> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/mashinsukyan/aws/aws-ec2-virtual-machine-scanning-setup.md).

# AWS EC2 仮想マシンスキャンのセットアップ

{% hint style="info" %}
この機能は以下で利用できます **Pro** および **Advanced** プランのみ。 [お問い合わせ](https://www.aikido.dev/contact) 詳細はこちら。
{% endhint %}

### なぜ仮想マシンをスキャンする必要があるのですか？ <a href="#why-should-i-scan-my-virtual-machines" id="why-should-i-scan-my-virtual-machines"></a>

仮想マシンスキャンでは、Aikidoが仮想マシンのディスクをスキャンし、脆弱なパッケージ、古いランタイム、リスクのあるライセンスを検出します。

### はじめに <a href="#getting-started" id="getting-started"></a>

Amazon EC2インスタンスのスキャンを有効にするには、まずAWSアカウントをAikidoに接続することから始めます。これを行うには、次に示す手順に従ってください。 [この記事](/docs/docs-ja/kuraudosukyan/connect-your-cloud/aws/connect-aws-account-to-aikido.md).

クラウドを接続すると、詳細ページに「Virtual Machines」というタブが表示されます。

![AWS EC2インスタンスのVMスキャンを有効にして、オープンソースの依存関係の問題を検出します。](/files/f42234c3ef92f6ea1595b67347a553627b0d6f08)

「Set Up VM Scanning」をクリックすると、次のページに移動します。

![IAMロールとポリシーの作成手順を含むAWS EC2ボリュームスキャンのセットアップ。](/files/3307b92c22d38e14823976b274da7888add9828c)

このページでは、スキャンしたい仮想マシンのアカウントに適用する必要があるAWS CloudFormationテンプレートを使用して、仮想マシンスキャンを設定できます。CloudFormationテンプレートは、AWSアカウントへのアクセスが制限されたロールを作成します。重要なのは、 **保持** そのロールの権限を

CloudFormationリソースが作成されると、作成されたAWSロールのARNが表示されます。それをコピーして、セットアップ画面の入力欄に追加してください。「保存」をクリックすると、Aikidoは直ちにアカウント内の仮想マシンの検出とスキャンを開始します。<br>

### VMのグループ化 <a href="#getting-started" id="getting-started"></a>

スキャン効率を最適化するため、Aikido は特定の EC2 インスタンスをグループ化し、各グループから 1 つのインスタンスのみをスキャンします。グループ化は次のように行われます:

* **Auto Scaling Group（ASG）**: 同じAWS Auto Scaling Group内のすべてのEC2インスタンスは、Aikidoでは1つのVMグループとして表示されます。VMグループ名はASG名と一致します。
* **Karpenterノードプール**: EKSクラスター内で同じKarpenterノードプールに属するすべてのEC2インスタンスは、まとめてグループ化されます。VMグループ名はKarpenterが使用するインスタンス名のパターンと一致します。
* **グループ化なし**: ASGまたはKarpenterノードプールの一部でないEC2インスタンスは、スタンドアロンVMとして扱われ、個別にスキャンされます。

### どのVMをスキャンするかの管理 <a href="#managing-which-vms-are-scanned" id="managing-which-vms-are-scanned"></a>

Aikido はサポートしています [VM スキャンの包含・除外モデル](/docs/docs-ja/mashinsukyan/aws/managing-which-vms-are-scanned.md).

### スキャン頻度

毎日、スキャンが有効になっているすべてのVMの10%が再スキャンされるため、平均すると各VMは10日に1回スキャンされます。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/mashinsukyan/aws/aws-ec2-virtual-machine-scanning-setup.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
