QueryPie Community Edition is live ๐ŸŽ‰ Get it now for free Download today!

๋ฌด๋ฃŒ๋กœ ์‹œ์ž‘ํ•˜๊ธฐ
ACP ๊ธฐ๋Šฅ

์‚ฌ์šฉ์ž ์—ญํ•  ๊ธฐ๋ฐ˜์˜ ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•˜๋Š” ๋ฐฉ๋ฒ•

์‚ฌ์šฉ์ž ์—ญํ•  ๊ธฐ๋ฐ˜์˜ ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•˜๋Š” ๋ฐฉ๋ฒ•

2024๋…„ 11์›” 29์ผ

์‚ฌ์šฉ์ž ์—ญํ•  ๊ธฐ๋ฐ˜์˜ ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•˜๋Š” ๋ฐฉ๋ฒ•

Overview

์„œ๋ฒ„์˜ ์ ‘๊ทผ ์ •์ฑ…(Policy)์€ IaC์™€ ๊ฐ™์€ ํ˜•ํƒœ๋กœ YAML Code๋ฅผ ๋ฒ ์ด์Šค๋กœ ๋™์ž‘ํ•ฉ๋‹ˆ๋‹ค. ์ ‘์†์„ ํ—ˆ์šฉํ•  ์š”์ผ ๋ฐ ์‹œ๊ฐ„์„ ์„ค์ •ํ•  ์ˆ˜ ์žˆ์„ ๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ์ ‘์† ๊ฐ€๋Šฅํ•œ IP ์ฃผ์†Œ ์„ค์ • ๋ฐ Audit ์—ฌ๋ถ€, Agent ์‚ฌ์šฉ ๊ฐ€๋Šฅ ์—ฌ๋ถ€๋ฅผ ์„ค์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ ์™ธ ์œ ์ €๋ณ„ ํ—ˆ์šฉ ์„ธ์…˜ ์ˆ˜ ๋˜ํ•œ ์„ค์ •์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. ์„œ๋ฒ„์— ๋Œ€ํ•œ ์‚ฌ์šฉ์ž ์•ก์„ธ์Šค๋ฅผ ํ—ˆ์šฉํ•˜๊ฑฐ๋‚˜ ์ œํ•œํ•˜๊ธฐ ์œ„ํ•ด ์กฐ์ง ๋‚ด์—์„œ์˜ ์‚ฌ์šฉ์ž ์—ญํ• ์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•˜๋Š” ์—ญํ•  ๊ธฐ๋ฐ˜ ์•ก์„ธ์Šค ์ œ์–ด(Role-Based Access Control, RBAC)๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. Role์€ ์—ฌ๋Ÿฌ ์ •์ฑ…์„ ์ข…ํ•ฉํ•˜์—ฌ ๋‹จ์ผ ์—ญํ• ๋กœ ์ •์˜ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋˜๋ฉฐ, ๊ด€๋ฆฌ์ž๋Š” ์‚ฌ์šฉ์ž ๋˜๋Š” ์‚ฌ์šฉ์ž ๊ทธ๋ฃน์— ์—ญํ• (Role)์„ ๋ถ€์—ฌํ•˜๊ฑฐ๋‚˜ ํšŒ์ˆ˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์„œ๋ฒ„ ์ •์ฑ… ๊ตฌ์„ฑํ•˜๊ธฐ

STEP 1 Policies ๋ฉ”๋‰ด์—์„œ Create Policy ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜์—ฌ ์ •์ฑ…์„ ๋“ฑ๋กํ•ฉ๋‹ˆ๋‹ค.

  • Name: ์ •์ฑ…์„ ๊ตฌ๋ถ„ํ•  ์ˆ˜ ์žˆ๋Š” ์ด๋ฆ„
  • Description: ํ•ด๋‹น ์ •์ฑ…์— ๋Œ€ํ•œ ์„ธ๋ถ€ ์ •๋ณด

STEP 2 ์ƒ์„ฑ๋œ ์ •์ฑ…์„ ์„ ํƒํ•˜๊ณ , Go to Editor Mode ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜์—ฌ ์ดํ•˜์˜ ๋ฐฉ๋ฒ•์œผ๋กœ ์ •์ฑ… ๋‚ด์šฉ์„ ์ˆ˜์ •ํ•ฉ๋‹ˆ๋‹ค.

  • ์šฐ์ธก์˜ ๋ฒ„ํŠผ์„ ํ†ตํ•ด ์ฝ”๋“œ์— ๋‚ด์šฉ์„ ์‚ฝ์ž… ๋˜๋Š” ์ˆ˜์ •ํ•ฉ๋‹ˆ๋‹ค.
    • Add Resource: ์„œ๋ฒ„ ๊ทธ๋ฃน๊ณผ ๊ณ„์ •์„ ์„ ํƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
    • Add Actions: ํ—ˆ์šฉํ•  ํ”„๋กœํ† ์ฝœ๊ณผ ๋ช…๋ น์–ด ํ…œํ”Œ๋ฆฟ์„ ์„ ํƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • ์ฝ”๋“œ ์—๋””ํ„ฐ ํ™”๋ฉด์—์„œ ์ฝ”๋“œ๋ฅผ ์ง์ ‘ ์ˆ˜์ •ํ•ฉ๋‹ˆ๋‹ค.
    • ํ•˜๋‹จ์˜ Errors ํƒญ์„ ํ†ตํ•ด ์ง์ ‘ ์ˆ˜์ •ํ•œ ์ฝ”๋“œ์˜ ์˜ค๋ฅ˜๋ฅผ ๋””๋ฒ„๊น…ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

STEP 3 ์ ‘๊ทผ ์ •์ฑ… ์ •์˜๊ฐ€ ์™„๋ฃŒ๋˜๋ฉด ์šฐ์ธก ์ƒ๋‹จ์— ํ™œ์„ฑํ™”๋œ Save ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜์—ฌ ์ •์ฑ…์„ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

์—ญํ• (Role) ์ƒ์„ฑํ•˜๊ธฐ

STEP 1 Roles ๋ฉ”๋‰ด์—์„œ Create Role ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜์—ฌ ์—ญํ• ์„ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค.

  • Name: ์—ญํ• ์„ ๊ตฌ๋ถ„ํ•  ์ˆ˜ ์žˆ๋Š” ์ด๋ฆ„
  • Description: ํ•ด๋‹น ์—ญํ• ์— ๋Œ€ํ•œ ์„ธ๋ถ€ ์ •๋ณด

STEP 2 ์ƒ์„ฑํ•œ ์—ญํ• ์„ ์„ ํƒํ•˜์—ฌ Assgin Policies ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜๊ณ  1๊ฐœ ์ด์ƒ์˜ Policy๋ฅผ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

  • Users/Groups: ํ•ด๋‹น Role์ด ๋ถ€์—ฌ๋˜์–ด์žˆ๋Š” ์‚ฌ์šฉ์ž/๊ทธ๋ฃน ๋ชฉ๋ก์„ ๋‚˜์—ดํ•ฉ๋‹ˆ๋‹ค.
  • Servers: ํ•ด๋‹น ์—ญํ• ์— ์˜ํ•ด ์ ‘๊ทผ ๊ฐ€๋Šฅํ•œ ์„œ๋ฒ„ ๋ชฉ๋ก์„ ๋‚˜์—ดํ•ฉ๋‹ˆ๋‹ค.

์—ญํ• (Role) ๋ถ€์—ฌํ•˜๊ธฐ

STEP 1 Access Control ๋ฉ”๋‰ด์—์„œ ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•  ์‚ฌ์šฉ์ž ํ˜น์€ ๊ทธ๋ฃน์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.

STEP 2 Roles ํƒญ์œผ๋กœ ์ด๋™ํ•˜์—ฌ ์šฐ์ธก Grant Roles ๋ฒ„ํŠผ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

STEP 3 ๋ถ€์—ฌํ•  1๊ฐœ ์ด์ƒ์˜ Role์˜ ์ฒดํฌ๋ฐ•์Šค๋ฅผ ์„ ํƒํ•˜๊ณ , ๋งŒ๋ฃŒ์ผ์„ ์ง€์ •ํ•ฉ๋‹ˆ๋‹ค.

STEP 4 Grant ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜์—ฌ ์ตœ์ข…์ ์œผ๋กœ Role์„ ๋ถ€์—ฌํ•ฉ๋‹ˆ๋‹ค.

์‚ฌ์šฉ์ž ์—ญํ•  ๊ธฐ๋ฐ˜์˜ ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•˜๋Š” ๋ฐฉ๋ฒ• | QueryPie