ํ”ผ๋“œ๋กœ ๋Œ์•„๊ฐ€๊ธฐ
๐Ÿš€ My First Day in the Cloud: How I Built a Secured Digital Fortress in Azure
Dev.toDev.to
Infrastructure

Azure ๊ธฐ๋ฐ˜ ๋ณด์•ˆ ๊ฐ•ํ™” VM ๊ตฌ์ถ• ๋ฐ Network Restriction ์šฐํšŒ ์„ค๊ณ„

๐Ÿš€ My First Day in the Cloud: How I Built a Secured Digital Fortress in Azure

Abhishek Kadlii2026๋…„ 5์›” 22์ผ3๋ถ„beginner

Context

๋‹จ์ผ ๊ณ„์ • ํƒˆ์ทจ ์œ„ํ—˜๊ณผ ์™ธ๋ถ€ ๊ณต๊ฒฉ ๋…ธ์ถœ์„ ๋ฐฉ์ง€ํ•˜๊ธฐ ์œ„ํ•œ ๋ณด์•ˆ ์ธํ”„๋ผ ๊ตฌ์ถ• ํ•„์š”์„ฑ ๋Œ€๋‘. ๋กœ์ปฌ ๋ฐ์ดํ„ฐ ์„ผํ„ฐ ๋ฆฌ์†Œ์Šค ๋ถ€์กฑ ๋ฐ ํ™ˆ ๋ผ์šฐํ„ฐ์˜ Port 22 ์ฐจ๋‹จ์œผ๋กœ ์ธํ•œ ์—ฐ๊ฒฐ ๋ณ‘๋ชฉ ๋ฐœ์ƒ.

Technical Solution

  • MFA ๊ธฐ๋ฐ˜ Security Defaults ์ ์šฉ์„ ํ†ตํ•œ ๊ณ„์ • ์ ‘๊ทผ ๊ถŒํ•œ ๊ฐ•ํ™”
  • Network Security Group(NSG) ์„ค์ •์„ ํ†ตํ•œ ํŠน์ • IP ํ™”์ดํŠธ๋ฆฌ์ŠคํŠธ ๊ธฐ๋ฐ˜ Traffic Filtering ๊ตฌํ˜„
  • ๋ฆฌ์†Œ์Šค ๋ถ€์กฑ ๋ฌธ์ œ ํ•ด๊ฒฐ์„ ์œ„ํ•ด Singapore ๋ฆฌ์ „์œผ๋กœ ์ธํ”„๋ผ ์œ„์น˜๋ฅผ ๋ณ€๊ฒฝํ•˜๋Š” Geo-Redundancy ์ „๋žต ์ ์šฉ
  • ํ™ˆ ๋ผ์šฐํ„ฐ์˜ SSH ํฌํŠธ ์ฐจ๋‹จ ๋ฌธ์ œ๋ฅผ Azure Serial Console์„ ํ†ตํ•œ Out-of-band Management ๋ฐฉ์‹์œผ๋กœ ์šฐํšŒ
  • ๋น„์šฉ ์ตœ์ ํ™”๋ฅผ ์œ„ํ•ด ์‚ฌ์šฉํ•˜์ง€ ์•Š๋Š” ์ž์›์„ Deallocate ์ƒํƒœ๋กœ ์ „ํ™˜ํ•˜๋Š” Pay-as-you-go ๋ชจ๋ธ ์ตœ์ ํ™”

- ์ธํ”„๋ผ ๊ตฌ์ถ• ์ „ ๊ณ„์ • ์ˆ˜์ค€์˜ MFA ์„ค์ • ์—ฌ๋ถ€ ํ™•์ธ - NSG ์„ค์ •์„ ํ†ตํ•œ Minimum Privilege ๊ธฐ๋ฐ˜์˜ ๋„คํŠธ์›Œํฌ ์ ‘๊ทผ ์ œ์–ด ์ ์šฉ - ํŠน์ • ๋ฆฌ์ „ ๋ฆฌ์†Œ์Šค ๋ถ€์กฑ ์‹œ ๋Œ€์ฒด ๋ฆฌ์ „ ํ™•๋ณด ์ „๋žต ์ˆ˜๋ฆฝ - ํ‘œ์ค€ ํฌํŠธ ์ฐจ๋‹จ ์ƒํ™ฉ์— ๋Œ€๋น„ํ•œ Serial Console ๋“ฑ ๊ด€๋ฆฌ์ž ์ „์šฉ ๋ฐฑ๋„์–ด ๊ฒฝ๋กœ ํ™•๋ณด - ๋ฏธ์‚ฌ์šฉ ๋ฆฌ์†Œ์Šค์˜ Deallocation์„ ํ†ตํ•œ ๋น„์šฉ ๋‚ญ๋น„ ๋ฐฉ์ง€

์›๋ฌธ ์ฝ๊ธฐ