Azure Storage Shared Key 접근 허용

계정 키 의존도를 줄이고 사용자·애플리케이션별 접근 권한을 사용하세요.

설명

Shared Key 인증은 Storage 계정 키로 요청을 승인합니다. 계정 키는 넓은 데이터 접근 권한을 가지므로 사용자나 애플리케이션별 권한 분리와 추적이 어렵습니다.

잠재적 영향

키가 유출되면 권한이 과도한 데이터 접근이나 변경에 악용될 수 있습니다.

해결 방법

클라이언트와 SAS 사용을 확인하고 지원되는 Microsoft Entra 인증 및 필요한 역할을 먼저 구성하세요. 호환성을 확인한 뒤 shared_access_key_enabled = false로 설정하세요.

예시

Shared Key 접근을 끄는 예시입니다. 특히 Azure Files와 운영 도구가 대체 인증을 사용할 수 있는지 먼저 확인하세요.

변경 전

hcl
resource "azurerm_storage_account" "example" {
  name                     = "examplestorage"
  resource_group_name      = azurerm_resource_group.example.name
  location                 = azurerm_resource_group.example.location
  account_tier             = "Standard"
  account_replication_type = "GRS"

  shared_access_key_enabled = true
}

변경 후

hcl
resource "azurerm_storage_account" "example" {
  name                     = "safestorage"
  resource_group_name      = "testRG"
  location                 = "northeurope"
  account_tier             = "Premium"
  account_replication_type = "LRS"
  account_kind             = "FileStorage"

  shared_access_key_enabled = false
}

참조