Upgrade to Pro — share decks privately, control downloads, hide ads and more …

スクラムチームのDevOpsを支えるPlatform Engineering @ 実践DevO...

SimSta
November 15, 2024
55

スクラムチームのDevOpsを支えるPlatform Engineering @ 実践DevOps! 〜KAGとkubellの取り組み〜

SimSta

November 15, 2024
Tweet

More Decks by SimSta

Transcript

  1. ΞδϟΠϧ%FW0QTͱ1MBUGPSN&OHJOFFSJOH ϓϥοτϑΥʔϜΤϯδχΞϦϯάͱ͸ IUUQTMFBSONJDSPTPGUDPNKBKQQMBUGPSNFOHJOFFSJOHXIBUJTQMBUGPSNFOHJOFFSJOH 4%-$ ιϑτ΢ΣΞ։ൃͷ ϑΣʔζΛࣔ͢ࢦ਑ ΞδϟΠϧ։ൃ খ͍͞αΠΫϧͰͷ ։ൃͷ࣮ફʹΑΔ ૉૣ͍Ձ஋ఏڙ

    %FW0QT ܧଓతͳσϦόϦʔΛ࣮ݱ͢ΔͨΊͷ ։ൃख๏ͱӡ༻ͷࣗಈԽɾޮ཰Խ 1MBUGPSN&OHJOFFSJOH ։ൃ΍ηΩϡϦςΟɾΨόφϯεΛ ؀ڥ੔උ΍*B$ɺࣗಈԽͳͲͰࢧԉ "HJMF4%-$4LZSPDLFUJOH:PVS1SPKFDUXJUI"HJMF1SJODJQMFT IUUQTNMTEFWDPNCMPHBHJMFTEMD
  2. ιϑτ΢ΣΞ։ൃΛ๺ւಓཱྀߦʹྫ͑Δͱʜ 4%-$ ໨త஍·Ͱͷ஍ਤ %FW0QT ަ௨खஈʢ৐Γ෺ʣ ΞδϟΠϧ։ൃ ͍ΖΜͳܦ༝஍Ͱඞཁͳ΋ͷΛ੔උ ΢ΥʔλʔϑΥʔϧ։ൃ ୯Ұͷަ௨खஈͰ໨త஍·Ͱ௚௨ 1MBUGPSN&OHJOFFSJOH

    ަ௨Πϯϑϥ ʢࠃಓɺߴ଎ɺۭ࿏ɺߤ࿏౳ʣ ࡳຈˠവؗ΁ߦ͘ͷʹ ͔ͭͯ͸మಓͰ͔͔͕࣌ؒͬͨ ࣨའ͔Βߤ࿏Λ੔උͰ͖Ε͹ େ෯ʹ͕࣌ؒ୹ॖͰ͖Δ͔΋͠Εͳ͍ খḺˠ໢૸΁ߦ͘ͷʹ ೔ߴɺѴ઒ɺ۴࿏ͳͲΛܦ༝ͯ͠ ඞཁͳ΋ͷΛἧ͍͑ͯ͘ͷ͕ΞδϟΠϧ ৐Γ෺ʢెาɺഅɺඈߦધʣ͕%FW0QT ಓͷ։୓͕1MBUGPSN&OHJOFFSJOH $PQZSJHIU˜4PVHPV4IPVLFO$0 -UE"MM3JHIUT3FTFSWFE
  3. ,"(1'&νʔϜͷ͓࢓ࣄ • ࣾ಺ڞ௨(JU)VC&OUFSQSJTF4FSWFSʢ()&4ʣͷ؅ཧ • ()&4΍ࣗࣾΫϥ΢υ؀ڥͷίετ࠷దԽ • ࣗࣾΫϥ΢υ؀ڥ΍*E1ͷӡ༻ɺ؅ཧ • ࣗࣾΫϥ΢υ؀ڥͱ֤Ҋ݅؀ڥͷηΩϡϦςΟվળ 


    ˠ4FDVSJUZ)VC΍(VBSE%VUZͷಋೖɺ؅ཧͳͲ • ֤εΫϥϜνʔϜ΁ͷώΞϦϯάɺࢧԉϝχϡʔ࡞੒ • ͦͷଞ ։ൃऀ؀ڥͷҰ෦Πϯϑϥ؅ཧ΍෦෼తͳ$$P&Λ୲͍ͳ͕Β গͣͭ͠1MBUGPSN&OHJOFFSJOHΛ࣮ફ
  4. LBHUPPMTͷ঺հ • (VBSE%VUZ4VNNBSJ[FS • (VBSE%VUZͷݕग़݁ՌΛ#FESPDLͰ෼͔Γ΍͔ͯ͘͢͠Β௨஌ • 4FDVSJUZ)VCʹू໿͞Εͨ(VBSE%VUZݕग़݁Ռʹ΋ରԠ • $PEF#VJME3VOOFS •

    ()&ͷ4FMGIPTUFE3VOOFSΛϚωʔδυͰల։ • 71$ͷ࡞੒͔Β(JU)VC"QQTܦ༝Ͱͷ઀ଓ·ͰΨΠυ෇͖Ͱ࡞੒ • /"54DIFEVMFS • /"5(BUFXBZΛ༵೔ͱ࣌ؒͰ࡞੒࡟আ͠ɺίετΛ࡟ݮ • TBNQMFTFDVSJUZIVCOPUJGJDBUJPOT • 4FDVSJUZ)VC͔Βͷ௨஌Λ4MBDL΁ૹ৴͢ΔͨΊͷ5FSSBGPSNίʔυ
  5. ྫɿ(VBSE%VUZ4VNNBSJ[FSͷߏ੒ *B$ʹ*OGSBTUSVDUVSF$PNQPTFSɺΞϓϦέʔγϣϯʹ4UFQ'VODUJPOTΛར༻ͯ͠ ϩʔίʔυ͔ͭ(6*Ͱͷࢹ֮ԽʹΑΔೝ஌ෛՙͷܰݮΛ࣮ݱ AWS Cloud GuardDuty Step Functions Bedrock SNS

    Invoke Execute EventBridge User Threats E-Mail Publish Slack Security Hub ᶃ(VBSE%VUZͷΠϕϯτΛ௚઀र͏ ᶄ4FDVSJUZ)VCʹू໿͞ΕͨΠϕϯτΛर͏ ͷͲͪΒ͔Λબ୒ͯ͠σϓϩΠՄೳ
  6. ,"(ͷ૊৫ͱ1MBUGPSN&OHJOFFSJOHతͳ՝୊ • ,"(ͷ૊৫ܗଶ • ࣄۀձࣾͱҟͳΓɺ֤Ҋ֤݅νʔϜͰγεςϜ͕ҟͳΔ • "84͚ͩͰͳ͘(PPHMF$MPVE"[VSFͷҊ݅΋ͦͦ͜͜ • ஍ਤʢཱྀߦઌʣ΍ަ௨खஈʢࣗಈंɺమಓɺඈߦػɺધʣ͕όϥόϥ 


    ˠಓ࿏͚ͩͰͳ͘ઢ࿏΍ۭ࿏ɺߤ࿏΋੔උ͠ͳ͚Ε͹ͳΒͳ͍ • ϓϥοτϑΥʔϜνʔϜͷݶք • ΧόʔͰ͖Δٕज़ྖҬ͕ݶΒΕͯ͠·͏ 
 ˠʮࢧԉͰ͖Δ΋ͷʯͱʮٻΊΒΕ͍ͯΔ΋ͷʯͷΞϯϚον • πʔϧ૿ՃʹΑΔϝϯςφϯε΍վળ͕Ͱ͖Δ࿑ྗͷෆ଍ • ಓ࿏Ҏ֎Λ։୓Ͱ͖ΔϦιʔε΍ϊ΢ϋ΢͕଍Γͳ͍ • ޮՌతʹ֤νʔϜΛࢧԉͰ͖Δ͔ͱ͍͏ෆ҆ɾɾɾ
  7. 1MBUGPSN&OHJOFFSJOHºΠϯφʔιʔεͷޮՌ • Φʔϓϯͳ؀ڥͷߏங • πʔϧ΍φϨοδΛࣾ಺શମͰڞ༗ɺ஝ੵ • ʮंྠͷ࠶ൃ໌ʯͷ๷ࢭɺαΠϩԽͷղফ • ίϥϘϨʔγϣϯจԽͷৢ੒ •

    ࣗൃతͳϑΟʔυόοΫͱίϯτϦϏϡʔγϣϯͷଅਐ • νʔϜؒɺνʔϜͱ1'&νʔϜؒͷίϛϡχέʔγϣϯڧԽ 
 ˠ֤νʔϜͷʮधཁʯΛΑΓ೺ѲͰ͖ΔΑ͏ʹͳΔ • ϓϩμΫτͱ૊৫ͷվળ • πʔϧͷ඼࣭΍։ൃੜ࢈ੑͷ޲্
  8. ,"(1MBUGPSN&OHJOFFSJOHͷ՝୊ • Πϯφʔιʔε͸ʮ1'&νʔϜͷෛ୲ܰݮʯΛҙຯ͠ͳ͍ • ϝϯςφϯεͷͨΊʹ͸֤ఏڙπʔϧΛཧղ͢Δඞཁ͕͋Δ • ։ൃνʔϜ͕ٻΊ͍ͯΔ΋ͷΛ἞ΈऔΓɺఏڙ͢Δ౒Ί͸࢒Δ • ʮࣗൃతͳࢀՃʯΛଅ͢؀ڥͮ͘Γ͕ٻΊΒΕΔ •

    πʔϧͷఏڙ΍ίϯτϦϏϡʔγϣϯ͸͋͘·Ͱળҙʢ༗ࢤʣ • ͍͔ʹଟ͘ͷϝϯόʔʹಈػ෇͚Λ༩͑ɺר͖ࠐΊΔ͔͕ॏཁ ˠҰछͷࣾ಺ίϛϡχςΟΛ1'&νʔϜ͕ӡӦ͢ΔΑ͏ͳߏਤ • ޮՌͷଌఆΛߦ͏ͨΊͷࢦඪ୳͠ • Πϯφʔιʔεͷҙٛ΍ӨڹΛఆྔతʹଌΔʢ4UBS਺ͳͲʁʣ
  9. ·ͱΊ • 1MBUGPSN&OHJOFFSJOHͷऔΓ૊ΈΛଅਐ্͍ͯ͘͠Ͱɺ 
 ΠϯφʔιʔεʹײԽ͞Εɺཱ྆ͤ͞ΔܗͰൃ଍ 
 ˠʮLBHUPPMTʯͱʮLBHJTNʯ • 1MBUGPSN&OHJOFFSJOHͱΠϯφʔιʔεͱͷ૊Έ߹ΘͤʹΑΓɺ 


    αΠϩԽͷղফ΍ंྠͷ࠶ൃ໌ͷ཈੍͕ظ଴Ͱ͖Δ • Πϯφʔιʔε׆ಈ͸1'&͕ӡӦ͢ΔίϛϡχςΟ 
 ˠଟ͘ͷਓΛר͖ࠐΈͳ͕ΒɺࣗൃతͳจԽΛৢ੒͢Δ • ઌਓͷφϨοδͱίϛϡχςΟ͔Βֶͼɺ࣮ફ͢Δʂ