VPC
AWS

VPC

1. Region, AZ(Availability Zone)

Region
- ์ „ ์„ธ๊ณ„์—์„œ ๋ฐ์ดํ„ฐ ์„ผํ„ฐ๋ฅผ ํด๋Ÿฌ์Šคํ„ฐ๋งํ•˜๋Š” ๋ฌผ๋ฆฌ์  ์œ„์น˜๋ฅผ Region, ๊ทธ ์ค‘ ๋…ผ๋ฆฌ์  ๋ฐ์ดํ„ฐ ์„ผํ„ฐ์˜ ๊ฐ ๊ทธ๋ฃน์„ AZ
- Region์€ ์—ฌ๋Ÿฌ ๊ฐœ์˜ AZ๋กœ ๊ตฌ์„ฑ
- ๊ฐ AZ๋Š” ๋…๋ฆฝ๋œ ์ „์›, ๋ƒ‰๊ฐ ๋ฐ ๋ฌผ๋ฆฌ์  ๋ณด์•ˆ์„ ๊ฐ–์ถ”๊ณ  ์žˆ์œผ๋ฉฐ ์ง€์—ฐ ์‹œ๊ฐ„์ด ๋งค์šฐ ์งง์€ ์ค‘๋ณต ๋„คํŠธ์›Œํฌ๋ฅผ ํ†ตํ•ด ์—ฐ๊ฒฐ
- 25๊ฐœ์˜ Region ์กด์žฌ(2021.07 ๊ธฐ์ค€)
- ์•„์‹œ์•„ ํƒœํ‰์–‘(์„œ์šธ) Region ์กด์žฌ


AZ
- AZ๋Š” AWS Region์˜ ์ค‘๋ณต ์ „๋ ฅ, ๋„คํŠธ์›Œํ‚น ๋ฐ ์—ฐ๊ฒฐ์ด ์ œ๊ณต๋˜๋Š” ํ•˜๋‚˜ ์ด์ƒ์˜ ๊ฐœ๋ณ„ ๋ฐ์ดํ„ฐ ์„ผํ„ฐ๋กœ ๊ตฌ์„ฑ
- ๋‹จ์ผ ๋ฐ์ดํ„ฐ ์„ผํ„ฐ๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ๋ณด๋‹ค ๋” ๋†’์€ ๊ฐ€์šฉ์„ฑ, ๋‚ด๊ฒฐํ•จ์„ฑ ๋ฐ ํ™•์žฅ์„ฑ์„ ๊ฐ–์ถ˜ ํ”„๋กœ๋•์…˜ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜๊ณผ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์šด์˜ ๊ฐ€๋Šฅ
- AWS Region์˜ ๋ชจ๋“  AZ๋Š” ๋†’์€ ๋Œ€์—ญํญ, ์ง€์—ฐ ์‹œ๊ฐ„์ด ์งง์€ ๋„คํŠธ์›Œํ‚น, ์™„์ „ํ•œ ์ค‘๋ณต์„ฑ์„ ๊ฐ–์ถ˜ ์ „์šฉ ๋ฉ”ํŠธ๋กœ ๊ด‘ ๋„คํŠธ์›Œํฌ์™€ ์ƒํ˜ธ ์—ฐ๊ฒฐ๋˜์–ด ์žˆ์–ด AZ ๊ฐ„์— ๋†’์€ ์ฒ˜๋ฆฌ๋Ÿ‰๊ณผ ์ง€์—ฐ ์‹œ๊ฐ„์ด ์งง์€ ๋„คํŠธ์›Œํ‚น์„ ์ œ๊ณต
- AZ ๊ฐ„์˜ ๋ชจ๋“  ํŠธ๋ž˜ํ”ฝ์€ ์•”ํ˜ธํ™”
- ์„œ๋น„์Šค์˜ ๊ณ ๊ฐ€์šฉ์„ฑ์„ ์œ„ํ•˜์—ฌ ๋‹ค์ค‘ AZ์— ์šด์˜ํ•  ์ˆ˜ ์žˆ์Œ
- ๋„คํŠธ์›Œํฌ ์„ฑ๋Šฅ์€ AZ ๊ฐ„ ๋™๊ธฐ ๋ณต์ œ ๊ธฐ๋Šฅ์„ ์ถฉ๋ถ„ํžˆ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ์Œ
- AZ๋Š” ๋‹ค๋ฅธ ๋ชจ๋“  AZ์™€ ์ˆ˜ ํ‚ฌ๋กœ๋ฏธํ„ฐ์— ์ƒ๋‹นํ•˜๋Š” ์œ ์˜๋ฏธํ•œ ๊ฑฐ๋ฆฌ๋ฅผ ๋‘๊ณ  ๋ฌผ๋ฆฌ์ ์œผ๋กœ ๋ถ„๋ฆฌ๋˜์–ด ์žˆ์œผ๋ฉฐ ๋ชจ๋“  AZ๋Š” ์„œ๋กœ 100km(60๋งˆ์ผ) ์ด๋‚ด์˜ ๊ฑฐ๋ฆฌ์— ์œ„์น˜
- ๋‹ค์ค‘ AZ์— ์šด์˜ํ•˜์—ฌ
- 81๊ฐœ์˜ AZ ์กด์žฌ(2021.07 ๊ธฐ์ค€)
- ์•„์‹œ์•„ ํƒœํ‰์–‘(์„œ์šธ) Region์— ap-northeast-2a/b/c/d AZ ์กด์žฌ

https://aws.amazon.com/ko/about-aws/global-infrastructure/?p=ngi&loc=1 

 

๊ธ€๋กœ๋ฒŒ ์ธํ”„๋ผ

AWS ๊ธ€๋กœ๋ฒŒ ์ธํ”„๋ผ ๋งต AWS ํด๋ผ์šฐ๋“œ๋Š” ์ „ ์„ธ๊ณ„ 25๊ฐœ์˜ ์ง€๋ฆฌ์  ๋ฆฌ์ „ ๋‚ด 81๊ฐœ์˜ ๊ฐ€์šฉ ์˜์—ญ์„ ์šด์˜ํ•˜๊ณ  ์žˆ์œผ๋ฉฐ, ์•ž์œผ๋กœ ํ˜ธ์ฃผ, ์ธ๋„, ์ธ๋„๋„ค์‹œ์•„, ์ด์Šค๋ผ์—˜, ์ŠคํŽ˜์ธ, ์Šค์œ„์Šค ๋ฐ ์•„๋ž์—๋ฏธ๋ฆฌํŠธ(UAE)์— 7๊ฐœ์˜

aws.amazon.com

 

2. VPC(Virtual Private Cluoud)

Region์— ์ƒ์„ฑํ•˜๋Š” ๋ถ„๋ฆฌ๋œ ๊ฐ€์ƒ ๋„คํŠธ์›Œํฌ ๋ง
์„ค์ • ๊ฐ€๋Šฅํ•œ ๋„คํŠธ์›Œํฌ ๋Œ€์—ญ(CIDR)
- 10.0.0.0/8(10.0.0.0 – 10.255.255.255)
- 172.16.0.0/12(172.16.0.0 – 172.31.255.255)
- 192.168.0.0/16(192.168.0.0 – 192.168.255.255)

VPC ์•ˆ์— CIDR์„ ๋‚˜๋ˆ  ๋ชฉ์ ์— ๋”ฐ๋ผ AZ์— Subnet ์ƒ์„ฑ

Instance(EC2, ๊ฐ€์ƒ ์„œ๋ฒ„)๋ฅผ ์ƒ์„ฑํ•  ๋•Œ ์ƒ์„ฑํ•  VPC&Subnet ์ง€์ •

VPC ๋‚ด๋ถ€๋Š” ํ†ต์‹  ๊ฐ€๋Šฅํ•˜์ง€๋งŒ VPC ๊ฐ„์€ ํ†ต์‹  ๋ถˆ๊ฐ€๋Šฅ(VPC Peering, Transit Gateway ๋“ฑ ์ถ”๊ฐ€ ์„œ๋น„์Šค ์‚ฌ์šฉ ํ•„์š”)

https://aws.amazon.com/ko/vpc/?vpc-blogs.sort-by=item.additionalFields.createdDate&vpc-blogs.sort-order=desc 

 

VPC Cloud VPSํ˜ธ์ŠคํŒ… | ๊ฐ€์ƒ ํ˜ธ์ŠคํŒ… | Amazon Web Services

VPC๋ฅผ ๊ธฐ์—… ๋„คํŠธ์›Œํฌ์— ์—ฐ๊ฒฐํ•˜์—ฌ ๊ธฐ์—… ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ํด๋ผ์šฐ๋“œ๋กœ ์ด์ „ํ•˜๊ฑฐ๋‚˜, ์ถ”๊ฐ€ ์›น ์„œ๋ฒ„๋ฅผ ์‹คํ–‰ํ•˜๊ฑฐ๋‚˜, ๋„คํŠธ์›Œํฌ์— ์ปดํ“จํŒ… ํŒŒ์›Œ๋ฅผ ์ถ”๊ฐ€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. VPC๋Š” ๊ธฐ์—… ๋ฐฉํ™”๋ฒฝ ๋’ค์—์„œ ํ˜ธ์ŠคํŒ…๋ 

aws.amazon.com

 

3. Public Subnet

Destination์ด 0.0.0.0/0์ผ ๊ฒฝ์šฐ Internet Gateway๋กœ ๋ผ์šฐํŒ…ํ•˜์—ฌ ์ธํ„ฐ๋„ท์— ์ ‘์† ๊ฐ€๋Šฅํ•œ Subnet

Public Subnet ๋‚ด์— Instance๋ฅผ ์ƒ์„ฑํ•  ๊ฒฝ์šฐ ๊ณต์ธ IP๋ฅผ ํ• ๋‹นํ•˜์—ฌ ์‚ฌ์šฉ์ž๊ฐ€ Instance์— ์ ‘์†ํ•  ์ˆ˜ ์žˆ์Œ

 

4. Private Subnet

์ธํ„ฐ๋„ท์— ์ ‘์† ๋ถˆ๊ฐ€๋Šฅํ•œ Subnet

Private Subnet ๋‚ด์— Instance๋ฅผ ์ƒ์„ฑํ•  ๊ฒฝ์šฐ ์‚ฌ์šฉ์ž๊ฐ€ ์ ‘์†ํ•  ์ˆ˜ ์—†์Œ(VPC ๋‚ด๋ถ€๋Š” ํ†ต์‹  ๊ฐ€๋Šฅ, Public Subnet์„ ํ†ตํ•ด ์ ‘์† ๊ฐ€๋Šฅ)

์ธํ„ฐ๋„ท ์ ‘์†์ด ํ•„์š”ํ•  ๊ฒฝ์šฐ Public Subnet์— NAT Gateway or NAT Instance/Bastion Host๋ฅผ ๋‘๊ณ  ์ธํ„ฐ๋„ท ์ ‘์† ๊ฐ€๋Šฅํ•˜๋„๋ก ํ•  ์ˆ˜ ์žˆ์Œ

- NAT Gateway ์‚ฌ์šฉ : Private Subnet > NAT Gateway(Public Subnet) > Internet Gateway > ์ธํ„ฐ๋„ท

- Bastion Host ์‚ฌ์šฉ : Private Subnet > NAT Instance/Bastion Host(Public Subnet) > Internet Gateway > ์ธํ„ฐ๋„ท

 

5. Route Table

Subnet์— ์„ค์ •

VPC CIDR Destination์ด Local๋กœ ์ž๋™ ์„ค์ •๋˜์–ด VPC ๋‚ด๋ถ€ ํ†ต์‹  ๊ฐ€๋Šฅ

๊ทธ ์™ธ ๋ชฉ์ ์— ๋”ฐ๋ผ Destination์„ ์ง€์ • ์—ฐ๊ฒฐ Gateway(Internet Gateway, NAT Gateway, Transit Gateway, VPN Gateway, Endpoint ๋“ฑ) ์„ค์ •

 

6. NACL(Network Access Control List)

Subnet์— ์„ค์ •

Stateless ๋ฐฉ์‹(์ƒํƒœ ๋น„์ €์žฅํ•˜์—ฌ Inbound/Outbound ๊ทœ์น™์„ ๋ณ„๋„๋กœ ์ ์šฉ ๋ฐ›์Œ)

Allow/Deny ๊ทœ์น™ ์žˆ์Œ

Top Down์œผ๋กœ ๊ทœ์น™ ํ™•์ธ(๊ทœ์น™์ด ํ™•์ธ๋˜๋ฉด ์•„๋ž˜ ๊ทœ์น™์€ ํ™•์ธํ•˜์ง€ ์•Š์Œ)

Subnet์—์„œ ํ—ˆ์šฉ/์ฐจ๋‹จ์ด ํ•„์š”ํ•œ Inbount/Outbount์˜ Type๊ณผ Protocol/Port๋ฅผ ์„ค์ •

 

7. SG(Securirty Group)

Instance์— ์„ค์ •

Stateful ๋ฐฉ์‹(์ƒํƒœ ์ €์žฅํ•˜์—ฌ Inbound/Outbound ๊ทœ์น™์„ ์ตœ์ดˆ๋งŒ ์ ์šฉ ๋ฐ›์Œ)

Allow ๊ทœ์น™๋งŒ ์žˆ์Œ

๋ชจ๋“  ๊ทœ์น™์„ ํ™•์ธ

Instance์—์„œ ํ—ˆ์šฉ์ด ํ•„์š”ํ•œ Inbount/Outbount์˜ Type๊ณผ Protocol/Port๋ฅผ ์„ค์ •

Inbound๋Š” Instance์— ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•ด SSH Port(web service๊ฐ€ ์˜ฌ๋ผ์™€์žˆ๋‹ค๋ฉด http/https๋„ ์—ด์–ด์ค˜์•ผ ํ•จ)
Outbound๋Š” ์ธํ„ฐ๋„ท ์ ‘์†์ด ํ•„์š”ํ•˜๊ธฐ ๋•Œ๋ฌธ์— All