Fides on Ubuntu 24.04 LTS
بواسطة cloudimg
Fides, open source privacy engineering, on Ubuntu 24.04 LTS
This is a repackaged open source product with additional charges for cloudimg support services.
Fides - Privacy Engineering Platform by cloudimg
Deploy your own privacy engineering platform on Azure in minutes - no manual installation, no shared credentials. This image delivers Fides 2.86.2, built by Ethyca, fully installed and hardened, so your team can start mapping personal data as soon as the VM boots.
What Fides Does
Fides is the system of record for how personal data moves through your organisation. You describe your systems and datasets against fideslang, a shared privacy taxonomy of data categories, data uses and data subjects, and Fides turns that description into working machinery.
It maps and inventories the personal data you hold, so you can answer what you store, where it lives and why you process it. It stores and enforces the consent preferences your customers have given you. And it automates data subject access and erasure requests by executing them against the systems the data actually lives in, rather than leaving them as a spreadsheet exercise. Everything is available through a documented REST API as well as the web interface, so privacy controls can be wired into your delivery process instead of bolted on afterwards.
Why This Image Instead of Manual Installation
Installing Fides by hand means providing a Python 3.13 interpreter that Ubuntu 24.04 does not ship, resolving 114 pinned dependencies, provisioning PostgreSQL and Redis, running 412 database migrations, wiring a celery worker to a broker, supplying a connector template tree the published package omits, and configuring a reverse proxy. This image removes that burden:
- Fides 2.86.2 installed from the official ethyca-fides distribution into a dedicated Python 3.13 virtual environment
- PostgreSQL 16 and Redis 7, both installed, configured and bound to the loopback interface
- A celery worker that executes privacy requests off the web request path, correctly wired to the broker
- nginx fronting the application on ports 80 and 443, with buffer sizes tuned for authenticated sessions
- The fideslang taxonomy seeded and ready to use, with 85 data categories, 56 data uses and 15 data subjects
- The Admin UI and the full REST API available immediately, with anonymous readiness endpoints for load balancer probes
- 24/7 cloudimg engineers handling upgrades, tuning and configuration
Secure By Default: Seven Secrets, All Generated On Your First Boot
Fides holds more shared secret surface than most applications, and the open source project publishes a working sample value for nearly all of it. Every one is generated uniquely on the first boot of each VM and none is baked into the image: the encryption key protecting stored connection credentials and access tokens, the root API client id and secret, the administrator username and password, the token signing secret, the database password, the cache password, and the TLS certificate.
The image ships with an empty application database, no administrator and no shared secret. The configuration writer refuses to write any published upstream default, and the build proves each published sample credential is rejected by the running server before the image ships. Your machine's credentials are written to a root only file.
Secure By Default: The Application Cannot Start Before Its Secrets Exist
The application and worker services are gated on a marker that first boot creates only after every secret is written and the database exists. The image ships without that marker, so the services physically cannot start against a half initialised database or an upstream default credential.
Getting Started
1. Launch the image on Standard_B2s or larger 2. Read the per instance credentials from /root/fides-credentials.txt 3. Browse to the VM on port 443, sign in, and explore the privacy taxonomy 4. Add your systems to the data map via the Admin UI or REST API
Licensing and Pricing
Fides is licensed under the Apache License 2.0 and is free; there is no per-seat fee. The cloudimg charge of 0.04 US dollars per vCPU hour covers packaging, security patching, image maintenance and 24/7 expert support. Restrict the web interface to your team's source addresses in your network security group: Fides holds a map of where your personal data lives.
cloudimg Support
24/7 technical support by email covers deployment, upgrades, connector configuration and privacy request tuning. Critical issues receive a one-hour average response.
cloudimg is not affiliated with or endorsed by Ethyca or the Fides project. All product and company names are trademarks of their respective holders, and use of them does not imply any affiliation or endorsement.