Runtime Insightsã«ããè匱æ§ãã€ãºã®ã«ããã¹ã«ãŒ
ããã«ã¡ã¯ã仿¥ã¯ã¯ãªã¹ãã£ã³ã»ãã¥ãã¥ã€ããSysdigã®ã¢ã¬ãã¯ã¹ã»ããŒã¬ã³ã¹ãã玹ä»ããŸããããã§ã¯ãSysdig runtime insightsã§æ§ç¯ããçµ±åã«ã€ããŠã話ããŸããäžçš®ã®æèèšå®ãšããŠãããã¯äœã«ã€ããŠã§ãã?åºèª¿è¬æŒã§ãç§ãã¡ã¯å€ãã®ããŒã¿ãååŸãããã®ããŒã¿ãå éšã«ãŒãã®éçºè ã³ã³ããã¹ãã«æã¡èŸŒããšãã䜿åœã垯ã³ãŠããããšãããããŸãããããããŸãã« ç§ãã¡ãDocker Scoutã§éæããããšããŠããããšã§ããç®æšã¯ãéçºè ãçŸå°ã§äœæ¥ããéã«å¯ŸåŠããªããã°ãªããªãèªç¥çéè² è·(ãã€ãº)ãå€§å¹ ã«æžãããŠããµãã©ã€ãã§ãŒã³ã®ã»ãã¥ãªãã£ãç¶ç¶çã«åäžãããããšã§ãããããŠãç«ã¡äžããããçŽ æŽãããããŒãããŒã·ããã®1ã€ãSysdigã§ãã
ãããŠä»ãåºèª¿è¬æŒã§ç€ºãããã®ãããå°ãæ·±ãæãäžããããšæããŸãã ããã§ã¯ãã¢ã¬ãã¯ã¹ã«SysdigããèŠãããŸãããã Sysdigã¯ãScoutãŠãŒã¶ãŒãšããŠScoutããã¢ã¯ã»ã¹ãããã¹ãŠã®äººã«ç¡æãã©ã€ã¢ã«ãæäŸããŠããã®ã§ãèªåã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã§ããã詊ãããšãã§ãããšæããŸãã ã¢ã¬ãã¯ã¹ããããåãé€ããŠãã ããã
ããããšãããããŸãã åºæ¬çã«ã仿¥ã®ç§ã®ç®æšã¯ãããããã®ã¹ã©ã€ãã§ããªããéå±ããããã©ã³ãã ãªããšã話ãããšã§ããã Sysdigã®ã€ã³ã¿ãŒãã§ãŒã¹ã®å éšããèŠãããŠãæ¬åœã«ã©ã€ãã®ãã®ã«çŠç¹ãåœãŠãããšæã£ãŠããŸãããã? ä»ãäœãèµ·ããŠããã®ã? 次ã«ãæåŸã«Dockerã«è¿ããŠãDockeråŽãžã®çµ±åã瀺ããŸãã
Sysdigã€ã³ã¿ãŒãã§ãŒã¹
ãããSysdigã®ã€ã³ã¿ãŒãã§ãŒã¹ã§ãã éèŠãªã®ã¯ãç°å¢å šäœãCNAPPããŒããã©ãªãªå šäœã§äœãèµ·ãã£ãŠããããšããããšã§ãã ããã¯ã¯ã©ãŠãã¢ã¯ãã£ããã£ã®ãã¥ãŒã§ããã? ãããã£ãŠãããã¯ã¯ã©ãŠãæ§æã«å¯ŸããŠå®éã«èµ·ãã£ãŠããããšã«ãªããŸãã ãããŠãç§ã¯ãããããã€ãã®ç°ãªãæ¹æ³ã§èŠãããšãã§ããŸãã ä»ã¯ãã¢ã«ãŠã³ãããªãŒãžã§ã³ããªãœãŒã¹ã®çš®é¡ãªã©ã§èŠãŠããŸãã ããããå€åç§ã¯ãããªã®ã¢ã«ãŠã³ããŸãã¯èª°ãã®ã¢ã«ãŠã³ããæ£ããæ©èœããŠããªãã®ã§ã¯ãªãããšçã£ãŠããŸãã ãããŠãããã¯ç§ã«ã©ã€ãæ€çŽ¢ããããããšãã§ããŸãã ãããªã¿ãããªã®ãããã§ãã£ãŠããããããããªã®ãã®ã ããèŠããŠãããã ããããã°ãç§ã¯Mateoã ããæ°ã«ããŠãããšèšããŸããå€åã¢ã¯ã·ã§ã³ãåé€ããŸãã ãããã£ãŠãdeleteãšå ¥åãå§ãããšãMateoã®åé€ã«ãã£ã«ã¿ãªã³ã°ãããŸããã? åºæ¬çã«ãã¯ã©ãŠãã§çºçããŠãããã¹ãŠã®ã€ãã³ãã調ã¹ãŠãéåžžã«å ·äœçãªãã®ãæ¢ãããšãã§ããŸããã? ãã®ã³ã³ããã¹ãã§äœããåé€ããããã³ã«ããããŸãã Mateoãåé€ããããåé€ãããããŠããã¹ãŠã®ã€ãã³ãã«æ»ã£ãŠãåé€ã¢ã¯ã·ã§ã³ãæ¢ããŠãã©ã€ãã§ãã¹ãŠã®ãã®ããµããã«ããå§ããããšãã§ããŸããã?
ããããããšã§ãä»äœãèµ·ããŠããã®ããšããèŠç¹ãçãŸããŸãã ãããŠããã®æç¹ã§ç§ã¯äœãæ°ã«ãã¹ãã§ãã? ããŒã¿ãååŸããŠãããŸããŸãªãã©ãã€ã ã§èŠãããšãã§ããŸãã ã€ãŸããã¯ã©ãŠãã®ã¢ã¯ãã£ããã£ã«ã€ããŠã§ããã AWSãGoogleãAzureãªã©ããã¹ãŠã®ã¯ã©ãŠãã§ãŠãŒã¶ãŒãäœãããŠããã®ããªã©ãå ·äœçã«èŠãŠã人ã®èŠç¹ããèŠãããšãã§ããŸãã ãããŠãç§ã¯ç§ãæããã®ãèŠãããšãã§ãããã®å šãåãæ€çŽ¢ãããããšãã§ããŸãã ç§ãããã«çœ®ããæååçšèªã¯ãã¯ã€ãã¯æ€çŽ¢ãè¡ããŸãã
ã¯ã©ã¹ã¿ãŒãäœæããå Žåã¯ãã¯ã©ã¹ã¿ãŒã®åé€ããªãŒãã®åé€ãèŠã€ããŠãã¯ã©ã¹ã¿ãŒã«å¯ŸããŠå®è¡ãããã¢ã¯ã·ã§ã³ãå ·äœçã«æ¢ãããšãã§ããŸãã ããããããšã§ãéåžžã«æ¬æ°ã§ã¹ããŒãã£ãŒãªæ¹æ³ã§ããããã¹ãŠã«ç®ãéãããšãã§ããŸãã ãŸããããããŠãŒã¶ãŒãã¯ã©ãŠãã®ãã®ããåãé¢ãããã«åç·šæããããKubernetesãã³ã³ããã§èµ·ãã£ãŠããããšãå ·äœçã«èª¿ã¹ããããããšãã§ããŸãã ããããŸãã¯ã¯ãŒã¯ããŒãã ãã«çµã蟌ãããšãã§ããŸãã
ã©ããããã§ããã
åºæ¬çã«ã¯ãä»èªåã®ç°å¢ã§äœãèµ·ãã£ãŠããã®ããçŸæç¹ã§æ¬åœã«æ°ã«ãã¹ãããšã¯äœããèŠèŠçã«æ¢ãããšãã§ããŸãã ããã¯ãç¹å®ã®ã¯ã©ã¹ã¿ãŒããæåŠãããŠãããã®ã瀺ãå§ããŠããã®ã§ãã¡ãã£ãšæ¥œããã§ãã ãããã£ãŠãã¹ãã£ã³è©äŸ¡ã«å€±æããããã«ã³ã³ãããæåŠãããã€ãã³ããçºçããŠããããšãããããŸãã ã§ããããããç§ã誰ãã«ã³ã³ãããäœããããšãããããã®ã³ã³ããã¯çç±ãäœã§ãããé©åãªãã®ãæž¡ã£ãŠããŸããã§ããã å®éã«ãã®å€±æã«é¢ããã€ãã³ããçºçããæ¬çªç°å¢ã«ããã·ã¥ããããšããŠãããã®ãèªããããŠããªã詳现ã¬ãã«ã確èªã§ããŸãã ã€ãŸããã©ã€ãããŒã¿ãšããããå®éã«è¡ã£ãŠããããšã®ã»ãšãã©ãéèŠãªã®ã§ãã
ãããã¯ãã¹ãŠãã®ã€ãã³ãã»ã¯ã·ã§ã³ããæ¥ãŠããŸãããéåžžã«èŠèŠçãªæ¹æ³ã§èŠãŠãã€ã³ãã©ã¹ãã©ã¯ãã£ãå®éã«ã©ã®ããã«èŠããããšããã³ã³ããã¹ãã§æ¢çŽ¢ã§ããŸãã ãã®èŠç¹ã§ã¯ããã¹ãŠã®ã€ãã³ãã§ããäŒçµ±çãªèŠç¹ãäžããŠããããããªãã®ã§ãã ããã«ã€ããŠè峿·±ãã®ã¯ãç©äºã®ããŸããŸãªè©³çްã«ããªãæ·±ãå ¥ã蟌ãããšãã§ããããã«ããã€ãã®åŒ·åãªãã£ã«ã¿ãŒã«ã¢ã¯ã»ã¹ã§ããããšã§ãã
ãã£ã«ã¿ãªã³ã°ãšåªå é äœä»ã
ç§ããããæ°ã«å ¥ã£ãŠããããšã® 1 ã€ã¯ãã»ãã¥ãªãã£çµç¹ãéå¶ããŠããŠãéŽäžã®æžå¿µãããå Žåãããããã³ã°ããŠããç¹å®ã® MITRE ã®æžå¿µãããå ŽåããŸã㯠PCI ã³ã³ãã©ã€ã¢ã³ã¹ãããå Žåã§ãã ãããã®ããŸããŸãªã³ã³ãã©ã€ã¢ã³ã¹ä»æ§ã®ãã£ã«ã¿ãŒã远å ãå§ãããšããããã®ããŸããŸãªãã¬ãŒã ã¯ãŒã¯å ã§ã©ã€ãéåãæ¢ãããšãã§ããŸãã ä»ã®ãšãããäžçªè¿ãã®ã¯6æéåã®ãã®ãªã®ã§ã 10 ååã®ãã®ã¯ãããŸãããããã®ç¹å®ã®ä»æ§ã«æºæ ããŠããããšãä¿èšŒããå¿ èŠããããšèšããŸãã ã€ãã³ããç·åçã«èŠãŠãç¹å®ã®ä»æ§ã«æºæ ããŠãããã©ããã確èªããŸãããã å³ã ãã®ãããããŒã ããšã«ç°ãªãæ¹æ³ã§ãããŸããŸãªãŠãŒã¹ã±ãŒã¹ã§ãã®ããŒã¿ã䜿çšã§ããŸãã
ç§ãã¡ãããã§è¡ã£ãŠããä»ã®ããšã®å€ãã¯ãããææçŸ©ãªæ¹æ³ã§ã客æ§ã®çæŽ»ã«æº¶ã蟌ãããšã§ãã ç§ãèšãããã®ã¯ããšã³ããŠãŒã¶ãŒãšããŠã»ãã¥ãªãã£çµç¹ãšååŒããå Žåãããã®éã®å Žåãç°ãªãæ¹èšã話ããŠããããšãå€ããšããããšã§ãã åãèšèªã話ããŠããã®ã«ãéãèšèã䜿ã£ãŠãããããã®èšèã®æå³ãæ®æ®µäœ¿ã£ãŠãããã®ãšéãã
ããã§ã®éåžžã«è¯ãäŸã® 1 ã€ã¯ãããšãã°ãã¹ãã£ç®¡çã«é¢ãããã®ã§ãã ããã¯ãç§ãã¡å šå¡ãæ°ã«ãããªããã°ãªããªãéèŠãªåéã§ãã éèŠãªã®ã¯æ§æã§ããã匷åãããé©åãªæ¹æ³ã§ã»ããã¢ãããããŠããããšã確èªããããšã§ãã ãããŠãã»ãšãã©ã®å Žåã仿§ãèŠãŠããŸãã ç¹°ãè¿ãã«ãªããŸãããPCIãNISTãªã©ãKubernetesãã³ã³ãããDockerãªã©ããããããã®ã«é¢ãããã¹ããã©ã¯ãã£ã¹ã§ãã çµå±ã®ãšãããéåžžãèšå®ãã¹ã«é¢ããã¬ããŒããåãåãããšã«ãªããŸãã
ã»ãã¥ãªãã£ã®å°éå®¶ãšããŠã®ç§ã®ä»äºã¯ãåºæ¬çã«ãããŒã ãä¿®æ£ããããã«æãéèŠã ãšæãããšãåªå ããããšã§ãã ãããŠãç§ã¯åœŒãã«ãã®ã¬ããŒããäžããã€ããã§ãã ç§ã¯ãããPDFãšããŠããŠã³ããŒãããå£è¶ãã«åœŒãã«ææž¡ããŠãããããã¹ãŠã®ããšãä¿®æ£ããŠãã ãããšèšãã€ããã§ãã ãããŠã圌ãã¯åºæ¬çã«ãã»ãã¥ãªãã£ã¯ç§ã«ããã¹ãããšã®èšå€§ãªãªã¹ããäžããŠãããããšèšãã§ãããã èšå®ãã¹ããã¡ãã¡èª¿ã¹ã«è¡ããªããã°ãªããŸããã ã©ããã£ãŠä¿®æ£ããã°ããã®ãã調ã¹ã«è¡ããªããšãããªãã ã©ãããã°ãããã§ãããã
ã§ããããå€ãã®ããŒã«ãããããããããééã£ãŠãããã®ãçè§£ãã«ãããã®ãæ°Ÿæ¿«ãããããªããšèšã£ãŠããŸãã ããã§ã¯ãrootãšããŠå®è¡ããããšãªã©ãèŠãŠã¿ãŸãããã ã§ããããã¡ãã£ãšããæç€ºããããŠããã®åŸãåŸãã¹ããã®ãæã«å ¥ããããšãã§ããŸãã ããããããŒã«ãéçšããŒã ãšåãèšèªã話ããããããšæããŸããã? ãŸãã¯ãéçºè ãšåãèšèªã話ããŸãã? ç§ãã¡ãããããšããŠããããšã¯ããããããã«äžæ©é²ããŠããªãŒã±ãŒããã®ä»æ§ã¯ã§ããŠããããŸã ã³ã³ãããrootãšããŠå®è¡ãã¹ãã§ã¯ãªãããšèšãããšã§ãã
ããã§ã¯ãç°å¢å šäœã§ãã¹ãŠã®ã«ãŒãã³ã³ãããèŠã€ããŠã¿ãŸãããã ãããã®ãã¡ã®1ã€ããã€ã©ã€ãããã°ãå®éã«ç¹å®ã®ãªã¹ã¯ãããã«éåããŠããç¹å®ã®ã³ã³ãããèŠãããšãã§ããŸãã ãªã圌ããrootãšããŠå®è¡ãããŠããã®ããããããŸãã ãã®å ŽåããŠãŒã¶ãŒã誰ã§ãããã誰ãèšå®ããŠããªãã®ã§ãããã©ã«ãã§rootã«ãªã£ãŠããŸãã ãããä¿®æ£ããŸãããã ç§ãã¡ã¯ã 1ã000 ã 1 ããŸãã¯ç§ãã¡ã®äŸ¡å€ãç§ãã¡ã®äŒç€Ÿã§äœ¿çšãããã®ã¯äœã§ãããããå®è¡ããããšãã§ããŸãã ãããŠããããããšãå®éã«ããããçæãããŸãã å³ã ç§ã¯ããã«æ¥ãŠãJiraããã±ããã·ã¹ãã ãéããšãã¯ã©ã¹ã¿ãŒã«çŽæ¥é©çšããŠå ã«é²ãããšãã§ãã仿§ãå®éã«å«ããããšãã§ããŸãã ãããã¯ãããäžæ©èžã¿èŸŒãã§ããããããããŸããã å¿ èŠã«å¿ããŠãå®éã«ãªããžããªã«çŽæ¥çµ±åããã¯ãŒã¯ãããŒã§çŽæ¥ãã«ãªã¯ãšã¹ããéãããšãã§ããŸãã
ããã®è¯ããšããã¯ãç¹°ãè¿ãã«ãªããŸãããç§ã¯èª°ãã«ããããã®ãã®ãçŽãããšå ±åããŠããã ãã§ã¯ãªããšããããšã§ãã ã»ãã¥ãªãã£ã®å°éå®¶ã¯ã䟡å€ã¯ããããã¹ãã ãšèšã£ãŠããŸãã ãã®ä»æ§ãæ¡çšãããããã® PR ã確èªããŠã¯ã©ã¹ã¿ãŒã«é©çšããããšããå§ãããŸãã
å®è¡å¯èœãªã€ãã³ã
ããã§ã®ç®æšã¯ãèšå®ãã¹ãã€ãã³ããç°å¢ã§å®éã«ç®ã«ããŠãããã®ã«é¢ãããã¹ãŠã®äŒè©±ãããšã³ããŠãŒã¶ãŒãå®éã«å®è¡ã§ããããã«ããããšã§ãã ãªããªããç§ãã¡ãæãé¿ãããã®ã¯ã人ã ãäœãããªããããªå€§ãããŠå·šå€§ãªã¬ããŒããæäŸããããšã ããã§ãã
ã©ã³ã¿ã€ã ã³ã³ããã¹ãã®äŸã§ã¯ããããã®çŽ æŽãããæ¥œããã€ãã³ãããã¹ãŠã€ã³ãµã€ã ãã¥ãŒã«è¡šç€ºãããŸããã ãããããã®ãããªãã®ã§å®éã«äœãã§ããã§ãããã? ãšããããã§ãããã§ã®ã€ãã³ãã§ãã ãã£ããæ¢ãã«è¡ããã
ç§ãèŠããã®ã¯Kubernetesã®ã¢ã¯ãã£ããã£ã®äžã«ãããšæãã®ã§ãã¿ãŒããã«ã«é¢é£ãããã®ãæ¢ãã«è¡ããŸãã ããã«ã¯ãã¿ãŒããã«ã·ã§ã«ãšã³ã³ãããšåŒã°ããã€ãã³ãããããŸãã ããã¯ãããããç§ãã¡å šå¡ã人çã§ãã£ãããšã®ããããšã§ãã ç§ãã¡ã¯çãã³ã³ããã«å ¥ããã·ã§ã«ãéããæ§æã倿ŽããŸããã ã»ãšãã©ã®å Žåãããã§åé¡ãªãã§ãããã ããããæ¬çªç°å¢ã§ã¯ããããããã®ããã«è¡ãã¹ãã§ã¯ãããŸãããã? ã§ãããããã®ããšãç¬èªã«æèãããã®ãããªçš®é¡ã®ã€ãã³ãã«æ³šæããå¿ èŠããããŸãã ãããããããç¶ããå Žåãå®éã«ã¯ã©ããªãã®ã§ãããã?
èªåã®ã€ãã³ãã調ã¹ãŠã¿ããšãããããªããšãèµ·ããŠããã®ãããããŸãã ç¹ã«æ¢ãã«è¡ããŸãããã ç§ã¯ããã§ãããæ¢ãã«è¡ãããšãã§ããŸãâç§ãã¡ã¯ããã匷調ããã ãã§ãã è¯ãç¹ã¯ãç§ãã¡ã®äžçã§ãããã®ã€ãã³ããèŠã€ããå Žåãã€ã³ã¹ãã¥ã«ã¡ã³ãã®æ¹æ³ã¯ããŒãã®ããªãæ·±ããšããã«ãããããç¹ã«ããã«é¢ããå€ãã®ãµããŒãããŒã¿ãåŸãããããšã§ãã ãã®å Žåã誰ããrootãšããŠã·ã§ã«ãšããŠãã°ã€ã³ããŠããããšãããããŸãã 圌ãã¯å®è¡ã³ãã³ããå®è¡ããBashã§ããã€ãã®ããŒã¿ããã«ããŠã³ããŸããã åºæ¬çã«ããã£ãŠã¯ãããªãããšããããããã£ããã§ãããã
ããã«ããããã¹ãŠã®ããã»ã¹å šäœãã¬ãã¥ãŒã§ããŸãã ããããããã»ã¹åããããå®è¡ãã芪ããã»ã¹ã芪ãä»ããŠæž¡ãããåŒæ°ãPIDãäœãèµ·ãã£ãã®ãã誰ããããããã®ããã³ã³ããã¹ããäœã§ãã£ãã®ããããã«ã¯ã¯ã©ãŠãã¬ãã«ã®ããŒã¿ãKubernetesããŒã¿ãªã©ãããããçš®é¡ã®ã¡ã¿ããŒã¿ã«ã€ããŠããå€ãã®ã³ã³ããã¹ããååŸããããšãã§ããŸãã
ãããéèŠãªçç±ã¯ãã€ãã³ãã«é¢ããå ç¢ãªã¡ã¿ããŒã¿ ã»ãããæäŸã§ããã°ãã€ãã³ããå®çšçãªãã®ã«ã§ããããã§ãã ç§ã¯ããã®åå空éã«ãã£ãããã®ãŠãŒã¶ãŒã«ããããã®ãããã«ããããããäœã§ããããšèšãããšãã§ããŸãã ç§ã¯ããã«ã€ããŠäœãããã«è¡ãå¿ èŠããããŸãã ç§ã¯ãããåãã«è¡ã£ãŠããã£ãšãããªããã°ãªããŸããããã ããã«ãããã€ãã³ãã§ããªãã®éã®ããŒã¿ãååŸã§ããå®éã«ããã䜿ã£ãŠäœããããããšãã§ããŸãã ç¹°ãè¿ãã«ãªããŸãããåã«å£è¶ãã«äœããæããã®ã§ã¯ãªããããå€ãã®ãµããŒãç¹æ§ãäžããããšããŠããŸãã
ããäžã€ãçããã«ãšã£ãŠéåžžã«éèŠãªããšã¯ãç§ãã¡ãDockerã§è¡ã£ãŠããããšãšããã®ã©ã³ã¿ã€ã ããŒã¿ãã³ã³ããã¹ãã®ãã¹ãŠãã©ã®ããã«åã蟌ãã§ãããæå³ã®ããããšãããã®ããšããããšã§ãã è匱æ§ã§ãããéå§ãããšæ±ºããã®ã¯ãå®è¡æã«ããŒã¿ãåã³ååŸããããã䜿ã£ãŠäœãæ¬æ°ãªããšãããæ¹æ³ã§ããã ãã®ãããå®è¡äžã®ãã¹ãŠã®ã¯ã©ã¹ã¿ã確èªããèšå®ãã¹ããããã«éèŠãªããšã«ããããã®ã¯ã©ã¹ã¿ã®è匱æ§ããå®éã«ã©ã®ããã«ãããã€ãããããªã©ã®ã³ã³ããã¹ãã§æ¢ãããšãã§ããŸãã
ã»ãã¥ãªãã£ã®èгç¹
ããã§ã®è¯ãç¹ã¯ããããã»ãã¥ãªãã£ã®å°éå®¶ãéçšæ åœè ã«ãšã£ãŠéåžžã«åœ¹ç«ã€ããšã§ãã 確ãã«ããã®ã€ã³ã¿ãŒãã§ãŒã¹ããã®äžç芳ã¯ãéçºè ã«ãšã£ãŠæè¯ã®ãŠãŒã¹ã±ãŒã¹ã§ã¯ãããŸããã éçºè ãæ¥ãŠãããããå®è¡ãããŠããç°å¢ã§ãã©ã®åå空éã§ã©ã€ãã§èŠããã®ãããã®ã³ã³ããã¹ãå ã§è匱æ§ãæ¢ãããããšãããããªããšã¯ããŸããããŸããã ãããã人ããããããããŸããããããã¯åœŒããäœãã§ããå Žæã§ã¯ãããŸããããã ããã¯éçºè ã®æ¥åžžã§ã¯ãããŸããã
Sysdigã®èŠç¹ããèŠããšãããã¯ç§ãã¡ã远ããããŠãã人ã§ã¯ãªããDocker Scoutã®ãããªäººã䜿ã£ãŠãã人ã§ãããä»ã®ãã³ããŒãå©çšããŠãã人ã§ãã ããã§ãããã«ããããŒã¿ããã¹ãŠåãå ¥ããŠãããŸããŸãªæ¹æ³ã§èŠãã®ãé¢çœãããŸããã ãä¿®æ£æžã¿ããšãããšã¯ã¹ããã€ãããããšãã䜿çšäžãä¿®æ£æžã¿ããšãããããããã®ãæ¢ãã«è¡ãããšãã§ããŸãã
ããã«ãããåºæ¬çã«ã¯ã倿°ã®è匱æ§ãåãäžããŠãæãéèŠãªãã®ãã€ãŸãçŸæç¹ã§æãéèŠãªãã®ã«çµã蟌ãããšãã§ããŸãã ç§ã¯ããã®ã¬ããŒããçæããããã人ã ã«æž¡ããŠäœæ¥ã«åãæããããšãã§ããã®ã§ãããã¯çŽ æŽãããããšã§ãã åºæ¬çã«èªåã®æéã«åªå é äœãä»ããããšãã§ããŸãã ããããããšã§ãçŸæç¹ã§æãéèŠãªããšã«éäžã§ããŸãã
ãããããã®ã䜿çšäžãã®ããŒã¿ãååŸããŠãéçºè ãå®éã«é¢å¿ãæã€ã¯ãŒã¯ãããŒã«ãã©ã°ã€ã³ã§ãããçŽ æŽããããšæããŸããã? 圌ããäœæ¥ããŠããã¿ãŒããã«ã«è²Œãä»ããŠãããŒã«ã«ã§ã¹ãã£ã³ãè¡ã£ãŠããããããçš®ã®IDEã䜿çšããããDocker Scoutãã©ã°ã€ã³ã䜿çšããããæ¥åžžçæŽ»ã§äœ¿çšããŠããããŒã«ã®ãããªãã®ã貌ãä»ããããšãã§ããã°ãããã¯åœŒããæ¥åžžçæŽ»ã§æã£ãŠããããçš®ã®ããŒã«ã§ãã ããã§äœãã§ããã®ããããã§ã©ã®ããã«æŽ»çšã§ããã®ã?
ãã®ãããDockerãªã©ãšææºããŠããã®ããŒã¿ããã©ãããã©ãŒã ããåãåºããéçºè ã®ãã©ãããã©ãŒã ã«çŽæ¥åã蟌ãããšã§ãéçºè ãåæãè¡ããšãã«ãããããããããŸããããã®ã³ã³ããã§ã¯ãã³ã³ãããŸãã¯ãã«ãããã€ã¡ãŒãžã§å®éã«äœ¿çšãããŠããããã±ãŒãžãããããŸãããšå€æã§ããããã«ããŸããã ãããã¯ç§ãæ°ã«ããå¿ èŠããããã®ã§ãã ä»ã®ãã¹ãŠã¯ããã®ã€ã¡ãŒãžããåŒãåºãå¿ èŠããããŸãã ãããããªããšããªããŠããã®ã«ã ããä¿®æ£ããå¿ èŠã¯ãªãã¯ãã§ãã ç§ã¯ç¹ã«ãããã®ãã®ã ããæ°ã«ãã¹ãã§ãã ã§ããããã·ã¹ãã åŽã§ã¯ãããã¯ããçš®ã®ãã®ã§ãã ããã¯ãã¹ãŠãéçšæ åœè ã«ã¢ã¯ã»ã¹æš©ãäžãããšãããã®ç¹å®ã®ãã¥ãŒã«é¢ãããã®ã§ãã
éçºè ã®èŠç¹
Scoutã®Dockerã¯ããã®ããŒã¿ãååŸããéçºè ã®èŠç¹ããããè峿·±ããã®ã«èŠããŠãããŸããã ã§ããããããããã¯ã¯ãªã¹ãã£ã³ã«ä»»ããŠããã®ããšã«ã€ããŠã圌ããæã£ãŠããããžã§ã³ãããããçµéšãããµã€ã¯ã«ã«ã€ããŠããããŠãããæ¥åžžçæŽ»ã«åãå ¥ããæ¹æ³ã«ã€ããŠããã£ãšè©±ããŠããããŸãã
ããããšããã¢ã¬ãã¯ã¹ã ãã®åã«ãå®ã¯çããã«è³ªåããããŸãã çããã¯ã©ããã£ãŠãããè¡ããŸãã? äŸãã°ãããã¹ãããã±ãŒãžãã¶ã€ã³ã®èæ¯ã«ãããã¯ãããžãŒã¯ã©ã®ãããªãã®ã§ãã?
ããã«äœ¿çšãããã¯ãããžãŒã¯ãå®éã®ã€ã³ãã©ã¹ãã©ã¯ãã£èªäœã§å®è¡ããããšãŒãžã§ã³ãã§ãã ããã¯ãç§ãã¡ããããã¹ãŠã®ããŒãã®ã«ãŒãã«ããã©ããŒã¹ãããã¹ãŠã®ã·ã¹ãã ã³ãŒã«ã調ã¹ãŸãã ãããŠããããã®åŒã³åºããã³ã³ãã€ã«äžã®ã©ã€ãã©ãªãšããã±ãŒãžã«é¢é£ä»ãããããã®åŒã³åºããèªåã§è¡ã£ãŠããŸãã ã³ã³ããã§äœ¿çšãããŠããããã±ãŒãžãæ£ç¢ºã«ææ¡ããã³ã³ããèªäœã®ã©ãããæ¥ãã®ããæ£ç¢ºã«ç¥ãããšãã§ããŸãã ãããŠãããã¯ãã¹ãŠã®ãšã³ã·ã¹ãã ããã¹ãŠã®èšèªã§æ©èœããŸãã
çµ±å
質åã«å ¥ãåã«ããã®çµ±åãã©ã®ããã«æ§ç¯ãããããããŠããã䜿ã£ãŠä»äœãã§ãããã«ã€ããŠå°ãã話ãããããšæããŸããSysdigã«ã¯ãç§ãã¡ãåŒã³åºããããªAPIããããŸãããããŠãéå§æ¹æ³ã¯ ãDocker Scoutã«ãã°ã€ã³ããããšã§ããéå§ããå Žæã¯çµ±åã»ã¯ã·ã§ã³ã§ãããããŠãäžã«ã¹ã¯ããŒã«ãããšãããã«Sysdigã¿ã€ã«ã衚瀺ãããŸãããããŠããã®ç¹å®ã®ã±ãŒã¹ã§ã¯ããã®Sysdigã¿ã€ã«ãèšå®ãããŠããã®ã§ãããã管çããããšãã§ããŸããæ°ãããã®ã远å ããããšèšããŸãããããŠãSysdigãšãŒãžã§ã³ãã®èšå®æ¹æ³ã説æããããã¥ã¡ã³ããžã®ãªã³ã¯ãæ¡å ããŸãããããã£ãŠãAPI ããŒã¯ã³ã®ããã«ãã©ã°ã€ã³ããå¿ èŠããããŸããã¯ã©ã¹ã¿ãŒåãšç°å¢ãéžæãããšãè¯ãã¹ã¿ãŒããåãããšãã§ããŸãã
ããã广çã«è¡ããšã2 ã€ã®ããšãèµ·ãããŸãã ããã§å¥ã®çµç¹ã«åãæ¿ããŸãããã éçºè ãã©ãã«ãšãã«ã®ãŒã泚ãã¹ããã«ã€ããŠããè¯ãéžæãããããã«ãSysdigããåéããŠãããã®ã¯2ã€ãããŸãã ããã¯åºèª¿è¬æŒã§ç€ºãããšããã§ãã ãã®ãã¥ãŒã«ã¯ãçµç¹å ã§èª°ããããã·ã¥ãããã¹ãŠã®ã€ã¡ãŒãžã广çã«äžèŠ§è¡šç€ºãããŸãã ããã¯ç§ã®ãã¹ãã¢ã«ãŠã³ããªã®ã§ãããžãªãªã³ç»åã§ã¯ãããŸããã
ããã«ã¯ãç°å¢ã«ãã£ãŠçµã蟌ãããã«äœ¿çšã§ããããããããŠã³ããããŸãã ä»ãç°å¢ã¯ãSysdigãç§ãã¡ã«äŒããããšãã§ãããã®ã«ãªããŸããã ãããã®ã€ã¡ãŒãžã¯ãç¹å®ã®ã¯ãŒã¯ããŒãåãšããŠç¹å®ã®ã¯ã©ã¹ã¿ãŒã§å®è¡ãããŠããŸãã ãããã«ååãä»ããããè«ççã«ã°ã«ãŒãåãããã§ããŸãã ã€ãŸãããã®ã¯ã©ã¹ã¿ãŒãæ¬çªç°å¢ããã®ä»ã®ã¯ã©ã¹ã¿ãŒãã¹ããŒãžã³ã°ãšåŒã¶ããSysdigãå ±åããååãç¶æããããšãã§ããŸãã æ¬¡ã«ããªã¹ããçµã蟌ãã§ãéçºè ããã®çš®ã®æ å ±ã«é¢å¿ã®ãã人ã ããç°å¢Xã§çŸåšå®è¡ãããŠããã€ã¡ãŒãžãéåžžã«ç°¡åã«ç¥ãããšãã§ããŸããããã¯ãã§ã«å€§ããªäŸ¡å€ã ãšæããŸãã æ¬¡ã«ãããã«äžæ©é²ãã§ã䜿çšäžã®ããã±ãŒãžæ å ±ã®åºçªã§ãã
VEXã®ç޹ä»
äžæ©äžãã£ãŠã VEX ãšããæŠå¿µã玹ä»ããããšæããŸããã€ãŸããVEX 㯠Vulnerability Exploitation eXchange ã®é åèªã§ããããã¯ããœãããŠã§ã¢ã®ãããã€ããŒããç¹å®ã®ããã±ãŒãž(ãµãã³ã³ããŒãã³ããå«ã)ã®ã³ã³ããã¹ãã§ç¹å®ã®CVEã«é¢ããæ å ±ãå ¬éããŠããç§ã¯åœ±é¿ãåããŠããã圱é¿ãåããŠããªãã調æ»äžããšèšãããšãã§ããæ°ãã仿§ã§ãããããã£ãŠãNPMãããžã§ã¯ããªã©ãDockerã€ã¡ãŒãžãã³ã³ã·ã¥ãŒããŒã«æå®ã§ããŸãã圱é¿ãåããŠããããšã確èªããŠãããšèšããŸãããããŠãé¡§å®¢ãæ¶è²»è ã«æåŸ ããŠããããšã«ã€ããŠãã€ã³ã©ã€ã³ã¹ããŒãã¡ã³ããè¡ãããšãã§ããŸããæ¬¡ã«å©çšå¯èœãªããŒãžã§ã³ã«ã¢ããã°ã¬ãŒãããŠã»ãããªã©ãšèšãããšãã§ããŸãã
ãã®å Žåããã®ç¹å®ã®CVEã¯ãç¹å®ã®Dockerã€ã¡ãŒãžã®ã³ã³ããã¹ãã§å¯ŸåŠããããšæããŸãã ãã®Dockerã€ã¡ãŒãžã®äžã§ãç§ã¯1ã€ã®ç¹å®ã®ããã±ãŒãžãèŠãŠããŸãã Scoutã¯æ¢ã«VEXããµããŒãããŠããŸãã VEXã¯ããŒã¿ããŒã¹ã«ã¢ããããŒãããããšãã§ããå éšçã«ã圹ã«ç«ã¡ãŸãã ãŸããç¹å®ã®CVEã®åœ±é¿ãåããŠããªãããšã广çã«äŒããããšãã£ãããå Žåã¯ãç¡èŠããŠããŸããŸããã ãã§ã«ç·©åçãè¬ããããŠããŸãã ãŸãã¯ãããšãã°ãç§ã圱é¿ãåããŠããŠãå šå¡ã次ã«å©çšå¯èœãªåºæ¬ã€ã¡ãŒãž ããŒãžã§ã³ã«ã¢ããã°ã¬ãŒãããå¿ èŠããããšèšãããšãã§ããŸãã ãã®ãã¯ãããžãŒããã®çµ±åã䜿çšããŠããããã®VEXã¹ããŒãã¡ã³ããèªåçã«äœæããScoutãªãŒã¬ããŒãŒã·ã§ã³ã«ãããªãã·ã¥ããŸãã
SysdigããåŸãããããŒã¿ã¯ãåºæ¬çã«ããžãã£ããšãã¬ãã£ãã®VEXã¹ããŒãã¡ã³ãã«ãããã³ã°ãããŸãã 䜿çšäžã®ããã±ãŒãžã«ã€ããŠã¯ããããã®ããã±ãŒãžã䜿çšãããŠãããšèšããŸãã Sysdigã¯ããããã¯å®éã«ããŒããããã©ã³ã¿ã€ã ã§ãããšã®ããšã§ããã®ã§ãç§ãã¡ã¯ã倧äžå€«ãããªãã¯åœ±é¿ãåããŸãããšèšããŸããã 䜿çšãããŠããªãä»ã®ããã±ãŒãžã«ã€ããŠã¯ãå®è¡æã«èªã¿èŸŒãŸããªãããã圱é¿ãåããªããšèšããŸãã ãããŠãããã¯ãã®æç¹ããããªããå©çšã§ããVEXã¹ããŒãã¡ã³ãã§ãã
VEXã¯ããããã®ã¹ããŒãã¡ã³ãã§äœãããããæå®ãããã匷ã䞻匵ããããããŸããã ããªãã¯ããããåãå ¥ããå¿ èŠããããŸãã? ããã¯ãçµå±ã®ãšãããä¿¡é Œãšããããã®çºèšãã©ãããæ¥ãŠããã®ããšããããšã§ãã ç§ã¯åœŒããä¿¡é Œããå¿ èŠããããŸãã? åãå ¥ããå¿ èŠã¯ãããŸãã? Sysdigã®å Žåã圌ããç§ãã¡ã®çµ±åãè³Œå ¥ããããã䜿çšãããŠããªãããšãåãããšããããã¯éåžžã«åŒ·ãã·ã°ãã«ã§ãããéåžžã«åŒ·ãæå³ãæã£ãŠããŸãã 誰ããDocker Hubããã®ä»ã®ã¬ãžã¹ããªã«å ¬éããã€ã³ã¿ãŒãããäžã®ã©ã³ãã ãªVEXã¹ããŒãã¡ã³ããä¿¡çšããªãã§ãã ããã ãã®æ å ±ãã©ãããæ¥ãŠããã®ããå¿ ãæ€èšŒããŠãã ããã
ãªãã£ã·ã£ã«ã€ã¡ãŒãžã«é¢ããŠã¯ãScoutã®äžå¡ãšããŠãªãã£ã·ã£ã«ã€ã¡ãŒãžããŒã ãšç©æ¥µçã«ååãããããã®ã€ã¡ãŒãžã®VEXã¹ããŒãã¡ã³ããæäŸããŠããŸãã ãã¡ããããã®ç¹å®ã®ã±ãŒã¹ã§ã¯ãããã¯ä¿¡é Œã§ããDocker Scoutã®ã€ã³ã¹ããŒã«ã®äžéšã§ããããã®ããŒã¿ãå®éã«èª¿ã¹ãå¿ èŠããããŸãã
ãã®æ å ±ã䜿çšããããšãããšãã©ã®ããã«èŠããŸãã? ã¹ã«ãŠãã³ãã³ããå®è¡ã§ããŸãããããã«ã¯å®è³ªçã«2ã€ã®èŠæ¹ããããŸãã äžçªäžãŸã§ã¹ã¯ããŒã«ããŸãããã ããã¯ããã€ãºã«å ããŠãããã±ãŒãžã䜿çšäžã§ããããšã瀺ãéåžžã«é«ãã·ã°ãã«ã§ãã ãã®è匱æ§ãçå£ã«æ€èšãã¹ãã§ããã? ã€ãŸããäžã«ã¹ã¯ããŒã«ãããšãããã¯Sysdigãæ§æãããŠããã¯ã©ã¹ã¿ãŒã«ãããã€ãããã¹ãã€ã¡ãŒãžã®1ã€ã§ãã ãããŠãäžã«ã¹ã¯ããŒã«ãããšãåºç€ãšãªãããã±ãŒãžãå®è¡æã«èªã¿èŸŒãŸããããããããã®CVEãå®éã«ãã¹ãŠç¢ºèªããå¿ èŠãããããšãããããŸãã
ããã¯ããã®ã䜿çšäžã®ããã±ãŒãžããããã§ç€ºããŠããããšã§ãã ããã¯Sysdigã®çµ±åã«ãããã®ã§ããã®CVEã®ããã±ãŒãžã®ä¿®æ£ããŒãžã§ã³ã«æŽæ°ããããšããå§ãããŸãã ç¹°ãè¿ãã«ãªããŸãããããã¯VEXã¹ããŒãã¡ã³ãã§ãã ä»ã®ãœãŒã¹ããå ¥æããããšãã§ããŸããããã®å ŽåãSysdigã®çµ±åã䜿çšããããšã§ãã©ã³ã¿ã€ã æ å ±ããçŽæ¥ååŸããããšãã§ããŸãã ããã«äžã«ã¯ã圱é¿ãåããŠããªãããžãŒããã¯ã¹ãããããããããšããããã®ã§ãããã¯ã·ã§ã«ã§ããããã¯å¿ èŠãªãããšèšãã®ã¯éåžžã«ç°¡åã§ãã ã¢ã¬ãã¯ã¹ãèšã£ãããã«ãç§ã¯ãããããããåé€ããå¿ èŠããããŸãããŸãã¯ç§ãæ¬åœã«ãããèŠå§ããã¹ãã§ããå¥ã®ææšãèŠããŸã§ããããç¡èŠããŠãåé¡ãããŸããã
ããã«ã¯ããŸããŸãªãã£ã«ã¿ãŒãªãã·ã§ã³ãããã®ã§ããã£ãšèŠãããšãã§ããŸãã å šéšèŠããŠããããããªããã§ããã©ãã VEXã®äœè ãããŠãããã¯ãã³ã³ã·ã¥ãŒããšããŠä¿¡é ŒãããVEXãããªãã·ã£ãŒãæå®ã§ããããšããæåã®è©Šã¿ã§ãã ãã®å ŽåãDocker/Sysdig integrationãšããæååãå ¥ãããšãSysdigããã®ã¹ããŒãã¡ã³ãã®ã¿ãåãå ¥ããããããšã«ãªããŸãã ã©ã³ãã ãªVEXã¹ããŒãã¡ã³ããèŠã€ãã£ããšããŠããããã¯é©çšãããªãã®ã§ãCVEã¯æåŸ ã©ããã«å ±åãããŸãã ããŒã«ã«ãã¡ã€ã«ã·ã¹ãã ããVEXãããŒãããæ¹æ³ãªã©ããããŸãããããã¯ãã®è©±ã®ç¯å²å€ã§ãã
ã»ãŒæ³å®ããŠããå 容ã ãšæããŸãã ãäžæãªç¹ãããããŸãããã 質åã¯ãããŸããããã¹ãŠã¯æããã§ãã 誰ãããã詊ããŸãã? æã®èŠãæ¹ã ã¯ã³ãããŒãã¹ãªãŒãå³ã
çµè«
㯠ããã«ããŒãž ãžã®ãªã³ã¯ãèŠã€ãããã©ããèŠãŠã¿ãŸããã â ããã¯ãããã圹ç«ã€ã§ããããSysdigã¯ç¡æã§ã詊ãããã ããŸããSysdigã«é£çµ¡ããããã®ãã©ãŒã ã«èšå ¥ããŠãã ãããéåžžã«ããŒã¿ããã ãšèããŸããå¶æ¥æ åœè ãšçŽæ¥è©±ãããšã¯ã§ããŸãããããã©ã€ã¢ã«ãåããŠããããããããåããŸããã»ããã¢ããã¯éåžžã«ç°¡åã§ãããã¹ãŠã³ã³ããåãããŠããã®ã§ãéåžžã«ç°¡åã«é²ããããšãã§ãã補åãããã£ãŠæ¥œããæ¹æ³ã§äœ¿çšããŸããå®ãºãã§ãããããããšãããããŸããã
ããã«è©³ãã
- Docker Scout GAã®çºè¡š:ãœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³ã®ããã®å®çšçãªæŽå¯
- Docker Scout 補åããŒãž
- Docker Scout ãã¶ã€ã³ ããŒãã㌠ããã°ã©ã
- Docker Scout ãã詊ããã ãã
- ç«ã¡äžããŠå®è¡ãããã§ãã?ã¯ã€ãã¯ã¹ã¿ãŒãã¬ã€ãã䜿çšãã
- DockerCon 2023 ã®ãã€ã©ã€ã (æ°ãã Docker LocalãCloudãAI/ML ã®ã€ãããŒã·ã§ã³)