ã³ã³ããã¯ãLinuxãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ãŠãŒã¶ãŒã¹ããŒã¹ã®è»œéããŒãžã§ã³ã§ããå®éãããã¯ãæäœéã®ãæäœéã®æ©èœã§ãã ããã«ãããããããããã¯ãŸã æ¬æ Œçãªãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ããããããã®ã³ã³ããèªäœã®å質ã¯æ¬æ Œçãªãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãšåããããéèŠã§ãã ãã®ããããŠãŒã¶ãŒãèªå®ãããææ°ã®ãšã³ã¿ãŒãã©ã€ãºã¬ãã«ã®ã³ã³ããã䜿çšã§ããããã«ã
Red Hat Enterprise LinuxïŒRHELïŒã€ã¡ãŒãžãé·ãéæäŸããŠããŸããã ã³ã³ãããã¹ãã§RHELã®ã³ã³ããã€ã¡ãŒãžãå®è¡ãããšãRHELã¯ç°å¢éã®äºææ§ãšç§»æ€æ§ãæäŸããŸãããã¡ããããããã¯æ¢ã«ããç¥ãããããŒã«ã§ãã ãã ãã1ã€ã®åé¡ããããŸããã Red Hat Enterprise Linuxã䜿çšããŠãã顧客ãããŒãããŒã§ãã£ãŠãããã®ãããªç»åãä»ã®èª°ãã«è»¢éããããšã¯ã§ããŸããã§ããã
ããããä»ã§ã¯ãã¹ãŠãå€ãã£ã
Red Hat Universal Base ImageïŒUBIïŒã®ãªãªãŒã¹ã«ããããµãã¹ã¯ãªãã·ã§ã³ãæã£ãŠãããã©ããã«é¢ä¿ãªããå
¬åŒã®Red Hatã³ã³ããã€ã¡ãŒãžã®äœ¿ãæ
£ããä¿¡é Œæ§ãã»ãã¥ãªãã£ãããã³é«æ§èœãååŸã§ããããã«ãªããŸããã ããã¯ãUBIã§ã³ã³ããåãããã¢ããªã±ãŒã·ã§ã³ãæ§ç¯ãããããéžæããã³ã³ããã¬ãžã¹ããªã«é
眮ããäžçãšå
±æã§ããããšãæå³ããŸãã Red Hat Universal Base Imageã䜿çšãããšãããããç°å¢ã®ã³ã³ããåãããã¢ããªã±ãŒã·ã§ã³ã§ãã©ãã§ã奜ããªå Žæã§ãã«ããå
±æãã³ã©ãã¬ãŒã·ã§ã³ã§ããŸãã
UBIã®ãããã§ãã»ãŒãã¹ãŠã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã§ã¢ããªã±ãŒã·ã§ã³ãå
¬éããã³å®è¡ã§ããŸãã ãã ããRed Hat OpenShiftãRed Hat Enterprise Linuxãªã©ã®Red Hatãã©ãããã©ãŒã ã§ããããå®è¡ãããšãè¿œå ã®ã¡ãªãããåŸãããšãã§ããŸãïŒããã«ãŽãŒã«ããè¿œå ãããŸãïŒïŒã UBIã®è©³çŽ°ãªèª¬æã«ç§»ããŸã§ãRHELãµãã¹ã¯ãªãã·ã§ã³ãå¿
èŠãªçç±ã«é¢ããçãFAQãæäŸããŸãã ããã§ã¯ãRHEL / OpenShiftãã©ãããã©ãŒã ã§UBIã€ã¡ãŒãžãå®è¡ãããšã©ããªããŸããïŒ
ããŒã±ãã£ã³ã°ã«æºè¶³ããŠããã®ã§ãUBIã«ã€ããŠè©³ãã説æããŸããã
UBIã䜿çšããçç±
UBIãããªãã«ãšã£ãŠåœ¹ç«ã€ããšãç解ããããã«ããªããæããå¿
èŠããããã®ïŒ
- ç§ã®éçºè
ã¯ãããããç°å¢ã§é
åžããã³å®è¡ã§ããã³ã³ããã€ã¡ãŒãžã䜿çšããããšèããŠããŸãã
- ç§ã®éçšããŒã ã¯ããšã³ã¿ãŒãã©ã€ãºã¬ãã«ã®ã©ã€ããµã€ã¯ã«ã§ãµããŒããããŠããåºæ¬çãªã€ã¡ãŒãžãæ±ããŠããŸã
- ç§ã®å»ºç¯å®¶ã¯ ã顧客/ãšã³ããŠãŒã¶ãŒã«Kubernetes OperatorãæäŸããããšèããŠããŸã
- ç§ã®é¡§å®¢ã¯ãRed Hatç°å¢å
šäœã«å¯Ÿãããšã³ã¿ãŒãã©ã€ãºã¯ã©ã¹ã®ãµããŒããæãŸ
ãªã ã - ç§ã®ã³ãã¥ããã£ã¯ãæåéãã©ãã§ãã¢ããªã±ãŒã·ã§ã³ãå
±æãå®è¡ãå
¬éããã¹ãããããšèããŠããŸãã
å°ãªããšã1ã€ã®ã·ããªãªãèªåã«åã£ãŠããå Žåã¯ãééããªãUBIã«æ³šæãæãå¿
èŠããããŸãã
åãªãåºæ¬çãªå€èŠ³ä»¥äžã®ãã®
UBIã¯æ¬æ ŒçãªOSã§ã¯ãããŸããããUBIã«ã¯3ã€ã®éèŠãªããšããããŸãã
- 3ã€ã®åºæ¬ç»åã®ã»ããïŒubiãubi-minimalãubi-initïŒ
- ããŸããŸãªããã°ã©ãã³ã°èšèªïŒnodejsãrubyãpythonãphpãperlãªã©ïŒã®æ¢è£œã®ã©ã³ã¿ã€ã ãå«ãç»å
- æãäžè¬çãªäŸåé¢ä¿ãæã€YUMãªããžããªå
ã®é¢é£ããã±ãŒãžã®ã»ãã
UBIã¯ã¯ã©ãŠãã®åºç€ãšããŠäœæãããŸãã-ã³ã³ããã§éçºããã³é
ä¿¡ããããã€ãã£ãããã³Webã¢ããªã±ãŒã·ã§ã³ã UBIã®ãã¹ãŠã®ã³ã³ãã³ãã¯RHELã®ãµãã»ããã§ãã UBIã®ãã¹ãŠã®ããã±ãŒãžã¯RHELãã£ãã«ãçµç±ããOpenShiftãRHELãªã©ã®ãµããŒããããŠããRed Hatãã©ãããã©ãŒã ã§èµ·åãããå ŽåãRHELã®ããã«ãµããŒããããŸãã
é«å質ã®ã³ã³ãããµããŒããæäŸããã«ã¯ããšã³ãžãã¢ãã»ãã¥ãªãã£ã¹ãã·ã£ãªã¹ããããã³ãã®ä»ã®è¿œå ãªãœãŒã¹ã®å€å€§ãªåªåãå¿
èŠã§ãã åºæ¬çãªã€ã¡ãŒãžããã¹ãããã ãã§ãªãããµããŒããããŠãããã¹ãã§ãã®åäœãåæããããšãå¿
èŠã§ãã
ã¢ããã°ã¬ãŒãã¿ã¹ã¯ã容æã«ãããããRed Hatã¯ç©æ¥µçã«éçºãšãµããŒããéçºããŠãããããšãã°RBI 8ãã¹ãã§UBI 7ãå®è¡ããããRHEL 7ãã¹ãã§UBI 8ãå®è¡ãããããããšãã§ããŸãã ãããšãã°ãã³ã³ããã€ã¡ãŒãžãŸãã¯äœ¿çšæžã¿ãã¹ãã®ãã©ãããã©ãŒã ã®æŽæ°ã ããã¯ãã¹ãŠã2ã€ã®ç¬ç«ãããããžã§ã¯ãã«åå²ã§ããŸãã
3ã€ã®åºæ¬çãªç»å
æå°é-ãã¹ãŠã®äŸåé¢ä¿ïŒPythonãNode.jsã.NETãªã©ïŒãæã€ã¢ããªã±ãŒã·ã§ã³çšã«èšèšãããŠããŸã
- ãã¬ã€ã³ã¹ããŒã«ãããã³ã³ãã³ãã®æå°ã»ãã
- suidå®è¡å¯èœãã¡ã€ã«ã¯ãããŸãã
- æå°ããã±ãŒãžãããŒãžã£ãŒããŒã«ãããïŒã€ã³ã¹ããŒã«ãæŽæ°ãã¢ã³ã€ã³ã¹ããŒã«ïŒ
ãã©ãããã©ãŒã -RHELã§å®è¡ãããŠãããã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³çš
- OpenSSL Unified Cryptographic Stack
- YUMãã«ã¹ã¿ãã¯
- 䟿å©ãªåºæ¬OSãŠãŒãã£ãªãã£ãå«ãŸããŠããŸãïŒtarãgzipãviãªã©ïŒ
ãã«ããµãŒãã¹-1ã€ã®ã³ã³ããã§è€æ°ã®ãµãŒãã¹ã®èµ·åãç°¡çŽ åããŸã
- èµ·åæã«systemdãå®è¡ããããã«æ§æ
- ãã«ã段éã§ãµãŒãã¹ãæå¹ã«ããæ©èœ
ããã°ã©ãã³ã°èšèªã®æ¢è£œã©ã³ã¿ã€ã ãåããã³ã³ããã®ç»å
UBIã«ã¯ãããã°ã©ãã³ã°èšèªã®ãµããŒããã€ã³ã¹ããŒã«ã§ããåºæ¬çãªã€ã¡ãŒãžã«å ããŠãå€ãã®ããã°ã©ãã³ã°èšèªã®æ¢è£œã®ã©ã³ã¿ã€ã ãåãããã«ãæžã¿ã®ã€ã¡ãŒãžãå«ãŸããŠããŸãã å€ãã®éçºè
ã¯ãåã«ã€ã¡ãŒãžãååŸããŠãéçºäžã®ã¢ããªã±ãŒã·ã§ã³ã§äœæ¥ãéå§ã§ããŸãã
Red Hatã¯ãUBIã®ãªãªãŒã¹ã«åãããŠãRHEL 7ããŒã¹ãšRHEL 8ããŒã¹ã®2ã»ããã®ã€ã¡ãŒãžãæäŸããŸãããããããRed Hat Software CollectionsïŒRHEL 7ïŒãšApplication StreamsïŒRHEL 8ïŒãããŒã¹ã«ãªããŸããã ãããã®ã©ã³ã¿ã€ã ã¯ææ°ã®ç¶æ
ã«ä¿ãããæšæºã§å¹Žéæ倧4ã€ã®ã¢ããããŒããåãåããããåžžã«ææ°ã§æãå®å®ããããŒãžã§ã³ã䜿çšããæ©äŒããããŸãã
UBI 7ã³ã³ããã€ã¡ãŒãžã®ãªã¹ãã¯æ¬¡ã®ãšããã§ããUBI 8ã®ã³ã³ããã€ã¡ãŒãžã®ãªã¹ãã¯æ¬¡ã®ãšããã§ããé¢é£ããã±ãŒãž
æ¢è£œã®ç»åã䜿çšããããšã¯éåžžã«äŸ¿å©ã§ãã Red Hatã¯é¢é£æ§ãç¶æããRHELã®æ°ããããŒãžã§ã³ã®ãªãªãŒã¹ã§æŽæ°ããŸãããŸãã
RHELã€ã¡ãŒãžããªã·ãŒæŽæ°
ããªã·ãŒã«åŸã£ãŠéèŠãªCVEæŽæ°ãè¡ãããšã§ããããã®ã€ã¡ãŒãžã®1ã€ãååŸããŠããã«ã¢ããªã±ãŒã·ã§ã³ã§äœæ¥ãéå§ã§ããŸãã
ãã ããã¢ããªã±ãŒã·ã§ã³ãäœæãããšãã«ãè¿œå ã®ããã±ãŒãžãçªç¶å¿
èŠã«ãªãå ŽåããããŸãã ãŸãã¯ãã¢ããªã±ãŒã·ã§ã³ãæ©èœãããããã«ãç¹å®ã®ããã±ãŒãžãæŽæ°ããå¿
èŠãããå ŽåããããŸãã ãã®ãããUBIã€ã¡ãŒãžã«ã¯ãyumãä»ããŠå©çšã§ããé«éã§å¯çšæ§ã®é«ãã³ã³ãã³ãé
ä¿¡ãããã¯ãŒã¯ãä»ããŠé
åžãããRPMã®ã»ãããä»å±ããŠããŸãïŒããã±ãŒãžãå¿
èŠã§ãïŒïŒã ãªãªãŒã¹ã®ãã®éèŠãªç¬éã«CI / CDã§yumæŽæ°ãå®è¡ãããšããããæ©èœããããšã確èªã§ããŸãã
RHELã¯åºç€ã§ã
RHELããã¹ãŠã®åºç€ã§ããããšãç¹°ãè¿ãããšã«é£œããããšã¯ãããŸããã Red Hatã®ã©ã®ããŒã ãåºæ¬çãªã€ã¡ãŒãžã®äœæã«åãçµãã§ãããç¥ã£ãŠããŸããïŒ ããšãã°ã次ã®ãšããã§ãã
- glibcãOpenSSLãªã©ã®ã³ã¢ã©ã€ãã©ãªãããã³PythonãRubyãªã©ã®èšèªã©ã³ã¿ã€ã ããã³ã³ããã§äœ¿çšãããå Žåã«äžè²«ããããã©ãŒãã³ã¹ãæäŸããã¯ãŒã¯ããŒãã§ç¢ºå®ã«åäœããããšãä¿èšŒãã責任ãè² ããšã³ãžãã¢ãªã³ã°ããŒã ã
- 補åã»ãã¥ãªãã£ã°ã«ãŒãã¯ãã©ã€ãã©ãªããã³èšèªç°å¢ã®ãšã©ãŒãšã»ãã¥ãªãã£åé¡ã®ã¿ã€ã ãªãŒãªä¿®æ£ã«åŸäºããŠããããã®ããã©ãŒãã³ã¹ã¯ç¹å¥ãªContainer Health Indexã°ã¬ãŒãã䜿çšããŠè©äŸ¡ãããŸãã
- ãããã¯ããããŒãžã£ãŒãšãšã³ãžãã¢ã®ããŒã ã¯ãæ°ããæ©èœãè¿œå ããé·ã補åã©ã€ããµã€ã¯ã«ãæäŸããŠããŸããããã«ãããåºç€ãšããŠäœ¿çšã§ããæè³ã«èªä¿¡ãæãŠãŸãã
Red Hat Enterprise Linuxã¯ã³ã³ãããŒã®åªãããã¹ãããã³ã€ã¡ãŒãžãšããŠæ©èœããŸãããå€ãã®éçºè
ã«ãšã£ãŠãããŸããŸãªåœ¢åŒã§ã·ã¹ãã ãæäœããèœåãéèŠã§ããããã®äžéšã¯Linuxã·ã¹ãã ã®äœ¿çšã«é¢ãããµããŒããããŠããã·ããªãªãè¶
ããå ŽåããããŸãã ãããŠãããã§æ®éçãªUBIç»åãå©ãã«ãªããŸãã
ä»ããã®æ®µéã§ãåçŽãªã³ã³ããåãããã¢ããªã±ãŒã·ã§ã³ã§äœæ¥ãéå§ããããã®åºæ¬çãªã€ã¡ãŒãžãæ¢ããŠãããšä»®å®ããŸãã ãŸãã¯ãå°æ¥ã«è¿ã¥ããã³ã³ãããšã³ãžã³ã§å®è¡ãããŠããã¹ã¿ã³ãã¢ãã³ã³ã³ãããããOpenShiftã§å®è¡ãããŠãããªãã¬ãŒã¿ã®æ§ç¯ãšèªèšŒã䜿çšããã¯ã©ãŠãåºæã®å±¥æŽã«ç§»è¡ããŠããŸããã ãããã«ãããUBIã¯ãã®ããã®åªããåºç€ãæäŸããŸãã
ã³ã³ããã«ã¯ãæ°ããããã±ãŒãžã³ã°åœ¢åŒã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ãŠãŒã¶ãŒã¹ããŒã¹ã®è»œéããŒãžã§ã³ãå«ãŸããŠããŸãã UBIã€ã¡ãŒãžã®ãªãªãŒã¹ã¯ãã³ã³ããåéçºã®æ°ããæ¥çæšæºãšãªãããšã³ã¿ãŒãã©ã€ãºã¯ã©ã¹ã®ã³ã³ããããã¹ãŠã®ãŠãŒã¶ãŒãç¬ç«ç³»ãœãããŠã§ã¢éçºè
ãããã³ãªãŒãã³ãœãŒã¹ã³ãã¥ããã£ã§å©çšå¯èœã«ãªããŸãã ç¹ã«ããœãããŠã§ã¢éçºè
ã¯ã
Kubernetes Operatorsãå«ããã¹ãŠã®ã³ã³ããåãããã¢ããªã±ãŒã·ã§ã³ã«å¯ŸããŠãåäžã®å®èšŒæžã¿ã®åºç€ã䜿çšããŠè£œåãæšæºåã§ããŸãã Red Hat Container Certificationããã³Red Hat OpenShift Operator Certificationèªå®ã¯ãUBIããŒã¹ã®éçºäŒç€Ÿã§ãå©çšã§ããŸããããã«ãããOpenShiftãªã©ã®Red Hatãã©ãããã©ãŒã ã§å®è¡ãããŠãããœãããŠã§ã¢ã®ç¶ç¶çãªæ€èšŒãå¯èœã«ãªããŸãã
ç»åã®äœ¿çšãéå§ããæ¹æ³
èŠããã«-éåžžã«ç°¡åã§ãã Podmanã¯ãRHELã ãã§ãªããFedoraãCentOSãããã³ä»ã®å€ãã®Linuxãã£ã¹ããªãã¥ãŒã·ã§ã³ã§ãå©çšã§ããŸãã å¿
èŠãªããšã¯ã次ã®ãªããžããªã®ããããããã€ã¡ãŒãžãã¢ã³ããŒãããã ãã§ãã
UBI 8ã®å ŽåïŒ
podman pull registry.access.redhat.com/ubi8/ubi podman pull registry.access.redhat.com/ubi8/ubi-minimal podman pull registry.access.redhat.com/ubi8/ubi-init
UBI 7ã®å ŽåïŒ
podman pull registry.access.redhat.com/ubi7/ubi podman pull registry.access.redhat.com/ubi7/ubi-minimal podman pull registry.access.redhat.com/ubi7/ubi-init
ãŸããå®å
šãªãŠãããŒãµã«ããŒã¹ã€ã¡ãŒãžã¬ã€ããåç
§ããŠãã ãã