAM ãå®å
šã«äœ¿çšãã ãªãã¬ãŒã·ã§ã³ã¹ã€ãŒã Cloud Monitoring Cloud Monitoring ã®åºæ¬æ©èœïŒGoogle Cloud ã®ææšã Ops ãšãŒãžã§ã³ãã®ææšãã«ã¹ã¿ã ææšãããã·ã¥ããŒãçïŒãçè§£ããŠãã ããã blog.g-gen.co.jp Cloud Monitoring ã«ã¯ãªãœãŒã¹ã®ã¢ãã¿ãªã³ã°ãã¢ã©ãŒãã®çºå ±ãªã©ã®æ©èœã®ã»ããç°¡æçãªã€ã³ã·ãã³ã管çã®æ©èœããããŸããããã¥ã¡ã³ãäžå¿ã§æ§ããªãã®ã§ãçè§£ãããŠããå¿
èŠããããŸãã ãŸã Google Kubernetes EngineïŒGKEïŒã§ã Cloud Monitoring ã䜿ã£ãã¢ãã¿ãªã³ã°ã掻èºããŸãããã¡ãã確èªããŠãããšããã§ãããã Cloud Logging Cloud Logging ã® ã·ã³ã¯ ïŒãã°ã«ãŒã¿ãŒïŒã®ä»æ§ãçšéããã£ããæŒãããŠãããŸããããã·ã³ã¯ããã©ã®ãµãŒãã¹ã«ãã°ããšã¯ã¹ããŒãã§ããã®ããã©ããªã¢ã¯ã·ã§ã³ã«ç¹ããããã®ãããšããç¹ãéèŠã§ãããŸã éçŽã·ã³ã¯ ã䜿ãããšã§ãçµç¹é
äžã®å
šãããžã§ã¯ãããç¹å®ãã©ã«ãé
äžã®è€æ°ã®ãããžã§ã¯ãã®ãã°ã容æã«éçŽããç£æ»çšãããžã§ã¯ãã«ä¿åããããšãã§ããŸãã åè : ãã°ãšã³ããªã転éãã Compute Engine VM ã« Ops Agent ãã€ã³ã¹ããŒã«ããã°ãVM äžã®ã¢ããªã±ãŒã·ã§ã³ãã°ãç°¡åã« Cloud Logging ã«éä¿¡ãããã°ã·ã³ã¯ã䜿ã£ãŠ BigQuery ã Cloud Storage ãžãã°ã転éãä¿åããããšãã§ããŸãã åè : Ops ãšãŒãžã§ã³ãã®æŠèŠ ãŸã Cloud Logging ãããã°ããã£ã«ã¿ããããã§ Pub/Sub ãžéä¿¡ããã°ãç¹å®ã®ãã°çºçãããªã¬ã«ããŠã€ãã³ãããªãã³ã§ Cloud Run functions ãèµ·åããããšãã§ããŸãããããã£ãæé¢ãèªãã æã«ãæ§æå³ãæãæµ®ãã¶ãããã«çè§£ããŠãããŸãããã Cloud Logging å
šäœã®æŠèŠã«ã€ããŠã¯ä»¥äžã®èšäºããåç
§ãã ããã blog.g-gen.co.jp ã»ãã¥ãªãã£ã»çµ±å¶ Network Intelligence Center Network Intelligence Center 㯠Google Cloud ã®ãããã¯ãŒã¯é¢é£ã®å¯èŠæ§ãæäŸããããã¢ãã¿ãªã³ã°ããã©ãã«ã·ã¥ãŒãã£ã³ã°ã«åœ¹ç«ã€ãµãŒãã¹ã§ãã以äžã®èšäºãèªãã§ãã©ã®ãããªæ©èœãããã®ãã確èªããŠãããŸãããã blog.g-gen.co.jp ãã¡ã€ã¢ãŠã©ãŒã«ã€ã³ãµã€ãæ©èœã«æ³šç®ã§ããããã¯ãèªåçã« VPC ã®ãã¡ã€ã¢ãŠã©ãŒã«ãã°ããã§ãã¯ããŠã«ãŒã«ã®æ£åžãçã«åœ¹ç«ã€æ©èœã§ãã ãªã VPC ã®ãã¡ã€ã¢ãŠã©ãŒã«ãã°ã¯ã ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ããšã«æç€ºçã«æå¹å ããå¿
èŠãããç¹ã«æ³šæããŸãããããã¡ã€ã¢ãŠã©ãŒã«ã®ãã°ãæå¹åããªããšããã¡ã€ã¢ãŠã©ãŒã«ã€ã³ãµã€ãæ©èœãåäœããããã€ãŸã§åŸ
ã£ãŠãæ€ç¥äºé
ããŒãã®ãŸãŸã§ãã Sensitive Data Protection Sensitive Data Protection ïŒæ§ç§° Cloud Data Loss PreventionãCloud DLPïŒã§äœãã§ãããã確èªããŠãããŸãããããŸããã¹ãã£ã³çµæã¯ã©ãã«ã©ã®ããã«é
眮ãããå¿çšãããã§ããããéèŠã«ãªã£ãŠããŸãã åè : Sensitive Data Protection overview ããŒã¿åŠçãã€ãã©ã€ã³äžã§ Sensitive Data Protection ã䜿ã£ãŠ PIIïŒå人è奿
å ±ïŒãæ€ç¥ããããšã§ãPII ãåé€ããŠããããŒã¿ãä¿åãããŠãŒã¹ã±ãŒã¹ãªã©ãæããããŸãã ãŸããSensitive Data Protection ã®æ€æ»çµæã¯ããŒã¿ã«å¯Ÿããã¡ã¿ããŒã¿ãšããŠãDataplex Universal Data Catalog ã«ä¿åã§ããŸãã Google Kubernetes EngineïŒGKEïŒ åºæ¬æŠå¿µ Professional Cloud Architect 詊éšã§ã¯ Google Kubernetes EngineïŒGKEïŒã ãã§ãªã Kubernetes ã®å
šè¬ç¥èãæ±ããããåé¡ããããŸãã PodãDeploymentãServiceãIngressãNamespaceãClusterãIstioããµãŒããããã¬ã€ã¯ããã€ã¯ããµãŒãã¹ãªã©ã®åèªãæŠå¿µã®çè§£ãé²ããŸãããã GKE ã Kubernetes ã«ã€ããŠã¯ä»¥äžã®èšäºãåèã«ããŠãã ããã blog.g-gen.co.jp blog.g-gen.co.jp ã¢ãã¿ãªã³ã° GKE ã¯ãã€ãã£ãã« Cloud Monitoring ã Cloud Logging ãšçµ±åãããŠããŸãããã®çµ±åæ©èœã¯ Cloud Operations for GKE ãšåŒã°ããŠããŸãã åè : GKE ã®ãªãã¶ãŒãããªã㣠GKE ã¯ã©ã¹ã¿ã§ Managed Service for Prometheus ãæå¹åããããšãã§ããŸããæ°èŠã¯ã©ã¹ã¿ã®ã¿ãªãããæ¢åã¯ã©ã¹ã¿ã§ãæå¹åãå¯èœã§ãã åè : Google Cloud Managed Service for Prometheus å®å
šãªããã〠readiness probe ãš liveness probe ãèšå®ããŠãããšãPod ãæŽæ°ãããéãªã©ã«ãæ£åžžã§ãªã Pod ã«ãã©ãã£ãã¯ãã«ãŒãã£ã³ã°ãããŠããŸãããµãŒãã¹ã«åœ±é¿ãåºãããšãé²ãããšãã§ããŸãã åè : ã³ã¹ããæé©åããã Kubernetes ã¢ããªã±ãŒã·ã§ã³ã GKE ã§å®è¡ããããã®ãã¹ã ãã©ã¯ãã£ã¹ - ã¢ããªã±ãŒã·ã§ã³ã«æçšãª readiness probe ãš liveness probe ãèšå®ãã GKE ããã® Google API ãžã®èªèšŒ GKE ã§å®è¡ãããŠããã¢ããªã±ãŒã·ã§ã³ãã Google Cloud ãµãŒãã¹ãžã¢ã¯ã»ã¹ããéã®æšå¥šäºé
ã確èªããŠãããŸãããã GKE ãã Google Cloud API ãžã®èªèšŒæ¹æ³ã®æåã®éžæè¢ã¯ Workload Identity æ©èœã§ãããã㯠Kubernetes ã®ãµãŒãã¹ã¢ã«ãŠã³ããš Google Cloud ã®ãµãŒãã¹ã¢ã«ãŠã³ããçŽã¥ããæ©èœã§ããGKE ã³ã³ãããããããš Kubernetes ãµãŒãã¹ã¢ã«ãŠã³ãã®ã¿ãæèããã°è¯ããã Kubernetes ãªãœãŒã¹ãš Google Cloud ãªãœãŒã¹ãççµåã«ãªããä¿å®æ§ãåäžããŸãã åè : GKE ã¯ãŒã¯ããŒããã Google Cloud API ã«å¯ŸããèªèšŒãè¡ã ããŒã¿ããŒã¹ã»åæ ããŒã¿åæãã©ãããã©ãŒã ã®éžæ Google Cloud ã®ããŒã¿åæç³»ãµãŒãã¹ã¯å€æ°ãããŸããããããããã©ããªãŠãŒã¹ã±ãŒã¹ã®ãšãã«éžæããã®ããæŒãããŠãããŸããããCloud SQLãDatastoreïŒFirestoreïŒãBigtableãSpannerãBigQuery ã®ç¹æ§ããããããèªåã®èšèã§èª¬æã§ããã§ããããïŒ éçšç®¡çã®ç¥èãåããããšãã®åããŠãããããã®ããŒã¿ããŒã¹ã®ããã¯ã¢ããæ¹æ³ãªã©ãæããŠãããŸãããã 以äžã®èšäºã®ããã®ä»ã®ããŒã¿ããŒã¹ã»ç§»è¡ãã®é
ã«ãŠãããŒã¿ããŒã¹ããšã®ãŠãŒã¹ã±ãŒã¹ãæžããŠããŸãã®ã§ãåç
§ãã ããã åè : Professional Data Engineer詊éšå¯Ÿçããã¥ã¢ã«ãåºé¡åŸåã»ååŒ·æ¹æ³ - G-gen Tech Blog - ããŒã¿ããŒã¹ã®éžæ äŸãã° Bigtable ã¯é«ã¹ã«ãŒããããåºãããŒã¿ããŒã¹ã§ããIoT ãã¢ããªã±ãŒã·ã§ã³ã®ãã©ããã³ã°ã®ãããªç§éæ°äžã®æžã蟌ã¿ãªã¯ãšã¹ãããããããªå Žåã«é©ããŠããŸããäžæ¹ã§æšæºç㪠SQL ã«ã¯å¯Ÿå¿ããŠããªãããã SQL ã§ã®æäœãå¿
èŠãªå Žåãããã©ã³ã¶ã¯ã·ã§ã³åŠçãå¿
èŠãªå Žåã«ã¯ Cloud SQL ã Spanner ãæ€èšããããšã«ãªããŸãã Firebase ã¯ãµãŒããŒã¬ã¹ã§ãªã¯ãšã¹ãæ°ã«å¿ããåŸé課éã§ãããããããŸãã¯ãŒã¯ããŒããå€ããªãã·ã¹ãã ã«ãããŠã³ã¹ããéèŠããå Žåãªã©ã«éžæã§ããŸãã åçš®ããŒã¿ããŒã¹ãµãŒãã¹ã«ã€ããŠã以äžã®èšäºãåèã«ããŠãã ããã åè : Cloud SQLã培åºè§£èª¬ïŒ - G-gen Tech Blog åè : Cloud Spanner ã培åºè§£èª¬ïŒ - G-gen Tech Blog åè : BigQueryã培åºè§£èª¬ïŒ(åºæ¬ç·š) - G-gen Tech Blog åè : Bigtableã培åºè§£èª¬ïŒ - G-gen Tech Blog åè : Firebaseã培åºè§£èª¬ïŒ - G-gen Tech Blog åè : AlloyDB for PostgreSQLã培åºè§£èª¬ïŒ - G-gen Tech Blog Cloud SQL ãªã³ãã¬ãã¹ããã®ããŒã¿ããŒã¹ïŒRDBïŒã®ç§»è¡å
ãšããŠã¯ Cloud SQL ãéžæãããããšãå€ãã¯ãã§ããã©ã®ãããªææ³ã§ç§»è¡ãã§ããããçè§£ããŠãããŸãããã ãŸããããã¯ã¢ãããšãªã¹ãã¢ã®æ¹æ³ãåé·åã®æ¹æ³ãªã©ãå¯çšæ§ã«é¢ããå
容ã¯èªä¿¡ããã£ãŠèšèšã»å®è£
ã§ãããããã«ææ¡ããŠãããŸãã èªåããã¯ã¢ããæ©èœã«å ãããã©ã³ã¶ã¯ã·ã§ã³ãã°ã®ä¿åæ¥æ°æå®ãªã©ãè¡ããç¹ãæŒãããŠãããŸãããŸãããã€ã³ãã€ã³ã¿ã€ã ãªã«ããªïŒPITRïŒæ©èœããçšããã«ã¯ãèªåããã¯ã¢ãããšãã€ã³ãã€ã³ã¿ã€ã ãªã«ããªã äž¡æ¹æå¹ã«ãã å¿
èŠããããŸãã PITR ã«ãããããŒã¿ããŒã¹ãç¹å®æå»ã®ç¶æ
ã§åŸ©æ§ããããšãã§ããŸãããã ããå
ã®ã€ã³ã¹ã¿ã³ã¹ãšã¯å¥ã€ã³ã¹ã¿ã³ã¹ãšããŠæ§ç¯ãããããšã«ãªããŸãã 以äžã®èšäºãåèã«ããŠãCloud SQL ã®ä»æ§ãäžéãçè§£ããŸãããã blog.g-gen.co.jp Cloud Storage Cloud Storageã®åºæ¬çãªä»æ§ãæŠå¿µã¯ Associate 詊éšã§æŒãããŠããã¯ãã§ããããã«ä»¥äžã®ãããªãã€ã³ããæŒãããŠãå¿çšçãªäœ¿ãæ¹ãçè§£ããŸãããã IAM ã«ããã¢ã¯ã»ã¹å¶åŸ¡ ãªããžã§ã¯ãã®ããŒãžã§ãã³ã° ä¿æããªã·ãŒãšä¿æããªã·ãŒã®ãã㯠ã¹ãã¬ãŒãžã¯ã©ã¹ïŒStandardãNearlineãColdlineãArchiveïŒ ä»¥äžã®èšäºã§ Cloud Storage ã®äžéãã®ä»æ§ã解説ããŠããŸãã®ã§ããåç
§ãã ããã blog.g-gen.co.jp ã³ã³ãã¥ãŒããµãŒãã¹ æŠèŠ Google Cloud ã®ã³ã³ãã¥ãŒããµãŒãã¹ã§ãã Compute EngineãCloud RunãCloud Run functionsãApp Engine ã«ã€ããŠãåãããã¯ãã®ã¢ãŒããã¯ãã£ãçšæ³ãéçšç®¡çããããã€ãã¹ã±ãŒãªã³ã°ãªã©ã®ç¹åŸŽãçè§£ããå¿
èŠããããŸãã ã©ã®ãããªãšãã«ã©ã®ãããã¯ããéžæããã®ãïŒããããã®ãããã¯ãã®åŒ·ã¿ã¯äœãïŒ ãå¯çšæ§ãé«ããæ¹æ³ã¯ïŒ ã³ã¹ããæé©åããã«ã¯ïŒ å®å
šã«ã¢ããªã±ãŒã·ã§ã³ã®æ°ããŒãžã§ã³ããããã€ããŠç§»è¡ããæ¹æ³ã¯ïŒ äŸãã° Cloud Run ã§ã¯ã æ°æ§ããŒãžã§ã³éã§ãã©ãã£ãã¯ãåŸã
ã«ç§»è¡ ããããšãã§ããŸããå²åãæå®ããããšã§ããæ°ããŒãžã§ã³ã«10%ãæ§ããŒãžã§ã³ã«90%ã®ãã©ãã£ãã¯ãã«ãŒãã£ã³ã°ããåé¡ãªãããšãããã£ãããåŸã
ã«%ãå€ããŠããããšãã£ãéçšãå¯èœã§ãã åè : ããŒã«ããã¯ã段éçãªããŒã«ã¢ãŠãããã©ãã£ãã¯ã®ç§»è¡ ãŸããéçãã¡ã€ã«ã¯ Cloud Storage ã«é
眮ã軜éãªããã¯ãšã³ã API 㯠Cloud Run functions ã§å®è£
ãããã³ãã«ã¯ Cloud Load Balancing ã眮ãããšãã£ã ã¯ã©ãŠããã€ãã£ããªã¢ãŒããã¯ã㣠ã¯å¯çšæ§ã»ã³ã¹ãå¹çãé«ãããšãçè§£ããŸãããã ãã®ããã«ããããã¯ãã®ç¹æ§ã掻ãããã¢ãŒããã¯ãã£ããããã€æ¹æ³ãªã©ãåãããŸãã 以äžã®èšäºãåèã«ããŠãã ããã blog.g-gen.co.jp App Engine App Engine ã§ã¯ãéçšå·¥æ°ãäœã ã¹ã¿ã³ããŒã ç°å¢ãšããã詳现ãªã«ã¹ã¿ãã€ãºãã§ãã ãã¬ãã·ãã« ç°å¢ãéžæã§ããŸãã ãããã€ã®å®¹æããéçšæ§ãåªå
ããå Žåã§ãéçºèšèªã JavaãNode.jsãGo ãªã©ãã¹ã¿ã³ããŒãç°å¢ã«å¯Ÿå¿ããŠããããã°ã©ãã³ã°èšèªã§ããå Žåã¯ãã¹ã¿ã³ããŒããéžæè¢ã«ãªããŸãã åè : App Engine ç°å¢ãéžæãã ãŸããApp Engine ã«ã¯æ°ããŒãžã§ã³ããããã€ããéããŸãã¯å¥ã® URL ãžæ°ããŒãžã§ã³ããããã€ããŠããã¹ãå®äºåŸã«ä»»æã®ã¿ã€ãã³ã°ã§æ¬çªææ Œããæ©èœããããŸãã åè : ã¢ããªã±ãŒã·ã§ã³ããã¹ãããŠãããã€ãã - ãã©ãã£ãã¯ç§»è¡åã® App Engine ã§ã®ãã¹ã ãŸããApp Engine ã®ãã¬ãã·ãã«ç°å¢ã¯ VPC ãããã¯ãŒã¯äžã® Compute Engine VM ã§å®è¡ãããäžæ¹ãã¹ã¿ã³ããŒãç°å¢ã¯ VPC å€ ã§å®è¡ãããŠããç¹ã«æ³šæãå¿
èŠã§ããã¹ã¿ã³ããŒãç°å¢ã® App Engine ã¢ããªã±ãŒã·ã§ã³ãã VPC ãªãœãŒã¹ããVPC ãããã¯ãŒã¯ãš VPN ãå°çšç·ã§æ¥ç¶ãããŠãããªã³ãã¬ãã¹ç°å¢ã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããã«ã¯ã ãµãŒããŒã¬ã¹ VPC ã¢ã¯ã»ã¹ ãèšå®ããå¿
èŠããããŸãã åè : App Engine ç°å¢ãéžæãã åè : VPC ãããã¯ãŒã¯ãžã®æ¥ç¶ CI/CD æŠèŠ Google Cloud ãµãŒãã¹ã䜿ã£ãŠ CI/CD ãã€ãã©ã€ã³ãæ§ç¯ããã«ã¯ã©ã®ãµãŒãã¹ã䜿ãããçè§£ããŠãããŸãããŸããåã³ã³ãã¥ãŒãã£ã³ã°ãµãŒãã¹ãžã®ã¢ããªã±ãŒã·ã§ã³ãããã€ã®æ¹æ³ãæŒãããŸããGoogle Cloud ãããã¯ãã§å®è£
ãã CI/CD ã§ã¯ã Cloud Build ãéèŠã§ãã Cloud Build ã¯ãã®ãµãŒãã¹åç§°ãããããšãã«ãå°çšã®ãµãŒãã¹ã«ãæããŸãããå®éã«ã¯ GKEãCloud RunãApp EngineãCloud Run functions ãªã©ãžã®ãããã€èªååã«ã䜿ãããŸãã Git ãªã©ã®ãœãŒã¹ã³ãŒãã¬ããžããªã®ç¹å®ã®ãã©ã³ãã«ããœãŒã¹ã³ãŒããã³ããããããããšãæ€ç¥ã㊠Cloud Build ãåãåºããã¢ããªã±ãŒã·ã§ã³ãã³ã³ããã®ãã«ãããã¹ããå®è¡ããããã®åŸ GKE ãªã©ã«ãããã€ããããšããäžé£ã®æµããåºæ¬ã§ãã åè : Google Cloud äžã§ã® DevOps ãš CI / CD ã«ã€ã㊠ã³ã³ããã»ãã¥ãªã㣠Binary Authorization ãšãããµãŒãã¹ã§ã¯ãGoogle Kubernetes EngineïŒGKEïŒã Cloud Run ã§ãçœ²åæžã¿ã®ã³ã³ããã€ã¡ãŒãžã以å€ã¯ãããã€ã§ããªãããã«ããæ©èœããããŸããããã«ãããæ€æ»ãããã»ãã¥ã¢ãªã€ã¡ãŒãžä»¥å€ã®ãããã€ãé²ãããšãã§ããŸãã åè : Binary Authorization ã®æŠèŠ VPC / ãããã¯ãŒã¯ VPC ã®åºæ¬ 以äžã®2èšäºãåèã«ã Virtual Private Cloud ïŒVPCïŒã®åºæ¬ã¯æ¹ããŠããããããŠãããŸãããã Google Cloud(æ§GCP)ã®VPCåºæ¬æ©èœãåŠã¶ïŒVPCã»ãµããããã»NATã»ãã¢ãªã³ã°ã»AWSãšã®éã - G-gen Tech Blog Google Cloudã®VPCã培åºè§£èª¬ïŒ(åºæ¬ç·š) - G-gen Tech Blog VPC ã«å¯ŸããŠãAssociate Cloud Engineer 詊éšãšåç以äžã®ã¬ãã«ã®çè§£ã¯å¿
èŠã§ããAssociate Cloud Engineer 詊éšå¯Ÿçèšäºã® VPC ã«é¢ããèšè¿°ããæ¹ããŠåèã«ããŠãã ããã åè : Associate Cloud Engineer詊éšå¯Ÿçããã¥ã¢ã«ãåºé¡åŸåã»ååŒ·æ¹æ³ - G-gen Tech Blog â VPC ãããã¯ãŒã¯ã»ãã¥ãªã㣠VPC ãã¡ã€ã¢ãŠã©ãŒã«ã®åºæ¬çãªä»æ§ã¯ãAssociate 詊éšãšåæ§ã«å¿
é ã§ãã ãŸã Cloud Armor ã®åºæ¬æŠå¿µããå®è£
æ¹æ³ïŒGoogle Cloud ã³ã³ãœãŒã«ããã³ gcloud ã³ãã³ãã©ã€ã³ïŒãæŒãããŠãããŸãããã åè : Cloud Armor ã»ãã¥ãªã㣠ããªã·ãŒãæ§æãã Cloud Armor ã¯ãã«ãããŒãžãã® WAF ãµãŒãã¹ã§ããL7 ã¬ãã«ã®æ»æãé²ãæ©èœã«å ããæ¥ç¶å
IP ã¢ãã¬ã¹ãå¶éããããšãã§ããŸããFastly ãªã©ã® CDN ããã®ãã©ãã£ãã¯ã¯èš±å¯ã§ãããããååä»ã IP ã¢ãã¬ã¹ãªã¹ããçšæãããŠããŸããFastly ã§èšãã° sourceiplist-fastly ãšãããããªãªã¹ãåã§ãã Cloud Armor ã®åºæ¬ã¯ä»¥äžã®èšäºã§ææ¡ããããšãã§ããŸãã blog.g-gen.co.jp æ¥ç¶æ§ æŠèŠ ç°ãªã VPC ãããã¯ãŒã¯ã«ååšãã VM å士ã§éä¿¡ããã«ã¯ã©ãããã°ãããããšãã£ãå¿çšçãªæ¹æ³ãçè§£ããŠãããŸãã以äžã®ããããã®ç¹åŸŽãçè§£ããŠãã ããã VPC éã§ VPC ãããã¯ãŒã¯ãã¢ãªã³ã°ãæ¥ç¶ãã VPC éã§ Cloud VPN ã䜿ã£ãŠæ¥ç¶ãã è€æ°ã® VPC ã® NIC ã VM ã«è¿œå ãã VPC ãããã¯ãŒã¯ãã¢ãªã³ã° ã䜿ããšãç°ãªã VPC ãããã¯ãŒã¯éãæ¥ç¶ã§ããŸããå©çšæéããããããæãã³ã¹ãå¹çã®è¯ãæ¹æ³ã§ããVPC ãããã¯ãŒã¯å士ãç°ãªããããžã§ã¯ãã ç°ãªãçµç¹ ã«æå±ããŠããŠããVPC ãããã¯ãŒã¯ãã¢ãªã³ã°ã䜿ãããšãã§ããŸãã åè : VPC ãããã¯ãŒã¯ ãã¢ãªã³ã° VPC éã®æšç§»çéä¿¡ VPC ãããã¯ãŒã¯ãã¢ãªã³ã°ã§2ã€ã® VPC ãããã¯ãŒã¯ãæ¥ç¶ãããšãèªåçã«ã«ãŒãã亀æãããçžäºã«éä¿¡ã§ããããã«ãªããŸãããã ã以äžã®ãããªå Žåã VPC A ãš VPC C å士ã¯éä¿¡ã§ããŸããã VPC A ===(Peering)=== VPC B ===(Peering)=== VPC C VPC A ãš C ã¯çŽæ¥ç¹ãã£ãŠããªãã®ã§ããäºãã«éä¿¡ã§ããŸããããã®ç¹æ§ããVPC ãããã¯ãŒã¯ãã¢ãªã³ã°ã§ã¯ãæšç§»çãªæ¥ç¶ã¯ã§ããªãããšè¡šçŸããŸããä¿ã«ãããã2ãããå¶éããšåŒã¶ããšããããŸãã ãã ãããã®æ§æã VPC ãããã¯ãŒã¯ãã¢ãªã³ã°ã§ã¯ãªã Cloud VPN ã§æ§æããã°ãé©åãªã«ãŒã亀æãèšå®ããåæã§ãæšç§»çãªéä¿¡ãå¯èœã§ãã ãã€ããªãããããã¯ãŒã¯ ãªã³ãã¬ãã¹ãããã¯ãŒã¯ãš VPC ãããã¯ãŒã¯ãæ¥ç¶ããããã®æ§ã
ãªæ¹æ³ãçè§£ããŠãããŸãããã Google Cloud ã«ã¯ã Dedicated Interconnect ã Partner Interconnect ã ãã€ã¬ã¯ããã¢ãªã³ã° ã ãã£ãªã¢ãã¢ãªã³ã° ãšåŒã°ãã4ã€ã®ã©ã€ããŒãæ¥ç¶æ¹æ³ãããããããããŠãŒã¹ã±ãŒã¹ãç°ãªããŸãã 现ããèšå®ãŸã§ã¯çè§£ããå¿
èŠã¯ãããŸãããã ã©ã®ãããªãšãã«ã©ããéžã¶ã ãçè§£ããŠãããŸãããã ãªã³ãã¬ãã¹ãã Google Cloud ã® VPC ãããã¯ãŒã¯ãžãã©ã€ããŒãæ¥ç¶ã確ç«ããããã«ã¯ãDedicated InterconnectïŒå°æåå°çšç·ïŒãŸã㯠Partner InterconnectïŒå
±æåå°çšç·ïŒãéžæããŸãããããã®å°çšç·ãµãŒãã¹ã䜿ãããšã§ãCloud VPN ã«æ¯ã¹ãŠãå®å®ãã垯åãšã¬ã€ãã³ã·ã確ä¿ã§ããŸãã äžæ¹ã§ãGoogle Workspace çã® Google ãµãŒãã¹ã«æ¥ç¶ããããšãã« ãã€ã¬ã¯ã ãã¢ãªã³ã°ïŒå°æåå°çšç·ïŒããã£ãªã¢ãã¢ãªã³ã°ïŒå
±æåå°çšç·ïŒãéžæããŸãã å°æåãå
±æåããšãã芳ç¹ã§ã¯ãèªç€Ÿã»ããŒã¿ã»ã³ã¿ãŒçãã Google ã® PoPïŒPoint of PresenceïŒã«çŽæ¥æ¥ç¶ã§ããå Žåã§ããããã€å®å®çã§åºã垯åãæ±ããããå Žåã«ãå°æåã§ãã Dedicated Interconnect / ãã€ã¬ã¯ããã¢ãªã³ã°ãéžæããŸããäžæ¹ã§ã³ã¹ããéèŠãããå Žåã¯ãå
±æåã§ãã Partner Interconnect / ãã£ãªã¢ãã¢ãªã³ã°ãéžæããŸãã åè : Network Connectivity ãããã¯ãã®éžæ å¯çšæ§ SLA Cloud VPN ã Cloud Interconnect ã®å¯çšæ§ã«ã€ããŠãçè§£ããŠãããŸãã Cloud VPN ã§èšãã°ã99.99% ã®å¯çšæ§ SLA ãé©çšãããã«ã¯ã以äžã®æ§æã§ããå¿
èŠããããŸãã 1å°ã® HA VPN ã²ãŒããŠã§ã€ãã2å°ã®ãã¢ããã€ã¹ã«æ¥ç¶ïŒãã³ãã«æ°ã¯2ïŒ 1å°ã® HA VPN ã²ãŒããŠã§ã€ããå€éš IP ã¢ãã¬ã¹ã2ã€æã€1å°ã®ãã¢ããã€ã¹ã«æ¥ç¶ïŒãã³ãã«æ°ã¯2ïŒ 1å°ã® HA VPN ã²ãŒããŠã§ã€ãã1ã€ã®å€éš IP ã¢ãã¬ã¹ãæã€1å°ã®ãã¢ããã€ã¹ã«æ¥ç¶ïŒãã³ãã«æ°ã¯2ïŒ ã€ãŸãããã³ãã«ã2ã€ç¢ºç«ãããŠããã°ããªã³ãã¬åŽã®ã«ãŒã¿ã1å°ã§ãã99.99%ã® å¯çšæ§ SLA ã®å¯Ÿè±¡ã«ãªããŸã ããã ã HA VPN ã²ãŒããŠã§ã€åŽã¯ã2ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããå¿
èŠããããŸãã 以äžã®ããã¥ã¡ã³ããåç
§ããæ§æãçè§£ããŠãããŠãã ããã åè : HA VPN ããããž - 99.99% ã®å¯çšæ§ SLA çšã«æ§æãã åè : Dedicated Interconnect ã§ 99.99% ã®å¯çšæ§ãå®çŸãã Compute Engine Compute Engine ã®åºæ¬ Compute Engine ã®åºæ¬çãªä»æ§ã¯ãAssociate 詊éšãšåæ§ã§ããããã«ãéçšã«ãããéèŠãšãªãå¿çšçãªæŠå¿µãå ããŠçè§£ããŠãããŸãããã blog.g-gen.co.jp ãããŒãžãã€ã³ã¹ã¿ã³ã¹ã°ã«ãŒã ãããŒãžãã€ã³ã¹ã¿ã³ã¹ã°ã«ãŒãïŒMIGïŒã«ãããã€ã³ã¹ã¿ã³ã¹ã®ã¢ããããŒãã®ä»æ§ãåãããããšããããŸãã MIG ã§ã€ã³ã¹ã¿ã³ã¹ãæŽæ°ãããšããæ¹æ³ããèªåæŽæ°ïŒAutomatic ãŸã㯠proactiveïŒããéžæïŒselective ãŸã㯠opportunisticïŒãã®äºçš®é¡ããããŸããåè
ã¯ã€ã³ã¹ã¿ã³ã¹ã®æŽæ°ãèªåçã«ãããŸããåŸè
ã¯æåã§åœä»€ãããšããæ°ã€ã³ã¹ã¿ã³ã¹ãäœæããããšãã«ã®ã¿æŽæ°ãããŸããæ¥äžã®çšŒåãæ¿ããã·ã¹ãã ãªã©ã§ã¯ãèªåæŽæ°ïŒproactive æŽæ°ïŒã¯ãªã¹ã¯ã倧ãããããé¿ããããšãæ€èšããŸãã åè : MIG ã§ VM æ§æã®æŽæ°ãèªåçã«é©çšãã â ã¿ã€ãã®æŽæ° ãªãŒãžã§ã³æ°žç¶ãã£ã¹ã¯ãå©çšããå¯çšæ§åäž ãªãŒãžã§ã³æ°žç¶ãã£ã¹ã¯ ã¯ãCompute Engine VM ã«ã¢ã¿ããå¯èœãªæ°žç¶ãã£ã¹ã¯ã§ããéåžžã®æ°žç¶ãã£ã¹ã¯ããŸãŒã³ãªãœãŒã¹ãªã®ã«å¯ŸããŠããªãŒãžã§ã³æ°žç¶ãã£ã¹ã¯ã¯ãªãŒãžã§ã³ãªãœãŒã¹ã§ããããçæ¹ã®ãŸãŒã³ã§é害ãçºçããŠããããŒã¿ã¯å¥ã®ãŸãŒã³ã«è€è£œãããŸãã Compute Engine VM ãè€æ°ã®ãŸãŒã³ã«ãããã€ããçŸçšç³»ãšåŸ
æ©ç³»ã®ã¢ã¯ãã£ã/ã¹ã¿ã³ãã€æ§æãåã£ãŠããå ŽåãçŸçšç³»ã®ãŸãŒã³ã忢ããŠãããªãŒãžã§ã³æ°žç¶ãã£ã¹ã¯ã§ããã°åŸ
æ©ç³»ã® VM 㫠匷å¶ã¢ã¿ãã ã§ããŸããããã«ãããå¯çšæ§ã®é«ãæ§æãå®çŸã§ããŸãã åè : ãã£ã¹ã¯ã®åæã¬ããªã±ãŒã·ã§ã³ã«ã€ã㊠åè : åæçã«è€è£œããããã£ã¹ã¯ã䜿çšã㊠HA ãµãŒãã¹ãæ§ç¯ãã ã©ã€ã»ã³ã¹ã®æã¡èŸŒã¿ Windows Server ã®ã©ã€ã»ã³ã¹ã¯ãäžå®æ¡ä»¶äžã§ Google Cloud ã«æã¡èŸŒãïŒBYOLïŒããšãã§ããŸãã以äžã®ããã¥ã¡ã³ããåèã«ãäžé£ã®æµããææ¡ããŠãã ããã åè : ãå®¢æ§ææã©ã€ã»ã³ã¹ã®äœ¿ ã©ã€ã»ã³ã¹ã®æã¡èŸŒã¿ã«ã¯ããªã³ãã¬ãã¹ã®ä»®æ³ãã·ã³ã®ãä»®æ³ãã£ã¹ã¯ãã¡ã€ã«ã Compute Engine ã«ã€ã³ããŒãããã€ã¡ãŒãžãäœæããŸãããŸãããããã€å
ã® Compute Engine ã¯ãç©ççã«å°æããã åäžããã³ãããŒã ã§ããå¿
èŠããããŸãã ãã®ä» 以äžã®ãããªçްãã仿§ãæŒãããŠãããŠãã ããã Cloud IAP Linux VM ã§ã®èµ·åã¹ã¯ãªããã®äœ¿çš ãªãŒããŒããããžã§ãã³ã°ïŒCPU ãã¡ã¢ãªãéå°ã«ã¢ãµã€ã³ãããŠãã VMïŒã«å¯ŸããŠæšå¥šäºé
ã衚瀺ããæ¹æ³ Spot VM ãã®ä»ã®ãããã¯ã 以äžã®ãããªãµãŒãã¹ãåºé¡ç¯å²ãšãªã£ãŠããŸãã现ããäœ¿ãæ¹ãŸã§åããã°çæ³çã§ãããæ¥åã§äœ¿ã£ãããšããªããã°ãæäœã§ããã©ã®ãããªãµãŒãã¹ãããã©ã®ãããªãšãã«ãã©ã®ããã«å©çšãããã®ãããªã©ãæŒãããŠãããŸãããã Migrate for Compute Engine ã©ã³ãã㯠ãšããèšèãææ¡ããŠãã Cloud Memorystore Cloud Filestore Fire store ã§ã¯ãªã File store éžæå¯èœãª Service Tier ãææ¡ãããŠãŒã¹ã±ãŒã¹ãã¹ã«ãŒãããäžã®éçå€ã確èªããŠãã Cloud Scheduler Anthos Service Mesh / Anthos Config Management Dataproc ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO å
èŠå¯å®ãšããçµæŽãæã€ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS èªå®è³æ Œããã³ Google Cloud èªå®è³æ Œã¯ãã¹ãŠååŸãXïŒæ§ TwitterïŒã§ã¯ Google Cloud ã Google Workspace ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
ããã«ã¡ã¯æ ªåŒäŒç€ŸG-genã®æž¡é@norryã§ãã ååã¯Businessãšãã£ã·ã§ã³ã§ã®ç«¯æ«ç®¡çãã話ããŸãããä»åã¯ãã®Enterpriseãšãã£ã·ã§ã³ç·šã«ãªããŸãã blog.g-gen.co.jp ä»åã¯äž»ã«å©çšäººæ°300å以äžã®Enterpriseãšãã£ã·ã§ã³ã§ç«¯æ«ç®¡çãå©çšãããå Žåã«ãGoogle Workspace Business Plusãšäœãéãã®ããç¥ãããæ¹ã®ãåèã«ãªãã°ãšæããŸãã è£è¶³ã«ãªããŸããEnterpriseãšãã£ã·ã§ã³ã¯300å以äžã®çµç¹ã§ãå©çšå¯èœãšãªã£ãŠããŸãã®ã§ããå©çšããããæ©èœãããå Žåã«ã¯éžæè¢ãšããŠã芧ãã ããã Businessãšãã£ã·ã§ã³ãšEnterpriseãšãã£ã·ã§ã³ã®å
šäœæ¯èŒèšäºã¯ãã¡ãã«ãªããŸãã blog.g-gen.co.jp 端æ«ç®¡çãèããæã«ã©ã®Google Workspace Enterpriseãã©ã³ãéžã¶ã¹ãã Enterprise Standardåã³Plusãéžæããæ¹ãè¯ãã±ãŒã¹ 端æ«ç®¡çã«ãããŠã®Business Premiumãšã®éã Business Premiumãäžå®ã®ç®¡çæ©èœã¯åãã£ãŠãã Google Workspaceãå°å
¥ãããªãæ ªåŒäŒç€ŸG-genã«ãçžè«ãã ããã 端æ«ç®¡ç ãèããæã«ã©ã®Google Workspace Enterpriseãã©ã³ãéžã¶ã¹ãã Google Workspace Enterpriseãšãã£ã·ã§ã³ã«ã¯ãEnterprise EssentialsããEnterprise StandardããEnterprise Plusãã®3ã€ã®ãã©ã³ããããŸã ãããŠãã®ãã©ã³ã®ãã¡ç«¯æ«ç®¡çãèæ
®ããå Žåã«ãã©ã³ã®éžæè¢ãšããŠã¯äžèšã®ïŒã€ã«ãªããŸããEnterprise Essentialsã¯ç«¯æ«ç®¡çã®ãšã³ã¿ãŒãã©ã€ãº ãšã³ããã€ã³ãç®¡çæ©èœãåããŠããŸããã®ã§çç¥ããŠããŸãã Enterprise Standard Enterprise Plus ãã ãEnterprise Essentialsãåºæ¬ã®ãšã³ããã€ã³ã管çãšé«åºŠãªãšã³ããã€ã³ã管çã®æ©èœã¯åããŠããŸãã®ã§ã300å以äžã§ Gmailä»¥å€ ã®æ©èœãå©çšã端æ«ç®¡çã¯å¥ã®ãµãŒãããŒãã£ãŒè£œåã§ã«ããŒããã±ãŒã¹ã«ã¯è¯ãããšæããŸãã Enterprise Standardåã³Plusãéžæããæ¹ãè¯ãã±ãŒã¹ Google Workspaceã300å以äžã§ã®å©çšãšæ§ã
ãªOSïŒChrome OSãAndroid ãiOSãWindowsïŒãçµ±åçã«ç®¡çãããå Žåã«Enterprise Standardåã³Enterprise PlusãããããããŸãã ãã®ãã©ã³ã§ã¯MDM (Mobile Device Management)ã®é åãã«ããŒããŠããŸãããµãŒãããŒãã£ãŒã®MDMãå©çšããã«Google Workspaceã®ã¿ã§ç®¡çããå Žåã«ã¯ãã¡ããéžæãã ããã ãã ããEnterprise Standardåã³Plusã®ãã©ã³ã«ãã㊠端æ«ç®¡ç ã§äœ¿ããæ©èœã«ã€ããŠå·®ç°ã¯ãããŸããã 以äžãGoogle Workspace Enterpriseã®åãã©ã³ã®ç«¯æ«ç®¡çã«ãããæ©èœæ¯èŒè¡šã«ãªããŸãã Enterprise Essentials Enterprise Standard Enterprise Plus åºæ¬ã®ãšã³ããã€ã³ã管çïŒå€æ°ã®æ©èœïŒ â â â é«åºŠãªãšã³ããã€ã³ã管çïŒå€æ°ã®æ©èœïŒ â â â ãšã³ã¿ãŒãã©ã€ãº ãšã³ããã€ã³ã管ç ã¢ãã€ã«ã¢ããªãåå¥ã«é
åžãã â â ããã€ã¹ç£æ»ãã° â â 䜿ãããŠããªãäŒç€Ÿææããã€ã¹ã«é¢ããã¬ããŒã â â äŒç€Ÿææã® Android ããã€ã¹ â â äŒç€Ÿææã® iOS ããã€ã¹ â â Windows ããã€ã¹ç®¡ç â â iOS ããŒã¿ã®ä¿è· â â ããã€ã¹ã®ãªã¢ãŒãã¯ã€ãïŒWindowsïŒ â â ã¢ãã€ã« ããã€ã¹ã®èšŒææž â â 管çã«ãŒã« â â 端æ«ç®¡çã«ãããŠã®Business Premiumãšã®éã Google Workspace Business Premiumã«ã端æ«ç®¡çã®æ©èœã¯åãã£ãŠããŸãããã§ã¯Business PremiumãšEnterprise Standardåã³Plusã§ã®æ©èœé¢ã§ã®éãã¯äœã§ãããã Business Premiumãäžå®ã®ç®¡çæ©èœã¯åãã£ãŠãã äžèšãæ¯èŒè¡šã«ãªããŸããBusiness Premiumã®å ŽåChrome OSãAndroid OSã®ã¿å¯Ÿè±¡ãšãããšã©ã€ã»ã³ã¹ã®ç¯å²å
ã§ç®¡çãå¯èœã§ããEnterprise Standardåã³Plusã§ã¯ãiOSããã€ã¹ã®ç®¡çãWindowsããã€ã¹ã®ãªã¢ãŒãã¯ã€ãïŒæ¶å»ïŒãã¢ãã€ã«ããã€ã¹ã®èšŒææžãªã©ããšã³ã¿ãŒãã©ã€ãºãªç°å¢ã§è€æ°ã®OSã管çããå Žåã«å¿
é ãªæ©èœãåãã£ãŠããäºãåãããŸãã Business Plus Enterprise Standard Enterprise Plus åºæ¬ã®ãšã³ããã€ã³ã管çïŒå€æ°ã®æ©èœïŒ â â â é«åºŠãªãšã³ããã€ã³ã管çïŒå€æ°ã®æ©èœïŒ â â â ãšã³ã¿ãŒãã©ã€ãº ãšã³ããã€ã³ã管ç ã¢ãã€ã«ã¢ããªãåå¥ã«é
åžãã â â â ããã€ã¹ç£æ»ãã° â â â 䜿ãããŠããªãäŒç€Ÿææããã€ã¹ã«é¢ããã¬ããŒã â â â äŒç€Ÿææã® Android ããã€ã¹ â â â äŒç€Ÿææã® iOS ããã€ã¹ â â Windows ããã€ã¹ç®¡ç â â iOS ããŒã¿ã®ä¿è· â â ããã€ã¹ã®ãªã¢ãŒãã¯ã€ãïŒWindowsïŒ â â ã¢ãã€ã« ããã€ã¹ã®èšŒææž â â 管çã«ãŒã« â â 以äžãããã©ã®çš®é¡ïŒOSïŒã®ç«¯æ«ãã©ã®çšåºŠç®¡çãããïŒãã°ã€ã³ãããªãããããã¯ãããçŽå€±æã®ã¯ã€ããªã©ïŒãã«ãã£ãŠãã©ã³ããæ€èšãã ããã Google Workspaceãå°å
¥ãããªãæ ªåŒäŒç€ŸG-genã«ãçžè«ãã ããã Google Workspaceã䜿ã£ãåãæ¹ã«å€ãããšæ¬åœã«çµç¹ã®ã³ãã¥ãã±ãŒã·ã§ã³ãšã³ã©ãã¬ãŒã·ã§ã³ã®ããæ¹ãå€ãã£ãŠã³ã£ãããããšæããŸãã ãã®æåãããå€ãã®äººã«äœæããŠãããããã§ããã æ ªåŒäŒç€ŸG-genã§ã¯Google Workspace / Google CloudïŒGCPïŒã5%å²åŒã§ãæäŸããŠãããŸãã g-gen.co.jp ãŸããGoogle Workspace / Google CloudïŒGCPïŒ/ Chrome book ã®å°å
¥ããéçšãŸã§ã®ãæ¯æŽãè¡ã£ãŠããŸãã®ã§ãæ€èšã®éã«ã¯ãã²ã声ãããã ããã ãåãåããã¯ãã¡ããã docs.google.com æž¡é å®£ä¹ (èšäºäžèЧ) ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš ããŒã¿åæåºç€ã®æ§ç¯ãã¯ã©ãŠã管çéçšããããã¯ãŒã¯ãå®åç¯å²ãGoogle Workspace æŽ»çšæšé²äžãGoogle Cloud èªå®è³æ Œã¯4è³æ Œä¿æ 鱿«ãã©ãã°ã©ãã¡ãŒã§ãèŠ³èæ€ç©ã塿 ¹æ€ç©ã«ããã£ãŠãŸãã
G-gen ã®ææã§ããåœèšäºã§ã¯ Google CloudïŒæ§ç§° GCPïŒã®èªå®è©Šéšã®äžã§ãåºæ¬çãªã¬ãã«ã®å
容ã§ãã Associate Cloud Engineer è©Šéš ã®åæ Œã«åœ¹ç«ã€æ
å ±ãèšèŒããŸãã ã¯ããã« åœèšäºã«ã€ã㊠詊éšã®æŠèŠ è©Šéšã®é£æåºŠ æšå¥šã®ååŒ·æ³ å¯Ÿçæžç± æŽæ°è©Šéš åºé¡åŸå çµç¹ãšãªãœãŒã¹ ãªãœãŒã¹éå±€ã®æŠå¿µ ãããžã§ã¯ããš API æå¹å çµç¹ã®ããªã·ãŒ IAM IAM ã®åºæ¬æŠå¿µ IAM ããŒã«ã¯ã¢ã«ãŠã³ãã§ã¯ãªãã°ã«ãŒãã«ä»äž åºæ¬ããŒã«ãšäºåå®çŸ©ããŒã« ãµãŒãã¹ã¢ã«ãŠã³ã VPC VPC ãšãµããããã®åºæ¬ ã»ã°ã¡ã³ããšãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã« éå®å
¬éã® Google ã¢ã¯ã»ã¹ Cloud DNS Cloud Load Balancing Compute Engine åºç€ç¥è ãã£ã¹ã¯ã»ããã¯ã¢ããã»ãªã¹ã㢠賌å
¥ãªãã·ã§ã³ ã³ã³ãã¥ãŒãã£ã³ã°ãµãŒãã¹ App Engine Google Kubernetes EngineïŒGKEïŒ Cloud Run ã³ã³ãã¥ãŒãã£ã³ã°ãµãŒãã¹ã®äœ¿ãåã Cloud Storage ããŒã¿ããŒã¹ãããŒã¿åæ Cloud SQL BigQuery Spanner ããŒã¿ããŒã¹ã®ãã¹ããªéžæ ããŒã¿ãã€ãã©ã€ã³ Google Cloud Observability Cloud Monitoring Cloud Logging Cloud Audit Logs æé è«æ±å
ã¢ã«ãŠã³ã äºç®ã¢ã©ãŒã å©çšæéã®èŠç©ãšã¢ãŒããã¯ã㣠å©çšæéããŒã¿ã® BigQuery ãžã®ãšã¯ã¹ããŒã Access Approval ãã®ä» Google Cloud ã®å²åŠ åéšç°å¢ ã¯ããã« åœèšäºã«ã€ã㊠åœèšäºã§ã¯ Google CloudïŒæ§ç§° GCPïŒã®èªå®è©Šéšã®äžã§ãåºæ¬çãªã¬ãã«ã®å
容ã§ãã Associate Cloud Engineer è©Šéš ã®åæ Œã«åœ¹ç«ã€æ
å ±ãèšèŒããŸãã 詊éšã® å©çšèŠçŽ ã«ãããŠã詊éšã®å
容ãå
¬éããããšã¯çŠããããŠããŸããæ¬æçš¿ã§ã¯è©Šéšåé¡ãã®ãã®ãæžãããšçã¯ããã åæ Œããããã«ã¯äœãç¥ã£ãŠããã¹ãã ããäžå¿ã«èšèŒããŸãã ãªãåœèšäºã«èšèŒãããŠããããšã§è©Šéšç¯å²ããã¹ãŠã«ããŒã§ããŠããããã§ã¯ãªãç¹ããäºæ¿ãã ãããå
¬åŒã§çºè¡šãããŠãã 詊éšã¬ã€ã ã æš¡æ¬è©Šéš ãé§äœ¿ããŠãåŠç¿ãé²ããŠãã ããã ãŸãåœè©Šéšã¯ã2024幎8æ26æ¥ã«è©Šéšå
å®¹ãæ¹èšãããŠããŸãïŒ2024幎11ææç¹ã§ã¯è±èªçã®ã¿ãæ¥æ¬èªçã«ã¯æªåæ ïŒãåœèšäºã¯æ°æ§ã©ã¡ãã®è©Šéšã«ã察å¿ã§ãã Tips ãèšèŒããŠããŸãããã©ã¡ãããšãããšæ°è©Šéšå¯ãã®å
容ãèšèŒãããŠããããšã«ãçæãã ããïŒåœèšäºã¯ã2024幎11æã«ææ°åãããŸããïŒã 詊éšã®æŠèŠ Associate Cloud Engineer è©Šéš ã¯ã Google Cloud ã®èªå®è©Šéšã®äžã§ãåºæ¬çãªè©Šéšã§ãã Google Cloud ã®ã€ã³ãã©ç³»ãµãŒãã¹ãäžå¿ã«ãã»ãã¥ãªãã£ãã¢ããªã±ãŒã·ã§ã³ãã¹ãã£ã³ã°ãããŒã¿ããŒã¹ãã¢ãã¿ãªã³ã°ãªã©ãå¹
åºãç¯å²ã察象ã§ããè©Šéšæéã¯120åã詊éšå顿°ã¯50åã§ãã 詊éšã¯æ¥æ¬èªãè±èªãã¹ãã€ã³èªããã«ãã¬ã«èªã§æäŸãããŠããŸãã åè : Associate Cloud Engineer ä»ã®è©ŠéšäžèЧã¯ä»¥äžããåç
§ãã ããã åè : Google Cloud èªå®è³æ Œ 詊éšã®é£æåºŠ åœè©Šéšã®é£æåºŠãšããŠã¯ãä»ã® Google Cloud èªå®è³æ Œãšæ¯èŒããŠã æ¯èŒçç°¡åã§ãã ãšèšããŸãã åæç¥èãšããŠãIPA ã®åºæ¬æ
å ±æè¡è
詊éšçšåºŠã®åºæ¬ç㪠IT ã®ç¥èããããã〠Google Cloud ã«é¢ããå€å°ã®æ¥åçµéšãæã£ãŠããããšãæãŸããã§ããå
¬åŒã¬ã€ãã«ã¯ã6ã¶æä»¥äžã® Google Cloud ã«ãããå®åçµéšããæšå¥šã§ãããšèšèŒãããŠããŸãããå¿
ããããããæºãããŠããªããŠããåååæ ŒãçããŸãã ãŸãæ®æ®µãã Google Cloud ã®å
¬åŒããã°ãããã¥ã¡ã³ãã®ãã¹ããã©ã¯ãã£ã¹ã«ç®ãéãããGoogle ã®èããã¯ã©ãŠããããããšãããäžçš®ã®ãã¯ã©ãŠãå²åŠãã«æ
£ããŠããããšãéèŠã§ããããã«å ããŠãåœèšäºã§è¿œå ã®åŠç¿ãããã°ãåæ Œã¯é£ãããªããšèšããŸãã æšå¥šã®ååŒ·æ³ æžç±ãå
¬åŒã®ãã¬ãŒãã³ã°ãåã Google Cloud ã®åºæ¬ãçè§£ãã 詊éšã¬ã€ã ãèªã¿åºé¡ç¯å²ãçè§£ãã åœèšäºãèªã¿ãåºé¡åŸåãçè§£ãã çè§£ãã詊éšç¯å²ã»åºé¡åŸåãããšã«å匷ãã æš¡æ¬è©Šéš ãåããè¶³ããªãç¥èãèªèããŠãã®ã£ãããåããå匷ããã äžèšã®ãã¡ 1. ã®åºç€åŠç¿ã«ã€ããŠã¯ãæžç±ãæ¥æ¬èªã§ããã€ãåºçãããŠããã®ã«å ãã Google Cloud Japan 瀟ã宿çã«ã»ãããŒãªã©ãéå¬ããŠããŸãã åèãšããŠã Google Cloud Certification Jumpstart ããã°ã©ã ãšããããã°ã©ã ããããŸãã以äžã®ãµã€ãã§ã¯ãéå»ã®ã»ãã·ã§ã³å
容ãåç»ã§é²èЧããããšãã§ããŸãã åè : 第 2 å Google Cloud Certification Jumpstart ããã°ã©ã å¯Ÿçæžç± è©Šéšå¯Ÿçã®æžç±ã䜿ã£ãŠåŠç¿ããã®ãæçšã§ããG-gen ã®ãšã³ãžãã¢ãå·çãããAssociate Cloud Engineer 詊éšã®å¯Ÿçæžç±ãåºçãããŠããŸãã åæ Œå¯Ÿç Google Cloudèªå®è³æ ŒAssociate Cloud Engineer ããã¹ãïŒæŒç¿åé¡ äœè
: ææ å銬 , äœã
æš é§¿å€ª , è€å²¡ éçŸ ãªãã¯ãã¬ã³ã Amazon æŽæ°è©Šéš åœè©Šéšã«ã¯ãåããŠåéšãããšãã«åãã詊éšã®ã»ãã«ãæŽæ°æã«åéšã§ãã æŽæ°è©Šéš ããããŸããæŽæ°è©Šéšã¯ãè³æ Œã®æå¹æéã® 60 æ¥åãã 30 æ¥åŸãŸã§ã®éã«åããããšãã§ããŸãã æŽæ°è©Šéšã§ã¯ãå顿°ãè©Šéšæéãåéšè²»çšããåå詊éšã«æ¯ã¹ãŠå°ãããªã£ãŠããŸãã é
ç® ååè©Šéš æŽæ°è©Šéš å顿° 50ïœ60å 20å è©Šéšæé 120å 60å åéšè²»çš $125ïŒçšå¥ïŒ $75ïŒçšå¥ïŒ æŽæ°è©Šéšã¯è±èªã𿥿¬èªã§åéšããããšãå¯èœã§ãã 詊éšç¯å²ã«ã€ããŠã¯ãåå詊éšãšæŽæ°è©Šéšã§ã»ãŒåãã§ããã詊éšã¬ã€ãã®ãã»ã¯ã·ã§ã³ 1: ã¯ã©ãŠã ãœãªã¥ãŒã·ã§ã³ç°å¢ã®èšå®ãã¯åºé¡ãããŸããã åºé¡åŸå Associate Cloud Engineer 詊éšã§ã¯ä»¥äžã®ãããªãµãŒãã¹ãäž»é¡ç¯å²ã§ãã çµç¹ / ãªãœãŒã¹ ã¢ã«ãŠã³ãïŒCloud Identity / Google WorkspaceïŒ Identity and Access ManagementïŒIAMïŒ Virtual Private CloudïŒVPCïŒ Cloud DNS Google Cloud CLIïŒgcloudãbqïŒ Compute Engine App Engine Cloud Run Google Kubernetes EngineïŒGKEïŒ Cloud Storage ããŒã¿ããŒã¹ç³»ãµãŒãã¹ïŒCloud SQLãCloud SpannerãBigtableãBigQuery) Cloud Monitoring / Cloud Logging å©çšæé åœèšäºã§ã¯ãã以éãã©ã®ãããªè©Šéšåé¡ãåºãããåºé¡åŸåã解説ããŠãããŸãã®ã§ãåèã«ããŠåãµãŒãã¹ã®å
å®¹ãæŒãããŠãã ãããããããªãèšèãç¥ããªãçšèªãããã°ãå
¬åŒããã¥ã¡ã³ããªã©ã蟿ããååç¥èãã€ããŠãã ããããã®ããã«å匷ããã°ã詊éšã«åæ Œã§ããã®ã«å ããå®è·µçãªç¥èã«ããªããŸãã çµç¹ãšãªãœãŒã¹ ãªãœãŒã¹éå±€ã®æŠå¿µ Google ãªãœãŒã¹ãéå±€æ§é ãšãªã£ãŠããããšãæŒãããŠãããŸããããæäžäœã« çµç¹ ãããããã®äžã« ãã©ã«ã ïŒå
¥ãåæ§é ãå¯èœïŒã ãããžã§ã¯ã ããããŠåã
ã®ä»®æ³ãã·ã³ïŒVMïŒã BigQuery ããŒãã«ãšãã£ãåå¥ãªãœãŒã¹ãé
眮ãããããªãŒæ§é ãšãªã£ãŠããŸãã åœç€Ÿã®å
éšè³æããæç² çµç¹ããããžã§ã¯ãèªäœãããªãœãŒã¹ã®äžçš®ã§ãããªãœãŒã¹ã¯ IAM ããªã·ãŒãæã£ãŠããããšããŸã IAM æš©éã¯ç¶æ¿ãããããšã«çæããŸãããã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp ãããžã§ã¯ããš API æå¹å Google Cloud ãå©çšéå§ããã«ã¯äœãå¿
èŠãããšèãããšããå°ãªããšããããžã§ã¯ããäœæããããšã¯ å¿
é ã§ãã ãŸãã åãµãŒãã¹ã® API ã®æå¹å ã®æŠå¿µãçè§£ããŠãã ãããäŸãã° Google Cloud ãããžã§ã¯ãã§ Spanner ãå©çšéå§ãããšããæåã«ãããžã§ã¯ãã§ API ãæå¹åããå¿
èŠããããŸãã åè : Google Cloud ãããžã§ã¯ãã§ã® API ã®æå¹å çµç¹ã®ããªã·ãŒ çµç¹ã®ããªã·ãŒ æ©èœã䜿ããšãGoogle Cloud çµç¹å
šäœã§äžå®ã®ã«ãŒã«ã匷å¶ããããšãã§ããŸãã blog.g-gen.co.jp ç¹ã« ãµãŒãã¹ã¢ã«ãŠã³ãããŒã®çºè¡ãçŠæ¢ããããªã·ãŒ ã¯ãããçšããããŸãã åè : æ°ãããµãŒãã¹ ã¢ã«ãŠã³ã ããŒã®äœæã忢ããå¶åŸ¡ãé©çšãã IAM IAM ã®åºæ¬æŠå¿µ Google Cloud ã® IAM ïŒIdentity and Access ManagementïŒã¯ã ãªãœãŒã¹ã«çŽã¥ããŠèšå®ãã ããã®ã§ããããŸã ç¶æ¿ã®æŠå¿µããã ããšãæ£ç¢ºã«çè§£ããŸããããIAM ã®æŠå¿µã«ã€ããŠã¯ã以äžã®èšäºãåèã«ããŠãã ããã blog.g-gen.co.jp ãããçè§£ã§ããã°ãäŸãã° VM ã«ã¢ã¿ããããããµãŒãã¹ã¢ã«ãŠã³ãã ãããžã§ã¯ããè·šãã§å¥ã®ãããžã§ã¯ãã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããã«ã¯ã©ãããã°ããã ãšãã質åã«ãåçã§ããŸãã IAM ããŒã«ã¯ã¢ã«ãŠã³ãã§ã¯ãªãã°ã«ãŒãã«ä»äž è€æ°ã®ããã¥ã¡ã³ãã§ç¹°ãè¿ãè¿°ã¹ãããŠãããã¹ããã©ã¯ãã£ã¹ãšããŠãã IAM ããŒã«ã¯ãåå¥ã® Google ã¢ã«ãŠã³ãã§ã¯ãªã Google ã°ã«ãŒãã«ä»äžããã¹ãã§ãã ããšãããã®ããããŸãã Google ã°ã«ãŒã ã¯ãGoogle ã¢ã«ãŠã³ããã°ã«ãŒãã³ã°ããããã®ä»çµã¿ã§ãGoogle Workspace ãŸã㯠Cloud Identity ã«åãã£ãŠããŸãã åå¥ã®ã¢ã«ãŠã³ãã«ããŒã«ãä»äžããŠããŸããšããã®äººãéè·ãããç°åã«ãªããã³ã«å€ãã®ãªãœãŒã¹ã«å¯Ÿã㊠IAM ã®ã¡ã³ããã³ã¹ãå¿
èŠã«ãªã£ãŠããŸããŸããã°ã«ãŒãã«ã¢ã«ãŠã³ããæå±ãããŠããã®ã°ã«ãŒãã« IAM ããŒã«ãä»äžããããã«ããŸãããã åè : ããªã·ãŒã®ç®¡ç åºæ¬ããŒã«ãšäºåå®çŸ©ããŒã« åºæ¬ããŒã«ãšäºåå®çŸ©ããŒã«ã®ããã€ããæŒãããŠãããŸããããåºæ¬ããŒã«ã¯ä»¥äžã®3ã€ã§ãã é²èЧè
ïŒ roles/viewer ïŒ ç·šéè
ïŒ roles/editor ïŒ ãªãŒããŒïŒ roles/owner ïŒ åºæ¬ããŒã«ã¯æš©éã倧ããããã å¯èœãªéãå©çšãé¿ããŸã ãäºåå®çŸ©ããŒã«ããã«ã¹ã¿ã ããŒã«ã䜿ã£ãŠãã现ããæš©éå¶åŸ¡ãããŸããããäºåå®çŸ©ããŒã«ã¯ä»¥äžã®ããã¥ã¡ã³ãã§ç¢ºèªã§ããŸããæ°ãå€ãããã®ã§ããã¡ããå
šãŠãèŠããå¿
èŠã¯ãããŸããã åè : ããŒã«ã«ã€ã㊠ãµãŒãã¹ã¢ã«ãŠã³ã Compute Engine VM äžã§çšŒåããããã°ã©ã ãã Google Cloud ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããéã®èªèšŒã»èªå¯ã¯ã ãµãŒãã¹ã¢ã«ãŠã³ã ã«æš©éãä»äžãããã®ãµãŒãã¹ã¢ã«ãŠã³ãã VM ã«ã¢ã¿ããããããšã§å®çŸããŸãã Compute Engine ã«ã¯ããã©ã«ããµãŒãã¹ã¢ã«ãŠã³ããååšããŸããããã®ããã©ã«ããµãŒãã¹ã¢ã«ãŠã³ããããããŠãŒã¶ãŒç®¡çã®ãµãŒãã¹ã¢ã«ãŠã³ããæ°èŠäœæããŠäœ¿çšããããšãæšå¥šãããŸãã åè : ãŠãŒã¶ãŒç®¡çã®ãµãŒãã¹ ã¢ã«ãŠã³ãã䜿çšãã VM ãäœæãã VPC VPC ãšãµããããã®åºæ¬ VPC ïŒVirtual Private CloudïŒãš ãµãããã ã®æŠå¿µããã¡ããšçè§£ããŸãã以äžã®èšäºããåèã«ãé¡ãããŸãã Google Cloud(æ§GCP)ã®VPCåºæ¬æ©èœãåŠã¶ïŒVPCã»ãµããããã»NATã»ãã¢ãªã³ã°ã»AWSãšã®éã Google Cloudã®VPCã培åºè§£èª¬ïŒ(åºæ¬ç·š) åè
ã®èšäºã§ VPC ã®å
šäœæŠèŠãæŽã¿ãåŸè
ã®èšäºã§è©³çŽ°ãæ·±å ãããŠçè§£ããã ããã°åœ¹ã«ç«ã€ããšæããŸãã VPC ã®ç¹ã«éèŠãªä»æ§ãšããŠã以äžãæããããŸãã VPC ã®äžã«äœã£ããµããããéã¯èªåçã«ã«ãŒãã亀æãããã®ã§ãäºãã«éä¿¡ã§ãã ãµããããã¯ãªãŒãžã§ã³ãªãœãŒã¹ã§ãã ãªãŒãžã§ã³Aã«äœã£ããµããããAãšããªãŒãžã§ã³Bã«äœã£ããµããããBã¯äºãã«éä¿¡ã§ããïŒãã¡ã€ã¢ãŠã©ãŒã«ã«ããå¶éã¯å¯èœïŒ ãŸãã VPC èªäœã¯ IP ã¢ãã¬ã¹åž¯ãæããããµãããããæã¡ãŸããVPC ãžã®ãµãããã远å ã¯å®¹æã«ã§ããŸãããæ¢åãµãããããæ¡åŒµããããšãã§ããïŒIP ã¢ãã¬ã¹åž¯ã®è¿œå ïŒãšããããšãæŒãããŸãããã ã»ã°ã¡ã³ããšãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã« Google Cloud ã§ã¯ãããæ¯èŒããã Amazon Web ServicesïŒAWSïŒãšæ¯ã¹ããšã现ãã VPC ããµãããããåå²ããªãåŸåã«ãããŸãã ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ãšãããã¯ãŒã¯ã¿ã°ãé§äœ¿ããŠããããã DMZ ãšå
éšãããã¯ãŒã¯ãåããããšã第1éžæè¢ã§ãããšã¯ãããå
šãéä¿¡ãããããªãç°å¢å士㯠VPC ãåããŸãããŸãã¯ããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®ä»çµã¿ãæ£ç¢ºã«çè§£ããŠãããŸãããã 以äžã®ãããªããšã«åçã§ããããã«ããŠãããŠãã ããã äžãïŒIngressïŒã«ãŒã«ãšäžãïŒEgressïŒã«ãŒã«ã®æŠå¿µ ãµãŒãã¹ã¢ã«ãŠã³ããŸãã¯ãããã¯ãŒã¯ã¿ã°ã䜿ã£ãŠãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®é©çšå¯Ÿè±¡ã€ã³ã¹ã¿ã³ã¹ãæå®ããæ¹æ³ ããã©ã«ãç¶æ
ã§ã¯ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã¯ã©ã®ãããªæåãããã®ã ãã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®é©çšå¯Ÿè±¡ VM ã¯ããµãŒãã¹ã¢ã«ãŠã³ããŸãã¯ãããã¯ãŒã¯ã¿ã°ã䜿ã£ãŠæå®ã§ããŸããããå³å¯ãªå¶åŸ¡ã®ããã«ã¯ããããã¯ãŒã¯ã¿ã°ããã ãµãŒãã¹ã¢ã«ãŠã³ãã䜿ãããšãæšå¥š ãããŸãã åè : ãµãŒãã¹ ã¢ã«ãŠã³ãã«ãããã£ã«ã¿ãªã³ã°ãšãããã¯ãŒã¯ ã¿ã°ã«ãããã£ã«ã¿ãªã³ã° éå®å
¬éã® Google ã¢ã¯ã»ã¹ éå®å
¬éã® Google ã¢ã¯ã»ã¹ ã Private Service Connect ã§äœãã§ããããæŒãããŸãããã blog.g-gen.co.jp blog.g-gen.co.jp ç¹ã«ãã€ããªãããããã¯ãŒã¯ïŒãªã³ãã¬ãšã¯ã©ãŠãã䜵çšãããããã¯ãŒã¯ïŒã§ã®ãŠãŒã¹ã±ãŒã¹ãæŒãããŸããPrivate Service Connect ã䜿ããšãCloud Run services ã®ãããªé VPC ãªãœãŒã¹ã«ãããªã³ãã¬ãã¹ããå°çšç·çµç±ã§ãªã¯ãšã¹ããåä¿¡ããããšãã§ããŸãã åè : ãªã³ãã¬ãã¹ãä»ã®ã¯ã©ãŠããããªã¯ãšã¹ããåä¿¡ãã Cloud DNS Cloud DNS ã®åºæ¬çãªæ©èœãæŒãããŠãã ããããŸã Cloud DNS 以åã«ãäžè¬ç㪠DNS ã®ä»çµã¿ãåã¬ã³ãŒãã¿ã€ãã®æå³ãªã©ã¯çè§£ããŠãã ããã Cloud DNS ã§ã¯äžè¬å
¬éãŸãŒã³ïŒPublic ZoneïŒãéå®å
¬éãŸãŒã³ïŒPrivate ZoneïŒã䜿ãããšãã§ããŸããåè
ã¯ã€ã³ã¿ãŒãããããåå解決ãã§ãããŸãŒã³ã§ãããåŸè
㯠Google Cloud ã® VPC ã®äžãªã©ãã©ã€ããŒããããã¯ãŒã¯ããã®ã¿åå解決ã§ãããŸãŒã³ã§ãã åè : äžè¬ç㪠DNS ã®æŠèŠ Cloud Load Balancing Cloud Load Balancing ã¯ããã«ãããŒãžãã®ããŒããã©ã³ãµãŒã§ããçšéã®ç°ãªã10çš®é¡ã®ããŒããã©ã³ãµãŒãååšããŸãã®ã§ãã©ããªã±ãŒã¹ã§ã©ã®ããŒããã©ã³ãµãŒãéžæãã¹ãããæŒãããŸãããå€éš vs å
éšããã°ããŒãã« vs ãªãŒãžã§ãã«ããHTTP(S) vs TCP/UDPããªã©ã®èгç¹ã§ãé©åãªããŒããã©ã³ãµãŒãéžæããŠãã ããã以äžã®ããã¥ã¡ã³ãã®ãã£ã·ãžã§ã³ã»ããªãŒã®å³ãåãããããã§ãã åè : ããŒããã©ã³ãµãéžæãã ãŸããããŒããã©ã³ãµãŒãå®éã«ã»ããã¢ãããããšãã®ãDNS ãšã®é¢ä¿æ§ãçè§£ããŸããããããŒããã©ã³ãµãŒãäœæãããšãIP ã¢ãã¬ã¹ãæãåºãããŸãããã® IP ã¢ãã¬ã¹ã«å¯Ÿã㊠DNS ã« A ã¬ã³ãŒããèšå®ããããšã§ããã¡ã€ã³åã§ããŒããã©ã³ãµãŒã«ã¢ã¯ã»ã¹ã§ããŸãã åè : ãã¡ã€ã³ãããŒããã©ã³ãµã«æ¥ç¶ãã Compute Engine åºç€ç¥è Compute Engine ã®åºç€çãªç¥èã¯ã以äžã®èšäºãåèã«ããŠçè§£ããŠãã ããã blog.g-gen.co.jp ãã£ã¹ã¯ã»ããã¯ã¢ããã»ãªã¹ã㢠Persistent Disk ïŒæ°žç¶ãã£ã¹ã¯ïŒã«é¢ããçè§£ãæ·±ããŠãããŸãããã Persistent Disk ããã®ã€ã³ã¹ã¿ã³ã¹äœæã¯ã©ãããã°ããã®ããããã¯ã¢ãããã¹ã±ãžã¥ãŒã«ããã«ã¯ã©ãããã°ãããããªã©ãå
¬åŒããã¥ã¡ã³ãããçè§£ããŠãããŸãã åè : ãã£ã¹ã¯ ã¹ãããã·ã§ããã®ã¹ã±ãžã¥ãŒã«ãäœæãã æ°žç¶ãã£ã¹ã¯ã«ã¯ãªãŒãžã§ã³æ°žç¶ãã£ã¹ã¯ãšããŸãŒã³æ°žç¶ãã£ã¹ã¯ããããŸãããããã®éããšãŠãŒã¹ã±ãŒã¹ãçè§£ããŠãããŠãã ããã åè : Persistent Disk 賌å
¥ãªãã·ã§ã³ Compute Engine ã«ã¯ããã€ãã®è³Œå
¥æ¹æ³ããããŸãã以äžãã人ã«èª¬æã§ãããŸã§çè§£ããŠãããŸãã ãªã³ããã³ã VM Spot VM 確çŽå©çšå²åŒïŒCUDïŒ ç¶ç¶å©çšå²åŒ Spot VM ã¯éåžžã«ãåŸã«èŠããŸããã 匷å¶çµäº ïŒããªãšã³ããïŒãããããšã«çæããŸãã 確çŽå©çšå²åŒïŒCUDïŒãç¶ç¶å©çšå²åŒã«ã€ããŠã¯ã以äžã®èšäºãåèã«ããŠãã ããã blog.g-gen.co.jp blog.g-gen.co.jp ã³ã³ãã¥ãŒãã£ã³ã°ãµãŒãã¹ App Engine App Engine ã®åŒ·ã¿ãäœããæŒãããŸãããã现ãã仿§ãŸã§èŠããå¿
èŠã¯ãªããã©ã®ãããªãµãŒãã¹ã§ãäœã匷ã¿ãšããŠããããçè§£ããŠãã ããã ãªãªãŒã¹ããè€æ°ã®ããŒãžã§ã³éã§ãŠãŒã¶ãã©ãã£ãã¯ã®å²åã調æŽã§ããã®ãåªããæ©èœã®äžã€ã§ãã åè : ãã©ãã£ãã¯ã®åå² Google Kubernetes EngineïŒGKEïŒ Google Kubernetes Engine ïŒGKEïŒ ã®åºæ¬çãªæŠå¿µãšãæäœæ¹æ³ïŒã¯ã©ã¹ã¿ã®æäœã Depoloyment ã Pod ã®ãããã€ïŒãçè§£ããããšãæãŸããã§ãã ã¯ã©ã¹ã¿ãããŒãããŒã«ãããŒããPodãDeploymentãService ãªã©ã®æŠå¿µãçè§£ããŠãã ããããŸãã以äžã®ãããªæäœãã³ãã³ãã©ã€ã³ã§è¡ãæ¹æ³ãææ¡ããŠãããŠãã ããã åäžãŸãŒã³ã®ã¯ã©ã¹ã¿ããã«ããŸãŒã³ã¯ã©ã¹ã¿ã«å€æŽããïŒãŸãŒã³ã®è¿œå ïŒ æ¢åã¯ã©ã¹ã¿ã«ãåŸæ¥ãšç°ãªããã·ã³ã¿ã€ãã®ããŒãã远å ããïŒæ°èŠããŒãããŒã«ã®è¿œå ïŒ Horizontal Pod Autoscaling ãš Vertical Pod AutoscalingïŒrecommendationïŒã®äœ¿ãæ¹ ä»¥äžã®èšäºãåèã«ããŠãã ããã blog.g-gen.co.jp Cloud Run Cloud Run ã®åºæ¬çãªæŠå¿µãšã䜿ãã¹ãã·ãŒã³ãçè§£ããŠãã ããã Cloud Run ã¯ãå©çšãå°èŠæš¡ãŸãã¯æ£çºçãªã¯ãŒã¯ããŒããç¹ã« API ããã¯ãšã³ãã Web ã¢ããªïŒSingle Page ApplicationãSPAïŒãªã©ã§å©çšã§ããŸãã 以äžã®èšäºãåèã«ããŠãã ããã blog.g-gen.co.jp ãŸãã ã³ãŒã«ãã¹ã¿ãŒã ã®æŠå¿µãçè§£ããŠãã ãããã³ãŒã«ãã¹ã¿ãŒããé²ãæãç°¡åãªæ¹æ³ã¯ãæå°ã€ã³ã¹ã¿ã³ã¹æ°ãå¢ããããšã§ãã blog.g-gen.co.jp ã³ã³ãã¥ãŒãã£ã³ã°ãµãŒãã¹ã®äœ¿ãåã App EngineãCloud RunãGoogle Kubernetes EngineïŒGKEïŒã¯ããããã¢ããªã±ãŒã·ã§ã³ããã¹ãããããã®ãµãŒãã¹ã§ãã ã³ã³ãã¥ãŒãã£ã³ã°ãµãŒãã¹ ãšç·ç§°ãããããšããããŸãã ã©ã®ãããªãšãã« ã ã©ã®ãµãŒãã¹ãå©çšããã®ã ãèããããããã«ããŠãããŸãããã 以äžã®èšäºãäžèªããåãµãŒãã¹ã®ç¹åŸŽãšäœ¿ãã¹ãå Žé¢ãçè§£ããŠãããŸãããã blog.g-gen.co.jp Cloud Storage Cloud Storage ã®ãŠãŒã¹ã±ãŒã¹ãæŒãããŠãã ãããCloud Storage ã¯ãªããžã§ã¯ãã¹ãã¬ãŒãžã§ãã®ã§ãéåžžã®ãã¡ã€ã«ã·ã¹ãã ãšã¯ç¹æ§ãçšéãç°ãªããŸããå®äŸ¡ã§ã¹ã±ãŒã©ãã«ãªã®ã§ãéæ§é åããŒã¿ãå«ãããã©ãŒãããããµã€ãºãç°ãªã倿§ãªããŒã¿ãã¯ã©ãŠãã«ä¿åããããã«é©ããéžæãšãªããŸãã ãŸããããŒã¿ã®ä¿åæéãã¢ã¯ã»ã¹é »åºŠã«ãã£ãŠãã©ã®ã¹ãã¬ãŒãžã¯ã©ã¹ãéžã¶ã¹ãããããã£ããæŒãããŠãããŸãã é »ç¹ã«ã¢ã¯ã»ã¹ããã : Standard 1ãæã«1床 : Nearline ååæã«1床 : Coldline 幎ã«1åæªæº : Archive 以äžã®ããã¥ã¡ã³ããåèã«ãªããŸãã åè : ã¹ãã¬ãŒãž ã¯ã©ã¹ ãŸã以äžã®èšäºã§ Cloud Storage ã®è©³çްã解説ããŠããŸãã®ã§ãæ¯éåèã«ããŠãã ããã blog.g-gen.co.jp ããŒã¿ããŒã¹ãããŒã¿åæ Cloud SQL 以äžã®åœç€Ÿèšäºãèªãã§ã Cloud SQL ã®åºæ¬çãªæ©èœãæŒãããŸãã blog.g-gen.co.jp BigQuery 以äžã®èšäºãåèã«ããŠã BigQuery ã®æ©èœãäžéãæŒãããŠãããŸãã blog.g-gen.co.jp Spanner 以äžã®èšäºãåèã«ããŠã Spanner ã®æ©èœãäžéãæŒãããŠãããŸãããäžçäžããã®å€§éã®ã¢ã¯ã»ã¹ãèŠèŸŒãŸãããããã©ã³ã¶ã¯ã·ã§ã³åŠçãå¿
èŠããSQL ã®äœ¿çšããªã©ã®ããŒã¯ãŒããããå Žåã¯ãSpanner ã®ãŠãŒã¹ã±ãŒã¹ã§ãã blog.g-gen.co.jp ããŒã¿ããŒã¹ã®ãã¹ããªéžæ 以äžã®åãã«çããããããã«ããŠãããŸããGoogle Cloud ã®ããŒã¿ããŒã¹ãµãŒãã¹ã®ç¹åŸŽãšãŠãŒã¹ã±ãŒã¹ãå¿
ãæŒãããŠãããŸãããã 倧éã® IoT ã»ã³ãµãŒããŒã¿ãæ ŒçŽããäœã¬ã€ãã³ã·ã§èªã¿åºãã®ã«é©ããããŒã¿ããŒã¹ã¯ïŒïŒBigTableïŒ è€æ°ã®ãªãŒãžã§ã³ã«ãŸããããã©ã³ã¶ã¯ã·ã§ã³ã¯ãŒã¯ããŒãã«é©ããããŒã¿ããŒã¹ã¯ïŒ (Cloud Spanner) Web ã¢ããªã±ãŒã·ã§ã³ãã䜿ã NoSQL ããŒã¿ããŒã¹ã¯ïŒïŒFirestoreïŒ äžè¬çãªã¢ããªã±ãŒã·ã§ã³ãã MySQL ã PostgreSQL ãªã©ã®ãªã¬ãŒã·ã§ãã«ããŒã¿ããŒã¹ã䜿ããããšãã¯ïŒïŒCloud SQLïŒ å€§éã®ããŒã¿ã«å¯Ÿã㊠SQL ã䜿ã£ãŠåæãè¡ããããšãã¯ïŒïŒBigQueryïŒ ããŒã¿ãã€ãã©ã€ã³ ããŒã¿ãã€ãã©ã€ã³ãå®çŸãããµãŒãã¹ã§ãã Dataflow ã®æŠèŠãçè§£ããŠãããŸãããã blog.g-gen.co.jp Google Cloud Observability Cloud Monitoring Cloud Monitoring ã®åºæ¬æ©èœã¯ä»¥äžã®èšäºã§æŒãããããšãã§ããŸãã blog.g-gen.co.jp ã¡ããªã¯ã¹ãç£èŠãããããå€ãè¶
ãããã¢ã¯ã·ã§ã³ãèµ·ããããšããåºæ¬çãªäœ¿ãæ¹ãæŒãããŸããã¢ã©ãŒãã®éç¥å
ã¯ãéç¥ãã£ãã«ããšããŠèšå®ã§ããŸãã åè : éç¥ãã£ãã«ã®ç®¡ç Pub/Sub ãéç¥å
ãšããŠèšå®ã§ããã®ã§ãã¢ã©ãŒãã奿©ã«ã¡ãã»ãŒãžã Pub/Sub ã«éãããããããªã¬ã« Cloud Functions ãèµ·åããä»»æã®å®å
ã«éç¥ãéãããšãã§ããŸãã Cloud Logging 以äžã®èšäºã§ Cloud Logging ã®æ©èœãææ¡ããå¿
èŠããããŸãã blog.g-gen.co.jp ç¹ã« Log Analytics æ©èœã ã·ã³ã¯ ïŒãã°ã«ãŒã¿ãŒïŒã®æ©èœãææ¡ããŠãã ããã Cloud Audit Logs èšŒè·¡ç®¡çæ©èœã§ãã Cloud Audit Logs ã®åºæ¬ãã以äžã®èšäºã§æŒãããŠãããŸãããã blog.g-gen.co.jp Cloud Audit Logs ã«ã¯ãGoogle Cloud APIs ãžã®ãªã¯ãšã¹ãã®å±¥æŽãèšé²ãããŸããäŸãã° Bigtable ã®ããã«ãAPI ã§ããŒã¿ã®èªã¿æžãããããµãŒãã¹ã®å Žåãèšå®ã«ãã£ãŠã¯ ããŒã¿ã®èªã¿æžãå±¥æŽãèšé² ããããšãã§ããŸãã æé è«æ±å
ã¢ã«ãŠã³ã è«æ±å
ã¢ã«ãŠã³ã ã®æŠå¿µã¯ä»¥äžã®èšäºã§æŒãããŠãããŸãããã blog.g-gen.co.jp äºç®ã¢ã©ãŒã è«æ±å
ã¢ã«ãŠã³ãã«å¯Ÿãã äºç®ã¢ã©ãŒã ã仿ããããšãã§ããŸãã åè : äºç®ãšäºç®ã¢ã©ãŒãã®äœæãç·šéãåé€ å©çšæéã®èŠç©ãšã¢ãŒããã¯ã㣠Google Cloud's pricing calculator ã䜿ã£ãŠæéãèŠç©ããããšãã§ããŸãã â åè : Google Cloud's pricing calculator ãããªãã¯ã¯ã©ãŠãã§ã¯ãæé©ãªå©çšæéãšãªãããèæ
®ããŠã¢ãŒããã¯ãã£ãèšèšããã®ããã¢ãŒããã¯ãã®ä»äºã«ãªããŸããããç®çãéæããããã®ã¢ãŒããã¯ãã£ã¯ç¡æ°ã«ãããŸããããã®äžã§ãæãã³ã¹ãå¹çè¯ãïŒCost-effective ã«ïŒå®çŸããæ¹æ³ãç·šã¿åºãããšãæ±ããããŸãã ã¢ãŒããã¯ãã£ãèãããšããååçã«ã¯ããããŒãžããµãŒãã¹ã䜿ãããšãã¯ããããŒãžããµãŒãã¹ã䜿ããæ¬¡ç¹ã§ã³ã³ããçãæåŸã®éžæè¢ãšããŠä»®æ³ãµãŒããéžæããããšèããã°è¯ãã§ããCloud Run functionsïŒæ§ Cloud FunctionsïŒã§ã¢ãŒããã¯ãã£ãå®çŸããã°ãCompute Engine ã® VM ãåžžæèµ·åãããå¿
èŠããªãã®ã§ã³ã¹ãå¹çãè¯ããªãããªã©ãäžäŸã§ãã å©çšæéããŒã¿ã® BigQuery ãžã®ãšã¯ã¹ããŒã è«æ±å
ã¢ã«ãŠã³ããã BigQuery ãžè«æ±ããŒã¿ãèªåãšã¯ã¹ããŒãããããšãã§ããŸãã ãã®ããŒã¿ããLooker StudioïŒæ§ç§°ããŒã¿ããŒã¿ã«ïŒã§å¯èŠåããŠåæããããšãã»ãªãªãŒã§ãã åè : Cloud Billing ããŒã¿ã BigQuery ã«ãšã¯ã¹ããŒããã Access Approval Access Approval ãäœãããããã®ãµãŒãã¹ãªã®ãããŸãå¿
èŠãª IAM ããŒã«ã¯äœããæŒãããŠãããŸãããã Access Approval 㯠Google ã®ãã¯ãã«ã«ãµããŒãçããŠãŒã¶ãŒã®ã³ã³ãã³ãã«ã¢ã¯ã»ã¹ããå¿
èŠãããå Žåã«ãæç€ºçãªæ¿èªãçµãªããšã¢ã¯ã»ã¹ã§ããªãããã«ããããšãã§ãããµãŒãã¹ã§ããæå¹åãããšãã¡ãŒã«ã Pub/Sub éç¥ã§æ¿èªäŸé Œãè¡ãããŸãã Access Approval æ¿èªè
ïŒ roles/accessapproval.approver ïŒããŒã«ãä»äžãããŠããã¢ã«ãŠã³ãã®ã¿ããæ¿èªãè¡ãããšãã§ããŸãã åè : Access Approval ã®æŠèŠ ãã®ä» Google Cloud ã®å²åŠ å
šäœãéããŠãéžæè¢ã®çµã蟌ã¿ã«è¿·ã£ãé㯠Google Cloud ã®å²åŠãšãããã¹ãå
±éèªèã«åºã¥ããŠå€æããŸãããã以äžã®ãããªããŒã¯ãŒããçè§£ããŠå€æã«æŽ»ããããšãã§ããã°ãèãæ¹ã倧ããééããã«æžã¿ãŸãã ããããããã¯èšã£ãŠããå®åã§ã¯ããããã¹ãã ãã...ããšããæ°æã¡ãããããŠãã¯ã©ãŠãã®å²åŠã«æ²¿ã£ãåçãéžã¶ããšãéèŠã§ãã å¯èœãªéããã«ãããŒãžããµãŒãã¹ã䜿ã 責任å
±æã¢ãã« æå°æš©éã®åå çµç¹å
šäœã§ã¬ããã³ã¹ãçºæ®ãã æš©éã®åè² ã¹ããŒãã¬ã¹ãªã¢ããªã±ãŒã·ã§ã³ãšã€ãã¥ãŒã¿ãã«ãªã€ã³ãã© èªååã«ãããã€ã«ã®åæž ã¹ã±ãŒã©ãã«ãé«å¯çšæ§ãå
ç¢æ§ ã¢ãã¿ãªã³ã°ãšèªåçãªéç¥ åéšç°å¢ åéšç°å¢ã«é¢ããåœç€Ÿã¡ã³ããŒã®å®äœéšã以äžã®èšäºã§ç޹ä»ãããŠããŸãã®ã§ãåèã«ããŠãã ããã blog.g-gen.co.jp blog.g-gen.co.jp ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãX (æ§ Twitter) ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-gen ã®ææã§ãã Google CloudïŒæ§ç§° GCPïŒã® Security Command Center ã¯ãGoogle Cloud ç°å¢ã®æ§æãã¹ãè匱æ§ãè
åšãç¹å®ããããã®çµ±åã»ãã¥ãªãã£ãã©ãããã©ãŒã ãµãŒãã¹ã§ããä»åã¯ãã® Security Command Center ã培åºè§£èª¬ããŸãã Security Command Center ãšã¯ æéãã£ã¢ ã¹ã¿ã³ããŒããã£ã¢ ãã¬ãã¢ã ãã£ã¢ ãšã³ã¿ãŒãã©ã€ãºãã£ã¢ ãã£ã¢å¥ã®æ©èœäžèЧ æé æŠèŠ ãã¬ãã¢ã ãã£ã¢ã®æé ãšã³ã¿ãŒãã©ã€ãºãã£ã¢ã®æé éçš éçšäœå¶ ç¡å¹åãšãã¥ãŒã Pub/Sub ãšã¯ã¹ããŒã Cloud Logging ãžã®ãšã¯ã¹ããŒã Security Health Analytics Security Health Analytics ãšã¯ æ€åºæ©èœã®äŸ 3 ã€ã®ã¹ãã£ã³ Web Security Scanner Web Security Scanner ãšã¯ 2 ã€ã®ã¹ãã£ã³ æ€åºçµæ 泚æç¹ Anomaly Detection Event Threat Detection Event Threat Detection ãšã¯ æ€ç¥å
容ã®äŸ æ€æ»å¯Ÿè±¡ã®ãã°ã®æå¹å ã«ã¹ã¿ã ã¢ãžã¥ãŒã« Container Threat Detection Container Threat Detection ãšã¯ æ€ç¥ã§ããå
容 Cloud Run Threat Detection Cloud Run Threat Detection ãšã¯ æ€ç¥ã§ããå
容 Virtual Machine Threat Detection Virtual Machine Threat Detection ãšã¯ æ€ç¥ã§ããå
容 VM ã®è匱æ§ã¬ããŒã Cryptomining Protection Program GeminiïŒçæ AIïŒã®å©çš ã³ã³ãã©ã€ã¢ã³ã¹è©äŸ¡ ã³ã³ãã©ã€ã¢ã³ã¹æšæºãšã®ãããã³ã° 代衚çãªã³ã³ãã©ã€ã¢ã³ã¹æšæº ãšã³ã¿ãŒãã©ã€ãºãã£ã¢ã®æ©èœ Compliance Manager Data Security Posture ManagementïŒDSPMïŒ Security Command Center ãšã¯ Security Command Center 㯠Google Cloud ç°å¢ãèªåçã«ã¹ãã£ã³ããŠãæ§æãã¹ãªã©ãèªåæ€ç¥ããŠäžèЧåããŠãããçµ±åã»ãã¥ãªãã£ãã©ãããã©ãŒã ãµãŒãã¹ã§ããSecurity Command Center 㯠SCC ãšç¥ç§°ãããå ŽåããããŸãã Security Command Center ã¯çæ AI ãšãçµ±åãããŠããããŸãæåã®æäžäœãã©ã³ã§ãããšã³ã¿ãŒãã©ã€ãºãã£ã¢ã§ã¯ãGoogle Cloud ã®ã¿ãªãããAmazon Web ServicesïŒAWSïŒãMicrosoft Azure ãä¿è·å¯Ÿè±¡ãšããããšãã§ããŸãã åè : Security Command Center ã®æŠèŠ åè : Security Command Center ã®æå¹åã®æŠèŠ Security Command Center ã¯ãç¡åã§äœ¿ãã ã¹ã¿ã³ããŒããã£ã¢ ãæåã® ãã¬ãã¢ã ãã£ã¢ ããã«ãã¯ã©ãŠãã«å¯Ÿå¿ã SIEM ã SOAR ã®æ©èœãä»åž¯ãã ãšã³ã¿ãŒãã©ã€ãºãã£ã¢ ã®3çš®é¡ã®æéäœç³»ããããŸãã ã¹ã¿ã³ããŒããã£ã¢ãšãã¬ãã¢ã ãã£ã¢ã®æå¹åç¯å²ã¯ãçµç¹ã¬ãã«ããŸãã¯ããããžã§ã¯ãã¬ãã«ãããéžæããããšãã§ããŸãããªã Security Command Center ãå©çšããã«ã¯ãGoogle Cloud ç°å¢ã§çµç¹ïŒOrganizationïŒãæ§æããŠããå¿
èŠããããŸãã åè : Security Command Center ã®ãµãŒãã¹ãã£ã¢ æéãã£ã¢ ã¹ã¿ã³ããŒããã£ã¢ ç¡åçã§ããã¹ã¿ã³ããŒããã£ã¢ã«ã¯ã以äžã®ãããªæ©èœãå«ãŸããŠããŸãã æ©èœå çš®é¡ æŠèŠ Security Health Analytics èåŒ±æ§ Google Cloud ã® IDïŒã¢ã«ãŠã³ãïŒãæš©éïŒIAMïŒããããã¯ãŒã¯ãããŒã¿ç®¡çãªã©ã«é¢ããèšå®ãã¹ãå±éºãªèšå®ãªã©ãæ€ç¥ Web Security Scanner èåŒ±æ§ Web ã¢ããªã±ãŒã·ã§ã³ã«å¯ŸããŠã¯ããŒã«ãè¡ããè匱æ§ãæ€ç¥ Anomaly Detection èåŒ±æ§ ç°åžžæ€ç¥ããµãŒãã¹ã¢ã«ãŠã³ãã®æŒæŽ©ã VM ã§ã®äžæ£ãªæå·é貚ãã€ãã³ã°ãªã©ãéåžžãšç°ãªãæåãç¹å® Sensitive Actions Service è
åš Google Cloud çµç¹ã«å¯ŸããŠè¡ãããã»ã³ã·ãã£ããªã¢ã¯ã·ã§ã³ãæ€ç¥ ç¶ç¶çãšã¯ã¹ããŒã 管ç Security Command Center ã®æ€ç¥äºé
ã Pub/Sub ã«ãšã¯ã¹ããŒããèªåéç¥ãåŸç¶ã¢ã¯ã·ã§ã³ã«ç¹ãã BigQuery ãšã®çµ±å ç®¡ç æ€åºçµæã BigQuery ã«ãšã¯ã¹ããŒããåæã«ç¹ãã äžèšã¯äžéšã§ããã詳现ãªäžèЧã¯ä»¥äžã®ããã¥ã¡ã³ãããåç
§ãã ããã åè : ã¹ã¿ã³ããŒã ãã£ã¢ ãã¬ãã¢ã ãã£ã¢ ãã¬ãã¢ã ãã£ã¢ã§ã¯ãã¹ã¿ã³ããŒããã£ã¢ã®ãã¹ãŠã®æ©èœã«å ããŠã以äžã®ãããªæ©èœãå«ãŸããŠããŸãã æ©èœå çš®é¡ æŠèŠ åŒ·åããã Security Health Analytics èåŒ±æ§ Security Health Analytics ã®è¿œå ã®æ€ç¥äºé
ãšãCIS ãã³ãããŒã¯ã PCI DSS ãªã©ã®æ¥çæšæºãžã®æºæ æ©èœãè¿œå æ»æãã¹ã·ãã¥ã¬ãŒã·ã§ã³ èåŒ±æ§ æ»æãæ
å ±ã®æãåãã詊ã¿ãããå¯èœæ§ã®ããçµè·¯ãç¹å®ããã¹ã³ã¢ä»ãããŠå¯èŠå CVE è©äŸ¡ èåŒ±æ§ æ€ç¥ãããè匱æ§ã«å¯Ÿã㊠MandiantïŒGoogle ã®ã»ãã¥ãªãã£ããŒã ïŒãè©äŸ¡ãã CVE è©äŸ¡ãä»äžããã Notebook Security Scanner èåŒ±æ§ Colab Enterprise ããŒãããã¯ã§äœ¿ãããŠãã Python ããã±ãŒãžã®è匱æ§ãæ€ç¥ Event Threat Detection è
åš æ©æ¢°åŠç¿çãæŽ»çšã㊠Cloud Logging ã Google Workspace ãç£èŠãããã«ãŠã§ã¢æŽ»åãããŒã¿æãåããªã©ã®ç°åžžæåãæ€ç¥ Container Threat Detection è
åš Google Kubernetes EngineïŒGKEïŒã®ã³ã³ããã«é¢ãããäžå¯©ãªãã€ããªå®è¡ãã©ã€ãã©ãªã®èªã¿èŸŒã¿ãªã©ã®æåãæ€ç¥ Cloud Run Threat Detection è
åš Cloud Run ã®ã³ã³ããã«é¢ãããäžå¯©ãªãã€ããªå®è¡ãã©ã€ãã©ãªã®èªã¿èŸŒã¿ãªã©ã®æåãæ€ç¥ Virtual Machine Threat Detection è
åš ãã€ããŒãã€ã¶ã¬ã€ã€ããã®ã¡ã¢ãªæ€æ»çã«ãããCompute Engine VM å
ã®æªæããã¢ããªã±ãŒã·ã§ã³ãæ€ç¥ ã»ãã¥ãªãã£ãã¹ãã£ãŒ ãã¹ãã£ãŒ Google Cloud ç°å¢å
šäœã®ã»ãã¥ãªãã£ã¹ããŒã¿ã¹ããå®çŸ©ããåºæºã«åºã¥ããŠã¢ãã¿ãªã³ã° ã³ã³ãã©ã€ã¢ã³ã¹è©äŸ¡ 管ç Google Cloud ç°å¢ã CIS BenchmarkãISO 27001ãPCI DSS çã®ã³ã³ãã©ã€ã¢ã³ã¹åºæºã«åºã¥ããŠé©åç¶æ³ãäžèЧå Cloud Logging ãžã®ãšã¯ã¹ããŒã ç®¡ç æ€ç¥äºé
ã Cloud Logging ã«åºå äžèšã¯äžéšã§ããã詳现ãªäžèЧã¯ä»¥äžã®ããã¥ã¡ã³ãããåç
§ãã ããã åè : ãã¬ãã¢ã ãã£ã¢ ãšã³ã¿ãŒãã©ã€ãºãã£ã¢ Google Cloud ã¯ãšã³ã¿ãŒãã©ã€ãºãã£ã¢ã® Security Command Center ãã ã¯ã©ãŠããã€ãã£ã ã¢ããªã±ãŒã·ã§ã³ä¿è·ãã©ãããã©ãŒã ïŒCNAPPïŒãšåŒç§°ããŠããŸããæåã®æäžäœãã©ã³ã§ãããšã³ã¿ãŒãã©ã€ãºãã£ã¢ã§ã¯ãGoogle Cloud ã®ã¿ãªãããAmazon Web ServicesïŒAWSïŒãMicrosoft Azure ãä¿è·å¯Ÿè±¡ãšããããšãã§ãã1ã€ã®ãã©ãããã©ãŒã ã§è€æ°ã¯ã©ãŠãã®ã»ãã¥ãªãã£æ
å ±ãçµ±å管çã§ããŸãã ãšã³ã¿ãŒãã©ã€ãºãã£ã¢ã«ã¯ãã¹ã¿ã³ããŒããã£ã¢ãšãã¬ãã¢ã ãã£ã¢ã®ãã¹ãŠã®ãµãŒãã¹ãšæ©èœã«å ããŠãSIEMãSOARãã±ãŒã¹ç®¡çæ©èœããã³ãããã¯æ©èœãªã©ãå©çšå¯èœã§ãããããã®è¿œå æ©èœã¯ã Google Security Operations ïŒGoogle SecOpsïŒã«ãã£ãŠæäŸãããŸãã SIEM 㯠Security Information and Event Management ã®ç¥ã§ããåçš® IT 補åãã¢ããªã±ãŒã·ã§ã³ãããã°ãã€ãã³ãæ
å ±ãéçŽãããªã¢ã«ã¿ã€ã åæãè¡ãããšã§ã»ãã¥ãªãã£æ
å ±ã®åéãæ€ç¥ãè¡ãä»çµã¿ã®ããšã§ãã ãŸã SOAR 㯠Security Orchestration, Automation and Response ã®ç¥ã§ãããã»ãã¥ãªãã£éçšã®èªååãè¡ãä»çµã¿ã®ããšã§ããæ€ç¥ãããè匱æ§ãäžå¯©ãªæåã«å¯ŸããŠãPlaybooks ãšåŒã°ããèªåã¯ãŒã¯ãããŒãçšãã察åŠãè¡ãããšãã§ããŸãã ããããè¿å¹Žãæ
å ±ã»ãã¥ãªãã£ã®åéã§æ³šç®ãããŠãããœãªã¥ãŒã·ã§ã³ã§ãããããããå®è£
ãã Google 補åã Google SecOps ã§ããæ¬æ¥ã¯ Google Cloud ãšã¯å¥è£œåãšããŠæäŸãããŠãã Google SecOps ããã³ãã«ãããæ§ã
ãªæ©èœãšçµ±åããŠå©çšã§ããã®ãã Security Command Center ã®ãšã³ã¿ãŒãã©ã€ãºãã£ã¢ã§ãã åè : ãšã³ã¿ãŒãã©ã€ãº ãã£ã¢ ãã£ã¢å¥ã®æ©èœäžèЧ åãã£ã¢ã§å©çšã§ããæ©èœã®äžèŠ§ãšæ¯èŒè¡šã¯ã以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : Security Command Center ã®ãµãŒãã¹ãã£ã¢ - ãµãŒãã¹ãã£ã¢ã®æ¯èŒ æé æŠèŠ Security Command Center ã®ã¹ã¿ã³ããŒããã£ã¢ã¯ ç¡æ ã§ããããã¬ãã¢ã ãã£ã¢ãšãšã³ã¿ãŒãã©ã€ãºãã£ã¢ã¯ æå ã§ãã ã¹ã¿ã³ããŒããã£ã¢ãšãã¬ãã¢ã ãã£ã¢ã¯ çµç¹å
šäœã§æå¹å ãããã ãããžã§ã¯ãã¬ãã«ã§æå¹å ããããéžæã§ãããããžã§ã¯ãã¬ãã«ã§æå¹åããå Žåã¯èª²é察象ã®ãªãœãŒã¹ç¯å²ã調æŽããããšãã§ããŸãããšã³ã¿ãŒãã©ã€ãºãã£ã¢ã¯ãçµç¹å
šäœã§æå¹åããå¿
èŠããããŸãã åè : Security Command Center pricing ãã¬ãã¢ã ãã£ã¢ã®æé Security Command Center ãã¬ãã¢ã ãã£ã¢ã®æéã¯ã察象ã®ãªãœãŒã¹æ°ã«ãã£ãŠæ±ºå®ããåŸé課éã§ãã以äžã®ãããªãµãŒãã¹ã®äœ¿çšããªã¥ãŒã ïŒãªãœãŒã¹æ°ïŒã«å¿ããŠèª²éãçºçããŸãã ãµãŒãã¹å 課é察象ãªãœãŒã¹ Compute Engine CPU vCore / æé Google Kubernetes EngineïŒAutopilotïŒ CPU vCore / æé Cloud SQL CPU vCore / æé App EngineïŒStandardïŒ ã€ã³ã¹ã¿ã³ã¹ / æé App EngineïŒFlexïŒ CPU vCore / æé Cloud Storage Class A/B ãªãã¬ãŒã·ã§ã³æ° BigQueryïŒãªã³ããã³ãïŒ ã¹ãã£ã³ããŒã¿ TB æ° BigQueryïŒEditionsïŒ ã¹ããã / æé æéå䟡ã¯ãSecurity Command Center ãçµç¹ã¬ãã«ã§æå¹åããããããžã§ã¯ãã¬ãã«ã§æå¹åãããã«ãã£ãŠç°ãªããŸããäŸãã° Compute Engine ã® vCPU ã³ã¢æ°ãããã®å䟡ã¯ãçµç¹ã¬ãã«ã§ã¯ $0.0057/hourããããžã§ã¯ãã¬ãã«ã§ã¯ $0.0071/hour ã§ãïŒãããã2025幎5æçŸåšïŒã ææ°ã®æéã¯ä»¥äžã®å
¬åŒããŒãžã§ã確èªãã ããã åè : Security Command Center pricing ãªãäžèšã®æéäœç³»ã¯ã2023幎6æ8æ¥ã®ã¢ããããŒãã«äŒŽãå¶å®ããããã®ã§ãããã以åã¯ããã¬ãã¢ã ãã£ã¢ãçµç¹ã¬ãã«ã§æå¹åããå ŽåãGoogle Cloud å
šäœã®å©çšæéã® 5 % ãŸã㯠$15,000/幎 ã®é«ãæ¹ãã1幎ãŸãã¯è€æ°å¹Žã®ãµãã¹ã¯ãªãã·ã§ã³ããšãããã®ã§ããã2025幎5æçŸåšã§ã¯ã䜿çšéããŒã¹ã®èª²éãå¯äžã®èª²éæ¹æ³ã§ãã åè : Security Command Center release notes - June 08, 2023 ãšã³ã¿ãŒãã©ã€ãºãã£ã¢ã®æé ãšã³ã¿ãŒãã©ã€ãºãã£ã¢ã®æéã¯ãæäœ1幎éã®ãµãã¹ã¯ãªãã·ã§ã³ã§ãã ã¢ã»ãããšããåäœã§ã¯ã©ãŠããªãœãŒã¹ãã«ãŠã³ãããã¢ã»ããæ°ã«å¿ãã課éãçºçããŸãããã ããæå°èª²ééé¡ã¯å¹Žéã§ $15,000 ã§ãã èŠç©ããæ¹æ³ã«ã€ããŠã¯ã以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããå¿
èŠã«å¿ã㊠Google Cloud ã販売ããŒãããŒã®ã®å¶æ¥æ
åœè
ãšæ
å ±é£æºãããŠãã ããã åè : Pricing for the Enterprise tier éçš éçšäœå¶ ååçã«ãSecurity Command Center ãæå¹åããã ãã§ã¯ã»ãã¥ãªãã£ãªã¹ã¯ã æ€ç¥ããããšããã§ã ãŸããã æ€ç¥å
å®¹ãæ£ããçè§£ã㊠Google Cloud ã®èšå®ãã»ãã¥ã¢ãªç¶æ
ã«å€æŽãããªã©ã éç¥ããããªã¹ã¯ã«å
·äœçã«å¯ŸåŠããéçšäœå¶ ãå¿
èŠã«ãªããŸãã ãã£ããããã¹ãã«ã«åºã¥ãéçšäœå¶ãç¯ããããèªå察åŠã®ä»çµã¿ãæ§ç¯ããªãéããSecurity Command Center ãããªãªã«ãå°å¹ŽãïŒéç¥ãç¹°ãè¿ãããããšã§ãã€ãºãšããŠæããããŠããŸããæ¬åœã«ãªã¹ã¯ãé«ãæ€ç¥ãè¡ããããšãã«ãå¿
èŠãªå¯ŸåŠãåãããªããªã£ãŠããŸãç¶æ
ã®æ¯å©ïŒã«ãªã£ãŠããŸãããšã«æ³šæãå¿
èŠã§ãã é©åãªéçšäœå¶ãšãããŒã確ä¿ããéç¥å
容ã«å¯Ÿããé©åãªå¯ŸåŠãç¶ç¶çã«è¡ãããšã§åããŠãSecurity Command Center ã¯äŸ¡å€ãçºæ®ããŸãã ç¡å¹åãšãã¥ãŒã Security Command Center ã®æ€åºçµæã¯ã ç¡å¹å ãŸã㯠ãã¥ãŒã ã§ããŸãã æ€ç¥ãããè匱æ§ãè
åšãžã®å¯ŸåŠãå®äºããå Žåããã®æ€ç¥çµæã ç¡å¹åãã ïŒ Inactive ç¶æ
ã«ããïŒããšã§ãæ€ç¥çµæã衚瀺ãããªããªããŸããäžåºŠç¡å¹åããŠããåãé
ç®ãå床æ€ç¥ããããšãæ€ç¥çµæã¯åã³æå¹åããïŒ Active ç¶æ
ã«ãªãïŒãŸãã ãªãæ€ç¥çµæãžã®å¯ŸåŠãå®äºããŠããèªåçã«ç¡å¹åãããã®ã¯ Security Health Analytics ãš VM Manager ã®æ€ç¥äºé
ã ã ã§ãããã ããæ¬¡åã®ã¹ãã£ã³ã§è匱æ§ã修埩ãããããšãæ€ç¥ããããŸã§æéããããå ŽåããããŸãããŸãããã以å€ã®å€ãã®è匱æ§ãè
åšã®æ€ç¥çµæã¯èªåçã«ç¡å¹åãããããšã¯ãªãããã æåã§ç¡å¹å ããå¿
èŠããããŸãã åè : æ€åºçµæã®ç¶æ
åè : ã³ã³ãœãŒã«ã§æ€åºçµæã確èªããŠç®¡çãã - æ€åºçµæã®ç¶æ
ã倿Žãã åè : è
åšã®èª¿æ»ãšå¯ŸåŠ - è
åšã®æ€åºã®ç¡å¹å äžæ¹ã§ãæ€ç¥çµæãåœéœæ§ã ã£ãå Žåãã€ãŸãå®éã«ã¯ç¡å®³ãããã¯ç¡èŠããŠè¯ãã«ãé¢ãããæ€ç¥ãããå Žåã¯ãæ€ç¥çµæã ãã¥ãŒããã ããšãã§ããŸããæ€ç¥çµæããã¥ãŒããããšãç¡å¹åããå Žåãšåæ§ã«äžèЧã«è¡šç€ºãããªããªããŸãããæ€ç¥çµæã¯æå¹åïŒ Active ïŒç¶æ
ãšããŠæ®ããæåæäœã«ããå衚瀺ãããããšãã§ããŸãã ãŸãã ãã¥ãŒãã«ãŒã« ãäœæããããšã§ãæå®ã®æ¡ä»¶ãæºãããæ€ç¥çµæãèªåçã«ãã¥ãŒãããããšãã§ããŸãããŸããã¥ãŒãã«ãŒã«ã§ã¯ããã¥ãŒããæ°žç¶çã«ãããããããã¯æéãæ±ºããäžæçãªãã¥ãŒããšããããšãã§ããŸãã åè : Security Command Center ã®æ€åºçµæããã¥ãŒããã Pub/Sub ãšã¯ã¹ããŒã Pub/Sub ãžã® ç¶ç¶ãšã¯ã¹ããŒã æ©èœãå©çšããããšã§ãSecurity Command Center ã®æ€åºçµæã Pub/Sub ã«èªåçã«ãšã¯ã¹ããŒãããããšãã§ããŸããPub/Sub ãžã®ãšã¯ã¹ããŒãã¯ããã¹ãŠã®ãã£ã¢ã§å©çšã§ããŸãã ã»ãŒãªã¢ã«ã¿ã€ã ã§æå®ãã Pub/Sub ãããã¯ã«æ€åºçµæããšã¯ã¹ããŒããããå€éšããŒã«ãªã©ã«é£æºãããããªãã¬ãŒã¿ãŒãžã®çºå ±ã«äœ¿çšã§ããŸãã åè : ç¶ç¶çãšã¯ã¹ããŒã Cloud Logging ãžã®ãšã¯ã¹ããŒã æ€ç¥äºé
ã Cloud Logging ã«ãã°ãšããŠãšã¯ã¹ããŒãã§ããŸããæ€ç¥äºé
ã Cloud Logging ã«ãšã¯ã¹ããŒãããããšã§ãåŸã
ã® Cloud Logging ã§ã®åæãããã°ã¢ã©ãŒããçšããçºå ±ã容æã«å®è£
ã§ããŸãã Cloud Logging ãžã®ãšã¯ã¹ããŒãã¯ã ãã¬ãã¢ã ãã£ã¢ä»¥äž ã§äœ¿çšã§ããŸãã åè : ãã°ã Cloud Logging ã«ãšã¯ã¹ããŒããã Security Health Analytics Security Health Analytics ãšã¯ Security Health Analytics ã¯ãGoogle Cloud ç°å¢ãèªåçã«ã¹ãã£ã³ããèšå®ãã¹ãã»ãã¥ã¢ã§ãªãèšå®ãªã©ãæ»æå¯Ÿè±¡ãšãªãå¯èœæ§ãšãªãæ§æãæ€ç¥ããæ©èœã§ãã Security Health Analytics ã¯ãã¹ã¿ã³ããŒããã£ã¢ãå«ã ãã¹ãŠã®ãã£ã¢ã§å©çšå¯èœ ã§ããããã¹ãŠã®æ€ç¥é
ç®ãå©çšããã«ã¯ãã¬ãã¢ã ãã£ã¢ä»¥äžãžã®ç»é²ãå¿
èŠã§ãã ãŸãããã¬ãã¢ã ãã£ã¢ä»¥äžã§ã¯ãã«ã¹ã¿ã æ€åºã¢ãžã¥ãŒã«ãäœæããããæ»æãã¹ã·ãã¥ã¬ãŒã·ã§ã³ïŒæ³å®ãããæ»æã«ãŒããçºçå¯èœæ§ã¹ã³ã¢çïŒã衚瀺ã§ããŸãã åè : Security Health Analytics ã®æŠèŠ æ€åºæ©èœã®äžèЧã¯ã以äžã®å
¬åŒããã¥ã¡ã³ãã«èšèŒãããŠããŸãã以äžã®ããã¥ã¡ã³ãã§ã¯æ€åºæ©èœããšã«ãã©ã®ãããªæ©èœãªã®ããã¹ã¿ã³ããŒããã£ã¢ã§å©çšå¯èœãªã®ãããã¬ãã¢ã ãã£ã¢ãžã®ç»é²ãå¿
èŠãªã®ãããŸããªã¢ã«ã¿ã€ã ã¹ãã£ã³ãè¡ãããã®ãããªã©ãäžèЧåãããŠããŸãã åè : Security Health Analytics ã®æ€åºçµæ ãªãããã¯ãšã³ãã§ã¯ Google Cloud ãªãœãŒã¹ã®ã¡ã¿ããŒã¿ã管çããä»çµã¿ã§ãã Cloud Asset Inventory ãšããä»çµã¿ã䜿ãããŠããŸãããŸããSecurity Health Analytics ã§æ€æ»å¯Ÿè±¡ã®å¯Ÿè±¡ãšãªããµãŒãã¹ã¯ä»¥äžã®éãã§ãã Cloud Monitoring and Cloud Logging Compute Engine Google Kubernetes Engine containers and networks Cloud Storage Cloud SQL Identity and Access ManagementïŒIAMïŒ Cloud Key Management ServiceïŒCloud KMSïŒ Cloud DNS åè : ãµããŒããããŠãã Google Cloud ã¯ã©ãŠã ãµãŒãã¹ æ€åºæ©èœã®äŸ 以äžã«ãã¹ã¿ã³ããŒããã£ã¢ã§æ€ç¥å¯èœãªé
ç®ã®äŸããªã¹ãã¢ããããŸãããã¬ãã¢ã ãã£ã¢ã§ã¯ããã«å€æ°ã®æ€åºæ©èœããããŸãã é
ç®å æŠèŠ PUBLIC_COMPUTE_IMAGE Compute Engine ã€ã¡ãŒãžãäžè¬å
¬éãããŠããŸã£ãŠãã OPEN_SSH_PORT VPC ãã¡ã€ã¢ãŠã©ãŒã«ã§ 22/TCP ã 22/SCTP ããŒããéããŠãã NON_ORG_IAM_MEMBER @gmail.com ã¡ãŒã«ã¢ãã¬ã¹ã®ã¢ã«ãŠã³ãã« IAM æš©éãä»äžãããŠãã MFA_NOT_ENFORCED Google WorkspaceïŒCloud IdentityïŒã« MFA ãæå¹ã«ãªã£ãŠããªããŠãŒã¶ãŒãååš PUBLIC_BUCKET_ACL äžè¬å
¬éãããŠãã Cloud Storage ãã±ãããååšãã PUBLIC_DATASET äžè¬å
¬éãããŠãã BigQuery ããŒã¿ã»ãããååšãã äžèšã¯äŸã§ãããæ€åºæ©èœã®äžèЧã¯ã以äžã®å
¬åŒããã¥ã¡ã³ãã«èšèŒãããŠããŸãã åè : Security Health Analytics ã®æ€åºçµæ 3 ã€ã®ã¹ãã£ã³ Security Health Analytics ã¯ä»¥äžã® 3 ã€ã®ã¢ãŒãã§ã¹ãã£ã³ãå®è¡ããŸãã ãããã¹ãã£ã³ïŒ1æ¥ã«1åãèªåã§çµç¹ãŸãã¯ãããžã§ã¯ããã¹ãã£ã³ïŒ ãªã¢ã«ã¿ã€ã ã¹ãã£ã³ïŒãªãœãŒã¹ã®å€æŽãæ€åºããŠã¹ãã£ã³ïŒ æ··åã¢ãŒãïŒããããšãªã¢ã«ã¿ã€ã ã®æ··åïŒ æ€åºé
ç®ã«ãã£ãŠãã©ã®ã¹ãã£ã³ãçšããããããç°ãªããŸãããããããèªåçã«è¡ãããŸããåæ²ã®æ€åºæ©èœäžèЧããã¥ã¡ã³ãã«ã察å¿ããŠããã¹ãã£ã³ã¿ã€ãã³ã°ãèšèŒãããŠããŸãã Web Security Scanner Web Security Scanner ãšã¯ Web Security Scanner 㯠Compute Engine ã App EngineïŒGAEïŒãGoogle Kubernetes EngineïŒGKEïŒã§ãã¹ããããŠãã Web ã¢ããªã±ãŒã·ã§ã³ã«å¯ŸããŠãã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®è匱æ§ã¹ãã£ã³ããããæ©èœã§ãã ãã ããã¹ãã£ã³ã§ãã察象ã¯ã€ã³ã¿ãŒãããã«å
¬éãããŠãã Web ã¢ããªã®ã¿ã§ãããããŒã«ã«ãããã¯ãŒã¯å
ã§äœ¿ããã瀟å
ã·ã¹ãã çã«ã¯äœ¿çšã§ããŸããã åè : Web Security Scanner ã®æŠèŠ 2 ã€ã®ã¹ãã£ã³ Web Security Scanner ã«ã¯ã ãããŒãžãã¹ãã£ã³ ãš ã«ã¹ã¿ã ã¹ãã£ã³ ã®2çš®é¡ããããŸãã ãããŒãžãã¹ãã£ã³ã¯ãé±ã«1åå®è¡ãããèªåçãªã¹ãã£ã³ã§ããèªèšŒãªãã GET ãªã¯ãšã¹ãã®ã¿ããšããå¶éããããŸãããããŒãžãã¹ãã£ã³ã¯ã ãã¬ãã¢ã ãã£ã¢ä»¥äž ã§å©çšã§ããŸãã ã«ã¹ã¿ã ã¹ãã£ã³ã¯ãæåå®è¡ã«ããã¹ãã£ã³ã§ããèªèšŒæ
å ±ãçšããŠæ€æ»ãã§ããŸãã ã¹ã¿ã³ããŒããã£ã¢ã§ã䜿çšã§ããŸã ããäžéšæ©èœãå¶éãããŠããŸãã æ€åºçµæ OWASP Top 10 ã«æºããæ€åºãè¡ãããšãã§ããŸãã以äžã®ããã¥ã¡ã³ãã«ãæ€åºçµæã®äžèЧããããŸãã åè : æ€åºçµæã®ã¿ã€ã äŸãšããŠä»¥äžã®ãããªãã®ããããŸãã é
ç®å æŠèŠ OUTDATED_LIBRARY æ¢ç¥ã®è匱æ§ãããã©ã€ãã©ãªãæ€åºããã SERVER_SIDE_REQUEST_FORGERY ãµãŒããŒåŽã®ãªã¯ãšã¹ã ãã©ãŒãžã§ãªïŒSSRFïŒã®è匱æ§ãæ€åºããã XSS ãã®ãŠã§ã ã¢ããªã±ãŒã·ã§ã³ã®ãã£ãŒã«ãã¯ãã¯ãã¹ãµã€ã ã¹ã¯ãªããã£ã³ã°ïŒXSSïŒæ»æã«å¯ŸããŠè匱ã§ãã æ³šæç¹ ã¹ãã£ã³ãå®è¡ãããšããã©ãŒã ãžã®å
¥åããã¿ã³æŒäžããªã³ã¯ãžã®ã¢ã¯ã»ã¹ãªã©ãäžè¬ãŠãŒã¶ãŒã®åããæš¡ãããªã¯ãšã¹ããè¡ãããŸãããã®ããã æ¬çªç°å¢ã«æãã¬ç Žå£çãªçµæ ãåãŒããããããŒãã§ã¯ãããŸããããã ãããã㯠Security Command Center ã ãã«èšããããšã§ã¯ãªããéåžžã®è匱æ§èšºæã§ãåãã§ãã å
¬åŒããã¥ã¡ã³ãã§ã¯ããã¹ããã©ã¯ãã£ã¹ãšããŠä»¥äžã玹ä»ãããŠããŸãã ãŸãããã¹ãç°å¢ã§ã¹ãã£ã³ãå®è¡ ãã¹ãã¢ã«ãŠã³ãã®å©çšããããš CSS ã¯ã©ã¹ inq-no-click ã®å©çš ã¹ãã£ã³åã«ããã¯ã¢ãããååŸããããš ãã¹ããè¡ããªã URL ãã¿ãŒã³ãæç€ºçã«æå®ããããš åè : ãã¹ã ãã©ã¯ãã£ã¹ Anomaly Detection Anomaly Detection ïŒç°åžžæ€åºïŒãšã¯ãèªèšŒæ
å ±ã®æŒæŽ©ãªã©ãç°åžžãªæåãæ€ç¥ã§ããä»çµã¿ã§ãã çµç¹ã¬ãã« ã§ Security Command Center ãæå¹åãããšã ãã¹ãŠã®ãã£ã¢ ã§èªåçã« Anomaly Detection ãæå¹åãããŸãããããžã§ã¯ãã¬ãã«ã§ã®æå¹åã§ã¯ãç°åžžæ€åºã¯ãµããŒããããŸããã äŸãšããŠã account_has_leaked_credentials ãšããæ€ç¥é
ç®ã§ã¯ããµãŒãã¹ã¢ã«ãŠã³ãã®èªèšŒæ
å ±ããªã³ã©ã€ã³ã«æµåºããããšãæ€ç¥ããŠãããŸãã åè : æ€åºãµãŒãã¹ - ç°åžžæ€åº Event Threat Detection Event Threat Detection ãšã¯ Event Threat Detection ã¯ãCloud Logging ããã³ Google Workspace ãã°ãç£èŠããæ©æ¢°åŠç¿çã«ããæ€æ»ããããšã§ããã¢ãªã¢ã«ã¿ã€ã ã§è
åšãæ€ç¥ããä»çµã¿ã§ãã Event Threat Detection 㯠ãã¬ãã¢ã ãã£ã¢ä»¥äž ã§å©çšããããšãã§ããŸãã åè : Event Threat Detection ã®æŠèŠ ãBigQuery ããã®ããŒã¿ã®æã¡åºãããVM äžã®ãã«ãŠã§ã¢ã«ããéä¿¡ããGoogle Workspace ã°ã«ãŒãã®å®å
šã§ãªãæš©éèšå®ããæ¿åºã«æ¯æŽãããæ»æãšçãããã¢ã¯ã·ã§ã³ããªã©ãæ€ç¥ããããšãã§ããŸãã æ€åºçµæã¯ Security Command Center ã³ã³ãœãŒã«çã§ç¢ºèªã§ããä»ãCloud Logging ã«åºåãããããPub/Sub ã«ãããªãã·ã¥ãããã§ãããããåŸç¶ã¢ã¯ã·ã§ã³ã®èªååãªã©ã«ãç¹ããããŸãã åè¿°ã® Security Health Analytics ã Cloud Asset Inventory ã®æ§ææ
å ±ãå
ã«æ€æ»ããã®ã«å¯ŸããŠãEvent Threat Detection ã¯ãCloud Logging ã Google Workspace ã®ãã°ãæ€æ»ããŠã¢ã¯ãã£ããã£ãæ€ç¥ããç¹ãç°ãªããŸãã æ€ç¥å
容ã®äŸ 以äžã®ããã¥ã¡ã³ãã«ãæ€ç¥å¯èœãªå
容ããªã¹ããããŠããŸãã åè : Event Threat Detection ã®ã«ãŒã« 以äžã¯ãæ€ç¥äºé
ã®äžéšæç²ã§ãã é
ç®å æŠèŠ DATA_EXFILTRATION_BIG_QUERY BigQuery ããããŒã¿ãçµç¹å€ãžã³ããŒãããçã Cloud Audit Logs ããæ€ç¥ MALWARE_BAD_DOMAIN ãã«ãŠã§ã¢éä¿¡ãšçããããã¡ã€ã³ãžã®éä¿¡ã Cloud DNS ã®ãã°ããæ€ç¥ ANOMALOUS_ACCESS Tor ãªã©å¿ååããããããã·ã® IP ãã Google Cloud ãªãœãŒã¹ã倿Žãããã Cloud Audit Logs ããæ€ç¥ BRUTE_FORCE_SSH VM ã® SSH ã«ãã«ãŒããã©ãŒã¹æ»æã Cloud Logging ã«ãšã¯ã¹ããŒãããã syslog ããæ€ç¥ SUSPICIOUS_LOGIN çããããã°ã€ã³ãçºçã Google Workspace ãã°ããæ€ç¥ 2SV_DISABLE ãŠãŒã¶ãŒã 2 段éèªèšŒãç¡å¹åããã Google Workspace ãã°ããæ€ç¥ æ€æ»å¯Ÿè±¡ã®ãã°ã®æå¹å Event Threat Detection ã¯ã Google Workspace ã®ãã°ã Cloud Logging ã®ãã°ã䜿ã£ãŠè
åšãæ€ç¥ããŸãã Cloud Audit Logs ã®ç®¡çã¢ã¯ãã£ããã£ç£æ»ãã°ïŒAdmin Activity audit logsïŒãããã©ã«ãã§æå¹åãããŠãã Cloud Logging ã«åºåãããã®ã§ãäœãèšå®ããªããŠãèªåçã«æ€ç¥å¯Ÿè±¡ã«ãªããŸãã ãããã以äžã®ãããªãã°ã¯å¿
èŠã«å¿ã㊠ON ã«ããå¿
èŠããããŸãã SSH logsãsyslogïŒOps Agent / Cloud Logging Agent çµç±ã§ Cloud Logging ã«ãšã¯ã¹ããŒãïŒ ããŒã¿ã¢ã¯ã»ã¹ç£æ»ãã°ïŒCloud Audit LogsïŒ VPC flow logs Cloud DNS logs Firewall Rules logs Cloud NAT logs ãããã®ãã°ã¯æç€ºçã«æå¹åããªããšåºåãããŸãããåºåãããŠããªãå Žåã¯ã Event Threat Detection ã®æ€æ»å¯Ÿè±¡ã«ããªããŸãããåºåã«ãã Cloud Logging ã®æéãå¢ããå¯èœæ§ãçè§£ãã€ã€ãå¿
èŠã«å¿ããŠæå¹åãæ€èšããŸãã Cloud Audit Logs ã«ã€ããŠã¯ä»¥äžã®èšäºã§è§£èª¬ããŠããŸãã®ã§ããåç
§ãã ããã blog.g-gen.co.jp ãŸããã°åºåå
ãšãªã Cloud Logging ã«ã€ããŠã¯ä»¥äžã®èšäºã§è§£èª¬ããŠããŸãã®ã§ããåç
§ãã ããã blog.g-gen.co.jp ã«ã¹ã¿ã ã¢ãžã¥ãŒã« Event Threat Detection ã® ã«ã¹ã¿ã ã¢ãžã¥ãŒã« ïŒCustom modulesïŒã¯ããŠãŒã¶ãŒãç¬èªã®è
åšæ€åºããžãã¯ãå®çŸ©ããEvent Threat Detection ã«çµã¿èŸŒãããšãã§ããæ©èœã§ãã åè : Event Threat Detection çšã«ã¹ã¿ã ã¢ãžã¥ãŒã«ã®æŠèŠ Event Threat Detection ã§ã¯ããã«ãŠã§ã¢ãã¯ãªãããã€ãã³ã°ãäžæ£ãªæš©éææ ŒãããŒã¿æãåãã®è©Šã¿ãªã©ãããŸããŸãªè
åšãæ€åºããããã® çµã¿èŸŒã¿ã¢ãžã¥ãŒã« ãæäŸããããã®ã®ãçµã¿èŸŒã¿ã§æäŸãããŠããªãèŠä»¶ã®æ€ç¥ãè¡ãããå Žåã«ããã®ã«ã¹ã¿ã ã¢ãžã¥ãŒã«ã䜿ããŸãã詳现ã¯ä»¥äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp Container Threat Detection Container Threat Detection ãšã¯ Container Threat Detection ã¯ãGoogle Kubernetes EngineïŒGKEïŒããŒãã®ã¢ãã¿ãªã³ã°ãè¡ããããŒãäžã®å€æŽãã³ã³ããã©ã³ã¿ã€ã äžã®äžå¯©ãªæåããã¢ãªã¢ã«ã¿ã€ã ã§æ€ç¥ããŸããã³ã³ããããŒãã§å®è¡ããããã€ããªãã³ã³ããã«ããŒããããã©ã€ãã©ãªãæ€æ»ãããã NLPïŒèªç¶èšèªåŠçïŒã«ãã bash ã¹ã¯ãªããã Python ã³ãŒãã®æ€æ»ãªã©ãè¡ãããŸãã Container Threat Detection 㯠ãã¬ãã¢ã ãã£ã¢ä»¥äž ã§å©çšã§ããŸãã åè : Container Threat Detection ã®æŠèŠ ãµããŒãããŠãã GKE ã®ããŒãžã§ã³çã¯ã以äžã®ããã¥ã¡ã³ããåç
§ããŠãã ããã åè : ãµããŒããããŠãã GKE ããŒãžã§ã³ã®äœ¿ç𠿀ç¥ã§ããå
容 Container Threat Detection ã§ã¯ã以äžã®ãããªå
å®¹ãæ€ç¥ã§ããŸãã é
ç®å æŠèŠ Added Malicious Binary Executed ãªãªãžãã«ã®ã³ã³ããã€ã¡ãŒãžã«ç¡ããæ¢ç¥ã®æªæãããã€ããªãå®è¡ããã Added Malicious Library Loaded ãªãªãžãã«ã®ã³ã³ããã€ã¡ãŒãžã«ç¡ããæ¢ç¥ã®æªæããã©ã€ãã©ãªãããŒãããã Malicious Script Executed æªæãã bash ã¹ã¯ãªãããå®è¡ããã Reverse Shell ãªã¢ãŒãã®ãœã±ãããžã®ã¹ããªãŒã ãªãã€ã¬ã¯ã·ã§ã³ãè¡ãããã»ã¹ãéå§ããã Malicious URL Observed æªæãã URL ãåŒæ°ãšããããã»ã¹ãèµ·åããŠãã åè : Container Threat Detection ã®æŠèŠ - Container Threat Detection æ€åºåš Cloud Run Threat Detection Cloud Run Threat Detection ãšã¯ Cloud Run Threat Detection ã¯ãCloud Run ã®ã³ã³ããã©ã³ã¿ã€ã äžã®äžå¯©ãªæåãæ€ç¥ããŸããContainer Threat Detection ãšåæ§ãã³ã³ããããŒãã§å®è¡ããããã€ããªãã³ã³ããã«ããŒããããã©ã€ãã©ãªãæ€æ»ãããŸãã Cloud Run Threat Detection 㯠ãã¬ãã¢ã ãã£ã¢ä»¥äž ã§å©çšã§ããŸãã Cloud Run Threat Detection ã¯ãCloud Run services ãš Cloud Run jobs ã«å¯Ÿå¿ããŠããŸãã åè : Cloud Run ã®è
åšæ€åºã®æŠèР以äžã®èšäºãåèã«ããŠãã ããã blog.g-gen.co.jp æ€ç¥ã§ããå
容 Cloud Run Threat Detection ã§ã¯ã以äžã®ãããªå
å®¹ãæ€ç¥ã§ããŸãã é
ç®å æŠèŠ Added Malicious Binary Executed ãªãªãžãã«ã®ã³ã³ããã€ã¡ãŒãžã«ç¡ããæ¢ç¥ã®æªæãããã€ããªãå®è¡ããã Added Malicious Library Loaded ãªãªãžãã«ã®ã³ã³ããã€ã¡ãŒãžã«ç¡ããæ¢ç¥ã®æªæããã©ã€ãã©ãªãããŒãããã Malicious Script Executed æªæãã bash ã¹ã¯ãªãããå®è¡ããã Reverse Shell ãªã¢ãŒãã®ãœã±ãããžã®ã¹ããªãŒã ãªãã€ã¬ã¯ã·ã§ã³ãè¡ãããã»ã¹ãéå§ããã Malicious URL Observed æªæãã URL ãåŒæ°ãšããããã»ã¹ãèµ·åããŠãã åè : Cloud Run ã®è
åšæ€åºã®æŠèŠ - æ€åºé
ç® Virtual Machine Threat Detection Virtual Machine Threat Detection ãšã¯ Virtual Machine Threat Detection ãšã¯ããã€ããŒãã€ã¶ã¬ã€ã€ããã®ã¡ã¢ãªæ€æ»ãããã£ã¹ã¯ã¯ããŒã³ã®æ€æ»ã«ãããCompute Engine VM å
ã®ãã«ãŠã§ã¢ãä»®æ³é貚ãã€ãã³ã°ãæ€ç¥ã§ããæ©èœã§ãã Virtual Machine Threat Detection ã¯ã ãã¬ãã¢ã ãã£ã¢ä»¥äž ã§å©çšã§ããŸãã åè : Virtual Machine Threat Detection ã®æŠèŠ æ€ç¥ã§ããå
容 Virtual Machine Threat Detection ã§æ€ç¥å¯èœãªã®ã¯ãæå·é貚ãã€ãã³ã°ãã«ãŒãã«ã¢ãŒãã«ãŒããããããã«ãŠã§ã¢ã§ãã 詳现ã¯ä»¥äžã®ããã¥ã¡ã³ããåç
§ããŠãã ããã åè : æ€åº VM ã®è匱æ§ã¬ããŒã VM Manager ã®è匱æ§ã¬ããŒã æ©èœã§ã¯ãSecurity Command Center ãš Compute Engine ã®éçšèªååããŒã«ã§ãã VM Manager ã飿ºããŠããšãŒãžã§ã³ãã«ãã VM å
ãã¹ãã£ã³ããããšã§ OS ã¬ãã«ã®è匱æ§ãæ€ç¥ããããšãã§ããŸãã VM Manager ã®è匱æ§ã¬ããŒã㯠ãã¬ãã¢ã ãã£ã¢ä»¥äž ã§å©çšã§ããŸãã 2025幎5æçŸåšã§ã¯ Preview å
¬éã§ããããšã«ãçæãã ããã 詳现ã¯ã以äžã®ããã¥ã¡ã³ããåç
§ããŠãã ããã åè : è匱æ§ã®æ€åºçµæ - VM Manager Cryptomining Protection Program Security Command Center Cryptomining Protection Program ã¯ãSecurity Command Center ãã¬ãã¢ã ãã£ã¢ããã³ãšã³ã¿ãŒãã©ã€ãºãã£ã¢ã®ãŠãŒã¶ã« Google ããæäŸããããè£åããã°ã©ã ã§ãã ãã®ããã°ã©ã ã«åå ãããšãCompute Engine VM ç°å¢ã Google Kubernetes Engine ç°å¢ã«ãããŠäžãäžã¯ãªãããã€ãã³ã°ïŒCrypto Miningãä»®æ³é貚ããã€ãã³ã°ããããã«äžæ£ã«ã³ã³ãã¥ãŒããªãœãŒã¹ã䜿çšããæ»æïŒãè¡ãããŠããŸã£ãå Žåã«ãããŠãSecurity Command Center Premium ãé©åã«èšå®ããŠããã®ã«ãé¢ãããæ€ç¥ãããªãã£ãå ŽåãGoogle Cloud ã¯ã¬ãžããã§ã®è£å¡«ãåããããšãã§ããŸãã ããã°ã©ã ã®åå èŠä»¶ãªã©ã®è©³çްã¯ã以äžã®ããã¥ã¡ã³ãããåç
§ãã ããã åè : Security Command Center Cryptomining Protection Program GeminiïŒçæ AIïŒã®å©çš Security Command Center ã«ã¯ãGoogle ãéçºããçæ AI ãœãªã¥ãŒã·ã§ã³ã§ãã Gemini ãçµã¿èŸŒãŸããŠããŸãã Gemini ãšã®é£æºæ©èœã䜿ããã®ã¯ã ãã¬ãã¢ã ãã£ã¢ä»¥äž ã§ãã æ©èœå å©çšå¯èœãªãã£ã¢ æŠèŠ æ€åºçµæã𿻿ãã¹ã® Gemini ã®æŠèŠ ãã¬ãã¢ã ã ãšã³ã¿ãŒãã©ã€ãº æ€ç¥äºé
ã«å¯ŸããŠæ»æçµè·¯ã®ã·ãã¥ã¬ãŒã·ã§ã³ãåçã«çæãæç€º èªç¶èšèªæ€çŽ¢ã«ãã è
åšèª¿æ» ãšã³ã¿ãŒãã©ã€ãº Google SecOps äžã§æ€åºçµæãã¢ã©ãŒãããã®ä»ã®æ
å ±ãèªç¶èšèªã§æ€çŽ¢ ã±ãŒã¹ã® AI 調æ»ãŠã£ãžã§ãã ãšã³ã¿ãŒãã©ã€ãº Google SecOps äžã§ã€ã³ã·ãã³ãã±ãŒã¹ã®æŠèŠã𿬡ã®ã¹ãããã®è¡šç€º åè : Security Command Center ã® Gemini ã®æ©èœ ã³ã³ãã©ã€ã¢ã³ã¹è©äŸ¡ ã³ã³ãã©ã€ã¢ã³ã¹æšæºãšã®ãããã³ã° ãã¬ãã¢ã ãã£ã¢ä»¥äž ã® Security Command Center ã§ã¯ãæ€ç¥æ©èœã«ããæ€åºãããçµæãã以äžã®ãããªã³ã³ãã©ã€ã¢ã³ã¹æšæºèŠæ Œã«ãããã³ã°ããããšãã§ããŸãïŒäžéšæç²ïŒã CIS Benchmark ISO 27001 PCI DSS OWASP Top 10 NIST 800-53 æ€åºçµæãã©ã®ã»ãã¥ãªãã£æšæºèŠæ Œã«éåããŠããå¯èœæ§ããããã¯ãã³ã³ãœãŒã«ç»é¢ã«è¡šç€ºãããŸãã æ€ç¥å
容ãã©ã®æšæºèŠæ Œã«é¢ä¿ãããå³åŽã®åã«è¡šç€ºãããŠãã ãŸã以äžã®ã¹ã¯ãªãŒã³ã·ã§ããã®ããã«ãã³ã³ãã©ã€ã¢ã³ã¹æšæºã®é
ç®ãšæ€ç¥äºé
ã®å¯Ÿç
§è¡šã衚瀺ã§ããŸããæ€ç¥äºé
ã1ã€ãã€æ¶ã蟌ãã§ããããšã§ãæšæºã«æºæ ããç¶æ
ã«è¿ã¥ããããšãã§ããŸãã ã³ã³ãã©ã€ã¢ã³ã¹æšæºã®é
ç®ãšæ€ç¥äºé
ã®å¯Ÿç
§è¡š åè : ã»ãã¥ãªãã£æšæºã®ã³ã³ãã©ã€ã¢ã³ã¹ãè©äŸ¡ããŠå ±åãã 代衚çãªã³ã³ãã©ã€ã¢ã³ã¹æšæº CIS ãã³ãããŒã¯ ã¯ã CIS (Center for Internet Security ãç±³åœã® åœå®¶å®å
šä¿éå± (NSA) ãç±³åœç«æšæºæè¡ç ç©¶æ (NIST) ãåŠè¡å£äœãªã©ãèšç«ããéå¶å©å£äœ) ãå®çŸ©ãããã³ãããŒã¯ã§ãã Amazon Web Services (AWS) ã«ããã Security Command Center ã®é¡äŒŒãµãŒãã¹ã§ãã AWS Security Hub ã§ããã»ãã¥ãªãã£åºæºãšããŠå©çšãããŠããŸãã PCI DSS ã¯ã¯ã¬ãžããã«ãŒãæ
å ±ãæ±ãããã®ã°ããŒãã«ãªã»ãã¥ãªãã£åºæºã§ãã ã¯ã¬ãžããã«ãŒããæ±ãã·ã¹ãã ã«é¢ãã£ãæ¹ã§ããã°ãäžåºŠã¯è³ã«ããèªèšŒååŸã«èŠåŽããããšãããã§ãããã OWASP Top 10 ã¯ç±³åœã®éå¶å©å£äœã§ãã OWASP Foundation ã宿çã«çºè¡ããŠããã»ãã¥ãªãã£ã¬ããŒãã§ãæ¥æ¬ã§ãåºãåç
§ãããŠããŸãã ãã®å£äœããæäŸãããŠãããªãŒãã³ãœãŒã¹ã®è匱æ§èšºæããŒã«ã§ãã OWASP ZAP ã¯ãã»ãã¥ãªãã£ã®æåæ¬ã§ããã³ãºãªã³ã«å©çšãããŠããã®ãããç®ã«ããŸãã NIST 800-53 ã¯ç±³åœã®æ¿åºæ©é¢ã§ããç±³åœç«æšæºæè¡ç ç©¶æ (NIST) ããç±³åœé£éŠæ¿åºã®æ
å ±ã·ã¹ãã ã®ã»ãã¥ãªãã£åºæºãšããŠå®çŸ©ãããã®ã§ãã ISO 27001 ã¯æ¥æ¬ã§ ISMS ãšããŠç¥ãããèªèšŒã®åœéèŠæ ŒãšããŠæåã§ããã Security Command Center ã§ã¯åçš®ã®æ€ç¥çµæããã®ãããªã³ã³ãã©ã€ã¢ã³ã¹æšæºã«ãããã³ã°ãããã®ã§ãèªèšŒååŸãªã©ã«åããŠç°å¢ãæŽåããããç¶ç¶çãªã¢ãã¿ãªã³ã°ãè¡ãããšãã§ããŸãã ãšã³ã¿ãŒãã©ã€ãºãã£ã¢ã®æ©èœ Compliance Manager Compliance Manager ã¯ãCIS BenchmarkãISO 27001ãNIST ãªã©ã®ã³ã³ãã©ã€ã¢ã³ã¹æšæºã«åºã¥ããèšå®ã®ãããã€ãè¡ã£ãããæšæºãžã®æºæ ç¶æ³ãããã·ã¥ããŒãåããããç£æ»ã¬ããŒããåºåããããã®æ©èœã§ãã Compliance Manager ã¯çµç¹ã¬ãã«ã§æå¹åããã ãšã³ã¿ãŒãã©ã€ãºãã£ã¢ ã§ã®ã¿å©çšå¯èœã§ããããã¬ãã¢ã ãã£ã¢ä»¥äžã§äœ¿çšå¯èœãªã³ã³ãã©ã€ã¢ã³ã¹è©äŸ¡æ©èœã®äžäœçã®äœçœ®ã¥ãã§ãã 管çç»é¢ãã Compliance Manager ãæå¹åãããšã䜵ã㊠Sensitive Data ProtectionãEvent Threat DetectionãData Security Posture ManagementïŒDSPMïŒãªã©ãæå¹åãããå€ãã® Security Command Center æ©èœãšé£æºããŠåäœããŸãã 詳现ã¯ä»¥äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : Compliance Manager overview Data Security Posture ManagementïŒDSPMïŒ Data Security Posture Management ïŒDSPMïŒã¯ãGoogle Cloud äžã®ããŒã¿ã®çš®é¡ãä¿åå Žæãã»ãã¥ãªãã£åºæºããã¹ããã©ã¯ãã£ã¹ãžã®æºæ ç¶æ³ãææ¡ããããã®æ©èœã§ãã DSPM ã«ã¯ ããŒã¿ã»ãã¥ãªãã£ããã·ã¥ããŒã ãå«ãŸããŠããŸãããã®ããã·ã¥ããŒãã§ã¯ãçµç¹ã®ããŒã¿ãã»ãã¥ãªãã£ãã³ã³ãã©ã€ã¢ã³ã¹ã®èŠä»¶ã«é©åããŠãããã確èªã§ããŸããããŒã¿ã®ãã±ãŒã·ã§ã³ïŒãªãŒãžã§ã³ïŒããããžã§ã¯ããGoogle Cloud ãããã¯ããªã©ã§ãã£ã«ã¿ãªã³ã°ããŠäžèŠ§è¡šç€ºããããšãã§ããŸãã ãŸã ããŒã¿ã»ãã¥ãªãã£ãã¬ãŒã ã¯ãŒã¯ ã§ã¯ãBigQuery ã§ã® CMEKïŒé¡§å®¢ç®¡çã®ç§å¯éµïŒã®å©çšç¶æ³ããCloud SQL ã€ã³ã¹ã¿ã³ã¹ã®å
¬éã¢ã¯ã»ã¹ã®ç¶æ³ãªã©ã®åºæ¬çãªèšå®ç¶æ³ãç£èŠã»æ€åºã§ããã»ããæå®ããããªã³ã·ãã«ä»¥å€ã®ããŒã¿ãžã®ã¢ã¯ã»ã¹ç¶æ³ãåœå€ããã®ã¢ã¯ã»ã¹ç¶æ³ãæå€§ä¿ææéããªã·ãŒã®éåç¶æ³ãªã©ãæ€åºã§ããŸãã DSPM ã«ã¯ããã®ä»ã«ãããŒã¿ã®ã»ãã¥ãªãã£ãç¶æããããã®æ©èœããããŸãã詳现ã¯ä»¥äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : Data Security Posture Management (DSPM) overview ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO å
èŠå¯å®ãšããçµæŽãæã€ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS èªå®è³æ Œããã³ Google Cloud èªå®è³æ Œã¯ãã¹ãŠååŸãXïŒæ§ TwitterïŒã§ã¯ Google Cloud ã Google Workspace ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
G-genã®ææã§ããGoogle CloudïŒæ§ç§° GCPïŒã®ã¯ã©ãŠãå WAF ã§ãã Google Cloud Armor ã«ã€ããŠãæŠèŠãç¹åŸŽãèšèŒããŸãã Cloud Armor ãšã¯ Cloud Armor ã®æŠèŠ WAF æ©èœ æé æéãã£ã¢ Standard ãã£ã¢ Enterprise ãã£ã¢ ã»ãã¥ãªãã£ããªã·ãŒ ã»ãã¥ãªãã£ããªã·ãŒãšã¯ ã»ãã¥ãªãã£ããªã·ãŒãã¢ã¿ããã§ãã察象 3çš®é¡ã®ã»ãã¥ãªãã£ããªã·ãŒ ã«ãŒã«ãšã¯ ã«ãŒã«ã®ãã¬ãã¥ãŒã¢ãŒã ååä»ã IP ã¢ãã¬ã¹ãªã¹ã ã«ãŒã«ã®èšè¿° éå±€åã»ãã¥ãªãã£ããªã·ãŒ DDoS 察ç DDoS ä¿è·æ©èœ DDoS 察å¿ãµããŒã DDoS è«æ±ä¿è· Adaptive ProtectionïŒé©å¿åä¿è·ïŒ Adaptive Protection ãšã¯ ã¢ã©ãŒã èªåçæã«ãŒã«ã®é©çš DDoS æ»æã®å¯èŠå ã¬ãŒãå¶é Bot 管ç éçšã»ãã®ã³ã° WAF ã®éçšäœæ¥ Cloud Armor ã®ãã°åºå Cloud Armor ãšã¯ Cloud Armor ã®æŠèŠ Google Cloud Armor ïŒä»¥äžãCloud ArmorïŒã¯ã¯ã©ãŠãåã® Web Application Firewall ïŒä»¥äžãWAFïŒã§ããããã«ãããŒãžããµãŒãã¹ã§ãã WAF ãšã¯ Web ã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿãã SQL ã€ã³ãžã§ã¯ã·ã§ã³ãã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ãšãã£ãã¢ããªã±ãŒã·ã§ã³ã¬ã€ã€ã®æ»æãæ€ç¥ããé²åŸ¡ããããã®ä»çµã¿ã§ããå ããŠãCloud Armor ã«ã¯ DDoS æ»æãžã®é²åŸ¡æ©èœãæã£ãŠããŸãã Cloud Armor ãä¿è·ã§ããã®ã¯ãååãšã㊠Google Cloud ã®ããŒããã©ã³ãµãŒã§ãã Cloud Load Balancing ã®èåŸã«ãã Web ã¢ããªã±ãŒã·ã§ã³ ã§ãã察å¿ããŠããããŒããã©ã³ãµãŒã®çš®é¡ã¯åŸè¿°ããŸãããŸããäžå®ã®å¶éã®ããšã§ããã°ãããªã㯠IP ãæã£ãŠãã VM ã«çŽæ¥ã«ãŒã«ãã¢ã¿ããããããšãã§ããŸãïŒãããã¯ãŒã¯ãšããžã»ãã¥ãªãã£ããªã·ãŒïŒããã¡ãã«ã€ããŠãåŸè¿°ããŸãã åè : Google Cloud Armor ã®æŠèŠ WAF æ©èœ Cloud Armor ã®æãåºæ¬çãªæ©èœã¯ãã»ãã¥ãªãã£ããªã·ãŒããèšå®ããããšã§ãWeb ã¢ããªã±ãŒã·ã§ã³ãã¢ããªã±ãŒã·ã§ã³ã¬ã€ã€ïŒL7ïŒã®æ»æããä¿è·ããããšã§ãã WAF ã«ãŒã«ã¯ Common Expression Language ïŒCELïŒãšåŒã°ããã«ã¹ã¿ã ã«ãŒã«èšèªã§èšè¿°ããŸãã ç°¡åãªèšè¿°ã§ OWASP Top 10 ãªã©ã®æ»æãç·©åããäºåæ§æã«ãŒã«ãåŒã³åºãããšãã§ãããããè€éãªã·ã°ããã£ãèªåã§æžãå¿
èŠã¯ãããŸããã ãªã OWASP Top 10 ãšã¯ãç±³åœã®éå¶å©å£äœã§ãã Open Worldwide Application Security ProjectïŒOWASPïŒã宿çã«å
¬éããŠãããWeb ã¢ããªã±ãŒã·ã§ã³ã«é¢ããé倧ãªãªã¹ã¯ã®ã©ã³ãã³ã°ã§ããWeb ã¢ããªã®ã»ãã¥ãªãã£ãªã¹ã¯ãè©äŸ¡ããéã«ãåºãåç
§ãããŠããŸãã åè : OWASP Top Ten æé æéãã£ã¢ Cloud Armor ã«ã¯ Cloud Armor Standard ãš Cloud Armor Enterprise ã®2ã€ã®æéãã£ã¢ããããŸãïŒEnterprise ã¯ä»¥å㯠Managed Protection Plus ãšåŒã°ããŠããŸãããã2024幎4æã«æ¹ç§°ããŸããïŒã Standard ãã£ã¢ã§ã¯éåžžã® WAF ã®æ©èœã§ããã¢ããªã±ãŒã·ã§ã³ã¬ã€ã€ïŒã¬ã€ã€ 7ïŒãžã®ã«ãŒã«ããŒã¹ã®é²åŸ¡æ©èœã«å ããäžéšã® Cloud Load Balancing ã«å¯Ÿãã DDoS æ»æãžã®é²åŸ¡æ©èœãåããŠããŸãã Enterprise ãã£ã¢ã§ã¯ Standard ãã£ã¢ã®æ©èœã«å ããŠã以äžã®ãããªæ©èœãåããŠããŸãã Google ã管çãããµãŒãããŒãã£ã® IP ã¢ãã¬ã¹ãªã¹ã Google ã管çãã Threat IntelligenceïŒè
åšæ
å ±ïŒã«ããé²åŸ¡æ©èœ Adaptive ProtectionïŒé©å¿åé²åŸ¡ãæ©æ¢°åŠç¿ã掻çšããè
åšæ€ç¥ïŒ 远å ã® DDoS é²åŸ¡æ©èœ 詳现ã«ã€ããŠã¯ã以äžã®å
¬åŒããã¥ã¡ã³ããåèã«ããŠãã ããã åè : Cloud Armor Enterprise overview Standard ãã£ã¢ Cloud Armor ã® Standard ãã£ã¢ã¯ã以äžã® 3 è»žã§æéãèšç®ããããåŸé課éå¶ã§ãã åŠçãããªã¯ãšã¹ãæ°ïŒã°ããŒãã«ã¹ã³ãŒãã®ããªã·ãŒã®å Žåã$0.75/100 äžä»¶ïŒ ã»ãã¥ãªãã£ããªã·ãŒæ°ïŒ$5/ä»¶ïŒ ã«ãŒã«æ°ïŒ$1/ä»¶ïŒ äžèšã«èšèŒã®æéã¯2025幎7æçŸåšã®å䟡ã§ããææ°ã®æéã¯ã以äžã®å
¬åŒããã¥ã¡ã³ãããåç
§ãã ããã åè : Google Cloud Armor pricing Enterprise ãã£ã¢ Enterprise ãã£ã¢ã«ã¯ã Paygo ïŒPay as you goãåŸé課éïŒãš Annual ïŒå¹Žéãµãã¹ã¯ãªãã·ã§ã³ïŒã®2çš®é¡ãããèª²éæ¹æ³ãéžæã§ããŸãããã®2ã€ã®éã§ã¯åãããããµãŒãã¹ãäžéšç°ãªããŸãã PayGo ã§ã¯ããããžã§ã¯ãããšã«$200/æã®åºæ¬æéãçºçããããã«ä¿è·å¯Ÿè±¡ãªãœãŒã¹ããšã«è¿œå ã®æéãçºçããŸããAnnual ã ãšãè«æ±å
ã¢ã«ãŠã³ãããšã« $3000/æã®åºæ¬æéãšãä¿è·å¯Ÿè±¡ãªãœãŒã¹ããšã®è¿œå æéãçºçããŸãã æéãèª²éæ¹æ³ã®è©³çްã¯ã以äžã®å
¬åŒããã¥ã¡ã³ãããåç
§ãã ããã åè : Google Cloud Armor pricing åè : Cloud Armor Enterprise overview ã»ãã¥ãªãã£ããªã·ãŒ ã»ãã¥ãªãã£ããªã·ãŒãšã¯ Cloud Armor ã® ã»ãã¥ãªãã£ããªã·ãŒ ãšã¯ãé²åŸ¡ã«ãŒã«ã®å®çŸ©ã®ããšã§ããã»ãã¥ãªãã£ããªã·ãŒãäœæããŠãå€éš HTTP(S) ããŒããã©ã³ãµã® ããã¯ãšã³ããµãŒãã¹ ã«ã¢ã¿ããããããšã§ãã«ãŒã«ã广ãçºæ®ããŸãã åè : ã»ãã¥ãªã㣠ããªã·ãŒã®æŠèŠ ã»ãã¥ãªãã£ããªã·ãŒã«ã¯ã以äžã®ãããªèšå®ãæãããããšãã§ããŸãã åå¥ã«ãŒã«ïŒIPã¢ãã¬ã¹ç¯å²ãªã¹ã / ã«ã¹ã¿ã ã«ãŒã«èšèªïŒ ããã©ã«ãã¢ã¯ã·ã§ã³ïŒæåŠ / èš±å¯ïŒ Adaptive Protection ã®æå¹ / ç¡å¹ ã¢ã¿ããå
ã®ããã¯ãšã³ããµãŒãã¹ ã»ãã¥ãªãã£ããªã·ãŒãã¢ã¿ããã§ãã察象 ã»ãã¥ãªãã£ããªã·ãŒã¯ãããŒããã©ã³ãµãŒïŒCloud Load BalancingïŒã䜿ã£ãŠãã VM çãä¿è·å¯Ÿè±¡ã«ããããšãã§ããŸãã ã»ãã¥ãªãã£ããªã·ãŒã®äœçœ®ã¥ã åŸè¿°ããããã«ã»ãã¥ãªãã£ããªã·ãŒã«ã¯ãããã¯ãšã³ãã»ãã¥ãªãã£ããªã·ãŒãããšããžã»ãã¥ãªãã£ããªã·ãŒãããããã¯ãŒã¯ãšããžã»ãã¥ãªãã£ããªã·ãŒãã®3çš®é¡ãããŸããããããããªã·ãŒãã¢ã¿ããå¯èœãªå¯Ÿè±¡ãªãœãŒã¹ã決ãŸã£ãŠãããäŸãšããŠãããã¯ãšã³ãã»ãã¥ãªãã£ããªã·ãŒã¯ä»¥äžã®ãªãœãŒã¹ã«ã¢ã¿ããããããšãã§ããŸãã Global external Application Load Balancer Classic Application Load Balancer Global external proxy Network Load Balancer Classic proxy Network Load Balancer Regional external Application Load Balancer Regional internal Application Load Balancer 3çš®é¡ã®ã»ãã¥ãªãã£ããªã·ãŒ ã»ãã¥ãªãã£ããªã·ãŒã«ã¯ä»¥äžã®3çš®é¡ããããŸãã ããã¯ãšã³ãã»ãã¥ãªãã£ããªã·ãŒ ãšããžã»ãã¥ãªãã£ããªã·ãŒ ãããã¯ãŒã¯ãšããžã»ãã¥ãªãã£ããªã·ãŒ ããã¯ãšã³ãã»ãã¥ãªãã£ããªã·ãŒ ã¯ããšããžãã±ãŒã·ã§ã³ (Google ã®ãã£ãã·ã¥ãµãŒããŒ) ããããã¯ãšã³ãã«ã«ãŒãã£ã³ã°ããããªã¯ãšã¹ããè©äŸ¡ããŸããã€ãŸãããã£ãã·ã¥ãããããªãã£ããªã¯ãšã¹ããåçã³ã³ãã³ããªã©ã察象ã§ãããšããžãããã£ãã·ã¥ã§è¿ããããªã¯ãšã¹ãã¯è©äŸ¡å¯Ÿè±¡ã«ãªããŸããã ãšããžã»ãã¥ãªãã£ããªã·ãŒ ã¯ããšããžãããã£ãã·ã¥ã è¿ãå ã«è©äŸ¡ãããã«ãŒã«ãé©çšãããŸããCloud CDN ãæå¹åããããã¯ãšã³ãã Cloud Storage ãã±ããã察象ãšãªããŸãã ãããã¯ãŒã¯ãšããžã»ãã¥ãªãã£ããªã·ãŒ ã¯ãããŒããã©ã³ãµãŒã䜿ããªã VM ã«ãå©çšå¯èœãªããªã·ãŒã§ããæ¥ç¶å
IP ã¢ãã¬ã¹ãªã©ã«ããå¶éããããGoogle ã®ãããã¯ãŒã¯ã®ãšããžã§ãããã¯ããããšãã§ããŸããããã«ããäžæ£ã¢ã¯ã»ã¹ã DDoS ã VM ã®ãããã¯ãŒã¯ãªãœãŒã¹ãæ¶è²»ããããšãé²ãããšãã§ããŸãã ããã3ã€ã®ããªã·ãŒã¯äœµçšããããšãå¯èœã§ãã ãŸãããããã®ããªã·ãŒã§å©çšå¯èœãªæ©èœãç°ãªã£ãŠããŸãã詳现ã¯å
¬åŒã¬ã€ãããåç
§ãã ããã åè : ã»ãã¥ãªã㣠ããªã·ãŒã®çš®é¡ ã«ãŒã«ãšã¯ ã»ãã¥ãªãã£ããªã·ãŒå
ã«ã¯è€æ°ã® ã«ãŒã« ãèšå®ã§ããŸããã«ãŒã«ã¯åªå
床é ã«è©äŸ¡ãããã«ãŒã«ã«åèŽãããšããããäœãåªå
床ã®ã«ãŒã«ã¯è©äŸ¡ãããŸããã ã«ãŒã«ã«ã¯ãåºæ¬ã¢ãŒããšè©³çްã¢ãŒãã®2ã€ã®ã¢ãŒãããããŸãã ã¢ãŒãå æŠèŠ åºæ¬ã¢ãŒã IP ã¢ãã¬ã¹ã«åºã¥ããŠãã©ãã£ãã¯ãèš±å¯ãŸãã¯æåŠ è©³çŽ°ã¢ãŒã Common Expression LanguageïŒCELïŒã§èšè¿°ããã«ã¹ã¿ã ã«ãŒã«ã«åºã¥ããŠãã©ãã£ãã¯ãèš±å¯ãŸãã¯æåŠ IP ã¢ãã¬ã¹ã«ããå¶éã§ããã°åºæ¬ã¢ãŒãã®ã«ãŒã«ããSQL ã€ã³ãžã§ã¯ã·ã§ã³ãªã©ã® L7 æ»æãé²ãã«ã¯è©³çްã¢ãŒãã®ã«ãŒã«ãäœæããŸãã 詳现ã¢ãŒãã®ã«ãŒã«ã§ã¯ã«ã¹ã¿ã ã«ãŒã«èšèªã䜿ã£ãŠèšè¿°ããå¿
èŠããããŸããã Google ãäœæã»ç®¡çãã äºåæ§æ WAF ã«ãŒã« ïŒãŸãã¯äºåæ§æãããã«ãŒã«ãPreconfigured rulesïŒãåŒã³åºãããšã§ãç°¡åãªèšè¿°ã§é²åŸ¡ã«ãŒã«ãäœæããããšãã§ããŸãã ãŸã詳现ã¢ãŒãã®ã«ãŒã«ã§ã¯ãIP ã¢ãã¬ã¹ããæšæž¬ããå°ççæ
å ±ããbot ãé²ãããã®ã«ãŒã«ãã¬ãŒãå¶éãªã©ã倿§ãªã«ãŒã«ãå®çŸ©å¯èœã§ãã åè : ã»ãã¥ãªã㣠ããªã·ãŒã®ã«ãŒã«ã管çãã åè : ã«ãŒã«ã®çš®é¡ Google äºåæ§æã«ãŒã«ã¯ãªãŒãã³ãœãŒã¹ã® ModSecurity Core Rule Set ãå
ã«ãªã£ãŠããŸãã åè : GitHub - coreruleset ã«ãŒã«ã®ãã¬ãã¥ãŒã¢ãŒã ã«ãŒã«ã¯ ãã¬ãã¥ãŒ ã¢ãŒãã«ããããšãã§ããå®éã«ãã©ãã£ãã¯ãæåŠããã«ããã°ã®èšé²ã ãããããããšãã§ããŸããäžè¬çã«ãã©ã€ã©ã³ããã®ã³ã°ã¢ãŒããšåŒã°ããæ©èœã§ãã åè : ãã¬ãã¥ãŒ ã¢ãŒã ååä»ã IP ã¢ãã¬ã¹ãªã¹ã ååä»ã IP ã¢ãã¬ã¹ãªã¹ããšã¯ããµãŒãããŒãã£ã® CDN (Contents Delivery Network) ãããã€ãã管çãã IP ã¢ãã¬ã¹ã®ãªã¹ãã§ãã2025幎7æçŸåšã§ã¯ FastlyãCloudFlareãImperva ãååä»ã IP ã¢ãã¬ã¹ãªã¹ããæäŸããŠããŸãã ãããã® CDN ãå©çšããŠããå Žåã¯ãã»ãã¥ãªãã£ããªã·ãŒã«ãŠååä»ã IP ã¢ãã¬ã¹ãªã¹ããèš±å¯å¯Ÿè±¡ãšããŠæå®ãããã®ä»ããããã¯ããããšã§ã CDN 以å€ããã®ã¢ã¯ã»ã¹ããããã¯ããããšãã§ããŸãã ãã ããååä»ã IP ã¢ãã¬ã¹ãªã¹ãã¯éåžžçïŒStandardïŒã§ã¯äœ¿çšã§ããŸãããè¿œå æéãæ¯æããCloud Armor Enterprise ãã£ã¢ã«ç»é²ããå¿
èŠããããŸãã åè : ååä»ã IP ã¢ãã¬ã¹ãªã¹ãã®å¯çšæ§ åè : IP ã¢ãã¬ã¹ãªã¹ã ãããã€ã ã«ãŒã«ã®èšè¿° 詳现ã¢ãŒãã®ã«ãŒã«ã§ã¯åè¿°ã®éããã«ã¹ã¿ã ã«ãŒã«èšèªã䜿ã£ãŠã«ãŒã«ãèšè¿°ããå¿
èŠããããŸãã ãã®èšèªã䜿ã£ãŠã Google ã® äºåæ§æ WAF ã«ãŒã« ïŒãŸãã¯äºåæ§æãããã«ãŒã«ãPreconfigured rulesïŒãåŒã³åºãã®ãåºæ¬çãªäœ¿ãæ¹ãšãªããŸãã 以äžã¯ãæãç°¡åãªäŸã§ãã SQL ã€ã³ãžã§ã¯ã·ã§ã³ãé²ãäºåæ§æã«ãŒã«ãåŒã³åºããŠããŸãã evaluatePreconfiguredExpr('sqli-stable') ãã ãããã®æžãæ¹ã ãšãäºåæ§æã«ãŒã« sqli-stable ã«å«ãŸããŠããå
šãŠã® SQL ã€ã³ãžã§ã¯ã·ã§ã³å¯Ÿçã®ã·ã°ããã£ãåå¿ããŠããŸããŸããåœéœæ§ïŒæ£åœãªãªã¯ãšã¹ãã§ããã®ã«ãé¢ããããäžæ£ãªã¯ãšã¹ããšããŠæ€ç¥ãããŠããŸãããšïŒãèµ·ãããããç¶æ
ã§ããåœéœæ§ã®å¯èœæ§ãäžããããã«ãæåºŠã¬ãã«ã®é«ãã·ã°ããã£ãç¡å¹åããããæå®ããããšãã§ããŸãã # ã«ãŒã«åã®åŸã«ç¡å¹åããã·ã°ããã£åãå
¥å evaluatePreconfiguredExpr('sqli-stable', ['owasp-crs-v030001-id942421-sqli', 'owasp-crs-v030001-id942432-sqli']) ãŸã || ïŒ2ã€ã®ãã€ãïŒã䜿ã£ãŠã«ãŒã«ã OR æ¡ä»¶ã§ç¹ããããšãã§ããŸãã以äžã®ããã«ã«ãŒã«ãæ°ç ã€ãªãã«ããŠã¢ã¯ã·ã§ã³ã ããã㯠ã«ããã°ã1ã€ã®ã«ãŒã«ã®äžã§è€æ°ã®äºåæ§æã«ãŒã«ãåŒã³åºãããšãã§ããŸãã evaluatePreconfiguredExpr('xss-stable') || evaluatePreconfiguredExpr('sqli-stable') äºåæ§æ WAF ã«ãŒã«ã®äžèЧãèšå®æ¹æ³ã¯ã以äžã®ããã¥ã¡ã³ããåç
§ããŠãã ããã åè : Google Cloud Armor ã®äºåæ§æ WAF ã«ãŒã«ã®æŠèŠ åè : äºåæ§æããã WAF ã«ãŒã«ãèšå®ãã åè : Google Cloud Armor ã®äºåæ§æ WAF ã«ãŒã«ã調æŽãã éå±€åã»ãã¥ãªãã£ããªã·ãŒ éå±€åã»ãã¥ãªãã£ããªã·ãŒ ïŒéå±€åããã¯ãšã³ãã»ãã¥ãªãã£ããªã·ãŒïŒã¯ãçµç¹ããã©ã«ãããããžã§ã¯ããªã©ã®çµç¹éå±€ã«çŽã¥ããããšã§ããã®éå±€ã®é
äžã«ããããã¯ãšã³ããµãŒãã¹ããã¹ãŠä¿è·ã§ããããªã·ãŒã§ãã éåžžã®ã»ãã¥ãªãã£ããªã·ãŒããªã·ãŒã¯ãããžã§ã¯ãã«äœæããŠããã¯ãšã³ããµãŒãã¹ã«çŽã¥ããŸãããéå±€åã»ãã¥ãªãã£ããªã·ãŒã¯ã çµç¹ãŸãã¯ãã©ã«ãã®ã¬ãã« ã«äœæããçµç¹ããã©ã«ãããããžã§ã¯ãã®ããããã«çŽã¥ããŸããçŽã¥ãããšããã®é
äžã«ãããã¹ãŠã®ããã¯ãšã³ããµãŒãã¹ã«ããªã·ãŒãé©çšãããŸãã察象ã¯ãã°ããŒãã«å€éšã¢ããªã±ãŒã·ã§ã³ããŒããã©ã³ãµãšãåŸæ¥ã®ïŒClassicïŒã¢ããªã±ãŒã·ã§ã³ããŒããã©ã³ãµã§ããçŽã¥ãæã«ãé©çšå¯Ÿè±¡ããé€å€ãããããžã§ã¯ããæå®ããããšãå¯èœã§ãã éå±€åã»ãã¥ãªãã£ããªã·ãŒã¯ Google Cloud Armor Enterprise ã®æ©èœã§ããéå±€åã»ãã¥ãªãã£ããªã·ãŒãé©çšããããããžã§ã¯ãã¯ãèªåçã« Google Cloud Armor Enterprise ã® PayGoïŒåŸé課éïŒã«ç»é²ãããŸãã®ã§ãè²»çšã«æ³šæãå¿
èŠã§ãã åè : Hierarchical security policies overview DDoS 察ç DDoS ä¿è·æ©èœ Cloud Armor ã«ã¯ DDoS ä¿è·æ©èœ ãåãã£ãŠããŸããStandard ãã£ã¢ãš Enterprise ãã£ã¢ã®äž¡æ¹ã§ DDoS å¯Ÿçæ©èœãå©çšå¯èœã§ãããEnterprise ãã£ã¢ã§ã¯ããä¿è·ç¯å²ãåºããªãããŸã Adaptive ProtectionïŒé©å¿åä¿è·ïŒãªã©ã®æ©èœãæäŸãããŸãã åãã£ã¢ã® DDoS 察çã®ç¯å²ã¯ä»¥äžã®ãšããã§ãã Standard Enterprise ã»External Application Load Balancer ã»External proxy Network Load Balancer ã»External Application Load Balancer ã»External proxy Network Load Balancer ã»External passthrough Network Load Balancer ã»Protocol forwarding ã»Public IP addresses (VMs) åè : Cloud Armor Enterprise ã®æŠèŠ DDoS 察å¿ãµããŒã Cloud Armor Enterprise ã®å¹Žéãµãã¹ã¯ãªãã·ã§ã³ãžã®ç»é²ã«å ããGoogle Cloud ã«ã¹ã¿ããŒã±ã¢ã®ãã¬ãã¢ã ã«ãç»é²ããŠããå Žåã DDoS 察å¿ãµããŒã ïŒDDoS response supportïŒãå©çšããããšãã§ããŸãã DDoS 察å¿ãµããŒãã§ã¯ Google ã® DDoS 察çããŒã ãšé£çµ¡ãåããæ¯æŽãåããããšãã§ããŸãã åè : DDoS 察å¿ãµããŒã DDoS è«æ±ä¿è· Cloud Armor Enterprise ã®å¹Žéãµãã¹ã¯ãªãã·ã§ã³ãžç»é²ããŠããå Žåã DDoS è«æ±ä¿è· ïŒDDoS bill protectionïŒãåããããšãã§ããŸãã äžãäžã Web ã¢ããªã±ãŒã·ã§ã³ã DDoS æ»æãåããŠããŸããå€å€§ãªãã©ãã£ãã¯ãçºçããŠããŸã£ã圱é¿ã§ Cloud Load BalancingãGoogle Cloud Armorããããã¯ãŒã¯äžããã©ãã£ãã¯ãªã©ã«å€§éã®èª²éãçºçããŠããŸã£ãå Žåã Google ã«ç³è«ããããšã§è©²åœã®å©çšæéã«å
åœã§ããã¯ã¬ãžãããåããããå ŽåããããŸãã 詳现ã¯ä»¥äžã確èªããŠãã ããã åè : DDoS è«æ±å¯Ÿç Adaptive ProtectionïŒé©å¿åä¿è·ïŒ Adaptive Protection ãšã¯ Adaptive Protection ïŒé©å¿åä¿è·ïŒãšã¯ãHTTP Flood ãªã©ã®ã¬ã€ã€ 7 ã® DDoS æ»æãšæãããæªããæåãæ€ç¥ããæ©æ¢°åŠç¿ã¢ãã«ã«ãã£ãŠã¢ã©ãŒããåºããããé²åŸ¡ã®ããã®ã·ã°ããã£ãèªåçæããæ©èœã§ãã Adaptive Protection ã®ãã«æ©èœãå©çšããããã«ã¯ Cloud Armor Enterprise ã«ç»é²ããå¿
èŠããããŸããäžæ¹ã® Standard ã ãšãã¢ã©ãŒãã®äžéšïŒåºæ¬ã¢ã©ãŒãïŒã®ã¿ãåãåãããšãã§ããŸããåºæ¬ã¢ã©ãŒãã«ã¯ãæ»æã·ã°ããã£ãæšå¥šã«ãŒã«ãå«ãŸããŸããã Adaptive Protection ã¯ã»ãã¥ãªãã£ããªã·ãŒåäœã§æå¹åã§ããŸãã æå¹ååŸãæ©æ¢°åŠç¿ã«ãã£ãŠããŒã¹ã©ã€ã³ã確ç«ãããã¢ã©ãŒãçæãã§ããããã«ãªããŸã§æäœã§ã 1 æéã®ãã¬ãŒãã³ã°æéãå¿
èŠãšãããŠããŸãã åè : Google Cloud Armor é©å¿åä¿è·ã®æŠèŠ ã¢ã©ãŒã Adaptive Protection ã§ã¯ãäžå®ã®åŠç¿æéäžã«ãã©ãã£ãã¯ãã¿ãŒã³ãåŠç¿ãããŸããåŠç¿åŸã«é«é »åºŠãŸãã¯å€§å®¹éã®ç°åžžãã©ãã£ãã¯ãæ€åºããããšã Cloud Logging ã«ã¢ã©ãŒããçæãããããã«ãªããŸãã ã¢ã©ãŒãã«ã¯ ä¿¡é ŒåºŠã¬ãã« , æ»æã·ã°ãã㣠, æšå¥šã«ãŒã« , ããŒã¹ã©ã€ã³ã®ãã¡åœ±é¿ãåããå²åã®äºæž¬å€ ãå«ãŸããŸãã ä¿¡é ŒåºŠã¬ãã« ãšã¯ãæ©æ¢°åŠç¿ã¢ãã«ãäºæž¬ããçµæã®ç¢ºãããã (確çã 0 ã 1 ã®æ°å€) ã§ãã ããŒã¹ã©ã€ã³ã®ãã¡åœ±é¿ãåããå²åã®äºæž¬å€ ãšã¯ãèªåçæãããã«ãŒã«ãå®éã«é©çšãããå Žåã«ããŒã¹ã©ã€ã³ã®ãã¡ã©ããããã®å²åã®ãã©ãã£ãã¯ã圱é¿ãåãããããšããäºæž¬å€ã§ãã èªåçæã«ãŒã«ã®é©çš èªåçæã«ãŒã«ãé©çšããã«ã¯ä»¥äžã® 2 ã€ã®æ¹æ³ããããŸãã Cloud Logging ã«åºåãããã¢ã©ãŒãã«ã«ãŒã«åãåºåãããã®ã§ãããã䜿ã£ãŠã»ãã¥ãªãã£ããªã·ãŒã«ã«ãŒã«ãèšè¿°ããïŒCEL ã®èšè¿°ïŒ ã³ã³ãœãŒã«ç»é¢ã® Adaptive Protection ããã·ã¥ããŒããã GUI ã§é©çšããïŒèªåé©çšïŒ ãã®ããã«ç°¡åã«ã«ãŒã«ãé©çšããããšãã§ããŸãããå®éã«ã¯ãã¬ãã¥ãŒã¢ãŒãã§è©Šé転ããããšãæšå¥šãããŸãããã¬ãã¥ãŒæéãèšããã«å®çšŒåããããšãæ£ãããã©ãã£ãã¯ã«ãŸã§äºæ³å€ã®åœ±é¿ãåºãïŒåœéœæ§ïŒå¯èœæ§ãããããã§ãã åè : æšå¥šã«ãŒã«ã®ããã〠åè : æšå¥šã«ãŒã«ãèªåã§ãããã€ãã DDoS æ»æã®å¯èŠå Cloud Armor ã® Enterprise ãã£ã¢ã«ç»é²ãããšãCloud Logging ãš Cloud Monitoring ã䜿ããDDoS æ»æã®ç¶æ³ãå¯èŠåããããšãã§ããŸãã éåžžã§ããšãCloud Armor ã® DDoS ä¿è·ã¯ã»ãã¥ãªãã£ããªã·ãŒé©çšåã«è¡ãããŠããŸããããDDoS æ»æã®ç¶æ³ã¯ãã°ãã¡ããªã¯ã¹ã«æ®ããŸãããããã Enterprise ãã£ã¢ã«ç»é²ããŠãããšãGlobal external Application Load balancers ã«éããCloud Logging ãã°ãš Cloud Monitoring ã¡ããªã¯ã¹ã«ãã㊠DDoS ä¿è·æ©èœã«ãããããã¯ããããã©ãã£ãã¯ã確èªããããšãã§ããŸãã åè : DDoS æ»æã®å¯èŠæ§ãã¬ã¡ããªãŒã«ã¢ã¯ã»ã¹ãã ã¬ãŒãå¶é Cloud Armor ã«ã¯ ã¬ãŒãå¶éæ©èœ ããããŸãããã®æ©èœã§ã¯ãå°æ°ã®ã¯ã©ã€ã¢ã³ãããã®å€§éã¢ã¯ã»ã¹ãæ€ç¥ããŠã ã¹ãããã« ïŒã¢ã¯ã»ã¹æ°ã®äžéïŒãããããããã®ã¯ã©ã€ã¢ã³ãã Ban ïŒçŠæ¢ïŒããããšãã§ããŸãã äŸãã°ã 20 åéã§ 2000 ãªã¯ãšã¹ã ãšããäžéãã«ãŒã«ã«èšå®ãããããè¶
ããå Žåã¯ã¢ã¯ã»ã¹æ°ãå¶éãããããããã¯ãã®ã¯ã©ã€ã¢ã³ããæå®ããç§æ°ã®éãã¢ã¯ã»ã¹çŠæ¢ã«ããããšãã§ããŸãã ãIP ã¢ãã¬ã¹ããHTTP ãããããCookieãããªã¯ãšã¹ãã®ãã¹ããªã©ã®å±æ§ã®ãã¡ãã1ã3åãŸã§ãçµã¿åãããŠããããã®ããŒãäžèŽãããªã¯ãšã¹ããåç®ããŠã¬ãŒãå¶éããããããšãã§ããŸãã ã«ãŒã«ã®äœææ¹æ³çã¯ä»¥äžããã¥ã¡ã³ããåç
§ããŠãã ããã åè : ã¬ãŒãå¶éã®æŠèŠ åè : ã¬ãŒãå¶éã«ãŒã«ã®æ§æ Bot 管ç Cloud Armor ã§ã¯ã reCAPTCHA Enterprise ãšã®çµ±åã«ãããbot 察çãå¯èœã§ãã ãã©ãã£ãã¯ã reCAPTCHA ã®ç¢ºèªç»é¢ïŒ ç§ã¯ããããã§ã¯ãããŸãã ãªã©ïŒãžãªãã€ã¬ã¯ããããªã©ã㊠bot ããã®ã¢ã¯ã»ã¹ãæåŠããããšãã§ããŸãã ã¢ããªã±ãŒã·ã§ã³ã®ããã³ããšã³ãã« Javascript ã§ reCAPTCHA ã®ã³ãŒããåã蟌ãããšã§ãã¢ããªãžã®ãªã¯ãšã¹ãã«ããŒã¯ã³ãåã蟌ã¿ãCloud Armor ããã®ããŒã¯ã³ããã§ãã¯ããŠãªã¹ã¯è©äŸ¡ãè¡ããããªã¯ã·ã§ã³ã¬ã¹è©äŸ¡ããšåŒã°ããææ³ãå®è£
å¯èœã§ãã 詳现ã¯ã以äžãåç
§ããŠãã ããã åè : Google Cloud Armor bot 管çã®æŠèŠ ãªã reCAPTCHA Enterprise 㯠Cloud Armor ãšã¯å¥ãµãŒãã¹ã§ãããå¥éè²»çšãçºçããããšã«çæããŠãã ããã åè : reCAPTCHA ã®æŠèŠ åè : reCAPTCHA ã®æé éçšã»ãã®ã³ã° WAF ã®éçšäœæ¥ Cloud Armor ã«éããã WAF 補åã«ã¯éçšãå¿
èŠã§ããäŸãšããŠã以äžã®ãããªäœæ¥ãçºçããŸãã 誀æ€ç¥ïŒåœéœæ§ïŒãžã®å¯Ÿå¿ æ°ãã«èŠã€ãã£ãè匱æ§ãžã®å¯Ÿå¿ 誀æ€ç¥ ïŒ åœéœæ§ ïŒãžã®å¯Ÿå¿ãšã¯ãWeb ã¢ããªã±ãŒã·ã§ã³ã®ä»æ§å€æŽããã«ãŒã«ã®ã·ã°ããã£ã®æŽæ°çããã£ãããšããŠãæ£åœãªãã©ãã£ãã¯ãäžæ£ã¢ã¯ã»ã¹ãšã㊠WAF ã«ãããã¯ãããŠããŸããããªãšãã«ãæç€ºçã«ãã©ãã£ãã¯ãèš±å¯ãããã誀æ€ç¥ããŠããã«ãŒã«ãç¡å¹åãããããäœæ¥ã§ãã ãã©ãã£ãã¯ããããã¯ãããå Žåã¯ãCloud Logging ã®ãã°ã確èªããŠãåå ãšãªã£ããã©ãã£ãã¯ãã·ã°ããã£ã確èªããŠå¯Ÿå¿ãæ€èšããŸãã åŸè
ã® æ°ãã«èŠã€ãã£ãè匱æ§ãžã®å¯Ÿå¿ ã§ã¯ãæ¥é ããè匱æ§ã«é¢ããæ
å ±åéãé©åã«è¡ããã«ãŒã«ã管çããŠãããŸããGoogle ã®äºåæ§æã«ãŒã«ã䜿çšããŠããã°ãåºæ¬çã«ã¯ã«ãŒã«ãèªåçã«æŽæ°ãããŠãããŸãããããããã¥ãŒã¹ãšãªããããªæ·±å»ãªè匱æ§ãçºçããçŽåŸã«ã¯ãæåã§ã«ãŒã«ã远å ããå¿
èŠæ§ãåºãŠãããããããŸããã äŸãšããŠ2021幎12æã«ã¯ãåºãå©çšãããŠãã Java çšã®ãã°åºåã©ã€ãã©ãªã§ãã log4j ã®è匱æ§ãèŠã€ãããå瀟ã¯å¯Ÿå¿ã«è¿œãããŸããããã®ãšãã«ã¯ Google ãæ°ããäºåæ§æã«ãŒã« cve-canary ãè¿
éã«éçºã»ã¢ããããŒãããããã察çãè¡ãããšãã§ããŸããã åè : Cloud Armor ã® WAF ã«ãŒã«ã§ Apache Log4j 2 ã®è匱æ§å¯Ÿç Cloud Armor ã®ãã°åºå Cloud Armor ã«ããæ€ç¥ã®ãã°ã確èªããããã«ã¯ã Cloud Load Balancing åŽã§ãã°ãæå¹å ããå¿
èŠãããç¹ã«æ³šæããŠãã ããã ããã©ã«ãã§ Cloud Armor èªäœã®ç£æ»ãã°ã¯åºåãããŸããããããããã«ã¯ã»ãã¥ãªãã£ããªã·ãŒã®èšå®å€æŽãªã©ç®¡ççãªãã°ãèšé²ãããã ãã§ããã©ãã£ãã¯ããããã¯ãããå Žåã®ãã°ãªã©ã¯ åºåãããŸãã ã å®éã®æ»æã«å¯Ÿãã察åŠãã誀æ€ç¥ïŒåœéœæ§ïŒå¯Ÿå¿ãªã©ãè¡ãããã«ãã WAF ã®ãã°åºåã¯å¿
é ãšèšã£ãŠããã§ãããã ããã«ã¯ããŒããã©ã³ãµãŒåŽã®ãã°ãæå¹åããå¿
èŠãããããšããããšãèŠããŠãããŸãããã åè : ãªã¯ãšã¹ã ãã®ã³ã°ã®äœ¿çš ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO å
èŠå¯å®ãšããçµæŽãæã€ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS èªå®è³æ Œããã³ Google Cloud èªå®è³æ Œã¯ãã¹ãŠååŸãXïŒæ§ TwitterïŒã§ã¯ Google Cloud ã Google Workspace ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
ããã«ã¡ã¯ã@norryã§ããèªåã¯ä¹å·ã¯çæ¬ãããã«ãªã¢ãŒãã§æ±äº¬æ¬ç€Ÿã®æ ªåŒäŒç€ŸG-genã«ãžã§ã€ã³ããŠããŸãã G-genã¯Google Cloudã®å°æ¥ãã³ããŒã§ããäºãããèªãã®å®ååäžã®çºGoogle Cloudã®èªå®è³æ ŒååŸã«åãçµãã§ããŸãã Googleã®èªå®è³æ Œã¯ KRYTERION ã§åéšå¯èœãªã®ã§ãããåœå
ã§ã¯ããŸã察å¿ããŠãã詊éšäŒå Žããªãä»åã¯çŠå²¡ã®è©ŠéšäŒå Žã§åéšããŸããã ãã®éã«åéšäŒå ŽåšèŸºã§å°ãè¿·ã£ãã®ã§ä¹å·ã§å¯äžã®äŒå Žã§ãã®ã§åéšããã人ã®åèã«ãªãã°å¹žãã§ããã¡ãªã¿ã«èªå®
ãããªã³ã©ã€ã³ã§ã®åéšãå¯èœãªã®ã§ããæ°å転æãå
ŒããŠä»åã¯äŒå Žã§åéšããŠããŸãã Google Cloudèªå®è³æ Œãšã¯ 詊éšäŒå Žãžã®ã¢ã¯ã»ã¹ Google Cloudèªå®è³æ Œãšã¯ Google Cloudã®èªå®è³æ Œãšã¯ Google Cloud ã®è·åããŒã¹ã®èªå®è³æ Œã¯ãGoogle Cloud ãã¯ãããžãŒã䜿çšããç¹å®ã®è·åã®éè¡èœåãè©äŸ¡ãããã®ã§ãã峿£ã«éçºãããæ¥çæšæºã®ææ³ã䜿çšããŠãåè·åã®ç¥èãã¹ãã«ãèœåã®è©äŸ¡ãè¡ãããŸããGoogle Cloud èªå®è³æ Œã¯ãå人ã®ãã£ãªã¢éçºã®ä¿é²ãšãé«ãã¹ãã«ãšå®è·µåãåããããŒã ã®æ§ç¯ã«åœ¹ç«ã¡ãŸãã ãšãããŸãã èªåã¯ä»å㯠Professional Cloud Architect 詊éšãåéšããŸãããAWSã§èšããšããã® Solutions Architect - Professionalã«ãããã§ãããããGoogle Cloudã®ãµãŒãã¹å
šè¬çãªå
容ãåãããŸãã Google Cloud èªå®è³æ Œã«ã€ããŠã¯ã以äžã®åœç€Ÿèšäºããåç
§ãã ããã blog.g-gen.co.jp 詊éšäŒå Žãžã®ã¢ã¯ã»ã¹ é»è»ã§è¡ãå Žåã¯å°äžéèµ€åé§
ã§äžè»ããŠãã ãããåŸæ©ïŒåã»ã©ã«ãªããŸãã 詊éšäŒå Žãžã¯15ååãžã®å
¥å Žã«ãªããŸãã®ã§äœè£ãæã£ãŠè©ŠéšäŒå Žã®è¿ããžè¡ããŸãããã 幞ãã«ãäŒå Žã®è¿ãã«ã¯ã«ãã§ãå«è¶åºã倿°ãããŸãã®ã§è©Šéšå匷ã®ä»äžãã«æã£ãŠããã§ãã æéã«ãªããŸãããäŒå Žãžåããã®ã§ãããã¡ãã®å»ºç©ãå°ãè€éã§å°å³ã§æžããŸããšãã®å Žæã«ãªããŸãã èªåã¯ééã£ãŠãã®åšèŸºãã°ã«ã°ã«ããŠããŸããŸããã äžã®åçã®ã©ãŒã¡ã³å±ããããå·Šæ ãããå
¥ãå£ã§ãã å
¥ãå£å
¥ã£ãŠãå·ŠåŽãã®ãšã¬ããŒã¿ãŒã§12FãŸã§äžãã£ãŠãã ããããããééã£ãŠå³åŽã«ä¹ããš12Fã§ããã£ãšé åãããäºã«ãªããŸãã ãšã¬ããŒã¿ãŒãããã峿ã«äŒå Žå
¥å£ããããŸãã å
¥ã£ãŠåä»ãæžãŸã詊éšã§ããåºé¡æ°50åã®å¶éæé120åã§ããã60åã»ã©ã§çµäºãäœãšãåæ ŒããŸãããã¯ã©ãŠãç³»è³æ Œå
šè¬ãããªã®ã§ãããåæ Œããäžåæ Œãã®è¡šç€ºãåããã«ãããŠããããããŸãã ããŠè©Šéšãçµãã£ãããè€çŸã«èŠçå±±ãã«ãŒã倧çŠãé£ã¹ãŸãããã â»ãåºã«æ®åœ±èš±å¯ãããã ããŠããŸã 倧çŠãé£ã¹ãåŸã¯è
¹ããªããšã瀌åãã«çŠå²¡çž£è·åœç¥ç€Ÿãž 以äžçŠå²¡åéšæ¥èšã§ãããçãããè¯ã詊éšã©ã€ããïŒ æž¡é å®£ä¹ (èšäºäžèЧ) ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš ããŒã¿åæåºç€ã®æ§ç¯ãã¯ã©ãŠã管çéçšããããã¯ãŒã¯ãå®åç¯å²ãGoogle Workspace æŽ»çšæšé²äžãGoogle Cloud èªå®è³æ Œã¯4è³æ Œä¿æ 鱿«ãã©ãã°ã©ãã¡ãŒã§ãèŠ³èæ€ç©ã塿 ¹æ€ç©ã«ããã£ãŠãŸãã
G-genã®ææã§ããGoogle CloudïŒæ§ç§° GCPïŒã®ãã«ãããŒãžãã®ããŒã¿ãŠã§ã¢ããŠã¹ã§ãã BigQuery ã«ã¯ãããã©ãŒãã³ã¹åäžãã³ã¹ãåæžã«åœããã ããŒãã£ã·ã§ã³ ãš ã¯ã©ã¹ã¿ãªã³ã° ãšããéèŠãªæŠå¿µããããŸããããããã®ä»çµã¿ã䜿ãåãã解説ããŠãããŸãã ããã©ãŒãã³ã¹ã®ããã®ããŒãã«èšèš ããŒãã£ã·ã§ã³ ããŒãã£ã·ã§ã³ãšã¯ äœ¿çšæ¹æ³ ããŒãã£ã·ã§ã³ãã£ã«ã¿èŠä»¶ ã¡ãªãã ããŒãã£ã·ã§ã³ã®åå²åºæº æéã®å åãèŸŒã¿æé æŽæ°ç¯å²ã®å ããŒãã£ã·ã§ã³ã®ç®¡ç ããŒãã£ã·ã§ã³ã®äžéãšæ³šæç¹ ã¯ã©ã¹ã¿ãªã³ã° ã¯ã©ã¹ã¿ãªã³ã°ãšã¯ äœ¿çšæ¹æ³ ã¯ã©ã¹ã¿åã«æå®ããå èªååã¯ã©ã¹ã¿ãªã³ã° ããŒãã£ã·ã§ã³ vs ã¯ã©ã¹ã¿ãªã³ã° ããŒãã£ã·ã§ã³ãšã¯ã©ã¹ã¿ãªã³ã°ã®éã ããŒãã£ã·ã§ã³ãšã¯ã©ã¹ã¿ãªã³ã°ã®äœ¿ãåããšäœµçš ããŒãã£ã·ã§ã³ã»ã¯ã©ã¹ã¿ãŒã®ã¬ã³ã¡ã³ããŒã·ã§ã³ åèæ
å ± ããã©ãŒãã³ã¹ã®ããã®ããŒãã«èšèš BigQuery ã«ãããŠãæé©ãªããã©ãŒãã³ã¹ãåºãããã®ããŒãã«èšèšãšããŠãæãéèŠãªã®ã ããŒãã£ã·ã§ãã³ã° ãš ã¯ã©ã¹ã¿ãªã³ã° ã§ãã äžè¬ç㪠RDBMSïŒãªã¬ãŒã·ã§ãã«ããŒã¿ããŒã¹ãããžã¡ã³ãã·ã¹ãã ïŒã§ã¯ãããŒãã«ã«å¯ŸããŠã€ã³ããã¯ã¹ãäœæããããšã§ãæ€çŽ¢ããã©ãŒãã³ã¹ãåäžãããŸããBigQuery ã«ã¯æ€çŽ¢ã€ã³ããã¯ã¹ïŒsearch indexïŒæ©èœããããã®ã®ãããã¯äž»ã«ç¹å®ã®æååãç¹å®ã®ãã£ãŒã«ãããé«éã«æ€çŽ¢ããããã«äœ¿çšããæ©èœã§ãããåºæ¬çã«ã¯åæãå¯èŠåã®ããã©ãŒãã³ã¹åäžã«å¯äžãããã®ã§ã¯ãããŸããã blog.g-gen.co.jp æ€çŽ¢ã€ã³ããã¯ã¹ã¯ãã·ã¹ãã ãã°ã®æ€çŽ¢ãã»ãã¥ãªãã£ç£æ»ãªã©ã®æååæ€çŽ¢ã®ããã©ãŒãã³ã¹ãåäžãããããã«äœ¿ããŸããäžæ¹ã§ãåœèšäºã§ç޹ä»ããããŒãã£ã·ã§ãã³ã°ãã¯ã©ã¹ã¿ãªã³ã°ã¯ãã¹ãã£ã³å¹çãé床ãã³ã¹ãããã©ãŒãã³ã¹ãåäžãããããã«æçšã§ãããã®ããå€ãã®æ©äŒã§ãããŒãã£ã·ã§ãã³ã°ãã¯ã©ã¹ã¿ãªã³ã°ã¯ãBigQuery ã®ããŒãã«èšèšã«ãããåºæ¬çãªèãã§ãããšãããŸãã ããŒãã£ã·ã§ã³ ããŒãã£ã·ã§ã³ãšã¯ ããŒãã£ã·ã§ã³ ãšã¯ã BigQuery ã®äžã€ã®ããŒãã«ããç¹å®ã®åã®å€ãåºæºã«ããŠå
éšçã«è€æ°ã®éšäœã«åå²ããæ©èœã§ããããã«ããã¯ãšãªæã«ã¹ãã£ã³ããç¯å²ãçããããã©ãŒãã³ã¹åäžãšã¹ãã£ã³æéã®ç¯çŽãã§ããŸãã åè : ããŒãã£ã·ã§ã³åå²ããŒãã«ã®æŠèŠ åå²åºæºãšããŠäœ¿ãåãããŒãã«äœææã«æå®ããããšã§ãããŒãã£ã·ã§ã³åå²ãããããŒãã«ãäœæããããšãã§ããŸãã1ã€ã®ããŒãã«ã«ã¯ãããŒãã£ã·ã§ã³åã¯1ã€ããæå®ã§ããŸããã ããŒãã£ã·ã§ã³ã§åå²ãããããŒãã« äœ¿çšæ¹æ³ ããŒãã«äœææ¹æ³ã¯ä»¥äžã®ããã¥ã¡ã³ãã®éãã§ãã åè : ããŒãã£ã·ã§ã³åå²ããŒãã«ã®äœæ äŸãšããŠã以äžã®ãã㪠DDL ã§ãããŒãã£ã·ã§ã³åå²ãããããŒãã«ãäœæããããšãã§ããŸãã CREATE TABLE mydataset.purchase_tran ( purchase_dt DATE , prod_id STRING, prod_name STRING, store_id INT64, store_name STRING ) PARTITION BY purchase_dt ãã®ããã«äœæãããããŒãã«ã§ä»¥äžã®ããã«ã¯ãšãªãå®è¡ãããšã BigQuery ã¯åœè©²ã®å€ãå«ãã ããŒãã£ã·ã§ã³ã ããã¹ãã£ã³ããŸãã SELECT * FROM mydataset.purchase_tran WHERE purchase_dt = " 2025-04-01 " ããŒãã£ã·ã§ã³ãã£ã«ã¿èŠä»¶ ããŒãã£ã·ã§ã³åå²ããŒãã«ã®äœææã«ã ããŒãã£ã·ã§ã³ãã£ã«ã¿èŠä»¶ ïŒPartition filter requirementsïŒãæå¹åããããšã§ãWHERE å¥ã§ããŒãã£ã·ã§ã³åãæå®ãããŠããªãã¯ãšãªãããšã©ãŒãšããŠæåŠããããšãã§ããŸãã ãããèšå®ããããšã§ãããŒãã«ã®å©çšè
ã¯ãããŒãã£ã·ã§ã³ã«ããã¹ãã£ã³ç¯å²ãæå®ããã¯ãšãªããæããããªããªããŸãã®ã§ãããŒãã«ã«å¯Ÿããäžçšæãªãã«ã¹ãã£ã³ãäºé²ããããšãã§ããŸãã ã¡ãªãã ããŒãã£ã·ã§ã³ãç¡ãå ŽåãBigQuery ã¯ããŒãã«å
šäœããã«ã¹ãã£ã³ããŸããããŒãã£ã·ã§ã³ã«ããç¯å²ã¹ãã£ã³ã¯ããã«ã¹ãã£ã³ã«æ¯ã¹ãŠå€§å¹
ã«ã¹ãã£ã³ç¯å²ãç¯çŽã§ããæéãšæéã®ç¯çŽãšãªããŸãã ãŸãåè¿°ã®ããŒãã£ã·ã§ã³ãã£ã«ã¿èŠä»¶ã䜿ãã°ããŠãŒã¶ãŒãå€§èŠæš¡ãªããŒãã«å
šäœã«å¯ŸããŠèª€ã£ãŠã¯ãšãªãå®è¡ããçã®ãè²»çšã®æ¥å¢ãé²ã广ããããŸãã ããŒãã£ã·ã§ã³ã®åå²åºæº æéã®å TIMESTAMP å ã DATE å ã DATETIME å ã®ããããã®åãããŒãã£ã·ã§ã³åãšããŠæå®å¯èœã§ãã TIMESTAMP åãš DATETIME åã§ã¯ãããŒãã£ã·ã§ã³ãæéåäœãæ¥åäœãæåäœã幎åäœã®ããããã§äœæã§ããŸãã DATE åã®å ŽåãããŒãã£ã·ã§ã³ã¯æ¥åäœãæåäœã幎åäœã§äœæã§ããŸãã ãããããåå²åäœãæå®ããªãå Žåãããã©ã«ãã¯æ¥åäœãšãªããŸãã 以äžã¯ãDDL ã®äŸã§ããDATE åã®åãããŒãã£ã·ã§ã³åã«æå®ãããšãããã©ã«ãã§ã¯æ¥åäœã§ã®åå²ã«ãªããŸããã以äžã®äŸã®ããã« DATE_TRUNC 颿°ã䜿ã£ãŠæåäœã§åãæšãŠãããšã§ãæåäœã®åå²ã«ãªããŸãã CREATE TABLE mydataset.newtable ( transaction_id INT64, transaction_date DATE ) PARTITION BY DATE_TRUNC(transaction_date, MONTH) OPTIONS ( require_partition_filter = TRUE ); åãèŸŒã¿æé åãèŸŒã¿æéãããŒãã£ã·ã§ã³åºæºãšããŠéžæãããšãBigQuery ãããŒã¿ãåã蟌ãã ã¿ã€ã ã¹ã¿ã³ãã«åºã¥ããŠããŒãã«ãåå²ãããŸãã åå²ç²åºŠã¯ãæéåäœãæ¥åäœãæåäœã幎åäœããéžæã§ããŸããããã©ã«ãã¯æ¥åäœã§ãã ããŒãã«äœææã«ã¯ã _PARTITIONTIME ãšããç䌌åïŒä»®æ³åïŒãããŒãã£ã·ã§ã³åãšããŠæå®ããŸãã 以äžã¯ãDDL ã®äŸã§ãã CREATE TABLE mydataset.newtable ( transaction_id INT64 ) PARTITION BY _PARTITIONDATE æŽæ°ç¯å²ã®å ããŒãã£ã·ã§ã³åå²ã®åºæºåãšããŠãINTEGER åã®åãæå®å¯èœã§ãããŸããã®å Žåãåå²ã®éå§å€ã»çµäºå€ãšåå²ã®ééãæå®ã§ããŸãã 以äžã¯ãDDL ã®äŸã§ãã CREATE TABLE mydataset.newtable ( customer_id INT64, date1 DATE ) PARTITION BY RANGE_BUCKET( customer_id, GENERATE_ARRAY( 0 , 100 , 10 ) ); ãã®äŸã§ã¯ customer_id åã§ããŒãã£ã·ã§ãã³ã°ããéå§å€ 0ãçµäºå€ 100ãéé 10 ãšããŠããŸãã ãã®ããã«èšå®ããå Žåãcustomer_id ã 0 ãã 9 ã®è¡ãæåã® ããŒãã£ã·ã§ã³ã«å
¥ãã10 ãã 19 ãæ¬¡ã®ããŒãã£ã·ã§ã³ã«å
¥ããŸãããã®åŠçã 99 ãŸã§ç¶ããŸãããã®ç¯å²å€ã®å€ã¯ã __UNPARTITIONED__ ãšããååã®ããŒãã£ã·ã§ã³ã«å
¥ããŸããcustomer_id ã NULL ã®è¡ã¯ã __NULL__ ãšããååã®ããŒãã£ã·ã§ã³ã«å
¥ããŸãã ããŒãã«ã«ã©ããªããŒãã£ã·ã§ã³ãååšããŠãããã¯ãããŒãã«ã®ã¡ã¿ããŒã¿ãã確èªã§ããŸãã åè : ããŒãã£ã·ã§ã³åå²ããŒãã«ã®ç®¡ç - ããŒãã£ã·ã§ã³ ã¡ã¿ããŒã¿ã®ååŸ ããŒãã£ã·ã§ã³ã®ç®¡ç æéåäœãŸãã¯åãèŸŒã¿æéã§åå²ããããŒãã«ã®å ŽåãããŒãã£ã·ã§ã³ã® æå¹æé ãèšå®ã§ããŸãã æå®ããæå¹æéãéãããããŒã¿ã¯èªåçã«åé€ãããŸãããã®ãšã BigQuery ã®ãŠãŒã¶ãŒã«å²ãåœãŠãããªãœãŒã¹ã¯æ¶è²»ãããŸãããæå¹æéãããŸã䜿ãããšã§ãããŠã¹ããŒãã³ã°çšã®ãžã§ãããŠãŒã¶ãŒãäœæããå¿
èŠããªããªããŸãã åè : ããŒãã£ã·ã§ã³åå²ããŒãã«ã®ç®¡ç - ããŒãã£ã·ã§ã³ã®æå¹æéãèšå®ãã ããã©ã«ãã®ããŒãã£ã·ã§ã³æå¹æéãããŒã¿ã»ããã§èšå®ã§ããã»ããããŒãã«åäœã§æå¹æéãèšå®ããããšãã§ããŸããããŒãã«ã§æå¹æéãèšå®ãããŠããå Žåã¯ãããŒãã«ã®æå¹æéãåªå
ãããŸãã ããŒãã£ã·ã§ã³ã®æå¹æéã¯ããŒãã«äœææã«æå®ããã»ããäœæåŸã«ã倿Žã§ããŸãã ããŒãã£ã·ã§ã³ã®äžéãšæ³šæç¹ 1ããŒãã«ãæãŠãããŒãã£ã·ã§ã³æ°ã«ã¯äžéãããã 1ããŒãã«ã«ã€ã10,000ããŒãã£ã·ã§ã³ãŸã§ ã§ããåŸæ¥ã¯4,000ãæå€§å€ã§ãããã2024幎5æ29æ¥ã®ã¢ããããŒãã§10,000ã«å€æŽãããŸããã ããã¯ãæéåäœã§ããã° 10,000 æé = çŽ416æ¥ = çŽ13ã¶æéã§ãããæ¥åäœã§ã®åå²ã§ããã° 10,000æ¥ = çŽ322ã¶æ = çŽ27幎ã§ãã ããŒãã£ã·ã§ã³æ°ã®äžéã«éãããšã ãžã§ãããšã©ãŒãšãªããŸã ãããŒãã£ã·ã§ã³ã®ããŒã¿ã®ããã¯ã¢ãããååŸããä»çµã¿ãçšæããããã§ãããŒãã£ã·ã§ã³ã«æå¹æéãèšããŠããŒã¿ãèªååé€ãããããã«ããçãéçšäžã®èæ
®ãæ€èšããå¿
èŠããããŸãã ãŸãã1 ã€ã®ãžã§ãã§å€æŽãããããŒãã£ã·ã§ã³ã®æ°ããã1 æ¥ã®åãèŸŒã¿æéããŒãã£ã·ã§ã³åå²ããŒãã«ãããã®ããŒãã£ã·ã§ã³ã®å€æŽåæ°ãã1 æ¥ã®åããŒãã£ã·ã§ã³åå²ããŒãã«ãããã®ããŒãã£ã·ã§ã³å€æŽæ°ããªã©ã«ãäžéããããŸãããããåŠçãããã«æµè§ŠããŠããªããã¯ãååæ³šæããå¿
èŠããããŸãã åè : å²ãåœãŠãšäžé - ããŒãã£ã·ã§ã³åå²ããŒã㫠以äžã¯ã10,001 åç®ã®ããŒãã£ã·ã§ã³ã远å ããããšããå Žåã®ãšã©ãŒã¡ãã»ãŒãžã§ãã Resources exceeded during query execution: Table my-project:my_dataset.my_table will have 10001 partitions when the job finishes, exceeding limit 10000. If partitions were recently expired, it may take some time to be reflected unless explicitly deleted. ããŒãã£ã·ã§ã³äžéãè¶
ããéã®ãšã©ãŒã¡ãã»ãŒãž ãŸãã1åã®ãžã§ãã§å€æŽå¯èœãªããŒãã£ã·ã§ã³æ°ã¯4,000ã§ãããããè¶
ãããããªã¯ãšãªãçºè¡ããå Žåã以äžã®ãããªã¡ãã»ãŒãžã衚瀺ãããŸãã Too many partitions produced by query, allowed 4000, query produces at least 10000 partitions ã¯ã©ã¹ã¿ãªã³ã° ã¯ã©ã¹ã¿ãªã³ã°ãšã¯ ã¯ã©ã¹ã¿ãªã³ã° ãšã¯ã BigQuery ã®ããŒãã«ã®ç¹å®ã®åã®å€ã«åºã¥ããŠããŒãã«ã®ããŒã¿ããœãŒãããå
éšçã«è¿ãäœçœ®ã«é
眮ãããããšã§ããã£ã«ã¿ãéèšã¯ãšãªãé«éåããæ©èœã§ãã ããŒãã«äœææã«ãåãã¯ã©ã¹ã¿ååãšããŠæå®ããŸãã ã¯ã©ã¹ã¿ãªã³ã°ãå©çšãããšãæå®ããåã®å€ã«åºã¥ããŠè¡ããœãŒããããããã WHERE å¥ã§ãã®åã«åºã¥ããŠãã£ã«ã¿ããã¯ãšãªãæããéãäžèŠãªããŒã¿ã®ã¹ãã£ã³ãã¹ãããããããšãã§ããŸãããŸããã¯ã©ã¹ã¿åããåã§ GROUP BY ããŠéèšããã¯ãšãªã®å Žåãè¡ããœãŒãããè¿ãäœçœ®ã«é
眮ãããŠããã®ã§ãããã©ãŒãã³ã¹ãåäžããŸãã åè : ã¯ã©ã¹ã¿åããŒãã«ã®æŠèŠ ã¯ã©ã¹ã¿ã¯ ããŒãã£ã·ã§ã³ãšäœµçšãã ããšãå¯èœã§ããã¯ã©ã¹ã¿ãªã³ã°ãšããŒãã£ã·ã§ãã³ã°ã䜵çšãããšãããŒã¿ã¯ããŒãã£ã·ã§ã³åå²ãããåŸã«ãã¯ã©ã¹ã¿åãããŸãã ãŸãã¯ã©ã¹ã¿ååã¯ã1ã€ã®ããŒãã«ã§è€æ°ïŒæå€§ 4 åãŸã§ïŒæå®å¯èœã§ããè€æ°æå®ããå Žåãæå®ã®é çªãéèŠã«ãªããŸãããŸãæåã«æå®ããåã§è¡ããœãŒããããæ¬¡ã«ãã®äžã§2çªãã«æå®ããåã§ãœãŒããæ¬¡ã«3çªç®... ãšããããã«ãé çªã«ãœãŒããããŸãã ã¯ã©ã¹ã¿åãããããŒãã« äœ¿çšæ¹æ³ ã¯ã©ã¹ã¿ãªã³ã°ãããããŒãã«ãäœæããæ¹æ³ã¯ã以äžã®ããã¥ã¡ã³ãã®ãšããã§ãã åè : ã¯ã©ã¹ã¿åããŒãã«ã®äœæãšäœ¿çš äŸãšããŠä»¥äžã®ãã㪠DDL ã§ãã¯ã©ã¹ã¿ãªã³ã°ãããããŒãã«ãäœæã§ããŸããäŸã§ã¯ãããŒãã£ã·ã§ãã³ã°ã䜵çšããŠããŸãã CREATE TABLE mydataset.purchase_tran_cls ( purchase_dt DATE , prod_id STRING, prod_name STRING, store_id INT64, store_name STRING ) PARTITION BY purchase_dt CLUSTER BY prod_id ãŸããæ¢åã®ããŒãã«ãã¯ã©ã¹ã¿ãªã³ã°ããããåã®æå®ã倿Žããããšãå¯èœã§ãã åè : ã¯ã©ã¹ã¿åããŒãã«ã®äœæãšäœ¿çš - ã¯ã©ã¹ã¿ãªã³ã°ä»æ§ã倿Žãã ã¯ã©ã¹ã¿åã«æå®ããå ã¯ã©ã¹ã¿åã«æå®ããåã¯ãäžæã®å€ãå€ãå«ãïŒã«ãŒãã£ããªãã£ã®é«ãïŒåãæšå¥šãããŸãããã®ã»ããããœãŒãã«ããã¹ãã£ã³ç¯å²ã®ã¹ãããã®å¹æãé«ãæåŸ
ãããããã§ãã ãŸããçµã¿åãããŠäœ¿ãããããšã®å€ãè€æ°ã®åãã¯ã©ã¹ã¿åãããšå¹æãæåŸ
ã§ããŸããå
ã®èšè¿°ã®éããé çªã«æ³šæããŠãé »ç¹ã« WHERE ã§æå®ããã㯠GROUP BY ãããè€æ°åãã¯ã©ã¹ã¿ååãšããŠæå®ãããšã广ã倧ãããªããŸãã åè : BigQuery ç¹é: ã¹ãã¬ãŒãžã®æŠèŠ åè : BigQuery ã®ã¯ã©ã¹ã¿ãªã³ã°ã§ ã¡ã³ããã³ã¹ã®æéãçã㊠ã¯ãšãªãé«éå èªååã¯ã©ã¹ã¿ãªã³ã° ã¯ã©ã¹ã¿ãªã³ã°ã®ã¡ã³ããã³ã¹ã¯èªåã§è¡ãããŸããããŒã¿ãæ°èŠã§è¿œå ããããã倿Žããããããå Žåã§ããèªåã§åã¯ã©ã¹ã¿ãªã³ã°ãè¡ãããŸããäžè¬çãªããŒã¿ããŒã¹è£œåã§å¿
èŠãšããã VACUUM ãšãã£ãåŠçã¯äžèŠã§ãã åã¯ã©ã¹ã¿ãªã³ã°ã¯ãã¹ããããªã©ã®ãªãœãŒã¹ãæ¶è²»ãããããšããªããèªåçãã€ééçã«è¡ãããããããŠãŒã¶ãŒãæèããå¿
èŠã¯ãããŸããã ããŒãã£ã·ã§ã³ vs ã¯ã©ã¹ã¿ãªã³ã° ããŒãã£ã·ã§ã³ãšã¯ã©ã¹ã¿ãªã³ã°ã®éã ããŒãã£ã·ã§ã³ãšã¯ã©ã¹ã¿ãªã³ã°ã¯äœµçšã§ããŸãããã©ã®ãããªã±ãŒã¹ã§ã©ã¡ãã䜿ãã°ããã®ãããŸãã©ã®ãããªåãæå®ããã°ããã®ãã䜿ãåãã«è¿·ããšãããããŸãã ããŒãã£ã·ã§ã³ãšã¯ã©ã¹ã¿ãªã³ã°ã®éãã¯ã以äžã®ãããªç¹ã«ãããŸãã ããŒãã£ã·ã§ãã³ã°ã§ã¯å®éã®ã¯ãšãªå®è¡åã« ãã©ã€ã©ã³ ã§ã¹ãã£ã³éã®è©Šç®ãã§ããïŒæé詊ç®ãå¯èœïŒãäžæ¹ã®ã¯ã©ã¹ã¿ãªã³ã°ã§ã¯ã詊ç®ã¯ããŒãã«åäœãããŒãã£ã·ã§ã³åäœã§è¡ããããããã©ã€ã©ã³ã«åæ ããããå®éã®ã¹ãã£ã³éã¯èŠç©ããããå°ãããªãå¯èœæ§ããã åè : ã¯ãšãªã®å®è¡ - ãã©ã€ã©ã³ ããŒãã£ã·ã§ãã³ã°ã§ã¯æå¹æéã®èšå®ãã§ãã ããŒãã£ã·ã§ãã³ã°ã§ã¯åå²ç²åºŠïŒæéã»æ¥ã»æã»å¹Žã»æŽæ°ç¯å²ïŒã®éžæãã§ãã ããŒãã£ã·ã§ãã³ã°ã§ã¯1ã€ã®åããæå®ã§ããªããã¯ã©ã¹ã¿ãªã³ã°ã§ã¯4åãŸã§æå®ã§ãã ããŒãã£ã·ã§ãã³ã°ã§ã¯ç¹å®ã®åã®åããæå®ã§ããªãããã¯ã©ã¹ã¿ãªã³ã°ã«ã¯åã®å¶éã¯ãªã ããŒãã£ã·ã§ã³ãšã¯ã©ã¹ã¿ãªã³ã°ã®äœ¿ãåããšäœµçš ãŸãã¯ããŒãã£ã·ã§ã³ãé©çšã§ããåããããã©ãããæ€èšããŸãã以äžã®ãããªå ŽåãããŒãã£ã·ã§ã³ã®å©çšãæ€èšããŸãã æ¥ä»ãŸãã¯æé ã®åã®åãããã ãããã®åã§ãã£ã«ã¿ ããã¯ãšãªããã ããŒãã£ã·ã§ã³ã® æå¹æéèšå® ã䜿ã£ãŠããŒãã«ã®ã¡ã³ããã³ã¹ãããã ãã©ã€ã©ã³ ã§ã¹ãã£ã³éïŒè²»çšïŒã®èŠç©ãããè¡ããã 1åã®ããŒãã£ã·ã§ã³ãããã®ããŒã¿éã ããã 10 GB ä»¥äž ã«ãªãèŠèŸŒã¿ïŒããæªæºã®å Žåã¯ãªãŒããŒãããã«ãã éã«éå¹ç ã«ãªãå¯èœæ§ãããããã¯ã©ã¹ã¿ãªã³ã°ã®äœ¿çšãæ€èšããïŒ äžèšã®èгç¹ã§ããŒãã£ã·ã§ãã³ã°ãé©çšããåãæ€èšãããåŸã以äžã®ããã«ã¯ã©ã¹ã¿ãªã³ã°ãé©çšããåãæ€èšããŸãã ãããã£ã«ã¿å¯Ÿè±¡ã«ãªãåã ããããŒãã£ã·ã§ãã³ã°ã¯æ¢ã«å¥ã®åã«é©çšããŠãã ãããã£ã«ã¿å¯Ÿè±¡ã«ãªãåã ããããŒã¿ãµã€ãºã 10 GB æªæº ã«ãªãèŠèŸŒã¿ ãããã£ã«ã¿å¯Ÿè±¡ã«ãªãåã§ãããå€ã® ã«ãŒãã£ããªãã£ã倧ãã ïŒã¯ã©ã¹ã¿åã«ããé床æ¹åã®å¯èœæ§ããïŒ ãããã£ã«ã¿å¯Ÿè±¡ã«ãªãåã ããããŒãã£ã·ã§ã³ã䜿ããšåå²ç²åºŠãå°ãããªãããã1ããŒãã«ã® äžéã§ãã 10,000 ããŒãã£ã·ã§ã³ ãè¶
ããŠããŸã ããŒãã«å
ã®å€§éšåã®ããŒãã£ã·ã§ã³ãé »ç¹ã«ïŒããšãã°ãæ°åããšã«ïŒå€æŽããããªãã¬ãŒã·ã§ã³ãããããã®å ŽåãããŒãã£ã·ã§ã³ã¯é¿ããŠã¯ã©ã¹ã¿ãªã³ã°ãå©çšããã1æ¥ãããã®ããŒãã£ã·ã§ã³å€æŽæ°ã®äžéããããã çµåã«äœ¿ãããŠããåãã¯ã©ã¹ã¿åã«ãã£ãŠ çµåãé«éå ããå¯èœæ§ãããïŒããŒã¿ãåãã«ã©ã ããã¡ã€ã«ã«èšé²ããã¹ãããéã®ããŒã¿ç§»åãæŒãããããïŒ ãã ã 64 MB æªæºã®ããŒãã«ãããŒãã£ã·ã§ã³ã§ã¯ã¯ã©ã¹ã¿åã®ã¡ãªããã¯å°ãã ãµã€ãºãããçšåºŠå€§ããããŒãã«ã®å Žåã¯äžèšã®ããã«æ€èšããããŒãã£ã·ã§ã³ãšã¯ã©ã¹ã¿ãªã³ã°ã䜵çšããããšã§ãã¹ãã£ã³æãç¯æžããŠããã©ãŒãã³ã¹ãšã³ã¹ãå¹çãåäžãããããå¯èœæ§ããããŸãã 以äžã®å
¬åŒããã¥ã¡ã³ããåç
§ããŠãã ããã åè : ããŒãã£ã·ã§ã³åå²ããŒãã«ã®æŠèŠ - ã¯ã©ã¹ã¿åããŒãã«ãšããŒãã£ã·ã§ã³åå²ããŒãã«ãçµã¿åããã åè : ã¯ã©ã¹ã¿åããŒãã«ã®æŠèŠ - ã¯ã©ã¹ã¿ãªã³ã°ã䜿çšããå Žå åè : ã¯ã©ã¹ã¿åããŒãã«ã®æŠèŠ - ã¯ã©ã¹ã¿åããŒãã«ãšããŒãã£ã·ã§ã³åå²ããŒãã«ãçµã¿åããã ããŒãã£ã·ã§ã³ã»ã¯ã©ã¹ã¿ãŒã®ã¬ã³ã¡ã³ããŒã·ã§ã³ BigQuery ã«ã¯ãéå»ã®ã¯ãŒã¯ããŒãã«åºã¥ããŠããŒãã«ã®é©åãªããŒãã£ã·ã§ãã³ã°ãã¯ã©ã¹ã¿ãªã³ã°ãæšå¥šããæ©èœããããŸãã Recommender API ãéå»30æ¥éã®å®çžŸãæ©æ¢°åŠç¿ã§åæããããŒãã«ã®é©åãªããŒãã£ã·ã§ãã³ã°ã»ã¯ã©ã¹ã¿ãªã³ã°èšå®ãæç€ºããŸãã察象ããŒãã«ã察象åããŸãã©ã®ãããã®ã¹ãããæéãç¯çŽã§ãããã®èŠèŸŒã¿ã衚瀺ãããŸãã æšå¥šã®å¯Ÿè±¡ãšãªãããŒãã«ã¯ãããŒãã£ã·ã§ãã³ã°ç¡ãã»ã¯ã©ã¹ã¿ãªã³ã°ç¡ãããããŒãã£ã·ã§ãã³ã°æãã»ã¯ã©ã¹ã¿ãªã³ã°ç¡ããã®ããŒãã«ã§ãã äžæ¹ã§ 10 GB 以äžã®ããŒãã«ãæ¢ã«ããŒãã£ã·ã§ã³ãšã¯ã©ã¹ã¿ãŒãäž¡æ¹èšå®æžã¿ã®ããŒãã«ããŸãéå»30æ¥ä»¥å
ã«èªã¿åããããŠããªãããŒãã«ãªã©ã¯å¯Ÿè±¡å€ãšãªããŸãã æšå¥šã¯ã³ã³ãœãŒã«ãgcloudãREST API ã§ç¢ºèªå¯èœã§ããã³ã³ãœãŒã«ã§ã¯ãç»é¢å³äžã®é»çããŒã¯ãã確èªã§ããŸãã åè : ããŒãã£ã·ã§ã³ãšã¯ã©ã¹ã¿ã®æšå¥šäºé
ã管çãã åèæ
å ± 以äžã®å
¬åŒèšäºã§ã¯ãããŒãã£ã·ã§ã³ãã¯ã©ã¹ã¿ãªã³ã°ã®ä»çµã¿ã詳现ã«è§£èª¬ãããŠããŸãã®ã§ãæ¯éåèã«ããŠãã ããã åè : BigQuery ç¹é: ã¹ãã¬ãŒãžã®æŠèŠ åè : BigQuery ã®ã¯ã©ã¹ã¿ãªã³ã°ã§ ã¡ã³ããã³ã¹ã®æéãçã㊠ã¯ãšãªãé«éå ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO å
èŠå¯å®ãšããçµæŽãæã€ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS èªå®è³æ Œããã³ Google Cloud èªå®è³æ Œã¯ãã¹ãŠååŸãXïŒæ§ TwitterïŒã§ã¯ Google Cloud ã Google Workspace ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
ã¿ãªããããã«ã¡ã¯ãG-genã®éŽæšããšãããã€ã§ãã Google Workspaceã«ãããŠãªãŒããŒæš©éãšããã®ããåç¥ã§ããããïŒ ãã®åã®éãããã¡ã€ã«ããã©ã«ãã®ãªãŒããŒæš©éã«ãªãã®ã§ãããäŸãã°ãã®ãªãŒããŒãGoogle Workspaceããåé€ãããå Žåãªã©ããªãŒããŒãäœæããããã¥ã¡ã³ããäžç·ã«åé€ãããŠããŸããŸãããŸãããã¡ã€ã«ã®å€æŽå±¥æŽãªã©ãæ¶ããŠããŸãããšãããã®ã§ã確å®ã«å®æœããæ¹æ³ãšããŠã¯âãªãŒããŒæš©éãå¥ã®ãŠãŒã¶ãŒã«ç§»ãâãšããäœæ¥ãå¿
èŠã«ãªããŸãã äŸãã° éè·è
ãåºãå Žå çã«ã¯å¿
èŠã«ãªãã®ã§ããæŽ»çšãã ããã ããã§ã¯ãã®æ¹æ³ãç°¡åã«èª¬æããŠãããŸãã ãŠãŒã¶ãŒãæäœå¯èœãªå Žå(éè·åãªã©) äžæ¬ã§ãªãŒããŒæš©éãä»ãæ¿ããæ¹æ³(éè·åŸãªã©) ãŠãŒã¶ãŒãæäœå¯èœãªå Žå(éè·åãªã©) ãŸã ãŠãŒã¶ãŒãéè·ããŠãããããŸããã¡ã€ã«æ°ãå°ãªãå Žåã«ã¯ä»¥äžã®æé ã§ç°¡åã«å®æœå¯èœã§ãã ãã¡ã€ã«ãå³ã¯ãªãã¯ïŒå
±æã®ã¡ãã¥ãŒããç·šéè
ã®ãã«ããŠã³ã«ãŠ ãªãŒããŒæš©éã®è²æž¡ ã«ãŠæäœå¯èœã§ãã ãã¡ã€ã«åäœã®è²æž¡æ¹æ³ ãã ãã¡ããäžåäžå宿œããã®ã¯çžåœããã©ãããã§ããããéè·è
ãã§ãããšããããšã¯ãããããã¡ã€ã«ãå€ãååšãããšæããŸããã ã§ã¯æ¬¡é
ã«ãŠ äžæ¬ã§è²æž¡ããæ¹æ³ ãã詊ããã ããã äžæ¬ã§ãªãŒããŒæš©éãä»ãæ¿ããæ¹æ³(éè·åŸãªã©) ãã¡ãã®æ¹æ³ã¯ç®¡çè
ã®ã¿ãå®è¡ã§ããæ¹æ³ã«ãªãã®ã§ããã管çã¡ãã¥ãŒãã以äžã®ããã«éžæããããŸãã ãã¢ããªãïŒãGoogle WorkspaceãïŒããã©ã€ããšããã¥ã¡ã³ããïŒããªãŒããŒæš©éã®è²æž¡ã ãªãŒããŒæš©éã®è²æž¡ ããã§è²æž¡åã®ãŠãŒã¶ãŒãåã³è²æž¡åŸã®ãŠãŒã¶ãŒãå
¥åããããšã§ãç°¡åã«äžæ¬ã§ãªãŒããŒæš©éãè²æž¡ããããšãå¯èœã§ãã ä»åã¯äœè€ããããéŽæšããã«è²æž¡ããŠã¿ãŸãããã ãªãŒããŒæš©éã®è²æž¡æäœ(1) ãªãŒããŒæš©éã®è²æž¡æäœ(2) äžèšæäœã宿œãããšã以äžã®ç»é¢ã®ããã«ãäœè€ãããä¿æããŠãããªãŒããŒæš©éããéŽæšã«è²æž¡ãããŠããããšããããšããããããšæããŸãã è²æž¡åŸã®ãªãŒããŒæš©é ãã ãããã§æ³šæãªã®ãæ¬æäœãå¯èœãªã®ã¯ åãçµç¹å
ã§ç®¡çãããŠãããŠãŒã¶ãŒã®ã¿ ã«ãªããŸãã®ã§ãå¥çµç¹çã«å
±æããŠãããã®ã«é¢ããŠã¯ãªãŒããŒæš©éãäžæ¬ã§å€æŽããããšã¯ã§ããŸããã ãã¡ãã«é¢ããŠã¯åŒãç¶ãGoogleãµããŒããå©çšãã€ã€èª¿æ»ããŠãããããšæããŸãã ä»åã®èšäºã¯ã©ã€ãã«ãããŸã§ãšãããŠããã ãããšæããŸãã 远䌞ïŒ11æ29æ¥ã«Google Cloud - Professional Collaboration EngineerãååŸãããŠããã ããŸããããã®ä»¶ã«é¢ããŠã¯ãŸãäœãã®æ©äŒã§ã Professional Collaboration Engineer éŽæš éæ (èšäºäžèЧ) å·è¡åœ¹å¡ COO ããžãã¹æšé²éš éšé· åºæ¬ããªãã§ãå±ãäž»ã«ããžãã¹ã®ç«ã¡äžããä»çµã¿ã¥ãããå¥œã æ¥ã
ãåªåãæ¥ã
ãæ¥œããããšã倧äºã« ã Professional Cloud Architect / Professional Workspace Administratorã®ã¿ä¿æããŠããŸãããããã倱å¹ããŠããŸããããªäºæã
G-gen ã®ææã§ããGoogle Cloud (æ§ç§° GCP) ã®ã»ãã¥ãªãã£ãµãŒãã¹ã§ãã Cloud IDS ã«ã€ããŠè§£èª¬ããŠãããŸãã Cloud IDS ãšã¯ ã¢ãŒããã¯ãã£ æ§æå³ IDS ãšã³ããã€ã³ã Packet mirroring policy è
åšæ€ç¥ Application-ID ã·ã°ããã£ãŒã»ãã éèŠåºŠ ã·ã°ããã£ãŒã®æŽæ°é »åºŠ æé äžé ã»ããã¢ãã ã»ããã¢ããæé åäœç¢ºèª Cloud IDS Cloud IDS ãšã¯ Cloud IDS ãšã¯ Google Cloud (æ§ç§° GCP) ã®ã»ãã¥ãªãã£ãµãŒãã¹ã§ãããGoogle Cloud äžã®ãããã¯ãŒã¯ã«ããã䟵å
¥ããã«ãŠã§ã¢ã«ããéä¿¡ãã³ãã³ã&ã³ã³ãããŒã«éä¿¡çãæ€ç¥ããä»çµã¿ã§ãã IDS ãšã¯ Intrusion Detection System ã®ç¥èªã§ãã 䟵å
¥æ€ç¥ã·ã¹ãã ã®ããšã§ããäž»ã«ãããã¯ãŒã¯ãã©ãã£ãã¯ãæ€æ»ããããšã§æå®³ãªã¢ã¯ã»ã¹ãæ€ç¥ããããšãç®çãšããä»çµã¿ãæããŸãããã°ãã° IPS/IDS ã®ããã«äŸµå
¥ 鲿¢ ã·ã¹ãã ãšã»ããã§èªãããããšãå€ããã®ã§ãã ãã®ãã Cloud IDS ã§æäŸãããã®ã¯äŸµå
¥ã® æ€ç¥ã ã ã§ãã䟵å
¥ã é²ãæ©èœã¯ãããŸãã ã Cloud IDS ã¯ãVPC ãããã©ãã£ãã¯ããã©ãŒãªã³ã° (è€è£œ) ã Palo Alto Networks ã®è
åšæ€ç¥æè¡ ã§æ€æ»ããŸãã ãŸããå©çšæéãšåŠçããŒã¿éã«å¿ããŠæéãçºçããŸããå
šãã©ãã£ãã¯ãæ€æ»ããããšãããµããããåäœãªã€ã³ã¹ã¿ã³ã¹åäœã§æ€æ»å¯Ÿè±¡ãã±ãããæå®ããããšãå¯èœã§ãã åè : Cloud IDS ã®æŠèŠ ã¢ãŒããã¯ãã£ æ§æå³ Cloud IDS ã®ã¢ãŒããã¯ãã£ã¯ã以äžã®ããã«å³ç€ºãããŸãã Cloud IDS ã®ã¢ãŒããã¯ã㣠IDS ãšã³ããã€ã³ã Cloud IDS ã§ã¯ IDS ãšã³ããã€ã³ã ãšãããªãœãŒã¹ãäœæããŸãã IDS ãšã³ããã€ã³ãèªäœã¯ãŸãŒã³ãªãœãŒã¹ã§ããã1ã€äœãã°åããªãŒãžã§ã³å
ã®å
šãŸãŒã³ã®ãã©ãã£ãã¯ãæ€æ»ã§ããŸãã IDS ãšã³ããã€ã³ã㯠Private services access ã®æ©èœã䜿ã£ãŠããŠãŒã¶ã® VM ãš Google ã管çããæ€æ»çš VM ã®éãæ¥ç¶ããŸãã ãã©ã¡ãŒã¿ãšããŠä»¥äžãæã¡ãŸãã æå°ã®ã¢ã©ãŒã (ã¢ã©ãŒããšããŠæ±ãæå°ã®éèŠåºŠã Critical > High > Medium > Low > Informational) ãã©ãã£ãã¯ãã° (ON or OFF) ãã©ãã£ãã¯ãã° ã¯ãæ€ç¥ãããè
åšãšã¯å¥ã«ããã©ãŒãªã³ã°ãããã©ãã£ãã¯ã®ãã°ã JSON ã§çæããŸãã 倧éã®ãã°ã Cloud Logging ãžéä¿¡ããå©çšæéã倧ãããªãããšãæ³å®ãããŸãã®ã§ãç¹ã«å¿
èŠãªçç±ãããå Žåãé€ããŠããªããšããããšãæãŸããã§ãããã Packet mirroring policy IDS ãšã³ããã€ã³ããäœæãããš Packet mirroring policy ãã¢ã¿ããããå¿
èŠããããŸãã ãã®ããªã·ãŒããã©ã®ãã©ãã£ãã¯ãæ€æ»å¯Ÿè±¡ãšããããæ±ºå®ããŸãã Packet mirroring policy ã§ã¯ä»¥äžã®ãã©ã¡ãŒã¿ãæã£ãŠããŸãã ããªã·ãŒã®ç¶æ
(æå¹ or ç¡å¹) ãã©ãŒãªã³ã°ã®å¯Ÿè±¡ (ãµããããåäœ or ãããã¯ãŒã¯ã¿ã°åäœ or ã€ã³ã¹ã¿ã³ã¹åäœ) ãã©ãŒãªã³ã°ã®ãã£ã«ã¿ (ãããã³ã« / IP ã¬ã³ãž / ãã©ãã£ãã¯ã®æ¹å) è
åšæ€ç¥ Application-ID æ€æ»ããããããã¯ãŒã¯ãã©ãã£ãã¯ã¯ Palo Alto Networks ãã¡ã³ããã³ã¹ãã Application-ID (App-ID) ãšãã ID ã«ãããã©ã®ã¢ããªã®ãã©ãã£ãã¯ã§ãããã倿ãããŸãã è
åšæ€ç¥ãããéããã®ãã©ãã£ãã¯ãäœã®ã¢ããªã±ãŒã·ã§ã³ã«ããçæããããã®ãªã®ããããã® App-ID ã«ãã£ãŠåé¡ãããŸãã App-ID ã¯é±æ¬¡çšåºŠã®é »åºŠã§æŽæ°ãããŠããã Cloud IDS ã®ãŠãŒã¶ãŒãæèããªããšããèªåã§ã¢ããããŒããããŠãããŸãã ã·ã°ããã£ãŒã»ãã Cloud IDS 㯠ã·ã°ããã£ãŒ ã«ãããã©ãã£ãã¯ãæ€æ»ããŸãã äŸãšããŠã以äžã®ãããªæåãšãªããŸãã ãããã¡ãªãŒããŒãããŒãã³ãŒãã®äžæ£å®è¡ããã®ä»ã®è匱æ§ãçªããã¢ã¯ã»ã¹ãªã©ãæ€ç¥ ã¹ãã€ãŠã§ã¢ããã³ãã³ã & ã³ã³ãããŒã« (C&C) ãµãŒããžã®éä¿¡ãæ€ç¥ éèŠåºŠ æ€ç¥ãããè
åšã¯ 5段éã«åé¡ ãããŸãã IDS ãšã³ããã€ã³ãã®èšå®ã§ã©ã®ã¬ãã«ãŸã§ãæ€ç¥å¯Ÿè±¡ãšããããæå®ã§ããŸãã éèŠåºŠ 説æ Critical æ·±å»ã ãµãŒãã«æ·±å»ãªãã¡ãŒãžãäžãããã®ããŸããšã¯ã¹ããã€ãã³ãŒããåºãç¥ãããŠãããæ»æè
ãæ»æå¯Ÿè±¡ã«é¢ããŠèªèšŒæ
å ±ãæ·±ãæ
å ±ãå¿
èŠãšããªããªã©ãå±éºåºŠãé«ãè
åš High é«ãå±éºã§ã¯ãããã®ã®ããšã¯ã¹ããã€ãã®é£æåºŠãé«ããç¹æš©ææ Œã«ç¹ãããªããæ»æå¯Ÿè±¡ãšãªãåŸãç¯å²ãçããªã©ã®çç±ã§ "æ·±å»" ã«ã¯åé¡ãããªãè
åš Medium äžãã€ã³ãã¯ãã¯äžçšåºŠã§ãæ»æè
ãåãããŒã«ã«ãããã¯ãŒã¯ã«ããå¿
èŠããã£ãããæšæºçã§ãªãèšå®ã«å¯ŸããŠã®ã¿å±éºã§ãã£ãããéå®çãªå¯Ÿè±¡ã«å¯ŸããŠã®ã¿å±éºãªè
åš Low äœãã€ã³ãã¯ããå°ãããããŒã«ã«ãããã¯ãŒã¯ãããã¯ç©ççãªã¢ã¯ã»ã¹ãå¯èœãªå Žåã®ã¿å±éºãšãªããããªã©ã®çç±ã§ãèŠåã¬ãã«ãšãããè
åš Informational æ
å ±ã¬ãã«ãçŽã¡ã«è
åšã«ã¯ãªãåŸãªããæœåšçã«å±éºãªãçãããæåãªã© ã·ã°ããã£ãŒã®æŽæ°é »åºŠ App-ID ãã·ã°ããã£ãŒã¯ããŠãŒã¶ãŒãæèããå¿
èŠãªãã èªåçã«ã¢ããããŒã ãããŸãã Palo Alto Networks ã«ããã¢ããããŒãã¯ãæ¥æ¬¡ã§ Cloud IDS ã«åæ ãããŸããåæ ã®é
ãã¯ãæå€§ã§ã 48 æéãšãããŠããŸãã æé Cloud IDS ã®æé㯠ãšã³ããã€ã³ãã®ååšããæé åäœã®èª²é + åŠçãããã©ãã£ãã¯ã® GB åäœã®èª²é ã®2軞ãšãªã£ãŠããŸãã 2021/11æç¹ã§æéã¯ä»¥äžã®ããã«ãªã£ãŠããŸãã ãšã³ããã€ã³ãæéããã: $1.50 / hour åŠçããŒã¿éããã: $0.07 / GB ææ°ã®æéã¯å¿
ã以äžã®ããã¥ã¡ã³ããåç
§ããŠãã ããã åè: Pricing äžé Cloud IDS ã«ã¯ä»¥äžã®äžé (Quotas) ãèšå®ãããŠããŸãã ã³ã³ãœãŒã«ã® å²ãåœãŠ ç»é¢ããç·©åãªã¯ãšã¹ããéä¿¡ããããšãå¯èœã§ãã ãŸãŒã³ãããã® IDS ãšã³ããã€ã³ãæ°: ããã©ã«ã 10 åãããã® API ãªã¯ãšã¹ãæ°: ããã©ã«ã 1,200 ã»ããã¢ãã ã»ããã¢ããæé ã»ããã¢ããæ¹æ³ã¯ä»¥äžã®ããã¥ã¡ã³ããåèã«ããŠãã ããã cloud.google.com 倧ãŸããªæµãã¯ä»¥äžã®ãšããã§ãã IDS ãšã³ããã€ã³ãã®äœææã«åŸ
ã¡æéã 10 åã»ã©ãããŸãããå
šäœãšããŠã¯ 30 åçšåºŠã§æ§ç¯ããããšãã§ããŸãã Private service access ãäœæ (Cloud SQL ãªã©ã§æ¢åã®ãã®ãããã°å©çšå¯èœ) IDS ãšã³ããã€ã³ããäœæ Packet mirroring policy ãäœæ åäœç¢ºèª Google Compute Engine (GCE) ã®ã³ã³ãœãŒã«ã§å¯Ÿè±¡ VM ãéžæã ãªãã¶ãŒãããªã㣠ã¿ããéžæãããšå¯Ÿè±¡ VM ã® Cloud Monitoring ã¡ããªã¯ã¹ (ææš) ãèŠãããšãã§ããŸãã ãã®äžã« Packet Monitoring ãšããé
ç®ããããŸãã ãããèŠããšã察象 VM ãããã±ããã IDS ãšã³ããã€ã³ããéããŠãã©ãŒãªã³ã°ãããŠããããšãåãããŸãã ãã±ãããã©ãŒãªã³ã°ãæå¹åãããŠãã ãŸããè
åšã確å®ã«æ€ç¥ãããããšã確ãããããã以äžã®ã³ãã³ãã VM äžã§å®è¡ããŸãããã curl http://example.com/cgi-bin/../../../..//bin/cat%%20/etc/passwd ãã°ãããããš Cloud IDS ã®ã³ã³ãœãŒã«ç»é¢ã§æ€ç¥ã High ãšããŠè
åšãããŠããããšã衚瀺ãããŸãã 察象ã¢ã©ãŒããã¯ãªãã¯ãããšã詳现ã衚瀺ããããšãã§ããŸãã ãã¹ãã§å®è¡ãã curl ãæ€ç¥ããã åè: Troubleshooting ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãTwitter ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
ããã«ã¡ã¯æ ªåŒäŒç€ŸG-genã®æž¡éïŒ@norryïŒã§ãã Google Workspace (以äžãGWS)ãå©çšããã«ããã£ãŠçµç¹ã®ç«¯æ«ã«å¯ŸããŠã»ãã¥ãªãã£ãŒãã©ãæ
ä¿ããŠããã®ãïŒæ°ã«ãããã®ã§ã¯ãªãã§ããããããã®æã«GWSã ãã§ã©ã®çšåºŠç®¡çå¯èœãªã®ããæ°ã«ãªãéšåããšæããŸãã ä»åã¯å©çšäººæ°1ã300åãŸã§ã®Businessãšãã£ã·ã§ã³ã®åãã©ã³ã§ããããããã®ç®¡çãããããããã®ãã©ã³ãå¿
èŠããšå€æããæã«ã圹ã«ç«ãŠãã°å¹žãã§ãã åãã©ã³ã®ãããŸããªå
šäœæ¯èŒã¯ãã¡ããåèã«ããŠãã ãã blog.g-gen.co.jp ã©ã®ãã©ã³ããªã¹ã¹ã¡ã Business Starteråã³Business Standardããªã¹ã¹ã¡ãªã±ãŒã¹ Business Plusããªã¹ã¹ã¡ãªã±ãŒã¹ äžèšã ãã§ã¯èŠä»¶ãæºãããªãã±ãŒã¹ æ··åããã¡ãªããŒã¯ãŒã GWSäžã®ããã€ã¹ç®¡çã®ã³ã³ãœãŒã«ã§è¯ãç®ã«ããããŒã¯ãŒã Businessãšãã£ã·ã§ã³ãããã€ã¹ç®¡çã®åãã©ã³æ©èœæ¯èŒ æ©èœæ¯èŒã®è£è¶³ åºæ¬ã®ãšã³ããã€ã³ã管ç ã»ãã¥ãªãã£èšå® ããã€ã¹ã®ç®¡ç ã¢ããªã®ç®¡ç ããã€ã¹ã®è©³çް é«åºŠãªãšã³ããã€ã³ã管ç ã»ãã¥ãªãã£èšå® ããã€ã¹ã®ç®¡ç ã¢ããªã®ç®¡ç ããã€ã¹ã®è©³çް Google Workspaceãå°å
¥ãããªãæ ªåŒäŒç€ŸG-genã«ãçžè«ãã ããã ã©ã®ãã©ã³ããªã¹ã¹ã¡ã ããã€ã¹ç®¡çã®Businessãšãã£ã·ã§ã³ã§ã®åãã©ã³æ©èœæ¯èŒã¯ãã¡ãã®ããã«ãªããŸãã Business Starter Business Standard Business Plus åºæ¬ã®ãšã³ããã€ã³ã管ç â â â Android ã¢ããªã®ç®¡ç â é«åºŠãªãšã³ããã€ã³ã管ç â ãšã³ã¿ãŒãã©ã€ãº ãšã³ããã€ã³ã管ç ã¢ãã€ã«ã¢ããªãåå¥ã«é
åžãã â ããã€ã¹ç£æ»ãã° â 䜿ãããŠããªãäŒç€Ÿææããã€ã¹ã«é¢ããã¬ããŒã â äŒç€Ÿææã® Android ããã€ã¹ â äžèšãåèã«ããªããæåã«ãªã¹ã¹ã¡ã®ãã©ã³ãã玹ä»ããããŸãã Business Starter åã³ Business Standard ããªã¹ã¹ã¡ãªã±ãŒã¹ ããã€ã¹ç®¡çãããªãããŸãã¯æäœéã®ç®¡çã ããèããŠããæ¹ã«ããããã§ãã åŸè¿°ããŸããããã€ã¹ç®¡çã ããèæ
®ããå ŽåããBusiness StarterããBusiness Standardãã«ã¯å·®ç°ããããŸããã åºæ¬çãªã¢ãã€ã«ããã€ã¹ç®¡ç ãå©çšå¯èœã§ã äž»ãªæ©èœãšããŠãã¹ã³ãŒã䜿çšã®å¿
é åãããã€ã¹ã®äžèЧååŸãGoogle ã¢ã«ãŠã³ãã®ãªã¢ãŒã ã¯ã€ããAndroid ããã€ã¹ãžã®ã¢ããªã±ãŒã·ã§ã³ã®ãªã¢ãŒã ã€ã³ã¹ããŒã«ãå¯èœã§ãã åºæ¬çãªç®¡çã®ããã€ã¹æ
å ±ç»é¢ ãŸãããŠãŒã¶ãŒã WindowsãMacãChromeãLinux ããã€ã¹ã®ã©ã®ãã©ãŠã¶ã䜿çšã㊠GWSã«ãã°ã€ã³ããå Žåã§ãããã®ããã€ã¹ããšã³ããã€ã³ã管çã«èªåç»é²ãããŸãã çšåºŠãšããŠããŠãŒã¶ãŒã«å¶éããããããªããã©ããªã¢ãã€ã«ããã€ã¹ãã¢ã¯ã»ã¹ããã®ããªïŒããããç¥ãããšãåºæ¥ãã°OKã§ãããããã¡ããéžæãã ããã Business Plus ããªã¹ã¹ã¡ãªã±ãŒã¹ AndoroidãiOSã®BYODããã€ã¹ã«å¯ŸããŠãã现ããå¶åŸ¡ãWindows端æ«ã管ç察象ã«ãããå Žåã«Business Plusãã©ã³ãããããã§ãã Business Plusãã©ã³ã§ã¯ é«åºŠãªã¢ãã€ã«ããã€ã¹ç®¡ç ãå©çšå¯èœã«ãªããŸãã Android ã§ã¯ä»äºçšãããã¡ã€ã«ã§å人ããŒã¿ãä»äºçšããŒã¿ããåé¢ããŠããã©ã€ãã·ãŒãå®ãããšãã§ããŸããiOS ããã€ã¹ãš Android ããã€ã¹ã§ä»äºçšã¢ããªã®äœ¿çšãèš±å¯ã管çããäºãå¯èœã§ãã Windows ããã€ã¹ç®¡çã§ã¯GWSã¢ã«ãŠã³ãã§ã®Windowsãã°ã€ã³ãããã€ã¹ããã®ããŒã¿ã®ã¯ã€ãïŒæ¶å»ïŒãããã€ã¹ã®è©³çްæ
å ±ã衚瀺ãããäºãå¯èœãšãªã£ãŠããŸãã äžèšã ãã§ã¯èŠä»¶ãæºãããªãã±ãŒã¹ ããããèš±å¯ããã端æ«ä»¥å€ã¯GWSã«ã¢ã¯ã»ã¹ãããããªãå Žåã¯ä»ã®æ¹æ³ããæ€èšãã ããã äŒç€Ÿææä»¥å€ã®ç«¯æ«ããã¢ã¯ã»ã¹ããæã«ç®¡çè
ã®æ¿èªãå¿
é ã«ããå ŽåãEnterpriseãšãã£ã·ã§ã³ããã®ä»ã®MDMããŒã«ããæ€èšãã ããã åºæ¬çãé«åºŠãªã¢ãã€ã«ããã€ã¹ã§ã¯ãŠãŒã¶ãŒã¯ç«¯æ«ã§äžåºŠã¯GWSã«ãã°ã€ã³ããäºãåºæ¥ãŠããŸããŸããããã°ã€ã³åŸã«ç®¡çã³ã³ãœãŒã«ããç¶æ³ã®ç¢ºèªãã¯ã€ãã®æäœã¯å¯èœã§ãã æ··åããã¡ãªããŒã¯ãŒã GWSäžã®ããã€ã¹ç®¡çã®ã³ã³ãœãŒã«ã§è¯ãç®ã«ããããŒã¯ãŒã GWS管çã³ã³ãœãŒã« ãã©ã³ã«ãã£ãŠã¢ãã€ã«ããã€ã¹ã«ã¯ããªã·ãŒé©çšåºæ¥ãããšã³ããã€ã³ãã«ã¯åºæ¥ãªãã¿ãããªäºããããŸããæ€èšããŠãããã¡ã«ã©ã®çš®é¡ã®ç«¯æ«ãªã®ãåãããªããªã£ãŠããã®ã§ãã䜿ãã¯ãŒãã ããŸãšããŠãããŸãã ã¢ãã€ã«ããã€ã¹ AndroidãiOSãGoogle sync ããã€ã¹ïŒæè¬æºåž¯ç«¯æ«ïŒ ãšã³ããã€ã³ã 管çã³ã³ãœãŒã«äžã§ã¯ããœã³ã³(WindowsãMacãLinux)ãšã¹ããŒãããŒã ããã€ã¹ããã©ã³èª¬æã®æã«ã¯ç«¯æ«å
šè¬ãæãäºãå€ã Chromeããã€ã¹ Chromebook ãšãã®ä»ã® Chrome OS æèŒããã€ã¹ 管ç察象ãã©ãŠã¶ åOSïŒWindowsãMacãLinuxïŒããç»é²ããŒã¯ã³ã䜿çšããŠç»é²ããã Chromeãã©ãŠã¶ ã®ããš ãŸãGoogleãšã³ããã€ã³ã管çã®ããã€ã¹èŠä»¶ã¯ ãã¡ã ã«ãªããŸã Businessãšãã£ã·ã§ã³ãããã€ã¹ç®¡çã®åãã©ã³æ©èœæ¯èŒ æ©èœæ¯èŒã®è£è¶³ å
ã«ãªã¹ã¹ã¡ãã©ã³ã®çµè«ã¯ãäŒãããŸããããããå°ãæ©èœã«ã€ããŠè©³ããç¥ãããæ¹åãã«è£è¶³ããããŠããã ããŸãã å床ã«ãªããŸãããããã€ã¹ç®¡çã®Businessãšãã£ã·ã§ã³ã§ã®åãã©ã³æ©èœæ¯èŒã¯ãã¡ãã®ããã«ãªããŸãã Business Starter Business Standard Business Plus åºæ¬ã®ãšã³ããã€ã³ã管ç â â â Android ã¢ããªã®ç®¡ç â é«åºŠãªãšã³ããã€ã³ã管ç â ãšã³ã¿ãŒãã©ã€ãº ãšã³ããã€ã³ã管ç ã¢ãã€ã«ã¢ããªãåå¥ã«é
åžãã â ããã€ã¹ç£æ»ãã° â 䜿ãããŠããªãäŒç€Ÿææããã€ã¹ã«é¢ããã¬ããŒã â äŒç€Ÿææã® Android ããã€ã¹ â äºé
ããè£è¶³ããŠãããŸãã åºæ¬ã®ãšã³ããã€ã³ã管ç åºæ¬ã®ãšã³ããã€ã³ã管ç ã¯GWSã®Business Starterãã©ã³ããBusiness PlusãŸã§å
šãŠã®ãã©ã³ã§å©çšå¯èœã§ãã ãŸããåºæ¬ã®ãšã³ããã€ã³ã管çã«ã¯ä»¥äžã®æ©èœãå«ãŸããŸãã ã»ãã¥ãªãã£èšå® ã»ãã¥ãªãã£èšå®ã§ã¯ã¢ãã€ã«ããã€ã¹ã«å¯ŸããŠãã¹ã³ãŒãã®äœ¿çšãå¿
é åããWindowsPCã«ãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ããäºã«ãã£ãŠGWSã®ã¢ã«ãŠã³ãã§ãã°ã€ã³ããäºãå¯èœã«ãªããŸãã åºæ¬çãªãã¹ã³ãŒãã®é©çšïŒã¢ãã€ã«ïŒ Windows çš Google èªèšŒæ
å ±ãããã€ã ããã€ã¹ã®ç®¡ç ããã€ã¹ã®ç®¡çã§ã¯ã¢ãã€ã« ããã€ã¹ãããŠãŒã¶ãŒã®ã¢ã«ãŠã³ããã¯ã€ãããèªçµç¹ã®Chromeãå©çšããŠãããŠãŒã¶ãŒããªã¢ãŒãã§ãã°ã¢ãŠããããã€ã¹äžã®ããœã³ã³çãã©ã€ãã«é¢ããæ
å ±ã確èªãªã©ãå¯èœã§ãã åºæ¬çãªã¢ãã€ã« ããã€ã¹ç®¡ç ããœã³ã³ã®åºæ¬ç®¡ç ãšã³ããã€ã³ãã®ç¢ºèª ããœã³ã³çãã©ã€ã ããã€ã¹ã®ããã㯠ã¢ã«ãŠã³ãã®ãªã¢ãŒãã¯ã€ãïŒã¢ãã€ã«ïŒ ãªã¢ãŒã ãã°ã¢ãŠãïŒããœã³ã³ïŒ ã¢ããªã®ç®¡ç ã¢ããªã®ç®¡çã§ã¯ç®¡çè
ãèšå®ããã¢ããªããŠãŒã¶ãŒãèŠã€ããŠã€ã³ã¹ããŒã«ããäºãã§ããä»äºçšãŸãã¯åŠæ ¡çšãšããŠã¢ããªç®¡çã§ããŸãã ãã ãBusiness Starterã§ã¯ç®¡ç察象ã¢ããªãèªåã€ã³ã¹ããŒã«ããããããã¯ãããããæ©èœã¯ãããŸããã äžè¬å
¬éããã³éå®å
¬éã® Android ã¢ããªã®éžæ ããã€ã¹ã®è©³çް ããã€ã¹ã®è©³çްã§ã¯ã¢ãã€ã«ããã€ã¹ããšã³ããã€ã³ãã®åºæ¬çãªæ
å ±ïŒçš®é¡ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãããã€ã¹IDïŒã管ç察象ããã€ã¹ã®æ°ã®æšç§»ãªã©ã確èªåºæ¥ãŸãã åºæ¬ç㪠ã¢ãã€ã« ããã€ã¹ ãš ãšã³ããã€ã³ã ã®è©³çް ããã€ã¹ ã¬ããŒã äŒç€Ÿææã®ããœã³ã³ã®ã€ã³ãã³ã㪠é«åºŠãªãšã³ããã€ã³ã管ç é«åºŠãªãšã³ããã€ã³ã管ç ã¯Business Plus以äžã®ãã©ã³ã§å©çšå¯èœã§ãã é«åºŠãªãšã³ããã€ã³ã管çã§ã¯ç«¯æ«ã®ç£èŠã ãã§ãªãå¶åŸ¡ãããMobile Device Management (MDM)ã®èŠçŽ ãå ãã£ãŠããŸãã æ©èœãšããŠã¯ä»¥äžã®ããã«ãªããŸãã ã»ãã¥ãªãã£èšå® ã»ãã¥ãªãã£ãŒããªã·ãŒã«ããã«ã¡ã©ã®äœ¿çšèš±å¯ã®å¶åŸ¡ããAndroidã§BYODã宿œããå Žåã«äŒç€Ÿå©çšã®ã¢ããªã±ãŒã·ã§ã³ãå¥ãã ä»äºçšãããã¡ã€ã« ãå©çšå¯èœã§ãã æšæºåãšåŒ·ååã®ãã¹ã³ãŒãã®é©çš ã¢ãã€ã« ããã€ã¹ã®ã»ãã¥ãªã㣠ããªã·ãŒ Android ã®ä»äºçšãããã¡ã€ã« ãããã¯ãŒã¯ç®¡ç ïŒã¢ãã€ã«ïŒ ããã€ã¹ã®ç®¡ç 詳现管çã«ãããããã¯ç»é¢éç¥ãªã©ã®ã¢ãã€ã« ããã€ã¹æ©èœã®å¶éãããã€ã¹ã®æå·åã®åŒ·å¶ãAndroid ããã€ã¹ / iPhone / iPad äžã®ã¢ããªã®ç®¡çãããã€ã¹ããã®ããŒã¿ã¯ã€ããè¡ããŸãã iPhone / iPadã詳现管çããã«ã¯ Apple ããã·ã¥èšŒææž ãèšå®ããŸãããã ã¢ãã€ã«ã®è©³çŽ°ç®¡ç Windows ããã€ã¹ç®¡ç * ããã€ã¹ã®æ¿èª ããã€ã¹ã®ãªã¢ãŒãã¯ã€ã ã¢ããªã®ç®¡ç äžéšã® Android ã¢ããªã§ã¯ 管ç察象ã¢ã㪠ãšããŠèšå®ãä¿åããäºãå¯èœã§ãäŸãã°Wi-Fi ã«æ¥ç¶ãããŠãããšãã«ã®ã¿ããŒã¿ãåæãããã©ããã®å¶åŸ¡ãå¯èœã§ãã iOS ã¢ããªã®ç®¡ç éå®å
¬éã® Android ãŠã§ãã¢ã㪠ã¢ãã€ã«ã¢ããªãåå¥ã«é
åžãã â Android ã¢ããªã®èšå® ããã€ã¹ã®è©³çް ããã€ã¹ã®ããã€ã¹IDã ãã§ãªãã·ãªã¢ã«çªå·ãªã©ã®ååŸãªã©ãã现ããéšåã®æ
å ±ãååŸããäºãå¯èœã§ãã äŒç€Ÿææã®ã¢ãã€ã« ããã€ã¹ã®ã€ã³ãã³ã㪠ã¢ãã€ã« ããã€ã¹ã®è©³çްã¬ããŒã ããã€ã¹ç®¡çã«ã€ããŠã¯æ©èœãå€ããã©ã³ã«ãã£ãŠã®éããåããã«ããéšåããããããããŸãã ãããªæã¯åŒç€Ÿã«ãæ°è»œã«ã声ãããã ãããã Google Workspaceãå°å
¥ãããªãæ ªåŒäŒç€ŸG-genã«ãçžè«ãã ããã æ ªåŒäŒç€ŸG-genã§ã¯Google Workspace / Google CloudïŒGCPïŒã5%å²åŒã§ãæäŸããŠãããŸãã g-gen.co.jp ãŸããGoogle Workspace / Google CloudïŒGCPïŒ/ Chrome book ã®å°å
¥ããéçšãŸã§ã®ãæ¯æŽãè¡ã£ãŠããŸãã®ã§ãæ€èšã®éã«ã¯ãã²ã声ãããã ããã ãåãåããã¯ãã¡ããã docs.google.com
G-gen ã®ææã§ããGoogle Cloud (æ§ç§° GCP) ã®ãããŒãžã㪠DNS ãµãŒãã¹ã§ãã Cloud DNS ã§ãå
æ¥å°ã£ãããšãçºçããŸãããåãããšãèµ·ãããšãã«èª°ãã®å©ãã«ãªãããã顿«ãšè§£æ±ºæ³ãèšèŒããŸãã ããããã£ãããš ãšã©ãŒã¡ãã»ãŒãž è§£æ±ºæ¹æ³ 泚æç¹ ããããã£ãããš Google Cloud (æ§ç§° GCP) ã®ãã«ãããŒãžã㪠DNS ãµãŒãã¹ã§ãã Cloud DNS ã§ããããã¡ã€ã³ã管çããŠããŸããããã仮㫠example.com ãšããŸãã ããæ¥ããšããçç±ãããããªãã¯ãŸãŒã³ã§ãã example.com ãå¥ã® Google Cloud ãããžã§ã¯ãã® Cloud DNS ã«ç§»åããå¿
èŠæ§ãåºãŠããŸããã åœåèããç§»è¡æ¹æ³ã¯ã以äžã®éãã§ãã ç§»è¡å
ãããžã§ã¯ãã«ãããªãã¯ãŸãŒã³ example.com ãäœæãã ç§»è¡å
ãŸãŒã³ãã gcloud ã³ãã³ãã«ããã¬ã³ãŒãã®å
容ã ãšã¯ã¹ããŒã ããç§»è¡å
ãŸãŒã³ã« ã€ã³ããŒã ãã ãååãããã³ã åŽã«ãç§»è¡å
ãŸãŒã³ã®æ°ãã NS ã¬ã³ãŒããç»é²ãã ãšã©ãŒã¡ãã»ãŒãž ããããªãããå
ã»ã©ã®æé 1. ã§ç§»è¡å
ãããžã§ã¯ãã«ãããªãã¯ãŸãŒã³ãäœæããããšãããšããã以äžã®ãããªãšã©ãŒã¡ãã»ãŒãžãåºãŠããŸããŸããã http://www.google.com/webmasters/verification/ ã§ã(ãã¡ã€ã³å)ããã¡ã€ã³ïŒãŸãã¯èŠªïŒã®æææš©ã確èªããŠãããããäžåºŠã詊ããã ãã ãšã©ãŒã¡ãã»ãŒãž ãã®ãšã©ãŒã§ããã以äžã®ãããªæ¡ä»¶ã®ãšãã«åºãŠããŸãããã§ãã æ¢ã« Cloud DNS ããã㯠Google Domains ã§ãã¡ã€ã³åã® DNS ã管çããŠãã ãã®ç¶æ
ã§ Cloud DNS ã«åããã¡ã€ã³åã®ãããªãã¯ãŸãŒã³ãäœæãã ãã£ããè±èªçã®ãšã©ãŒã¡ãã»ãŒãžãåãããšã倱念ããŠããã®ã§ããã ãã®å
¬åŒããã¥ã¡ã³ã ã«èšèŒãããŠãã Verify ownership of the example.com domain (or a parent), and then try again. ã«è©²åœããŠããããã§ãã è§£æ±ºæ¹æ³ ãã®ãšã©ãŒã¡ãã»ãŒãžã¯ããã¡ã€ã³åã®æªçšã鲿¢ããããã« Google ã® DNS ã§æ¢ã«ç®¡çäžã®ãã¡ã€ã³åã«ã€ããŠããããªãã¯ãŸãŒã³ãäœæããããšãã« Google åŽããã¡ã€ã³ã®æææš©ã確èªããããã«åºãã¡ãã»ãŒãžã§ãã ãšã©ãŒã¡ãã»ãŒãžã«ãã http://www.google.com/webmasters/verification/ ã«ã¢ã¯ã»ã¹ã Google ã® ãŠã§ããã¹ã¿ãŒ ã»ã³ãã©ã« ã«ãŠãã¡ã€ã³åãç»é²ããŸãã ãŠã§ããã¹ã¿ãŒ ã»ã³ãã©ã« 㯠Google æ€çŽ¢çµæã®é äœã®ç£èŠã管çãæ¹åãªã©ã®ããã« Google ã«ãã£ãŠæäŸãããŠãã Google Search Console ã®äžéšã§ãã ãŠã§ããã¹ã¿ãŒã»ã³ãã©ã« ããããã£ã远å ãæŒäžããŠãã¡ã€ã³åã®ç»é²ãé²ããŸãã ãã¡ã€ã³ã®æææš©ã®ç¢ºèªã«ã¯ã Google ã®æå®ãã HTML ãã¡ã€ã«ãåãã¡ã€ã³ãæã€ãŠã§ããµã€ãã«ã¢ããããŒããããªã©ã®æ¹æ³ããããŸããããã¡ã€ã³ã®ãŸãŒã³ã« TXT ã¬ã³ãŒãã CNAME ã¬ã³ãŒãã远å ããæ¹æ³ãéžæã§ããŸãã ãã¡ã€ã³åã®æææš©ã®ç¢ºèª æç€ºããã TXT ã¬ã³ãŒããç§»è¡å
ãŸãŒã³ã«ç»é²ããŠæææš©ã確èªãããšããããã以éã¯ç§»è¡å
ãããžã§ã¯ãã«åããã¡ã€ã³åã§ãããªãã¯ãŸãŒã³ãäœæããããšãå¯èœã«ãªããç¡äº DNS ãŸãŒã³ãç§»è¡ããããšãã§ããŸããã æ³šæç¹ äžé£ã®äœæ¥ã¯ãåãäœæ¥è
ã® Google ã¢ã«ãŠã³ãã§å®æœããå¿
èŠããããŸãã ãã¡ã€ã³åã®æææš©ã®ç¢ºèªã¯ Google ã¢ã«ãŠã³ãã«çŽä»ããŠããããã§ãã®ã§ãæææš©ã確èªããã Google ã¢ã«ãŠã³ãã§ãŸãŒã³ã®äœæçãè¡ãå¿
èŠããããŸãã ææ å銬 (èšäºäžèЧ) å·è¡åœ¹å¡ CTO / ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš éšé· å
èŠå¯å®ãšããçµæŽãæã€çŸ IT ãšã³ãžãã¢ãã¯ã©ãŠã管çã»éçšããããã¯ãŒã¯ã«ç¥èŠãAWS 12è³æ ŒãGoogle Cloudèªå®è³æ Œ11è³æ ŒãTwitter ã§ã¯ Google Cloud ã AWS ã®ã¢ããããŒãæ
å ±ãã€ã¶ãããŠããŸãã Follow @y_sugi_it
ä»åã¯çãããåç¥Google Workspace(æ§G Suite)ã®ãªã¹ã¹ã¡ãã©ã³æ¯èŒã«ãªããŸãã å人ã§Gmailã¯äœ¿ã£ãŠããã©äŒç€ŸãããŒã ã§å©çšããäºã¯ç¡ããæ€èšããŠãããã©ã©ã®ãã©ã³ãéžã¹ã°ããã®ããªïŒBusinessãEnterpriseã£ãŠãããã©åãšãã£ã·ã§ã³ã®éãã£ãŠäœã ããïŒããããæ¹ãžãåèã«ãªãã°å¹žãã§ãã Google Workspace æŠèŠ ãšãã£ã·ã§ã³ Business ãš Enterprise ã®æ¯èŒ ã¢ã«ãŠã³ãæ°äžé äž»èŠãªæ©èœæ¯èŒ Business ãšãã£ã·ã§ã³å
ã®æ¯èŒ æ¯èŒè¡š Businessãã©ã³ã®éžã³æ¹ Business Starter ãéžæããã±ãŒã¹ Business Standard ãéžæããå Žå Business Plus ãéžæããå Žå Google Workspace ã®å°å
¥ æŠèŠ Google Workspace ã® å
¬åŒãµã€ã ã«ã¯ãããããåãæ¹ã«å¯Ÿå¿ããçç£æ§åäžãšã³ã©ãã¬ãŒã·ã§ã³ã®ããŒã«ãããšããããŸãåŸæ¥å¡ã®çç£æ§ = ããŒã x äŒç€Ÿã®æå = ã³ãã¥ãã±ãŒã·ã§ã³ + ã³ã©ãã¬ãŒã·ã§ã³ãšèšãæããäºãåºæ¥ãŸãã ãã®çµç¹ã®ã³ãã¥ãã±ãŒã·ã§ã³ãšã³ã©ãã¬ãŒã·ã§ã³ãäžæ¯ããä¿é²ããããŒã«ã Google Workspace ã§ãã Google Workspace ã®ç¹åŸŽãšããŠåããŒã«ãç¬ç«ããŠååšããã®ã§ã¯ç¡ããããŒã ã®åãæå€§åããçºã«åã
ã®ããŒã«ãå¯ã«é£æºããŠããäºã«ãããŸãã äŸãã°éåžžã¯ãã£ãããšããã¥ã¡ã³ãäœæã¯å¥ã
ã®äŒç€Ÿã®ããŒã«ãå©çšããŠããå Žåãããã§ããããGoogle Workspaceã§ã¯ãã£ããããããªäŒè°ãªã©ã§ã³ãã¥ãã±ãŒã·ã§ã³ãåããªããã·ãŒã ã¬ã¹ã«è³æäœæãããäºãå¯èœã§ãã G-gen 瀟ã¯ãå
šå¡ãã«ãªã¢ãŒãã§å€åããŠããŸããPC 端æ«ã¯ ChromebookãããŒã«ãšã㊠Google Workspace ã䜿ã£ãŠä»äºãããŠããŸãããªã¯ã«ãŒãã®é¢ã«ãããŠããããã£ãåãæ¹ãã¢ããŒã«åºæ¥ããšããã®ã¯äŒæ¥ã«ãšã£ãŠå€§ããªã¢ããã³ããŒãžã«ãªãã®ã§ã¯ãªãã§ããããã Google Workspace ã®è©³çްã¯ã以äžã®èšäºãåç
§ããŠãã ããã blog.g-gen.co.jp ãšãã£ã·ã§ã³ 以äžã¯ãå
¬åŒã®ãã©ã³ã»æéããŒãžã§ãã workspace.google.co.jp ãšãã£ã·ã§ã³ã倧ããåãããš Business ãš Enterprise ã«åãããŸããEnterprise ãšãã£ã·ã§ã³ã¯ Business ãšãã£ã·ã§ã³ã®äžäœãšãã£ã·ã§ã³ã§ãã Business ãš Enterprise ã®æ¯èŒ ã¢ã«ãŠã³ãæ°äžé ãŸã㯠Businessã®æäžäœãšãã£ã·ã§ã³ã§ãã Business Plus ãš Enterprise ãæ¯èŒããŠã¿ãŸãããŸãã¯äžçªåãããããç¹ãšããŠãã¢ã«ãŠã³ãæ°ã®äžéããããŸãã ã Business Plus Enterprise å©çšå¯èœäººæ° 300人ãŸã§ ç¡å¶é äžèšã§ã¯ Enterprise ãšãã£ã·ã§ã³ã¯ã²ãšæ¬ãã«ãªã£ãŠããŸãããå®éã«ã¯ Enterprise Essentials ã Enterprise Standard ãEnterprise Plus** ã«åãããŠããŸãã Google Workspace ãå©çšãã人æ°ã 300å以äžã§ãããEnterpriseãå©çš ããããšã«ãªããŸãã ãŸã300å以äžã®å Žåã§ããPC 端æ«ãã¹ããŒããã©ã³ã管çäžã«çœ®ããŠç£èŠãå¶éãããããå Žåã«ã Enterprise ãæ€èšå¯Ÿè±¡ã«ãªããŸãã äž»èŠãªæ©èœæ¯èŒ åèãšã㊠Business ãšãã£ã·ã§ã³ã®æäžäœãã©ã³ã§ãã Business Plus ãš Enterprise ã®åãã©ã³ã§ã®ãäž»ãªæ©èœæ¯èŒãèšèŒããŸãã 2011幎11æçŸåšã®æ
å ±ã§ãã®ã§ãææ°æ
å ±ã¯ä»¥äžã®å
¬åŒããã¥ã¡ã³ãããåç
§ãã ããã åè : Google Workspace ã®åãšãã£ã·ã§ã³ã®æ¯èŒ Business Plus Enterprise Essentials Enterprise Standard Enterprise Plus åºæ¬æ
å ± æé¡æéïŒ1ãŠãŒã¶ãŒãããâ»çšå¥ïŒ 2,040å ãåãåãã ãåãåãã ãåãåãã ãŠãŒã¶ãŒäžéæ° 300人 æå®ãªã æå®ãªã æå®ãªã ã¹ãã¬ãŒãžã®å®¹é 5 TB *5人以äžã®ãŠãŒã¶ãŒãå¿
èŠ ïŒ4人以äžã®å Žåã¯ïŒTBïŒ 1TB å¿
èŠã«å¿ããŠæ¡åŒµå¯èœ å¿
èŠã«å¿ããŠæ¡åŒµå¯èœ ã¡ãŒã« Gmail â â â IMAP ã¯ã©ã€ã¢ã³ããš POP ã¯ã©ã€ã¢ã³ã â â â Google Meet äŒè°ãããã®åå è
æ°ã®äžé 250 150 250 250 ãã¡ã€ã³å
ããã³ä¿¡é Œã§ãããã¡ã€ã³ã®ã©ã€ã ã¹ããªãŒãã³ã° 1äžäºº 10äžäºº Google Chat Chat ã§ã®ãã¡ã€ã«ã®å
±æã管çãã â â â Chat ãšãµãŒãããŒãã£è£œã¢ãŒã«ã€ã ãœãªã¥ãŒã·ã§ã³ãšã®é£æº â â Google ã°ã«ãŒã ã°ã«ãŒã ã¡ã³ããŒã粟æ»ãã â â ã°ã«ãŒã ã¡ã³ããŒãå¶éãã â â åçã°ã«ãŒãïŒã¡ã³ããŒã·ãããèªåçã«ç®¡çïŒ â â ãã¹ãããã°ã«ãŒãã®ã¡ã³ããŒã確èªïŒéæ¥çãªã¡ã³ããŒïŒ â â ã»ãã¥ãªãã£ãš ããŒã¿ä¿è· ä¿¡é Œã§ããå€éšãã¡ã€ã³ãšã®é£æº â â â ããŒã¿æå€±é²æ¢ïŒDLPïŒ â â ãŠãŒã¶ãŒãšããã€ã¹ã®ç¶æ³ã«åºã¥ãã¢ã¯ã»ã¹å¶åŸ¡ â â Google ãµãŒãã¹ã®ã»ãã·ã§ã³ç¶ç¶æéãèšå®ãã â â â Cloud Identity Premium â â ã»ãã¥ãªã㣠ã»ã³ã¿ãŒ: ã»ãã¥ãªã㣠ããã·ã¥ããŒã â â ã»ãã¥ãªã㣠ã»ã³ã¿ãŒ: ã»ãã¥ãªãã£èª¿æ»ããŒã« â â ã»ãã¥ãªã㣠ã»ã³ã¿ãŒ: ã»ãã¥ãªãã£ã®ç¶æ³ããŒãž â â Fundamental ããŒã¿ ãªãŒãžã§ã³ â â Enterprise ããŒã¿ ãªãŒãžã§ã³ â ã¯ã©ã€ã¢ã³ããµã€ãæå·åïŒããŒã¿çïŒ â ç§»è¡ãããã¯ã HCL Notes ããç§»è¡ãã â â â ã¬ããŒããšç£æ»ãã° ãã©ã€ãã®è©³çްãªç£æ»ãšã¬ããŒã â â â BigQuery ãžã®ã¬ããŒãã®ãšã¯ã¹ããŒã â â 管çã¢ã¯ãã£ããã£ã®ã¢ã¯ã»ã¹ã®éææ§ãã° â ãŠãŒã¶ãŒã«é¢ããã¯ãŒã¯ ã€ã³ãµã€ã ã¬ããŒã â ãµãŒãããŒãã£è£œ ã¢ããªãšã®é£æº ã»ãã¥ã¢ LDAP: LDAP ããŒã¹ã®ã¢ããªããµãŒãã¹ãæ¥ç¶ãã â â â ãã¹ã¯ãŒããä¿ç®¡ãããã¢ããªãžã®ã¢ã¯ã»ã¹ã管çãã â â ããã€ã¹ç®¡ç ã¢ãã€ã«ã¢ããªãåå¥ã«é
åžãã â â â ããã€ã¹ç£æ»ãã° â â â 䜿ãããŠããªãäŒç€Ÿææããã€ã¹ã«é¢ããã¬ããŒã â â â äŒç€Ÿææã® Android ããã€ã¹ â â â äŒç€Ÿææã® iOS ããã€ã¹ â â Windows ããã€ã¹ç®¡ç â â iOS ããŒã¿ã®ä¿è· â â ããã€ã¹ã®ãªã¢ãŒãã¯ã€ãïŒWindowsïŒ â â ã¢ãã€ã« ããã€ã¹ã®èšŒææž â â 管çã«ãŒã« â â ãã©ã€ã ããã¥ã¡ã³ããšãã£ã¿ ã³ãã¯ããã ã·ãŒã â â â çµç¹ã®ãã©ã³ãã£ã³ã°ïŒã«ã¹ã¿ã ãã³ãã¬ãŒãïŒ â â â Chrome ãã©ãŠã¶ã§ãã©ã€ãã®ãã¡ã€ã«åè£ã®äœ¿çšãèš±å¯ãã â åè¿°ã®ãšãã Business Plus ã§ãäž»èŠãªæ©èœã¯ãµããŒããããŠããŸãããã©ã€ãã¹ããªãŒãã³ã°ãããã€ã¹å¶åŸ¡ã管çãã¬ããŒãã£ã³ã°ãšèšã£ãæ©èœã¯å©çšåºæ¥ãŸããã ãŸã Enterprise Essentials ã¯ã300å以äžã§ Google Workspace ãå©çšãããããã¡ãŒã«ã·ã¹ãã ã¯ä»ã«æã£ãŠããããçŽã¡ã«ç§»è¡ããããšã¯é£ãããããŸãã¯ã³ãã¥ãã±ãŒã·ã§ã³ïŒGoogle ChatïŒãã³ã©ãã¬ãŒã·ã§ã³ïŒãã©ã€ããããã¥ã¡ã³ããšãã£ã¿ïŒã ãå©çšãããããšãã£ããŠãŒã¹ã±ãŒã¹ã§ããããã§ããHCL Notes ããã®ç§»è¡ãå«ãŸããŠããã®ã Enterprise ãªãã§ã¯ãšèšããã§ãããã Enterprise ã®ãšãã£ã·ã§ã³ã«é¢ããŠã¯æ€èšãã¹ãèŠä»¶ãå€ãããããã²åœç€ŸãŸã§ãçžè«ãã ããã g-gen.co.jp Business ãšãã£ã·ã§ã³å
ã®æ¯èŒ æ¯èŒè¡š 次㫠Business ã«åé¡ããã3ã€ã®ãšãã£ã·ã§ã³ Business Starter ã Business Standard ã Business Plus ãæ¯èŒããŸãã Business Starter Business Standard Business Plus åºæ¬æ
å ± æé¡æéïŒ1ãŠãŒã¶ãŒãããâ»çšå¥ïŒ 680å 1,360å 2,040å å©çšå¯èœäººæ° 1ã300å 1ã300å 1ã300å ã¹ãã¬ãŒãžå®¹é 30GB 2TB 5TB 24æé365æ¥ã®é»è©±ãµããŒã â â â ã³ã¢ãµãŒãã¹ Gmailãšã«ã¬ã³ã㌠â â â Cloud Searchã«ãããã¡ã€ã³å
æ€çŽ¢ â â Google Vault â Google Chat â â â ãã©ã€ããš ããã¥ã¡ã³ã ããã¥ã¡ã³ãã®äœæ â â â ããŒã åãå
±æãã©ã€ã â â â Google Meet äŒè°ãããã®åå è
æ°ã®äžé 100å 150å 250å äŒè°ã®é²ç»ãšãã©ã€ããžã®ä¿å â â ãã€ãº ãã£ã³ã»ã« â â ãã¬ã€ã¯ã¢ãŠã ã«ãŒã â â ã»ãã¥ãªãã£ãš ããŒã¿ä¿è· ä¿¡é Œã§ããå€éšãã¡ã€ã³ãšã®é£æº â â ããŒã¿ãªãŒãžã§ã³ã®éžæ â â ããã€ã¹ç®¡ç åºæ¬ã®ãšã³ããã€ã³ã管ç â â â é«åºŠãªãšã³ããã€ã³ã管ç â ã¢ãã€ã«ã¢ããªã®åå¥é
åž â Businessãã©ã³ã®éžã³æ¹ Business Starter ãéžæããã±ãŒã¹ ãŸãã¯å°äººæ°ïŒ10å以äžïŒã§ã³ã¹ããæã㊠Google Workspace ã䜿ã£ãåãæ¹ã«ãã£ã¬ã³ãžãããå Žåã«ãªã¹ã¹ã¡ããŸãã äž»èŠãªæ©èœã§ããããã¥ã¡ã³ãäœæãã¡ãŒã«ãã«ã¬ã³ããŒããããªäŒè°ããã£ãããªã©ãå©çšããäºãåºæ¥ãŸãã äŸãã°å
šç€Ÿã«å°å
¥ããåã«å°äººæ°ã§ãã¹ãçã«å©çšããŠã¿ãã®ãè¯ãã§ãããã Business Standard ãéžæããå Žå ããå
±åäœæ¥ïŒã³ã©ãã¬ãŒã·ã§ã³ïŒãä¿é²ããçç£æ§åäžãã¯ããããå Žåã«ãªã¹ã¹ã¡ããŸãã Business Standard ããã¯ã¹ãã¬ãŒãžã®å®¹éãäžæ°ã«1ãŠãŒã¶ãŒãããïŒTBãŸã§å¢ããŸãã ãŸããããªäŒè°ã§ã¯ãäŒè°ã®é²ç»ãããã€ãºãã£ã³ã»ã«ãããã¬ã€ã¯ã¢ãŠãã«ãŒã ããªã©ããªã³ã©ã€ã³äŒè°ã ããããã®ã³ã©ãã¬ãŒã·ã§ã³æ©èœã匷åãããŸãã ãŸãåäžãã¡ã€ã³å
ã® Gmailããã©ã€ããããã¥ã¡ã³ããã«ã¬ã³ããŒãªã©ã«å«ãŸããããŒã¿ãå
æ¬çã«æ€çŽ¢ãææ¡ãããCloud Searchããå©çšããäºãå¯èœãšãªããŸãã Business Plus ãéžæããå Žå 倧容éã®ã¹ãã¬ãŒãžãšæŽã«ã»ãã¥ãªãã£ãé«ãããå Žåã«ãªã¹ã¹ã¡ããŸãã Business Plus ã§ã¯ã¹ãã¬ãŒãžã®å®¹éã1ãŠãŒã¶ãŒãããïŒTBã«ãªããŸãã ããã« Business Standard ã®æ©èœã«å ã㊠Google Workspace ã®ããããããŒã¿ã®ä¿æãæ€çŽ¢ãæžãåºããè¡ãããšãã§ããæ
å ±é瀺ã»ã¬ããã³ã¹ã®çºã®ãGoogle Vaultãããšã³ããã€ã³ã管çãªã©ããã»ãã¥ãªãã£ã«éç¹ã眮ããæ©èœã匷åãããŸãã å®å
šã« Google ãµãŒãã¹ã掻çšãããå Žåã«ã¯ãã²æŽ»çšãã ããã Google Workspace ã®å°å
¥ Google Workspace ãå°å
¥ãããªãæ ªåŒäŒç€ŸG-genã«ãçžè«ãã ãããGoogle Workspace ã䜿ã£ãåãæ¹ã«å€ãããšæ¬åœã«çµç¹ã®ã³ãã¥ãã±ãŒã·ã§ã³ãšã³ã©ãã¬ãŒã·ã§ã³ã®ããæ¹ãå€ãã£ãŠãé©ãã¯ãã§ãã ãã®æåãããå€ãã®äººã«äœæããŠãããããã§ããã æ ªåŒäŒç€Ÿ G-gen ã§ã¯ Google Workspace / Google Cloud (æ§ç§° GCP) ã5%å²åŒã§ãæäŸããŠãããŸãã g-gen.co.jp ãŸã Google Workspace / Google Cloud / Chromebook ã®å°å
¥ããéçšãŸã§ã®ãæ¯æŽãè¡ã£ãŠããŸãã®ã§ãæ€èšã®éã«ã¯ãã²ã声ãããã ããã æž¡é å®£ä¹ (èšäºäžèЧ) ã¯ã©ãŠããœãªã¥ãŒã·ã§ã³éš ããŒã¿åæåºç€ã®æ§ç¯ãã¯ã©ãŠã管çéçšããããã¯ãŒã¯ãå®åç¯å²ãGoogle Workspace æŽ»çšæšé²äžãGoogle Cloud èªå®è³æ Œã¯4è³æ Œä¿æ 鱿«ãã©ãã°ã©ãã¡ãŒã§ãèŠ³èæ€ç©ã塿 ¹æ€ç©ã«ããã£ãŠãŸãã