2024 庆尚北道第59届全国技能竞赛评分标准
1. 评分注意事项
职种名称
云计算
※ 评分时请注意以下事项。
1) AWS 区域使用 us-east-1。
2) 网页访问使用 Chrome 或 Firefox。
3) 在网页中,根据语言不同,显示文案可能不同。
4) shell 中命令的输出可能因版本不同而略有差异。
5) 试题和评分表中的 <> 是变量。请更改相应部分后输入。
6) 必须按题目顺序进行评分。
7) 已删除的评分资料无法恢复,请谨慎操作;在异议申请全部完成之后,删除选手创建的云资源。
8) 有部分分数的题目,其评分项中已写明部分分数。
9) 未单独设置部分分数的题目,必须全部正确才计分。
10) 读取资源信息的评分项,原则上通过脚本结果进行评分;如果选手有异议,可以直接输入命令进行确认。
11) (预期输出)表示紧邻其前的(命令输入)的预期输出。
12) 评分时,可以运行另行提供的评分脚本(wsc.sh)进行评分。但是,如果选手希望直接输入,可以按照评分标准表中列出的命令原样输入进行评分。评分脚本应指定在 root 路径下。
13) 分发的评分脚本(wsc.sh)应放置在 ec2-user 的顶级路径下。
14) 所有评分事项均在通过 ssh 连接到 wsc2024-bastion-ec2 后进行。
云计算 第1任务 评分标准 27 - 1
2. 评分标准表
1) 主要项目分值
| 任务 | 序号 | 主要项目 | 分值 | 独立 | 合议 | 比赛进行中 | 比赛结束后 | 备注 |
|---|---|---|---|---|---|---|---|---|
| 第1任务 | 1 | Network Configuration | 3.85 | ○ | | ○ | | |
| | 2 | Transit Between VPC | 0.35 | ○ | | ○ | | |
| | 3 | Bastion Server | 0.70 | ○ | | ○ | | |
| | 4 | Application Access Control | 3.15 | ○ | | ○ | | |
| | 5 | RDBMS | 0.70 | ○ | | ○ | | |
| | 6 | NoSQL | 0.35 | ○ | | ○ | | |
| | 7 | Container Registry | 0.35 | ○ | | ○ | | |
| | 8 | Container Orchestartion | 1.75 | ○ | | ○ | | |
| | 9 | Load Balancer | 1.40 | ○ | | ○ | | |
| | 10 | Static Page | 1.05 | ○ | | ○ | | |
| | 11 | CDN | 7.35 | ○ | | ○ | | |
| | 12 | DNS Security | 3.0 | ○ | | ○ | | |
| | 13 | CDN Security | 3.0 | ○ | | ○ | | |
| | 14 | K8S Security | 3.0 | ○ | | ○ | | |
| | 合计 | | 30 | | | | | |
云计算 第1任务 评分标准 27 - 2
2) 评分方法及标准
| 任务 | 主要项目序号 | 主要项目 | 细项序号 | 细项(评分方法) | 分值 |
|---|---|---|---|---|---|
| 第1任务 | 1 | Network Configuration | 1 | VPC | 0.35 |
| | | | 2 | Subnet | 0.35 |
| | | | 3 | Routing Table | 0.35 |
| | | | 4 | Flow Logs | 0.35 |
| | | | 5 | VPC Endpoint | 0.35 |
| | | | 6 | Endpoint Preparation Process | 1.05 |
| | | | 7 | Bastion Access to ECR | 1.05 |
| | 2 | Transit Between VPC | 1 | Transit Gateway Configure | 0.35 |
| | 3 | Bastion Server | 1 | Bastion Configure | 0.35 |
| | | | 2 | Bastion Security | 0.35 |
| | 4 | Application Access Control | 1 | VPC Lattice Configure | 1.05 |
| | | | 2 | Healthcheck | 1.05 |
| | | | 3 | Healthcheck Access | 1.05 |
| | 5 | RDBMS | 1 | RDS Configure | 0.35 |
| | | | 2 | DB RollBack | 0.35 |
| | 6 | NoSQL | 1 | Table Configure | 0.35 |
| | 7 | Container Registry | 1 | ECR Configure | 0.35 |
| | 8 | Container Orchestartion | 1 | EKS Configure | 0.35 |
| | | | 2 | EKS KMS Encryption | 0.35 |
| | | | 3 | DB Application Node Configure | 0.35 |
| | | | 4 | Other Application Node Configure | 0.35 |
| | | | 5 | Application Pods | 0.35 |
| | 9 | Ingress | 1 | ALB Configure | 0.35 |
| | | | 2 | Customer API Test | 0.35 |
| | | | 3 | Order API Test | 0.35 |
| | | | 4 | Order API Test | 0.35 |
| | 10 | Static Page | 1 | S3 Bucket Configure | 0.35 |
| | | | 2 | S3 Objects | 0.35 |
| | | | 3 | S3 Access | 0.35 |
| | 11 | CDN | 1 | CloudFront Configure | 1.05 |
| | | | 2 | Redirect HTTPS | 1.05 |
| | | | 3 | Static Page Test | 1.05 |
| | | | 4 | S3 Caching | 1.05 |
| | | | 5 | Customer API Test | 1.05 |
| | | | 6 | Product API Test | 1.05 |
| | | | 7 | Order API Test | 1.05 |
| | 12 | DNS Security | 1 | Public 创建 | 0.5 |
| | | | 2 | 外部访问 | 1.0 |
| | | | 3 | 内部访问 | 1.5 |
| | 13 | CDN Security | 1 | DNS Lookup | 0.5 |
| | | | 2 | AWS Certificate Management | 1.5 |
| | | | 3 | curl https | 1.0 |
| | 14 | K8S Security | 1 | latest tag | 1.5 |
| | | | 2 | prod label 部署 | 0.75 |
| | | | 3 | beta label 部署 | 0.75 |
| | 总分 | | | | 30 |
云计算 第1任务 评分标准 27 - 3
云计算 第1任务 评分标准 27 - 4
3) 评分内容
序号
前期准备
1) 通过 SSH 访问 wsc2024-bastion-ec2 服务器。
2) 执行 rm –rf ~/.aws。
0
3) 输入 aws configure,并将 default.region 设置为 us-east-1。
上述操作完成后,将输出“前期准备完成!开始评分!”字样。
序号
评分项
1-1-A
(命令输入)
```bash
aws ec2 describe-vpcs --filter Name=tag:Name,Values=wsc2024-ma-vpc --query "Vpcs[0].CidrBlock" \
; aws ec2 describe-vpcs --filter Name=tag:Name,Values=wsc2024-prod-vpc --query "Vpcs[0].CidrBlock" \
; aws ec2 describe-vpcs --filter Name=tag:Name,Values=wsc2024-storage-vpc --query "Vpcs[0].CidrBlock"
```
1-1
1-1-A
(预期输出)
```text
"10.0.0.0/16"
"172.16.0.0/16"
"192.168.0.0/16"
```
完全匹配
顺序重要
云计算 第1任务 评分标准 27 - 5
序号
评分项
aws ec2 describe-subnets --filter
Name=tag:Name,Values=wsc2024-ma-mgmt-sn-a --query "Subnets[0].CidrBlock"
\
; aws ec2 describe-subnets --filter
Name=tag:Name,Values=wsc2024-ma-mgmt-sn-b --query "Subnets[0].CidrBlock"
\
; aws ec2 describe-subnets --filter
Name=tag:Name,Values=wsc2024-prod-load-sn-a --query "Subnets[0].CidrBlock"
\
; aws ec2 describe-subnets --filter
Name=tag:Name,Values=wsc2024-prod-load-sn-b --query "Subnets[0].CidrBlock"
1-2-A
(命令输入)
\
; aws ec2 describe-subnets --filter
Name=tag:Name,Values=wsc2024-prod-app-sn-a --query "Subnets[0].CidrBlock"
\
; aws ec2 describe-subnets --filter
1-2
Name=tag:Name,Values=wsc2024-prod-app-sn-b --query "Subnets[0].CidrBlock"
\
; aws ec2 describe-subnets --filter
Name=tag:Name,Values=wsc2024-storage-db-sn-a --query
"Subnets[0].CidrBlock" \
; aws ec2 describe-subnets --filter
Name=tag:Name,Values=wsc2024-storage-db-sn-b --query
"Subnets[0].CidrBlock"
"10.0.0.0/24"
"10.0.1.0/24"
1-2-A
"172.16.0.0/24"
(预期输出)
"172.16.1.0/24"
完全匹配
"172.16.2.0/24"
顺序重要
"172.16.3.0/24"
"192.168.0.0/24"
"192.168.1.0/24"
云计算 第1任务 评分标准 27 - 6
序号
评分项
aws ec2 describe-route-tables --filters
"Name=tag:Name,Values=wsc2024-ma-mgmt-rt" --query
"RouteTables[].Routes[?GatewayId != null && starts_with(GatewayId,
'igw')].GatewayId" --output text \
; aws ec2 describe-route-tables --filters
"Name=tag:Name,Values=wsc2024-prod-load-rt" --query
"RouteTables[].Routes[?GatewayId != null && starts_with(GatewayId,
'igw')].GatewayId" --output text \
; aws ec2 describe-route-tables --filters
"Name=tag:Name,Values=wsc2024-prod-app-rt-a" --query
"RouteTables[].Routes[?NatGatewayId != null].NatGatewayId" --output text \
1-3-A
(命令输入)
; aws ec2 describe-route-tables --filters
"Name=tag:Name,Values=wsc2024-prod-app-rt-b" --query
"RouteTables[].Routes[?NatGatewayId != null].NatGatewayId" --output text \
; aws ec2 describe-route-tables --filters
1-3
"Name=tag:Name,Values=wsc2024-storage-db-rt-a" --query
"RouteTables[].Associations[].SubnetId" --output text | xargs -I {} aws ec2
describe-subnets --subnet-ids {} --query
"Subnets[].Tags[?Key=='Name'].Value" --output text \
; aws ec2 describe-route-tables --filters
"Name=tag:Name,Values=wsc2024-storage-db-rt-b" --query
"RouteTables[].Associations[].SubnetId" --output text | xargs -I {} aws ec2
describe-subnets --subnet-ids {} --query
"Subnets[].Tags[?Key=='Name'].Value" --output text
确认是否输出以“igw-”开头的字符串
确认是否输出以“igw-”开头的字符串
1-3-A
确认是否输出以“nat-”开头的字符串
(预期输出)
确认是否输出以“nat-”开头的字符串
顺序重要
wsc2024-storage-db-sn-a <- 完全匹配
wsc2024-storage-db-sn-b <- 完全匹配
云计算第1次作业评分标准 27 - 7
序号
评分项
VPC_ID=$(aws ec2 describe-vpcs --filters
"Name=tag:Name,Values=wsc2024-ma-vpc" --query "Vpcs[*].VpcId" --output
1-4-A
text)
1-4
(输入命令)
aws ec2 describe-flow-logs --filter "Name=resource-id,Values=$VPC_ID"
--query "FlowLogs[*].FlowLogId" --output text
1-4-A
确认是否输出以“fl-”开头的字符串
(预期输出)
1-5-A
aws ec2 describe-vpc-endpoints --query "VpcEndpoints[].ServiceName"
(输入命令)
1-5
1-5-A
[
(预期输出)
"com.amazonaws.us-east-1.s3",
ecr.dkr , s3
"com.amazonaws.us-east-1.ecr.dkr",
确认是否存在
]
POLICY_ARNS=$(aws iam list-attached-role-policies --role-name
wsc2024-bastion-role --query "AttachedPolicies[].PolicyArn" --output text)
for POLICY_ARN in $POLICY_ARNS; do
POLICY_VERSION=$(aws iam get-policy --policy-arn $POLICY_ARN --query
1-6-A
"Policy.DefaultVersionId" --output text)
(输入命令)
POLICY_DOCUMENT=$(aws iam get-policy-version --policy-arn $POLICY_ARN
--version-id $POLICY_VERSION --query "PolicyVersion.Document" --output json)
echo "$POLICY_DOCUMENT"
done
{
1-6
"Version": "2012-10-17",
"Statement": [
1-6-A
{
(预期输出)
"Effect": "Allow",
完全匹配
"Action": "*",
不得输出除此以外的 JSON
"Resource": "*"
}
]
}
云计算第1次作业评分标准 27 - 8
序号
评分项
export BUCKET_NAME="tesfsdfklsqwerlksdf"
export REGION="us-east-1"
export FILE_NAME="test_upload.txt"
export DOWNLOADED_FILE_NAME="downloaded_test_upload.txt"
aws s3api create-bucket --bucket $BUCKET_NAME --region $REGION >
1-6-B
/dev/null 2>&1
(输入命令)
1-6
echo "This is a test file for S3 upload and download." > $FILE_NAME
aws s3 cp $FILE_NAME s3://$BUCKET_NAME/ > /dev/null 2>&1
aws s3 cp s3://$BUCKET_NAME/$FILE_NAME $DOWNLOADED_FILE_NAME
aws s3 rm s3://$BUCKET_NAME/$FILE_NAME
aws s3api delete-bucket --bucket $BUCKET_NAME --region $REGION
1-6-B
download: s3://tesfsdfklsqwerlksdf/test_upload.txt to
(预期输出)
./downloaded_test_upload.txt
完全匹配
delete: s3://tesfsdfklsqwerlksdf/test_upload.txt
AWS_REGION=$(aws configure get region)
ACCOUNT_ID=$(aws sts get-caller-identity --query Account --output text)
1-7-A
docker rmi -f $(docker images) 2>/dev/null \
(输入命令)
; aws ecr get-login-password --region "$AWS_REGION" | docker login
(若1-6答错则不进行)
--username AWS --password-stdin
"$ACCOUNT_ID.dkr.ecr.$AWS_REGION.amazonaws.com" > /dev/null 2>&1 \
; docker pull
1-7
$ACCOUNT_ID.dkr.ecr.$AWS_REGION.amazonaws.com/customer-repo:latest
1-7-A
error pulling image configuration: download failed after attempts=1: denied:
(预期输出)
(若1-6答错则不进行)
AccessDeniedAccess
DeniedD266MTTR9A8Y6XAQoNG
AccessDenied
QmQ4OWAyNe/nB9X2st34y5tQWJlLL/9mpwK56unHhOR2izzuNUByqiNlL10Jtw3vp
确认输出
MJg+vdQ=
云计算第1次作业评分标准 27 - 9
序号
评分项
TGWS=$(aws ec2 describe-transit-gateways --query
"TransitGateways[*].{Name:Tags[?Key=='Name'].Value|[0]}" --output json)
TGW_NAMES=$(echo $TGWS | jq -r '.[].Name')
for TGW_NAME in $TGW_NAMES; do
echo "$TGW_NAME"
TGW_ID=$(aws ec2 describe-transit-gateways --filters
"Name=tag:Name,Values=$TGW_NAME" --query
"TransitGateways[0].TransitGatewayId" --output text)
ATTACHMENTS=$(aws ec2 describe-transit-gateway-attachments --filters
"Name=transit-gateway-id,Values=$TGW_ID" --query
2-1-A
"TransitGatewayAttachments[*].{Name:Tags[?Key=='Name'].Value|[0]}" --output json)
ATTACHMENT_NAMES=$(echo $ATTACHMENTS | jq -r '.[].Name')
(输入命令)
for ATTACHMENT_NAME in $ATTACHMENT_NAMES; do
echo "$ATTACHMENT_NAME"
done
ROUTE_TABLES=$(aws ec2 describe-transit-gateway-route-tables --filters
2-1
"Name=transit-gateway-id,Values=$TGW_ID" --query
"TransitGatewayRouteTables[*].{Name:Tags[?Key=='Name'].Value|[0]}" --output json)
ROUTE_TABLE_NAMES=$(echo $ROUTE_TABLES | jq -r '.[].Name')
for ROUTE_TABLE_NAME in $ROUTE_TABLE_NAMES; do
echo "$ROUTE_TABLE_NAME"
done
done
wsc2024-vpc-tgw
wsc2024-ma-tgw-attach
2-1-A
wsc2024-prod-tgw-attach
(预期输出)
wsc2024-storage-tgw-attach
完全匹配
wsc2024-ma-tgw-rt
顺序无关
wsc2024-prod-tgw-rt
wsc2024-storage-tgw-rt
云计算第1次作业评分标准 27 - 10
序号
评分项
INSTANCE_NAME_TAG="wsc2024-bastion-ec2"
INSTANCE_ID=$(aws ec2 describe-instances --filters
"Name=tag:Name,Values=$INSTANCE_NAME_TAG" --query
"Reservations[0].Instances[0].InstanceId" --output text)
AMI_ID=$(aws ec2 describe-instances --instance-ids "$INSTANCE_ID" --query
3-1-A
(输入命令)
3-1
"Reservations[0].Instances[0].ImageId" --output text)
AMI_DESCRIPTION=$(aws ec2 describe-images --image-ids "$AMI_ID" --query
"Images[0].Description" --output text)
INSTANCE_TYPE=$(aws ec2 describe-instances --instance-ids "$INSTANCE_ID"
--query "Reservations[0].Instances[0].InstanceType" --output text)
echo "$AMI_DESCRIPTION"
echo "$INSTANCE_TYPE"
3-1-A
(预期输出)
确认是否输出以“Amazon Linux 2023 AMI”开头的文本
t3.small <- 完全匹配
aws ec2 describe-security-groups --filter
3-2-A
Name=group-name,Values=wsc2024-bastion-sg --query
"SecurityGroups[0].IpPermissions[].{FromPort:FromPort,ToPort:ToPort,IpRanges:IpRa
(输入命令)
nges}"
[
{
"FromPort": 28282,
3-2
"ToPort": 28282,
3-2-A
"IpRanges": [
(预期输出)
{
"CidrIp": “0.0.0.0/0" <- 也可能只允许单个 IP
完全匹配
}
]
}
]
云计算第一题评分标准 27 - 11
序号
评分项
INSTANCE_NAME_TAG="wsc2024-bastion-ec2"
INSTANCE_DESC=$(aws ec2 describe-instances --filters
"Name=tag:Name,Values=$INSTANCE_NAME_TAG" --query
"Reservations[0].Instances[0]" --output json)
IAM_INSTANCE_PROFILE_ARN=$(echo $INSTANCE_DESC | jq -r
3-2-B
(输入命令)
3-2
'.IamInstanceProfile.Arn')
ROLE_NAME=$(aws iam get-instance-profile --instance-profile-name
$(echo $IAM_INSTANCE_PROFILE_ARN | awk -F'/' '{print $NF}') --query
"InstanceProfile.Roles[0].RoleName" --output text)
ROLE_POLICIES=$(aws iam list-attached-role-policies --role-name
"$ROLE_NAME" --query "AttachedPolicies[].PolicyName" --output text)
echo "$ROLE_POLICIES"
3-2-B
(预期输出)
AdministratorAccess
完全匹配
aws vpc-lattice list-service-networks --query
"items[?name=='wsc2024-lattice-svc-net'].name" --output text
SERVICE_NETWORK_ID=$(aws vpc-lattice list-service-networks --query
"items[?name=='wsc2024-lattice-svc-net'].id" --output text)
SVC_ASSOCIATION=$(aws vpc-lattice list-service-network-service-associations
4-1-A
(输入命令)
--service-network-identifier "$SERVICE_NETWORK_ID" --query items[*].id
--output text)
VPC_ASSOCIATION=$(aws vpc-lattice list-service-network-vpc-associations
4-1
--service-network-identifier "$SERVICE_NETWORK_ID" --query 'items[*].id'
--output text)
echo "$SVC_ASSOCIATION"
echo "$VPC_ASSOCIATION"
4-1-A
wsc2024-lattice-svc-net <- 完全匹配
(预期输出)
确认是否输出以“snsa-”开头的文本
顺序有关
确认是否输出以“snva-”开头的文本
云计算第一题评分标准 27 - 12
序号
评分项
TARGET_GROUP_ID=$(aws vpc-lattice list-target-groups
4-2-A
(输入命令)
--target-group-type IP | jq -r '.items[].id')
aws vpc-lattice list-targets --target-group-identifier
"$TARGET_GROUP_ID"
{
"items": [
4-2
4-2-A
{
(预期输出)
"id": "172.16.3.145",
status
"port": 8080,
是否为 HEALTH
"status": "HEALTHY"
确认,可能为多个
}
]
}
SERVICE_NETWORK_ID=$(aws vpc-lattice list-service-networks --query
4-3-A
"items[?name=='wsc2024-lattice-svc-net'].id" --output text)
aws vpc-lattice list-service-network-service-associations
(输入命令)
--service-network-identifier "$SERVICE_NETWORK_ID" --query items[*].id
--output text
4-3
4-3-A
复制以“snsa-”开头的文本
(预期输出)
云计算第一题评分标准 27 - 13
序号
评分项
1) 连接到名称为 wsc2024-lattice-svc-net 的 Service networks
2) 连接到从 4-3-A 复制的 ID
4-3-B
(控制台访问)
4-3
3) 复制 Domain Name
4) curl http://<从 4-3-B-3 项复制的 Domain>/healthcheck
4-3-B
(预期输出)
{"status":"ok."}
完全匹配
云计算第一题评分标准 27 - 14
序号
评分项
aws rds describe-db-clusters --db-cluster-identifier wsc2024-db-cluster
--query 'DBClusters[0].EngineVersion' --output text \
; aws rds describe-db-clusters --db-cluster-identifier wsc2024-db-cluster
5-1-A
--query 'DBClusters[0].MasterUsername' --output text \
(输入命令)
; aws rds describe-db-instances
--query
"DBInstances[?DBClusterIdentifier=='wsc2024-db-cluster'].DBInstanceClass"
--output text \
5-1
确认是否输出以“8.0.mysql_aurora”开头的文本
5-1-A
admin <- 完全匹配
(预期输出)
db.t3.medium
5-2-A
(输入命令)
db.t3.medium <- 完全匹配
aws rds describe-db-clusters --db-cluster-identifier wsc2024-db-cluster
--query "DBClusters[0].BacktrackWindow" --output text
5-2
5-2-A
(预期输出)
14400
完全匹配
云计算第一题评分标准 27 - 15
序号
评分项
6-1-A
(输入命令)
aws dynamodb describe-table --table-name order --query
'Table.KeySchema[?KeyType == `HASH`].AttributeName' --output text
6-1
6-1-A
(预期输出)
id
完全匹配
7-1-A
(输入命令)
7-1
aws ecr describe-repositories --query 'repositories[*].repositoryName'
--output text
7-1-A
(预期输出)
customer-repo
product-repo
order-repo
完全匹配
aws eks describe-cluster --name wsc2024-eks-cluster --query
8-1-A
(输入命令)
'cluster.version' --output text \
; aws eks describe-cluster --name wsc2024-eks-cluster --query
'cluster.logging.clusterLogging[].types' | jq .
--output text
1.29
[
8-1
[
"api",
8-1-A
"audit",
(预期输出)
"authenticator",
完全匹配
"controllerManager",
"scheduler"
]
]
云计算第一题评分标准 27 - 16
序号
评分项
8-2-A
8-2
(输入命令)
aws eks describe-cluster --name wsc2024-eks-cluster --query
"cluster.encryptionConfig[].provider.keyArn" --output text
8-2-A
确认是否输出以“arn:aws:kms:us-east-1”开头的文本
(预期输出)
kubectl get node -l app=db -o json | jq -r
'.items[].metadata.labels."eks.amazonaws.com/nodegroup"'
8-3-A
kubectl get nodes -l app=db -o json | jq -r '.items[].metadata.name'
(输入命令)
kubectl get nodes -l app=db -o json | jq -r '.items[] |
.metadata.labels["beta.kubernetes.io/instance-type"]'
8-3
wsc2024-db-application-ng
8-3-A
wsc2024-db-application-ng
(预期输出)
确认是否输出以“ip-“开头的文本
完全匹配,
确认是否输出以”ip-”开头的文本
必须输出多个才是正确答案
t3.medium
正确答案
t3.medium
kubectl get node -l app=other -o json | jq -r
'.items[].metadata.labels."eks.amazonaws.com/nodegroup"'
8-4-A
kubectl get nodes -l app=other -o json | jq -r '.items[].metadata.name'
(输入命令)
kubectl get nodes -l app=other -o json | jq -r '.items[] |
.metadata.labels["beta.kubernetes.io/instance-type"]'
8-4
wsc2024-other-ng
wsc2024-other-ng
8-4-A
确认是否输出以“ip-“开头的文本
(预期输出)
确认是否输出以”ip-”开头的文本
t3.medium
t3.medium
云计算第一题评分标准 27 - 17
序号
评分项
8-5-A
**8-5**
- **8-5-A**
- (输入命令)
```
kubectl get deploy -n wsc2024
```
- (预期输出)
```
完全一致
```
**9-1**
- **9-1-A**
- (输入命令)
```
aws elbv2 describe-load-balancers --names wsc2024-alb --query "LoadBalancers[].Scheme" --output text
aws elbv2 describe-load-balancers --names wsc2024-alb --query "LoadBalancers[].Type" --output text
```
- (预期输出)
```
internet-facing
application
完全一致
```
**9-2**
- **9-2-A**
- (输入命令)
```
LBDNS=$(aws elbv2 describe-load-balancers --names wsc2024-alb --query "LoadBalancers[].DNSName" --output text)
curl http://$LBDNS/v1/customer -X POST -H 'Content-Type: application/json' -d '{"id": "3101", "name": "Lee", "gender": "18"}'
echo "-"
```
- (失败时更改 id 后最多可重试 3 次)
- (预期输出)
```
{"customer":{"id":"3101","name":"Lee","gender":"18"},"message":"The customer is created."}
```
```
完全一致
```
云计算第1作业评分标准 27 - 18
序号
评分项
**9-3**
- **9-3-A**
- (输入命令)
```
LBDNS=$(aws elbv2 describe-load-balancers --names wsc2024-alb --query "LoadBalancers[].DNSName" --output text)
curl http://$LBDNS/v1/product -X POST -H 'Content-Type: application/json' -d '{"id": "3201", "name": "kim", "category": "stduent"}'
echo "-"
```
- (预期输出)
```
{"product":{"id":"3201","name":"kim","category":"stduent"},"message":"The product is created."}
```
```
完全一致
```
**9-4**
- **9-4-A**
- (输入命令)
```
LBDNS=$(aws elbv2 describe-load-balancers --names wsc2024-alb --query "LoadBalancers[].DNSName" --output text)
curl http://$LBDNS/v1/order -X POST -H 'Content-Type: application/json' -d '{"id": "3301", "customerid": "3101", "productid": "3201"}'
echo "-"
```
- (预期输出)
```
{"order":{"id":"3301","customerid":"3101","productid":"3201"},"message":"The order is created."}
```
```
完全一致
```
**10-1**
- **10-1-A**
- (输入命令)
```
aws s3 ls
```
- (预期输出)
```
2024-05-29 01:45:49 wsc2024-s3-static-zfff
```
确认是否输出 wsc2024-s3-static-<4位英文字母>
云计算第1作业评分标准 27 - 19
序号
评分项
**10-2**
- **10-2-A**
- (输入命令)
```
for bucket in $(aws s3api list-buckets --query "Buckets[?starts_with(Name, 'wsc2024-s3-static')].Name" --output text); do
aws s3 ls "s3://$bucket" --recursive
done
```
- (预期输出)
```
2024-05-30 02:19:44
10004 index.html
```
确认是否仅输出 index.html
**10-3**
- **10-3-A**
- (输入命令)
```
BUCKET_NAME=$(aws s3api list-buckets --query "Buckets[?starts_with(Name, 'wsc2024-s3-static')].Name" --output text)
curl https://s3.us-east-1.amazonaws.com/$BUCKET_NAME/index.html
```
- (预期输出)
```
AccessDeniedAccess
Denied61ZYXR7KRGYYQV0F1DV
S1AnW17Q1FBRzgyk37tJ36ONhVMkjn8M4A+mTm02SW2krmxIZ2uVIs5A25rYCTms
R8OG+A+I=
```
确认输出 AccessDenied
云计算第1作业评分标准 27 - 20
序号
评分项
**11-1**
- **11-1-A**
- (输入命令)
```
aws cloudfront list-distributions --query "DistributionList.Items[].Origins.Items[].DomainName" --output text
aws cloudfront list-distributions --query "DistributionList.Items[].IsIPV6Enabled" --output text
ID=$(aws cloudfront list-distributions --query "DistributionList.Items[].Id" --output text)
aws cloudfront get-distribution-config --id $ID --query 'DistributionConfig.PriceClass' --output text
```
- (预期输出)
```
确认是否输出以“wsc2024-s3-static-”开头的字符串
确认是否输出以“wsc2024-alb-”开头的字符串
False <- 完全一致
PriceClass_All <- 完全一致
```
**11-2**
- **11-2-A**
- (输入命令)
```
aws cloudfront list-distributions --query "DistributionList.Items[].DefaultCacheBehavior.ViewerProtocolPolicy" --output text
aws cloudfront list-distributions --query "DistributionList.Items[].CacheBehaviors.Items[].ViewerProtocolPolicy" --output text
```
- (预期输出)
```
redirect-to-https
redirect-to-https
完全一致
```
**11-3**
- **11-3-A**
- (输入命令)
```
DOMAIN=$(aws cloudfront list-distributions --query "DistributionList.Items[].DomainName" --output text)
curl https://$DOMAIN 2>/dev/null | grep -oP '(?<=
).*?(?=
)'
```
- (预期输出)
```
Welcome to Cloud Computing
```
```
完全一致
```
云计算第1作业评分标准 27 - 21
序号
评分项
**11-4**
- **11-4-A**
- (输入命令)
```
DOMAIN=$(aws cloudfront list-distributions --query "DistributionList.Items[].DomainName" --output text)
curl -s -I https://$DOMAIN | grep -i x-cache
```
- (只输入一次)
- (预期输出)
```
x-cache: Hit from cloudfront
```
```
完全一致
```
**11-5**
- **11-5-A**
- (输入命令)
```
DOMAIN=$(aws cloudfront list-distributions --query "DistributionList.Items[].DomainName" --output text)
curl https://$DOMAIN/v1/customer?id=3101
echo "-"
```
- (预期输出)
```
{"customer":{"id":"3101","name":"Lee","gender":"18"},"message":"The customer is well in database."}
```
```
完全一致
```
**11-6**
- **11-6-A**
- (输入命令)
```
DOMAIN=$(aws cloudfront list-distributions --query "DistributionList.Items[].DomainName" --output text)
curl https://$DOMAIN/v1/product?id=3201
echo "-"
```
- (预期输出)
```
{"product":{"id":"3201","name":"kim","category":"stduent"},"message":"The product is well in database."}
```
```
完全一致
```
**11-7**
- **11-7-A**
- (输入命令)
```
DOMAIN=$(aws cloudfront list-distributions --query "DistributionList.Items[].DomainName" --output text)
curl https://$DOMAIN/v1/order?id=3301
echo "-"
```
- (预期输出)
```
{"order":{"id":"3301","customerid":"3101","productid":"3201"},"message":"The order is well in database."}
```
```
完全一致
```
云计算第1作业评分标准 27 - 22
序号
评分项
**12-1**
- **12-1-A**
- (执行命令)
```
aws route53 list-hosted-zones --region us-east-1 | grep Name
```
- (说明)
确认是否有以 <非编号>.cloudhrdk*.com 返回的名称。
**12-2**
- **12-2-A**
- (说明)
在选手的 Windows PC 等外部环境中输入以下命令时,确认是否返回 54.0.0.10。
- (执行命令)
```
nslookup q1.${HOSTZONE}
```
**12-3**
- **12-3-A**
- (说明)
1) 访问 Bastion。
2) 输入以下命令,确认没有与 cloudhrdk 相关的域名。
- (执行命令)
```
cat /etc/hosts
```
- **12-3-B**
- (说明)
3) 输入以下命令,确认没有 Private hosted zone。
- (执行命令)
```
aws route53 list-hosted-zones --region us-east-1 --hosted-zone-type PrivateHostedZone
```
云计算第1作业评分标准 27 - 23
序号
评分项
**12-3-C**
输入以下命令,确认是否返回 172.16.0.10。
说明
共重复 4 次,且 4 次都必须返回 172.16.0.10。
12-3
12-3-C
nslookup q1.${hostzone}
执行命令
13-1-A
说明
输入以下命令,确认是否返回包含 cloudfront.net 的地址。
13-1
13-1-A
nslookup cf.${hostzone}
执行命令
13-2-A
说明
输入以下命令,确认是否返回包含 Amazon 或 AWS 的字符串。
13-2
13-2-A
执行命令
13-3-A
说明
echo -n "Q" | openssl s_client -connect cf.${hostzone}:443 2>
/dev/null | grep i:
输入以下命令,确认是否返回“Cloud Skills <비번호>”字符串。
13-3
13-3-A
curl https://cf.${hostzone}
执行命令
云计算第1次作业评分标准 27 - 24
序号
评分项
14-1-A
说明
输入以下命令,在 beta 命名空间中创建 Pod。
14-1-A
aws eks update-kubeconfig --region us-east-1 --name prod-<등번호>
执行命令
14-1-B
说明
14-1-B
kubectl apply -f beta.yaml
输入以下命令,确认 beta 命名空间中的 day1-beta Pod 是否已正确配置为 Running 状态。
kubectl get pods -n beta
执行命令
14-1
14-1-C
输入以下命令,在 prod 命名空间中创建 Pod。
说明
14-1-C
kubectl apply -f prod.yaml
执行命令
14-1-D
说明
14-1-D
输入以下命令,确认 prod 命名空间中的 day1-prod Pod 是否创建失败。
kubectl get pods -n prod
执行命令
云计算第1次作业评分标准 27 - 25
序号
评分项
14-2-A
输入命令,创建 day1-prod-pos Pod。
说明
14-2-A
kubectl apply -f prod-pos.yaml
执行命令
14-2-B
说明
14-2-B
输入命令,确认 day1-prod-pos Pod 是否已创建并处于 Running 状态。
kubectl get pods -n prod
执行命令
14-2
14-2-C
输入命令,创建 day1-prod-neg Pod。
说明
14-2-C
kubectl apply -f prod-neg.yaml
执行命令
14-2-D
说明
14-2-D
输入命令,确认 day1-prod-neg Pod 是否创建失败。
kubectl get pods -n prod
执行命令
云计算第1次作业评分标准 27 - 26
序号
评分项
14-3-A
输入命令,创建 day1-beta-pos Pod。
说明
14-3-A
kubectl apply -f beta-pos.yaml
执行命令
14-3-B
说明
14-3-B
输入命令,确认 day1-beta-pos Pod 是否已创建并处于 Running 状态。
kubectl get pods -n beta
执行命令
14-3
14-3-C
输入命令,创建 day1-beta-neg Pod。
说明
14-3-C
kubectl apply -f beta-neg.yaml
执行命令
14-3-D
说明
14-3-D
输入命令,确认 day1-beta-neg Pod 是否创建失败。
kubectl get pods -n beta
执行命令
云计算第1次作业评分标准 27 - 27