ããã«ã¡ã¯ãã¬ããããã㧠OpenShift ã¨ãã¹ãã¬ã¼ã¸ã¨ããçæ¥ã«ãã¦ããå®é½å®®(ãã¤ã¼)ã§ãã
ãªãã ãä¹
ãã¶ããªæãããã¾ãããä»å㯠Red Hat Trusted Software Supply Chain ã«ã¤ãã¦è©±ãã¾ãã
ä»å¹´ã®5æã«ã¢ã¡ãªã«ã§ Red Hat Summit 2023 ãéå¬ããã¾ããããã®ä¸ã§ã¯æ§ã
ãªæ°ãããããã¯ãããµã¼ãã¹ãçºè¡¨ããã¾ããã
ãã®ä¸ã®ä¸ã¤ã Red Hat Trusted Software Supply Chain (RHTSSC) ã§ãã
TL;DR
ç¡çãã3è¡ã§ã¾ã¨ãã¦ã¿ã¾ããRed Hat Trusted Software Supply Chain ã¨ã¯ã
- Red Hat OpenShift ä¸ã§ã»ãã¥ã¢ãªã½ããã¦ã§ã¢ãµãã©ã¤ãã§ã¼ã³ã®å®è£ ãå®ç¾ãããRed Hat ã®ããã¼ã¸ããµã¼ãã¹ã§ããã
- Red Hat Trusted Content, Red Hat Trusted Application Pipeline ãªã©è¤æ°ã®ãµã¼ãã¹ã使ããRed Hat ãæ㤠DevSecOps ã®ãã©ã¯ãã£ã¹ãé©ç¨ã§ããã
- ç¾å¨ã¯ "ãµã¼ãã¹ãã¬ãã¥ã¼" ç¶æ ã§ã¾ã GA ã§ã¯ãªãããwaitlistã«ç»é²ãããã¨ã¯ã§ããã
ãããããã®ã§ãã
æ¥å¢ãããµãã©ã¤ãã§ã¼ã³æ»æ
å°é家ãããªãã¤ããåããã«è¨ãã®ããªãã§ãããã½ããã¦ã§ã¢ãµãã©ã¤ãã§ã¼ã³ã¨ã¯ãã£ããè¨ãã°ãã¢ããªã±ã¼ã·ã§ã³ãçã¿åºããåãã¦ä½¿ãããªããªãã¾ã§ãããããããå¢å ´ã¾ã§ã«é¢ãã£ã¦ããããããæ§æè¦ç´ ãä¾åé¢ä¿ã®ç·ç§°ã§ãã
éçºè
ãçã¿åºãã³ã¼ãã¯ãã¡ããã®ãã¨ãããã±ã¼ã¸ãã©ã¤ãã©ãªããã¤ãã©ã¤ã³ãã¼ã«ããã«ããã¼ã«ãGitããã¹ããã¼ã«ãææç©ã®ãªãã¸ããªããã¼ã¹ã¤ã¡ã¼ã¸ãã³ã³ããã¬ã¸ã¹ããªãã³ã³ãããã©ãããã©ã¼ã ãããæããã°ããªãããã¾ããã
ããã»ã©ã¾ã§ããããããã¨ãæ®å¿µãªããã©ããã¦ãæ»æãåãã¦ãã¾ãéãçãããã®ã§ãã
ã³ã¼ãã«ããã¦ã¯ OSS ã³ãã¥ããã£ã§å
¬éããã¦ããããã±ã¼ã¸ãã©ã¤ãã©ãªãæ´»ç¨ãããã¨ãããã§ããããããã®ä»ãå
¬éããã¦ããã½ããã¦ã§ã¢ããã¼ã«é¡ã使ããã¨ãå¤ãã§ãããã
ãããã£ã誰ããå©ç¨ã§ãããã®ãæ»æãåããããã®ã§ãã
ä¾ãã° CI ãã¤ãã©ã¤ã³ã«ä¾µå
¥ããã¦ãã¾ãã¨ãGit ãªãã¸ããªã¸ã®çµè·¯ãã§ãã¾ãããã®å¾ã³ã¼ãããæ©å¯æ
å ±ãå¼ãæããã¦ãã¾ã£ãããæªæã®ããã³ã¼ããå·®ãè¾¼ãã ããªã©ãããããæ¾é¡ããã¦ãã¾ãã¾ãã
PyPI ã npm ã¨ãã£ããã¼ã«ã§ä½æ°ãªãããã±ã¼ã¸ãã¤ã³ã¹ãã¼ã«ããã¨ãå®ã¯æªæã®ãã人éã«ãã£ã¦ããã¯ãã¢ãä»è¾¼ã¾ãããã®ã§ãããããæ»æããã¦ãã¾ãã¨ãã£ããã¨ãããã¾ãã
ãããã£ãã½ããã¦ã§ã¢ãµãã©ã¤ãã§ã¼ã³ã¸ã®æ»æã¯ãSonatype 社ã®ã¬ãã¼ãã«ããã¨éå»3å¹´éã§742%ãæ¿å¢ãã¦ãã¾ãããããã£ã¦ããããã£ãæ»æã¸ã®å¯¾çã¯æ¥åã§ãã
Red Hat Trusted Software Supply Chainã£ã¦ãã³ã
Red Hat Trusted Software Supply Chain (RHTSSC) ã¯ããããã£ãæ»æã¸ã®å¯¾çãæ½ãããã»ãã¥ã¢ãªã½ããã¦ã§ã¢ãµãã©ã¤ãã§ã¼ã³ã®å®è£ ãå®ç¾ãã¾ãã
ã»ãã¥ã¢ãªã½ããã¦ã§ã¢ãµãã©ã¤ãã§ã¼ã³ãä½ãã«ã¯ããããã DevSecOps ã¨å¼ã°ããææ³ã使ãã¾ãããããã§ããããã§ã¯ããã¾ããã¨è¨ããã»ã©ç°¡åã§ã¯ããã¾ããã
ä½ãã©ãã©ã®ç¨åº¦ã»ãã¥ãªãã£å¯¾çããã°ä¸åº¦è¯ãã®ãããªã©æ§ã
ãªãã¨ã«é¢ããæ·±ãç¥èã¨çµé¨ã«åºã¥ãã¢ããã¼ããåããã¨ãçæ³çã§ãã
RHTSSC ã§ã¯ãRed Hat ã®ç¥èã¨çµé¨ã«åºã¥ãã DevSecOps ã®ãã©ã¯ãã£ã¹ãå©ç¨ãããã¨ãã§ãã¾ãã
RHTSSC ã¯ããã¼ã¸ããµã¼ãã¹ã§ãããRed Hat Hybrid Cloud Console ããã¢ã¯ã»ã¹ãããã¨ãã§ãã¾ãã
RHTSSC ã¯ããèªèº«ã®ååã®ãµã¼ãã¹ãããããã§ã¯ãªãã¦ãããã¤ãã®ãµã¼ãã¹ãä½µç¨ããç·ç§°ã§ãã
- Red Hat Trusted Application Pipeline (RHTAP)
https://console.redhat.com/preview/hac/application-pipeline - Red Hat Trusted Content (RHTC)
https://console.redhat.com/preview/application-services/trusted-content - Red Hat Advanced Cluster Security Cloud Service (RHACS Cloud)
https://console.redhat.com/preview/application-services/acs/overview
ãã¡ããããããã®ãµã¼ãã¹ã¯å¥ã ã«å©ç¨ãããã¨ãããã¼ããã§ãããã¾ããããããªï¼ð§
ãªãã§æ¯åããæªãã®ãã¨è¨ãã¨ããã®3ã¤ã®ãµã¼ãã¹ã¯ã¾ã ä¸è¬çã«ã¯ä½¿ããªãããã§ãã
RHTAP 㨠RHTCããã®2ã¤ã¯ãç¾å¨ "ãµã¼ãã¹ãã¬ãã¥ã¼" ã¨ããã¹ãã¼ã¿ã¹ã§ãã¾ã GA ããããµã¼ãã¹ã§ã¯ããã¾ããã
ãã㦠RHACS Cloud 㯠"Limited Available" ã¨ãã£ã¦å©ç¨ã§ããã¦ã¼ã¶ã¼ãããéå®ããã¦ãã¾ããè¿ããã¡ã«ç±³å½ã¨æ¬§å·ã§ GA äºå®ã§ã¯ããã¾ãããæ¥æ¬ã§ã¯ãã®å
ã§ãã
ãããããã¨ã§ãä»æ¥ææ¥ãã使ããã¨ãããã®ã§ã¯ãªãã®ã§ãã以å¾ã®ç´¹ä»ã¯ãããã£ãåæã§ã覧ããã ããã¨å¹¸çã®è³ãã§ãããã¾ãã§ãã
ã試ãã§ä½¿ã£ã¦ã¿ãããªããã¨ããæ¹ã¯ãwaitlist ã«ç»é²ãã¦å°ç¨ã® Slack Channel ã«åå ããã¨ã使ãæ¹ãæãã¦ããããã¨æãã¾ãã
Red Hat Trusted Application Pipeline
RHTAP ã¯ä¸»ã«ããã¼ã¸ããµã¼ãã¹åã® OpenShift Pipeline/Gitops ã¨èãã¦ããã ãã¦æ§ãã¾ããã
ãã®ä¸ã§ã»ãã¥ãªãã£å¯¾çãçãè¾¼ãã æ¨æºã®ãã¤ãã©ã¤ã³ããã£ã¦ããããæ´»ç¨ããå½¢ã«ãªãã¾ãããã¤ãã©ã¤ã³ã¯ã«ã¹ã¿ãã¤ãºãã§ãã¾ãã
ãã¤ãã©ã¤ã³ã®ä¸ã§ã¢ããªã±ã¼ã·ã§ã³ã® SBOM(Software Bill of Materials) ãä½ããã¾ãã
SBOM ã¯ãµãã©ã¤ãã§ã¼ã³ã®è¦ç´ ä¸è¦§è¡¨ã®ãããªãã®ã§ããSBOM ã¨å¤é¨ã®èå¼±æ§ãã¼ã¿ãã¼ã¹ãç
§ä¼ãããã¨ã§ãå®ã¯ãã¤ãªã¹ã¯ãªèå¼±æ§ãã¯ãã OSS ãæå³ãã使ã£ã¦ãããããå ´åã«æ°ã¥ããã¨ãã§ãã¾ãã
ã¾ãããã¤ãã©ã¤ã³ä¸ã§çã¿åºãããã³ã³ããã¤ã¡ã¼ã¸ã SBOM ãªã©ã®ææç©ã«ç½²åããããã¨ãã§ãã¾ãã ææç©ã«ç½²åãããã¨ã§ãæ»æè ã«ãããã«ã¦ã§ã¢ãªã©åºå ä¸æãªã½ããã¦ã§ã¢ãå ¥ãè¾¼ã¾ããããæ¹ãããããããããªã¹ã¯ãä¸ãããã¾ãã
Red Hat Trusted Content
RHTC ã¯éçºããã¢ããªã±ã¼ã·ã§ã³ã®ã»ãã¥ãªãã£ãã§ãã¯ããã¾ããvscode ãªã©ã®ã³ã¼ãã¨ãã£ã¿ã«ãã©ã°ã¤ã³ã¨ãã¦ç¨¼åãã¾ãã
RHTC ã¯ã¢ããªã±ã¼ã·ã§ã³ãä¾åããããã±ã¼ã¸ãã½ããã¦ã§ã¢è¨ºæããèå¼±æ§ã OSS ã©ã¤ã»ã³ã¹éåãªã©ãæ¤åºãã¦ããã¾ãã
ã¾ã Red Hat ãæä¾ããããã±ã¼ã¸ã«ã¤ãã¦ã¯ããã® SBOM 㨠VEX(Vulnerability Exploitability eXchange) ãå
¥æãããã¨ãã§ãã¾ãã
VEX ã¨ã¯ãSBOM ã¨èå¼±æ§ DB ããæ¤åºãããèå¼±æ§ãå®éã«ã¢ããªã±ã¼ã·ã§ã³ã«å½±é¿ãåã¼ãããè©ä¾¡ããä¸ã§å½¹ç«ã¤ãã®ã§ãã
SBOM 㨠VEX ã®é¢ä¿æ§ã«ã¤ãã¦ã¯ããã¡ãã®ããã° ã詳ããæ¸ããã¦ãã¾ãã
ããã¯å®ã¯ Red Hat Dependency Analytics ã¨ããæ¢åã®ãµã¼ãã¹ã¨ã»ã¼åãã§ããããå©ç¨ã§ããã¨ã¤ã¡ã¼ã¸ãã¦ããã ãã¦ã大ä¸å¤«ããªã¨æãã¾ãã Red Hat Dependency Analytics ã«ã¤ãã¦ã¯ãã¡ãã®è¨äºã«è©³ããã®ã§ããã¡ããã覧ä¸ããã
Red Hat Advanced Cluster Security Cloud Service
RHACS Cloud ã¯ãã»ã«ãããã¼ã¸ã® Red Hat Advanced Cluster Security (RHACS) ã®ããã¼ã¸ããµã¼ãã¹çã§ãã
RHACS ã¨ã®æ©è½çãªéããã»ã¼ãªããRHACS ã«ã¤ãã¦ã¯éå»ã«ãä½åãè¨äºã§åãä¸ãããã¦ãã¾ãã®ã§ãããã§ã¯èª¬æã¯çç¥ãã¾ãã
ã¾ã¨ã
ã¨ããããã§ãRed Hat Trusted Software Supply Chain ã®ç°¡åãªç´¹ä»ããã¾ããã
ãµã¤ãã¼æ»æã¯æ¥µãã¦å¤å²ã«ãããããå
¨ã¦ã網ç¾
çã«å¯¾çãããã¨ã¯æ¥µãã¦é£ããã¨è¨ãã¾ããããããITã»ãã¥ãªãã£ã¯çµæ§å°éçãªåéãªã®ã§åãã人æã¯å¤ãããã¾ããã
ãããä½ã対çããªãã§ãããã¨ã¯è¨±ãããªããå°é家ã§ãªãã¨ãèªè¡ã§ããç¯å²ã§ã¯èªè¡ãããã¨ãå¿
è¦ã§ãã
åè¿°ã®éãããµãã©ã¤ãã§ã¼ã³æ»æã¯æ¥å¢ãã¦ãã¾ãã誰ããç¥ã£ã¦ãããããªå
é²çãªä¼æ¥ã§ã被害ã«éã£ã¦ããã対çã¯æ¥åã§ãã
ã»ãã¥ãªãã£å¯¾çã®åºæ¬ã¯ãè
å¨ã®èªèã¨äºé²ãè¿
éãªæ¤ç¥ãããã¦ç´ æ©ã対å¿ã§ãããã½ããã¦ã§ã¢ãµãã©ã¤ãã§ã¼ã³ã§ããããåºãã«ãã¼ããã®ã Red Hat Trusted Software Supply Chain ã§ãã
æ®å¿µãªããä»ã¯ã¾ã GAåã§ããããããã£ããµã¼ãã¹ã Red Hat ã¯æä¾ãã¦ãããã ã¨é ã®çé ã«ç½®ãã¦ããã ããã°å¹¸ãã§ãã ã¨ããããã§ä»åã¯ããã¾ã§ã