AWS CLI v2로 DynamoDB에 대한 Attribute-Based Access Control 설정하기

AWS CLI v2로 DynamoDB에 대한 Attribute-Based Access Control 설정하기

이 코드 예제에서는 클라우드에서 DynamoDB에 대해 Attribute-Based Access Control(ABAC)을 구현하는 방법을 보여드려요.

출처: 문서

본문

다음 작업을 다루어요.

  • ABAC용 IAM 정책 생성
  • 부서별 태그가 지정된 테이블 생성
  • 태그 기반 테이블 목록 조회 및 필터링

Bash (AWS CLI with Bash script)

ABAC용 IAM 정책을 만들어요.

# Step 1: Create a policy document for ABAC
cat > abac-policy.json << 'EOF'
{
	"Version":"2012-10-17",
	"Statement": [
		{
			"Effect": "Allow",
			"Action": [
				"dynamodb:GetItem",
				"dynamodb:BatchGetItem",
				"dynamodb:Query",
				"dynamodb:Scan"
			],
			"Resource": "arn:aws:dynamodb:*:*:table/*",
			"Condition": {
				"StringEquals": {
					"aws:ResourceTag/Department": "${aws:PrincipalTag/Department}"
				}
			}
		},
		{
			"Effect": "Allow",
			"Action": [
				"dynamodb:PutItem",
				"dynamodb:UpdateItem",
				"dynamodb:DeleteItem",
				"dynamodb:BatchWriteItem"
			],
			"Resource": "arn:aws:dynamodb:*:*:table/*",
			"Condition": {
				"StringEquals": {
					"aws:ResourceTag/Department": "${aws:PrincipalTag/Department}",
					"aws:ResourceTag/Environment": "Development"
				}
			}
		}
	]
}
EOF

# Step 2: Create the IAM policy
aws iam create-policy \
 --policy-name DynamoDBDepartmentBasedAccess \
 --policy-document file://abac-policy.json

부서별 태그가 지정된 테이블을 만들어요.

# Create a DynamoDB table with tags for ABAC
aws dynamodb create-table \
 --table-name FinanceData \
 --attribute-definitions \
 AttributeName=RecordID,AttributeType=S \
 --key-schema \
 AttributeName=RecordID,KeyType=HASH \
 --billing-mode PAY_PER_REQUEST \
 --tags \
 Key=Department,Value=Finance \
 Key=Environment,Value=Development

# Create another table with different tags
aws dynamodb create-table \
 --table-name MarketingData \
 --attribute-definitions \
 AttributeName=RecordID,AttributeType=S \
 --key-schema \
 AttributeName=RecordID,KeyType=HASH \
 --billing-mode PAY_PER_REQUEST \
 --tags \
 Key=Department,Value=Marketing \
 Key=Environment,Value=Production

태그를 기반으로 테이블을 나열하고 필터링해요.

# List all DynamoDB tables
echo "Listing all tables:"
aws dynamodb list-tables

# Get ARNs for all tables
echo -e "\nGetting ARNs for all tables:"
TABLE_ARNS=$(aws dynamodb list-tables --query "TableNames[*]" --output text | xargs -I {} aws dynamodb describe-table --table-name {} --query "Table.TableArn" --output text)

# For each table ARN, list its tags
echo -e "\nListing tags for each table:"
for ARN in $TABLE_ARNS; do
 TABLE_NAME=$(echo $ARN | awk -F/ '{print $2}')
 echo -e "\nTags for table: $TABLE_NAME"
 aws dynamodb list-tags-of-resource --resource-arn $ARN
done

# Example: Find tables with a specific tag
echo -e "\nFinding tables with Environment=Production tag:"
for ARN in $TABLE_ARNS; do
 TABLE_NAME=$(echo $ARN | awk -F/ '{print $2}')
 TAGS=$(aws dynamodb list-tags-of-resource --resource-arn $ARN --query "Tags[?Key=='Environment' && Value=='Production']" --output text)
 if [ ! -z "$TAGS" ]; then
 echo "Table with Production tag: $TABLE_NAME"
 fi
done

API 상세는 AWS CLI Command Reference의 다음 항목을 참고해요.

  • CreatePolicy
  • CreateTable
  • ListTables

더 알아보기 (Learn more)