Skip to main content

16A. IAM ๊ทธ๋ฃน ์ƒ์„ฑํ•˜๊ธฐ

2024๋…„ 4์›” 24์ผLess than 1 minuteAWScrashcoursepyrasisawsamazon-web-services

16A. IAM ๊ทธ๋ฃน ์ƒ์„ฑํ•˜๊ธฐ ๊ด€๋ จ

๋ชฉ์ฐจ

์•„๋งˆ์กด ์›น ์„œ๋น„์Šค๋ฅผ ๋‹ค๋ฃจ๋Š” ๊ธฐ์ˆ 

16์žฅ - 1. IAM ๊ทธ๋ฃน ์ƒ์„ฑํ•˜๊ธฐ

์•„๋งˆ์กด ์›น ์„œ๋น„์Šค๋ฅผ ๋‹ค๋ฃจ๋Š” ๊ธฐ์ˆ 

IAM ๊ทธ๋ฃน์€ ์ด๋ฆ„ ๊ทธ๋Œ€๋กœ IAM ์‚ฌ์šฉ์ž๋“ค์„ ๋ชจ์•„๋†“์€ ๊ฒƒ์ž…๋‹ˆ๋‹ค. IAM ๊ทธ๋ฃน์— ์ ‘๊ทผ์ œ์–ด ๋ฐ ๊ถŒํ•œ์„ค์ •์„ ํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ IAM ๊ทธ๋ฃน์— ์„ค์ •๋œ ๋‚ด์šฉ์€ IAM ๊ทธ๋ฃน ์•ˆ์— ํฌํ•จ๋œ ๋ชจ๋“  ์‚ฌ์šฉ์ž๋“ค์—๊ฒŒ ์ ์šฉ๋ฉ๋‹ˆ๋‹ค.

EC2 ์ธ์Šคํ„ด์Šค๋งŒ ์ œ์–ดํ•  ์ˆ˜ ์žˆ๋Š” IAM ๊ทธ๋ฃน์„ ์ƒ์„ฑํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

AWS ์ฝ˜์†”๋กœ ์ ‘์†ํ•œ ๋’ค ๋ฉ”์ธ ํ™”๋ฉด์—์„œ Deployment & Management์˜ <FontIcon icon="iconfont icon-select"/>์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
AWS ์ฝ˜์†”๋กœ ์ ‘์†ํ•œ ๋’ค ๋ฉ”์ธ ํ™”๋ฉด์—์„œ Deployment & Management์˜ [IAM]์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
IAM ๊ทธ๋ฃน ๋ชฉ๋ก(<FontIcon icon="iconfont icon-select"/> โ†’ )์—์„œ ์œ„์ชฝ <FontIcon icon="iconfont icon-select"/> ๋ฒ„ํŠผ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
IAM ๊ทธ๋ฃน ๋ชฉ๋ก([Details] โ†’ [Groups])์—์„œ ์œ„์ชฝ [Create New Group] ๋ฒ„ํŠผ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

IAM ๊ทธ๋ฃน ์ด๋ฆ„์„ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.

Group Name์— ์„ ์ž…๋ ฅํ•˜๊ณ  <FontIcon icon="iconfont icon-select"/> ๋ฒ„ํŠผ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
Group Name์— EC2Admin์„ ์ž…๋ ฅํ•˜๊ณ  [Next Step] ๋ฒ„ํŠผ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

IAM ๊ทธ๋ฃน์— ๊ถŒํ•œ์„ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. Select Policy Template์—๋Š” AWS์˜ ๋ชจ๋“  ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•œ ์ ‘๊ทผ ๊ถŒํ•œ์„ Full Access, Read Only Access, ๊ธฐํƒ€ Access๋กœ ๊ตฌ๋ถ„ํ•˜์—ฌ ์ค€๋น„ํ•ด๋†“์•˜์Šต๋‹ˆ๋‹ค. ๊ฐœ์ˆ˜๊ฐ€ ์ƒ๋‹นํžˆ ๋งŽ์œผ๋ฏ€๋กœ ์Šคํฌ๋กค์„ ๋‚ด๋ ค Amazon EC2 Full Access์˜ [Select] ๋ฒ„ํŠผ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

AWS Policy Generator๋‚˜ ์ง์ ‘ ์ •์ฑ…Custom Policy์„ ์ž‘์„ฑํ•˜์—ฌ ์„ค์ •ํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค.

IAM ๊ทธ๋ฃน ๊ถŒํ•œ์„ค์ •
IAM ๊ทธ๋ฃน ๊ถŒํ•œ์„ค์ •

EC2์—๋งŒ ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ด์ฃผ๋Š” ์ •์ฑ… ํŒŒ์ผPolicy Document์ด ์ž๋™์œผ๋กœ ์ƒ์„ฑ๋ฉ๋‹ˆ๋‹ค.

<FontIcon icon="iconfont icon-select"/> ๋ฒ„ํŠผ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
[Next Step] ๋ฒ„ํŠผ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

์ง€๊ธˆ๊นŒ์ง€ ์„ค์ •ํ•œ ๋‚ด์šฉ์— ์ด์ƒ์ด ์—†๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

์ด์ƒ์ด ์—†์œผ๋ฉด <FontIcon icon="iconfont icon-select"/> ๋ฒ„ํŠผ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
์ด์ƒ์ด ์—†์œผ๋ฉด [Create Group] ๋ฒ„ํŠผ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

IAM ๊ทธ๋ฃน ๋ชฉ๋ก์— IAM ๊ทธ๋ฃน(EC2Admin)์ด ์ƒ์„ฑ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

์ด IAM ๊ทธ๋ฃน ์•ˆ์— ์†ํ•œ IAM ์‚ฌ์šฉ์ž๋Š” EC2 ์ธ์Šคํ„ด์Šค๋งŒ ์ œ์–ดํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
์ด IAM ๊ทธ๋ฃน ์•ˆ์— ์†ํ•œ IAM ์‚ฌ์šฉ์ž๋Š” EC2 ์ธ์Šคํ„ด์Šค๋งŒ ์ œ์–ดํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.