This post is also available in: English (è±èª) æ¦è¦ ããæ°å¹´ãDockerãPodmanãKubernetesãå«ããã¾ãã¾ãªã³ã³ãããã©ãããã©ã¼ã ã§ãcopyã³ãã³ã(cp)ã®èå¼±æ§ãè¤æ°ç¢ºèªããã¦ãã¾ããããããã®ä¸ã§æãæ·±å»ãªãã®ã¯ãã®7æã¨ããããæè¿çºè¦ã»é示ããããã®ã§ããé©ãã¹ããã¨ã«ãCVEã®èª¬æå 容ãããã¾ãã ã£ããã¨ãå ¬éãããã¨ã¯ã¹ããã¤ãããªãã£ããã¨ãªã©ã®çç±ãããæ¬èå¼±æ§ã¯å ¬éç´å¾ã«ã¯ã»ã¨ãã©æ³¨æãå¼ãã¾ããã§ããã ããããªãããCVE-2019-14271ãæ»æè ã«æªç¨ãããå ´åãDockerã®å®è£ ããcpã³ãã³ãã¯ãå®å ¨ãªã³ã³ãããã¬ã¤ã¯ã¢ã¦ãã«ã¤ãªããããã»ãã¥ãªãã£ä¸ã®åé¡ãå¼ãèµ·ããã¾ãããã®èå¼±æ§ã¯ã2æã«çºè¦ãããrunCèå¼±æ§ä»¥éã§åãã¦ã®å®å ¨ãªã³ã³ãããã¬ã¤ã¯ã¢ã¦ãã§ãã ãã®èå¼±æ§ãæªç¨ãããã«
表é¡ã®ãããªåé¡ãããï¼ãã®èª¿æ»ããã¨ããè¨é²ã§ãï¼ãªãï¼çµè«ãä¸è¨ã§è¨ãã¨--initã使ãï¼ã¨ãããã¨ã«ãªãã¾ãï¼ ããããDockerã³ã³ãããèµ·åããã¨ï¼CMDãããã¯ENTRYPOINTã«æå®ãããã³ãã³ããã³ã³ããå ã§PID 1ã¨ãã¦èµ·åãã¾ãï¼ãããä½ãæå³ãããã¨è¨ãã¨ï¼ãCMDãããã¯ENTRYPOINTã«æå®ãããã³ãã³ããã¯ãã®ã³ãã³ãèªä½ã®è²¬åãã¾ã£ã¨ãããã®ã¨åæã«ï¼initããã»ã¹ã¨ãã¦ã®æ¯ãèããè¡ããªããã°ãªããªãã¨ãããã¨ã«ãªãã¾ã (id:hayajo_77ããã«ãã®è¾ºã詳ããæãã¦ãããã¾ããï¼ãããã¨ããããã¾ã)ï¼ ã¤ã¾ãPID 1ã§åãã¦ããããã»ã¹ã¯ãSIGCHLDããã©ãããããã¨ã§å¤å ããã»ã¹ãé©åã«ååãï¼waitpidãããããã¨ããå¦çãé©åã«è¡ãå¿ è¦ãããã¾ãï¼ ãã¦ï¼puppeteerã使ã£ã¦Chromeãã©ã¦ã¶ãèµ·åããã¨ã©ããª
ã³ã³ããåä»®æ³åã®æè¡ãå®è£ ã¯Dockerãç»å ´ãã以åããåå¨ãã¦ããã¨ã¯ãããITæ¥çã§æ¬æ ¼çã«ã³ã³ããã®æ´»ç¨ãå§ã¾ã£ãã¨è¨ããã®ã¯ããã¯ã2013å¹´3æã«å½æã®dotCloudããDockerãç»å ´ãããã¨ããã£ããã§ãããã ãããã¦å§ã¾ã£ãã³ã³ããæ代ã®ç¬¬ä¸ç« ã¯ä»å¹´2017å¹´ãã³ã³ããã®æ¨æºä»æ§ãOpen Container Initiativeã«ãã£ã¦çå®å®äºããã³ã³ãããªã¼ã±ã¹ãã¬ã¼ã·ã§ã³ã®äºå®ä¸ã®æ¨æºãKubernetesã«æ±ºã¾ã£ããã¨ã§åºç¤æè¡ã®åºæ¬è¦ç´ ãããããåºã¾ããä¸ã¤ã®åºåããã¤ããããã«è¦ãã¾ãã ããã¦ä»å¾ã¯ããã®åºç¤æè¡ãç¨ããã³ã³ããã«ããåæ£ã¢ããªã±ã¼ã·ã§ã³ã®ããã®æ§ã ãªãµã¼ãã¹ãéçºããã¹ãããããã¤ãæ¬çªç°å¢ã«å¯¾å¿ãããã¼ã«ããµã¼ãã¹å®è¡ç°å¢ãªã©ã®ã½ãªã¥ã¼ã·ã§ã³ãç»å ´ãã競ã段éã¸å ¥ã£ã¦ããã®ã§ã¯ãªãã§ããããã ãã®è¨äºã§ã¯ãDockerç»å ´ããç¾
大æITå社ã¯ãä»®æ³åæè¡ãç¨ãããããã«ã¼ãã¨å¼ã°ããã軽éã§ç§»è¡æ§ã«åªããã³ã³ããå¼ã¢ããªã±ã¼ã·ã§ã³ï¼å¿ç¨ã½ããï¼å®è¡åºç¤ã®æ®åæ¡å¤§ã«ä¹ãåºããæ¥æ¬ï¼©ï¼¢ï¼ã¯èªç¤¾ã¯ã©ã¦ãã«ä¾åããããªã³ãã¬ãã¹ï¼èªåéç¨ï¼ã§ã使ããã³ã³ããå¼ã®å®è¡ç°å¢ãIBï¼ã¯ã©ã¦ããã©ã¤ãã¼ããã®æä¾ãå§ãããNECã¯ããã«ã¼ã®å©ä¾¿æ§ãçããã人工ç¥è½ï¼ï¼¡ï¼©ï¼ã®å©æ´»ç¨ãä¿é²ãããµã¼ãã¹ãç«ã¡ä¸ãããITã®æ°æ½®æµã§ããã³ã³ããåã®ä»®æ³åæè¡ãæ¥æ¬ã§ãããããæ¬çªç¨¼åã«å ¥ãã ããã«ã¼ã¯ã¢ããªãããã«ã¦ã¨ã¢ãªã©ãæ½è±¡åãã¦ãã³ã³ããæ¹å¼ã§ã³ã³ãã¯ãã«ã¾ã¨ãä¸ããæè¡ã大ããããªã·ã¹ãã ãä¸è¦ãªä¸ãå ´æãåããã«å¤æ§ãªã¯ã©ã¦ãããªã³ãã¬ãã¹ãªã©ãå®è¡ã§ããã ãã®æè¡ã¯ãªã¼ãã³ã½ã¼ã¹ã¨ãã¦è¤æ°æä¾ããã¦ããããä¸ã§ãããã«ã¼ã¯ç±³ã¢ãã¾ã³ã»ã¦ã§ãã»ãµã¼ãã¹ï¼ï¼¡ï¼·ï¼³ï¼ãç±³ãã¤ã¯ãã½ããï¼ï¼ï¼³ï¼ãã¯ã©ã¦ããµã¼ãã¹ã«æ¡ç¨ããããæ°
Dockerã³ã³ããå ãããã¹ããã·ã³ã®ã«ã¼ããåãå ·ä½çãªæ¹æ³ï¼ãããã¯/var/run/docker.sockãæããã¨ã¸ã®æ³¨æåèµ·ï¼ 2015/11/04 dockerã® -v ãªãã·ã§ã³ã使ã£ã¦ãã¹ããã·ã³ã®ãã£ã¬ã¯ããªããã¦ã³ãããã¨ãã¯ããã¦ã³ãããç¯å²ã«æ³¨æãå¿ è¦ï¼ç¹ã«/var/run/docker.sockããã¦ã³ããã¦ã¯ãªããªãï¼ã¨ãã話ãæ¸ãã¾ãã å ãã¿ã¯@lvhãæ¸ãã¦ãDon't expose the Docker socket (not even to a container)ã¨ããè¨äºã§ã1ã¶æåãããã«Hacker Newsã§è©±é¡ã«ãªã£ã¦ã¦ç¥ãã¾ããã ãã®å è¨äºã§ç´¹ä»ããã¦ããããã¤ãã®å±éºãªãã¦ã³ãã®ãã¿ã¼ã³ã«é¢ããæ å ±ããæè¿dockerã使ãå§ããèªåã«æç¨ãªæ å ±ã ã£ãã®ã§ãèªæãè¾¼ãã¦è¦ç¹ãæ¸ãã¦ããã¾ãã TL;DR /var/run/docke
注æ æ¬ä»¶è¨äºã§ãããç§ã®ä¸é©åãªè¡åï¼æ¾ã£ãã¹ã¯ãªãããæ¤è¨¼ãªãèµ°ãããï¼ãåå ã§ãããdockerã¯ï¼ç¹ã«ä½ãããªãã¨ãï¼å±éºãã¨ã®èª¤è§£ãçæ§ã«ä¸ããç¹ããè¿·æãããããããã¾ãããç³ã訳ãããã¾ããã æ¡æ£ããã¦ããè¨äºãåé¤ããã®ã¯ãããªã誤解ãæããããªãã¨æãã¾ããã®ã§ãåé ã«æ³¨æãä»è¨ãã¦ããã¾ãã以ä¸ã®è¨äºã¯ããèªåãä½ãã¦ããããã¡ãã¨æ¤è¨¼ã§ããªãã¨ã»ãã¥ãªãã£ãã¼ã«ãçã¿åºããã¨ããæå³ã§åèã«ãã¦é ããã°å¹¸ãã§ãã è¿½è¨ Twitterãã¯ã¦ãã§è¨åããã ãã¾ããçæ§ããããã¨ããããã¾ãã æ¬ä»¶ã¯pullãã¦ããã¤ã¡ã¼ã¸ãæªæããéçºè ã«ãããã®ãã©ããã«ãããããä¸é©åãªè¨å®ããã¦ããã¨èµ·ããå¾ã¾ãã â»ã³ã¡ã³ãæ¬ã«è³ªåã¸ã®åçã¨ããå½¢ã§ãç§ããã®ã¨ãã«èµ°ããã¦ããã¤ã¡ã¼ã¸ã®ä¸è¦§ãæãã¦ããã¾ãããã©ã®ã¤ã¡ã¼ã¸ãè©å¤ãããã®ã ã¨æãã¾ãã çæ§ã«ãããã¾ãã¦ã¯ãã
ãã®è¨äºã¯ã¯ã¦ãªã¨ã³ã¸ãã¢ã¢ããã³ãã«ã¬ã³ãã¼2015ã®1æ¥ç®ã§ããä»åã¯ãæ¢åã®éç¨ããã¼ã«ä¹ããããDockerã¤ã¡ã¼ã¸ã¸ã®chrootã«ãããããã¤ã®èãæ¹ã¨èªä½ã®ã³ã³ã»ãããã¼ã« droot ãç´¹ä»ãã¾ãã github.com èæ¯ Docker æ¬çªå°å ¥ã®èª²é¡ Docker å°å ¥ã®ç®ç Docker + chroot ã®ã¢ã¤ã㢠droot: Dockerã¤ã¡ã¼ã¸ã«chrootããã³ã³ãããã¼ã« droot ã®ä½¿ãæ¹ droot push: Dockerã¤ã¡ã¼ã¸ãtar ballåãS3ã«pushãã droot pull: S3ã«pushããã¤ã¡ã¼ã¸ããã¦ã³ãã¼ããå±éãã droot run: å±éå ã®ãã£ã¬ã¯ããªã«chrootãã droot ã®å®è£ droot push/pull ã®å®è£ droot run ã®å®è£ ãããã¦èªã¿ãã ãã¨ãã èæ¯ Dockerããªãªã¼
docker/dockercraft å ¬å¼ã®æªæ¹å¤Minecraftã¯ã©ã¤ã¢ã³ãããæ¥ç¶ãã¦Dockerã®ç®¡çãã§ããMinecraftäºæãµã¼ãã¼ãDockercraftãå ¬éããã¦ããã Dockercraft Dockercraftã®å®è¡æ¹æ³ 1. Minecraftã®ã¤ã³ã¹ãã¼ã«: Minecraft Minecraftã¯ã©ã¤ã¢ã³ãã¯æ¹å¤ãã¦ããªãã®ã§ãå ¬å¼ãªãªã¼ã¹ããã®ã¾ã¾ä½¿ããã 2. Dockercraftã¤ã¡ã¼ã¸ãpullããããã«ãããã docker pull dockercraft ãããã¯ã git clone git@github.com:docker/dockercraft.git docker build -t dockercraft dockercraft 3. Dockercraftã³ã³ããã¼ãå®è¡ãã docker run -t -i -d -p 255
ãã¡ã«ã¯ 2013 å¹´æ«ãããããã£ã¨ docker ã³ã³ãããéç¨ãç¶ãã¦ããç©çãã¹ãããã£ãã®ã ãã©ãæè¿ $ docker ps ã¨ããã¦ãçµæãæ»ã£ã¦ããã®ã« 20 ç§ããããããããã³ã³ããã®èµ·åã¨ãã«ãåããããæéãããã $ /etc/init.d/docker restart ãªã©ã¨ããããããªãã³ã³ããã使ç¨å¯è½ã«ãªãã¾ã§ 3 æéãããããã£ã¦ããã¨ã¯ããããé »ç¹ã«ã³ã³ãããæåã§èµ·åãããçµäºããããããã¹ãã§ã¯ãªããã docker ã®ãã¼ã¢ã³èªä½ãåèµ·åããã¨ãã¯æ¬å½ã«ç¨ãªã®ã§ãã£ã¨æ¾ç½®ãã¦ããã ãã©ããããã«æ¾ç½®ã§ããªããªã£ã¦ããã $ docker ps --all | wc -l ã¨ãã㨠103781 ã¨ããªã£ã¦ã¦ãã´ãã³ã³ãããã¤ã¡ã¼ã¸ã大éã«ãããããã®ã諸æªã®æ ¹æºãªã®ã§ã¯ãªããã¨ããäºæ³ãç«ã¦ãã ããã§ãã®ãããªã¹ã¯ãªããã§ã³ã³ãããæé¤ãã¦ã¿
ã¯ãã¯ããã åºåäºæ¥é¨ã®å¤§éæä¸ã§ãã責任ç¯å²ã¯åºåäºæ¥ã®ç´åºåããã³ãããã¯ã¼ã¯åºåã®ååéçºæ å½ã§ãäºæ¥é¨ã«ã¯ããããã®å£²ä¸ã§ã³ããããã¦ãã¾ãã ãã®è¨äºã§ã¯ãåç»å¤æã®ä»çµã¿ã«ãããDockerã®æ´»ç¨ã«ã¤ãã¦ç´¹ä»ãã¾ãã ã¯ãã¯ãããã¯8æ8æ¥ãiOS/Androidã®ãã©ã¦ã¶ã«ããã¦åç»ã¯ãªã¨ã¤ãã£ããæ²åºããåºåååãå ¬éãã¾ãããåºåååã¨ãã¦ã®è©³ç´°ã¯ãã¬ã¹ãªãªã¼ã¹ãã¹ã©ã¤ããè¦ã¦ããã ãã®ãããããããã®ã§ãããæ¬ç¨¿ã«é¢ä¿ããç¹å¾´ã¨ãã¦ã¹ãã¼ããã©ã³ã®ãã©ã¦ã¶ã§èªåçã«åçãéå§ãããã¨ãããã®ãããã¾ãã ã¹ãã¼ããã©ã³ã®ãã©ã¦ã¶ã«ããã¦ã¯ãç¾å¨ã®ã¨ãããåç»ãèªååçããããã¨ã¯åºæ¥ã¾ãããããã¯AppleãGoogleã¨ãã£ããã©ã¦ã¶ãã³ãã課ãã¦ããå¶ç´ã§ããããã§ãã¯ãã¯ãããã§ã¯ãjaniã¨ããã©ã¤ãã©ãªã使ããç¹å®ã®è¦åã«åºã¥ãã¦ä½ãããç»åããJavaSc
Built on Docker Swarm, Shipyard gives you the ability to manage Docker resources including containers, images, private registries and more. Shipyard differs from other management applications in that it promotes composability and is 100% compatible with the Docker Remote API. Shipyard manages containers, images, nodes, private registries cluster-wide as well as providing authentication and role ba
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}