Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Securing CI/CD Systems Through eBPF (recap)
Search
whywaita
PRO
November 24, 2022
Technology
1
920
Securing CI/CD Systems Through eBPF (recap)
Talked by
https://k8sjp.connpass.com/event/264501/
whywaita
PRO
November 24, 2022
Tweet
Share
More Decks by whywaita
See All by whywaita
self-hosted runnerと actions/cache の噛み合わせが悪かった件 #githubactionsmeetup
whywaita
PRO
3
2k
過去事例から見るモニタリングの大切さ #techfeed_live
whywaita
PRO
2
1.2k
バリエーションで差をつける。myshoesの新たな挑戦 #cicd_test_night
whywaita
PRO
0
5.5k
ディスクレスハイパーバイザ 〜運用しやすいクラウドのために〜
whywaita
PRO
0
150
GitHub Actions runner基盤におけるオンプレミスマルチテナントアプリケーションの運用 #CADC2022
whywaita
PRO
1
470
Development myshoes and Provide Cycloud-hosted runner -- GitHub Actions with your shoes. #cndjp
whywaita
PRO
0
45
イベント企画運営の経験と実際 / The history of organizing events by me
whywaita
PRO
0
20
作って(壊して?)学ぶインターネットのしくみ サイバーエージェントの実験用ASの紹介 / Introduce experimental AS in CyberAgent Internet Seminer
whywaita
PRO
0
87
CyberAgent における OSS の CI/CD 基盤開発 myshoes #CICD2021
whywaita
PRO
0
49
Other Decks in Technology
See All in Technology
Lambdaと地方とコミュニティ
miu_crescent
2
370
Application Development WG Intro at AppDeveloperCon
salaboy
0
180
Terraform Stacks入門 #HashiTalks
msato
0
350
20241120_JAWS_東京_ランチタイムLT#17_AWS認定全冠の先へ
tsumita
2
250
ハイパーパラメータチューニングって何をしているの
toridori_dev
0
140
複雑なState管理からの脱却
sansantech
PRO
1
140
BLADE: An Attempt to Automate Penetration Testing Using Autonomous AI Agents
bbrbbq
0
300
AWS Lambdaと歩んだ“サーバーレス”と今後 #lambda_10years
yoshidashingo
1
170
Engineer Career Talk
lycorp_recruit_jp
0
150
IBC 2024 動画技術関連レポート / IBC 2024 Report
cyberagentdevelopers
PRO
0
110
10XにおけるData Contractの導入について: Data Contract事例共有会
10xinc
6
620
TypeScript、上達の瞬間
sadnessojisan
46
13k
Featured
See All Featured
The Pragmatic Product Professional
lauravandoore
31
6.3k
Done Done
chrislema
181
16k
Java REST API Framework Comparison - PWX 2021
mraible
PRO
28
8.2k
Building Flexible Design Systems
yeseniaperezcruz
327
38k
GitHub's CSS Performance
jonrohan
1030
460k
Code Review Best Practice
trishagee
64
17k
Fontdeck: Realign not Redesign
paulrobertlloyd
82
5.2k
Principles of Awesome APIs and How to Build Them.
keavy
126
17k
Large-scale JavaScript Application Architecture
addyosmani
510
110k
Scaling GitHub
holman
458
140k
Building Better People: How to give real-time feedback that sticks.
wjessup
364
19k
Exploring the Power of Turbo Streams & Action Cable | RailsConf2023
kevinliebholz
27
4.3k
Transcript
4FDVSJOH$*$%4ZTUFNT 5ISPVHIF#1' ,VCFSOFUFT.FFUVQ5PLZP ,VCF$PO/"3FDBQ $ZCFS"HFOU *ODத ݐొ XIZXBJUB
த ݐొ XIZXBJUB $MPVE.BLFSBU$ZCFS"HFOU *OD ϓϥΠϕʔτΫϥυ *BB4
ϚωʔδυαʔϏε։ൃ TFMGIPTUFESVOOFSJO(JU)VC"DUJPOT XIZXBJUBNZTIPFT044EFWFMPQFS झຯࣗαʔό ,T!IPNF ϙʔΧʔ ,VCF$POॳࢀઓ ॳւ֎ ೖࠃΠϯλϏϡʔͰҰഊ 5IBOLZPVBNTZ😭
4FDVSJOH$*$%4ZTUFNT5ISPVHIF#1'
4FDVSJOH$*$%4ZTUFNT5ISPVHIF#1' • CZ"MFY*MHBZFW $ZDPEF ◦ IUUQTDZDPEFDPN • IUUQTTDIFEDP"V[ • IUUQTXXXZPVUVCFDPNXBUDI
WQD#(3'W4SW : • $*$%ΛηΩϡΞʹߦ͏ͨΊʹF#1'Λར༻͢ΔࢼΈ
• &YUFOEFE#FSLFMFZ1BDLFU'JMUFS • -JOVY,FSOFMͷ4BOECPYͰίʔυΛ࣮ߦ͢Δ ◦ ϦίϯύΠϧෆཁ Ͱ ҆શ ͔ͭ ߴ
• /FUXPSL 0CTFSWBCJMJUZͷར༻ࣄྫ͕ଟΊ ◦ ,VCFSOFUFT$/* .POJUPSJOH"HFOU લఏࣝF#1'
• &YUFOEFE#FSLFMFZ1BDLFU'JMUFS • -JOVY,FSOFMͷ4BOECPYͰίʔυΛ࣮ߦ͢Δ ◦ ϦίϯύΠϧෆཁ Ͱ ҆શ ͔ͭ ߴ
• /FUXPSL 0CTFSWBCJMJUZͷར༻ࣄྫ͕ଟΊ ◦ ,VCFSOFUFT$/*$JMJVN ◦ .POJUPSJOH"HFOUEBUBEPHBHFOU FCQG@FYQPSUFS લఏࣝF#1'
IUUQTUXJUUFSDPNHSBGBOBTUBUVT લఏࣝF#1'
IUUQTHSBGBOBDPNCMPHHSBGBOBBOEDJMJVNEFFQFCQGQPXFSFEPCTFSWBCJMJUZGPSLVCFSOFUFTBOEDMPVE OBUJWFJOGSBTUSVDUVSF લఏࣝF#1'
ຊ
4FDVSJOH$*$%4ZTUFNT5ISPVHIF#1' • $*$%ʹ͓͚ΔηΩϡϦςΟࣄҊ ◦ 4PMBS8JOETॺ໊͖ϑΝΠϧͷॻ ◦ $PEF$PWCBTIJOTUBMMFSͷॻ ◦ /1. 1Z1*αϓϥΠνΣʔϯΞλοΫ
• $*$%πʔϧ ͷηΩϡϦςΟରࡦ͍͠ ◦ ڧݖݶ شൃ͢Δڥ Մ؍ଌੑ
4FDVSJOH$*$%4ZTUFNT5ISPVHIF#1' • ఏҊ$*$%F#1'ϕʔεͳ"HFOUͷಋೖ • XIZF#1' ◦ ؆୯ʹՄ؍ଌੑͱηΩϡϦςΟχʔζΛߴΊΒΕΔ ◦ ࠷৽ΧʔωϧͰಈ࡞͢Δ ◦
ڧྗͳίϛϡχςΟͱπʔϧ • $JMJVN5FUSBHPOͷ࠾༻
• F#1'CBTFE 4FDVSJUZ0CTFSWBCJMJUZ ηΩϡϦςΟͷՄ؍ଌੑ BOE 3VOUJNF&OGPSDFNFOU ϦΞϧλΠϜ࣮ߦ੍ޚ • ੨ࢁ͞ΜʹΑΔຊޠهࣄ $JMJVN1SPKFDU͔Βެ։ʂ
F#1'Λ༻͍ͯηΩϡϦςΟͷՄ؍ଌੑΛͨΒ͢5FUSBHPOcHJIZPKQ $JMJVN5FUSBHPO IUUQTHJUIVCDPNDJMJVNUFUSBHPO ͔Θ͍͍ˠ
$JMJVN5FUSBHPO
4FDVSJOH$*$%4ZTUFNT5ISPVHIF#1' • $*$%γεςϜʹ$JMJVN5FUSBHPOΛಋೖ ◦ $*$%γεςϜʹ͓͚Δzಈ࡞Λ؍ଌ͢Δ ◦ ϓϩηε ίωΫγϣϯ ϑΝΠϧ *0ใ
• 5FUSBHPO࠾༻ཧ༝ ◦ LQSPCFΛ࢝Ίͱͯ͠ଟ͘ͷσʔλ͕औಘՄೳ ◦ LTҎ֎ͷڥͰಈ࡞͢Δ
4FDVSJOH$*$%4ZTUFNT5ISPVHIF#1'
1P$ͷ࣮༰ʹ͍ͭͯ • Ϗϧυڥͷ0CTFSWBMJCJUZ ◦ ϓϩηε ଓઌυϝΠϯ *1 • ιʔείʔυͷશੑ֬อ ◦
HPϑΝΠϧͷॻΛࢹ • ௨৴ઌͷ੍ޚ ◦ ڐՄͯ͠ͳ͍*1υϝΠϯͷଓՄ൱ • (JU)VC"DUJPOT্Ͱಈ࡞͢ΔΑ͏ߏஙࡁ
1P$ͷ࣮༰ʹ͍ͭͯ
4FDVSJOH$*$%4ZTUFNT5ISPVHIF#1' HJUDMPOF࣌ͷ HJUIVCDPNͷଓ UDQ@DPOOFDU ΛUSBDJOH͢Δ͜ͱͰ؍ଌޭ
4FDVSJOH$*$%4ZTUFNT5ISPVHIF#1' TFUVQHPͰ࣮ߦ͞Ε͍ͯΔ ϓϩηεใͷ؍ଌޭ
4FDVSJOH$*$%4ZTUFNT5ISPVHIF#1' • σϞ ◦ Ϗϧυதͷ HPϑΝΠϧͷॻ 4*(,*-- ◦ ڐՄ͍ͯ͠ͳ͍*1ͷ௨৴ 4*(,*--
◦ ڐՄ͍ͯ͠ͳ͍ϓϩηεͷੜ 4*(,*--
4FDVSJOH$*$%4ZTUFNT5ISPVHIF#1' • σϞ ◦ Ϗϧυதͷ HPϑΝΠϧͷॻ 4*(,*-- ◦ ڐՄ͍ͯ͠ͳ͍*1ͷ௨৴ 4*(,*--
◦ ڐՄ͍ͯ͠ͳ͍ϓϩηεͷੜ 4*(,*--
4FDVSJOH$*$%4ZTUFNT5ISPVHIF#1'
4FDVSJOH$*$%4ZTUFNT5ISPVHIF#1' • σϞ ◦ Ϗϧυதͷ HPϑΝΠϧͷॻ 4*(,*-- ◦ ڐՄ͍ͯ͠ͳ͍*1ͷ௨৴ 4*(,*--
◦ ڐՄ͍ͯ͠ͳ͍ϓϩηεͷੜ 4*(,*--
4FDVSJOH$*$%4ZTUFNT5ISPVHIF#1' (JU)VC"DUJPOT্ͷઃఆϑΝΠϧ͔Β $JMJVN5FUSBHPOͷઃఆΛੜ
·ͱΊ • F#1' $JMJVN5FUSBHPOύϫϑϧͳςΫϊϩδʔ • $*$%F#1'ʹΑͬͯ͞ΒʹηΩϡΞʹͳΔ • ࠓޙ1P$Ͱͬͨ"HFOUΛ044Խ༧ఆ ◦ ͞Εͯ·ͨ͠
IUUQTHJUIVCDPN$ZDPEF-BCTFCQGBHFOUBDUJPO • $POUSJCVUFͬͯΔΑʂ
ײ • 5FUSBHPOͷڧྗ͞Λेೋʹ׆͔͢ൃද ◦ 0CTFSWBCJMJUZ 3VOUJNF&OGPSDFNFOU ◦ ϕετϑΟοτ • ʮؾΛ͚ͭΔʯҎ্ͷ͜ͱ͕ग़དྷΔΑ͏ʹ
◦ $*$%ͷΑ͏ʹʮॏཁ͚ͩͲׂ͕͔Εʹ͍͘ʯ ಛʹ͜ͷΑ͏ͳऔΓΈ͕ඞཁʹͳΓͦ͏
αΠόʔΤʔδΣϯτͰͷऔΓΈ ϓϥΠϕʔτΫϥυͰͷ(JU)VC"DUJPOTج൫Λ ։ൃɾӡ༻த IUUQTXXXTMJEFTIBSFOFUXIZXBJUBEFWFMPQNFOUNZTIPFTBOEQSPWJEFDZDMPVEIPTUFESVOOFSHJUIVCBDUJPOT XJUIZPVSTIPFT
αΠόʔΤʔδΣϯτͰͷऔΓΈ IUUQTXXXTMJEFTIBSFOFUXIZXBJUBEFWFMPQNFOUNZTIPFTBOEQSPWJEFDZDMPVEIPTUFESVOOFSHJUIVCBDUJPOT XJUIZPVSTIPFT ಈతͳTFMGIPTUFESVOOFS XIZXBJUBNZTIPFT
4FDVSJOH$*$%4ZTUFNT5ISPVHIF#1'
αΠόʔΤʔδΣϯτͰͷऔΓΈ IUUQTXXXTMJEFTIBSFOFUXIZXBJUBEFWFMPQNFOUNZTIPFTBOEQSPWJEFDZDMPVEIPTUFESVOOFSHJUIVCBDUJPOT XJUIZPVSTIPFT ಈతͳ TFMGIPTUFESVOOFS XIZXBJUBNZTIPFT .BOBHFE 1P$"HFOU4FSWFS
Q?