ã·ãŒã ã¬ã¹ãªçµ±å
Docker Hardened ImagesïŒDHIïŒã¯ãæ¢åã®éçºããã³ãããã€ã¡ã³ãã¯ãŒã¯ãããŒã«ç¡çãªãçµ±åã§ããããèšèšãããŠãããã»ãã¥ãªãã£ã®åŒ·åãšäœ¿ããããã®äž¡ç«ãå®çŸããŸãã
Docker Hub ã§ã€ã¡ãŒãžã確èªãã
Organization ã ãµã€ã³ã¢ããâ ãå®äºãããšãããŒã 㯠Docker Hub äžã§ DHI ã«ã¿ãã°å šäœãçŽæ¥ç¢ºèªã§ããããã«ãªããŸããéçºè ãã»ãã¥ãªãã£ããŒã ã¯ä»¥äžã®ãããªããšãå¯èœã§ã:
-
å©çšå¯èœãªã€ã¡ãŒãžãèšèªïŒãã¬ãŒã ã¯ãŒã¯ã®ããªã¢ã³ãã確èªãã
-
ãµããŒããããŠãããã£ã¹ããªãã¥ãŒã·ã§ã³ãææ¡ãã
-
éçºçšããªã¢ã³ããšå®è¡æããªã¢ã³ãã®éããæ¯èŒãã
åãªããžããªã«ã¯ããµããŒããããŠããã¿ã°ãããŒã¹ã€ã¡ãŒãžã®æ§æãã€ã¡ãŒãžåºæã®ããã¥ã¡ã³ããªã©ã®ã¡ã¿ããŒã¿ãå«ãŸããŠããããããžã§ã¯ãã«æé©ãªããªã¢ã³ããéžã¶ã®ã«åœ¹ç«ã¡ãŸãã
CI/CD ã¯ãŒã¯ãããŒã§ DHI ã䜿çšãã
Docker Hardened ImagesïŒDHIïŒã¯ãDockerfile ãçšããŠæ§ç¯ãããä»»æã® CI/CD ãã€ãã©ã€ã³ã«ãããŠãããŒã¹ã€ã¡ãŒãžãšããŠãã®ãŸãŸå©çšã§ããŸãã
GitHub ActionsãGitLab CI/CDãJenkinsãCircleCI ãªã©ãããŒã ããã§ã«äœ¿çšããŠããèªååãã©ãããã©ãŒã ãšãç°¡åã«çµ±åã§ããŸãã
DevSecOps ã¹ã¿ãã¯ã«é©åããèšèš
Docker Hardened Images ã¯ãæ¢åã® DevSecOps ããŒã«ãã§ãŒã³ãšã·ãŒã ã¬ã¹ã«é£æºããããèšèšãããŠããŸãã
DHI ã¯ãã¹ãã£ãã³ã°ããŒã«ãã³ã³ããã¬ãžã¹ããªãCI/CD ã·ã¹ãã ãããªã·ãŒãšã³ãžã³ãªã©ãããŒã ããã§ã«äœ¿çšããŠããåçš®ããŒã«ãšé£æºå¯èœã§ãã
Docker ã¯å¹ åºããšã³ã·ã¹ãã ããŒãããŒãšé£æºããŠãããDHI ãæ¢åã®ã¯ãŒã¯ãããŒãããŒã«ãšãã®ãŸãŸåäœããããšãä¿èšŒããŠããŸãã
ãããã®ããŒãããŒã«ãããã¹ãã£ã³åŒ·åãã¡ã¿ããŒã¿æ€èšŒãã³ã³ãã©ã€ã¢ã³ã¹ã€ã³ãµã€ãã®æäŸããã€ãã©ã€ã³å ã§çŽæ¥å¯èœã«ãªããŸãã
ãã¹ãŠã® DHI ã«ã¯ä»¥äžãå«ãŸããŠããŸã:
-
眲åä»ããœãããŠã§ã¢éšå衚ïŒSBOMïŒ
-
CVE ããŒã¿
-
èåŒ±æ§æªçšå¯èœæ§æ å ±ïŒVEX ããã¥ã¡ã³ãïŒ
-
SLSA Build Level 3 ã«æºæ ãããã«ãããããã³ã¹
ãããã®ã¡ã¿ããŒã¿ã¯çœ²åãããæ§é åãããŠãããããããªã·ãŒãšã³ãžã³ãããã·ã¥ããŒãã«åã蟌ãã§ç£æ»ãã³ã³ãã©ã€ã¢ã³ã¹ã¯ãŒã¯ãããŒã«æŽ»çšããããšãå¯èœã§ãã
ä»»æã®ã¬ãžã¹ããªçµç±ã§é åžãã
DHIïŒDocker Hardened ImagesïŒã¯ãDocker Hub äžã®è²Žç€Ÿã®åå空éã«ãã©ãŒãããŸãããããããä»»æã® OCI æºæ ã¬ãžã¹ããªã«ããã·ã¥ããããšãå¯èœã§ããããšãã°:
-
Amazon ECR
-
Google Artifact Registry
-
GitHub Container Registry
-
Azure Container Registry
-
Harbor
-
JFrog Artifactory
-
ãã®ä»ã® OCI æºæ ãªã³ãã¬ãã¹ïŒã¯ã©ãŠãã¬ãžã¹ããª
ãã©ãŒãªã³ã°ã«ãããããŒã ã¯ããªã·ãŒããã«ãã·ã¹ãã ãå£ãããšãªãã奜ã¿ã®å Žæããã€ã¡ãŒãžã pull ã§ããããã«ãªããŸãã
ãŸãšã
Docker Hardened Images ã¯ãéçºãã CIãã¹ãã£ã³ããããã€ã«è³ããŸã§ãæ¢åã®ããŒã«ãšçµ±åãããŸããDHI ã¯æ¬¡ã®ãããªç¹åŸŽãåããŠããŸãïŒ
-
æšæºç㪠Docker ããŒã«ããã€ãã©ã€ã³ãšãã®ãŸãŸé£æºå¯èœ
-
äž»èŠãªã¹ãã£ããã³ã³ããã¬ãžã¹ããªã«å¯Ÿå¿
-
æ¢åã®ã³ã³ãã©ã€ã¢ã³ã¹ã·ã¹ãã ã«çµ±åã§ããã»ãã¥ãªãã£ã¡ã¿ããŒã¿ãå«ã
ã€ãŸãããšã³ãžãã¢ãªã³ã°ã¯ãŒã¯ãããŒãäžæããããšãªãããã匷åãªã»ãã¥ãªãã£ç®¡çãå°å ¥ã§ããŸãã