Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
開発エンジニアが取り組む DevSecOps ~ GitHub Enterprise × ...
Search
Kaz Watanabe
February 20, 2026
35
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
開発エンジニアが取り組む DevSecOps ~ GitHub Enterprise × Azure での実践~
Kaz Watanabe
February 20, 2026
More Decks by Kaz Watanabe
See All by Kaz Watanabe
Greenは本当にGreenか? - B/GデプロイとAPI自動テストで安心デプロイ
kaz29
1
190
CI/CD/IaC 久々に0から環境を作ったらこうなりました
kaz29
1
490
開発エンジニアが実践するDevSecOps
kaz29
0
150
PHPCon福岡2024-Azureもなかなかいいですよ.pdf
kaz29
2
370
Azure Container Apps + Bicep 〜 こんな感じで運用しています
kaz29
3
1.3k
20220908_フロントエンドパフォーマンス改善.pdf
kaz29
2
200
PHP製のPodCast配信用WebアプリをReact+Next.jsなSSGで作り直してみた話
kaz29
3
720
バックエンドエンジニアの私がお勧めする SPAフロントエンド開発環境
kaz29
6
6.3k
201909-PHPCon北海道-PHPでCI_CD.pdf
kaz29
0
4.2k
Featured
See All Featured
Primal Persuasion: How to Engage the Brain for Learning That Lasts
tmiket
0
370
Ethics towards AI in product and experience design
skipperchong
2
310
Dominate Local Search Results - an insider guide to GBP, reviews, and Local SEO
greggifford
PRO
0
200
Building the Perfect Custom Keyboard
takai
2
800
Un-Boring Meetings
codingconduct
0
320
sira's awesome portfolio website redesign presentation
elsirapls
0
280
Efficient Content Optimization with Google Search Console & Apps Script
katarinadahlin
PRO
1
630
Visualizing Your Data: Incorporating Mongo into Loggly Infrastructure
mongodb
49
10k
The Anti-SEO Checklist Checklist. Pubcon Cyber Week
ryanjones
0
170
Build The Right Thing And Hit Your Dates
maggiecrowley
39
3.2k
Sharpening the Axe: The Primacy of Toolmaking
bcantrill
46
2.9k
HDC tutorial
michielstock
2
720
Transcript
։ൃΤϯδχΞ͕औΓΉ DevSecOps ~ GitHub Enterprise × Azure Ͱͷ࣮ફ ~ ࣍ظϑϩϯτγεςϜ։ൃ෦ลҰ
0DUP/JIPO'PSN
2 WHO!? ลҰ JCOMגࣜձࣾ ࣍ظϑϩϯτγεςϜ։ൃ෦ WebΞϓϦέʔγϣϯͷ։ൃ DevOpsڥͷߏஙɾӡ༻ ΫϥυΠϯϑϥͷߏஙɾӡ༻ Microsoft Azure,
Developer Technologies (Azure Infrastructure as Code, Web Development) @kaz_29
3 ԿΛ͍ͯ͠Δ෦ॺ͔ʁ
4 DevOpsߏ֓ཁ DevSecOpsͷલʹ DevSecOpsͷऔΈ • ίʔυͷ݈શੑνΣοΫʢSonarQubeʣ • ύοέʔδߋ৽ΛࣗಈԽʢDependabotʣ • ίϯςφ੬ऑੑΛҰݩཧʢTrivy
+ Advanced Securityʣ औΈதͷMCP׆༻ʹ͍ͭͯ ·ͱΊ Agenda
%FW0QTߏ֓ཁ
6 %FW0QTͷߏ֓ཁ APIs FrontApps Push PR Exec Action CI CD/IaC
ղੳ݁Ռ Provision Deploy Advanced Security Container Scan ঢ়ଶΛཧ PR Dependabot Trivy Bicep phpcs/phpcbf eslint Vitest PHPUnit phpstan Docker Git ubuntu VSCode
DevSecOps
8 %FW4FD0QT ͔ͬ͠Γͨ͠DevOpsͷ࣮ݱ͕DevSecOpsͷલఏ DevɹOps Sec
9 • ΠϯϑϥੜɾઃఆͷࣗಈԽ(IaC) • ίʔυʹམͱ͢͜ͱͰɺΠϯϑϥΛιϑτΣΞ։ൃͱಉ͡ख๏ͰཧͰ͖Δ • όʔδϣϯཧ • શͯͷϦιʔε(ιʔείʔυɺIaCͷίʔυɺDBͷϚΠάϨʔγϣϯͳͲ) •
ςετͷࣗಈԽ • UnitTest, Functional Test, (E2E Test) • ϏϧυɾσϓϩΠͷࣗಈԽ • ϏϧυϓϩηεΛશͯࣗಈԽɺϫϯϘλϯͰ୭Ͱ࣮ߦͰ͖ΔΑ͏ʹɺ࣮ߦ݁ՌΛશһͰڞ༗ • ϦΞϧλΠϜʹใڞ༗ • શһ͕ࢀՃ͍ͯ͠ΔνϟοτͰશͯΛڞ༗ɺγεςϜʹى͖͍ͯΔ͜ͱΛ௨ɺίϛϡχέʔγϣϯίετͷݮ %FW0QTʹඞཁͳཁૉ
10 %FW0QTͷߏ֓ཁ $*13࡞࣌ʹ6OJU5FTUͳͲΛࣗಈ࣮ߦ ί ϯ ς φ ͷ Ϗ ϧ
υ ί σ ϯ ά ε λ Π ϧ ν Ϋ phpstan ʹ Α Δ ੩ త ղ ੳ UnitTest ɾ Functional Test ͷ ࣮ ߦ SonarQube ʹ Α Δ ੩ త ղ ੳ ࣮ ߦ ݁ Ռ Λ Teams ʹ ௨ SonaeQube Badge Λ PR ί ϝ ϯ τ ʹ ߘ ίʔυͷ৴པੑɾอकੑ ্ͷࢪࡦ w ݕ༰ͷྫ w ܕͷෆҰகͷݕ w ଘࡏ͠ͳ͍Ϋϥεϝ ιουͷݺͼग़͠ w ྻΩʔϓϩύςΟͷ ະఆٛΞΫηε w ౸ୡෆೳͳίʔυ 4"45ʢ੩తΞϓϦέʔγϣϯη ΩϡϦςΟςετʣ w ݕ༰ w όάηΩϡϦςΟͷ੬ऑੑ w ίʔυͷॏෳɺෳࡶੑɺίʔ σΟϯάنҧ w ςετΧόϨοδͷଌఆ w ٕज़తෛ࠴ͷఆྔԽ
11 %FW0QTͷߏ֓ཁ σϓϩΠͷࣗಈԽ ί υ ͷ ν Ϋ Ξ
τ ί ϯ ς φ Ϩ δ ε τ Ϧ ʹ ϩ ά Π ϯ λ ά ໊ Λ औ ಘ ί ϯ ς φ Λ build & push λ ά ໊ ͔ Β Ϧ Ϗ δ ϯ ໊ Λ ࡞ Azure ϩ ά Π ϯ ࣮ ߦ த ͷ Ϧ Ϗ δ ϯ Λ औ ಘ ৽ ͠ ͍ Ϧ Ϗ δ ϯ Λ σ ϓ ϩ Π (traf c: 0%) Azure ϩ ά Π ϯ ৽ چ ͷ Ϧ Ϗ δ ϯ ͷ traf c Λ ೖ ସ ͑ Azure ϩ ά Π ϯ چ Ϧ Ϗ δ ϯ Λ আ Build Deploy Flip Deactivate ঝೝ ঝೝ ϦϦʔελάΛ࡞ Ұ୴͜͜Ͱఀࢭ
12 %FW0QTͷߏ֓ཁ *B$֤ڥͷϓϩϏδϣχϯάΛࣗಈԽ IaC ί υ ͷ จ ๏ ν
Ϋ STG ֤ ڥ ͱ ͷ ࠩ Λ औ ಘ ࠩ Λ PR ί ϝ ϯ τ ʹ ߘ IaC ί υ ͷ จ ๏ ν Ϋ ϓ ϩ Ϗ δ χ ϯ ά ࣮ ߦ PR࡞ ঝೝ UAT PROD Bicepίʔυͱ ࠩΛൺֱ ͕ͳ͚Ε Ϛʔδ ϨϏϡʔ ϦϦʔε ߏมߋ Ұ୴͜͜Ͱఀࢭ
SonarQube
14 %FW0QTͷߏ֓ཁ ࠶ܝ APIs FrontApps Push PR Exec Action CI
ղੳ݁Ռ Provision Deploy Advanced Security Container Scan ঢ়ଶΛཧ PR Dependabot Trivy Bicep phpcs/phpcbf eslint Vitest PHPUnit phpstan Docker Git ubuntu VSCode CD/IaC
15 4POBS2VCF
16 SAST Static Application Security Testingɿ੩తΞϓϦέʔγϣϯηΩϡϦςΟςετ Azure্ʹߏங Community EditionΛࣗલͰӡ༻ Azure
Container Apps - ϏδωελΠϜҎ֎0εέʔϧͰίετ0) Azure Database for PostgreSQL Azure Storage(Files) PHP/TypescriptͳͲશͯͷϦϙδτϦͰར༻ 4POBS2VCF ߏ
17 Quality Gate • ΧόϨοδ80%Ҏ্ • ݱঢ়ଞ΄΅σϑΥϧτɺӶҙௐΛਐΊ͍ͯΔ ӡ༻্ͷͪΐͬͱͨ͠ • PRίϝϯτʹBadgeΛࣗಈߘ
• εϓϦϯτऴ൫ʹఆظνΣοΫɾରԠ 4POBS2VCF
Dependabot
19 %FW0QTͷߏ֓ཁ ࠶ܝ APIs FrontApps Push PR Exec Action CI
ղੳ݁Ռ Provision Deploy Advanced Security Container Scan ঢ়ଶΛཧ PR Dependabot Trivy Bicep phpcs/phpcbf eslint Vitest PHPUnit phpstan Docker Git ubuntu VSCode CD/IaC
20 GitHubۘͷϥΠϒϥϦɾύοέʔδͷґଘؔࣗಈཧπʔϧ ಛ • όʔδϣϯΞοϓΛݕ • ੬ऑੑΛݕ => ରԠ͢ΔPRΛࣗಈੜ(ޓੑͷϨϕϧChangeLogΛίϝϯτʹهࡌ) •
CIͱΈ߹ΘͤΔ͜ͱͰΞοϓσʔτͷखؒΛܰݮ %FQFOEBCPU
21 ઃఆ PHP(composer) / TS(npm)྆ํར༻ ि࣍ͰνΣοΫΛ࣮ߦ(݄༵ே) Security Update / Version
Update྆ํ༗ޮ Grouped update(ಛʹTSͰඞਢ) ӡ༻ auto-mergeະ༻ɻcompatibilityΛݟͯखಈஅ ࣗಈςετ͕௨ΕɺΧδϡΞϧʹϚʔδ PR͕ཷ·Δ εϓϦϯτຖʹ୲ཱͯΔͳͲνʔϜຖʹ͍ͯ͠Δ %FQFOEBCPU
Trivy + Advanced Security
23 %FW0QTͷߏ֓ཁ ࠶ܝ APIs FrontApps Push PR Exec Action CI
ղੳ݁Ռ Provision Deploy Advanced Security Container Scan ঢ়ଶΛཧ PR Dependabot Trivy Bicep phpcs/phpcbf eslint Vitest PHPUnit phpstan Docker Git ubuntu VSCode CD/IaC
24 OSSͷ੬ऑੑεΩϟφʔ ରԠൣғ͕͍ ίϯςφΠϝʔδ ϑΝΠϧγεςϜ ܰྔɾߴɾCIΈࠐΈ͕؆୯ SARIFܗࣜͰग़ྗՄೳ → GitHub Advanced
Security ͱ࿈ܞ 5SJWZ https://trivy.dev/
25 5SJWZ "EWBODFE4FDVSJUZ https://trivy.dev/ ίϯςφ੬ऑੑͷҰݩཧ ֤ API Π ϝ δ
ͷ ࠷ ৽ ൛ (latest) Λ औ ಘ Trivy Ͱ ੬ ऑ ੑ Λ ε Ω ϯ Advanced Security ʹ Upload ຖே࣮ߦ SARIF ܗ ࣜ Ͱ ग़ ྗ
26 શϦϙδτϦͷ੬ऑੑΛҰݩཧ ॏେ(Critical/High/Medium/Low)Ͱ༏ઌΛஅ ରԠঢ়گͷ͕Ͱ͖Δ (JU)VC"EWBODFE4FDVSJUZ https://trivy.dev/ 4FDVSJUZλϒͰҰݩཧ
27 Ξϥʔτཧͷϑϩʔ͕ະඋ • ΈԽͷݕ౼த… ରԠͷଐਓԽ • ରԠϑϩʔͷඋ PHPͷόʔδϣϯΞοϓͳͲɺ։ൃ×ӡ༻ͷ࿈ܞͷ͠͞ • ։ൃνʔϜɺӡ༻νʔϜͷ૬ޓཧղͷػձΛ࡞Δ
• ࿈ܞڧԽ 5SJWZ "EWBODFE4FDVSJUZ https://trivy.dev/ ࠓޙͷ՝
͓·͚
औΈதͷ MCP׆༻ʹ͍ͭͯ
30 "*ͱπʔϧΛͭͳ͙Φʔϓϯͳϓϩτίϧ w ݄"OUISPQJD͕ެ։ w ݄-JOVY'PVOEBUJPO ""*' ʹҠ (JU)VCެࣜ.$1αʔόʔΛެ։ .$1
.PEFM$POUFYU1SPUPDPM MCP αʔόʔɾπʔϧ Model Context Protocol ֤छAPIͳͲ …
31 ՝ w %FW0QTϝτϦΫεΛՄࢹԽ͍ͨ͠ʢ'PVS,FZTͱ͔ʣ w ͰɺμογϡϘʔυ࡞Δͷ໘ʜ .$1ͳΒʜ w 6*Λ࡞Βͳ͍͍ͯ͘ w
--.͕ΠϯλʔϑΣʔεʹͳΔ w ࣗવݴޠͰ͍߹ΘͤͰ͖Δ https://github.com/kaz29/mcp-server-example https://kaz29.hatenablog.com/entry/2026/01/12/163450 ͳͥ.$1Λࢼ͍ͯ͠Δ͔
·ͱΊ
33 ✅ ઐՈ͡Όͳͯ͘ɺDevSecOpsͰ͖Δ GitHubͷػೳ + OSS ΛΈ߹ΘͤΔ ᘳ͡Όͳ͍͍ͯ͘ɺͰ͖Δͱ͜Ζ͔Β ✅ DevOpsͷ͕େࣄ
CI/CDɺςετࣗಈԽɺϝτϦΫε ͕͜͜ͳ͍ͱSecurityࡌͤΒΕͳ͍ ✅ ՝͋Δɺܧଓతʹվળ ӡ༻ϑϩʔͷඋ νʔϜؒ࿈ܞͷڧԽ ✅ AIͷ׆༻ਐΊ͍ͯ͘ MCPͰϝτϦΫεੳΛݕূத ·ͱΊ
None