ããã·ã¥ããŒã
Docker Scout Dashboardâã¯ãOrganization å ã§ã€ã¡ãŒãžã®åæçµæãããŒã ãšå ±æããã®ã«åœ¹ç«ã¡ãŸããéçºè ã¯ãDocker HubãArtifactoryããã®ãã¹ãŠã®ã€ã¡ãŒãžã®ã»ãã¥ãªãã£ã¹ããŒã¿ã¹ãäžç®ã§ç¢ºèªããè¿ éã«ä¿®æ£æ¹æ³ãååŸã§ããŸããããã«ãããã»ãã¥ãªãã£ãã³ã³ãã©ã€ã¢ã³ã¹ãéçšãªã©ã®åœ¹å²ãæ ãããŒã ã¡ã³ããŒãã察åŠãã¹ãè匱æ§ãåé¡ãææ¡ã§ããããã«ãªããŸãã
æŠèŠ
Overviewã¿ãã§ã¯ãéžæãã Organization ã®ãªããžããªã®èŠçŽã衚瀺ããŸãã
ããŒãžäžéšã§è¡šç€ºãã Environment ãéžæã§ããŸããããã©ã«ãã§ã¯ãææ°ã®ããã·ã¥ã€ã¡ãŒãžã衚瀺ãããŸããå®è¡ç°å¢ã«ã€ããŠè©³ããã¯ãå®è¡ç°å¢ã¢ãã¿ãªã³ã°ãåç §ããŠãã ããã
Policy ããã¯ã¹ã«ã¯ãåããªã·ãŒã®çŸåšã®æºæ è©äŸ¡ãšãéžæããå®è¡ç°å¢ã®ãã¬ã³ãã衚瀺ãããŸãããã¬ã³ãã¯ãææ°ã®ã€ã¡ãŒãžãšåã®ããŒãžã§ã³ã®ããªã·ãŒå·®åã瀺ããŸããããªã·ãŒã®è©³çŽ°ã«ã€ããŠã¯ãããªã·ãŒè©äŸ¡ãåç §ããŠãã ããã
è匱æ§ãã£ãŒãã¯ãéžæããç°å¢å ã®ã€ã¡ãŒãžã«å¯Ÿããè匱æ§ã®ç·æ°ãæéçµéã«æ²¿ã£ãŠç€ºããŸããããããããŠã³ã¡ãã¥ãŒã§ãã£ãŒãã®æéã¹ã±ãŒã«ãèšå®ã§ããŸãã
ãŠã§ããµã€ãäžéšã®ããããŒã¡ãã¥ãŒã䜿çšããŠãDocker Scout ããã·ã¥ããŒãã®ããŸããŸãªäž»èŠã»ã¯ã·ã§ã³ã«ã¢ã¯ã»ã¹ã§ããŸãïŒ
- Policies: Organization ã®ããªã·ãŒæºæ ã衚瀺ããŸãã詳现ã¯ããªã·ãŒãåç §
- Images: Organization å ã® Docker Scout æå¹ãªããžããªãäžèŠ§è¡šç€ºããŸãã詳现ã¯ã€ã¡ãŒãžãåç §
- Base images: Organization å ã®ãªããžããªã§äœ¿çšãããŠãããã¹ãŠã®ããŒã¹ã€ã¡ãŒãžã衚瀺
- Packages: Organization å ã®ãªããžããªå šäœã®ããã±ãŒãžäžèŠ§
- Vulnerabilities: Organization ã®ã€ã¡ãŒãžã«å«ãŸãããã¹ãŠã® CVE ã衚瀺ã詳现ã¯è匱æ§ãåç §
- Integrations: ãµãŒãããŒãã£çµ±åã®äœæãšç®¡çã詳现ã¯çµ±åãåç §
- Settings: ãªããžããªèšå®ãè«æ±ã®ç®¡çã詳现ã¯èšå®ãåç §
ããªã·ãŒ
Policies ãã¥ãŒã§ã¯ãéžæãã Organization ãšå®è¡ç°å¢å ã®ãã¹ãŠã®ã€ã¡ãŒãžã«å¯Ÿããããªã·ãŒæºæ ã®å èš³ã衚瀺ãããŸããã€ã¡ãŒãžããããããŠã³ã¡ãã¥ãŒã䜿çšããŠãç¹å®ã®å®è¡ç°å¢ã«å¯Ÿããããªã·ãŒå èš³ã衚瀺ã§ããŸãã
ããªã·ãŒã®è©³çŽ°ã«ã€ããŠã¯ãããªã·ãŒè©äŸ¡ãåç §ããŠãã ããã
ã€ã¡ãŒãž
Images ãã¥ãŒã§ã¯ãéžæããç°å¢å ã® Docker Scout æå¹ãªããžããªå ã®ãã¹ãŠã®ã€ã¡ãŒãžã衚瀺ãããŸããç°ãªãç°å¢ãéžæããããããã¹ããã£ã«ã¿ãŒã§ãªããžããªåã§çµã蟌ãããšãã§ããŸãã
ãªã¹ãã«ã¯ãåãªããžããªã«ã€ããŠä»¥äžã®è©³çŽ°ã衚瀺ãããŸãïŒ
- ãªããžããªåïŒã¿ã°ããã€ãžã§ã¹ããé€ãã€ã¡ãŒãžãªãã¡ã¬ã³ã¹ïŒ
- éžæããå®è¡ç°å¢å ã®ææ°ã€ã¡ãŒãžã®ã¿ã°
- ææ°ã¿ã°ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãšã¢ãŒããã¯ãã£
- ææ°ã¿ã°ã®è匱æ§ã¹ããŒã¿ã¹
- ææ°ã¿ã°ã®ããªã·ãŒã¹ããŒã¿ã¹
ãªããžããªãªã³ã¯ãéžæãããšããã®ãªããžããªå ã®ãã¹ãŠã®ã€ã¡ãŒãžãªã¹ãã衚瀺ãããç¹å®ã®ã€ã¡ãŒãžã®è©³çŽ°ãªåæçµæã確èªããããã¿ã°ãæ¯èŒããŠããã±ãŒãžãè匱æ§ã®éãã確èªã§ããŸãã
ã€ã¡ãŒãžãªã³ã¯ãéžæãããšããã®ã¿ã°ãŸãã¯ãã€ãžã§ã¹ãã®è©³çŽ°ãã¥ãŒã衚瀺ããã次ã®2ã€ã®ã¿ãã§æ§æãšããªã·ãŒæºæ ã®è©³çŽ°ã確èªã§ããŸã:
-
Policy status ã¯ãéžæããã€ã¡ãŒãžã®ããªã·ãŒè©äŸ¡çµæã衚瀺ããŸãããŸããããªã·ãŒéåã«é¢ãã詳现ãªã³ã¯ããããŸãã
ããªã·ãŒã«ã€ããŠã®è©³çŽ°ã¯ãããªã·ãŒè©äŸ¡ãåç §ããŠãã ããã
-
Image layers ã¯ãã€ã¡ãŒãžåæçµæã®å èš³ã衚瀺ããŸããã€ã¡ãŒãžã«å«ãŸããè匱æ§ã®å šäœåãææ¡ããããããã©ã®ããã«äŸµå ¥ããããç解ã§ããŸãã
è匱æ§
Vulnerabilities ãã¥ãŒã§ã¯ãOrganization å ã®ã€ã¡ãŒãžã«å¯Ÿãããã¹ãŠã®è匱æ§ã®äžèŠ§ã衚瀺ãããŸãããã®äžèŠ§ã«ã¯ãCVE ã®é倧床ãå ±éè匱æ§ã¹ã³ã¢ãªã³ã°ã·ã¹ãã ïŒCVSSïŒã¹ã³ã¢ãããã³ä¿®æ£ããŒãžã§ã³ã®æç¡ãå«ãŸããŸãã衚瀺ããã CVSS ã¹ã³ã¢ã¯ããã¹ãŠã®æ å ±æºã®äžã§æãé«ãã¹ã³ã¢ã§ãã
ãã®ããŒãžã®ãªã³ã¯ãéžæãããšãCVE ã®è©³çŽ°ããŒãžãéããŸãããã®ããŒãžã¯å ¬éãããŠãããCVE ã«é¢ãã詳现ãªæ å ±ã衚瀺ãããŸããDocker Scout ã® Organization ã¡ã³ããŒã§ãªããŠãããã®ç¹å®ã® CVE 説æãžã®ãªã³ã¯ãä»ã®äººãšå ±æã§ããŸãã
ãµã€ã³ã€ã³ããŠããå Žåããã®ããŒãžã® My images ã¿ãã«ãCVE ã®åœ±é¿ãåãããã¹ãŠã®ã€ã¡ãŒãžãäžèŠ§è¡šç€ºãããŸãã
çµ±å
Integrations ããŒãžã§ã¯ãDocker Scout çµ±åïŒå®è¡ç°å¢çµ±åãã¬ãžã¹ããªçµ±åãªã©ïŒãäœæããã³ç®¡çã§ããŸããçµ±åã®éå§æ¹æ³ã«ã€ããŠã¯ãDocker Scout ã®ä»ã·ã¹ãã ãšã®çµ±åãåç §ããŠãã ããã
èšå®
Docker Scout ããã·ã¥ããŒãã®èšå®ã¡ãã¥ãŒã«ã¯æ¬¡ã®å 容ãå«ãŸããŸãïŒ
- Repository settings: ãªããžããªã®æå¹åãšç¡å¹å
- Notifications: Docker Scout ã®éç¥èšå®ã®ç®¡ç
ãªããžããªèšå®
Docker Scout ããªããžããªã§æå¹åãããšããã®ãªããžããªã«ããã·ã¥ãããæ°ããã¿ã°ãèªåã§åæãããŸããAmazon ECRãAzure ACRããŸãã¯ä»ã®ãµãŒãããŒãã£ã¬ãžã¹ããªã§ãªããžããªãæå¹ã«ããã«ã¯ããŸãçµ±åãè¡ãå¿ èŠããããŸããã³ã³ããã¬ãžã¹ããªã®çµ±åãåç §ããŠãã ããã
éç¥èšå®
éç¥èšå®âããŒãžã§ã¯ãDocker Scout ããã®éç¥åä¿¡èšå®ãå€æŽã§ããŸããéç¥èšå®ã¯å人çšã§ãèšå®å€æŽã¯å人ã®ã¢ã«ãŠã³ãã«ã®ã¿åœ±é¿ããOrganization å šäœã«ã¯åœ±é¿ããŸããã
Docker Scout ã®éç¥ã®ç®çã¯ã圱é¿ãåããäžæµã®å€æŽã«é¢ããæ å ±ãæäŸããããšã§ããæ°ããè匱æ§ãã»ãã¥ãªãã£ã¢ããã€ã¶ãªã§é瀺ããããã®è匱æ§ãã€ã¡ãŒãžã«åœ±é¿ãäžããå Žåã«éç¥ãããŸããæ°ããã€ã¡ãŒãžãããã·ã¥ããããšã§è匱æ§ã®åœ±é¿ãããªã·ãŒæºæ ãå€åããå Žåã«ã¯éç¥ã¯è¡ãããŸããã
éç¥ã¯åãªããžããªã®æåŸã«ããã·ã¥ãããã€ã¡ãŒãžã¿ã°ã«å¯ŸããŠã®ã¿ããªã¬ãŒãããŸãããæåŸã«ããã·ã¥ãããããšã¯ãã¬ãžã¹ããªã«æãæè¿ããã·ã¥ãããDocker Scout ã«ãã£ãŠåæãããã€ã¡ãŒãžã¿ã°ãæããŸããæåŸã«ããã·ã¥ãããã€ã¡ãŒãžãæ°ãã«é瀺ããã CVE ã®åœ±é¿ãåããŠããªãå Žåãéç¥ã¯ããªã¬ãŒãããŸããã
å©çšå¯èœãªéç¥èšå®ã¯æ¬¡ã®éãã§ãïŒ
-
Repository scope
ãã¹ãŠã®ãªããžããªããŸãã¯ç¹å®ã®ãªããžããªã®ã¿ã«ã€ããŠéç¥ãåãåãããéžæã§ããŸãããããã®èšå®ã¯çŸåšéžæãããŠãã Organization ã«é©çšãããæå±ããå Organization ããšã«å€æŽå¯èœã§ãã
-
All repositories: ã¢ã¯ã»ã¹æš©ã®ãããã¹ãŠã®ãªããžããªã«ã€ããŠéç¥ãåãåããŸãã
-
Specific repositories: ç¹å®ã®ãªããžããªã«ã€ããŠã®ã¿éç¥ãåãåããŸããéç¥ãåãåããããªããžããªåãå ¥åããŸãã
-
-
Delivery preferences
Docker Scout ããã®éç¥ã®åä¿¡æ¹æ³ãèšå®ããŸãããããã®èšå®ã¯ãæå±ãããã¹ãŠã® Organization ã«é©çšãããŸãã
- Notification pop-ups: Docker Scout ããã·ã¥ããŒãã«éç¥ãããã¢ããã¡ãã»ãŒãžãåä¿¡ããã«ã¯ããã®ãã§ãã¯ããã¯ã¹ããªã³ã«ããŸãã
- OS notifications: Docker Scout ããã·ã¥ããŒãããã©ãŠã¶ã¿ãã§éããŠããå Žåããã©ãŠã¶ãã OS ã¬ãã«ã®éç¥ãåä¿¡ããã«ã¯ããã®ãã§ãã¯ããã¯ã¹ããªã³ã«ããŸãã
OS éç¥ãæå¹ã«ããã«ã¯ãDocker Scout ããã©ãŠã¶ API ã䜿çšããŠéç¥ãéä¿¡ããæš©éãå¿ èŠã§ãã
ãã®ããŒãžãããSlackçµ±åãªã©ã®ããŒã ã³ã©ãã¬ãŒã·ã§ã³çµ±åã®èšå®ã«ãã¢ã¯ã»ã¹ã§ããŸãã
ãŸããDocker Desktop ã® Settings > Notifications ããéç¥èšå®ãå€æŽããããšãã§ããŸãã