{"id":1460,"date":"2018-12-25T20:39:26","date_gmt":"2018-12-25T11:39:26","guid":{"rendered":"https:\/\/www.rocher.kyoto.jp\/arbr\/?p=1460"},"modified":"2019-01-18T23:11:01","modified_gmt":"2019-01-18T14:11:01","slug":"lambda%e3%81%a8route53%e3%82%92%e4%bd%bf%e3%81%a3%e3%81%a6ddns%e6%a9%9f%e8%83%bd%e3%82%92%e4%bd%9c%e3%81%a3%e3%81%9f","status":"publish","type":"post","link":"https:\/\/www.rocher.kyoto.jp\/arbr\/?p=1460","title":{"rendered":"lambda\u3068Route53\u3092\u4f7f\u3063\u3066DDNS\u6a5f\u80fd\u3092\u4f5c\u3063\u305f"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">\u6982\u8981<\/h2>\n\n\n\n<p>\u56fa\u5b9aIP\u3092\u632f\u3063\u3066\u3044\u306a\u3044\u5e97\u7528\u306blambda\u3068Route53\u3092\u4f7f\u3063\u3066DDNS\u6a5f\u80fd\u3092\u4f5c\u3063\u305f<br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u80cc\u666f<\/h2>\n\n\n\n<p>\u3053\u306e\u9593\u3001<a href=\"https:\/\/www.rocher.kyoto.jp\/arbr\/?p=1455\">\u5e97\u306e\u547c\u3073\u51fa\u3057\u30d6\u30b6\u30fc<\/a>\u3092\u4f5c\u3063\u305f\u3051\u3069\u6b7b\u6d3b\u76e3\u8996\u3092\u3057\u3066\u3044\u306a\u3044\u3002zabbix\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u3092\u5165\u308c\u3088\u3046\u3068\u3057\u305f\u3051\u3069\u5e97\u306b\u306f\u56fa\u5b9aIP\u304c\u6765\u3066\u3044\u306a\u3044\u306e\u3067DDNS\u306a\u308a(VPN\u3092\u8cbc\u308b\u306a\u308a)\u3057\u306a\u3044\u3068\u3044\u3051\u306a\u3044\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u30b7\u30b9\u30c6\u30e0<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">\u74b0\u5883<\/h3>\n\n\n\n<ul class=\"wp-block-list\"><li>python3.7.0<\/li><li>raspbian9.4<\/li><li>Raspberry Pi B+<\/li><li>API Gateway<\/li><li>Lambda<\/li><li>Route53<\/li><\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u30b7\u30b9\u30c6\u30e0\u6982\u8981<\/h3>\n\n\n\n<p>\u5e97\u306e\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u5185\u306b\u3042\u308b\u30e9\u30ba\u30d1\u30a4\u304b\u3089API Gateway\u7d4c\u7531\u3067Lambda\u3092\u547c\u51fa\u3002<\/p>\n\n\n\n<p>\u547c\u3073\u51fa\u3055\u308c\u305fLambda\u3067\u547c\u3073\u51fa\u3057\u5143(\u30e9\u30ba\u30d1\u30a4)\u306e\u30b0\u30ed\u30fc\u30d0\u30ebIP\u3092\u53d6\u5f97\u3002<\/p>\n\n\n\n<p>\u4eca\u56de\u306e\u30b0\u30ed\u30fc\u30d0\u30ebIP\u304c\u524d\u56de\u306e\u30b0\u30ed\u30fc\u30d0\u30ebIP\u3068\u9055\u3063\u305f\u3089Lambda\u5185\u3067boto\u3092\u4f7f\u3063\u3066Route53\u306e\u30ec\u30b3\u30fc\u30c9\u3092\u5909\u66f4<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">lambda\u306e\u30bd\u30fc\u30b9<br><\/h3>\n\n\n\n<p>\u30dd\u30f3\u7f6e\u304d\u306e\u30e9\u30ba\u30d1\u30a4\u304b\u3089\u8d77\u52d5\u3057\u3066\u3044\u308b\u306e\u3067\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u7684\u306b\u4e0d\u5b89\u3002\u306a\u306e\u3067\u3001\u5bfe\u8c61\u30b5\u30fc\u30d0\u3068\u304bzoneId\u306f\u5f15\u6570\u3067\u306a\u304flambda\u5074\u3067\u6301\u3063\u3066\u3044\u308b\u3002<br>\u5bfe\u8c61\u306eA\u30ec\u30b3\u30fc\u30c9\u306a\u304b\u3063\u305f\u308a\u3057\u305f\u3089\u52d5\u304b\u306a\u3044\u3051\u3069\u30ed\u30b0\u898b\u305f\u3089\u306a\u3093\u3068\u304b\u306a\u308b\u306f\u305a\u3002<br><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>import boto3\nimport logging\n\nlogger = logging.getLogger()\nlogger.setLevel(logging.INFO)\n\ndef lambda_handler(event, context):\n        ZONE_ID = 'Route53\u306eHosted Zone ID'\n        logger.debug('call lambda')\n        source_ip = event['source_ip']\n        original_ip = event['original_ip']\n\n        logger.debug( 'source_ip -> ' + source_ip)\n        logger.debug( 'original_ip -> ' + original_ip)\n\n\n        if original_ip == '' or original_ip != source_ip:\n            logger.info('original_ip != source_ip')\n            logger.info( 'source_ip -> ' + source_ip)\n            logger.info( 'original_ip -> ' + original_ip)\n            client = boto3.client('route53')\n\n            try:\n                response = client.list_resource_record_sets(HostedZoneId=ZONE_ID)\n                target = [item for item in response['ResourceRecordSets'] if item['Name'] == 'hogehoge.epea.co.jp.' and item['Type'] == 'A'][0]\n                logger.info(target)\n\n                setting_ip = target['ResourceRecords'][0]['Value']\n\n                if setting_ip != source_ip:\n                    logger.info('modify start')\n                    target['ResourceRecords'][0]['Value'] = source_ip\n\n                    client.change_resource_record_sets(\n                        HostedZoneId = ZONE_ID,\n                        ChangeBatch = {\n                            'Comment': '\u591a\u5206IP\u304b\u308f\u3063\u305f',\n                            'Changes': [{\n                                'Action': 'UPSERT',\n                                'ResourceRecordSet':target\n                                }]\n                            }\n                    )\n                    logger.info('modify finish')\n            except Exception as e:\n                logger.error('KOKODESUKOKODESU')\n                import traceback\n                traceback.print_exc()\n                raise Exception(\"Check CloudWatch\")\n        return {\n            'statusCode': 200,\n            'body': source_ip\n        }\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u5168\u4f53\u306e\u547c\u3073\u51fa\u3057\u5143<br><\/h3>\n\n\n\n<p>Loop\u3057\u306a\u304c\u3089\u547c\u3073\u51fa\u3057\u7d9a\u3051\u308b\u306e\u307f\u3002<br><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#!\/usr\/bin\/env python3\n# coding: utf-8\nimport json\nimport logging\nimport time\nimport os\nimport signal\nimport sys\n\nimport requests\n\ndef invoker(originalip):\n    logger.debug('invocker start')\n    logger.debug( 'original_ip -> ' + original_ip)\n\n    headers = {'Content-Type' : 'application\/json','x-api-key': ddns_token}\n    payload = {'original_ip': original_ip}\n    res = requests.post('https:\/\/hogehoge.execute-api.ap-northeast-1.amazonaws.com\/default\/ddns'\n        , data=json.dumps(payload)\n        , headers=headers)\n    if res.status_code != 200:\n        print(res.text)\n        print(res.status_code)\n        raise Exception(\"TODO\")\n\n    logger.debug('res body ' + res.json()['body'])\n    logger.debug('invocker finish')\n    return res.json()['body']\n\ndef handler(signal, frame):\n    logger.info('invocker stop')\n    sys.exit(0)\n\nsignal.signal(signal.SIGINT, handler)\nsignal.signal(signal.SIGTERM, handler)\n\ntry:\n    formatter = '%(levelname)s : %(asctime)s : %(message)s'\n    logging.basicConfig(level = logging.INFO, filename = 'ddns.log', format=formatter)\nexcept:\n    print >> sys.stderr, 'error: could not open log file'\n    sys.exit(1)\nlogger = logging.getLogger(__name__)\nlogger.setLevel(logging.INFO)\n\nddns_token = os.environ['DDNS_TOKEN']\noriginal_ip = ''\nlogger.info('invocker start')\nlogger.debug('ddns_token ->[' + ddns_token + ']')\nwhile True:\n    logger.debug('in main loop')\n    original_ip = invoker(original_ip)\n    time.sleep(900)\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u6a29\u9650<br><\/h3>\n\n\n\n<p>\u30e9\u30e0\u30c0\u4f5c\u3063\u305f\u6642\u306b\u4f5c\u3089\u308c\u308b\u6a29\u9650\u306e\u4ed6\u306bRoute53\u306e\u30ec\u30b3\u30fc\u30c9\u53c2\u7167\/\u64cd\u4f5c\u6a29\u9650\u3092\u4ed8\u4e0e<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>{\n    \"Version\": \"2012-10-17\",\n    \"Statement\": [\n        {\n            \"Sid\": \"VisualEditor0\",\n            \"Effect\": \"Allow\",\n            \"Action\": [\n                \"route53:ChangeResourceRecordSets\",\n                \"route53:ListResourceRecordSets\"\n            ],\n            \"Resource\": [\n                \"arn:aws:route53:::change\/hostedzone\/Route53\u306eHosted Zone ID\",\n                \"arn:aws:route53:::hostedzone\/Route53\u306eHosted Zone ID\"\n            ]\n        }\n    ]\n}<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">API Gateway\u306e\u8a2d\u5b9a<\/h3>\n\n\n\n<p>\u30ea\u30af\u30a8\u30b9\u30c8\u306e\u30de\u30c3\u30d4\u30f3\u30b0<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#set ($body = $util.parseJson($input.json('$')))\n{\n   \"original_ip\" : \"$body.original_ip\",\n   \"source_ip\" : \"$context.identity.sourceIp\"    \n}\n<\/code><\/pre>\n\n\n\n<p>\u30a8\u30e9\u30fc\u6642\u306e\u30de\u30c3\u30d4\u30f3\u30b0<\/p>\n\n\n\n<p>\u6b63\u898f\u8868\u73fe\uff08\u3067\u306a\u304f\u305d\u306e\u307e\u307e\u3060\u3051\u3069\uff09 &#8220;Check CloudWatch&#8221;\u3067\u30e1\u30bd\u30c3\u30c9\u30ec\u30b9\u30dd\u30f3\u30b9\u306e\u30b9\u30c6\u30fc\u30bf\u30b9\u3092500\u306b\u6307\u5b9a<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">systemd<\/h3>\n\n\n\n<p>\u7279\u306b\u30b3\u30e1\u30f3\u30c8\u306a\u3057<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>[Unit]\nDescription=DDNS Daemon\n\n[Service]\nEnvironmentFile=\/home\/pi\/.config\/environment.d\/ddns.conf\nWorkingDirectory=\/home\/pi\/develop\/ddns\/\nExecStart=\/home\/pi\/develop\/ddns\/invoke_ddns.py\nExecStop=\/bin\/kill ${MAINPID}\nRestart=always\nType=simple\nUser=pi\nGroup=pi\n\n[Install]\nWantedBy=multi-user.target\n<\/code><\/pre>\n\n\n\n<p>\u305d\u308c\u306f\u305d\u3046\u3068<a href=\"http:\/\/bouldering-log.com\/?post_type=kansai&amp;p=2417\">\u30dc\u30eb\u30ed\u30b0<\/a>\u306b\u5e97\u306e\u60c5\u5831\u306e\u305b\u3066\u3082\u3089\u3063\u305f\u3051\u3069\u4eca\u306f\u307b\u3068\u3093\u3069\u66f4\u65b0\u3055\u308c\u3066\u306a\u3044\u306e\u306d\u3002\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 \u56fa\u5b9aIP\u3092\u632f\u3063\u3066\u3044\u306a\u3044\u5e97\u7528\u306blambda\u3068Route53\u3092\u4f7f\u3063\u3066DDNS\u6a5f\u80fd\u3092\u4f5c\u3063\u305f \u80cc\u666f \u3053\u306e\u9593\u3001\u5e97\u306e\u547c\u3073\u51fa\u3057\u30d6\u30b6\u30fc\u3092\u4f5c\u3063\u305f\u3051\u3069\u6b7b\u6d3b\u76e3\u8996\u3092\u3057\u3066\u3044\u306a\u3044\u3002zabbix\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\u3092\u5165\u308c\u3088\u3046\u3068\u3057\u305f\u3051\u3069\u5e97\u306b\u306f\u56fa\u5b9aIP\u304c\u6765 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[114,113,100],"tags":[],"class_list":["post-1460","post","type-post","status-publish","format-standard","hentry","category-aws","category-python","category-raspberrypi"],"_links":{"self":[{"href":"https:\/\/www.rocher.kyoto.jp\/arbr\/index.php?rest_route=\/wp\/v2\/posts\/1460","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rocher.kyoto.jp\/arbr\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rocher.kyoto.jp\/arbr\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rocher.kyoto.jp\/arbr\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rocher.kyoto.jp\/arbr\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1460"}],"version-history":[{"count":3,"href":"https:\/\/www.rocher.kyoto.jp\/arbr\/index.php?rest_route=\/wp\/v2\/posts\/1460\/revisions"}],"predecessor-version":[{"id":1467,"href":"https:\/\/www.rocher.kyoto.jp\/arbr\/index.php?rest_route=\/wp\/v2\/posts\/1460\/revisions\/1467"}],"wp:attachment":[{"href":"https:\/\/www.rocher.kyoto.jp\/arbr\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1460"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rocher.kyoto.jp\/arbr\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1460"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rocher.kyoto.jp\/arbr\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1460"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}