33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

ื”ืขืจื”. ืชืจื’ื•ื: ืื ืืชื” ืชื•ื”ื” ืœื’ื‘ื™ ื‘ืขื™ื•ืช ืื‘ื˜ื—ื” ื‘ืชืฉืชื™ืช ืžื‘ื•ืกืกืช Kubernetes, ืกืงื™ืจื” ืžืฆื•ื™ื ืช ื–ื• ืฉืœ Sysdig ื”ื™ื ื ืงื•ื“ืช ื”ืชื—ืœื” ืžืฆื•ื™ื ืช ืœื”ื™ื›ืจื•ืช ืžื”ื™ืจื” ืขื ื”ืคืชืจื•ื ื•ืช ื”ืจืœื•ื•ื ื˜ื™ื™ื ื”ื™ื•ื. ื”ื•ื ื›ื•ืœืœ ื’ื ืžืขืจื›ื•ืช ืžื•ืจื›ื‘ื•ืช ืฉืœ ืฉื—ืงื ื™ื ืžื•ื›ืจื™ื ื‘ืฉื•ืง, ื•ื’ื ื›ืœื™ ืขื–ืจ ื”ืจื‘ื” ื™ื•ืชืจ ืฆื ื•ืขื™ื ืฉืžื›ืกื™ื ื‘ืขื™ื” ืžืกื•ื™ืžืช. ื•ื‘ืชื’ื•ื‘ื•ืช, ืื ื—ื ื•, ื›ืžื• ืชืžื™ื“, ื ืฉืžื— ืœืœืžื•ื“ ืขืœ ื”ื ื™ืกื™ื•ืŸ ืฉืœื›ื ื‘ืฉื™ืžื•ืฉ ื‘ื›ืœื™ื ืืœื• ื•ืœืจืื•ืช ืงื™ืฉื•ืจื™ื ืœืคืจื•ื™ืงื˜ื™ื ื ื•ืกืคื™ื.

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes
ืžื•ืฆืจื™ ืชื•ื›ื ืช ื”ืื‘ื˜ื—ื” ืฉืœ Kubernetes... ื™ืฉ ื›ืœ ื›ืš ื”ืจื‘ื”, ื•ืœื›ืœ ืื—ื“ ื™ืฉ ืžื˜ืจื”, ื”ื™ืงืฃ ื•ืจื™ืฉื™ื•ื ื•ืช ืžืฉืœื•.

ืœื›ืŸ ื”ื—ืœื˜ื ื• ืœื™ืฆื•ืจ ืืช ื”ืจืฉื™ืžื” ื”ื–ื• ื•ื›ืœืœื ื• ื’ื ืคืจื•ื™ืงื˜ื™ ืงื•ื“ ืคืชื•ื— ื•ื’ื ืคืœื˜ืคื•ืจืžื•ืช ืžืกื—ืจื™ื•ืช ืฉืœ ืกืคืงื™ื ืฉื•ื ื™ื. ืื ื• ืžืงื•ื•ื™ื ืฉื–ื” ื™ืขื–ื•ืจ ืœืš ืœื‘ื—ื•ืจ ืืช ืืœื” ื”ืžืขื ื™ื™ื ื™ื ื‘ื™ื•ืชืจ ื•ืœื›ื•ื•ืŸ ืื•ืชืš ื‘ื›ื™ื•ื•ืŸ ื”ื ื›ื•ืŸ ื‘ื”ืชื‘ืกืก ืขืœ ืฆืจื›ื™ ื”ืื‘ื˜ื—ื” ื”ืกืคืฆื™ืคื™ื™ื ืฉืœืš ืฉืœ Kubernetes.

ืงื˜ื’ื•ืจื™ื•ืช

ื›ื“ื™ ืœื”ืงืœ ืขืœ ื”ื ื™ื•ื•ื˜ ื‘ืจืฉื™ืžื”, ื”ื›ืœื™ื ืžืกื•ื•ื’ื™ื ืœืคื™ ืคื•ื ืงืฆื™ื” ื•ื™ื™ืฉื•ื ืขื™ืงืจื™ื™ื. ื”ืกืขื™ืคื™ื ื”ืžืชืงื‘ืœื™ื ื”ื:

  • ืกืจื™ืงืช ืชืžื•ื ื•ืช ื•ื ื™ืชื•ื— ืกื˜ื˜ื™ ืฉืœ Kubernetes;
  • ืื‘ื˜ื—ืช ื–ืžืŸ ืจื™ืฆื”;
  • ืื‘ื˜ื—ืช ืจืฉืช Kubernetes;
  • ื”ืคืฆืช ืชืžื•ื ื•ืช ื•ื ื™ื”ื•ืœ ืกื•ื“ื•ืช;
  • ื‘ื™ืงื•ืจืช ืื‘ื˜ื—ื” Kubernetes;
  • ืžื•ืฆืจื™ื ืžืกื—ืจื™ื™ื ืžื•ืจื›ื‘ื™ื.

ื‘ื•ื ื ื™ื’ืฉ ืœืขื ื™ื™ืŸ:

ืกืจื™ืงืช ืชืžื•ื ื•ืช Kubernetes

ืขื•ื’ืŸ

  • ืืชืจ ืื™ื ื˜ืจื ื˜: anchore.com
  • ืจื™ืฉื™ื•ืŸ: ื—ื™ื ื (Apache) ื•ื”ืฆืขื” ืžืกื—ืจื™ืช

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

ื—ื‘ื™ืœืช Anchore ืžื ืชื—ืช ืชืžื•ื ื•ืช ืžื™ื›ืœ ื•ืžืืคืฉืจืช ื‘ื“ื™ืงื•ืช ืื‘ื˜ื—ื” ืขืœ ืกืžืš ืžื“ื™ื ื™ื•ืช ืžื•ื’ื“ืจืช ืขืœ ื™ื“ื™ ื”ืžืฉืชืžืฉ.

ื‘ื ื•ืกืฃ ืœืกืจื™ืงื” ื”ืจื’ื™ืœื” ืฉืœ ืชืžื•ื ื•ืช ืงื•ื ื˜ื™ื™ื ืจ ืœืื™ืชื•ืจ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื™ื“ื•ืขื•ืช ืžืžืกื“ ื”ื ืชื•ื ื™ื ืฉืœ CVE, Anchore ืžื‘ืฆืขืช ื‘ื“ื™ืงื•ืช ื ื•ืกืคื•ืช ืจื‘ื•ืช ื›ื—ืœืง ืžืžื“ื™ื ื™ื•ืช ื”ืกืจื™ืงื”: ื‘ื“ื™ืงืช Dockerfile, ืื™ืฉื•ืจื™ ื“ืœื™ืคื”, ื—ื‘ื™ืœื•ืช ืฉืœ ืฉืคื•ืช ืชื›ื ื•ืช ื‘ื”ืŸ ื ืขืฉื” ืฉื™ืžื•ืฉ (npm, maven ื•ื›ื•'). , ืจื™ืฉื™ื•ื ื•ืช ืชื•ื›ื ื” ื•ืขื•ื“ ื•ืขื•ื“.

Clair

  • ืืชืจ ืื™ื ื˜ืจื ื˜: coreos.com/clair (ืขื›ืฉื™ื• ื‘ื”ื“ืจื›ืช ืจื“ ื”ืื˜)
  • ืจื™ืฉื™ื•ืŸ: ื—ื™ื ื (Apache)

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

ืงืœื™ื™ืจ ื”ื™ื” ืื—ื“ ืžืคืจื•ื™ืงื˜ื™ ื”ืงื•ื“ ื”ืคืชื•ื— ื”ืจืืฉื•ื ื™ื ืœืกืจื™ืงืช ืชืžื•ื ื•ืช. ื–ื” ื™ื“ื•ืข ื›ืกื•ืจืง ื”ืื‘ื˜ื—ื” ืžืื—ื•ืจื™ ืจื™ืฉื•ื ื”ืชืžื•ื ื•ืช ืฉืœ Quay. (ื’ื ืž-CoreOS - ืžืฉื•ืขืจ. ืชืจื’ื•ื). ืงืœื™ื™ืจ ืžืกื•ื’ืœืช ืœืืกื•ืฃ ืžื™ื“ืข ืขืœ CVEs ืžืžื’ื•ื•ืŸ ืจื—ื‘ ืฉืœ ืžืงื•ืจื•ืช, ื›ื•ืœืœ ืจืฉื™ืžื•ืช ืฉืœ ืคื’ื™ืขื•ื™ื•ืช ืกืคืฆื™ืคื™ื•ืช ืœื”ืคืฆื” ืฉืœ ืœื™ื ื•ืงืก ื”ืžืชื•ื—ื–ืงื•ืช ืขืœ ื™ื“ื™ ืฆื•ื•ืชื™ ื”ืื‘ื˜ื—ื” ืฉืœ Debian, Red Hat ืื• Ubuntu.

ื‘ื ื™ื’ื•ื“ ืœืืื ืงื•ืจ, ืงืœื™ื™ืจ ืžืชืžืงื“ืช ื‘ืขื™ืงืจ ื‘ืื™ืชื•ืจ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื•ื”ืชืืžืช ื ืชื•ื ื™ื ืœ-CVE. ืขื ื–ืืช, ื”ืžื•ืฆืจ ืื›ืŸ ืžืฆื™ืข ืœืžืฉืชืžืฉื™ื ื›ืžื” ืืคืฉืจื•ื™ื•ืช ืœื”ืจื—ื‘ืช ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ื‘ืืžืฆืขื•ืช ืžื ื”ืœื™ ื”ืชืงื ื™ื ืฉืœ ืคืœืื’ื™ืŸ.

ื“ื’ื“ื”

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Dagda ืžื ืชื—ืช ื‘ืื•ืคืŸ ืกื˜ื˜ื™ ืชืžื•ื ื•ืช ืžื™ื›ืœ ืขื‘ื•ืจ ืคื’ื™ืขื•ื™ื•ืช ื™ื“ื•ืขื•ืช, ืกื•ืกื™ื ื˜ืจื•ื™ืื ื™ื™ื, ื•ื™ืจื•ืกื™ื, ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ื•ืื™ื•ืžื™ื ืื—ืจื™ื.

ื—ื‘ื™ืœืช Dagda ืฉื•ื ื” ืžื›ืœื™ื ื“ื•ืžื™ื ืื—ืจื™ื ื‘ืฉืชื™ ื“ืจื›ื™ื ื‘ื•ืœื˜ื•ืช:

  • ื–ื” ืžืฉืชืœื‘ ื”ื™ื˜ื‘ ืขื ClamAV, ื”ืคื•ืขืœ ืœื ืจืง ื›ื›ืœื™ ืœืกืจื™ืงืช ืชืžื•ื ื•ืช ืžื™ื›ืœ, ืืœื ื’ื ื›ืื ื˜ื™ ื•ื™ืจื•ืก.
  • ืžืกืคืง ื’ื ื”ื’ื ื” ื‘ื–ืžืŸ ืจื™ืฆื” ืขืœ ื™ื“ื™ ืงื‘ืœืช ืื™ืจื•ืขื™ื ื‘ื–ืžืŸ ืืžืช ืžื”ื“ืžื•ืŸ Docker ื•ืฉื™ืœื•ื‘ ืขื Falco (ืจืื” ืœืžื˜ื”) ื›ื“ื™ ืœืืกื•ืฃ ืื™ืจื•ืขื™ ืื‘ื˜ื—ื” ื‘ื–ืžืŸ ืฉื”ืžื›ื•ืœื” ืคื•ืขืœืช.

KubeXray

  • ืืชืจ ืื™ื ื˜ืจื ื˜: github.com/jfrog/kubexray
  • ืจื™ืฉื™ื•ืŸ: ื—ื™ื ื (Apache), ืืš ื“ื•ืจืฉ ื ืชื•ื ื™ื ืž-JFrog Xray (ืžื•ืฆืจ ืžืกื—ืจื™)

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

KubeXray ืžืื–ื™ืŸ ืœืื™ืจื•ืขื™ื ืžืฉืจืช Kubernetes API ื•ืžืฉืชืžืฉ ื‘ืžื˜ื ื ืชื•ื ื™ื ืž-JFrog Xray ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืฉืจืง ืคื•ื“ื™ื ืฉืชื•ืืžื™ื ืœืžื“ื™ื ื™ื•ืช ื”ื ื•ื›ื—ื™ืช ื™ืชื—ื™ืœื•.

KubeXray ืœื ืจืง ื‘ื•ื“ืง ืงื•ื ื˜ื™ื™ื ืจื™ื ื—ื“ืฉื™ื ืื• ืžืขื•ื“ื›ื ื™ื ื‘ืคืจื™ืกื•ืช (ื‘ื“ื•ืžื” ืœื‘ืงืจ ื”ืงื‘ืœื” ื‘-Kubernetes), ืืœื ื’ื ื‘ื•ื“ืง ื‘ืื•ืคืŸ ื“ื™ื ืžื™ ืงื•ื ื˜ื™ื™ื ืจื™ื ืคื•ืขืœื™ื ืœื’ื‘ื™ ืชืื™ืžื•ืช ืœืžื“ื™ื ื™ื•ืช ืื‘ื˜ื—ื” ื—ื“ืฉื”, ื•ืžืกื™ืจ ืžืฉืื‘ื™ื ื”ืžืชื™ื™ื—ืกื™ื ืœืชืžื•ื ื•ืช ืคื’ื™ืขื•ืช.

ืกื ื™ืง

  • ืืชืจ ืื™ื ื˜ืจื ื˜: snyk.io
  • ืจื™ืฉื™ื•ืŸ: ื’ืจืกืื•ืช ื—ื™ื ื (Apache) ื•ืžืกื—ืจื™ื•ืช

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Snyk ื”ื•ื ืกื•ืจืง ืคื’ื™ืขื•ืช ื™ื•ืฆื ื“ื•ืคืŸ ื‘ืžื•ื‘ืŸ ื–ื” ืฉื”ื•ื ืžื›ื•ื•ืŸ ืกืคืฆื™ืคื™ืช ืœืชื”ืœื™ืš ื”ืคื™ืชื•ื— ื•ืžืงื•ื“ื ื›"ืคืชืจื•ืŸ ื—ื™ื•ื ื™" ืœืžืคืชื—ื™ื.

Snyk ืžืชื—ื‘ืจ ื™ืฉื™ืจื•ืช ืœืžืื’ืจื™ ืงื•ื“, ืžื ืชื— ืืช ื”ืžื ื™ืคืกื˜ ืฉืœ ื”ืคืจื•ื™ืงื˜ ื•ืžื ืชื— ืงื•ื“ ืžื™ื•ื‘ื ื™ื—ื“ ืขื ืชืœื•ืช ื™ืฉื™ืจื” ื•ืขืงื™ืคื”. Snyk ืชื•ืžืš ื‘ืฉืคื•ืช ืชื›ื ื•ืช ืคื•ืคื•ืœืจื™ื•ืช ืจื‘ื•ืช ื•ื™ื›ื•ืœ ืœื–ื”ื•ืช ืกื™ื›ื•ื ื™ ืจื™ืฉื•ื™ ื ืกืชืจื™ื.

ื˜ืจื™ื•ื•ื™

  • ืืชืจ ืื™ื ื˜ืจื ื˜: github.com/knqyf263/trivy
  • ืจื™ืฉื™ื•ืŸ: ื—ื™ื ื (AGPL)

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Trivy ื”ื•ื ืกื•ืจืง ืคื’ื™ืขื•ืช ืžื™ื›ืœ ืคืฉื•ื˜ ืืš ืจื‘ ืขื•ืฆืžื” ื”ืžืฉืชืœื‘ ื‘ืงืœื•ืช ื‘ืฆื™ื ื•ืจ CI/CD. ื”ืชื›ื•ื ื” ื”ืžื“ื”ื™ืžื” ืฉืœื• ื”ื™ื ืงืœื•ืช ื”ื”ืชืงื ื” ื•ื”ืชืคืขื•ืœ: ื”ืืคืœื™ืงืฆื™ื” ืžื•ืจื›ื‘ืช ืžืงื•ื‘ืฅ ื‘ื™ื ืืจื™ ืื—ื“ ื•ืื™ื ื” ื“ื•ืจืฉืช ื”ืชืงื ื” ืฉืœ ืžืกื“ ื ืชื•ื ื™ื ืื• ืกืคืจื™ื•ืช ื ื•ืกืคื•ืช.

ื”ื—ื™ืกืจื•ืŸ ืฉืœ ื”ืคืฉื˜ื•ืช ืฉืœ Trivy ื”ื•ื ืฉืืชื” ืฆืจื™ืš ืœื”ื‘ื™ืŸ ืื™ืš ืœื ืชื— ื•ืœืฉืœื•ื— ืชื•ืฆืื•ืช JSON ื›ื“ื™ ืฉื›ืœื™ ืื‘ื˜ื—ื” ืื—ืจื™ื ืฉืœ Kubernetes ื™ื•ื›ืœื• ืœื”ืฉืชืžืฉ ื‘ื”ื.

ืื‘ื˜ื—ืช ื–ืžืŸ ืจื™ืฆื” ื‘-Kubernetes

ืคืืœืงื•

  • ืืชืจ ืื™ื ื˜ืจื ื˜: falco.org
  • ืจื™ืฉื™ื•ืŸ: ื—ื™ื ื (Apache)

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Falco ื”ื™ื ื—ื‘ื™ืœืช ื›ืœื™ื ืœืื‘ื˜ื—ืช ื–ืžื ื™ ืจื™ืฆื” ื‘ืขื ืŸ. ื—ืœืง ืžืžืฉืคื—ืช ืคืจื•ื™ืงื˜ื™ื CNCF.

ื‘ืืžืฆืขื•ืช ืขืจื›ืช ื”ื›ืœื™ื ืฉืœ Sysdig ืœืขื‘ื•ื“ื” ื‘ืจืžืช ืœื™ื‘ืช ืœื™ื ื•ืงืก ื•ื™ืฆื™ืจืช ืคืจื•ืคื™ืœ ืงืจื™ืื•ืช ืœืžืขืจื›ืช, Falco ืžืืคืฉืจืช ืœืš ืœืฆืœื•ืœ ืขืžื•ืง ืœืชื•ืš ื”ืชื ื”ื’ื•ืช ื”ืžืขืจื›ืช. ืžื ื•ืข ื—ื•ืงื™ ื–ืžืŸ ื”ืจื™ืฆื” ืฉืœื• ืžืกื•ื’ืœ ืœื–ื”ื•ืช ืคืขื™ืœื•ืช ื—ืฉื•ื“ื” ื‘ืืคืœื™ืงืฆื™ื•ืช, ืงื•ื ื˜ื™ื™ื ืจื™ื, ื”ืžืืจื— ื”ื‘ืกื™ืกื™ ื•ื‘ืžืชื–ืžืจ Kubernetes.

Falco ืžืกืคืงืช ืฉืงื™ืคื•ืช ืžืœืื” ื‘ืชืคืขื•ืœ ื‘ื–ืžืŸ ืจื™ืฆื” ื•ื‘ื–ื™ื”ื•ื™ ืื™ื•ืžื™ื ืขืœ ื™ื“ื™ ื”ื’ื“ืจืช ืกื•ื›ื ื™ื ืžื™ื•ื—ื“ื™ื ื‘ืฆืžืชื™ Kubernetes ืœืžื˜ืจื” ื–ื•. ื›ืชื•ืฆืื” ืžื›ืš, ืื™ืŸ ืฆื•ืจืš ืœืฉื ื•ืช ืžื›ื•ืœื•ืช ืขืœ ื™ื“ื™ ื”ื–ืจืงืช ืงื•ื“ ืฉืœ ืฆื“ ืฉืœื™ืฉื™ ืœืชื•ื›ื ืื• ืชืœื™ื™ืช ืžื›ื•ืœื•ืช ืฆื“ื“ื™ื•ืช.

ืžืกื’ืจื•ืช ืื‘ื˜ื—ื” ืฉืœ ืœื™ื ื•ืงืก ืœื–ืžืŸ ืจื™ืฆื”

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

ืžืกื’ืจื•ืช ืืœื•, ืžืงื•ืจื™ื•ืช ืœืœื™ื‘ื” ืฉืœ ืœื™ื ื•ืงืก, ืื™ื ืŸ "ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes" ื‘ืžื•ื‘ืŸ ื”ืจื’ื™ืœ, ืืš ืจืื•ื™ื•ืช ืœืฆื™ื•ืŸ ื›ื™ ื”ืŸ ืžื”ื•ื•ืช ืžืจื›ื™ื‘ ื—ืฉื•ื‘ ื‘ื”ืงืฉืจ ืฉืœ ืื‘ื˜ื—ืช ื–ืžืŸ ืจื™ืฆื”, ื”ื›ืœื•ืœื” ื‘ืžื“ื™ื ื™ื•ืช ื”ืื‘ื˜ื—ื” ืฉืœ Kubernetes Pod Security (PSP). .

AppArmor ืžืฆืจืฃ ืคืจื•ืคื™ืœ ืื‘ื˜ื—ื” ืœืชื”ืœื™ื›ื™ื ื”ืคื•ืขืœื™ื ื‘ืงื•ื ื˜ื™ื™ื ืจ, ื”ื’ื“ืจืช ื”ืจืฉืื•ืช ืžืขืจื›ืช ืงื‘ืฆื™ื, ื›ืœืœื™ ื’ื™ืฉื” ืœืจืฉืช, ืงื™ืฉื•ืจ ืกืคืจื™ื•ืช ื•ื›ื•'. ื–ื•ื”ื™ ืžืขืจื›ืช ืžื‘ื•ืกืกืช ื‘ืงืจืช ื’ื™ืฉื” ื—ื•ื‘ื” (MAC). ื‘ืžื™ืœื™ื ืื—ืจื•ืช, ื”ื™ื ืžื•ื ืขืช ื‘ื™ืฆื•ืข ืคืขื•ืœื•ืช ืืกื•ืจื•ืช.

ืœื™ื ื•ืงืก ืžืฉื•ืคืจืช ื‘ืื‘ื˜ื—ื” (SELinux) ื”ื•ื ืžื•ื“ื•ืœ ืื‘ื˜ื—ื” ืžืชืงื“ื ื‘ืœื™ื‘ืช ื”ืœื™ื ื•ืงืก, ื“ื•ืžื” ื‘ืžื•ื‘ื ื™ื ืžืกื•ื™ืžื™ื ืœ-AppArmor ื•ืœืขืชื™ื ืงืจื•ื‘ื•ืช ื‘ื”ืฉื•ื•ืื” ืืœื™ื•. SELinux ืขื•ืœื” ืขืœ AppArmor ืžื‘ื—ื™ื ืช ื›ื•ื—, ื’ืžื™ืฉื•ืช ื•ืขื“ื™ื ื•ืช. ื”ื—ืกืจื•ื ื•ืช ืฉืœื• ื”ื ืคื™ืชื•ื— ืืจื•ืš ื•ืžื•ืจื›ื‘ื•ืช ืžื•ื’ื‘ืจืช.

Secomp ื•-seccomp-bpf ืžืืคืฉืจื™ื ืœืš ืœืกื ืŸ ืงืจื™ืื•ืช ืžืขืจื›ืช, ืœื—ืกื•ื ืืช ื”ื‘ื™ืฆื•ืข ืฉืœ ืืœื” ืฉืขืœื•ืœื•ืช ืœื”ื™ื•ืช ืžืกื•ื›ื ื•ืช ืขื‘ื•ืจ ืžืขืจื›ืช ื”ื”ืคืขืœื” ื”ื‘ืกื™ืกื™ืช ื•ืื™ื ืŸ ื ื—ื•ืฆื•ืช ืœืคืขื•ืœื” ืจื’ื™ืœื” ืฉืœ ื™ื™ืฉื•ืžื™ ืžืฉืชืžืฉ. Secomp ื“ื•ืžื” ืœ-Falco ื‘ืžื•ื‘ื ื™ื ืžืกื•ื™ืžื™ื, ืื ื›ื™ ื”ื™ื ืœื ื™ื•ื“ืขืช ืืช ื”ืคืจื˜ื™ื ืฉืœ ืžื›ื•ืœื•ืช.

ืงื•ื“ ืคืชื•ื— ืฉืœ Sysdig

  • ืืชืจ ืื™ื ื˜ืจื ื˜: www.sysdig.com/opensource
  • ืจื™ืฉื™ื•ืŸ: ื—ื™ื ื (Apache)

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Sysdig ื”ื•ื ื›ืœื™ ืฉืœื ืœื ื™ืชื•ื—, ืื‘ื—ื•ืŸ ื•ื ื™ืคื•ื™ ื‘ืื’ื™ื ืฉืœ ืžืขืจื›ื•ืช ืœื™ื ื•ืงืก (ืขื•ื‘ื“ ื’ื ืขืœ Windows ื•-macOS, ืืš ืขื ืชื›ื•ื ื•ืช ืžื•ื’ื‘ืœื•ืช). ื–ื” ื™ื›ื•ืœ ืœืฉืžืฉ ืœืื™ืกื•ืฃ ืžื™ื“ืข ืžืคื•ืจื˜, ืื™ืžื•ืช ื•ื–ื™ื”ื•ื™ ืคืœื™ืœื™ (ื–ื™ื”ื•ื™ ืคืœื™ืœื™) ืžืขืจื›ืช ื”ื‘ืกื™ืก ื•ื›ืœ ืžื™ื›ืœื™ื ื”ืคื•ืขืœื™ื ืขืœื™ื”.

Sysdig ื’ื ืชื•ืžืš ื‘ืื•ืคืŸ ืžืงื•ืจื™ ื‘ืงื•ื‘ืฆื™ ื”ืคืขืœื” ื•ืžื˜ื ื ืชื•ื ื™ื ืฉืœ Kubernetes, ื•ืžื•ืกื™ืฃ ืžื™ืžื“ื™ื ื•ืชื•ื•ื™ื•ืช ื ื•ืกืคื•ืช ืœื›ืœ ืžื™ื“ืข ื”ืชื ื”ื’ื•ืช ื”ืžืขืจื›ืช ืฉื ืืกืฃ. ื™ืฉื ืŸ ืžืกืคืจ ื“ืจื›ื™ื ืœื ืชื— ืืฉื›ื•ืœ Kubernetes ื‘ืืžืฆืขื•ืช Sysdig: ืืชื” ื™ื›ื•ืœ ืœืœื›ื•ื“ ื ืงื•ื“ืช ื–ืžืŸ ื‘ืืžืฆืขื•ืช ืœื›ื™ื“ืช kubectl ืื• ืœื”ืคืขื™ืœ ืžืžืฉืง ืื™ื ื˜ืจืืงื˜ื™ื‘ื™ ื”ืžื‘ื•ืกืก ืขืœ ncurses ื‘ืืžืฆืขื•ืช ื”ืชื•ืกืฃ kubectl ืœื—ืคื•ืจ.

ืื‘ื˜ื—ืช ืจืฉืช Kubernetes

ืืคื•ืจื˜ื•

  • ืืชืจ ืื™ื ื˜ืจื ื˜: www.aporeto.com
  • ืจื™ืฉื™ื•ืŸ: ืžืกื—ืจื™

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Aporeto ืžืฆื™ืขื” "ืื‘ื˜ื—ื” ืžื•ืคืจื“ืช ืžืจืฉืช ื•ืชืฉืชื™ืช". ืžืฉืžืขื•ืช ื”ื“ื‘ืจ ื”ื™ื ืฉืฉื™ืจื•ืชื™ Kubernetes ืœื ืจืง ืžืงื‘ืœื™ื ืžื–ื”ื” ืžืงื•ืžื™ (ื›ืœื•ืžืจ, ServiceAccount ื‘- Kubernetes), ืืœื ื’ื ืžื–ื”ื” ืื•ื ื™ื‘ืจืกืœื™/ื˜ื‘ื™ืขืช ืืฆื‘ืข ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”ื ืœืื™ื ื˜ืจืืงืฆื™ื” ืžืื•ื‘ื˜ื—ืช ื•ืžืื•ืžืชืช ื”ื“ื“ื™ืช ืขื ื›ืœ ืฉื™ืจื•ืช ืื—ืจ, ื›ืžื• ื‘ืืฉื›ื•ืœ OpenShift.

Aporeto ืžืกื•ื’ืœืช ืœื™ืฆื•ืจ ืžื–ื”ื” ื™ื™ื—ื•ื“ื™ ืœื ืจืง ืขื‘ื•ืจ Kubernetes/ืžื›ื•ืœื•ืช ืืœื ื’ื ืขื‘ื•ืจ ืžืืจื—ื™ื, ืคื•ื ืงืฆื™ื•ืช ืขื ืŸ ื•ืžืฉืชืžืฉื™ื. ื‘ื”ืชืื ืœืžื–ื”ื™ื ืืœื” ื•ืœืžืขืจื›ืช ื›ืœืœื™ ืื‘ื˜ื—ืช ื”ืจืฉืช ืฉื ืงื‘ืขื• ืขืœ ื™ื“ื™ ื”ืžื ื”ืœ, ืชืชืืคืฉืจ ืื• ืชื—ืกื•ื ืชืงืฉื•ืจืช.

ืงืืœื™ืงื•

  • ืืชืจ ืื™ื ื˜ืจื ื˜: www.projectcalico.org
  • ืจื™ืฉื™ื•ืŸ: ื—ื™ื ื (Apache)

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Calico ื ืคืจืก ื‘ื“ืจืš ื›ืœืœ ื‘ืžื”ืœืš ื”ืชืงื ืช ืžืชื–ืžืจ ื”ืงื•ื ื˜ื™ื™ื ืจื™ื, ื”ืžืืคืฉืจ ืœื™ืฆื•ืจ ืจืฉืช ื•ื™ืจื˜ื•ืืœื™ืช ื”ืžืงืฉืจืช ืงื•ื ื˜ื™ื™ื ืจื™ื. ื‘ื ื•ืกืฃ ืœืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ื”ืจืฉืช ื”ื‘ืกื™ืกื™ืช ื”ื–ื•, ืคืจื•ื™ืงื˜ Calico ืขื•ื‘ื“ ืขื ืžื“ื™ื ื™ื•ืช ื”ืจืฉืช ืฉืœ Kubernetes ื•ืขื ืกื˜ ืคืจื•ืคื™ืœื™ ืื‘ื˜ื—ืช ืจืฉืช ืžืฉืœื•, ืชื•ืžืš ื‘ื ืงื•ื“ื•ืช ืงืฆื” ACL (ืจืฉื™ืžื•ืช ื‘ืงืจืช ื’ื™ืฉื”) ื•ื‘ื›ืœืœื™ ืื‘ื˜ื—ืช ืจืฉืช ืžื‘ื•ืกืกื™ ื”ืขืจื•ืช ืขื‘ื•ืจ ืชืขื‘ื•ืจืช ื›ื ื™ืกื” ื•ื™ืฆื™ืื”.

ืกื™ืœื™ื•ื

  • ืืชืจ ืื™ื ื˜ืจื ื˜: www.cilium.io
  • ืจื™ืฉื™ื•ืŸ: ื—ื™ื ื (Apache)

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Cilium ืคื•ืขืœืช ื‘ืชื•ืจ ื—ื•ืžืช ืืฉ ืฉืœ ืžื™ื›ืœ ื•ืžืกืคืงืช ืชื›ื•ื ื•ืช ืื‘ื˜ื—ืช ืจืฉืช ื”ืžื•ืชืืžื•ืช ื‘ืื•ืคืŸ ืžืงื•ืจื™ ืœืขื•ืžืกื™ ืขื‘ื•ื“ื” ืฉืœ Kubernetes ื•ืžื™ืงืจื•-ืฉื™ืจื•ืชื™ื. Cilium ืžืฉืชืžืฉ ื‘ื˜ื›ื ื•ืœื•ื’ื™ื™ืช ืœื™ื‘ืช ืœื™ื ื•ืงืก ื—ื“ืฉื” ื‘ืฉื BPF (Berkeley Packet Filter) ื›ื“ื™ ืœืกื ืŸ, ืœื ื˜ืจ, ืœื”ืคื ื•ืช ื•ืœืชืงืŸ ื ืชื•ื ื™ื.

Cilium ืžืกื•ื’ืœ ืœืคืจื•ืก ืžื“ื™ื ื™ื•ืช ื’ื™ืฉื” ืœืจืฉืช ื”ืžื‘ื•ืกืกืช ืขืœ ืžื–ื”ื™ ืžื™ื›ืœ ื‘ืืžืฆืขื•ืช ืชื•ื•ื™ื•ืช ื•ืžื˜ื ื ืชื•ื ื™ื ืฉืœ Docker ืื• Kubernetes. Cilium ื’ื ืžื‘ื™ืŸ ื•ืžืกื ืŸ ืคืจื•ื˜ื•ืงื•ืœื™ื ืฉื•ื ื™ื ืฉืœ ืฉื›ื‘ื” 7 ื›ื’ื•ืŸ HTTP ืื• gRPC, ื•ืžืืคืฉืจ ืœืš ืœื”ื’ื“ื™ืจ ืืช ืกื˜ ืงืจื™ืื•ืช ื”-REST ืฉื™ื•ืชืจื• ื‘ื™ืŸ ืฉืชื™ ืคืจื™ืกื•ืช Kubernetes, ืœืžืฉืœ.

Istio

  • ืืชืจ ืื™ื ื˜ืจื ื˜: istio.io
  • ืจื™ืฉื™ื•ืŸ: ื—ื™ื ื (Apache)

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Istio ื™ื“ื•ืขื” ื‘ื”ื˜ืžืขืช ืคืจื“ื™ื’ืžืช ืจืฉืช ื”ืฉื™ืจื•ืช ืขืœ ื™ื“ื™ ืคืจื™ืกืช ืžื™ืฉื•ืจ ื‘ืงืจื” ื‘ืœืชื™ ืชืœื•ื™ ื‘ืคืœื˜ืคื•ืจืžื” ื•ื”ืคื ื™ื” ืžื—ื“ืฉ ืฉืœ ื›ืœ ืชืขื‘ื•ืจืช ื”ืฉื™ืจื•ืช ื”ืžื ื•ื”ืœืช ื‘ืืžืฆืขื•ืช ืคืจื•ืงืกื™ Envoy ื”ื ื™ืชื ื™ื ืœื”ื’ื“ืจื” ื“ื™ื ืžื™ืช. Istio ืžื ืฆืœ ืืช ื”ืชืฆื•ื’ื” ื”ืžืชืงื“ืžืช ื”ื–ื• ืฉืœ ื›ืœ ื”ืžื™ืงืจื•-ืฉื™ืจื•ืชื™ื ื•ื”ืžื›ื•ืœื•ืช ื›ื“ื™ ืœื™ื™ืฉื ืืกื˜ืจื˜ื’ื™ื•ืช ืื‘ื˜ื—ืช ืจืฉืช ืฉื•ื ื•ืช.

ื™ื›ื•ืœื•ืช ืื‘ื˜ื—ืช ื”ืจืฉืช ืฉืœ Istio ื›ื•ืœืœื•ืช ื”ืฆืคื ืช TLS ืฉืงื•ืคื” ืœืฉื“ืจื•ื’ ืื•ื˜ื•ืžื˜ื™ ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ ื”ืชืงืฉื•ืจืช ื‘ื™ืŸ ืฉื™ืจื•ืชื™ ืžื™ืงืจื• ืœ-HTTPS, ื•ืžืขืจื›ืช ืื™ืžื•ืช ื•ื”ืจืฉืื” ืžืงื•ืจื™ืช ืฉืœ RBAC ื›ื“ื™ ืœืืคืฉืจ/ืœืžื ืข ืชืงืฉื•ืจืช ื‘ื™ืŸ ืขื•ืžืกื™ ืขื‘ื•ื“ื” ืฉื•ื ื™ื ื‘ืืฉื›ื•ืœ.

ื”ืขืจื”. ืชืจื’ื•ื: ืœืžื™ื“ืข ื ื•ืกืฃ ืขืœ ื”ื™ื›ื•ืœื•ืช ื”ืžืžื•ืงื“ื•ืช ื‘ืื‘ื˜ื—ื” ืฉืœ Istio, ืจืื” ืžืืžืจ ื–ื”.

ื ืžืจื”

  • ืืชืจ ืื™ื ื˜ืจื ื˜: www.tigera.io
  • ืจื™ืฉื™ื•ืŸ: ืžืกื—ืจื™

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

ืคืชืจื•ืŸ ื–ื”, ื”ืžื›ื•ื ื” "ื—ื•ืžืช ื”ืืฉ ืฉืœ Kubernetes", ืžื“ื’ื™ืฉ ื’ื™ืฉื” ืฉืœ ืืคืก ืืžื•ืŸ ืœืื‘ื˜ื—ืช ืจืฉืช.

ื›ืžื• ืคืชืจื•ื ื•ืช ืจืฉืช ืžืงื•ืจื™ื™ื ืื—ืจื™ื ืฉืœ Kubernetes, Tigera ืžืกืชืžื›ืช ืขืœ ืžื˜ื ื ืชื•ื ื™ื ื›ื“ื™ ืœื–ื”ื•ืช ืฉื™ืจื•ืชื™ื ื•ืื•ื‘ื™ื™ืงื˜ื™ื ืฉื•ื ื™ื ื‘ืืฉื›ื•ืœ ื•ืžืกืคืงืช ื–ื™ื”ื•ื™ ื‘ืขื™ื•ืช ื‘ื–ืžืŸ ืจื™ืฆื”, ืชืื™ืžื•ืช ืžืชืžืฉื›ืช ื•ื ืจืื•ืช ืจืฉืช ืขื‘ื•ืจ ืชืฉืชื™ื•ืช ืžืจื•ื‘ื•ืช ืขื ื ื™ื ืื• ื”ื™ื‘ืจื™ื“ื™ื•ืช ืขื ืžื›ื•ืœื•ืช ืžื•ื ื•ืœื™ื˜ื™ื•ืช.

ื˜ืจื™ืจืžื”

  • ืืชืจ ืื™ื ื˜ืจื ื˜: www.aporeto.com/opensource
  • ืจื™ืฉื™ื•ืŸ: ื—ื™ื ื (Apache)

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Trireme-Kubernetes ื”ื•ื ื™ื™ืฉื•ื ืคืฉื•ื˜ ื•ื ืงื™ ืฉืœ ืžืคืจื˜ ืžื“ื™ื ื™ื•ืช ื”ืจืฉืช ืฉืœ Kubernetes. ื”ืชื›ื•ื ื” ื”ื‘ื•ืœื˜ืช ื‘ื™ื•ืชืจ ื”ื™ื ืฉื‘ื ื™ื’ื•ื“ ืœืžื•ืฆืจื™ ืื‘ื˜ื—ืช ืจืฉืช ื“ื•ืžื™ื ืฉืœ Kubernetes - ืื™ืŸ ืฆื•ืจืš ื‘ืžื™ืฉื•ืจ ื‘ืงืจื” ืžืจื›ื–ื™ ื›ื“ื™ ืœืชืื ืืช ื”ืจืฉืช (ืจืฉืช). ื–ื” ื”ื•ืคืš ืืช ื”ืคืชืจื•ืŸ ืœื”ืจื—ื‘ื” ื‘ืฆื•ืจื” ื˜ืจื™ื•ื•ื™ืืœื™ืช. Trireme ืžืฉื™ื’ื” ื–ืืช ืขืœ ื™ื“ื™ ื”ืชืงื ืช ืกื•ื›ืŸ ื‘ื›ืœ ืฆื•ืžืช ืฉืžืชื—ื‘ืจ ื™ืฉื™ืจื•ืช ืœืขืจื™ืžืช ื”-TCP/IP ืฉืœ ื”ืžืืจื—.

ื”ืคืฆืช ืชืžื•ื ื•ืช ื•ื ื™ื”ื•ืœ ืกื•ื“ื•ืช

ื’ืจืคื™ืืก

  • ืืชืจ ืื™ื ื˜ืจื ื˜: grapheas.io
  • ืจื™ืฉื™ื•ืŸ: ื—ื™ื ื (Apache)

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Grafeas ื”ื•ื API ื‘ืงื•ื“ ืคืชื•ื— ืœื‘ื™ืงื•ืจืช ื•ื ื™ื”ื•ืœ ืฉืจืฉืจืช ืืกืคืงืช ื”ืชื•ื›ื ื”. ื‘ืจืžื” ื‘ืกื™ืกื™ืช, Grafeas ื”ื•ื ื›ืœื™ ืœืื™ืกื•ืฃ ืžื˜ื ื ืชื•ื ื™ื ื•ืชื•ืฆืื•ืช ื‘ื™ืงื•ืจืช. ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ื›ื“ื™ ืœืขืงื•ื‘ ืื—ืจ ืชืื™ืžื•ืช ืœืฉื™ื˜ื•ืช ืขื‘ื•ื“ื” ืžื•ืžืœืฆื•ืช ืœืื‘ื˜ื—ื” ื‘ืืจื’ื•ืŸ.

ืžืงื•ืจ ืจื™ื›ื•ื–ื™ ื–ื” ืœืืžืช ืขื•ื–ืจ ืœืขื ื•ืช ืขืœ ืฉืืœื•ืช ื›ืžื•:

  • ืžื™ ื”ืจื›ื™ื‘ ื•ื”ื—ืชื™ื ืžื›ื•ืœื” ืžืกื•ื™ืžืช?
  • ื”ืื ื”ื•ื ืขื‘ืจ ืืช ื›ืœ ืกื•ืจืงื™ ื”ืื‘ื˜ื—ื” ื•ื‘ื“ื™ืงื•ืช ืžื“ื™ื ื™ื•ืช ื”ืื‘ื˜ื—ื”? ืžืชื™? ืžื” ื”ื™ื• ื”ืชื•ืฆืื•ืช?
  • ืžื™ ืคืจืก ืืช ื–ื” ืœื™ื™ืฆื•ืจ? ื‘ืื™ืœื• ืคืจืžื˜ืจื™ื ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืžื”ืœืš ื”ืคืจื™ืกื”?

ื‘ื˜ื•ื˜ื•

  • ืืชืจ ืื™ื ื˜ืจื ื˜: in-toto.github.io
  • ืจื™ืฉื™ื•ืŸ: ื—ื™ื ื (Apache)

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

In-toto ื”ื™ื ืžืกื’ืจืช ืฉื ื•ืขื“ื” ืœืกืคืง ืฉืœืžื•ืช, ืื™ืžื•ืช ื•ื‘ื™ืงื•ืจืช ืขื‘ื•ืจ ื›ืœ ืฉืจืฉืจืช ื”ืืกืคืงื” โ€‹โ€‹ืฉืœ ื”ืชื•ื›ื ื”. ื‘ืขืช ืคืจื™ืกืช In-toto ืœืชืฉืชื™ืช, ืžื•ื’ื“ืจืช ืชื—ื™ืœื” ืชื•ื›ื ื™ืช ื”ืžืชืืจืช โ€‹โ€‹ืืช ื”ืฉืœื‘ื™ื ื”ืฉื•ื ื™ื ื‘ืฆื ืจืช (ืžืื’ืจ, ื›ืœื™ CI/CD, ื›ืœื™ QA, ื‘ื•ื ื™ ื—ืคืฆื™ื ื•ื›ื•') ื•ืืช ื”ืžืฉืชืžืฉื™ื (ื”ืื—ืจืื™ื) ื”ืžื•ืจืฉื™ื ืœืขืฉื•ืช ื–ืืช. ืœื™ื–ื•ื ืื•ืชื.

In-toto ืฉื•ืœื˜ ื‘ื‘ื™ืฆื•ืข ื”ืชื•ื›ื ื™ืช ืขืœ ื™ื“ื™ ื•ื™ื“ื•ื ืฉื›ืœ ืžืฉื™ืžื” ื‘ืฉืจืฉืจืช ืžื‘ื•ืฆืขืช ื›ื”ืœื›ื” ืจืง ืขืœ ื™ื“ื™ ืฆื•ื•ืช ืžื•ืจืฉื” ื•ื›ื™ ืœื ื‘ื•ืฆืขื• ืžื ื™ืคื•ืœืฆื™ื•ืช ืœื ืžื•ืจืฉื•ืช ืขื ื”ืžื•ืฆืจ ื‘ืžื”ืœืš ื”ืชื ื•ืขื”.

ืคื•ืจื˜ื™ืจื™ืก

  • ืืชืจ ืื™ื ื˜ืจื ื˜: github.com/IBM/portieris
  • ืจื™ืฉื™ื•ืŸ: ื—ื™ื ื (Apache)

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Portieris ื”ื•ื ื‘ืงืจ ืงื‘ืœื” ืขื‘ื•ืจ Kubernetes; ืžืฉืžืฉ ืœืื›ื™ืคืช ื‘ื“ื™ืงื•ืช ืืžื•ืŸ ื‘ืชื•ื›ืŸ. Portieris ืžืฉืชืžืฉ ื‘ืฉืจืช ื ื•ึนื˜ึธืจึดื™ื•ึนืŸ (ื›ืชื‘ื ื• ืขืœื™ื• ื‘ืกื•ืฃ ื‘ืžืืžืจ ื–ื” - ืžืฉื•ืขืจ. ืชืจื’ื•ื) ื›ืžืงื•ืจ ืืžืช ืœืื™ืžื•ืช ื—ืคืฆื™ื ืžื”ื™ืžื ื™ื ื•ื—ืชื•ืžื™ื (ื›ืœื•ืžืจ, ืชืžื•ื ื•ืช ืžื™ื›ืœ ืžืื•ืฉืจื•ืช).

ื›ืืฉืจ ืืชื” ื™ื•ืฆืจ ืื• ืžืฉื ื” ืขื•ืžืก ืขื‘ื•ื“ื” ื‘-Kubernetes, Portieris ื˜ื•ืขื ืช ืืช ืžื™ื“ืข ื”ื—ืชื™ืžื” ื•ืืช ืžื“ื™ื ื™ื•ืช ืืžื•ืŸ ื”ืชื•ื›ืŸ ืขื‘ื•ืจ ืชืžื•ื ื•ืช ื”ืžื›ื•ืœื” ื”ืžื‘ื•ืงืฉื•ืช, ื•ื‘ืžื™ื“ืช ื”ืฆื•ืจืš, ืžื‘ืฆืขืช ืฉื™ื ื•ื™ื™ื ื‘ืื•ื‘ื™ื™ืงื˜ ื”-API JSON ืชื•ืš ื›ื“ื™ ื›ื“ื™ ืœื”ืคืขื™ืœ ืืช ื”ื’ืจืกืื•ืช ื”ื—ืชื•ืžื•ืช ืฉืœ ืชืžื•ื ื•ืช ืืœื•.

ืงืžืจื•ืŸ

  • ืืชืจ ืื™ื ื˜ืจื ื˜: www.vaultproject.io
  • ืจื™ืฉื™ื•ืŸ: ื—ื™ื ื (MPL)

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Vault ื”ื•ื ืคืชืจื•ืŸ ืžืื•ื‘ื˜ื— ืœืื—ืกื•ืŸ ืžื™ื“ืข ืจื’ื™ืฉ: ืกื™ืกืžืื•ืช, ืืกื™ืžื•ื ื™ OAuth, ืื™ืฉื•ืจื™ PKI, ื—ืฉื‘ื•ื ื•ืช ื’ื™ืฉื”, ืกื•ื“ื•ืช Kubernetes ื•ืขื•ื“. ื”ื›ืกืคืช ืชื•ืžื›ืช ื‘ืชื›ื•ื ื•ืช ืžืชืงื“ืžื•ืช ืจื‘ื•ืช, ื›ื’ื•ืŸ ื”ืฉื›ืจืช ืืกื™ืžื•ื ื™ ืื‘ื˜ื—ื” ืืจืขื™ื™ื ืื• ืืจื’ื•ืŸ ืกื™ื‘ื•ื‘ ืžืคืชื—ื•ืช.

ื‘ืืžืฆืขื•ืช ืชืจืฉื™ื ื”-Helm, ื ื™ืชืŸ ืœืคืจื•ืก ืืช Vault ื›ืคืจื™ืกื” ื—ื“ืฉื” ื‘ืืฉื›ื•ืœ Kubernetes ืขื Consul ื›ืื—ืกื•ืŸ ืขื•ืจืคื™. ื”ื•ื ืชื•ืžืš ื‘ืžืฉืื‘ื™ Kubernetes ืžืงื•ืจื™ื™ื ื›ืžื• ืืกื™ืžื•ื ื™ ServiceAccount ื•ื™ื›ื•ืœ ืืคื™ืœื• ืœืฉืžืฉ ื›ื—ื ื•ืช ื”ืกื•ื“ื™ืช ืฉืœ Kubernetes ื”ืžื•ื’ื“ืจืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ.

ื”ืขืจื”. ืชืจื’ื•ื: ืื’ื‘, ืจืง ืืชืžื•ืœ, HashiCorp, ื”ืžืคืชื—ืช ืืช Vault, ื”ื›ืจื™ื–ื” ืขืœ ื›ืžื” ืฉื™ืคื•ืจื™ื ืœืฉื™ืžื•ืฉ ื‘-Vault ื‘-Kubernetes, ื•ื‘ืžื™ื•ื—ื“, ื”ื ืžืชื™ื™ื—ืกื™ื ืœืชืจืฉื™ื Helm. ืงืจื ืืช ื”ืคืจื˜ื™ื ื‘ ื‘ืœื•ื’ ืžืคืชื—ื™ื.

ื‘ื™ืงื•ืจืช ืื‘ื˜ื—ื” ืฉืœ Kubernetes

ืกืคืกืœ ืงื•ื‘

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Kube-bench ื”ื•ื ื™ื™ืฉื•ื Go ืฉื‘ื•ื“ืง ืื Kubernetes ื ืคืจืก ื‘ื‘ื˜ื—ื” ืขืœ ื™ื“ื™ ื”ืคืขืœืช ื‘ื“ื™ืงื•ืช ืžืจืฉื™ืžื” CIS Kubernetes Benchmark.

Kube-bench ืžื—ืคืฉ ื”ื’ื“ืจื•ืช ืชืฆื•ืจื” ืœื ืžืื•ื‘ื˜ื—ื•ืช ื‘ื™ืŸ ืจื›ื™ื‘ื™ ืืฉื›ื•ืœ (ื•ื›ื•', API, ืžื ื”ืœ ื‘ืงืจ ื•ื›ื•'), ื”ืจืฉืื•ืช ืงื‘ืฆื™ื ืžืคื•ืงืคืงื•ืช, ื—ืฉื‘ื•ื ื•ืช ืœื ืžืื•ื‘ื˜ื—ื™ื ืื• ื™ืฆื™ืื•ืช ืคืชื•ื—ื•ืช, ืžื›ืกื•ืช ืžืฉืื‘ื™ื, ื”ื’ื“ืจื•ืช ืžื’ื‘ืœืช ืฉื™ื—ื•ืช API ืœื”ื’ื ื” ืžืคื ื™ ื”ืชืงืคื•ืช DoS ื•ื›ื•'.

ืฆื™ื™ื“ ืงื•ื‘ื™ื•ืช

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Kube-Hunter "ืฆื•ื“" ืื—ืจ ืคื’ื™ืขื•ื™ื•ืช ืืคืฉืจื™ื•ืช (ื›ืžื• ื‘ื™ืฆื•ืข ืงื•ื“ ืžืจื—ื•ืง ืื• ื—ืฉื™ืคืช ื ืชื•ื ื™ื) ื‘ืืฉื›ื•ืœื•ืช Kubernetes. ื ื™ืชืŸ ืœื”ืคืขื™ืœ ืืช Kube-hunter ื›ืกื•ืจืง ืžืจื•ื—ืง - ื‘ืžืงืจื” ื–ื” ื”ื•ื ื™ืขืจื™ืš ืืช ื”ืืฉื›ื•ืœ ืžื ืงื•ื“ืช ืžื‘ื˜ื• ืฉืœ ืชื•ืงืฃ ืฆื“ ืฉืœื™ืฉื™ - ืื• ื›ืคื•ื“ ื‘ืชื•ืš ื”ืืฉื›ื•ืœ.

ืžืืคื™ื™ืŸ ื™ื™ื—ื•ื“ื™ ืฉืœ Kube-hunter ื”ื•ื ืžืฆื‘ "ืฆื™ื“ ืคืขื™ืœ", ืฉื‘ืžื”ืœื›ื• ื”ื•ื ืœื ืจืง ืžื“ื•ื•ื— ืขืœ ื‘ืขื™ื•ืช, ืืœื ื’ื ืžื ืกื” ืœื ืฆืœ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืฉื ืžืฆืื• ื‘ืืฉื›ื•ืœ ื”ื™ืขื“ ืฉืขืœื•ืœื•ืช ืœืคื’ื•ืข ื‘ืคืขื•ืœืชื•. ืื– ื”ืฉืชืžืฉ ื‘ื–ื”ื™ืจื•ืช!

Kubeaudit

  • ืืชืจ ืื™ื ื˜ืจื ื˜: github.com/Shopify/kubeaudit
  • ืจื™ืฉื™ื•ืŸ: ื—ื™ื ื (MIT)

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Kubeaudit ื”ื•ื ื›ืœื™ ืžืกื•ืฃ ืฉืคื•ืชื— ื‘ืžืงื•ืจ ืขืœ ื™ื“ื™ Shopify ื›ื“ื™ ืœื‘ื“ื•ืง ืืช ืชืฆื•ืจืช Kubernetes ืฉืœืš ืขื‘ื•ืจ ื‘ืขื™ื•ืช ืื‘ื˜ื—ื” ืฉื•ื ื•ืช. ืœื“ื•ื’ืžื”, ื–ื” ืขื•ื–ืจ ืœื–ื”ื•ืช ืงื•ื ื˜ื™ื™ื ืจื™ื ื”ืคื•ืขืœื™ื ืœืœื ื”ื‘ื—ื ื”, ืคื•ืขืœื™ื ื›ืฉื•ืจืฉ, ืžื ืฆืœื™ื ื”ืจืฉืื•ืช ืœืจืขื” ืื• ืžืฉืชืžืฉื™ื ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ ServiceAccount.

ืœ- Kubeaudit ื™ืฉ ื’ื ืชื›ื•ื ื•ืช ืžืขื ื™ื™ื ื•ืช ืื—ืจื•ืช. ืœื“ื•ื’ืžื”, ื”ื•ื ื™ื›ื•ืœ ืœื ืชื— ืงื‘ืฆื™ YAML ืžืงื•ืžื™ื™ื, ืœื–ื”ื•ืช ืคื’ืžื™ ืชืฆื•ืจื” ืฉืขืœื•ืœื™ื ืœื”ื•ื‘ื™ืœ ืœื‘ืขื™ื•ืช ืื‘ื˜ื—ื” ื•ืœืชืงืŸ ืื•ืชื ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™.

Kubesec

  • ืืชืจ ืื™ื ื˜ืจื ื˜: kubesec.io
  • ืจื™ืฉื™ื•ืŸ: ื—ื™ื ื (Apache)

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Kubesec ืžื™ื•ื—ื“ืช ื‘ื›ืš ืฉื”ื™ื ืกื•ืจืงืช ื™ืฉื™ืจื•ืช ืงื‘ืฆื™ YAML ืžืฉืื‘ื™ Kubernetes ืœืื™ืชื•ืจ ื”ื’ื“ืจื•ืช ื—ืœืฉื•ืช ืฉืขืœื•ืœื•ืช ืœื”ืฉืคื™ืข ืขืœ ื”ืื‘ื˜ื—ื”.

ืœื“ื•ื’ืžื”, ื”ื•ื ื™ื›ื•ืœ ืœื–ื”ื•ืช ื”ืจืฉืื•ืช ื•ื”ืจืฉืื•ืช ืžื•ื’ื–ืžื•ืช ืฉื ื™ืชื ื• ืœืคื•ื“, ื”ืคืขืœืช ืงื•ื ื˜ื™ื™ื ืจ ืขื root ื›ืžืฉืชืžืฉ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ, ื”ืชื—ื‘ืจื•ืช ืœืžืจื—ื‘ ื”ืฉืžื•ืช ืฉืœ ื”ืจืฉืช ืฉืœ ื”ืžืืจื—, ืื• ื—ื™ื‘ื•ืจื™ื ืžืกื•ื›ื ื™ื ื›ืžื• /proc ืžืืจื— ืื• ืฉืงืข Docker. ืชื›ื•ื ื” ืžืขื ื™ื™ื ืช ื ื•ืกืคืช ืฉืœ Kubesec ื”ื™ื ืฉื™ืจื•ืช ื”ื“ื’ืžื” ืžืงื•ื•ืŸ ืฉื‘ื• ืืชื” ื™ื›ื•ืœ ืœื”ืขืœื•ืช ืืช YAML ื•ืœื ืชื— ืื•ืชื• ืžื™ื“.

ืคืชื— ืืช ืกื•ื›ืŸ ื”ืžื“ื™ื ื™ื•ืช

  • ืืชืจ ืื™ื ื˜ืจื ื˜: www.openpolicyagent.org
  • ืจื™ืฉื™ื•ืŸ: ื—ื™ื ื (Apache)

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

ื”ืจืขื™ื•ืŸ ืฉืœ OPA (Open Policy Agent) ื”ื•ื ืœื”ืคืจื™ื“ ื‘ื™ืŸ ืžื“ื™ื ื™ื•ืช ืื‘ื˜ื—ื” ื•ืฉื™ื˜ื•ืช ืื‘ื˜ื—ื” ืžื•ืžืœืฆื•ืช ืžืคืœื˜ืคื•ืจืžืช ื–ืžืŸ ืจื™ืฆื” ืกืคืฆื™ืคื™ืช: Docker, Kubernetes, Mesosphere, OpenShift, ืื• ื›ืœ ืฉื™ืœื•ื‘ ื‘ื™ื ื™ื”ื.

ืœื“ื•ื’ืžื”, ืืชื” ื™ื›ื•ืœ ืœืคืจื•ืก ืืช OPA ื›-backend ืขื‘ื•ืจ ื‘ืงืจ ืงื‘ืœื” ืฉืœ Kubernetes, ื•ืœื”ืืฆื™ืœ ืœื• ื”ื—ืœื˜ื•ืช ืื‘ื˜ื—ื”. ื‘ื“ืจืš ื–ื•, ืกื•ื›ืŸ ื”-OPA ื™ื•ื›ืœ ืœื‘ื“ื•ืง, ืœื“ื—ื•ืช ื•ืืฃ ืœืฉื ื•ืช ื‘ืงืฉื•ืช ืชื•ืš ื›ื“ื™ ืชื ื•ืขื”, ืชื•ืš ื”ืงืคื“ื” ืขืœ ื›ื™ื‘ื•ื“ ืคืจืžื˜ืจื™ ื”ืื‘ื˜ื—ื” ืฉืฆื•ื™ื ื•. ืžื“ื™ื ื™ื•ืช ื”ืื‘ื˜ื—ื” ื‘-OPA ื›ืชื•ื‘ื” ื‘-DSL ืžืฉืœื”, Rego.

ื”ืขืจื”. ืชืจื’ื•ื: ื›ืชื‘ื ื• ืขื•ื“ ืขืœ OPA (ื•-SPIFFE) ื‘ ื”ื“ื‘ืจื™ื ื”ืืœื”.

ื›ืœื™ ื ื™ืชื•ื— ืื‘ื˜ื—ื” ืžืกื—ืจื™ื™ื ืฉืœ Kubernetes

ื”ื—ืœื˜ื ื• ืœื™ืฆื•ืจ ืงื˜ื’ื•ืจื™ื” ื ืคืจื“ืช ืœืคืœื˜ืคื•ืจืžื•ืช ืžืกื—ืจื™ื•ืช, ืžื›ื™ื•ื•ืŸ ืฉื”ืŸ ื ื•ื˜ื•ืช ืœื›ืกื•ืช ื›ืžื” ืชื—ื•ืžื™ ืื‘ื˜ื—ื” ื‘ื‘ืช ืื—ืช. ืžื•ืฉื’ ื›ืœืœื™ ืขืœ ื”ื™ื›ื•ืœื•ืช ืฉืœื”ื ื ื™ืชืŸ ืœืงื‘ืœ ืžื”ื˜ื‘ืœื”:

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes
* ืžื•ืžื—ื™ื•ืช ืžืชืงื“ืžืช ื•ื ื™ืชื•ื— ืฉืœืื—ืจ ื”ืžื•ื•ืช ืขื ืžืœื ืœื›ื™ื“ืช ืฉื™ื—ื•ืช ืžืขืจื›ืช.

ืืงื•ื•ื” ื‘ื™ื˜ื—ื•ืŸ

  • ืืชืจ ืื™ื ื˜ืจื ื˜: www.aquasec.com
  • ืจื™ืฉื™ื•ืŸ: ืžืกื—ืจื™

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

ื›ืœื™ ืžืกื—ืจื™ ื–ื” ืžื™ื•ืขื“ ืœืžื›ื•ืœื•ืช ื•ืขื•ืžืกื™ ืขื‘ื•ื“ื” ื‘ืขื ืŸ. ื–ื” ืžืกืคืง:

  • ืกืจื™ืงืช ืชืžื•ื ื•ืช ืžืฉื•ืœื‘ืช ืขื ืจื™ืฉื•ื ืžื™ื›ืœ ืื• ืฆื™ื ื•ืจ CI/CD;
  • ื”ื’ื ื” ื‘ื–ืžืŸ ืจื™ืฆื” ืขื ื—ื™ืคื•ืฉ ืื—ืจ ืฉื™ื ื•ื™ื™ื ื‘ืงื•ื ื˜ื™ื™ื ืจื™ื ื•ืคืขื™ืœื•ืช ื—ืฉื•ื“ื” ืื—ืจืช;
  • ื—ื•ืžืช ืืฉ ืžืงื•ืจื™ืช ืฉืœ ืžื™ื›ืœ;
  • ืื‘ื˜ื—ื” ืœืœื ืฉืจืช ื‘ืฉื™ืจื•ืชื™ ืขื ืŸ;
  • ืฆื™ื•ืช ื•ื‘ื™ืงื•ืจืช ื‘ืฉื™ืœื•ื‘ ืจื™ืฉื•ื ืื™ืจื•ืขื™ื.

ื”ืขืจื”. ืชืจื’ื•ื: ืจืื•ื™ ืœืฆื™ื™ืŸ ื’ื ืฉื™ืฉ ืจื›ื™ื‘ ื—ื™ื ื ืฉืœ ื”ืžื•ืฆืจ ื”ื ืงืจื ืžื™ืงืจื•ืกื•ืจืง, ื”ืžืืคืฉืจ ืœืš ืœืกืจื•ืง ืชืžื•ื ื•ืช ืžื™ื›ืœ ืœืื™ืชื•ืจ ื ืงื•ื“ื•ืช ืชื•ืจืคื”. ื”ืฉื•ื•ืื” ืฉืœ ื”ืชื›ื•ื ื•ืช ืฉืœื• ืขื ื’ืจืกืื•ืช ื‘ืชืฉืœื•ื ืžื•ืฆื’ืช ื‘ ื˜ื‘ืœื” ื–ื•.

ืงืคืกื•ืœื”8

  • ืืชืจ ืื™ื ื˜ืจื ื˜: capsule8.com
  • ืจื™ืฉื™ื•ืŸ: ืžืกื—ืจื™

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes
Capsule8 ืžืฉืชืœื‘ืช ื‘ืชืฉืชื™ืช ืขืœ ื™ื“ื™ ื”ืชืงื ืช ื”ื’ืœืื™ ื‘ืืฉื›ื•ืœ Kubernetes ืžืงื•ืžื™ ืื• ืขื ืŸ. ื’ืœืื™ ื–ื” ืื•ืกืฃ ื˜ืœืžื˜ืจื™ื” ืžืืจื— ื•ืจืฉืช, ื•ืžืชืื ืื•ืชื” ืขื ืกื•ื’ื™ื ืฉื•ื ื™ื ืฉืœ ื”ืชืงืคื•ืช.

ืฆื•ื•ืช Capsule8 ืžื—ื•ื™ื‘ ืœื’ื™ืœื•ื™ ืžื•ืงื“ื ื•ืžื ื™ืขืช ื”ืชืงืคื•ืช ื‘ืืžืฆืขื•ืช ื˜ืจื™ (0 ื™ืžื™ื) ืคื’ื™ืขื•ืช. Capsule8 ื™ื›ื•ืœื” ืœื”ืขืœื•ืช ื›ืœืœื™ ืื‘ื˜ื—ื” ืžืขื•ื“ื›ื ื™ื ื™ืฉื™ืจื•ืช ืœื’ืœืื™ื ื‘ืชื’ื•ื‘ื” ืœืื™ื•ืžื™ื ืฉื”ืชื’ืœื• ืœืื—ืจื•ื ื” ื•ืคื’ื™ืขื•ื™ื•ืช ืชื•ื›ื ื”.

Cavirin

  • ืืชืจ ืื™ื ื˜ืจื ื˜: www.cavirin.com
  • ืจื™ืฉื™ื•ืŸ: ืžืกื—ืจื™

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Cavirin ืคื•ืขืœืช ื›ืฆื“ ื ื’ื“ ืฉืœ ื”ื—ื‘ืจื” ืขื‘ื•ืจ ืกื•ื›ื ื•ื™ื•ืช ืชืงื ื™ ืื‘ื˜ื—ื” ืฉื•ื ื•ืช. ืœื ืจืง ืฉื”ื•ื ื™ื›ื•ืœ ืœืกืจื•ืง ืชืžื•ื ื•ืช, ืืœื ืฉื”ื•ื ื’ื ื™ื›ื•ืœ ืœื”ืฉืชืœื‘ ื‘ืฆื™ื ื•ืจ ื”-CI/CD, ื•ืœื—ืกื•ื ืชืžื•ื ื•ืช ืฉืื™ื ืŸ ืชื•ืืžื•ืช ืœืคื ื™ ืฉื”ืŸ ื ื›ื ืกื•ืช ืœืžืื’ืจื™ื ืคืจื˜ื™ื™ื.

ื—ื‘ื™ืœืช ื”ืื‘ื˜ื—ื” ืฉืœ Cavirin ืžืฉืชืžืฉืช ื‘ืœืžื™ื“ืช ืžื›ื•ื ื” ื›ื“ื™ ืœื”ืขืจื™ืš ืืช ืžืฆื‘ ืื‘ื˜ื—ืช ื”ืกื™ื™ื‘ืจ, ืžืฆื™ืขื” ืขืฆื•ืช ื›ื™ืฆื“ ืœื”ื’ื‘ื™ืจ ืืช ื”ืื‘ื˜ื—ื” ื•ืœืฉืคืจ ืืช ืชืื™ืžื•ืช ื”ืื‘ื˜ื—ื”.

ืžืจื›ื– ื”ืคื™ืงื•ื“ ืฉืœ Google Cloud Security

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Cloud Security Command Center ืขื•ื–ืจ ืœืฆื•ื•ืชื™ ืื‘ื˜ื—ื” ืœืืกื•ืฃ ื ืชื•ื ื™ื, ืœื–ื”ื•ืช ืื™ื•ืžื™ื ื•ืœืชืงืŸ ืื•ืชื ืœืคื ื™ ืฉื”ื ืคื•ื’ืขื™ื ื‘ื—ื‘ืจื”.

ื›ืคื™ ืฉื”ืฉื ืžืจืžื–, Google Cloud SCC ื”ื•ื ืœื•ื— ื‘ืงืจื” ืžืื•ื—ื“ ืฉื™ื›ื•ืœ ืœืฉืœื‘ ื•ืœื ื”ืœ ื“ื•ื—ื•ืช ืื‘ื˜ื—ื” ืฉื•ื ื™ื, ืžื ื•ืขื™ ืžืขืงื‘ ืื—ืจ ื ื›ืกื™ื ื•ืžืขืจื›ื•ืช ืื‘ื˜ื—ื” ืฉืœ ืฆื“ ืฉืœื™ืฉื™ ืžืžืงื•ืจ ืื—ื“ ื•ืžืจื•ื›ื–.

ืžืžืฉืง ื”-API ื”ื”ื“ื“ื™ืช ื”ืžื•ืฆืข ืขืœ ื™ื“ื™ Google Cloud SCC ืžืืคืฉืจ ืฉื™ืœื•ื‘ ืฉืœ ืื™ืจื•ืขื™ ืื‘ื˜ื—ื” ื”ืžื’ื™ืขื™ื ืžืžืงื•ืจื•ืช ืฉื•ื ื™ื ื›ื’ื•ืŸ Sysdig Secure (ืื‘ื˜ื—ืช ืžื™ื›ืœ ืขื‘ื•ืจ ื™ื™ืฉื•ืžื™ื ืžืงื•ืจื™ื™ื ื‘ืขื ืŸ) ืื• Falco (ืื‘ื˜ื—ืช ื–ืžืŸ ืจื™ืฆื” ื‘ืงื•ื“ ืคืชื•ื—).

ืชื•ื‘ื ื•ืช ืฉื›ื‘ื•ืช (Qualys)

  • ืืชืจ ืื™ื ื˜ืจื ื˜: layeredinsight.com
  • ืจื™ืฉื™ื•ืŸ: ืžืกื—ืจื™

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Layered Insight (ื›ื™ื•ื ื—ืœืง ืž-Qualys Inc) ื‘ื ื•ื™ื” ืขืœ ื”ืจืขื™ื•ืŸ ืฉืœ "ืื‘ื˜ื—ื” ืžืฉื•ื‘ืฆืช". ืœืื—ืจ ืกืจื™ืงืช ื”ืชืžื•ื ื” ื”ืžืงื•ืจื™ืช ืœืื™ืชื•ืจ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืชื•ืš ืฉื™ืžื•ืฉ ื‘ืฉื™ื˜ื•ืช ื ื™ืชื•ื— ืกื˜ื˜ื™ืกื˜ื™ ื•ื‘ื™ืฆื•ืข ื‘ื“ื™ืงื•ืช CVE, Layered Insight ืžื—ืœื™ืคื” ืื•ืชื” ื‘ืชืžื•ื ื” ืžื›ืฉื™ืจื ื™ืช ื”ื›ื•ืœืœืช ืกื•ื›ืŸ ื‘ืฆื•ืจื” ืฉืœ ื‘ื™ื ืืจื™.

ืกื•ื›ืŸ ื–ื” ืžื›ื™ืœ ืžื‘ื—ื ื™ ืื‘ื˜ื—ื” ื‘ื–ืžืŸ ืจื™ืฆื” ืœื ื™ืชื•ื— ืชืขื‘ื•ืจืช ืจืฉืช ืงื•ื ื˜ื™ื™ื ืจ, ื–ืจื™ืžื•ืช ืงืœื˜/ืคืœื˜ ื•ืคืขื™ืœื•ืช ื™ื™ืฉื•ืžื™ื. ื‘ื ื•ืกืฃ, ื”ื•ื ื™ื›ื•ืœ ืœื‘ืฆืข ื‘ื“ื™ืงื•ืช ืื‘ื˜ื—ื” ื ื•ืกืคื•ืช ืฉืฆื•ื™ื ื• ืขืœ ื™ื“ื™ ืžื ื”ืœ ื”ืชืฉืชื™ืช ืื• ืฆื•ื•ืชื™ DevOps.

NeuVector

  • ืืชืจ ืื™ื ื˜ืจื ื˜: neuvector.com
  • ืจื™ืฉื™ื•ืŸ: ืžืกื—ืจื™

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

NeuVector ืžื‘ืฆืขืช ื‘ื“ื™ืงื•ืช ืื‘ื˜ื—ื” ืฉืœ ืžื™ื›ืœ ื•ื”ื’ื ื” ืขืœ ื–ืžืŸ ืจื™ืฆื” ืขืœ ื™ื“ื™ ื ื™ืชื•ื— ืคืขื™ืœื•ืช ืจืฉืช ื•ื”ืชื ื”ื’ื•ืช ื™ื™ืฉื•ืžื™ื, ื™ืฆื™ืจืช ืคืจื•ืคื™ืœ ืื‘ื˜ื—ื” ืื™ื ื“ื™ื‘ื™ื“ื•ืืœื™ ืขื‘ื•ืจ ื›ืœ ืžื™ื›ืœ. ื–ื” ื™ื›ื•ืœ ื’ื ืœื—ืกื•ื ืื™ื•ืžื™ื ื‘ืขืฆืžื• ืขืœ ื™ื“ื™ ื‘ื™ื“ื•ื“ ืคืขื™ืœื•ืช ื—ืฉื•ื“ื” ืขืœ ื™ื“ื™ ืฉื™ื ื•ื™ ื›ืœืœื™ ื—ื•ืžืช ื”ืืฉ ื”ืžืงื•ืžื™ืช.

ืฉื™ืœื•ื‘ ื”ืจืฉืช ืฉืœ NeuVector, ื”ืžื›ื•ื ื” Security Mesh, ืžืกื•ื’ืœ ืœื‘ืฆืข ื‘ื“ื™ืงืช ืžื ื•ืช ืขืžื•ืงื” ื•ืกื™ื ื•ืŸ ืฉื›ื‘ื” 7 ืขื‘ื•ืจ ื›ืœ ื—ื™ื‘ื•ืจื™ ื”ืจืฉืช ื‘ืจืฉืช ืฉื™ืจื•ืช.

Stackrox

  • ืืชืจ ืื™ื ื˜ืจื ื˜: www.stackrox.com
  • ืจื™ืฉื™ื•ืŸ: ืžืกื—ืจื™

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

ืคืœื˜ืคื•ืจืžืช ื”ืื‘ื˜ื—ื” ืœืžื›ื•ืœื•ืช StackRox ืฉื•ืืคืช ืœื›ืกื•ืช ืืช ื›ืœ ืžื—ื–ื•ืจ ื”ื—ื™ื™ื ืฉืœ ื™ื™ืฉื•ืžื™ Kubernetes ื‘ืืฉื›ื•ืœ. ื›ืžื• ืคืœื˜ืคื•ืจืžื•ืช ืžืกื—ืจื™ื•ืช ืื—ืจื•ืช ื‘ืจืฉื™ืžื” ื–ื•, StackRox ืžื™ื™ืฆืจืช ืคืจื•ืคื™ืœ ื–ืžืŸ ืจื™ืฆื” ื”ืžื‘ื•ืกืก ืขืœ ื”ืชื ื”ื’ื•ืช ืงื•ื ื˜ื™ื™ื ืจ ืฉื ืฆืคื” ื•ืžืขืœื” ืื•ื˜ื•ืžื˜ื™ืช ืื–ืขืงื” ืขืœ ื›ืœ ืกื˜ื™ื™ื”.

ื‘ื ื•ืกืฃ, StackRox ืžื ืชื—ืช ืชืฆื•ืจื•ืช Kubernetes ื‘ืืžืฆืขื•ืช CIS Kubernetes ื•ื—ื•ืžืจื™ ื—ื•ืงื™ื ืื—ืจื™ื ื›ื“ื™ ืœื”ืขืจื™ืš ืชืื™ืžื•ืช ืœืžื›ื•ืœื•ืช.

Sysdig Secure

  • ืืชืจ ืื™ื ื˜ืจื ื˜: sysdig.com/products/secure
  • ืจื™ืฉื™ื•ืŸ: ืžืกื—ืจื™

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Sysdig Secure ืžื’ืŸ ืขืœ ื™ื™ืฉื•ืžื™ื ืœืื•ืจืš ื›ืœ ืžื—ื–ื•ืจ ื”ื—ื™ื™ื ืฉืœ ื”ืžื™ื›ืœ ื•-Kubernetes. ื”ื•ื ืกื•ืจืง ืชืžื•ื ื•ืช ืžื›ื•ืœื•ืช, ืžืกืคืง ื”ื’ื ื” ื‘ื–ืžืŸ ืจื™ืฆื” ืœืคื™ ืœืžื™ื“ืช ืžื›ื•ื ื”, ืžื‘ืฆืข Crim. ืžื•ืžื—ื™ื•ืช ืœื–ื™ื”ื•ื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื”, ื—ืกื™ืžืช ืื™ื•ืžื™ื, ืžืขืงื‘ื™ื ืขืžื™ื“ื” ื‘ืกื˜ื ื“ืจื˜ื™ื ืฉื ืงื‘ืขื• ื•ืžื‘ืงืจืช ืคืขื™ืœื•ืช ื‘ืฉื™ืจื•ืชื™ ืžื™ืงืจื•.

Sysdig Secure ืžืฉืชืœื‘ ืขื ื›ืœื™ CI/CD ื›ื’ื•ืŸ Jenkins ื•ืฉื•ืœื˜ ื‘ืชืžื•ื ื•ืช ื”ื ื˜ืขื ื•ืช ืžืจืฉืžื™ื ืฉืœ Docker, ื•ืžื•ื ืข ืžืชืžื•ื ื•ืช ืžืกื•ื›ื ื•ืช ืœื”ื•ืคื™ืข ื‘ื™ื™ืฆื•ืจ. ื–ื” ื’ื ืžืกืคืง ืื‘ื˜ื—ืช ื–ืžืŸ ืจื™ืฆื” ืžืงื™ืคื”, ื›ื•ืœืœ:

  • ืคืจื•ืคื™ืœ ื–ืžืŸ ืจื™ืฆื” ืžื‘ื•ืกืก ML ื•ื–ื™ื”ื•ื™ ืื ื•ืžืœื™ื•ืช;
  • ืžื“ื™ื ื™ื•ืช ื–ืžืŸ ืจื™ืฆื” ื”ืžื‘ื•ืกืกืช ืขืœ ืื™ืจื•ืขื™ ืžืขืจื›ืช, K8s-audit API, ืคืจื•ื™ืงื˜ื™ื ืงื”ื™ืœืชื™ื™ื ืžืฉื•ืชืคื™ื (FIM - ื ื™ื˜ื•ืจ ืฉืœืžื•ืช ืงื‘ืฆื™ื; cryptojacking) ื•ืžืกื’ืจืช MITER ATT & CK;
  • ืชื’ื•ื‘ื” ื•ื‘ื™ื˜ื•ืœ ืื™ืจื•ืขื™ื.

Tenable Container Security

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

ืœืคื ื™ ื”ื•ืคืขืช ื”ืงื•ื ื˜ื™ื™ื ืจื™ื, Tenable ื”ื™ื™ืชื” ื™ื“ื•ืขื” ื‘ืชืขืฉื™ื™ื” ื›ื—ื‘ืจื” ืฉืคื™ืชื—ื” ืืช Nessus, ื›ืœื™ ืคื•ืคื•ืœืจื™ ืœืื™ืชื•ืจ ืคื’ื™ืขื•ืช ื•ื‘ื™ืงื•ืจืช ืื‘ื˜ื—ื”.

Tenable Container Security ืžืžื ืคืช ืืช ื”ืžื•ืžื—ื™ื•ืช ืฉืœ ื”ื—ื‘ืจื” ื‘ืื‘ื˜ื—ืช ืžื—ืฉื‘ื™ื ื›ื“ื™ ืœืฉืœื‘ ืฆื™ื ื•ืจ CI/CD ืขื ืžืกื“ื™ ื ืชื•ื ื™ื ืฉืœ ืคื’ื™ืขื•ืช, ื—ื‘ื™ืœื•ืช ืžื™ื•ื—ื“ื•ืช ืœื–ื™ื”ื•ื™ ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ื•ืขืฆื•ืช ืื‘ื˜ื—ื”.

Twistlock (Palo Alto Networks)

  • ืืชืจ ืื™ื ื˜ืจื ื˜: www.twistlock.com
  • ืจื™ืฉื™ื•ืŸ: ืžืกื—ืจื™

33+ ื›ืœื™ ืื‘ื˜ื—ื” ืฉืœ Kubernetes

Twistlock ืžืงื“ืžืช ืืช ืขืฆืžื” ื›ืคืœื˜ืคื•ืจืžื” ื”ืžืชืžืงื“ืช ื‘ืฉื™ืจื•ืชื™ ืขื ืŸ ื•ืžื›ื•ืœื•ืช. Twistlock ืชื•ืžืš ื‘ืกืคืงื™ ืขื ืŸ ืฉื•ื ื™ื (AWS, Azure, GCP), ืžืชื–ืžื ื™ ืžื™ื›ืœ (Kubernetes, Mesospehere, OpenShift, Docker), ื–ืžื ื™ ืจื™ืฆื” ืœืœื ืฉืจืช, ืžืกื’ืจื•ืช ืจืฉืช ื•ื›ืœื™ CI/CD.

ื‘ื ื•ืกืฃ ืœืฉื™ื˜ื•ืช ื”ืื‘ื˜ื—ื” ื”ืจื’ื™ืœื•ืช ื‘ืจืžื” ื”ืืจื’ื•ื ื™ืช ื›ื’ื•ืŸ ืื™ื ื˜ื’ืจืฆื™ื” ืฉืœ ืฆื™ื ื•ืจื•ืช CI/CD ืื• ืกืจื™ืงืช ืชืžื•ื ื•ืช, Twistlock ืžืฉืชืžืฉืช ืœืžื™ื“ืช ืžื›ื•ื ื” ื›ื“ื™ ืœื™ืฆื•ืจ ื“ืคื•ืกื™ ื”ืชื ื”ื’ื•ืช ื•ื—ื•ืงื™ ืจืฉืช ืกืคืฆื™ืคื™ื™ื ืœืžื™ื›ืœ.

ืœืคื ื™ ื–ืžืŸ ืžื”, Twistlock ื ืจื›ืฉื” ืขืœ ื™ื“ื™ Palo Alto Networks, ื‘ืขืœืช ื”ืคืจื•ื™ืงื˜ื™ื Evident.io ื•-RedLock. ืขื“ื™ื™ืŸ ืœื ื™ื“ื•ืข ื‘ื“ื™ื•ืง ื›ื™ืฆื“ ื™ืฉื•ืœื‘ื• ืฉืœื•ืฉ ื”ืคืœื˜ืคื•ืจืžื•ืช ื”ืœืœื• ืคืจื™ื–ืžื” ืžืคืืœื• ืืœื˜ื•.

ืขื–ื•ืจ ืœื‘ื ื•ืช ืืช ืงื˜ืœื•ื’ ื›ืœื™ ื”ืื‘ื˜ื—ื” ื”ื˜ื•ื‘ ื‘ื™ื•ืชืจ ืฉืœ Kubernetes!

ืื ื• ืฉื•ืืคื™ื ืœื”ืคื•ืš ืืช ื”ืงื˜ืœื•ื’ ื”ื–ื” ืœืžืœื ื›ื›ืœ ื”ืืคืฉืจ, ื•ืœืฉื ื›ืš ืื ื• ื–ืงื•ืงื™ื ืœืขื–ืจืชื›ื! ืฆื•ืจ ืงืฉืจ (@sysdig) ืื ื™ืฉ ืœืš ื›ืœื™ ืžื’ื ื™ื‘ ื‘ืจืืฉ ืฉืจืื•ื™ ืœื”ื™ื›ืœืœ ื‘ืจืฉื™ืžื” ื–ื•, ืื• ืฉืืชื” ืžื•ืฆื ื‘ืื’/ืžื™ื“ืข ืžื™ื•ืฉืŸ.

ืืชื” ื™ื›ื•ืœ ื’ื ืœื”ื™ืจืฉื ืืœื™ื ื• ื ื™ื•ื–ืœื˜ืจ ื—ื•ื“ืฉื™ ืขื ื—ื“ืฉื•ืช ืขืœ ื”ืžืขืจื›ืช ื”ืืงื•ืœื•ื’ื™ืช ืžืงื•ืจื™ืช ื‘ืขื ืŸ ื•ืกื™ืคื•ืจื™ื ืขืœ ืคืจื•ื™ืงื˜ื™ื ืžืขื ื™ื™ื ื™ื ืžืขื•ืœื ื”ืื‘ื˜ื—ื” ืฉืœ Kubernetes.

ื .ื‘ ืžื”ืžืชืจื’ื

ืงืจื ื’ื ื‘ื‘ืœื•ื’ ืฉืœื ื•:

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”