- TOP
- ã¿ã°äžèЧ
- Jenkins
Jenkins
ã€ãã³ã
該åœããã³ã³ãã³ããèŠã€ãããŸããã§ãã
ãã¬ãžã³
該åœããã³ã³ãã³ããèŠã€ãããŸããã§ãã
æè¡ããã°
æ¬ããã°ã¯ 2025 幎 7 æ 21 æ¥ã«å
¬éããã AWS Blog â Beyond IAM access keys: Modern authentication approaches for AWS â ã翻蚳ãããã®ã§ãã AWS ã®èªèšŒã«ãããŠã AWS Identity and Access Management (IAM) ã¢ã¯ã»ã¹ããŒãªã©ã®é·æèªèšŒæ
å ±ã«äŸåããããšã¯ãèªèšŒæ
å ±ã®æŒæŽ©ãäžæ£ãªå
±æãçªåãªã©ã®ãªã¹ã¯ããããããŸãããã®èšäºã§ã¯ãAWS ã®ã客æ§ãåŸæ¥ IAM ã¢ã¯ã»ã¹ããŒã䜿çšããŠãã 5 ã€ã®äžè¬çãªãŠãŒã¹ã±ãŒã¹ãšãæ€èšãã¹ãããå®å
šãªä»£æ¿ææ®µã玹ä»ããŸãã AWS CLI ã¢ã¯ã»ã¹: AWS CloudShell ã®æŽ»çš äž»ã« AWS ã³ãã³ãã©ã€ã³ã€ã³ã¿ãŒãã§ã€ã¹ (AWS CLI) ã¢ã¯ã»ã¹ã®ããã«ã¢ã¯ã»ã¹ããŒã䜿çšããŠããå Žåã¯ã AWS CloudShell ã®å©çšãæ€èšããŠãã ãããAWS CloudShell ã¯ãã©ãŠã¶ããŒã¹ã® CLI ã§ã䜿ãæ
£ãã匷å㪠CLI æ©èœãæäŸããªãããããŒã«ã«ã§ã®èªèšŒæ
å ±ç®¡çã®å¿
èŠæ§ãæå°éã«æããŸãã ã»ãã¥ãªãã£ã匷åãã AWS CLI: AWS IAM Identity Center ããå
ç¢ãªãœãªã¥ãŒã·ã§ã³ãå¿
èŠãªå Žåã¯ãAWS CLI v2 ãš AWS IAM Identity Center ã®çµã¿åãããåªããèªèšŒã¢ãããŒããæäŸããŸãããã®çµ±åã«ããã以äžãå¯èœã«ãªããŸãã ãŠãŒã¶ãŒç®¡çã®äžå
å å€èŠçŽ èªèšŒ (MFA) ãšã®ã·ãŒã ã¬ã¹ãªçµ±å ã»ãã¥ãªãã£å¶åŸ¡ã®åŒ·å èšå®ã¯ AWS CLI ããã¥ã¡ã³ã ã䜿çšããŠç°¡åã«è¡ããMFA 㯠IAM Identity Center MFA ã¬ã€ã ã«åŸã£ãŠæå¹åã§ããŸãã ããŒã«ã«éçº: IDE çµ±å ããŒã«ã«ç°å¢ã§äœæ¥ããéçºè
åãã«ã¯ãVisual Studio Code ãªã©ã®ææ°ã®çµ±åéçºç°å¢ (IDE) ã AWS Toolkit ããµããŒãããŠãããIAM Identity Center ãéããå®å
šãªèªèšŒãæäŸããŸããããã«ãããã¹ã ãŒãºãªéçºäœéšãç¶æããªãããé·æã¢ã¯ã»ã¹ããŒãäžèŠã«ãªããŸãã詳现ã¯ã AWS IDE çµ±å ãã芧ãã ããã AWS ã³ã³ãã¥ãŒãã£ã³ã°ãµãŒãã¹ãš CI/CD ã¢ã¯ã»ã¹ ã¢ããªã±ãŒã·ã§ã³ãèªååãã€ãã©ã€ã³ã AWS ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãå¿
èŠãšããå ŽåãAWS ã³ã³ãã¥ãŒãã£ã³ã°ãµãŒãã¹ ( Amazon Elastic Compute Cloud (Amazon EC2) ã Amazon Elastic Container Service (Amazon ECS) ã AWS Lambda ) äžã§å®è¡ããå Žåã§ããCI/CD ããŒã«ãéããŠå®è¡ããå Žåã§ããIAM ããŒã«ãçæ³çãªãœãªã¥ãŒã·ã§ã³ãæäŸããŸãããããã®ããŒã«ã¯äžæçãªèªèšŒæ
å ±ã®ããŒããŒã·ã§ã³ãèªåçã«ç®¡çããã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ã«åŸããŸãã AWS ã³ã³ãã¥ãŒãã£ã³ã°ãµãŒãã¹ã®å Žå : ã³ã³ãã¥ãŒãã£ã³ã°ãªãœãŒã¹ã§æšæºã® IAM ããŒã«ã䜿çšããŸããå®è£
ã®è©³çްã«ã€ããŠã¯ã EC2 IAM ããŒã«ã®ããã¥ã¡ã³ã ãåç
§ããŠãã ãã AWS ã§ãã¹ãããã CI/CD ã®å Žå : AWS CodePipeline ã AWS CodeBuild ãªã©ã䜿çšããå Žåã¯ã ãµãŒãã¹ãªã³ã¯ããŒã« ã䜿çšããŠã¢ã¯ã»ã¹èš±å¯ãå®å
šã«ç®¡çããŸã Amazon EC2 ã§ã»ã«ããã¹ãããã CI/CD ããŒã«ã®å Žå : Jenkins ã GitLab ãªã©ã®ããŒã«ã AWS ãªãœãŒã¹äžã§å®è¡ããŠããå Žåã¯ãä»ã®ã³ã³ãã¥ãŒãã£ã³ã°ãµãŒãã¹ãšåæ§ã« IAM ããŒã« (ã€ã³ã¹ã¿ã³ã¹ãããã¡ã€ã«) ã䜿çšããŸã ãµãŒãããŒãã£ã® CI/CD ãµãŒãã¹ (GitHub ActionsãCircleCI ãªã©) ã«ã€ããŠã¯ã次㮠å€éšã¢ã¯ã»ã¹èŠä»¶ ãåç
§ããŠãã ããã å€éšã¢ã¯ã»ã¹èŠä»¶ ãµãŒãããŒãã£ã¢ããªã±ãŒã·ã§ã³ããªã³ãã¬ãã¹ã¯ãŒã¯ããŒããé¢ä¿ããã·ããªãªã§ã¯ãAWS 㯠3 ã€ã®æ¹æ³ãæäŸããŠããŸãã ãµãŒãããŒãã£ã¢ããªã±ãŒã·ã§ã³ : é·æã¢ã¯ã»ã¹ããŒã®ä»£ããã«ãIAM ããŒã«ãéããäžæçãªã»ãã¥ãªãã£èªèšŒæ
å ±ãå®è£
ããŸããã«ãŒããŠãŒã¶ãŒã®ã¢ã¯ã»ã¹ããŒã¯çµ¶å¯Ÿã«äœ¿çšããªãã§ãã ããã ãµãŒãããŒãã£ã¢ã¯ã»ã¹ã®ããã¥ã¡ã³ã ãåç
§ããŠãã ãã ãªã³ãã¬ãã¹ã¯ãŒã¯ããŒã : IAM Roles Anywhere ã䜿çšããŠãAWS 以å€ã®ã¯ãŒã¯ããŒãçšã®äžæçãªèªèšŒæ
å ±ãçæããŸãã詳现ã«ã€ããŠã¯ã AWS 以å€ã®ã¯ãŒã¯ããŒãã®ã¢ã¯ã»ã¹ ãåç
§ããŠãã ãã CI/CD SaaS (Software as a Service) : ã¯ã©ãŠãããŒã¹ã® CI/CD ãµãŒãã¹ã®å Žåã¯ã OpenID Connect (OIDC) ãš IAM ããŒã«ã®çµ±å ã䜿çšããŠãæ°žç¶çãªèªèšŒæ
å ±ã®å¿
èŠæ§ãæå°éã«æããŸããããã«ãããCI/CD ãã€ãã©ã€ã³ã¯ä¿¡é Œé¢ä¿ãéããŠäžæçãªèªèšŒæ
å ±ãååŸã§ããŸããå®è£
ã®è©³çްã«ã€ããŠã¯ãAWS OIDC ãããã€ããŒã®ããã¥ã¡ã³ããåç
§ããŠãã ãã ãã¹ããã©ã¯ãã£ã¹: æå°æš©éã®åå èªèšŒæ¹æ³ã«é¢ä¿ãªããåžžã«æå°æš©éã®ååãå®è£
ããŠãã ãããããã«ããããŠãŒã¶ãŒãšã¢ããªã±ãŒã·ã§ã³ãå¿
èŠãªã¢ã¯ã»ã¹èš±å¯ã®ã¿ãæã€ããã«ãªããŸããæ£ç¢ºãª IAM ããªã·ãŒã®äœæã«é¢ããã¬ã€ãã³ã¹ã«ã€ããŠã¯ã æå°æš©éã® IAM ããªã·ãŒãäœæããããã®ãã¯ãã㯠ãåç
§ããŠãã ããã æ³š: AWS 㯠AWS CloudTrail ãã°ã«åºã¥ãããªã·ãŒçæãæäŸããŠãããå®éã®äœ¿çšãã¿ãŒã³ã«åºã¥ããŠã¢ã¯ã»ã¹èš±å¯ãã³ãã¬ãŒããäœæã§ããŸãããã®æ©èœã«ã€ããŠã¯ã IAM ããªã·ãŒçæã®ããã¥ã¡ã³ã ãã芧ãã ããã ãŸãšã ãããŸã§ç޹ä»ããŠããããã«ãIAM ã¢ã¯ã»ã¹ããŒã«ä»£ããå®å
šãªä»£æ¿ææ®µã¯æ°å€ããããã»ãã¥ãªãã£ãªã¹ã¯ã軜æžããªãã AWS èªèšŒæŠç¥ã匷åã§ããŸããCloudShellãIAM Identity CenterãIDE çµ±åãIAM ããŒã«ãIAM Roles Anywhere ãªã©ã®ããŒã«ã䜿çšããããšã§ãææ°ã®ã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ã«æ²¿ã£ãå
ç¢ãªèªèšŒã¡ã«ããºã ãå®è£
ã§ããŸããéèŠãªãã€ã³ãã¯ä»¥äžã®ãšããã§ãã é·æã¢ã¯ã»ã¹ããŒãé¿ããäžæçãªèªèšŒæ
å ±ã䜿çšãã ãŠãŒã¹ã±ãŒã¹ã«æé©ãªèªèšŒæ¹æ³ãéžæãã ãã¹ãŠã®ã¢ã¯ã»ã¹æ¹æ³ã§æå°æš©éã®ååãå®è£
ãã ããªã·ãŒã®çæãšç®¡çã®ããã« AWS ãæäŸããçµã¿èŸŒã¿ããŒã«ã掻çšãã æ°ãããœãªã¥ãŒã·ã§ã³ãå©çšå¯èœã«ãªã£ãããèªèšŒæ¹æ³ã宿çã«èŠçŽããŠæŽæ°ãã ãããã®å€æŽãè¡ãããšã§ãã»ãã¥ãªãã£ãã¹ãã£ãæ¹åããã ãã§ãªããAWS ç°å¢å
šäœã®èªèšŒããã»ã¹ãå¹çåã§ããŸãããŸãã¯çŸåšã® IAM ã¢ã¯ã»ã¹ããŒã®ãŠãŒã¹ã±ãŒã¹ãç¹å®ãããããã®ããå®å
šãªä»£æ¿ææ®µã«æ®µéçã«ç§»è¡ããããšããå§ããŠãã ãããå°æ¥çã«ã»ãã¥ãªãã£ç®¡çã®è² æ
ã軜æžãããã»ãã¥ãªãã£ããŒã ã«ãšã£ãŠã倧ããªã¡ãªãããšãªãã§ãããã Mitch Beaumont Mitch ã¯ãªãŒã¹ãã©ãªã¢ã®ã·ãããŒãæ ç¹ãšãã Amazon Web Services ã®ããªã³ã·ãã«ãœãªã¥ãŒã·ã§ã³ã¢ãŒããã¯ãã§ãããªãŒã¹ãã©ãªã¢æå€§çŽã®éèãµãŒãã¹ã®ã客æ§ãšååããæ§ç¯ã»æäŸãã補åãæ©èœã®ã»ãã¥ãªãã£æ°Žæºãç¶ç¶çã«åäžãããæ¯æŽãããŠããŸããä»äºä»¥å€ã§ã¯ãå®¶æãšã®æéãåçæ®åœ±ããµãŒãã£ã³ã楜ããã§ããŸãã æ¬ããã°ã¯ Security Solutions Architect ã® äžå³¶ ç« å ã翻蚳ããŸããã
ã¯ããã« éçºè
ã®ããŒã«ã«ç°å¢ã§ã¯åé¡ãªããã«ããéãã®ã«ãCIïŒç¶ç¶çã€ã³ãã°ã¬ãŒã·ã§ã³ïŒç°å¢äžã®Jenkinsãªã©ã§ãã«ããããšãšã©ãŒã«ãªã£ãŠããŸããããªãç°å¢äŸåã®ãã«ããšã©ãŒãã¯ãå€ãã®éçºçŸå Žã§äžåºŠã¯çµéšããæ©ã¿ã§ã¯ãªãã§ããããã ç¹ã«ãæŽå²ã®é·ãã·ã¹ãã ãä¿å®ã»éçšããŠããçŸå Žã§ã¯ãéçºè
ã®PCã«ã¯ææ°ã®Visual Studioãã€ã³ã¹ããŒã«ãããŠããäžæ¹ã§ããã«ããµãŒããŒã«ã¯å€ãããŒãžã§ã³ã®ãã«ãããŒã«ïŒMSBuildãªã©ïŒããã®ãŸãŸæ®ã£ãŠãããšããã±ãŒã¹ãçãããããŸããã æ¬èšäºã§ã¯ãVB.NETïŒVisual Basic .NETïŒã®ãããžã§ã¯ãã«ãããŠçºçã
ã¯ããã« CI/CDããŒã«ãšããŠåºãå©çšãããŠããJenkinsã§ãããWindowsç°å¢ã®ã¹ã¬ãŒãããŒãããšãŒãžã§ã³ãã§ãã«ããå®è¡ããéãç¹æã®ãšã©ãŒã«æ©ãŸãããããšããããŸãã ãã®ä»£è¡šçãªãã®ãããã¡ã€ã«ãã¹ã«é¢é£ãããšã©ãŒã§ãã Linuxç°å¢ã§ã¯åé¡ãªãåäœããŠãããžã§ããWindowsç°å¢ã«ç§»è¡ããéãããããžã§ã¯ãã®ãã£ã¬ã¯ããªéå±€ãæ·±ããªã£ãã¿ã€ãã³ã°ã§ãçªåŠãšããŠãã«ãã倱æããããšããããŸãã æ¬èšäºã§ã¯ãJenkinsã§ã®ãã«ãå®è¡æã«**ããã¹ã®äžéšãèŠã€ãããŸããã§ããã**ãšãããšã©ãŒãçºçããå Žåã®åå ãšãã·ã¹ãã èšå®ã倿ŽããããšãªãJenkinsã®
åç»
該åœããã³ã³ãã³ããèŠã€ãããŸããã§ãã






