โ˜๏ธ๐Ÿ™‚0617[OPENSTACK,AWS]

๋ง์ง€ยท2022๋…„ 6์›” 17์ผ
0
post-custom-banner

๐Ÿ“Œ ์„ธ๋ฏธํ”„๋กœ์ ํŠธ2

  1. โœ”๏ธAWS ์Šคํ† ๋ฆฌ์ง€ ๊ณต๊ฐ„์„ ESXi์™€ ์—ฐ๊ฒฐ.
    โœ”๏ธAWS์™€ Openstack VPN ์—ฐ๊ฒฐ

  2. โœ”๏ธGSLB;Global Server Load Balancing

  • SLB(ELB);ServerLoadBalancing
    ELB์˜ ํ•œ๊ณ„; ํ•˜๋‚˜์˜ ๋ฆฌ์ „์„ ๋ฒ—์–ด๋‚  ์ˆ˜ ์—†์Œ.
    cross-region ๋ถˆ๊ฐ€๋Šฅ .์ด๊ฒƒ์„ ํ•˜๋ ค๋ฉด GSLB๋ฅผ ํ•ด์•ผํ•จ.
  • GSLB๋Š” ๋ฆฌ์ „์„ ๋„˜๋‚˜๋“œ๋Š” ELB.
  • route53์„ ๊ฐ•์กฐ.

GSLB๋ฅผ ์ด์šฉํ•ด์„œ failover(=์žฅ์• ์กฐ์น˜)(active passive์ƒํƒœ) active์— ๋ฌธ์ œ ์ƒ๊ธฐ๋ฉด passive๋กœ ๋„˜๊ธฐ๋Š” ๋ฐฉ์‹์œผ๋กœ.
ํ•˜์ง€๋งŒ route53์˜ ELB๋Š” ๋ฆฌ์ „์„ ๋ฒ—์–ด๋‚˜๋Š” ๊ฒƒ์— ํ•œ๊ณ„๊ฐ€ ์žˆ์–ด์„œ ELB๋งŒ์œผ๋กœ๋Š” GSLB๋ถˆ๊ฐ€.(๋‹ค๋ฅธ ๋Œ€๋ฅ™, ๋‹ค๋ฅธ ํ”Œ๋žซํผ์œผ๋กœ ๋„˜๊ธฐ๋Š” ๊ฒƒ๋“ค)
=> ๋•Œ๋ฌธ์— HAproxy๋ฅผ ELB๋’ท๋‹จ์— ์„ค์น˜ํ•ด์„œ ์—ฐ๊ฒฐํ•ด์•ผํ•จ.
๋งŒ์•ฝ์— ELB๋•Œ๋ฌธ์— ๋ญ๊ฐ€ ์•ˆ๋˜๋ฉด ELB ๊ฑท์–ด๋‚ด๊ณ  HAproxy ํ•˜๊ณ  http๋กœ ์ด์šฉํ•˜๊ธฐ. ELBํ•˜๋Š” ์ด์œ ๋Š” https,ACM์ด์šฉํ•˜๊ณ  ์‹ถ๊ธฐ ๋•Œ๋ฌธ์ž„.

AzureDB์„œ๋ฒ„ ์ด์šฉํ•˜๊ธฐ.

๐Ÿ“Œ OPENSTACK

๐Ÿ“™ ๋ณด์•ˆ๊ทธ๋ฃน

  1. ํ”„๋กœ์ ํŠธ - ๋„คํŠธ์›Œํฌ - ๋ณด์•ˆ๊ทธ๋ฃน - ๋ณด์•ˆ๊ทธ๋ฃน ์ƒ์„ฑ - ์ด๋ฆ„ : SG-WEB - ๋ณด์•ˆ๊ทธ๋ฃน ์ƒ์„ฑ

outbound ๋‚ด๋ณด๋‚ด๋Š” ๊ฒƒ์€ ํŠธ๋ž˜ํ”ฝ์ด ๋‹ค ํ—ˆ์šฉ ์ค‘. ๋“ค์–ด์˜ค๋Š” ๊ฒƒ์ด ์ฐจ๋‹จ๋˜๊ณ  ์žˆ์–ด์„œ ๊ทœ์น™์ถ”๊ฐ€ ํ•ด์•ผํ•จ.

1-1. ๊ทœ์น™ ์ถ”๊ฐ€ - ๊ทœ์น™ - ALL ICMP(ping), HTTP(web), SSH(keypair) - ์ถ”๊ฐ€

๐Ÿ“™ Floating IP์ƒ์„ฑ

โœ”๏ธ ํ”„๋กœ์ ํŠธ - ๋„คํŠธ์›Œํฌ - Floating IP - ํ”„๋กœ์ ํŠธ์— IPํ• ๋‹น - Pool : External-Network - IPํ• ๋‹น => 3๊ฐœ ์ƒ์„ฑ

๐Ÿ“™ ์ด๋ฏธ์ง€ ์ƒ์„ฑ

ํ”„๋กœ์ ํŠธ - COMPUTE - ์ด๋ฏธ์ง€ - ์ด๋ฏธ์ง€ ์ƒ์„ฑ - ์ด๋ฏธ์ง€ ์ด๋ฆ„ : CentOS7 - ์ด๋ฏธ์ง€ ์†Œ์Šค ํŒŒ์ผ : CentOS-7-x86_64-GenericCloud-2111.qcow2 / ํฌ๋ฉง :QCOW2 - ์ด๋ฏธ์ง€์ƒ์„ฑ

๐Ÿ“™ ํ‚ค ํŽ˜์–ด

โœ”๏ธ ํ”„๋กœ์ ํŠธ - COMPUTE - ํ‚ค ํŽ˜์–ด - ํ‚ค ํŽ˜์–ด ์ƒ์„ฑ - ํ‚ค ํŽ˜์–ด ์ด๋ฆ„ : open-key - ํ‚ค ์œ ํ˜• : SSHํ‚ค - ํ‚ค ํŽ˜์–ด ์ƒ์„ฑ

๐Ÿ“™ ์ธ์Šคํ„ด์Šค ์ƒ์„ฑ

โœ”๏ธ 1. ํ”„๋กœ์ ํŠธ - compute - ์ธ์Šคํ„ด์Šค - ์ธ์Šคํ„ด์Šค ์‹œ์ž‘ - ์ธ์Šคํ„ด์Šค ์ด๋ฆ„ : CentOS7 - next

โœ”๏ธ 1-1. ๋ณผ๋ฅจ ํฌ๊ธฐ : 10gb - centos7ํ• ๋‹น - next

โœ”๏ธ 1-2. m1.micro ํ• ๋‹น - next
โœ”๏ธ 1-3. ๋„คํŠธ์›Œํฌ internal-network ๊ทธ๋Œ€๋กœ -next
โœ๏ธ1:1๋‚˜ํŠธ ๋งคํ•‘์„ ํ†ตํ•ด์„œ ์™ธ๋ถ€์™€ ๋‚ด๋ถ€๋ฅผ ์—ฐ๊ฒฐํ•  ์˜ˆ์ •์ž„. ๊ผญ Internal์„ ํ•ด์„œ ์‚ฌ์„ค IP๋ฅผ ๋ฐ›์„ ์ˆ˜ ์žˆ๋„๋ก ํ•ด์•ผํ•จ.

โœ”๏ธ 1-4. ๋„คํŠธ์›Œํฌ ํฌํŠธ skip (next) - ๋ณด์•ˆ๊ทธ๋ฃน : default ํ• ๋‹น ํ•ด์ œ ํ›„ SG-WEB ํ• ๋‹น - next
โœ”๏ธ 1-5. open-key ํ• ๋‹น ํ™•์ธ ํ›„ next
โœ”๏ธ 1-6. ๊ตฌ์„ฑ - ์‚ฌ์šฉ์ž ์ •์˜ ์Šคํฌ๋ฆฝํŠธ :

#!/bin/bash
sed -i 's/^SELINUX=enforcing$/SELINUX=disabled/' /etc/selinux/config
yum install -y httpd
systemctl enable --now httpd

๐Ÿ“Œ AWS-VPN(Virtual Private Network; ๊ฐ€์ƒ ์‚ฌ์„ค ๋ง)

https://docs.aws.amazon.com/ko_kr/vpn/latest/s2svpn/VPC_VPN.html

๋‘ ์ง€์ ๊ฐ„์˜ ์—ฐ๊ฒฐ์„ ์ธํ„ฐ๋„ท์œผ๋กœ ์—ฐ๊ฒฐ.
๋ฐ์ดํ„ฐ ๋ณด์•ˆ์„ ์œ„ํ•ด์„œ key์ด์šฉ .

VP๊ฒŒ์ดํŠธ์›จ์ด๋Š” ์ธํ„ฐ๋„ท๊ฒŒ์ดํŠธ์›จ์ด๋ž‘ ๋˜‘๊ฐ™์€ ๊ฑด๋ฐ VPN์—ฐ๊ฒฐ๋งŒ์„ ์œ„ํ•ด์„œ ์žˆ๋Š” ๊ฒƒ์ด ๋‹ค๋ฆ„.
customer gateway๋Š” ์šฐ๋ฆฌ ์ปดํ“จํ„ฐ์˜ ๊ณต์šฉIP
์ด๊ฑฐ ๋‘˜ ์—ฐ๊ฒฐ์„ VPC์ปค๋„ฅ์…˜์ด ์•”ํ˜ธํ™”๋ฅผ ํ•ด์คŒ .
๋ˆ„๊ตฐ๊ฐ€๊ฐ€ ๋ณด๋”๋ผ๋„(ํ›”์ณ๊ฐ€๋”๋ผ๋„) ์•ˆ์ „ํ•˜๊ฒŒ ์ง€์ผœ์คŒ. ์„ ์ž์ฒด๋Š” ์ธํ„ฐ๋„ท. VPN์„ค์ •ํ•ด๋†”์„œ ์•”ํ˜ธํ™”๋ฅผ ํ•ด์„œ ๋ฐ์ดํ„ฐ๋ฅผ ์ง€์ผœ์คŒ.

๐Ÿ“™ ๊ณ ๊ฐ๊ฒŒ์ดํŠธ์›จ์ด ์ƒ์„ฑ

โœ”๏ธ 0. VPN-๊ณ ๊ฐ๊ฒŒ์ดํŠธ์›จ์ด(customer gateway)-๊ณ ๊ฐ ๊ฒŒ์ดํŠธ์›จ์ด ์ƒ์„ฑ

โœ”๏ธ 1. ์ด๋ฆ„ : MY-CGW - IP์ฃผ์†Œ : ๋‚ด PC์˜ ๊ณต์šฉ IP

๐Ÿ“™ ๊ฐ€์ƒ ํ”„๋ผ์ด๋น— ๊ฒŒ์ดํŠธ์›จ์ด ์ƒ์„ฑ

โœ”๏ธ 0. VPN-๊ฐ€์ƒํ”„๋ผ์ด๋น—๊ฒŒ์ดํŠธ์›จ์ด-๊ฐ€์ƒํ”„๋ผ์ด๋น—๊ฒŒ์ดํŠธ์›จ์ด ์ƒ์„ฑ
โœ”๏ธ 1. ์ด๋ฆ„ : MY-VGW - ๊ฐ€์ƒ ํ”„๋ผ์ด๋น— ๊ฒŒ์ดํŠธ์›จ์ด ์ƒ์„ฑ

๐Ÿ“™ ์ธ์Šคํ„ด์Šค ์ƒ์„ฑ

โœ”๏ธ ์ด๋ฆ„ : SEOUL - ์ด๋ฏธ์ง€ : ์•„๋งˆ์กด๋ฆฌ๋ˆ…์Šค - ์ธ์Šคํ„ด์Šค ์œ ํ˜• : t2.micro - ํ‚คํŽ˜์–ด : aws-key - VPC: MY-VPC - ์„œ๋ธŒ๋„ท : MY-PUBLIC-SUBNET-2A - ํผ๋ธ”๋ฆญ IP: ํ™œ์„ฑํ™” -๋ณด์•ˆ๊ทธ๋ฃน : SG-WEB - ์‚ฌ์šฉ์ž ๋ฐ์ดํ„ฐ :

#!/bin/bash
yum install -y httpd
systemctl enable --now httpd
echo "<h1>SEOUL</h1>" > /var/www/html/index.html

๐Ÿ“Œ Azure

๐Ÿ“™ ๋ฆฌ์†Œ์Šค๊ทธ๋ฃน ๋งŒ๋“ค๊ธฐ

โœ”๏ธ ์ด๋ฆ„ : RG-TEST , ๋ฆฌ์ „ : UK(south)
๊ฒ€ํ†  + ๋งŒ๋“ค๊ธฐ - ๋งŒ๋“ค๊ธฐ ํด๋ฆญ

๐Ÿ“™ ๊ฐ€์ƒ๋จธ์‹  ๋งŒ๋“ค๊ธฐ

โœ”๏ธ ๋งŒ๋“ค๊ธฐ - Azure๊ฐ€์ƒ๋จธ์‹  - ๋ฆฌ์†Œ์Šค ๊ทธ๋ฃน : RG-TEST - ์ด๋ฆ„ : LONDON - ์ง€์—ญ : UK South - ๊ฐ€์šฉ์„œ ์˜์—ญ : ์˜์—ญ 1 - ์ด๋ฏธ์ง€ : Centos based 7.9-ํฌ๊ธฐ : ์ ๊ฒฉ๋ฌด๋ฃŒ

โœ”๏ธ ํ‚ค ์Œ ์ด๋ฆ„ : azure-key -์ธ๋ฐ”์šด๋“œ ํฌํŠธ : HTTP, SSH - ๊ณ ๊ธ‰

โœ”๏ธ ์‚ฌ์šฉ์ž ์ง€์ • ๋ฐ์ดํ„ฐ ๋ฐ cloud-init :

#!/bin/bash
yum install -y httpd
systemctl enable --now httpd
echo "<h1>LONDON</h1>" > /var/www/html/index.html

=> ๊ฒ€ํ†  + ๋งŒ๋“ค๊ธฐ - ๋งŒ๋“ค๊ธฐ - ํ”„๋ผ์ด๋น— ํ‚ค ๋‹ค์šด๋กœ๋“œ ๋ฐ ๋ฆฌ์†Œ์Šค ๋งŒ๋“ค๊ธฐ

๐Ÿ“Œ GCP

์ธ์Šคํ„ด์Šค ๋งŒ๋“ค๊ธฐ - ์ด๋ฆ„ : oregon ๋ฆฌ์ „ : ์˜ค๋ฆฌ๊ฑด - ์˜์—ญ us-west1-b-๋จธ์‹ ์œ ํ˜• e2-micro

๋ถ€ํŒ…๋””์Šคํฌ - ๋ณ€๊ฒฝ - ์šด์˜์ฒด์ œ : centos-๋ฒ„์ „ : centos7

์•ก์„ธ์Šค ๋ฒ”์œ„ : ๋ชจ๋“  cloud API์— ๋Œ€ํ•œ ์ „์ฒด ์•ก์„ธ์Šค ํ—ˆ์šฉ
๋ฐฉํ™”๋ฒฝ : HTTPํŠธ๋ž˜ํ”ฝ ํ—ˆ์šฉ
์•„๋ž˜ ๋“œ๋ž๋‹ค์šด ๋‚ด๋ ค์„œ ๊ด€๋ฆฌ - ์ž๋™ํ™” ์‹œ์ž‘์Šคํฌ๋ฆฝํŠธ :

#!/bin/bash
sed -i 's/^SELINUX=enforcing$/SELINUX=disabled/' /etc/selinux/config
yum install -y httpd
systemctl enable --now httpd
echo "<h1>OREGON</h1>" > /var/www/html/index.html

=> ๋งŒ๋“ค๊ธฐ

๐Ÿ“Œ alibaba

๐Ÿ“™ Elastic Compute Service

โœ”๏ธ ์ „์— ๋งŒ๋“ค์–ด๋‘” ์ธ์Šคํ„ด์Šค start ๋ฒ„ํŠผ ํด๋ฆญ

[root@webserver ~]# echo "<h1>HONGKONG</h1>" > /var/www/html/index.html

๐Ÿ“Œ ์ธ์Šคํ„ด์Šค ์ •๋ณด ์ •๋ฆฌ

SEOUL(AWS) IP : 13.124.205.118
HONGKONG(alibaba) IP : 47.242.193.56
LONDON(Azure) IP : 20.0.8.179
OREGON(GCP) IP : 34.145.88.165

๐Ÿ“Œroute53

ํ˜ธ์ŠคํŒ… ์˜์—ญ ์ƒ์„ฑ - ๋„๋ฉ”์ธ ์ด๋ฆ„๋„ฃ๊ณ  ์ƒ์„ฑํ•ด๋‘๊ธฐ.

๐Ÿ“Œ ACM

โœ”๏ธ AWS Certificate Manager - ์ธ์ฆ์„œ ์š”์ฒญ - ํผ๋ธ”๋ฆญ ์ธ์ฆ์„œ ์š”์ฒญ - ์™„์ „ํžˆ ์ •๊ทœํ™”๋œ ๋„๋ฉ”์ธ ์ด๋ฆ„ : *.lovemj.shop - DNS ๊ฒ€์ฆ - ๊ถŒ์žฅ ์ฒดํฌ - ์š”์ฒญ ํด๋ฆญ

โœ”๏ธ ์ธ์ฆ์„œ ID ํด๋ฆญ - CNAME๋ณด์ผ ๋•Œ๊นŒ์ง€ ๊ธฐ๋‹ค๋ ธ๋‹ค๊ฐ€ Route53์—์„œ ๋ ˆ์ฝ”๋“œ ์ƒ์„ฑ ํด๋ฆญ - ๋ ˆ์ฝ”๋“œ ์ƒ์„ฑ -

๐Ÿ“Œ AWS - ์„œ์šธ,๋„์ฟ„ ์ธ์Šคํ„ด์Šค (HA)

โœ”๏ธ EC2-์ธ์Šคํ„ด์Šค - ์ธ์Šคํ„ด์Šค ์‹œ์ž‘ - ์ด๋ฆ„ : HA-seoul - ์•„๋งˆ์กด ๋ฆฌ๋ˆ…์Šค (๋””ํดํŠธ) - ํ‚ค ํŽ˜์–ด - aws-key - ๋„คํŠธ์›Œํฌ - ํŽธ์ง‘ - VPC : MY-VPC - ์„œ๋ธŒ๋„ท: ๋งˆ์ด ํผ๋ธ”๋ฆญ ์„œ๋ธŒ๋„ท C - ๋ณด์•ˆ๊ทธ๋ฃน : SG-WEB - ์ธ์Šคํ„ด์Šค ์‹œ์ž‘

# yum install -y haproxy
# vi /etc/haproxy/haproxy.cfg
global
    daemon

defaults
    mode               http

frontend  http-in
    bind *:80
    default_backend    backend_servers

backend backend_servers
    balance            roundrobin
#    cookie  SVID insert indirect nocache maxlife 10s
    server             seoul 13.124.205.118:80 cookie w1 check
    server             hongkong 47.242.193.56:80 cookie w2 check
    server             london 20.0.8.179:80 cookie w3 check
    server             oregon 34.145.88.165:80 cookie w4 check

# systemctl enable --now haproxy

โœ”๏ธ ์ธ์Šคํ„ด์Šค ํƒญ - HA-seoul์ฒดํฌ - ์ž‘์—… - ์ด๋ฏธ์ง€ ๋ฐ ํ…œํ”Œ๋ฆฟ - ์ด๋ฏธ์ง€ ์ƒ์„ฑ
์ด๋ฏธ์ง€ ์ด๋ฆ„ : MY-AMI - ์ด๋ฏธ์ง€ ์ƒ์„ฑ - ์žฌ๋ถ€ํŒ… ์•ˆ ํ•จ : ํ™œ์„ฑํ™” ํƒญ์—์„œ NAME MY-AMi, ์ฒดํฌํ•˜๊ณ  - ์ž‘์—… - AMI ๋ณต์‚ฌ - ๋Œ€์ƒ ๋ฆฌ์ „ : ์•„์‹œ์•„ ํƒœํ‰์–‘(๋„์ฟ„)- AMI๋ณต์‚ฌ ํด๋ฆญ

โœ”๏ธ ๋„์ฟ„ - EC2- ์ธ์Šคํ„ด์Šค -์ธ์Šคํ„ด์Šค ์‹œ์ž‘ - ์ด๋ฆ„ : HA-tokyo - ์ด๋ฏธ์ง€ : ๋‚ด AMI ; MY-AMI -์ƒˆ ํ‚ค ํŽ˜์–ด ์ƒ์„ฑ - ์ด๋ฆ„ : tokyo-key - RSA,.pem - ํ‚ค ํŽ˜์–ด ์ƒ์„ฑ - ๋„คํŠธ์›Œํฌ ์„ค์ • : VPC , ์„œ๋ธŒ๋„ท : DEF - ๋ณด์•ˆ๊ทธ๋ฃน์ƒ์„ฑ - SSH, HTTP - ์ธ์Šคํ„ด์Šค ์‹œ์ž‘

๐Ÿ“Œ AWS-๋กœ๋“œ๋ฐธ๋Ÿฐ์„œ

โœ”๏ธ์„œ์šธ - ๋กœ๋“œ๋ฐธ๋Ÿฐ์„œ - ALB ์ƒ์„ฑ - ์ด๋ฆ„ : seoul-alb - VPC : MY-VPC - ๋งคํ•‘ : a,c ;์„œ๋ธŒ๋„ท : ํผ๋ธ”๋ฆญ - ๋ณด์•ˆ๊ทธ๋ฃน : SG-ALB - ๋ฆฌ์Šค๋„ˆ : HTTPS ; ๋Œ€์ƒ๊ทธ๋ฃน ์ƒ์„ฑ - ์ด๋ฆ„ : TG-SEOUL - ํ”„๋กœํ† ์ฝœ : HTTP - ๋‹ค์Œ - ์ธ์Šคํ„ด์Šค HA-seoul๋งŒ ์„ ํƒ - ์•„๋ž˜์— ๋ณด๋ฅ˜ ์ค‘์ธ ๊ฒƒ์„ ํฌํ•จ - ๋Œ€์ƒ๊ทธ๋ฃน์ƒ์„ฑ - ๋‹ค์‹œ๋กœ๋“œ๋ฐธ๋Ÿฐ์„œ ํƒญ - ๋Œ€์ƒ๊ทธ๋ฃน TG-SEOUL์„ ํƒ - ACM์ธ์ฆ์„œ - ๋งŒ๋“ค์–ด๋‘” ๋„๋ฉ”์ธ์ธ์ฆ์„œ์„ ํƒ - ๋กœ๋“œ๋ฐธ๋Ÿฐ์„œ ์ƒ์„ฑ

โœ”๏ธ ๋„์ฟ„ - ๋กœ๋“œ๋ฐธ๋Ÿฐ์„œ - ALB ์ƒ์„ฑ - ์ด๋ฆ„ : tokyo-alb - VPC : DEF - ๋งคํ•‘ : a,c - ๋ณด์•ˆ๊ทธ๋ฃน : ์ƒˆ ๋ณด์•ˆ๊ทธ๋ฃน ์ƒ์„ฑ - ๋ณด์•ˆ๊ทธ๋ฃน ์ด๋ฆ„ : SG-ALB - ์„ค๋ช… : SG-ALB - ์ธ๋ฐ”์šด๋“œ ๊ทœ์น™์ถ”๊ฐ€ - HTTP,HTTPS (any.ipv4) - ๋ณด์•ˆ๊ทธ๋ฃน์ƒ์„ฑ ํด๋ฆญ - ๋‹ค์‹œ๋กœ๋“œ๋ฐธ๋Ÿฐ์„œ ์ƒ์„ฑ ํƒญ์œผ๋กœ ์™€์„œ, SG-ALB์„ ํƒ - ๋ฆฌ์Šค๋„ˆ : HTTPS, ๋Œ€์ƒ๊ทธ๋ฃน์ƒ์„ฑ ํด๋ฆญ - ์ด๋ฆ„ : TG-TOKYO- ํ”„๋กœํ† ์ฝœ : HTTP - ๋‹ค์Œ - ์ธ์Šคํ„ด์Šค HA-tokyo๋งŒ ์„ ํƒ - ์•„๋ž˜์— ๋ณด๋ฅ˜ ์ค‘์ธ ๊ฒƒ์„ ํฌํ•จ - ๋Œ€์ƒ๊ทธ๋ฃน ์ƒ์„ฑ ํด๋ฆญ -๋‹ค์‹œ๋กœ๋“œ๋ฐธ๋Ÿฐ์„œ ํƒญ - ๋Œ€์ƒ๊ทธ๋ฃน TG-TOKYO์„ ํƒ - ACM์ธ์ฆ์„œ ; ์ƒˆ ACM์ธ์ฆ์„œ ์š”์ฒญ - ์ธ์ฆ์„œ ์š”์ฒญ - ํผ๋ธ”๋ฆญ ์ธ์ฆ์„œ ์š”์ฒญ - ์™„์ „ํžˆ ์ •๊ทœํ™”๋œ ๋„๋ฉ”์ธ ์ด๋ฆ„ : *.lovemj.shop - DNS ๊ฒ€์ฆ - ๊ถŒ์žฅ ์ฒดํฌ - ์š”์ฒญ ํด๋ฆญ - ๋‹ค์‹œ ๋กœ๋“œ๋ฐธ๋Ÿฐ์Šค ์ƒ์„ฑ๋ชฐ๋ก์—์„œ - ๋งŒ๋“ค์–ด๋‘” ์ธ์ฆ์„œ ์„ ํƒ - ๋กœ๋“œ ๋ฐธ๋Ÿฐ์„œ์ƒ์„ฑ

๐Ÿ“Œ route53

๐Ÿ“™ํ…Œ์ŠคํŠธ ( ๋‹จ์ˆœ ๋ผ์šฐํŒ…)


๊ฐ ์ง€์—ญ์ด๋ฆ„์˜ ์›น์„œ๋ฒ„ IP๋‹ค ๋„ฃ๊ธฐ

๐Ÿ“™ alb ๋„๋ฉ”์ธ ์ƒ์„ฑ

์„œ์šธ

๋„์ฟ„

๐Ÿ“™ ์ƒํƒœ๊ฒ€์‚ฌ

โœ”๏ธactive
์ƒํƒœ๊ฒ€์‚ฌ - ์ƒํƒœ๊ฒ€์‚ฌ ์ƒ์„ฑ- ์ด๋ฆ„ : active - ๋„๋ฉ”์ธ ์ด๋ฆ„ ์ฒดํฌ - ํ”„๋กœํ† ์ฝœ : HTTPS - ๋„๋ฉ”์ธ์ด๋ฆ„ : ์„œ์šธ alb ๋„๋ฉ”์ธ

๊ณ ๊ธ‰๊ตฌ์„ฑ - ์š”์ฒญ ๊ฐ„๊ฒฉ : ํ‘œ์ค€30์ดˆ - ์‹คํŒจ ์ž„๊ณ„๊ฐ’ : 1 - ๋‹ค์Œ - ๊ฒฝ๋ณด์ƒ์„ฑ ์•„๋‹ˆ์˜ค - ์ƒํƒœ๊ฒ€์‚ฌ์ƒ์„ฑ

โœ”๏ธpassive
์ƒํƒœ๊ฒ€์‚ฌ์ƒ์„ฑ - ์ด๋ฆ„ : passive - ๋„๋ฉ”์ธ ์ด๋ฆ„ - ํ”„๋กœํ† ์ฝœ : HTTPS - ๋„๋ฉ”์ธ ์ด๋ฆ„ : ๋„์ฟ„ alb ๋„๋ฉ”์ธ - ๊ณ ๊ธ‰ - ์ž„๊ณ„๊ฐ’ : 1 - ๋‹ค์Œ - ๊ฒฝ๋ณด์ƒ์„ฑ ์•„๋‹ˆ์˜ค- ์ƒํƒœ๊ฒ€์‚ฌ์ƒ์„ฑ

๐Ÿ“™โœ”๏ธโœ๏ธ๐Ÿ“ขโญ๏ธ๐Ÿ“Œ

๐Ÿ“Œ ๊ธฐํƒ€

โญ๏ธ GLANCE

OPENSTACK ์ด๋ฏธ์ง€ ๋‹ค๋ฃจ๋Š” ์„œ๋น„์Šค

โญ๏ธs2s

Site to Site

โญ๏ธ transit ๊ฒŒ์ดํŠธ์›จ์ด vs ๊ฐ€์ƒ ํ”„๋ผ์ด๋น— ๊ฒŒ์ดํŠธ ์›จ์ด

๊ฐ€์ƒํ”„๋ผ์ด๋น— ๊ฒŒ์ดํŠธ์›จ์ด๋ฅผ ์ด์šฉํ•˜๋Š” ์ด์œ  ? VPN์—ฐ๊ฒฐ๋งŒ์„ ์œ„ํ•ด. transit์€ ์—ฌ๋Ÿฌ ๊ธฐ๋Šฅ์ด ์žˆ์Œ.
๊ฐ€์ƒ ํ”„๋ผ์ด๋น—์–ด ๋” ์ €๋ ดํ•จ. ๋น„์šฉํšจ์œจ์ .

โญ๏ธ ์ด์ค‘ํ™” (VRRP)๋กœ๋“œ๋ฐธ๋Ÿฐ์„œ ์žฅ์น˜๋ฅผ ๋‘ ๊ฐœ๋กœ.

profile
๊พธ์ค€ํžˆ, ์ฐจ๊ทผ์ฐจ๊ทผ
post-custom-banner

0๊ฐœ์˜ ๋Œ“๊ธ€