仿¥ã®ããžã¿ã«ç°å¢ã¯ãé »ç¹ãªã»ãã¥ãªãã£äŸµå®³ã«ãã£ãŠç¹åŸŽä»ããããåçã®æå€±ãæœåšçãªæ³ç責任ãããã³é¡§å®¢ã®ä¿¡é Œã®åªå€±ã«ã€ãªãããŸãã ãŒããã©ã¹ãã¢ãã«ã¯ãçµç¹ã®ã»ãã¥ãªãã£äœå¶ãæ¹åããã»ãã¥ãªãã£äŸµå®³ã®ãªã¹ã¯ãšç¯å²ãæå°éã«æããããã«èæ¡ãããŸããã
ãã®æçš¿ã§ã¯ããŒããã©ã¹ãã®ã»ãã¥ãªãã£ã«ã€ããŠèª¿æ»ãã Docker DesktopããŒã¹ã®éçºç°å¢å ã§ãŒããã©ã¹ããå®è£ ããããã®ããã€ãã®æŠç¥ã«ã€ããŠèª¬æããŸãã ãã®æŠèŠã¯ç¶²çŸ çã§ã¯ãããŸããããçµç¹ãç¬èªã®ã»ãã¥ãªãã£æŠç¥ãæ¹è¯ããŠå®è£ ããéã«æ§ç¯ã§ããåºæ¬çãªèŠç¹ãæäŸããŸãã

ãŒããã©ã¹ãã»ãã¥ãªãã£ãšã¯?
ãŒããã©ã¹ãã»ãã¥ãªãã£ã¢ãã«ã§ã¯ããããã¯ãŒã¯å¢çã®å éšãŸãã¯å€éšã®ãšã³ãã£ãã£ãèªåçã«ä¿¡é Œãããã¹ãã§ã¯ãªããšæ³å®ããŠããŸãã ãã®ã¢ãããŒãã§ã¯ãèªåçãªä¿¡é Œãæé€ãããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãèš±å¯ããåã«ããã¹ãŠã®èŠæ±ãšæäœã®å³å¯ãªæ€èšŒã矩åä»ããŸãã ãŒããã©ã¹ãã¯ãä¿¡é Œã®ç²åŸãäžè²«ããŠèŠæ±ããããšã§ãã»ãã¥ãªãã£å¯Ÿçãå€§å¹ ã«åŒ·åããŸãã
ãŒã ãã©ã¹ãã®ååãšå®è·µã«ã€ããŠã¯ãç±³åœåœç«æšæºæè¡ç ç©¶æ (NIST) ã®ç¹å¥åè¡ç© (800- 207 â ãŒã ãã©ã¹ã ã¢ãŒããã¯ãã£) ã§è©³ãã説æãããŠããŸãããã®ããã¥ã¡ã³ãã¯ã峿 Œãªã¢ã¯ã»ã¹å¶åŸ¡ãæå°éã®ç¹æš©ããã¹ãŠã®éçšå±æ§ãšç°å¢å±æ§ã®ç¶ç¶çãªæ€èšŒãªã©ããŒããã©ã¹ãã®ã³ã¢ååãæŠèª¬ããæš©åšããã¬ã€ããšããŠæ©èœããŸãã ããšãã°ãã»ã¯ã·ã§ã³ 2ã§ãããã®åºçç©ã®1 ã§ã¯ãçµç¹ãç¬èªã®ã»ãã¥ãªãã£ããŒãºã«åãããå ç¢ãªãŒããã©ã¹ãç°å¢ãå®è£ ããããã«æ¡çšã§ããåºæ¬ååã«ã€ããŠè©³ãã説æããŠããŸãããããã®ã¬ã€ãã©ã€ã³ãåç §ããããšã§ãå®åå®¶ã¯ãŒããã©ã¹ããå æ¬çã«çè§£ããããšãã§ãããããã¯ãŒã¯ã¢ãŒããã¯ãã£å šäœã«ãã®ååãæŠç¥çã«å®è£ ããçµç¹ã®ã»ãã¥ãªãã£äœå¶ã匷åããã®ã«åœ¹ç«ã¡ãŸãã
çµç¹ãã³ã³ããåãããã¢ããªã±ãŒã·ã§ã³ãã¯ã©ãŠãããŒã¹ã®ã¢ãŒããã¯ãã£ã«ç§»è¡ããã«ã€ããŠããŒããã©ã¹ãã®æ¡çšãäžå¯æ¬ ã§ãã ãããã®ç°å¢ã¯ãããžãã¹éèŠãæºããããã«ã³ã³ããããªãŒããæ¥éã«æ¡åŒµããã³é²åãããã€ãããºã ãç¹åŸŽã§ãã å¢çé²åŸ¡ã«äŸåããåŸæ¥ã®ã»ãã¥ãªãã£ã¢ãã«ãšã¯ç°ãªãããããã®ææ°ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ã¯ãã·ã¹ãã ã®å®å®æ§ã確ä¿ããªããç¶ç¶çãªå€æŽããµããŒãããã»ãã¥ãªãã£æŠç¥ãå¿ èŠã§ããÂ
ãŒããã©ã¹ããæåãããœãããŠã§ã¢éçºã©ã€ããµã€ã¯ã«(SDLC)ã«çµ±åããããšã¯éåžžã«éèŠã§ãã æ©æå°å ¥ã«ããããŒããã©ã¹ãã®ååã¯åã«ãããã€åŸã«è¿œå ãããã ãã§ãªããéçºããã»ã¹ã«çµã¿èŸŒãŸããæåããåºæ¬çãªã»ãã¥ãªãã£ãã¬ãŒã ã¯ãŒã¯ãæäŸãããŸãã
ã³ã³ãããšãŒããã©ã¹ã
ã³ã³ããåã«ãã£ãŠã¢ããªã±ãŒã·ã§ã³ãšç°å¢ãçžäºã«åé¢ããããšã§ãã¢ã¯ã»ã¹å¶åŸ¡ã®é©çšããã詳现ãªç£èŠããã³æ€åºã«ãŒã«ã®é©çšãçµæã®ç£æ»ã容æã«ãªãããŒããã©ã¹ãã®å®è£ ã«åœ¹ç«ã¡ãŸãã
åè¿°ã®ããã«ããããã®äŸã¯ Docker Desktop ã«åºæã®ãã®ã§ããã Kubernetes ãªã©ã®ãªãŒã±ã¹ãã¬ãŒã·ã§ã³ ã·ã¹ãã ãå«ããä»»æã®ã³ã³ããããŒã¹ã®ç°å¢ã«æŠå¿µãé©çšã§ããŸãã
匷åºãªåºç€:ãã¹ããšãããã¯ãŒã¯
ãŒããã©ã¹ãã®ååãDocker Desktopã«é©çšããå Žåããã¹ãã·ã¹ãã ããå§ããããšãéèŠã§ãã ãã®ã·ã¹ãã ã¯ãæå·åãããã¹ãã¬ãŒãžã®äœ¿çšããªãã¬ãŒãã£ã³ã° ã·ã¹ãã å ã®ãŠãŒã¶ãŒç¹æš©ã®å¶éããšã³ããã€ã³ãã®ç£èŠãšãã°ã®æå¹åãªã©ããŒã ãã©ã¹ãèŠä»¶ãæºããå¿ èŠããããŸãã ãã¹ã ã·ã¹ãã ã®ãããã¯ãŒã¯ ãªãœãŒã¹ãžã®æ¥ç¶ã«ã¯èªèšŒãå¿ èŠã§ããããã¹ãŠã®éä¿¡ã¯ã»ãã¥ãªãã£ã§ä¿è·ãããæå·åãããŠããå¿ èŠããããŸãã
æå°ç¹æš©ã®åå
æå°ç¹æš©ã®ååã¯ããŠãŒã¶ãŒãããã°ã©ã ããŸãã¯ããã»ã¹ãæå³ããæ©èœãå®è¡ããããã«å¿ èŠãªæå°éã®ã¢ã¯ã»ã¹èš±å¯ã®ã¿ãæã¡ããã以äžã®æš©éãæããªããšããåºæ¬çãªã»ãã¥ãªã㣠ã¢ãããŒãã§ãã ã³ã³ããã®æäœã«é¢ããŠã¯ããã®ååã广çã«å®è£ ããã«ã¯ãAppArmor / SELinuxã®äœ¿çšã seccomp (ã»ãã¥ã¢ã³ã³ãã¥ãŒãã£ã³ã°ã¢ãŒã)ãããã¡ã€ã«ã®äœ¿çšãã³ã³ãããrootãšããŠå®è¡ãããªãããã«ããããšãã³ã³ãããææ Œããæš©éãèŠæ±ãŸãã¯åä¿¡ããªãããã«ããããšãªã©ãå¿ èŠã§ãã
ãã ãã匷åããã Docker Desktop (Docker Business ãŸã㯠Docker Government ãµãã¹ã¯ãªãã·ã§ã³ã§å©çšå¯èœ) ã¯ãEnhanced Container Isolation (ECI) èšå®ãéããŠãã®èŠä»¶ãæºããããšãã§ããŸããECI ãã¢ã¯ãã£ããªå Žåãæ¬¡ã®åŠçãè¡ããŸãã
- æš©éã®ãªãã³ã³ããã®å®è¡: ECI ã¯ãã³ã³ããã
--privilegedãã©ã°ã§èµ·åãããå Žåã§ããã³ã³ããå ã®å®éã®ããã»ã¹ããã¹ããŸã㯠Docker Desktop VM å ã§ææ Œãããæš©éãæããªãããã«ããŸãã ãã®æé ã¯ãç¹æš©ææ Œæ»æãé²ãããã«éèŠã§ãã - ãŠãŒã¶ãŒåå空éã®åãããã³ã°: ECI ã§ã¯ãã³ã³ããå ã®ã«ãŒã ãŠãŒã¶ãŒã Docker Desktop VM å ã®ã³ã³ããå€ã®éã«ãŒã ãŠãŒã¶ãŒã«ããããããææ³ã䜿çšããŸãã ãã®ã¢ãããŒãã«ãããã³ã³ããã䟵害ãããå Žåã§ããæœåšçãªæå®³ãšã¢ã¯ã»ã¹ç¯å²ãå¶éãããŸãã
- ãã¡ã€ã«ã·ã¹ãã ãžã®ã¢ã¯ã»ã¹å¶é: ECI ã§å®è¡ãããã³ã³ããã¯ããã¹ããã·ã³ã®ãã¡ã€ã«ã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ãå¶éãããŠããŸãã ãã®å¶éã«ããã䟵害ãããã³ã³ãããã·ã¹ãã ãã¡ã€ã«ã倿Žãããããã¹ããã¡ã€ã«ã·ã¹ãã ã®æ©å¯æ§ã®é«ãé åã«ã¢ã¯ã»ã¹ãããããã®ãé²ãããšãã§ããŸãã
- æ©å¯æ§ã®é«ãã·ã¹ãã ã³ãŒã«ã®ãããã¯:ECIã¯ãç¹å®ã®çš®é¡ã®
mountæäœãªã©ãæ»æã§äžè¬çã«äœ¿çšãããã³ã³ããããã®ã·ã¹ãã ã³ãŒã«ããããã¯ãŸãã¯ãã£ã«ã¿ãªã³ã°ã§ããããããã¬ã€ã¯ã¢ãŠãã®ãªã¹ã¯ãããã«è»œæžã§ããŸãã - Docker ãšã³ãžã³ããã®åé¢: ECI ã¯ãæç€ºçã«èš±å¯ãããŠããªãéããã³ã³ããã Docker ãšã³ãžã³ã® API ãšçŽæ¥å¯Ÿè©±ããã®ãé²ããDocker ã€ã³ãã©ã¹ãã©ã¯ãã£èªäœãæšçãšããæ»æããä¿è·ããŸãã
ãããã¯ãŒã¯ã»ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³
ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã¯ãã³ã³ããéã®ãã©ãã£ãã¯ãããŒãå¶åŸ¡ããããšã§ãã»ãã¥ãªãã£ãããã«åŒ·åããæ¹æ³ãæäŸããŸãã 峿 Œãªãããã¯ãŒã¯ããªã·ãŒã®å®è£ ã«ãããèš±å¯ãããã³ã³ããã®ã¿ã察話ãèš±å¯ãããã»ãã¥ãªãã£éåãçºçããå Žåã®æ°Žå¹³ç§»åã®ãªã¹ã¯ãå€§å¹ ã«è»œæžãããŸãã ããšãã°ãæ¯æãåŠçã³ã³ããã¯ãã¢ããªã±ãŒã·ã§ã³ã®ç¹å®ã®éšåããã®æ¥ç¶ã®ã¿ãåãå ¥ããå®å šæ§ã®äœãä»ã®ãããã¯ãŒã¯ã»ã°ã¡ã³ãããåé¢ããããšãã§ããŸãã
ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã®æŠå¿µã¯ãAIã·ã¹ãã ãšã¯ãŒã¯ããŒãã«ã圹å²ãæãããŸãã ãããã¯ãŒã¯ãšããŒã¿ãã»ã°ã¡ã³ãåããããšã§ãçµç¹ã¯AIã€ã³ãã©ã¹ãã©ã¯ãã£ã®ããŸããŸãªéšåã«å¶åŸ¡ãé©çšãããã¬ãŒãã³ã°ããã¹ããæ¬çªç°å¢ã«äœ¿çšãããç°å¢ã广çã«åé¢ã§ããŸãã ãã®åé¢ã«ãããç°å¢éã®ããŒã¿æŒæŽ©ã®ãªã¹ããæžããã»ãã¥ãªãã£äŸµå®³ã®åœ±é¿ç¯å²ãçž®å°ãããŸãã
Docker Desktop ã®å ç¢ãªãããã¯ãŒã¯ã¯ããã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ã«å¯ŸåŠããããã®ããã€ãã®æ¹æ³ãæäŸããŸãã ããªããžãããã¯ãŒã¯ãå©çšããŠåããã¹ãå ã«åé¢ããããããã¯ãŒã¯ãäœæããããã³ã³ãããåå¥ã®MACã¢ãã¬ã¹ãæã€ç©çããã€ã¹ãšããŠæ±ãããšãã§ãã Macvlan ãããã¯ãŒã¯ãã©ã€ãã䜿çšããããšã§ã管çè ã¯ãŒããã©ã¹ãã®æå°ç¹æš©ã¢ã¯ã»ã¹ååã«æ²¿ã£ãæ£ç¢ºãªéä¿¡ãã¹ãå®çŸ©ã§ããŸãã ããã«ã Docker Compose ã¯ãäºåå®çŸ©ããããããã¯ãŒã¯äžã§éä¿¡ã§ããã³ã³ãããæå®ããŠããããã®ãããã¯ãŒã¯ãç°¡åã«ç®¡çããã³æ§æã§ããŸããÂ
ãã®èšå®ã«ãããã€ã³ãã©ã¹ãã©ã¯ã㣠ã¬ãã«ã§ã®ãã现ããªãããã¯ãŒã¯ ããªã·ãŒã容æã«ãªããŸãã ãŸããã³ã³ããã¢ã¯ã»ã¹ã®ç®¡çãç°¡çŽ åãã峿 Œãªãããã¯ãŒã¯ã»ã°ã¡ã³ããŒã·ã§ã³ããªã·ãŒãé©çšããŠãæ»æå¯Ÿè±¡é åãæå°éã«æããã³ã³ããåãããç°å¢ã§ã®äžæ£ã¢ã¯ã»ã¹ã®ãªã¹ã¯ã軜æžããŸãã ããã«ãDocker Desktop ã¯ãµãŒãããŒãã£ã®ãããã¯ãŒã¯ ãã©ã€ããŒããµããŒãããŠãããããã䜿çšããŠãã®åé¡ã«å¯ŸåŠããããšãã§ããŸãã
Docker Desktop ã§ã³ã³ããã«ãã¹ããšã¯ç°ãªããšã°ã¬ã¹ ã«ãŒã«ãå¿ èŠãªãŠãŒã¹ã±ãŒã¹ã§ã¯ãããšã¢ã®ã£ãã ã³ã³ãããã䜿çšãããšãã³ã³ããã«é©çšããã詳现ãªã«ãŒã«ãèšå®ã§ããŸãã ããšãã°ãã³ã³ããã¯ã€ã³ã¿ãŒãããããå®å šã«å¶éãããŠããŠããããŒã«ã«ãããã¯ãŒã¯äžã§ã¯èš±å¯ãããŠããå Žåãããã°ãæ¿èªããããã¹ãã®å°ããªã»ããã«ãããã·/ãã¡ã€ã¢ãŠã©ãŒã«ã§æ¥ç¶ããããšãã§ããŸãã
Kubernetesã§ã¯ããã®ã¿ã€ãã®ãã€ã¯ãã»ã°ã¡ã³ããŒã·ã§ã³ãšãããã¯ãŒã¯ãã©ãã£ãã¯ç®¡çã¯éåžžããµãŒãã¹ã¡ãã·ã¥ã«ãã£ãŠç®¡çãããããšã«æ³šæããŠãã ããã
èªèšŒãšæ¿èª
DockerããŒã¹ã®ãŒããã©ã¹ãç°å¢ã§ã¯ã匷åãªèªèšŒãšããŒã«ããŒã¹ã®ã¢ã¯ã»ã¹å¶åŸ¡(RBAC)ãå®è£ ããããšãéèŠã§ãã ãããã®ååã¯ãäžèšã®ããã«ãã¹ããšãããã¯ãŒã¯ããå§ããŠãããã€ãã®ç°ãªãé åã§å¯ŸåŠããå¿ èŠããããŸãã
ã·ã³ã°ã«ãµã€ã³ãªã³(SSO)ãšã¯ãã¹ãã¡ã€ã³ID管çã·ã¹ãã (SCIM) ãæå¹ã«ããŠãDocker SaaSãžã®ãŠãŒã¶ãŒèªèšŒã管çããããã«äœ¿çšããå¿ èŠããããŸãã ãããã®ããŒã«ã䜿çšãããšãã°ã«ãŒãã䜿çšããŠã¢ã«ãŠã³ãã¬ãã«ã§ããŒã«ãšããŒã ã®ã¡ã³ããŒã·ãããé©çšãããªã©ããŠãŒã¶ãŒã®ç®¡çãæ¹åã§ããŸãã ããã«ãDocker Desktop ã¯ã䜿çšäžã® Docker çµç¹ãžã®ãã°ã€ã³ãèŠæ±ãã匷å¶ããããã«èšå®ããŠããŠãŒã¶ãŒãä»ã®çµç¹ãå人ã¢ã«ãŠã³ãã«ãã°ã€ã³ã§ããªãããã«ããå¿ èŠããããŸãã
Docker Desktop ã§ã³ã³ãããããŒã«ã«ã§èšèšããããã€ããã«ãããã¹ãããå Žåãã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ãšååã«åãããããã«ã¯ãå ç¢ãªèªèšŒãšæ¿èªã®ã¡ã«ããºã ãå®è£ ããããšãéèŠã§ãã ã³ã³ããã®ã©ã€ããµã€ã¯ã«ã®å段éã§å³æ Œãªã¢ã¯ã»ã¹å¶åŸ¡ã宿œããããšãäžå¯æ¬ ã§ãã
ãã®ã¢ãããŒãã¯ãã¬ãžã¹ããªãšã€ã¡ãŒãžã®ã¢ã¯ã»ã¹ã管çããããšããå§ããŠãæ¿èªãããã€ã¡ãŒãžã®ã¿ãéçºããã»ã¹ã«åã蟌ãŸããããã«ããŸãã ããã¯ãå éšã¬ãžã¹ããªã䜿çšããä»ã®ã¬ãžã¹ããªãžã®ã¢ã¯ã»ã¹ããããã¯ãããã¡ã€ã¢ãŠã©ãŒã«èŠåãé©çšããããšã§å®çŸã§ããŸãã ãã ããããç°¡åãªæ¹æ³ã¯ãHardened Docker Desktop ãæäŸããæ©èœã§ãã ã¬ãžã¹ã㪠ã¢ã¯ã»ã¹ç®¡ç (RAM) ãš ã€ã¡ãŒãž ã¢ã¯ã»ã¹ç®¡ç (IAM) ã䜿çšããŠã€ã¡ãŒãžãšã¬ãžã¹ããªãå¶åŸ¡ããããšã§ãã
ã·ãŒã¯ã¬ãã管çã«é¢ããããªã·ãŒãšæé ã®å®è£ (ç®çã«åãããŠèšèšãããã·ãŒã¯ã¬ãã ã¹ãã¢ã®äœ¿çšãªã©) ã¯ãéçºããã»ã¹ã®äžéšã§ããå¿ èŠããããŸãã æåŸã«ãEnhanced Container Isolation (åè¿°ã®ãšãã) ã䜿çšãããšãã³ã³ããã®ç¹æš©ããã¹ã ãã©ã¯ãã£ã¹ã«åŸã£ãŠäžè²«ããŠç®¡çãããããã«ãªããŸãã
ãã®å æ¬çãªã¢ãããŒãã¯ãã»ãã¥ãªãã£ã匷åããã ãã§ãªããç¹ã«æ©å¯æ§ã®é«ãã¢ããªã±ãŒã·ã§ã³ããŒã¿ãç¬èªã®ã¢ããªã±ãŒã·ã§ã³ããŒã¿ãæ±ãå Žåã«ãéçºç°å¢ã®æŽåæ§ãšæ©å¯æ§ãç¶æããã®ã«ã圹ç«ã¡ãŸãã
ç£èŠãšç£æ»
Dockerç°å¢å ã®ã¢ã¯ãã£ããã£ã®ç¶ç¶çãªç£èŠãšç£æ»ã¯ãæœåšçãªã»ãã¥ãªãã£åé¡ãæ©æã«æ€åºããããã«äžå¯æ¬ ã§ãã ãããã®ã³ã³ãããŒã«ã¯ãäžèšã®é åã«åºã¥ããŠæ§ç¯ãããŠããããããã®ã³ã³ãããŒã«ã®åœ±é¿ã®ç£æ»ãšç£èŠãå¯èœã«ããŸãã
Docker Desktop ã¯ãã¢ããªã±ãŒã·ã§ã³ ãã©ãããã©ãŒã å šäœã®æäœã«é¢ããæŽå¯ãæäŸãã倿°ã®ãã°ãçæããŸãã ããã«ã¯ãããŒã«ã«ç°å¢ãå éš VMãã€ã¡ãŒãž ã¹ãã¢ãã³ã³ãã ã©ã³ã¿ã€ã ãªã©ã«é¢ããæ å ±ãå«ãŸããŸãã ãã®ããŒã¿ã¯ãæ¥çæšæºã®ããŒã«ã«ãã£ãŠãªãã€ã¬ã¯ãããã³è§£æ/åæã§ããŸãã
ã³ã³ããã®ãã®ã³ã°ã¯éèŠã§ãããåŠçã®ããã«ãªã¢ãŒããã°ã¢ã°ãªã²ãŒã¿ãŒã«éä¿¡ããå¿ èŠããããŸãã æé©ãªéçºã¢ãããŒãã§ã¯ãéçºã®ãã°åœ¢åŒãšãã° ã¬ãã«ãéçšç°å¢ã§äœ¿çšããããã®ãåæ ããå¿ èŠãããããããã®ããŒã¿ã䜿çšããŠéçºããã»ã¹ã®ç°åžžãæ¢ãã ãã§ãªããéçšããŒã ãéçšç°å¢ãã©ã®ããã«èŠããããææ¡ããããšãã§ããŸãã
Docker Scout
ã³ã³ããåãããã¢ããªã±ãŒã·ã§ã³ãã»ãã¥ãªãã£ããªã·ãŒãšãã©ã€ãã·ãŒããªã·ãŒã«æºæ ããŠããããšã確èªããããšããç¶ç¶çãªç£èŠã®éèŠãªéšåã§ãã Docker Scout ã¯ããã®åãçµã¿ããµããŒãããããã«ãŒãããèšèšãããŠããŸããÂ
Docker Scoutã¯ãã€ã¡ãŒãžãœãããŠã§ã¢ã®éšå衚(SBOM)ããéå§ããæ¢ç¥ããã³æ°ããCVEãšã»ãã¥ãªãã£ããªã·ãŒã«å¯ŸããŠç¶ç¶çã«ãã§ãã¯ããŸãã ãããã®ããªã·ãŒã«ã¯ã軜æžãã¹ã泚ç®åºŠã®é«ãCVEã®æ€åºãæ¿èªãããããŒã¹ã€ã¡ãŒãžã䜿çšãããŠããããšã®æ€èšŒãæå¹ãªã©ã€ã»ã³ã¹ã®ã¿ã䜿çšãããŠããããšã®ç¢ºèªãã€ã¡ãŒãžã«root以å€ã®ãŠãŒã¶ãŒãå®çŸ©ãããŠããããšã®ç¢ºèªãå«ãŸããŸãã ããã«ãDocker Scout ããªã·ãŒãšã³ãžã³ã䜿çšããŠãå©çšå¯èœãªããŸããŸãªããŒã¿ãã€ã³ãã䜿çšããŠã«ã¹ã¿ã ããªã·ãŒãèšè¿°ã§ããŸãã Â
äžå€ã³ã³ãã
ãããã€åŸã«å€æŽãããªãã€ãã¥ãŒã¿ãã« ã³ã³ããã®æŠå¿µã¯ãç°å¢ãä¿è·ããäžã§éèŠãªåœ¹å²ãæãããŸãã ã³ã³ããã倿Žããã®ã§ã¯ãªã眮ãæããããšã§ãç°å¢ã®ã»ãã¥ãªãã£ã匷åããå®è¡æã®äžæ£ãªå€æŽãæªæã®ãã倿Žãé²ããŸãã
Dockerã€ã¡ãŒãž(ããåºçŸ©ã«ã¯OCIæºæ ã®ã€ã¡ãŒãž)ã¯ãããã©ã«ãã§ã¯äžå€ã§ãã ã³ã³ãããšããŠãããã€ããããšãäžå€ã€ã¡ãŒãžã®äžã«ãã¹ã¯ã©ããã¬ã€ã€ãŒãã远å ããããšã§ãå®è¡äžã«æžã蟌ã¿å¯èœã«ãªããŸãã ãã®ã¬ã€ã€ãŒã¯ãã³ã³ããã®å¯¿åœãè¶ ããŠä¿æãããªãããšã«æ³šæããŠãã ããã ã³ã³ãããåãå€ããšãã¹ã¯ã©ããå±€ãåé€ãããŸãã
docker run ã³ãã³ãã« --read-only ãã©ã°ã远å ãããã docker compose ã« read_only: true ããŒãšå€ã®ãã¢ã远å ããããšã§ãäžå€ãã©ã°ã远å ãããšãDocker ã¯ã«ãŒã ãã¡ã€ã« ã·ã¹ãã ãèªã¿åãå°çšã§ããŠã³ãããã³ã³ãã ãã¡ã€ã« ã·ã¹ãã ãžã®æžã蟌ã¿ãé²ããŸãã
ã³ã³ãããäžå€ã«ããã ãã§ãªãã Dockerããªã¥ãŒã ã read/write ãŸã㯠read-onlyãšããŠããŠã³ãããããšãå¯èœã§ãã ã³ã³ããã®ã«ãŒããã¡ã€ã«ã·ã¹ãã ãèªã¿åãå°çšã«ããŠãããããªã¥ãŒã ã®èªã¿åã/æžã蟌ã¿ã䜿çšããŠãã³ã³ããã®æžã蟌ã¿ã¢ã¯ã»ã¹ãããé©åã«ç®¡çã§ããããšã«æ³šæããŠãã ããã
æå·å
転éäžãšä¿åäžã®äž¡æ¹ã§ããŒã¿ãå®å šã«æå·åãããŠããããšã確èªããããšã¯ãå®å šãªDockerç°å¢ã§ã¯äº€æžã®äœå°ããããŸããã Docker ã³ã³ããã¯ãã³ã³ããéãšã³ã³ããç°å¢ã®å€éšã®äž¡æ¹ã§ TLS ã䜿çšããããã«èšå®ããå¿ èŠããããŸãã Docker ã€ã¡ãŒãžãšããªã¥ãŒã ã¯ããŒã«ã«ã«ä¿åãããä¿åæã«ã¯ãã¹ã ã·ã¹ãã ã®ãã£ã¹ã¯æå·åã®æ©æµãåããããšãã§ããŸãã
ããŒã«ãã§ãŒã³ã®æŽæ°
æåŸã«ãDocker ããŒã 㯠CVE ãçºèŠããããšãã«ç¶ç¶çã«æ¹åãè¡ãã軜æžããŠãããããDocker Desktop ã ææ°ããŒãžã§ã³ã«æŽæ°ãããŠããããšã確èªããããšãéèŠã§ãã 詳现ã«ã€ããŠã¯ã Docker ã®ã»ãã¥ãªã㣠ããã¥ã¡ã³ã ãš Docker ã®ã»ãã¥ãªãã£ã«é¢ãããç¥ãããåç §ããŠãã ããã
ãŒããã©ã¹ãå°å ¥ã«ããã課é¡ã®å æ
Docker Desktopã䜿çšãããŒããã©ã¹ãã¢ãŒããã¯ãã£ã®å®è£ ã«ã¯ã課é¡ããªãããã§ã¯ãããŸããã ãã®ãããªèª²é¡ã«ã¯ããã®ãããªç°å¢ã®ç®¡çã®è€éããæœåšçãªããã©ãŒãã³ã¹ã®ãªãŒããŒããããã»ãã¥ãªãã£æèã®åäžã«åããçµç¹å ã®æåçãªå€é©ã®å¿ èŠæ§ãå«ãŸããŸãã ããããå®å šã§å埩åã®ããã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã¡ãªããã¯ããããã®èª²é¡ãã¯ããã«äžåãããããŒããã©ã¹ããžã®åãçµã¿ãšæè³ã¯äŸ¡å€ããããŸãã
çµè«
Docker Desktopç°å¢ã«ãŒããã©ã¹ãã®ååãçµã¿èŸŒãããšã¯ãé«åºŠãªãµã€ããŒè åšããææ°ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãä¿è·ããããã«äžå¯æ¬ ã§ãã ãããã®ååãçè§£ããŠå®è£ ããããšã§ãçµç¹ã¯ã¢ããªã±ãŒã·ã§ã³ãšããŒã¿ããã广çã«ä¿è·ããå®å šã§å埩åã®ããããžã¿ã« ãã¬ãŒã³ã¹ã確ä¿ã§ããŸãã
ããã«è©³ãã
- Docker Newsletter ã賌èªããŠãã ãããÂ
- åèèšäº: Docker ã§éçºè ã匷å: SOC 2ãISO 27001ãFedRAMP ãªã©ã®ã³ã³ãã©ã€ã¢ã³ã¹ã®ç°¡çŽ åãšã»ãã¥ãªãã£ã®åŒ·åã
- Docker Scout ã ãæ¬çªç°å¢ã«ç§»è¡ããåã«ã»ãã¥ãªãã£åé¡ã«å¯ŸåŠããæ¹æ³ãã芧ãã ããã
- Docker Scout ã®æ£åžžæ§ã¹ã³ã¢ãDocker Hub ãªããžããªå ã®ã³ã³ãã㌠ã€ã¡ãŒãžã®ã»ãã¥ãªãã£è©äŸ¡ã«ã€ããŠèª¬æããŸãã
- Docker ãã¹ã¯ãããã®ææ°ãªãªãŒã¹ãå ¥æããŸãã
- 質åããããŸãã? Docker ã³ãã¥ããã£ããæäŒãããŸãã
- ããã«ãŒã¯åããŠã§ãã? å§ããŸãããã