Docker Hardened Images ãæ¢çŽ¢ãã
Docker Hardened ImagesïŒDHIïŒã¯ããšã³ã¿ãŒãã©ã€ãºçšéã«åããŠèšèšããããã»ãã¥ã¢ãã€æ¬çªç°å¢å¯Ÿå¿ã®ã³ã³ããã€ã¡ãŒãžçŸ€ã§ãã
ãã®ããŒãžã§ã¯ãå©çšå¯èœãª DHI ãªããžããªã®æ¢çŽ¢æ¹æ³ãã€ã¡ãŒãžã®ã¡ã¿ããŒã¿ã®ç¢ºèªãããªã¢ã³ãã®è©³çްã®ç¢ºèªãæäŸãããŠããã»ãã¥ãªãã£ã¢ãã¹ããŒã·ã§ã³ã®çè§£ã«ã€ããŠèª¬æããŸãã
ãããã®æ å ±ãæŽ»çšããããšã§ãOrganization ã«ãã©ãŒãªã³ã°ããåã«ãã¢ããªã±ãŒã·ã§ã³ã«æé©ãªã€ã¡ãŒãžããªã¢ã³ããè©äŸ¡ã»éžå®ããããšãã§ããŸãã
Docker Hardened Images ã«ã¢ã¯ã»ã¹ãã
Docker Hardened Images ãå©çšããã«ã¯ããµãã¹ã¯ãªãã·ã§ã³ãå¿ èŠã§ãã
ãã¡ããããµã€ã³ã¢ãã ããŠã¢ã¯ã»ã¹ãéå§ããŠãã ããã
Docker Hardened Images ãæ¢çŽ¢ãã
Docker Hardened ImagesïŒDHIïŒãæ¢çŽ¢ããã«ã¯ã以äžã®æé ã«åŸããŸã:
-
Docker Hub ã«ã¢ã¯ã»ã¹ããŠãµã€ã³ã€ã³ããŸãã
-
My Hub ãéžæããŸãã
-
åå空éã®ããããããŠã³ãããDHI ã«ã¢ã¯ã»ã¹å¯èœãªèªèº«ã® Organization ãéžæããŸãã
-
DHI catalog ãéžæããŸãã
DHI ã®ããŒãžã§ã¯ãã€ã¡ãŒãžãé²èŠ§ã»æ€çŽ¢ããããã«ããŽãªããšã«ãã£ã«ã¿ãŒããããŠçµã蟌ãã ãã§ããŸãã
ãªããžããªã®è©³çްã確èªãã
ãªããžããªã®è©³çްã確èªããã«ã¯ã以äžã®æé ã«åŸããŸã:
-
Docker Hub ã«ã¢ã¯ã»ã¹ããŠãµã€ã³ã€ã³ããŸãã
-
My Hub ãéžæããŸãã
-
åå空éã®ããããããŠã³ãããDHI ã«ã¢ã¯ã»ã¹å¯èœãªèªèº«ã® Organization ãéžæããŸãã
-
DHI catalog ãéžæããŸãã
-
DHI ã«ã¿ãã°äžèЧããä»»æã®ãªããžããªãéžæããŸãã
ãªããžããªã®è©³çްããŒãžã§ã¯ã以äžã®æ å ±ã確èªã§ããŸãïŒ
-
Overview: ã€ã¡ãŒãžã®ç°¡åãªèª¬æ
-
Guides: ã€ã¡ãŒãžã®äœ¿ç𿹿³ããæ¢åã¢ããªã±ãŒã·ã§ã³ã®ç§»è¡æ¹æ³ã«é¢ããã¬ã€ã
-
Tags: ã€ã¡ãŒãžããªã¢ã³ãã®è¡šç€º ãå¯èœ
-
Security summary: ã¿ã°åãéžæãããšãããã±ãŒãžæ°ãæ¢ç¥ã®èåŒ±æ§æ°ãDocker Scout ã®ãã«ã¹ã¹ã³ã¢ãå«ãã»ãã¥ãªãã£ã®æŠèŠã衚瀺ãããŸã
-
Recently pushed tags: æè¿æŽæ°ãããã€ã¡ãŒãžããªã¢ã³ããšããã®æçµæŽæ°æ¥æã®äžèЧ
-
Mirror to repository: ã€ã¡ãŒãžã Organization ã®ãªããžããªã«ãã©ãŒããããã®æäœãâ»ãã©ãŒæäœã¯ Organization ãªãŒããŒã®ã¿å®è¡å¯èœ
-
View in repository: ãã§ã«ãã©ãŒããããªããžããªã®å Žæã確èªããããŸãã¯å¥ã®ãªããžããªã«ãã©ãŒããããã®ãªãã·ã§ã³
ã€ã¡ãŒãžããªã¢ã³ããæ¢çŽ¢ãã
ã€ã¡ãŒãžããªã¢ã³ãã確èªããã«ã¯ã以äžã®æé ã«åŸããŸã:
-
Docker Hub ã«ã¢ã¯ã»ã¹ããŠãµã€ã³ã€ã³ããŸãã
-
My Hub ãéžæããŸãã
-
åå空éã®ããããããŠã³ãããDHI ã«ã¢ã¯ã»ã¹å¯èœãªèªèº«ã® Organization ãéžæããŸãã
-
DHI catalog ãéžæããŸãã
-
DHI ã«ã¿ãã°äžèЧããä»»æã®ãªããžããªãéžæããŸãã
-
Tags ãéžæããŸãã
Tags ããŒãžã§ã¯ã以äžã®æ å ±ã確èªã§ããŸã:
-
Tags: ãã¹ãŠã®å©çšå¯èœãªã¿ã°ïŒ=ã€ã¡ãŒãžããªã¢ã³ãïŒã®äžèЧ
-
ComplianceïŒã³ã³ãã©ã€ã¢ã³ã¹ïŒ: é¢é£ããã³ã³ãã©ã€ã¢ã³ã¹åºåã®è¡šç€ºïŒäŸ:
FIPS
ãSTIG
ãªã©ïŒ -
DistributionïŒãã£ã¹ããªãã¥ãŒã·ã§ã³ïŒ: ããªã¢ã³ããããŒã¹ãšããŠãããã£ã¹ããªãã¥ãŒã·ã§ã³ïŒäŸ:
debian 12
ãalpine 3.21
ïŒ -
Package managerïŒããã±ãŒãžãããŒãžã£ïŒ: å©çšå¯èœãªããã±ãŒãžãããŒãžã£ïŒäŸ:
apt
ãapk
ã-
ïŒãªãïŒïŒ -
ShellïŒã·ã§ã«ïŒ: å©çšå¯èœãªã·ã§ã«ïŒäŸ:
bash
ãbusybox
ã-
ïŒãªãïŒïŒ -
UserïŒãŠãŒã¶ãŒïŒ: ã³ã³ãããå®è¡ããããŠãŒã¶ãŒïŒäŸïŒ
root
ãnonroot (65532)
ãnode (1000)
ïŒ -
Last pushedïŒæçµ pushïŒ: ãã®ã€ã¡ãŒãžããªã¢ã³ããæåŸã« push ãããæ¥æ°
-
VulnerabilitiesïŒè匱æ§ïŒ: æ·±å»åºŠå¥ã«åé¡ãããè匱æ§ã®æ°
-
HealthïŒãã«ã¹ïŒ: ãã®ããªã¢ã³ãã«å¯Ÿãã Docker Scout ã®ãã«ã¹ã¹ã³ã¢ãã¢ã€ã³ã³ãéžæãããšè©³çްã確èªã§ããŸãã
äžè¬ç㪠Docker Hub ã®ã€ã¡ãŒãžãšã¯ç°ãªããDocker Hardened Images ã§ã¯ latest
ã¿ã°ã¯äœ¿çšãããŸããã
åã€ã¡ãŒãžããªã¢ã³ãã¯ã3.13
ã 3.13-dev
ã®ãããªå®å
šãªã»ãã³ãã£ãã¯ããŒãžã§ã³ã¿ã°ã§å
¬éãããåžžã«ææ°ã®ç¶æ
ã«ä¿ãããŠããŸãã
ã€ã¡ãŒãžã®åçŸæ§ãæ
ä¿ããå¿
èŠãããå Žåã¯ããã€ãžã§ã¹ã ãåç
§ããŠç¹å®ã®ãªãªãŒã¹ããã³çãããããšãã§ããŸãã
ã€ã¡ãŒãžããªã¢ã³ãã®è©³çްã確èªãã
-
Docker Hub ã«ã¢ã¯ã»ã¹ããŠãµã€ã³ã€ã³ããŸãã
-
My Hub ãéžæããŸãã
-
åå空éã®ããããããŠã³ãããDHI ã«ã¢ã¯ã»ã¹å¯èœãªèªèº«ã® Organization ãéžæããŸãã
-
DHI catalog ãéžæããŸãã
-
DHI ã«ã¿ãã°äžèЧããä»»æã®ãªããžããªãéžæããŸãã
-
Tags ãéžæããŸãã
-
衚ã®äžãã確èªãããã€ã¡ãŒãžããªã¢ã³ãã®ã¿ã°ãã¯ãªãã¯ããŸãã
ã€ã¡ãŒãžããªã¢ã³ãã®è©³çްããŒãžã§ã¯ã以äžã®æ å ±ã確èªã§ããŸã:
-
PackagesïŒããã±ãŒãžïŒ: ã€ã¡ãŒãžã«å«ãŸãããã¹ãŠã®ããã±ãŒãžã®äžèЧãåããã±ãŒãžã®åç§°ãããŒãžã§ã³ãããŒã¹ãã£ã¹ããªãã¥ãŒã·ã§ã³ãã©ã€ã»ã³ã¹æ å ±ãªã©ã衚瀺ãããŸãã
-
SpecificationsïŒä»æ§ïŒ: ããªã¢ã³ãã«é¢ããäž»èŠãªæè¡æ å ±ã衚瀺ãããŸã:
-
ãœãŒã¹ããã³ãã«ãæ å ±: 䜿çšããã Dockerfile ã Git ã³ããã
-
ãã«ããã©ã¡ãŒã¿
-
Entrypoint
-
CMD
-
å®è¡ãŠãŒã¶ãŒ
-
äœæ¥ãã£ã¬ã¯ããª
-
ç°å¢å€æ°
-
ã©ãã«
-
ãã©ãããã©ãŒã
-
-
VulnerabilitiesïŒè匱æ§ïŒ: ãã®ããªã¢ã³ãã«é¢é£ããæ¢ç¥ã® CVE ã®äžèЧ:
-
CVE çªå·
-
æ·±å»åºŠ
-
察象ããã±ãŒãž
-
ä¿®æ£ããŒãžã§ã³
-
æçµæ€åºæ¥æ
-
ã¹ããŒã¿ã¹
-
æå¶ããã CVEïŒSuppressed CVEsïŒ
-
-
AttestationsïŒã¢ãã¹ããŒã·ã§ã³ïŒ: ããªã¢ã³ãã«ã¯ããã«ãããã»ã¹ãæ§æå 容ãã»ãã¥ãªãã£ç¶æ ãæ€èšŒããããã®ã»ãã¥ãªãã£ã¢ãã¹ããŒã·ã§ã³ãå«ãŸããŠããŸãããããã¯çœ²åä»ãã§ã
cosign
ã䜿çšããŠæ€èšŒå¯èœã§ããå©çšå¯èœãªã¢ãã¹ããŒã·ã§ã³ã®äžèЧã«ã€ããŠã¯ãã¢ãã¹ããŒã·ã§ã³ ãåç §ããŠãã ããã
次ã®ã¹ããã
å¿ èŠãªã€ã¡ãŒãžãèŠã€ãã£ããããã®ã€ã¡ãŒãžã Organization ã«ãã©ãŒ ã§ããŸãã
ãã§ã«ãã©ãŒæžã¿ã®å Žåã¯ãã€ã¡ãŒãžã®äœ¿çšãéå§ ã§ããŸãã