Upgrade to Pro — share decks privately, control downloads, hide ads and more …

アーティファクトが鍵!ビジネスを安全に進化させるDevSecOps実践 / Manage artifacts to practice DevSecOps

アーティファクトが鍵!ビジネスを安全に進化させるDevSecOps実践 / Manage artifacts to practice DevSecOps

Developers Summit 2021 Summer (デブサミ2021夏)

ihcomega56

July 30, 2021
Tweet

More Decks by ihcomega56

Other Decks in Technology

Transcript

  1. %FWͱ0QT͕෼அ͞Ε͍ͯΔͱ 15 ։ൃ ৽ػೳΛಧ͚͍ͨͷʹʂ • ಠྗͰσϓϩΠͰ͖ͳ͍ͨΊ ࡞ͬͨ΋ͷΛ͙͢ग़ͤͳ͍ • ຊ൪؀ڥͰൃੜͨ͠τϥϒϧ ʹࣗΒؾ෇͘͜ͱ͕Ͱ͖ͳ͍

    ӡ༻ ҆ఆՔಇ͍ͤͨ͞ͷʹʂ • ӡ༻ͷߟྀ͕ෆे෼ͳΞϓϦ Λ؅ཧ͠ͳͯ͘͸ͳΒͳ͍ • ໰୊ൃੜ࣌ɺΞϓϦͷ࢓༷͕ ෼͔ΒͣࣗྗͰղܾͰ͖ͳ͍
  2. %FWͱ0QT͕෼அ͞Ε͍ͯΔͱ 16 ։ൃ ৽ػೳΛಧ͚͍ͨͷʹʂ • ಠྗͰσϓϩΠͰ͖ͳ͍ͨΊ ࡞ͬͨ΋ͷΛ͙͢ग़ͤͳ͍ • ຊ൪؀ڥͰൃੜͨ͠τϥϒϧ ʹࣗΒؾ෇͘͜ͱ͕Ͱ͖ͳ͍

    ӡ༻ ҆ఆՔಇ͍ͤͨ͞ͷʹʂ • ӡ༻ͷߟྀ͕ෆे෼ͳΞϓϦ Λ؅ཧ͠ͳͯ͘͸ͳΒͳ͍ • ໰୊ൃੜ࣌ɺΞϓϦͷ࢓༷͕ ෼͔ΒͣࣗྗͰղܾͰ͖ͳ͍ ότϧ͹͔Γ௙ͬͯ ϏδωεɾαʔϏε͕ ੒௕͠ͳ͍
  3. ͦ΋ͦ΋ηΩϡϦςΟͬͯʜ 21 • Πϯϑϥɺιϑτ΢ΣΞɺ ώϡʔϚϯΤϥʔͳͲؾʹ ͢΂͖͜ͱ͸ଟذʹΘͨΔ • શͯΛηΩϡϦςΟ୲౰ʹ ؙ౤͛ͤͣɺαʔϏεվળ ͷͨΊʹڠྗΛଓ͚Δ

    • %FW4FD0QTͷλʔήοτ͸ ιϑτ΢ΣΞͷηΩϡϦ ςΟͰ͋Δ ʮ8IBUBSFUIFMBZFSTPGTFDVSJUZ "DZCFSTFDVSJUZSFQPSUʯ IUUQTHPNJOETJHIUDPNJOTJHIUTCMPHXIBUBSFUIFMBZFSTPGTFDVSJUZ
  4. ڀۃͷΰʔϧΛ໨ࢦͯ͠ • ϦϦʔεճ਺Λ૿΍͢ ϦϦʔε·Ͱͷ࣌ؒΛ୹͘͢Δ • ࡞ۀΛޮ཰Խ͢Δ • ࡞ۀΛεέʔϧͤ͞Δ • ϛε΍τϥϒϧΛݮΒ͢

    ૣ͘ݟ͚ͭͯରԠ͢Δ ˠʮ%FW0QTʯ΍ʮΞδϟΠϧ։ൃʯ͸จԽɺ࢟੎ͱ ͯ͜͠ΕΛ໨ࢦ͢ αʔϏεͷվળ͸΋ͪΖΜɺϦιʔεෆ଍΍໘౗ͳ࡞ۀͱ͍ͬͨ ։ൃऀ๊͕͑Δ਎ۙͳ೰Έͷλωʹ΋ޮ͘ 23
  5. νΣοΫ Ξ΢τ Ϗϧυ ςετ ϦϦʔε σϓϩΠ 30 ιϑτ΢ΣΞͷηΩϡϦςΟ΋৭ʑ 30 ڴҖ

    ϞσϦϯά 4"45 %"45 ϖϯςετ 4$" ϑΝδϯά 4"45 ϒϥοΫ ϘοΫε ςετ %"45 ϖϯςετ ϗϫΠτ ϘοΫε ςετ ϑΝδϯά 4$" ˞ਤ͸ҰྫͰ͢
  6. νΣοΫ Ξ΢τ Ϗϧυ ςετ ϦϦʔε σϓϩΠ 42 044ΛࣗಈνΣοΫ 42 ڴҖ

    ϞσϦϯά 4"45 %"45 ϖϯςετ 4$" ϑΝδϯά IPX
  7. νΣοΫ Ξ΢τ Ϗϧυ ςετ ϦϦʔε σϓϩΠ 44 044ΛૣΊɾఆظతʹࣗಈνΣοΫ 44 4$"

    4$" ˞؀ڥʹΑͬͯ͸ *%&༻ϓϥάΠϯʹΑΔ ։ൃதͷνΣοΫ΋Մ XIFO
  8. ιʔείʔυ WTΞʔςΟϑΝΫτ 50 ιʔείʔυ • ։ൃʹΑΔվमͷର৅Ͱ͋Γ ϏδωεϩδοΫΛ͸͡Ίͱ ͢Δಠࣗͷ੒Ռ෺ʹ͋ͨΔ • (JUͳͲͷόʔδϣϯ؅ཧ͕

    ਁಁ͍ͯ͠Δ ΞʔςΟϑΝΫτ • ґଘղܾ͕ࡁΜͰ͓Γಠࣗͷ ίʔυҎ֎ͷ෦඼΋ؚ·ΕΔ • ग़ՙ σϓϩΠ ର৅ͱͳΔ • ઐ༻πʔϧͰͷ؅ཧ͸ίʔυ ͱൺֱ͢Δͱਁಁ͍ͯ͠ͳ͍
  9. ΞʔςΟϑΝΫτ͕ॏཁͳཧ༝ 51 • ґଘղܾ͕ࡁΜͰ͍Δ • ग़ՙର৅ͱͳΔ ˣ • ࠷ऴతʹαʔόʔͰಈ͘΋ͷʹؚ·ΕΔ044 ͱ͞ΒʹͦΕ͕

    ґଘ͢Δ044 ͷνΣοΫ͕ՄೳͱͳΔ • ιʔε಺ͷઃఆϑΝΠϧʹ͸ʮԿΛऔಘ༧ఆ͔ʯͱ͍͏৘ใ ͔͠ͳ͍ • ಉ͡ιʔείʔυΛϏϧυͯ͠΋ɺΞʔςΟϑΝΫτͷத਎ ͕ຖճಉ͡ͱ͸ݶΒͳ͍ uGvCGNwr xy#pqz{ <B@e`|} xy)3i#<=
  10. 52 ΞʔςΟϑΝΫτ͕ॏཁͳཧ༝ ίʔσΟϯά Ϗϧυ ςετσϓϩΠ ݁߹ςετ ୯ମςετ ຊ൪σϓϩΠ ӡ༻ ΞʔςΟϑΝΫτ

    ஀ੜ ΞʔςΟϑΝΫτ͕࢖ΘΕଓ͚Δ ౓ੜ੒ͨ͠Βຊ൪σϓϩΠ·Ͱಉ͡΋ͷΛ࢖͏ !"#$%&'() *+,-./012 34/56789: ;<2=1>)=1? ιʔείʔυ͕ ΞʔςΟϑΝΫτʹͳΔ·Ͱ
  11. • औಘͨ͠ΞʔςΟϑΝΫτ΋ϦϙδτϦʹ อ؅͓ͯ͘͠ • Ωϟογϡͷ໾ׂΛՌͨ͢ • ߴ଎ʹऔಘͰ͖Δ • ֎෦ϦϙδτϦʹΞΫηε Ͱ͖ͳͯ͘΋औಘͰ͖Δ

    औಘͭͭ͠ อ؅͢Δ %PDLFS)VC  .BWFO$FOUSBM  OQNͳͲ όΠφϦɾ ϦϙδτϦϚωʔδϟʔ࢖͍ํ ͦͷ 56
  12. औಘͭͭ͠ อ؅͢Δ %PDLFS)VC  .BWFO$FOUSBM  OQNͳͲ όΠφϦɾ ϦϙδτϦϚωʔδϟʔͱ4$"ͦͷ •

    औಘͯ͠อ؅ͨ͠ΞʔςΟϑΝΫτʹରͯ͠΋ ࢖͍ͬͯΔ044ͷεΩϟϯΛ͢Δ • /(͕ݟ͔ͭͬͨΒऔಘΛېࢭ͠ ࢖Θͳ͍Α͏ઃఆͰ͖Δ εΩϟϯ 57
  13. νΣοΫ Ξ΢τ Ϗϧυ ςετ ϦϦʔε σϓϩΠ 59 ࣮ݱ͍ͨ͠ύΠϓϥΠϯ 59 อ؅ͨ͠

    λΠϛϯάͰ 4$" 7$4 #3. TFSWFST TFSWFST ϦϦʔεલʹ 4$"
  14. πʔϧΛ௥Ճͨ͠Β 60 • 044ͷεΩϟϯ͸ʮ౰ͨΓલʯͱͯ͠ܧଓతʹ࣮ࢪ͢Δ • /(͕͋ͬͨࡍͷϑϩʔΛ༧ΊܾΊɺܭըஈ֊ͰߟྀʹೖΕΔ • ʮࠓճ͚ͩεΩϟϯΛεΩοϓʂʯʮٸ͔͗ͩΒεϧʔʂʯͱ ϧʔϧΛܗ֚Խͤ͞ͳ͍ •

    ࣗಈεΩϟϯͱਓྗͷ࡞ۀΛ૊Έ߹Θͤͯ044Λ׆༻͢Δ • ྫ͑͹ͦ΋ͦ΋ͷٕज़બఆʹ͸ਓͷ൑அ ࢖͍উखɺߋ৽ස౓ɺ ϝϯςφʔͷ਺ͳͲΛ;·͑ͯ ͕ඞཁͱͳΔ • εΩϟϯͰݟ͔ͭͬͨ/(ʹͲ͏ରԠ͢Δ͔ʹ͍ͭͯ΋൑அ͕ ඞཁͱͳΔ͜ͱ͕͋Δ • ॏཁͳ൑அʹ࣌ؒΛׂͨ͘Ίʹ΋ࣗಈԽ͕༗ޮͱͳΔ
  15. ࢀߟจݙ • +FOOJGFS%BWJT 3ZO %BOJFMTʰ&GGFDUJWF %FW0QT ʕຊபʹΑΔ࣋ଓՄೳͳ૊৫จԽͷҭͯํʱ • ʮ8IBUJT%FW0QT ʯIUUQTKGSPHDPNEFWPQTUPPMTXIBUJTEFWPQT

    • ʮ8IBU BSF UIF  MBZFST PG TFDVSJUZ " DZCFSTFDVSJUZ SFQPSUʯ IUUQTHPNJOETJHIUDPNJOTJHIUTCMPHXIBUBSFUIFMBZFSTPGTFDVSJUZ • ʮ&YQMPSF ZPVS 044 EFQFOEFODJFT 7JTVBMMZʯIUUQTXXXMJOLFEJODPNQVMTFFYQMPSFZPVSPTT EFQFOEFODJFTWJTVBMMZNJDIBFMNVMMFS • ʮ+BWB EFQFOEFODZ NBOBHFNFOU IPX NBOZ MJOFT PG DPEF EPFT NZ BQQMJDBUJPO IPME ʯ IUUQTTOZLJPCMPHKBWBEFQFOEFODZNBOBHFNFOU • ܦࡁ࢈ۀল঎຿৘ใ੓ࡦہαΠόʔηΩϡϦςΟ՝ʮ044ͷར׆༻ٴͼͦͷηΩϡϦςΟ֬อʹ޲͚ͨ؅ཧख๏ ʹؔ͢Δࣄྫूʯ IUUQTXXXNFUJHPKQQSFTTQEG • ೔ܦΫϩεςοΫ ೥݄೔ܝࡌʮ · ͨ ΋ 4USVUT ੬ ऑ ੑ ඃ ֐ ɺ ࠃ ަ ল Ͱ ໿  ສ ݅ ͷ ৘ ใ ྲྀ ग़ ͔ ʯ IUUQTYUFDIOJLLFJDPNJUBUDMOFXT • ೔ܦΫϩεςοΫ ೥݄೔ܝࡌʮ 8FCαΠτͷ੬ऑੑΛ೥લ͔Β์ஔ͔ɺϝχίϯ৘ใ࿙ӮͷݪҼʯ IUUQTYUFDIOJLLFJDPNBUDMOYUDPMVNO • ʮ#FTUQSBDUJDFTGPSJOUSPEVDJOH+'SPH9SBZJOUPZPVS%FW4FD0QT QSPDFTTʯ IUUQTNFEJBKGSPHDPNXQDPOUFOUVQMPBET#FTUQSBDUJDFTGPSJOUSPEVDJOH +'SPH9SBZJOUPZPVS%FW4FD0QTQSPDFTTQEG 72 72