{"id":26040,"date":"2025-12-01T19:02:23","date_gmt":"2025-12-01T19:02:23","guid":{"rendered":"https:\/\/pokecon.jp\/job\/?p=26040"},"modified":"2025-12-01T19:02:23","modified_gmt":"2025-12-01T19:02:23","slug":"aws%e3%81%a7organizationalunit%e3%81%94%e3%81%a8%e3%81%ab%e5%88%a9%e7%94%a8%e6%96%99%e9%87%91%e3%82%92%e9%9b%86%e8%a8%88%e3%81%99%e3%82%8b%e7%92%b0%e5%a2%83%e3%82%92%e4%bd%9c%e6%88%90%e3%81%97","status":"publish","type":"post","link":"https:\/\/pokecon.jp\/job\/26040\/","title":{"rendered":"AWS\u3067OrganizationalUnit\u3054\u3068\u306b\u5229\u7528\u6599\u91d1\u3092\u96c6\u8a08\u3059\u308b\u74b0\u5883\u3092\u4f5c\u6210\u3057\u305f\u8a71 &#8211; FURYU Tech Blog"},"content":{"rendered":"\n<\/p>\n<div>\n<p>\u3053\u306e\u8a18\u4e8b\u306f <a target=\"_blank\" href=\"https:\/\/qiita.com\/advent-calendar\/2025\/furyu\">\u30d5\u30ea\u30e5\u30fcAdvent Calendar 2025<\/a> \u306e2\u65e5\u76ee\u306e\u8a18\u4e8b\u3067\u3059\u3002<\/p>\n<p>\u3053\u3093\u306b\u3061\u306f\u3001\u30d5\u30ea\u30e5\u30fc\u682a\u5f0f\u4f1a\u793e\u3067\u30d4\u30af\u30c8\u30ea\u30f3\u30af\u306e\u958b\u767a\u3092\u3057\u3066\u3044\u308b\u307e\u3055\u304a\u3067\u3059\ud83d\udc7b<\/p>\n<p>\u4eca\u65e5\u306fAWS\u30a2\u30ab\u30a6\u30f3\u30c8A\u306eEC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3067\u52d5\u3044\u3066\u3044\u308bRundeck\u304b\u3089\u30a2\u30ab\u30a6\u30f3\u30c8B\u306b\u3042\u308bLambda\u3092\u5b9f\u884c\u3057\u3001\u305d\u306eLambda\u306e\u4e2d\u3067OrganizationalUnit\u3054\u3068\u306bAWS\u306e\u5229\u7528\u6599\u91d1\u3092\u96c6\u8a08\u3057\u3088\u3046\u3068\u3057\u305f\u8a71\u3092\u3057\u307e\u3059\u3002<br \/>\n\u4eca\u56de\u306f\u305d\u3053\u3067\u5fc5\u8981\u306a\u30ea\u30bd\u30fc\u30b9\u3092CDK\u3067\u4f5c\u6210\u3057\u305f\u90e8\u5206\u306e\u304a\u8a71\u304c\u30e1\u30a4\u30f3\u3067\u3001\u96c6\u8a08\u3059\u308bPython\u30b3\u30fc\u30c9\u306e\u89e3\u8aac\u306f\u307b\u307c\u3057\u307e\u305b\u3093\u3002<\/p>\n<p>\u3056\u3063\u304f\u308a\u3068\u3057\u305f\u69cb\u6210\u306f\u3053\u306e\u3088\u3046\u306a\u611f\u3058\u3002<\/p>\n<figure class=\"figure-image figure-image-fotolife\" title=\"\u3056\u3063\u304f\u308a\u3068\u3057\u305f\u69cb\u6210\u56f3\"><span itemscope=\"\" itemtype=\"http:\/\/schema.org\/Photograph\"><img decoding=\"async\" src=\"https:\/\/cdn-ak.f.st-hatena.com\/images\/fotolife\/f\/furyu-tech\/20251202\/20251202000032.jpg\" width=\"761\" height=\"341\" loading=\"lazy\" title=\"\" class=\"hatena-fotolife\" itemprop=\"image\"\/><\/span><figcaption>\u3056\u3063\u304f\u308a\u3068\u3057\u305f\u69cb\u6210\u56f3<\/figcaption><\/figure>\n<\/p>\n<p>\u30a2\u30ab\u30a6\u30f3\u30c8A\u5074\u306f\u65e2\u306b\u3042\u308b\u74b0\u5883\u3092\u5229\u7528\u3057\u3001\u30a2\u30ab\u30a6\u30f3\u30c8B\u5074\u306eLambda\u5468\u308a\u3092\u65b0\u305f\u306b\u7528\u610f\u3057\u307e\u3059\u3002\u30a2\u30ab\u30a6\u30f3\u30c8B\u5074\u306e\u30ed\u30fc\u30eb\u304c\u7d30\u304b\u304f\u5206\u304b\u308c\u3066\u3044\u308b\u306e\u3067\u5c11\u3057\u3084\u3084\u3053\u3057\u3044\u3067\u3059\u304c\u3001\u305d\u308c\u305e\u308c\u306e\u5f79\u5272\u306b\u57fa\u3065\u3044\u305f\u5fc5\u8981\u306a\u5206\u5272\u3092\u3057\u305f\u7d50\u679c\u3053\u306e\u3088\u3046\u306b\u306a\u308a\u307e\u3057\u305f\u3002<\/p>\n<p>\u3067\u306f\u4ee5\u4e0b\u3067\u4e00\u500b\u4e00\u500b\u306e\u30ea\u30bd\u30fc\u30b9\u306e\u5b9f\u88c5\u306b\u3064\u3044\u3066\u793a\u3057\u3066\u3044\u304d\u307e\u3059\u3002<\/p>\n<h2 id=\"\u30a2\u30ab\u30a6\u30f3\u30c8A\u5074\u306e\u30ed\u30fc\u30eb\u306b\u6a29\u9650\u8ffd\u52a0\">\u30a2\u30ab\u30a6\u30f3\u30c8A\u5074\u306e\u30ed\u30fc\u30eb\u306b\u6a29\u9650\u8ffd\u52a0<\/h2>\n<p>\u30a2\u30ab\u30a6\u30f3\u30c8A\u306eEC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u306b\u4ed8\u4e0e\u3059\u308b\u30ed\u30fc\u30eb\u306b\u4ee5\u4e0b\u306e\u8a2d\u5b9a\u3092\u8ffd\u52a0\u3057\u307e\u3059\u3002<\/p>\n<pre class=\"code lang-typescript\" data-lang=\"typescript\" data-unlink=\"\"><span class=\"synIdentifier\">new<\/span> PolicyStatement(<span class=\"synIdentifier\">{<\/span>\n    <span class=\"synStatement\">effect<\/span>: Effect.ALLOW,\n    <span class=\"synStatement\">actions<\/span>: <span class=\"synIdentifier\">[<\/span><span class=\"synConstant\">'sts:AssumeRole'<\/span><span class=\"synIdentifier\">]<\/span>,\n    <span class=\"synStatement\">resources<\/span>: <span class=\"synIdentifier\">[<\/span>\n        <span class=\"synConstant\">'arn:aws:lambda:ap-northeast-1:\u30a2\u30ab\u30a6\u30f3\u30c8B:function:Lambda\u547c\u3073\u51fa\u3057\u7528\u30ed\u30fc\u30eb'<\/span>  \n    <span class=\"synIdentifier\">]<\/span>,\n<span class=\"synIdentifier\">}<\/span>)\n<\/pre>\n<p>\u30a2\u30ab\u30a6\u30f3\u30c8A\u304b\u3089\u30a2\u30ab\u30a6\u30f3\u30c8B\u306eLambda\u3092\u5b9f\u884c\u3059\u308b\u969b\u306b\u3001\u3053\u306eresources\u3067\u6307\u5b9a\u3057\u305f\u30ed\u30fc\u30eb\u3092Assume\u3057\u3066\u304b\u3089Lambda\u306e\u547c\u3073\u51fa\u3057\u3092\u3057\u307e\u3059\u3002<br \/>\nShell\u30b9\u30af\u30ea\u30d7\u30c8\u3067\u66f8\u304f\u3068\u3053\u3093\u306a\u611f\u3058\u3067\u3059\u3002<\/p>\n<pre class=\"code Shell\" data-lang=\"Shell\" data-unlink=\"\">aws sts assume-role \\\n  --role-arn arn:aws:iam::\u30a2\u30ab\u30a6\u30f3\u30c8B:role\/Lambda\u547c\u3073\u51fa\u3057\u7528\u30ed\u30fc\u30eb \\\n  --role-session-name cost-check-lambda-session \\\n  --output json &gt; \/tmp\/session.json\n\n# \u53d6\u5f97\u3057\u305f\u4e00\u6642\u8a8d\u8a3c\u60c5\u5831\u3067Lambda\u3092\u5b9f\u884c\nAWS_ACCESS_KEY_ID=$(cat \/tmp\/session.json | jq -r '.Credentials.AccessKeyId') \\\nAWS_SECRET_ACCESS_KEY=$(cat \/tmp\/session.json | jq -r '.Credentials.SecretAccessKey') \\\nAWS_SESSION_TOKEN=$(cat \/tmp\/session.json | jq -r '.Credentials.SessionToken') \\\naws lambda invoke \\\n  --function-name arn:aws:lambda:ap-northeast-1:\u30a2\u30ab\u30a6\u30f3\u30c8B:function:cost-check-lambda \\\n  --region ap-northeast-1 \\\n  \/tmp\/costCheckLambdaResponse.json<\/pre>\n<h2 id=\"\u30a2\u30ab\u30a6\u30f3\u30c8B\u5074\u306e\u30ea\u30bd\u30fc\u30b9\u4f5c\u6210\">\u30a2\u30ab\u30a6\u30f3\u30c8B\u5074\u306e\u30ea\u30bd\u30fc\u30b9\u4f5c\u6210<\/h2>\n<h3 id=\"\u30ed\u30fc\u30eb1-Lambda\u306e\u547c\u3073\u51fa\u3057\u7528\u30ed\u30fc\u30eb\">\u30ed\u30fc\u30eb1: Lambda\u306e\u547c\u3073\u51fa\u3057\u7528\u30ed\u30fc\u30eb<\/h3>\n<p>Lambda\u3092\u547c\u3073\u51fa\u3057\u3066\u5b9f\u884c\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u308b\u6a29\u9650\u3092\u6301\u3064\u30ed\u30fc\u30eb\u3092\u4f5c\u308a\u307e\u3059\u3002<br \/>\n\u524d\u8ff0\u306e\u30a2\u30ab\u30a6\u30f3\u30c8A\u5074\u3067Assume\u3057\u3066\u4f7f\u7528\u3059\u308b\u3082\u306e\u3067\u3059\u3002<br \/>\n\u3053\u306e\u30ed\u30fc\u30eb\u306b\u306f\u3001\u30b9\u30af\u30ea\u30d7\u30c8\u5185\u3067\u884c\u3046\u64cd\u4f5c\u306b\u5fc5\u8981\u306a\u6a29\u9650\u306f\u4e0d\u8981\u3067\u3059\u3002<\/p>\n<pre class=\"code lang-typescript\" data-lang=\"typescript\" data-unlink=\"\"><span class=\"synIdentifier\">const<\/span> role = <span class=\"synIdentifier\">new<\/span> Role(<span class=\"synType\">this<\/span>, <span class=\"synConstant\">'lambda-execution-role'<\/span>, <span class=\"synIdentifier\">{<\/span>  \n    <span class=\"synStatement\">roleName<\/span>: <span class=\"synConstant\">'lambda-execution-role'<\/span>,  \n    <span class=\"synStatement\">assumedBy<\/span>: <span class=\"synIdentifier\">new<\/span> ServicePrincipal(<span class=\"synConstant\">'lambda.amazonaws.com'<\/span>),  \n    <span class=\"synStatement\">managedPolicies<\/span>: <span class=\"synIdentifier\">[<\/span>  \n        ManagedPolicy.fromAwsManagedPolicyName(<span class=\"synConstant\">'service-role\/AWSLambdaBasicExecutionRole'<\/span>),\n        ManagedPolicy.fromAwsManagedPolicyName(<span class=\"synConstant\">'service-role\/AWSLambdaVPCAccessExecutionRole'<\/span>),\n        <span class=\"synIdentifier\">new<\/span> ManagedPolicy(<span class=\"synType\">this<\/span>, <span class=\"synConstant\">'lambda-policy-3'<\/span>, <span class=\"synIdentifier\">{<\/span>  \n            <span class=\"synStatement\">path<\/span>: <span class=\"synConstant\">'\/service-role\/'<\/span>,  \n            <span class=\"synStatement\">managedPolicyName<\/span>: <span class=\"synConstant\">'InvokeCostLambda'<\/span>,  \n            <span class=\"synStatement\">statements<\/span>: <span class=\"synIdentifier\">[<\/span>  \n                <span class=\"synIdentifier\">new<\/span> PolicyStatement(<span class=\"synIdentifier\">{<\/span>  \n                    <span class=\"synStatement\">effect<\/span>: Effect.ALLOW,  \n                    <span class=\"synStatement\">actions<\/span>: <span class=\"synIdentifier\">[<\/span><span class=\"synConstant\">'lambda:InvokeFunction'<\/span><span class=\"synIdentifier\">]<\/span>,  \n                    <span class=\"synStatement\">resources<\/span>: <span class=\"synIdentifier\">[<\/span>  \n                        <span class=\"synConstant\">'arn:aws:lambda:ap-northeast-1:\u30a2\u30ab\u30a6\u30f3\u30c8B:function:cost-check-lambda'<\/span>  \n                    <span class=\"synIdentifier\">]<\/span>,  \n                <span class=\"synIdentifier\">}<\/span>),  \n            <span class=\"synIdentifier\">]<\/span>,  \n        <span class=\"synIdentifier\">}<\/span>)\n});  \n  \nrole.assumeRolePolicy?.addStatements(  \n    <span class=\"synIdentifier\">new<\/span> PolicyStatement(<span class=\"synIdentifier\">{<\/span>  \n        <span class=\"synStatement\">effect<\/span>: Effect.ALLOW,  \n        <span class=\"synStatement\">principals<\/span>: <span class=\"synIdentifier\">[<\/span>\n            <span class=\"synIdentifier\">new<\/span> ArnPrincipal(<span class=\"synConstant\">\"arn:aws:iam::\u30a2\u30ab\u30a6\u30f3\u30c8A:role\/RundeckBatchRole\"<\/span>)  \n        <span class=\"synIdentifier\">]<\/span>,  \n        <span class=\"synStatement\">actions<\/span>: <span class=\"synIdentifier\">[<\/span><span class=\"synConstant\">'sts:AssumeRole'<\/span><span class=\"synIdentifier\">]<\/span>  \n    <span class=\"synIdentifier\">}<\/span>)  \n)\n<\/pre>\n<h3 id=\"\u30ed\u30fc\u30eb2-Lambda\u81ea\u4f53\u306b\u4ed8\u4e0e\u3059\u308b\u30ed\u30fc\u30eb\">\u30ed\u30fc\u30eb2: Lambda\u81ea\u4f53\u306b\u4ed8\u4e0e\u3059\u308b\u30ed\u30fc\u30eb<\/h3>\n<p>Lambda\u304c\u547c\u3073\u51fa\u3055\u308c\u305f\u969b\u306b\u3001Lambda\u81ea\u8eab\u304c\u5b9f\u884c\u306b\u4f7f\u7528\u3059\u308b\u30ed\u30fc\u30eb\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002<br \/>\n\u96d1\u306b\u3044\u3046\u3068Lambda\u306e\u4f5c\u6210\u6642\u306b\u30ed\u30fc\u30eb\u3092\u6307\u5b9a\u3059\u308b\u304b\u3068\u601d\u3044\u307e\u3059\u304c\u3001\u305d\u308c\u3067\u3059\u3002<br \/>\n\u3053\u3044\u3064\u306f\u6b21\u3067\u4f5c\u308b\u300c\u30ed\u30fc\u30eb3:\u96c6\u8a08\u30b9\u30af\u30ea\u30d7\u30c8\u5185\u3067Assume\u3059\u308b\u7528\u30ed\u30fc\u30eb\u300d\u3092Assume\u3067\u304d\u308c\u3070\u305d\u308c\u3067\u3088\u3044\u306e\u3067\u3001\u975e\u5e38\u306b\u30b7\u30f3\u30d7\u30eb\u3067\u3059\u3002<\/p>\n<pre class=\"code lang-typescript\" data-lang=\"typescript\" data-unlink=\"\"><span class=\"synIdentifier\">const<\/span> role = <span class=\"synIdentifier\">new<\/span> Role(<span class=\"synType\">this<\/span>, <span class=\"synConstant\">'cost-check-role'<\/span>, <span class=\"synIdentifier\">{<\/span>  \n    <span class=\"synStatement\">roleName<\/span>: <span class=\"synConstant\">'cost-check-role'<\/span>,  \n    <span class=\"synStatement\">assumedBy<\/span>: <span class=\"synIdentifier\">new<\/span> ServicePrincipal(<span class=\"synConstant\">'lambda.amazonaws.com'<\/span>),  \n    <span class=\"synStatement\">managedPolicies<\/span>: <span class=\"synIdentifier\">[<\/span>\n        <span class=\"synIdentifier\">new<\/span> ManagedPolicy(<span class=\"synType\">this<\/span>, <span class=\"synConstant\">'lambda-worker-policy'<\/span>, <span class=\"synIdentifier\">{<\/span>\n            <span class=\"synStatement\">path<\/span>: <span class=\"synConstant\">'\/service-role\/'<\/span>,  \n            <span class=\"synStatement\">managedPolicyName<\/span>: <span class=\"synConstant\">'assumeCostCheckRole'<\/span>,  \n            <span class=\"synStatement\">statements<\/span>: <span class=\"synIdentifier\">[<\/span>  \n                <span class=\"synIdentifier\">new<\/span> PolicyStatement(<span class=\"synIdentifier\">{<\/span>  \n                    <span class=\"synStatement\">effect<\/span>: Effect.ALLOW,  \n                    <span class=\"synStatement\">actions<\/span>: <span class=\"synIdentifier\">[<\/span>\n                        <span class=\"synConstant\">'sts:AssumeRole'<\/span>\n                    <span class=\"synIdentifier\">]<\/span>,  \n                    <span class=\"synStatement\">resources<\/span>: <span class=\"synIdentifier\">[<\/span>  \n                        <span class=\"synConstant\">'arn:aws:iam::\u30a2\u30ab\u30a6\u30f3\u30c8B:role\/cost-check-role'<\/span>  \n                    <span class=\"synIdentifier\">]<\/span>,  \n                <span class=\"synIdentifier\">}<\/span>),  \n            <span class=\"synIdentifier\">]<\/span>,  \n        <span class=\"synIdentifier\">}<\/span>)\n});  \n<\/pre>\n<h3 id=\"\u30ed\u30fc\u30eb3-\u96c6\u8a08\u30b9\u30af\u30ea\u30d7\u30c8\u5185\u3067Assume\u3059\u308b\u7528\u30ed\u30fc\u30eb\">\u30ed\u30fc\u30eb3: \u96c6\u8a08\u30b9\u30af\u30ea\u30d7\u30c8\u5185\u3067Assume\u3059\u308b\u7528\u30ed\u30fc\u30eb<\/h3>\n<p>\u96c6\u8a08\u306e\u305f\u3081\u306e\u5404\u7a2e\u64cd\u4f5c\u306b\u5fc5\u8981\u306a\u6a29\u9650\u3092\u307e\u3068\u3081\u305f\u30ed\u30fc\u30eb\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002<br \/>\n\u96c6\u8a08\u30b9\u30af\u30ea\u30d7\u30c8\u5185\u3067\u3053\u306e\u30ed\u30fc\u30eb\u3092Assume\u3059\u308b\u3053\u3068\u3067\u5fc5\u8981\u306a\u6a29\u9650\u3092\u7372\u5f97\u3057\u3001Organizations\u3084\u5229\u7528\u6599\u91d1\u306e\u60c5\u5831\u3092\u53d6\u5f97\u3059\u308b\u3068\u3044\u3063\u305f\u64cd\u4f5c\u304c\u53ef\u80fd\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<pre class=\"code lang-typescript\" data-lang=\"typescript\" data-unlink=\"\"><span class=\"synIdentifier\">const<\/span> role = <span class=\"synIdentifier\">new<\/span> Role(<span class=\"synType\">this<\/span>, <span class=\"synConstant\">'cost-check-role'<\/span>, <span class=\"synIdentifier\">{<\/span>  \n    <span class=\"synStatement\">roleName<\/span>: <span class=\"synConstant\">'cost-check-role'<\/span>,  \n    <span class=\"synStatement\">assumedBy<\/span>: <span class=\"synIdentifier\">new<\/span> ServicePrincipal(<span class=\"synConstant\">'lambda.amazonaws.com'<\/span>),  \n    <span class=\"synStatement\">managedPolicies<\/span>: <span class=\"synIdentifier\">[<\/span>\n        <span class=\"synIdentifier\">new<\/span> ManagedPolicy(<span class=\"synType\">this<\/span>, <span class=\"synConstant\">'cost-check-policy'<\/span>, <span class=\"synIdentifier\">{<\/span>\n            <span class=\"synStatement\">path<\/span>: <span class=\"synConstant\">'\/service-role\/'<\/span>,  \n            <span class=\"synStatement\">managedPolicyName<\/span>: <span class=\"synConstant\">'CheckCost'<\/span>,  \n            <span class=\"synStatement\">statements<\/span>: <span class=\"synIdentifier\">[<\/span>  \n                <span class=\"synIdentifier\">new<\/span> PolicyStatement(<span class=\"synIdentifier\">{<\/span>  \n                    <span class=\"synStatement\">effect<\/span>: Effect.ALLOW,  \n                    <span class=\"synStatement\">actions<\/span>: <span class=\"synIdentifier\">[<\/span>\n                        <span class=\"synConstant\">'ce:GetCostAndUsage'<\/span>,  \n                        <span class=\"synConstant\">'ce:GetUsageReport'<\/span>,  \n                        <span class=\"synConstant\">'ce:ListCostCategoryDefinitions'<\/span>,  \n                        <span class=\"synConstant\">'organizations:ListParents'<\/span>,  \n                        <span class=\"synConstant\">'organizations:DescribeOrganizationalUnit'<\/span>,  \n                        <span class=\"synConstant\">'organizations:ListAccounts'<\/span>\n                    <span class=\"synIdentifier\">]<\/span>,  \n                    <span class=\"synStatement\">resources<\/span>: <span class=\"synIdentifier\">[<\/span>  \n                        <span class=\"synConstant\">'*'<\/span>\n                    <span class=\"synIdentifier\">]<\/span>,  \n                <span class=\"synIdentifier\">}<\/span>),  \n            <span class=\"synIdentifier\">]<\/span>,  \n        <span class=\"synIdentifier\">}<\/span>)\n});  \n\nrole.assumeRolePolicy?.addStatements(  \n    <span class=\"synIdentifier\">new<\/span> PolicyStatement(<span class=\"synIdentifier\">{<\/span>  \n        <span class=\"synStatement\">effect<\/span>: Effect.ALLOW,  \n        <span class=\"synStatement\">principals<\/span>: <span class=\"synIdentifier\">[<\/span>\n            <span class=\"synIdentifier\">new<\/span> ArnPrincipal(<span class=\"synConstant\">\"arn:aws:iam::\u30a2\u30ab\u30a6\u30f3\u30c8B:role\/lambda-worker-role\"<\/span>)  \n        <span class=\"synIdentifier\">]<\/span>,  \n        <span class=\"synStatement\">actions<\/span>: <span class=\"synIdentifier\">[<\/span><span class=\"synConstant\">'sts:AssumeRole'<\/span><span class=\"synIdentifier\">]<\/span>  \n    <span class=\"synIdentifier\">}<\/span>)  \n)\n<\/pre>\n<p>\u5bfe\u8c61\u30ea\u30bd\u30fc\u30b9\uff08managedPolicies -&gt; statements -&gt; resources\u306e\u5185\u5bb9\uff09\u304c <code>*<\/code> \u306b\u306a\u3063\u3066\u3044\u307e\u3059\u304c\u3001OrganizationsAPI\u3084CostExplorerAPI(ce)\u3067\u306f\u7d44\u7e54\u5168\u4f53\/\u30a2\u30ab\u30a6\u30f3\u30c8\u6a2a\u65ad\u306e\u60c5\u5831\u3092\u53d6\u5f97\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u3001\u30ea\u30bd\u30fc\u30b9\u5236\u9650\u3092\u304b\u3051\u308b\u306e\u306f\u73fe\u5b9f\u7684\u3067\u306f\u306a\u3044\u305f\u3081\u3067\u3059\u3002<\/p>\n<p>\u3082\u3057OrganizationalUnit\u304c\u4f55\u968e\u5c64\u304b\u306b\u306a\u3063\u3066\u304a\u308a\u3001\u305d\u306e\u89aa\u5b50\u95a2\u4fc2\u306a\u3069\u3082\u53d6\u5f97\u3057\u305f\u3044\u3088\u3046\u306a\u5834\u5408\u306f <code>managedPolicies<\/code> \u3067\u6307\u5b9a\u3057\u3066\u3044\u308b <code>statements<\/code> \u5185\u306e <code>actions<\/code> \u304c\u4e0d\u8db3\u3057\u3066\u3044\u308b\u306e\u3067\u3001\u8ffd\u52a0\u304c\u5fc5\u8981\u3067\u3059\u3002\u81ea\u74b0\u5883\u3067\u306f\u4e0d\u8981\u3060\u3063\u305f\u306e\u3067\u672a\u78ba\u8a8d\u3067\u3059\u304c\u3001\u304a\u305d\u3089\u304f\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u3082\u306e\u304c\u5fc5\u8981\u306b\u306a\u308a\u307e\u3059\u3002<br \/>\n&#8211; organizations:ListRoots<br \/>\n&#8211; organizations:ListChildren<br \/>\n&#8211; organizations:ListOrganizationalUnitsForParent<br \/>\n&#8211; organizations:DescribeAccount<\/p>\n<p>\u3061\u306a\u307f\u306b\u5c11\u3057\u3060\u3051\u4f8b\u793a\u3059\u308b\u3068\u3001\u3053\u306e\u30ed\u30fc\u30eb\u3092Assume\u3057\u3066OrganizationalUnit\u306e\u60c5\u5831\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308bPython\u30b3\u30fc\u30c9\u306f\u3053\u3093\u306a\u611f\u3058\u3002<\/p>\n<pre class=\"code lang-python\" data-lang=\"python\" data-unlink=\"\">sts_client = boto3.client(<span class=\"synConstant\">'sts'<\/span>)  \n  \nassumed_role = sts_client.assume_role(  \n    RoleArn=<span class=\"synConstant\">'arn:aws:iam::\u30a2\u30ab\u30a6\u30f3\u30c8B:role\/cost-check-role'<\/span>,  \n    RoleSessionName=<span class=\"synConstant\">'ou_read_session'<\/span>  \n)  \n  \nclient = boto3.client(  \n    <span class=\"synConstant\">'organizations'<\/span>,  \n    aws_access_key_id=assumed_role[<span class=\"synConstant\">'Credentials'<\/span>][<span class=\"synConstant\">'AccessKeyId'<\/span>],  \n    aws_secret_access_key=assumed_role[<span class=\"synConstant\">'Credentials'<\/span>][<span class=\"synConstant\">'SecretAccessKey'<\/span>],  \n    aws_session_token=assumed_role[<span class=\"synConstant\">'Credentials'<\/span>][<span class=\"synConstant\">'SessionToken'<\/span>]  \n)\n\nou_cache = {}  \n<span class=\"synStatement\">for<\/span> account_id <span class=\"synStatement\">in<\/span> LINKED_ACCOUNT.keys():  \n    \n    response = client.list_parents(ChildId=account_id)  \n    parent_id = response[<span class=\"synConstant\">'Parents'<\/span>][<span class=\"synConstant\">0<\/span>][<span class=\"synConstant\">'Id'<\/span>]  \n  \n    \n    ou_response = client.describe_organizational_unit(OrganizationalUnitId=parent_id)  \n    ou_cache[account_id] = ou_response[<span class=\"synConstant\">'OrganizationalUnit'<\/span>][<span class=\"synConstant\">'Name'<\/span>]\n<\/pre>\n<h3 id=\"\u30ed\u30b0\u30b0\u30eb\u30fc\u30d7\">\u30ed\u30b0\u30b0\u30eb\u30fc\u30d7<\/h3>\n<p>\u3053\u306e\u8a18\u4e8b\u306e\u8da3\u65e8\u7684\u306b\u306f\u3042\u307e\u308a\u91cd\u8981\u3067\u306f\u306a\u3044\u3067\u3059\u304c\u3001Lambda\u306e\u5b9f\u884c\u30ed\u30b0\u3092\u4fdd\u6301\u3055\u305b\u308b\u30ed\u30b0\u30b0\u30eb\u30fc\u30d7\u3092\u4f5c\u308a\u307e\u3059\u3002<\/p>\n<pre class=\"code lang-typescript\" data-lang=\"typescript\" data-unlink=\"\"><span class=\"synIdentifier\">new<\/span> LogGroup(<span class=\"synType\">this<\/span>, <span class=\"synConstant\">'cost-check-lambda-log-group'<\/span>, <span class=\"synIdentifier\">{<\/span>  \n    <span class=\"synStatement\">logGroupName<\/span>: <span class=\"synConstant\">'cost-check-lambda-log-group'<\/span>,  \n    <span class=\"synStatement\">retention<\/span>: RetentionDays.ONE_MONTH,  \n<span class=\"synIdentifier\">}<\/span>);\n<\/pre>\n<p>\u7279\u5225\u306a\u3053\u3068\u306f\u306a\u306b\u3082\u306a\u3044\u3067\u3059\u3002<\/p>\n<h3 id=\"Lambda\">Lambda<\/h3>\n<p>\u6700\u5f8c\u306b\u96c6\u8a08\u3092\u3055\u305b\u308bLambda\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002<\/p>\n<pre class=\"code lang-typescript\" data-lang=\"typescript\" data-unlink=\"\"><span class=\"synIdentifier\">const<\/span> func = <span class=\"synIdentifier\">new<\/span> PythonFunction(<span class=\"synType\">this<\/span>, <span class=\"synConstant\">'cost-check-lambda'<\/span>, <span class=\"synIdentifier\">{<\/span>  \n    <span class=\"synStatement\">functionName<\/span>: <span class=\"synConstant\">'cost-check-lambda'<\/span>,  \n    <span class=\"synStatement\">runtime<\/span>: Runtime.PYTHON_3_13,  \n    <span class=\"synStatement\">entry<\/span>: <span class=\"synConstant\">'src\/lambda\/cost'<\/span>,  \n    <span class=\"synStatement\">index<\/span>: <span class=\"synConstant\">'cost.py'<\/span>,  \n    <span class=\"synStatement\">handler<\/span>: <span class=\"synConstant\">'main'<\/span>,  \n    <span class=\"synStatement\">timeout<\/span>: Duration.minutes(<span class=\"synConstant\">3<\/span>),  \n    <span class=\"synStatement\">vpc<\/span>: Vpc.fromVpcAttributes( <span class=\"synType\">this<\/span>, <span class=\"synConstant\">'cost-check-lambda-vpc'<\/span>, <span class=\"synIdentifier\">{<\/span>  \n        <span class=\"synStatement\">availabilityZones<\/span>: <span class=\"synIdentifier\">[<\/span><span class=\"synConstant\">'ap-northeast-1c'<\/span>, <span class=\"synConstant\">'ap-northeast-1d'<\/span><span class=\"synIdentifier\">]<\/span>,  \n        <span class=\"synStatement\">vpcId<\/span>: <span class=\"synConstant\">'vpc-XXXXXXXXXXXXXXXXX'<\/span>,  \n    <span class=\"synIdentifier\">}<\/span>),  \n    <span class=\"synStatement\">vpcSubnets<\/span>: <span class=\"synIdentifier\">{<\/span>\n        <span class=\"synStatement\">subnets<\/span>: <span class=\"synIdentifier\">[<\/span>\n            Subnet.fromSubnetId(<span class=\"synType\">this<\/span>, <span class=\"synConstant\">'subnet1'<\/span>, <span class=\"synConstant\">'subnet-XXXXXXXXXXXXXXXXX'<\/span>),\n            Subnet.fromSubnetId(<span class=\"synType\">this<\/span>, <span class=\"synConstant\">'subnet2'<\/span>, <span class=\"synConstant\">'subnet-XXXXXXXXXXXXXXXXX'<\/span>)\n\n        <span class=\"synIdentifier\">]<\/span>,  \n    <span class=\"synIdentifier\">}<\/span>,  \n    <span class=\"synStatement\">role<\/span>: Role.fromRoleArn(<span class=\"synType\">this<\/span>, <span class=\"synConstant\">'lambda-worker-role'<\/span>, <span class=\"synConstant\">'arn:aws:iam::\u30a2\u30ab\u30a6\u30f3\u30c8B:role\/lambda-worker-role'<\/span>),  \n    <span class=\"synStatement\">logGroup<\/span>: LogGroup.fromLogGroupName(<span class=\"synType\">this<\/span>, <span class=\"synConstant\">'cost-check-lambda-log-group'<\/span>, <span class=\"synConstant\">'cost-check-lambda-log-group'<\/span>),  \n<span class=\"synIdentifier\">}<\/span>);  \n\nfunc.addPermission(<span class=\"synConstant\">'\u30a2\u30ab\u30a6\u30f3\u30c8A-permission'<\/span>, <span class=\"synIdentifier\">{<\/span>  \n            <span class=\"synStatement\">principal<\/span>: <span class=\"synIdentifier\">new<\/span> AccountPrincipal(<span class=\"synConstant\">'\u30a2\u30ab\u30a6\u30f3\u30c8A'<\/span>),  \n            <span class=\"synStatement\">action<\/span>: <span class=\"synConstant\">'lambda:InvokeFunction'<\/span>\n        <span class=\"synIdentifier\">}<\/span>)\n<\/pre>\n<h2 id=\"\u30c7\u30d7\u30ed\u30a4\u9806\u5e8f\u306b\u3064\u3044\u3066\">\u30c7\u30d7\u30ed\u30a4\u9806\u5e8f\u306b\u3064\u3044\u3066<\/h2>\n<p>\u5c11\u3057\u3060\u3051\u3084\u3084\u3053\u3057\u3044\u306e\u3067\u30c7\u30d7\u30ed\u30a4\u9806\u5e8f\u3092\u6574\u7406\u3059\u308b\u3068\u3001\u4e0b\u8a18\u306e\u3088\u3046\u306a\u9806\u5e8f\u3067\u4f5c\u696d\u3059\u308b\u3053\u3068\u306b\u306a\u308b\u3068\u601d\u3044\u307e\u3059\u3002<\/p>\n<ol>\n<li>\u30ed\u30fc\u30eb1: Lambda\u306e\u547c\u3073\u51fa\u3057\u7528\u30ed\u30fc\u30eb \u306e\u30c7\u30d7\u30ed\u30a4\n<ul>\n<li>\u672c\u6765Lambda\u306eArn\u3092\u6307\u5b9a\u3059\u308b\u7b87\u6240\u306f\u4e00\u6642\u7684\u306b <code>*<\/code> \u306a\u3069\u306b\u3057\u3066\u30c7\u30d7\u30ed\u30a4\u3059\u308b<\/li>\n<\/ul>\n<\/li>\n<li>\u30a2\u30ab\u30a6\u30f3\u30c8A\u5074\u306e\u30ed\u30fc\u30eb\u306b\u6a29\u9650\u8ffd\u52a0\n<ul>\n<li>1\u3067\u4f5c\u6210\u3057\u305f\u30ed\u30fc\u30eb\u306eArn\u3092\u6307\u5b9a\u3059\u308b<\/li>\n<\/ul>\n<\/li>\n<li>\u30ed\u30fc\u30eb2: Lambda\u81ea\u4f53\u306b\u4ed8\u4e0e\u3059\u308b\u30ed\u30fc\u30eb\u306e\u30c7\u30d7\u30ed\u30a4\n<ul>\n<li>\u672c\u6765\u30ed\u30fc\u30eb3\u306eArn\u3092\u6307\u5b9a\u3059\u308b\u7b87\u6240\u306f\u4e00\u6642\u7684\u306b\u306a\u3057\u7b49\u3067\u30c7\u30d7\u30ed\u30a4\u3059\u308b<\/li>\n<\/ul>\n<\/li>\n<li>\u30ed\u30fc\u30eb3: \u96c6\u8a08\u30b9\u30af\u30ea\u30d7\u30c8\u5185\u3067Assume\u3059\u308b\u7528\u30ed\u30fc\u30eb\n<ul>\n<li>3\u3067\u4f5c\u6210\u3057\u305f\u30ed\u30fc\u30eb\u306eArn\u3092\u6307\u5b9a\u3059\u308b<\/li>\n<\/ul>\n<\/li>\n<li>\u30ed\u30fc\u30eb2: Lambda\u81ea\u4f53\u306b\u4ed8\u4e0e\u3059\u308b\u30ed\u30fc\u30eb\u306e\u66f4\u65b0\n<ul>\n<li>4\u3067\u4f5c\u6210\u3057\u305f\u30ed\u30fc\u30eb\u306eArn\u3092\u6307\u5b9a\u3059\u308b<\/li>\n<\/ul>\n<\/li>\n<li>\u30ed\u30b0\u30b0\u30eb\u30fc\u30d7\u306e\u30c7\u30d7\u30ed\u30a4<\/li>\n<li>Lambda\u306e\u30c7\u30d7\u30ed\u30a4\n<ul>\n<li>3\u3067\u4f5c\u6210\u3057\u305f\u30ed\u30fc\u30eb\u3092\u6307\u5b9a\u3059\u308b<\/li>\n<li>6\u3067\u4f5c\u6210\u3057\u305f\u30ed\u30b0\u30b0\u30eb\u30fc\u30d7\u3092\u6307\u5b9a\u3059\u308b<\/li>\n<\/ul>\n<\/li>\n<li>\u30ed\u30fc\u30eb1: Lambda\u306e\u547c\u3073\u51fa\u3057\u7528\u30ed\u30fc\u30eb \u306e\u3000\u66f4\u65b0\n<ul>\n<li>7\u3067\u4f5c\u6210\u3057\u305fLambda\u306eArn\u3092\u6307\u5b9a\u3059\u308b<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p>\u4ee5\u4e0a\u3067\u300c\u30a2\u30ab\u30a6\u30f3\u30c8A\u306eEC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3067\u5185\u3067\u52d5\u304fRundeck\u304b\u3089\u3001\u30a2\u30ab\u30a6\u30f3\u30c8B\u306b\u3042\u308bLambda\u3092\u5b9f\u884c\u3057\u3001\u305d\u306eLambda\u306e\u4e2d\u3067OrganizationalUnit\u3054\u3068\u306bAWS\u306e\u5229\u7528\u6599\u91d1\u3092\u96c6\u8a08\u3059\u308b\u300d\u3068\u3044\u3046\u30b7\u30ca\u30ea\u30aa\u3067\u5fc5\u8981\u306a\u30ea\u30bd\u30fc\u30b9\u305f\u3061\u306f\u3059\u3079\u3066\u7528\u610f\u304c\u3067\u304d\u307e\u3057\u305f\u3002<\/p>\n<p>\u3042\u3068\u306fPython\u30b3\u30fc\u30c9\u5185\u3067 <a target=\"_blank\" href=\"https:\/\/boto3.amazonaws.com\/v1\/documentation\/api\/latest\/reference\/services\/sts\/client\/assume_role.html\">assume_role<\/a> \u3067\u30ed\u30fc\u30eb\u3092Assume\u3057\u3001 <a target=\"_blank\" href=\"https:\/\/boto3.amazonaws.com\/v1\/documentation\/api\/latest\/guide\/paginators.html\">get_paginator<\/a> \u3092\u4f7f\u3063\u3066\u30a2\u30ab\u30a6\u30f3\u30c8\u4e00\u89a7\u3092\u53d6\u5f97\u3001 <a target=\"_blank\" href=\"https:\/\/boto3.amazonaws.com\/v1\/documentation\/api\/latest\/reference\/services\/organizations\/client\/list_parents.html\">list_parents<\/a> \u3067\u89aa\u30a2\u30ab\u30a6\u30f3\u30c8\u306e\u53d6\u5f97\u3001<a target=\"_blank\" href=\"https:\/\/boto3.amazonaws.com\/v1\/documentation\/api\/latest\/reference\/services\/organizations\/client\/describe_organizational_unit.html\">describe_organizational_unit<\/a> \u3067OrganizationalUnit\u306e\u53d6\u5f97\u3001<a target=\"_blank\" href=\"https:\/\/boto3.amazonaws.com\/v1\/documentation\/api\/latest\/reference\/services\/ce\/client\/get_cost_and_usage.html\">get_cost_and_usage<\/a> \u3067\u5229\u7528\u6599\u91d1\u306e\u53d6\u5f97\u3001\u3068\u3044\u3046\u611f\u3058\u3067\u66f8\u3044\u3066\u3044\u3051\u3070OrganizationalUnit\u306e\u60c5\u5831\u306b\u57fa\u3065\u3044\u3066\u30a2\u30ab\u30a6\u30f3\u30c8\u3054\u3068\u306e\u5229\u7528\u6599\u91d1\u3092\u96c6\u8a08\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>\u6700\u5c0f\u9650\u306e\u539f\u5247\u3068\u3044\u3044\u307e\u3059\u304b\u3001\u300c\u5fc5\u8981\u306a\u3068\u3053\u308d\u306b\u5fc5\u8981\u306a\u3060\u3051\u300d\u306e\u65b9\u91dd\u3067IAM\u30ed\u30fc\u30eb\u30923\u3064\u306b\u5206\u3051\u305f\u3053\u3068\u306b\u3088\u308a\u3001\u3069\u3053\u306b\u306a\u3093\u306e\u6a29\u9650\u304c\u5fc5\u8981\u306a\u306e\u304b\u3092\u6574\u7406\u3057\u305f\u308a\u3001\u30c7\u30d7\u30ed\u30a4\u3059\u308b\u9806\u5e8f\u304c\u3084\u3084\u3053\u3057\u304f\u306a\u3063\u305f\u308a\u3057\u305f\u306e\u304c\u5730\u5473\u306a\u96e3\u822a\u30dd\u30a4\u30f3\u30c8\u3067\u3057\u305f\u3002<br \/>\n\u7279\u306b\u30c7\u30d7\u30ed\u30a4\u306e\u624b\u9806\u306b\u95a2\u3057\u3066\u306f\u3001\u6a29\u9650\u3092\u6700\u5c0f\u9650\u306b\u3059\u308b\u306b\u306f\u3069\u3046\u3057\u3066\u3082\u76f8\u4e92\u306b\u53c2\u7167\u3055\u305b\u308b\u5fc5\u8981\u304c\u751f\u3058\u308b\u305f\u3081\u8907\u96d1\u306b\u306a\u3063\u3066\u3057\u307e\u3044\u307e\u3057\u305f\u304c\u3001\u3053\u3053\u306f\u3084\u3080\u3092\u5f97\u306a\u3044\u3068\u3053\u308d\u304b\u306a\u3068\u601d\u3044\u307e\u3059\u3002<\/p>\n<p>\u3067\u306f\u3067\u306f\u304a\u75b2\u308c\u69d8\u3067\u3057\u305f\u2615<\/p>\n<\/div>\n<p><script>(function(d, s, id) {\n  var js, fjs = d.getElementsByTagName(s)[0];\n  if (d.getElementById(id)) return;\n  js = d.createElement(s); js.id = id;\n  js.src = \"\/\/connect.facebook.net\/ja_JP\/sdk.js#xfbml=1&appId=719729204785177&version=v17.0\";\n  fjs.parentNode.insertBefore(js, fjs);\n}(document, 'script', 'facebook-jssdk'));<\/script><br \/>\n<br \/>\n<br \/><a href=\"https:\/\/tech.furyu.jp\/entry\/202512020000\">\u5143\u306e\u8a18\u4e8b\u3092\u78ba\u8a8d\u3059\u308b <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"\u3053\u306e\u8a18\u4e8b\u306f \u30d5\u30ea\u30e5\u30fcAdvent Calendar 2025 \u306e2\u65e5\u76ee\u306e\u8a18\u4e8b\u3067\u3059\u3002 \u3053\u3093\u306b\u3061\u306f\u3001\u30d5\u30ea\u30e5\u30fc\u682a\u5f0f\u4f1a\u793e\u3067\u30d4\u30af\u30c8\u30ea\u30f3\u30af\u306e\u958b\u767a\u3092\u3057\u3066\u3044\u308b\u307e\u3055\u304a\u3067\u3059\ud83d\udc7b \u4eca\u65e5\u306fAWS\u30a2\u30ab\u30a6\u30f3\u30c8A\u306eEC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3067\u52d5\u3044\u3066\u3044\u308bRund [&hellip;]","protected":false},"author":1,"featured_media":26041,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[4],"tags":[],"class_list":["post-26040","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-company-tec"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>AWS\u3067OrganizationalUnit\u3054\u3068\u306b\u5229\u7528\u6599\u91d1\u3092\u96c6\u8a08\u3059\u308b\u74b0\u5883\u3092\u4f5c\u6210\u3057\u305f\u8a71 - FURYU Tech Blog - \u30dd\u30b1\u30b3\u30f3<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/tech.furyu.jp\/entry\/202512020000\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"AWS\u3067OrganizationalUnit\u3054\u3068\u306b\u5229\u7528\u6599\u91d1\u3092\u96c6\u8a08\u3059\u308b\u74b0\u5883\u3092\u4f5c\u6210\u3057\u305f\u8a71 - FURYU Tech Blog - \u30dd\u30b1\u30b3\u30f3\" \/>\n<meta property=\"og:description\" content=\"\u3053\u306e\u8a18\u4e8b\u306f \u30d5\u30ea\u30e5\u30fcAdvent Calendar 2025 \u306e2\u65e5\u76ee\u306e\u8a18\u4e8b\u3067\u3059\u3002 \u3053\u3093\u306b\u3061\u306f\u3001\u30d5\u30ea\u30e5\u30fc\u682a\u5f0f\u4f1a\u793e\u3067\u30d4\u30af\u30c8\u30ea\u30f3\u30af\u306e\u958b\u767a\u3092\u3057\u3066\u3044\u308b\u307e\u3055\u304a\u3067\u3059\ud83d\udc7b \u4eca\u65e5\u306fAWS\u30a2\u30ab\u30a6\u30f3\u30c8A\u306eEC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3067\u52d5\u3044\u3066\u3044\u308bRund [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/tech.furyu.jp\/entry\/202512020000\" \/>\n<meta property=\"og:site_name\" content=\"\u30dd\u30b1\u30b3\u30f3\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-01T19:02:23+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/pokecon.jp\/job\/wp-content\/uploads\/2025\/12\/https3A2F2Fcdn-ak.f.st-hatena.com2Fimages2Ffotolife2Ff2Ffuryu-tech2F202512022F2025120200003.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"1300\" \/>\n\t<meta property=\"og:image:height\" content=\"583\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"info@pokecon.jp\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u57f7\u7b46\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"info@pokecon.jp\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u63a8\u5b9a\u8aad\u307f\u53d6\u308a\u6642\u9593\" \/>\n\t<meta name=\"twitter:data2\" content=\"3\u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/tech.furyu.jp\\\/entry\\\/202512020000#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/26040\\\/\"},\"author\":{\"name\":\"info@pokecon.jp\",\"@id\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/#\\\/schema\\\/person\\\/16c9f07b1ba984d165d9aee259bda997\"},\"headline\":\"AWS\u3067OrganizationalUnit\u3054\u3068\u306b\u5229\u7528\u6599\u91d1\u3092\u96c6\u8a08\u3059\u308b\u74b0\u5883\u3092\u4f5c\u6210\u3057\u305f\u8a71 &#8211; FURYU Tech Blog\",\"datePublished\":\"2025-12-01T19:02:23+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/26040\\\/\"},\"wordCount\":119,\"image\":{\"@id\":\"https:\\\/\\\/tech.furyu.jp\\\/entry\\\/202512020000#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/https3A2F2Fcdn-ak.f.st-hatena.com2Fimages2Ffotolife2Ff2Ffuryu-tech2F202512022F2025120200003.jpeg\",\"articleSection\":[\"\u4f01\u696d\u30c6\u30c3\u30af\"],\"inLanguage\":\"ja\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/26040\\\/\",\"url\":\"https:\\\/\\\/tech.furyu.jp\\\/entry\\\/202512020000\",\"name\":\"AWS\u3067OrganizationalUnit\u3054\u3068\u306b\u5229\u7528\u6599\u91d1\u3092\u96c6\u8a08\u3059\u308b\u74b0\u5883\u3092\u4f5c\u6210\u3057\u305f\u8a71 - FURYU Tech Blog - \u30dd\u30b1\u30b3\u30f3\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/tech.furyu.jp\\\/entry\\\/202512020000#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/tech.furyu.jp\\\/entry\\\/202512020000#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/https3A2F2Fcdn-ak.f.st-hatena.com2Fimages2Ffotolife2Ff2Ffuryu-tech2F202512022F2025120200003.jpeg\",\"datePublished\":\"2025-12-01T19:02:23+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/#\\\/schema\\\/person\\\/16c9f07b1ba984d165d9aee259bda997\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/tech.furyu.jp\\\/entry\\\/202512020000#breadcrumb\"},\"inLanguage\":\"ja\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/tech.furyu.jp\\\/entry\\\/202512020000\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"ja\",\"@id\":\"https:\\\/\\\/tech.furyu.jp\\\/entry\\\/202512020000#primaryimage\",\"url\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/https3A2F2Fcdn-ak.f.st-hatena.com2Fimages2Ffotolife2Ff2Ffuryu-tech2F202512022F2025120200003.jpeg\",\"contentUrl\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/https3A2F2Fcdn-ak.f.st-hatena.com2Fimages2Ffotolife2Ff2Ffuryu-tech2F202512022F2025120200003.jpeg\",\"width\":1300,\"height\":583},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/tech.furyu.jp\\\/entry\\\/202512020000#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u30db\u30fc\u30e0\",\"item\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AWS\u3067OrganizationalUnit\u3054\u3068\u306b\u5229\u7528\u6599\u91d1\u3092\u96c6\u8a08\u3059\u308b\u74b0\u5883\u3092\u4f5c\u6210\u3057\u305f\u8a71 &#8211; FURYU Tech Blog\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/#website\",\"url\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/\",\"name\":\"\u30dd\u30b1\u30b3\u30f3\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"ja\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/#\\\/schema\\\/person\\\/16c9f07b1ba984d165d9aee259bda997\",\"name\":\"info@pokecon.jp\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"ja\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2b0549cd9f7907c092ca5fbb283baf72337f235726e4b46fa39ec0b701ac2fe2?s=96&d=wavatar&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2b0549cd9f7907c092ca5fbb283baf72337f235726e4b46fa39ec0b701ac2fe2?s=96&d=wavatar&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2b0549cd9f7907c092ca5fbb283baf72337f235726e4b46fa39ec0b701ac2fe2?s=96&d=wavatar&r=g\",\"caption\":\"info@pokecon.jp\"},\"url\":\"https:\\\/\\\/pokecon.jp\\\/job\\\/author\\\/infopokecon-jp\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"AWS\u3067OrganizationalUnit\u3054\u3068\u306b\u5229\u7528\u6599\u91d1\u3092\u96c6\u8a08\u3059\u308b\u74b0\u5883\u3092\u4f5c\u6210\u3057\u305f\u8a71 - FURYU Tech Blog - \u30dd\u30b1\u30b3\u30f3","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/tech.furyu.jp\/entry\/202512020000","og_locale":"ja_JP","og_type":"article","og_title":"AWS\u3067OrganizationalUnit\u3054\u3068\u306b\u5229\u7528\u6599\u91d1\u3092\u96c6\u8a08\u3059\u308b\u74b0\u5883\u3092\u4f5c\u6210\u3057\u305f\u8a71 - FURYU Tech Blog - \u30dd\u30b1\u30b3\u30f3","og_description":"\u3053\u306e\u8a18\u4e8b\u306f \u30d5\u30ea\u30e5\u30fcAdvent Calendar 2025 \u306e2\u65e5\u76ee\u306e\u8a18\u4e8b\u3067\u3059\u3002 \u3053\u3093\u306b\u3061\u306f\u3001\u30d5\u30ea\u30e5\u30fc\u682a\u5f0f\u4f1a\u793e\u3067\u30d4\u30af\u30c8\u30ea\u30f3\u30af\u306e\u958b\u767a\u3092\u3057\u3066\u3044\u308b\u307e\u3055\u304a\u3067\u3059\ud83d\udc7b \u4eca\u65e5\u306fAWS\u30a2\u30ab\u30a6\u30f3\u30c8A\u306eEC2\u30a4\u30f3\u30b9\u30bf\u30f3\u30b9\u3067\u52d5\u3044\u3066\u3044\u308bRund [&hellip;]","og_url":"https:\/\/tech.furyu.jp\/entry\/202512020000","og_site_name":"\u30dd\u30b1\u30b3\u30f3","article_published_time":"2025-12-01T19:02:23+00:00","og_image":[{"width":1300,"height":583,"url":"https:\/\/pokecon.jp\/job\/wp-content\/uploads\/2025\/12\/https3A2F2Fcdn-ak.f.st-hatena.com2Fimages2Ffotolife2Ff2Ffuryu-tech2F202512022F2025120200003.jpeg","type":"image\/jpeg"}],"author":"info@pokecon.jp","twitter_card":"summary_large_image","twitter_misc":{"\u57f7\u7b46\u8005":"info@pokecon.jp","\u63a8\u5b9a\u8aad\u307f\u53d6\u308a\u6642\u9593":"3\u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/tech.furyu.jp\/entry\/202512020000#article","isPartOf":{"@id":"https:\/\/pokecon.jp\/job\/26040\/"},"author":{"name":"info@pokecon.jp","@id":"https:\/\/pokecon.jp\/job\/#\/schema\/person\/16c9f07b1ba984d165d9aee259bda997"},"headline":"AWS\u3067OrganizationalUnit\u3054\u3068\u306b\u5229\u7528\u6599\u91d1\u3092\u96c6\u8a08\u3059\u308b\u74b0\u5883\u3092\u4f5c\u6210\u3057\u305f\u8a71 &#8211; FURYU Tech Blog","datePublished":"2025-12-01T19:02:23+00:00","mainEntityOfPage":{"@id":"https:\/\/pokecon.jp\/job\/26040\/"},"wordCount":119,"image":{"@id":"https:\/\/tech.furyu.jp\/entry\/202512020000#primaryimage"},"thumbnailUrl":"https:\/\/pokecon.jp\/job\/wp-content\/uploads\/2025\/12\/https3A2F2Fcdn-ak.f.st-hatena.com2Fimages2Ffotolife2Ff2Ffuryu-tech2F202512022F2025120200003.jpeg","articleSection":["\u4f01\u696d\u30c6\u30c3\u30af"],"inLanguage":"ja"},{"@type":"WebPage","@id":"https:\/\/pokecon.jp\/job\/26040\/","url":"https:\/\/tech.furyu.jp\/entry\/202512020000","name":"AWS\u3067OrganizationalUnit\u3054\u3068\u306b\u5229\u7528\u6599\u91d1\u3092\u96c6\u8a08\u3059\u308b\u74b0\u5883\u3092\u4f5c\u6210\u3057\u305f\u8a71 - FURYU Tech Blog - \u30dd\u30b1\u30b3\u30f3","isPartOf":{"@id":"https:\/\/pokecon.jp\/job\/#website"},"primaryImageOfPage":{"@id":"https:\/\/tech.furyu.jp\/entry\/202512020000#primaryimage"},"image":{"@id":"https:\/\/tech.furyu.jp\/entry\/202512020000#primaryimage"},"thumbnailUrl":"https:\/\/pokecon.jp\/job\/wp-content\/uploads\/2025\/12\/https3A2F2Fcdn-ak.f.st-hatena.com2Fimages2Ffotolife2Ff2Ffuryu-tech2F202512022F2025120200003.jpeg","datePublished":"2025-12-01T19:02:23+00:00","author":{"@id":"https:\/\/pokecon.jp\/job\/#\/schema\/person\/16c9f07b1ba984d165d9aee259bda997"},"breadcrumb":{"@id":"https:\/\/tech.furyu.jp\/entry\/202512020000#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/tech.furyu.jp\/entry\/202512020000"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/tech.furyu.jp\/entry\/202512020000#primaryimage","url":"https:\/\/pokecon.jp\/job\/wp-content\/uploads\/2025\/12\/https3A2F2Fcdn-ak.f.st-hatena.com2Fimages2Ffotolife2Ff2Ffuryu-tech2F202512022F2025120200003.jpeg","contentUrl":"https:\/\/pokecon.jp\/job\/wp-content\/uploads\/2025\/12\/https3A2F2Fcdn-ak.f.st-hatena.com2Fimages2Ffotolife2Ff2Ffuryu-tech2F202512022F2025120200003.jpeg","width":1300,"height":583},{"@type":"BreadcrumbList","@id":"https:\/\/tech.furyu.jp\/entry\/202512020000#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u30db\u30fc\u30e0","item":"https:\/\/pokecon.jp\/job\/"},{"@type":"ListItem","position":2,"name":"AWS\u3067OrganizationalUnit\u3054\u3068\u306b\u5229\u7528\u6599\u91d1\u3092\u96c6\u8a08\u3059\u308b\u74b0\u5883\u3092\u4f5c\u6210\u3057\u305f\u8a71 &#8211; FURYU Tech Blog"}]},{"@type":"WebSite","@id":"https:\/\/pokecon.jp\/job\/#website","url":"https:\/\/pokecon.jp\/job\/","name":"\u30dd\u30b1\u30b3\u30f3","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/pokecon.jp\/job\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/pokecon.jp\/job\/#\/schema\/person\/16c9f07b1ba984d165d9aee259bda997","name":"info@pokecon.jp","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/secure.gravatar.com\/avatar\/2b0549cd9f7907c092ca5fbb283baf72337f235726e4b46fa39ec0b701ac2fe2?s=96&d=wavatar&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/2b0549cd9f7907c092ca5fbb283baf72337f235726e4b46fa39ec0b701ac2fe2?s=96&d=wavatar&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/2b0549cd9f7907c092ca5fbb283baf72337f235726e4b46fa39ec0b701ac2fe2?s=96&d=wavatar&r=g","caption":"info@pokecon.jp"},"url":"https:\/\/pokecon.jp\/job\/author\/infopokecon-jp\/"}]}},"_links":{"self":[{"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/posts\/26040","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/comments?post=26040"}],"version-history":[{"count":1,"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/posts\/26040\/revisions"}],"predecessor-version":[{"id":26042,"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/posts\/26040\/revisions\/26042"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/media\/26041"}],"wp:attachment":[{"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/media?parent=26040"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/categories?post=26040"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pokecon.jp\/job\/wp-json\/wp\/v2\/tags?post=26040"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}