{"id":2172,"date":"2021-04-06T18:21:14","date_gmt":"2021-04-06T15:21:14","guid":{"rendered":"https:\/\/artem.services\/?p=2172"},"modified":"2021-04-06T18:22:57","modified_gmt":"2021-04-06T15:22:57","slug":"aws-s3-%d1%80%d0%b0%d0%b7%d1%80%d0%b5%d1%88%d0%b8%d1%82%d1%8c-%d0%bf%d1%83%d0%b1%d0%bb%d0%b8%d1%87%d0%bd%d1%8b%d0%b9-%d0%b4%d0%be%d1%81%d1%82%d1%83%d0%bf-%d0%ba-%d0%be%d0%b1%d1%8a%d0%b5%d0%ba%d1%82","status":"publish","type":"post","link":"https:\/\/artem.services\/?p=2172","title":{"rendered":"AWS &#8212; S3: \u0420\u0430\u0437\u0440\u0435\u0448\u0438\u0442\u044c \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043e\u0431\u044a\u0435\u043a\u0442\u0430\u043c \u0447\u0435\u0440\u0435\u0437 VPN"},"content":{"rendered":"<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-214\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2018\/11\/AWS-Logo.png\" alt=\"\" width=\"975\" height=\"450\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2018\/11\/AWS-Logo.png 975w, https:\/\/artem.services\/wp-content\/uploads\/2018\/11\/AWS-Logo-300x138.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2018\/11\/AWS-Logo-768x354.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2018\/11\/AWS-Logo-954x440.png 954w\" sizes=\"(max-width: 975px) 100vw, 975px\" \/><\/p>\n<h3>\u0426\u0435\u043b\u044c:<\/h3>\n<p>\u0420\u0430\u0437\u0440\u0435\u0448\u0438\u0442\u044c \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043d\u0430 \u0447\u0442\u0435\u043d\u0438\u0435 \u0434\u043b\u044f \u0432\u0441\u0435\u0445 \u043e\u0431\u044a\u0435\u043a\u0442\u043e\u0432 \u0432 <strong>S3<\/strong> \u043a\u043e\u0440\u0437\u0438\u043d\u0435 \u0442\u043e\u043b\u044c\u043a\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f <strong>VPN<\/strong> \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435, \u0434\u043b\u044f \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0441 \u043c\u0438\u0440\u0430 \u043e\u0431\u044a\u0435\u043a\u0442\u044b \u0434\u043e\u043b\u0436\u043d\u044b \u0431\u044b\u0442\u044c \u043d\u0435 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u044b\u043c\u0438. \u0412 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0441\u0435\u0440\u0432\u0438\u0441\u0430 <strong>VPN<\/strong> \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f <strong>OpenVPN<\/strong>, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u0440\u0430\u0437\u0432\u0435\u0440\u043d\u0443\u0442 \u0433\u0434\u0435 \u0443\u0433\u043e\u0434\u043d\u043e, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u0440\u0430\u0437\u0440\u0435\u0448\u0430\u044e\u0449\u0438\u0435 \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u0431\u0443\u0434\u0435\u043c \u0441\u0442\u0440\u043e\u0438\u0442\u044c \u043d\u0430 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 <strong>IP<\/strong> \u0430\u0434\u0440\u0435\u0441\u0430.<\/p>\n<p>&nbsp;<\/p>\n<p>\u0414\u043b\u044f \u043d\u0430\u0447\u0430\u043b\u0430 \u043d\u0443\u0436\u043d\u043e \u0443\u0437\u043d\u0430\u0442\u044c \u0441\u043f\u0438\u0441\u043e\u043a \u0441\u0435\u0442\u0435\u0439, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043e\u0442\u043d\u043e\u0441\u044f\u0442\u0441\u044f \u043a \u044d\u043d\u0434\u043f\u043e\u0438\u043d\u0442\u0430\u043c <strong>S3<\/strong> \u0441\u0435\u0440\u0432\u0438\u0441\u0430 \u0432 \u043d\u0443\u0436\u043d\u043e\u043c \u043d\u0430\u043c \u0440\u0435\u0433\u0438\u043e\u043d\u0435, \u0447\u0442\u043e\u0431\u044b \u043d\u0435 \u0437\u0430\u0432\u043e\u0440\u0430\u0447\u0438\u0432\u0430\u0442\u044c \u0432\u0435\u0441\u044c \u0442\u0440\u0430\u0444\u0444\u0438\u043a \u0447\u0435\u0440\u0435\u0437 <strong>VPN<\/strong>. \u0414\u043b\u044f \u044d\u0442\u043e \u0441\u043a\u0430\u0447\u0438\u0432\u0430\u0435\u043c <a href=\"https:\/\/ip-ranges.amazonaws.com\/ip-ranges.json\" target=\"_blank\" rel=\"noopener noreferrer\">\u0430\u043a\u0442\u0443\u0430\u043b\u044c\u043d\u044b\u0439 \u0441\u043f\u0438\u0441\u043e\u043a \u0441\u0435\u0442\u0435\u0439<\/a> \u0438 \u043f\u0430\u0440\u0441\u0438\u043c \u0435\u0433\u043e:<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\r\njq '.prefixes[] | select(.region==&quot;eu-central-1&quot;) | select(.service==&quot;S3&quot;) | .ip_prefix' &lt; ip-ranges.json\r\n<\/pre>\n<p>&nbsp;<\/p>\n<blockquote><p>\u0413\u0434\u0435, &quot;<strong>eu-central-1<\/strong>&quot; \u0440\u0435\u0433\u0438\u043e\u043d, \u0432 \u043a\u043e\u0442\u043e\u0440\u043e\u043c \u043d\u0430\u0445\u043e\u0434\u0438\u0442\u0441\u044f \u043d\u0443\u0436\u043d\u0430\u044f S3 \u043a\u043e\u0440\u0437\u0438\u043d\u0430.<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<p>\u0412\u044b \u0434\u043e\u043b\u0436\u043d\u044b \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442 \u0432\u0438\u0434\u0430:<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\r\n&quot;52.219.170.0\/23&quot;\r\n&quot;52.219.168.0\/24&quot;\r\n&quot;3.5.136.0\/22&quot;\r\n&quot;52.219.72.0\/22&quot;\r\n&quot;52.219.44.0\/22&quot;\r\n&quot;52.219.169.0\/24&quot;\r\n&quot;52.219.140.0\/24&quot;\r\n&quot;54.231.192.0\/20&quot;\r\n&quot;3.5.134.0\/23&quot;\r\n&quot;3.65.246.0\/28&quot;\r\n&quot;3.65.246.16\/28&quot;\r\n<\/pre>\n<p>&nbsp;<\/p>\n<p>\u0422\u0435\u043f\u0435\u0440\u044c \u043f\u0435\u0440\u0435\u0432\u043e\u0434\u0438\u043c \u043c\u0430\u0441\u043a\u0443 \u043f\u043e\u0434\u0441\u0435\u0442\u0438 \u0432 4-\u0445 \u0431\u0430\u0439\u0442\u043d\u044b\u0439 \u0444\u043e\u0440\u043c\u0430\u0442 \u0438 \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u043c \u0432 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u044e <strong>OpenVPN<\/strong> \u0441\u0435\u0440\u0432\u0435\u0440\u0430, \u043a\u0430\u043a &quot;<strong>push<\/strong>&quot; \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u044b:<\/p>\n<pre class=\"brush: bash; title: ; notranslate\" title=\"\">\r\npush &quot;route 52.219.170.0 255.255.254.0&quot;\r\npush &quot;route 52.219.168.0 255.255.255.0&quot;\r\npush &quot;route 3.5.136.0 255.255.252.0&quot;\r\npush &quot;route 52.219.72.0 255.255.252.0&quot;\r\npush &quot;route 52.219.44.0 255.255.252.0&quot;\r\npush &quot;route 52.219.169.0 255.255.255.0&quot;\r\npush &quot;route 52.219.140.0 255.255.255.0&quot;\r\npush &quot;route 54.231.192.0 255.255.240.0&quot;\r\npush &quot;route 3.5.134.0 255.255.254.0&quot;\r\npush &quot;route 3.65.246.0 255.255.255.240&quot;\r\npush &quot;route 3.65.246.16 255.255.255.240&quot;\r\n<\/pre>\n<p>&nbsp;<\/p>\n<p>\u041f\u0435\u0440\u0435\u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u043c \u0441\u0435\u0440\u0432\u0438\u0441 <strong>OpenVPN<\/strong> \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0438 \u043f\u043e\u0441\u043b\u0435 \u043f\u0435\u0440\u0435\u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043c\u044b \u0434\u043e\u043b\u0436\u043d\u044b \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0441\u043f\u0438\u0441\u043e\u043a \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u044b\u0445 \u0441\u0435\u0442\u0435\u0439 \u0438 \u0442\u0440\u0430\u0444\u0444\u0438\u043a \u0431\u0443\u0434\u0435\u0442 \u0438\u0434\u0442\u0438 \u0447\u0435\u0440\u0435\u0437 <strong>VPN<\/strong> \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435.<\/p>\n<p>&nbsp;<\/p>\n<p>\u0422\u0435\u043f\u0435\u0440\u044c \u043e\u0441\u0442\u0430\u043b\u043e\u0441\u044c \u0434\u043e\u0431\u0430\u0432\u0438\u0442\u044c \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0443\u044e \u043f\u043e\u043b\u0438\u0442\u0438\u043a\u0443 \u043a <strong>S3<\/strong> \u043a\u043e\u0440\u0437\u0438\u043d\u0435:<\/p>\n<pre class=\"brush: java; title: ; notranslate\" title=\"\">\r\n{\r\n    &quot;Version&quot;: &quot;2012-10-17&quot;,\r\n    &quot;Statement&quot;: [\r\n        {\r\n            &quot;Sid&quot;: &quot;Allow only from VPN&quot;,\r\n            &quot;Effect&quot;: &quot;Allow&quot;,\r\n            &quot;Principal&quot;: &quot;*&quot;,\r\n            &quot;Action&quot;: [\r\n                &quot;s3:GetObject&quot;,\r\n                &quot;s3:ListBucket&quot;\r\n            ],\r\n            &quot;Resource&quot;: [\r\n                &quot;arn:aws:s3:::artem-services&quot;,\r\n                &quot;arn:aws:s3:::artem-services\/*&quot;\r\n            ],\r\n            &quot;Condition&quot;: {\r\n                &quot;IpAddress&quot;: {\r\n                    &quot;aws:SourceIp&quot;: &quot;1.2.3.4&quot;\r\n                }\r\n            }\r\n        }\r\n    ]\r\n}\r\n<\/pre>\n<p>&nbsp;<\/p>\n<blockquote><p>\u0413\u0434\u0435, &quot;<strong>artem-services<\/strong>&quot; &#8212; \u0438\u043c\u044f <strong>S3<\/strong> \u043a\u043e\u0440\u0437\u0438\u043d\u044b, \u0430 &quot;<strong>1.2.3.4<\/strong>&quot; &#8212; <strong>IP<\/strong> \u0430\u0434\u0440\u0435\u0441 <strong>OpenVPN<\/strong> \u0441\u0435\u0440\u0432\u0435\u0440\u0430.<\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>\u0426\u0435\u043b\u044c: \u0420\u0430\u0437\u0440\u0435\u0448\u0438\u0442\u044c \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043d\u0430 \u0447\u0442\u0435\u043d\u0438\u0435 \u0434\u043b\u044f \u0432\u0441\u0435\u0445 \u043e\u0431\u044a\u0435\u043a\u0442\u043e\u0432 \u0432 S3 \u043a\u043e\u0440\u0437\u0438\u043d\u0435 \u0442\u043e\u043b\u044c\u043a\u043e \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f VPN \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435, \u0434\u043b\u044f \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0441 \u043c\u0438\u0440\u0430 \u043e\u0431\u044a\u0435\u043a\u0442\u044b \u0434\u043e\u043b\u0436\u043d\u044b \u0431\u044b\u0442\u044c \u043d\u0435 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u044b\u043c\u0438. \u0412 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0441\u0435\u0440\u0432\u0438\u0441\u0430 VPN \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f OpenVPN, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043c\u043e\u0436\u0435\u0442 \u0431\u044b\u0442\u044c \u0440\u0430\u0437\u0432\u0435\u0440\u043d\u0443\u0442 \u0433\u0434\u0435 \u0443\u0433\u043e\u0434\u043d\u043e, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u0440\u0430\u0437\u0440\u0435\u0448\u0430\u044e\u0449\u0438\u0435 \u043f\u0440\u0430\u0432\u0438\u043b\u043e \u0431\u0443\u0434\u0435\u043c \u0441\u0442\u0440\u043e\u0438\u0442\u044c \u043d\u0430 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 IP \u0430\u0434\u0440\u0435\u0441\u0430. &nbsp; \u0414\u043b\u044f \u043d\u0430\u0447\u0430\u043b\u0430 \u043d\u0443\u0436\u043d\u043e \u0443\u0437\u043d\u0430\u0442\u044c \u0441\u043f\u0438\u0441\u043e\u043a \u0441\u0435\u0442\u0435\u0439, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043e\u0442\u043d\u043e\u0441\u044f\u0442\u0441\u044f &hellip; <a href=\"https:\/\/artem.services\/?p=2172\" class=\"more-link\">\u041f\u0440\u043e\u0434\u043e\u043b\u0436\u0438\u0442\u044c \u0447\u0438\u0442\u0430\u0442\u044c<span class=\"screen-reader-text\"> &quot;AWS &#8212; S3: \u0420\u0430\u0437\u0440\u0435\u0448\u0438\u0442\u044c \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u044b\u0439 \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u043e\u0431\u044a\u0435\u043a\u0442\u0430\u043c \u0447\u0435\u0440\u0435\u0437 VPN&quot;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[24],"tags":[25,12,35,1769],"_links":{"self":[{"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts\/2172"}],"collection":[{"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2172"}],"version-history":[{"count":3,"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts\/2172\/revisions"}],"predecessor-version":[{"id":2175,"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts\/2172\/revisions\/2175"}],"wp:attachment":[{"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2172"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2172"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2172"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}