AWS DVA-C02 #102 AWS STS
AWS DVA-C02 #102 AWS STS — #개발자의도구들 #AWS시험 #AWSDVAC02 #DVAc02덤프 #AWSSTS 참고: ExamPotic Disscu...
#DVA-C02#Naver Blog
#개발자의도구들 #AWS시험 #AWSDVAC02 #DVAc02덤프 #AWSSTS
참고: ExamPotic Disscussion
문제 찾는법 : 여기 최하단
요구사항 분석
- 프론트엔드(JS)에서 AWS SDK로 여러 AWS API를 호출해야 함.
- 현재 \\STS 자격 증명 발급을 위해 하드코딩한 자격 정보(JSON)\\를 앱에 포함 → 보안 취약.
- 하드코딩 없이 브라우저에서 임시 보안 자격 증명을 얻어야 함.
- 정적 자산은 S3 → CloudFront로 서빙
보기 분석
- A. Add a Lambda@Edge function to the distribution. Invoke the function on viewer request. Add permissions to the function's execution role to allow the function to access AWS STS. Move all SDK calls from the frontend into the function.
- B. Add a CloudFront function to the distribution. Invoke the function on viewer request. Add permissions to the function's execution role to allow the function to access AWS STS. Move all SDK calls from the frontend into the function.
- C. Add a Lambda@Edge function to the distribution. Invoke the function on viewer request. Move the credentials from the JSON file into the function. Move all SDK calls from the frontend into the function.
- D. Add a CloudFront function to the distribution. Invoke the function on viewer request. Move the credentials from the JSON file into the function. Move all SDK calls from the frontend into the function.
📌 Key Concepts
1. CloudFront function: 네트워크 호출/AWS SDK 사용 불가하다.
2. Lambda@Edge는 Labmda 실행 역할로 STS/AWS API 호출 가능
3. hardcode를 피하기
A. ✅
B. ❌
C. credentials -> Lambda function에 넣기 👉 여전히 Hardcoded된 자격증명
D. ❌
개념 정리
AWS STS
Security Token Service
STS는 AWS 리소스에 접근이 필요한 사용자나 애플리케이션에 일시적인 보안 자격 증명을 제공하는 서비스이다.
🚀 STS 임시 자격 증명 (Access Key, Secret Access Key)
STS로 임시 자격 증명(Temporary Security Credentials)이 다음과 같은 내용을 발급
- Access Key
- Secret Access Key
- Session Token: 자격 증명의 유효성 확인, 유효기간 만료 고려
📌 STS의 임시 자격 증명을 얻는 방법
- AWS CLI
- AWS SDK
- AWS Management Console
- Lambda
- 3rd-party tools , SSO
결론
임시 자격증명이 필요할 때는 STS를 호출해서 임의로 자격증명을 받아서 사용하자.