33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

ื ืื˜ื™ืฅ. ื˜ืจืึทื ืกืœ.: ืื•ื™ื‘ ืื™ืจ ื–ืขื ื˜ ื•ื•ืึทื ื“ืขืจื™ื ื’ ื•ื•ืขื’ืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืื™ืŸ ืงื•ื‘ืขืจื ืขื˜ืขืก-ื‘ืื–ื™ืจื˜ ื™ื ืคืจืึทืกื˜ืจืึทืงื˜ืฉืขืจ, ื“ื™ ื•ื™ืกื’ืขืฆื™ื™ื›ื ื˜ ืื™ื‘ืขืจื‘ืœื™ืง ืคื•ืŸ Sysdig ืื™ื– ืึท ื’ืจื•ื™ืก ืกื˜ืึทืจื˜ื™ื ื’ ืคื•ื ื˜ ืคึฟืึทืจ ืึท ืฉื ืขืœ ืงื•ืง ืื™ืŸ ื“ื™ ืงืจืึทื ื˜ ืกืึทืœื•ืฉืึทื ื–. ืขืก ื›ื•ืœืœ ื‘ื™ื™ื“ืข ืงืึธืžืคึผืœืขืงืก ืกื™ืกื˜ืขืžืขืŸ ืคื•ืŸ ื‘ืึทื•ื•ื•ืกื˜ ืžืึทืจืง ืคึผืœื™ื™ึทืขืจืก ืื•ืŸ ืคื™ืœ ืžืขืจ ื‘ืึทืฉื™ื™ื“ืŸ ื™ื•ื˜ื™ืœืึทื˜ื™ื– ื•ื•ืึธืก ืกืึธืœื•ื•ืข ืึท ื‘ืึทื–ื•ื ื“ืขืจ ืคึผืจืึธื‘ืœืขื. ืื•ืŸ ืื™ืŸ ื“ื™ ื‘ืึทืžืขืจืงื•ื ื’ืขืŸ, ื•ื•ื™ ืฉื˜ืขื ื“ื™ืง, ืžื™ืจ ื•ื•ืขืœืŸ ื–ื™ื™ืŸ ืฆื•ืคืจื™ื“ืŸ ืฆื• ื”ืขืจืŸ ื•ื•ืขื’ืŸ ื“ื™ื™ืŸ ื“ืขืจืคืึทืจื•ื ื’ ืžื™ื˜ ื“ื™ ืžื›ืฉื™ืจื™ื ืื•ืŸ ื–ืขืŸ ืœื™ื ืงืก ืฆื• ืื ื“ืขืจืข ืคึผืจืึทื“ื–ืฉืขืงืก.

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื
Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ื•ื•ื™ื™ื›ื•ื•ืืจื’ ืคึผืจืึธื“ื•ืงื˜ืŸ ... ืขืก ื–ืขื ืขืŸ ืึทื–ื•ื™ ืคื™ืœืข ืคื•ืŸ โ€‹โ€‹ื–ื™ื™, ื™ืขื“ืขืจ ืžื™ื˜ ื–ื™ื™ืขืจ ืื™ื™ื’ืขื ืข ื’ืึธื•ืœื–, ืคืึทืจื ืขื ืื•ืŸ ืœื™ื™ืกืึทื ืกื™ื–.

ืึทื– ืก ื•ื•ืึธืก ืžื™ืจ ื‘ืึทืฉืœืึธืกืŸ ืฆื• ืžืึทื›ืŸ ื“ืขื ืจืฉื™ืžื” ืื•ืŸ ืึทืจื™ื™ึทื ื ืขืžืขืŸ ื‘ื™ื™ื“ืข ืึธืคึฟืŸ ืžืงื•ืจ ืคึผืจืึทื“ื–ืฉืขืงืก ืื•ืŸ ื’ืขืฉืขืคื˜ ืคึผืœืึทื˜ืคืึธืจืžืก ืคื•ืŸ ืคืึทืจืฉื™ื“ืขื ืข ื•ื•ืขื ื“ืึธืจืก. ืžื™ืจ ื”ืึธืคืŸ ืึทื– ื“ืึธืก ื•ื•ืขื˜ ื”ืขืœืคึฟืŸ ืื™ืจ ืฆื• ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ื“ื™ ืžืขืจืกื˜ ืื™ื ื˜ืขืจืขืกืื ื˜ ืื•ืŸ ืึธื ื•ื•ื™ื™ึทื–ืŸ ืื™ืจ ืื™ืŸ ื“ื™ ืจืขื›ื˜ ืจื™ื›ื˜ื•ื ื’ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ื™ืŸ ืกืคึผืขืฆื™ืคื™ืฉ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ื‘ืื“ืขืจืคืขื ื™ืฉืŸ.

ะšะฐั‚ะตะณะพั€ะธะธ

ืฆื• ืžืึทื›ืŸ ื“ื™ ืจืฉื™ืžื” ื’ืจื™ื ื’ืขืจ ืฆื• ื ืึทื•ื•ื™ื’ื™ืจืŸ, ื“ื™ ืžื›ืฉื™ืจื™ื ื–ืขื ืขืŸ ืึธืจื’ืึทื ื™ื–ื™ืจื˜ ืœื•ื™ื˜ ื”ื•ื™ืคึผื˜ ืคื•ื ืงืฆื™ืข ืื•ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ. ื“ื™ ืคืืœื’ืขื ื“ืข ืกืขืงืฉืึทื ื– ื–ืขื ืขืŸ ื‘ืืงื•ืžืขืŸ:

  • ืงื•ื‘ืขืจื ืขื˜ืขืก ื‘ื™ืœื“ ืกืงืึทื ื™ื ื’ ืื•ืŸ ืกื˜ืึทื˜ื™ืง ืึทื ืึทืœื™ืกื™ืก;
  • ืจื•ื ื˜ื™ืžืข ื–ื™ื›ืขืจื”ื™ื™ื˜;
  • Kubernetes ื ืขืฅ ื–ื™ื›ืขืจื”ื™ื™ึทื˜;
  • ื‘ื™ืœื“ ืคืึทืจืฉืคึผืจื™ื™ื˜ื•ื ื’ ืื•ืŸ ืกื™ืงืจื™ืฅ ืคืึทืจื•ื•ืึทืœื˜ื•ื ื’;
  • Kubernetes ื–ื™ื›ืขืจื”ื™ื™ึทื˜ ืงืึธื ื˜ืจืึธืœื™ืจืŸ;
  • ืคื•ืœืฉื˜ืขื ื“ื™ืง ื’ืขืฉืขืคื˜ ืคึผืจืึธื“ื•ืงื˜ืŸ.

ืœืืžื™ืจ ื’ื™ื™ืŸ ืฆื• ื“ื™ ื‘ื™ื–ื ืขืก:

ืกืงืึทื ื™ื ื’ Kubernetes ื‘ื™ืœื“ืขืจ

ืึทื ืงืขืจ

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: anchore.com
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (ืึทืคึผืึทื˜ืฉื™) ืื•ืŸ ื’ืขืฉืขืคื˜ ืคืึธืจืฉืœืึธื’

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

ืึทื ื˜ืฉืึธืจืข ืึทื ืึทืœื™ื–ื™ืจื˜ ืงืึทื ื˜ื™ื™ื ืขืจ ื‘ื™ืœื“ืขืจ ืื•ืŸ ืึทืœืึทื•ื– ื–ื™ื›ืขืจื”ื™ื™ื˜ ื˜ืฉืขืงืก ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื‘ืึทื ื™ืฆืขืจ-ื“ื™ืคื™ื™ื ื“ ืคึผืึทืœืึทืกื™ื–.

ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืฆื• ื“ื™ ื’ืขื•ื•ื™ื™ื ื˜ืœืขืš ืกืงืึทื ื™ื ื’ ืคื•ืŸ ืงืึทื ื˜ื™ื™ื ืขืจ ื‘ื™ืœื“ืขืจ ืคึฟืึทืจ ื‘ืึทื•ื•ื•ืกื˜ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืคื•ืŸ ื“ื™ CVE ื“ืึทื˜ืึทื‘ื™ื™ืก, ืึทื ื˜ืฉืึธืจืข ืคึผืขืจืคืึธืจืžื– ืคื™ืœืข ื ืึธืš ื˜ืฉืขืงืก ื•ื•ื™ ืึท ื˜ื™ื™ืœ ืคื•ืŸ ื–ื™ื™ืŸ ืกืงืึทื ื™ื ื’ ืคึผืึธืœื™ื˜ื™ืง: ื˜ืฉืขืง ื“ื™ ื“ืึธืงืงืขืจืคื™ืœืข, ืงืจืึทื“ืขื ื˜ืฉืึทืœ ืœื™ืงืก, ืคึผืึทืงืึทื“ื–ืฉืึทื– ืคื•ืŸ ื“ื™ ื’ืขื•ื•ื™ื™ื ื˜ ืคึผืจืึธื’ืจืึทืžืžื™ื ื’ ืฉืคึผืจืึทื›ืŸ (npm, maven, ืขื˜ืง. .), ื•ื•ื™ื™ื›ื•ื•ืืจื’ ืœื™ื™ืกืึทื ืกื™ื– ืื•ืŸ ืคื™ืœ ืžืขืจ.

ืงืœืึธืจ

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: coreos.com/clair (ืื™ืฆื˜ ืื•ื ื˜ืขืจ ื“ื™ ื˜ื•ื˜ืขืœื™ื“ื–ืฉ ืคื•ืŸ Red Hat)
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (ืึทืคึผืึทื˜ืฉื™)

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

Clair ืื™ื– ื’ืขื•ื•ืขืŸ ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืขืจืฉื˜ืข ืขืคึฟืŸ ืžืงื•ืจ ืคึผืจืึทื“ื–ืฉืขืงืก ืคึฟืึทืจ ื‘ื™ืœื“ ืกืงืึทื ื™ื ื’. ืขืก ืื™ื– ื•ื•ื™ื™ื“ืœื™ ื‘ืึทื•ื•ื•ืกื˜ ื•ื•ื™ ื“ื™ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืกืงืึทื ื ืขืจ ื”ื™ื ื˜ืขืจ ื“ื™ Quay ื‘ื™ืœื“ ืจืขื’ื™ืกื˜ืจื™ (ืื•ื™ืš ืคึฟื•ืŸ CoreOS - ืึทืคึผืคึผืจืึธืงืก. ืื™ื‘ืขืจื–ืขืฆื•ื ื’). Clair ืงืขื ืขืŸ ืงืœื™ื™ึทื‘ืŸ CVE ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹โ€‹โ€‹ืึท ื‘ืจื™ื™ื˜ ืคืึทืจืฉื™ื™ื“ื ืงื™ื™ึทื˜ ืคื•ืŸ ืงื•ื•ืืœืŸ, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืจืฉื™ืžื•ืช ืคื•ืŸ ืœื™ื ื•ืงืก ืคืึทืจืฉืคึผืจื™ื™ื˜ื•ื ื’-ืกืคึผืขืฆื™ืคื™ืฉ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื•ื•ืึธืก ื“ื™ Debian, Red Hat ืึธื“ืขืจ Ubuntu ื–ื™ื›ืขืจื”ื™ื™ื˜ ื˜ื™ืžื– ื”ืึทืœื˜ืŸ.

ื ื™ื˜ ืขื ืœืขืš Anchore, Clair ืคืึธื•ืงื™ืกื™ื– ื‘ืคึฟืจื˜ ืื•ื™ืฃ ื“ืขืจื’ื™ื™ื•ื ื’ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื•ืŸ ื•ื•ืึธืก ืจื™ื›ื˜ืŸ ื“ืึทื˜ืŸ ืฆื• CVEs. ืึธื‘ืขืจ, ื“ืขืจ ืคึผืจืึธื“ื•ืงื˜ ืึธืคืคืขืจืก ื™ื•ื–ืขืจื– ืขื˜ืœืขื›ืข ืึทืคึผืขืจื˜ื•ื ืึทื˜ื™ื– ืฆื• ื™ืงืกืคึผืึทื ื“ ืคืึทื ื’ืงืฉืึทื ื– ื ื™ืฆืŸ ืฆืึทืคึผืŸ-ืื™ืŸ ื“ืจื™ื•ื•ืขืจืก.

ื“ืึทื’ื“ืึท

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: github.com/eliasgranderubio/dagda
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (ืึทืคึผืึทื˜ืฉื™)

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

Dagda ืคึผืขืจืคืึธืจืžื– ืกื˜ืึทื˜ื™ืง ืึทื ืึทืœื™ืกื™ืก ืคื•ืŸ ืงืึทื ื˜ื™ื™ื ืขืจ ื‘ื™ืœื“ืขืจ ืคึฟืึทืจ ื‘ืึทื•ื•ื•ืกื˜ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–, ื˜ืจืึธื“ื–ืฉืึทื ืก, ื•ื•ื™ืจื•ืกืขืก, ืžืึทืœื•ื•ืึทืจืข ืื•ืŸ ืื ื“ืขืจืข ื˜ืจืขืฅ.

ืฆื•ื•ื™ื™ ื ืึธื•ื˜ืึทื‘ืึทืœ ืคึฟืขื™ึดืงื™ื™ื˜ืŸ ื•ื™ืกื˜ื™ื™ืœืŸ Dagda ืคื•ืŸ ืื ื“ืขืจืข ืขื ืœืขืš ืžื›ืฉื™ืจื™ื:

  • ืขืก ื™ื ื˜ืึทื’ืจื™ื™ืฅ ื‘ื™ืฉืœื™ื™ืžืขืก ืžื™ื˜ ืงืœืึทืžืึทื•ื•, ืึทืงื˜ื™ื ื’ ื ื™ื˜ ื‘ืœื•ื™ื– ื•ื•ื™ ืึท ื’ืขืฆื™ื™ึทื’ ืคึฟืึทืจ ืกืงืึทื ื™ื ื’ ืงืึทื ื˜ื™ื™ื ืขืจ ื‘ื™ืœื“ืขืจ, ืึธื‘ืขืจ ืื•ื™ืš ื•ื•ื™ ืึทืŸ ืึทื ื˜ื™ื•ื•ื™ืจื•ืก.
  • ืื•ื™ืš ื’ื™ื˜ ืจื•ื ื˜ื™ืžืข ืฉื•ืฅ ื“ื•ืจืš ืจื™ืกื™ื•ื•ื™ื ื’ ืคืึทืงื˜ื™ืฉ-ืฆื™ื™ื˜ ื’ืขืฉืขืขื ื™ืฉืŸ ืคื•ืŸ ื“ื™ ื“ืึธืงืงืขืจ ื“ื™ื™ืžืึทืŸ ืื•ืŸ ื™ื ื˜ืึทื’ืจื™ื™ื˜ื™ื ื’ ืžื™ื˜ Falco (ื–ืข ืื•ื ื˜ืŸ) ืฆื• ื–ืึทืžืœืขืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื’ืขืฉืขืขื ื™ืฉืŸ ื‘ืฉืขืช ื“ืขืจ ืงืึทื ื˜ื™ื™ื ืขืจ ืื™ื– ืคืœื™ืกื ื“ื™ืง.

KubeXray

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: github.com/jfrog/kubexray
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (ืึทืคึผืึทื˜ืฉื™), ืึธื‘ืขืจ ืจื™ืงื•ื•ื™ื™ืขืจื– ื“ืึทื˜ืŸ ืคื•ืŸ JFrog Xray (ื’ืขืฉืขืคื˜ ืคึผืจืึธื“ื•ืงื˜)

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

KubeXray ืœื™ืกืึทื ื– ืฆื• ื’ืขืฉืขืขื ื™ืฉืŸ ืคื•ืŸ ื“ื™ Kubernetes API ืกืขืจื•ื•ืขืจ ืื•ืŸ ื ื™ืฆื˜ ืžืขื˜ืึทื“ืึทื˜ืึท ืคื•ืŸ JFrog Xray ืฆื• ืขื ืฉื•ืจ ืึทื– ื‘ืœื•ื™ื– ืคึผืึธื“ืก ื•ื•ืึธืก ื’ืœื™ื™ึทื›ืŸ ื“ื™ ืงืจืึทื ื˜ ืคึผืึธืœื™ื˜ื™ืง ื–ืขื ืขืŸ ืœืึธื ื˜ืฉื˜.

KubeXray ื ื™ื˜ ื‘ืœื•ื™ื– ืึทื“ืึทืฅ ื ื™ื™ึท ืึธื“ืขืจ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื˜ ืงืึทื ื˜ื™ื™ื ืขืจื– ืื™ืŸ ื“ื™ืคึผืœื•ื™ืžืึทื ืฅ (ืขื ืœืขืš ืฆื• ื“ื™ ืึทืจื™ื™ึทื ื˜ืจืขื˜ืŸ ืงืึธื ื˜ืจืึธืœืœืขืจ ืื™ืŸ Kubernetes), ืึธื‘ืขืจ ืื•ื™ืš ื“ื™ื ืึทืžื™ืงืึทืœืœื™ ื˜ืฉืขืงืก ืคืœื™ืกื ื“ื™ืง ืงืึทื ื˜ื™ื™ื ืขืจื– ืคึฟืึทืจ ื”ืขืกืงืขื ืžื™ื˜ ื ื™ื™ึทืข ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืึทืœืึทืกื™ื–, โ€‹โ€‹โ€‹โ€‹ืจื™ืžื•ื•ื•ื™ื ื’ ืจืขืกื•ืจืกืŸ ื•ื•ืึธืก ื“ืขืจืžืึธื ืขืŸ ืฉืคึผื™ืจืขื•ื•ื“ื™ืง ื‘ื™ืœื“ืขืจ.

ืกื ื™ืง

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: snyk.io
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (ืึทืคึผืึทื˜ืฉื™) ืื•ืŸ ื’ืขืฉืขืคื˜ ื•ื•ืขืจืกื™ืขืก

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

Snyk ืื™ื– ืึท ื•ืžื’ืขื•ื•ื™ื™ื ื˜ืœืขืš ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืกืงืึทื ื ืขืจ ื•ื•ื™ื™ึทืœ ืขืก ืกืคึผืึทืกื™ืคื™ืงืœื™ ื˜ืึทืจื’ืึทืฅ ื“ื™ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ ืคึผืจืึธืฆืขืก ืื•ืŸ ืื™ื– ืคึผืจืึธืžืึธื˜ืขื“ ื•ื•ื™ ืึท "ื™ืงืขืจื“ื™ืง ืœื™ื™ื–ื•ื ื’" ืคึฟืึทืจ ื“ืขื•ื•ืขืœืึธืคึผืขืจืก.

Snyk ืงืึทื ืขืงืฅ ื’ืœื™ื™ืš ืฆื• ืงืึธื“ ืจื™ืคึผืึทื–ืึทื˜ืึธืจื™ื–, ืคึผืึทืจืกืขืก ื“ื™ ืคึผืจื•ื™ืขืงื˜ ืžืึทื ืึทืคืขืกื˜ื™ื™ืฉืึทืŸ ืื•ืŸ ืึทื ืึทืœื™ื–ืขืก ื“ื™ ื™ืžืคึผืึธืจื˜ื™ื“ ืงืึธื“ ืฆื•ื–ืืžืขืŸ ืžื™ื˜ ื“ื™ืจืขืงื˜ ืื•ืŸ ื•ืžื“ื™ืจืขืงื˜ ื“ื™ืคึผืขื ื“ืึทื ืกื™ื–. Snyk ืฉื˜ื™ืฆื˜ ืคื™ืœืข ืคืึธืœืงืก ืคึผืจืึธื’ืจืึทืžืžื™ื ื’ ืฉืคึผืจืึทื›ืŸ ืื•ืŸ ืงืขื ืขืŸ ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ืคืึทืจื‘ืึธืจื’ืŸ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืจื™ืกืงืก.

ื˜ืจื™ื•ื•ื™

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: github.com/knqyf263/trivy
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (AGPL)

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

ื˜ืจื™ื•ื•ื™ ืื™ื– ืึท ืคึผืฉื•ื˜ ืึธื‘ืขืจ ืฉื˜ืึทืจืง ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืกืงืึทื ื ืขืจ ืคึฟืึทืจ ืงืึทื ื˜ื™ื™ื ืขืจื– ื•ื•ืึธืก ืœื™ื™ื›ื˜ ื™ื ื˜ืึทื’ืจื™ื™ืฅ ืื™ืŸ ืึท ืกื™ / ืกื™ ืจืขืจื  - ืœื™ื ื™ืข. ื–ื™ื™ืŸ ื ืึธื•ื˜ืึทื‘ืึทืœ ืฉื˜ืจื™ืš ืื™ื– ื“ื™ ื™ื– ืคื•ืŸ ื™ื ืกื˜ืึทืœื™ืจื•ื ื’ ืื•ืŸ ืึธืคึผืขืจืึทืฆื™ืข: ื“ื™ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ื‘ืืฉื˜ื™ื™ื˜ ืคื•ืŸ ืึท ืื™ื™ืŸ ื‘ื™ื™ื ืขืจื™ ืื•ืŸ ื˜ื•ื˜ ื ื™ืฉื˜ ื“ืึทืจืคืŸ ื™ื ืกื˜ืึทืœื™ืจื•ื ื’ ืคื•ืŸ ืึท ื“ืึทื˜ืึทื‘ื™ื™ืก ืึธื“ืขืจ ื ืึธืš ืœื™ื™ื‘ืจืขืจื™ื–.

ื“ื™ ื“ืึทื•ื ืกื™ื™ื“ ืคื•ืŸ ื˜ืจื™ื•ื•ื™ ืก ืคึผืึทืฉื˜ืขืก ืื™ื– ืึทื– ืื™ืจ ื”ืึธื‘ืŸ ืฆื• ืจืขื›ืขื ืขืŸ ืื•ื™ืก ื•ื•ื™ ืฆื• ืคึผืึทืจืก ืื•ืŸ ืคืึธืจื•ื™ืก ื“ื™ ืจืขื–ื•ืœื˜ืึทื˜ืŸ ืื™ืŸ JSON ืคึฟืึธืจืžืึทื˜ ืึทื–ื•ื™ ืึทื– ืื ื“ืขืจืข Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื ืงืขื ืขืŸ ื ื•ืฆืŸ ื–ื™ื™.

ืจื•ื ื˜ื™ืžืข ื–ื™ื›ืขืจื”ื™ื™ื˜ ืื™ืŸ Kubernetes

ืคืึทืœืงืึธ

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: falco.org
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (ืึทืคึผืึทื˜ืฉื™)

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

Falco ืื™ื– ืึท ื’ืึทื ื’ ืคื•ืŸ ืžื›ืฉื™ืจื™ื ืคึฟืึทืจ ืกื™ืงื™ื•ืจื™ื ื’ ื•ื•ืึธืœืงืŸ ืจื•ื ื˜ื™ืžืข ื™ื ื•ื•ื™ื™ืจืึทื ืžืึทื ืฅ. ื˜ื™ื™ืœ ืคื•ืŸ ื“ื™ ืคึผืจื•ื™ืขืงื˜ ืžืฉืคึผื—ื” ืงื ืงืฃ.

ืžื™ื˜ Sysdig ืก ืœื™ื ื•ืงืก ืงืขืจืŸ-ืžื“ืจื’ื” ืžื›ืฉื™ืจื™ื ืื•ืŸ ืกื™ืกื˜ืขื ืจื•ืคืŸ ืคึผืจืึธืคื™ืœื™ื ื’, Falco ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื•ื ื˜ืขืจื˜ื•ืงื  ื–ื™ืš ื˜ื™ืฃ ืื™ืŸ ืกื™ืกื˜ืขื ื ืึทื˜ื•ืจ. ื–ื™ื™ืŸ ืจื•ื ื˜ื™ืžืข ื›ึผืœืœื™ื ืžืึธื˜ืึธืจ ืื™ื– ื˜ื•ื™ื’ืขื•ื•ื“ื™ืง ืคื•ืŸ ื“ื™ื˜ืขืงื˜ื™ื ื’ ืกืึทืกืคึผื™ืฉืึทืก ื˜ืขื˜ื™ืงื™ื™ื˜ ืื™ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื–, ืงืึทื ื˜ื™ื™ื ืขืจื–, ื“ื™ ืึทื ื“ืขืจืœื™ื™ื™ื ื’ ื‘ืึทืœืขื‘ืึธืก ืื•ืŸ ื“ื™ Kubernetes ืึธืจื˜ืฉืขืกื˜ืจืึทื˜ืึธืจ.

Falco ื’ื™ื˜ ื’ืึทื ืฅ ื“ื•ืจื›ื–ืขื™ืงื™ื™ึทื˜ ืื™ืŸ ื“ื™ ืจื•ื ื˜ื™ืžืข ืื•ืŸ ืกืึทืงืึธื ืข ื“ื™ื˜ืขืงืฉืึทืŸ ื“ื•ืจืš ื“ื™ืคึผืœื•ื™ื™ื ื’ ืกืคึผืขืฆื™ืขืœืข ืื’ืขื ื˜ืŸ ืื•ื™ืฃ Kubernetes ื ืึธื•ื“ื– ืคึฟืึทืจ ื“ื™ ืฆื•ื•ืขืงืŸ. ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜, ืขืก ืื™ื– ื ื™ื˜ ื“ืึทืจืคึฟืŸ ืฆื• ืžืึธื“ื™ืคื™ืฆื™ืจืŸ ืงืึทื ื˜ื™ื™ื ืขืจื– ื“ื•ืจืš ื™ื ื˜ืจืึธื•ื“ื•ืกื™ื ื’ ื“ืจื™ื˜-ืคึผืึทืจื˜ื™ื™ ืงืึธื“ ืื™ืŸ ื–ื™ื™ ืึธื“ืขืจ ืึทื“ื™ื ื’ ืกื™ื™ื“ืงืึทืจ ืงืึทื ื˜ื™ื™ื ืขืจื–.

ืœื™ื ื•ืงืก ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคืจืึทืžืขื•ื•ืึธืจืงืก ืคึฟืึทืจ ืจื•ื ื˜ื™ืžืข

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

ื“ื™ ื’ืขื‘ื•ื™ืจืŸ ืคืจืึทืžืขื•ื•ืึธืจืงืก ืคึฟืึทืจ ื“ื™ ืœื™ื ื•ืงืก ืงืขืจืŸ ื–ืขื ืขืŸ ื ื™ืฉื˜ "Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื" ืื™ืŸ ื“ืขื ื˜ืจืื“ื™ืฆื™ืื ืขืœืŸ ื–ื™ื ืขืŸ, ืึธื‘ืขืจ ื–ื™ื™ ื–ืขื ืขืŸ ื•ื•ืขืจื˜ ื“ืขืจืžืื ื˜ ื•ื•ื™ื™ึทืœ ื–ื™ื™ ื–ืขื ืขืŸ ืึท ื•ื•ื™ื›ื˜ื™ืง ืขืœืขืžืขื ื˜ ืื™ืŸ ื“ืขื ืงืึธื ื˜ืขืงืกื˜ ืคื•ืŸ ืจื•ื ื˜ื™ืžืข ื–ื™ื›ืขืจื”ื™ื™ื˜, ื•ื•ืึธืก ืื™ื– ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืื™ืŸ ื“ื™ Kubernetes Pod Security Policy (PSP).

ืึทืคึผืคึผืึทืจืžืึธืจ ืึทื˜ืึทื˜ืฉื™ื– ืึท ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืจืึธืคื™ืœ ืฆื• ืคึผืจืึทืกืขืกืึทื– ืคืœื™ืกื ื“ื™ืง ืื™ืŸ ื“ืขื ืงืึทื ื˜ื™ื™ื ืขืจ, ื“ื™ืคื™ื™ื ื™ื ื’ ื˜ืขืงืข ืกื™ืกื˜ืขื ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื–, ื ืขืฅ ืึทืงืกืขืก ื›ึผืœืœื™ื, ืงืึทื ืขืงื˜ื™ื ื’ ืœื™ื™ื‘ืจืขืจื™ื–, ืขื˜ืง. ื“ืึธืก ืื™ื– ืึท ืกื™ืกื˜ืขื ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ืžืึทื ื“ืึทื˜ืึธืจื™ ืึทืงืกืขืก ืงืึธื ื˜ืจืึธืœ (MAC). ืื™ืŸ ืื ื“ืขืจืข ื•ื•ืขืจื˜ืขืจ, ืขืก ืคึผืจื™ื•ื•ืขื ืฅ ืคึผืจืึธื•ื›ื™ื‘ืึทื˜ืึทื“ ืึทืงืฉืึทื ื–.

ื–ื™ื›ืขืจื”ื™ื™ื˜-ืขื ื›ืึทื ืกื˜ ืœื™ื ื•ืงืก (SELinux) ืื™ื– ืึท ืึทื•ื•ืึทื ืกื™ืจื˜ืข ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžืึธื“ื•ืœืข ืื™ืŸ ื“ื™ ืœื™ื ื•ืงืก ืงืขืจืŸ, ืขื ืœืขืš ืื™ืŸ ืขื˜ืœืขื›ืข ืึทืกืคึผืขืงืฅ ืฆื• AppArmor ืื•ืŸ ืึธืคื˜ ืงืึทืžืคึผืขืจื“ ืžื™ื˜ ืื™ื. SELinux ืื™ื– ื”ืขื›ืขืจ ืฆื• ืึทืคึผืึทืจืžืึธืจ ืื™ืŸ ืžืึทื›ื˜, ื‘ื™ื™ื’ื™ืงื™ื™ื˜ ืื•ืŸ ืงื•ืกื˜ืึธืžื™ื–ืึทื˜ื™ืึธืŸ. ื–ื™ื™ึทืŸ ื“ื™ืกืึทื“ื•ื•ืึทื ื˜ื™ื“ื–ืฉื™ื– ื–ืขื ืขืŸ ืœืึทื ื’ ืœืขืจื ืขืŸ ื•ื™ืกื‘ื™ื™ื’ ืื•ืŸ ื’ืขื•ื•ืืงืกืŸ ืงืึทืžืคึผืœืขืงืกื™ื˜ื™.

Secomp ืื•ืŸ seccomp-bpf ืœืึธื–ืŸ ืื™ืจ ืฆื• ืคื™ืœื˜ืขืจ ืกื™ืกื˜ืขื ืงืึทืœืœืก, ืคืึทืจืฉืคึผืึทืจืŸ ื“ื™ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ื“ื™ ื•ื•ืึธืก ื–ืขื ืขืŸ ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ื’ืขืคืขืจืœืขืš ืคึฟืึทืจ ื“ื™ ื‘ืึทื–ืข ืึทืก ืื•ืŸ ื–ืขื ืขืŸ ื ื™ืฉื˜ ื“ืืจืฃ ืคึฟืึทืจ ื ืึธืจืžืึทืœ ืึธืคึผืขืจืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื‘ืึทื ื™ืฆืขืจ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื–. Secommp ืื™ื– ืขื ืœืขืš ืฆื• Falco ืื™ืŸ ืขื˜ืœืขื›ืข ื•ื•ืขื’ืŸ, ื›ืึธื˜ืฉ ืขืก ืงืขืŸ ื ื™ืฉื˜ ื•ื•ื™ืกืŸ ื“ื™ ืกืคึผืขืกื™ืคื™ืงืก ืคื•ืŸ ืงืึทื ื˜ื™ื™ื ืขืจื–.

Sysdig ืขืคืขื ืขืŸ ืžืงื•ืจ

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: www.sysdig.com/opensource
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (ืึทืคึผืึทื˜ืฉื™)

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

Sysdig ืื™ื– ืึท ื’ืึทื ืฅ ื’ืขืฆื™ื™ึทื’ ืคึฟืึทืจ ืึทื ืึทืœื™ื™ื–ื™ื ื’, ื“ื™ืึทื’ื ืึธืกื™ื ื’ ืื•ืŸ ื“ื™ื‘ืึทื’ื™ื ื’ ืœื™ื ื•ืงืก ืกื™ืกื˜ืขืžืขืŸ (ืึทืจื‘ืขื˜ ืื•ื™ืš ืื•ื™ืฃ Windows ืื•ืŸ macOS, ืึธื‘ืขืจ ืžื™ื˜ ืœื™ืžื™ื˜ืขื“ ืคืึทื ื’ืงืฉืึทื ื–). ืขืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืคึฟืึทืจ ื“ื™ื˜ื™ื™ืœื“ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื–ืึทืžืœื•ื ื’, ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ ืื•ืŸ ืคืึธืจืขื ืกื™ืง ืึทื ืึทืœื™ืกื™ืก. (ืคืึธืจืขื ืกื™ืง) ื“ื™ ื‘ืึทื–ืข ืกื™ืกื˜ืขื ืื•ืŸ ืงื™ื™ืŸ ืงืึทื ื˜ื™ื™ื ืขืจื– ืคืœื™ืกื ื“ื™ืง ืื•ื™ืฃ ืขืก.

Sysdig ืื•ื™ืš ื ื™ื™ื˜ื™ื•ื• ืฉื˜ื™ืฆื˜ ืงืึทื ื˜ื™ื™ื ืขืจ ืจื•ื ื˜ื™ืžืข ืื•ืŸ Kubernetes ืžืขื˜ืึทื“ืึทื˜ืึท, ืึทื“ื™ื ื’ ื ืึธืš ื“ื™ืžืขื ืฉืึทื ื– ืื•ืŸ ืœืึทื‘ืขืœืก ืฆื• ืึทืœืข ืกื™ืกื˜ืขื ื ืึทื˜ื•ืจ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืขืก ืงืึทืœืขืงืฅ. ืขืก ื–ืขื ืขืŸ ืขื˜ืœืขื›ืข ื•ื•ืขื’ืŸ ืฆื• ืึทื ืึทืœื™ื™ื– ืึท Kubernetes ืงื ื•ื™ืœ ืžื™ื˜ Sysdig: ืื™ืจ ืงืขื ืขืŸ ื“ื•ืจื›ืคื™ืจืŸ ืคื•ื ื˜-ืื™ืŸ-ืฆื™ื™ื˜ ื›ืึทืคึผืŸ ื“ื•ืจืš ืงื•ื‘ืขืงื˜ืœ ื›ืึทืคึผืŸ ืึธื“ืขืจ ืงืึทื˜ืขืจ ืึทืŸ ncurses-ื‘ืื–ื™ืจื˜ ื™ื ื˜ืขืจืึทืงื˜ื™ื•ื• ืฆื•ื‘ื™ื ื“ ื ื™ืฆืŸ ืึท ืคึผืœื•ื’ื™ืŸ ืงื•ื‘ืขืงื˜ืœ ื’ืจืึธื‘ืŸ.

Kubernetes Network Security

ืึทืคึผืึธืจืขื˜ืึธ

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: www.aporeto.com
  • ืœื™ืกืขื ืกืข: ื’ืขืฉืขืคื˜

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

Aporeto ืึธืคืคืขืจืก "ื–ื™ื›ืขืจื”ื™ื™ึทื˜ ืืคื’ืขืฉื™ื™ื“ื˜ ืคื•ืŸ ื“ื™ ื ืขืฅ ืื•ืŸ ื™ื ืคืจืึทืกื˜ืจืึทืงื˜ืฉืขืจ." ื“ืึธืก ืžื™ื™ื ื˜ ืึทื– Kubernetes ื‘ืึทื“ื™ื ื•ื ื’ืก ื‘ืึทืงื•ืžืขืŸ ื ื™ืฉื˜ ื‘ืœื•ื™ื– ืึท ื”ื™ื’ืข ืฉื™ื™ึทืŸ (ื“"ื” ืกืขืจื•ื•ื™ืก ืึทืงืึทื•ื ื˜ ืื™ืŸ Kubernetes), ืึธื‘ืขืจ ืื•ื™ืš ืึท ื•ื ื™ื•ื•ืขืจืกืึทืœ ืฉื™ื™ึทืŸ / ืคื™ื ื’ืขืจืคึผืจื™ื ื˜ ื•ื•ืึธืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืฆื• ื™ื‘ืขืจื’ืขื‘ืŸ ืกื™ืงื™ื•ืจืœื™ ืื•ืŸ ืžื™ื•ื˜ืฉื•ืึทืœื™ ืžื™ื˜ ืงื™ื™ืŸ ืื ื“ืขืจืข ืกืขืจื•ื•ื™ืก, ืœืžืฉืœ ืื™ืŸ ืึทืŸ OpenShift ืงื ื•ื™ืœ.

Aporeto ืื™ื– ื˜ื•ื™ื’ืขื•ื•ื“ื™ืง ืฆื• ื“ื–ืฉืขื ืขืจื™ื™ื˜ ืึท ื™ื™ื ืฆื™ืง ืฉื™ื™ึทืŸ ื ื™ื˜ ื‘ืœื•ื™ื– ืคึฟืึทืจ Kubernetes / ืงืึทื ื˜ื™ื™ื ืขืจื–, ืึธื‘ืขืจ ืื•ื™ืš ืคึฟืึทืจ ืžื—ื ื•ืช, ื•ื•ืึธืœืงืŸ ืคืึทื ื’ืงืฉืึทื ื– ืื•ืŸ ื™ื•ื–ืขืจื–. ื“ืขืคึผืขื ื“ื™ื ื’ ืื•ื™ืฃ ื“ื™ ื™ื“ืขื ื˜ื™ืคื™ืขืจืก ืื•ืŸ ื“ื™ ื’ืึทื ื’ ืคื•ืŸ ื ืขืฅ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื›ึผืœืœื™ื ื‘ืึทืฉื˜ื™ืžื˜ ื“ื•ืจืš ื“ื™ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ, ืงืึธืžื•ื ื™ืงืึทืฆื™ืข ื•ื•ืขื˜ ื–ื™ื™ืŸ ืขืจืœื•ื™ื‘ื˜ ืึธื“ืขืจ ืืคื’ืขืฉื˜ืขืœื˜.

ืงืึทืœื™ืงืึธ

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: www.projectcalico.org
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (ืึทืคึผืึทื˜ืฉื™)

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

ืงืึทืœื™ืงืึธ ืื™ื– ื˜ื™ืคึผื™ืงืœื™ ื“ื™ืคึผืœื•ื™ื“ ื‘ืขืฉืึทืก ืึท ืงืึทื ื˜ื™ื™ื ืขืจ ืึธืจืงืขืกื˜ืจืึทื˜ืึธืจ ื™ื™ึทื ืžืึธื ื˜ื™ืจื•ื ื’, ืึทืœืึทื•ื™ื ื’ ืื™ืจ ืฆื• ืฉืึทืคึฟืŸ ืึท ื•ื•ื™ืจื˜ื•ืึทืœ ื ืขืฅ ื•ื•ืึธืก ื™ื ื˜ืขืจืงืึทื ืขืงืฅ ืงืึทื ื˜ื™ื™ื ืขืจื–. ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืฆื• ื“ื™ ื™ืงืขืจื“ื™ืง ื ืขืฅ ืคืึทื ื’ืงืฉืึทื ืึทืœื™ื˜ื™, ื“ื™ Calico ืคึผืจื•ื™ืขืงื˜ ืึทืจื‘ืขื˜ ืžื™ื˜ Kubernetes ื ืขื˜ื•ื•ืึธืจืง ืคึผืึธืœื™ืกื™ืขืก ืื•ืŸ ื–ื™ื™ืŸ ืื™ื™ื’ืขื ืข ื’ืึทื ื’ ืคื•ืŸ ื ืขืฅ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืจืึธื•ืคื™ื™ืœื–, ืฉื˜ื™ืฆื˜ ืขื ื“ืคึผื•ื™ื ื˜ ืึทืงืœืก (ืึทืงืกืขืก ืงืึธื ื˜ืจืึธืœ ืจืฉื™ืžื•ืช) ืื•ืŸ ืึทื ืึธื˜ืึทืฆื™ืข-ื‘ืื–ื™ืจื˜ ื ืขืฅ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื›ึผืœืœื™ื ืคึฟืึทืจ ื™ื ื’ืจืขืกืก ืื•ืŸ ืขื’ืจืขืกืก ืคืึทืจืงืขืจ.

ืกื™ืœื™ื•ื

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: www.cilium.io
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (ืึทืคึผืึทื˜ืฉื™)

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

ืกื™ืœื™ื•ื ืึทืงืฅ ื•ื•ื™ ืึท ืคื™ื™ืจื•ื•ืึทืœ ืคึฟืึทืจ ืงืึทื ื˜ื™ื™ื ืขืจื– ืื•ืŸ ื’ื™ื˜ ื ืขืฅ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึฟืขื™ึดืงื™ื™ื˜ืŸ ื ื™ื™ื˜ื™ื•ื•ืœื™ ื˜ื™ื™ืœืขืจื“ ืฆื• ืงื•ื‘ืขืจื ืขื˜ืขืก ืื•ืŸ ืžื™ืงืจืึธืกืขืจื•ื•ื™ืกืขืก ื•ื•ืขืจืงืœืึธื•ื“ื–. ืกื™ืœื™ื•ื ื ื™ืฆื˜ ืึท ื ื™ื™ึทืข ืœื™ื ื•ืงืก ืงืขืจืŸ ื˜ืขื›ื ืึธืœืึธื’ื™ืข ื’ืขืจื•ืคึฟืŸ BPF (Berkeley Packet Filter) ืฆื• ืคื™ืœื˜ืขืจ, ืžืึธื ื™ื˜ืึธืจ, ืจื™ื“ืขืจืขืงื˜ ืื•ืŸ ืจื™ื›ื˜ื™ืง ื“ืึทื˜ืŸ.

ืกื™ืœื™ื•ื ืื™ื– ื˜ื•ื™ื’ืขื•ื•ื“ื™ืง ืคื•ืŸ ื“ื™ืคึผืœื•ื™ื™ื ื’ ื ืขืฅ ืึทืงืกืขืก ืคึผืึทืœืึทืกื™ื– ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ืงืึทื ื˜ื™ื™ื ืขืจ IDs ื ื™ืฆืŸ Docker ืึธื“ืขืจ Kubernetes ืœืึทื‘ืขืœืก ืื•ืŸ ืžืขื˜ืึทื“ืึทื˜ืึท. ืกื™ืœื™ื•ื ืื•ื™ืš ืคืืจืฉื˜ื™ื™ื˜ ืื•ืŸ ืคื™ืœื˜ืขืจืก ืคืึทืจืฉื™ื“ืŸ ืฉื™ื›ื˜ืข 7 ืคึผืจืึธื˜ืึธืงืึธืœืก ืึทื–ืึท ื•ื•ื™ HTTP ืึธื“ืขืจ gRPC, ืึทืœืึทื•ื™ื ื’ ืื™ืจ ืฆื• ื“ืขืคื™ื ื™ืจืŸ ืึท ืกื›ื•ื ืคื•ืŸ REST ืงืึทืœืœืก ื•ื•ืึธืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ืขืจืœื•ื™ื‘ื˜ ืฆื•ื•ื™ืฉืŸ ืฆื•ื•ื™ื™ Kubernetes ื“ื™ืคึผืœื•ื™ืžืึทื ืฅ, ืœืžืฉืœ.

ื™ืกื˜ื™ืึธ

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: istio.io
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (ืึทืคึผืึทื˜ืฉื™)

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

Istio ืื™ื– ื•ื•ื™ื™ื“ืœื™ ื‘ืึทื•ื•ื•ืกื˜ ืคึฟืึทืจ ื™ืžืคึผืœืึทืžืขื ื™ื ื’ ื“ื™ ืกืขืจื•ื•ื™ืก ืžืขืฉ ืคึผืึทืจืึทื“ื™ื’ื ื“ื•ืจืš ื“ื™ืคึผืœื™ื™ื™ื ื’ ืึท ืคึผืœืึทื˜ืคืึธืจืžืข-ืคืจื™ื™ึท ืงืึธื ื˜ืจืึธืœ ืคืœืึทืš ืื•ืŸ ืจื•ื˜ื™ื ื’ ืึทืœืข ื’ืขืจืื˜ืŸ ืกืขืจื•ื•ื™ืก ืคืึทืจืงืขืจ ื“ื•ืจืš ื“ื™ื ืึทืžื™ืงืึทืœืœื™ ืงืึทื ืคื™ื’ื™ืขืจื“ ืขื ื•ื•ื•ื™ ืคึผืจืึทืงืกื™ื–. Istio ื ื™ืฆื˜ ื“ืขื ืึทื•ื•ืึทื ืกื™ืจื˜ืข ืžื™ื™ื ื•ื ื’ ืคื•ืŸ ืึทืœืข ืžื™ืงืจืึธ ื‘ืึทื“ื™ื ื•ื ื’ืก ืื•ืŸ ืงืึทื ื˜ื™ื™ื ืขืจื– ืฆื• ื™ื ืกื˜ืจื•ืžืขื ื˜ ืคืึทืจืฉื™ื“ืŸ ื ืขืฅ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืกื˜ืจืึทื˜ืขื’ื™ืขืก.

Istio ืก ื ืขืฅ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืงื™ื™ืคึผืึทื‘ื™ืœืึทื˜ื™ื– ืึทืจื™ื™ึทื ื ืขืžืขืŸ ื˜ืจืึทื ืกืคึผืขืจืึทื ื˜ TLS ืขื ืงืจื™ืคึผืฉืึทืŸ ืฆื• ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืึทืคึผื’ืจื™ื™ื“ ืงืึธืžื•ื ื™ืงืึทืฆื™ืข ืฆื•ื•ื™ืฉืŸ ืžื™ืงืจืึธ ื‘ืึทื“ื™ื ื•ื ื’ืก ืฆื• ื”ื˜ื˜ืคึผืก, ืื•ืŸ ืึท ืคึผืจืึทืคึผืจื™ื™ืึทื˜ืขืจื™ RBAC ืœืขื’ื™ื˜ื™ืžืึทืฆื™ืข ืื•ืŸ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืกื™ืกื˜ืขื ืฆื• ืœืึธื–ืŸ / ืœื™ื™ืงืขื ืขืŸ ืงืึธืžื•ื ื™ืงืึทืฆื™ืข ืฆื•ื•ื™ืฉืŸ ืคืึทืจืฉื™ื“ืขื ืข ื•ื•ืขืจืงืœืึธื•ื“ื– ืื™ืŸ ื“ืขื ืงื ื•ื™ืœ.

ื ืื˜ื™ืฅ. ื˜ืจืึทื ืกืœ.: ืฆื• ืœืขืจื ืขืŸ ืžืขืจ ื•ื•ืขื’ืŸ Istio ืก ื–ื™ื›ืขืจื”ื™ื™ื˜-ืคืึธื•ืงื™ืกื˜ ืงื™ื™ืคึผืึทื‘ื™ืœืึทื˜ื™ื–, ืœื™ื™ืขื ืขืŸ ื“ืขื ืึทืจื˜ื™ืงืœ.

ื˜ื™ื’ืขืจืึท

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: www.tigera.io
  • ืœื™ืกืขื ืกืข: ื’ืขืฉืขืคื˜

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

ื’ืขืจื•ืคึฟืŸ ื“ื™ "Kubernetes Firewall," ื“ืขื ืœื™ื™ื–ื•ื ื’ ืขืžืคืึทืกื™ื™ื–ื™ื– ืึท ื ื•ืœ ืฆื•ื˜ืจื•ื™ ืฆื•ื’ืึทื ื’ ืฆื• ื ืขืฅ ื–ื™ื›ืขืจื”ื™ื™ื˜.

ืขื ืœืขืš ืฆื• ืื ื“ืขืจืข ื’ืขื‘ื•ื™ืจืŸ Kubernetes ื ืขื˜ื•ื•ืึธืจืงื™ื ื’ ืกืึทืœื•ืฉืึทื ื–, Tigera ืจื™ืœื™ื™ื– ืื•ื™ืฃ ืžืขื˜ืึทื“ืึทื˜ืึท ืฆื• ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ื“ื™ ืคืึทืจืฉื™ื“ืŸ ื‘ืึทื“ื™ื ื•ื ื’ืก ืื•ืŸ ืึทื‘ื“ื–ืฉืขืงืฅ ืื™ืŸ ื“ืขื ืงื ื•ื™ืœ ืื•ืŸ ื’ื™ื˜ ืจื•ื ื˜ื™ืžืข ืึทืจื•ื™ืกื’ืขื‘ืŸ ื“ื™ื˜ืขืงืฉืึทืŸ, ืงืขืกื™ื™ื“ืขืจื“ื™ืง ื”ืขืกืงืขื ืงืึธื ื˜ืจืึธืœื™ืจื•ื ื’ ืื•ืŸ ื ืขืฅ ื•ื•ื™ื–ืึทื‘ื™ืœื™ื˜ื™ ืคึฟืึทืจ ืžืึทืœื˜ื™-ื•ื•ืึธืœืงืŸ ืึธื“ืขืจ ื›ื™ื™ื‘ืจื™ื“ ืžืึทื ืึทืœื™ื˜ื™ืง ืงืึทื ื˜ืึทื™ื ืขืจื™ื™ื–ื“ ื™ื ืคืจืึทืกื˜ืจืึทืงื˜ืฉืขืจ.

ื˜ืจื™ืจืขืžืข

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: www.aporeto.com/opensource
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (ืึทืคึผืึทื˜ืฉื™)

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

Trireme-Kubernetes ืื™ื– ืึท ืคึผืฉื•ื˜ ืื•ืŸ ืกื˜ืจื™ื™ื˜ืคืึธืจื•ื•ืขืจื“ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ Kubernetes ื ืขื˜ื•ื•ืึธืจืง ืคึผืึธืœื™ืกื™ืขืก ื‘ืึทืฉืจื™ื™ึทื‘ื•ื ื’. ื“ื™ ืžืขืจืกื˜ ื ืึธื•ื˜ืึทื‘ืึทืœ ืฉื˜ืจื™ืš ืื™ื– ืึทื– - ื ื™ื˜ ืขื ืœืขืš Kubernetes ื ืขืฅ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืจืึธื“ื•ืงื˜ืŸ - ืขืก ื˜ื•ื˜ ื ื™ืฉื˜ ื“ืึทืจืคืŸ ืึท ื”ื•ื™ืคื˜ ืงืึธื ื˜ืจืึธืœ ืคืœืึทืš ืฆื• ืงืึธื•ืึธืจื“ืึทื ืึทื˜ ื“ื™ ื™ื™ื’ืœ. ื“ืึธืก ืžืื›ื˜ ื“ื™ ืœื™ื™ื–ื•ื ื’ ื˜ืจื™ื•ื•ื™ืึทืœื™ ืกืงืึทืœืึทื‘ืœืข. ืื™ืŸ ื˜ืจื™ืจืขืžืข, ื“ืึธืก ืื™ื– ืึทื˜ืฉื™ื•ื•ื“ ื“ื•ืจืš ื™ื ืกื˜ืึธืœื™ื ื’ ืึทืŸ ืึทื’ืขื ื˜ ืื•ื™ืฃ ื™ืขื“ืขืจ ื ืึธื“ืข ื•ื•ืึธืก ื’ืœื™ื™ืš ืงืึทื ืขืงืฅ ืฆื• ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก ืก TCP / IP ืึธื ืœื™ื™ื’ืŸ.

ื‘ื™ืœื“ ืคึผืจืึทืคึผืึทื’ื™ื™ืฉืึทืŸ ืื•ืŸ ืกืขืงืจืขืฅ ืžืึทื ืึทื’ืขืžืขื ื˜

ื’ืจืึทืคืขืึทืก

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: grafeas.io
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (ืึทืคึผืึทื˜ืฉื™)

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

Grafeas ืื™ื– ืึทืŸ ืึธืคึฟืŸ ืžืงื•ืจ ืึทืคึผื™ ืคึฟืึทืจ ื•ื•ื™ื™ื›ื•ื•ืืจื’ ืฆื•ืฉื˜ืขืœืŸ ืงื™ื™ื˜ ืึทื“ืึทื˜ื™ื ื’ ืื•ืŸ ืคืึทืจื•ื•ืึทืœื˜ื•ื ื’. ืื•ื™ืฃ ืึท ื™ืงืขืจื“ื™ืง ืžื“ืจื’ื”, Grafeas ืื™ื– ืึท ื’ืขืฆื™ื™ึทื’ ืคึฟืึทืจ ืงืึทืœืขืงื˜ื™ื ื’ ืžืขื˜ืึทื“ืึทื˜ืึท ืื•ืŸ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ืคื™ื™ื ื“ื™ื ื’ื–. ืขืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื ื•ืฆื˜ ืฆื• ืฉืคึผื•ืจ ื”ืขืกืงืขื ืžื™ื˜ ื‘ืขืกื˜ืขืจ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืจืึทืงื˜ื™ืกื™ื– ืื™ืŸ ืึทืŸ ืึธืจื’ืึทื ื™ื–ืึทืฆื™ืข.

ื“ืขื ืกืขื ื˜ืจืึทืœื™ื™ื–ื“ ืžืงื•ืจ ืคื•ืŸ ืืžืช ื”ืขืœืคึผืก ืขื ื˜ืคึฟืขืจืŸ ืฉืืœื•ืช ื•ื•ื™:

  • ื•ื•ืขืจ ื”ืึธื˜ ื’ืขื–ืืžืœื˜ ืื•ืŸ ื’ืขื—ืชืžืขื˜ ืคึฟืึทืจ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ืงืึทื ื˜ื™ื™ื ืขืจ?
  • ื”ืื˜ ืขืก ื“ื•ืจื›ื’ืขื’ืื ื’ืขืŸ ืึทืœืข ื–ื™ื›ืขืจื”ื™ื™ื˜ ืกืงืึทื ื– ืื•ืŸ ื˜ืฉืขืงืก ืคืืจืœืื ื’ื˜ ื“ื•ืจืš ื“ื™ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืึธืœื™ื˜ื™ืง? ื•ื•ืขืŸ? ื•ื•ืืก ื–ืขื ืขืŸ ื’ืขื•ื•ืขืŸ ื“ื™ ืจืขื–ื•ืœื˜ืื˜ืŸ?
  • ื•ื•ืขืจ ื“ื™ืคึผืœื•ื™ื“ ืขืก ืฆื• ืคึผืจืึธื“ื•ืงืฆื™ืข? ื•ื•ืึธืก ืกืคึผืขืฆื™ืคื™ืฉ ืคึผืึทืจืึทืžืขื˜ืขืจืก ื–ืขื ืขืŸ ื’ืขื ื™ืฆื˜ ื‘ืขืฉืึทืก ื“ื™ืคึผืœื•ื™ืžืึทื ื˜?

ืื™ืŸ-ื˜ืึธื˜ืึธ

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: ืื™ืŸ-toto.github.io
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (ืึทืคึผืึทื˜ืฉื™)

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

ืื™ืŸ-ื˜ืึธื˜ืึธ ืื™ื– ืึท ืคืจื™ื™ืžื•ื•ืขืจืง ื“ื™ื–ื™ื™ื ื“ ืฆื• ืฆื•ืฉื˜ืขืœืŸ ืึธืจื ื˜ืœืขื›ืงื™ื™ึทื˜, ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื•ืŸ ืึทื“ืึทื˜ื™ื ื’ ืคื•ืŸ ื“ื™ ื’ืื ืฆืข ื•ื•ื™ื™ื›ื•ื•ืืจื’ ืฆื•ืฉื˜ืขืœืŸ ืงื™ื™ื˜. ื•ื•ืขืŸ ื“ื™ืคึผืœื™ื™ื™ื ื’ In-toto ืื™ืŸ ืึทืŸ ื™ื ืคืจืึทืกื˜ืจืึทืงื˜ืฉืขืจ, ืึท ืคึผืœืึทืŸ ืื™ื– ืขืจืฉื˜ืขืจ ื“ื™ืคื™ื™ื ื“ ื•ื•ืึธืก ื‘ืืฉืจื™ื™ื‘ื˜ ื“ื™ ืคืึทืจืฉื™ื“ืŸ ืกื˜ืขืคึผืก ืื™ืŸ ื“ื™ ืจืขืจื  - ืœื™ื ื™ืข (ืจื™ืคึผืึทื–ืึทื˜ืึธืจื™, CI / CD ืžื›ืฉื™ืจื™ื, QA ืžื›ืฉื™ืจื™ื, ืึทืจื˜ืึทืคืึทืงื˜ ืงืึทืœืขืงื˜ืขืจื–, ืืื–"ื• ื•) ืื•ืŸ ื“ื™ ื™ื•ื–ืขืจื– (ืคืึทืจืึทื ื˜ื•ื•ืึธืจื˜ืœืขืš ืžืขื ื˜ืฉืŸ) ื•ื•ืึธืก ื–ืขื ืขืŸ ืขืจืœื•ื™ื‘ื˜ ืฆื• ื ื•ืฆืŸ. ืึธื ื”ื™ื™ื‘ืŸ ื–ื™ื™.

ืื™ืŸ-ื˜ืึธื˜ืึธ ืžืึธื ื™ื˜ืึธืจืก ื“ื™ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ื“ืขื ืคึผืœืึทืŸ, ื•ื•ืขืจืึทืคื™ื™ื™ื ื’ ืึทื– ื™ืขื“ืขืจ ืึทืจื‘ืขื˜ ืื™ืŸ ื“ืขืจ ืงื™ื™ื˜ ืื™ื– ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืจืขื›ื˜ ื‘ืœื•ื™ื– ื“ื•ืจืš ืึธื˜ืขืจื™ื™ื–ื“ ืคึผืขืจืกืึทื ืขืœ ืื•ืŸ ืึทื– ืงื™ื™ืŸ ืึทื ืึธื˜ืขืจื™ื™ื–ื“ ืžืึทื ื™ืคึผื™ืึทืœื™ื™ืฉืึทื ื– ื–ืขื ืขืŸ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืžื™ื˜ ื“ื™ ืคึผืจืึธื“ื•ืงื˜ ื‘ืขืฉืึทืก ื‘ืึทื•ื•ืขื’ื•ื ื’.

Portieris

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: github.com/IBM/portieris
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (ืึทืคึผืึทื˜ืฉื™)

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

Portieris ืื™ื– ืึท ืึทืจื™ื™ึทื ื˜ืจืขื˜ืŸ ืงืึธื ื˜ืจืึธืœืœืขืจ ืคึฟืึทืจ Kubernetes; ื’ืขื ื™ืฆื˜ ืฆื• ื“ื•ืจื›ืคื™ืจืŸ ืื™ื ื”ืึทืœื˜ ืฆื•ื˜ืจื•ื™ ื˜ืฉืขืงืก. Portieris ื ื™ืฆื˜ ืึท ืกืขืจื•ื•ืขืจ ื ืึธื•ื˜ืขืจื™ (ืžื™ืจ ื”ืึธื‘ืŸ ื’ืขืฉืจื™ื‘ืŸ ื•ื•ืขื’ืŸ ืื™ื ืื™ืŸ ื“ื™ ืกื•ืฃ ื“ื™ ืืจื˜ื™ืงืœ - ืึทืคึผืคึผืจืึธืงืก. ืื™ื‘ืขืจื–ืขืฆื•ื ื’) ื•ื•ื™ ืึท ืžืงื•ืจ ืคื•ืŸ ืืžืช ืฆื• ื•ื•ืึทืœืึทื“ื™ื™ื˜ ื˜ืจืึทืกื˜ื™ื“ ืื•ืŸ ื’ืขื—ืชืžืขื˜ ืึทืจื˜ืึทืคืึทืงืฅ (ื“"ื” ื‘ืื•ื•ื™ืœื™ืงื˜ ืงืึทื ื˜ื™ื™ื ืขืจ ื‘ื™ืœื“ืขืจ).

ื•ื•ืขืŸ ืึท ื•ื•ืขืจืงืœืึธื•ื“ ืื™ื– ื‘ืืฉืืคืŸ ืึธื“ืขืจ ืžืึทื“ืึทืคื™ื™ื“ ืื™ืŸ Kubernetes, Portieris ื“ืึทื•ื ืœืึธื•ื“ื– ื“ื™ ืกื™ื™ื ื™ื ื’ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืื•ืŸ ืื™ื ื”ืึทืœื˜ ืฆื•ื˜ืจื•ื™ ืคึผืึธืœื™ื˜ื™ืง ืคึฟืึทืจ ื“ื™ ื’ืขื‘ืขื˜ืŸ ืงืึทื ื˜ื™ื™ื ืขืจ ื‘ื™ืœื“ืขืจ ืื•ืŸ, ืื•ื™ื‘ ื ื™ื™ื˜ื™ืง, ืžืื›ื˜ ืขื ื“ืขืจื•ื ื’ืขืŸ ืื™ืŸ ื“ื™ JSON API ื›ื™ื™ืคืขืฅ ืฆื• ืœื•ื™ืคืŸ ื’ืขื—ืชืžืขื˜ ื•ื•ืขืจืกื™ืขืก ืคื•ืŸ ื“ื™ ื‘ื™ืœื“ืขืจ.

Vault

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: www.vaultproject.io
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (MPL)

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

Vault ืื™ื– ืึท ื–ื™ื›ืขืจ ืœื™ื™ื–ื•ื ื’ ืคึฟืึทืจ ืกื˜ืึธืจื™ื ื’ ืคึผืจื™ื•ื•ืึทื˜ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข: ืคึผืึทืกื•ื•ืขืจื“ื–, OAuth ื˜ืึธืงืขื ืก, PKI ืกืขืจื˜ื™ืคื™ืงืึทืฅ, ืึทืงืกืขืก ืึทืงืึทื•ื ืฅ, Kubernetes ืกื™ืงืจื™ืฅ, ืขื˜ืง. ื•ื•ืึธืœื˜ ืฉื˜ื™ืฆื˜ ืคื™ืœืข ืึทื•ื•ืึทื ืกื™ืจื˜ืข ืคึฟืขื™ึดืงื™ื™ื˜ืŸ, ืึทื–ืึท ื•ื•ื™ ืœื™ืกื™ื ื’ ื™ืคืขืžืขืจืึทืœ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื˜ืึธืงืขื ืก ืึธื“ืขืจ ืึธืจื’ืึทื ื™ื™ื–ื™ื ื’ ืฉืœื™ืกืœ ืจืึธื•ื˜ื™ื™ืฉืึทืŸ.

ืžื™ื˜ ื“ื™ ื”ืขืœื ื˜ืฉืึทืจื˜, Vault ืงืขื ืขืŸ ื–ื™ื™ืŸ ื“ื™ืคึผืœื•ื™ื“ ื•ื•ื™ ืึท ื ื™ื™ึทืข ื“ื™ืคึผืœื•ื™ืžืึทื ื˜ ืื™ืŸ ืึท Kubernetes ืงื ื•ื™ืœ ืžื™ื˜ ืงืึธื ืกื•ืœ ื•ื•ื™ ื‘ืึทืงืขื ื“ ืกื˜ืึธืจื™ื“ื–ืฉ. ืขืก ืฉื˜ื™ืฆื˜ ื’ืขื‘ื•ื™ืจืŸ Kubernetes ืจืขืกื•ืจืกืŸ ื•ื•ื™ ServiceAccount ื˜ืึธืงืขื ืก ืื•ืŸ ืงืขื ืขืŸ ืืคื™ืœื• ืฉืคึผื™ืœืŸ ื•ื•ื™ ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืงืจืึธื ืคึฟืึทืจ Kubernetes ืกื™ืงืจื™ืฅ.

ื ืื˜ื™ืฅ. ื˜ืจืึทื ืกืœ.: ื“ื•ืจืš ื“ืขื ื•ื•ืขื’, ื ืึธืจ ื ืขื›ื˜ืŸ ื“ื™ ืคื™ืจืžืข HashiCorp, ื•ื•ืึธืก ื“ืขื•ื•ืขืœืึธืคึผืก ื•ื•ืึธืœื˜, ืžื•ื“ื™ืข ืขื˜ืœืขื›ืข ื™ืžืคึผืจื•ื•ื•ืžืึทื ืฅ ืคึฟืึทืจ ื ื™ืฆืŸ ื•ื•ืึธืœื˜ ืื™ืŸ ืงื•ื‘ืขืจื ืขื˜ืขืก ืื•ืŸ ืกืคึผืขืฆื™ืขืœ ื–ื™ื™ ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ื“ื™ ื”ืขืœื ื˜ืฉืึทืจื˜. ืœื™ื™ืขื ืขืŸ ืžืขืจ ืื™ืŸ ื“ืขื•ื•ืขืœืึธืคึผืขืจ ื‘ืœืึธื’.

Kubernetes Security Audit

ืงื•ื‘ืข-ื‘ืึทื ืง

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: github.com/aquasecurity/kube-bench
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (ืึทืคึผืึทื˜ืฉื™)

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

Kube-bench ืื™ื– ืึท Go ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืึทื– ื˜ืฉืขืงืก ืฆื™ Kubernetes ืื™ื– ืกื™ืงื™ื•ืจืœื™ ื“ื™ืคึผืœื•ื™ื“ ื“ื•ืจืš ืคืœื™ืกื ื“ื™ืง ื˜ืขืกืฅ ืคึฟื•ืŸ ืึท ืจืฉื™ืžื” ืกื™ืก ืงื•ื‘ืขืจื ืขื˜ืขืก ื‘ืขื ื˜ืฉืžืึทืจืง.

Kube-Bench ื–ื•ื›ื˜ ืคึฟืึทืจ ื™ื ืกืึทืงื™ืขืจ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืกืขื˜ื˜ื™ื ื’ืก ืฆื•ื•ื™ืฉืŸ ืงื ื•ื™ืœ ืงืึทืžืคึผืึธื•ื ืึทื ืฅ (ืขื˜ืง, API, ืงืึธื ื˜ืจืึธืœืœืขืจ ืคืึทืจื•ื•ืึทืœื˜ืขืจ, ืืื–"ื• ื•), ืคึผืจืึธื‘ืœืขืžืึทื˜ื™ืฉ ื˜ืขืงืข ืึทืงืกืขืก ืจืขื›ื˜, ืึทื ืคึผืจืึทื˜ืขืงื˜ื™ื“ ืึทืงืึทื•ื ืฅ ืึธื“ืขืจ ืขืคืขื ืขืŸ ืคึผืึธืจืฅ, ืžื™ื˜ืœ ืงื•ื•ืึธื˜ืึทืก, ืกืขื˜ื˜ื™ื ื’ืก ืคึฟืึทืจ ืœื™ืžื™ื˜ื™ื ื’ ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ืึทืคึผื™ ืงืึทืœืœืก ืฆื• ื‘ืึทืฉื™ืฆืŸ ืงืขื’ืŸ ื“ืึธืก ืื ืคืืœืŸ ืืื–"ื• ื•

ืงื•ื‘ืข-ื™ืขื’ืขืจ

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: github.com/aquasecurity/kube-hunter
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (ืึทืคึผืึทื˜ืฉื™)

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

Kube-Hunter ื›ืึทื ืฅ ืคึฟืึทืจ ืคึผืึธื˜ืขื ืฆื™ืขืœ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– (ืึทื–ืึท ื•ื•ื™ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ื•ื•ื™ื™ึทื˜ ืงืึธื“ ืึธื“ืขืจ ืึทื ื˜ืคึผืœืขืงื•ื ื’ ืคื•ืŸ ื“ืึทื˜ืŸ) ืื™ืŸ Kubernetes ืงืœืึทืกื˜ืขืจื–. Kube-Hunter ืงืขื ืขืŸ ื–ื™ื™ืŸ ืœื•ื™ืคืŸ ื•ื•ื™ ืึท ื•ื•ื™ื™ึทื˜ ืกืงืึทื ืขืจ - ืื™ืŸ ื•ื•ืึธืก ืคืึทืœ ืขืก ื•ื•ืขื˜ ืึธืคึผืฉืึทืฆืŸ ื“ืขื ืงื ื•ื™ืœ ืคึฟื•ืŸ ื“ื™ ืคื•ื ื˜ ืคื•ืŸ ืžื™ื™ื ื•ื ื’ ืคื•ืŸ ืึท ื“ืจื™ื˜-ืคึผืึทืจื˜ื™ื™ ืึทื˜ืึทืงืขืจ - ืึธื“ืขืจ ื•ื•ื™ ืึท ืคึผืึธื“ ื™ืŸ ื“ืขืจ ืงื ื•ื™ืœ.

ื ืึธืคึผืฉื™ื™ื“ื ื“ื™ืง ืฉื˜ืจื™ืš ืคื•ืŸ Kube-Hunter ืื™ื– ื–ื™ื™ืŸ "ืึทืงื˜ื™ื•ื• ื’ื™ื™ืขื’" ืžืึธื“ืข, ื‘ืขืฉืึทืก ื•ื•ืึธืก ืขืก ื ื™ื˜ ื‘ืœื•ื™ื– ืจื™ืคึผืึธืจืฅ ืคึผืจืึธื‘ืœืขืžืก, ืึธื‘ืขืจ ืื•ื™ืš ืคืจื•ื•ื•ื˜ ืฆื• ื ื•ืฆืŸ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื“ื™ืกืงืึทื•ื•ืขืจื“ ืื™ืŸ ื“ื™ ืฆื™ืœ ืงื ื•ื™ืœ ื•ื•ืึธืก ืงืขืŸ ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ืฉืึทื˜ืŸ ื–ื™ื™ืŸ ืึธืคึผืขืจืึทืฆื™ืข. ืึทื–ื•ื™ ื ื•ืฆืŸ ืžื™ื˜ ื•ื•ืึธืจืขื ืขืŸ!

ืงื•ื‘ืขืึทื•ื“ื™ื˜

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: github.com/Shopify/kubeaudit
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (MIT)

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

Kubeaudit ืื™ื– ืึท ืงืึทื ืกืึธื•ืœ ื’ืขืฆื™ื™ึทื’ ืขืจื™ื“ื–ืฉื ืึทืœื™ ื“ืขื•ื•ืขืœืึธืคึผืขื“ ื‘ื™ื™ Shopify ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ Kubernetes ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืคึฟืึทืจ ืคืึทืจืฉื™ื“ืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื™ืฉื•ื–. ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ืขืก ื”ืขืœืคึผืก ืฆื• ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ืงืึทื ื˜ื™ื™ื ืขืจื– ืคืœื™ืกื ื“ื™ืง ืึทื ืจื™ืกื˜ืจื™ืงื˜ื™ื“, ืคืœื™ืกื ื“ื™ืง ื•ื•ื™ ื•ื•ืึธืจืฆืœ, ืึทื‘ื™ื•ื–ื™ื ื’ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ืึธื“ืขืจ ื ื™ืฆืŸ ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืกืขืจื•ื•ื™ืก ืึทืงืึทื•ื ื˜.

Kubeaudit ื”ืื˜ ืื ื“ืขืจืข ื˜ืฉื™ืงืึทื•ื•ืข ืคึฟืขื™ึดืงื™ื™ื˜ืŸ. ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ืขืก ืงืขื ืขืŸ ืคื•ื ืึทื ื“ืขืจืงืœื™ื™ึทื‘ืŸ ื”ื™ื’ืข YAML ื˜ืขืงืขืก, ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืคืœืึธื– ื•ื•ืึธืก ืงืขืŸ ืคื™ืจืŸ ืฆื• ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืจืึธื‘ืœืขืžืก ืื•ืŸ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืคืึทืจืจื™ื›ื˜ืŸ ื–ื™ื™.

ืงื•ื‘ืขืกืขืง

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: kubesec.io
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (ืึทืคึผืึทื˜ืฉื™)

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

Kubesec ืื™ื– ืึท ืกืคึผืขืฆื™ืขืœ ื’ืขืฆื™ื™ึทื’ ืื™ืŸ ื•ื•ืึธืก ืขืก ืกืงืึทื ื– ื’ืœื™ื™ืš YAML ื˜ืขืงืขืก ื•ื•ืึธืก ื‘ืึทืฉืจื™ื™ึทื‘ืŸ Kubernetes ืจืขืกื•ืจืกืŸ, ืื™ืจ ื–ื•ื›ื˜ ืคึฟืึทืจ ืฉื•ื•ืึทืš ืคึผืึทืจืึทืžืขื˜ืขืจืก ื•ื•ืึธืก ืงืขืŸ ื•ื•ื™ืจืงืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜.

ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ืขืก ืงืขื ืขืŸ ื“ืขื˜ืขืงื˜ ื™ื‘ืขืจื™ืง ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ืื•ืŸ ืคึผืขืจืžื™ืฉืึทื ื– ื’ืขื’ืขื‘ืŸ ืฆื• ืึท ืคึผืึธื“, ืœื•ื™ืคืŸ ืึท ืงืึทื ื˜ื™ื™ื ืขืจ ืžื™ื˜ ื•ื•ืึธืจืฆืœ ื•ื•ื™ ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ื‘ืึทื ื™ืฆืขืจ, ืงืึทื ืขืงื˜ื™ื ื’ ืฆื• ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก ืก ื ืขืฅ ื ืึธืžืขืŸ ืคึผืœืึทืฅ ืึธื“ืขืจ ื’ืขืคืขืจืœืขืš ืžืึทื•ื ืฅ ื•ื•ื™ /proc ื‘ืึทืœืขื‘ืึธืก ืึธื“ืขืจ ื“ืึธืงืงืขืจ ื›ืึธืœืขืœ. ืืŸ ืื ื“ืขืจ ื˜ืฉื™ืงืึทื•ื•ืข ืฉื˜ืจื™ืš ืคื•ืŸ Kubesec ืื™ื– ื“ื™ ื“ืขืžืึธ ื“ื™ื ืกื˜ ื‘ื ื™ืžืฆื ืึธื ืœื™ื™ืŸ, ืื™ืŸ ื•ื•ืึธืก ืื™ืจ ืงืขื ืขืŸ ืฆื•ืคึฟืขืœื™ืงืขืจ YAML ืื•ืŸ ื’ืœื™ื™ืš ืึทื ืึทืœื™ื™ื– ืขืก.

ืขืคึฟืŸ ืคึผืึธืœื™ื˜ื™ืง ืึทื’ืขื ื˜

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: www.openpolicyagent.org
  • ืœื™ืกืขื ืกืข: ืคืจื™ื™ (ืึทืคึผืึทื˜ืฉื™)

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

ื“ืขืจ ื‘ืึทื’ืจื™ืฃ ืคื•ืŸ ืึธืคึผืึท (ืขืคึฟืŸ ืคึผืึธืœื™ื˜ื™ืง ืึทื’ืขื ื˜) ืื™ื– ืฆื• ื“ื™ืงืึธื•ืคึผื•ืœ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืึทืœืึทืกื™ื– ืื•ืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื‘ืขืกื˜ืขืจ ืคึผืจืึทืงื˜ื™ืกื™ื– ืคื•ืŸ ืึท ืกืคึผืขืฆื™ืคื™ืฉ ืจื•ื ื˜ื™ืžืข ืคึผืœืึทื˜ืคืึธืจืžืข: ื“ืึธืงืงืขืจ, ืงื•ื‘ืขืจื ืขื˜ืขืก, ืžืขืกืึธืกืคืขืจืข, ืึธืคึผืขื ืฉื™ืคื˜, ืึธื“ืขืจ ืงื™ื™ืŸ ืงืึธืžื‘ื™ื ืึทืฆื™ืข ื“ืขืจืคื•ืŸ.

ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ืื™ืจ ืงืขื ืขืŸ ืฆืขื•ื•ื™ืงืœืขืŸ OPA ื•ื•ื™ ืึท ื‘ืึทืงืขื ื“ ืคึฟืึทืจ ื“ื™ Kubernetes ืึทืจื™ื™ึทื ื˜ืจืขื˜ืŸ ืงืึธื ื˜ืจืึธืœืœืขืจ, ื“ืขืœืึทื’ื™ื™ื˜ื™ื ื’ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื“ื™ืกื™ื–ืฉืึทื ื– ืฆื• ืขืก. ื“ืขืจ ื•ื•ืขื’, ื“ื™ OPA ืึทื’ืขื ื˜ ืงืขื ืขืŸ ื•ื•ืึทืœืึทื“ื™ื™ื˜, ืึธืคึผื•ื•ืึทืจืคืŸ ืื•ืŸ ืืคื™ืœื• ืžืึธื“ื™ืคื™ืฆื™ืจืŸ ืจื™ืงื•ื•ืขืก ืื•ื™ืฃ ื“ื™ ืคืœื™ืขืŸ, ืื•ืŸ ื™ื ืฉื•ืจื™ื ื’ ืึทื– ื“ื™ ืกืคึผืขืกื™ืคื™ืขื“ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืึทืจืึทืžืขื˜ืขืจืก ื–ืขื ืขืŸ ื‘ืื’ืขื’ื ื˜. OPA ืก ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืึทืœืึทืกื™ื– ื–ืขื ืขืŸ ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ ื–ื™ื™ึทืŸ ืคึผืจืึทืคึผืจื™ื™ืึทื˜ืขืจื™ DSL ืฉืคึผืจืึทืš, Rego.

ื ืื˜ื™ืฅ. ื˜ืจืึทื ืกืœ.: ืžื™ืจ ื’ืขืฉืจื™ื‘ืŸ ืžืขืจ ื•ื•ืขื’ืŸ OPA (ืื•ืŸ SPIFFE) ืื™ืŸ ื“ืขื ืžืึทื˜ืขืจื™ืึทืœ.

ืคื•ืœืฉื˜ืขื ื“ื™ืง ื’ืขืฉืขืคื˜ ืžื›ืฉื™ืจื™ื ืคึฟืึทืจ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืึทื ืึทืœื™ืกื™ืก

ืžื™ืจ ื‘ืึทืฉืœืึธืกืŸ ืฆื• ืฉืึทืคึฟืŸ ืึท ื‘ืึทื–ื•ื ื“ืขืจ ืงืึทื˜ืขื’ืึธืจื™ืข ืคึฟืึทืจ ื’ืขืฉืขืคื˜ ืคึผืœืึทื˜ืคืึธืจืžืก ื•ื•ื™ื™ึทืœ ื–ื™ื™ ื˜ื™ืคึผื™ืงืœื™ ื“ืขืงืŸ ืงื™ื™ืคืœ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื’ืขื‘ื™ื˜ืŸ. ื ื’ืขื ืขืจืึทืœ ื’ืขื“ืึทื ืง ืคื•ืŸ ื–ื™ื™ืขืจ ืงื™ื™ืคึผืึทื‘ื™ืœืึทื˜ื™ื– ืงืขื ืขืŸ ื–ื™ื™ืŸ ื‘ืืงื•ืžืขืŸ ืคื•ืŸ ื“ื™ ื˜ื™ืฉ:

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื
* ืึทื•ื•ืึทื ืกื™ืจื˜ืข ื“ื•ืจื›ืงื•ืง ืื•ืŸ ืคึผืึธืกื˜-ืžืึธืจื˜ืขื ืึทื ืึทืœื™ืกื™ืก ืžื™ื˜ ื’ืึทื ืฅ ืกื™ืกื˜ืขื ืจื•ืคืŸ ื›ื™ื™ื“ื–ืฉืึทืงื™ื ื’.

ืึทืงื•ื•ืึท ื–ื™ื›ืขืจื”ื™ื™ึทื˜

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: www.aquasec.com
  • ืœื™ืกืขื ืกืข: ื’ืขืฉืขืคื˜

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

ื“ืขื ื’ืขืฉืขืคื˜ ื’ืขืฆื™ื™ึทื’ ืื™ื– ื“ื™ื–ื™ื™ื ื“ ืคึฟืึทืจ ืงืึทื ื˜ื™ื™ื ืขืจื– ืื•ืŸ ื•ื•ืึธืœืงืŸ ื•ื•ืขืจืงืœืึธื•ื“ื–. ืขืก ื’ื™ื˜:

  • ื‘ื™ืœื“ ืกืงืึทื ื™ื ื’ ื™ื ืึทื’ืจื™ื™ื˜ื™ื“ ืžื™ื˜ ืึท ืงืึทื ื˜ื™ื™ื ืขืจ ืจืขื’ื™ืกื˜ืจื™ ืึธื“ืขืจ ืกื™ / ืกื™ ืจืขืจื  - ืœื™ื ื™ืข;
  • ืจื•ื ื˜ื™ืžืข ืฉื•ืฅ ืžื™ื˜ ื–ื•ื›ืŸ ืคึฟืึทืจ ืขื ื“ืขืจื•ื ื’ืขืŸ ืื™ืŸ ืงืึทื ื˜ื™ื™ื ืขืจื– ืื•ืŸ ืื ื“ืขืจืข ืกืึทืกืคึผื™ืฉืึทืก ืึทืงื˜ื™ื•ื•ื™ื˜ืขื˜ืŸ;
  • ืงืึทื ื˜ื™ื™ื ืขืจ-ื’ืขื‘ื•ื™ืจืŸ ืคื™ื™ืจื•ื•ืึทืœ;
  • ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึฟืึทืจ ืกืขืจื•ื•ืขืจืœืขืกืก ืื™ืŸ ื•ื•ืึธืœืงืŸ ื‘ืึทื“ื™ื ื•ื ื’ืก;
  • ืงืึธืžืคึผืœื™ืึทื ืกืข ื˜ืขืกื˜ื™ื ื’ ืื•ืŸ ืึทื“ืึทื˜ื™ื ื’ ืงืึทืžื‘ื™ื™ื ื“ ืžื™ื˜ ื’ืขืฉืขืขื ื™ืฉ ืœืึธื’ื™ื ื’.

ื ืื˜ื™ืฅ. ื˜ืจืึทื ืกืœ.: ืขืก ืื™ื– ืื•ื™ืš ื›ื“ืื™ ืฆื• ื‘ืืžืขืจืงืŸ ืึทื– ืขืก ื–ืขื ืขืŸ ืคึผืึธื˜ืขืจ ืงืึธืžืคึผืึธื ืขื ื˜ ืคื•ืŸ ื“ื™ ืคึผืจืึธื“ื•ืงื˜ ื’ืขืจื•ืคืŸ ืžื™ืงืจืึธืกืงืึทื ืขืจ, ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื™ื‘ืขืจืงื•ืงืŸ ืงืึทื ื˜ื™ื™ื ืขืจ ื‘ื™ืœื“ืขืจ ืคึฟืึทืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–. ื ืคืึทืจื’ืœื™ื™ึทืš ืคื•ืŸ ื–ื™ื™ึทืŸ ืงื™ื™ืคึผืึทื‘ื™ืœืึทื˜ื™ื– ืžื™ื˜ ื‘ืึทืฆืึธืœื˜ ื•ื•ืขืจืกื™ืขืก ืื™ื– ื“ืขืจืœืื ื’ื˜ ืื™ืŸ ื“ืขื ื˜ื™ืฉ.

ืงืึทืคึผืกืœ 8

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: capsule8.com
  • ืœื™ืกืขื ืกืข: ื’ืขืฉืขืคื˜

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื
Capsule8 ื™ื ื˜ืึทื’ืจื™ื™ืฅ ืื™ืŸ ื“ื™ ื™ื ืคืจืึทืกื˜ืจืึทืงื˜ืฉืขืจ ื“ื•ืจืš ื™ื ืกื˜ืึธืœื™ื ื’ ื“ื™ ื“ืขื˜ืขืงื˜ืึธืจ ืื•ื™ืฃ ืึท ื”ื™ื’ืข ืึธื“ืขืจ ื•ื•ืึธืœืงืŸ Kubernetes ืงื ื•ื™ืœ. ื“ืขืจ ื“ืขื˜ืขืงื˜ืึธืจ ืงืึทืœืขืงืฅ ื‘ืึทืœืขื‘ืึธืก ืื•ืŸ ื ืขืฅ ื˜ืขืœืขืžืขื˜ืจื™, ืงืึธืจืึทืœื™ื™ื˜ื™ื ื’ ืขืก ืžื™ื˜ ืคืึทืจืฉื™ื“ืขื ืข ื˜ื™ื™ืคึผืก ืคื•ืŸ ืื ืคืืœืŸ.

ื“ื™ ืงืึทืคึผืกื•ืœืข8 ืžืึทื ืฉืึทืคึฟื˜ ื–ืขื˜ ื–ื™ื™ืŸ ืึทืจื‘ืขื˜ ื•ื•ื™ ืคืจื™ ื“ื™ื˜ืขืงืฉืึทืŸ ืื•ืŸ ืคืึทืจื”ื™ื˜ื•ื ื’ ืคื•ืŸ ืื ืคืืœืŸ ื ื™ืฆืŸ ื ื™ื™ึท (0-ื˜ืึธื’) ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–. Capsule8 ืงืขื ืขืŸ ืืจืืคืงืืคื™ืข ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื˜ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื›ึผืœืœื™ื ื’ืœื™ื™ืš ืฆื• ื“ืขื˜ืขืงื˜ืึธืจืก ืื™ืŸ ืขื ื˜ืคืขืจ ืฆื• ื ื™ื™ ื“ื™ืกืงืึทื•ื•ืขืจื“ ื˜ืจืขืฅ ืื•ืŸ ื•ื•ื™ื™ื›ื•ื•ืืจื’ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–.

ืงืึทื•ื•ื™ืจื™ืŸ

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: www.cavirin.com
  • ืœื™ืกืขื ืกืข: ื’ืขืฉืขืคื˜

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

ืงืึทื•ื•ื™ืจื™ืŸ ืืงื˜ืŸ ื•ื•ื™ ืึท ืคื™ืจืžืข-ื–ื™ื™ึทื˜ ืงืึธื ื˜ืจืึทืงื˜ืึธืจ ืคึฟืึทืจ ืคืึทืจืฉื™ื“ืŸ ื™ื™ื“ื–ืฉืึทื ืกื™ื– ื™ื ื•ื•ืึทืœื•ื•ื“ ืื™ืŸ ื–ื™ื›ืขืจืงื™ื™ึทื˜ ืกื˜ืึทื ื“ืึทืจื“ืก. ื ื™ื˜ ื‘ืœื•ื™ื– ืงืขื ืขืŸ ืขืก ื™ื‘ืขืจืงื•ืงืŸ ื‘ื™ืœื“ืขืจ, ืึธื‘ืขืจ ืขืก ืงืขื ืขืŸ ืื•ื™ืš ื•ื™ืกืฉื˜ื™ืžืขืŸ ืื™ืŸ ื“ื™ ืกื™ / ืกื™ ืจืขืจื  - ืœื™ื ื™ืข, ื‘ืœืึทืงื™ื ื’ ื ื™ื˜-ื ืึธืจืžืึทืœ ื‘ื™ืœื“ืขืจ ืื™ื™ื“ืขืจ ื–ื™ื™ ืึทืจื™ื™ึทืŸ ืคืืจืžืื›ื˜ ืจื™ืคึผืึทื–ืึทื˜ืึธืจื™ื–.

ื“ื™ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืกื•ื•ื™ื˜ ืคื•ืŸ Cavirin ื ื™ืฆื˜ ืžืึทืฉื™ืŸ ืœืขืจื ืขืŸ ืฆื• ืึทืกืกืขืกืก ื“ื™ื™ืŸ ืกื™ื™ื‘ืขืจืกืขืงื•ืจื™ื˜ื™ ื”ืึทืœื˜ื  ื–ื™ืš, ืื•ืŸ ืึธืคืคืขืจืก ืขืฆื•ืช ืฆื• ืคึฟืึทืจื‘ืขืกืขืจืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืื•ืŸ ืคึฟืึทืจื‘ืขืกืขืจืŸ ื”ืขืกืงืขื ืžื™ื˜ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืกื˜ืึทื ื“ืึทืจื“ืก.

Google Cloud Security Command Center

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

ืงืœืึธื•ื“ ืกืขืงื•ืจื™ื˜ื™ ืงืึทืžืึทื ื“ ืฆืขื ื˜ืขืจ ื”ืขืœืคึผืก ื–ื™ื›ืขืจื”ื™ื™ื˜ ื˜ื™ืžื– ืฆื• ื–ืึทืžืœืขืŸ ื“ืึทื˜ืŸ, ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ื˜ืจืขืฅ ืื•ืŸ ืขืœื™ืžื™ื ื™ืจืŸ ื–ื™ื™ ืื™ื™ื“ืขืจ ื–ื™ื™ ืฉืึทื˜ืŸ ื“ื™ ืคื™ืจืžืข.

ื•ื•ื™ ื“ืขืจ ื ืึธืžืขืŸ ืกืึทื’ื“ื–ืฉืขืก, Google Cloud SCC ืื™ื– ืึท ื™ื•ื ืึทืคื™ื™ื“ ืงืึธื ื˜ืจืึธืœ ื˜ืึทืคืœื™ืข ื•ื•ืึธืก ืงืขื ืขืŸ ื•ื™ืกืฉื˜ื™ืžืขืŸ ืื•ืŸ ืคื™ืจืŸ ืึท ืคืึทืจืฉื™ื™ื“ื ืงื™ื™ึทื˜ ืคื•ืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืจื™ืคึผืึธืจืฅ, ืึทืกืขื˜ ืึทืงืึทื•ื ื˜ื™ื ื’ ืขื ื“ื–ืฉืึทื ื– ืื•ืŸ ื“ืจื™ื˜-ืคึผืึทืจื˜ื™ื™ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืกื™ืกื˜ืขืžืขืŸ ืคึฟื•ืŸ ืื™ื™ืŸ, ืกืขื ื˜ืจืึทืœื™ื™ื–ื“ ืžืงื•ืจ.

ื“ื™ ื™ื ื˜ืขืจืึธืคึผืขืจืึทื‘ืœืข ืึทืคึผื™ ื’ืขืคึฟื™ื ื˜ ื“ื•ืจืš Google Cloud SCC ืžืื›ื˜ ืขืก ื’ืจื™ื ื’ ืฆื• ื•ื™ืกืฉื˜ื™ืžืขืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื’ืขืฉืขืขื ื™ืฉืŸ ื•ื•ืึธืก ืงื•ืžืขืŸ ืคึฟื•ืŸ ืคืึทืจืฉื™ื“ืŸ ืงื•ื•ืืœืŸ, ืึทื–ืึท ื•ื•ื™ Sysdig Secure (container ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึฟืึทืจ ื•ื•ืึธืœืงืŸ ื’ืขื‘ื•ื™ืจืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื–) ืึธื“ืขืจ Falco (Open Source ืจื•ื ื˜ื™ืžืข ื–ื™ื›ืขืจื”ื™ื™ื˜).

Layered Insight (Qualys)

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: layeredinsight.com
  • ืœื™ืกืขื ืกืข: ื’ืขืฉืขืคื˜

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

Layered Insight (ืื™ืฆื˜ ื˜ื™ื™ืœ ืคื•ืŸ Qualys Inc) ืื™ื– ื’ืขื‘ื•ื™ื˜ ืื•ื™ืฃ ื“ืขืจ ื‘ืึทื’ืจื™ืฃ ืคื•ืŸ "ืขืžื‘ืขื“ื™ื“ ื–ื™ื›ืขืจื”ื™ื™ื˜." ื ืึธืš ืกืงืึทื ื™ื ื’ ื“ืขืจ ืึธืจื™ื’ื™ื ืขืœ ื‘ื™ืœื“ ืคึฟืึทืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื ื™ืฆืŸ ืกื˜ืึทื˜ื™ืกื˜ื™ืฉ ืึทื ืึทืœื™ืกื™ืก ืื•ืŸ CVE ื˜ืฉืขืงืก, Layered Insight ืจื™ืคึผืœื™ื™ืกื™ื– ืขืก ืžื™ื˜ ืึท ื™ื ืกื˜ืจื•ืžืขื ื˜ืขื“ ื‘ื™ืœื“ ื•ื•ืึธืก ื›ื•ืœืœ ื“ื™ ืึทื’ืขื ื˜ ื•ื•ื™ ืึท ื‘ื™ื™ื ืขืจื™.

ื“ืขืจ ืึทื’ืขื ื˜ ื›ึผื•ืœืœ ืจื•ื ื˜ื™ืžืข ื–ื™ื›ืขืจื”ื™ื™ื˜ ื˜ืขืกืฅ ืฆื• ืึทื ืึทืœื™ื™ื– ืงืึทื ื˜ื™ื™ื ืขืจ ื ืขืฅ ืคืึทืจืงืขืจ, ื™ / ืึธ ืคืœืึธื•ื– ืื•ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืึทืงื˜ื™ื•ื•ื™ื˜ืขื˜ืŸ. ืื™ืŸ ืึทื“ื™ืฉืึทืŸ, ืขืก ืงืขื ืขืŸ ื“ื•ืจื›ืคื™ืจืŸ ื ืึธืš ื–ื™ื›ืขืจื”ื™ื™ื˜ ื˜ืฉืขืงืก ืกืคึผืขืกื™ืคื™ืขื“ ื“ื•ืจืš ื“ื™ ื™ื ืคืจืึทืกื˜ืจืึทืงื˜ืฉืขืจ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืึธื“ืขืจ DevOps ื˜ื™ืžื–.

NeuVector

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: neuvector.com
  • ืœื™ืกืขื ืกืข: ื’ืขืฉืขืคื˜

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

NeuVector ืงืึธื ื˜ืจืึธืœืก ืงืึทื ื˜ื™ื™ื ืขืจ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืื•ืŸ ื’ื™ื˜ ืจื•ื ื˜ื™ืžืข ืฉื•ืฅ ื“ื•ืจืš ืึทื ืึทืœื™ื™ื–ื™ื ื’ ื ืขืฅ ื˜ืขื˜ื™ืงื™ื™ื˜ ืื•ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ื ืึทื˜ื•ืจ, ืงืจื™ื™ื™ื˜ื™ื ื’ ืึท ื™ื—ื™ื“ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืจืึธืคื™ืœ ืคึฟืึทืจ ื™ืขื“ืขืจ ืงืึทื ื˜ื™ื™ื ืขืจ. ืขืก ืงืขืŸ ืื•ื™ืš ืคืึทืจืฉืคึผืึทืจืŸ ื˜ืจืขืฅ ืื•ื™ืฃ ื–ื™ืš, ื™ื–ืึธืœื™ืจืŸ ืกืึทืกืคึผื™ืฉืึทืก ื˜ืขื˜ื™ืงื™ื™ื˜ ื“ื•ืจืš ื˜ืฉืึทื ื’ื™ื ื’ ื”ื™ื’ืข ืคื™ื™ืจื•ื•ืึทืœ ื›ึผืœืœื™ื.

ื“ื™ ื ืขืฅ ื™ื ืึทื’ืจื™ื™ืฉืึทืŸ ืคื•ืŸ NeuVector, ื‘ืึทื•ื•ื•ืกื˜ ื•ื•ื™ ืกืขืงื•ืจื™ื˜ื™ ืžืขืฉ, ืื™ื– ื˜ื•ื™ื’ืขื•ื•ื“ื™ืง ืคื•ืŸ ื˜ื™ืฃ ืคึผืึทืงืึทื˜ ืึทื ืึทืœื™ืกื™ืก ืื•ืŸ ืฉื™ื›ื˜ืข 7 ืคึฟื™ืœื˜ืจื™ืจื•ื ื’ ืคึฟืึทืจ ืึทืœืข ื ืขืฅ ืงืึทื ืขืงืฉืึทื ื– ืื™ืŸ ื“ื™ ืกืขืจื•ื•ื™ืก ืžืขืฉ.

StackRox

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: www.stackrox.com
  • ืœื™ืกืขื ืกืข: ื’ืขืฉืขืคื˜

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

ื“ื™ ืกื˜ืึทืงืงืจืึธืงืก ืงืึทื ื˜ื™ื™ื ืขืจ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืœืึทื˜ืคืึธืจืžืข ืกื˜ืจื™ื™ื•ื•ื– ืฆื• ื“ืขืงืŸ ื“ื™ ื’ืื ืฆืข ืœืขื‘ืŸ ืคื•ืŸ Kubernetes ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ืื™ืŸ ืึท ืงื ื•ื™ืœ. ื•ื•ื™ ืื ื“ืขืจืข ื’ืขืฉืขืคื˜ ืคึผืœืึทื˜ืคืึธืจืžืก ืื•ื™ืฃ ื“ืขืจ ืจืฉื™ืžื”, StackRox ื“ื–ืฉืขื ืขืจื™ื™ืฅ ืึท ืจื•ื ื˜ื™ืžืข ืคึผืจืึธืคื™ืœ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื‘ืืžืขืจืงื˜ ืงืึทื ื˜ื™ื™ื ืขืจ ื ืึทื˜ื•ืจ ืื•ืŸ ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืจื™ื™ื–ืึทื– ืึท ืฉืจืขืง ืคึฟืึทืจ ื“ื™ื•ื•ื™ื™ื™ืฉืึทื ื–.

ืึทื“ื“ื™ื˜ื™ืึธื ืึทืœืœื™, StackRox ืึทื ืึทืœื™ื–ืขืก Kubernetes ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทื ื– ื ื™ืฆืŸ ื“ื™ Kubernetes CIS ืื•ืŸ ืื ื“ืขืจืข ืจื•ืœื‘ืึธืึธืงืก ืฆื• ืึธืคึผืฉืึทืฆืŸ ื“ื™ ื”ืขืกืงืขื ืคื•ืŸ ืงืึทื ื˜ื™ื™ื ืขืจื–.

Sysdig Secure

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: sysdig.com/products/secure
  • ืœื™ืกืขื ืกืข: ื’ืขืฉืขืคื˜

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

Sysdig Secure ืคึผืจืึทื˜ืขืงืฅ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ืื™ื‘ืขืจ ื“ื™ ื’ืื ืฆืข ืงืึทื ื˜ื™ื™ื ืขืจ ืื•ืŸ Kubernetes ืœื™ื™ืคืกื™ื™ืง. ืขืจ ืกืงืึทื ื– ื‘ื™ืœื“ืขืจ ืงืึทื ื˜ื™ื™ื ืขืจื–, ื’ื™ื˜ ืจื•ื ื˜ื™ืžืข ืฉื•ืฅ ืœื•ื™ื˜ ืฆื• ืžืึทืฉื™ืŸ ืœืขืจื ืขืŸ ื“ืึทื˜ืŸ, ืคึผืขืจืคืึธืจืžื– ืงืจืขื. ืขืงืกืคึผืขืจื˜ื™ื– ืฆื• ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–, ื‘ืœืึทืงืก ื˜ืจืขืฅ, ืžืึธื ื™ื˜ืึธืจืก ื”ืขืกืงืขื ืžื™ื˜ ื’ืขื’ืจื™ื ื“ืขื˜ ืกื˜ืึทื ื“ืึทืจื“ืก ืื•ืŸ ืึทื“ืึทืฅ ืึทืงื˜ื™ื•ื•ื™ื˜ืขื˜ืŸ ืื™ืŸ ืžื™ืงืจืึธ ื‘ืึทื“ื™ื ื•ื ื’ืก.

Sysdig Secure ื™ื ื˜ืึทื’ืจื™ื™ืฅ ืžื™ื˜ ืกื™ / ืงืึธืžืคึผืึทืงื˜ื“ื™ืกืง ืžื›ืฉื™ืจื™ื ืึทื–ืึท ื•ื•ื™ Jenkins ืื•ืŸ ืงืึธื ื˜ืจืึธืœืก ื‘ื™ืœื“ืขืจ ืœืึธื•ื“ื™ื“ ืคึฟื•ืŸ ื“ืึธืงืขืจ ืจืขื’ื™ืกื˜ืจื™ื–, ืคึผืจืขื•ื•ืขื ื˜ื™ื ื’ ื’ืขืคืขืจืœืขืš ื‘ื™ืœื“ืขืจ ืื™ืŸ ืคึผืจืึธื“ื•ืงืฆื™ืข. ืขืก ืื•ื™ืš ื’ื™ื˜ ืคื•ืœืฉื˜ืขื ื“ื™ืง ืจื•ื ื˜ื™ืžืข ื–ื™ื›ืขืจื”ื™ื™ื˜, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜:

  • ML-ื‘ืื–ื™ืจื˜ ืจื•ื ื˜ื™ืžืข ืคึผืจืึธืคื™ืœื™ื ื’ ืื•ืŸ ืึทื ืึทืžืึทืœื™ ื“ื™ื˜ืขืงืฉืึทืŸ;
  • ืจื•ื ื˜ื™ืžืข ืคึผืึทืœืึทืกื™ื– ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ืกื™ืกื˜ืขื ื’ืขืฉืขืขื ื™ืฉืŸ, K8s-audit API, ืฉืœืึธืก ืงื”ืœ ืคึผืจืึทื“ื–ืฉืขืงืก (FIM - ืžืึธื ื™ื˜ืึธืจื™ื ื’ ืคื•ืŸ ื˜ืขืงืข ืึธืจื ื˜ืœืขื›ืงื™ื™ึทื˜; ืงืจื™ืคึผื˜ืึธื“ื–ืฉืึทืงื™ื ื’) ืื•ืŸ ืคืจื™ื™ืžื•ื•ืขืจืง MITER AT&CK;
  • ืขื ื˜ืคืขืจ ืื•ืŸ ื”ืึทื›ืœืึธื˜ืข ืคื•ืŸ โ€‹โ€‹ื™ื ืกืึทื“ืึทื ืฅ.

ื˜ืขื ืึทื‘ืœืข ืงืึทื ื˜ื™ื™ื ืขืจ ื–ื™ื›ืขืจื”ื™ื™ึทื˜

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

ืื™ื™ื“ืขืจ ื“ื™ ืึทื“ื•ื•ืขื ื˜ ืคื•ืŸ ืงืึทื ื˜ื™ื™ื ืขืจื–, Tenable ืื™ื– ื•ื•ื™ื™ื“ืœื™ ื‘ืึทื•ื•ื•ืกื˜ ืื™ืŸ ื“ื™ ืื™ื ื“ื•ืกื˜ืจื™ืข ื•ื•ื™ ื“ื™ ืคื™ืจืžืข ื”ื™ื ื˜ืขืจ Nessus, ืึท ืคืึธืœืงืก ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ื’ื™ื™ืขื’ ืื•ืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืึทื“ืึทื˜ื™ื ื’ ื’ืขืฆื™ื™ึทื’.

Tenable Container Security ืœืขื•ื•ืขืจืึทื“ื–ืฉืึทื– ื“ื™ ืคื™ืจืžืข 'ืก ืงืึธืžืคึผื™ื•ื˜ืขืจ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืขืงืกืคึผืขืจื˜ื™ื– ืฆื• ื•ื™ืกืฉื˜ื™ืžืขืŸ ืึท CI / CD ืจืขืจื  - ืœื™ื ื™ืข ืžื™ื˜ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ื“ืึทื˜ืึทื‘ื™ื™ืกื™ื–, ืกืคึผืขืฉืึทืœื™ื™ื–ื“ ืžืึทืœื•ื•ืึทืจืข ื“ื™ื˜ืขืงืฉืึทืŸ ืคึผืึทืงืึทื“ื–ืฉืึทื– ืื•ืŸ ืจืขืงืึทืžืึทื ื“ื™ื™ืฉืึทื ื– ืคึฟืึทืจ ืจื™ื–ืึทืœื•ื•ื™ื ื’ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื˜ืจืขืฅ.

Twistlock (Palo Alto Networks)

  • ื•ื•ืขื‘ื–ื™ื™ึทื˜ืœ: www.twistlock.com
  • ืœื™ืกืขื ืกืข: ื’ืขืฉืขืคื˜

33+ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื

Twistlock ืคึผืจืึทืžืึธื•ืฅ ื–ื™ืš ื•ื•ื™ ืึท ืคึผืœืึทื˜ืคืึธืจืžืข ืคืึธื•ืงื™ืกื˜ ืื•ื™ืฃ ื•ื•ืึธืœืงืŸ ื‘ืึทื“ื™ื ื•ื ื’ืก ืื•ืŸ ืงืึทื ื˜ื™ื™ื ืขืจื–. Twistlock ืฉื˜ื™ืฆื˜ ืคืึทืจืฉื™ื“ืŸ ื•ื•ืึธืœืงืŸ ืคึผืจืึทื•ื•ื™ื™ื“ืขืจื– (AWS, Azure, GCP), ืงืึทื ื˜ื™ื™ื ืขืจ ืึธืจืงืขืกื˜ืจืึทื˜ืึธืจืก (Kubernetes, Mesospehere, OpenShift, Docker), ืกืขืจื•ื•ืขืจืœืขืกืก ืจื•ื ื˜ื™ืžืข, ืžืขืฉ ืคืจืึทืžืขื•ื•ืึธืจืงืก ืื•ืŸ ืกื™ / ืกื™ ืžื›ืฉื™ืจื™ื.

ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืฆื• ืงืึทื ื•ื•ืขื ืฉืึทื ืึทืœ ืขื ื˜ืขืจืคึผืจื™ื™ื–-ืžื™ื™ื ื•ื ื’ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื˜ืขืงื ื™ืงืก ืึทื–ืึท ื•ื•ื™ ืกื™ / ืกื™ ืจืขืจื  - ืœื™ื ื™ืข ื™ื ื˜ืึทื’ืจื™ื™ืฉืึทืŸ ืึธื“ืขืจ ื‘ื™ืœื“ ืกืงืึทื ื™ื ื’, Twistlock ื ื™ืฆื˜ ืžืึทืฉื™ืŸ ืœืขืจื ืขืŸ ืฆื• ื“ื–ืฉืขื ืขืจื™ื™ื˜ ืงืึทื ื˜ื™ื™ื ืขืจ-ืกืคึผืขืฆื™ืคื™ืฉ ื ืึทื˜ื•ืจืึทืœ ืคึผืึทื˜ืขืจื ื– ืื•ืŸ ื ืขืฅ ื›ึผืœืœื™ื.

ืขื˜ืœืขื›ืข ืžืึธืœ ืฆื•ืจื™ืง, Twistlock ืื™ื– ื’ืขืงื•ื™ืคื˜ ื“ื•ืจืš Palo Alto Networks, ื•ื•ืึธืก ืึธื•ื ื– ื“ื™ Evident.io ืื•ืŸ RedLock ืคึผืจืึทื“ื–ืฉืขืงืก. ืขืก ืื™ื– ื ืึธืš ื ื™ืฉื˜ ื‘ืึทื•ื•ื•ืกื˜ ื•ื•ื™ ืคึผื•ื ืงื˜ ื“ื™ ื“ืจื™ื™ ืคึผืœืึทื˜ืคืึธืจืžืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ื™ื ืึทื’ืจื™ื™ื˜ื™ื“ ืื™ืŸ ืคึผืจื™ืกืžืึท ืคึฟื•ืŸ ืคึผืึทืœืึธ ืึทืœื˜ืึธ.

ื”ื™ืœืฃ ื‘ื•ื™ืขืŸ ื“ืขืจ ื‘ืขืกื˜ืขืจ ืงืึทื˜ืึทืœืึธื’ ืคื•ืŸ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื›ืฉื™ืจื™ื!

ืžื™ืจ ืฉื˜ืจืขื‘ืŸ ืฆื• ืžืึทื›ืŸ ื“ืขื ืงืึทื˜ืึทืœืึธื’ ื•ื•ื™ ืคื•ืœืฉื˜ืขื ื“ื™ืง ื•ื•ื™ ืžืขื’ืœืขืš, ืื•ืŸ ืคึฟืึทืจ ื“ืขื ืžื™ืจ ื“ืึทืจืคึฟืŸ ื“ื™ื™ืŸ ื”ื™ืœืฃ! ืจื•ืฃ ืื•ื ื– (@ืกื™ืกื˜ื™ื“) ืื•ื™ื‘ ืื™ืจ ื”ืึธื˜ ืึท ืงื™ืœ ื’ืขืฆื™ื™ึทื’ ืื™ืŸ ื–ื™ื ืขืŸ ื•ื•ืึธืก ืื™ื– ื•ื•ืขืจื˜ ืฆื• ื™ื ืงืœื•ื–ืฉืึทืŸ ืื™ืŸ ื“ืขืจ ืจืฉื™ืžื”, ืึธื“ืขืจ ืื™ืจ ื’ืขืคึฟื™ื ืขืŸ ืึท ื˜ืขื•ืช / ืึทื•ื˜ื“ื™ื™ื˜ื™ื“ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข.

ืื™ืจ ืงืขื ื˜ ืื•ื™ืš ืึทื‘ืึธื ื™ืจืŸ ืฆื• ืื•ื ื“ื–ืขืจ ื›ื•ื™ื“ืขืฉืœืขืš ื ื•ื–ืœืขื˜ืขืจ ืžื™ื˜ ื ื™ื™ึทืขืก ืคื•ืŸ ื“ื™ ื•ื•ืึธืœืงืŸ-ื’ืขื‘ื•ื™ืจืŸ ื™ืงืึธื•ืกื™ืกื˜ืึทื ืื•ืŸ ืžืขืฉื™ื•ืช ื•ื•ืขื’ืŸ ื˜ืฉื™ืงืึทื•ื•ืข ืคึผืจืึทื“ื–ืฉืขืงืก ืคื•ืŸ ื“ื™ ื•ื•ืขืœื˜ ืคื•ืŸ Kubernetes ื–ื™ื›ืขืจื”ื™ื™ื˜.

ืคึผืก ืคื•ืŸ ืื™ื‘ืขืจื–ืขืฆืขืจ

ืœื™ื™ืขื ืขืŸ ืื•ื™ืš ืื•ื™ืฃ ืื•ื ื“ื–ืขืจ ื‘ืœืึธื’:

ืžืงื•ืจ: www.habr.com

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’