Upgrade to Pro — share decks privately, control downloads, hide ads and more …

乗っ取れKubernetes!!~リスクから学ぶKubernetesセキュリティの考え方~/k...

mochizuki875
November 28, 2024

 乗っ取れKubernetes!!~リスクから学ぶKubernetesセキュリティの考え方~/k8s-risk-and-security

2024/11/28 CloudNative Days Winter 2024
15:20-16:00 Track C
乗っ取れKubernetes!!
~リスクから学ぶKubernetesセキュリティの考え方~

セッション動画
https://event.cloudnativedays.jp/cndw2024/talks/2378

mochizuki875

November 28, 2024
Tweet

More Decks by mochizuki875

Other Decks in Technology

Transcript

  1. "HFOEB ಋೖ ɹຊηογϣϯͷΰʔϧ ɹ,VCFSOFUFTηΩϡϦςΟͷશମ૾ ɹ,VCFSOFUFTηΩϡϦςΟͷϓϥΫςΟε ,VCFSOFUFT΁ͷ߈ܸࣄྫ ɹঢ়گઃఆ ɹ۩ମతͳ߈ܸࣄྫ ɹɹ,VCFSOFUFTΫϥελ΁ͷ৵ೖ 45&1

     ɹɹෆਖ਼ͳϫʔΫϩʔυͷ࡞੒ 45&1  ɹɹ/PEF΁ͷ৵ೖ 45&1  ɹ߈ܸࣄྫͷ෮श ରࡦͷߟ͑ํ ɹ<ରࡦ>,VCFSOFUFTΫϥελ΁ͷ৵ೖ 45&1  ɹ<ରࡦ>ෆਖ਼ͳϫʔΫϩʔυͷ࣮ߦ 45&1  ɹ<ରࡦ>/PEF΁ͷ৵ೖ 45&1  ɹରࡦͷ·ͱΊ ·ͱΊ
  2. "HFOEB ಋೖ ɹຊηογϣϯͷΰʔϧ ɹ,VCFSOFUFTηΩϡϦςΟͷશମ૾ ɹ,VCFSOFUFTηΩϡϦςΟͷϓϥΫςΟε ,VCFSOFUFT΁ͷ߈ܸࣄྫ ɹঢ়گઃఆ ɹ۩ମతͳ߈ܸࣄྫ ɹɹ,VCFSOFUFTΫϥελ΁ͷ৵ೖ 45&1

     ɹɹෆਖ਼ͳϫʔΫϩʔυͷ࡞੒ 45&1  ɹɹ/PEF΁ͷ৵ೖ 45&1  ɹ߈ܸࣄྫͷ෮श ରࡦͷߟ͑ํ ɹ<ରࡦ>,VCFSOFUFTΫϥελ΁ͷ৵ೖ 45&1  ɹ<ରࡦ>ෆਖ਼ͳϫʔΫϩʔυͷ࣮ߦ 45&1  ɹ<ରࡦ>/PEF΁ͷ৵ೖ 45&1  ɹରࡦͷ·ͱΊ ·ͱΊ
  3. ,VCFSOFUFTͷηΩϡϦςΟʹؔ͢ΔϓϥΫςΟε ✅,VCFSOFUFT4FDVSJUZ 0 ff i DJBM  ɹɹIUUQTLVCFSOFUFTJPEPDTDPODFQUTTFDVSJUZ ✅$*4,VCFSOFUFT#FODINBSLT ɹɹIUUQTXXXDJTFDVSJUZPSHCFODINBSLLVCFSOFUFT

    ✅08"41,VCFSOFUFT4FDVSJUZ$IFBU4IFFU ɹɹIUUQTDIFBUTIFFUTFSJFTPXBTQPSHDIFBUTIFFUT,VCFSOFUFT@4FDVSJUZ@$IFBU@4IFFUIUNM ✅08"41,VCFSOFUFT5PQ5FO ɹɹIUUQTPXBTQPSHXXXQSPKFDULVCFSOFUFTUPQUFO ✅,VCFSOFUFT)BSEFOJOH(VJEF ɹɹIUUQTNFEJBEFGFOTFHPW"VH$53@,6#&3/&5&4@)"3%&/*/(@(6*%"/$&@@1%' ✅/*4541"QQMJDBUJPO$POUBJOFS4FDVSJUZ(VJEF ɹɹIUUQTOWMQVCTOJTUHPWOJTUQVCTTQFDJBMQVCMJDBUJPOTOJTUTQQEG
  4. "HFOEB ಋೖ ɹຊηογϣϯͷΰʔϧ ɹ,VCFSOFUFTηΩϡϦςΟͷશମ૾ ɹ,VCFSOFUFTηΩϡϦςΟͷϓϥΫςΟε ,VCFSOFUFT΁ͷ߈ܸࣄྫ ɹঢ়گઃఆ ɹ۩ମతͳ߈ܸࣄྫ ɹɹ,VCFSOFUFTΫϥελ΁ͷ৵ೖ 45&1

     ɹɹෆਖ਼ͳϫʔΫϩʔυͷ࡞੒ 45&1  ɹɹ/PEF΁ͷ৵ೖ 45&1  ɹ߈ܸࣄྫͷ෮श ରࡦͷߟ͑ํ ɹ<ରࡦ>,VCFSOFUFTΫϥελ΁ͷ৵ೖ 45&1  ɹ<ରࡦ>ෆਖ਼ͳϫʔΫϩʔυͷ࣮ߦ 45&1  ɹ<ରࡦ>/PEF΁ͷ৵ೖ 45&1  ɹରࡦͷ·ͱΊ ·ͱΊ
  5. ,VCFSOFUFTΫϥελ΁ͷ৵ೖ 45&1 ࠷ॳʹ߈ܸऀ͸ϙʔτεΩϟϯΛߦ͍·͢ɻ εΩϟϯͷ݁ՌɺΠϯλʔωοτ্ʹϙʔτ͕ެ։͞Ε͍ͯΔͷΛൃݟ͠·͢ɻ QPSU ONBQQ99999 /NBQTDBOSFQPSUGPSOPEF """"  )PTUJTVQ

    TMBUFODZ  /PUTIPXODMPTFEUDQQPSUT DPOOSFGVTFE  103545"5&4&37*$&  UDQPQFOVOLOPXO  /NBQEPOF*1BEESFTT IPTUVQ TDBOOFEJOTFDPOET
  6.  ࢀߟ ,VCFSOFUFTͷΞʔΩςΫνϟ LVCFMFUͱݺ͹ΕΔ/PEFͷ"HFOU͕ϙʔτͰ"1*Λެ։͍ͯ͠Δɻ LVCFDUM FUDE LVCFQSPYZ LVCFMFU LVCFBQJTFSWFS LVCFDPOUSPMMFSNBOBHFS

    LVCFTDIFEVMFS /PEFͰ1PEΛ؅ཧ͢Δ"HFOU LVCFBQJTFSWFS͔Β ϦΫΤετΛड͚෇͚Δ"1*Λ ϙʔτͰެ։ 
  7. ,VCFSOFUFTΫϥελ΁ͷ৵ೖ 45&1 ͢Δͱ/PEFͰ࣮ߦ͞Ε͍ͯΔ1PEҰཡΛऔಘͰ͖·ͨ͠ɻ UFTUQPE OPEF """" QPET DVSMLIUUQT/0%&@*1QPETcKR \ LJOE1PE-JTU

     BQJ7FSTJPOW  NFUBEBUB\^  JUFNT< \ NFUBEBUB\ OBNFUFTUQPE  OBNFTQBDFUNQ   DPOUBJOFST< \ OBNFVCVOUV   test-podというPodに 目を付ける
  8. ,VCFSOFUFTΫϥελ΁ͷ৵ೖ 45&1 ࣍ʹର৅ͷ1PEʹؚ·ΕΔίϯςφ಺Ͱ೚ҙͷίϚϯυΛϦϞʔτ࣮ߦ͢ΔͨΊͷSVOͱ͍͏ ΤϯυϙΠϯτʹϦΫΤετΛૹ৴͠·͢ɻ ·ͣ͸͜ͷޙͷ߈ܸʹ࢖༻͢ΔODBUΛίϯςφʹΠϯετʔϧ͠·͢ɻ UFTUQPE OPEF """" SVO DNE

    DVSML91045(IUUQT/0%&@*1SVOUNQUFTUQPEVCVOUVEBUBVSMFODPEFDNEBQUVQEBUF DVSML91045(IUUQT/0%&@*1SVOUNQUFTUQPEVCVOUVEBUBVSMFODPEFDNEBQUJOTUBMMZODBU ncatをインストール /podsで取得したPodを対象に /runを実行
  9. ,VCFSOFUFTΫϥελ΁ͷ৵ೖ 45&1 ଓ͍ͯΠϯετʔϧͨ͠ODBU༻͍ͯϦόʔεγΣϧΛ࣮ߦ͠·͢ɻ ͜ΕͰ߈ܸऀ͸ެ։͞Ε͍ͯͨLVCFMFUΛܦ༝ͯ͠1PEʹؚ·ΕΔίϯςφʹ৵ೖͰ͖·ͨ͠ɻ ͸࣮ࡍʹ͸දࣔ͞Ε·ͤΜ UFTUQPE OPEF """" SVO DNE

    3FWFSTF 4IFMM DVSML91045(IUUQT/0%&@*1SVOUNQUFTUQPEVCVOUV EBUBVSMFODPEFDNECJOODFCJOCBTI߈ܸ୺຤*1ΞυϨε リバースシェルを実行 ODMQ IPTUOBNF UFTUQPE XIPBNJ SPPU コンテナに侵入できた 😊 1000ポートで待ち受け ߈ܸ୺຤
  10. ෆਖ਼ͳϫʔΫϩʔυͷ࡞੒ 45&1 ͜ͷ1PE͕,VCFSOFUFTΫϥελʹରͯ͠ͲͷΑ͏ͳݖݶΛ͍࣋ͬͯΔ͔֬ೝͯ͠Έ·͢ɻ Ͳ͏΍Β͜ͷ1PEʹ͸ɺ৵ೖͨ͠,VCFSOFUFTΫϥελʹ͓͍ͯ1PEʹؔ͢ΔҰఆͷݖݶ͕ ෇༩͞Ε͍ͯͦ͏Ͱ͢ɻ UFTUQPE OPEF """" LVCFDUMBVUIDBOJMJTU 3FTPVSDFT/PO3FTPVSDF63-T3FTPVSDF/BNFT7FSCT

    QPETFYFD<><>< > QPETMPH<><>< >  QPET<><><HFUMJTU >  クラスタ上の Podに関する権限が 付与されている
  11. ෆਖ਼ͳϫʔΫϩʔυͷ࡞੒ 45&1 ௚઀1PEʹ৵ೖ͢Δ͜ͱ͸׎Θͳ͔ͬͨͷͰɺ৵ೖͨ͠1PEͱಉ͡/BNFTQBDF͔ͭ λʔήοτͱͳΔ1PEͱಉ͡/PEFʹ౿୆ͱͳΔ੬ऑͳ ಛݖίϯςφΛؚΉ 1PEΛσϓϩΠ͠ɺ ͦΕΛܦ༝ͯ͠߈ܸΛࢼΈΔ͜ͱʹ͠·͢ɻ QSPE UNQ UNQ

    NBMJDJPVTQPE CBDLFOEBQQ UFTUQPE OPEF #### OPEF """" DQ $$$$ DBU&0'cLVCFDUMBQQMZG BQJ7FSTJPOW LJOE1PE NFUBEBUB OBNFNBMJDJPVTQPE OBNFTQBDFUNQ TQFD IPTU1*%USVF DPOUBJOFST OBNFVCVOUV JNBHFVCVOUV DPNNBOE<CJOTI D XIJMFEPTMFFQEPOF> TFDVSJUZ$POUFYU QSJWJMFHFEUSVF OPEF4FMFDUPS LVCFSOFUFTJPIPTUOBNFOPEF &0' 脆弱な設定 ターゲットと同じNode 侵入したPodと同じNamespace
  12. ෆਖ਼ͳϫʔΫϩʔυͷ࡞੒ 45&1 ίϚϯυΛ࣮ߦͨ݁͠Ռɺλʔήοτͷ1PEͱಉ͡/PEFʹ੬ऑͳ1PEͷσϓϩΠ͢Δ͜ͱ͕ Ͱ͖·ͨ͠ɻ ͜͜Ͱ͸͜ͷ࣍ͷ߈ܸʹ༻͍ΔͨΊͷ1PEΛσϓϩΠ͠·͕ͨ͠ɺ࣮ࡍͷ߈ܸͰ͸ΫϦϓτϚΠφʔͷΑ͏ͳ1PEΛσϓϩΠ͞ΕΔέʔε΋૝ఆ͞Ε·͢ɻ QSPE UNQ UNQ NBMJDJPVTQPE CBDLFOEBQQ

    UFTUQPE OPEF #### OPEF """" DQ $$$$ LVCFDUMHFUQPEPXJEFOUNQ /".&3&"%:45"564/0%& NBMJDJPVTQPE3VOOJOHOPEF UFTUQPE3VOOJOHOPEF
  13. /PEF΁ͷ৵ೖ 45&1 ߈ܸऀ͕OPEFʹσϓϩΠͨ͠੬ऑͳ1PEʹ͸ಛݖ͕෇༩͞Ε͍ͯ·͢ɻ ͜ΕΛར༻͢Δ͜ͱͰɺ߈ܸऀ͸OPEFʹ৵ೖ͢Δ͜ͱ͕Ͱ͖·͢ɻ ͜ͷΑ͏ʹίϯςφ͔Β/PEFʹ৵ೖ͢Δ͜ͱΛ$POUBJOFS#SFBLPVUͱݺͼ·͢ɻ UNQ NBMJDJPVTQPE OPEF #### QSPE

    CBDLFOEBQQ (勝った...!) 😏 OTFOUFSUBCJOCBTI QZUIPODJNQPSUQUZQUZTQBXO CJOCBTI  SPPU!OPEFIPTUOBNF OPEF SPPU!OPEFXIPBNJ SPPU コンテナからNodeに侵入できた
  14. /PEF΁ͷ৵ೖ 45&1 OPEFͰ࣮ߦ͞Ε͍ͯΔίϯςφҰཡΛ֬ೝ͠·͢ɻ UNQ NBMJDJPVTQPE OPEF #### QSPE CBDLFOEBQQ SPPU!OPEFDSJDUMQT

    $0/5"*/&3/".&10% ECCGCBVCVOUVNBMJDJPVTQPE EBBFDGDBQQCBDLFOEBQQ
  15. /PEF΁ͷ৵ೖ 45&1 /PEF͔Β߈ܸର৅ͷίϯςφʹ৵ೖ͠୳ࡧΛߦͳͬͨ݁Ռɺ ࠓճ͸ൿີ৘ใͱͯ͠ɺ͜ͷ1PE͕઀ଓͯ͠Δͱ૝ఆ͞ΕΔ%#ͷ৘ใΛୣऔͰ͖·ͨ͠ɻ UNQ NBMJDJPVTQPE OPEF #### QSPE CBDLFOEBQQ

    %# SPPU!CBDLFOEBQQDSJDUMFYFDJUEBBFDGDCJOCBTI SPPU!CBDLFOEBQQMTEBUB DSFEFOUJBMT SPPU!CBDLFOEBQQDBUEBUBDSFEFOUJBMT %"5"#"4&@)045ECFYBNQMFDPN %"5"#"4&@1035 %"5"#"4&@/".&DVTUPNFS %"5"#"4&@64&3/".&VTFS %"5"#"4&@1"44803%1!TTXSE 秘密情報を奪取できた 👍
  16. "HFOEB ಋೖ ɹຊηογϣϯͷΰʔϧ ɹ,VCFSOFUFTηΩϡϦςΟͷશମ૾ ɹ,VCFSOFUFTηΩϡϦςΟͷϓϥΫςΟε ,VCFSOFUFT΁ͷ߈ܸࣄྫ ɹঢ়گઃఆ ɹ۩ମతͳ߈ܸࣄྫ ɹɹ,VCFSOFUFTΫϥελ΁ͷ৵ೖ 45&1

     ɹɹෆਖ਼ͳϫʔΫϩʔυͷ࡞੒ 45&1  ɹɹ/PEF΁ͷ৵ೖ 45&1  ɹ߈ܸࣄྫͷ෮श ରࡦͷߟ͑ํ ɹ<ରࡦ>,VCFSOFUFTΫϥελ΁ͷ৵ೖ 45&1  ɹ<ରࡦ>ෆਖ਼ͳϫʔΫϩʔυͷ࣮ߦ 45&1  ɹ<ରࡦ>/PEF΁ͷ৵ೖ 45&1  ɹରࡦͷ·ͱΊ ·ͱΊ
  17. ,VCFSOFUFTΫϥελʹର͢Δ/8੍ޚ ,VCFSOFUFTͷ֤ίϯϙʔωϯτ͸ɺίϯϙʔωϯτؒͷ࿈ܞ΍ϔϧενΣοΫͳͲͷ໨తͰ ಛఆͷϙʔτΛެ։͍ͯ͠·͢ɻ45&1Ͱ͸LVCFMFUͷϙʔτ͕֎෦ެ։͞Ε͍ͯͨ͜ͱ͕ɺ ߈ܸऀʹ,VCFSOFUFTΫϥελ΁ͷΞΫηεΛڐͨ͠ཁҼͰͨ͠ɻ ཁҼ FUDE LVCFQSPYZ LVCFMFU LVCFBQJTFSWFS LVCFDPOUSPMMFSNBOBHFS

    LVCFTDIFEVMFS LVCFDUM クラスタ データを保持 Podの配置を決定 各種リソースの状態を管理 Kubernetes APIを公開 クラスタネットワークを管理 NodeのPodを管理するAgent        )FBMUI$IFDL FUDE"EWJSUJTF  *OUFSOFU
  18. ,VCFSOFUFTίϯϙʔωϯτͷઃఆ OPEF """" BQJ7FSTJPOLVCFMFUDPO fi HLTJPWCFUB LJOE,VCFMFU$PO fi HVSBUJPO BVUIFOUJDBUJPO

    BOPOZNPVT FOBCMFEUSVF XFCIPPL DBDIF55-T FOBCMFEUSVF Y DMJFOU$"'JMFFUDLVCFSOFUFTQLJDBDSU BVUIPSJ[BUJPO NPEF"MXBZT"MMPX  ,VCFMFU$PO fi HVSBUJPO OPEF 匿名ユーザーの認証を許可 認可の無効化 LVCFMFU  ʹ౸ୡͰ͖Ε͹ ೝূɾೝՄෆཁͰ "1*ΞΫηεՄೳͳঢ়ଶ ,VCFSOFUFTͷ֤ίϯϙʔωϯτʹ͸༷ʑͳઃఆ߲໨͕ଘࡏ͠·͢ɻ 45&1Ͱ͸LVCFMFUͷઃఆ͕ద੾ʹߦΘΕ͓ͯΒͣɺ"1*ͷೝূɾೝՄ͕ແޮԽ͞Ε͍ͯͨ͜ͱ͕ ߈ܸऀʹLVCFMFUͷ"1*ͷ࣮ߦΛڐͨ͠ཁҼͰͨ͠ɻ  ཁҼ
  19. ,VCFSOFUFTίϯϙʔωϯτͷઃఆ ,VCFSOFUFTͷίϯϙʔωϯτʹ͸༷ʑͳઃఆ߲໨͕ଘࡏ͠·͕͢ɺ ͜ΕΒͷઃఆΛద੾ʹߦ͏ʹ͸$*4,VCFSOFUFT#FODINBSLT ͕ࢀߟʹͳΓ·͢ɻ $*4,VCFSOFUFT#FODINBSLTͰ͸/PEF͓Αͼίϯϙʔωϯτʹର͢Δਪ঑ઃఆ͕ఆٛ͞Ε͍ͯ·͢ɻ ˞Ճ͑ͯʮ1PMJDJFTʯͰ͸͜ͷޙղઆ͢Δ֤छରࡦʹ͍ͭͯ΋Ұ෦ݴٴ͞Ε͍ͯΔɻ $POUSPM1MBOF$PNQPOFOUT ɹ$POUSPM1MBOF/PEF$PO fi HVSBUJPO'JMFT

    ɹ"1*4FSWFS ɹ$POUSPMMFS.BOBHFS ɹ4DIFEVMFS FUDE $POUSPM1MBOF$PO fi HVSBUJPO ɹ"VUIFOUJDBUJPOBOE"VUIPSJ[BUJPO ɹ-PHHJOH 8PSLFS/PEFT ɹ8PSLFS/PEF$PO fi HVSBUJPO'JMFT ɹ,VCFMFU ɹLVCFQSPYZ 1PMJDJFT ɹ3#"$BOE4FSWJDF"DDPVOUT ɹ1PE4FDVSJUZ4UBOEBSET ɹ/FUXPSL1PMJDJFTBOE$/* ɹ4FDSFUT.BOBHFNFOU ɹ&YUFOTJCMF"ENJTTJPO$POUSPM ɹ(FOFSBM1PMJDJFT $*4,VCFSOFUFT#FODINBSLT IUUQTXXXDJTFDVSJUZPSHCFODINBSLLVCFSOFUFT ରࡦ
  20. ,VCFSOFUFTίϯϙʔωϯτͷઃఆ ྫ͑͹,VCFSOFUFTͷ+PCͱͯ͠LVCFCFODIΛ࣮ߦͨ͠৔߹͸ɺ ҎԼͷΑ͏ʹ1PEͷϩάͱͯ݁͠ՌΛ֬ೝͰ͖·͢ɻ ࠓճ໰୊ͱͳͬͨLVCFMFUʹؔ͢Δઃఆͷෆඋ΋ݕ஌͞Ε͍ͯΔ͜ͱ͕֬ೝͰ͖·͢ɻ LVCFDUMBQQMZGKPCZBNM LVCFDUMMPHTLVCFCFODIDCEMO  <*/'0>,VCFMFU <'"*->&OTVSFUIBUUIFBOPOZNPVTBVUIBSHVNFOUJTTFUUPGBMTF "VUPNBUFE

     <'"*->&OTVSFUIBUUIFBVUIPSJ[BUJPONPEFBSHVNFOUJTOPUTFUUP"MXBZT"MMPX "VUPNBUFE  <1"44>&OTVSFUIBUUIFDMJFOUDB fi MFBSHVNFOUJTTFUBTBQQSPQSJBUF "VUPNBUFE  <1"44>7FSJGZUIBUUIFSFBEPOMZQPSUBSHVNFOUJTTFUUP .BOVBM  <1"44>&OTVSFUIBUUIFTUSFBNJOHDPOOFDUJPOJEMFUJNFPVUBSHVNFOUJTOPUTFUUP .BOVBM   4VNNBSZOPEF DIFDLT1"44 DIFDLT'"*- DIFDLT8"3/ DIFDLT*/'0  ରࡦ OPEFͰLVCFCFODIΛ࣮ߦͨ݁͠Ռ ൈਮ ͜ΕΒʹ͖ͪΜͱରॲ͍ͯ͠Ε͹ LVCFMFUͷ"1*͕ෆਖ਼ʹ࣮ߦ͞ΕΔͷΛ ๷͙͜ͱ͕Ͱ͖ͨ
  21. UNQ ,VCFSOFUFTΫϥελ಺෦ͷ/8੍ޚ ,VCFSOFUFTͰ͸1PEʹ/FUXPSL1PMJDZ Λద༻͢Δ͜ͱͰɺ/8੍ݶΛߦ͏͜ͱ͕Ͱ͖·͢ɻ ͜ΕʹΑΓɺҙਤͨ͠௨৴Ҏ֎Λःஅ͠ෆਖ਼ͳ௨৴ͷϦεΫΛ௿Լͤ͞Δ͜ͱʹܨ͕Γ·͢ɻ ˞ͳ͓ɺ/FUXPSL1PMJDZΛ࢖༻͢ΔͨΊʹ͸ɺ/FUXPSL1PMJDZΛαϙʔτ͢Δ/FUXPSL1MVHJOΛ࢖༻͢Δඞཁ͕͋Γ·͢ɻ ɹ·ͨɺ/FUXPSL1MVHJOʹΑͬͯ͸ಠࣗͷ/FUXPSL1PMJDZΛαϙʔτ͍ͯ͠Δέʔε΋͋Γ·͢ɻ /FUXPSL1PMJDJFT IUUQTLVCFSOFUFTJPEPDTDPODFQUTTFSWJDFTOFUXPSLJOHOFUXPSLQPMJDJFT UFTUQPE

    BQJ7FSTJPOOFUXPSLJOHLTJPW LJOE/FUXPSL1PMJDZ NFUBEBUB OBNFEFOZBMM OBNFTQBDFUNQ TQFD QPE4FMFDUPS\^ QPMJDZ5ZQFT *OHSFTT &HSFTT BQJ7FSTJPOOFUXPSLJOHLTJPW LJOE/FUXPSL1PMJDZ NFUBEBUB OBNFUFTUOFUQPM OBNFTQBDFUNQ TQFD QPE4FMFDUPS NBUDI-BCFMT BQQUFTU QPMJDZ5ZQFT *OHSFTT &HSFTT JOHSFTT TPNFSVMF FHSFTT TPNFSVMF ඞཁʹԠͯ͡ ݸผͷ1PEʹڐՄϧʔϧΛ ؚΉϙϦγʔΛద༻ /BNFTQBDFશମʹ શͯͷ௨৴Λېࢭ͢Δ ϙϦγʔΛద༻ ରࡦ
  22.  ิ଍ 4FSWJDFΛࢦఆͨ͠௨৴ΛڐՄ͢Δ৔߹ 4FSWJDFΛࢦఆͯ͠ଞͷ1PEʹΞΫηεΛߦ͏৔߹ɺ ,VCFSOFUFTͷ಺෦%/4 $PSF%/4 Ͱ4FSWJDFͷ໊લղܾΛߦ͏͜ͱʹͳΓ·͢ɻ ͜ͷͨΊ಺෦%/4ʹର͢Δ&HSFTT௨৴ͷڐՄΛߦ͏ඞཁ͕͋Δ఺ʹ஫ҙ͍ͯͩ͘͠͞ɻ BQJ7FSTJPOOFUXPSLJOHLTJPW LJOE/FUXPSL1PMJDZ

    NFUBEBUB OBNFUFTUOFUQPM OBNFTQBDFUNQ TQFD QPE4FMFDUPS NBUDI-BCFMT BQQUFTU QPMJDZ5ZQFT *OHSFTT &HSFTT JOHSFTT TPNFSVMF FHSFTT TPNFSVMF UP OBNFTQBDF4FMFDUPS NBUDI-BCFMT LVCFSOFUFTJPNFUBEBUBOBNFLVCFTZTUFN QPE4FMFDUPS NBUDI-BCFMT LTBQQLVCFEOT QPSUT QPSU QSPUPDPM6%1 QPSU QSPUPDPM5$1 ରࡦ 内部DNSへの通信を許可
  23. ,VCFSOFUFTΫϥελʹର͢Δݖݶ੍ޚ ,VCFSOFUFTʹ͸େ͖͘෼͚ͯछྨͷϢʔβʔͷ֓೦͕ଘࡏ͠·͢ɻ ͜ΕΒʹର͠3#"$ͷ࢓૊ΈΛ༻͍Δ͜ͱͰɺ,VCFSOFUFTΫϥελʹର͢ΔݖݶΛ෇༩Ͱ͖·͢ɻ 3PMF#JOEJOH $MVTUFS3PMF#JOEJOH 3PMF $MVTUFS3PMF 6TJOH3#"$"VUIPSJ[BUJPO IUUQTLVCFSOFUFTJPEPDTSFGFSFODFBDDFTTBVUIOBVUI[SCBD 6TFS(SPVQ

    4FSWJDF"DDPVOU ,VCFSOFUFTʹؔ͢ΔݖݶΛఆٛ ԿͷϦιʔε SFTPVSDFTOPO3FTPVSDF63-T ʹ Կͷૢ࡞ WFSCT ΛڐՄ͢Δ͔ Ϣʔβʔͱ ݖݶΛඥ෇͚ ,VCFSOFUFTΛૢ࡞͢ΔϢʔβʔ 㲈LVCFDUMΛ࣮ߦ͢Δਓ  ,VCFSOFUFT֎෦Ͱ؅ཧ 9ূ໌ॻ΍֎෦ϢʔβʔετΞͰఆٛ 1PEͳͲ͕࢖༻͢ΔγεςϜΞΧ΢ϯτ ,VCFSOFUFT಺෦Ͱ؅ཧ ,VCFSOFUFTͷϦιʔεͱͯ͠ఆٛ "VUIFOUJDBUJOH IUUQTLVCFSOFUFTJPEPDTSFGFSFODFBDDFTTBVUIOBVUI[BVUIFOUJDBUJPO ཁҼ
  24. ,VCFSOFUFTΫϥελʹର͢Δݖݶ੍ޚ 45&1Ͱ߈ܸऀʹෆਖ਼ͳ1PEΛ࡞੒͞Εͯ͠·ͬͨ௚઀తͳཁҼ͸ɺ 4FSWJDF"DDPVOUʹQPET΍FYFDαϒϦιʔε ʹؔ͢Δશͯͷૢ࡞ݖݶ WFSCT ͕෇༩͞Ε͍ͯͨ͜ͱ ʹ͋Γ·͢ɻ˞LVCFDUMFYFDΛߦ͏ࡍ͸QPETFYFDͱ͍͏αϒϦιʔεʹΞΫηε͢Δ UFTUTB 3FGFSSJOHUPSFTPVSDFT IUUQTLVCFSOFUFTJPEPDTSFGFSFODFBDDFTTBVUIOBVUI[SCBDSFGFSSJOHUPSFTPVSDFT

    ɹɹɹ ɹɹɹSVMFT ɹɹɹBQJ(SPVQT ɹɹɹ ɹɹɹSFTPVSDFT ɹɹɹQPET ɹɹɹQPETFYFD ɹɹɹQPETMPH ɹɹɹWFSCT ɹɹɹ  ɹɹɹ ɹɹɹSVMFT ɹɹɹBQJ(SPVQT ɹɹɹ ɹɹɹSFTPVSDFT ɹɹɹQPET ɹɹɹWFSCT ɹɹɹHFU ɹɹɹMJTU ɹɹɹBQJ7FSTJPOW ɹɹɹLJOE1PE ɹɹɹNFUBEBUB ɹɹɹOBNFUFTUQPE ɹɹɹ ɹɹɹTQFD ɹɹɹDPOUBJOFST ɹɹɹ ɹɹɹTFSWJDF"DDPVOU/BNFUFTUTB ɹɹɹ ཁҼ クラスタ全体に対する権限 Namespace内の権限
  25. ,VCFSOFUFTΫϥελͷར༻ऀͱͯ͠1PEʹݖݶΛ༩͑Δ৔߹ ✅EFGBVMU4FSWJDF"DDPVOUΛ࢖༻͢Δ ɹɹ✔1PEͷ4FSWJDF"DDPVOUΛࢦఆ͠ͳ͚Ε͹EFGBVMU4FSWJDF"DDPVOU͕ඥ෇͚ΒΕΔ ɹɹ✔EFGBVMU4FSWJDF"DDPVOU͸ݖݶΛ΄ͱΜͲ࣋ͨͳ͍ "1*΍7FSTJPO৘ใΛऔಘͰ͖Δఔ౓  ɹɹ✔ͨͩ͠EFGBVMU4FSWJDF"DDPVOUʹݖݶΛඥ෇͚ͳ͍͜ͱʹ஫ҙ ✅1PEʹ4FSWJDF"DDPVOUΛඥ෇͚ͳ͍ ɹɹ✔ҰൠతͳϫʔΫϩʔυͰ͋Ε͹,VCFSOFUFTʹؔ͢Δݖݶ͸ͦ΋ͦ΋ෆཁͳ͜ͱ͕ଟ͍ ɹɹ✔EFGBVMU4FSWJDF"DDPVOUͰ͸,VCFSOFUFTΫϥελʹର͢Δೝূࣗମ͸ߦ͑ͯ͠·͏

    ɹɹ✔4FSWJDF"DDPVOUΛඥ෇͚ͳ͚Ε͹ೝূ͞ΕΔͷΛ๷ࢭͰ͖Δ ✅ݖݶΛඥ෇͚Δ৔߹͸ඞཁ࠷খݶʹ͢Δ ɹɹ✔΍ΉΛಘͣݖݶΛඥ෇͚Δ৔߹͸ඞཁ࠷খݶʹ͢Δ ɹɹɹɹFH1PEͷࢀরͷΈ͕ඞཁͰ͋Ε͹HFU΍MJTUͷΈʹWFSCTΛݶఆ͢Δ %FGBVMUTFSWJDFBDDPVOUT IUUQTLVCFSOFUFTJPEPDTDPODFQUTTFDVSJUZTFSWJDFBDDPVOUTEFGBVMUTFSWJDFBDDPVOUT BQJ7FSTJPOW LJOE1PE NFUBEBUB OBNFUFTUQPE  TQFD DPOUBJOFST  TFSWJDF"DDPVOU/BNFUFTUTB  ରࡦ
  26. ,VCFSOFUFTΫϥελͷར༻ऀͱͯ͠1PEʹݖݶΛ༩͑Δ৔߹ ✅EFGBVMU4FSWJDF"DDPVOUΛ࢖༻͢Δ ɹɹ✔1PEͷ4FSWJDF"DDPVOUΛࢦఆ͠ͳ͚Ε͹EFGBVMU4FSWJDF"DDPVOU͕ඥ෇͚ΒΕΔ ɹɹ✔EFGBVMU4FSWJDF"DDPVOU͸ݖݶΛ΄ͱΜͲ࣋ͨͳ͍ "1*΍7FSTJPO৘ใΛऔಘͰ͖Δఔ౓  ɹɹ✔ͨͩ͠EFGBVMU4FSWJDF"DDPVOUʹݖݶΛඥ෇͚ͳ͍͜ͱʹ஫ҙ ✅1PEʹ4FSWJDF"DDPVOUΛඥ෇͚ͳ͍ ɹɹ✔ҰൠతͳϫʔΫϩʔυͰ͋Ε͹,VCFSOFUFTʹؔ͢Δݖݶ͸ͦ΋ͦ΋ෆཁͳ͜ͱ͕ଟ͍ ɹɹ✔EFGBVMU4FSWJDF"DDPVOUͰ͸,VCFSOFUFTΫϥελʹର͢Δೝূࣗମ͸ߦ͑ͯ͠·͏

    ɹɹ✔4FSWJDF"DDPVOUΛඥ෇͚ͳ͚Ε͹ೝূ͞ΕΔͷΛ๷ࢭͰ͖Δ ✅ݖݶΛඥ෇͚Δ৔߹͸ඞཁ࠷খݶʹ͢Δ ɹɹ✔΍ΉΛಘͣݖݶΛඥ෇͚Δ৔߹͸ඞཁ࠷খݶʹ͢Δ ɹɹɹɹFH1PEͷࢀরͷΈ͕ඞཁͰ͋Ε͹HFU΍MJTUͷΈʹWFSCTΛݶఆ͢Δ %FGBVMUTFSWJDFBDDPVOUT IUUQTLVCFSOFUFTJPEPDTDPODFQUTTFDVSJUZTFSWJDFBDDPVOUTEFGBVMUTFSWJDFBDDPVOUT BQJ7FSTJPOW LJOE1PE NFUBEBUB OBNFUFTUQPE  TQFD DPOUBJOFST  BVUPNPVOU4FSWJDF"DDPVOU5PLFOGBMTF  ରࡦ
  27. ,VCFSOFUFTΫϥελͷར༻ऀͱͯ͠1PEʹݖݶΛ༩͑Δ৔߹ ✅EFGBVMU4FSWJDF"DDPVOUΛ࢖༻͢Δ ɹɹ✔1PEͷ4FSWJDF"DDPVOUΛࢦఆ͠ͳ͚Ε͹EFGBVMU4FSWJDF"DDPVOU͕ඥ෇͚ΒΕΔ ɹɹ✔EFGBVMU4FSWJDF"DDPVOU͸ݖݶΛ΄ͱΜͲ࣋ͨͳ͍ "1*΍7FSTJPO৘ใΛऔಘͰ͖Δఔ౓  ɹɹ✔ͨͩ͠EFGBVMU4FSWJDF"DDPVOUʹݖݶΛඥ෇͚ͳ͍͜ͱʹ஫ҙ ✅1PEʹ4FSWJDF"DDPVOUΛඥ෇͚ͳ͍ ɹɹ✔ҰൠతͳϫʔΫϩʔυͰ͋Ε͹,VCFSOFUFTʹؔ͢Δݖݶ͸ͦ΋ͦ΋ෆཁͳ͜ͱ͕ଟ͍ ɹɹ✔EFGBVMU4FSWJDF"DDPVOUͰ͸,VCFSOFUFTΫϥελʹର͢Δೝূࣗମ͸ߦ͑ͯ͠·͏

    ɹɹ✔4FSWJDF"DDPVOUΛඥ෇͚ͳ͚Ε͹ೝূ͞ΕΔͷΛ๷ࢭͰ͖Δ ✅ݖݶΛඥ෇͚Δ৔߹͸ඞཁ࠷খݶʹ͢Δ ɹɹ✔΍ΉΛಘͣݖݶΛඥ෇͚Δ৔߹͸ඞཁ࠷খݶʹ͢Δ ɹɹɹɹFH1PEͷࢀরͷΈ͕ඞཁͰ͋Ε͹HFU΍MJTUͷΈʹWFSCTΛݶఆ͢Δ %FGBVMUTFSWJDFBDDPVOUT IUUQTLVCFSOFUFTJPEPDTDPODFQUTTFDVSJUZTFSWJDFBDDPVOUTEFGBVMUTFSWJDFBDDPVOUT  SVMFT BQJ(SPVQT  SFTPVSDFT QPET QPETFYFD QPETMPH WFSCT   HFU MJTU 必要最小限のresources 必要最小限のverbs ରࡦ
  28. ,VCFSOFUFTΫϥελͷ؅ཧऀͱͯ͠ར༻ऀʹݖݶΛ༩͑Δ৔߹ ✅෇༩͢Δݖݶ͸ඞཁ࠷খݶʹ͢Δ ɹɹ✔Ϣʔβʔʹ͸ԿΒ͔ͷݖݶΛ෇༩͢Δඞཁ͕͋Δ ɹɹ✔/BNFTQBDFɺϦιʔεछผʹԠͨ͡ඞཁ࠷খݶͷݖݶΛ෇༩ ɹɹ✔#VJMEJO3PMF Λ׆༻͢Δͷ΋͋Γ BENJOFEJUWJFX UFOBOUB UFOBOUC 6TFS(SPVQ

    6TFS(SPVQ ॏཁϦιʔε΁ͷΞΫηε͸ېࢭ 8PSLMPBEܥϦιʔε΁ͷΞΫηε͸ڐՄ 6TFSGBDJOHSPMFT IUUQTLVCFSOFUFTJPEPDTSFGFSFODFBDDFTTBVUIOBVUI[SCBDVTFSGBDJOHSPMFT /BNFTQBDF୯Ґͷ੍ޚ Ϧιʔεछผ୯Ґͷ੍ޚ ରࡦ
  29. ,VCFSOFUFTΫϥελͷ؅ཧऀͱͯ͠ར༻ऀʹݖݶΛ༩͑Δ৔߹ ✅෇༩͢Δݖݶ͸ඞཁ࠷খݶʹ͢Δ ɹɹ✔Ϣʔβʔʹ͸ԿΒ͔ͷݖݶΛ෇༩͢Δඞཁ͕͋Δ ɹɹ✔/BNFTQBDFɺϦιʔεछผʹԠͨ͡ඞཁ࠷খݶͷݖݶΛ෇༩ ɹɹ✔#VJMEJO3PMF Λ׆༻͢Δͷ΋͋Γ BENJOFEJUWJFX  ✅ݖݶঢ֨ʹ஫ҙ ɹɹ✔SFTPVSDFTͱWFSCTͷ૊Έ߹ΘͤʹΑͬͯ͸௥ՃͷݖݶΛऔಘͰ͖Δ৔߹͕͋Δ

    ✅ϫΠϧυΧʔυ ͷ࢖༻ʹ஫ҙ ɹɹ✔ҙਤ͠ͳ͍ݖݶؚ͕·Εͯ͠·͏Մೳੑ͕͋Δ SFTPVSDFT WFSCT ֓ཁ SPMFT DMVTUFSSPMFT FTDBMBUF ݱࡏ෇༩͞Ε͍ͯͳ͍ݖݶΛ෇༩Ͱ͖Δ ݖݶऔಘͷͨΊͷ3PMFʹର͢ΔDSFBUFVQEBUF͕ڐՄ͞ΕΔ CJOE ݱࡏ෇༩͞Ε͍ͯͳ͍ݖݶΛؚΉ3PMFΛඥ෇͚Ͱ͖Δ ݖݶऔಘͷͨΊͷ3PMF#JOEJOHʹର͢ΔDSFBUFVQEBUF͕ڐՄ͞ΕΔ VTFST HSPVQT TFSWJDFBDDPVOUT JNQFSTPOBUF ଞͷϢʔβʔݖݶͰΞΫηε Ϣʔβʔِ૷ ग़དྷͯ͠·͏ LVCFDUMBTɺLVCFDUMBTHSPVQͰTVEPతͳ͜ͱ͕Ͱ͖ΔΠϝʔδ ରࡦ
  30. ,VCFSOFUFTΫϥελͷ؅ཧऀͱͯ͠ར༻ऀʹݖݶΛ༩͑Δ৔߹ ✅෇༩͢Δݖݶ͸ඞཁ࠷খݶʹ͢Δ ɹɹ✔Ϣʔβʔʹ͸ԿΒ͔ͷݖݶΛ෇༩͢Δඞཁ͕͋Δ ɹɹ✔/BNFTQBDFɺϦιʔεछผʹԠͨ͡ඞཁ࠷খݶͷݖݶΛ෇༩ ɹɹ✔#VJMEJO3PMF Λ׆༻͢Δͷ΋͋Γ BENJOFEJUWJFX  ✅ݖݶঢ֨ʹ஫ҙ ɹɹ✔SFTPVSDFTͱWFSCTͷ૊Έ߹ΘͤʹΑͬͯ͸௥ՃͷݖݶΛऔಘͰ͖Δ৔߹͕͋Δ

    ✅ϫΠϧυΧʔυ ͷ࢖༻ʹ஫ҙ ɹɹ✔ҙਤ͠ͳ͍ݖݶؚ͕·Εͯ͠·͏Մೳੑ͕͋Δ SFTPVSDFT WFSCT ֓ཁ SPMFT DMVTUFSSPMFT FTDBMBUF ݱࡏ෇༩͞Ε͍ͯͳ͍ݖݶΛ෇༩Ͱ͖Δ ݖݶऔಘͷͨΊͷ3PMFʹର͢ΔDSFBUFVQEBUF͕ڐՄ͞ΕΔ CJOE ݱࡏ෇༩͞Ε͍ͯͳ͍ݖݶΛؚΉ3PMFΛඥ෇͚Ͱ͖Δ ݖݶऔಘͷͨΊͷ3PMF#JOEJOHʹର͢ΔDSFBUFVQEBUF͕ڐՄ͞ΕΔ VTFST HSPVQT TFSWJDFBDDPVOUT JNQFSTPOBUF ଞͷϢʔβʔݖݶͰΞΫηε Ϣʔβʔِ૷ ग़དྷͯ͠·͏ LVCFDUMBTɺLVCFDUMBTHSPVQͰTVEPతͳ͜ͱ͕Ͱ͖ΔΠϝʔδ  BQJ(SPVQT SCBDBVUIPSJ[BUJPOLTJP SFTPVSDFT SPMFT WFSCT FTDBMBUF MJTU HFU DSFBUF VQEBUF QBUDI EFMFUF これだけでは 現在付与されている 以上の権限をRoleに 追加できない ରࡦ
  31. ,VCFSOFUFTΫϥελͷ؅ཧऀͱͯ͠ར༻ऀʹݖݶΛ༩͑Δ৔߹ ✅෇༩͢Δݖݶ͸ඞཁ࠷খݶʹ͢Δ ɹɹ✔Ϣʔβʔʹ͸ԿΒ͔ͷݖݶΛ෇༩͢Δඞཁ͕͋Δ ɹɹ✔/BNFTQBDFɺϦιʔεछผʹԠͨ͡ඞཁ࠷খݶͷݖݶΛ෇༩ ɹɹ✔#VJMEJO3PMF Λ׆༻͢Δͷ΋͋Γ BENJOFEJUWJFX  ✅ݖݶঢ֨ʹ஫ҙ ɹɹ✔SFTPVSDFTͱWFSCTͷ૊Έ߹ΘͤʹΑͬͯ͸௥ՃͷݖݶΛऔಘͰ͖Δ৔߹͕͋Δ

    ✅ϫΠϧυΧʔυ ͷ࢖༻ʹ஫ҙ ɹɹ✔ҙਤ͠ͳ͍ݖݶؚ͕·Εͯ͠·͏Մೳੑ͕͋Δ SFTPVSDFT WFSCT ֓ཁ SPMFT DMVTUFSSPMFT FTDBMBUF ݱࡏ෇༩͞Ε͍ͯͳ͍ݖݶΛ෇༩Ͱ͖Δ ݖݶऔಘͷͨΊͷ3PMFʹର͢ΔDSFBUFVQEBUF͕ڐՄ͞ΕΔ CJOE ݱࡏ෇༩͞Ε͍ͯͳ͍ݖݶΛؚΉ3PMFΛඥ෇͚Ͱ͖Δ ݖݶऔಘͷͨΊͷ3PMF#JOEJOHʹର͢ΔDSFBUFVQEBUF͕ڐՄ͞ΕΔ VTFST HSPVQT TFSWJDFBDDPVOUT JNQFSTPOBUF ଞͷϢʔβʔݖݶͰΞΫηε Ϣʔβʔِ૷ ग़དྷͯ͠·͏ LVCFDUMBTɺLVCFDUMBTHSPVQͰTVEPతͳ͜ͱ͕Ͱ͖ΔΠϝʔδ  BQJ(SPVQT SCBDBVUIPSJ[BUJPOLTJP SFTPVSDFT SPMFT WFSCT CJOE MJTU HFU DSFBUF VQEBUF BQJ(SPVQT SCBDBVUIPSJ[BUJPOLTJP SFTPVSDFT SPMFCJOEJOHT WFSCT MJTU HFU DSFBUF VQEBUF QBUDI EFMFUF これだけでは 現在付与されている 以上の権限を持つRoleは 紐付けできない ରࡦ
  32. ,VCFSOFUFTΫϥελͷ؅ཧऀͱͯ͠ར༻ऀʹݖݶΛ༩͑Δ৔߹ ✅෇༩͢Δݖݶ͸ඞཁ࠷খݶʹ͢Δ ɹɹ✔Ϣʔβʔʹ͸ԿΒ͔ͷݖݶΛ෇༩͢Δඞཁ͕͋Δ ɹɹ✔/BNFTQBDFɺϦιʔεछผʹԠͨ͡ඞཁ࠷খݶͷݖݶΛ෇༩ ɹɹ✔#VJMEJO3PMF Λ׆༻͢Δͷ΋͋Γ BENJOFEJUWJFX  ✅ݖݶঢ֨ʹ஫ҙ ɹɹ✔SFTPVSDFTͱWFSCTͷ૊Έ߹ΘͤʹΑͬͯ͸௥ՃͷݖݶΛऔಘͰ͖Δ৔߹͕͋Δ

    ✅ϫΠϧυΧʔυ ͷ࢖༻ʹ஫ҙ ɹɹ✔ҙਤ͠ͳ͍ݖݶؚ͕·Εͯ͠·͏Մೳੑ͕͋Δ SFTPVSDFT WFSCT ֓ཁ SPMFT DMVTUFSSPMFT FTDBMBUF ݱࡏ෇༩͞Ε͍ͯͳ͍ݖݶΛ෇༩Ͱ͖Δ ݖݶऔಘͷͨΊͷ3PMFʹର͢ΔDSFBUFVQEBUF͕ڐՄ͞ΕΔ CJOE ݱࡏ෇༩͞Ε͍ͯͳ͍ݖݶΛؚΉ3PMFΛඥ෇͚Ͱ͖Δ ݖݶऔಘͷͨΊͷ3PMF#JOEJOHʹର͢ΔDSFBUFVQEBUF͕ڐՄ͞ΕΔ VTFST HSPVQT TFSWJDFBDDPVOUT JNQFSTPOBUF ଞͷϢʔβʔݖݶͰΞΫηε Ϣʔβʔِ૷ ग़དྷͯ͠·͏ LVCFDUMBTɺLVCFDUMBTHSPVQͰTVEPతͳ͜ͱ͕Ͱ͖ΔΠϝʔδ  BQJ(SPVQT  SFTPVSDFT VTFST HSPVQT TFSWJDFBDDPVOUT WFSCT JNQFSTPOBUF ରࡦ
  33. ,VCFSOFUFTΫϥελͷ؅ཧऀͱͯ͠ར༻ऀʹݖݶΛ༩͑Δ৔߹ ✅෇༩͢Δݖݶ͸ඞཁ࠷খݶʹ͢Δ ɹɹ✔Ϣʔβʔʹ͸ԿΒ͔ͷݖݶΛ෇༩͢Δඞཁ͕͋Δ ɹɹ✔/BNFTQBDFɺϦιʔεछผʹԠͨ͡ඞཁ࠷খݶͷݖݶΛ෇༩ ɹɹ✔#VJMEJO3PMF Λ׆༻͢Δͷ΋͋Γ BENJOFEJUWJFX  ✅ݖݶঢ֨ʹ஫ҙ ɹɹ✔SFTPVSDFTͱWFSCTͷ૊Έ߹ΘͤʹΑͬͯ͸௥ՃͷݖݶΛऔಘͰ͖Δ৔߹͕͋Δ

    ✅ϫΠϧυΧʔυ ͷ࢖༻ʹ஫ҙ ɹɹ✔ҙਤ͠ͳ͍ݖݶؚ͕·Εͯ͠·͏Մೳੑ͕͋Δ SFTPVSDFT WFSCT ֓ཁ SPMFT DMVTUFSSPMFT FTDBMBUF ݱࡏ෇༩͞Ε͍ͯͳ͍ݖݶΛ෇༩Ͱ͖Δ ݖݶऔಘͷͨΊͷ3PMFʹର͢ΔDSFBUFVQEBUF͕ڐՄ͞ΕΔ CJOE ݱࡏ෇༩͞Ε͍ͯͳ͍ݖݶΛؚΉ3PMFΛඥ෇͚Ͱ͖Δ ݖݶऔಘͷͨΊͷ3PMF#JOEJOHʹର͢ΔDSFBUFVQEBUF͕ڐՄ͞ΕΔ VTFST HSPVQT TFSWJDFBDDPVOUT JNQFSTPOBUF ଞͷϢʔβʔݖݶͰΞΫηε Ϣʔβʔِ૷ ग़དྷͯ͠·͏ LVCFDUMBTɺLVCFDUMBTHSPVQͰTVEPతͳ͜ͱ͕Ͱ͖ΔΠϝʔδ SVMFT BQJ(SPVQT   SFTPVSDFT   WFSCT   ରࡦ
  34. ,VCFSOFUFTΫϥελͷϙϦγʔ੍ޚ ,VCFSOFUFTͰ͸ɺσϑΥϧτͰͲͷΑ͏ͳઃఆΛ࣋ͭ1PEͷσϓϩΠ΋ڐՄ͞Ε͍ͯ·͢ɻ ͜ͷͨΊ߈ܸऀ͸45&1Ͱɺ,VCFSOFUFTΫϥελʹ੬ऑͳ1PEΛσϓϩΠ͠ɺ 45&1ͷ߈ܸ /PEF΁ͷ৵ೖ ʹܨ͛Δ͜ͱ͕Ͱ͖·ͨ͠ɻ ݖݶ͑͋͞Ε͹ͲͷΑ͏ͳ1PE΋σϓϩΠͰ͖Δ NBMJDJPVTQPE BQJ7FSTJPOW LJOE1PE

    NFUBEBUB OBNFNBMJDJPVTQPE OBNFTQBDFUNQ TQFD IPTU1*%USVF DPOUBJOFST OBNFVCVOUV JNBHFVCVOUV DPNNBOE<CJOTI > TFDVSJUZ$POUFYU QSJWJMFHFEUSVF OPEF4FMFDUPS LVCFSOFUFTJPIPTUOBNFOPEF 脆弱な設定 ཁҼ
  35.  ࢀߟ ,VCFSOFUFT"1*ʹ͓͚ΔॲཧͷྲྀΕ ,VCFSOFUFT"1* LVCFBQJTFSWFS ͕ϦΫΤετΛड৴͢Δͱɺ ҎԼͷΑ͏ͳϑΣʔζΛܦͯϦιʔε͕࡞੒͞Ε·͢ ௨ৗϙϦγʔ੍ޚ͸"ENJTTJPOϑΣʔζͰߦΘΕ·͢ɻ Ϣʔβʔͷೝূ "VUIFOUJDBUJPO

    "VUIPSJ[BUJPO "ENJTTJPO ݖݶʹجͮ͘ೝՄ ϦΫΤετ಺༰ͷ ݕূ 7BMJEBUJPO ͱมߋ .VUBUJPO $POUSPMMJOH"DDFTTUPUIF,VCFSOFUFT"1* IUUQTLVCFSOFUFTJPEPDTDPODFQUTTFDVSJUZDPOUSPMMJOHBDDFTT 3.2.2. Kubernetesクラスタに対する権限制御 3.2.3. Kubernetesクラスタのポリシー制御 ,VCFSOFUFT"1* LVCFBQJTFSWFS .VUBUJPO 7BMJEBUJPO ରࡦ
  36. ,VCFSOFUFTΫϥελͷϙϦγʔ੍ޚ ϙϦγʔ੍ޚΛ࣮ݱ͢Δ୅දతͳखஈͱͯ͠ɺྫ͑͹ҎԼͷΑ͏ͳ΋ͷ͕͋Γ·͢ɻ ✅1PE4FDVSJUZ"ENJTTJPO ,VCFSOFUFT#VJMUJO W4UBCMF  ɹɹIUUQTLVCFSOFUFTJPEPDTDPODFQUTTFDVSJUZQPETFDVSJUZBENJTTJPO ✅7BMJEBUJOH"ENJTTJPO1PMJDZ ,VCFSOFUFT#VJMUJO W4UBCMF

     ɹɹIUUQTLVCFSOFUFTJPEPDTSFGFSFODFBDDFTTBVUIOBVUI[WBMJEBUJOHBENJTTJPOQPMJDZ ✅.VUBUJOH"ENJTTJPO1PMJDZ ,VCFSOFUFT#VJMUJO W"MQIB༧ఆ  ɹɹ ,&1 IUUQTHJUIVCDPNLVCFSOFUFTFOIBODFNFOUTUSFFNBTUFSLFQTTJHBQJNBDIJOFSZNVUBUJOHBENJTTJPOQPMJDJFT ɹɹ ଟ෼ެࣜEPD͸͜ΕʹͳΔ͸ͣ IUUQTLVCFSOFUFTJPEPDTSFGFSFODFBDDFTTBVUIOBVUI[NVUBUJOHBENJTTJPOQPMJDZ ✅,ZWFSOP SE1BSUZ  ɹɹIUUQTLZWFSOPJP ✅01"(BUFLFFQFS SE1BSUZ  ɹɹIUUQTPQFOQPMJDZBHFOUHJUIVCJPHBUFLFFQFSXFCTJUF ରࡦ
  37. ,VCFSOFUFTΫϥελͷϙϦγʔ੍ޚ ϙϦγʔ ֓ཁ نఆ߲໨ͷྫ ηΩϡϦςΟϨϕϧ 1SJWJMFHFE ઃఆ߲໨ʹنఆΛઃ͚ͳ͍ϙϦγʔ  نఆͳ͠ ௿

    #BTFMJOF ϦεΫ͕໌֬Ͱ͋Δઃఆ߲໨ʹ͍ͭͯ࠷௿ݶͷنఆΛߦͬͨϙϦγʔ ɾಛݖίϯςφͷېࢭ ɾϗετͱͷ/BNFTQBDFڞ༗ͷېࢭ ɾ)PTU1BUIͷېࢭ FUD த 3FTUSJDUFE ৄࡉͳઃఆ߲໨·ͰنఆΛߦͬͨϕετϓϥΫςΟεʹ֘౰͢ΔϙϦγʔ ɾ#BTFMJOFͷ߲໨શͯ ɾSPPUϢʔβʔͰͷίϯςφ࣮ߦېࢭ ɾಛݖঢ֨ͷېࢭ ɾ4FDDPNQͷڧ੍ FUD ߴ ͜͜Ͱ͸ྫͱͯ͠ɺ,VCFSOFUFT#VJMUJOͷػೳͰ͋Δ1PE4FDVSJUZ"ENJTTJPOʹ͍ͭͯղઆ͠·͢ɻ 1PE4FDVSJUZ"ENJTTJPOͰ͸ɺ͋Β͔͡Ί,VCFSOFUFTͰఆٛ͞Εͨ1PEʹؔ͢Δ ϙϦγʔ 1PE4FDVSJUZ4UBOEBSET ʹج͖ͮϙϦγʔ੍ޚ 7BMJEBUJPO Λߦ͏͜ͱ͕Ͱ͖·͢ɻ 1PE4FDVSJUZ4UBOEBSET IUUQTLVCFSOFUFTJPEPDTDPODFQUTTFDVSJUZQPETFDVSJUZTUBOEBSET 1PE4FDVSJUZ4UBOEBSETͷ֓ཁ ରࡦ
  38. ,VCFSOFUFTΫϥελͷϙϦγʔ੍ޚ ϙϦγʔ ֓ཁ نఆ߲໨ͷྫ ηΩϡϦςΟϨϕϧ 1SJWJMFHFE ઃఆ߲໨ʹنఆΛઃ͚ͳ͍ϙϦγʔ  نఆͳ͠ ௿

    #BTFMJOF ϦεΫ͕໌֬Ͱ͋Δઃఆ߲໨ʹ͍ͭͯ࠷௿ݶͷنఆΛߦͬͨϙϦγʔ ɾಛݖίϯςφͷېࢭ ɾϗετͱͷ/BNFTQBDFڞ༗ͷېࢭ ɾ)PTU1BUIͷېࢭ FUD த 3FTUSJDUFE ৄࡉͳઃఆ߲໨·ͰنఆΛߦͬͨϕετϓϥΫςΟεʹ֘౰͢ΔϙϦγʔ ɾ#BTFMJOFͷ߲໨શͯ ɾSPPUϢʔβʔͰͷίϯςφ࣮ߦېࢭ ɾಛݖঢ֨ͷېࢭ ɾ4FDDPNQͷڧ੍ FUD ߴ 1PE4FDVSJUZ4UBOEBSET IUUQTLVCFSOFUFTJPEPDTDPODFQUTTFDVSJUZQPETFDVSJUZTUBOEBSET 1PE4FDVSJUZ4UBOEBSETͷ֓ཁ ରࡦ QSJWJMFHFEUSVFΛېࢭ IPTU1*%USVFΛېࢭ ͜͜Ͱ͸ྫͱͯ͠ɺ,VCFSOFUFT#VJMUJOͷػೳͰ͋Δ1PE4FDVSJUZ"ENJTTJPOʹ͍ͭͯղઆ͠·͢ɻ 1PE4FDVSJUZ"ENJTTJPOͰ͸ɺ͋Β͔͡Ί,VCFSOFUFTͰఆٛ͞Εͨ1PEʹؔ͢Δ ϙϦγʔ 1PE4FDVSJUZ4UBOEBSET ʹج͖ͮϙϦγʔ੍ޚ 7BMJEBUJPO Λߦ͏͜ͱ͕Ͱ͖·͢ɻ
  39. ,VCFSOFUFTΫϥελͷϙϦγʔ੍ޚ 1PE4FDVSJUZ"ENJTTJPOʹΑΔϙϦγʔ੍ޚ͸ɺ ੍ޚର৅ͱ͢Δ/BNFTQBDFʹϥϕϧΛ෇༩͢Δ͜ͱͰ࣮ݱͰ͖·͢ɻ ҎԼ͸UNQ/BNFTQBDFʹରͯ͠#BTFMJOFϙϦγʔʹҧ൓͢Δ1PEͷσϓϩΠΛېࢭ͢ΔྫͰ͢ɻ BQJ7FSTJPOW LJOE/BNFTQBDF NFUBEBUB OBNFUNQ MBCFMT #BTFMJOFϙϦγʔʹҧ൓͢Δ1PEͷσϓϩΠΛېࢭ

    QPETFDVSJUZLVCFSOFUFTJPFOGPSDFCBTFMJOF QPETFDVSJUZLVCFSOFUFTJPFOGPSDFWFSTJPOW 3FTUSJDUFEϙϦγʔʹҧ൓͢Δ1PEͷσϓϩΠΛݕ஌ͨ͠৔߹͸"VEJU-PHʹه࿥ QPETFDVSJUZLVCFSOFUFTJPBVEJUSFTUSJDUFE QPETFDVSJUZLVCFSOFUFTJPBVEJUWFSTJPOW 3FTUSJDUFEϙϦγʔʹҧ൓͢Δ1PEͷσϓϩΠΛݕ஌ͨ͠৔߹͸ܯࠂΛදࣔ QPETFDVSJUZLVCFSOFUFTJPXBSOSFTUSJDUFE QPETFDVSJUZLVCFSOFUFTJPXBSOWFSTJPOW 1PE4FDVSJUZ"ENJTTJPO IUUQTLVCFSOFUFTJPEPDTDPODFQUTTFDVSJUZQPETFDVSJUZBENJTTJPO baselineに違反するPodを禁止 ରࡦ
  40. ,VCFSOFUFTΫϥελͷϙϦγʔ੍ޚ ࣮ࡍʹ#BTFMJOFϙϦγʔʹҧ൓͢Δ1PEͷσϓϩΠΛࢼΈΔͱɺ σϓϩΠʹࣦഊ͢Δ͜ͱ͕֬ೝͰ͖·͢ɻ45&1Ͱ͸͜ͷΑ͏ͳϙϦγʔ੍ޚ͕ߦΘΕ͍ͯΕ͹ɺ ߈ܸऀʹΑΔ੬ऑͳ1PEͷσϓϩΠΛ๷͙͜ͱ͕Ͱ͖·ͨ͠ɻ DBU&0'cLVCFDUMBQQMZG BQJ7FSTJPOW LJOE1PE NFUBEBUB OBNFNBMJDJPVTQPE OBNFTQBDFUNQ

    TQFD IPTU1*%USVF  TFDVSJUZ$POUFYU QSJWJMFHFEUSVF  &0' &SSPSGSPNTFSWFS 'PSCJEEFO FSSPSXIFODSFBUJOH45%*/QPETNBMJDJPVTQPEJTGPSCJEEFOWJPMBUFT1PE4FDVSJUZ CBTFMJOFWIPTUOBNFTQBDFT IPTU1*%USVF QSJWJMFHFE DPOUBJOFSVCVOUVNVTUOPUTFU TFDVSJUZ$POUFYUQSJWJMFHFEUSVF baselineに違反するPodのデプロイが拒否された ରࡦ
  41. <ରࡦ>/PEF΁ͷ৵ೖ 45&1 ࠓճͷ45&1ͷέʔεʹ͓͍ͯɺ׬ᘳͳରࡦ͸΄΅ෆՄೳͰ͢ɻ ίϯςφ͸௨ৗɺίϯςφϗετ͔Βִ཭͞Εͨϓϩηεͱ࣮ͯ͠ߦ͞Ε·͢ɻ ͔͠͠45&1Ͱ߈ܸऀ͕σϓϩΠͨ͠ಛݖίϯςφ QSJWJMFHFEUSVF ͸ɺ ίϯςφϗετͷ-JOVYΧʔωϧʹରͯ͠શͯͷݖݶΛִ࣋ͭ཭ੑͷ௿͍ϓϩηεͱ࣮ͯ͠ߦ͞Ε·͢ɻ ͭ·Γಛݖίϯςφʹ৵ೖ͞ΕΔ͜ͱ͸ɺ/PEFͷಛݖΛୣऔ͞Εͨͷͱಉ౳Ͱ͋Δͱݴ͑·͢ɻ ˞ίϯςφͰ͸ݖݶҎ֎ʹ΋ɺ/BNFTQBDFΛ͸͡Ίͱ࣮ͨ͠ߦۭؒ΍ɺϑΝΠϧγεςϜɺϦιʔεͳͲෳ਺ͷٕज़Λ૊Έ߹Θִͤͨ཭͕࣮ݱ͞Ε·͢ɻ

    ɹ45&1Ͱ͸QSJWJMFHFEUSVFҎ֎ʹIPTU1*%USVFͱ͍͏ઃఆΛߦͳ͍ͬͯ·͕͢ɺ͜Ε͸1*%/BNFTQBDFΛίϯςφͱϗετͰڞ༗͢Δͱ͍͏ઃఆͰ͢ɻ ɹ͜Ε͸͋͘·Ͱ߈ܸΛ੒ཱ͠΍͘͢͢ΔͨΊͷઃఆͳͷͰɺ͜͜Ͱ͸ਂ͘ݴٴ͠·ͤΜɻ /PEF ίϯςφϗετ /PEFͷ-JOVYΧʔωϧʹର͢Δ ݖݶ੍͕ݶ͞Εͳ͍ ͋ΒΏΔૢ࡞͕Մೳ ࣮ߦ؀ڥݖݶϦιʔε ͷ؍఺Ͱִ཭ $POUBJOFS 1SPDFTT $POUBJOFS 1SPDFTT ڐՄ͞Εͨૢ࡞ͷΈՄೳ
  42. ίϯςφઐ༻04 $POUBJOFS3VOUJNF $POUBJOFS3VOUJNF LVCFMFU LVCFMFU CBTI TTI ൚༻04 ίϯςφઐ༻04 ɾ

    ɾ ɾ ͜Εʹର͢Δରࡦͱͯ͠ɺίϯςφ࣮ߦʹಛԽͨ͠ίϯςφઐ༻04ͷ࢖༻͕ڍ͛ΒΕ·͢ɻ ίϯςφઐ༻04͸൚༻04 3)&-΍6CVOUVͳͲ ͱൺ΂ඞཁ࠷௿ݶͷ΋ͷͷΈؚ͕·Ε͍ͯΔͨΊɺ ,VCFSOFUFTΫϥελΛߏ੒͢Δ/PEFͷ-JOVYσΟετϦϏϡʔγϣϯͱͯ͠࠾༻͢Δ͜ͱͰ ੬ऑੑ΍ΞλοΫαʔϑΣεͷ࡟ݮʹ༗ޮͰ͋Δͱݴ͑·͢ɻ ˞ͦͷଞʹ΋ಛఆͷϑΝΠϧγεςϜ͕3FBE0OMZʹͳ͍ͬͯΔͳͲɺσΟετϦϏϡʔγϣϯʹΑΓৄࡉͳ࢓༷͸ҟͳΓ·͢ ରࡦ ίϯςφͷ࣮ߦʹෆཁͳ΋ͷΛ ۃྗؚ·ͳ͍
  43. ίϯςφઐ༻04 ίϯςφઐ༻04ʹ͸ྫ͑͹࣍ͷ΋ͷ͕͋Γ·͢ɻ ✅#PUUMFSPDLFU "84  IUUQTBXTBNB[PODPNCPUUMFSPDLFU ✅$POUBJOFS0QUJNJ[FE04 (PPHMF$MPVE  IUUQTDMPVEHPPHMFDPNDPOUBJOFSPQUJNJ[FEPT

    ✅"[VSF-JOVY$POUBJOFS)PTU .JDSPTPGU"[VSF  IUUQTMFBSONJDSPTPGUDPNB[VSFB[VSFMJOVY ✅'FEPSB$PSF04 'FEPSB  IUUQTGFEPSBQSPKFDUPSHDPSFPT ✅5BMPT-JOVY 4*%&30-"#  IUUQTXXXUBMPTEFW ରࡦ
  44. ৼΔ෣͍؂ࢹ ҎԼ͸'BMDPʹΑΔ45&1ͷ$POUBJOFS#SFBLPVUʹؔ͢ΔΠϕϯτݕ஌ͷྫͰ͢ɻ ݕ஌ͨ͠Πϕϯτ͸'BMDPTJEFLJDL Λ༻͍ͯ4MBDL౳ʹసૹՄೳ͢Δ͜ͱ͕Ͱ͖·͢ɻ LVCFDUMMPHTGBMDPLTHMCOGBMDPG *OGPSNBUJPOBM1SJWJMFHFEDPOUBJOFSTUBSUFE FWU@UZQFDPOUBJOFSVTFSVTFS@VJE VTFS@MPHJOVJEQSPDFTTDPOUBJOFSEGBBQSPD@FYFQBUIQBSFOU/"DPNNBOEDPOUBJOFSEGBB UFSNJOBMDPOUBJOFS@JEEGBBDPOUBJOFS@JNBHFEPDLFSJPMJCSBSZVCVOUVDPOUBJOFS@JNBHF@UBH DPOUBJOFS@OBNFVCVOUVLT@OTUNQLT@QPE@OBNFNBMJDJPVTQPE

     /PUJDF"TIFMMXBTTQBXOFEJOBDPOUBJOFSXJUIBOBUUBDIFEUFSNJOBM FWU@UZQFFYFDWFVTFSSPPU VTFS@VJEVTFS@MPHJOVJEQSPDFTTCBTIQSPD@FYFQBUIVTSCJOCBTIQBSFOUDPOUBJOFSETIJNDPNNBOECBTI UFSNJOBMFYF@ fl BHT&9&@83*5"#-&c&9&@-08&3@-":&3DPOUBJOFS@JEEGBB DPOUBJOFS@JNBHFEPDLFSJPMJCSBSZVCVOUVDPOUBJOFS@JNBHF@UBHDPOUBJOFS@OBNFVCVOUVLT@OTUNQ LT@QPE@OBNFNBMJDJPVTQPE  /PUJDF/BNFTQBDFDIBOHF TFUOT CZVOFYQFDUFEQSPHSBN FWU@UZQFTFUOTVTFSSPPUVTFS@VJE VTFS@MPHJOVJEQSPDFTTOTFOUFSQSPD@FYFQBUIVTSCJOOTFOUFSQBSFOUCBTIDPNNBOEOTFOUFSUBCJOCBTI UFSNJOBMDPOUBJOFS@JEEGBBDPOUBJOFS@JNBHFEPDLFSJPMJCSBSZVCVOUVDPOUBJOFS@JNBHF@UBH DPOUBJOFS@OBNFVCVOUVLT@OTUNQLT@QPE@OBNFNBMJDJPVTQPE ରࡦ nsenterによるContainer Breakoutを検知 'BMDPTJEFLJDL IUUQTGBMDPPSHEPDTPVUQVUTGPSXBSEJOH 特権コンテナが実行されたことを検知 コンテナ内でshellを実行されたことを検知
  45. ରࡦͷ·ͱΊ ؍఺ ରࡦͷ֓ཁ ରࡦख๏ͷྫ ,VCFSOFUFTΫϥελʹର͢Δ/8੍ޚ ֎෦͔Βͷ,VCFSOFUFTίϯϙʔωϯτ΁ͷෆਖ਼ͳ/8ΞΫηεΛ๷ࢭ͢Δ %$$MPVE/8 ,VCFSOFUFTίϯϙʔωϯτͷઃఆ ,VCFSOFUFTίϯϙʔωϯτͷઃఆΛద੾ʹߦ͍ηΩϡϦςΟϨϕϧΛ޲্ͤ͞Δ LVCFCFODI

    ,VCFSOFUFTΫϥελ಺෦ͷ/8੍ޚ ,VCFSOFUFTΫϥελ಺෦Ͱͷෆਖ਼ͳ/8ΞΫηεΛ๷ࢭ͢Δ /FUXPSL1PMJDZ ,VCFSOFUFTΫϥελʹର͢Δݖݶ੍ޚ ࠷খݖݶͷݪଇʹ४ڌ͠Ϋϥελͷෆਖ਼ͳૢ࡞Λ๷ࢭ͢Δ 3#"$ ,VCFSOFUFTΫϥελͷϙϦγʔ੍ޚ ϙϦγʔ੍ޚͷ࣮ࢪʹΑΓෆਖ਼ͳϦιʔεͷ࡞੒Λ๷ࢭ͢Δ 1PE4FDVSJUZ"ENJTTJPO 7BMJEBUJOH"ENJTTJPO1PMJDZ .VUBUJOH"ENJTTJPO1PMJDZ SEQBSUZ ίϯςφઐ༻04 /PEFʹίϯςφઐ༻04Λ༻͍Δ͜ͱͰΞλοΫαʔϑΣεΛ࠷খԽ͢Δ $MPVE$P4 'FEPSB$PSF04 5BMPT-JOVY ৼΔ෣͍؂ࢹ ηΩϡϦςΟϦεΫʹܨ͕ΓಘΔΫϥελ಺Ͱͷෆ৹ͳڍಈΛݕ஌͢Δ 'BMDP 5FUSBHPO 5SBDFF ߈ܸࣄྫͷ45&1ʹԊͬͯɺ,VCFSOFUFTʹ͓͚Δ୅දతͳηΩϡϦςΟରࡦΛղઆ͠·ͨ͠ɻ
  46.  ࢀߟ ͦͷଞରࡦͷྫ ,VCFSOFUFTΫϥελࣗମʹؔ͢Δରࡦʹ͸֘౰͠·ͤΜ͕ɺ,VCFSOFUFTΫϥελΛར༻͢Δ ίϯςφ։ൃऀͷηΩϡϦςΟରࡦΛิॿ͢Δख๏ͱͯ͠ྫ͑͹࣍ͷΑ͏ͳ΋ͷ͕͋Γ·͢ɻ ✅ܧଓతͳεΩϟϯ ɹ,VCFSOFUFTͰ࣮ߦ͞ΕΔ1PEʹؚ·ΕΔ੬ऑੑ΍ઃఆෆඋΛܧଓతʹεΩϟϯ͢Δɻ ɹɹ5SJWZ0QFSBUPS IUUQTBRVBTFDVSJUZHJUIVCJPUSJWZPQFSBUPS 

    ɹɹ,VCFTDBQF0QFSBUPS IUUQTLVCFTDBQFJPEPDTPQFSBUPS  ✅Πϝʔδॺ໊ͷݕূ ɹ࢖༻͢ΔίϯςφΠϝʔδͷॺ໊Λݕূ͠ɺෆਖ਼ͳίϯςφΠϝʔδͷ࢖༻Λ๷ࢭ͢Δɻ ɹɹ1PMJDZ$POUSPMMFS IUUQTEPDTTJHTUPSFEFWQPMJDZDPOUSPMMFSPWFSWJFX  ɹɹ,ZWFSOP IUUQTLZWFSOPJPEPDTXSJUJOHQPMJDJFTWFSJGZJNBHFTTJHTUPSF  ✅αϯυϘοΫε؀ڥͷఏڙ ɹηΩϡϦςΟ͕ڧԽ͞ΕͨίϯςφϥϯλΠϜΛఏڙ͢Δ͜ͱͰִ཭ੑͷߴ͍ίϯςφͷ࣮ߦΛࢧԉ͢Δɻ ɹɹ3VOUJNF$MBTT IUUQTLVCFSOFUFTJPEPDTDPODFQUTDPOUBJOFSTSVOUJNFDMBTT  ɹɹH7JTPS IUUQTHWJTPSEFW  ɹɹ,BUB$POUBJOFST IUUQTLBUBDPOUBJOFSTJP
  47.  ࢀߟ աڈʹൃݟ͞Εͨ,VCFSOFUFTʹؔ࿈͢Δ੬ऑੑͷྫ ,VCFSOFUFTΫϥελͰར༻͢Δίϯϙʔωϯτʹؚ·ΕΔ੬ऑੑʹ͍ͭͯ΋஫ҙ͕ඞཁͰ͢ɻ ✅$7&IUUQTOWEOJTUHPWWVMOEFUBJMDWF ɹɹ/PEFͱͷ௨৴Λߦ͏ࡍʹDSFEFOUJBM৘ใ͕ୣऔ͞ΕΔՄೳੑʹܨ͕ΔLVCFBQJTFSWFSͷ੬ऑੑ ✅$7&IUUQTOWEOJTUHPWWVMOEFUBJM$7& ɹɹίϯςφ͔ΒDHSPVQWͷSFMFBTF@BHFOUΛհͯ͠ಛݖঢ֨ΛҾ͖ى͜͢-JOVYΧʔωϧͷ੬ऑੑ ✅$7& -FBLZ7FTTFMT

    IUUQTOWEOJTUHPWWVMOEFUBJM$7& ɹɹίϯςφ͔ΒίϯςφϗετͷϑΝΠϧγεςϜ΁ͷΞΫηεΛҾ͖ى͜͢SVODͷ੬ऑੑ ✅$7&IUUQTOWEOJTUHPWWVMOEFUBJM$7& ɹɹඇਪ঑ͷHJU3FQPUZQFWPMVNFΛ࢖༻ͯ͠ಛݖঢ֨ΛҾ͖ى͜͢LVCFMFUͷ੬ऑੑɹɹ ࢀߟ ,VCFSOFUFT0 ff i DJBM$7&'FFE ɹɹɹIUUQTLVCFSOFUFTJPEPDTSFGFSFODFJTTVFTTFDVSJUZP ffi DJBMDWFGFFE
  48. "HFOEB ಋೖ ɹຊηογϣϯͷΰʔϧ ɹ,VCFSOFUFTηΩϡϦςΟͷશମ૾ ɹ,VCFSOFUFTηΩϡϦςΟͷϓϥΫςΟε ,VCFSOFUFT΁ͷ߈ܸࣄྫ ɹঢ়گઃఆ ɹ۩ମతͳ߈ܸࣄྫ ɹɹ,VCFSOFUFTΫϥελ΁ͷ৵ೖ 45&1

     ɹɹෆਖ਼ͳϫʔΫϩʔυͷ࡞੒ 45&1  ɹɹ/PEF΁ͷ৵ೖ 45&1  ɹ߈ܸࣄྫͷ෮श ରࡦͷߟ͑ํ ɹ<ରࡦ>,VCFSOFUFTΫϥελ΁ͷ৵ೖ 45&1  ɹ<ରࡦ>ෆਖ਼ͳϫʔΫϩʔυͷ࣮ߦ 45&1  ɹ<ରࡦ>/PEF΁ͷ৵ೖ 45&1  ɹରࡦͷ·ͱΊ ·ͱΊ