객체 암호화를 갱신하는 Batch Operations 작업 만들기
객체 암호화를 갱신하는 Batch Operations 작업 만들기
여러 객체의 서버 측 암호화 유형을 단일 요청으로 바꾸고 싶을 때 S3 Batch Operations를 쓸 수 있어요. 이 문서에서는 AWS CLI로 두 가지 예제를 따라가 볼게요. 하나는 한 KMS 키에서 다른 KMS 키로 바꾸는 작업이고, 다른 하나는 SSE-S3 암호화 객체를 SSE-KMS로 갱신하는 작업이에요.
출처: 문서
본문
단일 요청으로 두 개 이상의 Amazon S3 객체의 서버 측 암호화 유형을 갱신하려면 S3 Batch Operations를 사용할 수 있어요. S3 Batch Operations는 Amazon S3 콘솔, AWS Command Line Interface(AWS CLI), AWS SDK, Amazon S3 REST API를 통해 사용할 수 있죠.
아래 명령을 실행하려면 AWS CLI가 설치되고 구성되어 있어야 해요. AWS CLI가 설치되어 있지 않다면 AWS Command Line Interface User Guide의 Install or update to the latest version of the AWS CLI 문서를 참고하세요. 또는 AWS CloudShell을 사용해 콘솔에서 AWS CLI 명령을 실행할 수도 있어요. AWS CloudShell은 AWS Management Console에서 바로 실행할 수 있는 브라우저 기반의 사전 인증된 셸이에요. 자세한 내용은 AWS CloudShell User Guide의 What is CloudShell? 과 Getting started with AWS CloudShell 문서를 참고하세요.
예제 1 – 한 AWS KMS 키에서 다른 KMS 키로 암호화된 객체를 갱신하는 Batch Operations 작업 만들기
다음 예제는 일반 용도 버킷에 있는 여러 객체의 암호화 설정을 갱신하는 S3 Batch Operations 작업을 만드는 방법을 보여줘요. 이 명령은 한 AWS Key Management Service(AWS KMS) 키로 암호화된 객체를 다른 KMS 키를 사용하도록 바꾸는 작업을 만들어요. 이 작업은 영향을 받는 객체의 매니페스트를 생성·저장하고 결과 보고서도 만들어요. 이 명령을 사용하려면 사용자 입력 플레이스홀더를 자신의 정보로 바꾸세요.
aws s3control create-job --account-id account-id \
--no-confirmation-required \
--operation '{ "S3UpdateObjectEncryption": { "ObjectEncryption": { "SSEKMS": { "KMSKeyArn": "KMS-key-ARN-to-apply", "BucketKeyEnabled": false } } } }' \
--report '{ "Enabled": true, "Bucket": "report-bucket-ARN", "Format": "Report_CSV_20180820", "Prefix": "report", "ReportScope": "AllTasks" }' \
--manifest-generator '{ "S3JobManifestGenerator": { "ExpectedBucketOwner": "account-id", "SourceBucket": "source-bucket-ARN", "EnableManifestOutput": true, "ManifestOutputLocation": { "Bucket": "manifest-bucket-ARN", "ManifestFormat": "S3InventoryReport_CSV_20211130", "ManifestPrefix": "manifest-prefix" }, "Filter": { "MatchAnyObjectEncryption": [ { "SSEKMS": { "KmsKeyArn": "kms-key-ARN-to-match" } } ] } } }' \
--priority 1 \
--role-arn batch-operations-role-ARN
최상의 성능을 위해 KmsKeyArn 필터를 MatchAnyPrefix, CreatedAfter, MatchAnyStorageClass 같은 다른 객체 메타데이터 필터와 함께 사용하는 걸 권장해요.
예제 2 – SSE-S3로 암호화된 객체를 SSE-KMS로 갱신하는 Batch Operations 작업 만들기
다음 예제는 일반 용도 버킷에 있는 여러 객체의 암호화 설정을 갱신하는 S3 Batch Operations 작업을 만드는 방법을 보여줘요. 이 명령은 Amazon S3 관리형 키를 사용한 서버 측 암호화(SSE-S3)로 암호화된 객체를 AWS Key Management Service(AWS KMS) 키를 사용한 서버 측 암호화(SSE-KMS)로 바꾸는 작업을 만들어요. 이 작업은 영향을 받는 객체의 매니페스트를 생성·저장하고 결과 보고서도 만들어요. 이 명령을 사용하려면 사용자 입력 플레이스홀더를 자신의 정보로 바꾸세요.
aws s3control create-job --account-id account-id \
--no-confirmation-required \
--operation '{ "S3UpdateObjectEncryption": { "ObjectEncryption": { "SSEKMS": { "KMSKeyArn": "KMS-key-ARN-to-apply", "BucketKeyEnabled": false } } } }' \
--report '{ "Enabled": true, "Bucket": "report-bucket-ARN", "Format": "Report_CSV_20180820", "Prefix": "report", "ReportScope": "AllTasks" }' \
--manifest-generator '{ "S3JobManifestGenerator": { "ExpectedBucketOwner": "account-id", "SourceBucket": "source-bucket-ARN", "EnableManifestOutput": true, "ManifestOutputLocation": { "Bucket": "manifest-bucket-ARN", "ManifestFormat": "S3InventoryReport_CSV_20211130", "ManifestPrefix": "manifest-prefix" }, "Filter": { "MatchAnyObjectEncryption": [ { "SSES3": { } } ] } } }' \
--priority 1 \
--role-arn batch-operations-role-ARN
최상의 성능을 위해 KmsKeyArn 필터를 MatchAnyPrefix, CreatedAfter, MatchAnyStorageClass 같은 다른 객체 메타데이터 필터와 함께 사용하는 걸 권장해요.