Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps - Status | Demo | Docs | Install
  1. Cloudron Forum
  2. Feature Requests
  3. CIS Benchmark Compliance

CIS Benchmark Compliance

Scheduled Pinned Locked Moved Feature Requests
10 Posts 5 Posters 938 Views 8 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C Offline
    C Offline
    charlesnw
    wrote on last edited by
    #1

    This is the out of the box results on a fully patched/updated Cloudron per Wazuh (as of about 90 seconds ago).

    73d259c6-b25d-4067-8a26-f02727500baa-image.png

    I will be deploying a test instance of Cloudron on a VM with a set of CIS/NIST ansible playbooks to get the node to 100% compliance and see if anything breaks.

    1 Reply Last reply
    3
    • robiR Offline
      robiR Offline
      robi
      wrote on last edited by
      #2

      Can you post the list of failures?

      Conscious tech

      1 Reply Last reply
      2
      • nebulonN Away
        nebulonN Away
        nebulon
        Staff
        wrote on last edited by
        #3

        The full list would indeed be interesting to see. Especially what comes after disabling all those kernel modules.

        1 Reply Last reply
        2
        • C Offline
          C Offline
          charlesnw
          wrote on last edited by
          #4

          I’ll see about getting the full list exported to a text file and posted.

          1 Reply Last reply
          2
          • C Offline
            C Offline
            charlesnw
            wrote on last edited by
            #5

            Is there a way to upload a text file to the forum? I have a csv of the wazuh report exported.

            1 Reply Last reply
            0
            • C Offline
              C Offline
              charlesnw
              wrote on last edited by
              #6

              I have uploaded it here: https://staticbits.reachableceo.com/CloudronWazuhReport-2025-30-12.csv

              1 Reply Last reply
              0
              • J Offline
                J Offline
                joseph
                Staff
                wrote on last edited by
                #7

                From a quick read it seems most (all?) are just general linux things. Have you tried this on a fresh Ubuntu 24.04 system without Cloudron? Because I suspect most of these "issues" are in that as well. Most of them are not really issues in my eyes atleast.

                1 Reply Last reply
                1
                • C Offline
                  C Offline
                  charlesnw
                  wrote on last edited by
                  #8

                  As I mentioned, I'll be applying Ansible playbooks to bring the base system to 100% compliance.

                  I never said these were Cloudron issues. I said that I would be testing Cloudron on a 100% compliant base system and fixing anything that is broken. I don't expect any issues. Because, as you mentioned, these are all base system config tweaks.

                  Cloudron runs everything 100% in Docker images.

                  Where I suspect change may be needed, is at the Cloudron container level when I start scanning everything with Trivy.

                  Do you use hardened Docker base images?

                  necrevistonnezrN 1 Reply Last reply
                  2
                  • C Offline
                    C Offline
                    charlesnw
                    wrote on last edited by
                    #9

                    As I have said, I'm deploying a FLO stack (with Cloudron at the core) into a startup that I'm building (as CIO/CTO). We have to be CMMC compliant. Making sure Cloudron works on a 100% compliant base system is the first milestone. While you may not consider them issues, they do need to be addressed to be compliant. That's "my problem". If a fully compliant base system causes an issue in Cloudron , that's "our problem". 🙂

                    While you, and many Cloudron users may not care about CMMC/HIPPA/SOC/PCI compliance, I (and my board) do. I'm also building a small side business which will sell Cloudron as a service (pre setup/configured, all applications have admin password changed, admin passwords stored in Bitwarden) (the new Bitwarden SSO makes that possible without bootstrapping issues) and it will have CMMC/SOC/PCI/HIPPA compliance (at the higher tier).

                    1 Reply Last reply
                    4
                    • C charlesnw

                      As I mentioned, I'll be applying Ansible playbooks to bring the base system to 100% compliance.

                      I never said these were Cloudron issues. I said that I would be testing Cloudron on a 100% compliant base system and fixing anything that is broken. I don't expect any issues. Because, as you mentioned, these are all base system config tweaks.

                      Cloudron runs everything 100% in Docker images.

                      Where I suspect change may be needed, is at the Cloudron container level when I start scanning everything with Trivy.

                      Do you use hardened Docker base images?

                      necrevistonnezrN Offline
                      necrevistonnezrN Offline
                      necrevistonnezr
                      wrote on last edited by
                      #10

                      @charlesnw said in CIS Benchmark Compliance:

                      Do you use hardened Docker base images?

                      See the discussion here: https://forum.cloudron.io/topic/14762/docker-hardened-images In short: No, for good reasons (maintenance and standards)

                      1 Reply Last reply
                      1

                      Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                      Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                      With your input, this post could be even better 💗

                      Register Login
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • Bookmarks
                      • Search