Dev-Kyuu
article thumbnail

์šฐ๋ฆฌ ํŒ€ ๋…ธ์…˜์— ์ž‘์„ฑํ•œ ๋‚ด์šฉ์ธ๋ฐ ๊ฐ™์€ ๋‚ด์šฉ์œผ๋กœ ๊ณ ๋ฏผํ•˜๊ณ ์žˆ๋Š” ๋ถ„์ด ์žˆ์œผ์‹ค ์ˆ˜ ์žˆ์œผ๋‹ˆ ์ฐธ์กฐํ•˜์‹œ๋ผ๊ณ  ์˜ฌ๋ฆฝ๋‹ˆ๋‹ค โœจ

 

Github Action์„ ์ด์šฉํ•œ CI/CD ๊ตฌ์„ฑ์‹œ ํ”„๋กœ์ ํŠธ ๋นŒ๋“œ์— ํ•„์š”ํ•œ ๋ชจ๋“  ํŒŒ์ผ์ด ๊นƒํ—ˆ๋ธŒ์— ์˜ฌ๋ผ๊ฐ€์•ผํ•˜๋Š”๋ฐ

aws key ๊ฐ™์ด ๊ณต๊ฐœ๋œ ์žฅ์†Œ์— ์˜ฌ๋ฆฌ๋ฉด ์•ˆ๋˜๋Š” ์ •๋ณด๋“ค์„ ์–ด๋–ป๊ฒŒ ์ฒ˜๋ฆฌํ•ด์•ผํ• ๊นŒ โ“

 

๐Ÿ”‘ GPG๋กœ ์ฃผ์š”ํŒŒ์ผ ์•”ํ˜ธํ™” ํ•˜์—ฌ์—…๋กœ๋“œํ•˜๊ธฐ

  • gpg๋Š” GnuPG(Privacy Guard)์˜ OpenPGP ๋ถ€๋ถ„์„ ๊ตฌํ˜„ํ•œ ์•”๋ณตํ˜ธํ™” ํ”„๋กœ๊ทธ๋žจ์œผ๋กœ ์š”๊ฑธ ์‚ฌ์šฉํ•œ๋‹ค.

GPG Key ์ƒ์„ฑํ•˜๊ธฐ

1. GPG Key ์ƒ์„ฑ
gpg --gen-key
2. gpg secring.gpg ํŒŒ์ผ ์ƒ์„ฑ(๊ฐœ์ธํ‚ค)
gpg --export-secret-keys -o secring.gpg
3. gpg keyid ์–ป๊ธฐ
gpg --list-keys --keyid-format short

4. ๊ณต๊ฐœํ‚ค ์„œ๋ฒ„๋กœ ์ „์†ก
gpg2 --keyserver hkp://pool.sks-keyservers.net --recv-keys ๋นจ๊ฐ„๋ฐ•์Šค๋ถ€๋ถ„์—์žˆ๋Š”Key๊ฐ’

 

GPG Key๋กœ ์•”ํ˜ธํ™”ํ•˜๊ธฐ

  • ์ด์ œ ์ƒ์„ฑ๋œ ์•”ํ˜ธํ™”ํ‚ค๋กœ ๋‚ด๊ฐ€ ์•”ํ˜ธํ™” ํ•˜๊ณ ์ž ํ•˜๋Š” ํŒŒ์ผ์„ ์•”ํ˜ธํ™” ํ•œ๋‹ค ๐Ÿ˜Ž

 

1) ์„ค์ • ํŒŒ์ผ์ด ์žˆ๋Š” ๊ฒฝ๋กœ๋กœ ์ด๋™ํ•˜๊ธฐ

1. ํด๋” ๊ฒฝ๋กœ๋กœ ์ด๋™
cd /Users/kyuung/../src/main/resources

2. ํด๋” ๋ฆฌ์ŠคํŠธ ํ™•์ธ  > ll

2) application-aws.properties ํŒŒ์ผ tar ํ˜•์‹์œผ๋กœ ์••์ถ•

1. application-aws.properties ์••์ถ• 

tar cvf application.tar application-aws.properties
( tar cvf ์••์ถ•๋˜๊ณ ๋‚˜์„œ์˜ํŒŒ์ผ๋ช… ์••์ถ•ํ•˜๊ณ ์‹ถ์€ ๋Œ€์ƒํŒŒ์ผ๋ช… )
    3) GPG ์•”ํ˜ธํ™”
gpg -c application.tar
  • ์ด ๋ช…๋ น์–ด ์ž…๋ ฅํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ์ฐฝ์ด ๋œจ๋Š”๋ฐ ๋น„๋ฐ€๋ฒˆํ˜ธ ๋‘๋ฒˆ ์ž…๋ ฅํ•˜๋ฉด ๋จ! ๋‚ด๊ฐ€ ์“ฐ๊ณ ์‹ถ์€๊ฑฐ๋ฃฝ

⇒ ๊ทธ๋Ÿฌ๋ฉด application.tar.gpg ํŒŒ์ผ์ด ์ƒ๊ธด๊ฒƒ์„ ๋ณผ ์ˆ˜ ์žˆ๋‹น

**) ์•”ํ˜ธํ™”๋˜๊ธฐ ์ „ ์›๋ณธํŒŒ์ผ (application-aws.properties, application.tar)์€ ์‚ญ์ œํ•˜๊ฑฐ๋‚˜ .gitignore์— ์˜ฌ๋ ค์„œ ์—…๋กœ๋“œ ๋˜์ง€ ์•Š๋„๋ก ํ•˜๊ธฐ!!

 

 

๋ฒˆ์™ธ ) GPG Key๋กœ ์•”ํ˜ธํ™”ํ•œ ํŒŒ์ผ ๋ณตํ˜ธํ™”ํ•˜๊ธฐ

  • GPG Key๋กœ ์•”ํ˜ธํ™”ํ•œ ํŒŒ์ผ์„ ์—ด์–ด์„œ ์ˆ˜์ •ํ• ์ผ์ด ์žˆ๋‹ค๋ฉด ์•„๋ž˜์™€ ๊ฐ™์ด ์ง„ํ–‰ํ•˜๋ฉด ๋œ๋‹ค.

1) ์„ค์ • ํŒŒ์ผ์ด ์žˆ๋Š” ๊ฒฝ๋กœ๋กœ ์ด๋™ํ•˜๊ธฐ

1. ํด๋” ๊ฒฝ๋กœ๋กœ ์ด๋™
cd /Users/kyuung/../src/main/resources

2. ํด๋” ๋ฆฌ์ŠคํŠธ ํ™•์ธ  > ll 

2) GPG ์•”ํ˜ธํ™” ํŒŒ์ผ ๋ณตํ˜ธํ™”ํ•˜๊ธฐ

gpg --quiet --batch --yes --always-trust --decrypt --output ./๋ณตํ˜ธํ™”ํ›„ํŒŒ์ผ๋ช… ./๋ณตํ˜ธํ™”ํ• ํŒŒ์ผ๋ช…

ex ) gpg --quiet --batch --yes --always-trust --decrypt --output ./application.tar ./application.tar.gpg

3) tar ์••์ถ•ํ•ด์ œํ•ด์„œ ์‚ฌ์šฉํ•˜๊ธฐ

tar -xvf ์••์ถ•ํ•ด์ œํ•  ํŒŒ์ผ๋ช…

์ด์ƒ ๋!

 

*) ๋งŒ์•ฝ ์ด ํŒŒ์ผ์„ ์ € ์ฒ˜๋Ÿผ GitHub Action์—์„œ ์ž๋™์œผ๋กœ ๋นŒ๋“œ๋˜๊ฒŒ ํ•˜๋ ค๋ฉด Repository์˜ Security Key์— key๊ฐ’์„ ๋„ฃ๊ณ  ์ฒ˜๋ฆฌํ•ด์ฃผ๋ฉด ๋จ !

profile

Dev-Kyuu

@kyuu_ng

ํฌ์ŠคํŒ…์ด ์ข‹์•˜๋‹ค๋ฉด "์ข‹์•„์š”โค๏ธ" ๋˜๋Š” "๊ตฌ๋…๐Ÿ‘๐Ÿป" ํ•ด์ฃผ์„ธ์š”!