<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[CIS Benchmark Compliance]]></title><description><![CDATA[<p dir="auto">This is the out of the box results on a fully patched/updated Cloudron per Wazuh (as of about 90 seconds ago).</p>
<p dir="auto"><img src="/assets/uploads/files/1767059999892-73d259c6-b25d-4067-8a26-f02727500baa-image-resized.png" alt="73d259c6-b25d-4067-8a26-f02727500baa-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">I will be deploying a test instance of Cloudron on a VM with a set of CIS/NIST ansible playbooks to get the node to 100% compliance and see if anything breaks.</p>
]]></description><link>https://forum.cloudron.io/topic/14814/cis-benchmark-compliance</link><generator>RSS for Node</generator><lastBuildDate>Tue, 19 May 2026 07:28:09 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/14814.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 30 Dec 2025 02:01:21 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to CIS Benchmark Compliance on Fri, 02 Jan 2026 22:24:21 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/charlesnw" aria-label="Profile: charlesnw">@<bdi>charlesnw</bdi></a> said in <a href="/post/117780">CIS Benchmark Compliance</a>:</p>
<blockquote>
<p dir="auto">Do you use hardened Docker base images?</p>
</blockquote>
<p dir="auto">See the discussion here: <a href="https://forum.cloudron.io/topic/14762/docker-hardened-images">https://forum.cloudron.io/topic/14762/docker-hardened-images</a> In short: No, for good reasons (maintenance and standards)</p>
]]></description><link>https://forum.cloudron.io/post/117851</link><guid isPermaLink="true">https://forum.cloudron.io/post/117851</guid><dc:creator><![CDATA[necrevistonnezr]]></dc:creator><pubDate>Fri, 02 Jan 2026 22:24:21 GMT</pubDate></item><item><title><![CDATA[Reply to CIS Benchmark Compliance on Wed, 31 Dec 2025 13:08:09 GMT]]></title><description><![CDATA[<p dir="auto">As I have said, I'm deploying a FLO stack (with Cloudron at the core) into a startup that I'm building (as CIO/CTO). We have to be CMMC compliant. Making sure Cloudron works on a 100% compliant base system is the first milestone. While you may not consider them issues, they do need to be addressed to be compliant. That's "my problem". If a fully compliant base system causes an issue in Cloudron , that's "our problem". <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=11345d81604" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>
<p dir="auto">While you, and many Cloudron users may not care about CMMC/HIPPA/SOC/PCI compliance, I (and my board) do. I'm also building a small side business which will sell Cloudron as a service (pre setup/configured, all applications have admin password changed, admin passwords stored in Bitwarden) (the new Bitwarden SSO makes that possible without bootstrapping issues) and it will have CMMC/SOC/PCI/HIPPA compliance (at the higher tier).</p>
]]></description><link>https://forum.cloudron.io/post/117781</link><guid isPermaLink="true">https://forum.cloudron.io/post/117781</guid><dc:creator><![CDATA[charlesnw]]></dc:creator><pubDate>Wed, 31 Dec 2025 13:08:09 GMT</pubDate></item><item><title><![CDATA[Reply to CIS Benchmark Compliance on Wed, 31 Dec 2025 13:03:57 GMT]]></title><description><![CDATA[<p dir="auto">As I mentioned, I'll be applying Ansible playbooks to bring the base system to 100% compliance.</p>
<p dir="auto">I never said these were Cloudron issues. I said that I would be testing Cloudron on a 100% compliant base system and fixing anything that is broken. I don't expect any issues. Because, as you mentioned, these are all base system config tweaks.</p>
<p dir="auto">Cloudron runs everything 100% in Docker images.</p>
<p dir="auto">Where I suspect change may be needed, is at the Cloudron container level when I start scanning everything with Trivy.</p>
<p dir="auto">Do you use hardened Docker base images?</p>
]]></description><link>https://forum.cloudron.io/post/117780</link><guid isPermaLink="true">https://forum.cloudron.io/post/117780</guid><dc:creator><![CDATA[charlesnw]]></dc:creator><pubDate>Wed, 31 Dec 2025 13:03:57 GMT</pubDate></item><item><title><![CDATA[Reply to CIS Benchmark Compliance on Wed, 31 Dec 2025 09:53:00 GMT]]></title><description><![CDATA[<p dir="auto">From a quick read it seems most (all?) are just general linux things. Have you tried this on a fresh Ubuntu 24.04 system without Cloudron? Because I suspect most of these "issues" are in that as well. Most of them are not really issues in my eyes atleast.</p>
]]></description><link>https://forum.cloudron.io/post/117767</link><guid isPermaLink="true">https://forum.cloudron.io/post/117767</guid><dc:creator><![CDATA[joseph]]></dc:creator><pubDate>Wed, 31 Dec 2025 09:53:00 GMT</pubDate></item><item><title><![CDATA[Reply to CIS Benchmark Compliance on Wed, 31 Dec 2025 01:23:02 GMT]]></title><description><![CDATA[<p dir="auto">I have uploaded it here: <a href="https://staticbits.reachableceo.com/CloudronWazuhReport-2025-30-12.csv" target="_blank" rel="noopener noreferrer nofollow ugc">https://staticbits.reachableceo.com/CloudronWazuhReport-2025-30-12.csv</a></p>
]]></description><link>https://forum.cloudron.io/post/117758</link><guid isPermaLink="true">https://forum.cloudron.io/post/117758</guid><dc:creator><![CDATA[charlesnw]]></dc:creator><pubDate>Wed, 31 Dec 2025 01:23:02 GMT</pubDate></item><item><title><![CDATA[Reply to CIS Benchmark Compliance on Wed, 31 Dec 2025 01:20:18 GMT]]></title><description><![CDATA[<p dir="auto">Is there a way to upload a text file to the forum? I have a csv of the wazuh report exported.</p>
]]></description><link>https://forum.cloudron.io/post/117757</link><guid isPermaLink="true">https://forum.cloudron.io/post/117757</guid><dc:creator><![CDATA[charlesnw]]></dc:creator><pubDate>Wed, 31 Dec 2025 01:20:18 GMT</pubDate></item><item><title><![CDATA[Reply to CIS Benchmark Compliance on Tue, 30 Dec 2025 15:56:10 GMT]]></title><description><![CDATA[<p dir="auto">I’ll see about getting the full list exported to a text file and posted.</p>
]]></description><link>https://forum.cloudron.io/post/117734</link><guid isPermaLink="true">https://forum.cloudron.io/post/117734</guid><dc:creator><![CDATA[charlesnw]]></dc:creator><pubDate>Tue, 30 Dec 2025 15:56:10 GMT</pubDate></item><item><title><![CDATA[Reply to CIS Benchmark Compliance on Tue, 30 Dec 2025 07:44:44 GMT]]></title><description><![CDATA[<p dir="auto">The full list would indeed be interesting to see. Especially what comes after disabling all those kernel modules.</p>
]]></description><link>https://forum.cloudron.io/post/117711</link><guid isPermaLink="true">https://forum.cloudron.io/post/117711</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Tue, 30 Dec 2025 07:44:44 GMT</pubDate></item><item><title><![CDATA[Reply to CIS Benchmark Compliance on Tue, 30 Dec 2025 04:51:53 GMT]]></title><description><![CDATA[<p dir="auto">Can you post the list of failures?</p>
]]></description><link>https://forum.cloudron.io/post/117704</link><guid isPermaLink="true">https://forum.cloudron.io/post/117704</guid><dc:creator><![CDATA[robi]]></dc:creator><pubDate>Tue, 30 Dec 2025 04:51:53 GMT</pubDate></item></channel></rss>