01.User & Group

Identity and Access Management

user & groups

์œ ์ €๋ฅผ ์ƒ์„ฑํ•˜๊ณ , ๊ทธ๋ฃนํ™”๋ฅผ ๋‹ด๋‹น

image-20220506144843800

  1. ๊ธ€๋กœ๋ฒŒ ์„œ๋น„์Šค์ด๋‹ค.
  2. ๋ฃจํŠธ ๊ณ„์ •์€ default ์ด๋ฉฐ, ๊ณต์œ ํ•ด์„œ๋Š” ์•ˆ๋œ๋‹ค
  3. ์œ ์ €๋“ค์€ ์กฐ์ง์•ˆ์— ์žˆ๊ณ , ๊ทธ๋ฃนํ™” ํ•  ์ˆ˜ ์žˆ๋‹ค.
  4. ๊ทธ๋ฃน๋“ค์€ ์œ ์ €๋“ค๋งŒ ํฌํ•จํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ๋‹ค๋ฅธ ๊ทธ๋ฃน์„ ํฌํ•จํ•˜์ง„ ๋ชปํ•œ๋‹ค.
  5. ์œ ์ €๋Š” ๊ทธ๋ฃน์— ์†ํ•˜์ง€ ์•Š์„ ์ˆ˜๋„ ์žˆ๋‹ค.
  6. ์œ ์ €๋Š” ์—ฌ๋Ÿฌ ๊ทธ๋ฃน์— ์†ํ•  ์ˆ˜ ์žˆ๋‹ค.
    • User(N) : Group(M)
    • ManyToMany ๊ด€๊ณ„

02.Permissions

์œ ์ €๋“ค๊ณผ ๊ทธ๋ฃน์€ ์ •์ฑ…์ด๋ผ ๋ถˆ๋ฆฌ๋Š” ๋ฌธ์„œ์— ์˜ํ•ด ๊ถŒํ•œ์ด ํ• ๋‹น๋œ๋‹ค.

  1. ์ •์ฑ…์€ ์œ ์ €๋“ค์˜ ๊ถŒํ•œ์„ ์ •์˜ํ•œ๋‹ค.
    • ๊ถŒํ•œ์„ ์ •์˜ํ•˜์ง€์•Š์œผ๋ฉด, ์œ ์ €๊ฐ€ ๋„ˆ๋ฌด ๋งŽ์€ ์„œ๋น„์Šค๋ฅผ ์‹คํ–‰ํ•˜๊ฒŒ ๋  ์ˆ˜ ์žˆ๋‹ค => ๋น„์šฉ ์ดˆ๋ž˜
  2. ์‚ฌ์šฉ์ž๊ฐ€ ํ•„์š”ํ•œ ๋งŒํผ์˜ ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•ด์•ผ ํ•œ๋‹ค.
    • ์ตœ์†Œ๊ถŒํ•œ ์›์น™
  3. ์ •์ฑ… Json ํŒŒ์ผ ์˜ˆ์‹œ
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "ec2:Describe*",
      "Resource": "*"
        },
    {
      "Effect": "Allow",
      "Action": "elasticloadbalancing:Describe*",
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "cloudwatch:ListMetrics",
        "cloudwatch:GetMetricStatistics",
        "cloudwatch:Describe*"
      ],
      "Resource": "*"
    }
  ]
}

aws-iam

03.Account Alias

๊ณ„์ • ID ๋กœ ๋กœ๊ทธ์ธํ•˜๋ฉด ๊นŒ๋จน๊ธฐ ์‰ฌ์šฐ๋ฏ€๋กœ ๋ณ„์นญ์„ ์ฃผ์–ด์„œ ๋กœ๊ทธ์ธํ• ๋•Œ ์‰ฝ๊ฒŒ ํ•  ์ˆ˜ ์žˆ๋‹ค.

image-20220507143430268

)

image-20220507143613453

04. IAM User Access Billing Dashboard

IAM user ๊ฐ€ ๊ฒฐ์ œ ๋Œ€์‹œ๋ณด๋“œ ์— ์ ‘๊ทผํ•˜๋ ค๋ฉด ์•„๋ž˜ ์‚ฌ์ง„๊ณผ ๊ฐ™์€ ์„ค์ •์„ ํ•ด์ฃผ์–ด์•ผ ํ•œ๋‹ค.

image-20220510020857401

ํƒœ๊ทธ: , ,

์นดํ…Œ๊ณ ๋ฆฌ:

์—…๋ฐ์ดํŠธ:

๋Œ“๊ธ€๋‚จ๊ธฐ๊ธฐ