Ubuntuã»ãã¥ãªãã£ã¢ã«ãã¡ããã
Brian Kennedyã«ããã
ãµãŒããŒã§ã®æåã®5åé ãã¯ãã»ãšãã©ã®æ»æãããµãŒããŒãè¿
éã«ä¿è·ããããã®åªããå
¥éæžã§ãã
å®å
šãªã¬ã€ããè£å®ããããã«ããã®ããã¥ã¢ã«ã«ã¯ããã€ãã®ä¿®æ£ããããŸãã ãŸããè¥ããšã³ãžãã¢ã®ããã«ããã€ãã®ããšã詳ãã説æããããšæããŸãã
æ¯æããã°ãŠã©ããã®ã¡ãŒã«éç¥ã確èªããæ°çŸïŒå Žåã«ãã£ãŠã¯æ°åïŒã®ã¢ã¯ã»ã¹è©Šè¡ã®å€±æã培åºçã«èгå¯ããŸãã ïŒå€ãã¯ããªãå¹³å¡ã§ã-1234ã®ãã¹ã¯ãŒãã§äœåºŠãäœåºŠã
root
ãšããŠãã°ã€ã³ããããšããŠããŸãïŒã ããã§ç޹ä»ããäžè¬çãªæ¹æ³è«ã¯ãDebian / UbuntuãµãŒããŒã«é©ããŠããŸãã éåžžãDockerã³ã³ããã®ãã¹ããšããŠã®ã¿æ©èœããŸãããååã¯åãã§ãã
å€§èŠæš¡ãªç°å¢ã§ã¯ã
Ansibleã
Shipyardãªã©ã®ããŒã«ã§å®å
šèªåã€ã³ã¹ããŒã«ã䜿çšããããšããå§ãããŸãããåäžã®ãµãŒããŒãäžããããAnsibleã®ã¿ã¹ã¯ãéžæããããšããããŸãããã®ãããªç¶æ³ã§ã¯ãæç€ºãæå³ãããŠããŸãã
泚ïŒãã®ãã«ãã¯åºæ¬çãªã¢ã«ãã¡ããããšããŠäœæãããŠããŸãã å¿
èŠã«å¿ããŠæ¡åŒµããã³è£è¶³ããå¿
èŠããããŸãããŸãã¯
ãŸã ã«ãŒããã¹ã¯ãŒãããæã£ãŠããŸããã ã©ã³ãã ã§è€éãªãã®ãéžæããããšæããŸãã æå€§è€é床èšå®ã§ãã¹ã¯ãŒããããŒãžã£ãŒãžã§ãã¬ãŒã¿ãŒã䜿çšããŸãã ãã¹ã¯ãŒããããŒãžã£ãŒã¯ãã¹ã¯ãŒããä¿åããŠæå·åããé·ããã¹ã¿ãŒãã¹ã¯ãŒãã§ã®ã¿ã¢ã¯ã»ã¹ã§ããããã«ããŸãã ããã§ã¯ãåé·ãªã»ãã¥ãªãã£å¯Ÿçãããã€ãæäŸãããŠããŸãïŒé·ããŠè€éãªã©ã³ãã ãã¹ã¯ãŒã+æå·åãšå¥ã®é·ããã¹ã¯ãŒãã«ãããã¹ã¯ãŒãä¿è·ïŒã ãã¹ã¯ãŒããããŒãžã£ãŒãŸãã¯ä»ã®ããŒã«ã䜿çšããŠããŸãããäœããã®æå·åã䜿çšããŠãã¹ã¯ãŒããå®å
šã«ä¿ã¡ãŸãã ãã®rootãã¹ã¯ãŒãã¯ãsudoãã¹ã¯ãŒããçŽå€±ããå Žåã«ã®ã¿å¿
èŠã§ãã
# passwd
*泚ïŒã«ãŒããã¹ã¯ãŒãã«é¢ããè峿·±ãè°è«ã¯ã HNãšRedditã§å§ãŸããŸããã èªã䟡å€ããããŸããããã§ããªããžããªãæŽæ°ããææ°ã®ããããé©çšããå¿
èŠããããŸãã æ¬¡ã¯ãã»ãã¥ãªãã£æŽæ°ããã°ã©ã ã®ã€ã³ã¹ããŒã«ã®èªååã«é¢ããå¥ã®ã»ã¯ã·ã§ã³ã«ãªããŸãã
apt-get update
apt-get upgrade
ãŠãŒã¶ãŒã远å
ã«ãŒããšããŠãµãŒããŒã«ã¢ã¯ã»ã¹ããªãã§ãã ããã Brian Kennedyãã€ã³ã¹ããŒã«ãããŠãŒã¶ãŒãäœæãããšããåãã«ãŒã«ã«åŸããŸãããç¬èªã®ã«ãŒã«ã䜿çšããããšãã§ããŸãã ç§ãã¡ã®å°ããªããŒã ã§ã¯ã1人ã®ãŠãŒã¶ãŒãèªèšŒã«äœ¿çšããããšã«åé¡ã¯ãããŸããã§ããããå€§èŠæš¡ãªããŒã ã§ã¯ãç¹æš©ã¬ãã«ãç°ãªããšãªãŒãã®ã¿ãsudoç¹æš©ãååŸããå¥ã®ãŠãŒã¶ãŒãäœæããæ¹ãé©åã§ãã
useradd deploy
mkdir /home/deploy
mkdir /home/deploy/.ssh
chmod 700 /home/deploy/.ssh
deployãŠãŒã¶ãŒã®åªå
ã·ã§ã«ãã€ã³ã¹ããŒã«ããŸããbashã䜿çšããŸãã
usermod -s /bin/bash deploy
èŠç¢ºèªïŒ
chmod 700
ã¯ãã¢ã«ãŠã³ãææè
ãããã°ã©ã ã®èªã¿åããæžã蟌ã¿ãå®è¡ã®æš©éãæã£ãŠããããšãæå³ããŸãã ãŸã rootã§ããã
chown
ã«ãã®ãã©ã«ããŒã§
chown
å±éãŠãŒã¶ãŒãšå±éã°ã«ãŒãã«å¯ŸããŠååž°çã«å®è¡ããŸãã ãã®ãŠãŒã¶ãŒã®ã¿ã.sshãã©ã«ããŒãæäœã§ããããã«ããå¿
èŠããããŸãã
SSHããŒèªèšŒ
ãµãŒããŒãžã®å
¥åã«ãã¹ã¯ãŒãã䜿çšããªãããã«ããŸãã ãã©ã€ã¢ã³ã®æç€ºãåºãåŸãããã«ã€ããŠå€ãã®è«äºããããŸããããç§ããã®ç«å Žã«åæããåŸåããããŸãã ãã®ããŒãã«é¢ããããã€ãã®ã³ã¡ã³ããæ¬¡ã«ç€ºããŸãã
- SSHããŒã¯ãããå€ãã®æ
å ±ãå«ãã§ããå¿
èŠãããããããã¹ã¯ãŒããããåªããŠããŸãã
- ãã¹ã¯ãŒãã¯ãã«ãŒããã©ãŒã¹ã«ããããšãã§ããŸãã å
¬ééµã§æšæž¬ããããšã¯æ¬è³ªçã«äžå¯èœã§ãããããå®å
šã«å®å
šãšèŠãªãããšãã§ããŸãã
- ã³ã³ãã¥ãŒã¿ãŒã®çé£ã¯ã©ãã§ããïŒ ã¯ããç§å¯éµã¯ãããŸãããssh-keyã®åŒã³åºãã¯ç°¡åã§ãauthorized_keysããå
¬ééµãåé€ããã ãã§ãã ãŸããå®å
šã§é·ããã¹ãã¬ãŒãºã§ç§å¯éµãä¿è·ããå¿
èŠããããŸãã æ¬¡ã®æ®µèœãåç
§ããŠãã ããã
- ããã¯ãã¹ãŠãããŒãä¿è·ããå®å
šã§é·ããã¹ã¯ãŒããã¬ãŒãºã®æ¡ä»¶ã§ã®ã¿æ©èœããŸãã ç¹°ãè¿ããŸãããããã¯éåžžã«éèŠã§ãã
ããã§ãéå»ã«ãã¹ã¯ãŒãèªèšŒãæ®ããŸãããã id_rsa.pubã®å
容ãã³ããŒããŸã
1ããŒã«ã«ãã·ã³ããauthorized_keysãã¡ã€ã«å
ã®ãµãŒããŒãžã
vim /home/deploy/.ssh/authorized_keys
Linuxã®ã»ãã¥ãªãã£ååïŒ
æå°ç¹æš©ã®ååïŒã«åŸã£ãŠ ãé©åãªç¹æš©ãèšå®ããŸãã
chmod 400 /home/deploy/.ssh/authorized_keys
chown deploy:deploy /home/deploy -R
chmod 400
ã¯ãææè
ã®ã¿ããã¡ã€ã«ãèªã¿åããããã«èš±å¯ãèšå®ããŸãã å¥ã®
chown
ã¯ããŠãŒã¶ãŒã«ããŒã ãã£ã¬ã¯ããªã®ææè
ãïŒååž°çã«ïŒå±éãããã°ã«ãŒãã«å±éãããŸãã ãã®ãã£ã¬ã¯ããªã®ææè
ã«èªã¿åããæžã蟌ã¿ãããã³å®è¡ã®ã¢ã¯ã»ã¹èš±å¯ãèšå®ãããšãã«ãããã«ã€ããŠåã«èšåããŸããã
ãã®åŸããŠãŒã¶ãŒã®deployãšsudoãæ£ãããã¹ãããŠãã«ãŒãèªèšŒãç¡å¹ã«ããsshããŒã®ã¿ã䜿çšããŠèªèšŒãèšå®ããŸãã
å±éãŠãŒã¶ãŒã®ãã¹ããšsudoã®ã€ã³ã¹ããŒã«
ãããã€ãŠãŒã¶ãŒã®èªèšŒãã©ã®ããã«çºçãããã確èªãããšåæã«ãäžãäžã®ããã«ã«ãŒãã«å¯ŸããŠsshæ¥ç¶ãéãããŸãŸã«ããŸãã ãã¹ãŠãæ£åžžã«æ©èœããå ŽåããªãŒãã³ã«ãŒãæ¥ç¶ã䜿çšããŠãããã€çšã®ãã¹ã¯ãŒããèšå®ããŸãã ãã¹ã¯ãŒãèªèšŒãç¡å¹ã«ããŠãããããsudoãé©çšãããšãã«ãã®ãã¹ã¯ãŒãã䜿çšãããŸãã åã³ãã¹ã¯ãŒããããŒãžã£ãŒãå®è¡ããŠãè€éã§ã©ã³ãã ãªãã¹ã¯ãŒããçæããæå·åããã圢åŒã§ä¿åããååã«éç¥ããŸãïŒæå·åããããã¡ã€ã«ãšãã¹ã¯ãŒãã®åæïŒã
passwd deploy
sudoã®ã€ã³ã¹ããŒã«ã¯ç°¡åã§ãã sudoãã¡ã€ã«ãéããŸãã
visudo
以äžã«ç€ºãããã«ãrootãŠãŒã¶ãŒãšããŠã°ã«ãŒã
%sudo
ã远å ããŸãã ä»ã®ãã¹ãŠã®ãŠãŒã¶ãŒãšã°ã«ãŒããã
#
èšå·ãä»ããã³ã¡ã³ãã§ç¡å¹ã«ãªã£ãŠããããšã確èªããŸãïŒãŠãŒã¶ãŒã«ã¯ãã¬ãã£ãã¯ã¹ããªããã°ã«ãŒãã¯
%
å§ãŸããŸãïŒã ã»ãšãã©ã®æ°èŠã€ã³ã¹ããŒã«ã§ã¯ã念ã®ããã«äœããããŸããã
root ALL=(ALL) ALL
%sudo ALL=(ALL:ALL) ALL
次ã«ã
deploy
ãŠãŒã¶ãŒã
sudo
ã°ã«ãŒãã«è¿œå ããŸãã
usermod -a -G sudo deploy
ããã«ãããå
ã»ã©äœæãããã¹ã¯ãŒããå
¥åããåŸããããã€ãŠãŒã¶ãŒãsudoã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸãã
ä¿®æ£ã¡ã¢ïŒRedditã®ãŠãŒã¶ãŒackackacksynã«ããŠãŒã¶ãŒãsudoãªã¹ãã«çŽæ¥è¿œå ããªãããã«æ£ããæ³šæããŠãããããšã«æè¬ããŸã ã
sshããŒãã°ã€ã³ãã¢ã¯ãã£ãã«ãã
ãã®ãã·ã³ã®sshèšå®ã¯æ¬¡ã®å Žæã«ä¿åãããŸãã
vim /etc/ssh/sshd_config
ããã«æ°è¡ã远å ããå¿
èŠããããŸãã ç§ã«ã¯ã圌ãã¯èªåèªèº«ã§ããªãæç¢ºã§ããããã«æããŸãã ããã¯ãæ¥ç¶ã«äœ¿çšããIPã¢ãã¬ã¹ã§ãã åœç€Ÿã§ã¯ãOpenVPNãšæå·åèªèšŒãåããVPNæ§æã䜿çšããŠããããããµãŒããŒã«æ¥ç¶ããã«ã¯ãèªèšŒããŠVPNã«æ¥ç¶ããå¿
èŠããããŸãã
PermitRootLogin no
PasswordAuthentication no
AllowUsers deploy@(your-VPN-or-static-IP)
sshãµãŒãã¹ãåèµ·åããŠããããã®ã«ãŒã«ããã¹ãŠã¢ã¯ãã£ãã«ããŸãã ãããã忥ç¶ããå¿
èŠããããŸãïŒããã¯deployãŠãŒã¶ãŒãä»ããŠè¡ããŸãïŒïŒã
service ssh restart
ãã¡ã€ã¢ãŠã©ãŒã«ã®ã€ã³ã¹ããŒã«
éåžžã2ã€ã®ãã£ã³ãããããŸãã IPtablesãçŽæ¥äœ¿çšãããã®ãããã°ãèšå®ããã»ã¹ãç°¡çŽ åããããã«IPtablesã®äžã®ã¬ã€ã€ãŒã§ãã
ufw
ãšåŒã°ãã䟿å©ãªã€ã³ã¿ãŒãã§ãŒã¹ã䜿çšãããã®ããããŸãã ã»ãã¥ãªãã£ã®èгç¹ããã¯ãéåžžãããã·ã³ãã«ãªãªãã·ã§ã³ãæãŸããã§ãã
DigitalOceanã®ufwã¯æ¬åœã«åªããŠãããåºæ¬çãªããšãæ¯æŽããŸãã
ufw
Ubuntuã«ããã©ã«ãã§ã€ã³ã¹ããŒã«ãããDebianã§ã¯
apt-get install ufw
å®è¡ããã ãã§ãã
ããã©ã«ãã§ã¯ã
ufw
ã¯ãã¹ãŠã®çä¿¡æ¥ç¶ãæåŠãããã¹ãŠã®çºä¿¡æ¥ç¶ãèš±å¯ããå¿
èŠããããŸãããèµ·åããŸããïŒããã§ãªãå Žåãã©ã®ããã«æ¥ç¶ããŸããïŒïŒã éåžžéããšèŠãªãããæ¥ç¶ãééããŠãæç€ºçã«èš±å¯ããŸãã
ãŸããIPv6ããµããŒãããŠããããšã確èªããŠãã ããã æ§æãã¡ã€ã«ãéããŸãã
vim /etc/default/ufw
IPv6ã
yes
èšå®ã
yes
ã
IPV6=yes
éãäºå®ã®æ®ãã®ããŒãã«ã€ããŠã¯ãã³ãã³ãã©ã€ã³ãã
ufw
ããŒã«ã䜿çšã§ããŸããããã¯éåžžã«äŸ¿å©ã§ãã
sudo ufw allow from {your-ip} to any port 22
sudo ufw allow 80
sudo ufw allow 443
sudo ufw disable
sudo ufw enable
1ã€ã¯åé·ãªææ®µã§ãIPã¢ãã¬ã¹ããã®æ¥ç¶ã®ã¿ãSSHïŒæšæºSSHããŒãïŒãä»ããŠæ¥ç¶ã§ããããã«ããŸã
2 ã 2çªç®ãš3çªç®ã®ããŒã ã¯ãhttpããã³httpsãã©ãã£ãã¯ãéããŸãã
æ³šïŒæåã®ã«ãŒã«ãèšå®ããå ŽåïŒããã³å®è¡ããå¿
èŠãããå ŽåïŒãæ¥ç¶ããéçIPã¢ãã¬ã¹ãŸãã¯ã»ãã¥ã¢VPNãããããšã確èªããŠãã ããã åçIPã¢ãã¬ã¹ã䜿çšãããšãå°æ¥ãµãŒããŒã«ã¢ã¯ã»ã¹ã§ããªããªããŸãã
èªåã»ãã¥ãªãã£æŽæ°
ç§ã¯ãããã奜ãã§ãã å®å
šã§ã¯ãããŸãããããªãªãŒã¹åŸã«ããããã¹ããããããããåªããŠããŸãã
apt-get install unattended-upgrades
vim /etc/apt/apt.conf.d/10periodic
ãã®ãã¡ã€ã«ã次ã®ããã«æŽæ°ããŸãã
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Download-Upgradeable-Packages "1";
APT::Periodic::AutocleanInterval "7";
APT::Periodic::Unattended-Upgrade "1";
ç§ã¯éåžžã宿çãªæŽæ°ãç¡å¹ã«ããã»ãã¥ãªãã£ã®æŽæ°ã®ã¿ãæ®ãæ¹ãè¯ããšãããã©ã€ã¢ã³ã«åæããŸãã ã¢ã€ãã¢ã¯ãäŸåé¢ä¿ã®ããããã±ãŒãžã®æŽæ°ã®ããã«ã¢ããªã±ãŒã·ã§ã³ãçªç¶åäœã忢ãããšããŸãè¯ããªãããã»ãã¥ãªãã£ã®æŽæ°ã¯ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã§äŸåé¢ä¿ã®åé¡ãäœæããããšã¯ã»ãšãã©ãªããšããããšã§ãã
vim /etc/apt/apt.conf.d/50unattended-upgrades
次ã®ããã«ãã¡ã€ã«ãç·šéããŸãã
Unattended-Upgrade::Allowed-Origins {
"Ubuntu lucid-security";
//"Ubuntu lucid-updates";
};
ãã¹ãŠæºåå®äºã§ãã
Fail2ban

fail2banã¯ãçãããã¢ã¯ãã£ããã£ãæ€åºããããšããã«ããã¢ã¯ãã£ãã«ãããã¯ããåªããããã±ãŒãžã§ãã 圌ãã®
ãŠã£ãã«ãããšãfail2banã¯ãã°ãã¡ã€ã«ïŒ
/var/log/apache/error_log
ïŒãã¹ãã£ã³ããçãããå
åã瀺ãIPã¢ãã¬ã¹ãçŠæ¢ããŠããŸã-ééã£ããã¹ã¯ãŒãã®å
¥åããšã¯ã¹ããã€ãã®æ€çŽ¢ãªã©ãå€ããã... Fail2Banãã€ã³ã¹ããŒã«ãããçŽåŸããŸããŸãªãµãŒãã¹ïŒapacheãcourierãsshãªã©ïŒã®ãã£ã«ã¿ãŒã
apt-get install fail2ban
äºèŠçŽ èªèšŒ
ã»ãã¥ãªãã£æšæºã«æºæ ããã·ã¹ãã ãèšèšããå Žåã2èŠçŽ èªèšŒãå¿
èŠã§ãã çè«çã«ã¯ãä»ã®ãã¹ãŠã®ä¿è·ææ®µã«å ããŠ2èŠçŽ èªèšŒãã¢ã¯ãã£ãã«ããå ŽåããµãŒããŒãžã®ã¢ã¯ã»ã¹ãåŸãããã«ïŒã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ãéãããšã«ããïŒãæ»æè
ã¯æ¬¡ã®ããšãå¿
èŠã«ãªããŸãã
- èšŒææžãšVPNã¢ã¯ã»ã¹ããŒãžã®ã¢ã¯ã»ã¹ã
- ã³ã³ãã¥ãŒã¿ãŒã«ã¢ã¯ã»ã¹ããŠç§å¯éµãååŸããŸãã
- ç§å¯éµã®ãã¹ãã¬ãŒãºã«ã¢ã¯ã»ã¹ããŸãã
- äºèŠçŽ èªèšŒã®ããã«é»è©±ã«ã¢ã¯ã»ã¹ããŸãã
ãããã¯ãå
æããªããã°ãªããªãå€ãã®éå£ïŒ4ã€ïŒã§ãã sudoãä»ããŠã«ãŒãã¢ã¯ã»ã¹ãååŸããå Žåã§ããAESæå·åïŒ5çªç®ã®ããªã¢ïŒã§ä¿è·ãããŠããå±éãã¹ã¯ãŒããèŠã€ããå¿
èŠããããŸãã
ããã±ãŒãžãã€ã³ã¹ããŒã«ããŸãã
apt-get install libpam-google-authenticator
ã€ã³ã¹ããŒã«ããã«ã¯ãã³ãã³ããå®è¡ããæç€ºã«åŸã£ãŠãã ããïŒ
su deploy
google-authenticator
äºèŠçŽ èªèšŒã¯éåžžã«ç°¡åã«ã€ã³ã¹ããŒã«ã§ããã»ãã¥ãªãã£ã®è¿œå ã¬ã€ã€ãŒã远å ãããŸãã
ãã°ãŠã©ãã
ãã®ããŒã«ã¯ãäºåŸã®åã³ãšç£èŠã«é©ããŠããŸãã ãã°ãŠã©ããã¯ãã°ã远跡ããèšå®ã«åŸã£ãŠãæ¯æ¥ãçŸããæ§é åãããèŠçŽãã¡ãŒã«ã§éä¿¡ããŸãã ããã¯éåžžã«é¢çœãããŒã¿ã§ããããµãŒããŒãžã®ã¢ã¯ã»ã¹è©Šè¡ãæ¯æ¥äœåçºçãããã«é©ãã§ãããã ã»ãã¥ãªãã£ã確ä¿ããããšãããã«éèŠããååã«ç€ºãããã ãã«ã€ã³ã¹ããŒã«ããŸããã
DigitalOceanã«ã¯Logwatch
ã®ã€ã³ã¹ããŒã«ãšèšå®ã«é¢ããåªãã説æããããŸãã
ã 10åã®
æéã«éã«åããããå Žåã¯ãã€ã³ã¹ããŒã«ããŠcronã¿ã¹ã¯ãå®è¡ããæ¯æ¥èµ·åããŠé»åã¡ãŒã«ãéä¿¡ããŸãã
apt-get install logwatch
cronãžã§ãã远å ããŸãã
vim /etc/cron.daily/00logwatch
cronãã¡ã€ã«ã«æ¬¡ã®è¡ã远å ããŸãã
/usr/sbin/logwatch --output mail --mailto you@example.com --detail high
ãã¹ãŠæºåå®äº
ããããã«ã äžèšã®ãã¹ãŠãå®äºããåŸãäž»ãªæžå¿µäºé
ããã³é害ç¹ã¯ã¢ããªã±ãŒã·ã§ã³ãšãµãŒãã¹ã«ãªããŸãã ããã¯å®å
šã«ç°ãªãé åã§ãã
ç§ãã¡ã¯ããã¹ããã©ã¯ãã£ã¹ãšããã»ã¹ãå¯èœãªéã圢åŒåããŠèª¬æããããšã
ãŸã ã詳ããç¥ãããå Žåã¯ã
ãªããžããªã調ã¹ãŠãã ããã ãã¹ãŠããããªãã¯ãã¡ã€ã³ã«ãããç§ãã¡ã¯ãããè£å
ãç¶ããŸãã
1 `.pub`ãæå®ãããŠããããšã確èªããŠãã ããã ãšãŠãç°¡åã«æããŸãããç§ãå°ãããšããç§å¯éµïŒ `id_rsa`ãæ¡åŒµåãªãã§ïŒãéã£ãŠãã圌ãã®ãã£ãªã¢ã®éã«ãç§ã¯2人ã®ä»²éã«äŒããŸããïŒäž¡æ¹ãšã*ç§ãã¡ã®äŒç€Ÿã§åããŠããŸãã-圌ãã¯ããã«ããã§åããŠããŸããïŒå
¬ééµãéä¿¡ããŸãã
èšäºã«æ»ã2 SSHæ¥ç¶ã«æšæºããŒããšéæšæºããŒãã®ã©ã¡ããå²ãåœãŠããã«ã€ããŠã®æèŠã¯ç°ãªããŸãã
ãããš
ããã®äž¡åŽ
ã®è°è«ãèŠãŠãã ããã
èšäºã«æ»ã