SPIFFE Meetup Tokyo #2
åºæ¬æ å ±
- æ¥æ
- ã
- éå¬åœ¢åŒ
- çŸå°éå¬
- äŒå Ž
- æ ªåŒäŒç€ŸPreferred Networks
ã€ãã³ãå 容
SPIFFE Meetup Tokyo 2 ã®é
ä¿¡ã§é³å£°ãåºãŠããªãããã§ããããããã®å¯Ÿå¿ãé£ãããããæ¬æ¥ã¯é
ä¿¡ãäžæ¢ãããŠãã ããã倧å€ç³ãèš³ãããŸãããããäºæ¿ãã ããã
ãAttestation Internals in SPIREã以å€ã®ã»ãã·ã§ã³ã«ã€ããŠã¯åŸæ¥é²ç»ãé
ä¿¡äºå®ã§ãã
æŠèŠ
SPIFFE Meetup Tokyo #2 ãéå¬ããŸãïŒ ãã®ããŒãã¢ãã㯠SPIFFE/SPIREãäžå¿ãšãã Zero Trust NetworkãSecure Introduction é¢é£ã®æè¡ã«ã€ããŠå ±æããäŒã§ãã
SPIFFEãšã¯?
SPIFFEã¯Zero Trust Networkã®èãæ¹ã«ããšã¥ããµãŒãã¹éèªèšŒã®ä»æ§ã§ãã2002幎ã«çºè¡šãããPlan9 security designã2005幎ã«çºè¡šãããGoogleã®LOASã®æµããæ±²ãã§äœãããŠããŸãã
è¿å¹Žã®Microserviceåãããã·ã¹ãã ã®ãããªworkloadéã®éä¿¡ã«ãããŠããéä¿¡å ãä¿¡é Œã§ãããã ããã¡ãã»ãŒãžã®æ£åœæ§ãä¿¡ãããããããšãããããªèª²é¡ããã©ã®ãããªç°å¢(cloud/on-prem, container/VM)ã§ãã£ãŠããåworkload㯠åäžã€ã³ã¿ãã§ãŒã¹ã§ç¢ºèªã§ãããã¬ãŒã ã¯ãŒã¯ã®ä»æ§ã§ãããŸããSPIFFEã¯ç°ãªããã¡ã€ã³éã§å©çšããå Žåã«ãããŠãäžå€®ç®¡çãå¿ èŠããªããšããç¹åŸŽããããŸãã
ãã詳现ãªèª¬æã¯ã次ã®è³æããã芧ããã ããŸãã
- SPIFFEã§äœã解決ã§ããã®ã
- SPIFFEãšãã®å®è£ ã§ããSPIREã«ã€ããŠ
- SPIFFE Meetup Tokyo - YouTube
ã¿ã€ã ããŒãã«
| æé | å 容 | ã¹ããŒã«ãŒ |
|---|---|---|
| 18:30~19:00 | åä»éå§ (19:30ãŸã§)ããœãŒã·ã£ã« | |
| 19:00~19:05 | Opening (5min) | |
| 19:05~19:35 | Securing the Service Mesh with SPIRE (30min) | åç° éŸéЬ (@ryysud), ãŒããã©ãæ ªåŒäŒç€Ÿ |
| 19:35~20:05 | Attestation Internals in SPIRE (30min) | Shingo Omura(@everpeace), Preferred Networks, Inc. |
| 20:05~20:35 | Challenging Multiple SPIRE (30min) | å®äœçŸ åä¹ (@hiyosi), ãŒããã©ãæ ªåŒäŒç€Ÿ) |
| 20:35~21:00 | æèŠªã¿ã€ã sponsored by Preferred Networks, Inc. | |
| 21:00-21:30 | LT倧äŒ(å5min) | - |
19:05~19:35 Securing the Service Mesh with SPIRE (30min)
by åç° éŸéЬ (@ryysud), ãŒããã©ãæ ªåŒäŒç€Ÿ
Service Mesh ã®éèŠãªèª²é¡ãšããŠãµãŒãã¹éã®èªèšŒãéä¿¡ã®æå·åãªã©ãæããããŸããSPIFFE ã®åç §å®è£ ã§ãã SPIRE ã«ã¯ Workload Identity ãšããŠã® SPIFFE ID ãå«ã X.509èšŒææž ãšéµãèªåã§é åžããã³ããŒããŒã·ã§ã³ããæ©èœãåãã£ãŠãããSecret discovery service (SDS) API ãä»ã㊠Envoy ãšé£æºããããšãå¯èœã«ãªã£ãŠããŸãããã®çºè¡šã§ã¯ãããã®æ©èœã掻çšããŠãSPIRE ãš Envoy ãçµã¿åãããã»ãã¥ã¢ãª Service Mesh ãæ§ç¯ããæ¹æ³ã玹ä»ããŸãã
Bio: 2015幎㫠DMM.com ã«æ°åãšããŠå ¥ç€ŸãHadoop Ecosystem ãå©çšããããŒã¿åæåºç€ã®éçºãšéçšã«åŸäºã2018幎12æãããŒããã©ãæ ªåŒäŒç€Ÿã§ Kubernetes ãããŒã¹ãšããã€ã³ãã©åºç€ã®ç ç©¶éçºãè¡ã£ãŠãããæè¿ã®æ¥åã§ã¯ SPIRE ãè§Šãããšãå€ããäŒæ¥ã«ã¯è¶£å³ã§ã³ã³ããªãã¥ãŒããããŠããã
19:35~20:05 Attestation Internals in SPIRE (30min)
by Shingo Omura(@everpeace), Preferred Networks, Inc.
In SPIRE, attestation is the essential process because it certifies a node or workload, i.e. it asserts the identities of them. This talk describes how SPIRE implement this process and make it flexible. Moreover, it explains the detail of how spire-server and spire-agent (running at a node) interacts in the attestation process.
Bio: Shingo Omura is an ML platform engineer in Preferred Networks, Inc where he works on developing tools and systems for their Kubernetes clusters. He is specialized in designing efficient distributed systems, scalable and resilient reactive applications. He is a member of Kubeflow project and has contributed kube-scheduler and other kubernetes related projects.
è¬æŒã¯æ¥æ¬èªã§ããã¹ã©ã€ãã¯è±èªã§äœæäºå®ã§ãã
20:05~20:35 Challenging Multiple SPIRE (30min)
by å®äœçŸ åä¹ (@hiyosi), ãŒããã©ãæ ªåŒäŒç€Ÿ)
SPIFFEã®å®è£ ã®äžã€ã§ããSPIREã®åé·åã«åãçµãã äºäŸã«ã€ããŠç޹ä»ããŸãã SPIREã®ããã¥ã¡ã³ãã§ã¯åé·åããæ¹æ³ãšããŠã¹ããŒãã¬ã¹æ§æãšã¹ããŒããã«æ§æã玹ä»ãããŠããŸãã ããããåé·åããéã®æ§æãèšŒææžã®æ€èšŒãã§ãŒã³ã泚æç¹ãªã©ã«ã€ããŠç޹ä»ããããšæããŸãã
bio: æISPã«ãŠã·ã¹ãã éçšåºç€ã®éçºãIDaaSãµãŒãã¹ã®ç«ã¡äžããªã©ã«é¢ãã£ãåŸã2016幎9æã«ãŒããã©ãæ ªåŒäŒç€Ÿã«å ¥ç€ŸãçŸåšã¯ã€ã³ãã©åºç€ã®ç ç©¶éçºãè¡ã£ãŠãããZero Trust NetworkãèªèšŒæè¡ã«èå³ãããã
20:35~21:00 æèŠªã¿ã€ã sponsored by æ ªåŒäŒç€ŸPreferred Networks
é£ã¹ãªããã®æèŠªã¿ã€ã ã§ãã軜é£ãããªã³ã¯ãæäŸäºå®ã§ããæªæå¹Žããã³èªåè»ãªã©ã®è»äž¡ãé転ããäºå®æ¹ã¯çµ¶å¯Ÿã«é£²é ããªãã§ãã ããã
21:00~21:25 LT倧äŒx5 (å5å)
ãåå æ > LTæ ãã«æ³šæäºé ã®èšèŒããããŸããLTåžæè ã¯å¿ ã確èªããŠãã ããã
- Istioãæ¬çªç°å¢ã«å°å ¥ããŠã¿ã (TakuyaTezuka)
- Envoy SDS (taiki45)
- TBD
- TBD
- TBD
åå æ
äžè¬æ ïŒæœéžïŒ
æœéžæ ã§ããåœæ¥è£æ¬ ã§æ¥å ŽãããŠãåå ããæããããŠããã ããŸããäºããäºæ¿ãã ããã
LTæ ïŒæœéžïŒ
LTã¯5åå³å®ã§ããåå ç³èŸŒã¿æã« LT ã¿ã€ãã«ã®ç»é²ããé¡ãããŸãã
åæããã®ä»
åæãªã©ã§åå ãåžæãããæ¹ã¯ãå³ã«ã©ã äžå€®ã®ãªã³ã¯ããäºåã«äž»å¬è å®ã«çšä»¶ããé£çµ¡ãã ãããä¿å®äžã®çç±ãããäºåé£çµ¡ãªãã®åå ã¯ãæããããŠããã ããŸãããŸãåœæ¥æäŸããããã¶ãããŒã«ãªã©ã®é£²é£ç©ã¯äžè¬åå è åãã«ãªããŸããäºããäºæ¿ãã ããã
åå è²»
ç¡æ
åœæ¥ã®åä»ã«ã€ããŠ
- æéïŒ18:30 éå Žã§ãã19:30 以éã¯å ¥å Žã§ããªããªããŸãã
- å ŽæïŒæ ªåŒäŒç€ŸPreferred Networks / æ±äº¬éœå代ç°åºå€§æçº1-6-1倧æçºãã«3é 328åº
åä»ã®éã«ãåä»ç¥šããã¹ããŒããã©ã³çã§æç€ºããé¡ããŸãã
äžç¶
SPIFFE Meetup Tokyo 2 ã®é
ä¿¡ã§é³å£°ãåºãŠããªãããã§ããããããã®å¯Ÿå¿ãé£ãããããæ¬æ¥ã¯é
ä¿¡ãäžæ¢ãããŠãã ããã倧å€ç³ãèš³ãããŸãããããäºæ¿ãã ããã
ãAttestation Internals in SPIREã以å€ã®ã»ãã·ã§ã³ã«ã€ããŠã¯åŸæ¥é²ç»ãé
ä¿¡äºå®ã§ãã
- YouTube Live ã§é ä¿¡ãäºå®ããŠããŸããé¡ãæ ã蟌ãå¯èœæ§ããããŸããäºããäºæ¿ãã ããã
- https://youtu.be/WJApRS1DWng
- SPIFFE Meetup Tokyo - YouTube
äŒå Žèšåã«ã€ããŠ
- ãããžã§ã¯ã¿ã®è§£å床㯠WUXGA (1920Ã1200) ã§ãã
- å ¥å端å㯠HDMI, D-Sub 15ãã³, USB-C, Mini DisplayPort ã§ãã
- ã²ã¹ã Wi-Fi ãå©çšå¯èœã§ãã黿ºã¯æ°ã«éãããããŸãã
泚æäºé ãªã©
- åä»ç¥šã«èšèŒã®æ¬äººã®ã¿ãåå ã§ããŸããåä»ç¥šããæã¡ã§ãªãæ¹ã¯å ¥å Žã§ããŸãããåä»ç¥šã¯ã¹ããŒããã©ã³ã§ã®æç€ºã§å ¥å Žã§ããŸãã
- 18:30 éå Žã§ãã19:30 以éã¯å ¥å Žã§ããªããªããŸãã
- äŒå Žã¯çŠç ã§ãã
å 責äºé
- 貎éåã®ç®¡çã¯åèªã§ãé¡ãããããŸããäžäžçé£ã»çŽå€±çã®äºæ ãçºçããŠããäž»å¬è åŽã§ã¯äžå責任ãè² ããŸããã
泚æäºé
â» ãã¡ãã®ã€ãã³ãæ å ±ã¯ãå€éšãµã€ãããååŸããæ å ±ãæ²èŒããŠããŸãã
â» æ²èŒã¿ã€ãã³ã°ãæŽæ°é »åºŠã«ãã£ãŠã¯ãæ å ±æäŸå ããŒãžã®å 容ãšå·®ç°ãçºçããŸãã®ã§äºããäºæ¿ãã ããã
â» ææ°æ å ±ã®ç¢ºèªãåå ç³èŸŒæç¶ããã€ãã³ãã«é¢ãããåãåããçã¯æ å ±æäŸå ããŒãžã«ãŠãé¡ãããŸãã

ãåãåãã
é¢é£ããã€ãã³ã

ã·ã¹ãã ãšã³ãžãã¢ã®ãããã£ãªã¢ã»ã©ãŠã³ãžãSIerããäºæ¥äŒç€Ÿã«è»¢è·ããŠã©ãã ã£ãïŒã
2026/06/13(å) éå¬
ãçŸå Žã®çç·Žè ã®ç®ã«ãªã倿ããAIãšã¯ïŒãæ ã·ã¹ Update Day 2026 in åå€å±
2026/05/19(ç«) éå¬
AIæ©èœå®è£ ç¥èŠïŒãããã¯ãéçºãšã³ãžãã¢å匷äŒ
2026/05/14(æš) éå¬
ã¯ã©ãŠãRADIUSã§ç¡ç·LANèªèšŒãå®å šã«å®çŸ ç¡ç·AP11ãã³ããŒã®éããšã¯ïŒïŒCisco Meraki / HPE Aruba / Juniper Mist / Extreme Networks...
2026/05/20(æ°Ž) éå¬
ãCopilotã2å¹Žä»¥äžæŽ»çšããäºäŸãã玹ä»ãæ ã·ã¹ Update Day 2026 in åå€å±
2026/05/19(ç«) éå¬- TOP
- ã€ãã³ã
- SPIFFE Meetup Tokyo #2
