1 of 37

EC2로 Bastion Host 구축, 그게 최선인가요?

EC2로 Bastion Host를 구축하면서 생기는 문제점을 극복하기 위한, Pod와 IAM Role을 사용한 새로운 방식

AUSG 8기 안지완

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

2 of 37

자기소개

  • 몰로코 SRE 인턴
  • 중앙대학교 4학년 재학 중
  • 쿠버네티스와의 운명적인 만남
  • 애증의 홈서버 소유자 (완돌이)

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

3 of 37

일반적인 Bastion Host 구축

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

4 of 37

일반적인 Bastion Host 구축

sshkey.pem

ingress: <사내망>:22

ingress: <Bastion IP>:22

Elastic IP (Bastion IP)

private.pem

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

5 of 37

일반적인 Bastion Host 구축

sshkey.pem

ingress: <사내망>:22

ingress: <Bastion IP>:22

Elastic IP (Bastion IP)

Public IP

AWSEC2FullAccess

private.pem

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

6 of 37

일반적인 Bastion Host 구축

BH-1

BH-2

BH-3

AmazonEC2FullAccess

No Audit log…

DevOps Engineer

Expensive…

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

7 of 37

Session Manager

Session Manager

Developers

Cloudwatch

Private subnet

VPC

Interface Endpoint

(AWS PrivateLink)

IAM Authentication

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

8 of 37

Session Manager

  • 3개의 Interface Endpoint 필요
  • AWS PrivateLink 비용 발생
  • Cloudwatch 비용 발생
  • 제한적인 사용 (EC2 Instance Profile에 한정됨)

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

9 of 37

Session Manager

Session Manager

Developers

Cloudwatch

Private subnet

VPC

Interface Endpoint

(AWS PrivateLink)

IAM Authentication

🤔

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

10 of 37

보안과 편의의 균형점

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

11 of 37

To-Be: Manageable Bastion Host

DevOps Engineer

Manage access

Bastion

Host

Minimal Access

Group

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

12 of 37

IAM Role

실제 개발자

AWS_ACCESS_KEY_ID

AWS_SECRET_ACCESS_KEY

IAM User

실제 개발자

IAM Role

영구적인 접근 권한

임시적인 접근 권한

임시 사용 요청

임시 액세스 키 발급

실제 개발자

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

13 of 37

IAM Role

실제 개발자

IAM Role

임시 사용 요청 (Assume)

임시 액세스 키 발급

임시 액세스 키로 리소스 접근 요청

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

14 of 37

IAM Role

실제 개발자

IAM Role

임시 사용 요청

AWS_ACCESS_KEY_ID

AWS_SECRET_ACCESS_KEY

AWS_SESSION_TOKEN

임시 액세스 키로

로그인

AWS STS

Security Token Service

Trust Relationship 확인

임시 세션

리소스 접근

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

15 of 37

IAM Role

IAM UserGroup

sts:AssumeRole

Trust Relationship

devA

devB

devC

devD

IAM Role

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

16 of 37

IAM Role

DevOps Engineer

그룹 구성원 관리

Bastion

Host

최소 권한

IAM UserGroup

IAM Role

IAM Role 사용 요청 권한

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

17 of 37

IAM Role

IAM Role

devC

Assume Role

Temporal Session

Access Key 등록

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

18 of 37

EKS IAM Authenticator

IAM

Authenticator

Kube

apiserver

aws-auth

configmap

Role (Assumed Temporal User)

User

접근 시도

인증된 접근만

허용

configmap 참조하여

IAM 인증

참조

EKS Control Plane

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

19 of 37

Ubuntu Pod

Ubuntu Pod

kubectl run bastion-pod —image=ubuntu:latest

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

20 of 37

aws-auth Configmap

Jiwan (IAM User)

IAM Role

sts:AssumeRole

IAM Role을 Assume하여 얻은

임시 세션은 EKS의

‘bastion-user-group’과 매핑됨

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

21 of 37

Role, Rolebinding

Role

Rolebinding

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

22 of 37

So far…

DevOps Engineer

Manage access

via UserGroup

Assume Role

Bastion-user-group

IAM Role

Bastion

Pod

Assume Role Policy

pods/exec

pods/portforward

Role, Rolebinding

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

23 of 37

문제점

개발자

Assume Role

Acquire session

위의 Credential은 모두 임시 Credential

-> 만료될 때마다 저 과정을 모두 반복…?

Temp session

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

24 of 37

Main Goal

보안과 편의의 균형점

어떻게 개발자들이 이 일련의 과정을 알지 않아도

Bastion Host를 쉽게 사용할 수 있게 할까?

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

25 of 37

As-Is

개발자

Assume Role

Acquire session

Temp session

Bastion

Pod

Access

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

26 of 37

To-be

Assume Role

$ kubectl exec -it bastion-pod -n bastion-host /bin/bash

Temp session

Access To Bastion Pod

Bastion

Pod

$ aws eks update-kubeconfig --region ap-northeast-2 --name example-eks

--role-arn = arn:aws:iam::12345678:role/bastion-role

EKS에 인증을 할 때, 항상 사전에 해당 IAM Role을

Assume하도록 설정

개발자

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

27 of 37

KubeConfig

$ aws eks get-token --region ap-northeast-2 --cluster-name example-eks --output json \

-role arn:aws:iam::12345678:role/bastion-role

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

28 of 37

KubeConfig

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

29 of 37

KubeConfig

AWS STS에 인증

Kube-apiserver에 인증

(ExecCredential: CRD)

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

30 of 37

KubeConfig

Kubernetes

general

kubeconfig

ca.crt

client.crt

eks

kubeconfig

command

to acquire token

추가적으로 Poilcy가 필요: `eks:describeCluster`, `eks:listCluster`

개발자

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

31 of 37

So far…

DevOps Engineer

Manage access

via UserGroup

Bastion

Pod

자동으로 Role을 Assume후 인증용 토큰을

취득하도록 설정된 Kubeconfig 등록

Bastion-user-group

Assume Role Policy

EKS Describe Policy

EKS List Cluster Policy

$ kubectl exec -it bastion-pod /bin/bash

EKS

$ aws eks update-kubeconfig --region ap-northeast-2 \

—name example-eks

--role-arn = arn:aws:iam::12345678:role/bastion-role

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

32 of 37

Audit with Access Advisor

IAM Role Access Advisor

IAM UserGroup Access Advisor

누가 이 IAM Role을 사용했는가?

Bastion Pod에 언제 접근했는가?

= 무료!

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

33 of 37

Developer Experience

DB 접근할 때 Cli 사용…?

=> PostgreSQL, MySQL, MongoDB…

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

34 of 37

Developer Experience

Bastion Pod

OpenSSH

Server

SSH Tunneling

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

35 of 37

Developer Experience

Bastion Pod

OpenSSH

Server

$ kubectl port-forward bastion-pod 2222:2222

port 2222

SSH Tunneling 설정을 localhost:2222로 설정

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

36 of 37

개발자가 해야할 것?

  • DevOps 팀에 Bastion Pod 사용 요청
  • DevOps 팀이 알려주는 명령어 두개 그대로 복붙
  • 가이드를 보며 SSH Tunneling 설정 그대로 따라하기
    • 이마저도 설정할 것들 별로 없음

=> 생산성, 보안, 개발자 경험 증가

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.

37 of 37

감사합니다.

©AUSG · AUSGCON 2024, All rights reserved.

©AUSG · AUSGCON 2024, All rights reserved.