Skip to content

Infrastructure-as-Code archive of the To2 project, generated by scanning AWS resources with former2.

Notifications You must be signed in to change notification settings

acc-to2/chat-infra

Folders and files

NameName
Last commit message
Last commit date

Latest commit

ย 

History

19 Commits
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

๐ŸŒฉ๏ธ To2 ์ธํ”„๋ผ ๋ ˆํฌ์ง€ํ† ๋ฆฌ

์ด ์ €์žฅ์†Œ๋Š” To2 ํ”„๋กœ์ ํŠธ์˜ AWS ์ธํ”„๋ผ ํ˜„ํ™ฉ์„ ์ฝ”๋“œ๋กœ ๊ธฐ๋กํ•˜๊ณ  ๊ด€๋ฆฌํ•ฉ๋‹ˆ๋‹ค.
former2๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ”„๋กœ์ ํŠธ์˜ ๋ชจ๋“  AWS ๋ฆฌ์†Œ์Šค๋ฅผ ์Šค์บ”ํ•˜๊ณ , ๊ทธ ๊ฒฐ๊ณผ๋ฅผ ์ฝ”๋“œ๋กœ ๊ธฐ๋กํ•˜๊ณ  ์ •๋ฆฌํ–ˆ์Šต๋‹ˆ๋‹ค.


๐Ÿ“‚ ํด๋” ๊ตฌ์กฐ

.
โ”œโ”€โ”€ former_scan.yaml  # former2๋กœ ์Šค์บ”ํ•œ ์ „์ฒด ๋ฆฌ์†Œ์Šค ์›๋ณธ ํŒŒ์ผ
โ”œโ”€โ”€ templates/        # ๊ฐ ๋ฆฌ์†Œ์Šค๋ฅผ ์ข…๋ฅ˜๋ณ„๋กœ ๋ถ„๋ฆฌํ•˜๊ณ  ์„ค๋ช…์„ ์ถ”๊ฐ€ํ•œ ํŒŒ์ผ๋“ค
โ”‚   โ”œโ”€โ”€ s3.yaml
โ”‚   โ”œโ”€โ”€ ecs.yaml
โ”‚   โ””โ”€โ”€ ...
โ””โ”€โ”€ README.md

๐Ÿ“ ์ธํ”„๋ผ ์•„ํ‚คํ…์ฒ˜ ๋‹ค์ด์–ด๊ทธ๋žจ

To2 Architecture


๐Ÿงฑ ์ฃผ์š” ๋ชจ๋“ˆ ์„ค๋ช…

๐Ÿ”น ๋„คํŠธ์›Œํ‚น ๊ตฌ์„ฑ

  • VPC: ํผ๋ธ”๋ฆญ/ํ”„๋ผ์ด๋น— ์„œ๋ธŒ๋„ท ๋ถ„๋ฆฌ
  • Security Group: ์„œ๋น„์Šค๋ณ„ ์ตœ์†Œ ๊ถŒํ•œ ์„ค์ •
  • NAT Gateway: ํ”„๋ผ์ด๋น— ์„œ๋ธŒ๋„ท์˜ ์ธํ„ฐ๋„ท ์ ‘๊ทผ
  • VPC Endpoint: S3, DynamoDB, MQ, DDB, CloudWatch, ECR ๋“ฑ ์„œ๋น„์Šค ์—ฐ๊ฒฐ
  • ALB: HTTP ์š”์ฒญ ๋ผ์šฐํŒ…

๐Ÿ”น ์„œ๋น„์Šค ์‹คํ–‰

  • AWS ECS Fargate: ๋ฐฑ์—”๋“œ ์ปจํ…Œ์ด๋„ˆ ๊ธฐ๋ฐ˜ ์„œ๋น„์Šค
  • AWS Lambda: ์„œ๋ฒ„๋ฆฌ์Šค ์œ ํ‹ธ๋ฆฌํ‹ฐ ํ•จ์ˆ˜ ์ฒ˜๋ฆฌ

๐Ÿ”น ๋ฐฐํฌ ๋ฐ CI/CD

  • Github Actions: CI/CD ์ž๋™ํ™”
  • Docker & ECR: ์ปจํ…Œ์ด๋„ˆ ์ด๋ฏธ์ง€ ๋นŒ๋“œ ๋ฐ ์ €์žฅ
  • Amazon S3, CloudFront: ํ”„๋ก ํŠธ์—”๋“œ ์ •์  ํŒŒ์ผ ๋ฐฐํฌ
  • Amazon Route53: ์‚ฌ์šฉ์ž ๋„๋ฉ”์ธ ๊ด€๋ฆฌ

๐Ÿ”น ๋ฐ์ดํ„ฐ ๋ฐ ๋ฉ”์‹œ์ง•

  • Amazon DynamoDB: ์„œ๋ฒ„๋ฆฌ์Šค NoSQL DB
  • Amazon MQ (ActiveMQ): ๋ฉ”์‹œ์ง• ๋ธŒ๋กœ์ปค

๐Ÿ”น ๋กœ๊น… ๋ฐ ๋ชจ๋‹ˆํ„ฐ๋ง

  • Amazon CloudWatch: ๋กœ๊ทธ ์ˆ˜์ง‘ ๋ฐ ์ง€ํ‘œ ๋ชจ๋‹ˆํ„ฐ๋ง

๐Ÿงฏ ํŠธ๋Ÿฌ๋ธ”์ŠˆํŒ… ํžˆ์Šคํ† ๋ฆฌ

ECR Pull ์ธ์ฆ ์˜ค๋ฅ˜

  • ๋ฌธ์ œ: ECR API ํ˜ธ์ถœ ์ค‘ ์ธ์ฆ ์˜ค๋ฅ˜ ๋ฐœ์ƒ
  • ์กฐ์น˜: STS ์—”๋“œํฌ์ธํŠธ ๋ˆ„๋ฝ ํ™•์ธ โ†’ ์ถ”๊ฐ€ ํ›„ ํ•ด๊ฒฐ

Cognito Access Token ๋ˆ„๋ฝ ํ•„๋“œ ์˜ค๋ฅ˜

  • ๋ฌธ์ œ: ํ† ํฐ์— email ํ•„๋“œ ์—†์Œ โ†’ ์ธ์ฆ ๋กœ์ง ์˜ค๋ฅ˜
  • ์กฐ์น˜: email ํ•„๋“œ ์‚ฝ์ž… Lambda ํ•จ์ˆ˜ ์ƒ์„ฑ ํ›„
    pre-token-generation trigger๋กœ ์—ฐ๊ฒฐํ•˜์—ฌ ํ•ด๊ฒฐ

๐Ÿ’ก ๊ฐœ์„  ๋ฐ ๋น„์šฉ ์ ˆ๊ฐ ๊ณ„ํš

  • Amazon MQ โ†’ Redis ElastiCache Pub/Sub

    • ํ˜„์žฌ๋Š” ๊ตฌํ˜„ ์šฉ์ด์„ฑ์„ ๊ณ ๋ คํ•ด ActiveMQ ์‚ฌ์šฉ
    • ์ถ”ํ›„ Redis Pub/Sub๋กœ ์ „ํ™˜ํ•˜์—ฌ ๋น„์šฉ ์ ˆ๊ฐ ์˜ˆ์ •
  • NAT Gateway ์ œ๊ฑฐ

    • Lambda ํ”„๋ก์‹œ + API Gateway ๊ตฌ์„ฑ์œผ๋กœ ์™ธ๋ถ€ API ํ˜ธ์ถœ ๋Œ€์ฒด ๊ฐ€๋Šฅ
    • ํ˜„์žฌ ๋Œ€์ฒด ์‹œ 403 ์˜ค๋ฅ˜ ๋ฐœ์ƒ โ†’ API Gateway ๋ฆฌ์†Œ์Šค ์ •์ฑ… ์ˆ˜์ •์œผ๋กœ ํ•ด๊ฒฐ ๊ฐ€๋Šฅ๋Šฅ

About

Infrastructure-as-Code archive of the To2 project, generated by scanning AWS resources with former2.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Contributors 2

  •  
  •