èªååããä¿¡é Œæ§ã®é«ããœãããŠã§ã¢ããªããªãŒã®ããã®ã«ã¹ã¿ã CI/CDãã€ãã©ã€ã³éçºãèªä¿¡ãæã£ãŠãããŠã³ã¿ã€ã ãªãã§æ¯æ¥ãªãªãŒã¹ãå¯èœã«ãããããã€ã¡ã³ããã€ãã©ã€ã³ãæ§ç¯ããŸãã
å§ãã
åªããCI/CDãšã¯ãåã«ãããã€ãèªååããã ãã§ã¯ãããŸãããããã¯ãæããããšãªã1æ¥ã«è€æ°åãªãªãŒã¹ã§ãããšããèªä¿¡ã§ããç§ãã¡ã¯ãåé¡ãæ©æã«çºèŠãã確å®ã«ãããã€ããããŒã ã«è¿ éãªãã£ãŒãããã¯ãæäŸãããã€ãã©ã€ã³ãæ§ç¯ããŸãããã®çµæãåžå Žæå ¥ãŸã§ã®æéã®ççž®ãæ¬çªç°å¢ã§ã®ã€ã³ã·ãã³ãã®åæžããããŠéçºè ã®æºè¶³åºŠåäžã«ã€ãªãããŸãã
ã客æ§ã®ãšã³ã·ã¹ãã ã«å¿ããŠãGitHub ActionsãGitLab CIããŸãã¯Jenkinsãåºç€ãšããŠæ§ç¯ããŸããã³ã³ãããã«ãã«ã¯Dockerã䜿çšãããã«ãã¹ããŒãžãã«ããšã¬ã€ã€ãŒãã£ãã·ã³ã°ãå©çšããŸãããããã€ã¡ã³ãã¯KubernetesãVercelãAWSããŸãã¯ã客æ§ãéžæãããã©ãããã©ãŒã ãã¿ãŒã²ãããšããŸããã·ãŒã¯ã¬ãã管çã«ã¯VaultãŸãã¯ã¯ã©ãŠããã€ãã£ããªãœãªã¥ãŒã·ã§ã³ã䜿çšããŸãã
æåã§ãããã€ããŠããããŒã ããèªåã®ãã·ã³ã§ã¯åãããšããåé¡ã«çŽé¢ããŠããããŒã ããŸãã¯ããžãã¹ãå¿ èŠãšããéãã§ãªãªãŒã¹ã§ããªãããŒã ã察象ã§ãããŒããããã€ãã©ã€ã³ãæ§ç¯ããå¿ èŠãããå Žåã§ããé ããäžå®å®ããŸãã¯äžååãªæ¢åã®ãã€ãã©ã€ã³ãæ¹åãããå Žåã§ããåœç€Ÿã¯ä¿¡é Œæ§ã®é«ãèªååãæäŸããŸãã
çŸåšã®ãããã€ããã»ã¹ãç£æ»ããåé¡ç¹ãç¹å®ããç®æšãšãããããã€é »åºŠãšä¿¡é Œæ§ãå®çŸ©ããŸãã
ãã¹ããã»ãã¥ãªãã£ã¹ãã£ã³ãææ Œã¯ãŒã¯ãããŒãå«ã倿®µéãã€ãã©ã€ã³ãèšèšããŸãã
ãã€ãã©ã€ã³æ§æãæ§ç¯ããç°å¢ãèšå®ããã·ãŒã¯ã¬ãããæ§æãããããã€æŠç¥ãå®è£ ããŸãã
ãã€ãã©ã€ã³ãé害ã·ããªãªãåŠçããããŒã«ããã¯ãæ£ããæ©èœãããã£ãŒãããã¯ãè¿ éã§ããããšãæ€èšŒããŸãã
ãã€ãã©ã€ã³ã®äœ¿çšæ³ãææžåããããŒã ããã¬ãŒãã³ã°ãããã€ãã©ã€ã³ã¡ã³ããã³ã¹ã®ããã®éçšãã©ã¯ãã£ã¹ã確ç«ããŸãã
èªä¿¡ãæã£ãŠããŠã³ã¿ã€ã ãªãã§ãããŒã ãæ¯æ¥ãªãªãŒã¹ã§ããCI/CDãã€ãã©ã€ã³ãæ§ç¯ããŸãããã
åœç€Ÿã¯ GitHub Actions, GitLab CI, Jenkins, CircleCI, AWS CodePipeline, Azure DevOps, ããã³ ArgoCD äžã§ãã€ãã©ã€ã³ãæ§ç¯ããŠããŸããã客æ§ã®æ¢åã®ããŒã«ããã¹ãã£ã³ã°ç°å¢ãããã³ã¯ãŒã¯ãããŒèŠä»¶ã«åºã¥ããŠãã©ãããã©ãŒã ãéžæããŸãã
MicrocosmWorksã«ãããCI/CDãã€ãã©ã€ã³éçºã¯ã1æéããã$15ïœ$40ã§äŸ¡æ Œèšå®ãããŠããããã€ãã©ã€ã³èšèšãèªåãã¹ãçµ±åããããã€èªååãããã³ç°å¢ç®¡çãå«ãŸããŸãã
ã¯ãã䞊åãžã§ãå®è¡ãäŸåé¢ä¿ãšãã«ãææç©ã®ã€ã³ããªãžã§ã³ããªãã£ãã·ã¥ã倿Žããããã¡ã€ã«ã«åºã¥ãéžæçãªãã¹ãå®è¡ãããã³Dockerã¬ã€ã€ãŒãã£ãã·ã¥ãéããŠãã€ãã©ã€ã³ãæé©åããããšã§ããã«ãæéã50ã80%ççž®ããŸãã
ãã©ãããã©ãŒã ãã€ãã£ãã®ã·ãŒã¯ã¬ãã管çãå©çšããHashiCorp VaultãAWS Secrets Managerã®ãããªå€éšã®Vaultãšçµ±åããŠããŸããã¯ã©ãŠããããã€ã¡ã³ãåãã«ã¯OIDCããŒã¹ã®èªèšŒãå®è£ ããã·ãŒã¯ã¬ããããã«ãåºåã«èšé²ãããããå ¬éããããããªãããã«åŸ¹åºããŠããŸãã
ã¯ãããããã€åã«ã»ãã¥ãªãã£åé¡ãæ€åºããããã«ãSonarQube ã®ãã㪠SAST ããŒã«ãSnyk ãŸã㯠Dependabot ã«ããäŸåé¢ä¿ã®è匱æ§ã¹ãã£ã³ãTrivy ã«ããã³ã³ããã€ã¡ãŒãžã¹ãã£ã³ãããã³ Checkov ã«ããã€ã³ãã©ããªã·ãŒãã§ãã¯ããã€ãã©ã€ã³ã«çµ±åããŠããŸãã