ã³ã³ããã»ãã¥ãªãã£ãšDocker Scout
ã³ã³ããã¯ãå€ãã®å Žåãæ¬çªç°å¢ãªã©ã®å®å šãªç°å¢ã§å®è¡ãããŸãã å®å šãªã³ã³ãããäœæããã«ã¯äœãå¿ èŠã§ãã? ã€ã¡ãŒãžã®æ§ç¯æ¹æ³ãšã³ã³ãããšããŠã®å®è¡æ¹æ³ã®äž¡æ¹ããã³ã³ããã®ã»ãã¥ãªãã£ã«åœ±é¿ããŸãã ã³ã³ããã»ãã¥ãªãã£ãšDocker Scoutã®ã»ãã·ã§ã³ã§ã¯ãã³ã³ãããŠãŒã¶ãŒãèªã¿åãå°çšã³ã³ãããLinuxæš©éãã€ã¡ãŒãžã«å«ããã¹ããã®ãåºæ¬ã€ã¡ãŒãžãè匱æ§ãããªã·ãŒã®é©çšã修埩ãªã©ãã»ãã¥ãªãã£ã®è€æ°ã®åŽé¢ã«ã€ããŠèª¬æããŸãã
Â
åã
ãããDocker Container Security and Scoutã§ãã ãã®ãã¬ãŒã³ããŒã·ã§ã³ã§ã¯ãéçšã€ã¡ãŒãžãšã³ã³ãããå«ããã€ã¡ãŒãžãšã³ã³ãããã»ãã¥ãªãã£ã§ä¿è·ããæ¹æ³ã«ã€ããŠèª¬æããŸãã ã€ã¡ãŒãžã®äŸåé¢ä¿ãæ§æããŸãã¯ã©ã³ããã ãªãã·ã§ã³ã倿Žãããšãã¢ããªã±ãŒã·ã§ã³ã®åäœã«åœ±é¿ãäžããå¯èœæ§ããããŸãã æ¬çªç°å¢ã«ãããã€ããåã«ã倿Žãååã«ãã¹ãããŠãã ããã
Â
ç®æ¬¡
- ã³ã³ããã»ãã¥ãªã㣠(0:23)
- ã·ãŒã¯ã¬ãã&ã³ã³ãã (5:02)
- ãã©ã¹ãããããŒã¹ã€ã¡ãŒãž (9:11)
- Docker Scout (10:17)
- ãœãããŠã§ã¢éšå衚 (12:50)
- Docker Scout (15:01)
- ã㢠(16:18)
- ããã«è©³ãã
Â
ã³ã³ããã»ãã¥ãªã㣠(0:23)
ãã®ã»ã¯ã·ã§ã³ã§ã¯ãã³ã³ããã®ã»ãã¥ãªãã£ã«ã€ããŠèª¬æããŸãã Linuxã³ã³ãããšãLinuxããã»ã¹ãä¿è·ããæ¹æ³ãããã³æãå®å šãªã€ã¡ãŒãžãäœæããæ¹æ³ã«çŠç¹ãåœãŠãŸãã æåã«è©±ãã®ã¯ãrootãŠãŒã¶ãŒãšérootãŠãŒã¶ãŒã§ãã Root ã¯ãã³ã³ããã®ããã©ã«ããŠãŒã¶ãŒã§ãã ãããé root ãŠãŒã¶ãŒã«å€æŽã§ããç¹ã«æ¬çªç°å¢ã§ã³ã³ãããå®è¡ããŠããå Žåã¯å€æŽããå¿ èŠããããŸãã ããã¯ãããã€ãã®ç°ãªãæ¹æ³ã§è¡ãããšãã§ããŸãã ããã¯ãDockerfile ãš Docker run ã³ãã³ãããŸã㯠Docker Compose ã§è¡ãããšãã§ããŸãã ããã§ã¯ãæåã®ãªãã·ã§ã³ãšããŠãDockerfileå ã«ãŠãŒã¶ãŒ(myuser)ã远å ããŠããŸãã ã€ãŸããDockerfile ãå®è¡ããããšããã® root ãŠãŒã¶ãŒã¯ããã®ç¹å®ã®ã³ã³ãããŒãå®è¡ãããšãã«æå®ãã myuser ã«å€æŽãããŸãã ããã§ã run ã³ãã³ãã§åãããšãè¡ãããšãã§ããŸãã Docker ã® -user ãå®è¡ãããšãã°ã«ãŒã ID ãšãã®äžã§æå®ããããŠãŒã¶ãŒ ID ã衚瀺ãããŸãã ãŸãã¯ãäžã®äŸã§ã¯ãCompose ãã¡ã€ã«ãèŠãããšãã§ããŸãã ãã® Compose ãã¡ã€ã«å ã§ã¯ããã©ã°ã€ã³ãããŠããç°å¢å€æ°ã®ãŠãŒã¶ãŒ ID ã§æå®ãããŠãããŠãŒã¶ãŒã確èªã§ããŸãã äžçªäžã«ããã®ã¯ããŠãŒã¶ãŒã®æç€ºãšãã®ããŸããŸãªäœ¿ç𿹿³ã«ã€ããŠè©³ãã説æããããã°ã§ãã®ã§ããã²ã芧ãã ããã
user ã³ãã³ãã§å®è¡ã§ãããã¹ãŠã®çš®é¡ã®æäœãæ£ç¢ºã«ç€ºãããã®ãã 1 ã€ã®äŸã瀺ãããã«ãDocker init ã add user ã³ãã³ããçæããæ¹æ³ã次ã«ç€ºããŸãã ããã§ã¯ãããã«è¿œå ãããŠããããŸããŸãªãªãã·ã§ã³ãããããããããšãããããŸãã ãã¹ã¯ãŒããç¡å¹ã«ããŠããŸãã å®¶ã¯ãªããšèšã£ãŠããã®ã§ãã ãã°ã€ã³ããªããšèšã£ãŠããŸãã ã·ã§ã«ã¯ãããŸããã å®¶ãäœãå¿ èŠã¯ãããŸããã ããã«æå®ãããŠãŒã¶ãŒIDã¯ãå¿ èŠã«å¿ããŠadd userã³ãã³ãã«è¿œå ã§ãããã¹ãŠã®ãªãã·ã§ã³ã§ãã å¿ é ã§ã¯ãããŸãããããã®æ¹æ³ã§è¡ãããšã§ãã€ã¡ãŒãžãšã³ã³ããã®ã»ãã¥ãªãã£ã匷åããã®ã«åœ¹ç«ã€ããšã¯ç¢ºãã§ãã æ¬¡ã¯ãèªã¿åãå°çšã³ã³ãããšLinuxæ©èœã§ãã ããã©ã«ãã§ã¯ãã³ã³ãããå®è¡ããŠããå®è¡äžã«ãã®ã³ã³ããã®ãã¡ã€ã«ã·ã¹ãã ã«æžã蟌ãããšãã§ããŸãã ããªãã¯å ¥ã£ãŠããã«å€æŽãå ããããšãã§ããŸãã ã¢ããªã±ãŒã·ã§ã³ã¯ãå®è¡äžã«å€æŽãå ããããšãã§ããŸãã æ¬çªç°å¢ã§ã¯ããããæãŸãªãå ŽåããããŸãã æ¬çªç°å¢ã§ã¯ç°å¢ãäžå€ã«ããããããããŸããããããã¯çã«ããªã£ãŠããŸãã ãããè¡ãããã«ãç§ãã¡ãè¡ã£ãŠããã®ã¯ãèªã¿åãå°çšæ©èœãå®è¡ãããªãã·ã§ã³ãæäŸããããšã§ãã ã€ã¡ãŒãžãèªã¿åãå°çšã«ãããšãã€ã¡ãŒãžã«æžã蟌ãããšãã§ããªããªããŸãã ãã¡ããããã®åé¡ã®åé¡ã¯ãã¢ããªã±ãŒã·ã§ã³ãåäœäžã«æžã蟌ãå¿ èŠããããšããããšã§ãã ããšãã°ãäžæãã£ã¬ã¯ããªãžã®ãã®ã ããã«æžã蟌ãããšãã§ããå¿ èŠããããããããŸããã ãã®ãããèªã¿åãå°çšãã©ã°ã䜿çšãããšãtempfs ãšåŒã°ãããã®ãéããŠãããè¡ãããšãã§ããŸãã ã€ãŸããtempfsãè¡ã£ãŠããããšã¯ããã¡ã€ã«ã·ã¹ãã ã«æžã蟌ã代ããã«ã¡ã¢ãªã«æžã蟌ãããšãèš±å¯ããããšã§ãã ã€ãŸãããã®ã³ã³ããã忢ãããšããã® tempfs ã¡ã¢ãªé åã¯æ¶ããŸãã ç¹å®ã®æç¹ã§ã¯ä¿åãããŸããã ããããäžæçã«ç©äºãæžãåºãã ãã§ããã°ãããã¯åé¡ã§ã¯ãããŸããã ãããã£ãŠãããã©ã«ãã§ã¯ãèªã¿åãå°çšãã©ã°ã䜿çšãããšãäžæãã£ã¬ã¯ããªã¯ tempfs ã§ã«ããŒãããŸãã ãããããã®ç¹å®ã®ãã£ã¬ã¯ããªæ§é ã«ãæžã蟌ãå¿ èŠãããå¥ã®ãã®ãããå Žåã¯ã©ãã§ããããã ãŸããèªåã§tempfsã䜿ãããšãã§ããŸãã tempfsã«ã€ããŠã¯ãããã«ãªã¹ããããŠãããªã³ã¯ã«ç§»åããtempfsã䜿çšããä»ã®ãã£ã¬ã¯ããªãæå®ã§ããŸãã ããŠãããªããç©ãä¿åããããã«ã¡ã¢ãªã䜿çšããŠããå Žåã¯ãã¡ã¢ãªã®å¶çŽã念é ã«çœ®ãå¿ èŠãããããšãèŠããŠãããŠãã ããã ã¡ã¢ãªãäžè¶³ãããšãå®éã«äœããæžã蟌ãããã®ã¹ããŒã¹ãäžè¶³ããããšã«ãªããŸãã ã¹ã©ã€ãã®ãã1ã€ã®èŠçŽ ã¯ãLinuxã®æ©èœã§ãã ã³ã³ãã㯠Linux ããã»ã¹ã§ãããããä»ã® Linux ããã»ã¹ãšåæ§ã« Linux æ©èœãåããŠããŸãã å³åŽã«è¡šç€ºãããŠããå Žåã¯ãããã©ã«ãã§å²ãåœãŠãããŠããæ©èœã§ãã ãããã®æ©èœã®äžéšã¯ããã®ããã»ã¹ãæ¬çªç°å¢ã§å®è¡ã§ããããã«ããããã®ã§ã¯ãªããããããŸãããããšãã°ãã°ã«ãŒãIDã匷å¶çµäºããããèšå®ãããããŠãŒã¶ãŒIDãèšå®ãããããŸãã ãããã£ãŠãæ©èœãåé€ããã远å ããããæ±ºå®ã§ããŸãã å·ŠåŽã«âcap-drop=ALLãšæžãããŠããŸãã ãããè¡ã£ãŠããã®ã¯ãæ¬çªç°å¢ã§Linuxã®æ©èœããã¹ãŠåé€ããããªããšãããã®ã§ãã ãŸããããã以å€ã«ããå¿ èŠã«å¿ããŠè¿œå ã§ããæ©èœããããããããŸãã ãŸããå¿ èŠã«å¿ããŠãåé€ãŸãã¯è¿œå ããåã ã®ãã®ãéžæã§ããŸãã ããã®2çªç®ã®ãªã³ã¯ã«ã¯ããã¹ãŠã®ç°ãªãæ©èœã®ãªã¹ããããã远å ãŸãã¯åé€ããæ©èœã決å®ã§ããŸãã
Â
ã·ãŒã¯ã¬ãã&ã³ã³ãã (5:02)
ããŠãã·ãŒã¯ã¬ãããšã³ã³ããã«ã€ããŠå°ãã話ãããŸãããã ã³ã³ããã¯ãå€ãã®å Žåãå®è¡ããããã«ã·ãŒã¯ã¬ããã«ã¢ã¯ã»ã¹ããå¿ èŠããããŸãã ãŠãŒã¶ãŒåããã¹ã¯ãŒããªã©ãTLSèšŒææžãããŒãSSHããŒãããŒã¿ããŒã¹ããã®ä»ã®å éšãµãŒããŒã®ååãã¢ãã¬ã¹ãªã©ã®éèŠãªããŒã¿ãªã©ãããŸããŸãªãã®ããããŸãã ã§ã¯ããããã®ç§å¯ã«ã¢ã¯ã»ã¹ããå¿ èŠãããå Žåããã®ç§å¯ã¯ã©ãããå ¥æããã®ã§ãããã? ããŠãããã«ã¯ããŸããŸãªãªãã·ã§ã³ããããŸãã ããã€ãã®æªããªãã·ã§ã³ã1ã€ã®å€§äžå€«ãªãªãã·ã§ã³ããããŠ1ã€ã®è¯ããªãã·ã§ã³ã ãœãŒã¹ã³ãŒãå ã®ã·ãŒã¯ã¬ãããèŠã€ããããšãã§ããã®ã§ããœãŒã¹ã³ãŒãã«ã¢ã¯ã»ã¹ã§ãã人ãªã誰ã§ããããèŠãããšãã§ããŸãã ãŸããã·ãŒã¯ã¬ããã倿Žããå¿ èŠãããå Žåã¯ãã¢ããªã±ãŒã·ã§ã³ãåæ§ç¯ããå¿ èŠããããŸãã ããããç»åã«çŽæ¥çµã¿èŸŒãããšãã§ããã®ã§ãç»åã«ã¢ã¯ã»ã¹ã§ãã人ãªã誰ã§ãèŠãããšãã§ããŸãã ãŸããã·ãŒã¯ã¬ããã倿Žããå¿ èŠãããå Žåã¯ãã€ã¡ãŒãžãåæ§ç¯ããå¿ èŠããããŸãã å®è¡ã¹ã¯ãªããã«æ ŒçŽããŠããœãŒã¹ç®¡çã«ããã¯ã¢ããããããšãã§ããŸãã ããã§ãã€ã¡ãŒãžã倿ŽããŠãã€ã¡ãŒãžãåæ§ç¯ããå¿ èŠããªããªããŸãããããœãŒã¹ç®¡çã«ã¢ã¯ã»ã¹ã§ãããŠãŒã¶ãŒã¯åŒãç¶ãã€ã¡ãŒãžã衚瀺ã§ããŸãã ãããç°å¢å€æ°ã«å ¥ããããšãã§ããŸãã ããã¯ãç§å¯ããã®ãããªããšãè¡ãæ¹æ³ãšããŠãã瀺ãããŸãã ããããç°å¢å€æ°ãé 眮ããããããšãã°ãããããã³ããŒã«ãã³ããããããããšãç°å¢å€æ°ãšããŠè¡šç€ºãããŸãã ãŸãããã®ãã·ã³äžã®ãã¹ãŠã®ããã»ã¹ã§äœ¿çšã§ããŸãã ã§ãããããããæ¬åœã«è¯ãéžæè¢ã§ã¯ãããŸããã ããããã¡ã€ã«ã«å ¥ããŠãããã»ã¹ãç§å¯ãååŸããå Žæãèªèã§ããããã«ããããšãã§ããŸããããã®éçšãã·ã³ã§äœ¿çšã§ããŸãã ããã¯åé¡ãããŸããã ãããã£ãŠãç§å¯ãã©ãã§å ¥æããããç¥ã£ãŠããã®ã¯ããã»ã¹ã ãã§ãã ãããããã·ã³ã«ã¢ã¯ã»ã¹ã§ãã人ãªã誰ã§ããã®ç§å¯ãèŠã€ãã«è¡ãããšãã§ããŸãã ãããŠæåŸã«ãç§å¯ã®ä¿ç®¡åº«ããããŸãã ã€ãŸããããã¯ã·ãŒã¯ã¬ãã管çã¢ããªã±ãŒã·ã§ã³ã«ãªããŸãã ãããŠãã·ãŒã¯ã¬ãããèŠæ±ããŠããããã»ã¹ã®ã¿ãããã®ããŒã«ãããå®éã«ã·ãŒã¯ã¬ããã«ã¢ã¯ã»ã¹ã§ããŸãã ããã¯ãã»ãã¥ãªãã£ã®é«ãç°å¢ã§ã·ãŒã¯ã¬ãããåŠçããå Žåã«æšå¥šãããæ¹æ³ã§ãã
ããŠããã®ç¹å®ã®ããã»ã¹ã®å®è¡æ¹æ³ã«ã€ããŠå°ãã話ãããŸããã ã§ã¯ããã®ã€ã¡ãŒãžã®æ§ç¯ã«ã€ããŠå°ãã話ãããŸãããã æ¬çªç°å¢ãŸãã¯ã»ãã¥ã¢ã¿ã€ãã®ç°å¢ã®ã€ã¡ãŒãžãæ§ç¯ããéã«èæ ®ãã¹ãç¹ã¯äœã§ãã? ãŸãããã®ç»åã«åã£ãŠãããã®ãå¶éããããšèããŠããŸãã ãã®ãããéçºããŒã«ãšè£œåã€ã¡ãŒãžãå¶éããããšèããŠããŸãã æ¬çªç°å¢ã§ã¢ããªã±ãŒã·ã§ã³ãå®è¡ããããã«å¿ èŠãªãã®ã ããå¿ èŠã§ãã ã€ãŸãããœãŒã¹ã³ãŒãã¯å¿ èŠãªããšããããšã§ãã IDEã¯å¿ èŠãããŸããã ã³ã³ãã€ã©ã¯å¿ èŠãããŸããã ãããã¬ã¯å¿ èŠãããŸããã ãããã€ã§ããªããã«ãã¢ãŒãã£ãã¡ã¯ãã¯å¿ èŠãããŸããã åºæ¬çã«ãéçºè ãæ¬çªç°å¢ã§å¿ èŠãšããããŒã«ã¯å¿ èŠãããŸããã ãã®éçšã€ã¡ãŒãžã«ã¯ããã®ã¢ããªã±ãŒã·ã§ã³ãå®è¡ããããã«å¿ èŠãªãã®ã ããå«ããå¿ èŠããããŸãã OSããŒã«ã«ã€ããŠãåãããšãèšããŸãã ã³ã³ãããã¢ããªã±ãŒã·ã§ã³ãå®è¡ããããã«å¿ èŠãªãã®ã ããæã€ã¹ãã ãšèšã£ãŠãããªããããã¯ããã±ãŒãžã€ã³ã¹ããŒã©ãŒããšãã£ã¿ãŒãCurlã®ãããªãããã¯ãŒã¯ããŒã«ãããã«ã¯Pingã®ãããªãã®ãç¹ã«Sudoã®ãããªãã®ã¯å¿ èŠãªãããšãæå³ããŸãã
ã¢ããªã±ãŒã·ã§ã³ãå®è¡ããŠããã ãã§ããã°ããã®ãããªãã®ã¯å¿ èŠãããŸãããããã¯ãç§ãã¡ã®ãããã¯ã·ã§ã³ã€ã¡ãŒãžãè¡ãã¹ãããšã§ãã ããã§ã©ããŸã§è¡ããã®ã? ããŠãããŒã¹ã€ã¡ãŒãžãããã«å¶äœãç¶ããããšãã§ããŸãã ç§ãã¡ã¯ãã»ãšãã©å«ãŸããŠããªãç¹å®ã®ãã£ã¹ããªãã¥ãŒã·ã§ã³ã¬ã¹ããŒã¹ã€ã¡ãŒãžã«ç§»åããããšãã§ããŸãããã¹ã¯ã©ããã€ã¡ãŒãžãšåŒã°ãããã®ãŸã§è¡ãããšãã§ããŸãã ã¹ã¯ã©ããç»åã«ã¯ã»ãšãã©äœãå ¥ã£ãŠããªãã®ã§ãããããå§ããããšãã§ããŸãã ãããŸã§ãããŒã¹ã€ã¡ãŒãžãããã®ãåé€ããŠãã¢ããªã±ãŒã·ã§ã³ãå°ããããããšã«ã€ããŠè©±ããŠããŸããã ããã¯çŽ æŽãããããšã ãšèšã£ãŠããŸãããããæç¹ã§ãã¢ããªã±ãŒã·ã§ã³ãå®è¡ããããã«å®éã«å¿ èŠã«ãªãå¯èœæ§ã®ãããã®ãåãåãå§ããããšãã§ããããšãçè§£ããå¿ èŠããããŸãã ãããã£ãŠãã¹ã¯ã©ããã®ãããªãã®ã«ãŸã§èžã¿èŸŒãå Žåã¯ãã¢ããªã±ãŒã·ã§ã³ãå¿ èŠãšãããã¹ãŠã®åºç€ãã¯ãããžãŒãçè§£ããå¿ èŠããããŸãã ããšãã°ãã¹ã¯ã©ããã§äœæ¥ãè¡ããšããããã¯ãŒã¯ã©ã€ãã©ãªãDNS over TCPã®ãããªãã®ããµããŒãããŠããªãããšã«æ°ä»ããããããŸããããŸããKubernetesã¯ã©ã¹ã¿ã§ã¢ããªã±ãŒã·ã§ã³ãå®è¡ããããã«ã¯ãããå¿ èŠã§ããããšã«æ°ã¥ããããããŸããã ãããã¯ãããŒã¹ã€ã¡ãŒãžãå¯èœãªéãæå°éã®ç¶æ ã«ãŸã§åãåãããšããã»ã©ãèæ ®ããªããã°ãªããªãçš®é¡ã®ãã®ã§ãã
Â
ãã©ã¹ãããããŒã¹ã€ã¡ãŒãž (9:11)
ããŠãããŒã¹ã€ã¡ãŒãžãåãããšã«ã€ããŠè©±ããŸããã ã¢ã«ãã€ã³ãããŒã¹ã€ã¡ãŒãžãšããŠéžãã ãšä»®å®ããŸãããã æ¬¡ã®åé¡ã¯ããã®ã¢ã«ãã€ã³ã¯ã©ãããæã«å ¥ããã®ããšããããšã§ãã 誰ããããäœããã©ã®ããã«äœã£ãã®ããã©ããã£ãŠç¥ãããšãã§ããŸãã? ã§ããããã³ãã¥ããã£ã®ç»åãäŸãã°ã¹ãŒããŒãšãªãŒãã®ã¢ã«ãã€ã³ã®ãããªãã®ã䜿ãããšãã§ããŸããã誰ãäœã£ãã®ãããªãäœã£ãã®ããå®å šãã©ãããããããŸããã ããè¯ããªãã·ã§ã³ã¯ãããã®äžéšã«ç€ºãããŠããããã«ãDockerå ¬åŒã€ã¡ãŒãžã®ãããªãã®ã䜿çšããããšã§ããããã¯ãDockerå ¬åŒã€ã¡ãŒãžã§ããããšã瀺ãã¿ã°ãä»ããAlpineã§ãã ã€ãŸããDockerãç¬èªã«æ§ç¯ããããDockerãã³ãã¥ããã£ãšçŽæ¥é£æºããŠæ§ç¯ãç£ç£ãããã®ã©ã¡ããã§ãã ã ãããç§ãã¡ã¯ãã®äžã«äœãå«ãŸããŠããããæ£ç¢ºã«ç¥ã£ãŠããŸãã Docker æ€èšŒæžã¿ã®çºè¡å ã€ã¡ãŒãžã¯ãRed HatãSuseãGrafana ãªã©ã®ããŒãããŒããã®ãã®ã§ããããããã®åºæãæ¯ããŠããŸãã ãããŠãããŒãåãããã€ã¡ãŒãžããããŸãã 匷åãããã€ã¡ãŒãžãšã¯ãCVE ãåé€ãããSLA ãèšå®ãããã€ã¡ãŒãžã§ãã ãããå©çšå¯èœãªå¥ã®ãªãã·ã§ã³ã§ãã
Â
Docker Scout (10:17)
ããŠãåã ã®ã€ã¡ãŒãžã®ä¿è·ããé¢ããŠãDocker Scoutãšãä¿¡é Œã§ãããœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³ãæäŸããããã«ããã«äœãæäŸã§ãããã«ã€ããŠè©±ãå§ããŸãããã ã§ã¯ãéçºããã»ã¹ãèŠãŠã¿ãŸãããã ã§ããããéçºè ãšããŠããã®å Žåã¯ç§ããããã¥ãŒãµãŒã«ãªããŸãã ç§ã¯ãã¢ããªã±ãŒã·ã§ã³ãæžããŠãããšãã«ãã¹ããã©ã¯ãã£ã¹ã«åŸãããã«è©Šã¿ãã€ããã§ãã ç§ã¯èªåã®ã³ãŒãããœãŒã¹ã³ãŒããæã£ãŠããŠããããæžãã€ããã§ãã ç§ã¯ãåŒã蟌ãäºå®ã®ããŸããŸãªäŸåé¢ä¿ãæã€ããšã«ãªããŸãã ã¢ããªã±ãŒã·ã§ã³ãæ£ããåäœããããã«å¿ èŠãªããŸããŸãªã©ã€ãã©ãªããã®ä»ã®ãã®ããããŸãã Dockerfileã䜿çšããŠãããããã«ãããŸãã ãã®æç¹ã§ãäœããã®è匱æ§ã¹ãã£ã³ãè¡ãããããšã«ãªããŸãã äœæãããããã±ãŒãžãã€ã¡ãŒãžããããŸãã ãããŠãããã¯æ¶è²»è ã«å±ããããã®ã§ãã ãã®ããã»ã¹ã§ã¯ããã¹ããã©ã¯ãã£ã¹ã«åŸã£ãŠã¿ãããšæããŸãã ç§ã¯ãèªåãæžããŠããã³ãŒããå®å šã§ããããšã確èªããããšæããŸãã ååŸããŠããäŸåé¢ä¿ãã人æ°ããããå®å šã§ãããšæãããé©åãªãã®ã§ããããšã確èªããããšæããŸãã ãã«ãã®ãã¹ããã©ã¯ãã£ã¹ã«åŸãããã«åªããŸãã ã ãããéçºè ãšããŠã®ç§ã¯ããªãæ°åãè¯ãã§ãã ç§ã¯ããããéä¿¡ãããå®å šãªã³ãŒãã§ããããšã確èªããããã«ãåžžèçãªããšãããããšããŸããã ã ãããèªåã®ä»äºã¯ããªãããŸããã£ããšæããŠããŸãã
ã§ããããããç§ããã®ããã»ã¹ã®æ¶è²»è ã§ããããã®ãã¹ãŠãéããç®±ã§ãããäœãèµ·ãã£ãã®ãããããªããšããããçªç¶ãããããçš®é¡ã®çåãæ¹§ããŠããŸãã 誰ããããäœã£ãã®ã§ãã? ãœãŒã¹ã³ãŒãã䟵害ãŸãã¯æäœãããŠããªãããšã確èªããã«ã¯ã©ãããã°ããã§ãã? ãŸãã¯ãäŸåé¢ä¿ãããªããèšããšããã®ãã®ã§ããããšãã©ããã£ãŠç¥ãããšãã§ããŸãã? ãŸãã¯ããã«ããæ¹ãããŸãã¯å€æŽãããŠããªãããšããŸãã¯ããã±ãŒãžã䟵害ãããããšãã©ã®ããã«ç¢ºèªã§ããŸãã? ãããšããããããã¹ãŠå€ããŠãä»ã§ã¯ããã«å¯Ÿããè匱æ§ããããããããšãããã©ãã§ãããã? ãããã¯ããœãããŠã§ã¢ã®æ¶è²»è ãå®éã«äœãåŸãŠããã®ããæ¬åœã«çè§£ãããããèªåã®ç°å¢ã«ãšã£ãŠå®å šã§ããããšã確èªããããšæã£ãŠããããã«å°ããŠããéèŠãªè³ªåã§ãã ãã®ããããããã®åé¡ãå®çŸ©ãã解決ããããã®ããŒã«ãå¿ èŠã§ãã
ããŠããããè¡ãããã«å©çšã§ããããŒã«ãããã€ããããŸãã 1ã€ç®ã¯ããœãããŠã§ã¢éšå衚(SBOM)ã§ãã ããã«ããããã®ãœãããŠã§ã¢ã¢ãŒãã£ãã¡ã¯ãã«äœãå«ãŸããŠããããããããŸãã ã€ãŸãããã®äžã«ããããŸããŸãªããã±ãŒãžããã¹ãŠããããŸãã æ¬¡ã¯æ¥æŽã§ãã æ¥æŽãšã¯ãéºç©ã®æŽå²ããããã©ãããæ¥ãã®ãã誰ãäœã£ãã®ããã©ã®ããã«äœã£ãã®ãã蚌æãããã®ã§ãã ãããŠæåŸã«ãããã±ãŒãžã®çœ²åããããŸãã ããã¯ãåºæãšãã®ä¿¡é Œæ§ãæ€èšŒããèªèšŒã§ãããæ¶è²»è ã¯ãèªåãåŸãŠãããã®ãå®éã«ããã§ãããããçš®ã®ä»£æ¿åã§ã¯ãªãããšãããããŸãã
Â
ãœãããŠã§ã¢éšå衚 (12:50)
ããŠãããã§ã¯ããœãããŠã§ã¢ã®éšå衚ã«ã€ããŠããå°ã詳ãã説æããŸãããã ããã§ãé£åã®æ é€ãšæåã®ãªã¹ãããããŸãã ããã¯ãã¹ãŠã®é£åã«å¿ èŠã§ãããéåžžã«åœ¹ç«ã¡ãŸãã ã«ããªãŒãã³ã¬ã¹ãããŒã«ãªã©ãããããæ å ±ãåŸãããšãã§ããŸãã ãŸããéé ã§ææã®ãªã¹ãã衚瀺ãããŸãã ãããã£ãŠãããã«äœããããããããŠæ¬¡ã®ã¢ã€ãã ã«å¯ŸããŠåã¢ã€ãã ãã©ãã ããããã確èªã§ããŸãã ãŸããäžçªäžã«ã¯ãã¢ã¬ã«ã®ãŒãæã€äººã ã«ãšã£ãŠéèŠãªç¹å®ã®ã¢ã¬ã«ã²ã³ãå«ãŸããŠãããã©ããã«ã€ããŠã®ãã®ããããŸãã ããã«ããããããã®Cookieãšãã®å 容ã«ã€ããŠå€ãã®æ å ±ãåŸãããŸãã ã ããããã®ã¯ãããŒãé£ã¹ããã©ããã«ã€ããŠãæ å ±ã«åºã¥ããæ±ºå®ãäžãããšãã§ããŸãã ã§ã¯ããœãããŠã§ã¢ã«ã€ããŠãåãããšãã§ãããšãããã©ãã§ãããããããããå®éã«ã¯ãããããåªããããšãã§ãããšãããã©ãã§ããããã ãœãããŠã§ã¢éšå衚ã䜿çšãããšãããã±ãŒãžãšãªãæåã®ãªã¹ããæäŸããã ãã§ãªããå®éã«ãããã®ããã±ãŒãžã®ããããã«é¢ããæ å ±ããµãã©ã€ã€ãŒã誰ã§ããããããŒãžã§ã³ãäœã§ãããããããã®éã®äŸåé¢ä¿ãäœã§ããããæäŸã§ããŸãã 圌ãã®ä¿¡é Œæ§ã®ããã«ããã®äœè ã¯èª°ã§ããã ãããã®æ å ±ã¯ãã¹ãŠããœãããŠã§ã¢ã®éšå衚ã«å«ããããšãã§ããŸãã ã€ãŸããCookieã¬ãã«ã®æ å ±ãæäŸããã ãã§ãªãããã以äžã®æ å ±ãæäŸãããœãããŠã§ã¢ãã«ããããªã¢ã«ãé¢é£ä»ããããŠãããã®ç¹å®ã®ã¢ãŒãã£ãã¡ã¯ããã©ã®ããã«ä¿¡é Œãããã«ã€ããŠãããé©åãªæ±ºå®ãäžãããšãã§ããŸãã
ãœãããŠã§ã¢éšå衚ã«ã¯ããŸããŸãªåœ¢åŒããããŸãã ãœãããŠã§ã¢ããã±ãŒãžã®ããŒã¿äº€æãšãµã€ã¯ãã³DXããããŸãã Scout ã¯ããããã®ç°ãªã圢åŒã®äž¡æ¹ããµããŒãããŠããŸãã ãŸããVulnerability Exploitability Exchange(èåŒ±æ§æªçšå¯èœæ§äº€æ)ãŸãã¯VEXããã¥ã¡ã³ããšåŒã°ãããã®ãããããªãã·ã§ã³ã§è¿œå ããããšãã§ããŸãã VEXã®ããã¥ã¡ã³ããè¡ã£ãŠããããšã¯ããã®ç¹å®ã®ããã±ãŒãžã«ãã®ç¹å®ã®è匱æ§ããããšèšããããã«ããŠããããšã§ãããäœããã®çç±ã§ã³ãŒãã®ãã®éšåãå®éã«å®è¡ããŠããªãããããã®è匱æ§ãæªçšããããšã¯ã§ããŸããã ããããããšã§ã確ãã«ãã®è匱æ§ã¯ããããå¿é ããå¿ èŠã¯ãªãã®ã ãšçè§£ããããšãã§ããŸãã ã€ãŸããè匱æ§ã«é¢ããæžå¿µããã®ãããªããšã®éšã ããã«ããã£ãŠããã®ã§ãã
Â
Docker Scout (15:01)
Docker Scout ã§ã¯ãããŸããŸãªæ©èœãæäŸããŠããŸãã Docker Hubå ã«ã¯ãããŒã¹ã€ã¡ãŒãžã䜿çšã§ãããã®ä»ã®ã€ã¡ãŒãžããã«ããŠã³ããããã®ä¿¡é Œã§ããã³ã³ãã³ãããããŸãã ç§ãã¡ã¯ããœãŒã¹ãããã«ãããã±ãŒãžãŸã§ãSDLCãéããŠããªã·ãŒè©äŸ¡ãè¡ã£ãŠããã誰ããäœãèµ·ãã£ãŠããã®ãã確èªã§ããããã«ãããã®ããã»ã¹å šäœã«é¢ããèšé²ã·ã¹ãã ãæäŸããŠããŸãã ç§ãã¡ã¯çããã®ããã»ã¹ã®ã©ãã«ç»åããããã«é¢ä¿ãªããç»åã§äœãèµ·ãã£ãŠããããçè§£ããŠããŸãã Scoutã¯ããµãã©ã€ãã§ãŒã³å šäœã«ããã£ãŠå®çšçãªæŽå¯ãæäŸããŸãã ãããã£ãŠãDocker Scoutã䜿çšãããšããœãããŠã§ã¢ã®å質ã確ä¿ãã顧客ããä¿¡é Œãããå®è£ ããŠããã¬ãŒãã¬ãŒã«ãŸãã¯ããªã·ãŒã«æºæ ããŠããããšã確èªã§ããŸãã
ã§ã¯ãã¹ã«ãŠãã¯å®éã«äœãããŠããã®ã§ãããã? ããã§è©³ãã説æããŸãããã ãŸããèåŒ±æ§æ å ±ã®ããŸããŸãªãœãŒã¹ããŸãšããããšã§ãã ããŠãè匱æ§ã«ã€ããŠè©±ããšãã圌ãã¯ãã°ãã°åœå®¶è匱æ§ããŒã¿ããŒã¹ã«ã€ããŠè©±ããŸãã ããã¯ãå€ãã®äººãè匱æ§ãååŸããããã«è¡ãå Žæã§ãã ãããããããã®ä»ã®ããŒã¿ããŒã¹ãè匱æ§ã®ã«ã¿ãã°ã®å€ãã¯ãå®éã«ã¯è匱æ§ããŒã¿ããŒã¹ãããè匱æ§ã«ã€ããŠè©³çްã«èª¬æããŠããããšãããããŸããã ç§ãã¡ãè¡ã£ãŠããã®ã¯ãããããã¹ãŠã®ç°ãªããœãŒã¹ã1æéã«æå€§3åãã«ããããããã¹ãŠã1ã€ã®ããŒã¿ããŒã¹ã«ãŸãšããããšã§ãããããã¹ãŠã®ç°ãªããœãŒã¹ããæé©ãªæ å ±ãå ¥æãããœãããŠã§ã¢ã«ã©ã®ãããªè匱æ§ãããããå®éã«çè§£ã§ããããã«ããããšã§ãã
ããŠãããã®æ¬¡ã®éšåã¯ãè匱æ§ãããæ©ãèŠã€ããŠä¿®æ£ããããšã§ãã ç§ãã¡ã¯ã人ã ãCIããã»ã¹ããã¹ãããã»ã¹ããŸãã¯æ®å¿µãªããæ¬çªç°å¢ã§è匱æ§ãèŠã€ããŠããã®ãç®ã®åœããã«ããŠããŸãã å¯èœã§ããã°ãããã»ã¹ã®æ©ã段éã§è匱æ§ãèŠã€ããæ¹ãã¯ããã«è¯ãã§ãããã ãã®ãããéçºè ã¯ã䜿çšããŠãããœãããŠã§ã¢ã«ã©ã®ãããªè匱æ§ãããããçè§£ããããããä¿®æ£ããæ¹æ³ã«é¢ããæ å ±ãå ¥æã§ããããã«ããããšèããŠããŸãã ããã¯ãéçºè ããã®æ å ±ãèŠãããšãã§ãããŸã£ããç°ãªãããã»ã¹ããŸã£ããç°ãªãèŠæ¹ã§ã¯ãªãã仿¥ã®ãœãããŠã§ã¢ãšã®èªç¶ãªéšåã§ããããã«ãéçºè ããã®æ å ±ãèŠãããšãã§ããããã«ããããã«ãç§ãã¡Dockerã«ãšã£ãŠéåžžã«éèŠã§ãã ããããè匱æ§ã«ã€ããŠã ã話ããŠããããã§ã¯ãããŸããã ãŸããããªã·ãŒã«ã€ããŠã話ããŠããŸãã ç§ãã¡ã¯ãããªã·ãŒãèšå®ããéçºè ãCIãSDLCå šäœããããã®ããªã·ãŒãéµå®ã§ããããã«ããããšèããŠããŸãã ãä¿®æ£ã§ããé倧ãªè匱æ§ã¯ãªãããšãããããªããšãããããåºæ¬ã€ã¡ãŒãžã¯ææ°ã®ç¶æ ã«ãããããã䜿çšããããªãç¹å®ã®GPLã©ã€ã»ã³ã¹ã䜿çšããŠããããããããã¯ãå®è¡ãã¹ãã§ãªãã®ã«rootãŠãŒã¶ãŒãšããŠå®è¡ããŠããªããããšãã£ãããšããããŸãã ãã®ãããããªã·ãŒã¯è匱æ§ãè¶ ããããŸããŸãªãã®ã«åºã¥ããŠããå¯èœæ§ããããŸãã
ãããã£ãŠã次ã¯CIããã»ã¹èªäœãèŠãŠãããŸãã ãããã£ãŠãCIããã»ã¹ããããéçºè ãè¡ã£ãŠããããšãšã¯ç°ãªãè匱æ§ã®è©äŸ¡æ¹æ³ãããå Žåãè匱æ§ãäœã§ããããã©ã®ããã«è©äŸ¡ãããã©ã®ããã«ä¿®æ£ãããŠããããçè§£ããããšããã®ã«åé¡ãçºçããå¯èœæ§ããããŸãã Docker Scout ã CI ããã»ã¹ã«çŽæ¥çµ±åããæ©èœãæäŸããŠããŸãã ãã®ããã«ãéçºãšCIã®äž¡æ¹ã§åãè©äŸ¡ããã»ã¹ãé²è¡ãããããè匱æ§ãšã¯äœããVEXã¹ããŒãã¡ã³ããªã©ããããã©ããã«ã€ããŠå šå¡ãåæããŸãã
ããŠã次ã«è匱æ§ã®ã¹ããŒã¿ã¹ãè©äŸ¡ããããšæããŸãã SDLCå šäœã§ãããäœã§ããããçè§£ããå¿ èŠããããŸãã ã§ããããéçºè ãäœãããŠããã®ããããŸããŸãªãªããžããªã«äœããã§ãã¯ã€ã³ãããŠããã®ããèŠãŠããã®æ å ±ãåéããå®éã«Scoutããã·ã¥ããŒããéããŠçè§£ã§ããããã«ããŸãã ãã®ããããã¹ãŠã®ç»åã®ãã¹ãŠã®ã¡ã¿ããŒã¿ããªã¢ã«ã¿ã€ã ã§ç¢ºèªããããã§äœãèµ·ãã£ãŠããã®ããå®éã«çè§£ããå¿ èŠãªã¢ã¯ã·ã§ã³ã«åªå é äœãä»ããããšãã§ããŸãã SDLCãšè匱æ§ã«ã€ããŠããã§æ³šæãã¹ãéèŠãªéšåã¯ãåžžã«è匱æ§ããŒãã«ãªãããã§ã¯ãªããšããããšã§ãã åžžã«æ°ããè匱æ§ãäŸµå ¥ããŠãããããè匱æ§ã§äœãèµ·ãã£ãŠãããããªã¢ã«ã¿ã€ã ã§ææ¡ããããšã¯ããã¹ãŠã®ç°ãªãç°å¢ã§éèŠã«ãªããŸãã
ãŸããæ¬çªç°å¢ã§äœãèµ·ãã£ãŠããã®ããçè§£ã§ããããã«ããããšèããŠããŸãã Docker Scoutã䜿çšãããšãæ¬çªç°å¢ã«ã¿ã°ä»ããããã€ã¡ãŒãžãå®éã«èŠãŠãæ¬çªç°å¢ã§äœãèµ·ãã£ãŠãããã確èªã§ããŸãã ãŸããæ¬çªç°å¢ã®ã©ã³ã¿ã€ã åæãçµã³ä»ããŠãããã§äœãèµ·ãã£ãŠãããã確èªããããšãã§ããŸãã ãã®ãããæ¬çªç°å¢ã§å®éã«äœãå®è¡ãããŠããã®ããããæ·±ãçè§£ããããã«äŒŽãè匱æ§ãããªã·ãŒã®åé¡ã確èªããããšãã§ããŸãã Docker Scoutã¯ãDocker Desktopãéçºçšã®ã³ãã³ãã©ã€ã³ãããŸããŸãªCI/CDããŒã«ãArtifactoryãECRãACRãªã©ã®ã¬ãžã¹ããªãSysdigãªã©ã®ã©ã³ã¿ã€ã ããŒã«ãªã©ãããŸããŸãªããŒã«ãšçµ±åãããŠãããæéã®çµéãšãšãã«ãããã®çµ±åã«åžžã«æ°ããæ©èœã远å ãããŠããŸãã
Â
ã㢠(16.18)
ããã§ã¯ãç§ã話ããŠãããããã®æ©èœã®äžéšã瀺ãæãæ¥ãŸããã ããã§ãScoutã®ãã¢ãµãŒãã¹ã䜿çšããŸãã URLã¯ãã¡ãã§ã芧ããã ããŸãã åãGitHubãªããžããªãããŠã³ããŒãããŠããã®GitHubãªããžããªã䜿çšããŠèªåã§è¡ãããšããŠããã®ãšåããã¢ãè¡ãããšãã§ããŸãã æ¬¡ã«ãVS codeã«åãæ¿ããŸãã ããã«ã¯Scoutã®ãã¢ãµãŒãã¹ãããããã®ç¹å®ã®ã€ã¡ãŒãžãæ§ç¯ããããšããå§ããŸãã ãããŠä»ããã®ç¹å®ã®ã€ã¡ãŒãžãæ§ç¯ããŸãã ããã«ã¯çŽ 20 ç§ããããŸãã ãããŠããã®ã€ã¡ãŒãžãæ§ç¯ããããScoutãäœãæäŸã§ããããæ€èšãå§ããŸãã ããŠããã®ç¹å®ã®ã€ã¡ãŒãžãæ§ç¯ããŸããã ããã§ããã«ãã³ããããããšã«æ°ä»ãã§ããã:ãããã€ã¡ãŒãžã®è匱æ§ã®æšå¥šäºé ãèŠããããã®Docker Scoutã¯ã€ãã¯ãã¥ãŒãå®è¡ããŠãã ããã ç§ã¯ãããããã§ãã ã ããããããã³ããŒããŠããã«è²Œãä»ããŸãã
ããŠãããã§äœãèµ·ãã£ãã®ãèŠãŠã¿ãŸãããã ãã®ããã®ãœãããŠã§ã¢éšå衚ãäœæããŸããã ãã®ãœãããŠã§ã¢éšå衚ã¯åã®äŸãããã£ãã·ã¥ãããŸãããããœãããŠã§ã¢éšåè¡šã®ææãçæãããŸãã æ¬¡ã«ããã®ç¹å®ã®ã€ã¡ãŒãžã«å¯Ÿããããªã·ãŒãè©äŸ¡ããŸãã ãããŠããããããè匱æ§ã«é¢ããæ å ±ãæäŸããŸãã ãããŒãé«å€ 20 ãäž 8 ã 4 å®å€ã®2ã€ã®ã¯ãªãã£ã«ã«ãããããã§ãã ç§ã¯æ¬åœã«ããããã®ã¯ãªãã£ã«ã«ãšãã€ã®äžè©±ããããã§ããç§ã¯ã§ãããªãã ãããŠãããªã·ãŒã«äžãããšãããªã·ãŒã®ã¹ããŒã¿ã¹ã倱æã§ããããšã衚瀺ãããŸãã ãã®ãããä¿®æ£å¯èœãªé倧ã§é«ãè匱æ§ã ãã§ãªãã察åŠããå¿ èŠããããŸãããDockerfileã«ããã©ã«ãã®érootãŠãŒã¶ãŒãããŸããã ãã®ããããããä¿®æ£ããå¿ èŠããããéçºè ãšããŠã¯ä¿®æ£ã§ããªããµãã©ã€ãã§ãŒã³ã¢ãŠãã®èªèšŒãæ¬ èœããŠããŸããããããäœã§èµ·ãã£ãŠããã®ããçè§£ããããšãéèŠã§ãã
ã ããããããããç§ã¯ããã€ãã®ããšãè¡ãããšãã§ããŸãã ç¹°ãè¿ãã«ãªããŸãããããã¯ç§ã«äœãã§ãããã«ã€ããŠã®ãã³ããäžããŠãããŸãã ç§ã¯èªåã®ããªã·ãŒéåãèŠã«è¡ãããšãã§ããŸãã èªåã®åŒ±ããèŠã€ããããšãã§ããŸãã ç§ã¯å ã«é²ãã§ãããããŸãã ã ãããç§ã¯å ã«é²ãã§ãããã§ãããè¡ãã€ããã§ãã CVEã®ãªã¹ããããã±ãŒãžããšã«ååŸããŸãã ã§ããããããã«æ¥ãŠãåããã±ãŒãžã«CVEãå«ãŸããŠããããšãå®éã«ç¢ºèªããããšãã§ããŸãã ãããŠãCVEããšã«ãCVEçªå·ãååŸããŸãã ãã®ç¹å®ã®CVEã®è©³çްãå®éã«ç¢ºèªããããã®URLãååŸããŸãã 圱é¿ãåããç¯å²ãšåºå®ç¯å²ãååŸããŸãã ç§ã¯å®éã«ãããã®ãããããä¿®æ£ããããã«äœã倿Žããå¿ èŠãããããç¥ã£ãŠããŸãã ããã¯ãç§ãæ¢ããŠãããã¹ãŠã®æ å ±ãäžããŠãããŸãã Scoutã®ãã¢ã§Docker Scout SBOMãå®è¡ããããšãã§ããŸãã ãããŠãããã«ãããSBOMã®èªã¿ããã圢åŒãåŸãããŸãã ããã«ããããã®ãœãããŠã§ã¢ã®éšå衚ãã©ã®ãããªãã®ããããããŸãã ããã§ã¯ãããã±ãŒãžã®çš®é¡ãååãããŒãžã§ã³ãããã±ãŒãžã®äœæè ãããã±ãŒãžã®èª¬æãã©ã€ã»ã³ã¹ãã¢ã¯ã»ã¹å ã®URLããããŠå®éã«ãã®ç¹å®ã®éšåã«å°éããããã®ãã¹ã確èªã§ããŸãã ããã¯ããœãããŠã§ã¢ãã«ããããªã¢ã«å ã«è¡šç€ºãããæ å ±ã®çš®é¡ã§ããããããã®ããã±ãŒãžãããã«å«ããããã®ã§ãããå«ããããšã«æµæããªããšæãããã®ãã©ãããçè§£ããã®ã«åœ¹ç«ã¡ãŸãã
ãããŸã§ã«ç€ºãããã¹ãŠã®ãã®ã¯ã³ãã³ãã©ã€ã³ãä»ããŠããããã®ãã¹ãŠã®äœæ¥ã¯ã³ãã³ãã©ã€ã³ããå®è¡ã§ãã瀺ããæ¹æ³ã䜿çšããã ãã§å®è¡ã§ããŸãã ããããGUIã瀺ããããã§äœãã§ãããã瀺ããŸãã ããã§ã¯ãDocker Desktop GUIã䜿çšããŠããŸãã å®éã«ã¯ãScoutã®ãã¢ç»åã«ã¢ã¯ã»ã¹ããŠãããã±ãŒãžãCVEã衚瀺ããããåã«ã¯ãªãã¯ããã ãã§åããã®ã衚瀺ãããåã«èŠãã®ãšåãèåŒ±æ§æ å ±ã衚瀺ãããŸãããã¬ã€ã€ãŒããšã®åœ¢åŒã§è¡šç€ºãããŸãã ããŒã¹ã€ã¡ãŒãžã«ã¯ããããã®è匱æ§ãããããšãããããŸãããããã«æ¥ããšãã¡ãã£ãšåŸ ã£ãŠãã ããããã«ãã®äžéšãšããŠå°å ¥ããè匱æ§ãããã€ãããããããåŠçããå¿ èŠãããããšãããããŸãã ã§ããããç§ã¯ããããèŠãŠããããã«äœãèµ·ãã£ãŠããã®ããèŠãããšããããšãã§ããŸãã ã§ãããããã®ç¹å®ã®ã¢ããªã±ãŒã·ã§ã³ã§ã®ãšã¯ã¹ãã¬ã¹ãç¥ã£ãŠãããããšãã£ãŠããšã¯ã¹ãã¬ã¹ã«è¡ããšãããã«ã¯è€æ°ã®è匱æ§ãããããšãããããŸãã ã ãããæåã®ãã®ã«è¡ããšã説æãåºãŠãããã㯠4ã§ä¿®æ£ãããŸããããšæããŠãããŸãã17ã3ã OKãã ããç§ã¯å°ãªããšã 4ã«æŽæ°ããå¿ èŠããããŸãã17ã3ã æ¬¡ã®ãã®ã«è¡ã£ãŠãäœãæžããŠãããèŠãŠã¿ãŸãããã ãã㯠4ãšèšã£ãŠããŸãã19ã2ã ãããããããã£ãŠã¿ããã ãããŠãããã«ã¯ããäžã€ãããŸãã ãããŠããã㯠4ãšèšã£ãŠããŸãã20ã0ã ããŠãããã¯ãã ã®äœãã§ããããç§ã¯ãã® 4ãç¥ã£ãŠããŸãã20ã0 ã¯ç§ã«ãšã£ãŠããè¯ãããŒãžã§ã³ã§ãã ã ããç§ã¯å ã«é²ãã§ãããã 4ã«æŽæ°ããã€ããã§ãã20ã0ã ã§ã¯ãä»ããã«ã§ãå§ããŸãããã VS Code ã«æ»ããŸãã ããã§ããã±ãŒãžãªã¹ããéããŸãã ãããŠãç§ã¯éããŠããŠããããç§ã®ãšã¯ã¹ãã¬ã¹ã§ãã ã ããç§ã¯å ã«é²ãã§ãããã 4ã«å€æŽããŸãã20ã0ã ãããŠãç§ãã¡ã¯ãããä¿åããã€ããã§ãã ãããŠä»ãç§ã¯ããã2 Vãæ§ç¯ããŸãã ããã§ãæ°ããããã±ãŒãžã§ãã«ããããŸãã ç¹°ãè¿ãã«ãªããŸããããã«ãã«ã¯æ°ç§ããããŸãã ãããŠãã¯ã€ãã¯ãã¥ãŒãåå®è¡ããŠãäœãèµ·ãã£ãŠããã®ãã確èªããŸãã ããã§ã¯ã€ãã¯ãã¥ãŒãå®è¡ãããšãè匱æ§ã®æ°ãæžå°ããŠããããšãããããŸãããããã¯è¯ãããšã§ãã ãããç§ãã¡ãæãã§ããããšã§ãããè匱æ§ã®æ°ãå®éã«æžå°ããŠããããšã確èªãããã®ã§ãã ä»ãç§ã¯ãŸã ããŒã¹ã€ã¡ãŒãžã«ããããã®ãã®ãæã£ãŠããŸãã ããã§ãããäžåºŠãGUIã«æ»ãã®ã¯ããããã°ã©ãã£ã«ã«ã«è¡šç€ºããåªããæ¹æ³ãæäŸããããã§ãã ç§ã¯V2 ã«å ¥ããä»åºŠã¯æšå¥šãããä¿®æ£ãèŠãã€ããã§ãã CLIã§ãããå床è¡ãããšããããã§è¡ãããšãã§ããŸãã ããŒã¹ã€ã¡ãŒãžã®æšå¥šäºé ãååŸããŸãã ããã¯ã倧äžå€«ã1ã€ã®ãªãã·ã§ã³ã¯ãåã«ããŒã¹ã€ã¡ãŒãžãæŽæ°ããŠææ°ã®ãã®ãåŒãåºãããšãã§ãããšããããšã§ãã ããããããã¯ç§ãæ¬åœã«ããããããšã§ã¯ãããŸããã ããŒã¹ã€ã¡ãŒãžãæå®ãããã§ãã ã ãããç§ã¯ããã«æ¥ãã€ããã§ãã ç§ã¯çŸåš 3ã䜿çšããŠããŸãã14ã ãããŠä»ãããã¯èšã£ãŠããŸããOKãããªã㯠3ã«è¡ãããšãã§ããŸãã20ã ãããŠãããã¯å®éã«ããªãã®ã¯ãªãã£ã«ã«ã 2ãããªãã®é«å€ã 15æžããããšã«ãªããŸãã ããªãã¯ãŸã 1 åªäœãæã£ãŠããã§ãããã ç§ã¯ããã§å€§äžå€«ã§ãã ãã®æ°ããããã±ãŒãžã«ã€ããŠå°ãæ å ±ãæäŸããŠããŸãã ãããŠããã㯠from ã³ãã³ãã§ãã ã ãããç§ã¯ãããã€ããã€ããã§ãã VSã³ãŒãã«æ»ããŸãã Dockerfileã«ç§»åããŸãã ããã«ç§ã®fromã¹ããŒãã¡ã³ãããããŸãã ãããŠãæ°ãããã®ãå ¥ããŠä¿åããŸãã ãããŠããããããäžåºŠäœããŸãããã
ã ããä»ãç§ãã¡ã¯V3ãæ§ç¯ããŸãã ããããããããåã«ããã®ãŠãŒã¶ãŒãä¿®æ£ããå¿ èŠãããããšãã»ãšãã©å¿ããŠããŸããã ã ããç§ã¯ãããrootãšããŠå®è¡ããŠããŸããã ã§ã¯ãããããã£ãŠã¿ãŸãããã ãããŠä»ãç§ãã¡ã¯ v3ãæ§ç¯ããŸãã æ°ããããŒã¹ã€ã¡ãŒãžãåŒã£åŒµãã ãã§ãã ãã®ãããåã³ãã«ãããããŸã§ã«æ°ç§ããããŸãã 倧äžå€«ã§ãã ããã§ã¯ããã1ã€ã¯ã€ãã¯ãã¥ãŒãèŠãŠã¿ãŸãããã å ã«é²ãã§ããããäžã«åãããŠèŠãããšãã§ããããã«ããŸãã ããã§ãroot以å€ã®ãŠãŒã¶ãŒã解決ãããããšãããããŸãã ä¿®æ£å¯èœãªã¯ãªãã£ã«ã«ãŸãã¯ãã€ã¯è§£æ±ºãããŠããŸããã ãããŠããããäžã«ã¹ã¯ããŒã«ãããšãäžäœåãš21äœåãæ®ã£ãŠããããšãããããŸãããããã¯åé¡ãããŸãããããã¯ãåã ã®éçºè ãè匱æ§ãšããªã·ãŒã®åé¡ãçè§£ããã¬ã€ãã³ã¹ã䜿çšããŠããããä¿®æ£ã§ãããéçºè ã®èŠç¹ã®äŸã瀺ããŠããŸãã ããã§ã¯ãã¹ã«ãŠãããã·ã¥ããŒã(scout.docker.com)ãèŠãŠãããé«ãã¬ãã«ã§äœãèµ·ãã£ãŠããã®ããå®éã«ç¢ºèªã§ããããã«ããŸãããã
ããç§ãããã«æ¥ãŠããã©ãŠã¶ã«è¡ã£ãŠ scout.docker.com ã«è¡ããšã ãªã³ã¯ãããªããžããªããã€ã³ããã¯ã¹ãäœæããããã¹ãŠã®ã€ã¡ãŒãžã®ããã·ã¥ããŒãã衚瀺ãããŸãã Docker HubãArtifactoryãECRãACRã®ãããã§ãã£ãŠãããããã«é¢ããæ å ±ãèŠãããšãã§ããããšã ããã§ã¯ãããªã·ãŒãããã©ã«ãã®érootãŠãŒã¶ãŒãAGPL V3 ã©ã€ã»ã³ã¹ãªããä¿®æ£äžå¯èœãªé倧ãªè匱æ§ãŸãã¯é«ãè匱æ§ã確èªã§ããŸãã ã³ã³ãã©ã€ã¢ã³ã¹ã«é¢ããæ å ±ã¯èŠãŠããŸãããéå»7æ¥éã®åŸåãèŠãŠããŸããç¶æ³ã¯è¯ããªã£ãã®ãããããšãæªããªã£ãã®ãã äœãèµ·ãã£ãŠããã®ããããããçè§£ã§ããŸãã SonarQubeã®å質ã²ãŒãã®ãããªãã®ãèŠãããšãã§ããŸãã ãŸããåžžã«æ°ããè匱æ§ãçºèŠãããŠãããããè匱æ§ãäœã§ãããããªã¢ã«ã¿ã€ã ã§ç¢ºèªããããšãã§ããŸãã ãã®ãããæ°ããªè匱æ§ãçºèŠãããå Žåã¯ãããã«ç¥ããããã®ã§ãã ãã¹ãŠã®ãã®ãå®å šã«åã¹ãã£ã³ããå¿ èŠã¯ãããŸããã ããªãã¯ãªã¢ã«ã¿ã€ã ã§ç¥ãããã§ã-ç§ã¯ããã«ãã£ãŠã©ã®ããã«åœ±é¿ãåããŸãã? 次ã®Log4jãåºãŠããããã³ãŒãã«äœé±éãè²»ããå¿ èŠã¯ãããŸããã ãã®ããŒãžã§ã³ã®Log ã j ã®ã©ã®ã¢ããªã±ãŒã·ã§ã³ã«ãããã©ã®ããã«ä¿®æ£ããã®ããããã«ç¥ãããã§ãã4Scoutã§ã¯ããããã®é倧ã§é倧ãªè匱æ§ãä»»æã®è匱æ§ãå®éã«ç¢ºèªããããŸããŸãªã€ã¡ãŒãžã®ã©ãã圱é¿ãåããããããã«ç¢ºèªã§ããæ©èœãæäŸããŠããŸãã ããã¯ããœãããŠã§ã¢è«æ±æžã®è³æã䜿çšããŠãã©ã®ããã±ãŒãžãã©ã®ã€ã¡ãŒãžã«å«ãŸããŠãããããããŠãããã®åœ±é¿ãäœã§ããããçè§£ããããã«ã§ããããšã§ãã ãããã£ãŠãããã§ã¯ãæè¿ã®ããŸããŸãªé«ããã³é倧ãªè匱æ§ã®äžéšã確èªãã圱é¿ãåããã€ã¡ãŒãžã確èªã§ããŸãã ã ãããããã«ãã®äžã«å ¥ã£ãŠãç¹å®ã®ãã®ãèŠãããšãã§ããŸãã
ããããã¯ãæåŸã«ããã·ã¥ããããã®ã瀺ããŠããŸãããã¿ã°ä»ãã䜿çšããŠç°å¢ãæå®ãããšãæ¬çªç°å¢ãšããŠã¿ã°ä»ããããç°å¢ãå®éã«èŠãããšãã§ããæ¬çªç°å¢ã§ã©ã®ããã«æ©èœããŠãããã確èªããããšãã§ããŸãã ããã«ãããæ¬çªç°å¢ãšä»ã®æ¬çªç°å¢ãã©ããªã£ãŠããããå®éã«ç¢ºèªããããšãã§ããŸãã ä»ã§ã¯ãæŠèŠã ãã§ãªããåã ã®ããªã·ãŒãªã©ãèŠãŠãé±ããšã«ã©ã®ããã«é²ãã§ãããã確èªã§ããŸãã åã ã®ã€ã¡ãŒãžãã€ã³ããã¯ã¹åããããã¹ãŠã®ç°ãªãã€ã¡ãŒãžãè匱æ§ã®æ°ãæåŸã«ããã·ã¥ãããã®ã¯ãã€ãããã®ãããªãã®ãããªã·ãŒã«æºæ ããŠãããã©ããããã¹ãŠã®æ å ±ã調ã¹ãããšãã§ããŸãã ããŒã¹ã€ã¡ãŒãžãèŠãŠãããŸããŸãªã€ã¡ãŒãžã§ã©ã®ããŒã¹ã€ã¡ãŒãžã䜿çšãããŠãããã確èªããããã«é¢ããæ å ±ãååŸã§ããŸãã åã ã®ããã±ãŒãžãèŠãŠãã©ã®ç¹å®ã®ããã±ãŒãžãã©ã®ç¹å®ã®ç»åã§äœ¿çšãããŠãããã確èªã§ããŸãã ç§ãã¡ã¯è匱æ§ã«ãã£ãŠè¡ãããšãã§ããŸãã ãããã£ãŠãCVEçªå·ãããå Žåã¯ãããã«ããããããŠããã®åœ±é¿ãåãããã¹ãŠã®ç¹å®ã®ç»åã確èªã§ããŸãã ãŸããèšç床ã§äžŠã¹æ¿ããããšãã§ããŸãã ãããã£ãŠãããã§ã¯CVSã¹ã³ã¢ 10 è匱æ§ã瀺ããããããå«ãŸããŠããç»åã¯æ¬¡ã®ãšããã§ãã ãŸããããã§ã¯ããŸããŸãªã¿ã€ãã®ã·ã¹ãã ãžã®çµ±åã«ã€ããŠãèŠãŠãããŸãã ã³ã³ããã¬ãžã¹ããªãžã®çµ±åãCIçµ±åããªã¢ã«ã¿ã€ã æŽæ°ãçµ±åãªã©ãããããã¹ãŠã確èªã§ããŸãã ããã§ãããã¹ãŠã®ç°ãªãçµ±åã«é¢ããæ å ±ãååŸã§ããŸãã
ããŠããã®ãã¬ãŒã³ããŒã·ã§ã³ããèãããã ããèª ã«ããããšãããããŸããã Scoutã§ã®äœæ¥ã楜ãã¿ãæ°ããã³ã³ãããä¿è·ã§ããããšãé¡ã£ãŠããŸãã ããããšãããããŸãã
Â
ããã«è©³ãã
- ããã«ãŒã¯åããŠã§ãã? å§ããŸãããã
- 泚ç®ã®ã¬ã€ãã§Docker補åãæ·±ãæãäžããŸãã
- Docker Newsletter ã賌èªããŠãã ããã
- Docker ãã¹ã¯ãããã®ææ°ãªãªãŒã¹ãå ¥æããŸãã
- 質åããããŸãã? Docker ã³ãã¥ããã£ããæäŒãããŸãã