Docker Scout ãš Amazon ECR ã®çµ±å
Docker Scout ãš Amazon Elastic Container Registry (ECR) ãçµ±åããããšã§ãECR ãªããžããªã«ãã¹ããããŠããã€ã¡ãŒãžã®ã€ã³ãµã€ãã衚瀺ã§ããŸããDocker Scout ãš ECR ãçµ±åãããªããžããªã§ Docker Scout ãæå¹åãããšããªããžããªã«ã€ã¡ãŒãžãããã·ã¥ãããã³ã«èªåçã«ã€ã¡ãŒãžåæãéå§ãããŸããDocker Scout ããã·ã¥ããŒããŸã㯠docker scout
CLI ã³ãã³ãã䜿çšããŠãã€ã¡ãŒãžã®ã€ã³ãµã€ãã衚瀺ã§ããŸãã
ä»çµã¿
Docker Scout ãš ECR ãçµ±åããããã«ãCloudFormation ã¹ã¿ãã¯ãã³ãã¬ãŒãã䜿çšããŠãECR ã¬ãžã¹ããªãš Docker Scout ã®çµ±åã«å¿ èŠãª AWS ãªãœãŒã¹ãäœæããã³èšå®ã§ããŸããAWS ãªãœãŒã¹ã®è©³çŽ°ã«ã€ããŠã¯ãCloudFormation ã¹ã¿ãã¯ãã³ãã¬ãŒãããåç §ãã ããã
次ã®å³ã¯ãDocker Scout ECR çµ±åã®ä»çµã¿ã瀺ããŠããŸãã
çµ±ååŸãDocker Scout 㯠ECR ã¬ãžã¹ããªã«ããã·ã¥ãããã€ã¡ãŒãžãèªåçã«ååŸããŠåæããŸããã€ã¡ãŒãžã®ã¡ã¿ããŒã¿ã¯ Docker Scout ãã©ãããã©ãŒã ã«ä¿åãããŸãããDocker Scout ã¯ã³ã³ããã€ã¡ãŒãžèªäœãä¿åããŸãããDocker Scout ã®ããŒã¿åãæ±ãæ¹æ³ã®è©³çŽ°ã«ã€ããŠã¯ãããŒã¿ã®åãæ±ãããåç §ãã ããã
CloudFormation ã¹ã¿ãã¯ãã³ãã¬ãŒã
以äžã®è¡šã¯ãèšå®ãªãœãŒã¹ã®èª¬æã瀺ããŠããŸãã
ãããã®ãªãœãŒã¹ãäœæãããšãAWS ã¢ã«ãŠã³ãã«å°é¡ã®ç¶ç¶çãªã³ã¹ããçºçããŸããè¡šã® ã³ã¹ã åã«ã¯ã1 æ¥ããã 100 åã®ã€ã¡ãŒãžãããã·ã¥ããã ECR ã¬ãžã¹ããªãçµ±åããéã®æšå®æé¡ã³ã¹ãã衚瀺ãããŠããŸãã
ãŸããDocker Scout ã ECR ããã€ã¡ãŒãžãååŸããéã«çºçãã egress ã³ã¹ããé©çšãããŸããegress ã³ã¹ãã¯çŽ $0.09/GB ã§ãã
ãªãœãŒã¹ã¿ã€ã | ãªãœãŒã¹å | 説æ | ã³ã¹ã |
---|---|---|---|
AWS::SNSTopic::Topic | SNSTopic | AWS ãªãœãŒã¹äœææã« Docker Scout ãžéç¥ããããã® SNS ãããã¯ã | ç¡æ |
AWS::SNS::TopicPolicy | TopicPolicy | åæã»ããã¢ããéç¥ã®ããã®ãããã¯å®çŸ©ã | ç¡æ |
AWS::SecretsManager::Secret | ScoutAPICredentials | Docker Scout ãžã®ã€ãã³ãçºç«ã«äœ¿çšãã EventBridge ã®èªèšŒæ å ±ãä¿åã | $0.42 |
AWS::Events::ApiDestination | ApiDestination | ECR ã®ããã·ã¥ããã³åé€ã€ãã³ãã Docker Scout ã«éä¿¡ãã EventBridge æ¥ç¶ã | $0.01 |
AWS::Events::Connection | Connection | Docker Scout ãžã® EventBridge æ¥ç¶çšã®èªèšŒæ å ±ã | ç¡æ |
AWS::Events::Rule | DockerScoutEcrRule | ECR ã®ããã·ã¥ãšåé€ã Docker Scout ã«éä¿¡ããã«ãŒã«ã®å®çŸ©ã | ç¡æ |
AWS::Events::Rule | DockerScoutRepoDeletedRule | ECR ãªããžããªã®åé€ã Docker Scout ã«éä¿¡ããã«ãŒã«ã®å®çŸ©ã | ç¡æ |
AWS::IAM::Role | InvokeApiRole | ApiDestination ãžã®ã€ãã³ãã¢ã¯ã»ã¹ãèš±å¯ããå
éšããŒã«ã | ç¡æ |
AWS::IAM::Role | AssumeRoleEcrAccess | Docker Scout çµ±åã®èšå®ã«å¿
èŠãª ScoutAPICredentials ãžã®ã¢ã¯ã»ã¹æš©éãæã€ããŒã«ã | ç¡æ |
æåã®ã¬ãžã¹ããªã®çµ±å
AWS ã¢ã«ãŠã³ã㧠CloudFormation ã¹ã¿ãã¯ãäœæããDocker Scout ã®çµ±åãæå¹åããŸãã
åææ¡ä»¶ïŒ
- AWS ã¢ã«ãŠã³ããžã®ã¢ã¯ã»ã¹æš©ãããããªãœãŒã¹äœææš©éãããããšã
- Docker Organization ã®ãªãŒããŒã§ããããšã
ã¹ã¿ãã¯ã®äœææ¹æ³ïŒ
-
Docker Scout ããã·ã¥ããŒãã® ECR çµ±åããŒãžâã«ç§»åããŸãã
-
Create on AWS ãã¿ã³ãéžæããŸãã
ããã«ãããæ°ãããã©ãŠã¶ã¿ã㧠AWS CloudFormation ã³ã³ãœãŒã«ã® Create stack ãŠã£ã¶ãŒããéããŸããAWS ã«ãµã€ã³ã€ã³ããŠããªãå Žåã¯ãæåã«ãµã€ã³ã€ã³ããŒãžã«ãªãã€ã¬ã¯ããããŸãã
ãã¿ã³ãã°ã¬ãŒè¡šç€ºãããŠããå Žåã¯ãDocker Organization ã«å¿ èŠãªæš©éããããŸããã
-
Create stack ãŠã£ã¶ãŒãã®æé ã«åŸã£ãŠæäœãå®äºããŸããçµ±åããã AWS ãªãŒãžã§ã³ãéžæãããªãœãŒã¹ã®äœææç¶ããå®äºããŠãã ããã
ãŠã£ã¶ãŒãå ã®ãã£ãŒã«ã㯠CloudFormation ãã³ãã¬ãŒãã«ãã£ãŠäºåã«å ¥åãããŠãããããç·šéããå¿ èŠã¯ãããŸããã
-
ãªãœãŒã¹ãäœæããããšïŒAWS ã³ã³ãœãŒã«ã® CloudFormation ã¹ããŒã¿ã¹ã
CREATE_COMPLETE
ãšãªãïŒãDocker Scout ããã·ã¥ããŒãã® ECR çµ±åããŒãžã«æ»ããŸããIntegrated registries ãªã¹ãã«ãçµ±åãã ECR ã¬ãžã¹ããªã®ã¢ã«ãŠã³ã ID ãšãªãŒãžã§ã³ã衚瀺ãããŸããçµ±åãæåããå Žåãã¹ããŒã¿ã¹ã¯ Connected ãšãªããŸãã
ECR çµ±åã¯ããã§æå¹åãããŸãããã¬ãžã¹ããªå ã®ãªããžããªããšã« Docker Scout ãæå¹åããã«ã¯ããªããžããªèšå®âã«ç§»åããŠãã ããã
ãªããžããªãæå¹åãããšãããã·ã¥ãããã€ã¡ãŒãžã Docker Scout ã«ãã£ãŠåæãããŸããåæçµæ㯠Docker Scout ããã·ã¥ããŒãã«è¡šç€ºãããŸãããªããžããªã«ãã§ã«ã€ã¡ãŒãžãããå ŽåãDocker Scout ã¯ææ°ã®ã€ã¡ãŒãžããŒãžã§ã³ãèªåçã«ååŸããŠåæããŸãã
è¿œå ã®ã¬ãžã¹ããªã®çµ±å
è¿œå ã®ã¬ãžã¹ããªãçµ±åããã«ã¯ïŒ
-
Docker Scout ããã·ã¥ããŒãã®ECR çµ±åããŒãžâã«ç§»åããŸãã
-
ãªã¹ãã®äžéšã«ãã Add ãã¿ã³ãéžæããŸãã
-
AWS ãªãœãŒã¹ã®äœææé ãå®äºããŸãã
-
ãªãœãŒã¹ãäœæããããšãDocker Scout ããã·ã¥ããŒãã® ECR çµ±åããŒãžã«æ»ããŸãã
Integrated registries ãªã¹ãã«ãçµ±åãã ECR ã¬ãžã¹ããªã®ã¢ã«ãŠã³ã ID ãšãªãŒãžã§ã³ã衚瀺ãããŸããçµ±åãæåããå Žåãã¹ããŒã¿ã¹ã¯ Connected ãšãªããŸãã
次ã«ãåæããããªããžããªããšã« Docker Scout ãæå¹åããããã«ããªããžããªèšå®ã«ç§»åããŠãã ããã
çµ±åã®åé€
çµ±åããã ECR ã¬ãžã¹ããªãåé€ããã«ã¯ãDocker çµç¹ã®ãªãŒããŒã§ããå¿ èŠããããŸãã
-
Docker Scout ããã·ã¥ããŒãã®ECR çµ±åããŒãžâã«ç§»åããŸãã
-
çµ±åãããã¬ãžã¹ããªã®ãªã¹ããããåé€ãããã¬ãžã¹ããªãèŠã€ããActions åã®åé€ã¢ã€ã³ã³ãéžæããŸãã
åé€ã¢ã€ã³ã³ãç¡å¹ã«ãªã£ãŠããå Žåã¯ãDocker Organization ã«å¿ èŠãªæš©éããããŸããã
-
éãããã€ã¢ãã°ã§ãRemove ãéžæããŠç¢ºèªããŸãã
Docker Scout ããã·ã¥ããŒãããçµ±åãåé€ããŠããAWS ã¢ã«ãŠã³ãå ã®ãªãœãŒã¹ã¯åé€ãããŸããã
Docker Scout ã§çµ±åãåé€ããåŸãAWS ã³ã³ãœãŒã«ã«ç§»åããåé€ãããçµ±åã® DockerScoutECRIntegration CloudFormation ã¹ã¿ãã¯ãåé€ããŠãã ããã
ãã©ãã«ã·ã¥ãŒãã£ã³ã°
ã¬ãžã¹ããªãçµ±åã§ããªã
Docker Scout ããã·ã¥ããŒãã®ECR çµ±åããŒãžâã§ãçµ±åã® Status ã確èªããŠãã ããã
-
ã¹ããŒã¿ã¹ãé·æé Pending ã®å Žåã¯ãAWS åŽã§çµ±åããŸã å®äºããŠããªãããšã瀺ããŸããPending ãªã³ã¯ãéžæã㊠CloudFormation ãŠã£ã¶ãŒããéãããã¹ãŠã®æé ãå®äºããŠãã ããã
-
Error ã¹ããŒã¿ã¹ã¯ããã¯ãšã³ãã§åé¡ãçºçããããšã瀺ããŸããçµ±åã®åé€ãè©Šã¿ãå床äœæããŠã¿ãŠãã ããã
ECR ã€ã¡ãŒãžãããã·ã¥ããŒãã«è¡šç€ºãããªã
ECR ã€ã¡ãŒãžã®åæçµæã Docker Scout ããã·ã¥ããŒãã«è¡šç€ºãããªãå ŽåïŒ
-
Docker Scout ããªããžããªã§æå¹åãããŠããããšã確èªããŠãã ãããã¢ã¯ãã£ããªãªããžããªã®è¡šç€ºãšç®¡çã¯ãªããžããªèšå®âã§è¡ããŸãã
-
ã¬ãžã¹ããªã® AWS ã¢ã«ãŠã³ã ID ãšãªãŒãžã§ã³ã ECR çµ±åããŒãžã«ãªã¹ããããŠããããšã確èªããŠãã ããã
ã¢ã«ãŠã³ã ID ãšãªãŒãžã§ã³ã¯ãã¬ãžã¹ããªã®ãã¹ãåã«å«ãŸããŠããŸãïŒ
<aws_account_id>.dkr.ecr.<region>.amazonaws.com/<image>