IAM ๋ฐ AWS CLI

mjยท2026๋…„ 1์›” 6์ผ

AWS Certified Solutions Architect Associate

๋ชฉ๋ก ๋ณด๊ธฐ
1/4
post-thumbnail

IAM

๐Ÿ’ก IAM (Identity Access Management)
AWS์˜ ๋ณด์•ˆ ์ธ์ฆ ์„œ๋น„์Šค๋กœ, AWS ๊ณ„์ • ๋ฐ ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•œ ๋ณด์•ˆ์„ ๊ด€๋ฆฌํ•˜๊ณ  ๊ถŒํ•œ์„ ์ œ์–ดํ•œ๋‹ค.

  • IAM์€ ๊ธ€๋กœ๋ฒŒ ์„œ๋น„์Šค๋‹ค. (์„ ํƒํ•  ๋ฆฌ์ „์ด ์—†๋‹ค๋Š” ๋œป)
  • ์‹ค์ œ ๋ฌผ๋ฆฌ์  ์‚ฌ์šฉ์ž์™€ ๋งคํ•‘ํ•œ๋‹ค.

Root Account

  • ์ฒ˜์Œ ๊ณ„์ •์„ ์ƒ์„ฑํ•˜๋ฉด ๊ธฐ๋ณธ์ ์œผ๋กœ ๋งŒ๋“ค์–ด์ง„๋‹ค.
  • ๋ฃจํŠธ ๊ณ„์ •์€ ์ฒ˜์Œ ๊ณ„์ •์ƒ์„ฑํ–ˆ์„๋•Œ๋งŒ ์‚ฌ์šฉํ•˜๊ณ , ์ดํ›„์—๋Š” IAM์œผ๋กœ Users๋ฅผ ๋งŒ๋“ค์–ด ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ๊ถŒ์žฅ๋œ๋‹ค.(๋ณด์•ˆ ๊ฐ•ํ™”๋ฅผ ์œ„ํ•ด)

IAM Users

: ์‚ฌ์šฉ์ž

  • ํ•˜๋‚˜์˜ ์‚ฌ์šฉ์ž๋Š” ์—ฌ๋Ÿฌ ๊ทธ๋ฃน์— ์†ํ•  ์ˆ˜ ์žˆ๋‹ค.
  • ๋ฐ˜๋“œ์‹œ ์‚ฌ์šฉ์ž๊ฐ€ ๊ทธ๋ฃน์— ์†ํ•ด์•ผํ•˜๋Š”๊ฑด ์•„๋‹ˆ๋‹ค.
  • IAM ์ •์ฑ…์€ IAM ์‚ฌ์šฉ์ž์—๊ฒŒ ์ง์ ‘ ์ง€์ •, ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ๋‹ค. (๊ทธ๋ฃน์„ ํ†ตํ•ด ์ •์ฑ… ์ง€์ •ํ•˜๋Š” ๊ฒƒ์ด ์•„๋‹Œ ์‚ฌ์šฉ์ž ๊ฐœ๋ณ„๋งˆ๋‹ค ์ง์ ‘ ์ง€์ •๊ฐ€๋Šฅ)

IAM Groups

: ์‚ฌ์šฉ์ž๋“ค์„ ๋ฌถ์–ด ๊ทธ๋ฃน์œผ๋กœ ๊ด€๋ฆฌํ•œ๋‹ค.

  • ๊ทธ๋ฃน์•ˆ์— ๊ทธ๋ฃน์„ ํฌํ•จ์‹œํ‚ฌ ์ˆ˜ ์—†๋‹ค.



๋ฐฉ์–ด ๋งค์ปค๋‹ˆ์ฆ˜

1. ๋น„๋ฐ€๋ฒˆํ˜ธ ๊ฐ•ํ™”

2. MFA (Multi-Factor Authentication)

๋น„๋ฐ€๋ฒˆํ˜ธ + ๋ณด์•ˆ๊ธฐ๊ธฐ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ด์ค‘์œผ๋กœ ๋ณด์•ˆ์„ ๊ฐ•ํ™”ํ•œ๋‹ค.

MFA์˜ ์ด์ ์€ ์•จ๋ฆฌ์Šค๊ฐ€ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ๋„๋‚œ๋‹นํ•˜๊ฑฐ๋‚˜ ํ•ดํ‚น๋‹นํ•˜์—ฌ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์žŠ์–ด๋ฒ„๋ฆฐ ๊ฒฝ์šฐ์—๋„ ํ•ด์ปค๊ฐ€ ์•จ๋ฆฌ์Šค์˜ ๋ฌผ๋ฆฌ์  ์žฅ์น˜๋„ ํ™•๋ณดํ•ด์•ผ ํ•˜๋ฏ€๋กœ ๊ณ„์ •์ด ์†์ƒ๋˜์ง€ ์•Š๋Š”๋‹ค๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค

  • Virtual MFA ์‹ค์ œ ์žฅ๋น„ ์—†์ด๋„ ๋ณด์•ˆ์„ ๊ฐ•ํ™”ํ•ด์ค€๋‹ค. ์˜ˆ์‹œ๋กœ ์Šค๋งˆํŠธํฐ์— ์ธ์ฆ์•ฑ์„ ์„ค์น˜ํ•˜๋Š” ๋ฐฉ๋ฒ•์ด ์žˆ๋‹ค. ๋กœ๊ทธ์ธํ• ๋•Œ ๋น„๋ฐ€๋ฒˆํ˜ธ + ์Šค๋งˆํŠธํฐ twilio ์ธ์ฆ์•ฑ์—์„œ ์ƒ์„ฑ๋œ ์ธ์ฆ์ฝ”๋“œ๋ฅผ ์›น์‚ฌ์ดํŠธ์— ๊ทธ๋Œ€๋กœ ์ž…๋ ฅ
  • ๋ฌผ๋ฆฌ์  ์žฅ์น˜ (e.g. ๋ณด์•ˆํ† ํฐ)



Permissions

  • IAM ์ •์ฑ…์„ JSON ๋ฌธ์„œ๋กœ ์ง€์ •

๐Ÿ’ก ์ตœ์†Œ ๊ถŒํ•œ์˜ ์›์น™ (least privilege principle)
: ์‚ฌ์šฉ์ž ๋˜๋Š” ์‹œ์Šคํ…œ์ด ์—…๋ฌด ์ˆ˜ํ–‰์— ๊ผญ ํ•„์š”ํ•œ ๊ถŒํ•œ๋งŒ ๋ถ€์—ฌ๋ฐ›์•„์•ผ ํ•œ๋‹ค.

Policies Structure

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "PublicReadGetObject",
      "Effect": "Allow",
      "Principal": {
			  "AWS": "arn:aws:iam::123456789012:user/Alice"
			},
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::my-public-bucket/*"
    }
  ]
}

Consists of

  • Version:
  • Id:
  • Statement: ํ•œ ๊ฐœ ์ด์ƒ์˜ statements (required)

Statements consist of

  • Sid(์‹œ๋“œ): Statement ID (์„ ํƒ์‚ฌํ•ญ)
  • Effect(ํšจ๊ณผ): Allow / Deny
  • Principal(์›์น™/์ฃผ์ฒด): ๋ˆ„๊ฐ€ ์•ก์„ธ์Šคํ•˜๋Š”์ง€
  • Action(์กฐ์น˜): ์–ด๋–ค API๋ฅผ ํ—ˆ์šฉ/๊ฑฐ๋ถ€ํ• ์ง€
  • Resource(๋ฆฌ์†Œ์Šค): ์–ด๋–ค ๋ฆฌ์†Œ์Šค์— ์ ์šฉํ• ์ง€
  • Condition(์กฐ๊ฑด):



IAM Roles ์—ญํ• 

โ†’ ์ž„์‹œ๋œ ๊ถŒํ•œ ๋ถ€์—ฌ

๋‹ค๋ฅธ AWS ๋ฆฌ์†Œ์Šค๋‚˜ ์„œ๋น„์Šค์— ์ž„์‹œ๋กœ ์•ก์„ธ์Šคํ•˜๊ธฐ ์œ„ํ•ด์„œ ํŠน์ •์‚ฌ์šฉ์ž๋‚˜ ์„œ๋น„์Šค๊ฐ€ ์ž„์‹œ์ ์œผ๋กœ ๊ถŒํ•œ์„ ์–ป๊ฒŒํ•˜๋Š” ๋ฐฉ๋ฒ•์ด๋‹ค.

โ›‘๏ธย ๋ชจ์ž๋กœ ์ƒ๊ฐํ•˜๋ฉด ์ดํ•ดํ•˜๊ธฐ ์‰ฝ๋‹ค.
Developer๊ฐ€ DA๋ชจ์ž๋ฅผ ์“ฐ๋ฉด ์ž ์‹œ DA์—…๋ฌด๋ฅผ ์ˆ˜ํ–‰๊ฐ€๋Šฅํ•˜๊ฒŒ๋œ๋‹ค. ๋‹จ, ๊ธฐ์กด์˜ Developer์˜ ๊ถŒํ•œ์€ ์—†์–ด์ง„๋‹ค.

IAM ๋ณด์•ˆ๋„๊ตฌ

โ†’ ๊ณ„์ •์˜ ๊ถŒํ•œ์„ ๊ฐ์‹œํ•˜๊ธฐ ์œ„ํ•จ์ด๋‹ค.

1. IAM Credential Reports ์ž๊ฒฉ์ฆ๋ช…๋ณด๊ณ ์„œ
csvํŒŒ์ผ๋กœ ์ƒ์„ฑ๋จ. ๊ณ„์ •์„ ์ƒ์„ฑํ•œ ์‹œ๊ธฐ, pw๋ฅผ ๋ฐ”๊พผ ์‹œ๊ธฐ, access key๋ฅผ ๋งŒ๋“  ์‹œ๊ธฐโ€ฆ ๋“ฑ์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ํŒŒ์•…๊ฐ€๋Šฅ.

2. IAM Access Advisor ์•ก์„ธ์Šค ๊ด€๋ฆฌ์ž
์–ธ์ œ ์–ด๋–ค ์„œ๋น„์Šค์— ์ ‘๊ทผํ–ˆ๋Š”์ง€๋ฅผ ๋ณด์—ฌ์ค€๋‹ค.



How can users access AWS?

1. Management Console

AWS ๊ด€๋ฆฌ๋ฅผ ์œ„ํ•œ ์›น ๊ธฐ๋ฐ˜ ์ธํ„ฐํŽ˜์ด์Šค (aws ์›น์—์„œ ์ ‘์†ํ•˜๋Š” ๋ฐฉ๋ฒ•)

2. AWS CLI

Command Line Interface
AWS๋ฅผ CLI๋กœ ์ ‘๊ทผํ•˜๋Š” ๋ฐฉ๋ฒ•, access key๊ฐ€ ํ•„์š”ํ•˜๋‹ค.

3. AWS SDK

Software Development Kit
์ฝ”๋“œ ๋‚ด์—์„œ API๋ฅผ ํ˜ธ์ถœํ•˜๊ธฐ ์œ„ํ•œ ๋ฐฉ๋ฒ•, access key๊ฐ€ ํ•„์š”ํ•˜๋‹ค.



IAM Section โ€“ Summary

  • Users: mapped to a physical user, has a password for AWS Console
  • Groups: contains users only
  • Policies: JSON document that outlines permissions for users or groups
  • Roles: for EC2 instances or AWS services
  • Security: MFA + Password Policy
  • AWS CLI: manage your AWS services using the command-line
  • AWS SDK: manage your AWS services using a programming language
  • Access Keys: access AWS using the CLI or SDK
  • Audit: IAM Credential Reports & IAM Access Advisor



์ฐธ๊ณ 
https://www.udemy.com/course/best-aws-certified-solutions-architect-associate/

profile
์ผ๋‹จ ํ•˜์ž.

0๊ฐœ์˜ ๋Œ“๊ธ€