AWSã䜿ã£ãŠã€ã³ãã©æ§ç¯ãããéã«ããŸãæåã«åºãŠããã®ããVPCãããµããããããã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ããã«ãŒãããŒãã«ããšããçšèªã
ãã®èšäºã§ã¯ã以äžã®å 容ãå³ãçšããŠãããããã解説ããŠããŸãããã®èšäºãèªãã°ãAWSã§ã€ã³ã¿ãŒãããæ¥ç¶å¯èœãªç°å¢ãæ§ç¯ããããšãã§ããŸãã
- VPCãšã¯ïŒ
- VPCãäœæãããªãŒãžã§ã³ãéžã¶
- VPCãäœæããæ¹æ³
- ãµãããããšã¯ïŒ
- VPCã«ãµãããããäœæããæ¹æ³
- ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãšã¯ïŒ
- ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãäœæããŠãVPCã«ã¢ã¿ããããæ¹æ³
- ã«ãŒãããŒãã«ãšã¯ïŒ
- ã«ãŒãããŒãã«ã«ã«ãŒãã远å ããæ¹æ³
- ã«ãŒãããŒãã«ãšãµãããããé¢é£ä»ããæ¹æ³
VPCãšã¯ïŒ
VPCïŒAmazon Virtual Private CloudïŒã¯ãAWSäžã«æ§ç¯ã§ããèªåå°çšã®ãããã¯ãŒã¯ç©ºéã§ããäŸãããªããèªåã®å®¶ã®LANïŒããŒã«ã«ãããã¯ãŒã¯ïŒãã®ãããªãã®ã§ãã
ãã®VPCã®äžã«ã¯ãEC2ïŒä»®æ³ãµãŒããŒïŒãRDSïŒããŒã¿ããŒã¹ïŒãªã©ã®AWSãªãœãŒã¹ãèªç±ã«é 眮ããããšãã§ããã€ã³ã¿ãŒãããæ¥ç¶ã®æç¡ãã¢ã¯ã»ã¹å¶åŸ¡ãIPã¢ãã¬ã¹ã®å²ãåœãŠãªã©ã现ããèšå®ã§ããŸãã
VPCã®ç¹åŸŽ
- ä»ã®ãŠãŒã¶ãŒãšã¯å®å šã«éé¢ãããŠãããããå®å šæ§ãé«ã
- ãããã¯ãŒã¯æ§æãèªç±ã«ã«ã¹ã¿ãã€ãºå¯èœ
- VPCã®äœæèªäœã«ã¯æéã¯ããããªãïŒéä¿¡ãªã©ã«ã¯èª²éããïŒ
ãè£è¶³ãAWSã¢ã«ãŠã³ãäœæçŽåŸã®ç¶æ
AWSã¢ã«ãŠã³ããäœã£ãçŽåŸã¯ä»¥äžã®ãããªç¶æ ã«ãªã£ãŠããŸãã

AWSã®ã¢ã«ãŠã³ããäœæããçŽåŸã¯ãããã«äœ¿ãå§ããããããã«ãããã©ã«ãVPCãããããã©ã«ããµããããããªã©ãèªåã§çšæãããŠããŸãããã ãããããã¯ãããŸã§ã詊ããåæèšå®çšã®ãã®ã§ãããã»ãã¥ãªãã£é¢ã®å¶éããããããæ¬çªç°å¢ã§ã¯ããŸã䜿ãããªããããäžå³ã§ã¯å²æããŠããŸãã
ãã®èšäºã§ã¯ã以äžã®æ§æãäœæããŸãã

ãã®æ§æãäœæããããã«ã¯ã以äžã®äœæ¥ãè¡ãå¿ èŠããããŸãã
- æ°èŠã«VPCãäœæãã
- ãã®VPCå ã«ãµããããïŒããã§ã¯ãããªãã¯ãµããããïŒãäœæãã
- ã€ã³ã¿ãŒããããžæ¥ç¶ããããã®ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãäœæããŠãVPCã«ã¢ã¿ãããã
- ã«ãŒãããŒãã«ã«ã«ãŒãã远å ãããµããããã«é¢é£ä»ãã
ãããã®äœæ¥ãè¡ãããšã§ã€ã³ã¿ãŒãããæ¥ç¶å¯èœãªç°å¢ãæŽããŸããã§ã¯ããŸãVPCã®äœæããè¡ããŸãããã
ã¹ããã1ïŒVPCãäœæãããªãŒãžã§ã³ãéžã¶
VPCã¯ãã©ã®ãªãŒãžã§ã³ã«äœæãããããæåã«æ±ºããå¿ èŠããããŸãã
ä»åã¯æ¥æ¬ããã®å©çšãæ³å®ããŠããã¢ãžã¢ãã·ãã£ãã¯ïŒæ±äº¬ïŒããªãŒãžã§ã³ã䜿çšããŸããAWSãããžã¡ã³ãã³ã³ãœãŒã«å³äžã®ããªãŒãžã§ã³éžæãã«ããŠã³ãããããã¢ãžã¢ãã·ãã£ãã¯ïŒæ±äº¬ïŒããéžæããŠæ±äº¬ãªãŒãžã§ã³ã«åãæ¿ããŸãã

ã¹ããã2ïŒVPCãäœæãã
VPCãäœæããŸããAWSãããžã¡ã³ãã³ã³ãœãŒã«ã«ãã°ã€ã³ããäžéšã®æ€çŽ¢ããŒã§ãVPCããæ€çŽ¢ããŠéããŸãã

ãVPCãäœæããã¯ãªãã¯ããŸãã

VPCäœæç»é¢ãéããŸãã以äžã®å 容ãå ¥åãããVPCãäœæããã¯ãªãã¯ããŸãã
- äœæãããªãœãŒã¹
- ãVPCã®ã¿ããéžæããŸãã
- ååã¿ã°
my-vpc-01
ãªã©ãããããããååãå ¥åããŸãã- AWSã§ã¯å€ãã®ãªãœãŒã¹ãæ±ããããæå³ã®ããååãã€ããŠãããšç®¡çãæ¥œã«ãªããŸãã
- IPv4 CIDR ãããã¯
- VPCã®IPv4ã¢ãã¬ã¹ç¯å²ãCIDR圢åŒã§å ¥åããŸãã
- ããã§ã¯ã
10.0.0.0/16
ãå ¥åããŠããŸãã - ãªããAWSäžã«æ§ç¯ããã·ã¹ãã ã§ã¯ã次ã®ãã©ã€ããŒãIPã¢ãã¬ã¹ã®ç¯å²å
ã§ã
/16
ã/28
ã®CIDRãããã¯ãæå®ããå¿ èŠããããŸãã䜿ããç¯å²ã¯ã以äžã®3ã€ã§ã10.0.0.0
ïœ10.255.255.255
(10.0.0.0/8
ãã¬ãã£ãã¯ã¹)172.16.0.0
ïœ172.31.255.255
(172.16.0.0/12
ãã¬ãã£ãã¯ã¹)192.168.0.0
ïœ192.168.255.255
(192.168.0.0/16
ãã¬ãã£ãã¯ã¹)
- å®éã®ã·ã¹ãã ã§ã¯ä»ã®ãããã¯ãŒã¯ãšæ¥ç¶ããå¯èœæ§ããããããä»ã·ã¹ãã ãšéè€ããªãIPç¯å²ãéžã¶ã®ãéèŠã§ãã
- IPv4ã¢ãã¬ã¹ç¯å²ã¯VPCäœæåŸã¯å€§ããã§ããªãã®ã§ã倧ããã«èšå®ããããšãããããããŸãã
- IPv6 CIDR ãããã¯
- AWSãçšæããŠããIPv6ã¢ãã¬ã¹ãå²ãåœãŠãããŸãããä»åã¯ç¹ã«äœ¿çšããªããããIPv6 CIDR ãããã¯ãªããã«ãã§ãã¯ãå ¥ããŸãã
- ããã³ã·ãŒ
- ä»®æ³ã€ã³ã¹ã¿ã³ã¹ãã©ããªç©çãã¹ãïŒãµãŒããŒïŒã§åããããæ±ºããèšå®ã§ãã
- ãããã©ã«ãïŒå ±æïŒããéžæããŸããããã©ã«ãã§ã¯ãä»ã®ãŠãŒã¶ãŒãšåãç©çãã¹ãã®äžã§ä»®æ³ã€ã³ã¹ã¿ã³ã¹ãåããŸããååã»ãã¥ãªãã£ãä¿ãããŠããŠãã³ã¹ããå®ããã¿ãŸãã
- ãå°æïŒDedicatedïŒãã«ãããšç©çãã¹ããèªåã ãã§äœ¿ãèšå®ã«ãªããŸããã³ã¹ããé«ããªãã®ã§ãç¹å¥ãªçç±ããªããã°ãããã©ã«ãïŒå ±æïŒãã§ååã§ãã

VPCãäœæãããŸããããã䜿ãã®VPCããã¯ãªãã¯ããŸãããã

VPCã®äžèЧã衚瀺ãããŸããä»åäœæããVPCïŒmy-vpc-01
ïŒã远å ãããŠããããšãåãããŸãã

ããã§VPCã®äœæãå®äºã§ãã
ä»åã10.0.0.0/16
ãšããCIDRãããã¯ãæå®ããŠVPCãäœæããŸããããã®èšå®ã«ãããæå€§ã§65,536åã®IPã¢ãã¬ã¹ããã®VPCå
ã§å©çšã§ããããã«ãªããŸãããªããä»ã®æ§æã¯ä»¥äžã®ããã«ãªã£ãŠããŸãã

è£è¶³
- VPCãäœæãããšåæã«ããã©ãã£ãã¯ã®æµãïŒéä¿¡çµè·¯ïŒã管çããããã®ãããã©ã«ãã«ãŒãããŒãã«ããèªåçã«äœãããŸãããã ãããã®ã«ãŒãããŒãã«ã«ç»é²ãããŠããã«ãŒã«ã¯ããåãVPCå ã®éä¿¡ã ãèš±å¯ããããšããæäœéã®ã«ãŒã«ã®ã¿ã§ãããã®ããããã®ãŸãŸã§ã¯ã€ã³ã¿ãŒããããžã®éä¿¡ãªã©ã¯ã§ããŸãããã€ã³ã¿ãŒãããã«ã¯æ¥ç¶ããã«ã¯ããã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ã®äœæããšãã«ãŒãã®è¿œå ããå¿ èŠã«ãªããŸããåŸã»ã©ãã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ã®äœæããšãã«ãŒãã®è¿œå ãã«ã€ããŠèª¬æããŸãã
- ãŸããããããã¯ãŒã¯ACLïŒã¢ã¯ã»ã¹ã³ã³ãããŒã«ãªã¹ãïŒããšãããéä¿¡ãå¶åŸ¡ããããäžã€ã®ãªãœãŒã¹ãèªåäœæãããŠããŸããããã¯ãVPCå ã®ãµããããããšã«éä¿¡ã®èš±å¯ã»æåŠãèšå®ãããã®ã§ãããä»åã¯èšå®ã倿Žããªããã説æã¯çç¥ããŸãã
- ããã«ããã»ãã¥ãªãã£ã°ã«ãŒãããèªåçã«äœæãããŸããããã¯ãã€ã³ã¹ã¿ã³ã¹åäœã§éä¿¡ãå¶åŸ¡ããããã®ãã¡ã€ã¢ãŠã©ãŒã«ã®ãããªæ©èœã§ããããã©ã«ãã§ã¯ãåãã»ãã¥ãªãã£ã°ã«ãŒãã«æå±ããã€ã³ã¹ã¿ã³ã¹éã®éä¿¡ã®ã¿ãã€ã³ããŠã³ãïŒåä¿¡ïŒã§èš±å¯ãããã¢ãŠãããŠã³ãïŒéä¿¡ïŒã¯ãã¹ãŠã®éä¿¡ãèš±å¯ãããŠããŸããã»ãã¥ãªãã£ã°ã«ãŒãã¯ã¹ããŒããã«ã§ãããããã€ã³ããŠã³ãã§èš±å¯ãããéä¿¡ã«å¯Ÿããå¿çã¯ã¢ãŠãããŠã³ãã§ãèªåçã«èš±å¯ãããŸããä»åã¯èšå®ã倿Žããªããã説æã¯çç¥ããŸãã
ãµãããããšã¯ïŒ
VPCã¯æå®ããIPã¢ãã¬ã¹ã®ç¯å²ïŒCIDRãããã¯ïŒã䜿ã£ãŠãããã¯ãŒã¯ãæ§æããŸããããšãã°ãå
ã»ã©ã®ã¹ãããã§æå®ãã10.0.0.0/16
ã§ã¯ãVPCå
šäœã§65,536åã®IPã¢ãã¬ã¹ã䜿ããããšã«ãªããŸãããã ããå
šãŠã®ã€ã³ã¹ã¿ã³ã¹ããã®VPCã«çœ®ããšã管çãç
©éã«ãªã£ãŠããŸããŸãã
ããã§IPã¢ãã¬ã¹ã®ç¯å²ãããå°ããåå²ããŠãè«ççãªã°ã«ãŒããšããŠæ±ããããã«ãããã®ãããµããããïŒSubnetïŒãã§ãããã®ãµããããã®äžã«ãEC2ã€ã³ã¹ã¿ã³ã¹ïŒä»®æ³ãµãŒããŒïŒãRDSã€ã³ã¹ã¿ã³ã¹ïŒããŒã¿ããŒã¹ïŒãªã©ã®AWSãªãœãŒã¹ãé 眮ããŸãã
ãµããããã䜿ãããšã§ããããã¯ãŒã¯ãå¯èŠåã»åé¡ã»å¶åŸ¡ãããããªããŸããäŸãã°ããå€éšãšéä¿¡ãããšãªã¢ïŒãããªãã¯ãµããããïŒããšãå€éšããã¯éé¢ããããšãªã¢ïŒãã©ã€ããŒããµããããïŒããªã©ã«åããããšãã§ããŸããä»åã¯ãã€ã³ã¿ãŒãããã«æ¥ç¶ã§ããããããªãã¯ãµããããããäœæããŸãã
ã¹ããã3ïŒVPCã«ãµãããããäœæãã
ãVPCãã®ç»é¢ã®å·Šã¡ãã¥ãŒã§ããµããããããã¯ãªãã¯ããŸãã

ç»é¢å³åŽã«ãµããããã®äžèЧã衚瀺ãããŸããããã§ããµãããããäœæããã¿ã³ãã¯ãªãã¯ããŸãã

ãµããããäœæç»é¢ãéããŸãã以äžã®å 容ãå ¥åããããµãããããäœæããã¯ãªãã¯ããŸãã
- VPC ID
- ãµãããããã©ã®VPCã«äœæããããæå®ããŸãã
- ããã§ã¯åã®ã¹ãããã§äœæããVPCïŒäŸïŒ
my-vpc-01
ïŒãéžæããŸãã
- ãµããããå
- ãµããããã«ä»ããååãå ¥åããŸãã
- ããã§ã¯ã
public-my-subnet-1a
ãšå ¥åããŸããã - ååã¯ä»»æã§ããã管çããããããããã«ã以äžã®ãããªåœåãããããã§ãã
public-subnet-1a
ïŒã€ã³ã¿ãŒãããæ¥ç¶å¯èœãªãµããããã§ãã¢ãã€ã©ããªãã£ãŸãŒã³ã1aãçšïŒprivate-subnet-1c
ïŒã€ã³ã¿ãŒãããæ¥ç¶ããªããµããããã§ãã¢ãã€ã©ããªãã£ãŸãŒã³ã1cãçšïŒ
- ã¢ãã€ã©ããªãã£ãŸãŒã³
- ãµãããããé
眮ããã¢ãã€ã©ããªãã£ãŸãŒã³ïŒAZïŒãéžã³ãŸããæ±äº¬ãªãŒãžã§ã³ã¯4ã€ã®AZã§æ§æãããŠããŸãããé垞䜿çšã§ããã®ã¯ä»¥äžã®ïŒã€ãšãªããŸãã
ap-northeast-1a
ap-northeast-1c
ap-northeast-1d
- ããã§ã¯ã
ap-northeast-1a
ãéžæããŸããã
- ãµãããããé
眮ããã¢ãã€ã©ããªãã£ãŸãŒã³ïŒAZïŒãéžã³ãŸããæ±äº¬ãªãŒãžã§ã³ã¯4ã€ã®AZã§æ§æãããŠããŸãããé垞䜿çšã§ããã®ã¯ä»¥äžã®ïŒã€ãšãªããŸãã
- IPv4 ãµãããã CIDR ãããã¯
- ãã®ãµããããã§äœ¿çšããIPã¢ãã¬ã¹ã®ç¯å²ãCIDR圢åŒã§æå®ããŸãã
- ããã§ã¯ã
10.0.1.0/24
ïŒâçŽ256åã®IPã¢ãã¬ã¹ãå©çšå¯èœïŒãå ¥åããŸããã - ããµããããã§äœ¿çšããIPã¢ãã¬ã¹ã®ç¯å²ãã¯ãVPCã§æå®ããIPã¢ãã¬ã¹ã®ç¯å²å
ïŒããã§ã¯ã
10.0.0.0/16
ïŒãã«åãŸã£ãŠããã°OKã§ãã

ãµããããïŒããã§ã¯ãpublic-my-subnet-1a
ïŒãäœæãããŸããã

ä»ã®æ§æã¯ä»¥äžã®ãããªç¶æ ã«ãªã£ãŠããŸãã

ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãšã¯ïŒ
ãããŸã§ã§ã以äžã®æ§æãæŽããŸããã
- VPCïŒä»®æ³ãããã¯ãŒã¯ç©ºéïŒã®äœæ
- ãµããããïŒå°ããªãããã¯ãŒã¯åäœïŒã®äœæ
ãããããã®ãŸãŸã§ã¯ã€ã³ã¿ãŒããããšã®éä¿¡ãã§ããŸããããªããªããã€ã³ã¿ãŒããããžã®åºå ¥ãå£ãšãªããã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ïŒInternet GatewayïŒãããªãããã§ãã
ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ã¯ãVPCå ã®ãªãœãŒã¹ïŒEC2ãªã©ïŒãšãå€éšã®ã€ã³ã¿ãŒããããšã®éã§éä¿¡ãå¯èœã«ããããã«å¿ èŠã§ããããšãã°ãVPCå ã«EC2ã€ã³ã¹ã¿ã³ã¹ãç«ã¡äžããŠWebãµãŒããŒãšããŠå ¬éãããå Žåããã®ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãéããŠã€ã³ã¿ãŒãããããã¢ã¯ã»ã¹ãããããšã«ãªããŸãã
ã§ã¯ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãäœæããŠãããŸãããã
ã¹ããã4ïŒã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãäœæããŠãVPCã«ã¢ã¿ãããã
VPCç»é¢ã®å·Šã¡ãã¥ãŒã§ãã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ããã¯ãªãã¯ããŸãã

ç»é¢å³åŽã«ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ã®äžèЧã衚瀺ãããŸãããã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãäœæããã¯ãªãã¯ããŸãã

ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€äœæç»é¢ãéããŸãã以äžã®å 容ãæå®ãããã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãäœæããã¯ãªãã¯ããŸãã
- ååã¿ã°
igw-my-vpc-01
ãªã©ã管çããããããã«ãååãä»ããŠãããŸãããã- ããã§ã¯ã
my-internet-gateway
ãå ¥åããŠããŸãã

ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãäœæãããŸããããããããã®æç¹ã§ã¯ãdetachedïŒæªæ¥ç¶ïŒãã®ç¶æ ã«ãªã£ãŠããŸããã€ãŸãããŸã ã©ã®VPCã«ãæ¥ç¶ïŒã¢ã¿ããïŒãããŠããããåäœã§ã¯æ©èœããŠããŸãããç¶ããŠVPCãžã®ã¢ã¿ããã宿œããã®ã§ãç»é¢äžéšããŒã®ãVPCãžã¢ã¿ããããã¯ãªãã¯ããŸãã

ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãã¢ã¿ããããVPCïŒmy-vpc-01
ïŒãéžæãããã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ã®ã¢ã¿ããããã¯ãªãã¯ããŸãã
ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãVPCã«æ¥ç¶ããäœæ¥ããã¢ã¿ããããšåŒã³ãŸãã

ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ã®ã¢ã¿ãããå®äºããŸãããã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ã®ç¶æ ããAttachedãã«ãªãã°VPCãšã®çŽä»ããå®äºã§ããããã§ãVPCã«ã€ã³ã¿ãŒããããšã®åºå ¥å£ãæ¥ç¶ãããã«ãŒãããŒãã«ãæ£ããèšå®ããã°ãVPCå ã®ãªãœãŒã¹ããå€éšã€ã³ã¿ãŒããããžã®éä¿¡ãå¯èœã«ãªããŸãã

ãªããä»ã®æ§æã¯ä»¥äžã®ãããªç¶æ ã«ãªã£ãŠããŸãã

ã«ãŒãããŒãã«ãšã¯ïŒ
åã®ã¹ãããã§ãVPCã«ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãã¢ã¿ããããããšãã§ããŸãããããã«ãããVPCããã€ã³ã¿ãŒããããžåºãŠããããã®åºå ¥å£ã確ä¿ãããç¶æ ã«ãªããŸããã
ããããçŸåšã®ãŸãŸã§ã¯ãŸã ã€ã³ã¿ãŒãããéä¿¡ã¯ã§ããŸããããªããªãããã©ãå®ãŠã®éä¿¡ããã©ãã«æµããããšããã«ãŒã«ïŒã«ãŒãã£ã³ã°æ å ±ïŒãã«ãŒãããŒãã«ã«èšå®ãããŠããªãããã§ãã
ã«ãŒãããŒãã«ïŒRoute TableïŒã¯ããããã¯ãŒã¯å ã®éä¿¡ã®âéé âãæ±ºããããã®èšå®ã§ããããšãã°ã以äžã®ãããªã«ãŒã«ãå®çŸ©ã§ããŸãã
- ãèªåãšåããããã¯ãŒã¯å ïŒVPCå ïŒãžã®éä¿¡ â ãã®ãŸãŸå éšéä¿¡ã
- ãã€ã³ã¿ãŒãããäžïŒå€éšïŒãžã®éä¿¡ïŒäŸïŒGoogleãGitHubãªã©ïŒ â ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãéãã
VPCäœææã«ã¯ããã©ã«ãã®ã«ãŒãããŒãã«ãèªåçã«1ã€äœæãããŠããããããæ°ããäœæããããµããããã«èªåã§é¢é£ä»ããããŠããŸããããããããã©ã«ãã®ã«ãŒãããŒãã«ã«ã¯ããVPCå ã®IPã¢ãã¬ã¹å®ã®éä¿¡ã¯VPCå ã§å®çµããããšããæå°éã®ã«ãŒã«ããèšå®ãããŠããŸãããã€ãŸããçŸç¶ã§ã¯ãããªã£ãŠããŸãã
- èªåãšåããããã¯ãŒã¯å ïŒVPCå ïŒãžã®éä¿¡ â OK
- ã€ã³ã¿ãŒãããäžïŒå€éšïŒã®éä¿¡ â NGïŒã«ãŒãããªãããéããªãïŒ
ããã§ãã€ã³ã¿ãŒãããéä¿¡ãå¯èœã«ããããã«ããå šãŠã®å€éšå®ãŠéä¿¡ïŒ0.0.0.0/0ïŒã¯ãã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãéãããšããã«ãŒã«ã远å ããŠãããŸãã
ã¹ããã5ïŒã«ãŒãããŒãã«ã«ã«ãŒãã远å ãã
VPCç»é¢ã®å·Šã¡ãã¥ãŒã§ãã«ãŒãããŒãã«ããã¯ãªãã¯ããŸããVPCãäœæããéã«èªåçã«äœæãããVPCã®ãããã©ã«ãã«ãŒãããŒãã«ããéžæåŸãç»é¢äžãã€ã³ã§ãã«ãŒããã¿ããã¯ãªãã¯ããŠããã«ãŒããç·šéããã¯ãªãã¯ããŸãã

ããã§ã¯ãããã©ã«ãã«ãŒãããŒãã«ã«è¿œå ã®ã«ãŒããç»é²ããŠããŸããããããæ°èŠäœæãããµããããã¯èªåçã«ããã©ã«ãã«ãŒãããŒãã«ãžé¢é£ä»ãããããããã€ã³ã¿ãŒããããžéä¿¡ããªããã©ã€ããŒããµãããããäœãå¯èœæ§ãããå Žåã¯ããããããŸãããæ°èŠã§ã«ãŒãããŒãã«ãäœæããããšãããããããŸãã
ã«ãŒãç·šéç»é¢ãéããŸããã«ãŒãç·šéç»é¢ãéããšãçŸæç¹ã§ã¯1ã€ã ãã®ã«ãŒãæ
å ±ãç»é²ãããŠããã®ã確èªã§ããŸããããã¯ã10.0.0.0/16
ïŒä»åäœæããVPCã®IPã¢ãã¬ã¹ç¯å²ïŒã«å¯Ÿããã«ãŒãã§ãããã®ã«ãŒãã®ã¿ãŒã²ããã¯ãlocalïŒããŒã«ã«ïŒããšãªã£ãŠããŸããããã¯ãVPCå
ã§ã®éä¿¡ã¯ãã®ãŸãŸå¯èœãšããæå³ã§ãããã ãããã以å€ã®ãã¹ãŠã®éä¿¡ïŒããšãã° éä¿¡å
ã8.8.8.8
ã 1.1.1.1
ãªã©ïŒã«ãããŠãã€ã³ã¿ãŒãããäžã®å€éšãµãŒããŒã«ã¢ã¯ã»ã¹ããããšãããšãããã®éä¿¡å
ã®ã«ãŒããå®çŸ©ãããŠããªãããããã¹ãŠç Žæ£ãããïŒå±ããªãïŒããšããç¶æ
ã«ãªã£ãŠããŸããã€ãŸãä»ã®ãŸãŸã§ã¯ãVPCã®äžã®éä¿¡ã¯OKã ãã©ãã€ã³ã¿ãŒãããã«ã¯äžååºãŠãããªããšããæ§æã«ãªã£ãŠãããšããããšã§ãããªã®ã§ãã«ãŒãã远å ããŠãVPCå
å®ä»¥å€ã®éä¿¡ã«é¢ããŠã¯ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãžåãããã«èšå®ããŸãããã«ãŒãã远å ããã¯ãªãã¯ããŸãã

æ°èŠè¿œå ãããæ ã§éä¿¡å ã«ã0.0.0.0/0ããšå ¥åããã¿ãŒã²ããã«ãã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ããéžæããŸãã

èªåçã«ã¿ãŒã²ããã«ãigw-ããšå
¥åãããã®ã§ãéžæè¢ã®äžããå
ã»ã©äœæããã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ïŒããã§ã¯ãmy-internet-gateway
ïŒãéžæããã倿Žãä¿åããã¯ãªãã¯ããŸããããã§VPCå
å®ä»¥å€ã®éä¿¡ã«é¢ããŠã¯ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãžåãããã«èšå®ã§ããŸããã

0.0.0.0/0
ã¯ããã©ã«ãã«ãŒããšãã£ãŠãã«ãŒãããŒãã«ã«ç»é²ãããŠããã©ã®ã¢ãã¬ã¹ã«ãäžèŽããªãå Žåã®ã«ãŒãã§ãã10.0.0.0/16
以å€ãé€ããã¹ãŠã®IPv4ã¢ãã¬ã¹ã®ã¿ãŒã²ãããã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ã«ããŠããã®ã§ãVPCå
å®ä»¥å€ã®éä¿¡ã«é¢ããŠã¯ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãžåããŸãã
ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãžã®ã«ãŒãã远å ãããŠããããšã確èªã§ããŸãã

ã¹ããã6ïŒã«ãŒãããŒãã«ãšãµãããããé¢é£ä»ãã
åã®ã¹ãããã§ãã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãžã®ã«ãŒãïŒçµè·¯ïŒãã«ãŒãããŒãã«ã«è¿œå ããŸãããããã§ãã€ã³ã¿ãŒãããã«åºãŠããããã®éãã¯æŽããŸãããããã®ãŸãŸã§ã¯ãŸã éä¿¡ã§ããŸããã
AWSã§ã¯ããã©ã®ãµãããããã©ã®ã«ãŒãããŒãã«ã䜿ããããæç€ºçã«æå®ããå¿ èŠããããŸãããããã«ãŒãããŒãã«ã«ãã€ã³ã¿ãŒãããã«åºãã«ãŒãããèšå®ãããŠããŠãããµããããããã®ã«ãŒãããŒãã«ã䜿ã£ãŠããªããã°ãã€ã³ã¿ãŒãããéä¿¡ã¯è¡ãããŸããã
ã«ãŒãããŒãã«ãšãµããããã®é¢é£ä»ããè¡ããŸããããäœæããVPCã®ã«ãŒãããŒãã«ãéžæåŸãç»é¢äžãã€ã³ã§ããµããããã®é¢é£ä»ããã¿ããã¯ãªãã¯åŸãããµããããã®é¢é£ä»ããç·šéããã¯ãªãã¯ããŸãã

ä»åäœæãããµããããïŒããã§ã¯ãpublic-my-subnet-1a
ïŒãéžæãããé¢é£ä»ããä¿åããã¯ãªãã¯ããŸãã

ã«ãŒãããŒãã«ã«ãµãããããé¢é£ä»ããããšãã§ããŸããã

ä»ã®æ§æã¯ä»¥äžã®ãããªç¶æ ã«ãªã£ãŠããŸãã

æ¬èšäºã®ãŸãšã
ãã®èšäºã§ã¯ä»¥äžã®å 容ã説æããŸããã
- VPCãšã¯ïŒ
- VPCãäœæãããªãŒãžã§ã³ãéžã¶
- VPCãäœæããæ¹æ³
- ãµãããããšã¯ïŒ
- VPCã«ãµãããããäœæããæ¹æ³
- ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãšã¯ïŒ
- ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ãäœæããŠãVPCã«ã¢ã¿ããããæ¹æ³
- ã«ãŒãããŒãã«ãšã¯ïŒ
- ã«ãŒãããŒãã«ã«ã«ãŒãã远å ããæ¹æ³
- ã«ãŒãããŒãã«ãšãµãããããé¢é£ä»ããæ¹æ³
ãèªã¿é ãããããšãããããŸãããããšã¯ããã®ãããã¯ãŒã¯å ã«EC2ãèµ·åããã°ãã€ã³ã¿ãŒãããããã¢ã¯ã»ã¹ã§ãããµãŒããŒãç«ã¡äžãããŸãïŒ