CIS hardening
Every StoreFrame environment is hardened against CIS Benchmark Level 1 controls at provision time and re-applied on every platform run.
Every Ubuntu VM that StoreFrame provisions, including customer Magento environments and trial VMs, is hardened against CIS Benchmark Level 1 controls. The hardening runs as part of the platform's hardening role and is applied at provision time and on every subsequent platform run. There is no manual hardening step: a freshly provisioned VM passes the controls listed below the first time you SSH into it.
What gets applied
Each control targets a specific CIS section:
| Control | CIS section | What it does |
|---|---|---|
| SSH hardening | 5.2 | Restricts SSH ciphers, MACs, KEX algorithms; disables root login; enforces protocol 2 |
| Fail2Ban | — | Adds Fail2Ban as a second layer of SSH brute-force protection |
| Kernel network settings | 3.x | Kernel-level network hardening (rp_filter, syncookies, redirects, etc.) |
| Audit trail | 4.1 | Installs and configures audit trail for security-relevant events |
| PAM hardening | 5.3, 5.4 | Password quality rules and account lockout via PAM |
| File integrity monitoring | 1.3 | AIDE file integrity monitoring with a daily check |
| Cron hardening | 5.1 | Tightens permissions and access control on cron directories |
| Unused kernel modules | 3.1 | Disables unused network protocols (dccp, sctp, rds, tipc) |
| Additional controls | Various | GRUB permissions, AppArmor enforce, core dumps disabled, time sync, journald, rsyslog, sudo logging |
| Loopback firewall rules | 3.5.3.3.1 | Loopback traffic rules in UFW |
| Docker network hardening | — | Preserves client IPs through Docker so security tools see real source IPs |
Additional controls
These smaller controls are applied alongside the ones above:
- Apport removed (CIS 1.5.5)
- GRUB and audit binary permissions (CIS 1.4, 4.1.4.11) —
chmod 600on/boot/grub/grub.cfgandchmod 700on audit binaries - AppArmor in enforce mode (CIS 1.6) — installed, all profiles set to enforce, enabled at boot
- Core dumps disabled (CIS 1.4.1)
- Shell timeout (CIS 5.5.4)
- Default umask (CIS 5.5.5) — umask 027
- Chrony for time sync (CIS 2.1.1)
- Insecure packages removed (CIS 2.3) —
ftp,tnftp,telnet,inetutils-telnet;rsyncservice masked - Journald hardened (CIS 4.2.1.x) — persistent storage, compression, syslog forwarding, rotation caps
- Rsyslog file mode (CIS 4.2.2.4) —
$FileCreateMode 0640 - Sudo logging and PTY enforcement (CIS 5.2.4, 5.2.5)
- Login banner (CIS 1.5.2) — authorized-users-only notice in
/etc/issue - Group integrity (CIS 6.2.3, 6.2.4) — every GID in
/etc/passwdexists in/etc/group; no users haveshadowas primary group
Verification with Wazuh SCA
Every customer VM also runs the Wazuh agent (see Wazuh). Wazuh's Security Configuration Assessment (SCA) module evaluates the host against CIS Ubuntu policies and produces a compliance score visible on the Wazuh dashboard. Because the hardening applies the controls that the SCA policy expects, most checks pass on a freshly provisioned VM without manual intervention.
A few checks that don't apply to cloud VMs, such as separate disk partitions for /tmp and /var, are excluded from the score.
Scope
Environments are hardened to CIS Benchmark Level 1. If your workload needs Level 2, contact support.
Related
- Wazuh — agent that audits these controls and reports compliance
- CrowdSec — behavioral firewall layer on top of the hardened base
- OpenResty + Lua security pipeline — application-layer security on top of the OS-level hardening