Local Zone에서 디렉터리 버킷 만들기
Local Zone에서 디렉터리 버킷 만들기 (Creating a directory bucket in a Local Zone)
Local Zones에서는 디렉터리 버킷을 만들어 특정 데이터 경계(perimeter)에 객체를 저장·검색해 데이터 상주(residency) 사용 사례를 충족할 수 있어요. S3 디렉터리 버킷은 Local Zones에서 지원되는 유일한 버킷 유형이고, LocalZone이라는 버킷 위치 유형을 포함해요. 디렉터리 버킷 이름은 사용자가 제공하는 기본 이름과 버킷 위치의 Zone ID 및 --x-s3가 들어 있는 접미사로 구성돼요. DescribeAvailabilityZones API 연산으로 Local Zone ID 목록을 얻을 수 있어요. 자세한 내용은 "디렉터리 버킷 명명 규칙 (Directory bucket naming rules)"을 참고해요.
참고:
- S3를 포함한 AWS Dedicated Local Zones(Dedicated Local Zones)의 모든 서비스에서 Dedicated Local Zone에 어떤 리소스든 만들거나 접근하려면 관리자가 먼저 AWS 계정을 활성화해야 해요. 자세한 내용은 "Local Zones 계정 활성화 (Enable accounts for Local Zones)"를 참고해요.
- 데이터 상주 요구 사항을 위해 게이트웨이 VPC 엔드포인트에서만 버킷에 접근할 수 있게 할 것을 권장해요. 자세한 내용은 "VPC에서 프라이빗 연결 (Private connectivity from your VPC)"을 참고해요.
- Local Zone 네트워크 경계 그룹 안에서만 접근을 제한하려면 IAM 정책에
s3express:AllAccessRestrictedToLocalZoneGroup조건 키를 사용할 수 있어요. 자세한 내용은 "Local Zones 디렉터리 버킷 인증·인가 (Authenticating and authorizing for directory buckets in Local Zones)"를 참고해요.
다음은 AWS Management Console, AWS CLI, AWS SDK로 단일 Local Zone에 디렉터리 버킷을 만드는 방법을 설명해요.
출처: 문서
본문
콘솔에서 Local Zone 디렉터리 버킷 만들기
- AWS Management Console에 로그인하고 Amazon S3 콘솔(https://console.aws.amazon.com/s3/)을 열어요.
- 탐색 표시줄에서 현재 표시된 AWS 리전의 이름을 선택한 다음, 디렉터리 버킷을 만들 Local Zone의 부모 리전을 선택해요.
참고: 부모 리전에 대한 자세한 내용은 "Local Zones의 디렉터리 버킷 개념"을 참고해요.
- 왼쪽 탐색 창에서 Buckets(버킷)을 선택해요.
- Create bucket(버킷 만들기)을 선택해요. Create bucket 페이지가 열려요.
- General configuration(일반 구성) 아래에서 버킷이 만들어질 AWS 리전을 확인해요.
- Bucket type(버킷 유형) 아래에서 Directory(디렉터리)를 선택해요.
참고: 디렉터리 버킷을 지원하지 않는 리전을 선택하면 버킷 유형이 일반 목적 버킷으로 기본 설정돼요. 디렉터리 버킷을 만들려면 지원되는 리전을 선택해야 해요. 디렉터리 버킷을 지원하는 리전 목록은 "디렉터리 버킷의 리전·존 엔드포인트"를 참고해요. 버킷을 만든 뒤에는 버킷 유형을 바꿀 수 없어요.
- Bucket location(버킷 위치) 아래에서 사용하려는 Local Zone을 선택해요.
참고: 버킷을 만든 뒤에는 Local Zone을 바꿀 수 없어요.
- Bucket location 아래에서 Local Zone 장애가 발생할 경우 데이터를 사용할 수 없거나 유실될 수 있다는 점을 인지한다는 확인란을 선택해요.
중대한 사항: 디렉터리 버킷은 단일 Local Zone 내의 여러 장치에 저장되지만, Local Zone 전체에 걸쳐 중복 저장되지는 않아요.
- Bucket name(버킷 이름)에 디렉터리 버킷 이름을 입력해요. 디렉터리 버킷 명명 규칙에 대한 자세한 내용은 "일반 목적 버킷 명명 규칙"을 참고해요. 콘솔로 디렉터리 버킷을 만들 때 기본 이름에 접미사가 자동으로 추가돼요. 이 접미사에는 선택한 Local Zone의 Zone ID가 포함돼요. 버킷을 만든 뒤에는 이름을 바꿀 수 없어요.
중대한 사항: 계정 번호 같은 민감한 정보는 버킷 이름에 넣지 마세요. 버킷 이름은 버킷의 객체를 가리키는 URL에 그대로 보여요.
- Object Ownership(객체 소유권) 아래에서 Bucket owner enforced(버킷 소유자 강제) 설정이 자동으로 활성화되고 모든 접근 제어 목록(ACL)이 비활성화돼요. 디렉터리 버킷에서는 ACL이 비활성화되고 활성화할 수 없어요. Bucket owner enforced 설정이 활성화되면 버킷 소유자가 버킷의 모든 객체를 자동으로 소유하며 완전한 제어권을 가져요. ACL은 더 이상 S3 버킷 데이터에 대한 접근 권한에 영향을 주지 않아요. 버킷은 접근 제어를 정의하는 데 정책만 사용해요. Amazon S3의 대부분의 현대 사용 사례는 더 이상 ACL을 사용할 필요가 없어요. 자세한 내용은 "객체 소유권 제어 및 버킷에 대한 ACL 비활성화"를 참고해요.
- Block Public Access settings for this bucket(이 버킷의 퍼블릭 액세스 차단 설정) 아래에서 디렉터리 버킷의 모든 Block Public Access 설정이 자동으로 활성화돼요. 이 설정은 디렉터리 버킷에서 수정할 수 없어요. 공개 접근 차단에 대한 자세한 내용은 "Amazon S3 스토리지에 대한 공개 접근 차단"을 참고해요.
- Default encryption(기본 암호화) 아래에서 디렉터리 버킷은 기본적으로 Amazon S3 관리형 키를 이용한 서버 측 암호화(SSE-S3)로 데이터를 암호화해요. 디렉터리 버킷의 데이터를 AWS Key Management Service 키를 이용한 서버 측 암호화(SSE-KMS)로 암호화할 수도 있어요.
- Create bucket(버킷 만들기)을 선택해요. 버킷을 만든 뒤에는 버킷에 파일과 폴더를 추가할 수 있어요. 자세한 내용은 "디렉터리 버킷에서 객체 작업하기"를 참고해요.
AWS CLI로 Local Zone 디렉터리 버킷 만들기
이 예제는 AWS CLI로 Local Zone에 디렉터리 버킷을 만드는 방법을 보여 줘요. 이 명령을 사용하려면 사용자 입력 자리 표시자를 자신의 정보로 바꿔요.
디렉터리 버킷을 만들 때는 구성 세부 정보를 제공하고 다음 명명 규칙을 사용해야 해요: bucket-base-name--zone-id--x-s3.
aws s3api create-bucket
--bucket bucket-base-name--zone-id--x-s3
--create-bucket-configuration 'Location={Type=LocalZone,Name=local-zone-id},Bucket={DataRedundancy=SingleLocalZone,Type=Directory}'
--region parent-region-code
Local Zone ID와 부모 리전 코드에 대한 자세한 내용은 "Local Zones의 디렉터리 버킷 개념"을 참고해요. AWS CLI 명령에 대한 자세한 내용은 AWS CLI Command Reference의 create-bucket을 참고해요.
SDK 예제로 Local Zone 디렉터리 버킷 만들기
SDK for Go
이 예제는 AWS SDK for Go로 Local Zone에 디렉터리 버킷을 만드는 방법을 보여 줘요.
var bucket = "bucket-base-name--zone-id--x-s3" // The full directory bucket name
func runCreateBucket(c *s3.Client) {
resp, err := c.CreateBucket(context.Background(), &s3.CreateBucketInput{
Bucket: &bucket,
CreateBucketConfiguration: &types.CreateBucketConfiguration{
Location: &types.LocationInfo{
Name: aws.String("local-zone-id"),
Type: types.LocationTypeLocalZone,
},
Bucket: &types.BucketInfo{
DataRedundancy: types.DataRedundancySingleLocalZone,
Type: types.BucketTypeDirectory,
},
},
})
var terr *types.BucketAlreadyOwnedByYou
if errors.As(err, &terr) {
fmt.Printf("BucketAlreadyOwnedByYou: %s\n", aws.ToString(terr.Message))
fmt.Printf("noop...\n") // No operation performed, just printing a message
return
}
if err != nil {
log.Fatal(err)
}
fmt.Printf("bucket created at %s\n", aws.ToString(resp.Location))
}
SDK for Java 2.x
이 예제는 AWS SDK for Java 2.x로 Local Zone에 디렉터리 버킷을 만드는 방법을 보여 줘요.
public static void createBucket(S3Client s3Client, String bucketName) {
//Bucket name format is {base-bucket-name}--{local-zone-id}--x-s3
//example: doc-example-bucket--local-zone-id--x-s3 is a valid name for a directory bucket created in a Local Zone.
CreateBucketConfiguration bucketConfiguration = CreateBucketConfiguration.builder()
.location(LocationInfo.builder()
.type(LocationType.LOCAL_ZONE)
.name("local-zone-id").build()) //this must match the Local Zone ID in your bucket name
.bucket(BucketInfo.builder()
.type(BucketType.DIRECTORY)
.dataRedundancy(DataRedundancy.SINGLE_LOCAL_ZONE)
.build()).build();
try {
CreateBucketRequest bucketRequest = CreateBucketRequest.builder().bucket(bucketName).createBucketConfiguration(bucketConfiguration).build();
CreateBucketResponse response = s3Client.createBucket(bucketRequest);
System.out.println(response);
}
catch (S3Exception e) {
System.err.println(e.awsErrorDetails().errorMessage());
System.exit(1);
}
}
AWS SDK for JavaScript
이 예제는 AWS SDK for JavaScript로 Local Zone에 디렉터리 버킷을 만드는 방법을 보여 줘요.
// file.mjs, run with Node.js v16 or higher
// To use with the preview build, place this in a folder
// inside the preview build directory, such as /aws-sdk-js-v3/workspace/
import { S3 } from "@aws-sdk/client-s3";
const region = "parent-region-code";
const zone = "local-zone-id";
const suffix = `${zone}--x-s3`;
const s3 = new S3({ region });
const bucketName = `bucket-base-name--${suffix}`; // Full directory bucket name
const createResponse = await s3.createBucket(
{ Bucket: bucketName,
CreateBucketConfiguration: {Location: {Type: "LocalZone", Name: "local-zone-id"},
Bucket: { Type: "Directory", DataRedundancy: "SingleLocalZone" }}
}
);
SDK for .NET
이 예제는 SDK for .NET으로 Local Zone에 디렉터리 버킷을 만드는 방법을 보여 줘요.
using (var amazonS3Client = new AmazonS3Client())
{
var putBucketResponse = await amazonS3Client.PutBucketAsync(new PutBucketRequest
{
BucketName = "bucket-base-name--local-zone-id--x-s3",
PutBucketConfiguration = new PutBucketConfiguration
{
BucketInfo = new BucketInfo { DataRedundancy = DataRedundancy.SingleLocalZone, Type = BucketType.Directory },
Location = new LocationInfo { Name = "local-zone-id", Type = LocationType.LocalZone }
}
}).ConfigureAwait(false);
}
SDK for PHP
이 예제는 AWS SDK for PHP로 Local Zone에 디렉터리 버킷을 만드는 방법을 보여 줘요.
require 'vendor/autoload.php';
$s3Client = new S3Client([
'region' => 'parent-region-code',
]);
$result = $s3Client->createBucket([
'Bucket' => 'bucket-base-name--local-zone-id--x-s3',
'CreateBucketConfiguration' => [
'Location' => ['Name'=> 'local-zone-id', 'Type'=> 'LocalZone'],
'Bucket' => ["DataRedundancy" => "SingleLocalZone" ,"Type" => "Directory"] ],
]);
SDK for Python (Boto3)
이 예제는 AWS SDK for Python(Boto3)로 Local Zone에 디렉터리 버킷을 만드는 방법을 보여 줘요.
import logging
import boto3
from botocore.exceptions import ClientError
def create_bucket(s3_client, bucket_name, local_zone):
'''
Create a directory bucket in a specified Local Zone
:param s3_client: boto3 S3 client
:param bucket_name: Bucket to create; for example, 'bucket-base-name--local-zone-id--x-s3'
:param local_zone: String; Local Zone ID to create the bucket in
:return: True if bucket is created, else False
'''
try:
bucket_config = {
'Location': {
'Type': 'LocalZone',
'Name': local_zone
},
'Bucket': {
'Type': 'Directory',
'DataRedundancy': 'SingleLocalZone'
}
}
s3_client.create_bucket(
Bucket = bucket_name,
CreateBucketConfiguration = bucket_config
)
except ClientError as e:
logging.error(e)
return False
return True
if __name__ == '__main__':
bucket_name = 'BUCKET_NAME'
region = 'parent-region-code'
local_zone = 'local-zone-id'
s3_client = boto3.client('s3', region_name = region)
create_bucket(s3_client, bucket_name, local_zone)
SDK for Ruby
이 예제는 AWS SDK for Ruby로 Local Zone에 디렉터리 버킷을 만드는 방법을 보여 줘요.
s3 = Aws::S3::Client.new(region:'parent-region-code')
s3.create_bucket(
bucket: "bucket-base-name--local-zone-id--x-s3",
create_bucket_configuration: {
location: { name: 'local-zone-id', type: 'LocalZone' },
bucket: { data_redundancy: 'SingleLocalZone', type: 'Directory' }
}
)