Cloud/aws

[ Aws ] S3 ๋งŒ๋“ค๊ณ  ๊ถŒํ•œ ์„ค์ •ํ•˜๊ธฐ - YEOL

tenchoi 2022. 12. 30. 13:26

๐Ÿ“€ ํ™˜๊ฒฝ 

Aws platform

๐Ÿ”– ๊ฐœ์š”

Aws์—์„œ S3๋ฅผ ๋งŒ๋“ค๊ณ  ๊ถŒํ•œ ์„ค์ •ํ•ด ์ค๋‹ˆ๋‹ค

๐Ÿ“’ ๋ชฉ์ฐจ

  • What is the S3
  • How to create S3

 

- What is the S3 

S3(Simple Storage Service)๋ž€ ํ™•์žฅ์„ฑ, ๋ฐ์ดํ„ฐ ๊ฐ€์šฉ์„ฑ, ๋ณด์•ˆ ๋ฐ ์„ฑ๋Šฅ์„ ์ œ๊ณตํ•˜๋Š” ๊ฐ์ฒด ์Šคํ† ๋ฆฌ์ง€ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค
๋‹ค์–‘ํ•œ ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•˜๊ณ  ์•ก์„ธ์Šค๋ฅผ ๊ด€๋ฆฌํ•˜๊ฑฐ๋‚˜ ์Šคํ† ๋ฆฌ์ง€ ๋กœ๊น… ๋ฐ ๋ชจ๋‹ˆํ„ฐ๋ง์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค

๊ถŒํ•œ ๊ด€๋ฆฌ๋ฅผ ํฌ๊ฒŒ 3๊ฐœ์˜ ์œ ํ˜•์œผ๋กœ ๋‚˜๋ˆด์Šต๋‹ˆ๋‹ค ์ง„ํ–‰ํ•˜๋ฉด์„œ ์„ค๋ช…๋“œ๋ฆฝ๋‹ˆ๋‹ค
- Public Access
- ACL(Access Control List)
- Bucket Policy

- How to create S3

Aws ๊ฒ€์ƒ‰์ฐฝ์—์„œ S3๋ฅผ ๊ฒ€์ƒ‰ํ•ฉ๋‹ˆ๋‹ค
๋ฒ„ํ‚ท ๋งŒ๋“ค๊ธฐ ๋ฒ„ํŠผ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค

 

์˜๋„์— ๋งž๋Š” ๋ฒ„ํ‚ท ๋ช…์„ ์ž‘์„ฑํ•ฉ๋‹ˆ๋‹ค
๊ตญ๋‚ด ๊ฐœ๋ฐœ์ผ ๊ฒฝ์šฐ ๋ฆฌ์ „์€ ๋‹น์—ฐํžˆ ์„œ์šธ๋กœ ํ•ฉ๋‹ˆ๋‹ค


ACL
๋ฒ„ํ‚ท ์†Œ์œ ์ž๋ฅผ ์ œ์™ธํ•˜๊ณ (๋‹ค๋ฅธ Aws ๊ณ„์ •) ๋ชจ๋“  ์œ ์ €๋‚˜ ์ธ์ฆ๋œ ์‚ฌ์šฉ์ž ๊ทธ๋ฃน๋“ฑ์—๊ฒŒ 
๊ฐ์ฒด, ๋ฒ„ํ‚ท์˜ ์ฝ๊ธฐ/์“ฐ๊ธฐ ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•ฉ๋‹ˆ๋‹ค
public ํ•˜๊ฒŒ ์ ‘๊ทผ์„ ํ—ˆ์šฉํ•˜๊ธฐ ์œ„ํ•ด ACL์„ ํ—ˆ์šฉํ•ฉ๋‹ˆ๋‹ค

 

Public Access
์™ธ๋ถ€ ๋ชจ๋“  ์‚ฌ์šฉ์ž์˜ ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ์„ค์ •ํ•˜๋Š” ๊ธฐ๋Šฅ์ž…๋‹ˆ๋‹ค

๋ชจ๋“  ์‚ฌ์šฉ์ž๊ฐ€ ์ ‘๊ทผ ๊ฐ€๋Šฅํ•˜๊ฒŒ ์„ค์ •ํ•ด ์ค๋‹ˆ๋‹ค
๋ณด์•ˆ์ƒ ๊ณต๊ฐœ๋˜์ง€ ๋ง์•„์•ผ ํ•  ํŒŒ์ผ์€ ์—…๋กœ๋“œ๋ฅผ ์ž์ œํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค 

 

์ด์™ธ์— ๊ธฐ๋ณธ์„ค์ •์€ default๋ฅผ ๋”ฐ๋ฆ…๋‹ˆ๋‹ค


ํŒŒ์ผ์„ ํ•˜๋‚˜ ์˜ฌ๋ ค ์ •์ƒ ๋™์ž‘ํ•˜๋Š”์ง€ ํ™•์ธํ•ด ๋ด…๋‹ˆ๋‹ค

 

์—…๋กœ๋“œ ๋ฒ„ํŠผ์„ ํด๋ฆญํ•œ ํ›„ ์ผ๋ฐ˜ํŒŒ์ผ์„ ์—…๋กœ๋“œํ•ฉ๋‹ˆ๋‹ค


์—…๋กœ๋“œ ํ•œ ๊ฐ์ฒด๋ฅผ ํด๋ฆญํ•ด URL์„ ์›น์‚ฌ์ดํŠธ์— ๊ฒ€์ƒ‰ํ•ฉ๋‹ˆ๋‹ค


์•„๋ž˜์™€ ๊ฐ™์ด ๊ถŒํ•œ์ด ๋ถ€์กฑํ•˜๋‹ค๊ณ  ๋‚˜์˜ต๋‹ˆ๋‹ค

 

Bucket Policy
๋ฒ„ํ‚ท ์ •์ฑ…์€ ์‚ฌ์šฉ ๊ถŒํ•œ์„ ๊ฐ€์ง€๋Š” ๊ถŒํ•œ ๋ฒ”์œ„๋ฅผ ์„ค์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค
ACL์— ๋น„ํ•ด ๋ณด๋‹ค ์„ธ๋ถ„ํ™”๋œ ์•ก์„ธ์Šค ๊ถŒํ•œ ๊ด€๋ฆฌ๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค

์ด๋ฏธ์ง€ ์šฐ์ธก ํ•˜๋‹จ์— ํŽธ์ง‘ ๋ฒ„ํŠผ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค

 

์ขŒ์ธก์˜ ๋ฒ„ํ‚ท ARN์„ ๋ณต์‚ฌํ•ฉ๋‹ˆ๋‹ค
์šฐ์ธก์˜ ์ •์ฑ… ์ƒ์„ฑ๊ธฐ๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค


์•„๋ž˜์˜ ํŽ˜์ด์ง€์—์„œ ์ •์ฑ… ์ƒ์„ฑ์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค
Select Policy: S3 Bucket Policy
principal: *
Action: GetObject
ARN: ์กฐ๊ธˆ ์ „ ๋ณต์‚ฌํ•ด๋‘” S3 ARN ๋ถ™์—ฌ ๋„ฃ๊ธฐ

 

Add Statement ๋ฒ„ํŠผ๋ถ€ํ„ฐ ์ˆœ์ฐจ์ ์œผ๋กœ ์ƒ์„ฑ๋˜๋Š” ๋ฒ„ํŠผ์„ ๋ˆŒ๋Ÿฌ์ค๋‹ˆ๋‹ค
์ƒ์„ฑ๋œ JSON ํ˜•์‹์˜ ๋ฒ„ํ‚ท ์ •์ฑ…์„ ๋ณต์‚ฌํ•ฉ๋‹ˆ๋‹ค

 

์ด์ „ ํŽ˜์ด์ง€๋กœ ๋Œ์•„์™€ ๋ณต์‚ฌํ•œ ์ •์ฑ…์„  ๋ถ™์—ฌ ๋„ฃ๊ธฐ ํ•ฉ๋‹ˆ๋‹ค
์ •์ฑ… ์ค‘ key๊ฐ’์ด Resource์ธ ๊ณณ์˜ Value์— /*์„ ํ•„์ˆ˜์ ์œผ๋กœ ๋ถ™์ž…๋‹ˆ๋‹ค
ํ•ด๋‹น ๋ฒ„ํ‚ท ๋ฆฌ์†Œ์Šค์˜ root path ๊ธฐ์ค€์œผ๋กœ ์–ด๋””๋“  ์ ‘๊ทผ ๊ฐ€๋Šฅํ•˜๋‹ค๋Š” ํ‘œ์‹œ์ž…๋‹ˆ๋‹ค


ACL์€ ๋ชจ๋“  ์œ ์ €๊ฐ€ ์ฝ๊ธฐ ๊ฐ€๋Šฅํ•˜๊ฒŒ๋” ์•„๋ž˜์™€ ๊ฐ™์ด ์ž‘์„ฑํ•ด ์ค๋‹ˆ๋‹ค

๊ทธ๋ฆฌ๊ณ  ์—…๋กœ๋“œํ•œ ์ด๋ฏธ์ง€๋ฅผ ํด๋ฆญํ•˜์—ฌ ์ •์ƒ ๋™์ž‘ ํ•˜๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค

 

๐ŸŒŸ ๊ทผ๊ฑฐ ์žˆ๋Š” ์กฐ์–ธ์€ ์–ธ์ œ๋‚˜ ํ™˜์˜ํ•ฉ๋‹ˆ๋‹ค. ์„ฑ์‹คํ•œ ์ฝ”๋”ฉ ํ•˜์„ธ์š”.