0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

AWS STSエンドポイント種類

0
Posted at

1️⃣ 前提:STS エンドポイントの種類

STS には 2 種類のエンドポイントがあります。

  • グローバルエンドポイント
    https://sts.amazonaws.com
  • リージョンエンドポイント
    https://sts.<region>.amazonaws.com
    例:https://sts.ap-northeast-1.amazonaws.com

2️⃣ グローバルエンドポイント動作モード

概要

  • すべての STS API 呼び出しを
    sts.amazonaws.com に集約
  • 実体としては us-east-1 で処理

特徴

  • 古い AWS SDK / CLI との互換性が高い
  • リージョン指定を意識しなくてよい
  • us-east-1 障害時の影響を受けやすい

メリット / デメリット

メリット

  • 設定が簡単
  • 既存システムの変更が最小

デメリット

  • 単一リージョン依存
  • レイテンシが高くなりがち
  • セキュリティ統制が弱い(リージョン制御不可)

3️⃣ リージョン互換モード(リージョンエンドポイント)

概要

  • STS API を 各リージョンのエンドポイントで処理
  • 利用リージョンに応じて明示的に指定

特徴

  • 高可用性
  • 低レイテンシ
  • リージョン単位の制御が可能

メリット / デメリット

メリット

  • 障害影響の局所化
  • VPC エンドポイント(PrivateLink)利用可
  • セキュリティ・監査要件に強い

デメリット

  • SDK / CLI でリージョン指定が必要
  • 古いツールでは非対応の場合あり

4️⃣ 両者の比較

観点 グローバル動作モード リージョン互換モード
エンドポイント sts.amazonaws.com sts..amazonaws.com
実行リージョン us-east-1 固定 各リージョン
可用性 低め 高い
レイテンシ 高め 低い
VPC エンドポイント ❌ ✅
推奨度 旧方式 現在の推奨

5️⃣ AWS の推奨

AWS は **リージョン互換モード(リージョンエンドポイント)**の利用を推奨しています。

理由:

  • 可用性・セキュリティ向上
  • 災害影響範囲の限定
  • Zero Trust / Private 接続対応

6️⃣ 設定例

AWS CLI

aws configure set sts_regional_endpoints regional

環境変数

export AWS_STS_REGIONAL_ENDPOINTS=regional

7️⃣ 一言まとめ(設計書向け)

STS はグローバルエンドポイントではなく、リージョンエンドポイント(リージョン互換モード)の利用を標準とする。

0
0
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?