Sysdigã§ã³ã³ããã»ãã¥ãªãã£ã¢ãã«ããã¹ã¿ãŒãã
ç§ã®ååã¯ãšãªãã¯ã»ã«ãŒã¿ãŒã§ãã ç§ã¯Sysdigã®ãããã¯ãããŒã±ãã£ã³ã°ããŒã ã«æå±ããŠããŸãã ç§ã¯ãåœç€Ÿã®äž»èŠãªã»ãã¥ãªãã£ã¢ãŒããã¯ãã§ããAlexãšäžç·ã«åå ããŠããŸãã 圌ãé£ããŠè¡ããŸããã 圌ã¯ã¹ã±ãžã¥ãŒã«ã«èŒã£ãŠããªãã£ããã©ãããã¯åœŒãé£ãã質åã«çããããšãã§ããããã ãã ã³ã³ããã®ã»ãã¥ãªãã£ã«ã€ããŠå°ãã話ãããããšæããŸãã ããã«ãã人ã®ãã¡ãã»ãšãã©ãéçºè ã§ãããšèªèããŠãã人ã¯ã©ããããããŸãã? DevOpsã®ãããªäººã¯ããããéããšèãããªã? ã»ãã¥ãªãã£ãéçšãªã©ãä»ã«äœããããŸãã? ããŠãç§ãã¡ã¯è¯ã人ãã¡ãæ··ãåãããŠããŸãã
仿¥ã®ç®æšã®äžéšã¯ãã³ã³ããã®ã»ãã¥ãªãã£åé¡ã«é¢ããŠæ¥çã§èŠãããããšã«ã€ããŠå°ã話ãããšã§ãã ãŸããã³ã³ãããæ§ç¯ãããšãã«å®è¡ã§ããããã€ãã®ãã¹ããã©ã¯ãã£ã¹ã«ã€ããŠã説æããŸãã ç§ãã¡ã¯ãç§ãã¡ãå³ã·ãŒã«ããšåŒã¶ã®ã奜ããªãã®ãã€ãŸãã³ã³ããã皌åããŠãããšãã«ãããªããã§ããããšã®ããã€ããå°ãæãäžããŸãã?
Sysdigãš Docker Scout ã®çµ±åãæãåºããŠããã ããã»ãã¥ãªãã£åé¡ãCVEãªã©ãã©ããæåã«ä¿®æ£ãã¹ããè¿·ã£ãŠãããã®ã«åªå é äœãä»ããããã®è¿œå ã®æ¯æŽãæäŸããŸããã©ã³ã¿ã€ã ã€ã³ãµã€ããšåŒã°ãããã®ã¯ããã«åœ¹ç«ã€ã®ã§ããã®ã¡ãã»ãŒãžãé ä¿¡ããŸãã
ã³ã³ããã»ãã¥ãªãã£ã¢ãã«
ã³ã³ããã®ã»ãã¥ãªãã£ã¢ãã«ã«ã€ããŠã話ãããŸãã®ã§ãã³ã³ããæ åœè ãã»ãã¥ãªãã£æ åœè ãããå Žåã¯ãå¿é ããªãã§ãã ãããããªãã¯æ£ããå Žæã«ããŸãã çŽ æŽãããã
ããã§ã¯ãç§ãã¡ãè¡ãã¹ãããšã®äžéšãã€ãŸãã³ã³ããã»ãã¥ãªãã£ã¢ãã«ãšåŒãã§ãããã®ã«ã€ããŠèª¬æããŸãã ããŸãããã°ãããã¯ããªãã«ãšã£ãŠåœ¹ã«ç«ã¡ãŸãã å ã»ã©è¿°ã¹ãããã«ãã·ããã¬ãã/ã·ãŒã«ãã©ã€ããããã³ã©ã€ããµã€ã¯ã«å šäœã«ãããããã€ãã®ãã¹ããã©ã¯ãã£ã¹ã«ã€ããŠèª¬æããŸãã
ã»ãã¥ãªãã£äžã®åé¡ã¯ããã€ãèããããŸããããã® 1 ã€ã¯ã³ã³ããã®å 容ã«åºã¥ããŠããŸãã ãããããããã³ã³ãããæ§ç¯ãããšãã«ã¯ããããæ£ããããšã§ã¯ãªããããªããšãããããšããããããããŸããã ãŸããå¿ ãããäœããããã§ã¯ãªããåšå²ã®ç°å¢ã«ãããŠãããããããã«ããã¹ãã§ã¯ãªãã¢ã¯ã»ã¹ãå¯èœã«ãããã®ãã€ãŸã人ã ãããªãã®ãã¢ãèŠããããè£å£ãéã£ããããããšãã§ãããªã©ãéèŠãªããšããããŸãã ã³ã³ãããKubernetesãã¯ã©ãŠããªã©ãæ¥çã§ã¯å€ãã®ããšãèµ·ãã£ãŠãããã³ãŒãã£ã³ã°ããå®è¡ãŸã§ãããŸããŸãªããšã«å¯Ÿå¿ããå¿ èŠããããŸãã ãªããªããç§ãã¡ã¯ä»¥åãããã¯ããã«é »ç¹ã«ãããã€ããŠããããã§ãã ããã§ã®æ°åã¯åºæ¬çã«ã 60%ã®äŒæ¥ãããã1æ¥ã«äœåºŠãããŸãã¯æ°æ¥ããšã«è¡ã£ãŠãããšå ±åããŠãããããã4ç§ããšã«è¡ã£ãŠããããšãšæ¯èŒããŠããŸãã
ã·ããå·Š
ç§ãã¡ã¯ç©äºã«ã€ããŠãããªããã°ãªããŸããã ããŒã¹ãèœãšããã«ç©äºã«åªå é äœãä»ããã«ã¯ã©ãããã°ããã§ãããã? çºçããå¯èœæ§ã®ããåé¡ãã©ã®ããã«æ€åºãã察å¿ããŸãã? ãŸããã·ããã¬ããã«ã€ããŠè©±ããŸãããã çããã®äžã«ã¯ãç§ãšåãããã«ããã®èšèãèããšç®ãäžžãããŠããŸãæ¹ãå€ããããããŸããããããã¯éèŠãªæŠå¿µã§ãããåºæ¬çã«ã¯ãç§ãã¡ãçºå±ããŠãããšããæãæ©ã段éããæ£ããããšããããšããããšã§ãã ãããã®ããšãã§ããã ãæ©ãä¿®æ£ããŠãã ããã ã§ããããç§ãã¡ã«ã§ããããšã¯ãããããããŸãã ç§ãã¡ã¯ããããããŒã«ã¹ã«ãŒããã€ããã§ãã 1ã€ã¯ãç§ãã¡ãæ¢ããããªãã£ããããããžã§ã¯ããé ãããããŠããªãããšã§ãã ç§ãã¡ã¯åŸã§ãã®ãããªããšãé²ãããã®ã§ãããããã¯åŸã§ããããšãããšã³ã¹ãããããããã§ãã ããè¯ãããšã¯ãããåŠçããããšã§ãã çããã®å€ããããããåãçµãã§ããã»ãã¥ãªãã£åé¡ã«ã¯ã©ã®ãããªãã®ããããŸãã? 1ã€ã¯ãç»åãã¹ãã£ã³ããŠãããšãã«å ±åãããCVEãéåžžã«å€ããã°ã«èšé²ãããŠããããšã§ãã æšæ¥ãçããã®äœäººãã«åºäŒããŸããããããããªããšãããŠãããšã¯æããªãããšèšããŸããã ã§ããããããã¯æžå¿µäºé ã§ãããã§ããå Žæã¯ãããããããŸãã ãã®æ¹æ³ã®ããã€ãã«ã€ããŠã話ãããŸãã
ããäžã€ã¯ãç§ãã¡ãèªç€Ÿã®é¡§å®¢ã調æ»ããã°ããã®ã¬ããŒãã®1ã€ã§ãã Sysdigã¯SaaSãã©ãããã©ãŒã ãéå¶ããŠãããå€ãã®ã客æ§ãã³ã³ããå¿åã§ãã å®éã« root ãšããŠã³ã³ãããå®è¡ããŠããã客æ§ã®æ°ã調ã¹ãŸããã ããŠãæã«ã¯ããããå¿ èŠãããã®ã§ãããã«ã€ããŠã¯åŸã§èª¬æããŸãããç§ãã¡ãèŠãŠããã³ã³ããã® 83%ã¯ã«ãŒããšããŠå®è¡ãããŠãããããã¯éåžžã«å¯å®¹ã§ãããããããæ£ããããšã§ã¯ãããŸããã ãã®çç±ã«ã€ããŠã¯ãåŸã»ã©èª¬æããŸãã
ç§ãã¡ãèŠãŠããããäžã€ã®åé¡ã¯ãã¢ã¬ãã¯ã¹ãããã«ã€ããŠè©±ããšæããŸãããç§ãã¡ãå§ããã€ã¡ãŒãžã¯ãããŒã¹ã€ã¡ãŒãžãšããŠã€ã¡ãŒãžãã€ãã¿ãããã䜿ã£ãŠæ§ç¯ãå§ããã®ã¯ãšãŠãç°¡åãªã®ã§ãããã«ã¯å€ãç ããªããããªãã®ããããšããããšã§ãã
åºæ¬çã«ã¯ãç»åã®å 容ãèŠããšãããã«ã¯ããããæé«ã§ã¯ãªããã®ãããªãããããå«ãŸããŠãããšããããšã§ãã ããªãã¯ã€ã³ã¿ãŒãããäžã®ã©ã³ãã ãªå ŽæããNginxããå§ããŠããŸãã ãããå šäœçãªã€ã³ãã©ã§äœ¿çšãããšãæéãç¯çŽã§ããŸãããéåžžã¯ãŸã ç¥ããªããã®ãå«ãŸããŠãããããæåã«è¡ãã¹ãããšã¯ã¹ãã£ã³ããããšã§ããã? æ§æçã«ãè匱æ§çã«ããæ°ã«ãªãå¯èœæ§ã®ãããã®ã¯ãã¹ãŠ 90%çšåºŠã§èŠã€ãããŸãã ã€ãŸããã¯ãªãããžã£ããã³ã°ãã·ãŒã¯ã¬ããã®åã蟌ã¿ããã®ä»ã®ãããã·ã«é¢ããããšãªã©ãããŸããããªãå¯èœæ§ããããšããããšã§ãã ãããããã®ã³ã³ããå ã®ãã®ã®çŽ 10%ã¯ãå®éã«å®è¡ãéå§ããããŸã§è¡šç€ºãããŸããã
ã€ãŸãã 90%ãšããã®ã¯çŽ æŽãããããšã§ãããããã§ã 10%ã®ãªã¹ã¯ãè åšã¯ããã®ç¹å®ã®ã³ã³ããã§å®éã«ã¯ãŒã¯ããŒããå®è¡ãããŸã§çŸããŸããã ãªãéèŠãªã®ããšãããšããã®å€ããããªã倧ããªåœ±é¿ãäžããããããšãªãã¯ã話ããŠããã¬ããŒãã§ã¯ãã¯ãªãããã€ããŒã1ãã«ãçæããããã«ããããã53ã®ãªãœãŒã¹ãæ¶è²»ããŠããããšã瀺ãããŠããŸããã?ãã®ãããXMãªã°ããã®ç»åã®å éšã«ãã€ã¯ãããŠããã®ã¯ã倧ããªåé¡ã§ãã ãããã£ãŠãéçºãããææããªããžããªã«ããææãã¯ã©ã¹ã¿ãŒã«åãå ¥ããããææãšããã³ã³ããã¹ãã§ãããã®ããšãèŠãŠããªããšãããŸããŸãªäž»èŠãªé åãèŠéããŠããããšã«ãªããŸãã ãããŠããã®éçºã©ã€ããµã€ã¯ã«ãããããããã®ããšã念é ã«çœ®ãå¿ èŠããããŸãã
ããã¯ãç§ãã¡ã®çµç¹ã«å€ãã®äŒæ¥ãæã£ãŠããè åšèª¿æ»ããŒã ãããã圌ãããããã®ããšãçºèŠããè峿·±ãããã°ãããããæžããŠããç§ãã¡ã¯ãã®ãããªããšãèµ·ããŠããã®ãç®ã®åœããã«ããŠããããããŠããã®å€ãã 10%ã®åéã§èµ·ãã£ãŠããããšè¿°ã¹ãŠããããšã«èµ·å ããŠããŸãã
ãã«ã ãã©ã¯ãã£ã¹
ãã«ãã®å®è·µã«ã€ããŠå°ãã話ãããŸãããã ããã«ã€ããŠã¯ãããã«èª¬æããŸãã ã³ãŒããšãã®æ¹æ³ã瀺ãã€ããã¯ãããŸããããããã®ããã€ãã¯ç°¡åãªããšã§ãã ä¿¡é Œã§ããæ å ±æºã䜿çšããŠãã ãããã? ç§ãã¡ã¯ãæ¢ç¥ã®ãããªãã·ã£ãŒãä¿¡é Œã§ãããœãŒã¹ãããèªå®ãããªãã·ã£ãŒã«å¯ŸããŠæ£ããããšãè¡ã£ãDocker Hubãªã©ã®ã€ã¡ãŒãžãååŸãããããã®ãªããžããªã§ã¹ãã£ã³ãããŠãããã®ãååŸããŠã圌ãã«äœãèµ·ãã£ãŠããã®ããææ¡ããããšèããŠããŸãã ä»é±ãã客æ§ããã®é»è©±ãèããŠããŸããã ãããŠããã®ãã¡ã®1人ããã¯ããç§ãã¡ã¯ãã«ã ãã£ãŒãã䜿ã£ãŠäœããå±éããŠããŸããããšèšããŸãããããã«ã¯ããã®ç»åãåŒã£åŒµã£ãŠãããã»ãã¥ãªãã£ã§ãã¹ãŠã®ãã®ãã©ã³ãã ã«è¿åããã¹ãã£ã³ãããŠããªãå ŽæããååŸãããšããè¡ããããŸããã ãããã¯ããªããé¿ãããçš®é¡ã®ãã®ã§ãããã ããããä¿¡é Œã§ããããšã確èªããŠãã ããã
ããã¯ãã¹ãŠããªããããªãã®æ å ±æºãç¥ã£ãŠããããšã確èªããããšã§ããããããè¡ãã«ã¯ããŸããŸãªæ¹æ³ããããŸãã æ¬åœã«ç°¡åã«å®çŸã§ããæ¹æ³ã®1ã€ã¯ãç»åã®ååžãã©ããªã£ãŠããããšããããšã§ãã ããã¯ã©ã³ãã ãªUbuntuã€ã¡ãŒãžã§ãã? UBIã®ç»åã§ãã? ããã¯ChainGuardã®ãããªå¶å©å£äœããæ¥ãŠããŸãã?ããã«å¯ŸåŠããæ¹æ³ã¯ããã€ããããŸããããã®ã¢ããªã±ãŒã·ã§ã³ã®æ§ç¯ãéå§ãããšãã«ãå šäœçã«ããè¯ãå§¿å¢ãä¿ã€ããšãã§ããŸãã
1ã€æãããªããšã¯ãäžå¿ èŠãªç¹æš©ãé¿ããããšã§ãã ããªãããããå©ããããšãã§ãããªããrootãšããŠå®è¡ããªãã§ãã ããã ããŠãèŠãŠãã ããããããå¿ èŠãªãšãããããŸãã å®éããã®ã³ã³ãããç¹æš©ãšããŠå®è¡ããããã«å¿ èŠãªé©åãªã¬ãã«ã®æŽå¯ãåŸãããã«ãç§ãã¡ãè¡ã£ãŠããããšãããã€ããããŸããã? ãããããããå¿ èŠãªå Žåã¯ãç°å¢å ã§ä»ã®ããšãããªãããã«ããããæ£åœåããããšãã§ããŸãã
ããã«å ããŠãä»ã«äœãä»ãå ããããšã¯ãããŸãã? ç§ã¯æ¬åœã«ããã§ã¯ãªããšããæå³ã§ãããã ããæ³šæããŠãã ããã å°ãªããšããã³ã³ããã誰ãšããŠå®è¡ããããæå®ããŠããããšã確èªããå¿ èŠããããŸãã 奜ããªããã«èµ°ãããã ãã§ã¯ãããŸããã ç¹å®ã®ãŠãŒã¶ãŒåãããããã®ããã«äœ¿çšãããã®ãæå®ããŠãã ããã æ¬åœã«ãæ¬åœã«ç°¡åã«æã«å ¥ãã®ã¯ããã®ç¹å®ã®å®¹åšã®å§¿å¢ãéãããŠããããšã確èªããããšã§ãã æš©éã¯ã¯ãã§ããã? ãããã¯å¿ ããã察åŠããã®ãæã楜ããããšã§ã¯ãªããç§ãã¡ã¯çãäžæ¥ãéããããã ãã«chmod 777 ãè¡ã£ãŠããŸããããããããæ¬çªç°å¢ã§ã¯ãããè¡ãã¹ãã§ã¯ãããŸããã
çŽ æŽãããããããŠãç§ãééã£ãŠããå Žåã¯ç§ãä¿®æ£ããŸãããåããŠç»åãååŸãããšããããã¯æ¬è³ªçã«ã«ãŒããšããŠèšå®ãããŠããŸããã? éåžžããŠãŒã¶ãŒãšããŠå®è¡ãããŠããç»åããããã衚瀺ãããŸã 1000ã 倧äžå€«ã§ããã ãŠãŒã¶ãŒ 0ã ã¯ã ãããåªããŠããŸãã
次ã¯ããå°ãããªãããŒã ãšæããŸãã ããããç§ã®ã€ã¡ãŒãžã«ãã©ãçãã®ã¯ãäŸåé¢ä¿ããã®ä»ã®ããã±ãŒãžã§ç¶æ¿ãããå¯èœæ§ã®ãããã®ããŸãã¯å ã»ã©Nginxã®è©±ããããããããŸããããç§ã䜿çšããªããã®ããã¹ãŠå«ãŸããŠããŸãã ãããã®ãã®ãè匱ã§ãããšããããªãã¯ããããç§ãã¡ãåŒã¶ãšããã®è¥å€§åãæ£ããã€ã¡ãŒãžãæã£ãŠããŸãã ããªãã¯ããã«ã€ããŠæ³šæãããã§ãâããªãã®ç»åãã¹ãªã ã«ä¿ã¡ãŸãã
ããã¯ãã«ãã¹ããŒãžãã«ãã§ãâãã®æŠå¿µãããããããŸããã? åºæ¬çã«ã¯ãå¿ èŠãªãšãã«å¿ èŠãªãã®ãéããŠãããšããæå³ã§ãã äŸãã°ãããæç¹ã§å¿ èŠã«ãªãå¯èœæ§ã®ãããã®ããã¹ãŠåããŠãããã®ãå¿ ãããæã«å ¥ãã«è¡ãå¿ èŠã¯ãããŸããã éåžžã«åçŽãªãã®ããå§ããŠãå¿ èŠãªã¬ã€ã€ãŒã®ãã®ã€ã¡ãŒãžã«å¿ èŠãªãã®ãå±éããŠãã ããã åºæ¬çã«ã¯ããã®ããšãæå°éã«ãšã©ããããšã倧åã§ãã ãããæã£ãŠããªãã倪éœã®äžã§ãã¹ãŠãæã£ãŠããã ããããã³ã³ããã«netcatã¯å¿ èŠãããŸããã ã¯ããããã¯ãã£ãããã§ãããé²åºã¹ãããã§ãããã®ã§ãããªããããªãã®å€åããããŠããããšã確èªããŠãã ããã çã«ããªã£ãæ¹æ³ã§ç©äºãè¡ãã ã¹ãªã ã«ä¿ã¡ãŸããæå°éã«æããŠãã ããã
æ¢ç¥ã®æå°éã®ç»åããå§ããããšãã§ããŸããããã®ãã£ã¹ããªãã¥ãŒã·ã§ã³ã¬ã¹ã®æŠå¿µããããŸãã çµå±ã®ãšãããã¢ããªã«å¿ èŠã®ãªãããŒãã®ãããªãã®ãããããå ¬éããããããŸãããã?
æµãããªãã«è¿ã¥ããééã£ãããšãããæ¹æ³ãæžããããã«ã§ããããšã¯ãããããããŸãã ç§ãã¡ã¯æ£ããããšãããããšã«ã€ããŠè©±ããŠããã®ã§ãã è³æ Œæ å ±ãããŒãã³ãŒãããªãã§ãã ããã ãããéµã§ããã? ããå€éšã¹ãã¢ã®ãããªãã®ã䜿ããã®ã§ããã°ãããšãããã奜éœåã§ãã£ãŠããå éšã«ç§å¯ã®ãããªãã®ãå ¥ããããããŸããã ãããããããªãæ¹ãããã§ãããããªããªãã誰ããããã«å°éãããšããã«ã圌ãã¯ä»ã®ããšãå§ããããšãã§ããããã§ãã
ããã¯ãæ©æã«ããããŠé »ç¹ã«å§ããããã®ãã¹ããã©ã¯ãã£ã¹ã§ãã ç§ãäœåºŠèŠããããããŸããããéçºè ãèªåã®ã©ãããããã§è¡ã£ãŠããããšãããããã·ã³ãã«ã«ããŠããããã§ãã 圌ãã¯ãã¹ãã«åæ Œããããšãã§ããŸããã圌ãã¯ããã«è·ç©ãéã¶ããšãã§ããŸããã ããã¯äŸ¿å©ã§ãã誀解ããªãã§ãã ããããããããªãã¯æåã«ãããã®è¡çç¶æ ãå®è·µããå¿ èŠããããŸãã ããããªããšãäºæ ãèµ·ãããŸãã æªæãããããšã¯ã»ãšãã©ãããŸããã ãŠãŒã¶ãŒã¯ããªãã£ã¹ã¹ããŒã¹ã§èªåã®ãã¡ã³ã¿ãžãŒã远äœéšããããªãããå°éãçããããªãã®ã§ã¯ãããŸããã 圌ãã¯ãã èªåã®ä»äºãããããšããŠããã ãã§ããã? ãããŠãããªããæªãç¿æ £ãæªãè¡çç¶æ ãç¥ã£ãŠããããšä»¥å€ãèª°ãæ¬åœã«æªãããã§ã¯ãªãã®ã§ã人ã ãæåããæ£ããæ¹æ³ã§ãããè¡ãããšãã§ããããã«ããããšãéèŠãªã®ã§ãã
æããã«ã次ã®è³ªåã¯ãæ©å¯æ å ±ãå«ããªãã§ãã ããã ç§ãã¡ã¯æ¬åœã«è¯ãããã°ãæã£ãŠããŸãã®ã§ãæåŸã«ç޹ä»ããŸãã ã§ããããã«ã¯äœãããã®ãã®ãå ¥ã£ãŠããŠãããããã«ã¯ãªããšæã£ãŠãããã§ãããå®ã¯ãŸã ã¬ã€ã€ãŒã®1ã€ã«äžãã£ãŠãããã§ãã ãã®ãããªãã®ã¯ãããªããæãŸãªãæ©å¯ã®æ§è³ªã®ãã®ããŸã ããã«ãããããããŸããã
ãªã³ãµã€ããŸãã¯ã©ããã§ãã©ã€ããŒãã¬ãžã¹ããªã䜿çšããŠãã人ã¯äœäººããŸãã? ãããããã®ã¯è¯ãããšã§ããããããä¿è·ããããã«é©åãªçš®é¡ã®æš©éããã®ã䜿çšããŠããããšã確èªããŠãã ããã ãããšéä¿¡ããããã®é©åãªçš®é¡ã®å®å šãªãããã³ã«ã䜿çšãããªã©ã ãããã€ãŸããããã€ãã®ã¬ãžã¹ããªãæã€ããšãæããªãã§ãã ããã ããªãã¯ããã¹ãŠã®ã¢ãŒãã£ãã¡ã¯ããæšãŠãŠã倪éœã®äžã®ãã¹ãŠãããã«å ¥ãããããŠãããªããããããçš®é¡ã®é»éã®ã€ã¡ãŒãžããã¹ãŠä¿æãããã®ããããããããŸãããã? æ¬çªç°å¢ã§å®è¡ãããŠãããã®ã¯ãéçºãã©ã³ããããã¬ãžã¹ããªãšã¯ç°ãªãã¬ãžã¹ããªããæ¥ãŠããå¯èœæ§ããããŸãã ããã«ãããããã»ã¹ãéããŠç©äºã宣äŒããéã«ãããçšåºŠã®å³å¯ããæã€ããšãã§ããŸãã
èªåãã§ãã¯
ããã¯ãç§ãã¡ãéèŠã ãšèããŠããããã€ãã®ããšã«ã€ããŠå°ã説æããŸãããã«ãã®èгç¹ããèããããšããªãæ¹ã®ããã«ããããã®ããšã®ããã€ãããã§ãã¯ãèªååããæ©èœããåç¥ã§ããããå¿ããŠããŸã£ãå Žåã«åããŠããªã³ã¿ãŒã®ãããªãã®ãèšçœ®ããŠãæ£ããããšãããªãã£ãå Žåã«èŠåããããšãã§ããŸããã€ãŸãã Haskell Dockerfile Linter ãšåŒã°ãããã®ããããå®éã«è¡ãéããåã«ããããã®åé¡ã®ããã€ããå ¬éããŸãã
ã ãããããããæåã®æ¹æ³ã§èšå®ãããŠããªããããã®ããšã«å¯ŸããŠã¯ãããŸãäœãã§ããªãããšãããããŸãã äžéšã®ç»åã¹ãã£ããŒã¯ãSysdigããããã®ãã®ã®äžéšãèŠãããã«ããããã®æŽå¯ãæäŸããŸãã ããšãã°ããã®ç»åã¯ã«ãŒããšããŠèšå®ãããŠããŸãã äŸãã°ããã€ãã©ã€ã³ãçµç±ããäœããé²è¡ããã®ãå®éã«ãããã¯ããããšãã§ããŸããããã®ã¬ãã«ã®å¯èŠæ§ãèªåçã«è¡ãããããã«ããããšã§ãåã«è匱ãªãã®ãèªã¿åãã ãã§ãªããããã§ããã? èšå®ããªãã«ãªã£ãŠããããšã
ããŠãèªåã®çµç¹ã§ã¯ãå®éã«ã¯ã¹ãã£ã³ãè¡ã£ãŠããªãããŸãã¯å°ãªããšãç»åãååã«è¡ãããŠããªããšèããŠãã人ã¯ã©ããããããã§ãããã? ãããèŠãŸããã ããã¯ããªãã®ããžãã¹ã®æ§è³ªããããªããåããŠããèŠæš¡ãã¹ããŒãã«ãããã®ãããããŸãããããããäœããã®ã¬ãã«ã圢ã§è¡ãã®ã¯è¯ãããšã§ãã ãåç¥ã®ããã«ãããããçµã¿èŸŒãã¬ãžã¹ããªã¯ãããããããŸãã ããã¯ããã«ãããããããå ã«é²ãã§ããã䜿çšããã®ã¯è¯ãèãã§ã - ãããã¯ã©ãŠãã岞å£ã®äœãã§ããããšããããã¯ãã以å€ã®ãã®ã§ããããšã ãŸããã¹ã¿ã³ãã¢ãã³ã®ããŒã«ã§ãå©çšã§ããŸãã ç§ãã¡ã¯Snykãšããçµç¹ãšææºããŠããŸããçŸåšãDocker ScoutãšææºããŠããŸãã ãããŠããããã¯ãç©äºãã¹ãã£ã³ãããŠããããšã確èªããããã«é 眮ã§ãããã®ã§ãã ã¹ã«ãŠããããããã£ãŠããããšã¯ç¥ã£ãŠããŸããç§ãã¡ã¯ããããç§ãã¡ãæšå¥šãããã®ãããã«å¯ŸåŠããããã«ããªãããã ã¶ã€ããããšãã§ãããã®ã ãšèšããŸãã
çŽ æŽãããã®ã¯ããã®ãã€ããŒãªãªããžã§ã³ã«ã¢ããã°ã¬ãŒãããã ãã§ãå®éã«ã¯ããã ãã®åé¡ã解決ããããšããèªã¿åºããåºãŠããããšã§ãã ã¯ã³ã·ã§ããã®ããã«ãã»ãã¥ãªãã£ã®èгç¹ããã¯ã¯ããã«è¯ãç¶æ ã«ãªããŸãã ã§ãããããããã®ããšã¯æéãç¯çŽãããšããç¹ã§éåžžã«éèŠã§åœ¹ç«ã€ããšã§ãããã¢ã¬ãã¯ã¹ãããã«ã€ããŠå€ãã®ç¹ãææããã®ãæäŒã£ãŠãããããšãç§ã¯ç¥ã£ãŠããŸãã ããã¯å®å šã§ããã ãã§ãªããæéãç¯çŽããããšã§ããããŸãã
次ã®ã¹ã©ã€ãã¯ããããåŠå®ã«è¡šããŠããŸãã CI/CDãã€ãã©ã€ã³ãJenkinsãªã©ã䜿çšããŠãã人ã¯ã©ããããããŸãã? ãããããã¯ããªãã®äžéšã§ããããŸã ãããããŠããªã人ããããããããŸããã ããããã¹ãã£ã³ã®äžéšãããã«æŒã蟌ãããšãèããŠã¿ãŠãã ãããããããã°ãJenkinsã®ãããªäœãã«ä¹ã£ãŠãããšãã«ããããã®èªã¿åãå€ãããã«åŸãããããã«ãªããŸãã ãããŠããããå®éã«ã¬ãžã¹ããªãªããžããªã«æµã蟌ãåã«ããããã«å¯ŸåŠããŠããã®ã§ãã ãŸããããã ãã§ã¯çµãããªããšãèããŠããŸãã ã€ãŸããã¬ãžã¹ããªã®ã¹ãã£ã³ãæ§ç¯äžã®ã¹ãã£ã³ãªã©ã§ãã ããã«ãã©ãçãã®ã«åœ¹ç«ã€ããŒã«ã¯ãããããããŸãã®ã§ããããã®åé¡ã«è¿ éã«å¯ŸåŠã§ããåŸã§èª°ãã«è©ãå©ãããããšã¯ãããŸããã ãããŠãã©ã³ã¿ã€ã ã«é¢ããããšãèæ ®ããå¿ èŠããããŸãããããŠç§ã¯ããªãã«ãããåãããšãä»»ããŸãã
ãããæ¬åœã«éèŠã«ãªãã®ã¯ãã¢ããªã±ãŒã·ã§ã³ãäœã䜿çšããŠããããæ£ç¢ºã«ææ¡ã§ããããããšæããŸãããã éçºè ã®èŠç¹ããèŠããšãå€ãã®å Žåãããçš®ã®åºæ¬ã€ã¡ãŒãžããå§ããŠããã®äžã«ã¢ããªã±ãŒã·ã§ã³ã®å®è¡ã«å¿ èŠãªãã®ãéããŠããŸãã ãããŠãæ¬çªç°å¢ã«ãããã€ããŠããŸãã å¿ ç¶çã«ãCVEãè匱æ§ããããŠä¿®æ£ããªããã°ãªããªãããšã®ãªã¹ããã2é±éã3é±éã4é±éåŸã«å€§éã«æã«å ¥ãããšã«ãªããŸãã ãã®å€ãã¯ãå®éã«ã¯æŽ»çšããŠããªãç»åãããã°ããã±ãŒãžã®æ°ããæ¥ãŠããŸãã çŸåšãSysdigã®ãããªäººã ãšãã©ã³ã¿ã€ã ã¹ãã£ã³ã®æŠå¿µãè¡ã£ãŠããä»ã®äººã ãšã®éã«ãçŽ æŽãããæè¡ãç»å ŽããŠããŸãã ããã¯ãåã«ã€ã¡ãŒãžãå床ååŸããã ãã§ãªããã€ã¡ãŒãžå ã®ã©ã€ãã©ãªã調ã¹ãŠããããã³ã³ããã«ãã£ãŠå®éã«å®è¡ãããŠãããã®ã«é¢é£ä»ããããšã§ãã
ãããã£ãŠãã«ã¹ã¿ã ã€ã¡ãŒãžããã«ããããšããã®ã€ã¡ãŒãžå ã®ã©ã®ã©ã€ãã©ãªãå®éã«äœ¿çšããŠã¢ããªã±ãŒã·ã§ã³ã匷åããŠããããææ¡ã§ããŸãã æçµçã«ã¯ãåºæ¬çã«ããããã® 15ã20 ããã±ãŒãžããããã® 30ã 40ã 50 ã©ã€ãã©ãªãç§ã®ã³ã¢ã¢ããªã±ãŒã·ã§ã³ãæ§æãããšèšãããšãã§ããŸãã ãããŠãããã«ã¯ä»ã®ã©ã€ãã©ãªãã€ã¡ãŒãžãããã±ãŒãžãªã©ãããããããã¯äžåºŠãåŒã³åºãããããšã¯ãããŸããããè匱æ§ããããŸãã
2ã€ã®ããšãããŸãããã ã¬ããŒããäœæãã䜿çšäžã®ãã®ãšäœ¿çšãããŠããªããã®ã®éã«ç·ãåŒããŸãããã 䜿çšäžã®ãã®ãä¿®æ£ããææ¥ã¯ãã¢ããªã±ãŒã·ã§ã³ã«ãã£ãŠå®éã«åŒã³åºãããããšã®ãªãè匱ãªãã®ããã¹ãŠåé€ããŸãããã ã€ãŸããã»ãã¥ãªãã£æ åœè ã¯ãã¢ããªã±ãŒã·ã§ã³å ã§å®éã«å®è¡ãããŠãããã®ã ãã«ç¯å²ãéå®ããŠããããã 50 ããŒãžã«ãåã¶è匱æ§ã®ãªã¹ããæäŸããŠããªããšããããšã§ãã æ¬¡ã®ã€ãã¬ãŒã·ã§ã³ãµã€ã¯ã«ã次ã®ãããé©çšãµã€ã¯ã«ã§ã¯ããããããªã³ããå€§å¹ ã«åæžãããŸãã ãã®ãããååã¯ãŸã ããªãé·ãã§ãããä¿®æ£ãã代ããã«ã䜿çšããŠããªãç¶¿æ¯ããã¹ãŠåãé€ããŠããŸãã ãããŠæ¬¡åã¯ãã¢ããªã±ãŒã·ã§ã³ã«ãã£ãŠå®éã«äœ¿çšãããŠãããã®ã«é¢ããã¬ããŒãã®ã¿ãååŸããŸãã ããã«ãããéçºè ã®æéãç¯çŽã§ããŸããã»ãã¥ãªãã£æ åœè ã®æéãç¯çŽã§ããŸããããã¯ããªããæ¬åœã«æ°ã«ããŠããããšãããããã«ããªãã®äžæ¥ã®äžã§ããå€ãã®æéãäžããŸã - ããã¯ããªãããã§ã«ãã£ãããšããããããã ãã§ãªããããªãã®äŒç€Ÿã«äŸ¡å€ãä»å ããããšã§ãã ã§ãããããã®ã©ã³ã¿ã€ã èŠçŽ ã¯æ¬åœã«è峿·±ããã®ã§ãåºæ¬çã«ã¯ããã®ç»åå ã®æœåšçãªãªã¹ã¯ãçµã蟌ã¿ãå®éã«éèŠãªããšã ããé²ããããšãã§ããããã«ããæ¹æ³ã§ãã
éåžžã«è¯ãã§ãããããŠããã«çްãããã€ã³ãã眮ããŸãããã ãããããªããããé£ããã®ãããããŠãªããã®ãããªCVEã¬ããŒããè¿ã£ãŠããã®ãã«å§åãããå¯èœæ§ããããšããããšã§ããã£ãããšã§ãã ããã«ã¯ããããã®ãã®ããããå€ãã®ã客æ§ãåããŠã¹ãã£ã³ããç»åã䜿çšããéèŠåºŠã®é«ããã®ãéèŠãªãã®ããããããããŸãã ãããŠãããã«ã©ã察åŠããã°ããã®ãããšããæãã§ãã ãã®èª²é¡ã®äžéšã¯ãæ¥ã ããã°ã«èšé²ãããCVEããŸããŸãå¢ããŠããããšã§ãã ããã§ãã©ã³ã¿ã€ã èŠçŽ ã®åºçªã§ãã ã ã£ãŠãããããã¢ã°ã©ãããã®ã·ããªãªã«ãªã£ã¡ããããã
ããããç§ãã¡ã¯æ·±å»åºŠãèŠãããšæã£ãŠããŸã - å€ãã®äººã¯ãé«å€ãšé倧æ§ã ãã«å¯ŸåŠããã§ãããã 圌ãã¯ããšã¯ã¹ããã€ãããããã©ãããç¥ãããã£ãŠããŸãã ããããããã¯è匱ã§ãããç§ãã¡ããããŸã§ã«èª°ãããããæªãç®çã«äœ¿çšããæ¹æ³ãèŠãããšããããŸããã ãããç¥ãããšã¯éèŠã§ãããã€ã³ã¿ãŒãããã«å ¬éãããŠãããã®ã«åºã¥ããŠåªå é äœãä»ããããšãã§ããããã§ãã ããã«ã¯å¥ã®çšèªããããŸãããæãåºããŸããã ãšã«ãããnet-netãããã¯å°éå¯èœã§ãã? ä¿®æ£ã¯ãããŸãã? æ¢ç¥ã®ä¿®æ£ããªãå Žåã¯ããã®è匱æ§ã«å¯ŸããŠä»ã«äœãä¿è·ããããææ¡ããããæ¢ç¥ã®è匱æ§ãæªçšãããŠããåäœãç£èŠããããšèããŠããŸãã ãããŠããã®æ°ããæ¬¡å ããIs it in useãã远å ããŠããŸãã ãããŠããããSysdigã®ä¿¡æ¡ã§ãããSysdigã«ã€ããŠä»ã«èŠããŠããããšãäœããªããšããŠããããã¯è¯ãããšã§ãã
Sysdigã®
æåŸã«ãAlexããã©ãããã©ãŒã å šäœã«ã€ããŠã話ãããŸãããã©ã³ã¿ã€ã ã«é¢ãããã¹ãŠã®ããšãå¯èŠåããã®ã«åœ¹ç«ã£ãŠããŸãã ãããŠããããåªå é äœä»ãã«åœ¹ç«ãŠãŠããŸãã å€ãã®çããã¯ãéçºè ã§ããã°ããã®å³ã®å·ŠåŽã«ãããããããŸããããäžéšã®æ§æã§ã¯ãæš©éã«ã€ããŠè©±ããŸããããäœæ¥å 容ã«ãã£ãŠã¯ããã®æŠå¿µã䜿çšããŠäœ¿çšããŠããŸãã 䜿çšäžã¯ãäœãåªå ããªãããæ±ºå®ããã®ã«åœ¹ç«ã€ããäœãã·ããããŠå€æŽããããæ±ºå®ããã®ã«åœ¹ç«ã¡ãŸããã? ã§ã¯ããããªãã¯ã¯ã©ãŠãã®ããã«ã³ã³ãããå®è¡ããŠãã人ã¯äœäººããã®ã§ãããã? ã ãããç§ã¯ããããã¹ãŠã®æš©éãäžããããŠããŸããããããããæ±ºããŠäœ¿çšããªããããŸãã¯ç§ã®ä»äºãããå¿ èŠããªããã®ããã§ãã ç§ãã¡ã¯ãããªãããããçè§£ããã·ããããå€ããããšãã§ããããã«ãæäŒãããŸãã
é»è©±åŽã§ã¯ãã客æ§ã®äžäººãããããããªãã¯ç§ã«ããããã®æéãç¯çŽããŠããããšèšã£ãŠããŸãã ãããŠããããã¢ã¬ãã¯ã¹ãèšã£ãŠããããšã®æ£å³ã§ãã æšæ¥ããŒã¹ã§åãã質åãåãäžããŠã¿ãŠãç§ã話ããçããã®å€ãããSysdigã®ç§å¯ã®ãœãŒã¹ãã©ããã£ãŠç¥ãã®ããã³ã³ãã以å€ã«ãäœããåããŠãããã©ãããç¥ãã®ãããšãã質åãåããŸããã ã©ã®ããã±ãŒãžãå®è¡ãããŠãããã¯ãã©ãããã°ããããŸãã?
ç§ãã¡ã®èšè£ æ¹æ³ã¯ãã»ãšãã©ã®ãã®ãšã¯å°ãç°ãªããŸãã ç§ãã¡ã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ãã詳现ãåŒãåºãããã«ãäžçš®ã®ããã ã¢ããã¢ãããŒããæ¡çšããŸããã ãã®å€ãã¯ç§ãã¡ã®å®¶ç³»ããæ¥ãŠããŸãã Sysdigã¯çŽ 10 幎åã«èšç«ãããWiresharkã®å ±åéçºè ã«ãã£ãŠèšç«ãããŸããã ãŸããWiresharkã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ãææããŠããå Žåããã±ãããååŸããŠã¢ããªã±ãŒã·ã§ã³å ã§äœãèµ·ãã£ãŠãããã確èªããããã®çŽ æŽãããããŒã«ã§ããã ç§ãã¡ã解決ããããšããåé¡ã¯ãã€ã³ãã©ãã¹ã€ãããªã©ãææããŠããªãã¯ã©ãŠãã§ãã©ã®ããã«ãããå®çŸããããšããããšã§ããã ã¹ãã ããŒãã«ã¢ã¯ã»ã¹ã§ããªãã®ã§ãããã©ãããŸãã? ç§ãã¡ãèãåºãã解決çã¯ãã¯ã©ãŠãã§æãäžè¬çã§ãªã忝ã¯ãç§ãã¡ãå®è¡ããŠãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ããã
ã«ãŒãã«ã«å ¥ã蟌ã¿ãã·ã¹ãã ã³ãŒã«ãã€ã³ã¿ãŒã»ããã§ããã°ããã±ãããšåãã¬ãã«ã®ç²åºŠãåŸãããŸãã ã§ããããå®éã«ã¯ãããæå³ã§ã¯ããè©³çŽ°ã«ææ¡ã§ãããšèšããã§ãããããnet-netã¯ããã¹ãŠã®ã·ã¹ãã ã³ãŒã«ããã¹ãŠã®ããã»ã¹ããã¹ãŠã®ãã¡ã€ã«ã¢ã¯ã»ã¹ã確èªã§ãããããã©ã€ãã©ãªãããã±ãŒãžããããäœããæ¥ãã®ãã«é¢é£ä»ããããšãã§ãããšããããšã§ãã ãã®ãããã©ã³ã¿ã€ã ã¯ãŒã¯ããŒãã«é¢ããéåžžã«è©³çŽ°ãªæ å ±ãååŸããããã§äœãèµ·ãã£ãŠãããã確èªã§ããããã«ãªããŸããã ãã®åŸã次ã®ã¹ããŒãžã«é²ã¿ããããã¯çŽ æŽããããå®è¡äžã®ã¯ãŒã¯ããŒãã®ããŒã¿ããã¹ãŠç¢ºèªã§ãããã¯ã©ãŠãèªäœã¯ã©ãã ããããšèããŸããã 䜿çšããŠããä»ã®SaaSãµãŒãã¹ã¯ã©ãã§ãã?
ç§ãã¡ã¯ãã·ã¹ãã ã³ãŒã«ã®ã€ã³ã¿ãŒã»ããã«ã€ããŠãåãã¢ãŒããã¯ãã£ãæ¡çšããKubernetesã®ç£æ»ãã°ãAWSã®ã¯ã©ãŠã蚌跡ãã°ãGCPã®åæ§ã®ãã°ãOktaã®ãã°ãªã©ãããããçš®é¡ã®ãœãŒã¹ã調ã¹ãŠãæªæã®ããã¢ã¯ãã£ããã£ãã¹ããªãŒãã³ã°ããŒã¿ã®æŠå¿µãæ¢ãããšãã§ããããã«ããŸããã ã€ãŸããç§ãã¡ã䜿çšãããšã³ãžã³å šäœã¯ãå ¥ã£ãŠãããã¹ãŠã®ããŒã¿ãèŠãŠãç°åžžãªæŽ»åãèŠãŠãããšããããšã§ããã ããã¯ãSnort ããã¿ãŒã³ããã±ãããèŠãã®ãšã»ãŒåãã ãšèããããšãã§ããŸãã Sysdigã¯ããã¿ãŒã³ãã·ã¹ãã ã³ãŒã«ãç£æ»ãã¡ã€ã«ããã°ãã¡ã€ã«ãªã©ã調ã¹ãŠããŸãã æ¶Œããã
ããã§çãã¹ãããŒã¯ã«åãæãããŸãã ãã 容åšåŽã«çްãããã€ã³ããä¹ããããã ãã«ã ã³ã³ããã¯å·ŠåŽã®ããã«èŠããå ŽåããããŸãã ããããã©ãã䜿çšãããŠããããæããŠãæéããéãåŽåãå€§å¹ ã«ç¯çŽããçŸåšçµéšããŠããç²åŽã®äžéšãæžããããšãã§ãããšãããã©ãã§ããããã æåŸã®ç¬éã«ãèŠéããå Žåã§ããããã¯Docker Scoutã®ãããªãã®ã掻çšãå§ããèšç»ã®äžéšã§ãã ãããDockerã®äººã ãšäžç·ã«æã¡èŸŒããã®ã§ãããæšæ¥ãããçºè¡šã§ããããšãéåžžã«å¬ããæããŸãã ç¹°ãè¿ãã«ãªããŸãããåãäŸ¡å€ææ¡ã§ãã ããããæãéèŠãªã®ã¯ãå®å šãªç»åãããè¿ éã«æäŸããããšã§ãã
ã€ãŸãããã®æ å ±ã¯ Vex (è匱æ§äº€æ) ã®åœ¢ã§ Docker Scout ã«éä¿¡ãããããDocker Scout ã«ãã£ãŠåŒãåºããããããŠã次ã®ãããªå¯èŠæ§ãåŸãããŸãã ããããããã¯ãå®éã«äœã圱é¿ãåããã®ããæç¢ºã«ææ¡ã§ããããã«ããããšã§ãããªããªãã誰ããããã«ãã©ãçãããšãã§ããããã§ãã ãããŠãããã«ç ã£ãŠããã®ã¯äœã§ãããã? ãããéèŠã§ãç§ãã¡ã¯ãããªããææã§èŠã€ããŠããç¬éãèŠãã®ã倧奜ãã§ããã®åŸã圱é¿ãåãããã®ã ããèŠããŠããããšããã®æ°ããã£ãšç®¡çãããããªããç§ãã¡ã¯ãã£ãšå¹žãã«ãªããŸãã
å·Šã·ãã/ã·ãŒã«ãå³
以äžããSysdigãšDocker Scoutã«ã€ããŠãäŒããããéèŠãªã¡ãã»ãŒãžã§ãã æåŸã«ãå ã«è¿°ã¹ãããã«ãå·Šã«ã·ãã/å³ã«ã·ãŒã«ãããŸãã ã·ãŒã«ãã©ã€ããšã¯? äžéšã®äººã«ãšã£ãŠã¯ãããã¯ããªãã®ãã¡ã€ã³ã«ãããŸããäžéšã®äººã«ãšã£ãŠã¯ãããã¯ããªãã®ãã¡ã€ã³ã«ãããŸããã ãããããããã«ãããããã¯éèŠãªæŠå¿µã§ãã Alexã¯ãã©ã³ã¿ã€ã ã®è åšæ€åºã¯ãå®éã«ã¯ãæ§ç¯ãããã®ãDockerããŒããŸãã¯ããçš®ã®ã¯ã©ã¹ã¿ã§å®è¡ãããŠãããšãã«ãã¹ãŠã§ããã? ç§ãã¡ã¯ãã®ããšãèŠå®ãããã®ã§ãã äžçæé«ã®è匱æ§ç®¡çãè¡ã£ãŠããäžéšã®æªãè¡åãé²ãããšã¯ã§ããŸããã ããã¯ç§ãã¡ãç£èŠãããããšã§ããããããã¯ç§ããã®è匱æ§ãä¿®æ£ã§ããªãå Žåã®ã»ãŒããã£ãããã«ãªãå¯èœæ§ããããŸããç§ã¯èª°ãããããæªçšããããšãããšãã«äºæ³ãããçµæãã©ããªãããç£èŠããã€ããã§ãã
éèŠãªã®ã¯ããããã®ã©ã³ã¿ã€ã ã®è åšã«ã©ã®ããã«å¯ŸåŠãããããããŠèªåã®ç°å¢ã§äœãæœåšçã«ãªã¹ã¯ã«ãããããŠããããã©ã®ããã«ææ¡ããããšããããšã§ãã ãã®æŠå¿µã¯ãå®è¡äžã®ã³ã³ããããããå ¬éãããŠãããã®ãããå Žåãã¯ãªãããã€ãã³ã°ã®ãããªãã®ãæ¢ãå¿ èŠããããšããããšã§ãã ããŒã¿ã®æªçšãæ¢ãå¿ èŠããããŸãã åºæ¬çã«ã¯ãããã«ã©ã³ãã ãªMITREçšèªãæ¿å ¥ããããæ¢ãå¿ èŠããããŸãã ãã®ããã®ã©ã³ã¿ã€ã è åšãœãªã¥ãŒã·ã§ã³ãæã€ããšãã§ããããšã¯ãããªãè峿·±ãããšã§ããããããå¿ èŠã§ãã ããã¯EDRã®ãããªãã®ã§ãã¯ã©ãŠãçšãšèããŠãã ãããç§ãã¡ã¯ã皌åäžã®ãã®ããªã¹ã¯ã«ããããããé²åºããªãããã«ããããã«ããã®ã¹ããŒã¹ã«é©åãããããšããŠããŸãã æ¬¡ã«ããã®ããŒã¿ãååŸããŠéçºè ã«è¿ããã¢ããªã±ãŒã·ã§ã³ãæ§ç¯ããŠãã人ã ã«è¿éããããšã§ãåºæ¬çã«ã¯ããè¯ãäœæ¥ãè¡ããéèŠãªããšã«ããå€ãã®æéãè²»ãããããã«ããŠããŸãã Dockerã®ãããªäººã ãšææºããããšã§ãéçºè ã¯ãã®ããŒã¿ãæ©æã«ååŸããé »ç¹ã«ååŸããŠãå°æ¥ã®æœåšçãªãªã¹ã¯ãåé¿ã§ããŸãã ãããã
ç§ãã¡ãäŒç€ŸãšããŠæã£ãŠããå šäœçãªç®æšã¯ãå¯èœãªéãå€ãã®äººã ã®æéã广çã«ç¯çŽããããšã§ãããããè匱æ§ç®¡çã«ã€ããŠåãæ°ãå¬ãã»ã©è©±ããŸããã ä»ã®æ±ã«é¢ããŠã¯ãã¯ã©ãŠãã€ã³ãã©ã¹ãã©ã¯ãã£å ã®ãŠãŒã¶ãŒæš©éããªãœãŒã¹ã¢ã¯ã»ã¹ãªã©ã«ã€ããŠèšãã°ãããã»ã©éãã¯ãããŸããã ã¯ã©ãŠããã¬ã€ã«ãªã©ã®ã©ã³ã¿ã€ã ãã°ãèŠããšããŠãŒã¶ãŒãäœãããŠããã®ããäœã«ã¢ã¯ã»ã¹ããŠããã®ããäœã«è§ŠããŠããã®ãã確èªã§ãããããã®ããŸããŸãªåœ¹å²ã«å¯ŸããŠé©åãªæš©éãšããŒã¿ã»ãããææ¡ã§ããŸãã
ãããã£ãŠãã©ã³ã¿ã€ã ã³ã³ããã¹ãã§ãŠãŒã¶ãŒã¢ã¯ã»ã¹ãèŠãããšãã§ããã°ããã®ãŠãŒã¶ãŒã¯å®éã«ã¯ãããã®é åã«ã¢ã¯ã»ã¹ããããšã¯ãªãããããã®æš©éã»ããã䜿çšããããšããªãã£ããšæããã«èšããŸãã ããããåŒãé¢ããŸãããã ãŠãŒã¶ãŒãä¿¡é ŒããŠããªãããã§ã¯ãããŸãããããã®ãŠãŒã¶ãŒã®è³æ Œæ å ±ãå ¬éããããšãããŒã¯ã³ãå ¬éãããŸãã 圌ãã圱é¿ãäžããããšãã§ããã®ã¯ããã®ççºååŸã§ããã? ã§ã¯ããã®ã©ã³ã¿ã€ã ããŒã¿ã«åºã¥ããŠããããã®ããšãå¶éããŸãããã
çµè«
ããã€ãã®è³ªåããåãããŸãã å®å šã確ä¿ããªããããã€ãããŒã·ã§ã³ãèµ·ããæéã確ä¿ããŸãããã æšæ¥ãDockerã®ããŒã ããŒãžããçãã ã®ã¯ãæåããå®å šãªãœãããŠã§ã¢ãæ§ç¯ããããšã§ãã ç§ãã¡ã¯çã粟ç¥çã«ãããæãã§ããŸãã é¢åãªããšã§ã¯ãããŸãããã? ãããŠãç§ãã¡ãåé²ããã«ã€ããŠãDocker Scoutãæ¯æŽããŠããå€ãã®ããšãéèŠãªã®ã§ãã å·Šã«ã·ããããå³ã«ã·ãŒã«ãããŸãã ã©ã¡ããéèŠã§ãã ã·ããã©ã€ãã¯ããªãã®ç¯å²ã«ã¯ãªããããããŸããããæ¬çªç°å¢ã®å®è¡ç°å¢ã«é¢å¿ã®ãã人ã®ããã®ãã®ã§ãã ã§ããããç§ãã¡ãå©ããããšãã§ãããã©ããç§ãã¡ã«ç¥ãããŠãã ããã ç§ãã¡ã¯ãç§ãã¡ãæ®ããããã€ãã®ç¬éã«ããªããæã£ãŠãã質åãããããã«ç§ãã¡ã蚪åããããšãããªãã«æåŸ ããŸãã ãã§ã«ãæã¡ã®æ¹ãå€ããšæããŸãã®ã§ããããããé¡ãããããŸãã
ããŠãããã§çµããã§ãã èŽè¡ã®äžã«ããŠãããŠããããšããç§ãã¡ã®ããã°ã«ã¯ãã£ãšåºç¯ãªè©³çްããããããããŸãã 倧äžå€«ã§ãã æ¶Œããã ã©ããªè³ªåã§ãã
質çå¿ç
倧äžå€«ã§ãã ãã®ãããã»ãã¥ãªãã£ããŒã ã倧ããªåé¡ãæ±ããŠããããšã¯ãå€ãã®äººãç¥ã£ãŠãããããããŸããã ããã¯ãããŸããŸãªçç±ã§ã³ã³ããåãšé·å¹Žã®æµå¯Ÿé¢ä¿ã«ããããããŸã§ã³ã³ããåã«ã¯ã»ãã¥ãªãã£ãåŒ·ãæ¬ ããŠããããã§ãã ãããŠãSysdigãšDocker Scoutãã³ã³ããã¹ãã£ã³ã®ããã«ç»å Žããããšã«ãªããšããã³ãã«ã®çµããã«å ãèŠããŠããããã«æããŸãã ç§ã®è³ªåã¯ãISO 2701ãCMMCã®ãããªã»ãã¥ãªãã£ãã¬ãŒã ã¯ãŒã¯æšæºã¯ãSysdigãšDocker Scoutã§æºããããã®ã§ãããã?
éšåçã«ã¯ãç§ãããã2ã€ã®ããšãå®è¡ããŠãããšèšãããšã¯ã§ããŸããããããã£ãŠç§ã¯æºæ ããŠããŸããããããã¯ããªããæºæ ããŠããçç±ã瀺ãããã®ããªãã®ææç©ã®äžéšã§ãã ã¹ãã£ã³ãã¬ããŒãäœæãããŒã¿ã»ããã®ååŸä»¥å€ã®å¶åŸ¡ãäœæ¥ãå¿ èŠã«ãªããŸããããããã¯å¶åŸ¡ãã¬ãŒã ã¯ãŒã¯å ã®ææç©ã§ããããããã®æšæºã«æºæ ããããã«äœ¿çšãããã®ã§ãã
ããŠãããã«ããã»ãã¥ãªãã£ããŒã ã¯å°ãæºè¶³ããŸãã
ãããŠãç§ãã¡ããã®è£œåã䜿ã£ãŠå šç¯å²ã«ããã£ãŠè¡ã£ãŠããããšã®1ã€ãã€ãŸããã¹ãã£ã³ã詊ã¿ãæç¹ãããã¹ãã£ç®¡çãã©ã³ã¿ã€ã ã«è³ããŸã§ãããã¯ç©ã«äŸåãããšããããšã§ãã ãã¹ãã£ãŒã®éäžã§ã 27001ãžã®ISOã®ã¬ããŒããããããšããã§ãéåžžã¯ã¯ã©ãŠãããŒã¹ããªã³ãã¬ãã¹ãOpenShiftãªã©ã®ç°å¢ã確èªããŸãã ã§ãããããããèµ€ã§ããããããªããå¿ããŠããç·ã§ãã ããã§ã¯ãããªãããã£ãŠããªãããšãèµ°ã£ãŠããªãå ·äœçãªããšã玹ä»ããŸãã åãæ¿ãããããšãããã€ããããŸããããããæ£ããè¡ãããŠããªãå¯èœæ§ããããŸãã ããããããŸãããã¹ãã£ã³ã®é¢ã§ã¯ãISOã«æºæ ããå¿ èŠãããå Žåã¯ãããããçšæããå¿ èŠããããŸãã ã©ã³ã¿ã€ã åŽã§ã¯ããã®ããšãç§ãã¡ãããªãã«äžãããã®ããªã·ãŒãããªã¬ãŒããå Žåãããªãã¯ããããISOãPCIããŸãã¯æºããããšããŠããæšæºã«éåããŠããããšãç¥ã£ãŠããå¿ èŠããããŸãã
çµå±ã®ãšãããç¹ã«ã³ã³ããã®è匱æ§ç®¡çã«é¢é£ããã³ã³ãã©ã€ã¢ã³ã¹ä»æ§ã«ã¯ãå€ãã®æææš©ããããšããããšã§ãã ããããããã®ç¹å®ã®ã¹ãã£ã³ã§ã¯ããã®ç°å¢ã§ã¯ 50 ã¯ãªãã£ã«ã«ããçºçããªããšããåé¡ã«å¯ŸåŠããªããã°ãªããªãã£ãã§ãããã ãã以äžã®ãã®ãããã°ãç£æ»ãªã©ã¯å€±æããã§ãããã ãã®ãããç¹å®ã®ã¯ãªãã£ã«ã«ãç¹å®ã®é«ãè匱æ§ã®ãªã¹ã¯ã軜æžããããã«å€ãã®æéãè²»ããããšã«ãªããŸãããããã§äœ¿çšäžã®ã³ã³ã»ãããéèŠã«ãªããŸãã åºæ¬çã«ãããã¯é«ãè匱æ§ã§ããããšã蚌æã§ããŸãã ããã¯å®éã«ã¯åŒã°ããŠããªãã®ã§ããã®ç¹å®ã®çç±ã«åºã¥ããŠãç§ãã¡ã®ãã¬ãŒã ã¯ãŒã¯ã§é«ããã®ããäžçšåºŠã®ãã®ãŸã§ãªã¹ã¯ã軜æžããããšãã§ããŸãã ãããŠãããã«è¯ãããšã«ã次ã«ã¹ãã£ã³ãããšãã«ã¯ãæåã«ç©ãåãé€ãããšã«ãªãã®ã§ãããã«ã¯ãããŸããã ã§ãããããããã®æ¿çã®å€ãã¯ãåºæ¬çã«ã¯ã¯ãªãã£ã«ã«ãã«ãŠã³ãããé«å€ãã«ãŠã³ãããéçã¯äœãããªããªããç§ãã¡ãæã€ããšãã§ãããã©ããã¯ããçšåºŠèš±å®¹ãããããã§ãã ã°ãããŠããŸãããç£æ»äººã¯ããèŠãŠããŸãã
ãšããã§ãã³ã³ããåŽã暪ã«ãããŠããŠãèŠåå¡ãåå ããªãããšããã£ããšããç¹ã«ã€ããŠã¯ãç§ãåæèŠã§ãã ç¹ã«ãã® 18 ã«æéã§ããã®ç¶æ³ã¯å€åããŠããŸãã äŸãã°ãã»ãã¥ãªãã£ããŒã ãå¢ããŠããããã«ãããã¯çµç¹ã®èŠæš¡ãªã©ã«ãã£ãŠç°ãªããããããŸãããã圌ãã¯ã¯ã©ãŠããã€ãã£ããç¹ã«ã¯ã©ãŠãã«çå£ã«åãçµãã§ããŸãã
ã§ããããã·ããã¬ãããæ¬åœã«éèŠã«ãªãã®ã¯ãã»ãã¥ãªãã£ããŒã ãšæ©æã«ã³ã³ããéçºã飿ºãããããšãã§ããã°ã圌ãããããããããçè§£ããããã«ãªããããããªãã®ç掻ã¯ã¯ããã«è¯ããªãã§ãããã
ããã§ã¯ãeBPFã䜿ã£ãã¹ã©ã€ãã®1ã€ãèŠããŸããã ããã«ã€ããŠ2ã€ã®è³ªåãããããšæããŸãã ãããåãªããããŒãã§ããå Žåãããã¯äœãã®åŒ·å¶ãè¡ããããªãã®ã§ããããããšãåãªãå¯èŠ³æž¬æ§ã§ãã? 次ã«ãããšãã°ãCiliumãå®è¡ãããã«ãŒãã«ã¬ãã«ã§ãåäœããŠããå Žåãããã¯ã©ã®ããã«å ±åããŸãã?
eBPFã®å Žåããã¹ãŠãç¬èªã®å°ããªã¡ã¢ãªç©ºéã§å®è¡ãããŸãã ããã¯ã»ãšãã© - ããã¯æªãäŸãã§ã - ããããJVMã®ãããªãã®ã ãšèããŠãã ããã eBPFã¯ãã³ã³ããåãããå°ããªå Žæã§å®è¡ããã飿¥ããeBPFã¢ããªã±ãŒã·ã§ã³ã«å¹²æžããªããããå ±åã§ããŸãã ããã¯äœãæªãããšã§ã¯ãããŸããã SysdigåŽããèŠããšãèªã¿åãå°çšã®ããã»ã¹ãšããŠå®è¡ãããŠãããããããŒã¿ãåŒãåºããšãã«è¡ã£ãŠããã®ã¯ãã³ããããã³ã°èªã¿åãã§ãã ãããã£ãŠãeBPFèªäœã®å éšã«ã¯çŽæ¥çãªåŒ·å¶ã¯ãªããã«ãŒãã«ãžã®é©åãªã¢ã¯ã»ã¹ãè¡ãã¹ãã§ã¯ãããŸããã ããã¯ãšãŠãããšãŠãæãããšãªã®ã§ããããªããšããã人ããéããããšããå§ãããŸãã Nvidiaãããªããäœãããã§ã¯ãªããããããŸããããããã§ã®æ žãšãªãä¿¡æ¡ã¯ãç§ãã¡ãç®ã«ãããã®ã«å¯Ÿãããã¹ãŠã®åå¿ããã¹ãŠã®å·è¡ãäºåŸãŸãã¯ããã«æ²¿ã£ãŠè¡ããããšããããšã§ãã
Sysdigã®ã€ã³ã¿ãŒãã§ãŒã¹ã«ã¯ãã³ã³ããããªããããªã·ãŒããããŸãã ããã¯ãã³ã³ãããå®è¡ãããåŸã«çªç¶äœãæ°ãããã®ã远å ãããã³ã³ãããããå Žåããã®ã³ã³ããã忢ããããããã»ã¹ã匷å¶çµäºãããããŸãã¯ããããå®è¡ãããªãããã«ããããéžæã§ããããšã瀺ããŠããŸãã ãã®å Žåãã³ã³ãããäœããè¡ããã·ã¹ãã ãæç¥šãåŒã³ãããSysdigããããèŠãŠããšãŒãžã§ã³ãããããèªã¿ãããããã®ç¹å®ã®ããšã«å¯ŸããŠã鲿¢ãã¢ã¯ã·ã§ã³ããããšèšãã®ã§ãã ç§ã¯ptraceãäœãã§ãããæ®ºãã«è¡ãã€ããã§ãããããŠããã§ããã¯ãã¹ãŠäžçŽç·ã«è¡ãããŸãã ããã¯ç¹ã«ã«ãŒãã«ã§ã¯èµ·ãã£ãŠããŸããããªããªãç§ãã¡ã¯ã«ãŒãã«ã«æžããããªãããã§ãã ããã¯çã«ããªã£ãŠããŸãã? ãããããã¯çã«ããªã£ãŠããŸãã
ãããŠã2çªç®ã®è³ªåã§ãããPCIãªã©ã®ã³ã³ãã©ã€ã¢ã³ã¹ããã¯ã«ã€ããŠèšåãããŸããã äŸãã°ãCISOãç¬èªã®ã³ã³ãã©ã€ã¢ã³ã¹ãæã£ãŠãããšããŸãã äŸãã°ãéè¡ã®ã¢ããªã±ãŒã·ã§ã³ã§ãããcidããŒã¿ãããããã®ããŒã¿ããããäœããã®ãããã¯ãŒã¯ãä»ããŠã¢ã¯ã»ã¹ããããã©ããã確èªããããšããŸãã ããªãã¯ããªãèªèº«ã®ããªã·ãŒæœè¡ãšäžç·ã«æ¥ãããšãã§ããŸãã?
ãããããçšåºŠãSysdigã§è¡ããã¹ãŠã®ããšã¯ãªãŒãã³ãœãŒã¹ã«åºã¥ããŠããã®ã§ãã©ã³ã¿ã€ã ãšã³ãžã³ã¯Falcoãcspmãšã³ãžã³ã¯ãã¹ãŠregoã§æžãããŠãããã³ã³ãããŒã©ãŒããã®ãšã³ãã©ãŒã¹ã¡ã³ãããã¹ãŠregoã§è¡ãããŠããŸãã ã§ããããããããã¹ãŠããªãŒãã³ã¹ã¿ã³ããŒããªã®ã§ãã
ã§ããããå€ãã®å Žåãèªåã®ããªã·ãŒãæã¡èŸŒãã§å®è¡ããããšãã§ããŸãã 補åã«ã¯ããã¹ãŠã®ãã®ãèªåã§å®å šã«æã¡èŸŒãããšãã§ããªãç¹å®ã®é åããããŸãããç¹å®ã®ã³ã³ãããŒã©ãŒã®èŠä»¶ã«åãããŠååšãããã®ãã«ã¹ã¿ãã€ãºã§ããŸãã ãªããªããæ£çŽã«èšããšãããã¯éåžžã«è€éãªæ§æèšèªã§ãããã»ãšãã©ã®éšåã§å€±æãããããªããšã人ã ã«å®è¡ããããã¯ãªãããã§ãã ãã®ãããé«åºŠã«ã«ã¹ã¿ãã€ãºå¯èœãªããªã·ãŒã倿°ãããåºæ¬çãªåãçµã¿ãšããŠäœ¿çšããããšãã§ããŸãã
ãšããã§ãããªããeBPFã«ã€ããŠå°ããã®ã§ãç§ã¯ããªããšããªãããããåãåã£ãŠããªããªãããã«ãã誰ãã«ãªãã¡ãŒããããã§ããããªãååãæ¬ããããŸãã ã§ãããã仿¥ã¯ãããæã«åãã®ã«ãµããããæ¥ãããããŸããã®ã§ãeBPFã®ã³ã³ã»ããã«ã€ããŠå®¶ã«æã¡åž°ãããšãã§ããŸãã Sysdigã®åé¡ã§ã¯ãããŸããã ããã¯æ¬åœã«eBPFã«ã€ããŠã§ãã ã§ããããç§ãã¡ã¯Linuxã«ãŒãã«èªäœã®äžã§éåžžã«æ©ã段éã§eBPFã«æ·±ãé¢ãã£ãŠããŸããã ç§ãã¡ã®åŸæ¥å¡ã®äžã«ã¯ããã®ã³ãŒãã®å€ããåµãåºããLinuxã«å€æãããããå®è¡ããã®ãæäŒã£ãŠãã人ãã¡ãããŸããã ããã«ã€ããŠã¯ããšãŠã楜ãããªãœãŒã¹ããããŸãã éã«èšãã°ãé£è¡æ©ã®äžã§ããããç ããããã«ãªããããããŸããã ãšããã§ãeBPFã¯ãç¥ããªã人ã®ããã«èª¬æãããšãæ¡åŒµãããBerkeley Packet Filterã§ãããä»ã§ã¯ãã±ãããšã¯ã»ãšãã©é¢ä¿ãããŸããã ããã¯ãã«ãŒãã«ã¬ãã«ã§ãããã®å°ããªããã°ã©ã ãååŸããŠå®è¡ããæ¹æ³ã§ãã
ãæ¥å Žããã ããèª ã«ããããšãããããŸãã çæ§ãããããšãããããŸããã
ããã«è©³ãã
- ã³ã³ããã®ã»ãã¥ãªãã£ãšãããéèŠãªçç±
- ã³ã³ãããšã¯Â
- Docker ãã¹ã¯ãããã®ææ°ãªãªãŒã¹ãå ¥æããŸãã
- 質åããããŸãã? Docker ã³ãã¥ããã£ããæäŒãããŸãã
- ããã«ãŒã¯åããŠã§ãã? å§ããŸãããã
- Docker Newsletter ã賌èªããŠãã ããã