{"id":1489,"date":"2025-06-04T06:03:25","date_gmt":"2025-06-03T21:03:25","guid":{"rendered":"https:\/\/itstudy365.com\/blog\/?p=1489"},"modified":"2025-06-04T06:03:25","modified_gmt":"2025-06-03T21:03:25","slug":"kubernetes-learning-%e7%ac%ac31%e7%ab%a0%ef%bc%9a%e3%82%b3%e3%83%b3%e3%83%86%e3%83%8a%e3%81%ae%e3%82%bb%e3%82%ad%e3%83%a5%e3%83%aa%e3%83%86%e3%82%a3%e5%af%be%e7%ad%96%ef%bc%88podsecurity%e3%81%aa","status":"publish","type":"post","link":"https:\/\/itstudy365.com\/blog\/2025\/06\/04\/kubernetes-learning-%e7%ac%ac31%e7%ab%a0%ef%bc%9a%e3%82%b3%e3%83%b3%e3%83%86%e3%83%8a%e3%81%ae%e3%82%bb%e3%82%ad%e3%83%a5%e3%83%aa%e3%83%86%e3%82%a3%e5%af%be%e7%ad%96%ef%bc%88podsecurity%e3%81%aa\/","title":{"rendered":"Kubernetes Learning \u7b2c31\u7ae0\uff1a\u30b3\u30f3\u30c6\u30ca\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\uff08PodSecurity\u306a\u3069\uff09\uff5eKubernetes\u74b0\u5883\u3092\u5b88\u308b\u305f\u3081\u306b\u6700\u4f4e\u9650\u77e5\u3063\u3066\u304a\u304d\u305f\u3044\u3053\u3068\uff5e"},"content":{"rendered":"\n<button id=\"bb1\" type=\"button\" value=\"Play\" class=\"responsivevoice-button\" title=\"ResponsiveVoice Tap to Start\/Stop Speech\"><span>&#128266; Play<\/span><\/button>\n        <script>\n            bb1.onclick = function(){\n                if(responsiveVoice.isPlaying()){\n                    responsiveVoice.cancel();\n                }else{\n                    responsiveVoice.speak(\"Kubernetes\u3067\u306f\u3001\u591a\u304f\u306e\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u304c\u30b3\u30f3\u30c6\u30ca\u3068\u3057\u3066\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002\u4fbf\u5229\u306a\u4e00\u65b9\u3067\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u304c\u4e0d\u5341\u5206\u306a\u307e\u307e\u3060\u3068\u3001\u5185\u90e8\u304b\u3089\u306e\u653b\u6483\u3084\u8aa4\u64cd\u4f5c\u306b\u3088\u3063\u3066\u30af\u30e9\u30b9\u30bf\u30fc\u5168\u4f53\u304c\u5371\u967a\u306b\u3055\u3089\u3055\u308c\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002 \u305d\u306e\u305f\u3081\u3001\u300c\u30b3\u30f3\u30c6\u30ca\u306b\u4f55\u3092\u8a31\u53ef\u3059\u308b\u304b\u3001\u4f55\u3092\u7981\u6b62\u3059\u308b\u304b\u300d\u3092\u5236\u5fa1\u3059\u308b\u624b\u6bb5\u304c\u5fc5\u8981\u3067\u3059\u3002\u305d\u3053\u3067\u767b\u5834\u3059\u308b\u306e\u304c Kubernetes \u306e PodSecurity\uff08\u30dd\u30c3\u30c9\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\uff09 \u6a5f\u80fd\u3067\u3059\u3002 \ud83d\udd10 \u306a\u305c\u30b3\u30f3\u30c6\u30ca\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u304c\u5fc5\u8981\u304b\uff1f \u4f8b\u3092\u6319\u3052\u3066\u307f\u307e\u3059\u3002 \u3042\u308bPod\u304c\u300croot\u30e6\u30fc\u30b6\u30fc\u3067\u52d5\u4f5c\u300d\u3057\u3066\u3044\u308b \u30db\u30b9\u30c8\u306e \/etc \u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u3092 hostPath \u30de\u30a6\u30f3\u30c8\u3067\u8aad\u307f\u66f8\u304d\u3067\u304d\u308b \u30b3\u30f3\u30c6\u30ca\u304b\u3089\u4ed6\u306ePod\u306e\u30e1\u30bf\u30c7\u30fc\u30bf\u3092\u629c\u304d\u53d6\u308b \u3053\u3046\u3057\u305f\u8a2d\u5b9a\u306f\u3001\u60aa\u610f\u306e\u3042\u308b\u30e6\u30fc\u30b6\u30fc\u306b\u3068\u3063\u3066\u300c\u30af\u30e9\u30b9\u30bf\u30fc\u4e57\u3063\u53d6\u308a\u306e\u5165\u53e3\u300d\u3068\u306a\u308a\u5f97\u307e\u3059\u3002\u3053\u308c\u3092\u9632\u3050\u305f\u3081\u306b\u306f\u3001\u660e\u793a\u7684\u306a\u5236\u9650\u3092\u5b9a\u3081\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002 \u2705 PodSecurity\u3068\u306f\uff1f Kubernetes 1.25 \u4ee5\u964d\u3001PodSecurityPolicy\uff08PSP\uff09\u306f\u5ec3\u6b62\u3055\u308c\u3001\u4ee3\u308f\u308a\u306bPod Security Admission\uff08PSA\uff09 \u3068\u3044\u3046\u6a5f\u80fd\u304c\u6b63\u5f0f\u306b\u5c0e\u5165\u3055\u308c\u307e\u3057\u305f\u3002 PSA \u306f\u3001Pod\u306e\u4ed5\u69d8\uff08YAML\uff09\u3092\u30c1\u30a7\u30c3\u30af\u3057\u3066\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u57fa\u6e96\u306b\u6cbf\u308f\u306a\u3044Pod\u3092\u62d2\u5426\u30fb\u8b66\u544a\u3059\u308b\u4ed5\u7d44\u307f\u3067\u3059\u3002 \ud83d\udea6 PodSecurity \u306e\u30e2\u30fc\u30c9\uff083\u6bb5\u968e\uff09 \u30ec\u30d9\u30eb\u8aac\u660e\u4f8bprivileged\u5236\u9650\u306a\u3057\uff08\u6700\u3082\u7de9\u3044\uff09root\u3067\u306e\u5b9f\u884c\u3001\u7279\u6a29\u30b3\u30f3\u30c6\u30ca\u306a\u3069OKbaseline\u4e00\u822c\u7684\u306a\u7528\u9014\u306b\u9069\u3057\u305f\u6700\u4f4e\u9650\u306e\u5236\u9650hostPath\u4f7f\u7528NG\u3001\u7279\u6a29\u30e2\u30fc\u30c9NGrestricted\u672c\u756a\u5411\u3051\u306e\u5f37\u3044\u5236\u9650root\u30e6\u30fc\u30b6\u30fcNG\u3001CAP\u306e\u8ffd\u52a0NG \u306a\u3069 \u3053\u308c\u3089\u306e\u30ec\u30d9\u30eb\u306fNamespace\u5358\u4f4d\u3067\u9069\u7528\u3067\u304d\u307e\u3059\u3002 \ud83e\udde9 Namespace \u3078\u306e\u9069\u7528\u4f8b Namespace\u306b\u5bfe\u3057\u3066 restricted \u30ec\u30d9\u30eb\u3092\u9069\u7528\u3059\u308b\u4f8b\u3067\u3059\uff1a kubectl label namespace dev \\ pod-security.kubernetes.io\/enforce=restricted \\ pod-security.kubernetes.io\/enforce-version=latest \u3053\u308c\u306b\u3088\u308a\u3001dev \u540d\u524d\u7a7a\u9593\u306b restricted \u30ec\u30d9\u30eb\u306e\u30dd\u30ea\u30b7\u30fc\u304c\u5f37\u5236\u3055\u308c\u3001\u30eb\u30fc\u30eb\u306b\u9055\u53cd\u3059\u308bPod\u306f\u4f5c\u6210\u3067\u304d\u306a\u304f\u306a\u308a\u307e\u3059\u3002 \ud83e\uddea \u30e2\u30fc\u30c9\u306e\u7a2e\u985e PodSecurity\u306b\u306f3\u3064\u306e\u300c\u52d5\u4f5c\u30e2\u30fc\u30c9\u300d\u304c\u3042\u308a\u307e\u3059\uff1a \u30e2\u30fc\u30c9\u8aac\u660eenforce\u9055\u53cd\u304c\u3042\u308c\u3070 Pod \u4f5c\u6210\u3092\u62d2\u5426audit\u62d2\u5426\u306f\u3057\u306a\u3044\u304c\u30ed\u30b0\u306b\u8a18\u9332\u3059\u308bwarn\u30e6\u30fc\u30b6\u30fc\u306b\u8b66\u544a\u3092\u51fa\u3059\u304c\u62d2\u5426\u306f\u3057\u306a\u3044 \u4f8b\u3048\u3070\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u3001\u8b66\u544a\u3068\u76e3\u67fb\u3060\u3051\u3092\u8a2d\u5b9a\u3059\u308b\u3053\u3068\u3082\u3067\u304d\u307e\u3059\uff1a kubectl label namespace test \\ pod-security.kubernetes.io\/audit=restricted \\ pod-security.kubernetes.io\/warn=restricted \ud83d\udee0 \u904b\u7528\u306e\u30dd\u30a4\u30f3\u30c8 \u958b\u767a\u7528Namespace\u3067\u306fbaseline\u3001\u5546\u7528\u74b0\u5883\u3067\u306frestricted\u3092\u4f7f\u3046\u306e\u304c\u57fa\u672c kubectl explain pod.spec \u3067\u8a31\u5bb9\u3055\u308c\u308b\u4ed5\u69d8\u3092\u78ba\u8a8d\u3059\u308b\u3068\u3088\u3044 kube-apiserver \u306e\u30ed\u30b0\u3084 kubectl create \u306e\u51fa\u529b\u3092\u898b\u3066\u30eb\u30fc\u30eb\u9055\u53cd\u3092\u628a\u63e1\u3067\u304d\u308b \u2699\ufe0f \u4ed6\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\uff08\u88dc\u8db3\uff09 PodSecurity\u3060\u3051\u3067\u306a\u304f\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u5bfe\u7b56\u3082\u6709\u52b9\u3067\u3059\uff1a readOnlyRootFilesystem \u3092\u6709\u52b9\u306b\u3059\u308b SecurityContext \u3067 runAsNonRoot, allowPrivilegeEscalation \u3092\u5236\u9650 NetworkPolicy \u3067\u901a\u4fe1\u5236\u9650 RBAC \u3067\u64cd\u4f5c\u6a29\u9650\u3092\u5236\u9650 \ud83d\udd1a \u307e\u3068\u3081 Kubernetes\u306f\u5f37\u529b\u306a\u4ed5\u7d44\u307f\u3092\u63d0\u4f9b\u3057\u3066\u304f\u308c\u307e\u3059\u304c\u3001\u4f55\u3082\u5236\u9650\u3057\u306a\u3044\u72b6\u614b\u306f\u975e\u5e38\u306b\u5371\u967a\u3067\u3059\u3002\u305d\u306e\u7b2c\u4e00\u6b69\u3068\u3057\u3066\u300cPod\u306b\u8a31\u53ef\u3059\u308b\u3053\u3068\uff0f\u7981\u6b62\u3059\u308b\u3053\u3068\u300d\u3092Namespace\u5358\u4f4d\u3067\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\u3059\u308bPodSecurity\u306e\u8a2d\u5b9a\u306f\u91cd\u8981\u3067\u3059\u3002\", \"Japanese Female\");\n                }\n            };\n        <\/script>\n    <\/p>\n\n\n\n<p>Kubernetes\u3067\u306f\u3001\u591a\u304f\u306e\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u304c<strong>\u30b3\u30f3\u30c6\u30ca<\/strong>\u3068\u3057\u3066\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002\u4fbf\u5229\u306a\u4e00\u65b9\u3067\u3001<strong>\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u304c\u4e0d\u5341\u5206\u306a\u307e\u307e\u3060\u3068\u3001\u5185\u90e8\u304b\u3089\u306e\u653b\u6483\u3084\u8aa4\u64cd\u4f5c\u306b\u3088\u3063\u3066\u30af\u30e9\u30b9\u30bf\u30fc\u5168\u4f53\u304c\u5371\u967a\u306b\u3055\u3089\u3055\u308c\u308b<\/strong>\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u305d\u306e\u305f\u3081\u3001<strong>\u300c\u30b3\u30f3\u30c6\u30ca\u306b\u4f55\u3092\u8a31\u53ef\u3059\u308b\u304b\u3001\u4f55\u3092\u7981\u6b62\u3059\u308b\u304b\u300d\u3092\u5236\u5fa1\u3059\u308b\u624b\u6bb5<\/strong>\u304c\u5fc5\u8981\u3067\u3059\u3002\u305d\u3053\u3067\u767b\u5834\u3059\u308b\u306e\u304c Kubernetes \u306e <strong>PodSecurity\uff08\u30dd\u30c3\u30c9\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\uff09<\/strong> \u6a5f\u80fd\u3067\u3059\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\ud83d\udd10 \u306a\u305c\u30b3\u30f3\u30c6\u30ca\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u304c\u5fc5\u8981\u304b\uff1f<\/h3>\n\n\n\n<p>\u4f8b\u3092\u6319\u3052\u3066\u307f\u307e\u3059\u3002<\/p>\n\n\n\n<ul>\n<li>\u3042\u308bPod\u304c\u300croot\u30e6\u30fc\u30b6\u30fc\u3067\u52d5\u4f5c\u300d\u3057\u3066\u3044\u308b<\/li>\n\n\n\n<li>\u30db\u30b9\u30c8\u306e <code>\/etc<\/code> \u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u3092 <code>hostPath<\/code> \u30de\u30a6\u30f3\u30c8\u3067\u8aad\u307f\u66f8\u304d\u3067\u304d\u308b<\/li>\n\n\n\n<li>\u30b3\u30f3\u30c6\u30ca\u304b\u3089\u4ed6\u306ePod\u306e\u30e1\u30bf\u30c7\u30fc\u30bf\u3092\u629c\u304d\u53d6\u308b<\/li>\n<\/ul>\n\n\n\n<p>\u3053\u3046\u3057\u305f\u8a2d\u5b9a\u306f\u3001\u60aa\u610f\u306e\u3042\u308b\u30e6\u30fc\u30b6\u30fc\u306b\u3068\u3063\u3066\u300c\u30af\u30e9\u30b9\u30bf\u30fc\u4e57\u3063\u53d6\u308a\u306e\u5165\u53e3\u300d\u3068\u306a\u308a\u5f97\u307e\u3059\u3002<br>\u3053\u308c\u3092\u9632\u3050\u305f\u3081\u306b\u306f\u3001<strong>\u660e\u793a\u7684\u306a\u5236\u9650\u3092\u5b9a\u3081\u308b\u5fc5\u8981<\/strong>\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u2705 PodSecurity\u3068\u306f\uff1f<\/h3>\n\n\n\n<p>Kubernetes 1.25 \u4ee5\u964d\u3001<strong>PodSecurityPolicy\uff08PSP\uff09\u306f\u5ec3\u6b62\u3055\u308c\u3001\u4ee3\u308f\u308a\u306bPod Security Admission\uff08PSA\uff09<\/strong> \u3068\u3044\u3046\u6a5f\u80fd\u304c\u6b63\u5f0f\u306b\u5c0e\u5165\u3055\u308c\u307e\u3057\u305f\u3002<\/p>\n\n\n\n<p>PSA \u306f\u3001Pod\u306e\u4ed5\u69d8\uff08YAML\uff09\u3092\u30c1\u30a7\u30c3\u30af\u3057\u3066\u3001<strong>\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u57fa\u6e96\u306b\u6cbf\u308f\u306a\u3044Pod\u3092\u62d2\u5426\u30fb\u8b66\u544a\u3059\u308b<\/strong>\u4ed5\u7d44\u307f\u3067\u3059\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\ud83d\udea6 PodSecurity \u306e\u30e2\u30fc\u30c9\uff083\u6bb5\u968e\uff09<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>\u30ec\u30d9\u30eb<\/th><th>\u8aac\u660e<\/th><th>\u4f8b<\/th><\/tr><\/thead><tbody><tr><td><strong>privileged<\/strong><\/td><td>\u5236\u9650\u306a\u3057\uff08\u6700\u3082\u7de9\u3044\uff09<\/td><td>root\u3067\u306e\u5b9f\u884c\u3001\u7279\u6a29\u30b3\u30f3\u30c6\u30ca\u306a\u3069OK<\/td><\/tr><tr><td><strong>baseline<\/strong><\/td><td>\u4e00\u822c\u7684\u306a\u7528\u9014\u306b\u9069\u3057\u305f\u6700\u4f4e\u9650\u306e\u5236\u9650<\/td><td>hostPath\u4f7f\u7528NG\u3001\u7279\u6a29\u30e2\u30fc\u30c9NG<\/td><\/tr><tr><td><strong>restricted<\/strong><\/td><td>\u672c\u756a\u5411\u3051\u306e\u5f37\u3044\u5236\u9650<\/td><td>root\u30e6\u30fc\u30b6\u30fcNG\u3001CAP\u306e\u8ffd\u52a0NG \u306a\u3069<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>\u3053\u308c\u3089\u306e\u30ec\u30d9\u30eb\u306f<strong>Namespace\u5358\u4f4d\u3067\u9069\u7528<\/strong>\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\ud83e\udde9 Namespace \u3078\u306e\u9069\u7528\u4f8b<\/h3>\n\n\n\n<p>Namespace\u306b\u5bfe\u3057\u3066 <code>restricted<\/code> \u30ec\u30d9\u30eb\u3092\u9069\u7528\u3059\u308b\u4f8b\u3067\u3059\uff1a<\/p>\n\n\n\n<div class=\"hcb_wrap\"><pre class=\"prism line-numbers lang-bash\" data-lang=\"Bash\"><code>kubectl label namespace dev \\\n  pod-security.kubernetes.io\/enforce=restricted \\\n  pod-security.kubernetes.io\/enforce-version=latest<\/code><\/pre><\/div>\n\n\n\n<p>\u3053\u308c\u306b\u3088\u308a\u3001<code>dev<\/code> \u540d\u524d\u7a7a\u9593\u306b <code>restricted<\/code> \u30ec\u30d9\u30eb\u306e\u30dd\u30ea\u30b7\u30fc\u304c\u5f37\u5236\u3055\u308c\u3001<strong>\u30eb\u30fc\u30eb\u306b\u9055\u53cd\u3059\u308bPod\u306f\u4f5c\u6210\u3067\u304d\u306a\u304f\u306a\u308a\u307e\u3059<\/strong>\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\ud83e\uddea \u30e2\u30fc\u30c9\u306e\u7a2e\u985e<\/h3>\n\n\n\n<p>PodSecurity\u306b\u306f3\u3064\u306e\u300c\u52d5\u4f5c\u30e2\u30fc\u30c9\u300d\u304c\u3042\u308a\u307e\u3059\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>\u30e2\u30fc\u30c9<\/th><th>\u8aac\u660e<\/th><\/tr><\/thead><tbody><tr><td><code>enforce<\/code><\/td><td>\u9055\u53cd\u304c\u3042\u308c\u3070 Pod \u4f5c\u6210\u3092\u62d2\u5426<\/td><\/tr><tr><td><code>audit<\/code><\/td><td>\u62d2\u5426\u306f\u3057\u306a\u3044\u304c\u30ed\u30b0\u306b\u8a18\u9332\u3059\u308b<\/td><\/tr><tr><td><code>warn<\/code><\/td><td>\u30e6\u30fc\u30b6\u30fc\u306b\u8b66\u544a\u3092\u51fa\u3059\u304c\u62d2\u5426\u306f\u3057\u306a\u3044<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>\u4f8b\u3048\u3070\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u3001\u8b66\u544a\u3068\u76e3\u67fb\u3060\u3051\u3092\u8a2d\u5b9a\u3059\u308b\u3053\u3068\u3082\u3067\u304d\u307e\u3059\uff1a<\/p>\n\n\n\n<div class=\"hcb_wrap\"><pre class=\"prism line-numbers lang-bash\" data-lang=\"Bash\"><code>kubectl label namespace test \\\n  pod-security.kubernetes.io\/audit=restricted \\\n  pod-security.kubernetes.io\/warn=restricted<\/code><\/pre><\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\ud83d\udee0 \u904b\u7528\u306e\u30dd\u30a4\u30f3\u30c8<\/h3>\n\n\n\n<ul>\n<li><strong>\u958b\u767a\u7528Namespace\u3067\u306fbaseline\u3001\u5546\u7528\u74b0\u5883\u3067\u306frestricted<\/strong>\u3092\u4f7f\u3046\u306e\u304c\u57fa\u672c<\/li>\n\n\n\n<li><code>kubectl explain pod.spec<\/code> \u3067\u8a31\u5bb9\u3055\u308c\u308b\u4ed5\u69d8\u3092\u78ba\u8a8d\u3059\u308b\u3068\u3088\u3044<\/li>\n\n\n\n<li><code>kube-apiserver<\/code> \u306e\u30ed\u30b0\u3084 <code>kubectl create<\/code> \u306e\u51fa\u529b\u3092\u898b\u3066\u30eb\u30fc\u30eb\u9055\u53cd\u3092\u628a\u63e1\u3067\u304d\u308b<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u2699\ufe0f \u4ed6\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\uff08\u88dc\u8db3\uff09<\/h3>\n\n\n\n<p>PodSecurity\u3060\u3051\u3067\u306a\u304f\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u5bfe\u7b56\u3082\u6709\u52b9\u3067\u3059\uff1a<\/p>\n\n\n\n<ul>\n<li><strong>readOnlyRootFilesystem<\/strong> \u3092\u6709\u52b9\u306b\u3059\u308b<\/li>\n\n\n\n<li><strong>SecurityContext<\/strong> \u3067 <code>runAsNonRoot<\/code>, <code>allowPrivilegeEscalation<\/code> \u3092\u5236\u9650<\/li>\n\n\n\n<li><strong>NetworkPolicy<\/strong> \u3067\u901a\u4fe1\u5236\u9650<\/li>\n\n\n\n<li><strong>RBAC<\/strong> \u3067\u64cd\u4f5c\u6a29\u9650\u3092\u5236\u9650<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\ud83d\udd1a \u307e\u3068\u3081<\/h2>\n\n\n\n<p>Kubernetes\u306f\u5f37\u529b\u306a\u4ed5\u7d44\u307f\u3092\u63d0\u4f9b\u3057\u3066\u304f\u308c\u307e\u3059\u304c\u3001<strong>\u4f55\u3082\u5236\u9650\u3057\u306a\u3044\u72b6\u614b\u306f\u975e\u5e38\u306b\u5371\u967a<\/strong>\u3067\u3059\u3002<br>\u305d\u306e\u7b2c\u4e00\u6b69\u3068\u3057\u3066\u300cPod\u306b\u8a31\u53ef\u3059\u308b\u3053\u3068\uff0f\u7981\u6b62\u3059\u308b\u3053\u3068\u300d\u3092Namespace\u5358\u4f4d\u3067\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\u3059\u308b<strong>PodSecurity\u306e\u8a2d\u5b9a<\/strong>\u306f\u91cd\u8981\u3067\u3059\u3002<\/p>\n\n\n\n<p>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[55],"tags":[56],"_links":{"self":[{"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/posts\/1489"}],"collection":[{"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/comments?post=1489"}],"version-history":[{"count":1,"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/posts\/1489\/revisions"}],"predecessor-version":[{"id":1490,"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/posts\/1489\/revisions\/1490"}],"wp:attachment":[{"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/media?parent=1489"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/categories?post=1489"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/tags?post=1489"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}