{"id":270,"date":"2026-07-03T12:00:00","date_gmt":"2026-07-03T12:00:00","guid":{"rendered":"https:\/\/konteynerium.com\/?p=212"},"modified":"2026-10-06T11:34:00","modified_gmt":"2026-10-06T11:34:00","slug":"container-image-guvenligi-zafiyet-taramasi-en-iyi-uygulamalar","status":"publish","type":"post","link":"https:\/\/konteynerium.com\/index.php\/2026\/07\/03\/container-image-guvenligi-zafiyet-taramasi-en-iyi-uygulamalar\/","title":{"rendered":"Container Image G\u00fcvenli\u011fi: Zafiyet Taramas\u0131 ve En \u0130yi Uygulamalar"},"content":{"rendered":"<p>Bir Docker imaj\u0131, sizin yazd\u0131\u011f\u0131n\u0131z kodun yan\u0131 s\u0131ra genellikle onlarca (bazen y\u00fczlerce) ba\u015fkas\u0131n\u0131n yazd\u0131\u011f\u0131 paketi de i\u00e7inde ta\u015f\u0131r: taban i\u015fletim sistemi katmanlar\u0131, programlama dili \u00e7al\u0131\u015fma zaman\u0131, k\u00fct\u00fcphaneler&#8230; Bunlar\u0131n herhangi birinde bilinen bir g\u00fcvenlik a\u00e7\u0131\u011f\u0131 varsa, o a\u00e7\u0131k sizin imaj\u0131n\u0131za da ge\u00e7er. Container image g\u00fcvenli\u011fi, bu riski build a\u015famas\u0131nda yakalamak ve olabildi\u011fince k\u00fc\u00e7\u00fcltmekle ilgilidir.<\/p>\n<h2>1. K\u00fc\u00e7\u00fck ve g\u00fcncel taban imaj se\u00e7in<\/h2>\n<p>Bir imaj\u0131n g\u00fcvenlik a\u00e7\u0131\u011f\u0131 say\u0131s\u0131, \u00e7o\u011funlukla i\u00e7indeki paket say\u0131s\u0131yla do\u011fru orant\u0131l\u0131d\u0131r. <code>ubuntu:latest<\/code> gibi genel ama\u00e7l\u0131, b\u00fcy\u00fck bir taban imaj yerine daha dar kapsaml\u0131 alternatifler se\u00e7mek, sald\u0131r\u0131 y\u00fczeyini do\u011frudan k\u00fc\u00e7\u00fclt\u00fcr:<\/p>\n<table>\n<thead>\n<tr>\n<th>Taban imaj<\/th>\n<th>Yakla\u015f\u0131k boyut<\/th>\n<th>Not<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>ubuntu:24.04<\/code><\/td>\n<td>~80 MB<\/td>\n<td>Genel ama\u00e7l\u0131, \u00e7ok paket i\u00e7erir<\/td>\n<\/tr>\n<tr>\n<td><code>node:20<\/code><\/td>\n<td>~380 MB<\/td>\n<td>Debian tabanl\u0131, geli\u015ftirme ara\u00e7lar\u0131 dahil<\/td>\n<\/tr>\n<tr>\n<td><code>node:20-slim<\/code><\/td>\n<td>~180 MB<\/td>\n<td>Gereksiz ara\u00e7lar \u00e7\u0131kar\u0131lm\u0131\u015f<\/td>\n<\/tr>\n<tr>\n<td><code>node:20-alpine<\/code><\/td>\n<td>~50 MB<\/td>\n<td>Minimal Alpine Linux tabanl\u0131<\/td>\n<\/tr>\n<tr>\n<td><code>gcr.io\/distroless\/nodejs20<\/code><\/td>\n<td>~120 MB<\/td>\n<td>Kabuk (shell) bile i\u00e7ermez<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&#8220;Distroless&#8221; imajlar en u\u00e7taki se\u00e7enektir: i\u00e7lerinde paket y\u00f6neticisi, kabuk (<code>sh<\/code>\/<code>bash<\/code>) hatta \u00e7o\u011fu zaman temel Linux komutlar\u0131 bile yoktur \u2014 bir sald\u0131rgan container&#8217;a s\u0131zsa bile elinde \u00e7al\u0131\u015ft\u0131rabilece\u011fi neredeyse hi\u00e7bir ara\u00e7 kalmaz.<\/p>\n<h2>2. \u0130maj\u0131 etiket sabitleyerek (pin) kullan\u0131n, <code>:latest<\/code>&#8216;ten ka\u00e7\u0131n\u0131n<\/h2>\n<pre><code># Ka\u00e7\u0131n\u0131n \u2014 hangi s\u00fcr\u00fcm\u00fc \u00e7ekti\u011finiz belirsiz, g\u00fcncellemede ne de\u011fi\u015fti bilinmez\nFROM node:latest\n\n# Tercih edin \u2014 \u00fcretilebilir (reproducible), denetlenebilir\nFROM node:20.15.1-alpine3.20<\/code><\/pre>\n<p>Sabit bir s\u00fcr\u00fcm etiketi, &#8220;d\u00fcn \u00e7al\u0131\u015fan build bug\u00fcn neden bozuldu?&#8221; sorununu \u00f6nler ve bir g\u00fcvenlik taramas\u0131n\u0131n sonucunu tekrar \u00fcretilebilir k\u0131lar.<\/p>\n<h2>3. Zafiyet taramas\u0131 (vulnerability scanning) yap\u0131n<\/h2>\n<p>\u0130maj\u0131n\u0131z\u0131 push etmeden \u00f6nce, i\u00e7indeki paketleri bilinen g\u00fcvenlik a\u00e7\u0131\u011f\u0131 veritabanlar\u0131yla (CVE) kar\u015f\u0131la\u015ft\u0131ran bir taray\u0131c\u0131dan ge\u00e7irin. En yayg\u0131n a\u00e7\u0131k kaynak ara\u00e7 <strong>Trivy<\/strong>&#8216;dir:<\/p>\n<pre><code># Trivy kurulumundan sonra tek komutla tarama\ntrivy image benim-uygulamam:1.0\n\n# Sadece \"y\u00fcksek\" ve \"kritik\" seviyeli a\u00e7\u0131klar\u0131 g\u00f6ster,\n# b\u00f6yle bir a\u00e7\u0131k bulunursa CI\/CD ad\u0131m\u0131n\u0131 ba\u015far\u0131s\u0131z say\ntrivy image --severity HIGH,CRITICAL --exit-code 1 benim-uygulamam:1.0<\/code><\/pre>\n<p>Bu taramay\u0131 CI\/CD pipeline&#8217;\u0131n\u0131za (\u00f6rne\u011fin her <code>docker build<\/code>&#8216;dan sonra) eklemek, g\u00fcvenlik a\u00e7\u0131\u011f\u0131 olan bir imaj\u0131n production&#8217;a hi\u00e7 ula\u015fmamas\u0131n\u0131 sa\u011flar.<\/p>\n<div class=\"callout\">\n  <span class=\"glyph\">\u2713<\/span><\/p>\n<p>Docker Hub, GitHub Container Registry ve \u00e7o\u011fu bulut sa\u011flay\u0131c\u0131n\u0131n kendi registry&#8217;si de push edilen imajlar\u0131 otomatik olarak tarayabilir \u2014 bu \u00f6zelli\u011fi registry ayarlar\u0131n\u0131zdan etkinle\u015ftirmek, ek bir ara\u00e7 kurmadan temel bir g\u00fcvenlik katman\u0131 sa\u011flar.<\/p>\n<\/div>\n<h2>4. Gizli bilgileri (secret) imaja asla g\u00f6mmeyin<\/h2>\n<p>API anahtarlar\u0131, veritaban\u0131 parolalar\u0131 gibi gizli bilgileri <code>ENV<\/code> veya <code>ARG<\/code> ile do\u011frudan Dockerfile&#8217;a yazmak yayg\u0131n ama tehlikeli bir hatad\u0131r \u2014 bu de\u011ferler imaj\u0131n katmanlar\u0131nda kal\u0131c\u0131 olarak saklan\u0131r ve <code>docker history<\/code> ile kolayca g\u00f6r\u00fclebilir:<\/p>\n<pre><code># Yapmay\u0131n \u2014 parola imaj katman\u0131na kal\u0131c\u0131 olarak g\u00f6m\u00fcl\u00fcr\nARG DB_PASSWORD=gizli123\nENV DB_PASSWORD=$DB_PASSWORD\n\n# Bunun yerine: \u00e7al\u0131\u015fma zaman\u0131nda d\u0131\u015far\u0131dan enjekte edin\n# docker run -e DB_PASSWORD=gizli123 ...\n# veya Docker Compose'da bir .env dosyas\u0131 \/ secrets kullan\u0131n<\/code><\/pre>\n<h2>5. Gereksiz katmanlar\u0131 ve dosyalar\u0131 build ba\u011flam\u0131ndan \u00e7\u0131kar\u0131n<\/h2>\n<p>Multi-stage build (bkz. <a href=\"https:\/\/konteynerium.com\/index.php\/2026\/05\/01\/dockerfile-yazmaya-giris\/\">Dockerfile Yazmaya Giri\u015f<\/a> yaz\u0131m\u0131z) ile build ara\u00e7lar\u0131n\u0131 nihai imajdan tamamen ay\u0131rmak, hem boyutu k\u00fc\u00e7\u00fclt\u00fcr hem de derleyici, test ara\u00e7lar\u0131 gibi gereksiz yaz\u0131l\u0131mlar\u0131n \u00fcretim imaj\u0131nda bulunmas\u0131n\u0131 \u00f6nler \u2014 bu yaz\u0131l\u0131mlardaki olas\u0131 a\u00e7\u0131klar da b\u00f6ylece devreye girmez.<\/p>\n<h2>H\u0131zl\u0131 kontrol listesi<\/h2>\n<ul>\n<li>K\u00fc\u00e7\u00fck, minimal bir taban imaj kullan\u0131yor musunuz? (<code>alpine<\/code>, <code>slim<\/code>, distroless)<\/li>\n<li>Taban imaj s\u00fcr\u00fcm\u00fcn\u00fc sabitlediniz mi, <code>:latest<\/code> kullanm\u0131yor musunuz?<\/li>\n<li>\u0130maj\u0131 CI\/CD i\u00e7inde otomatik olarak tar\u0131yor musunuz? (Trivy, Grype, registry&#8217;nin kendi taray\u0131c\u0131s\u0131)<\/li>\n<li>Container root olmayan bir kullan\u0131c\u0131yla m\u0131 \u00e7al\u0131\u015f\u0131yor? (bkz. <a href=\"https:\/\/konteynerium.com\/index.php\/2026\/06\/26\/rootless-container-nedir-neden-kullanmalisiniz\/\">Rootless container<\/a> yaz\u0131m\u0131z)<\/li>\n<li>Gizli bilgiler imaja g\u00f6m\u00fcl\u00fc de\u011fil, \u00e7al\u0131\u015fma zaman\u0131nda m\u0131 enjekte ediliyor?<\/li>\n<li>Multi-stage build ile build ara\u00e7lar\u0131 nihai imajdan ayr\u0131\u015ft\u0131r\u0131lm\u0131\u015f m\u0131?<\/li>\n<\/ul>\n<p>Bu portaldaki <a href=\"https:\/\/konteynerium.com\/index.php\/dockerfile-optimizasyon-kontrolcusu\/\">Dockerfile Kontrolc\u00fcs\u00fc<\/a> arac\u0131, bu kontrol listesindeki maddelerin \u00e7o\u011funu (taban imaj etiketi, USER talimat\u0131, g\u00f6m\u00fcl\u00fc s\u0131r tespiti gibi) Dockerfile&#8217;\u0131n\u0131z\u0131 yap\u0131\u015ft\u0131rd\u0131\u011f\u0131n\u0131z anda otomatik olarak kontrol eder \u2014 imaj\u0131 build etmeden \u00f6nce h\u0131zl\u0131 bir \u00f6n kontrol i\u00e7in kullanabilirsiniz.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>K\u00fc\u00e7\u00fck taban imaj se\u00e7iminden Trivy ile zafiyet taramas\u0131na, gizli bilgilerin imaja g\u00f6m\u00fclmesini \u00f6nlemeye kadar container image g\u00fcvenli\u011fi i\u00e7in pratik bir kontrol listesi.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"seviye":[9],"class_list":["post-270","post","type-post","status-publish","format-standard","hentry","category-orkestrasyon-guvenlik","seviye-ileri"],"_links":{"self":[{"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/posts\/270","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/comments?post=270"}],"version-history":[{"count":1,"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/posts\/270\/revisions"}],"predecessor-version":[{"id":571,"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/posts\/270\/revisions\/571"}],"wp:attachment":[{"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/media?parent=270"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/categories?post=270"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/tags?post=270"},{"taxonomy":"seviye","embeddable":true,"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/seviye?post=270"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}