Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
k8sとOPAつなげてみた - Admission Controller編
Search
Kengo Suzuki
March 18, 2019
Technology
1.1k
1
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
k8sとOPAつなげてみた - Admission Controller編
Kengo Suzuki
March 18, 2019
More Decks by Kengo Suzuki
See All by Kengo Suzuki
男(監査)はつらいよ - Policy as CodeからAIエージェントへ
ken5scal
5
1.2k
AI時代の大規模データ活用とセキュリティ戦略
ken5scal
1
550
Pwned Labsのすゝめ
ken5scal
2
1.3k
信頼性に挑む中で拡張できる・得られる1人のスキルセットとは?
ken5scal
3
1.4k
Eventual Detection Engineering
ken5scal
0
3k
脆弱性対応をこの先生きのこるには
ken5scal
0
1.8k
LayerXとMDMのリスク評価と年次対応の実例(公開版)
ken5scal
2
1.5k
AWSだ! Google Cloudだ! Azureだ! 認証連携だ!
ken5scal
9
2.7k
適応し続けるプロダクトとセキュリティ
ken5scal
5
2.6k
Other Decks in Technology
See All in Technology
AI de Idea
kawaguti
PRO
2
130
技術的負債から考える、AI時代のエンジニアリング投資 — ビズリーチの技術的負債と向き合った経験から、変更し続けられるソフトウェアを考える/ technical-debt-con2026
visional_engineering_and_design
4
3.3k
SREへの勘違いに気づいた後の話
tomodakengo
0
110
aws-iot-platform-architecture-use-cases.pdf
ma2shita
0
370
【技術的負債conf】事業成長に伴う技術的負債の説明責任とAIによるモニタリング、認知的負債について
i35_267
3
1.8k
おい、エージェントを使って終わらせろ
nwiizo
2
740
顧客に向き合う開発組織へ。リアーキテクチャとフィーチャーチーム化で挑む組織改革
safie
0
2.1k
「ピッケル本」日本語版は4.0(第6版)が出版されるべき / pickaxe4-nagoyark05
kakutani
2
200
幾何アルゴリズムで なめらかなピン操作を / iOSDC Japan 2026 / smoothpin
kazumanagano
0
360
ユーザー価値を届け続けるためにウォンテッドリーが大切にしている文化
kotaminato
0
180
バイブコーディング時代のWebアプリ開発入門~Cloud Runで学ぶセキュアなビルドとデプロイ
waiwai2111
1
140
AIは推し活である。
kurazuuuuuu
1
840
Featured
See All Featured
Discover your Explorer Soul
emna__ayadi
2
1.3k
Heart Work Chapter 1 - Part 1
lfama
PRO
10
36k
Navigating Weather and Climate Data
rabernat
0
520
Rebuilding a faster, lazier Slack
samanthasiow
85
9.6k
A better future with KSS
kneath
240
18k
Digital Projects Gone Horribly Wrong (And the UX Pros Who Still Save the Day) - Dean Schuster
uxyall
1
2.9k
Designing Dashboards & Data Visualisations in Web Apps
destraynor
232
55k
BBQ
matthewcrist
89
10k
How to make the Groovebox
asonas
2
2.4k
Skip the Path - Find Your Career Trail
mkilby
1
230
ラッコキーワード サービス紹介資料
rakko
1
4.9M
Lightning Talk: Beautiful Slides for Beginners
inesmontani
PRO
2
700
Transcript
k8sͱOPAͭͳ͛ͯΈͨ - Admission Controllerฤ 2019/03/18 @ken5scal
Ζ͏ͱͨ͜͠ͱ 1. k8sͷAdmission ControllerΛOPAʹ͚Δ 2. k8s APIαʔόʔͷϦΫΤετʹOPAϙϦγʔΛ ద༻͢Δ
k8s Admission Controllerͱ - k8s APIαʔόʔʹର͢ΔೝূɾೝՄ͞ΕͨϦΫΤετ ͷΦϒδΣΫτ͕ӬଓԽ͞ΕΔલʹɺ੍ޚ͢Δػߏ - ϓϥάΠϯʹΑͬͯɺͲͷΑ͏ͳ੍ޚΛ͢Δ͔ܾΊΒΕ Δ
OPAʢΦʔύʣͱ - ϦΫΤετͷਖ਼ੑΛݕূͯ͠ɺΤʔδΣϯτʹ ݁ՌΛฦ͢ɺ͍ΘΏΔϙϦγʔΤϯδϯ - ʮCloud Native Meetup Tokyo #4ʯͷൃදࢀর
https://speakerdeck.com/ken5scal/introduction-to-open-policy-agent
- ValidatingAdmissionWebhookʹOPAΛઃఆ - k8s APIαʔόʹର͢ΔͲͷΑ͏ͳΞΫγϣϯΛࢦ ఆ͢Δ͔ɺͬͪ͜ʹॻ͘ k8s Admission ControllerͱOPAɹͦͷᶃ
cat > webhook-configuration.yaml <<EOF kind: ValidatingWebhookConfiguration apiVersion: admissionregistration.k8s.io/v1beta1 metadata: name:
opa-validating-webhook webhooks: - name: validating-webhook.openpolicyagent.org rules: - operations: ["CREATE", "UPDATE"] apiGroups: ["*"] apiVersions: ["*"] resources: ["*"] clientConfig: caBundle: $(cat ca.crt | base64 | tr -d '\n') service: namespace: opa name: opa EOF https://aws.amazon.com/jp/blogs/opensource/using-open-policy-agent-on-amazon-eks/
- OPAͷϙϦγʔͦͷͷRegoͰهड़ - k8sͷConfigMapsͱͯ͠औΓࠐΉ k8s Admission ControllerͱOPAɹͦͷᶄ
ྫ1: IngressͷFQDNࢦఆ
package kubernetes.admission import data.kubernetes.namespaces deny[msg] { input.request.kind.kind = "Ingress" input.request.operation
= "CREATE" host = input.request.object.spec.rules[_].host not fqdn_matches_any(host, valid_ingress_hosts) msg = sprintf("invalid ingress host %q", [host]) } valid_ingress_hosts = {host | whitelist = namespaces[input.request.namespace].metadata.annotations["ingress- whitelist"] hosts = split(whitelist, ",") host = hosts[_] } https://www.openpolicyagent.org/docs/kubernetes-admission-control.html
% cat ingress-bad.yaml apiVersion: extensions/v1beta1 kind: Ingress metadata: name: ingress-bad
spec: rules: - host: acmecorp.com http: paths: - backend: serviceName: nginx servicePort: 80 % kubectl create -f ingress-bad.yaml -n qa Error from server (invalid ingress host "acmecorp.com"): error when creating "ingress- bad.yaml": admission webhook "validating-webhook.openpolicyagent.org" denied the request: invalid ingress host "acmecorp.com" https://www.openpolicyagent.org/docs/kubernetes-admission-control.html
ྫ1: ίϯςφϨδετϦͷࢦఆ
cat > image_source.rego <<EOF package kubernetes.admission deny[msg] { input.request.kind.kind =
"Pod" input.request.operation = "CREATE" image = input.request.object.spec.containers[_].image name = input.request.object.metadata.name not registry_whitelisted(image,whitelisted_registries) msg = sprintf("pod %q has invalid registry %q", [name, image]) } whitelisted_registries = {registry | registries = [ “602401143452.dkr.ecr.ap-northeast-1.amazonaws.com" ] registry = registries[_] } registry_whitelisted(str, patterns) { registry_matches(str, patterns[_]) } registry_matches(str, pattern) { contains(str, pattern) } https://aws.amazon.com/jp/blogs/opensource/using-open-policy-agent-on-amazon-eks/
% cat nginx.yaml kind: Pod apiVersion: v1 metadata: name: nginx
labels: app: nginx namespace: default spec: containers: - image: nginx name: nginx % kubectl apply -f nginx.yaml Error from server (pod "nginx" has invalid registry "nginx"): error when creating "nginx.yaml": admission webhook "validating-webhook.openpolicyagent.org" denied the request: pod "nginx2" has invalid registry "nginx" https://aws.amazon.com/jp/blogs/opensource/using-open-policy-agent-on-amazon-eks/
Ͱ͖ͳ͍͜ͱ - Runtimeͷ੍ޚ - APIαʔόʔʹର͢Δૢ࡞੍͔͠ޚͰ͖ͳ͍ - “ϙϦγʔ”ͷద༻ͳͷͰ੩తͳݕࠪͩͱΓͳ͍ - OPAͦͷͷͷ੍ޚ -
etc
͜͜ʹςΩετΛೖΕ·͢ɻ ͻͱͭͷεϥΠυʹ༰Λ٧Ί͗͢ ͳ͍Α͏ʹ͠·͠ΐ͏ɻ ʮ̍ຕͷεϥΠυʹ̍ͭͷҙຯʯ͕ εϥΠυ࡞ΓͷجຊͰ͢ɻ ٕज़ॻయͰOPAωλͷബ͍ຊͩ͠·͢
@ken5scal
Thank you