> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/zen-firewall/zen-installation-instructions/zen-firewall-for-python/django.md).

# Python（Django）

このガイドでは、Aikido の Zen Firewall をアプリケーションにインストールして設定する手順を順を追って説明します。以下の手順に従って、アプリケーションを保護してください。

問題や不具合が発生した場合は、サポートチャットまたは GitHub の issue で遠慮なくご連絡ください

<https://github.com/AikidoSec/firewall-python>

## 要件

* Python 3.8以上（3.13までサポート）。
* Django（Zen Firewall に対応）。
* [Aikidoアカウント](/docs/docs-ja/hajimeni/setting-up-your-account.md) & [Zen Firewallトークン](/docs/docs-ja/zen-firewall/zen-installation-instructions/creating-an-aikido-zen-firewall-token.md)

## インストールと設定

{% stepper %}
{% step %}
**AikidoによるZen Firewallのインストール**

pip で Zen をインストールします:

```bash
pip install aikido_zen
```

トークンの環境変数を設定します:

```bash
export AIKIDO_TOKEN=AIK_RUNTIME_YOUR_TOKEN_HERE
```

可能であれば、エントリポイントの先頭、他のインポートより前で Zen を有効にします:

```python
import aikido_zen

aikido_zen.protect()
```

で `manage.py`、Zen の初期化は先頭に置いてください：

{% @aikido-custom-code/code-highlight language="python" content="! manage.py
import os
import sys
+import aikido\_zen

if **name** == "**main**":

* aikido\_zen.protect()
  \# ..." %}
  {% endstep %}

{% step %}
**リクエストブロックとユーザー識別を有効にする**

このミドルウェアを使用して、レート制限、ユーザー識別、およびブロック機能を有効にします。

Zen Firewall は、攻撃をブロックするためにこのミドルウェアを必要としません。基本的な攻撃防御はこれなしでも動作します。このミドルウェアは、Zen が次のような保護に使用する追加のリクエスト コンテキストを提供します。 [レート制限](/docs/docs-ja/zen-firewall/zen-features/setting-up-rate-limiting-for-routes.md), [ユーザーのブロック](/docs/docs-ja/zen-firewall/zen-features/blocking-users-with-zen-firewall.md), [ボットのブロック](/docs/docs-ja/zen-firewall/zen-features/blocking-bot-traffic-with-zen-firewall.md), [国別ブロック](/docs/docs-ja/zen-firewall/zen-features/blocking-traffic-by-country-with-zen-firewall.md)、そして [脅威アクター](/docs/docs-ja/zen-firewall/zen-features/blocking-known-threat-actors-with-zen-firewall.md) ブロック。

アプリケーションのユーザー識別方法やリクエスト処理方法に合わせて、例を調整してください。

Aikido ミドルウェアを追加する `settings.py`:

{% @aikido-custom-code/code-highlight language="python" content="! settings.py
MIDDLEWARE = \[
\# Your auth middleware should run before this

* "aikido\_zen.middleware.AikidoDjangoMiddleware",
  \# ...
  ]" %}

認証ミドルウェアでユーザーを設定してください：

```python
from aikido_zen import set_user

set_user({"id": "123", "name": "John Doe"})
```

{% endstep %}

{% step %}
**Zen Firewallをドライラン／検知専用モードで開始する**

```bash
AIKIDO_BLOCK=false AIKIDO_TOKEN=AIK_RUNTIME_ python manage.py runserver
```

Aikido Zen エージェントが取得できるよう、トークンを環境変数として設定してください。まだトークンをお持ちでない場合は、次に従ってください [こちらの手順](/docs/docs-ja/zen-firewall/zen-installation-instructions/creating-an-aikido-zen-firewall-token.md).

```bash
AIKIDO_TOKEN=AIK_RUNTIME_
```

期待どおりに動作し、いかなるリクエストもブロックしないことを確認するため、まずは dry モードでアプリを起動することをおすすめします。誤検知を避けるため、Zen Firewall はステージング環境で 2 週間運用することを推奨します。

```bash
AIKIDO_BLOCK=false
```

{% hint style="info" %}
次を使用できます `AIKIDO_DEBUG=true` これを有効にすると、エージェントの動作に関するより詳細な情報を得られるデバッグモードになります。環境変数の詳細については： [環境変数による設定](/docs/docs-ja/zen-firewall/zen-installation-instructions/configuration-via-environment-variables.md)
{% endhint %}
{% endstep %}

{% step %}
**アプリをテストする**

アプリケーションにアクセスして、いくつかの操作を行うか、いくつかのページを開いてください。Zen がアプリケーション内のルートを自動的に検出します。

{% hint style="info" %}
Zen は10分ごとにデータを Aikido に送信します
{% endhint %}

次の Zen アプリケーションのページを確認すると、エージェントが正常に動作しているかを検証できます:

* **イベント**: 「Application started」イベントが表示されるはずです。
* **ルート**: しばらくすると、アプリケーションのルートが、メソッド、ルート、リクエストとともにここに表示され始めます。
* **インスタンス**: Zen がインストールされているアプリケーションのアクティブなインスタンス数が表示されるはずです。

<figure><img src="/files/bb6b16755cff4893513acdf0b399ab02ac7f5629" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**ダッシュボードでレート制限を設定する**

Zen Firewall ミドルウェアを追加したら、Aikido ダッシュボードでレート制限を設定して、ブルートフォース攻撃からルートを保護するテストができます。

1. 作成したアプリをクリックします。
2. 次へ移動します **ルート** タブを開きます。
3. 制限したいルートを見つけて、クリックします **レート制限を設定する**.
4. 手順に従ってレート制限を設定します（例：1分あたり5リクエスト）。

![認証ルートに保護とレート制限のオプションを表示する、API ルート管理インターフェース。](/files/e261faad47cc6b8291385535f551e58938a77367)

![POST /auth/login のレート制限を 1分あたり5リクエストに設定します。](/files/532f8ebb75a40ac740e8c3d35685a3aeb1b7e97d)

**レート制限を確認する**

アプリを起動し、レート制限を設定したルートに1分以内に5回アクセスしてみてください。5回目の試行の後、レート制限エラーが表示されるはずです。

```
Aikido ファイアウォールによりレート制限されています。（あなたの IP: 1.2.3.4）
```

{% endstep %}

{% step %}
**次のステップ**

おめでとうございます。Zen Firewall のインストールに成功しました。問題が発生した場合や、ご不明な点、機能の追加要望がある場合は、遠慮なくサポートまでご連絡ください。

これで、Zen Firewall が提供する多くの機能を試すことができます:

* [Zen Firewallでボットトラフィックをブロック](/docs/docs-ja/zen-firewall/zen-features/blocking-bot-traffic-with-zen-firewall.md)
* [Zen FirewallでTorトラフィックをブロックまたは監視](/docs/docs-ja/zen-firewall/zen-features/blocking-tor-traffic-with-zen-firewall.md)
* [Zen Firewallでユーザーを追跡](/docs/docs-ja/zen-firewall/zen-features/blocking-users-with-zen-firewall.md)
* [Zen Firewallで既知の脅威アクターをブロック](/docs/docs-ja/zen-firewall/zen-features/blocking-known-threat-actors-with-zen-firewall.md)
* [Zen Firewallで国別にトラフィックをブロック](/docs/docs-ja/zen-firewall/zen-features/blocking-traffic-by-country-with-zen-firewall.md)
* [ルートのレート制限を設定](/docs/docs-ja/zen-firewall/zen-features/setting-up-rate-limiting-for-routes.md)
* [アウトバウンドドメインを監視](/docs/docs-ja/zen-firewall/zen-features/monitor-outbound-domains.md)

追加情報:

* [Zenのパフォーマンスと信頼性](/docs/docs-ja/zen-firewall/miscellaneous/how-zen-works-performance-reliability.md)
* [Zen Firewallのブロックモードと検知モード](/docs/docs-ja/zen-firewall/zen-features/blocking-vs-detection-mode-in-zen-firewall.md)
* [Zen統計を理解する](/docs/docs-ja/zen-firewall/zen-features/understanding-your-zen-statistics.md)
  {% endstep %}
  {% endstepper %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/zen-firewall/zen-installation-instructions/zen-firewall-for-python/django.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
