CIS ãã³ãããŒã¯
CIS Docker ãã³ãããŒã¯ãšã¯ïŒ
CIS Docker ãã³ãããŒã¯Â ã¯ãäžççã«èªç¥ãããŠãã CIS ãã³ãããŒã¯ ã®äžéšã§ãããCenter for Internet SecurityïŒCISïŒÂ ã«ãã£ãŠçå®ãããŠããŸãã
ãã®ãã³ãããŒã¯ã¯ãã³ã³ãããã¹ããDocker ããŒã¢ã³ãã³ã³ããã€ã¡ãŒãžãã³ã³ããã©ã³ã¿ã€ã ãªã©ãDocker ã³ã³ãããšã³ã·ã¹ãã å šäœã«é¢ããæšå¥šãããå®å šãªæ§æãå®çŸ©ããŠããŸãã
ãªã CIS ãã³ãããŒã¯æºæ ãéèŠãªã®ã
CIS Docker ãã³ãããŒã¯ã«åŸãããšã§ãçµç¹ã¯æ¬¡ã®ãããªã¡ãªãããåŸãããŸã:
-
åºãèªç¥ãããããŒããã³ã°ã¬ã€ãã©ã€ã³ã«åºã¥ããã»ãã¥ãªãã£ãªã¹ã¯ãäœæžã§ããã
-
CIS ã³ã³ãããŒã«ãåç §ããèŠå¶èŠä»¶ãå¥çŽèŠä»¶ãæºããããšãã§ããã
-
ããŒã éã§ã€ã¡ãŒãžã Dockerfile ã®éçšæ¹æ³ãæšæºåã§ããã
-
å ¬éæšæºã«åºã¥ãæ§æå€æã«ãããç£æ»å¯Ÿå¿ã®æºåç¶æ³ã瀺ãããšãã§ããã
Docker Hardened Images ã«ããã CIS ãã³ãããŒã¯æºæ
Docker Hardened ImagesïŒDHIïŒã¯ã»ãã¥ãªãã£ãéèŠããŠèšèšãããŠãããã³ã³ããã€ã¡ãŒãžããã³ Dockerfile æ§æã«é©çšãããç¯å²ã«ãããŠãææ°ã® CIS Docker ãã³ãããŒã¯ïŒv1.8.0ïŒã®é¢é£ã³ã³ãããŒã«ã«æºæ ããŠããããšãæ€èšŒãããŠããŸãã
CIS æºæ ã® DHI ã¯ãSection 4ïŒã€ã¡ãŒãžããã³ Dockerfile ã®ãã¹ããã©ã¯ãã£ã¹ïŒã«å«ãŸãããã¹ãŠã®ã³ã³ãããŒã«ã«æºæ ããŠããŸãã
å¯äžã®äŸå€ã¯ Docker Content TrustïŒDCTïŒã®æå¹åãæ±ããã³ã³ãããŒã«ã§ããããã㯠Docker ã«ãã£ãŠå ¬åŒã«å»æ¢Â ãããŠããŸãã
CIS æºæ ã® DHI ãããŒã¹ã«ããããšã§ãããŒã ã¯ãã³ãããŒã¯ã«åºã¥ããã€ã¡ãŒãžã¬ãã«ã®ãã¹ããã©ã¯ãã£ã¹ããããè¿ éãã€å®å¿ããŠæ¡çšã§ããŸãã
CIS Docker ãã³ãããŒã¯ã«ã¯ããã¹ããããŒã¢ã³ãã©ã³ã¿ã€ã ã«é¢ããã³ã³ãããŒã«ãå«ãŸããŠããŸãã CIS æºæ ã® DHI ã察å¿ããã®ã¯ãã€ã¡ãŒãžããã³ Dockerfile ã«é¢ããç¯å²ïŒSection 4ïŒã®ã¿ã§ãã å šäœçãªæºæ ã¯ãããåºãç°å¢ã®æ§æãéçšæ¹æ³ã«ãäŸåããŸãã
CIS æºæ ã€ã¡ãŒãžã®ç¹å®
CIS æºæ ã®ã€ã¡ãŒãžã¯ãDocker Hardened Images ã«ã¿ãã°å ã§ CIS ãšè¡šç€ºãããŠããŸãã
ããããæ¢ãã«ã¯ãã€ã¡ãŒãžãæ¢çŽ¢ãã ã«é²ã¿ãåã€ã¡ãŒãžäžèŠ§ã§ CIS 衚瀺ã確èªããŠãã ããã
ãã³ãããŒã¯ã®å ¥æ
ææ°ã® CIS Docker ãã³ãããŒã¯ã¯ã以äžã®ãªã³ã¯ãã CIS å ¬åŒãµã€ãããçŽæ¥ããŠã³ããŒãã§ããŸã: https://www.cisecurity.org/benchmark/dockerÂ