> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/mashinsukyan/aws/aws-ec2-virtual-machine-scanning-setup.md).

# AWS EC2仮想マシンスキャンの設定

{% hint style="info" %}
この機能は **Pro** に、 **Advanced** プランのみで利用できます。 [お問い合わせ](https://www.aikido.dev/contact) を参照してください。
{% endhint %}

### なぜ仮想マシンをスキャンする必要があるのですか？ <a href="#why-should-i-scan-my-virtual-machines" id="why-should-i-scan-my-virtual-machines"></a>

仮想マシンのスキャンでは、Aikido が仮想マシンのディスクをスキャンし、脆弱なパッケージ、古いランタイム、リスクのあるライセンスを検出します。

### はじめに <a href="#getting-started" id="getting-started"></a>

Amazon EC2 インスタンスのスキャンを有効にするには、まず AWS アカウントを Aikido に接続します。これを行うには、以下に示す手順に従ってください。 [この記事](/docs/docs-ja/kuraudosukyan/connect-your-cloud/aws/connect-aws-account-to-aikido.md).

クラウドを接続すると、詳細ページに「Virtual Machines」というタブが表示されます。

![AWS EC2 インスタンスの VM スキャンを有効にして、オープンソースの依存関係の問題を検出します。](/files/f42234c3ef92f6ea1595b67347a553627b0d6f08)

「Set Up VM Scanning」をクリックすると、次のページに移動します：

![IAM ロールとポリシーの作成手順を含む AWS EC2 ボリュームスキャンのセットアップ。](/files/3307b92c22d38e14823976b274da7888add9828c)

このページでは、スキャンしたい仮想マシンのアカウントに適用する AWS CloudFormation テンプレートを使用して、仮想マシン スキャンを設定できます。この CloudFormation テンプレートにより、AWS アカウントへのアクセスが制限されたロールが作成されます。重要なのは **保持** スキャンを実行するために Aikido に必要な最小限の権限であるため、ロールの権限をそのままにしておいてください。

CloudFormation リソースが作成されると、作成された AWS のロールの ARN が表示されます。それをコピーして、セットアップ画面の入力欄に追加してください。「保存」をクリックすると、Aikido はすぐにアカウント内の仮想マシンの検出を開始し、スキャンします。

### VM のグループ化 <a href="#vm-grouping" id="vm-grouping"></a>

スキャン効率を最適化するため、Aikido は特定の EC2 インスタンスをグループ化し、各グループから 1 つのインスタンスのみをスキャンします。グループ化は次のように行われます。

* **Auto Scaling グループ（ASG）**：同じ AWS Auto Scaling グループに属するすべての EC2 インスタンスは、Aikido では 1 つの VM グループとして表示されます。VM グループ名は ASG 名と一致します。
* **Karpenter ノードプール**：同じ EKS クラスター内の同一の Karpenter ノードプールに属するすべての EC2 インスタンスは、まとめてグループ化されます。VM グループ名は、Karpenter が使用するインスタンス名のパターンと一致します。
* **グループ化なし**：ASG や Karpenter ノードプールに属していない EC2 インスタンスは、スタンドアロンの VM として扱われ、個別にスキャンされます。

### スキャン対象の VM を管理する <a href="#managing-which-vms-are-scanned" id="managing-which-vms-are-scanned"></a>

Aikido は [VM スキャンの包含・除外モデルをサポートしています](/docs/docs-ja/mashinsukyan/aws/managing-which-vms-are-scanned.md).

### スキャン頻度

毎日、スキャン対象として有効になっている全VMの10%が再スキャンされるため、平均すると各VMは10日に1回スキャンされます。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/mashinsukyan/aws/aws-ec2-virtual-machine-scanning-setup.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
