ํ”ผ๋“œ๋กœ ๋Œ์•„๊ฐ€๊ธฐ
๐ŸงญDiseรฑando VPCs en AWS: patrones reales (hub-spoke, mesh, multi-account).
Dev.toDev.to
Infrastructure

Multi-Account ๋ฐ Hub-and-Spoke ์„ค๊ณ„๋ฅผ ํ†ตํ•œ ์—”ํ„ฐํ”„๋ผ์ด์ฆˆ ๋„คํŠธ์›Œํฌ ํ™•์žฅ์„ฑ ํ™•๋ณด

๐ŸงญDiseรฑando VPCs en AWS: patrones reales (hub-spoke, mesh, multi-account).

Oscar Gaviria2026๋…„ 5์›” 18์ผ6๋ถ„intermediate

Context

๋‹จ์ผ VPC ๊ธฐ๋ฐ˜ ์„ค๊ณ„๋Š” ์„œ๋น„์Šค ์„ฑ์žฅ ์‹œ ๋ณด์•ˆ ์ œ์–ด ๋ฐ ํ™˜๊ฒฝ ๋ถ„๋ฆฌ ๊ณผ์ •์—์„œ ๋ณ‘๋ชฉ ํ˜„์ƒ ๋ฐœ์ƒ. ํŠนํžˆ ๋‹ค์ˆ˜ ํŒ€๊ณผ ํ™˜๊ฒฝ(Dev, QA, Prod)์ด ํ˜ผ์žฌ๋จ์— ๋”ฐ๋ผ ๋„คํŠธ์›Œํฌ ๋ณต์žก๋„ ์ฆ๊ฐ€ ๋ฐ ๊ด€๋ฆฌ ์ฃผ์ฒด ๋ถˆ๋ถ„๋ช…์œผ๋กœ ์ธํ•œ ์šด์˜ ๋ฆฌ์Šคํฌ ์ฆ๋Œ€.

Technical Solution

  • Trust Boundary ๋ฐ Blast Radius ์ตœ์†Œํ™”๋ฅผ ์œ„ํ•œ AWS Organizations ๊ธฐ๋ฐ˜ Multi-Account ์ „๋žต ์ฑ„ํƒ
  • Transit Gateway๋ฅผ ํ†ตํ•œ Hub-and-Spoke ๊ตฌ์กฐ ์„ค๊ณ„๋กœ ์ค‘์•™ ์ง‘์ค‘์‹ ํŠธ๋ž˜ํ”ฝ ์ œ์–ด ๋ฐ ์—ฐ๊ฒฐ์„ฑ ํ™•๋ณด
  • NAT Gateway ์ค‘์•™ํ™”๋ฅผ ํ†ตํ•œ VPC๋ณ„ ์ค‘๋ณต ๋น„์šฉ ์ œ๊ฑฐ ๋ฐ ํšจ์œจ์ ์ธ ์ธํ„ฐ๋„ท ์•„์›ƒ๋ฐ”์šด๋“œ ๊ฒฝ๋กœ ๊ด€๋ฆฌ
  • AWS Network Firewall ๋„์ž…์„ ํ†ตํ•œ Hub ์ค‘์‹ฌ์˜ ์ค‘์•™ ์ง‘์ค‘์‹ ํŠธ๋ž˜ํ”ฝ ๊ฒ€์‚ฌ ์ฒด๊ณ„ ๊ตฌ์ถ•
  • IaC ํŒŒ์ดํ”„๋ผ์ธ ๋ฐ ์Šน์ธ ํ”„๋กœ์„ธ์Šค ๋„์ž…์„ ํ†ตํ•œ Route Table ๋ณ€๊ฒฝ ๊ถŒํ•œ์˜ ๊ฑฐ๋ฒ„๋„Œ์Šค ์ฒด๊ณ„ํ™”
  • VPC Peering์˜ N*(N-1)/2 ๋ณต์žก๋„ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•ด Transit Gateway ์ค‘์‹ฌ์˜ ๊ณ„์ธต์  ์—ฐ๊ฒฐ ๊ตฌ์กฐ ์ ์šฉ

- ํ–ฅํ›„ 12๊ฐœ์›” ๋‚ด ๊ณ„์ • ์ˆ˜ ๋ฐ ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ์—ฐ๊ฒฐ ํ•„์š”์„ฑ ๊ฒ€ํ†  - ๋™์„œํ–ฅ(East-West) ํŠธ๋ž˜ํ”ฝ ๊ทœ๋ชจ์— ๋”ฐ๋ฅธ Transit Gateway ๋น„์šฉ ์‹œ๋ฎฌ๋ ˆ์ด์…˜ ์ˆ˜ํ–‰ - ์ค‘์•™ ์ง‘์ค‘์‹ ๊ฒ€์‚ฌ ๋„์ž… ์‹œ ๋ฐœ์ƒ ๊ฐ€๋Šฅํ•œ ๋น„๋Œ€์นญ ๋ผ์šฐํŒ…(Asymmetric Routing) ๋ฐฉ์ง€ ์„ค๊ณ„ ํ™•์ธ - ๋„คํŠธ์›Œํฌ ๋ณ€๊ฒฝ ๊ถŒํ•œ์„ ํŠน์ • ํŒ€์œผ๋กœ ์ œํ•œํ•˜๊ณ  IaC ๊ธฐ๋ฐ˜์˜ ๋ฆฌ๋ทฐ ํ”„๋กœ์„ธ์Šค ๊ตฌ์ถ•

์›๋ฌธ ์ฝ๊ธฐ