π§± μ 체 ꡬ쑰 λ¨Όμ 보기
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "Example",
"Effect": "Allow",
"Principal": { },
"Action": [ ],
"Resource": "*"
}
]
}
π ν΅μ¬μ Statement μ 5κ° μμ π§© 1. Statement (μ 체 λ¬Άμ) π βνλμ κΆν κ·μΉβ β’ μ¬λ¬ κ° λ§λ€ μ μμ
β’ Principalλ§λ€ νλμ© λ§λλ κ² μ μ
π‘ μμ π βEC2κ° KMS μ¬μ© κ°λ₯β = Statement 1κ° π βSecrets Managerλ κ°λ₯β = Statement 1κ° π·οΈ 2. Sid (Statement ID) π κ·Έ κ·μΉ μ΄λ¦ (μλ³μ©) β’ κ·Έλ₯ μ΄λ¦μ΄λΌ κΈ°λ₯ μμ
β’ μ±μ μλ μν₯ κ±°μ μμ
π‘ μμ
"Sid": "AllowEC2"
π μλ―Έ: β’ EC2 κ΄λ ¨ κ·μΉμ΄κ΅¬λ
βοΈ 3. Effect
π νμ©μΈμ§ / κ±°λΆμΈμ§
β’ "Allow" β νμ© β
β’ "Deny" β κ±°λΆ β
π‘ μμ
"Effect": "Allow"
π μλ―Έ: β’ μ΄ μ‘°κ±΄μ νμ©
β οΈ λνμμλ κ±°μ 100% Allowλ§ μ
π€ 4. Principal (ν΅μ¬π₯)
π λκ° μ¬μ©ν μ μλμ§
π‘ μμ 1 (EC2 Role)
"Principal": {
"AWS": "arn:aws:iam::123456789012:role/EC2Role"
}
π EC2 μλ²κ° μ¬μ© π‘ μμ 2 (μλΉμ€)
"Principal": {
"Service": "secretsmanager.amazonaws.com"
}
π Secrets Manager μ¬μ© π― 5. Action π λ¬΄μ¨ νλμ ν μ μλμ§ π‘ KMSμμ μμ£Ό μ°λ 3κ°
"Action": [
"kms:Encrypt",
"kms:Decrypt",
"kms:GenerateDataKey"
]
π μλ―Έ: β’ Encrypt β μνΈν
β’ Decrypt β 볡νΈν
β’ GenerateDataKey β λ°μ΄ν° ν€ μμ±
β οΈ μ€μ ν¬μΈνΈ β’ Decrypt λΉ μ§λ©΄ β 볡νΈν μ€ν¨
β’ GenerateDataKey λΉ μ§λ©΄ β Secrets Manager μ€λ₯
π¦ 6. Resource π μ΄λ€ 리μμ€μ μ μ©ν μ§ π‘ μμ
"Resource": "*"
π μλ―Έ: β’ μ΄ KMS ν€ μ 체
π KMSμμλ λλΆλΆ * μ¬μ© (μν κΈ°μ€)
π₯ μ 체 μμ (μλ²½ μ΄ν΄μ©)
π μν©:
β’
EC2κ° Secrets Managerμμ DB λΉλ°λ²νΈ μ½μ
{
"Sid": "AllowEC2ToUseKMS",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::123456789012:role/EC2Role"
},
"Action": [
"kms:Decrypt",
"kms:Encrypt",
"kms:GenerateDataKey"
],
"Resource": "*"
}
π ν΄μ π Sid: EC2μ© κ·μΉ
π Effect: νμ©
π Principal: EC2Role
π Action: μ볡νΈν κ°λ₯
π Resource: μ΄ KMS ν€ π§ μ§μ§ μ€μν ν΄μ 곡μ π μ μ± μ½λ λ²:
Principalκ° Actionμ Resourceμ λν΄ Effect νλ€
π‘ μ μ©ν΄λ³΄λ©΄
π βEC2Roleμ΄ KMS ν€λ₯Ό μ볡νΈννλλ‘ νμ©β
π₯ μνμ© ν΅μ¬ μμ½νλͺ©μλ―ΈStatementκ·μΉ νλSidμ΄λ¦EffectAllow / DenyPrincipalλκ°Action무μμResourceμ΄λμ
π₯ λ§μ§λ§ ν λ°© μ 리
π βλκ°(Principal)κ° λ¬΄μ(Action)μ μ΄λ(Resource)μ λν΄ νμ©(Effect)λλμ§ μ μνλ κ²β
μνλ©΄ λ€μ λ¨κ³λ‘
π βμ΄ κ³Όμ μμ KMS + Secrets Manager + RDS νλ¦β
π βμ€μ μ μ λ°λ μν€ν μ²β μ΄κ±° μ΄μ΄μ λ± μνμ©μΌλ‘ λ§λ€μ΄μ€κ² π