使用 ImageCleaner 清除 Azure Kubernetes Service (AKS) 叢集上易受攻擊的過時映像

適用於: ✔️ AKS 自動化 ✔️ AKS 標準

通常我們會使用管線在 Azure Kubernetes Service (AKS) 叢集上建置和部署映像。 雖然非常適合用來建立映像,但此程序通常不會考慮留下的過時映像,而這可能會導致叢集節點上的映像高載。 這些映像可能包含弱點,這可能會造成安全性問題。 若要消除叢集中的安全性風險,您可以清除這些未參考的映像。 手動清除映像可能需要大量時間。 Image Cleaner 會執行自動映像識別和移除,以降低過時映像的風險,並減少清除映像所需的時間。

AKS Automatic 是大多數 AKS 工作負載建議採用、適合正式環境使用的預設選項。 影像清理器預設在 AKS 自動叢集中,幫助移除帶有漏洞的未使用映像檔。

在 AKS Standard 叢集中,影像清理是可選的,且你可以明確啟用。

欲了解更多關於 AKS 自動的資訊,請參閱 What is Azure Kubernetes Service (AKS) Automatic?

附註

Image Cleaner 是以 Eraser 為基礎的功能。 在 AKS 上,特徵名稱與屬性名稱為 Image Cleaner,而相關的影像清潔器膠囊名稱則包含 Eraser。

AKS Automatic 與 AKS Standard 的行為

先決條件

  • Azure 訂用帳戶。 如果您沒有 Azure 訂用帳戶,您可以建立免費帳戶。
  • 若要透過 Azure CLI 進行 AKS Standard 設定,需使用 Azure CLI 2.49.0 或更新版本。 執行 az --version 來尋找您的版本。 如果您需要安裝或升級,請參閱安裝 Azure CLI。

限制

Image Cleaner 尚未支援 Windows 節點集區或 AKS 虛擬節點。

Image Cleaner 的運作方式

當你在叢集上啟用映像清理器時,它會部署一個名為 eraser-controller-manager 的控制器管理員 Pod。

顯示 ImageCleaner 工作流程的圖表的螢幕擷取畫面。在叢集上執行的 ImageCleaner Pod 可產生 ImageList,或提供手動輸入。

影像清理器支援自動與手動清理模式。

AKS Standard 的設定選項

在 AKS Standard 搭配 Azure CLI 設定 Image Cleaner 時,請使用這些選項。

名稱 描述 必要
--enable-image-cleaner 為 AKS 叢集啟用映像清理工具 是的,除非你明確指定停用
--disable-image-cleaner 停用 AKS 叢集的映像清理程式 是的,除非你特別指定啟用
--image-cleaner-interval-hours 排定跑步的時間間隔以小時為單位。 Azure CLI 預設為一週。 最少要24小時。 最多三個月。 Azure CLI 不需要;ARM 範本或其他客戶端則需要

附註

如果你停用映像清理器,之後又重新啟用,但沒有明確傳遞設定,之前的設定值會被重複使用。

自動模式

當你部署 eraser-controller-manager時,映像清理器會自動執行以下操作:

  • 開始清理,並為每個節點建立 eraser-aks-xxxxx 工作艙。
  • 使用 收藏容器 收集未使用的影像。
  • 使用 trivy-scanner 容器搭配 trivy 掃描漏洞。
  • 使用 移除器 容器移除未使用的有漏洞的影像。
  • 完成後刪除背景工作 Pod。
  • 根據 --image-cleaner-interval-hours 排定下一次清理作業。

手動模式

您可以藉由定義 CRD 物件 ImageList 手動觸發清除。 這會觸發 eraser-contoller-manager ,為每個節點建立 eraser-aks-xxxxx 背景工作Pod,並完成手動移除程式。

附註

停用 Image Cleaner 之後,舊設定仍存在。 這表示如果您再次啟用此功能而未明確傳遞設定,則會使用現有的值,而不是預設值。

在 AKS 自動版和 AKS 標準版上使用映像清理工具

AKS 自動化系统

Image Cleaner 已預先設定於 AKS Automatic 叢集上,而這類叢集是大多數 AKS 工作負載建議採用、可用於正式環境的預設選項。 你不需要另外執行啟用指令。

要建立 AKS 自動叢集,請參見 建立 AKS 自動叢集。

當您想要針對性修復或操作驗證時,請使用本文中的手動清理與監控指引。

AKS 標準:在新的叢集上啟用

在新的 AKS Standard 叢集上使用 az aks create 帶有 --enable-image-cleaner 參數的指令啟用影像清理器。

az aks create \
    --resource-group myResourceGroup \
    --name myManagedCluster \
    --enable-image-cleaner \
    --generate-ssh-keys

AKS 標準:在現有叢集上啟用

請使用 az aks update 指令在現有的 AKS Standard 叢集上啟用影像清理器。

az aks update \
  --resource-group myResourceGroup \
  --name myManagedCluster \
  --enable-image-cleaner

AKS 標準:對新叢集或現有叢集進行更新間隔

使用 --image-cleaner-interval-hours 參數更新新建或現有 AKS Standard 叢集的影像清理間隔。

# Create a new cluster with specifying the interval
az aks create \
    --resource-group myResourceGroup \
    --name myManagedCluster \
    --enable-image-cleaner \
    --image-cleaner-interval-hours 48 \
    --generate-ssh-keys

# Update the interval on an existing cluster
az aks update \
    --resource-group myResourceGroup \
    --name myManagedCluster \
    --enable-image-cleaner \
    --image-cleaner-interval-hours 48

使用 Image Cleaner 手動移除映像

重要事項

name 必須設定為 imagelist。

使用下列 kubectl apply 命令手動移除映像。 本範例會移除未使用的 docker.io/library/alpine:3.7.3 映像。

cat <<EOF | kubectl apply -f -
apiVersion: eraser.sh/v1
kind: ImageList
metadata:
  name: imagelist
spec:
  images:
    - docker.io/library/alpine:3.7.3
EOF

手動清除是一次性作業,只有在建立新的 imagelist 或變更現有的 imagelist 時才會觸發。 刪除映像之後,將不會自動刪除 imagelist。

如果您需要觸發另一次手動清除,您必須建立新的 imagelist 或變更現有的映像。 如果您要再次移除同一個映像,您必須建立新的 imagelist。

刪除現有的 ImageList 並建立新的 ImageList

  1. 使用 imagelist 命令移除舊的 kubectl delete。

    kubectl delete ImageList imagelist
    
  2. 使用同一個映像名稱建立新的 imagelist。 下列範例會使用與上一個範例相同的映像。

    cat <<EOF | kubectl apply -f -
    apiVersion: eraser.sh/v1
    kind: ImageList
    metadata:
      name: imagelist
    spec:
      images:
        - docker.io/library/alpine:3.7.3
    EOF
    

修改現有的 ImageList

使用 imagelist 命令修改現有的 kubectl edit。

kubectl edit ImageList imagelist

# Add a new image to the list
apiVersion: eraser.sh/v1
kind: ImageList
metadata:
  name: imagelist
spec:
  images:
      docker.io/library/python:alpine3.18

使用手動模式時,eraser-aks-xxxxx Pod 會在工作完成後的 10 分鐘內刪除。

映像排除清單

排除清單中指定的映像不會從叢集移除。 Image Cleaner 支援系統和使用者定義的排除清單。 不支援編輯系統排除清單。

檢查系統排除清單

使用下列 kubectl get 命令檢查系統排除清單。

kubectl get -n kube-system configmap eraser-system-exclusion -o yaml

建立使用者定義的排除清單

  1. 建立範例 JSON 檔案以包含排除的映像。

    cat > sample.json <<EOF
    {"excluded": ["excluded-image-name"]}
    EOF
    
  2. 使用下列 configmap 和 kubectl create 命令,使用範例 JSON 檔案建立 kubectl label。

    kubectl create configmap excluded --from-file=sample.json --namespace=kube-system
    kubectl label configmap excluded eraser.sh/exclude.list=true -n kube-system
    

在 AKS Standard 上停用影像清理器

使用 az aks update 帶有 --disable-image-cleaner 參數的指令在 AKS Standard 叢集上停用影像清理器。

az aks update \
  --resource-group myResourceGroup \
  --name myManagedCluster \
  --disable-image-cleaner

常見問題 (FAQs)

AKS 自動版預設有啟用影像清理功能嗎?

Yes. 影像清理器已預先設定在 AKS 自動叢集上。

我需要在 AKS Automatic 上執行 Image Cleaner 的啟用指令嗎?

否。 請使用 AKS Standard 的啟用指令。

如何檢查 Image Cleaner 使用哪個版本?

kubectl describe configmap -n kube-system eraser-manager-config | grep tag -C 3

除了 Trivy 掃描器之外,Image Cleaner 是否支援其他弱點掃描器?

否。

我可以指定要清除映像的弱點層級嗎?

否。 弱點層級的預設設定包括:

  • LOW,
  • MEDIUM,
  • HIGH 和
  • CRITICAL

您無法自訂預設設定。

如何檢閱 Image Cleaner 已清除的映像?

映射記錄會儲存在 eraser-aks-xxxxx 背景工作Pod中。 eraser-aks-xxxxx 運作時,您可以執行下列命令來檢視刪除記錄:

kubectl logs -n kube-system <worker-pod-name> -c collector
kubectl logs -n kube-system <worker-pod-name> -c trivy-scanner
kubectl logs -n kube-system <worker-pod-name> -c remover

eraser-aks-xxxxx Pod 會在工作完成後的 10 分鐘內刪除。 您可以遵循下列步驟來啟用 Azure 監視器附加元件,並使用容器深入解析 Pod 記錄資料表。 此後,系統會儲存歷程記錄,即使已刪除 eraser-aks-xxxxx,您也可以檢閱記錄檔。

  1. 請確保您的叢集啟用 Azure 監視器。 如需詳細步驟,請參閱在 AKS 叢集上啟用容器深入解析。

  2. 預設情況下,該命名空間中執行 kube-system 容器的日誌不會被收集。 在 ConfigMap 中,從 exclude_namespaces 移除 kube-system 命名空間,並套用該 ConfigMap 以啟用這些日誌的收集功能。 如需詳細資料,請參閱設定容器深入解析資料收集。

  3. 使用 az aks show 命令取得 Log Analytics 資源識別碼。

      az aks show --resource-group myResourceGroup --name myManagedCluster
    

    幾分鐘後,命令會傳回解決方案的 JSON 格式資訊,包括工作區資源識別碼:

    "addonProfiles": {
      "omsagent": {
        "config": {
          "logAnalyticsWorkspaceResourceID": "/subscriptions/<WorkspaceSubscription>/resourceGroups/<DefaultWorkspaceRG>/providers/Microsoft.OperationalInsights/workspaces/<defaultWorkspaceName>"
        },
        "enabled": true
      }
    }
    
  4. 在 Azure 入口網站中,搜尋工作空間資源 ID,然後選擇日誌。

  5. 複製以下其中一項查詢並貼上到查詢視窗。

    • 如果您的叢集使用 ContainerLogV2 結構描述,請使用下列查詢。 如果你還在用 ContainerLog,升級到 ContainerLogV2。

      ContainerLogV2
      | where PodName startswith "eraser-aks-" and PodNamespace == "kube-system"
      | project TimeGenerated, PodName, LogMessage, LogSource
      
    • 如果你想繼續使用 ContainerLog,請改用以下查詢:

      let startTimestamp = ago(1h);
      KubePodInventory
      | where TimeGenerated > startTimestamp
      | project ContainerID, PodName=Name, Namespace
      | where PodName startswith "eraser-aks-" and Namespace == "kube-system"
      | distinct ContainerID, PodName
      | join
      (
          ContainerLog
          | where TimeGenerated > startTimestamp
      )
      on ContainerID
      // at this point before the next pipe, columns from both tables are available to be "projected". Due to both
      // tables having a "Name" column, we assign an alias as PodName to one column which we actually want
      | project TimeGenerated, PodName, LogEntry, LogEntrySource
      | summarize by TimeGenerated, LogEntry
      | order by TimeGenerated desc
       ```
      
      
  6. 選取 [執行]。 任何已刪除的映像記錄會出現在 [結果] 區域中。