> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/kuraudosukyan/connect-your-cloud/connect-alibaba-account.md).

# Alibaba Cloud を接続する

### Alibaba Cloud を接続する理由は？

クラウドインフラの保護は、ユーザーデータを守るうえで極めて重要です。Aikido のセキュリティチェックを活用して、Alibaba Cloud 環境の設定ミスを検出・修正できます。

#### **主なユースケース**

* Aikido は、攻撃者が Alibaba Cloud 環境に侵入できる重大なクラウド設定ミスを可視化します。私たちは、実際のビジネス影響につながるリスクに集中し、ノイズを取り除きます。すべての設定チェックは [こちら。](https://app.aikido.dev/clouds/checks)
* Aikido は、セットアップの進化に合わせて新たなリスクを継続的に監視します。
* Alibaba Cloud Container Registry (ACR) のコンテナイメージスキャン。
* Alibaba Cloud インスタンス上の Local VM Scanner による仮想マシンのスキャン。

Aikido は上記に対して毎日コンプライアンススキャンを実行します。

### 開始するには

へ移動し [クラウド概要ページ](https://app.aikido.dev/clouds) Aikido で **「Cloud に接続」**&#x3092;クリックし、 **Alibaba Cloud** を一覧から選択します。

<figure><img src="/files/2d4e1250209b392dcbb77cae4fac04b055c2e268" alt=""><figcaption></figcaption></figure>

{% stepper %}
{% step %}
**Alibaba Cloud にログインして、オンボーディングを設定します**

Alibaba Cloud には 2 つの方法で接続できます:

* **単一の Alibaba アカウント:** 一度に 1 つの Alibaba Cloud アカウントを接続します。アカウント数が少ない場合や、小さく始めたい場合に最適です。
* **Alibaba Resource Directory 全体:** Alibaba の組織全体を一度に接続できます。Aikido は Resource Directory 内のすべてのアカウントを自動で取得し、後から追加された新しいアカウントも含まれます。複数アカウントを大規模に管理するチームに最適です。

{% tabs %}
{% tab title="Alibaba Resource Directory 全体" %}
**Alibaba Resource Directory 全体**

1. にサインインし [Alibaba Cloud コンソール](https://www.alibabacloud.com/) を **管理アカウント** で使用します。
2. 確認してください [Stack Groups の信頼済みアクセス](https://www.alibabacloud.com/help/en/ros/user-guide/use-stack-groups-to-deploy-resources-across-accounts-and-regions) が Resource Directory で有効になっていることを。
3. Aikido のウィザードで、以下を入力します:
   * **Resource Directory ID** （例: `rd-XXXXXX`)
   * **ルート Directory ID または Folder ID** （例: `r-abcdef` または `fd-abcdefghij, fd-jihgfedcba`）。すべてをスキャンするにはルート ID を使用し、対象を絞るには特定の Folder ID を列挙します。
   * **除外するアカウント ID** *（任意）*：Aikido にスキップさせたいアカウント。
   * **ACR スキャンを有効化** Aikido に、インフラに加えて Alibaba Cloud Container Registry のイメージもスキャンさせたい場合。

これらの値は Alibaba コンソールの **Resource Directory**.
{% endtab %}

{% tab title="単一の Alibaba アカウント" %}
**単一の Alibaba アカウント**

次へ移動します： [Alibaba Cloud コンソール](https://www.alibabacloud.com/) で見つかり、接続したいアカウントでサインインします。
{% endtab %}
{% endtabs %}
{% endstep %}

{% step %}
**RAM ロールとポリシーを作成**

Aikido のウィザードで **「RAM ロールとポリシーを作成」**&#x3092;クリックします。これにより、テンプレートが事前入力された Alibaba Cloud ROS が開きます。このロールは Aikido に読み取り専用の監査権限を付与し、Aikido がインフラを編集することは決してできません。

*AccessKey ペアやパスワードが Aikido と共有されることはありません。*

* ウィザードに表示される値を `ExternalId` パラメータとして入力してください（例: `aikido-3377`).
* （Resource Directory の設定のみ） `ResourceDirectoryFolderIds` および `EnableAcrScanning` について、Aikido で設定したのと同じ値を指定してください。
* チェックを入れます **「Alibaba Cloud ROS が RAM リソースを作成できることを確認します」**.
* をクリック **作成**.

正確な ROS テンプレートを確認するには、 [こちらをクリック](https://aikido-cspm-templates.s3.eu-west-1.amazonaws.com/alibaba-ros-template-production.json)してください。必要であれば、ウィザードは同等の Terraform テンプレートも生成できます。
{% endstep %}

{% step %}
**AikidoRoleARN をコピーして Aikido に貼り付けます**

Alibaba Cloud ROS で、今作成したスタックを開き、 **Outputs** タブに移動します。 **AikidoRoleARN** の値をコピーし、Aikido ウィザードの入力欄に貼り付けて、 **続行**.

<figure><img src="/files/56d71b654994873851764b1ba8de26d4eb32011a" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**クラウド接続に名前を付ける**

Aikido で接続したクラウドに名前を付け、運用環境（Production、Staging、Development、Mixed）のどれで動作するかを選択します。これにより、Aikido は重大度とビジネス影響に基づいて検出結果の優先順位付けを行いやすくなります。 **保存** で完了します。

<figure><img src="/files/e0a7ae15d289b757d39704d5a6c88889d9c2cbac" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

アカウント接続後、数分以内に Aikido が脅威になり得る設定ミスを報告します。

### コンテナイメージのスキャン

{% hint style="info" %}
Alibaba Cloud Resource Directory を接続する場合、コンテナイメージは RAM ロール経由でスキャンされるため、追加の操作は不要です。このセクションは個別の ACR 接続にのみ関連します。
{% endhint %}

Alibaba Cloud Container Registry (ACR) および Alibaba Cloud から利用するほとんどのサードパーティレジストリは OCI 互換のため、Aikido でスキャンできます。

Alibaba Cloud Container Registry で読み取り専用または pull のみのユーザーを作成します: <https://www.alibabacloud.com/help/en/acr/user-guide/configure-access-credentials>

その後、以下の OCI ガイドに従ってコンテナイメージスキャンを設定します:

{% content-ref url="/pages/6a5d72cfab9a6689c7c638172ccd7e285110bf66" %}
[汎用 OCI 対応レジストリ](/docs/docs-ja/kontenaimjisukyan/standalone-registries/generic-oci-compatible-registry.md)
{% endcontent-ref %}

### 仮想マシンのスキャン

Alibaba Cloud 上の仮想マシンをスキャンするには、Local VM Scanner を使用します。パッケージ、システム依存関係、設定をインスタンス上で直接検査します。

{% content-ref url="/pages/bff6559245dacffd7e3b448230318335c527273b" %}
[ローカル VM スキャン](/docs/docs-ja/mashinsukyan/local-vm-scanning.md)
{% endcontent-ref %}

ECS インスタンスは、 [ユーザーデータを設定して](https://www.alibabacloud.com/help/en/ecs/user-guide/customize-the-initialization-configuration-for-an-instance) 必要なバイナリをダウンロードしてインストールすることで Local VM Scanner を取得できます。通常お使いの自動化ツール（Ansible、Terraform でプロビジョニングしたスクリプト、cloud-init）を使って中央から展開することもでき、その場合は新しい Alibaba Cloud インスタンスが自動的に登録されます。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/kuraudosukyan/connect-your-cloud/connect-alibaba-account.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
