AWS Identity uye Access Management

Chikamu 1 chechitatu

Muna 2011, Amazon yakaratidza kuwanikwa kweAWS Identity & Access Management (IAM) kutsigira CloudFront. IAM yakatanga muna 2010 uye yakasanganisira S3 kutsigirwa. AWS Identity & Access Management (IAM) inoita kuti uve nevashandisi vakawanda mukati meAAS account. Kana wakashandisa Amazon Web Services (AWS), iwe unoziva kuti nzira chete yekugadzirisa zvinyorwa muAWS zvinosanganisira kupa zita rako rekushandisa uye password kana kuwana zvigetsi.

Uku ndiko kuchengeteka kwechokwadi kune vakawanda vedu. IAM inopedza kukosha kwekugovana mapepaji uye kuwanika maiyi.

Kushandura nguva yedu yepamusoro yeAWS password kana kugadzira zvigadzirwa zvitsva inongova sarudzo inonyangadza apo mushandi anogona kusiya boka redu. IWS Identity & Access Management (IAM) yakanga iri kutanga kutanga kubvumira mumwe munhu wekombikiti nemunhu mumwe nomumwe. Zvisinei, isu tiri S3 / CloudFront user kuitira kuti tave tichitarisira CloudFront kuwedzerwa kune IAM iyo yakazoitika pakupedzisira.

Ndakawana magwaro ebasa iri kuti ave akapararira. Kune zvikwata zvishomanana zvepakati pechitatu izvo zvinopa huwandu hweshumiro yeIvaIri & Access Management (IAM). Asi vashandi vanowanzotadza saka ndakatsvaga sarudzo yakasununguka yekugadzirisa IAM nebasa redu Amazon S3.

Nyaya iyi inofamba nenzira yekugadzira Mutambo weMirayiridzo weMirairo unotsigira IAM nekugadzira boka / user neS3 access. Iwe unofanirwa kuva neAngs AWS S3 sekugadzirisa account usati watanga kugadzira Identity & Access Management (IAM).

Nyaya yangu, Kushandisa Amazon Simple Storage Service (S3), ichakutungamirira kuburikidza nekugadzirisa iyo AWS S3 account.

Heano matanho anobatanidzwa mukugadza nekushandisa mushumiri muIAM. Izvi zvakanyorwa zveWindows asi unokwanisa tweak kuti ushandiswe muLuxux, UNIX uye / kana Mac OSX.

  1. Isa nekugadzirisa Interface yeMirayiridzo (CLI)
  1. Gadzira Gulu
  2. Ipai Gwara Kuwana S3 Bucket uye CloudFront
  3. Gadzira User uye Wedzera Kuboka
  4. Gadzira Login Profile uye Gadzira Keys
  5. Test Access

Isa nekugadzirisa Interface yeMirayiridzo (CLI)

IAM Command Line Toolkit chirongwa cheJava chiripo muAwS Developers Tools yeAmazambique. Icho chibvumirano chinokubvumira kuti uite mirairo yeIAM API kubva pane shell utility (DOS yeWindows).

Zvose zvemirayiridzo yeIAM inogona kumhanya kubva kuRovera Prompt. Yese yemirairo inotanga ne "iam-".

Gadzira Gulu

Pano pane mazana emapoka makumi mapfumbamwe anogona kuumbwa pane imwe nhoroondo yeAWS. Kunyange zvazvo iwe unogona kuisa mvumo muIAM kumusangano wevashandisi, kushandisa mapoka kungava tsika yakanakisisa. Heino nzira yekuumba boka muIAM.

Ipai Gwara Kuwana S3 Bucket uye CloudFront

Zvitemo zvinodzora izvo boka rako rinokwanisa kuita muS3 kana CloudFront. Nokutadza, boka rako haringakwanisi kuwana chero chinhu muAWS. Ndakawana zvinyorwa zvemitemo kuti ive yakanaka asi pakuumba mazana emitemo, ndakaita zvishoma zvekuedza uye kukanganisa kuti zvinhu zvishandise nenzira yandida kuti vashande.

Iwe une zvingasarudzwa zvekugadzira mitemo.

Rimwe sarudzo iwe unogona kuvanyorera zvakananga muMutevere Prompt. Sezvo iwe ungangodaro uri kugadzira chirongwa uye uchichigadzirisa, kwandiri zvakaratidzika zviri nyore kuwedzera purogiramu yacho mumutauro wefaira uye wobva waisa iyo faira faira separameter ine murairo iam-groupup loadpolicy. Heino nzira yekushandisa text file uye kuisa kuIAM.

Pane zvakawanda zvingasarudzwa kana zvasvika pamitemo yeIAM. Amazon ine chitubu chaicho chiripo chiripo chinonzi AWS Policy Generator. Iri shanduro inopa GUI apo iwe unogona kugadzira mazano ako uye kuunza kode chaiyo iwe unoda kutevedzera mutemo. Iwe unogonawo kuongorora chikamu chePamusoro Purogiramu yeMutauro weKushandisa AWS Identity uye Access Access zvinyorwa zvepaIndaneti.

Gadzira User uye Wedzera Kuboka

Iyo nzira yekusika musikana mutsva uye kuwedzera kune boka kuti igovapa kuwanika kunosanganisira matanho maviri.

Gadzira Logon Profile uye Ita Keys

Panguva ino, iwe wakasika mushumiri asi unofanirwa kuvapa nenzira yekuwedzera uye kubvisa zvinhu kubva kuS3.

Pane zvipo zviviri zvinowanikwa kupa vashandi vako nekusvika kuS3 vachishandisa IAM. Iwe unogona kuisa Purogiramu yeNyore uye kupa vashandi vako ne password. Vanogona kushandisa zvigwaro zvavo kuti vapinde muAmazoni AWS Console. Icho chakanaka ndechokupa vashandi vako ruzivo rwekugona uye kiyi yekuvanzika. Vanogona kushandisa zvishandiso izvi muzvikwata zvepakati pechitatu seS3 Fox, CloudBerry S3 Explorer kana S3 Browser.

Gadzira Login Profile

Kugadzira Purogiramu yeNyoresa yevashandisi vako S3 inovapa zita rekushandisa uye password ravanogona kushandisa kuti vauye kuAmazone AWS Console.

Dza Keys

Kugadzira AWS Siri Access Access Chinoenderana neAWS Access Key ID inobvumira vashandi vako kushandisa sadhi yepurogiramu yepane seye yakambotaurwa. Ramba uchiyeuka kuti sekuchengeteka, iwe unogona kuwana zvigetsi izvi panguva yekuwedzera kwehuwandu hwemashandisi. Iva nechokwadi chekukopa uye kuisa zvakabuda kubva kuRovera Prompt uye uchengetedze mune faira faira. Iwe unogona kutumira faira kumunhu wako.

Test Access

Iye zvino zvawakasika mapoka eIAM / vashandisi uye wakapa mapoka ekugona kushandisa mazano, unoda kuedza kuwanikwa.

Console Access

Vashandisi vako vanogona kushandisa zita ravo rekushandisa uye password kuti vapinde muAWS Console. Zvisinei, iyi haisi peji rekutsvaga peji rekushandisa iro rinoshandiswa pakutevedzera AWS account.

Pane URL yakakosha yaungashandisa iyo ichapa fomu yekunyorera yeAngs account yako yeAwS chete. Heino URL kuti uende kuS3 yevashandi vako veIAM.

https://AWS-ACCOUNT-NUMBER.signin.aws.amazon.com/console/s3

IAWS-ACCOUNT-NUMBER ndiyo nhamba yako yenguva dzose yeAWS. Iwe unogona kuwana izvi nokupinda mukati maFomu yeWebhu Web Service Sign In. Login and click on Account | Basa reAunti. Nhamba yekambani yako iri munzvimbo yepamusoro yekona. Iva nechokwadi chokuti wabvisa dashes. I URL inogona kutarisa chimwe chinhu seS https://123456789012.signin.aws.amazon.com/console/s3.

Kushandisa Access Keys

Iwe unokwanisa kutora uye kuisa chero ipi zvayo yezvikwata zvechitatu zvekare zvinotaurwa munyaya ino. Pinda muIndaneti yako yeKupindira uye ChiShona ChiShona Chikamu pane zvinyorwa zvepakati pechitatu.

Ndinokurudzira zvakasimba kuti iwe ugadzire mutengi wekutanga uye uve nemushandisi uyo aedze zvizere kuti vanogona kuita zvose zvavanofanira kuita muS3. Mushure mokunge uchitsigira mumwe wevashandisi vako, unogona kuenderera mberi nekugadzira vese vashandisi vako S3.

Resources

Hezvino zvishomanana zvidzidzo kukupa kunzwisisa kwakanakisisa kweUnoziva & Access Management (IAM).