AWS Shield Advancedの適用要否の確認

サービスのDDoS対応要件に合わせて追加の保護を検討してください。

説明

AWS Shield Standardは一般的なDDoS攻撃に対する基本的な保護を提供します。Shield Advancedは別途サブスクリプションを契約することで、対応リソースに追加の検出、緩和、対応支援を提供します。

想定される影響

追加の保護が必要な重要サービスでShield Advancedを使用しない場合は、その対応機能や支援を利用できません。

対処方法

サービスのリスクと費用を検討し、Shield Advancedが必要な対象を選んでください。契約後に対応リソースのARNをaws_shield_protectionに関連付け、保護の状態を確認してください。

例

以下はElastic IPにShield Advancedの保護を設定する例です。実際のサービスへの関連付けは省略しており、有効なサブスクリプションが必要です。

変更前

hcl
resource "aws_eip" "service_ip" {
  domain = "vpc"
}

変更後

hcl
data "aws_region" "current" {}
data "aws_caller_identity" "current" {}

resource "aws_eip" "service_ip" {
  domain = "vpc"
}

resource "aws_shield_protection" "service_ip" {
  name         = "example"
  resource_arn = "arn:aws:ec2:${data.aws_region.current.name}:${data.aws_caller_identity.current.account_id}:eip-allocation/${aws_eip.service_ip.id}"
}

参考資料