ð AWS VPC â å®å šãªãã¡ã¬ã³ã¹ã¬ã€ã
VPC ãšã¯äœãïŒ AWS å ã®ããªãå°çšã®åé¢ããããã©ã€ããŒããããã¯ãŒã¯ãããã¯ã¯ã©ãŠãå ã®ããªãã®ãã©ã€ããŒãããŒã¿ã»ã³ã¿ãŒã ãšèããŠãã ãããæç€ºçã«èš±å¯ããªãéããäœãåºå ¥ãããŸããã
ð ç®æ¬¡â
ð§ Core Conceptsâ
VPC ã¯ããªãã®ä»®æ³ãããã¯ãŒã¯ç°å¢ãå®å šã«ã³ã³ãããŒã«ã§ããŸããããã«ã¯ IP ã¢ãã¬ã¹ç¯å²ããµãããããã«ãŒãããŒãã«ãã²ãŒããŠã§ã€ãªã©ãå«ãŸããŸãã
äž»ãªäºå®:
-
VPC ã¯åäžã® AWS ãªãŒãžã§ã³ å ã«ååšããŸã
-
VPC ã¯ è€æ°ã®ã¢ãã€ã©ããªãã£ãŒãŸãŒã³ (AZ) ã«ãŸãããããšãã§ããŸã
-
å AWS ã¢ã«ãŠã³ãã¯ãªãŒãžã§ã³ããšã« ããã©ã«ã VPC ãååŸããŸã (ããã«äœ¿çšå¯èœãªç¶æ ã§æäŸãããŸã)
-
VPC èªäœã¯ ç¡æ ã§ã â ãã ãäžéšã®ã³ã³ããŒãã³ã (NAT GatewayãVPC Endpoints) ã«ã¯ã³ã¹ããããããŸã
-
ãªãŒãžã§ã³ããšã« è€æ°ã® VPC ãäœæã§ããŸã (ããã©ã«ãäžé: 5ãå¢å ãèŠæ±å¯èœ)
ð VPC Architecture Diagramâ
Internet
â
âŒ
ââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ
â VPC (172.16.0.0/16) â
â â
â ââââââââââââââââââââââââââââââââââââââââââââââââââââ â
â â PUBLIC SUBNET (172.16.1.0/24) â â
â â - Has route to Internet Gateway â â
â â - Resources CAN have public IPs â â
â â - ALB (Load Balancer) lives here â â
â â - ECS tasks live here (if no NAT Gateway) â â
â ââââââââââââââââââââââââââââââââââââââââââââââââââââ â
â â â
â ⌠(security group allows) â
â ââââââââââââââââââââââââââââââââââââââââââââââââââââ â
â â PRIVATE SUBNET (172.16.2.0/24) â â
â â - NO route to Internet Gateway â â
â â - Resources CANNOT reach internet directly â â
â â - RDS databases live here â â
â â - Redis / ElastiCache lives here â â
â ââââââââââââââââââââââââââââââââââââââââââââââââââââ â
ââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ
ð Key Components Deep Diveâ
| ã³ã³ããŒãã³ã | æ©èœ | 顿š |
| VPC | AWS å ã®åé¢ããããããã¯ãŒã¯ | ããªãã®ãã©ã€ããŒãããŒã¿ã»ã³ã¿ãŒ |
| Subnet | VPC å ã® IP ç¯å²ã§ã1 ã€ã® AZ ã«é 眮 | ããŒã¿ã»ã³ã¿ãŒå ã®ã«ãŒã |
| Internet Gateway | VPC ããããªãã¯ã€ã³ã¿ãŒãããã«æ¥ç¶ | ããã³ãã㢠|
| NAT Gateway | ãã©ã€ããŒããªãœãŒã¹ã®ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãèš±å¯ (ã¢ãŠãããŠã³ãã®ã¿) | äžæ¹åã®ã¡ãŒã«ã¹ããã |
| Route Table | ãã©ãã£ãã¯ã®éä¿¡å ãå®çŸ© | éè·¯æšè |
| Security Group | ãªãœãŒã¹ããšã®ã¹ããŒããã«ãã¡ã€ã¢ãŠã©ãŒã« (ã€ã³ã¹ã¿ã³ã¹ã¬ãã«) | å人çãªããã£ã¬ãŒã |
| NACL | ãµããããããšã®ã¹ããŒãã¬ã¹ãã¡ã€ã¢ãŠã©ãŒã« | 建ç©ã®ã»ãã¥ãªãã£ã²ãŒã |
| VPC Endpoint | ã€ã³ã¿ãŒããããªãã§ AWS ãµãŒãã¹ãžã®ãã©ã€ããŒãæ¥ç¶ | å¥ã®å»ºç©ãžã®å éšéè·¯ |
| Elastic IP | éçãªãããªã㯠IPv4 ã¢ãã¬ã¹ | åºå®é»è©±çªå· |
ð¢ CIDR Blocks & IP Addressingâ
CIDR (Classless Inter-Domain Routing) 㯠VPC ã® IP ç¯å²ãå®çŸ©ããŸãã
äžè¬ç㪠VPC CIDR ãããã¯:
| CIDR ããã㯠| IP ç¯å² | åèš IP | ãŠãŒã¹ã±ãŒã¹ |
10.0.0.0/16 | 10.0.0.0 â 10.0.255.255 | 65,536 | å€§èŠæš¡æ¬çª VPC |
172.16.0.0/16 | 172.16.0.0 â 172.16.255.255 | 65,536 | æšæº VPC |
192.168.0.0/16 | 192.168.0.0 â 192.168.255.255 | 65,536 | ããå°èŠæš¡ãªç°å¢ |
10.0.0.0/24 | 10.0.0.0 â 10.0.0.255 | 256 | åäžã®å°èŠæš¡ãµãããã |
CIDR èšç®ã¯ã€ãã¯:
-
/16= 65,536 IPs -
/20= 4,096 IPs -
/24= 256 IPs -
/28= 16 IPs (AWS ã§æå°)
ã«ãŒã«:
-
VPC CIDR ç¯å²:
/16(æå€§) ãã/28(æå°) -
AWS ã¯ãã¹ãŠã®ãµããããã§ 5 ã€ã® IP ãäºçŽããŸã (æåã® 4 ã€ãšæåŸã® 1 ã€)
-
VPC ããã¢ãªã³ã°ããããªã³ãã¬ãã¹ã«æ¥ç¶ããå Žåã¯ãCIDR ç¯å²ããªãŒããŒã©ãããããªãã§ãã ãã
ð Subnetsâ
ãµãããã㯠VPC å ã® IP ç¯å²ã§ã1 ã€ã®ç¹å®ã®ã¢ãã€ã©ããªãã£ãŒãŸãŒã³ ã«é 眮ãããŸãã
ãããªã㯠vs ãã©ã€ããŒã â å¯äžã®å®éã®éãâ
| æ©èœ | ãããªãã¯ãµãããã | ãã©ã€ããŒããµãããã |
| Internet Gateway ãžã®ã«ãŒã | â ã¯ã | â ããã |
| ãªãœãŒã¹ããããªã㯠IP ãååŸ | â å¯èœ | â äžå¯ |
| çŽæ¥ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ | â ã¯ã | â ããã (NAT ãå¿ èŠ) |
| äžè¬çãªäœäºº | ALBãBastion ãã¹ããWeb ãµãŒã㌠| ããŒã¿ããŒã¹ããã£ãã·ã¥ãã¢ããªãµãŒã㌠|
éèŠãªæŽå¯: ãµãããããããããªãã¯ããŸãã¯ããã©ã€ããŒããã«ããã®ã¯ãã«ãŒãããŒãã«ã®ã¿ ã§ã â Internet Gateway ãžã®ã«ãŒãããããã©ããã®ã¿ãä»ã«ã¯äœããããŸããã
é«å¯çšæ§ã®ããã®è€æ° AZ ãµããããâ
åžžã«å°ãªããšã 2 ã€ã® AZ ã«ãŸããããµãããããäœæããŸã:
VPC (10.0.0.0/16)
âââ Public Subnet AZ-a (10.0.1.0/24)
âââ Public Subnet AZ-b (10.0.2.0/24)
âââ Private Subnet AZ-a (10.0.3.0/24)
âââ Private Subnet AZ-b (10.0.4.0/24)
ãã®ããã«ããŠã1 ã€ã® AZ ãããŠã³ããå Žåãã¢ããªã¯ããäžæ¹ã§å®è¡ãç¶ããŸãã
ðª Internet Gateway (IGW)â
-
VPC ããããªãã¯ã€ã³ã¿ãŒãããã«æ¥ç¶ããŸã
-
VPC ããšã« 1 〠(1 ã€ã® VPC ã« 1 ã€ã® IGW ã®ã¿ã¢ã¿ããã§ããŸã)
-
æ°Žå¹³ã¹ã±ãŒãªã³ã°å¯èœãåé·ãé«å¯çšæ§ â AWS ã管ç
-
ç¡æ â æéåäœã®æéãŸãã¯ããŒã¿åŠçæéãªã
-
ãªããã°ãVPC å ã®ãªãœãŒã¹ã¯ã€ã³ã¿ãŒãããã«å°éããããã€ã³ã¿ãŒãããããã¢ã¯ã»ã¹ããããã§ããŸãã
ãªãœãŒã¹ãã€ã³ã¿ãŒãããã¢ã¯ã»ã¹å¯èœã«ããã«ã¯ãããããã¹ãŠãå¿ èŠã§ã:
-
VPC ã«ã¢ã¿ããããã IGW
-
0.0.0.0/0â IGW ãæãã«ãŒãããŒãã«ãšã³ã㪠-
ãªãœãŒã¹ããããªã㯠IP ãŸã㯠Elastic IP ãæã£ãŠãã
-
ã»ãã¥ãªãã£ã°ã«ãŒãããã©ãã£ãã¯ãèš±å¯ããŠãã
ð NAT Gatewayâ
ãã©ã€ããŒããµãããã å ã®ãªãœãŒã¹ã ã¢ãŠãããŠã³ãã®ã¿ ã§ã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ããããšãèš±å¯ããŸã (äŸ: æŽæ°ã®ããŠã³ããŒããDocker ã€ã¡ãŒãžã®ååŸ)ã
äž»ãªè©³çް:
-
ãããªãã¯ãµãããã ã«é 眮
-
Elastic IP ãå¿ èŠã§ã
-
æé¡çŽ 32 ãã« + ããŒã¿åŠç $0.045/GB
-
é«å¯çšæ§ã®ãã AZ ããšã« 1 〠(2-3 AZ = æé¡ 64 ïœ 96 ãã«ãNAT ã®ã¿)
-
AWS ã§ç®¡ç â ãããäžèŠ
ã³ã¹ãåæžã®ä»£æ¿æ¡: ãããªã㯠IP ãæã€ãããªãã¯ãµããããã«ãªãœãŒã¹ãé 眮ãã代ããã« NAT Gateway ã䜿çšããŸããããã¯ã»ãã¥ãªãã£é¢ã§ã¯å£ããŸãããæé¡ 100 ãã«ä»¥äžç¯çŽã§ããŸããããã¯å€ãã®éçºã»ã¹ããŒãžã³ã°ç°å¢ã宿œããŠããŸãã
ðº Route Tablesâ
ãã¹ãŠã®ãµããããã¯ã«ãŒãããŒãã«ã«é¢é£ä»ããããŠããŸããã«ãŒãããŒãã«ã¯ãã©ãã£ãã¯ã®è¡ãå ãæå®ããŸãã
ãããªãã¯ãµããããã«ãŒãããŒãã«â
Destination â Target
172.16.0.0/16 â local (VPC å
ã«çãŸã)
0.0.0.0/0 â igw-xxxx (internet gateway)
ãã©ã€ããŒããµããããã«ãŒãããŒãã« (NAT 䜿çš)â
Destination â Target
172.16.0.0/16 â local (VPC å
ã«çãŸã)
0.0.0.0/0 â nat-xxxx (NAT gateway)
ãã©ã€ããŒããµããããã«ãŒãããŒãã« (NAT ãªããå®å šã«åé¢)â
Destination â Target
172.16.0.0/16 â local (VPC å
ã«çãŸã)
localã«ãŒãã¯èªåã§ãåé€ããããšã¯ã§ããŸãããããã«ããããã¹ãŠã® VPC å éšãã©ãã£ãã¯ãå éšã«çãŸãããšãä¿èšŒãããŸãã
ð¡ Security Groupsâ
AWS ã§æãéèŠãªã»ãã¥ãªãã£ã³ã³ãããŒã«ã åã ã®ãªãœãŒã¹ (EC2ãRDSãECSãALB ãªã©) ã«æ¥ç¶ãããã¹ããŒããã«ãã¡ã€ã¢ãŠã©ãŒã«ã
äž»ãªç¹æ§â
| ç¹æ§ | ã»ãã¥ãªãã£ã°ã«ãŒã |
| ã¬ãã« | ãªãœãŒã¹ (ã€ã³ã¹ã¿ã³ã¹) ã¬ãã« |
| ã¹ããŒããã«? | â ã¯ã â ã€ã³ããŠã³ããèš±å¯ãããŠããå Žåãã¬ã¹ãã³ã¹ã¯èªåçã«èš±å¯ãããŸã |
| ããã©ã«ãåäœ | ãã¹ãŠã®ã€ã³ããŠã³ããæåŠããã¹ãŠã®ã¢ãŠãããŠã³ããèš±å¯ |
| ã«ãŒã« | èš±å¯ã«ãŒã«ã®ã¿ (æåŠã«ãŒã«ãªã) |
| åç §å¯èœ | ä»ã®ã»ãã¥ãªãã£ã°ã«ãŒããCIDR ãããã¯ããŸãã¯ãã¬ãã£ãã¯ã¹ãªã¹ã |
ã»ãã¥ãªãã£ã°ã«ãŒããã§ãŒã³ (ãã¹ããã©ã¯ãã£ã¹)â
IP ã¢ãã¬ã¹ã®ä»£ããã«ãã»ãã¥ãªãã£ã°ã«ãŒãã ä»ã®ã»ãã¥ãªãã£ã°ã«ãŒã ãåç §ããŸã:
Internet â ALB SG (allows port 80/443 from 0.0.0.0/0)
â
âŒ
ECS SG (allows port 5000 from ALB SG only)
â
âŒ
RDS SG (allows port 5432 from ECS SG only)
Redis SG (allows port 6379 from ECS SG only)
ãããéèŠãªçç±: æ°ãã ECS ã¿ã¹ã¯ã远å ãããšãECS ã»ãã¥ãªãã£ã°ã«ãŒããã¢ã¿ãããããŠããããèªåçã« RDS ã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸããIP ã¢ãã¬ã¹ãã©ããããæŽæ°ããå¿ èŠã¯ãããŸããã
äžè¬çãªããŒããªãã¡ã¬ã³ã¹â
| ãµãŒãã¹ | ããŒã | ãããã³ã« |
| HTTP | 80 | TCP |
| HTTPS | 443 | TCP |
| SSH | 22 | TCP |
| PostgreSQL | 5432 | TCP |
| MySQL | 3306 | TCP |
| Redis | 6379 | TCP |
| ã«ã¹ã¿ã ã¢ã㪠(äŸ: Redash) | 5000 | TCP |
ð§± Network ACLs (NACLs)â
ãµããããã¬ãã« ã§ã®ç¬¬ 2 ã®ã»ãã¥ãªãã£ã¬ã€ã€ãŒã
| ç¹æ§ | NACL | ã»ãã¥ãªãã£ã°ã«ãŒã |
| ã¬ãã« | ãµããããã¬ãã« | ãªãœãŒã¹ã¬ãã« |
| ã¹ããŒããã«? | â ããã â ã€ã³ããŠã³ããšã¢ãŠãããŠã³ãã®äž¡æ¹ãèš±å¯ããå¿ èŠããããŸã | â ã¯ã |
| ããã©ã«ãåäœ | ãã¹ãŠèš±å¯ (ããã©ã«ã NACL) | ãã¹ãŠã®ã€ã³ããŠã³ããæåŠ |
| ã«ãŒã«ã¿ã€ã | èš±å¯ãšæåŠã«ãŒã« | èš±å¯ã®ã¿ |
| è©äŸ¡ | ã«ãŒã«ã¯çªå·é ã«åŠç | ãã¹ãŠã®ã«ãŒã«ãè©äŸ¡ããã |
å®éã«ã¯: ã»ãšãã©ã®äººã¯ NACL ãããã©ã«ã (ãã¹ãŠèš±å¯) ã«èšå®ãããŸãŸã«ããŠãã»ãã¥ãªãã£ã°ã«ãŒãã«äŸåããŸããNACL ã¯ããã¯ã¢ããã¬ã€ã€ãŒãšããŠããŸãã¯ç¹å®ã® IP ã¢ãã¬ã¹ããããã¯ããå Žåã«æçšã§ãã
ð VPC Endpointsâ
ã€ã³ã¿ãŒããããéããããšãªã AWS ãµãŒãã¹ã«ã¢ã¯ã»ã¹ããŸãããã©ãã£ãã¯ã¯ AWS ã®ãã©ã€ããŒããããã¯ãŒã¯äžã«çãŸããŸãã
2 ã€ã®ã¿ã€ãâ
| ã¿ã€ã | ã³ã¹ã | å¯Ÿå¿ | åäœæ¹æ³ |
| Gateway Endpoint | ç¡æ | S3ãDynamoDB ã®ã¿ | ã«ãŒãããŒãã«ãšã³ããªã远å |
| Interface Endpoint | æé¡çŽ 7 ãã« + ããŒã¿ | ãã®ä»ã®ã»ãšãã©ã® AWS ãµãŒãã¹ (ECRãSecrets ManagerãCloudWatch ãªã©) | ãµããããã« ENI ãäœæ |
䜿çšããã¿ã€ãã³ã°: ãªãœãŒã¹ããã©ã€ããŒããµããããã« NAT Gateway ãªãã§ãAWS ãµãŒãã¹ (S3 ã ECR ãªã©) ã«ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãªãã§ã¢ã¯ã»ã¹ããå¿ èŠãããå ŽåãVPC Endpoints ããããå¯èœã«ããŸãã
ð VPC Peering & Transit Gatewayâ
VPC Peeringâ
-
2 ã€ã® VPC ãæ¥ç¶ããŠããã©ã€ããŒã IP ã䜿çšããŠéä¿¡ã§ããããã«ããŸã
-
ãªãŒãžã§ã³éããã³ã¢ã«ãŠã³ãéã§ãã¢ãªã³ã°å¯èœ
-
ç¡æ (éåžžã®ããŒã¿è»¢éæéã®ã¿æ¯æã)
-
CIDR ç¯å²ã ãªãŒããŒã©ãããããããšã¯ã§ããŸãã
-
3 ã€ä»¥äžã® VPC ã§ã¯è€éã«ãªããŸã (åãã¢ã«ç¬èªã®ãã¢ãªã³ã°æ¥ç¶ãå¿ èŠ)
Transit Gatewayâ
-
è€æ°ã® VPCãVPNãããã³ãªã³ãã¬ãã¹ãããã¯ãŒã¯ãæ¥ç¶ãã äžå€®ãã
-
å€ãã® VPC ãããå Žåããã¢ãªã³ã°ãããã¯ããã«ã¯ãªãŒã³
-
æé¡çŽ $0.05 à ã¢ã¿ããã¡ã³ãæ° + ããŒã¿è»¢é
-
3 ã€ä»¥äžã® VPC ãããçµç¹ã«æé©
ð Traffic Flow Example (Redash Setup)â
ãŠãŒã¶ãŒãªã¯ãšã¹ãã VPC ãéã㊠Redash ã«å°éããæ¹æ³ã¯æ¬¡ã®éãã§ã:
1. ãŠãŒã¶ãŒãã©ãŠã¶ â https://redash.yourdomain.com
â
2. DNS (Route 53) â ALB ã®ãããªã㯠IP ã«è§£æ±º
â
3. Internet Gateway â VPC ãžã®ãã©ãã£ãã¯ãèš±å¯
â
4. ALB (ãããªãã¯ãµãããã) â SG 㯠0.0.0.0/0 ããã® 443 ããŒããèš±å¯
â SSL ãçµäºãã¿ãŒã²ããã°ã«ãŒãã«è»¢é
â
5. ã¿ãŒã²ããã°ã«ãŒã â ããŒã 5000 ã® ECS ã¿ã¹ã¯ã«ã«ãŒãã£ã³ã°
â
6. ECS ã¿ã¹ã¯ (ãããªãã¯ãµãããã) â SG 㯠ALB SG ããã® 5000 ããŒããèš±å¯
â Redash ã³ã³ãããå®è¡
â
ââââ RDS (ãã©ã€ããŒããµãããã) â SG 㯠ECS SG ããã® 5432 ããŒããèš±å¯
â ã¯ãšãªçµæãè¿ã
â
ââââ Redis (ãã©ã€ããŒããµãããã) â SG 㯠ECS SG ããã® 6379 ããŒããèš±å¯
ãã£ãã·ã¥ãããããŒã¿ãè¿ã
ECS ãç°ãªããµããããã® RDS ãšéä¿¡ã§ããã®ã¯ãªãã§ãã? ãããã åã VPC å
ã«ããããã§ããlocal ã«ãŒã (172.16.0.0/16 â local) ã«ããããã¹ãŠã®å
éš VPC ãã©ãã£ãã¯ãå
éšã«çãŸããŸããã»ãã¥ãªãã£ã°ã«ãŒãã¯ãã©ã®ç¹å®ã®ãªãœãŒã¹ãéä¿¡ã§ããããå¶åŸ¡ããŸãã
ð Common Architecture Patternsâ
ãã¿ãŒã³ 1: ã·ã³ãã« (éçºã»ã¹ããŒãžã³ã°) â NAT Gateway ãªãâ
Internet â IGW â ãããªãã¯ãµãããã (ALB + ãããªã㯠IP ä»ã ECS)
â
ãã©ã€ããŒããµãããã (RDSãRedis)
-
ã³ã¹ã: ãããã¯ãŒã¯ã«æé¡çŽ $0
-
ãã¬ãŒããªã: ECS ã¿ã¹ã¯ã¯ãããªã㯠IP ãæã£ãŠãã (ã»ãã¥ãªãã£é¢ã§ããå£ã)
ãã¿ãŒã³ 2: æšæº (æ¬çª)â
Internet â IGW â ãããªãã¯ãµãããã (ALB ã®ã¿)
â
ãã©ã€ããŒããµãããã (ECS ã¿ã¹ã¯ãã¢ããªãµãŒããŒ)
â â
NAT Gateway VPC Endpoints
â â
(ã¢ãŠãããŠã³ã (AWS ãµãŒãã¹
ã€ã³ã¿ãŒããã) ãã©ã€ããŒã)
â
åé¢ããããµãããã (RDSãRedis)
-
ã³ã¹ã: NAT ã«æé¡çŽ $32-96
-
å©ç¹: ã³ã³ãã¥ãŒããªãœãŒã¹ã«å ¬é IP ããªã
ãã¿ãŒã³ 3: ãšã³ã¿ãŒãã©ã€ãº (è€æ° VPC)â
ãªã³ãã¬ãã¹ ââ Transit Gateway ââ VPC-Prod
â ââ VPC-Staging
â ââ VPC-Dev
â ââ Shared Services VPC
-
ã³ã¹ã: ããé«ã (Transit Gateway + è€æ°ã® NAT)
-
å©ç¹: ç°å¢éã®å®å šãªåé¢
ð° Cost Breakdownâ
| ã³ã³ããŒãã³ã | ã³ã¹ã | æ³šèš |
| VPC | ç¡æ | â |
| Subnets | ç¡æ | â |
| Internet Gateway | ç¡æ | â |
| Route Tables | ç¡æ | â |
| Security Groups | ç¡æ | â |
| NACLs | ç¡æ | â |
| Elastic IP (ã¢ã¿ããæžã¿) | ç¡æ | ã¢ã¿ãããããŠããªãå Žåã¯ææ (æé¡çŽ $3.65) |
| NAT Gateway | æé¡çŽ $32 + $0.045/GB | AZ ããš â AZ ã®æ°ã§ä¹ç® |
| Gateway VPC Endpoint (S3/DynamoDB) | ç¡æ | â |
| Interface VPC Endpoint | æé¡çŽ $7 + $0.01/GB | ãšã³ããã€ã³ããAZ ããš |
| VPC Peering | ç¡æ | ããŒã¿è»¢éæéãé©çš |
| Transit Gateway | æé¡çŽ $36 (ã¢ã¿ããã¡ã³ã) | + åŠçããŒã¿ $0.02/GB |
| ããŒã¿è»¢é (ã¯ãã¹ AZ) | åæ¹å $0.01/GB | é«ãã©ãã£ãã¯ã§ã¯å ç®ããã |
| ããŒã¿è»¢é (ã€ã³ã¿ãŒãããåã) | çŽ $0.09/GB | æ 100GB ãŸã§ã¯ç¡æã®å Žåããã |
â Best Practices Checklistâ
-
CIDR ç¯å²ãèšç»ãã â VPC äœæåã«ãä»ã® VPC ãšãªã³ãã¬ãã¹ãšã®éè€ãé¿ãã
-
è€æ°ã® AZ ã䜿çšãã â æå° 2ãçæ³ã¯é«å¯çšæ§ã®ãã 3
-
ããŒã¿ããŒã¹ããã©ã€ããŒããµããããã«é 眮 â RDS ããããªãã¯ã€ã³ã¿ãŒãããã«å ¬éããªã
-
ã»ãã¥ãªãã£ã°ã«ãŒããã§ãŒã³ãäœ¿çš â IP ã¢ãã¬ã¹ã®ä»£ããã« SG ãåç §
-
VPC Flow Logs ãæå¹ã«ãã â ãããã°ãšã»ãã¥ãªãã£ç£æ»ã®ãã
-
DNS ãã¹ãå + DNS 解決ãæå¹ã«ãã â å€ãã® AWS ãµãŒãã¹ã«å¿ èŠ
-
S3 Gateway Endpoint ãäœ¿çš â ç¡æã§ NAT ããŒã¿æéãåé¿
-
ãã¹ãŠã«ã¿ã°ãä»ãã â VPCããµãããããã«ãŒãããŒãã«ãã»ãã¥ãªãã£ã°ã«ãŒã
-
æ¬çªãšéçºã»ã¹ããŒãžã³ã°çšã«å¥ã ã® VPC ã䜿çš
-
AWS Secrets Manager ãäœ¿çš â ããŒã¿ããŒã¹èªèšŒæ å ±ãããŒãã³ãŒãã£ã³ã°ããªã
-
RDS ã€ã³ã¹ã¿ã³ã¹ã®ãPublicly Accessibleãã false ã«èšå®
-
ã»ãã¥ãªãã£ã°ã«ãŒãã宿çã«ã¬ãã¥ãŒ â æªäœ¿çšã®ã«ãŒã«ãåé€ããé床ã«åºãã¢ã¯ã»ã¹ãåé€
â Common Mistakes & Troubleshootingâ
ãããŒãããœã³ã³ãã RDS ã«æ¥ç¶ã§ããªããâ
åå : RDS ããã©ã€ããŒããµããããå
ã«ãããSG 㯠ECS SG ã®ãã©ãã£ãã¯ã®ã¿ãèš±å¯ãããPublicly Accessibleã㯠false ã§ãã
ä¿®æ£: Bastion ãã¹ããAWS Session ManagerããŸã㯠VPN ã䜿çšããŠæ¥ç¶ããŸããæ¬çªç°å¢ã§ RDS ããããªãã¯ã¢ã¯ã»ã¹å¯èœã«ããªãã§ãã ããã
ãECS ã¿ã¹ã¯ã Docker ã€ã¡ãŒãžããã«ã§ããªããâ
åå : ã¿ã¹ã¯ããã©ã€ããŒããµããããå
ã«ãããã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ããããŸããã
ä¿®æ£: NAT Gateway ã远å ãããããããªã㯠IP ã®ãããããªãã¯ãµããããã«ç§»åããããECR çšã® VPC Endpoints ã䜿çšããŸãã
ãã»ãã¥ãªãã£ã°ã«ãŒãã®ã«ãŒã«ãæ©èœããŠããªããâ
åå : äžè¬çãªåå :
-
ããŒãçªå·ãééã£ãŠãã
-
å¥ã®ã»ãã¥ãªãã£ã°ã«ãŒããåç §ããŠãã
-
NACL ã®ã¢ãŠãããŠã³ãã«ãŒã«ãå¿ããŠãã (NACL ã¯ã¹ããŒãã¬ã¹!)
-
ãªãœãŒã¹ã« SG ãã¢ã¿ãããããŠããªã
ããµããããã® IP ãæ¯æžãããâ
åå : å°ãããã CIDR ã䜿çšããŸãã (äŸ: /28 = AWS ã 5 ã€ãäºçŽããåŸã䜿çšå¯èœãª IP 㯠11 ã®ã¿)ã
ä¿®æ£: ãã倧ããªãµãããããäœæããŸããVPC ã«ã»ã«ã³ã㪠CIDR ãããã¯ã远å ã§ããŸãã
ãã¯ãã¹ AZ ããŒã¿è»¢éã³ã¹ããé«ããâ
åå : AZ éã®ãã©ãã£ãã¯ã¯åæ¹å $0.01/GB ã®ã³ã¹ããããããŸãã
ä¿®æ£: å¯èœãªå Žåã¯é¢é£ãããªãœãŒã¹ãåã AZ ã«é
眮ããããã³ã¹ããåãå
¥ããŸãã
ð Useful Links & Resourcesâ
Official AWS Documentationâ
Learning Resourcesâ
Toolsâ
-
Reachability Analyzer â ãªãœãŒã¹éã®æ¥ç¶åé¡ããããã°ãã
-
VPC Flow Logs â ãªãœãŒã¹ã«äœã®ãã©ãã£ãã¯ãåœãã£ãŠãããã確èª
ð Quick Reference Cardâ
VPC = ãã©ã€ããŒããããã¯ãŒã¯ (ç¡æ)
Subnet = ãããã¯ãŒã¯å
ã®ã«ãŒã (ç¡æ)
IGW = ã€ã³ã¿ãŒããããžã®ããã³ãã㢠(ç¡æ)
NAT GW = äžæ¹åã¢ãŠãããŠã³ãã㢠($$$)
Route Table = ãã©ãã£ãã¯æšè (ç¡æ)
Security Group = ãªãœãŒã¹ããšã®ããã£ã¬ãŒã (ç¡æãã¹ããŒããã«)
NACL = 建ç©ã®ã»ãã¥ãªãã£ã²ãŒã (ç¡æãã¹ããŒãã¬ã¹)
VPC Endpoint = AWS ãžã®å
éšãã³ãã« (S3/DynamoDB ã¯ç¡æ)
ãããªãã¯ãµãããã = IGW ãžã®ã«ãŒããã
ãã©ã€ããŒããµãããã = IGW ãžã®ã«ãŒããªã
ãããæåéãå¯äžã®éãã§ãã
æçµæŽæ°: 2026 幎 3 æ