Slide 85
Slide 85 text
,VCFTFDΛ༻͍ͯ,VCFSOFUFT.BOJGFTUΛεΩϟϯ͢Δ͜ͱͰɺҎԼͷΑ͏ʹίϯςφىಈઃఆͷධՁΛߦ͏͜ͱ͕Ͱ͖·͢ɻ
ࠓճͷ߈ܸͷओཁҼͱͳͬͨ1SJWJMFHFEઃఆ͕$SJUJDBMͰݕ͞Ε͍ͯΔଞɺ
ִੑΛߴΊΔͨΊͷਪઃఆ͕BEWJTFͱͯ͠ݕ͞Ε͍ͯΔ͜ͱ͕͔Γ·͢ɻ
LVCFTFDTDBOXFCJOTFDVSFQPEZNM
<
\
PCKFDU1PEXFCJOTFDVSFEFGBVMU
WBMJEUSVF
fi
MF/BNFXFCJOTFDVSFQPEZNM
NFTTBHF'BJMFEXJUIBTDPSFPGQPJOUT
TDPSF
TDPSJOH\
DSJUJDBM<
\
JE1SJWJMFHFE
TFMFDUPSDPOUBJOFST<>TFDVSJUZ$POUFYUQSJWJMFHFEUSVF
SFBTPO1SJWJMFHFEDPOUBJOFSTDBOBMMPXBMNPTUDPNQMFUFMZVOSFTUSJDUFEIPTUBDDFTT
QPJOUT
^
>
BEWJTF<
\
JE"QQBSNPS"OZ
TFMFDUPSNFUBEBUBBOOPUBUJPOTaDPOUBJOFSBQQBSNPSTFDVSJUZCFUBLVCFSOFUFTJPOHJOYa
SFBTPO8FMMEF
fi
OFE"QQ"SNPSQPMJDJFTNBZQSPWJEFHSFBUFSQSPUFDUJPOGSPNVOLOPXOUISFBUT8"3/*/(/05130%6$5*0/3&"%:
QPJOUT
^
ɾ
ɾ
ɾ
{
"id": "ReadOnlyRootFilesystem",
"selector": "containers[] .securityContext .readOnlyRootFilesystem == true",
"reason": "An immutable root filesystem can prevent malicious binaries being added to PATH and increase attack cost",
"points": 1
},
ίϯςφηΩϡϦςΟͷߟ͑ํίϯςφ ରࡦ