|
- <?xml version="1.0" encoding="utf-8"?>
- <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
- "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
- <html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
- <head>
- <!-- 2023-04-20 Thu 22:23 -->
- <meta http-equiv="Content-Type" content="text/html;charset=utf-8" />
- <meta name="viewport" content="width=device-width, initial-scale=1" />
- <title>Lab 11 Solution Amirlan Sharipov (BS21-CS-01)</title>
- <meta name="author" content="Amirlan Sharipov (BS21-CS-01)" />
- <meta name="generator" content="Org Mode" />
- <style>
- #content { max-width: 60em; margin: auto; }
- .title { text-align: center;
- margin-bottom: .2em; }
- .subtitle { text-align: center;
- font-size: medium;
- font-weight: bold;
- margin-top:0; }
- .todo { font-family: monospace; color: red; }
- .done { font-family: monospace; color: green; }
- .priority { font-family: monospace; color: orange; }
- .tag { background-color: #eee; font-family: monospace;
- padding: 2px; font-size: 80%; font-weight: normal; }
- .timestamp { color: #bebebe; }
- .timestamp-kwd { color: #5f9ea0; }
- .org-right { margin-left: auto; margin-right: 0px; text-align: right; }
- .org-left { margin-left: 0px; margin-right: auto; text-align: left; }
- .org-center { margin-left: auto; margin-right: auto; text-align: center; }
- .underline { text-decoration: underline; }
- #postamble p, #preamble p { font-size: 90%; margin: .2em; }
- p.verse { margin-left: 3%; }
- pre {
- border: 1px solid #e6e6e6;
- border-radius: 3px;
- background-color: #f2f2f2;
- padding: 8pt;
- font-family: monospace;
- overflow: auto;
- margin: 1.2em;
- }
- pre.src {
- position: relative;
- overflow: auto;
- }
- pre.src:before {
- display: none;
- position: absolute;
- top: -8px;
- right: 12px;
- padding: 3px;
- color: #555;
- background-color: #f2f2f299;
- }
- pre.src:hover:before { display: inline; margin-top: 14px;}
- /* Languages per Org manual */
- pre.src-asymptote:before { content: 'Asymptote'; }
- pre.src-awk:before { content: 'Awk'; }
- pre.src-authinfo::before { content: 'Authinfo'; }
- pre.src-C:before { content: 'C'; }
- /* pre.src-C++ doesn't work in CSS */
- pre.src-clojure:before { content: 'Clojure'; }
- pre.src-css:before { content: 'CSS'; }
- pre.src-D:before { content: 'D'; }
- pre.src-ditaa:before { content: 'ditaa'; }
- pre.src-dot:before { content: 'Graphviz'; }
- pre.src-calc:before { content: 'Emacs Calc'; }
- pre.src-emacs-lisp:before { content: 'Emacs Lisp'; }
- pre.src-fortran:before { content: 'Fortran'; }
- pre.src-gnuplot:before { content: 'gnuplot'; }
- pre.src-haskell:before { content: 'Haskell'; }
- pre.src-hledger:before { content: 'hledger'; }
- pre.src-java:before { content: 'Java'; }
- pre.src-js:before { content: 'Javascript'; }
- pre.src-latex:before { content: 'LaTeX'; }
- pre.src-ledger:before { content: 'Ledger'; }
- pre.src-lisp:before { content: 'Lisp'; }
- pre.src-lilypond:before { content: 'Lilypond'; }
- pre.src-lua:before { content: 'Lua'; }
- pre.src-matlab:before { content: 'MATLAB'; }
- pre.src-mscgen:before { content: 'Mscgen'; }
- pre.src-ocaml:before { content: 'Objective Caml'; }
- pre.src-octave:before { content: 'Octave'; }
- pre.src-org:before { content: 'Org mode'; }
- pre.src-oz:before { content: 'OZ'; }
- pre.src-plantuml:before { content: 'Plantuml'; }
- pre.src-processing:before { content: 'Processing.js'; }
- pre.src-python:before { content: 'Python'; }
- pre.src-R:before { content: 'R'; }
- pre.src-ruby:before { content: 'Ruby'; }
- pre.src-sass:before { content: 'Sass'; }
- pre.src-scheme:before { content: 'Scheme'; }
- pre.src-screen:before { content: 'Gnu Screen'; }
- pre.src-sed:before { content: 'Sed'; }
- pre.src-sh:before { content: 'shell'; }
- pre.src-sql:before { content: 'SQL'; }
- pre.src-sqlite:before { content: 'SQLite'; }
- /* additional languages in org.el's org-babel-load-languages alist */
- pre.src-forth:before { content: 'Forth'; }
- pre.src-io:before { content: 'IO'; }
- pre.src-J:before { content: 'J'; }
- pre.src-makefile:before { content: 'Makefile'; }
- pre.src-maxima:before { content: 'Maxima'; }
- pre.src-perl:before { content: 'Perl'; }
- pre.src-picolisp:before { content: 'Pico Lisp'; }
- pre.src-scala:before { content: 'Scala'; }
- pre.src-shell:before { content: 'Shell Script'; }
- pre.src-ebnf2ps:before { content: 'ebfn2ps'; }
- /* additional language identifiers per "defun org-babel-execute"
- in ob-*.el */
- pre.src-cpp:before { content: 'C++'; }
- pre.src-abc:before { content: 'ABC'; }
- pre.src-coq:before { content: 'Coq'; }
- pre.src-groovy:before { content: 'Groovy'; }
- /* additional language identifiers from org-babel-shell-names in
- ob-shell.el: ob-shell is the only babel language using a lambda to put
- the execution function name together. */
- pre.src-bash:before { content: 'bash'; }
- pre.src-csh:before { content: 'csh'; }
- pre.src-ash:before { content: 'ash'; }
- pre.src-dash:before { content: 'dash'; }
- pre.src-ksh:before { content: 'ksh'; }
- pre.src-mksh:before { content: 'mksh'; }
- pre.src-posh:before { content: 'posh'; }
- /* Additional Emacs modes also supported by the LaTeX listings package */
- pre.src-ada:before { content: 'Ada'; }
- pre.src-asm:before { content: 'Assembler'; }
- pre.src-caml:before { content: 'Caml'; }
- pre.src-delphi:before { content: 'Delphi'; }
- pre.src-html:before { content: 'HTML'; }
- pre.src-idl:before { content: 'IDL'; }
- pre.src-mercury:before { content: 'Mercury'; }
- pre.src-metapost:before { content: 'MetaPost'; }
- pre.src-modula-2:before { content: 'Modula-2'; }
- pre.src-pascal:before { content: 'Pascal'; }
- pre.src-ps:before { content: 'PostScript'; }
- pre.src-prolog:before { content: 'Prolog'; }
- pre.src-simula:before { content: 'Simula'; }
- pre.src-tcl:before { content: 'tcl'; }
- pre.src-tex:before { content: 'TeX'; }
- pre.src-plain-tex:before { content: 'Plain TeX'; }
- pre.src-verilog:before { content: 'Verilog'; }
- pre.src-vhdl:before { content: 'VHDL'; }
- pre.src-xml:before { content: 'XML'; }
- pre.src-nxml:before { content: 'XML'; }
- /* add a generic configuration mode; LaTeX export needs an additional
- (add-to-list 'org-latex-listings-langs '(conf " ")) in .emacs */
- pre.src-conf:before { content: 'Configuration File'; }
-
- table { border-collapse:collapse; }
- caption.t-above { caption-side: top; }
- caption.t-bottom { caption-side: bottom; }
- td, th { vertical-align:top; }
- th.org-right { text-align: center; }
- th.org-left { text-align: center; }
- th.org-center { text-align: center; }
- td.org-right { text-align: right; }
- td.org-left { text-align: left; }
- td.org-center { text-align: center; }
- dt { font-weight: bold; }
- .footpara { display: inline; }
- .footdef { margin-bottom: 1em; }
- .figure { padding: 1em; }
- .figure p { text-align: center; }
- .equation-container {
- display: table;
- text-align: center;
- width: 100%;
- }
- .equation {
- vertical-align: middle;
- }
- .equation-label {
- display: table-cell;
- text-align: right;
- vertical-align: middle;
- }
- .inlinetask {
- padding: 10px;
- border: 2px solid gray;
- margin: 10px;
- background: #ffffcc;
- }
- #org-div-home-and-up
- { text-align: right; font-size: 70%; white-space: nowrap; }
- textarea { overflow-x: auto; }
- .linenr { font-size: smaller }
- .code-highlighted { background-color: #ffff00; }
- .org-info-js_info-navigation { border-style: none; }
- #org-info-js_console-label
- { font-size: 10px; font-weight: bold; white-space: nowrap; }
- .org-info-js_search-highlight
- { background-color: #ffff00; color: #000000; font-weight: bold; }
- .org-svg { }
- </style>
- </head>
- <body>
- <div id="content" class="content">
- <h1 class="title">Lab 11 Solution Amirlan Sharipov (BS21-CS-01)</h1>
- <div id="table-of-contents" role="doc-toc">
- <h2>Table of Contents</h2>
- <div id="text-table-of-contents" role="doc-toc">
- <ul>
- <li><a href="#orgb5383c0">1. Question 1</a></li>
- <li><a href="#org68c7989">2. Question 2</a>
- <ul>
- <li><a href="#orga0d213f">2.1. Choose a host OS that provides maximum container isolation. (hardened host OS)</a></li>
- <li><a href="#org68baa0a">2.2. Use network namespaces</a></li>
- <li><a href="#org5ffdd26">2.3. Use kubernetes to manage access right</a></li>
- <li><a href="#org7a83b2b">2.4. Monitor the logs using SIEM tools</a></li>
- <li><a href="#orgc61de8d">2.5. Don’t use outdated images</a></li>
- </ul>
- </li>
- <li><a href="#orgf0252b1">3. Question 3</a></li>
- <li><a href="#orgad34306">4. Question 4</a></li>
- <li><a href="#org10585ce">5. Question 5</a></li>
- <li><a href="#org2339204">6. Question 6</a></li>
- <li><a href="#org5da35ee">7. Question 8</a></li>
- </ul>
- </div>
- </div>
-
- <div id="outline-container-orgb5383c0" class="outline-2">
- <h2 id="orgb5383c0"><span class="section-number-2">1.</span> Question 1</h2>
- <div class="outline-text-2" id="text-1">
- <p>
- Source: <a href="https://stackoverflow.com/questions/21553353/what-is-the-difference-between-cmd-and-entrypoint-in-a-dockerfile">https://stackoverflow.com/questions/21553353/what-is-the-difference-between-cmd-and-entrypoint-in-a-dockerfile</a>
- Usually, the entrypoint is /bin/sh -c CMD. So this command gets executed when the container is run.
- It’s a standard practice to customize CMD, though. If you want to use other shell for executing commands, it may be useful to customize the entrypoint.
- </p>
- </div>
- </div>
-
- <div id="outline-container-org68c7989" class="outline-2">
- <h2 id="org68c7989"><span class="section-number-2">2.</span> Question 2</h2>
- <div class="outline-text-2" id="text-2">
- <p>
- Source: <a href="https://www.redhat.com/en/topics/security/container-security">https://www.redhat.com/en/topics/security/container-security</a>
- </p>
- </div>
- <div id="outline-container-orga0d213f" class="outline-3">
- <h3 id="orga0d213f"><span class="section-number-3">2.1.</span> Choose a host OS that provides maximum container isolation. (hardened host OS)</h3>
- </div>
- <div id="outline-container-org68baa0a" class="outline-3">
- <h3 id="org68baa0a"><span class="section-number-3">2.2.</span> Use network namespaces</h3>
- </div>
- <div id="outline-container-org5ffdd26" class="outline-3">
- <h3 id="org5ffdd26"><span class="section-number-3">2.3.</span> Use kubernetes to manage access right</h3>
- </div>
- <div id="outline-container-org7a83b2b" class="outline-3">
- <h3 id="org7a83b2b"><span class="section-number-3">2.4.</span> Monitor the logs using SIEM tools</h3>
- </div>
- <div id="outline-container-orgc61de8d" class="outline-3">
- <h3 id="orgc61de8d"><span class="section-number-3">2.5.</span> Don’t use outdated images</h3>
- </div>
- </div>
-
- <div id="outline-container-orgf0252b1" class="outline-2">
- <h2 id="orgf0252b1"><span class="section-number-2">3.</span> Question 3</h2>
- <div class="outline-text-2" id="text-3">
- <p>
- <img src="./container-ls-1.jpg" alt="container-ls-1.jpg" />
- <img src="./container-ls-2.jpg" alt="container-ls-2.jpg" />
- </p>
- </div>
- </div>
- <div id="outline-container-orgad34306" class="outline-2">
- <h2 id="orgad34306"><span class="section-number-2">4.</span> Question 4</h2>
- <div class="outline-text-2" id="text-4">
- <p>
- Source: <a href="https://docs.docker.com/engine/reference/commandline/cp/">https://docs.docker.com/engine/reference/commandline/cp/</a>
- docker cp [OPTIONS] CONTAINER:SRC_PATH DEST_PATH|-
- </p>
-
- <p>
- Example:
- </p>
- <div class="org-src-container">
- <pre class="src src-bash"><span style="color: #c792ea;">cat</span> ~/nginx.sh
- </pre>
- </div>
-
- <pre class="example" id="orgb1f78fc">
- #!/bin/bash
-
- docker run \
- -v /etc/ssl/certs/monica.crt:/etc/ssl/certs/monica.crt \
- -v /etc/ssl/private/monica.key:/etc/ssl/private/monica.key \
- -v /home/rinri/.config/nginx:/etc/nginx/conf.d \
- -v /home/rinri/edu/sna/:/var/www \
- -p 80:80 -p 443:443 -p 5000:5000 \
- --restart unless-stopped \
- -d nginx
-
- </pre>
-
- <p>
- After running nginx.sh:
- <img src="./container-cp.jpg" alt="container-cp.jpg" />
- </p>
- </div>
- </div>
-
- <div id="outline-container-org10585ce" class="outline-2">
- <h2 id="org10585ce"><span class="section-number-2">5.</span> Question 5</h2>
- <div class="outline-text-2" id="text-5">
- <div class="org-src-container">
- <pre class="src src-bash"><span style="color: #c792ea;">echo</span> <span style="color: #c3e88d;">"Run Nginx container:"</span>
- <span style="color: #c792ea;">cat</span> ~/nginx.sh
- <span style="color: #c792ea;">echo</span> <span style="color: #c3e88d;">"Config file:"</span>
- <span style="color: #c792ea;">cat</span> ~/.config/nginx/test.conf
- </pre>
- </div>
-
- <pre class="example" id="org01c388f">
- Run Nginx container:
- #!/bin/bash
-
- docker run \
- -v /etc/ssl/certs/monica.crt:/etc/ssl/certs/monica.crt \
- -v /etc/ssl/private/monica.key:/etc/ssl/private/monica.key \
- -v /home/rinri/.config/nginx:/etc/nginx/conf.d \
- -v /home/rinri/edu/sna/:/var/www \
- -p 80:80 -p 443:443 -p 5000:5000 \
- --restart unless-stopped \
- -d nginx
-
- Config file:
- server {
- listen 5000;
- listen [::]:5000;
- root /var/www;
- index index.html index.htm;
-
- location / {
- try_files $uri $uri/ =404;
- }
- }
-
- server {
- listen 80;
- listen [::]:80;
-
- server_name monica.local;
-
- return 302 https://$server_name$request_uri;
- }
-
- server {
- listen 443;
- listen [::]:443;
-
- include conf.d/snippets/self-signed.conf;
-
- server_name monica.local;
-
- location / {
- proxy_pass http://172.17.0.4;
- proxy_set_header Host monica.local;
- }
- }
- </pre>
- </div>
- </div>
-
- <div id="outline-container-org2339204" class="outline-2">
- <h2 id="org2339204"><span class="section-number-2">6.</span> Question 6</h2>
- <div class="outline-text-2" id="text-6">
- <p>
- In /etc/rsyslog.conf:
- $ModLoad imtcp.so
- $InputTCPServerRun 514
- </p>
-
- <p>
- Command:
- docker run -it –log-driver syslog –log-opt syslog-address=tcp://172.17.0.1:514 alpine ash
- </p>
- </div>
- </div>
-
- <div id="outline-container-org5da35ee" class="outline-2">
- <h2 id="org5da35ee"><span class="section-number-2">7.</span> Question 8</h2>
- <div class="outline-text-2" id="text-7">
- <p>
- FROM alpine
- RUN apk add –update –no-cache python3 && ln -sf python3 /usr/bin/python
- RUN python3 -m ensurepip
- RUN pip3 install –no-cache –upgrade pip setuptools
- RUN touch index.html
- RUN echo “<html><h1>Testing web</h1></html>” >> index.html
- CMD [“python”, “-m”, “http.server”]
- </p>
-
- <p>
- changed apt to apk.
- source: <a href="https://stackoverflow.com/questions/62554991/how-do-i-install-python-on-alpine-linux">https://stackoverflow.com/questions/62554991/how-do-i-install-python-on-alpine-linux</a>
- </p>
- </div>
- </div>
- </div>
- <div id="postamble" class="status">
- <p class="author">Author: Amirlan Sharipov (BS21-CS-01)</p>
- <p class="date">Created: 2023-04-20 Thu 22:23</p>
- </div>
- </body>
- </html>
|