{"id":888,"date":"2025-06-25T17:10:22","date_gmt":"2025-06-25T08:10:22","guid":{"rendered":"https:\/\/baresupport.jp\/blog\/?p=888"},"modified":"2025-06-25T17:10:24","modified_gmt":"2025-06-25T08:10:24","slug":"github-actions%e3%81%a7aws-cdk%e3%82%92%e8%87%aa%e5%8b%95%e3%83%87%e3%83%97%e3%83%ad%e3%82%a4%e3%81%99%e3%82%8b%e6%96%b9%e6%b3%95%ef%bd%9cassume-role%e3%81%a7%e3%82%bb%e3%82%ad%e3%83%a5%e3%82%a2","status":"publish","type":"post","link":"https:\/\/baresupport.jp\/blog\/2025\/06\/25\/888\/","title":{"rendered":"GitHub Actions\u3067AWS CDK\u3092\u81ea\u52d5\u30c7\u30d7\u30ed\u30a4\u3059\u308b\u65b9\u6cd5\uff5cAssume Role\u3067\u30bb\u30ad\u30e5\u30a2\u306b\u69cb\u7bc9"},"content":{"rendered":"\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_76 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\"><p class=\"ez-toc-title\" style=\"cursor:inherit\">\u3053\u306e\u8a18\u4e8b\u306e\u76ee\u6b21<\/p>\n<\/div><nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/baresupport.jp\/blog\/2025\/06\/25\/888\/#%E3%81%AF%E3%81%98%E3%82%81%E3%81%AB\" >\u306f\u3058\u3081\u306b<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/baresupport.jp\/blog\/2025\/06\/25\/888\/#GitHub_Actions%E3%81%A8%E3%81%AF%EF%BC%9F\" >GitHub Actions\u3068\u306f\uff1f<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/baresupport.jp\/blog\/2025\/06\/25\/888\/#CDK%E3%83%97%E3%83%AD%E3%82%B8%E3%82%A7%E3%82%AF%E3%83%88%E3%81%AE%E3%83%87%E3%83%97%E3%83%AD%E3%82%A4%E3%83%AF%E3%83%BC%E3%82%AF%E3%83%95%E3%83%AD%E3%83%BC\" >CDK\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u306e\u30c7\u30d7\u30ed\u30a4\u30ef\u30fc\u30af\u30d5\u30ed\u30fc<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/baresupport.jp\/blog\/2025\/06\/25\/888\/#%E3%83%87%E3%83%97%E3%83%AD%E3%82%A4%E5%AF%BE%E8%B1%A1%E3%81%AE%E3%83%AA%E3%82%BD%E3%83%BC%E3%82%B9\" >\u30c7\u30d7\u30ed\u30a4\u5bfe\u8c61\u306e\u30ea\u30bd\u30fc\u30b9<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/baresupport.jp\/blog\/2025\/06\/25\/888\/#%E5%89%8D%E6%8F%90%E6%9D%A1%E4%BB%B6\" >\u524d\u63d0\u6761\u4ef6<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/baresupport.jp\/blog\/2025\/06\/25\/888\/#1_GitHub_Actions%E3%81%8B%E3%82%89Assume%E3%81%A7%E3%81%8D%E3%82%8BIAM%E3%83%AD%E3%83%BC%E3%83%AB%E3%82%92CDK%E3%81%A7%E4%BD%9C%E6%88%90%E3%81%99%E3%82%8B\" >1. GitHub Actions\u304b\u3089Assume\u3067\u304d\u308bIAM\u30ed\u30fc\u30eb\u3092CDK\u3067\u4f5c\u6210\u3059\u308b<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/baresupport.jp\/blog\/2025\/06\/25\/888\/#2_GitHub_Actions%E3%81%AE%E3%83%AF%E3%83%BC%E3%82%AF%E3%83%95%E3%83%AD%E3%83%BC%E3%83%95%E3%82%A1%E3%82%A4%E3%83%AB%E3%82%92%E4%BD%9C%E6%88%90%E3%81%99%E3%82%8B\" >2. GitHub Actions\u306e\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u30d5\u30a1\u30a4\u30eb\u3092\u4f5c\u6210\u3059\u308b<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/baresupport.jp\/blog\/2025\/06\/25\/888\/#3_GitHub_Secrets%E3%81%ABIAM%E3%83%AD%E3%83%BC%E3%83%AB%E3%81%AEARN%E3%82%92%E7%99%BB%E9%8C%B2%E3%81%99%E3%82%8B\" >3. GitHub Secrets\u306bIAM\u30ed\u30fc\u30eb\u306eARN\u3092\u767b\u9332\u3059\u308b<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/baresupport.jp\/blog\/2025\/06\/25\/888\/#4%E3%83%87%E3%83%97%E3%83%AD%E3%82%A4%E3%81%AE%E5%AE%9F%E8%A1%8C\" >4.\u30c7\u30d7\u30ed\u30a4\u306e\u5b9f\u884c<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/baresupport.jp\/blog\/2025\/06\/25\/888\/#%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E4%B8%8A%E3%81%AE%E6%B3%A8%E6%84%8F%E7%82%B9\" >\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4e0a\u306e\u6ce8\u610f\u70b9<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/baresupport.jp\/blog\/2025\/06\/25\/888\/#%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E4%B8%8A%E3%81%AE%E3%83%81%E3%82%A7%E3%83%83%E3%82%AF%E3%83%9D%E3%82%A4%E3%83%B3%E3%83%88\" >\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4e0a\u306e\u30c1\u30a7\u30c3\u30af\u30dd\u30a4\u30f3\u30c8<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/baresupport.jp\/blog\/2025\/06\/25\/888\/#%E6%9C%AC%E7%95%AA%E7%92%B0%E5%A2%83%E3%81%B8%E3%81%AE%E3%82%A2%E3%82%AF%E3%82%BB%E3%82%B9%E3%82%92%E5%AE%89%E5%85%A8%E3%81%AB%E7%AE%A1%E7%90%86%E3%81%99%E3%82%8B\" >\u672c\u756a\u74b0\u5883\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3092\u5b89\u5168\u306b\u7ba1\u7406\u3059\u308b<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/baresupport.jp\/blog\/2025\/06\/25\/888\/#%E3%82%A2%E3%82%AF%E3%82%BB%E3%82%B9%E7%AE%A1%E7%90%86%E3%81%A7%E5%BE%97%E3%82%89%E3%82%8C%E3%82%8B3%E3%81%A4%E3%81%AE%E3%83%A1%E3%83%AA%E3%83%83%E3%83%88\" >\u30a2\u30af\u30bb\u30b9\u7ba1\u7406\u3067\u5f97\u3089\u308c\u308b3\u3064\u306e\u30e1\u30ea\u30c3\u30c8<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/baresupport.jp\/blog\/2025\/06\/25\/888\/#%E3%81%BE%E3%81%A8%E3%82%81\" >\u307e\u3068\u3081<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"%E3%81%AF%E3%81%98%E3%82%81%E3%81%AB\"><\/span><strong>\u306f\u3058\u3081\u306b<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p>AWS\u4e0a\u306b\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u30c7\u30d7\u30ed\u30a4\u3059\u308b\u969b\u3001\u5b89\u5168\u304b\u3064\u52b9\u7387\u7684\u306b\u904b\u7528\u3059\u308b\u305f\u3081\u306b\u306f\u3001\u624b\u4f5c\u696d\u3067\u306f\u306a\u304f\u81ea\u52d5\u5316\u3055\u308c\u305f\u4ed5\u7d44\u307f\uff08CI\/CD\u30d1\u30a4\u30d7\u30e9\u30a4\u30f3\uff09\u3092\u5c0e\u5165\u3059\u308b\u3053\u3068\u304c\u91cd\u8981\u3067\u3059\u3002<\/p>\n\n\n\n<p>\u672c\u8a18\u4e8b\u3067\u306f\u3001\u30a4\u30f3\u30d5\u30e9\u69cb\u7bc9\u30c4\u30fc\u30eb\u3067\u3042\u308bAWS CDK\uff08Cloud Development Kit\uff09\u3068\u3001GitHub\u304c\u63d0\u4f9b\u3059\u308bCI\/CD\u30b5\u30fc\u30d3\u30b9\u300cGitHub Actions\u300d\u3092\u7d44\u307f\u5408\u308f\u305b\u3066\u3001\u30a4\u30f3\u30d5\u30e9\u306e\u81ea\u52d5\u30c7\u30d7\u30ed\u30a4\u3092\u5b9f\u73fe\u3059\u308b\u65b9\u6cd5\u3092\u89e3\u8aac\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<p>GitHub Actions\u306f\u3001YAML\u5f62\u5f0f\u306e\u30d5\u30a1\u30a4\u30eb\u3067\u51e6\u7406\u5185\u5bb9\u3092\u5b9a\u7fa9\u3057\u3001\u30ea\u30dd\u30b8\u30c8\u30ea\u3078\u306e\u5909\u66f4\u3084\u624b\u52d5\u64cd\u4f5c\u3092\u30c8\u30ea\u30ac\u30fc\u3068\u3057\u3066\u3001\u81ea\u52d5\u7684\u306b\u30d3\u30eb\u30c9\u3084\u30c7\u30d7\u30ed\u30a4\u3092\u5b9f\u884c\u3067\u304d\u308b\u4ed5\u7d44\u307f\u3067\u3059\u3002\u3053\u308c\u3089\u3092\u6d3b\u7528\u3057\u3001CDK\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u3092\u5b89\u5168\u306b\u3001\u624b\u9593\u306a\u304f\u52b9\u7387\u7684\u306b\u30c7\u30d7\u30ed\u30a4\u3059\u308b\u65b9\u6cd5\u3092\u7d39\u4ecb\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"291\" src=\"https:\/\/baresupport.jp\/blog\/wp-content\/uploads\/2025\/06\/image2-1024x291.png\" alt=\"\" class=\"wp-image-889\" srcset=\"https:\/\/baresupport.jp\/blog\/wp-content\/uploads\/2025\/06\/image2-1024x291.png 1024w, https:\/\/baresupport.jp\/blog\/wp-content\/uploads\/2025\/06\/image2-300x85.png 300w, https:\/\/baresupport.jp\/blog\/wp-content\/uploads\/2025\/06\/image2-768x218.png 768w, https:\/\/baresupport.jp\/blog\/wp-content\/uploads\/2025\/06\/image2.png 1298w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"GitHub_Actions%E3%81%A8%E3%81%AF%EF%BC%9F\"><\/span><strong>GitHub Actions\u3068\u306f\uff1f<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p>GitHub Actions\u306f\u3001GitHub\u304c\u63d0\u4f9b\u3059\u308bCI\/CD\uff08\u7d99\u7d9a\u7684\u30a4\u30f3\u30c6\u30b0\u30ec\u30fc\u30b7\u30e7\u30f3\uff0f\u7d99\u7d9a\u7684\u30c7\u30ea\u30d0\u30ea\u30fc\uff09\u30b5\u30fc\u30d3\u30b9\u3067\u3059\u3002\u30ea\u30dd\u30b8\u30c8\u30ea\u5185\u306b.github\/workflows\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u3092\u4f5c\u6210\u3057\u3001YAML\u5f62\u5f0f\u306e\u30d5\u30a1\u30a4\u30eb\u3067\u51e6\u7406\u5185\u5bb9\u3092\u5b9a\u7fa9\u3059\u308b\u3053\u3068\u3067\u3001\u30b3\u30fc\u30c9\u306e\u5909\u66f4\u306b\u5fdc\u3058\u305f\u81ea\u52d5\u5316\u304c\u53ef\u80fd\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n\n\n\n<p>YAML\u30d5\u30a1\u30a4\u30eb\u3067\u306f\u3001\u300c\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u300d\u3068\u547c\u3070\u308c\u308b\u81ea\u52d5\u5316\u306e\u51e6\u7406\u5168\u4f53\u3092\u5b9a\u7fa9\u3057\u307e\u3059\u3002\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u306f\u8907\u6570\u306e\u30b8\u30e7\u30d6\u3067\u69cb\u6210\u3055\u308c\u3001\u5404\u30b8\u30e7\u30d6\u306e\u4e2d\u306b\u30b9\u30c6\u30c3\u30d7\u3092\u8a18\u8ff0\u3059\u308b\u3053\u3068\u3067\u3001\u5177\u4f53\u7684\u306a\u51e6\u7406\uff08\u305f\u3068\u3048\u3070\u300c\u30b3\u30fc\u30c9\u3092\u30c1\u30a7\u30c3\u30af\u30a2\u30a6\u30c8\u3059\u308b\u300d\u300c\u4f9d\u5b58\u95a2\u4fc2\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u300d\u300c\u30c7\u30d7\u30ed\u30a4\u3092\u5b9f\u884c\u3059\u308b\u300d\u306a\u3069\uff09\u3092\u9806\u756a\u306b\u5b9f\u884c\u3067\u304d\u307e\u3059\u3002\u30b8\u30e7\u30d6\u306f\u4e26\u5217\u306b\u3001\u30b9\u30c6\u30c3\u30d7\u306f\u30b8\u30e7\u30d6\u5185\u3067\u9806\u756a\u306b\u5b9f\u884c\u3055\u308c\u308b\u306e\u304c\u57fa\u672c\u3067\u3059\u3002<\/p>\n\n\n\n<p>\u305f\u3068\u3048\u3070\u3001\u30d7\u30c3\u30b7\u30e5\u3084\u30d7\u30eb\u30ea\u30af\u30a8\u30b9\u30c8\u306a\u3069\u306e\u30a4\u30d9\u30f3\u30c8\u3092\u30c8\u30ea\u30ac\u30fc\u306b\u3057\u3066\u3001\u30c6\u30b9\u30c8\u3084\u30d3\u30eb\u30c9\u3001\u30c7\u30d7\u30ed\u30a4\u3068\u3044\u3063\u305f\u4f5c\u696d\u3092\u81ea\u52d5\u3067\u5b9f\u884c\u3067\u304d\u307e\u3059\u3002\u3053\u308c\u306b\u3088\u308a\u3001\u624b\u4f5c\u696d\u306e\u30df\u30b9\u3092\u9632\u304e\u3064\u3064\u3001\u52b9\u7387\u7684\u306a\u958b\u767a\u30fb\u904b\u7528\u304c\u5b9f\u73fe\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u4e3b\u306a\u7279\u5fb4\u306f\u4ee5\u4e0b\u306e\u901a\u308a\u3067\u3059\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>YAML\u3067\u5b9a\u7fa9\uff1a\u30b7\u30f3\u30d7\u30eb\u306a\u8a18\u6cd5\u3067\u67d4\u8edf\u306b\u51e6\u7406\u30d5\u30ed\u30fc\u3092\u8a18\u8ff0\u53ef\u80fd&nbsp;&nbsp;<\/li><li>GitHub\u3068\u306e\u7d71\u5408\uff1a\u30d7\u30c3\u30b7\u30e5\u3084\u30d7\u30eb\u30ea\u30af\u30a8\u30b9\u30c8\u306a\u3069\u306e\u30a4\u30d9\u30f3\u30c8\u3067\u81ea\u52d5\u7684\u306b\u5b9f\u884c\u3055\u308c\u308b&nbsp;&nbsp;<\/li><li>\u30de\u30c8\u30ea\u30c3\u30af\u30b9\u30d3\u30eb\u30c9\uff1a\u7570\u306a\u308b\u74b0\u5883\uff08\u4f8b\uff1aOS\u3084Node.js\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\uff09\u3067\u540c\u6642\u306b\u30c6\u30b9\u30c8\u53ef\u80fd&nbsp;&nbsp;<\/li><li>\u30bb\u30eb\u30d5\u30db\u30b9\u30c8\u30e9\u30f3\u30ca\u30fc\uff1a\u81ea\u793e\u74b0\u5883\u306a\u3069\u4efb\u610f\u306e\u30de\u30b7\u30f3\u4e0a\u3067\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u3092\u52d5\u304b\u305b\u308b&nbsp;&nbsp;<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"CDK%E3%83%97%E3%83%AD%E3%82%B8%E3%82%A7%E3%82%AF%E3%83%88%E3%81%AE%E3%83%87%E3%83%97%E3%83%AD%E3%82%A4%E3%83%AF%E3%83%BC%E3%82%AF%E3%83%95%E3%83%AD%E3%83%BC\"><\/span><strong>CDK\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u306e\u30c7\u30d7\u30ed\u30a4\u30ef\u30fc\u30af\u30d5\u30ed\u30fc<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p>\u3053\u3053\u304b\u3089\u306f\u3001CDK\u3067\u4f5c\u6210\u3057\u305f\u30a4\u30f3\u30d5\u30e9\u69cb\u6210\u3092GitHub Actions\u7d4c\u7531\u3067\u81ea\u52d5\u30c7\u30d7\u30ed\u30a4\u3059\u308b\u305f\u3081\u306e\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u4f5c\u6210\u304a\u3088\u3073\u8a2d\u5b9a\u306e\u624b\u9806\u3092\u7d39\u4ecb\u3057\u307e\u3059\u3002\u4eca\u56de\u306f\u3001\u524d\u56de\u69cb\u7bc9\u3057\u305fECS\u74b0\u5883\u3092\u30d9\u30fc\u30b9\u306b\u3001GitHub Actions\u306b\u3088\u308bCI\/CD\u3092\u8a2d\u5b9a\u3057\u3066\u3044\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"%E3%83%87%E3%83%97%E3%83%AD%E3%82%A4%E5%AF%BE%E8%B1%A1%E3%81%AE%E3%83%AA%E3%82%BD%E3%83%BC%E3%82%B9\"><\/span><strong>\u30c7\u30d7\u30ed\u30a4\u5bfe\u8c61\u306e\u30ea\u30bd\u30fc\u30b9<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p>\u3053\u306e\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u3067\u306f\u3001\u4ee5\u4e0b\u306e\u30ea\u30bd\u30fc\u30b9\u3092CDK\u3092\u901a\u3058\u3066AWS\u4e0a\u306b\u30c7\u30d7\u30ed\u30a4\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>ECS Fargate\u30af\u30e9\u30b9\u30bf\u30fc\uff1a\u30b3\u30f3\u30c6\u30ca\u3092\u5b9f\u884c\u3059\u308b\u57fa\u76e4\uff08CDK\u3067\u5b9a\u7fa9\u6e08\u307f\uff09<\/li><li>Application Load Balancer\uff08ALB\uff09\uff1a\u5916\u90e8\u304b\u3089\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u51e6\u7406\u30fb\u5206\u914d<\/li><li>VPC\u3068\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30ea\u30bd\u30fc\u30b9\uff1a\u30de\u30eb\u30c1AZ\u69cb\u6210\u306e\u4eee\u60f3\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u74b0\u5883<\/li><li>GitHub Actions\u7528IAM\u30ed\u30fc\u30eb\uff1aGitHub Actions\u304b\u3089AWS\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308b\u305f\u3081\u306e\u30ed\u30fc\u30eb\uff08Assume Role\u3092\u5229\u7528\uff09<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"%E5%89%8D%E6%8F%90%E6%9D%A1%E4%BB%B6\"><\/span><strong>\u524d\u63d0\u6761\u4ef6<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p>\u4f5c\u696d\u3092\u59cb\u3081\u308b\u524d\u306b\u3001\u4ee5\u4e0b\u306e\u6e96\u5099\u304c\u6574\u3063\u3066\u3044\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>GitHub\u30a2\u30ab\u30a6\u30f3\u30c8<\/li><li>AWS\u30a2\u30ab\u30a6\u30f3\u30c8<\/li><li>CDK\u3067\u4f5c\u6210\u3057\u305f\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u304c\u3001GitHub\u30ea\u30dd\u30b8\u30c8\u30ea\u306b\u30d7\u30c3\u30b7\u30e5\u6e08\u307f\u3067\u3042\u308b\u3053\u3068<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"1_GitHub_Actions%E3%81%8B%E3%82%89Assume%E3%81%A7%E3%81%8D%E3%82%8BIAM%E3%83%AD%E3%83%BC%E3%83%AB%E3%82%92CDK%E3%81%A7%E4%BD%9C%E6%88%90%E3%81%99%E3%82%8B\"><\/span><strong>1. GitHub Actions\u304b\u3089Assume\u3067\u304d\u308bIAM\u30ed\u30fc\u30eb\u3092CDK\u3067\u4f5c\u6210\u3059\u308b<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p>GitHub Actions\u304cAWS\u30ea\u30bd\u30fc\u30b9\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308b\u306b\u306f\u3001IAM\u30ed\u30fc\u30eb\u306e\u6a29\u9650\u3092\u4e00\u6642\u7684\u306b\u5f15\u304d\u53d7\u3051\u308b\uff08Assume\u3059\u308b\uff09\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002&nbsp; \u3053\u306e\u4ed5\u7d44\u307f\u306f\u300cAssume Role\u300d\u3068\u547c\u3070\u308c\u3001GitHub\u304c\u767a\u884c\u3059\u308bOIDC\uff08OpenID Connect\uff09\u30c8\u30fc\u30af\u30f3\u3092\u4fe1\u983c\u60c5\u5831\u3068\u3057\u3066\u5229\u7528\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<p>Assume Role\u3068\u306f\u3001\u4fe1\u983c\u3055\u308c\u305f\u5916\u90e8\u306e\u30b5\u30fc\u30d3\u30b9\u3084\u30e6\u30fc\u30b6\u30fc\u304c\u3001\u4e00\u6642\u7684\u306bIAM\u30ed\u30fc\u30eb\u306e\u6a29\u9650\u3092\u5f15\u304d\u53d7\u3051\u3001AWS\u30ea\u30bd\u30fc\u30b9\u3092\u64cd\u4f5c\u3067\u304d\u308b\u4ed5\u7d44\u307f\u3067\u3059\u3002\u30a2\u30af\u30bb\u30b9\u30ad\u30fc\u306e\u767a\u884c\u304c\u4e0d\u8981\u306a\u305f\u3081\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30ea\u30b9\u30af\u3092\u4f4e\u6e1b\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u3053\u3053\u3067\u306f\u3001CDK\u3092\u4f7f\u3063\u3066\u4ee5\u4e0b\u306e\u69cb\u6210\u3092\u6301\u3064IAM\u30ed\u30fc\u30eb\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>GitHub\u306eOIDC\u30d7\u30ed\u30d0\u30a4\u30c0\u30fc\u3092\u767b\u9332<\/li><li>\u7279\u5b9a\u306eGitHub\u30ea\u30dd\u30b8\u30c8\u30ea\u306e\u307f\u304b\u3089Assume\u53ef\u80fd\u306a\u4fe1\u983c\u30dd\u30ea\u30b7\u30fc\u3092\u8a2d\u5b9a<\/li><li>CDK\u30fbECS\u306a\u3069\u306e\u30c7\u30d7\u30ed\u30a4\u306b\u5fc5\u8981\u306a\u30dd\u30ea\u30b7\u30fc\u3092\u4ed8\u4e0e<\/li><li>\u30ed\u30fc\u30eb\u306eARN\u3092CloudFormation\u51fa\u529b\uff08\u5f8c\u7d9a\u306e\u8a2d\u5b9a\u3067\u5229\u7528\uff09<\/li><\/ul>\n\n\n\n<p>\u4ee5\u4e0b\u304c\u3001\u4e0a\u8a18\u3092CDK\u3067\u5b9f\u88c5\u3057\u305f\u30b9\u30bf\u30c3\u30af\u306e\u30b3\u30fc\u30c9\u3067\u3059\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>import * as cdk from 'aws-cdk-lib';\nimport * as iam from 'aws-cdk-lib\/aws-iam';\nimport { Construct } from 'constructs';\n\nconst GITHUB_USERNAME = \"your_user_name\"\nconst REPOSITORY_NAME = \"your_repository_name\"\n\nexport class GitHubActionsRoleStack extends cdk.Stack {\n  constructor(scope: Construct, id: string, props?: cdk.StackProps) {\n    super(scope, id, props);\n\n\/\/ GitHub\u306eOIDC\u30d7\u30ed\u30d0\u30a4\u30c0\u30fc\u3092\u4f5c\u6210\n    const githubProvider = new iam.OpenIdConnectProvider(this, 'GitHubProvider', {\n      url: 'https:\/\/token.actions.githubusercontent.com',\n      clientIds: &#91;'sts.amazonaws.com'],\n\/\/   ref) https:\/\/github.blog\/changelog\/2023-06-27-github-actions-update-on-oidc-integration-with-aws\/thumbprints: &#91;'6938fd4d98bab03faadb97b34396831e3780aea1'],\n    });\n\n\/\/ github actions \u304b\u3089\u306e\u4f7f\u7528\u3092\u8a31\u53ef\u3057\u305fIAM\u30ed\u30fc\u30eb\u3092\u4f5c\u6210\n    const githubActionsRole = new iam.Role(this, 'GitHubActionsRole', {\n      assumedBy: new iam.WebIdentityPrincipal(githubProvider.openIdConnectProviderArn, {\n        StringEquals: {\n          'token.actions.githubusercontent.com:aud': 'sts.amazonaws.com',\n        },\n        StringLike: {\n          'token.actions.githubusercontent.com:sub': `repo:${GITHUB_USERNAME}\/${REPOSITORY_NAME}:*`\n        }\n      }),\n      description: 'Role for GitHub Actions to deploy CDK stack',\n    });\n\n\/\/ CDK\u30c7\u30d7\u30ed\u30a4\u306b\u5fc5\u8981\u306a\u6a29\u9650\u3092\u4ed8\u4e0e\n    githubActionsRole.addToPolicy(\n      new iam.PolicyStatement({\n        effect: iam.Effect.ALLOW,\n        actions: &#91;\n          'cloudformation:*',\n          'ecs:*',\n          'ecr:*',\n          'iam:*',\n          'logs:*',\n          's3:*',\n          'vpc:*',\n        ],\n        resources: &#91;'*'],\n      })\n    );\n\n\/\/ \u30ed\u30fc\u30eb\u306eARN\u3092\u51fa\u529bnew cdk.CfnOutput(this, 'RoleArn', {\n      value: githubActionsRole.roleArn,\n      description: 'ARN of the GitHub Actions role',\n    });\n  }\n}<\/code><\/pre>\n\n\n\n<p>\u3053\u306eCDK\u30b9\u30bf\u30c3\u30af\u3092\u30c7\u30d7\u30ed\u30a4\u3059\u308b\u306b\u306f\u3001\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>cdk deploy GitHubActionsRoleStack --profile ${YOUR_PROFILE}<\/code><\/pre>\n\n\n\n<p>\u30c7\u30d7\u30ed\u30a4\u304c\u5b8c\u4e86\u3059\u308b\u3068\u3001\u30ed\u30fc\u30eb\u306eARN\u304c\u51fa\u529b\u3055\u308c\u307e\u3059\u3002\u3053\u306eARN\u306f\u3001GitHub Actions\u306e\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u30d5\u30a1\u30a4\u30eb\u3067\u4f7f\u7528\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"2_GitHub_Actions%E3%81%AE%E3%83%AF%E3%83%BC%E3%82%AF%E3%83%95%E3%83%AD%E3%83%BC%E3%83%95%E3%82%A1%E3%82%A4%E3%83%AB%E3%82%92%E4%BD%9C%E6%88%90%E3%81%99%E3%82%8B\"><\/span><strong>2. GitHub Actions\u306e\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u30d5\u30a1\u30a4\u30eb\u3092\u4f5c\u6210\u3059\u308b<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p>IAM\u30ed\u30fc\u30eb\u306e\u6e96\u5099\u304c\u3067\u304d\u305f\u3089\u3001GitHub\u4e0a\u3067CDK\u3092\u81ea\u52d5\u5b9f\u884c\u3059\u308b\u305f\u3081\u306e\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u30d5\u30a1\u30a4\u30eb\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002GitHub\u30ea\u30dd\u30b8\u30c8\u30ea\u306e.github\/workflows\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306b deploy.yml\u3068\u3044\u3046\u540d\u524d\u3067\u4ee5\u4e0b\u306e\u5185\u5bb9\u3092\u8a18\u8ff0\u3057\u3066\u304f\u3060\u3055\u3044\u3002\u3053\u306e\u30d5\u30a1\u30a4\u30eb\u306f\u3001main\u30d6\u30e9\u30f3\u30c1\u3078\u306e\u30d7\u30c3\u30b7\u30e5\u3084\u624b\u52d5\u5b9f\u884c\u306b\u3088\u3063\u3066CDK\u30b9\u30bf\u30c3\u30af\u306e\u30c7\u30d7\u30ed\u30a4\u51e6\u7406\u3092\u30c8\u30ea\u30ac\u30fc\u3059\u308b\u5f79\u5272\u3092\u6301\u3061\u307e\u3059\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>name: Deploy CDK Stack\n\non:\n  push:\n    branches:\n      - main\n  workflow_dispatch:\n\npermissions:\n  id-token: write\n  contents: read\n  \n\njobs:\n  deploy:\n    defaults:\n      run:\n        working-directory: ${cdk\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u306e\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u3092\u6307\u5b9a}\n    runs-on: ubuntu-latest\n    environment: \n      name: main\n    steps:\n      - uses: actions\/checkout@v3\n\n      - name: Setup Node.js\n        uses: actions\/setup-node@v3\n        with:\n          node-version: '20'\n\n      - name: Install dependencies\n        run: npm ci\n\n      - name: Configure AWS credentials\n        uses: aws-actions\/configure-aws-credentials@v2\n        with:\n          role-to-assume: ${{ secrets.AWS_ROLE_ARN }}\n          aws-region: ap-northeast-1\n\n      - name: CDK Deploy\n        run: npx cdk deploy --all --require-approval never<\/code><\/pre>\n\n\n\n<p>\u3053\u306e\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u30d5\u30a1\u30a4\u30eb\u306e\u4e3b\u306a\u30dd\u30a4\u30f3\u30c8\u306f\u4ee5\u4e0b\u306e\u901a\u308a\u3067\u3059\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>\u30c8\u30ea\u30ac\u30fc\u8a2d\u5b9a\uff08<\/strong><strong>on<\/strong><strong>\uff09<\/strong><strong><br><\/strong>main\u30d6\u30e9\u30f3\u30c1\u3078\u306epush\u3084\u3001\u624b\u52d5\u5b9f\u884c\uff08workflow_dispatch\uff09\u304c\u30c8\u30ea\u30ac\u30fc\u306b\u306a\u308a\u307e\u3059\u3002<\/li><li><strong>\u6a29\u9650\u8a2d\u5b9a\uff08<\/strong><strong>permissions<\/strong><strong>\uff09<\/strong><strong><br><\/strong>id-token: write\uff1aOIDC\u30c8\u30fc\u30af\u30f3\u3092\u751f\u6210\u3059\u308b\u305f\u3081\u306b\u5fc5\u8981\u3002<br>contents: read\uff1aGitHub\u30ea\u30dd\u30b8\u30c8\u30ea\u306e\u30b3\u30fc\u30c9\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308b\u305f\u3081\u306b\u5fc5\u8981\u3002<\/li><li><strong>Node.js\u74b0\u5883\uff08<\/strong><strong>setup-node<\/strong><strong>\uff09<\/strong><strong><br><\/strong>CDK\u3092\u4f7f\u3046\u305f\u3081\u306b\u5fc5\u8981\u306aNode.js\u3092\u30d0\u30fc\u30b8\u30e7\u30f320\u3067\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u3057\u307e\u3059\u3002<\/li><li><strong>AWS\u8a8d\u8a3c\u60c5\u5831\uff08<\/strong><strong>configure-aws-credentials<\/strong><strong>\uff09<\/strong><strong><br><\/strong>CDK\u3067\u4f5c\u6210\u3057\u305fIAM\u30ed\u30fc\u30eb\u306eARN\u3092\u4f7f\u3063\u3066AWS\u306b\u8a8d\u8a3c\u3057\u307e\u3059\u3002\u3053\u306eARN\u306f\u6b21\u306e\u30b9\u30c6\u30c3\u30d7\u3067 GitHub Secrets \u306b\u767b\u9332\u3057\u307e\u3059\u3002<\/li><li><strong>CDK\u30c7\u30d7\u30ed\u30a4\uff08<\/strong><strong>cdk deploy<\/strong><strong>\uff09<\/strong><strong><br><\/strong>&#8211;require-approval never \u3092\u6307\u5b9a\u3059\u308b\u3053\u3068\u3067\u3001\u624b\u52d5\u627f\u8a8d\u306a\u3057\u306b\u30c7\u30d7\u30ed\u30a4\u304c\u53ef\u80fd\u306b\u306a\u308a\u307e\u3059\u3002<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"3_GitHub_Secrets%E3%81%ABIAM%E3%83%AD%E3%83%BC%E3%83%AB%E3%81%AEARN%E3%82%92%E7%99%BB%E9%8C%B2%E3%81%99%E3%82%8B\"><\/span><strong>3. GitHub Secrets\u306bIAM\u30ed\u30fc\u30eb\u306eARN\u3092\u767b\u9332\u3059\u308b<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p>CDK\u3067\u4f5c\u6210\u3057\u305fIAM\u30ed\u30fc\u30eb\u306eARN\u306f\u3001GitHub Actions\u306e\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u3067AWS\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u307e\u3059\u3002\u3053\u306eARN\u3092GitHub\u4e0a\u306b\u5b89\u5168\u306b\u4fdd\u6301\u3059\u308b\u305f\u3081\u3001Secrets\uff08\u30b7\u30fc\u30af\u30ec\u30c3\u30c8\uff09\u6a5f\u80fd\u3092\u4f7f\u3063\u3066\u767b\u9332\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u8a2d\u5b9a\u624b\u9806<\/h4>\n\n\n\n<ol class=\"wp-block-list\"><li>GitHub\u30ea\u30dd\u30b8\u30c8\u30ea\u306e\u300cSettings\u300d\u30bf\u30d6\u3092\u958b\u304f<\/li><li>\u300cSecrets and variables\u300d\u2192\u300cActions\u300d\u3092\u9078\u629e<\/li><li>\u300cNew repository secret\u300d\u3092\u30af\u30ea\u30c3\u30af<\/li><li>\u540d\u524d\u3092AWS_ROLE_ARN\u3001\u5024\u3092CDK\u3067\u51fa\u529b\u3055\u308c\u305f\u30ed\u30fc\u30eb\u306eARN\u3092\u8a2d\u5b9a<\/li><\/ol>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>\u9805\u76ee<\/strong><\/td><td><strong>\u5165\u529b\u5185\u5bb9<\/strong><\/td><\/tr><tr><td><strong>Name<\/strong><\/td><td>AWS_ROLE_ARN\uff08\u2190\u56fa\u5b9a\u540d\u3001YAML\u30d5\u30a1\u30a4\u30eb\u5185\u3067\u53c2\u7167\uff09<\/td><\/tr><tr><td><strong>Secret<\/strong><\/td><td>CDK\u3067\u51fa\u529b\u3055\u308c\u305fIAM\u30ed\u30fc\u30eb\u306eARN\uff08\u4f8b\uff1aarn:aws:iam::123456789012:role\/GitHubActionsRole\uff09<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>\u3053\u308c\u3067GitHub\u5074\u306e\u6e96\u5099\u306f\u5b8c\u4e86\u3067\u3059\u3002<\/p>\n\n\n\n<p>\u7d9a\u3044\u3066\u3001\u5b9f\u969b\u306e\u30ef\u30fc\u30af\u30d5\u30ed\u30fc\u5185\u3067\u306e\u547c\u3073\u51fa\u3057\u65b9\u6cd5\u3092\u898b\u3066\u307f\u307e\u3057\u3087\u3046\u3002<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>with:\n  role-to-assume: ${{ secrets.AWS_ROLE_ARN }}<\/code><\/pre>\n\n\n\n<p>Secrets\u306fGitHub Actions\u306e\u74b0\u5883\u5185\u3067\u306e\u307f\u4f7f\u7528\u3067\u304d\u3001\u5916\u90e8\u306b\u6f0f\u308c\u306a\u3044\u3088\u3046\u5b89\u5168\u306b\u7ba1\u7406\u3055\u308c\u307e\u3059\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"4%E3%83%87%E3%83%97%E3%83%AD%E3%82%A4%E3%81%AE%E5%AE%9F%E8%A1%8C\"><\/span>4.\u30c7\u30d7\u30ed\u30a4\u306e\u5b9f\u884c<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p>\u6e96\u5099\u3057\u305f deploy.yml\u30d5\u30a1\u30a4\u30eb\u3092main\u30d6\u30e9\u30f3\u30c1\u306b\u30d7\u30c3\u30b7\u30e5\u3059\u308b\u3068\u3001GitHub Actions\u304c\u81ea\u52d5\u7684\u306b\u5b9f\u884c\u3055\u308c\u3001CDK\u30b9\u30bf\u30c3\u30af\u304c\u30c7\u30d7\u30ed\u30a4\u3055\u308c\u307e\u3059\u3002\u30c7\u30d7\u30ed\u30a4\u306e\u9032\u884c\u72b6\u6cc1\u306f\u3001GitHub\u30ea\u30dd\u30b8\u30c8\u30ea\u306e\u300cActions\u300d\u30bf\u30d6\u304b\u3089\u78ba\u8a8d\u3067\u304d\u307e\u3059\u3002&nbsp;&nbsp;<\/p>\n\n\n\n<p>\u5404\u30b9\u30c6\u30c3\u30d7\u306e\u30ed\u30b0\u3092\u898b\u308b\u3053\u3068\u3067\u3001\u5b9f\u884c\u72b6\u6cc1\u3084\u30a8\u30e9\u30fc\u306e\u6709\u7121\u3092\u78ba\u8a8d\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"361\" src=\"https:\/\/baresupport.jp\/blog\/wp-content\/uploads\/2025\/06\/image-11-1024x361.png\" alt=\"\" class=\"wp-image-890\" srcset=\"https:\/\/baresupport.jp\/blog\/wp-content\/uploads\/2025\/06\/image-11-1024x361.png 1024w, https:\/\/baresupport.jp\/blog\/wp-content\/uploads\/2025\/06\/image-11-300x106.png 300w, https:\/\/baresupport.jp\/blog\/wp-content\/uploads\/2025\/06\/image-11-768x271.png 768w, https:\/\/baresupport.jp\/blog\/wp-content\/uploads\/2025\/06\/image-11-1536x542.png 1536w, https:\/\/baresupport.jp\/blog\/wp-content\/uploads\/2025\/06\/image-11-2048x723.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E4%B8%8A%E3%81%AE%E6%B3%A8%E6%84%8F%E7%82%B9\"><\/span><strong>\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4e0a\u306e\u6ce8\u610f\u70b9<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p>GitHub Actions\u306f\u4fbf\u5229\u306a\u81ea\u52d5\u5316\u30c4\u30fc\u30eb\u3067\u3059\u304c\u3001AWS\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u8a2d\u5b9a\u3092\u884c\u3046\u5834\u5408\u306f\u7279\u306b\u6ce8\u610f\u304c\u5fc5\u8981\u3067\u3059\u3002\u4e07\u304c\u4e00\u3001GitHub\u30a2\u30ab\u30a6\u30f3\u30c8\u304c\u4e57\u3063\u53d6\u3089\u308c\u305f\u5834\u5408\u3001AWS\u74b0\u5883\u3078\u306e\u4e0d\u6b63\u30a2\u30af\u30bb\u30b9\u306b\u3064\u306a\u304c\u308b\u30ea\u30b9\u30af\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u4ee5\u4e0b\u306e\u30dd\u30a4\u30f3\u30c8\u3092\u62bc\u3055\u3048\u3066\u3001\u6700\u5c0f\u6a29\u9650\u306e\u539f\u5247\uff08\u5fc5\u8981\u306a\u64cd\u4f5c\u3060\u3051\u3092\u8a31\u53ef\uff09\u3092\u5b88\u308b\u3088\u3046\u306b\u3057\u307e\u3057\u3087\u3046\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3%E4%B8%8A%E3%81%AE%E3%83%81%E3%82%A7%E3%83%83%E3%82%AF%E3%83%9D%E3%82%A4%E3%83%B3%E3%83%88\"><\/span>\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4e0a\u306e\u30c1\u30a7\u30c3\u30af\u30dd\u30a4\u30f3\u30c8<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>IAM\u30ed\u30fc\u30eb\u306e\u4f7f\u7528\uff08Assume Role\uff09<\/strong><strong><br><\/strong>\u30a2\u30af\u30bb\u30b9\u30ad\u30fc\u3092\u4f7f\u308f\u305a\u3001IAM\u30ed\u30fc\u30eb\u3092\u4f7f\u3063\u3066\u4e00\u6642\u7684\u306b\u6a29\u9650\u3092\u4ed8\u4e0e\u3059\u308b\u3053\u3068\u3067\u3001\u6f0f\u3048\u3044\u30ea\u30b9\u30af\u3092\u6e1b\u3089\u305b\u307e\u3059\u3002<\/li><li><strong>OIDC\u306e\u6d3b\u7528\u3068\u30c8\u30fc\u30af\u30f3\u5236\u5fa1<\/strong><strong><br><\/strong>GitHub Actions\u304b\u3089\u306e\u8a8d\u8a3c\u306b\u306fOIDC\u3092\u5229\u7528\u3057\u307e\u3059\u3002\u30c8\u30fc\u30af\u30f3\u306e\u6709\u52b9\u671f\u9650\u3092\u5236\u9650\u3059\u308b\u3053\u3068\u3067\u3001\u5b89\u5168\u6027\u3092\u9ad8\u3081\u3089\u308c\u307e\u3059\u3002<\/li><li><strong>Secrets\u3067\u6a5f\u5bc6\u60c5\u5831\u3092\u7ba1\u7406<\/strong><strong><br><\/strong>\u74b0\u5883\u5909\u6570\u3084\u8a8d\u8a3c\u60c5\u5831\u306f\u3001\u30ea\u30dd\u30b8\u30c8\u30ea\u306e\u300cSecrets\u300d\u3067\u5b89\u5168\u306b\u7ba1\u7406\u3057\u307e\u3057\u3087\u3046\u3002\u30b9\u30c6\u30fc\u30b8\u30f3\u30b0\u3084\u672c\u756a\u306a\u3069\u3001\u74b0\u5883\u3054\u3068\u306b\u5024\u3092\u5206\u3051\u308b\u306e\u3082\u6709\u52b9\u3067\u3059\u3002<\/li><\/ul>\n\n\n\n<p>\u3053\u3046\u3057\u305f\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u3092\u8e0f\u307e\u3048\u3066\u3001\u6b21\u306f\u672c\u756a\u74b0\u5883\u306e\u30a2\u30af\u30bb\u30b9\u6a29\u9650\u7ba1\u7406\u306b\u3064\u3044\u3066\u898b\u3066\u3044\u304d\u307e\u3057\u3087\u3046\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"%E6%9C%AC%E7%95%AA%E7%92%B0%E5%A2%83%E3%81%B8%E3%81%AE%E3%82%A2%E3%82%AF%E3%82%BB%E3%82%B9%E3%82%92%E5%AE%89%E5%85%A8%E3%81%AB%E7%AE%A1%E7%90%86%E3%81%99%E3%82%8B\"><\/span><strong>\u672c\u756a\u74b0\u5883\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3092\u5b89\u5168\u306b\u7ba1\u7406\u3059\u308b<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p>GitHub Actions\u3068Assume Role\u306e\u4ed5\u7d44\u307f\u3092\u4f7f\u3046\u3053\u3068\u3067\u3001AWS\u672c\u756a\u74b0\u5883\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3092\u3088\u308a\u5b89\u5168\u304b\u3064\u52b9\u7387\u7684\u306b\u7ba1\u7406\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u3053\u306e\u65b9\u6cd5\u3092\u4f7f\u3046\u3053\u3068\u3067\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u30e1\u30ea\u30c3\u30c8\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"%E3%82%A2%E3%82%AF%E3%82%BB%E3%82%B9%E7%AE%A1%E7%90%86%E3%81%A7%E5%BE%97%E3%82%89%E3%82%8C%E3%82%8B3%E3%81%A4%E3%81%AE%E3%83%A1%E3%83%AA%E3%83%83%E3%83%88\"><\/span><strong>\u30a2\u30af\u30bb\u30b9\u7ba1\u7406\u3067\u5f97\u3089\u308c\u308b3\u3064\u306e\u30e1\u30ea\u30c3\u30c8<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>\u30a2\u30af\u30bb\u30b9\u6a29\u306e\u5206\u96e2\u304c\u3067\u304d\u308b<\/strong><strong><br><\/strong>\u958b\u767a\u8005\u306fGitHub\u30ea\u30dd\u30b8\u30c8\u30ea\u306b\u3060\u3051\u30a2\u30af\u30bb\u30b9\u3059\u308c\u3070\u3088\u304f\u3001AWS\u30b3\u30f3\u30bd\u30fc\u30eb\u3084IAM\u30e6\u30fc\u30b6\u30fc\u3078\u306e\u76f4\u63a5\u30a2\u30af\u30bb\u30b9\u306f\u4e0d\u8981\u306b\u306a\u308a\u307e\u3059\u3002<br>\u2192 \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30ea\u30b9\u30af\u306e\u4f4e\u6e1b\u306b\u7e4b\u304c\u308a\u307e\u3059\u3002<\/li><li><strong>\u76e3\u67fb\u30ed\u30b0\u304c\u53d6\u308a\u3084\u3059\u304f\u306a\u308b<\/strong><strong><br><\/strong>GitHub Actions\u306e\u5b9f\u884c\u5c65\u6b74\u3068\u3001AWS\u306eCloudTrail\u3092\u7d44\u307f\u5408\u308f\u305b\u308b\u3053\u3068\u3067\u3001\u300c\u8ab0\u304c\u3001\u3044\u3064\u3001\u4f55\u3092\u30c7\u30d7\u30ed\u30a4\u3057\u305f\u304b\u300d\u3092\u53ef\u8996\u5316\u3067\u304d\u307e\u3059\u3002<br>\u2192 \u30c8\u30e9\u30d6\u30eb\u6642\u306e\u8abf\u67fb\u3084\u30b3\u30f3\u30d7\u30e9\u30a4\u30a2\u30f3\u30b9\u5bfe\u5fdc\u306b\u3082\u6709\u52b9\u3067\u3059\u3002<\/li><li><strong>\u5916\u6ce8\u5148\u3068\u3082\u5b89\u5168\u306b\u5354\u696d\u3067\u304d\u308b<\/strong><strong><br><\/strong>GitHub\u30ea\u30dd\u30b8\u30c8\u30ea\u306e\u30a2\u30af\u30bb\u30b9\u6a29\u3060\u3051\u3092\u5171\u6709\u3059\u308c\u3070\u3001\u5916\u6ce8\u5148\u306b\u3082\u958b\u767a\u3084\u30c7\u30d7\u30ed\u30a4\u3092\u4efb\u305b\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<br>\u2192 AWS\u30a2\u30ab\u30a6\u30f3\u30c8\u3078\u306e\u76f4\u63a5\u30a2\u30af\u30bb\u30b9\u3092\u907f\u3051\u3089\u308c\u308b\u305f\u3081\u3001\u5b89\u5168\u6027\u304c\u9ad8\u307e\u308a\u307e\u3059\u3002<\/li><\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"%E3%81%BE%E3%81%A8%E3%82%81\"><\/span><strong>\u307e\u3068\u3081<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p>\u3053\u306e\u8a18\u4e8b\u3067\u306f\u3001GitHub Actions\u3092\u4f7f\u3063\u3066CDK\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u3092\u81ea\u52d5\u30c7\u30d7\u30ed\u30a4\u3059\u308b\u65b9\u6cd5\u3092\u7d39\u4ecb\u3057\u307e\u3057\u305f\u3002<br>\u30dd\u30a4\u30f3\u30c8\u306f\u4ee5\u4e0b\u306e\u901a\u308a\u3067\u3059\u3002<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Assume Role\u3068OIDC\u3092\u6d3b\u7528\u3059\u308b\u3053\u3068\u3067\u3001\u30a2\u30af\u30bb\u30b9\u30ad\u30fc\u3092\u4f7f\u308f\u305a\u3001\u5b89\u5168\u306bAWS\u3078\u8a8d\u8a3c\u3067\u304d\u307e\u3059\u3002<\/li><li>GitHub Actions\u304b\u3089\u306e\u30c7\u30d7\u30ed\u30a4\u306b\u3088\u308a\u3001\u624b\u52d5\u64cd\u4f5c\u306a\u3057\u3067\u30a4\u30f3\u30d5\u30e9\u69cb\u7bc9\u3092\u81ea\u52d5\u5316\u3067\u304d\u307e\u3059\u3002<\/li><li>AWS\u306e\u30a2\u30af\u30bb\u30b9\u6a29\u3092\u6e21\u3055\u305a\u306b\u3001\u5916\u6ce8\u5148\u3084\u30c1\u30fc\u30e0\u30e1\u30f3\u30d0\u30fc\u3068\u5b89\u5168\u306b\u958b\u767a\u30fb\u904b\u7528\u304c\u3067\u304d\u307e\u3059\u3002<\/li><\/ul>\n\n\n\n<p>\u3053\u306e\u3088\u3046\u306b\u3001GitHub\u3068CDK\u3092\u7d44\u307f\u5408\u308f\u305b\u308b\u3053\u3068\u3067\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3068\u52b9\u7387\u3092\u4e21\u7acb\u3057\u305f\u30a4\u30f3\u30d5\u30e9\u7ba1\u7406\u304c\u5b9f\u73fe\u3067\u304d\u307e\u3059\u3002\u305c\u3072\u3054\u81ea\u8eab\u306e\u30d7\u30ed\u30b8\u30a7\u30af\u30c8\u306b\u3082\u53d6\u308a\u5165\u308c\u3066\u307f\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n\n\n\n<p>\u4eca\u56de\u7d39\u4ecb\u3057\u305f\u69cb\u6210\u3092\u30d9\u30fc\u30b9\u306b\u3001Slack\u901a\u77e5\u3084\u30c6\u30b9\u30c8\u306e\u81ea\u52d5\u5b9f\u884c\u306a\u3069\u3001\u3088\u308a\u5b9f\u8df5\u7684\u306aCI\/CD\u30d1\u30a4\u30d7\u30e9\u30a4\u30f3\u306b\u3082\u767a\u5c55\u3055\u305b\u3066\u3044\u304f\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u306f\u3058\u3081\u306b AWS\u4e0a\u306b\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u30c7\u30d7\u30ed\u30a4\u3059\u308b\u969b\u3001\u5b89\u5168\u304b\u3064\u52b9\u7387\u7684\u306b\u904b\u7528\u3059\u308b\u305f\u3081\u306b\u306f\u3001\u624b\u4f5c\u696d\u3067\u306f\u306a\u304f\u81ea\u52d5\u5316\u3055\u308c\u305f\u4ed5\u7d44\u307f\uff08CI\/CD\u30d1\u30a4\u30d7\u30e9\u30a4\u30f3\uff09\u3092\u5c0e\u5165\u3059\u308b\u3053\u3068\u304c\u91cd\u8981\u3067\u3059\u3002 \u672c\u8a18\u4e8b\u3067\u306f\u3001\u30a4\u30f3\u30d5\u30e9\u69cb\u7bc9\u30c4\u30fc\u30eb\u3067\u3042\u308bAWS C [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":891,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[18],"tags":[],"class_list":["post-888","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech-blog"],"aioseo_notices":[],"views":2437,"_links":{"self":[{"href":"https:\/\/baresupport.jp\/blog\/wp-json\/wp\/v2\/posts\/888","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/baresupport.jp\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/baresupport.jp\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/baresupport.jp\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/baresupport.jp\/blog\/wp-json\/wp\/v2\/comments?post=888"}],"version-history":[{"count":5,"href":"https:\/\/baresupport.jp\/blog\/wp-json\/wp\/v2\/posts\/888\/revisions"}],"predecessor-version":[{"id":896,"href":"https:\/\/baresupport.jp\/blog\/wp-json\/wp\/v2\/posts\/888\/revisions\/896"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/baresupport.jp\/blog\/wp-json\/wp\/v2\/media\/891"}],"wp:attachment":[{"href":"https:\/\/baresupport.jp\/blog\/wp-json\/wp\/v2\/media?parent=888"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/baresupport.jp\/blog\/wp-json\/wp\/v2\/categories?post=888"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/baresupport.jp\/blog\/wp-json\/wp\/v2\/tags?post=888"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}