SAML for using Amazon Managed Grafana Workspace (To-Do)

  • kkumtree

2024-11-02T21:43:00+09:00

aws
grafana

Organization์˜ ์ด์Šˆ๊ฐ€ ์žˆ์–ด Amazon Managed Grafana Workspace๋ฅผ ์‚ฌ์šฉํ•˜๋ ค๋ฉด SAML ์ธ์ฆ์„ ๊ตฌ์„ฑํ•ด์•ผํ•˜๋Š”๋ฐ, SAML ์ธ์ฆ ์ œ์–ด๊ฐ€ ๋˜๋ฉด ๊ฒ€ํ† ํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

๋‹น์—ฐํžˆ ๊ฑฐ์˜ 4๋…„์ด ๋‹ค๋˜๊ฐ€๋‹ˆ Amazon Managed Grafana โ€“ Getting Started์™€๋Š” ๋‹ค๋ฅธ ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.

ํ˜„์žฌ ์ œ ๊ถŒํ•œ์œผ๋กœ๋Š” Organization์„ ์ƒ์„ฑํ•  ์ˆ˜ ์—†์–ด์„œ, Workspace๋งŒ ์ƒ์„ฑํ•ด๋ณด์•˜์Šต๋‹ˆ๋‹ค.
์ฆ‰, ๋งค์šฐ ๋А์Šจํ•œ ๊ถŒํ•œ์œผ๋กœ Workspace๋ฅผ ๋งŒ๋“ค์–ด์ฃผ๊ฒ ๋‹ค ์ด๊ฒƒ์ž…๋‹ˆ๋‹ค.

1. ‘๋”ธ๊น’์œผ๋กœ ์‹œ์ž‘ํ•˜๊ธฐ

  • Getting Started with ๋”ธ๊น

amg-workspace

  • ์ด๋ฆ„๋งŒ ์ง“๊ณ , ๋„˜์–ด๊ฐ€ ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

step1-ws-name

  • AWS IIC IAM Identity Center (๊ตฌ, AWS SSO)๋ฅผ ํ™œ์šฉํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค.
    • ์‹ ๊ฒฝ์จ์•ผํ• ๊ฒŒ ๋งŽ๋„ค์š”

step2-enable-sso

  • ๋”ธ~๊น, ์œ ์ €๋ฅผ ๋งŒ๋“ค์–ด๋ด…์‹œ๋‹ค.

step2-create-user

  • YEO-EUK-SHI… ๋ ๋ฆฌ๊ฐ€ ์—†์ง€์š”. IAM Identity Center ํ™œ์„ฑํ™”๋ถ€ํ„ฐ ํ•ด์•ผ๊ฒ ๋„ค์š”.

get-stuck-in-step2

2. IAM Identity Center ํ™œ์„ฑํ™” ์‹œ๋„

๋ณดํ†ต, ์ด๋•Œ ์กฐ๊ธˆ ๋งํ–ˆ๋‹ค๋Š” ์ƒ๊ฐ์ด ๋“ค๊ธฐ ์‹œ์ž‘ํ•˜์ฃ 

  • IAM Identity Center ๋ฉ”๋‰ด์—์„œ Enable์„ ๋”ธ๊น ํ•ฉ๋‹ˆ๋‹ค.

click-enable-click

  • Recommended ์‹ซ์€๋ฐ์š”! ๋‚œ ๋‹ค๋ฅธ๊ฑฐ ํ•  ๊ฑด๋ฐ์š”! ํ•˜๋ฉด ๊ฒฝ๊ณ  ์—„์ฒญ ๋‚ ๋ฆฝ๋‹ˆ๋‹ค.

stern-warning-not-recommended

- Users, groups, and AWS managed applications are isolated to this account instance.
  - ์„ ํƒ์ง€ ๊ทธ๋Œ€๋กœ, ํ˜„์žฌ ๋กœ๊ทธ์ธํ•œ ๊ณ„์ •์— ๊ฒฉ๋ฆฌ๋œ๋‹ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค.  
- This account instance doesn't support granting users and groups access to - AWS accounts in an AWS organization.  
  - AWS Org.์— ์†ํ•œ ๊ณ„์ •์— ๊ถŒํ•œ ๋ถ€์—ฌ ์•ˆ๋œ๋‹ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค.  
- This account instance can't be upgraded to become an organization instance.
  - `Recommended` ์„ ํƒ์ง€๋กœ ์—…๊ทธ๋ ˆ์ด๋“œ ์•ˆ๋œ๋‹ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค.  
  • ์•Œ์•˜์–ด, ์•Œ์•˜๋‹ค๊ณ . ์™ผ์ชฝ์„ ์„ ํƒํ•˜๊ณ  Continue๋ฅผ ๋”ธ๊น

click-continue-with-recommended

  • ์•„ ๋งž๋‹ค, ์ฃผ์ธ๋‹˜ ํ—ˆ๊ฐ€ ๋งก์•„์•ผํ•˜์ง€…

failed-with-insufficient-permission

  • ์ด๋ฏธ ๊ฒฝ๊ณ  ์ˆ™์ง€ํ–ˆ์œผ๋‹ˆ, ์˜ค๋ฅธ์ชฝ ์„ ํƒ์ง€๋กœ Continue๋ฅผ ๋”ธ๊น
    • ํ•œ 5~10์ดˆ ๊ฐ€๋Ÿ‰ ์†Œ์š”

click-continue-without-recommended

  • ์ด์ œ ๋ญ˜ํ•ด์•ผํ• ๊นŒ… ์ด๋Œ€๋กœ ๋˜๋Š” ๊ฒƒ์ผ๊นŒ…

what-to-do-next

  • ๋‹ค์‹œ ์‹œ๋„!

retry

  • UpdateSsoConfiguration ๊ถŒํ•œ ๋„ฃ์œผ๋ผ๋Š” ์—„์ค‘ํ•œ ์ง€์‹œ…
    • ์• ๋‹น์ดˆ, ์•ˆ๋˜๋Š” ๊ฒƒ ๊ฐ™์•„๋ณด์ด๋Š”๋ฐ…

error-again

  • ์—๋ผ, Document ์†Œํ™˜!

  • ์•„๋ž˜ ๊ถŒํ•œ์„ ์ œ๊ฒŒ ๋‹ค ๋„ฃ์–ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

    • AWSGrafanaAccountAdministrator
    • AWSSSOMasterAccountAdministrator
    • AWSOrganizationsFullAccess
    • AWSSSODirectoryAdministrator

exodia-managed-permission

  • ๋˜ ์•ˆ๋˜์„œ, ์ธ๋ผ์ธ ํ•˜๋‚˜๋งŒ ๋„ฃ์–ด๋ณด๊ณ  ์•ˆ๋˜๋ฉด ๋˜์ ธ์•ผ๊ฒ ์Šต๋‹ˆ๋‹ค.

UpdateSSOConfiguration

  • ์•„ ๊ทธ๋ƒฅ ์•ˆ๋˜๋Š” ๊ฑฐ์˜€๋„ค์š”. ์ผ๋‹จ ๋„˜์–ด๊ฐ€์•ผ๊ฒ ๋„ค์š”.

you-are-not-allowed

3. SAML-based AMG

  • SAML ์ธ์ฆ์œผ๋กœ ์„ ํƒํ•ด๋ณด๊ณ  ๊ณ„์† ์ƒ์„ฑ์‹œ๋„ ํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

use-saml-auth

  • ๋‹ค๋ฅธ ์˜ต์…˜์€ ์•„๋ž˜์™€ ๊ฐ™์Šต๋‹ˆ๋‹ค.

amg-options

  • ๊ฒฝ๊ณ ๊ฐ€ ์•„์ฐ”ํ•œ๋ฐ…

need-more-permission-to-ams-prom

add-one-more-permission

  • ์—๋Ÿฌ๋Š” ์—†์• ์ง€ ๋ชปํ–ˆ์ง€๋งŒ, ์›Œํฌ์ŠคํŽ˜์ด์Šค ์ž์ฒด๋Š” ์ƒ์„ฑ์ด ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ฐœ์ฐœ

workspace-created

amg-hello-world

4. SAML ์„ค์ •

  • SAML์˜ ๊ฒฝ์šฐ, ์ œ๊ฐ€ Admin์ธ SAML์ด ์—†์–ด์„œ ๋‚˜์ค‘์— ๊ฒ€ํ† ํ•ด๋ณผ ์ƒ๊ฐ์ž…๋‹ˆ๋‹ค.

kkumtree

plumber for infra

kkumtree

Source code on GitHub

ยฉ 2025 kkumtree and contributors All rights reserved.
Licensed under
CC BY-NC-ND 4.0