ã€ã¡ãŒãžããããã³ã¹
ã€ã¡ãŒãžããããã³ã¹ãšã¯ïŒ
ã€ã¡ãŒãžããããã³ã¹ïŒimage provenanceïŒ ãšã¯ãã³ã³ããã€ã¡ãŒãžã®èµ·æºãäœæè ãæŽåæ§ã远跡ããããã®ã¡ã¿ããŒã¿ã®ããšã§ãã
ããã«ããã以äžã®ãããªéèŠãªçåã«çããããšãã§ããŸã:
-
ãã®ã€ã¡ãŒãžã¯ã©ãããæ¥ãã®ãïŒ
-
誰ããã®ã€ã¡ãŒãžããã«ãããã®ãïŒ
-
æ¹ãããããŠããªããïŒ
ããããã³ã¹ã¯ä¿¡é Œã§ãããã«ãããã»ã¹ã«ãã£ãŠçæãããããšã蚌æãããä¿¡é Œã®é£éïŒchain of custodyïŒã確ç«ããŸãã
ããã«ããã䜿çšããŠããã€ã¡ãŒãžãçæ£ãã€æ€èšŒå¯èœã§ããããšã確èªã§ããŸãã
ãªãã€ã¡ãŒãžããããã³ã¹ãéèŠãªã®ã
ããããã³ã¹ïŒç±æ¥æ å ±ïŒã¯ããœãããŠã§ã¢ãµãã©ã€ãã§ãŒã³ã®ã»ãã¥ãªãã£ã«ãããåºç€ã§ãã
ããããªããã°ã以äžã®ãããªãªã¹ã¯ãçºçããŸã:
-
æ€èšŒãããŠããªãããŸãã¯æªæã®ããã€ã¡ãŒãžãå®è¡ããŠããŸã
-
瀟å ããªã·ãŒãèŠå¶èŠä»¶ãžã®æºæ ã«å€±æãã
-
ã³ã³ãããæ§æããã³ã³ããŒãã³ããããã®çæããã»ã¹ã«é¢ããå¯èŠæ§ã倱ã
äžæ¹ã§ãä¿¡é Œã§ããããããã³ã¹ãããã°ã以äžã®ã¡ãªããããããŸã:
-
ä¿¡é Œæ§ã®ç¢ºä¿ïŒã€ã¡ãŒãžãçæ£ã§ãããæ¹ãããããŠããªãããšã確èªã§ããŸãã
-
ãã¬ãŒãµããªãã£ã®ç¢ºä¿ïŒãã«ãããã»ã¹å šäœãšäœ¿çšããããœãŒã¹å ¥åã远跡ã§ããŸãã
-
ç£æ»å¯Ÿå¿æ§ã®åäžïŒã³ã³ãã©ã€ã¢ã³ã¹ããã«ãã®æŽåæ§ã蚌æããæ€èšŒå¯èœãªèšŒæ ãæç€ºã§ããŸãã
ããã«ãããããã³ã¹ã¯ããªã·ãŒã®èªåé©çšïŒããªã·ãŒã²ãŒãïŒãæ¯æŽããSLSAïŒSupply-chain Levels for Software ArtifactsïŒã®ãããªãã¬ãŒã ã¯ãŒã¯ã«ãããŠãå¿ é èŠä»¶ãšãããŠããŸãã
Docker Hardened Images ã«ããããããã³ã¹ã®ãµããŒã
Docker Hardened ImagesïŒDHIïŒã¯ããã«ãã€ã³ã®ããããã³ã¹æ©èœãåããŠãããã»ãã¥ã¢ããã©ã«ããªéçšãä¿é²ãããµãã©ã€ãã§ãŒã³ã»ãã¥ãªãã£æšæºãžã®æºæ ãæ¯æŽããããèšèšãããŠããŸãã
ã¢ãã¹ããŒã·ã§ã³
DHI ã«ã¯ãã¢ãã¹ããŒã·ã§ã³ïŒæ©æ¢°å¯èªãªã¡ã¿ããŒã¿ïŒãå«ãŸããŠãããã€ã¡ãŒãžãããã€ã»ã©ãã§ã»ã©ã®ããã«ããã«ããããã®ããèšé²ããŸãã
ããã㯠in-toto ã®ãããªæ¥çæšæºãçšããŠçæãããSLSA ããããã³ã¹Â ã«æºæ ããŠããŸãã
ã¢ãã¹ããŒã·ã§ã³ã掻çšããããšã§ã以äžãå¯èœã«ãªããŸã:
-
ãã«ãã æåŸ ãããæé ã©ããã«å®è¡ãããããæ€èšŒãã
-
å ¥åããã«ãç°å¢ã ããªã·ãŒã«æºæ ããŠããããšã確èªãã
-
ç°ãªãã·ã¹ãã ãã¹ããŒãžããŸããã§ ãã«ãããã»ã¹ã远跡ïŒãã¬ãŒã¹ïŒ ãã
ã³ãŒã眲å
ãã¹ãŠã® Docker Hardened Image ã¯ã眲åä»ã ã§æäŸãããŠãããã€ã¡ãŒãžã®ãã€ãžã§ã¹ããšãšãã«ã¬ãžã¹ããªã«ä¿åãããŸãã
ãããã®çœ²åã¯ãã€ã¡ãŒãžã®çæ£æ§ã蚌æå¯èœã«ããæå·ç蚌æ ã§ãããcosign
ãDocker ScoutãKubernetes ã® Admission Controller ãªã©ã®ããŒã«ãšäºææ§ããããŸãã
眲åä»ãã€ã¡ãŒãžã掻çšããããšã§ã以äžã®ããšãå¯èœã«ãªããŸã:
-
ã€ã¡ãŒãžã Docker ã«ãã£ãŠå ¬éããããã®ã§ããããšã確èªãã
-
ã€ã¡ãŒãžã æ¹ãããŸãã¯åå ¬éãããŠããªãããæ€åºãã
-
CI/CD ãæ¬çªç°å¢ã§ã®ãããã€ã«ãããŠã眲åã®æ€èšŒãå¿ é åãã