13. ec2 "vpc-800040e5" do
security_group "AccountServer-SSHSecurityGroup-P0GE4GWO3JYN" do
description "Enable SSH access via port 22”
ingress do
permission :tcp, 22..22 do
ip_ranges(
Definitions.ip.CM.Iwamotocho3F,
Definitions.ip.CM.Joetsu,
Definitions.ip.CM.Sapporo,
Definitions.ip.CM.Iwamotocho5F,
Definitions.ip.CM.Office
)
end
end
egress do
permission :any do
ip_ranges(
"0.0.0.0/0”
)
end
end
end
end
29. 29【最後に】piculetで困ってること2
? IAM Role → Role のassumeRoleのクレデンシャルだと
セキュリティーグル?プにAWSアカウントIDが付与される
? IAM User → Role のassumeRoleだとOK
security_group "ueki-default-sg" do
description "ssh and http"
ingress do
permission :any do
groups(
["123456789012", "sg-63b4510c"]
)
end
end
end