ããŠããŒ
ãã®ã»ã¯ã·ã§ã³ã§ã¯ãDocker Hardened ImagesïŒDHIïŒãæ±ãããã®å®è·µçãªã¹ããããã€ã¹ãããã®ã¬ã€ããæäŸããŸãã
åã㊠DHI ãè©äŸ¡ããå Žåã§ããæ¬çªç°å¢ã® CI/CD ãã€ãã©ã€ã³ã«çµ±åããå Žåã§ããããã§ç޹ä»ããåãããã¯ãå°å ¥ã®å šãã§ãŒãºïŒæ¢çŽ¢ãããããã°ãŸã§ïŒãé ã远ã£ãŠãµããŒãããŸãã
ã»ãã¥ãªãã£ãä¿ã¡ãªããã¹ã ãŒãºã«å°å ¥ã§ããããããããã¯ã¯ DHI 掻çšã®äžè¬çãªã©ã€ããµã€ã¯ã«ã«æ²¿ã£ãŠæ§æãããŠããŸãã
ã©ã€ããµã€ã¯ã«ã®æµã
-
DHI ã«ã¿ãã°å ã§å©çšå¯èœãªã€ã¡ãŒãžãã¡ã¿ããŒã¿ãæ¢çŽ¢ãã
-
ä¿¡é Œã§ããã€ã¡ãŒãžãèªèº«ã®åå空éãã¬ãžã¹ããªã«ãã©ãŒãã
-
DHI ãéçºã»CIã»æ¬çªã¯ãŒã¯ãããŒã«åãå ¥ããæ¢åã¢ããªã±ãŒã·ã§ã³ãã»ãã¥ã¢ãã€ãããã«ãªããŒã¹ã€ã¡ãŒãžãžç§»è¡ãã
-
眲åã»SBOMã»ããããã³ã¹ã®æ€èšŒããè匱æ§ã¹ãã£ã³ãéããŠã€ã¡ãŒãžãåæãã
-
ããªã·ãŒãé©çšããã»ãã¥ãªãã£ãšã³ã³ãã©ã€ã¢ã³ã¹ãç¶æãã
-
ã€ã¡ãŒãžã倿Žããã«ãDHI ããŒã¹ã®ã³ã³ããããããã°ãã
以äžã®åãããã¯ã¯ãã®ã©ã€ããµã€ã¯ã«ã®ã¹ããããšå¯Ÿå¿ããŠãããDHI ã®æ¢çŽ¢ããå°å ¥ãéçšã»ä¿å®ãŸã§ãå®å¿ããŠé²ããããããæ§æãããŠããŸãã
ã¹ããããã€ã¹ãããã¬ã€ã
Docker Hardened Images ãæ¢çŽ¢ãã
Docker Hub äžã® DHI ã«ã¿ãã°ã§ããªããžããªãããªã¢ã³ããã¡ã¿ããŒã¿ãã¢ãã¹ããŒã·ã§ã³ã®æ¢ãæ¹ãšè©äŸ¡æ¹æ³ãåŠã³ãŸãããã
Docker Hardened Image ãªããžããªããã©ãŒãã
ã€ã¡ãŒãžã Organization ã®åå空éã«ãã©ãŒããå¿ èŠã«å¿ããŠä»ã®ãã©ã€ããŒãã¬ãžã¹ããªã«ããã·ã¥ããæ¹æ³ãåŠã³ãŸãã
Docker Hardened Image ã䜿çšãã
DockerfileãCI ãã€ãã©ã€ã³ãæšæºçãªéçºã¯ãŒã¯ãããŒã§ Docker Hardened Images ã pullã»å®è¡ã»åç §ããæ¹æ³ãåŠã³ãŸãã
æ¢åã¢ããªã±ãŒã·ã§ã³ã Docker Hardened Images ã«ç§»è¡ãã
Dockerfile ãæŽæ°ããã»ãã¥ã¢ãã€æå°æ§æã§æ¬çªå¯Ÿå¿å¯èœãªãã«ãã«åã㊠DHI ãå°å ¥ããæé ãé ã远ã£ãŠè§£èª¬ããŸãã
Docker Hardened Image ãæ€èšŒãã
Docker Scout ã cosign ã䜿ã£ãŠãSBOMãããããã³ã¹ãèåŒ±æ§æ å ±ãªã©ã®çœ²åä»ãã¢ãã¹ããŒã·ã§ã³ãæ€èšŒããæ¹æ³ãåŠã³ãŸãã
Docker Hardened Image ãã¹ãã£ã³ãã
Docker ScoutãGrypeãTrivy ã䜿ã£ãŠãDHI ã«æ¢ç¥ã®è匱æ§ããªããã¹ãã£ã³ããæ¹æ³ãåŠã³ãŸãããã
ããªã·ãŒã§ Docker Hardened Images ã®äœ¿çšã匷å¶ãã
Docker Scout ã®ã€ã¡ãŒãžããªã·ãŒæ©èœã䜿ã£ãŠãDHI ã®äœ¿çšã匷å¶ã»ç®¡çããæ¹æ³ãåŠã³ãŸãã
Docker Hardened Image ããããã°ãã
Docker Debug ã䜿ã£ãŠãããŒããã³ã°ãããã€ã¡ãŒãžäžã®å®è¡äžã³ã³ããã倿Žããã«èª¿æ»ããæ¹æ³ãåŠã³ãŸãã