ããŒã¹ã€ã¡ãŒãžã®ããŒããã³ã°
ããŒã¹ã€ã¡ãŒãžã®ããŒããã³ã°ãšã¯ïŒ
ããŒã¹ã€ã¡ãŒãžã®ããŒããã³ã°ãšã¯ãã³ã³ããã€ã¡ãŒãžã®åºç€ã¬ã€ã€ãŒãã»ãã¥ã¢ã«ããããã«ããã®å 容ãæå°åããã»ãã¥ãªãã£ãæåªå ãšããããã©ã«ãèšå®ãæœãããã»ã¹ã®ããšã§ãã
ããŒããã³ã°ãããããŒã¹ã€ã¡ãŒãžã§ã¯ãã·ã§ã«ãã³ã³ãã€ã©ãããã±ãŒãžãããŒãžã£ãšãã£ãäžèŠãªã³ã³ããŒãã³ããåé€ããããšã§ãæ»æå¯Ÿè±¡é åãå¶éããæ»æè ãã³ã³ããå ã§å¶åŸ¡ã奪åãããæš©éãææ Œããããããããšãé£ããããŸãã
ããŒããã³ã°ã«ã¯ãé root ãŠãŒã¶ãŒãšããŠã®å®è¡ãæžã蟌ã¿å¯èœãªé åã®åæžãã€ãã¥ãŒã¿ããªãã£ã«ããäžè²«æ§ã®ç¢ºä¿ãšãã£ããã¹ããã©ã¯ãã£ã¹ã®é©çšãå«ãŸããŸãã
Docker Official Images ã Docker Verified Publisher Images ãã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ã«åŸã£ãŠããŸãããããå¹ åºããŠãŒã¹ã±ãŒã¹ããµããŒãããããã«ãDocker Hardened Images ã»ã©åŸ¹åºçã«ã¯ããŒããã³ã°ãããŠããªãå ŽåããããŸãã
ãªãéèŠãªã®ãïŒ
ã»ãšãã©ã®ã³ã³ããã¯ã䜿çšããŠããããŒã¹ã€ã¡ãŒãžããã»ãã¥ãªãã£å§¿å¢ãç¶æ¿ããŸãã
ããŒã¹ã€ã¡ãŒãžã«äžèŠãªããŒã«ãå«ãŸããŠããããææ Œãããæš©éã§åäœããŠããããããšããã®äžã«æ§ç¯ããããã¹ãŠã®ã³ã³ãããåããªã¹ã¯ã«ãããããŸãã
ããŒã¹ã€ã¡ãŒãžãããŒããã³ã°ããããšã§:
-
æ»æå¯Ÿè±¡é åãåæž: æªçšãããå¯èœæ§ã®ããããŒã«ãã©ã€ãã©ãªãåãé€ã
-
æå°æš©éã®ååã培åº: root ã¢ã¯ã»ã¹ãæé€ããã³ã³ãããã§ããããšãå¶éãã
-
ä¿¡é Œæ§ãšäžè²«æ§ãåäž: å®è¡æã®å€æŽãæ§æããªãããåé¿ãã
-
ã»ãã¥ã¢ãªãœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³ã«æºæ : ã³ã³ãã©ã€ã¢ã³ã¹åºæºã®éæãæ¯æŽãã
ããŒããã³ã°ãããããŒã¹ã€ã¡ãŒãžã䜿çšããããšã¯ãã³ã³ããã§æ§ç¯ã»å®è¡ãããœãããŠã§ã¢ãä¿è·ããããã®æåã®éèŠãªã¹ãããã§ãã
äœãåé€ããããªããªã®ã
ããŒããã³ã°ãããã€ã¡ãŒãžã§ã¯ãã»ãã¥ã¢ãªæ¬çªç°å¢ã«ãããŠãªã¹ã¯ãé«ãããŸãã¯äžèŠãšãããäžè¬çãªã³ã³ããŒãã³ããåé€ãããŸã:
åé€ãããã³ã³ããŒãã³ã | çç± |
---|---|
ã·ã§ã«ïŒäŸ: sh ãbash ïŒ | ãŠãŒã¶ãŒãæ»æè ãã³ã³ããå ã§ä»»æã®ã³ãã³ããå®è¡ããã®ãé²ããã |
ããã±ãŒãžãããŒãžã£ïŒäŸ: apt ãapk ïŒ | ãã«ãåŸã«ãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ã§ããªãããã«ããããªãããé²åºãåæž |
ã³ã³ãã€ã©ãã€ã³ã¿ããªã¿ | æªæããã³ãŒããå®è¡ã»æ³šå ¥ããããã«å©çšããåŸãããŒã«ã®å°å ¥ãé²ããã |
ãããã°ããŒã«ïŒäŸ: strace ãcurl ãwget ïŒ | æªçšãæ å ±æŒæŽ©ã®ãªã¹ã¯ã軜æžãããã |
æªäœ¿çšã®ã©ã€ãã©ãªããã±ãŒã« | ã€ã¡ãŒãžãµã€ãºãçž®å°ããæ»æãã¯ãã«ãæå°åãããã |
Docker Hardened Images ã«ãããããŒã¹ã€ã¡ãŒãžã®ããŒããã³ã°ã®é©çš
Docker Hardened ImagesïŒDHIïŒã¯ãèšè𿮵éããããŒã¹ã€ã¡ãŒãžã®ããŒããã³ã°ååãåãå ¥ããŠããŸãã
åã€ã¡ãŒãžã¯ããã®çšéã«å¿
èŠãªãã®ã ããå«ãããã«æ§ç¯ãããŠãããã¢ããªã±ãŒã·ã§ã³ããã«ãããå ŽåïŒ-dev
ã -sdk
ã¿ã°ïŒãæ¬çªã§å®è¡ããå Žåãªã©ã«å¿ããæ§æãçšæãããŠããŸãã
Docker Hardened Image ã®ç¹åŸŽ
Docker Hardened Images ã¯ä»¥äžã®ç¹æ§ãåããŠããŸã:
-
ãããã«: å¿ èŠäžå¯æ¬ ãªã©ã€ãã©ãªããã€ããªã®ã¿ãå«ã
-
ã€ãã¥ãŒã¿ãã«: ã€ã¡ãŒãžã¯ãã«ãæã«åºå®ãããå®è¡æã®ã€ã³ã¹ããŒã«ã¯äžå¯
-
ããã©ã«ãã§é root: ç¹å¥ãªèšå®ãããªãéããã³ã³ããã¯éç¹æš©ãŠãŒã¶ãŒã§å®è¡ããã
-
çšéå¥ã¹ã³ãŒã: éçºçšïŒ
-dev
ïŒãSDK ããŒã¹ã®ãã«ãçšïŒ-sdk
ïŒãæ¬çªã©ã³ã¿ã€ã çšãšãã£ãç°ãªãã¿ã°ãæäŸ
ãããã®ç¹æ§ã«ãã£ãŠãéçºã»ãã¹ãã»æ¬çªç°å¢ãéããŠäžè²«ããã»ãã¥ã¢ãªæåãå®çŸããŸãã
Docker Hardened Image ã®äºææ§ã«é¢ããèæ ®ç¹
Docker Hardened Images ã¯å€ãã®äžè¬çãªããŒã«ãåé€ããŠããããããã¹ãŠã®ãŠãŒã¹ã±ãŒã¹ã§ãã®ãŸãŸå©çšã§ãããšã¯éããŸããããã®ããæ¬¡ã®ãããªå·¥å€«ãå¿ èŠã«ãªãå ŽåããããŸã:
-
ãã«ãã¹ããŒãžãã«ãã䜿çšããŠã
-dev
ã€ã¡ãŒãžã§ã³ãŒããã³ã³ãã€ã«ãäŸåé¢ä¿ãã€ã³ã¹ããŒã«ãããã®ææç©ãããŒããã³ã°ãããã©ã³ã¿ã€ã ã€ã¡ãŒãžã«ã³ããŒãã -
ã·ã§ã«ã¹ã¯ãªããã眮ãæãã: ãšã³ããªãã€ã³ãçšã®ãã€ããªãå©çšããããå¿ èŠã«å¿ããŠæç€ºçã«ã·ã§ã«ãå«ãã
-
Docker Debug ãå©çšããŠãäžæçã«ã³ã³ããã調æ»ã»ãã©ãã«ã·ã¥ãŒãããããŒã¹ã€ã¡ãŒãžã倿Žããã«åé¡è§£æ±ºãè¡ã
ãããã®ãã¬ãŒããªãã¯æå³çãªãã®ã§ãããã»ãã¥ã¢ã§åçŸå¯èœããã€æ¬çªå¯Ÿå¿å¯èœãªã³ã³ãããæ§ç¯ããããã®ãã¹ããã©ã¯ãã£ã¹ãæ¯æŽããŸãã