ã¯ããã«
æè¿ãçæAIã®æ´»ç¨ãå¢ãã¦ãã¾ãããç¹ã«ãOpenShiftã®ã¤ã¡ã¼ã¸ã¬ã¸ã¹ããªã«å¯¾ãã³ã³ããã¤ã¡ã¼ã¸ãpushããéã«å¿ è¦ã¨ãªãæå°æ¨©éã®ãã¼ã«ã«ã¤ãã¦ãçæAI Copilotã§ç¢ºèªãã¦ã¿ã¾ããããã®è¨äºã§ã¯ããã®çµé¨ãå ±æããçæAI Copilotãã©ã®ããã«å½¹ç«ã¤ããå ·ä½çã«ç¤ºãã¾ãã
æå°æ¨©éã®ãã¼ã«
ããã³ãã
ç§ã¯ãOpenShiftç°å¢ã§æ°ããªServiceã¢ã«ã¦ã³ããä½æãã¾ããæ°ããªServiceAccountã§ã¯ã
skopeo copy
ã³ãã³ãã使ã£ã¦ãOpenShiftã®ã¤ã¡ã¼ã¸ã¬ã¸ã¹ããªã«å¯¾ããã³ã³ããã¤ã¡ã¼ã¸ãpushãã¾ããæ°ããªServiceAccountã«ä»ä¸ãã¹ããæå°æ¨©éã®ãã¼ã«ãæãã¦ãã ããã
åç
OpenShiftç°å¢ã§æ°ããªServiceã¢ã«ã¦ã³ããä½æãã
skopeo copy
ã³ãã³ãã使ã£ã¦ã³ã³ããã¤ã¡ã¼ã¸ãpushããããã«ã¯ãæå°éã®æ¨©éã¨ãã¦ä»¥ä¸ã®ãã¼ã«ãå¿ è¦ã§ãï¼
system:image-puller
ï¼ãã®ãã¼ã«ã¯ãOpenShiftã®ã¤ã¡ã¼ã¸ã¬ã¸ã¹ããªããã¤ã¡ã¼ã¸ãpullãã権éãæä¾ãã¾ããããã¯skopeo copy
ã³ãã³ããã½ã¼ã¹ã¤ã¡ã¼ã¸ãpullããããã«å¿ è¦ã§ãã
system:image-builder
ï¼ãã®ãã¼ã«ã¯ãæ°ããã¤ã¡ã¼ã¸ããã«ãããã¤ã¡ã¼ã¸ã¹ããªã¼ã ã«pushãã権éãæä¾ãã¾ããããã¯skopeo copy
ã³ãã³ããã¿ã¼ã²ããã¤ã¡ã¼ã¸ãpushããããã«å¿ è¦ã§ãããããã®ãã¼ã«ã¯ãæ°ããªServiceã¢ã«ã¦ã³ãã«ä»ä¸ãããã¨ã§ãå¿ è¦ãªæä½ãè¡ãããã®æå°éã®æ¨©éãæä¾ãã¾ãããã ãããããã®ãã¼ã«ãé©åã«æ©è½ããããã«ã¯ãé©åãªåå空éã§ã®ãã¼ã«ãã¤ã³ãã£ã³ã°ãå¿ è¦ã§ããå ·ä½çãªæä½ã¯ã以ä¸ã®ããã«ãªãã¾ãï¼
# ServiceAccountã®ä½æ oc create serviceaccount my-service-account # å¿ è¦ãªãã¼ã«ã®ä»ä¸ oc policy add-role-to-user system:image-puller system:serviceaccount:myproject:my-service-account oc policy add-role-to-user system:image-builder system:serviceaccount:myproject:my-service-account
ä¸è¨ã®ã³ãã³ãã§ã¯ã
myproject
ã¯ããªãã®ããã¸ã§ã¯ãã®ååãmy-service-account
ã¯æ°ãã«ä½æããServiceã¢ã«ã¦ã³ãã®ååã«ç½®ãæãã¦ãã ãããããã«ãããæ°ããªServiceã¢ã«ã¦ã³ãã¯ãOpenShiftã®ã¤ã¡ã¼ã¸ã¬ã¸ã¹ããªã«å¯¾ãã¦ãã³ã³ããã¤ã¡ã¼ã¸ãpullããpushãããã¨ãå¯è½ã¨ãªãã¾ãããã ããã»ãã¥ãªãã£ä¸ã®çç±ããããããã®ãã¼ã«ã¯æå°éã®æ¨©éãæä¾ãããã®ã§ãããä»ã®æ¨©éãå¿ è¦ãªå ´åã¯ãé©åãªãã¼ã«ã追å ããå¿ è¦ãããã¾ããã¾ãããããã®æä½ã¯ç®¡çè 権éãæã¤ã¦ã¼ã¶ã¼ãè¡ãå¿ è¦ãããã¾ãããèªèº«ã®ç°å¢ã«åããã¦é©åã«è¨å®ãã¦ãã ããã
registry-editorãã¼ã«ã¨ã®éã
ããã³ãã
registry-editorãã¼ã«ãä»ä¸ããæ¹æ³ã¨ã¯ä½ãéãã¾ããï¼
åç
registry-editor
ãã¼ã«ãä»ä¸ãããã¨ããOpenShiftã®ã¤ã¡ã¼ã¸ã¬ã¸ã¹ããªã«å¯¾ãã¦ã¤ã¡ã¼ã¸ãpushããããã®ä¸ã¤ã®æ¹æ³ã§ã¹²³â´ããã®ãã¼ã«ã¯ãã¤ã¡ã¼ã¸ã®æ¸ãåºããããã·ã¥ãå®è¡ããããã®æ¨©éãæä¾ãã¾ã¹²³â´ãå ·ä½çãªæä½ã¯ä»¥ä¸ã®ããã«ãªãã¾ãï¼
# registry-editorãã¼ã«ã®ä»ä¸ oc policy add-role-to-user registry-editor <user_name>
ãã ãã
registry-editor
ãã¼ã«ãä»ä¸ããã¨ããã®ã¦ã¼ã¶ã¼ã¯ã¬ã¸ã¹ããªå ¨ä½ã«å¯¾ãã¦ã¤ã¡ã¼ã¸ãpushãã権éãæã¤ãã¨ã«ãªãã¾ã¹²³â´ãããã¯ãç¹å®ã®ããã¸ã§ã¯ãã ãã«å¯¾ããã¢ã¯ã»ã¹å¶éãè¨ãããå ´åã«ã¯é©ãã¦ãã¾ãããä¸æ¹ã
system:image-puller
ã¨system:image-builder
ã®ãã¼ã«ãä»ä¸ããæ¹æ³ã§ã¯ãç¹å®ã®ããã¸ã§ã¯ãå ã§ã®ã¿ã¤ã¡ã¼ã¸ãpullããpushãã権éãæã¤Serviceã¢ã«ã¦ã³ããä½æãããã¨ãã§ãã¾ããããã«ãããããç´°ããã¢ã¯ã»ã¹å¶å¾¡ãå¯è½ã¨ãªãã¾ãããããã£ã¦ãã©ã¡ãã®æ¹æ³ãé¸æãããã¯ãããªãã®ã»ãã¥ãªãã£è¦ä»¶ãããã¸ã§ã¯ãã®è¦ä»¶ã«ããã¾ããå ¨ä½ã®ã¬ã¸ã¹ããªã«å¯¾ããã¢ã¯ã»ã¹æ¨©éãå¿ è¦ãªå ´åã¯
registry-editor
ãã¼ã«ããç¹å®ã®ããã¸ã§ã¯ãã«å¯¾ããã¢ã¯ã»ã¹æ¨©éã ããå¿ è¦ãªå ´åã¯system:image-puller
ã¨system:image-builder
ã®ãã¼ã«ãä»ä¸ããæ¹æ³ãé¸æãã¦ãã ããã¹²³â´ãã½ã¼ã¹: Copilot ã¨ã®ä¼è©±ã 2024/7/1 (1) 第4ç« ã¬ã¸ã¹ããªã¼ã¸ã®ã¢ã¯ã»ã¹ | Red Hat Product Documentation. https://docs.redhat.com/ja/documentation/openshift_container_platform/4.11/html/registry/accessing-the-registry. (2) Accessing the registry | Registry | OpenShift Container .... https://docs.openshift.com/container-platform/4.6/registry/accessing-the-registry.html. (3) 第5ç« Accessing the registry OpenShift Container Platform 4. .... https://access.redhat.com/documentation/ja-jp/openshift_container_platform/4.2/html/registry/accessing-the-registry. (4) 第4ç« ã¬ã¸ã¹ããªã¼ã¸ã®ã¢ã¯ã»ã¹ | Red Hat Product Documentation. https://access.redhat.com/documentation/ja-jp/openshift_container_platform/4.1/html/registry/accessing-the-registry. (5) 5.6. ãã¼ã«ã®ã¦ã¼ã¶ã¼ã¸ã®è¿½å OpenShift Container Platform 4 .... https://access.redhat.com/documentation/ja-jp/openshift_container_platform/4.4/html/authentication_and_authorization/adding-roles_using-rbac. (6) ja.wikipedia.org. https://ja.wikipedia.org/wiki/OpenShift.
ã¾ã¨ã
ãå¿ è¦ã¨ãªãæå°æ¨©éã®ãã¼ã«ããç°¡åã«ç¢ºèªãããã¨ãã§ãã¾ãããã¾ãã以ä¸ã®2ã¤ã®ãã¼ã«ãä»ä¸ããæ¹æ³ã®éããæ確ã«åããã¾ããã
- ã
registry-editor
ãã¼ã«ãä»ä¸ããã¨ããã®ã¦ã¼ã¶ã¼ã¯ã¬ã¸ã¹ããªå ¨ä½ã«å¯¾ãã¦ã¤ã¡ã¼ã¸ãpushãã権éãæã¤ãã¨ã«ãªãã¾ããã - ã
system:image-puller
ã¨system:image-builder
ã®ãã¼ã«ãä»ä¸ããæ¹æ³ã§ã¯ãç¹å®ã®ããã¸ã§ã¯ãå ã§ã®ã¿ã¤ã¡ã¼ã¸ãpullããpushãã権éãæã¤Serviceã¢ã«ã¦ã³ããä½æãããã¨ãã§ãã¾ããã
ãããã®ç¥èã¯ãOpenShiftã®ã¤ã¡ã¼ã¸ã¬ã¸ã¹ããªã«å¯¾ããæä½ãè¡ãéã®åèã«ãªãã¾ããçæAI Copilotã®æ´»ç¨ã«ããããããã®æ å ±ãå¹ççã«å¾ããã¨ãã§ãã¾ãããä»å¾ããã¾ãã¾ãªã·ã¼ã³ã§çæAIãæ´»ç¨ãã¦ããããã¨æãã¾ãã