تخطي إلى المحتوى الرئيسي
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/lynxroute.appwrite-8528e5f8-0dde-48d6-8eae-5f925273f87e/image1_Azureready.png

Appwrite - Hardened Backend-as-a-Service

بواسطة Lynxroute

Appwrite 1.9.6 - CIS Level 1 hardened open-source backend-as-a-service on Ubuntu 24.04 LTS

What is Appwrite

Appwrite is an open-source Backend-as-a-Service (BaaS) platform that gives developers a production backend without building one. Its PHP/Swoole API server runs as a Docker Compose stack and exposes authentication (email/password, OAuth, phone, magic URL), databases (collections and documents), file storage, serverless functions in multiple runtimes, scheduled tasks, messaging, and realtime subscriptions over REST and GraphQL APIs plus a web Console. Official SDKs cover web, Flutter, Apple, Android, and server languages (Node, Python, PHP, and more). Application data, sessions, and queues persist in a bundled MongoDB and Redis, both reachable only on the internal container network. Licensed BSD-3-Clause, with no vendor lock-in.

Why self-host Appwrite

Running Appwrite on a VM you control keeps user accounts, auth flows, application data, and function execution inside your own tenant rather than a managed backend service. Self-hosting suits teams with data residency requirements, organisations operating under GDPR, HIPAA or ISO 27001, and any product where backend state must stay within your own perimeter with no per-action fees. Appwrite is BSD-3-Clause licensed, fully auditable, with no vendor lock-in.

What this VM image adds

Security hardening:

  • Unique data-encryption key and service secrets generated per instance at first launch - no shipped default keys; the at-rest encryption key, executor secret, and MongoDB passwords are rotated on first boot
  • Self-signed TLS on 443 via an nginx reverse proxy - TLS terminated on port 443, the Appwrite stack served from the internal Traefik router on loopback; the application speaks plain HTTP only inside the host
  • MongoDB and Redis on the internal container network only - the database and cache are never published to the host or the public interface
  • No admin baked into the image - the first user you register in the Console becomes the root admin, and further Console sign-ups close automatically
  • Readiness splash - a loading page is served while the multi-container stack initialises, so the first visit never lands on a broken or error screen
  • UFW firewall - TCP 443 open externally for buyer use, TCP 22 for SSH; all other inbound dropped; Azure IMDS and WireServer egress pre-configured
  • fail2ban - SSH brute-force protection
  • AppArmor - mandatory access control
  • CVE scan - every image is scanned with Trivy before release

OS hardening (CIS Level 1):

  • CIS Ubuntu 24.04 LTS Level 1 Benchmark via ansible-lockdown
  • auditd for system call auditing of critical paths
  • SSH hardening - PasswordAuthentication disabled, key-only access, PermitRootLogin no, LoginGraceTime 60
  • Kernel hardening - SYN cookies, ASLR, rp_filter, kexec disabled, IPv6 off
  • /tmp as tmpfs with nosuid, nodev, noexec

Compliance artifacts (inside the VM):

  • SBOM - CycloneDX 1.6 at /etc/lynxroute/sbom.json with Appwrite pinned by version, PURL, BSD-3-Clause license, supplier, and hash
  • CIS Conformance Report at /etc/lynxroute/cis-report.html (OpenSCAP, Azure tailoring profile, 0 FAIL rules)
  • Tailored CIS profile at /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
  • Operator credentials file at /root/appwrite-credentials.txt (mode 0600) with the Console URL, the first-login instructions, and the internal MongoDB credentials

Quick Start

  1. Deploy VM from Azure Marketplace (Standard_D4s_v3 recommended)
  2. Open NSG: TCP 443 from your trusted sources, TCP 22 from your management IPs only
  3. SSH: ssh -i key.pem azureuser@<PUBLIC_IP>, then sudo cat /root/appwrite-credentials.txt for the Console URL and details
  4. Open https://<PUBLIC_IP>/console in your browser and accept the self-signed certificate warning
  5. Click Sign up and register with your real email - the first registered user becomes the root admin and further Console sign-ups close automatically

The multi-container stack takes a few minutes to initialise on first boot; a loading page is shown until it is ready. Restrict NSG port 443 to your own IP until you have registered, so no one else can claim the root admin. nginx is the TLS perimeter on port 443 fronting the internal Traefik router; replace the self-signed certificate with a CA-signed one for production (certbot is pre-installed), then point _APP_DOMAIN at your domain in /opt/appwrite/.env and restart.

العربية (ليبيا)
أيقونة إلغاء الاشتراك في اختيارات خصوصيتك خيارات خصوصيتك
خصوصية صحة المستهلك خريطة الموقع اتصل بنا الخصوصية وملفات تعريف الارتباط شروط الاستخدام العلامات التجارية حول إعلاناتنا إدارة ملفات تعريف الارتباط