View a markdown version of this page

Amazon ECS サービススケーリング実行ブロックのサンプルポリシー - Amazon Application Recovery Controller (ARC)

翻訳は機械翻訳により提供されています。提供された翻訳内容と英語版の間で齟齬、不一致または矛盾がある場合、英語版が優先します。

Amazon ECS サービススケーリング実行ブロックのサンプルポリシー

(オプション) ターゲットグループのヘルスを待機するアクセス許可

Amazon ECS サービススケーリング実行ブロックで waitELBTargetGroupHealthyオプションが有効になっている場合は、次のアクセス許可を追加します。このオプションの詳細については、「Amazon ECS サービススケーリング実行ブロック」を参照してください。

  • ecs:ListTasks — チェックするターゲットをリージョンスイッチが認識できるように、サービスの実行中のタスクを一覧表示します。

  • ecs:DescribeTasks — ターゲットグループエントリを識別する各タスクのネットワーク詳細 (タスク ENI IP アドレス、またはコンテナインスタンスとホストポート) を取得します。

  • elasticloadbalancing:DescribeTargetHealth — 関連付けられたターゲットグループ内のサービスのターゲットの状態を読み取ります。

  • ecs:DescribeContainerInstances — タスクのコンテナインスタンスをターゲットマッチング用の EC2 インスタンス ID に解決します。サービスが bridgeまたは hostネットワークモードを使用するタスクを実行する場合にのみ必要です。

waitELBTargetGroupHealthy オプションが無効になっている場合は、これらのアクセス許可を省略できます。

以下は、Amazon ECS サービススケーリングのリージョンスイッチプランに実行ブロックを追加する場合にアタッチする JSON ポリシーの例です。

{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "ecs:DescribeServices", "ecs:UpdateService" ], "Resource": [ "arn:aws:ecs:us-east-1:111122223333:service/app-cluster-primary/app-service", "arn:aws:ecs:us-west-2:111122223333:service/app-cluster-secondary/app-service" ] }, { "Effect": "Allow", "Action": [ "ecs:DescribeClusters" ], "Resource": [ "arn:aws:ecs:us-east-1:111122223333:cluster/app-cluster-primary", "arn:aws:ecs:us-west-2:111122223333:cluster/app-cluster-secondary" ] }, { "Effect": "Allow", "Action": [ "ecs:ListServices" ], "Resource": "*" }, { "Effect": "Allow", "Action": [ "application-autoscaling:DescribeScalableTargets", "application-autoscaling:RegisterScalableTarget" ], "Resource": "*" }, { "Effect": "Allow", "Action": [ "cloudwatch:GetMetricStatistics" ], "Resource": "*" }, { "Sid": "RequiredOnlyWhenWaitELBTargetGroupHealthyEnabled", "Effect": "Allow", "Action": [ "ecs:ListTasks", "elasticloadbalancing:DescribeTargetHealth" ], "Resource": "*" }, { "Sid": "DescribeTasksWhenWaitELBTargetGroupHealthyEnabled", "Effect": "Allow", "Action": [ "ecs:DescribeTasks" ], "Resource": [ "arn:aws:ecs:us-east-1:111122223333:task/app-cluster-primary/*", "arn:aws:ecs:us-west-2:111122223333:task/app-cluster-secondary/*" ] }, { "Sid": "RequiredOnlyForBridgeOrHostNetworkModeTasks", "Effect": "Allow", "Action": [ "ecs:DescribeContainerInstances" ], "Resource": [ "arn:aws:ecs:us-east-1:111122223333:container-instance/app-cluster-primary/*", "arn:aws:ecs:us-west-2:111122223333:container-instance/app-cluster-secondary/*" ] } ] }