ํ”ผ๋“œ๋กœ ๋Œ์•„๊ฐ€๊ธฐ
๐Ÿ” IAM en AWS vs IAM en GCP: Diferencias que pueden romper tu arquitectura.
Dev.toDev.to
Security

AWS์˜ Granular Control๊ณผ GCP์˜ Hierarchical Model ๊ธฐ๋ฐ˜ IAM ์„ค๊ณ„ ์ „๋žต ๋น„๊ต

๐Ÿ” IAM en AWS vs IAM en GCP: Diferencias que pueden romper tu arquitectura.

Oscar Gaviria2026๋…„ 4์›” 13์ผ4๋ถ„intermediate

Context

ํด๋ผ์šฐ๋“œ ๋„ค์ดํ‹ฐ๋ธŒ ํ™˜๊ฒฝ์—์„œ ์‹ ์› ๊ธฐ๋ฐ˜ ๋ณด์•ˆ์˜ ์ค‘์š”์„ฑ์ด ์ฆ๋Œ€๋จ์— ๋”ฐ๋ผ AWS์™€ GCP์˜ ์ƒ์ดํ•œ IAM ๋ชจ๋ธ ๋ถ„์„์ด ํ•„์š”ํ•จ. AWS์˜ ๋ถ„์‚ฐํ˜• ์ œ์–ด ๋ฐฉ์‹๊ณผ GCP์˜ ์ค‘์•™ ์ง‘์ค‘ํ˜• ๊ณ„์ธต ๊ตฌ์กฐ ์‚ฌ์ด์˜ ์ธ์ง€์  ๋ชจ๋ธ ์ฐจ์ด๋กœ ์ธํ•œ ์•„ํ‚คํ…์ฒ˜ ๋ถ•๊ดด ์œ„ํ—˜์„ ์ง„๋‹จํ•จ.

Technical Solution

  • AWS์˜ JSON ๊ธฐ๋ฐ˜ Explicit Policy๋ฅผ ํ†ตํ•œ ๋ฆฌ์†Œ์Šค ๋‹จ์œ„์˜ Granular Control ๊ตฌํ˜„
  • GCP์˜ Organization-Folder-Project๋กœ ์ด์–ด์ง€๋Š” Hierarchical Structure ๊ธฐ๋ฐ˜์˜ ๊ถŒํ•œ ์ƒ์† ์„ค๊ณ„
  • AWS์˜ STS(Security Token Service) ๊ธฐ๋ฐ˜ Role ์ „ํ™˜์„ ํ†ตํ•œ ์ผ์‹œ์  ๊ถŒํ•œ ๋ถ€์—ฌ ๋ฉ”์ปค๋‹ˆ์ฆ˜ ์ ์šฉ
  • GCP์˜ Service Account ์ค‘์‹ฌ ์‹๋ณ„์ž ์ฒด๊ณ„์™€ Predefined Role ๋ฐ”์ธ๋”ฉ์„ ํ†ตํ•œ ๊ด€๋ฆฌ ๋ณต์žก๋„ ์ œ๊ฑฐ
  • ๊ถŒํ•œ ์ƒ์†์œผ๋กœ ์ธํ•œ Over-permissioning ๋ฐฉ์ง€๋ฅผ ์œ„ํ•œ GCP ๊ณ„์ธต ๊ตฌ์กฐ์˜ ์ •๋ฐ€ํ•œ ์„ค๊ณ„ ๋ฐ ๊ฒฉ๋ฆฌ
  • Least Privilege ์›์น™ ๋‹ฌ์„ฑ์„ ์œ„ํ•œ IaC ๊ธฐ๋ฐ˜์˜ ์ž๋™ํ™”๋œ ๊ถŒํ•œ ๊ฒ€์ฆ ํ”„๋กœ์„ธ์Šค ๋„์ž…

- GCP ๋„์ž… ์‹œ ์ƒ์œ„ ๋…ธ๋“œ(Folder/Project)์˜ ๊ถŒํ•œ์ด ํ•˜์œ„ ๋ฆฌ์†Œ์Šค์— ์ž๋™ ์ƒ์†๋จ์„ ๊ณ ๋ คํ•œ ๊ณ„์ธต ์„ค๊ณ„ ๊ฒ€ํ†  - AWS ์šด์˜ ์‹œ Policy ๋ณต์žก๋„ ์ฆ๊ฐ€์— ๋”ฐ๋ฅธ Over-permissioning ์—ฌ๋ถ€๋ฅผ ์ •๊ธฐ์ ์œผ๋กœ ๊ฐ์‚ฌ - ์„œ๋น„์Šค ๊ฐ„ ์ธ์ฆ ๊ตฌํ˜„ ์‹œ AWS Role๊ณผ GCP Service Account์˜ ๋™์ž‘ ์ฐจ์ด๋ฅผ ๋ฐ˜์˜ํ•œ ์ธ์ฆ ๋กœ์ง ์„ค๊ณ„ - IaC๋ฅผ ํ†ตํ•œ IAM ์„ค์ • ๋ฒ„์ „ ๊ด€๋ฆฌ ๋ฐ ๋ณ€๊ฒฝ ์ด๋ ฅ ์ถ”์  ์ฒด๊ณ„ ๊ตฌ์ถ•

์›๋ฌธ ์ฝ๊ธฐ