DevSecOpsïŒãŒããããããž
amrit
ï¿¥1,767
åçŽ / devops, devsecops
ãã®ã³ãŒã¹ã¯ãéçºè ãDevOpsãšã³ãžãã¢ãã»ãã¥ãªãã£ãšã³ãžãã¢ãæ°äººãQAãã€ã³ãã©ããã«ãïŒãªãªãŒã¹ãITãããã³InfoSec/AppSecã®å°éå®¶ã察象ãšããŠããŸããå®è·µçãªããŒã«ããã¯ãããžãŒãæ¥çã®ã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ã䜿çšããŠDevSecOpsã®å®è·µãåŠã³ãå®è£ ããããšèããŠããæ¹ã«æé©ã§ãã ãœãããŠã§ã¢éçºã©ã€ããµã€ã¯ã«ïŒSDLCïŒå šäœïŒã¢ãŒããã¯ãã£ãã³ãŒããããã€ã³ãã©ããã€ãã©ã€ã³ãã³ã³ãããã©ã³ã¿ã€ã ç°å¢ãŸã§ïŒã«ã»ãã¥ãªãã£ãçµ±åãããã³ãºãªã³äœéšãåŸãããšãã§ããŸãã ãã®ã³ãŒã¹ã§ã¯ãDevOpsãã¯ã©ãŠãããµã€ããŒã»ãã¥ãªãã£ã®çŸåšã®åžå Žååãšåæ§ã«ãããé«ãå ±é ¬ãåŸããããããã¯ã©ã¹ã®è·åã«å°±ãããã«åœ¹ç«ã€ãéèŠã®é«ãDevSecOpsã¹ãã«ãç¿åŸã§ããŸãã仿¥ã®ããžã¿ã«ãã¡ãŒã¹ãã®äžçã§ã¯ããšã³ãžãã¢ãªã³ã°ã®ã¯ãŒã¯ãããŒã«ã»ãã¥ãªãã£ãçµã¿èŸŒãããšã¯ããã¯ããªãã·ã§ã³ã§ã¯ãªããããžãã¹ã®æåã«äžå¯æ¬ ã§ãã DevSecOpsïŒJenkinsãšã¢ãã³ãªããŒã«ã䜿çšããSDLCãžã®ã»ãã¥ãªãã£çµ±å ãã®ã³ãŒã¹ã¯ãã»ãã¥ãªãã£ããã·ããã¬ãããããå®å šã§ã¹ã±ãŒã©ãã«ãªèªååãããDevOpsãã€ãã©ã€ã³ãæ§ç¯ãããå人ãããŒã ã«æé©ã§ãã åŠç¿å å®¹ïŒ - ã»ãã¥ãªãã£ã®ååãã¢ãŒããã¯ãã£ãçµç¹ã®ãã¹ããã©ã¯ãã£ã¹ãDevOpsã¯ãŒã¯ãããŒã«çµ±åãã - ãœãŒã¹ã³ãŒããªããžããªã«ãããã·ãŒã¯ã¬ãããèªèšŒæ å ±ãæ©å¯ããŒã¿ã®å¶çºçãªé²åºã鲿¢ãã - Linuxã·ã¹ãã ãä»®æ³ãã·ã³ãCI/CDãã«ããšãŒãžã§ã³ããä¿è·ãã - 以äžã®è匱æ§ãç¹å®ãä¿®æ£ããããé©çšããïŒ - ã¢ããªã±ãŒã·ã§ã³ã®äŸåé¢ä¿ - Dockerfileãšã³ã³ããã€ã¡ãŒãž - ã©ã³ã¿ã€ã ã¢ããªã±ãŒã·ã§ã³ç°å¢ - Dockerã€ã¡ãŒãžãã³ã³ãããããã³ã³ã³ããåãããã¯ãŒã¯ããŒããä¿è·ãã - ããªã·ãŒãšã»ãã¥ãªãã£ã¹ãã£ã³ã䜿çšããŠInfrastructure as Code (Terraform)ãä¿è·ãã - èšå®ãã¹ãæ»æã«å¯ŸããŠCI/CDãã€ãã©ã€ã³ãå ç¢åããä¿è·ãã - 以äžã®ææ³ã䜿çšããŠã»ãã¥ãªãã£ãã¹ããå®è¡ããïŒ - è åšã¢ããªã³ã° (Threat Modeling) - ãŠããããã¹ãããã³çµ±åãã¹ã - ãœãããŠã§ã¢æ§æåæ (SCA) - éçã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãã¹ã (SAST) - åçã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãã¹ã (DAST) - ãªãªãŒã¹åŸã®æåãã¹ãã«é Œãã®ã§ã¯ãªãããã«ãããã¹ãããããã€ã®æ®µéã§ã»ãã¥ãªãã£ãã¹ããèªååãã åŠç¿äœéš åã³ã³ã»ããã¯ãã·ã³ãã«ã§èŠèŠçããã€æ§é åãããæ¹æ³ã§èª¬æãããŸãïŒ - ã¹ã©ã€ãããŒã¹ã®æŠå¿µèª¬æ - ãã®åŸã®å®è·µçãªãªã¢ã«ã¯ãŒã«ãã»ã©ã åè¬å å®¹ïŒ - Jenkinsã䜿çšããŠãç¬èªã®Linux VMãã»ãã¥ãªãã£ããŒã«ãCI/CDãã€ãã©ã€ã³ãã»ããã¢ãããã - Dockerã€ã¡ãŒãžãã³ã³ãããã€ã³ãã©ãä¿è·ãã - ã³ãŒã¹ã§äœ¿çšããããã¹ãŠã®ã³ãŒããèšå®ãäŸãå«ãŸããŠããå°çšã®GitHubãªããžããªã䜿çšãã ãã®ã³ãŒã¹ãåè¬ããçç± â ãªã³ã©ã€ã³ã§å©çšå¯èœãªãæãå®è·µçã§ãã³ãºãªã³äžå¿ã®DevSecOpsããŒããã£ã³ãã®äžã€ â é«é¡ãªæè²æ©é¢ãè¬åž«ïŒå€ãã®å Žå$400â$4000ã®è²»çšããããïŒãä»ããã«ãDevSecOpsãã¯ã©ãŠãã»ãã¥ãªãã£ãã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãåŠã¶ â å æ¬çã§ææ°ã®ã«ãªãã¥ã©ã ã«ãããèªåã®ããŒã¹ã§é²ããããåŠç¿ â åŸæ¥ã®DevOpsãšã¢ãã³ãªDevSecOpsã®éããæç¢ºã«çè§£ â ãã€ãã©ã€ã³ã®ããããæ®µéã§ã»ãã¥ãªãã£ãçµã¿èŸŒãæ¹æ³ãåŠã¶ â æ¬çªç°å¢ã®åŸã«åé¡ãä¿®æ£ããã®ã§ã¯ãªããæ©ãæ®µéã§ã»ãã¥ãªãã£ã¹ãã£ã³ãèªååãã â ç¡æããã³ãªãŒãã³ãœãŒã¹ã®ã»ãã¥ãªãã£ããŒã«ã䜿çšãããã³ãºãªã³äœéš â DevOpsãšã»ãã¥ãªãã£ã®ã³ã©ãã¬ãŒã·ã§ã³ã«é¢ããGartnerã¬ããŒããåç §ããæ¥çã®æŽå¯ ã³ãŒã¹ä¿®äºæ ãã®ã³ãŒã¹ãä¿®äºãããŸã§ã«ãDevSecOpsã®ããŒã«ããã¯ãããžãŒãå®è·µã«é¢ãã匷åãªçè«çç¥èãšåºç¯ãªãã³ãºãªã³çµéšãç¿åŸã§ããŸããå®éã®ãããžã§ã¯ããçµç¹ã®ããã«ãå®å šãªDevOpsãŸãã¯DevSecOpsãã€ãã©ã€ã³ãç¬èªã«èšèšãæ§ç¯ãå®è£ ããããšã«èªä¿¡ãæãŠãããã«ãªããŸãã ãŸããDevSecOpsããã³SecOpsã®åºç€ç¥èããã¹ãããæ€èšŒããããã®DevSecOpsã¯ã€ãºã«ãã¢ã¯ã»ã¹ã§ããŸãã ç®æš åŠç¿äœéš åã³ã³ã»ããã¯ãã·ã³ãã«ã§èŠèŠçããã€æ§é åãããæ¹æ³ã§èª¬æãããŸãïŒ - ã¹ã©ã€ãããŒã¹ã®æŠå¿µèª¬æ - ãã®åŸã®å®è·µçãªãªã¢ã«ã¯ãŒã«ãã»ã©ã åè¬å å®¹ïŒ - Jenkinsã䜿çšããŠãç¬èªã®Linux VMãã»ãã¥ãªãã£ããŒã«ãCI/CDãã€ãã©ã€ã³ãã»ããã¢ãããã - Dockerã€ã¡ãŒãžãã³ã³ãããã€ã³ãã©ãä¿è·ãã - ã³ãŒã¹ã§äœ¿çšããããã¹ãŠã®ã³ãŒããèšå®ãäŸãå«ãŸããŠããå°çšã®GitHubãªããžããªã䜿çšãã åææ¡ä»¶ 以äžã®åºæ¬çãªç¥èããããšåœ¹ç«ã¡ãŸãããå¿ é ã§ã¯ãããŸããããã¹ãŠãŒããã説æããŸãïŒ - DevOps & Jenkins - Docker & ã³ã³ãã - Linux, CLI & ã·ã§ã«ã¹ã¯ãªãã - ã»ãã¥ãªãã£ã®åºç€
åçŽ
devops, devsecops


![æãåãããªããåŠã¶React A to Z [19ããŒãžã§ã³åæ ]è¬çŸ©ãµã ãã€ã«](https://cdn.inflearn.com/public/courses/329170/cover/223c54c0-9220-4937-836d-70a36be3eb1c/329170-eng.png?w=420)









