Docker/Kuberneteséçºã»éç¨ã®ããã®ã»ãã¥ãªãã£å®è·µã¬ã¤ã
4,048å (3,680å+ç¨)
é¢é£ãµã¤ã
æ¬æ¸ã®é¢é£ãã¼ã¸ãç¨æããã¦ãã¾ãã
å 容紹ä»
DockerãKubernetesã使ã£ã¦ã¢ããªã±ã¼ã·ã§ã³ããããã¤ãããã¨ã¯ããã¾ãå½ããåã«ãªãã¤ã¤ããã¾ããããããªãããDockerãKubernetesã®ã»ãã¥ãªãã£ã確ä¿ãããã¨ã¯ãã¾ã ã«ç°¡åã§ã¯ããã¾ãããããã©ã«ãã®è¨å®ã§ã³ã³ãããå®è¡ãã¦ãã¾ããã? Kubernetesã®ãªã½ã¼ã¹ã«å¯¾ãã権éãæ£ããè¨å®ã§ãã¦ãã¾ãã?
æ¬æ¸ã¯ãDockerãKubernetesã®ã»ãã¥ãªãã£ãå¼·åããããã®è¨å®æ¹æ³ãã便å©ãªãã¼ã«ã®ä½¿ãæ¹ã«ã¤ãã¦ãç¶²ç¾ çãã¤è©³ç´°ã«è¨ãã¦ãã¾ããã¾ããDockerã«ä»£ããã³ã³ããã¨ã³ã¸ã³ã¨ãã¦è©±é¡ã®Podmanãªã©ãææ°ã®ã½ããã¦ã§ã¢ã«é¢ããæ å ±ããµãã ãã«çãè¾¼ã¿ã¾ããã
第1ç« ãDocker/Kubernetesã®ãããããã»DockerãKubernetesã®ä½¿ãæ¹ã«ã¤ãã¦ç°¡åã«ãããããã¾ãã
第2ç« ãã³ã³ããéç¨ã«ãããè å¨ã®äºä¾ãã»DockerãKubernetesãæ§æããã³ã³ãã¼ãã³ãã®éå»ã®èå¼±æ§æ å ±ããè¨å®ãã¹ã«ããæ»æ被害äºä¾ãç´¹ä»ãã¾ãã
第3ç« ãã©ã³ã¿ã¤ã ã®ã»ãã¥ãªãã£Tipsãã»Docker APIã¨ã³ããã¤ã³ããä¿è·ããæ¹æ³ãã³ã³ãããérootã¦ã¼ã¶ã§å®è¡ããæ¹æ³ããSELinuxã§ãã¡ã¤ã«ã¢ã¯ã»ã¹ãå³ããå¶éããæ¹æ³ãªã©ãç´¹ä»ãã¾ãã
第4ç« ãã¤ã¡ã¼ã¸ã®ã»ãã¥ãªãã£Tipsãã»Dockerã¤ã¡ã¼ã¸ã®èå¼±æ§ãæ¤æ»ããæ¹æ³ãããã©ã¤ãã¼ãã¤ã¡ã¼ã¸ã¬ã¸ã¹ããªã®æ§ç¯æ¹æ³ãªã©ãç´¹ä»ãã¾ãã
第5ç« ãKubernetesã¯ã©ã¹ã¿ã®ã»ãã¥ãªãã£Tipsãã»Service AccountãRBACã®åºæ¬çãªè¨å®æ¹æ³ãããç¬èªã®Admission Webhookã®éçºæ¹æ³ã¨ãã£ãå¿ç¨çãªTipsã¾ã§å¹ åºãç´¹ä»ãã¾ãã
第6ç« ãã¢ããªã±ã¼ã·ã§ã³ééä¿¡ãå®ããã»Network PolicyãIstioã使ã£ã¦Podã®éä¿¡ãå¶å¾¡ããæ¹æ³ããSPIFFEã§ã¢ããªã±ã¼ã·ã§ã³ãèªè¨¼ããæ¹æ³ãç´¹ä»ãã¾ãã
æ¸èªæ å ±
- èè : é ç° ç大, äºååµ ç¶¾, å®ä½ç¾ åä¹
- çºè¡æ¥: 2020-02-27 (ç´æ¸ç±ççºè¡æ¥: 2020-02-27)
- æçµæ´æ°æ¥: 2020-02-27
- ãã¼ã¸ã§ã³: 1.0.0
- ãã¼ã¸æ°: 352ãã¼ã¸(PDFçæç®)
- 対å¿ãã©ã¼ããã: PDF
- åºç社: ãã¤ããåºç
対象èªè
èè ã«ã¤ãã¦
é ç° ç大
æ¥æ¬é»ä¿¡é»è©±æ ªå¼ä¼ç¤¾ã½ããã¦ã§ã¢ã¤ããã¼ã·ã§ã³ã»ã³ã¿æå±ãå ¥ç¤¾ä»¥æ¥ããªã¼ãã³ã½ã¼ã¹ã½ããã¦ã§ã¢ï¼OSSï¼ã«é¢ããæ´»åã«å¾äºãMobyï¼dockerdï¼ãBuildKitãcontainerd ãªã©ã®OSS ã®ã¡ã³ããï¼éçºå§å¡ï¼ãåãã¦ãããã¨ãã«Rootless ã³ã³ããæè¡ã«è²¢ç®ãã¾ããDocker Meetup Tokyo ãå ±åéå¶ãã¦ããã
äºååµ ç¶¾
OpenStack ããã¼ã¹ã¨ããIaaS/PaaS ã®ã¯ã©ã¦ããµã¼ãã¹åºç¤ã5 å¹´ã»ã©éçºããã®ã¡ã2017 å¹´ããã¼ããã©ãæ ªå¼ä¼ç¤¾ã§ã¤ãã¼ç¤¾åãã®Kubernetes 管çåºç¤ã®ç 究éçºãæ å½ãã»ããKubernetes é¢é£ã®OSS éçºããKubernetes Meetup Tokyo ãå ±åéå¶ãã¦ããã
å®ä½ç¾ åä¹
IDaaS ã®ç«ã¡ä¸ããªã©èªè¨¼é¢é£ã®ããã¸ã§ã¯ãã«å¾äºããã®ã¡ã2016 å¹´9 æã«ã¼ããã©ãæ ªå¼ä¼ç¤¾ã«å ¥ç¤¾ãZero Trust Network ããµã¼ãã¹èªè¨¼ã®æè¡ãä¸å¿ã«ã¤ã³ãã©åºç¤ã®ç 究éçºãè¡ã£ã¦ããã社å¤æ´»åã¨ãã¦SPIFFE/SPIRE ããã¸ã§ã¯ãã¸ã®ã³ã³ããªãã¥ã¼ã·ã§ã³ãã¯ãããSPIFFE Meetup Tokyo ãå ±åéå¶ãã¦ããã
ç®æ¬¡
第1ç« ãDocker/Kubernetesã®ãããã
- 1.1ãDockerã®å¾©ç¿
- 1.2ãKubernetesã®å¾©ç¿
第2ç« ãã³ã³ããéç¨ã«ãããè å¨ã®äºä¾
- 2.1ãAPI ã¨ã³ããã¤ã³ãã®è¨å®ãã¹
- 2.2ãã©ã³ã¿ã¤ã ãã«ã¼ãã«ã®èå¼±æ§
- 2.3ãã¤ã¡ã¼ã¸ã®èå¼±æ§
第3ç« ãã©ã³ã¿ã¤ã ã®ã»ãã¥ãªãã£Tips
- 3.1ãDocker APIã¨ã³ããã¤ã³ããä¿è·ãã
- 3.2ãã³ã³ããå®è¡ã¦ã¼ã¶ãå¤æ´ãã
- 3.3ãã±ã¼ãããªãã£ãã·ã¹ãã ã³ã¼ã«ãå¶éãã
- 3.4ããã¡ã¤ã«ã¢ã¯ã»ã¹ãå¶å¾¡ãã
- 3.5ããªã½ã¼ã¹ãå¶éãã
- 3.6ã代æ¿ã©ã³ã¿ã¤ã ãå©ç¨ãã
- 3.7ãã³ã³ãããç£è¦ãã
- 3.8ãè¨å®ãæ¤è¨¼ãã
第4ç« ãã¤ã¡ã¼ã¸ã®ã»ãã¥ãªãã£Tips
- 4.1ãDockerfile ãããã©ã¤ãã¼ããªGit ãS3 ã«ã¢ã¯ã»ã¹ãã
- 4.2ãã³ã³ããå ã§å®å ¨ã«ã¤ã¡ã¼ã¸ããã«ããã
- 4.3ãã¤ã¡ã¼ã¸ã®èå¼±æ§ãæ¤æ»ãã
- 4.4ãæ¹ç«ãããã¤ã¡ã¼ã¸ã®ãããã¤ãé²ã
- 4.5ããã©ã¤ãã¼ãã¬ã¸ã¹ããªãæ§ç¯ããï¼Harborï¼
第5ç« ãKubernetesã¯ã©ã¹ã¿ã®ã»ãã¥ãªãã£tips
- 5.1ãã¯ã©ã¹ã¿ãææ°ã®ç¶æ ã«ä¿ã¤ããã«
- 5.2ããã¹ãæ»æããå®ãAPI ã®ã¢ã¯ã»ã¹å¶å¾¡
- 5.3ãèªè¨¼ã¢ã¸ã¥ã¼ã«ã®é¸ã³æ¹ã¨ä½¿ãæ¹
- 5.4ãService Account ã«ãããµã¼ãã¹èªè¨¼ã¨ã¢ã«ã¦ã³ã管ç
- 5.5ãèªå¯ã¢ã¸ã¥ã¼ã«ã®ç¨®é¡ã¨å©ç¨æ¹æ³
- 5.6ãAdmissionã³ã³ããã¼ã©ã«ããæè»ãªã¢ã¯ã»ã¹å¶å¾¡
- 5.7ãWebhookã§ç¬èªã®Admission Controlã追å ãã
- 5.8ãã·ã¹ãã ã³ã³ãã¼ãã³ãééä¿¡ã®ä¿è·
- 5.9ãã¹ã±ã¸ã¥ã¼ã©ã«ããå²ãå½ã¦ãã¼ãã®å¶å¾¡
- 5.10ãç§å¯æ å ±ã管çãã
- 5.11ãGitOps ã®ããã®Secret 管ç
第6ç« ãã¢ããªã±ã¼ã·ã§ã³ééä¿¡ãå®ã
- 6.1ãNetwork Policy ã使ã£ã¦Pod ã®éä¿¡ãå¶å¾¡ãã
- 6.2ãIstioã使ã£ã¦Podéã®éä¿¡ãå®ã
- 6.3ãSPIFFE ã«ããã¢ããªã±ã¼ã·ã§ã³ã®èªè¨¼
- 6.4ãã¯ã©ã¹ã¿å¤é¨ã¨ã®éä¿¡ãå®ã