[AWS] AWS AWS IAM User์™€ Role ๊ตฌ์„ฑ

2025. 10. 27. 22:50ยทCloud/AWS

AWS IAM์ด๋ž€?

AWS IAM์—์„œ IAM์ด๋ž€ Identity and Access Management์˜ ์•ฝ์ž์ด๋‹ค. IAM์€ AWS ์„œ๋น„์Šค ๋ฐ ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•œ ์ ‘๊ทผ ์ œ์–ด๋ฅผ ์ค‘์•™์—์„œ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ฃผ๋Š” ์„œ๋น„์Šค์ด๋‹ค. ์‚ฌ์šฉ์ž, ๊ทธ๋ฃน, ์—ญํ• ์„ ์ƒ์„ฑํ•˜๊ณ  ๊ถŒํ•œ์„ ํ†ตํ•ด ์ ‘๊ทผ ๊ถŒํ•œ์„ ์„ค์ •ํ•˜์—ฌ ์ ‘๊ทผ ๊ถŒํ•œ์„ ์ œ์–ดํ•œ๋‹ค.

AWS IAM ์ฃผ์š” ๊ตฌ์„ฑ์š”์†Œ

  • User: Account ์ ‘๊ทผ์— ์‚ฌ์šฉํ•˜๋Š” ์‹ ์›์ •๋ณด (ID/PW)
  • Group: ๊ณตํ†ต๋œ ํŠน์ง•์„ ๊ฐ–๋Š” User๋ฅผ ๋ฌถ๋Š” ๋‹จ์œ„
  • Role: ๋ฆฌ์†Œ์Šค์— ๊ถŒํ•œ์„ ํ• ๋‹นํ•  ๋•Œ ์‚ฌ์šฉ
  • Policy: ํ•  ์ˆ˜ ์žˆ๋Š” ๊ฒƒ๊ณผ ์—†๋Š” ๊ฒƒ์„ ๋ช…์‹œ

IAM User, IAM Group, IAM Role ์ฐจ์ด์ 

๊ตฌ๋ถ„ IAM User IAM Group IAM Role
๋Œ€์ƒ ๋‹จ์ผ ์‚ฌ์šฉ์ž User์˜ ์ง‘ํ•ฉ ๋ณต์ˆ˜ ์‚ฌ์šฉ์ž, ๋ฆฌ์†Œ์Šค ex) EC2
๋ชฉ์  AWS ์ ‘๊ทผ์„ ์œ„ํ•œ ์ž๊ฒฉ ์ฆ๋ช… ๋™์ผํ•œ ์„ฑ๊ฒฉ์„ ๊ฐ–๋Š” IAM User๋ฅผ Group ๋‹จ์œ„๋กœ ๋ฌถ์–ด Group์— ๊ถŒํ•œ์„ ํ• ๋‹นํ•ด ๋™์‹œ์— ์ ์šฉํ•˜์—ฌ ๊ด€๋ฆฌ ์ž„์‹œ ๊ถŒํ•œ ์œ„์ž„
๋ณด์•ˆ ์ธ์ฆ ID/PW, Access Key - STS Token
์ธ์ฆ๊ธฐ๊ฐ„ ์˜๊ตฌ - ์ž„์‹œ

IAM Role

  • ์ผ์ • ์‹œ๊ฐ„ ์ดํ›„ ๋งŒ๋ฃŒ๋˜๋Š” ์ž„์‹œ ์ž๊ฒฉ์ฆ๋ช…
  • IAM Role์˜ ๋‘ ๊ฐ€์ง€ ๊ถŒํ•œ ์ •์ฑ… ์ •์˜ ์˜์—ญ
    • ์‹ ๋ขฐ ์ •์ฑ…: ๋ˆ„๊ฐ€ ์—ญํ• ์„ ๋งก์„ ์ˆ˜ ์žˆ๋Š”์ง€ ์ •์˜
    • ๊ถŒํ•œ ์ •์ฑ…: ์—ญํ• ์ด ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ๋Š” ๊ถŒํ•œ ์ •์ฑ…

IAM Policy

  • IAM ์ž๊ฒฉ ์ฆ๋ช…์— ์—ฐ๊ฒฐํ•ด AWS ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•œ ์ ‘๊ทผ ๊ถŒํ•œ ์ •๋ณด๊ฐ€ ์ •์˜๋˜์–ด ์žˆ๋Š” ๊ฐ์ฒด
  • IAM Policy๋Š” JSON ํŒŒ์ผ ํ˜•ํƒœ๋กœ ๊ตฌ์„ฑ
  • IAM Policy๋Š” ์ž๊ฒฉ ์ฆ๋ช… ๊ธฐ๋ฐ˜ ์ •์ฑ…(Identity-based Policies)์™€ ๋ฆฌ์†Œ์Šค ๊ธฐ๋ฐ˜ ์ •์ฑ…(Resource-based Policies)๋กœ ๊ตฌ๋ถ„

AWS IAM User์™€ Role ๊ตฌ์„ฑ ์‹ค์Šต

IAM User ์ƒ์„ฑ

AdministratorAccess ๊ถŒํ•œ์„ ํ• ๋‹นํ•œ IAM User๋กœ ๋กœ๊ทธ์ธ

  1. AdministratorAccess ๊ถŒํ•œ์„ ํ• ๋‹นํ•  IAM User๋กœ ์ƒ์„ฑํ•œ๋‹ค.
  2. ๊ถŒํ•œ ์˜ต์…ฉ์—์„œ ์ง์ ‘ ์ •์ฑ… ์—ฐ๊ฒฐ์„ ์„ ํƒํ•˜๊ณ  ๊ถŒํ•œ ์ •์ฑ…์—์„œ Administrator Access ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•œ๋‹ค.

  1. ์ฝ˜์†” ๋กœ๊ทธ์ธ URL๋กœ ์ ‘์†ํ•ด IAM User๋กœ ๋กœ๊ทธ์ธํ•œ๋‹ค.

→ Administrator Access ๊ถŒํ•œ์ด ์žˆ์œผ๋ฏ€๋กœ ์ธ์Šคํ„ด์Šค๋ฅผ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ๋‹ค.

  1. ๊ถŒํ•œ ์‚ญ์ œ ํ›„ EC2 ์ฝ˜์†”๋กœ ๋‹ค์‹œ ์ ‘์†ํ•œ๋‹ค.

→ ๊ถŒํ•œ์ด ๋ถ€์—ฌ๋˜์ง€ ์•Š์•„ ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ•จ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

Access Key์™€ Secret Key๋ฅผ ์ด์šฉํ•ด์„œ ์ ‘์†

  1. ReadOnlyAccess ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•œ๋‹ค.

  1. ์•ก์„ธ์Šค ํ‚ค๋ฅผ ๋งŒ๋“ ๋‹ค.
  2. configure๋กœ User์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ Bastion ์„œ๋ฒ„์— ์ž…๋ ฅํ•œ๋‹ค.
$ sudo su -
Last login: Mon Jul 22 03:38:15 UTC 2024 on pts/1
# aws configure
AWS Access Key ID [None]: 
AWS Secret Access Key [None]: 
Default region name [None]: ap-northeast-2
Default output format [None]: json
# aws sts get-caller-identity
{
    "UserId": "AWS Access Key ID ๊ฐ’",
    "Account": "339712890055",
    "Arn": "arn:aws:iam::339712890055:user/lab-edu-iam-user-01"
}
  1. ์ž…๋ ฅํ•œ ํ›„ 80๋ฒˆ ํฌํŠธ๋ฅผ ์—ด๊ณ  ์ ‘์†ํ•œ๋‹ค. (Access Key์™€ Secret Key๋ฅผ ์ด์šฉํ•ด EC2 ์ •๋ณด๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋Š”์ง€ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•œ ์ž‘์—…์ด๋‹ค.)
  2. # cd streamlit-project/ # streamlit run main.py --server.port 80 & [1] 58815 # Collecting usage statistics. To deactivate, set browser.gatherUsageStats to False. You can now view your Streamlit app in your browser. Network URL: External URL:

EC2 ์ •๋ณด๋ฅผ ์ฝ์–ด์˜ฌ ์ˆ˜ ์žˆ๋‹ค๋Š” ์ ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.


IAM role ์ƒ์„ฑ

  1. EC2์— ๋ถ€์—ฌํ•  ์ƒˆ ์—ญํ•  ์ƒ์„ฑํ•œ๋‹ค.

  1. Administrator Access ๊ถŒํ•œ์„ ์„ค์ •ํ•œ๋‹ค.

  1. ํ•ด๋‹น ์—ญํ• ์„ ์ƒ์„ฑ๋˜์–ด์žˆ๋Š” EC2์— ๋ถ€์—ฌํ•œ๋‹ค.

\

  1. ๋กœ๋“œ๋ฐธ๋Ÿฐ์„œ์˜ dns ์ฃผ์†Œ๋ฅผ ํ†ตํ•ด ์ ‘์†ํ•˜์—ฌ web-server๋ฅผ ํ™•์ธํ•œ๋‹ค.

EC2 ์ •๋ณด๋ฅผ ์ฝ์–ด์˜ฌ ์ˆ˜ ์žˆ๋‹ค๋Š” ์ ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.


์‹ค์Šต ๋‚ด์šฉ์€ Cloud Wave ๊ต์œก ๋‹น์‹œ ๋‚ด์šฉ์„ ๋ฐ”ํƒ•์œผ๋กœ ์ž‘์„ฑ.

์ €์ž‘์žํ‘œ์‹œ ๋น„์˜๋ฆฌ ๋ณ€๊ฒฝ๊ธˆ์ง€ (์ƒˆ์ฐฝ์—ด๋ฆผ)

'Cloud > AWS' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[AWS] AWS ECS์™€ AWS EKS  (0) 2025.10.20
[AWS] Terraform์œผ๋กœ AWS ์ธํ”„๋ผ ๊ด€๋ฆฌ ๋ฐ ์ž๋™ํ™”  (0) 2025.06.30
[AWS] AWS EC2๋ž€?  (0) 2025.05.01
'Cloud/AWS' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€
  • [AWS] AWS ECS์™€ AWS EKS
  • [AWS] Terraform์œผ๋กœ AWS ์ธํ”„๋ผ ๊ด€๋ฆฌ ๋ฐ ์ž๋™ํ™”
  • [AWS] AWS EC2๋ž€?
The Engineer, Lucy
The Engineer, Lucy
  • The Engineer, Lucy
    Growing up for My Future๐Ÿ’•
    The Engineer, Lucy
    • Instagram
    • GitHub
  • ์ „์ฒด
    ์˜ค๋Š˜
    ์–ด์ œ
    • ๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ (187) N
      • Linux (26)
      • Infra (9)
      • Cloud (28) N
        • AWS (4) N
        • GCP (4)
        • Docker (4)
        • Kubernetes (14)
        • IaC (2)
      • NGINX (1)
      • DevOps (3)
      • Computer Science (17)
        • Data Structure (0)
        • Algorithms (1)
        • Operating System (3)
        • Network (11)
        • Database System (2)
      • Coding Test (97)
        • Algorithms (89)
        • SQL (7)
      • ETC (6)
  • ๋ธ”๋กœ๊ทธ ๋ฉ”๋‰ด

    • ํ™ˆ
    • ํƒœ๊ทธ
    • ๋ฐฉ๋ช…๋ก
  • ๊ณต์ง€์‚ฌํ•ญ

  • ๋งํฌ

    • Lucy's Instagram
    • Lucy's GitHub
  • ์ธ๊ธฐ ๊ธ€

  • ํƒœ๊ทธ

    ๋„คํŠธ์›Œํฌ
    Baekjoon
    ์ฝ”๋”ฉํ…Œ์ŠคํŠธ ๊ณต๋ถ€
    ํ‹ฐ์Šคํ† ๋ฆฌ์ฑŒ๋ฆฐ์ง€
    ์˜ค๋ธ”์™„
    ๋ฆฌ๋ˆ…์Šค๋งˆ์Šคํ„ฐ 2๊ธ‰
    K8s
    ๋‹ค์ด๋‚˜๋ฏน ํ”„๋กœ๊ทธ๋ž˜๋ฐ
    network
    ์‰˜ ์Šคํฌ๋ฆฝํŠธ
    Shell Script
    ํ”„๋กœ๊ทธ๋ž˜๋จธ์Šค
    programmers
    cs ๊ธฐ์ดˆ ์ง€์‹ ์ •๋ฆฌ
    ๋ฐฑ์ค€
    Kubernetes
    ์ž๋ฐ”
    ๋ฆฌ๋ˆ…์Šค
    ๋„คํŠธ์›Œํฌ ๊ธฐ์ดˆ ์ง€์‹
    terraform
    docker
    AWS
    ์ฟ ๋ฒ„๋„คํ‹ฐ์Šค
    ์…ธ ์Šคํฌ๋ฆฝํŠธ
    ๋„ˆ๋น„์šฐ์„ ํƒ์ƒ‰
    Shell
    Java
    bfs
    ๋„์ปค
    Linux
  • ์ตœ๊ทผ ๋Œ“๊ธ€

  • ์ตœ๊ทผ ๊ธ€

  • hELLOยท Designed By์ •์ƒ์šฐ.v4.10.3
The Engineer, Lucy
[AWS] AWS AWS IAM User์™€ Role ๊ตฌ์„ฑ
์ƒ๋‹จ์œผ๋กœ

ํ‹ฐ์Šคํ† ๋ฆฌํˆด๋ฐ”