๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

๊ฐœ๋ฐœ/AWS

AWS ์†”๋ฃจ์…˜ ์•„ํ‚คํ…ํŠธ AWS-SAA(C02) ์‹œํ—˜๊ณต๋ถ€ (ํŒ & ์ฃผ์š” ๊ฐœ๋…)

๋ฐ˜์‘ํ˜•

 

๐Ÿ’ก  TIPS

  • Windows server -> FSx
  • ์ธ์Šคํ„ด์Šค๋ผ๋ฆฌ ์ „์†ก์†๋„ ํ–ฅ์ƒ -> Placement Group
  • secure network connectivity -> Site to Site VPN
  • ~~TB์˜ ๋ฐ์ดํ„ฐ๋ฅผ ์ดˆ๊ธฐ์— ์ „์†กํ•ด์•ผ ํ•จ -> Snowball
  • ์ „ ์„ธ๊ณ„ ์œ ์ €์—๊ฒŒ ๋น ๋ฅธ ์ ‘๊ทผ ์ œ๊ณต -> CloudFront
  • ํŠน์ • ๊ตญ๊ฐ€์—์„œ์˜ ์ ‘๊ทผ์„ ๋ง‰๊ณ ์ž ํ•จ -> CloudFront Geo restriction
  • ์šฉ๋Ÿ‰์„ ์ž์œ ๋กญ๊ฒŒ ๋ฐ”๊พธ๊ณ  ์—ฌ๋Ÿฌ ์ธ์Šคํ„ด์Šค์—์„œ ์ ‘๊ทผ -> EFS File system
  • ์ดˆ๋‹น ์ˆ˜์‹ญ๋งŒ๊ฐœ์˜ ํŠธ๋žœ์ ์…˜์„ ์ฒ˜๋ฆฌํ•  block storage -> EC2 instance store
  • Key-value request -> Dynamo DB
  • API gateway + ์˜ˆ์ธก ๋ถˆ๊ฐ€๋Šฅํ•œ ์š”์ฒญ ํŒจํ„ด -> Lambda
  • ์ธ์Šคํ„ด์Šค๋ฅผ ์ฃผ๊ธฐ์ ์œผ๋กœ(ex) ๋งค์›” ์ดˆ์—๋งŒ) 20๊ฐœ๋กœ ๋Š˜๋ ค์ค˜์•ผ ํ•˜๋ฉด? -> Scheduled Reserved Instances
  • Layer4(TCP/UDP)์—์„œ์˜ ๊ณ ๊ฐ€์šฉ์„ฑ -> Network Load Balancer
  • CPU ์‚ฌ์šฉ๋ฅ ์— ๋”ฐ๋ผ Auto Acaling -> target tracking policy
  • S3 object๋ฅผ ์‹ค์ˆ˜๋กœ ์‚ญ์ œํ•˜์ง€ ์•Š์œผ๋ ค๋ฉด? -> versioning, MFA Delete
  • EC2์—์„œ S3 bucket์— ์ ‘๊ทผ -> S3์— ๋Œ€ํ•œ IAM์ƒ์„ฑํ•˜์—ฌ EC2 ์ธ์Šคํ„ด์Šค ํ”„๋กœํ•„์— ์ถ”๊ฐ€
  • High availability -> Multi AZ
  • ์•”ํ˜ธํ™”? -> ๊ฑฐ์˜ KMS
  • Decoupling -> SQS
  • Secured internet connection -> NAT gateway
  • RESTful services -> API gateway
  • ํŒŒ์ผ ๋ณต์‚ฌ๋ณธ์„ ๋™๊ธฐํ™”ํ•˜์—ฌ ๊ด€๋ฆฌํ•˜๊ณ  ์‹ถ๋‹ค -> File Gateway
  • ์ฝ๊ธฐ ๋ถ€ํ•˜๊ฐ€ ํฐ ์ƒํƒœ... -> Read Replica

๐Ÿ“š ๋คํ”„ ๋ณด๋ฉฐ ํ—ท๊ฐˆ๋ ธ๋˜ ๋‚ด์šฉ 

SG vs. NACL

SG(Security Group)

  • Instance Level
  • stateful(์ธ๋ฐ”์šด๋“œ ํŠธํŒจํ”ฝ๋งŒ ๋ช…์‹œ)
    NACL
  • VPC Level
  • stateless
  • default
    * default NACL : ๋ชจ๋“  in/outbound traffic ํ—ˆ์šฉ
    • ์‚ฌ์šฉ์ž์ง€์ • NACL : ๋ชจ๋“  in/outbound traffic ์ฐจ๋‹จ

S3 with Transfer Acceleration

S3๋กœ์˜ ์—…๋กœ๋“œ/๋‹ค์šด๋กœ๋“œ ์†๋„ ํ–ฅ์ƒ (50~500%)
ํŠธ๋ž˜ํ”ฝ์„ ์•„๋งˆ์กด CloudFront์˜ ๋ถ„์‚ฐ๋œ Edge Location๊ณผ AWS backbonne network๋ฅผ ํ†ตํ•ด ์ฒ˜๋ฆฌํ•˜์—ฌ ์†๋„ ํ–ฅ์ƒ์‹œํ‚จ๋‹ค.

Route 53 active-passive failover configuration

๊ธฐ๋ณธ ๋ฆฌ์†Œ์Šค ๋˜๋Š” ๋ฆฌ์†Œ์Šค ๊ทธ๋ฃน์ด ๋Œ€๋ถ€๋ถ„์˜ ์‹œ๊ฐ„ ๋™์•ˆ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•˜๋„๋ก ํ•˜๊ณ  ๋ณด์กฐ ๋ฆฌ์†Œ์Šค ๋˜๋Š” ๋ฆฌ์†Œ์Šค ๊ทธ๋ฃน์€ ๊ธฐ๋ณธ ๋ฆฌ์†Œ์Šค๊ฐ€ ์‚ฌ์šฉ ๋ถˆ๊ฐ€๋Šฅํ•  ๊ฒฝ์šฐ๋ฅผ ๋Œ€๋น„ํ•ด ๋Œ€๊ธฐ ์ค‘์— ์žˆ๋„๋ก ์„ค์ •ํ•จ

Amazon Kinesis

Amazon Kinesis Data Streams: ์‹ค์‹œ๊ฐ„ ๋ฐ์ดํ„ฐ ์ŠคํŠธ๋ฆฌ๋ฐ ์„œ๋น„์Šค. ์กฐ์ • ๊ฐ€๋Šฅํ•˜๊ณ  ๋‚ด๊ตฌ์„ฑ์ด ๋›ฐ์–ด๋‚จ. ์ˆ˜์‹ญ ๋งŒ ๊ฐœ์˜ ์†Œ์Šค์—์„œ ์ดˆ๋‹น ๊ธฐ๊ฐ€๋ฐ”์ดํŠธ์˜ ๋ฐ์ดํ„ฐ๋ฅผ ์—ฐ์†์ ์œผ๋กœ ์บก์ฒ˜ํ•  ์ˆ˜ ์žˆ์Œ. ๋ฐ์ดํ„ฐ์˜ ์ˆœ์„œ๋ฅผ ์ง€ํ‚ฌ ์ˆ˜ ์žˆ์Œ.
Amazon Kineses Data Firehose : ์‹ค์‹œ๊ฐ„ ๋ถ„์„์„ ์œ„ํ•ด ๋ฐ์ดํ„ฐ ์ŠคํŠธ๋ฆผ์„ ์บก์ฒ˜ ๋ฐ ๋ณ€ํ™˜ํ•˜์—ฌ AWS ๋ฐ์ดํ„ฐ ์Šคํ† ์–ด๋กœ ๋กœ๋“œ
Amazon Kinesis Data Analytics : SQL ๋˜๋Š” Apache Flink๋ฅผ ํ†ตํ•ด ์‹ค์‹œ๊ฐ„์œผ๋กœ ๋ฐ์ดํ„ฐ ์ŠคํŠธ๋ฆผ์„ ๋ถ„์„

AWS Global Accelerator Vs. Amazon CloudFront?

๋‘˜ ๋‹ค edge location์„ ํ™œ์šฉํ•˜๋Š” ์„œ๋น„์Šค์ด๋‹ค
Cloudfront๋Š” ์บ์‹ฑ ๊ฐ€๋Šฅํ•œ ์ปจํ…์ธ (์ด๋ฏธ์ง€, ๋น„๋””์˜ค..)์™€ ๋™์  ์ปจํ…์ธ (API acceleration, dynamic. site delivery..)์˜ ์„ฑ๋Šฅ์„ ํ–ฅ์ƒ์‹œํ‚ค๋Š”๋ฐ ์‚ฌ์šฉ๋œ๋‹ค
Global Accelerator๋Š” TCP/UDP๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๋ณด๋‹ค ๋‹ค์–‘ํ•œ ์šฉ๋„์˜ ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์— ์‚ฌ์šฉ๋œ๋‹ค. non-HTTP ์˜ˆ๋ฅผ๋“ค์–ด ๊ฒŒ์ด๋ฐ(UDP), IOT(MQTT), VoIP ๋“ฑ์— ์‚ฌ์šฉ๋œ๋‹ค.

AWS Direct Connect vs. AWS Site-to-Site VPN

DirectConnect : private network. ์ผ๊ด€์„ฑ(consistentcy)์€ ์ œ๊ณตํ•˜์ง€๋งŒ ๋ณด์•ˆ์€ ๋–จ์–ด์ง„๋‹ค. ์ฒ˜์Œ ์„ค์ •ํ•  ๋•Œ ์ตœ์†Œ 1๋‹ฌ ์ด์ƒ ์†Œ์š”๋œ๋‹ค.
Site-to-Site VPN : ๋ณด์•ˆ์„ฑ์ด ๋†’๊ณ  ๋ฐ”๋กœ ์„ธํŒ…์ด ๊ฐ€๋Šฅํ•˜๋‹ค. ์ผ๊ด€์„ฑ์€ ๋–จ์–ด์ง€์ง€๋งŒ Accelerated Site-to-Site VPN๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ์ผ๊ด€์„ฑ์„ ๋ณด์žฅํ•  ์ˆ˜ ์žˆ๋‹ค. Accelerated Site-to-Site VPN ์€ ๊ฐ€์šฉ์„ฑ์ด ๋†’์€ AWS global network๋ฅผ ํ™œ์šฉํ•˜์—ฌ ๋” ์ผ๊ด€์„ฑ ๋†’์€ ๊ฒฝํ—˜์„ ์ œ๊ณตํ•œ๋‹ค.

Amazon RDS Read Replicas for MySQL w/ Multi-AZ deployments

Amazond RDS๋Š” ๊ฐ™์€ ๋˜๋Š” ๋‹ค๋ฅธ ๋ฆฌ์ „์— read-only copy๋ฅผ ์ƒ์„ฑํ•  ์ˆ˜ ์žˆ๋‹ค.
์ด Read replica๋Š” read๊ฐ•๋„๊ฐ€ ๋†’์€ workload์— ๋Œ€ํ•ด ํ™•์žฅ์„ฑ์„ ์ œ๊ณตํ•˜๊ณ 
ํ•„์š”ํ•˜๋ฉด standalone database๋กœ ์Šน๊ฒฉ๋  ์ˆ˜ ์žˆ๋‹ค.
business reporting์ด๋‚˜ data warehouse๊ฐ€ ํ•„์š”ํ•  ๋•Œ์—๋„ primary DB instance๋Œ€์‹  read replica์—์„œ read query๋ฅผ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ๋‹ค.

Elastic Load Balancer vs. AWS Global Accelerator

ELB : ๋‹จ์ผ ๋ฆฌ์ „์—์„œ์˜ Load balancing ์ œ๊ณต
AWS Global Accelerator : ์—ฌ๋Ÿฌ ๋ฆฌ์ „์— ๊ฑธ์นœ ํŠธ๋ ˆํ”ฝ ๊ด€๋ฆฌ ์ œ๊ณต. global client๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•˜๋Š” workload๊ฐ€ ์žˆ๋‹ค๋ฉด AWS Global Accelerator๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์„ ๊ถŒ์žฅํ•จ.

AWS S3 Cross-region Replication

์ ˆ๋Œ€ ์œ ์‹ค๋˜์–ด์„  ์•ˆ๋˜๋Š” ์ค‘์š”ํ•œ ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•  ๋•Œ ๋‹ค๋ฅธ ๋ฆฌ์ „์— S3๋ฅผ ์ƒ์„ฑํ•˜๊ณ  cross-Region replication์„ ์„ค์ •ํ•  ์ˆ˜ ์žˆ๋‹ค

AWS S3 Gateway Endpoint, Interface Endpoint

Gateway endpoint : internet ๊ฑฐ์น˜์ง€ ์•Š๊ณ  ์ €์žฅ์†Œ ์ ‘๊ทผํ•  ๋•Œ ์‚ฌ์šฉ. ์•„๋งˆ์กด S3 public ip ์ฃผ์†Œ๋ฅผ ์‚ฌ์šฉํ•˜๊ณ , on premise์—์„œ์˜ ์ ‘๊ทผ์„ ํ—ˆ์šฉํ•˜์ง€ ์•Š๋Š”๋‹ค. VPC ๋‚ด์—์„œ๋Š” ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์—์„œ ์—”๋“œํฌ์ธํŠธ ๋ณ€๊ฒฝ๋“ฑ์ด ํ•„์š”์—†์ด ๋ฐ”๋กœ ์ ์šฉ์ด ๋˜์ง€๋งŒ ip๋Š” ์ œ๊ณต๋˜์ง€ ์•Š๋Š”๋‹ค.
Interface gateway : VPC์—์„œ์˜ private IP address๋ฅผ ์‚ฌ์šฉํ•˜๊ณ , on-premise์—์„œ์˜ ์ ‘๊ทผ์„ ํ—ˆ์šฉํ•œ๋‹ค.

Amazon CloudFront

EC2์ธ์Šคํ„ด์Šค์—์„œ ํ˜ธ์ŠคํŒ…์ค‘์ธ ์›น์‚ฌ์ดํŠธ์ด๊ณ , ALB๊ฐ€ ์„ธํŒ…๋˜์–ด์žˆ๋‹ค.
์›น์‚ฌ์ดํŠธ๋Š” dynamic๊ณผ static์ด ์„ž์—ฌ์žˆ๋‹ค.
์ „์„ธ๊ณ„์˜ ์‚ฌ์šฉ์ž๋“ค์ด ์›น์‚ฌ์ดํŠธ๊ฐ€ ๋Š๋ฆฌ๋‹ค๊ณ  ํ•  ๋•Œ ๋ฐฉ๋ฒ•์€?

dynamic์ด๊ณ  EC2๋‹ˆ๊น coludfront์•„๋‹Œ ์ค„ ์•Œ์•˜๋Š”๋ฐ, cloudfront..
CloudFront distribution์„ ์ƒ์„ฑํ•˜๊ณ , ALB๋ฅผ ์˜ค๋ฆฌ์ง„์œผ๋กœ ์„ค์ •ํ•œ๋‹ค. Amazon Route 53 ๋ ˆ์ฝ”๋“œ๋ฅผ CloudFront๋ฅผ ๋ฐ”๋ผ๋ณด๋„๋ก ์—…๋ฐ์ดํŠธํ•œ๋‹ค.

cloudfront๊ฐ€ ๊ทธ๋ƒฅ ์ •์  ์ปจํ…์ธ  ์บ์‹ฑ์ด๋ผ๊ณ ๋งŒ ์ƒ๊ฐํ–ˆ๋Š”๋ฐ ๋” ์ฐฏ์•„๋ด์•ผํ• ๋“ฏ..

Geolocation vs. Geoproximity

Geolocation : ์‚ฌ์šฉ์ž์˜ ์œ„์น˜์— ๊ธฐ๋ฐ˜ํ•˜์—ฌ ํŠธ๋ž˜ํ”ฝ ๋ผ์šฐํŒ…ํ•˜๋ ค๋Š” ๊ฒฝ์šฐ
Geoproximity : ๋ฆฌ์†Œ์Šค์˜ ์œ„์น˜๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ํŠธ๋ž˜ํ”ฝ์„ ๋ผ์šฐํŒ…ํ•˜๊ณ  ํ•„์š”์— ๋”ฐ๋ผ ํ•œ ์œ„์น˜์˜ ๋ฆฌ์†Œ์Šค์—์„œ ๋‹ค๋ฅธ ์œ„์น˜์˜ ๋ฆฌ์†Œ์Šค๋กœ ํŠธ๋ž˜ํ”ฝ์„ ๋ณด๋‚ด๋ ค๋Š” ๊ฒฝ์šฐ

Network allow/deny rules

  • WAF : IP -> block
  • ACL on CloudFront distribution : CloudFront๋Š” ์„œ๋ธŒ๋„ท ์ƒ์— ์žˆ๋Š”๊ฒŒ ์•„๋‹ˆ๋ฏ€๋กœ ACL์ ์šฉ ๋ถˆ๊ฐ€(ACL์€ Subnet์ƒ์—์„œ๋งŒ ์ ์šฉ ๊ฐ€๋Šฅ)
  • SG: SG๋Š” deny rule ์—†์Œ

AWS Directory Service

AWS์˜ ๊ด€๋ฆฌํ˜• Active Directory(AD)๋ฅผ ํ™œ์šฉ
ํด๋ผ์šฐ๋“œ์˜ ์—ฌ๋Ÿฌ ์›Œํฌ๋กœ๋“œ์—์„œ AD ๊ณต์œ 
๊ด€๋ฆฌ ์ž‘์—… ๊ฐ„์†Œํ™”

RDS & ASG(Auto Scaling Group)

RDS๋Š” managed service์ด๋ฏ€๋กœ AWS๊ฐ€ scaling์„ ๊ด€๋ฆฌํ•˜๋ฏ€๋กœ ASG์™€๋Š” ๊ด€๊ณ„๊ฐ€ ์—†์Œ

AWS Storage Gateway (File, Tape, Volume)

Storage Gateway : Hybrid storage(cloud + on-prem). ๋””ํดํŠธ๋กœ ๋ฐ์ดํ„ฐ๋ฅผ ์•”ํ˜ธํ™”ํ•จ. File, Tape, Volume ์„ธ ์ข…๋ฅ˜๊ฐ€ ์žˆ๋‹ค.
1. Storage File Gateway : NFS๋‚˜ SMBํ”„๋กœํ† ์ฝœ์„ ์ด์šฉํ•ด์„œ Amazon S3์— ์ ‘๊ทผํ•˜๋Š” ์ธํ„ฐํŽ˜์ด์Šค. S3์˜ค๋ธŒ์ ํŠธ๋กœ ์ €์žฅ๋˜๊ณ  lifecycle management๋‚˜ cross-region replication๊ณผ ๊ฐ™์€ ๊ธฐ๋Šฅ์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค. ๊ฐ๊ฐ์˜ ํŒŒ์ผ ๊ฒŒ์ดํŠธ์›จ์ด๋Š” ์ตœ๋Œ€ 10๊ฐœ์˜ ๋ฒ„ํ‚ท์— ์‰์–ดํ•  ์ˆ˜ ์žˆ๋‹ค.
2. Storage Volume Gateway : ๋ธ”๋ก์Šคํ† ๋ฆฌ์ง€๋ฅผ ํด๋ผ์šฐ๋“œ๋กœ ์ด์ „. ๋กœ์ปฌ ์บ์‹ฑ ๊ธฐ๋Šฅ์ด ์žˆ๋Š” ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ๋ธ”๋ก ์Šคํ† ๋ฆฌ์ง€. iSCSI ํ”„๋กœํ† ์ฝœ ์‚ฌ์šฉ. ๋ฐฑ์—…์ด๋‚˜ DR(disaster recovery์— ์‚ฌ์šฉ.
3. Storage Tape Gateway : ๋ฐฑ์—…์šฉ

์ฐธ๊ณ ) https://cloud.in28minutes.com/aws-certification-aws-storage-gateway

AWS Storage Gateway Hardware Appliance

amazon.com์—์„œ ์ฃผ๋ฌธํ•˜์—ฌ ์‚ฌ์šฉํ•˜๋Š” ํ•˜๋“œ์›จ์–ด ์žฅ๋น„.
virtualized environment์—†์ด๋„ Storge Getway๋ฅผ ์„ธํŒ…ํ•  ์ˆ˜ ์žˆ์Œ

ACID

atomicity, consistency, isolation, and durability

Service Control Policy

์—ฌ๋Ÿฌ ๊ณ„์ •์— ๋Œ€ํ•œ IAM์„ ์ค‘์•™ ๊ด€๋ฆฌ.
AWS Organization์„ ํ†ตํ•ด์„œ ์ƒ์„ฑํ•œ๋‹ค

Encryption

SSE-S3((Server Side Encryption with S3-Managed Keys): AWS๊ฐ€ data key์™€ master key ๋‘˜ ๋‹ค ๊ด€๋ฆฌํ•จ
SSE-KMS(Server Side Encryption with KMS-Managed Keys): AWS ๊ฐ€ data key๋ฅผ ์‚ฌ์šฉ์ž๊ฐ€ master key๋ฅผ ๊ด€๋ฆฌํ•จ
SSE-C(Server Side Encryption with Customer-Provided Keys): Master key์™€ data key ๋ชจ๋‘ ์‚ฌ์šฉ์ž๊ฐ€ ๊ด€๋ฆฌํ•จ

๋ณต์žกํ•˜๊ฒŒ IGW๋‚˜ VPC peering connnection ์„ ์„ค์ •ํ•  ํ•„์š” ์—†์ด ์„œ๋กœ ๋‹ค๋ฅธ ๊ณ„์ •, VPC์— ์žˆ๋Š” ๋‘ ์„œ๋น„์Šค๋ฅผ ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ์Œ

ASG(Auto Scaling Group) and Region

ASG๋Š” ์—ฌ๋Ÿฌ region์— ๊ฑธ์ณ์„œ ์„ค์ •๋  ์ˆ˜๋Š” ์—†๋‹ค.

Fargate

์ปจํ…Œ์ด๋„ˆ์— ์ ํ•ฉํ•œ ์„œ๋ฒ„๋ฆฌ์Šค ์ปดํ“จํŒ… ์—”์ง„์œผ๋กœ ECS ์™€ EKS์—์„œ ๋ชจ๋‘ ์ž‘๋™ํ•จ.

Transit Gateway

์ค‘์•™ ํ—ˆ๋ธŒ๋ฅผ ํ†ตํ•ด VPC์™€ ์˜จํ”„๋ ˆ๋ฏธ์Šค ๋„คํŠธ์›Œํฌ๋ฅผ ์—ฐ๊ฒฐ
๋ณต์žกํ•œ ํ”ผ์–ด๋ง ๊ด€๊ณ„๋ฅผ ์ œ๊ฑฐํ•˜์—ฌ ๋„คํŠธ์›Œํฌ๋ฅผ ๊ฐ„์†Œํ™”

AWS Organiztions

๊ฒฐ์ œ๋ฅผ ๊ด€๋ฆฌํ•˜๊ณ , ์•ก์„ธ์Šค, ๊ทœ์ • ์ค€์ˆ˜ ๋ฐ ๋ณด์•ˆ์„ ์ œ์–ดํ•˜๊ณ , AWS ๊ณ„์ •์—์„œ ๋ฆฌ์†Œ์Šค๋ฅผ ๊ณต์œ ํ•˜๋Š” ์ผ์„ ๋ชจ๋‘ ์ค‘์•™์—์„œ ์†์‰ฝ๊ฒŒ ์ฒ˜๋ฆฌ

๋ฐ˜์‘ํ˜•