AWS

AWS ๋„คํŠธ์›Œํฌ ์„œ๋น„์Šค ์†Œ๊ฐœ ๋ฐ ์‚ฌ์šฉ ๋ฐฉ๋ฒ•(200)

1. AWS ๋„คํŠธ์›Œํ‚น ์„œ๋น„์Šค

 

- ์ฐธ๊ณ  : https://aws.amazon.com/ko/vpc/?nc2=type_a

 

VPC Cloud VPSํ˜ธ์ŠคํŒ… | ๊ฐ€์ƒ ํ˜ธ์ŠคํŒ… | Amazon Web Services

IP ์ฃผ์†Œ ๋ฒ”์œ„ ์„ ํƒ, ์„œ๋ธŒ๋„ท ์ƒ์„ฑ, ๋ผ์šฐํŒ… ํ…Œ์ด๋ธ”๊ณผ ๋„คํŠธ์›Œํฌ ๊ฒŒ์ดํŠธ์›จ์ด ๊ตฌ์„ฑ ๋“ฑ ๊ฐ€์ƒ ๋„คํŠธ์›Œํ‚น ํ™˜๊ฒฝ์„ ์ œ์–ดํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ธํ„ฐ๋„ท์— ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ๋Š” ์›น ์„œ๋ฒ„๋ฅผ ์œ„ํ•ด ํผ๋ธ”๋ฆญ ์„œ๋ธŒ๋„ท์„ ์ƒ์„ฑํ•˜๏ฟฝ๏ฟฝ

aws.amazon.com

- VPC : AWS ํด๋ผ์šฐ๋“œ์— ๋งŒ๋“œ๋Š” ๊ฐ€์ƒ์˜ ๋ฐ์ดํ„ฐ์„ผํ„ฐ

- VPN : on-premise ๋ฐ์ดํ„ฐ ์„ผํ„ฐ์™€ VPC์˜ IPsec VPN ์—ฐ๊ฒฐ

- Direct Connect : on-premise ๋ฐ์ดํ„ฐ ์„ผํ„ฐ์™€ VPC์˜ ์ „์šฉ์„  ์—ฐ๊ฒฐ

- ELB : ๊ด€๋ฆฌํ˜• Load Balancer ์„œ๋น„์Šค

- Route53 :  ๊ด€๋ฆฌํ˜• DNS ์„œ๋น„์Šค

 

2. VPC(Virtual Private Cloud)

  . ์‚ฌ์šฉ์ž๊ฐ€ ์ •์˜ํ•œ ๊ฐ€์ƒ์˜ ๋„คํŠธ์›Œํฌ ํ™˜๊ฒฝ(๋…ผ๋ฆฌ์  ๊ฒฉ๋ฆฌ)

  . ์‚ฌ์šฉ์ž ๋ณ„ ๋„คํŠธ์›Œํฌ ์ œ์–ด ๊ฐ€๋Šฅ

  . on-premise ๋ฐ์ดํ„ฐ ์„ผํ„ฐ์™€ ์—ฐ๊ฒฐ ์˜ต์…˜

  . Region, IP ๋Œ€์—ญ ์„ค์ • 

  . AZ์— Subnet ์ƒ์„ฑ(AZ ๋‚ด๋ถ€๋Š” ์ดˆ๊ณ ์† ๋„คํŠธ์›Œํฌ๋กœ ์—ฐ๊ฒฐ)

  . Routing ์„ค์ •

  . Traffic ํ†ต์ œ

 

- Subnet(CIDR)

  . VPC ํ™•์žฅ ์‹œ๋‚˜๋ฆฌ์˜ค ๊ณ ๋ ค

  . /16 ~ /28(ip ์ฃผ์†Œ 18๊ฐœ)๊นŒ์ง€ ๊ฐ€๋Šฅ

  . ์ƒ์„ฑ ํ›„ ๋ณ€๊ฒฝ ๋ถˆ๊ฐ€

  . 10.0.0.0 : ๋„คํŠธ์›Œํฌ ์ฃผ์†Œ

  . 10.0.0.1 : VPC ๋ผ์šฐํ„ฐ์šฉ์œผ๋กœ ์˜ˆ์•ฝ๋œ ์ฃผ์†Œ

  . 10.0.0.2 : AWS์—์„œ ์˜ˆ์•ฝํ•œ DNS ์ฃผ์†Œ, AmazonProvided DNS

  . 10.0.0.3 : AWS์—์„œ ํ–ฅํ›„ ์‚ฌ์šฉ์„ ์œ„ํ•ด ์˜ˆ์•ฝ

  . 10.0.0.255 : ๋ธŒ๋กœ๋“œ์บ์ŠคํŠธ ์ฃผ์†Œ, VPC์—์„œ๋Š” ๋ธŒ๋กœ๋“œ์บ์ŠคํŠธ๋ฅผ ์ง€์›ํ•˜์ง€ ์•Š์œผ๋ฉฐ AWS์—์„œ ์˜ˆ์•ฝ

  . ์ž๋™์œผ๋กœ main route table ์ƒ์„ฑ ๋จ(๋ชจ๋“  subnet๋ผ๋ฆฌ ํ†ต์‹  ๊ฐ€๋Šฅํ•˜๋ฉฐ ์ถ”๊ฐ€ ๊ฐ€๋Šฅ)

 

- Route Table

  . subnet ๋‹จ์œ„ ๋ผ์šฐํŒ… ํ†ต์ œ

 

- Network ACL

  . subnet ๋‹จ์œ„

  . stateless ๋ฐฉํ™”๋ฒฝ

  . allow/deny

  . rule # ordering

 

- Security Group

  . ์ธ์Šคํ„ด์Šค ๋‹จ์œ„

  . stateful ๋ฐฉํ™”๋ฒฝ

  . allow only

 

3. VPC ํ™•์žฅ : Internet

 

- VPC Internet Gateway(only 1๊ฐœ)

  . Public VPC <-> Internet

  . 1:1 NAT(Public IP or EIP ํ•„์š”)

  . IPv4, IPv6 ์ง€์›

 

- VPC NAT Gateway(AWS๊ฐ€ ์™„์ „ํžˆ ๊ด€๋ฆฌ)

  . Private VPC <-> Internet

  . Private subnet์— path, update, download ๋ชฉ์ ์œผ๋กœ ๊ตฌ์„ฑ

  . 1:1 NAT(EIP ํ•„์š”)

  . Security group ์ ์šฉ ๋ถˆ๊ฐ€

 

- EIP

  . ์œ ๋™ public ip๊ฐ€ ์•„๋‹Œ ๊ณ ์ •๋œ ip 

  . ํ•˜๋‚˜์˜ ๋ฆฌ์ „๋‹น 5๊ฐœ์˜ ELP ๊ฐ€๋Šฅ(์ถ”๊ฐ€ ๊ฐ€๋Šฅ)

 

4. VPC ํ™•์žฅ : on-premise

 

- VPN Gateway : Ipsec site to site vpn์„ ํ†ตํ•ด ์•”ํ˜ธํ™” ํ„ฐ๋„ ๊ตฌ์„ฑ, ์ด์ค‘ํ™”

- AWS Direct Gateway : ์ „์šฉํšŒ์„ ์„ ํ†ตํ•˜์—ฌ ๊ณ ๊ฐ์‚ฌ์™€ ์ง์ ‘ ์—ฐ๊ฒฐ(Direct Connect)

 

5. VPC ํ™•์žฅ : other AWS Regions

 

- VPC๊ฐ„ ํ•˜๋‚˜๋งŒ ์ œ๊ณตํ•˜๋ฉฐ ip๊ฐ€ ์ค‘๋ณต๋˜๋ฉด ์•ˆ๋จ

- ๋™์ผ region ๋‚ด VPC๊ฐ„ ์™„์ „ํžˆ ๊ฒฉ๋ฆฌ๋œ ์—ฐ๊ฒฐ

- Routing table์„ ํ†ตํ•ด ํ†ต์ œ ๊ฐ€๋Šฅํ•˜์ง€๋งŒ Trnst routing์€ ์ œ๊ณตํ•˜์ง€ ์•Š์Œ

 

- VPC Endpoints - Gateway Type

  . ์ธํ„ฐ๋„ท์„ ๊ฒฝ์œ ํ•˜์ง€์•Š๊ณ  EC2, S3, DynamoDB ์—ฐ๊ฒฐ

  . ๋‹ค์–‘ํ•œ ์ ‘๊ทผ ์ œ์–ด ์ •์ฑ… ์ ์šฉ(Route table, VPC Endpoint policy, S3 Bucket policy, Security group with profix list)

 

- VPC Private Link VPC Endpoints - Interface Type

  . Private Link๋ฅผ ํ†ตํ•ด ์—ฐ๊ฒฐ(๋น„๊ณต๊ฐœ)

  . ๋‹ค๋ฅธ AWS ๊ณ„์ •์—์„œ ํ˜ธ์ŠคํŒ…๋œ VPC Endpoint service๋‚˜  AWS Marketplace ํŒŒํŠธ๋„ˆ ์„œ๋น„์Šค์˜ VPC๋ฅผ ๋น„๊ณต๊ฐœ๋กœ ์—ฐ๊ฒฐ

  . IGW, NAT Gateway, Pulic IP, DX ๋ถˆํ•„์š”

  . ์ค‘์•™ํ™”๋œ Internal service(DB, ๋กœ๊น…, ๋ชจ๋‹ˆํ„ฐ๋ง), microservice , SaaS์— ์‚ฌ์šฉ

 

6. VPC ๊ด€๋ฆฌ : VPC Flow Logs

 

- network packet ์ˆ˜์ง‘

- cloudwatch logs group์— ๊ธฐ๋ก(10-15๋ถ„ ์ง€์—ฐ)

- ์ผ๋ถ€ ์ˆ˜์ง‘๋˜์ง€ ์•Š๋Š” ๋กœ๊ทธ๋“ค์ด ์žˆ์Œ(dns, dhcp, windows license ๋“ฑ)

 

7. Direct Connect

 

- ๊ณ ๊ฐ ์ „์šฉ์˜ 1Gbps ๋˜๋Š” 10Gbps Fiber Cross Connect

- DX connect๋‹น ์ตœ๋Œ€ 50๊ฐœ์˜ ๊ฐ€์ƒ ์ธํ„ฐํŽ˜์ด์Šค(public and private) ์ƒ์„ฑ ๋ฐ ์—ฐ๊ฒฐ ๊ฐ€๋Šฅ

- ๊ณ ๊ฐ์˜ on-premise network์™€ VPC ์ง์ ‘ ์—ฐ๊ฒฐ

 - VPN ๋Œ€๋น„ ๋‚ฎ์€ ์ง€์—ฐ๊ณผ ์ง€์†์ ์ด๊ณ  ์˜ˆ์ธก ๊ฐ€๋Šฅํ•œ ์„ฑ๋Šฅ ๋ณด์žฅ

 - ๋‚ฎ์€ ํŠธ๋ž˜ํ”ฝ ์š”๊ธˆ(VPN, Internet ๋Œ€๋น„)

 

- Public, Private VIF(Virtual Interface)

  . Public VIF : on-premise์™€ VPC ์—ฐ๊ฒฐํ•˜๊ธฐ ์œ„ํ•œ ์šฉ๋„, BGP ๊ตฌ์„ฑ์‹œ, Private ASN ์‚ฌ์šฉ ๊ฐ€๋Šฅ

  . Private VIF : on-premise์™€ Public AWS ์„œ๋น„์Šค(S3, DynamoDB ๋“ฑ)์— ์ง์ ‘ ์—ฐ๊ฒฐํ•˜๊ธฐ ์œ„ํ•œ ์šฉ๋„, BGP ๊ตฌ์„ฑ์‹œ ๊ณ ๊ฐ์˜ Public ASN ํ•„์š”

- Site ์ด์ค‘ํ™” ๊ตฌ์„ฑ ๊ฐ€๋Šฅ

. ํ•˜๋‚˜์˜ DX location์— ๋‹ค์ˆ˜์˜ DX location์„ ๊ตฌ์„ฑํ•œ ๊ฒฝ์šฐ ๋ฌผ๋ฆฌ์ ์ธ H/W(Router)์— ๋Œ€ํ•œ ๋ถ„๋ฆฌ ๊ฐ€๋Šฅ

 

8. Transit gateway

 

- VPC์™€ on-premise ๋ฐ์ดํ„ฐ์„ผํ„ฐ์˜ interconnect ์ง€์›

- ์‹ฌํ”Œํ•œ ๋„คํŠธ์›Œํฌ ํ† ํด๋กœ์ง€ ๊ตฌํ˜„์œผ๋กœ ๊ด€๋ฆฌ ๋ถ€๋‹ด ๊ฒฝ๊ฐ

- VPN, Direct connect์™€ ๋‹จ์ผ ์ ‘์ 

- on-premise ๋ฐ์ดํ„ฐ์„ผํ„ฐ์™€ VPN ์—ฐ๊ฒฐ ์‹œ ECMP ์ง€์›์œผ๋กœ 50Gbps+ ๋Œ€์—ญํญ ๊ฐ€๋Šฅ

- ๋ชจ๋‹ˆํ„ฐ๋ง ๊ฐ€๋Šฅ

- ๋ผ์šฐํŒ… ๋„๋ฉ”์ธ ๋ณ„ ๋…ผ๋ฆฌ์ ์ธ ๋„คํŠธ์›Œํฌ ๋ถ„๋ฆฌ

 

9. Elastic Load Balancing(ELB)

 

- ์ฐธ๊ณ  : https://aws.amazon.com/ko/elasticloadbalancing/?nc=sn&loc=0

 

์›น ์„œ๋ฒ„ ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ | ์„œ๋ฒ„ ๋กœ๋“œ ๋ฐธ๋Ÿฐ์‹ฑ | Amazon Web Services

Elastic Load Balancing์€ ๋“ค์–ด์˜ค๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ํŠธ๋ž˜ํ”ฝ์„ Amazon EC2 ์ธ์Šคํ„ด์Šค, ์ปจํ…Œ์ด๋„ˆ, IP ์ฃผ์†Œ, Lambda ํ•จ์ˆ˜์™€ ๊ฐ™์€ ์—ฌ๋Ÿฌ ๋Œ€์ƒ์— ์ž๋™์œผ๋กœ ๋ถ„์‚ฐ์‹œํ‚ต๋‹ˆ๋‹ค. Elastic Load Balancing์€ ๋‹จ์ผ ๊ฐ€์šฉ ์˜์—ญ ๋˜๋Š” ์—ฌ๋Ÿฌ

aws.amazon.com

- ๋ฆฌ์ „ ๋‚ด load balancing service

- ๋‹ค์ˆ˜์˜ ๊ฐ€์šฉ์˜์—ญ์œผ๋กœ ํŠธ๋ž˜ํ”ฝ ๋ถ„๋ฐฐ

- ํ—ฌ์Šค ์ฒดํฌ

- ์˜คํ†  ์Šค์ผ€์ผ๋ง๊ณผ ์—ฐ๋™ ๊ฐ€๋Šฅ

- IP๊ฐ€ ๋ณ€๊ฒฝ๋˜๊ธฐ ๋•Œ๋ฌธ์— DNS Name ์‚ฌ์šฉ ๊ถŒ์žฅ(but ๊ณ ์ • IP ์‚ฌ์šฉ ๊ฐ€๋Šฅ)

- TLS Termination ๊ฐ€๋Šฅ

 

- Application Load Balancer

  . HTTP, HTTPS, HTTP2, WebSockets ์ง€์›

  . L7

  . Listener : port, protocol ์ง€์ •, ์ตœ๋Œ€ 50๊ฐœ ์ƒ์„ฑ ๊ฐ€๋Šฅ, ALB๋‹น ์ตœ์†Œ 1๊ฐœ ์ง€์ •, Contents ๊ธฐ๋ฐ˜ ๋ฃฐ ์ง€์ •(host/path ๊ธฐ๋ฐ˜)

  . Target group : ALB ๋ฐ‘๋‹จ ํƒ€์ผ“๋“ค์˜ logical ๊ทธ๋ฃน

 

- Network Load Balancer

  . L4

  . TCP Protocol ์ง€์›

  . ๊ณ ์„ฑ๋Šฅ - ์ดˆ๋‹น ์ˆ˜๋ฐฑ๋งŒ ์š”์ฒญ ์ฒ˜๋ฆฌ, ๋‚ฎ์€ ์ง€์—ฐ

  . NLB์—๋Š” AZ๋‹น ํ•˜๋‚˜์˜ ๊ณ ์ • IP ๋ถ€์—ฌ

  . long running์— ์ ํ•ฉ

  . listner, target group, targets ์‚ฌ์šฉ

 

- Classic Load Balancer : for HTTP, HTTPS, TCP

 

10. Route53

 

- ์ฐธ๊ณ  : https://aws.amazon.com/ko/route53/?nc2=type_a

 

Amazon Route 53 - Amazon Web Services

Amazon Route 53๋Š” ๋‹ค๋ฅธ AWS ๊ธฐ๋Šฅ ๋ฐ ์„œ๋น„์Šค์™€ ์ž˜ ์—ฐ๋™๋˜๋„๋ก ์„ค๊ณ„๋˜์—ˆ์Šต๋‹ˆ๋‹ค. Amazon Route 53๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋„๋ฉ”์ธ ์ด๋ฆ„์„ Amazon EC2 ์ธ์Šคํ„ด์Šค, Amazon S3 ๋ฒ„ํ‚ท, Amazon CloudFront ๋ฐฐํฌ ๋ฐ ๊ธฐํƒ€ AWS ๋ฆฌ์†Œ์Šค์— ๋งคํ•‘ํ•  ๏ฟฝ

aws.amazon.com

- ๊ณ ๊ฐ€์šฉ์„ฑ, ํด๋ผ์šฐ๋“œ ๊ธฐ๋ฐ˜์€ scalable DNS ์„œ๋น„์Šค

- 100% SLA ์ œ๊ณต

- ์ง€์—ญ์‹œ๊ฐ„/์ง€์—ญ/๊ฐ€์ค‘์น˜ ๊ธฐ๋ฐ˜ ๊ฐ€๋Šฅ

 

- Public Hosted Zone

  . ๋„๋ฉ”์ธ ๊ตฌ๋งค ํ•„์š”

  . ์ธํ„ฐ๋„ท์—์„œ ๋„๋ฉ”์ธ ํŠธ๋ž˜ํ”ฝ ๋ผ์šฐํŒ…

  . ๊ฐ€์ค‘์น˜ ๊ธฐ๋ฐ˜ ๋ ˆ์ฝ”๋“œ ๋ฐ ์žฅ์• ์กฐ์น˜ ๋ ˆ์ฝ”๋“œ๋ฅผ ํฌํ•จํ•œ ๋ชจ๋“  ์˜ต์…˜ ์‚ฌ์šฉ ๊ฐ€๋Šฅ

  . pulic

 

- Private Hosted Zone

  . ๋„๋ฉ”์ธ ๊ตฌ๋งค ๋ถˆํ•„์š”

  . VPC๋‚ด ๋„๋ฉ”์ธ ํŠธ๋ž˜ํ”ฝ ๋ผ์šฐํŒ…

  . ๊ฐ€์ค‘์น˜ ๊ธฐ๋ฐ˜ ๋ ˆ์ฝ”๋“œ ๋ฐ ์žฅ์• ์กฐ์น˜ ๋ ˆ์ฝ”๋“œ์—๋งŒ ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ์Œ

  . private