تخطي إلى المحتوى الرئيسي
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/lynxroute.drupal-dc688af1-b229-4566-bf88-d76287eefbac/image3_Azureready.png

Drupal - Hardened Self-Hosted CMS

بواسطة Lynxroute

Drupal 11.3.16 - CIS Level 1 hardened CMS on Ubuntu 24.04 LTS, SBOM + CIS Report

What is Drupal

Drupal is a leading open-source content management system (CMS) and web application framework used by governments, universities and enterprises worldwide. It is a PHP application backed by a MySQL/MariaDB or PostgreSQL database and served by nginx with PHP-FPM; this image installs it with Composer (the drupal/recommended-project layout). Drupal gives you structured content types and fields, taxonomy, the Views query builder, flexible URL aliases, a roles-and-permissions access model, revisions and workflows, multilingual content, a theming layer, a REST/JSON:API for headless and decoupled front-ends, and one of the largest module ecosystems of any CMS. This image ships Drupal 11.3.13 on PHP 8.3 with MariaDB. GPL-2.0-or-later license, no vendor lock-in.

Why self-host Drupal

Running Drupal on a VM you control keeps all content, accounts and visitor data inside your own tenant rather than a managed CMS service. Self-hosting suits teams under GDPR or data-residency rules, public-sector sites, and any workload where editorial content and personal data must stay within your own perimeter with no per-seat fees and no third-party access.

What this VM image adds

Security hardening:

  • Site pre-installed at first boot - a unique admin password is generated on first launch and stored in /root/drupal-credentials.txt (mode 0600); there is no install wizard to run and no shared default credential baked into the image
  • Unique MariaDB password - generated at first boot; the database and PHP-FPM are bound to 127.0.0.1 only and never exposed to the network
  • Update Status beacon disabled - the image does not phone home for version checks; you can re-enable it under Extend
  • settings.php locked down - the public files directory is isolated and trusted host patterns are tracked automatically
  • Self-signed TLS certificate generated at build and replaceable with your own CA-signed certificate (certbot is pre-installed)
  • UFW firewall - TCP 443 for the web UI and TCP 22 for SSH; all other inbound dropped
  • fail2ban - SSH brute-force protection
  • AppArmor - mandatory access control
  • CVE scan - every image is scanned with Trivy before release

OS hardening (CIS Level 1):

  • CIS Ubuntu 24.04 LTS Level 1 Benchmark via ansible-lockdown
  • auditd - system call auditing for critical paths
  • SSH hardening - PasswordAuthentication disabled, key-only access, PermitRootLogin no, LoginGraceTime 60
  • Kernel hardening - SYN cookies, ASLR, rp_filter, IPv6 off
  • /tmp as tmpfs - nosuid, nodev, noexec
  • Azure IMDS endpoints - egress rules pre-configured (169.254.169.254, 168.63.129.16)

Compliance artifacts (inside the VM):

  • SBOM - CycloneDX 1.6 at /etc/lynxroute/sbom.json
  • CIS Conformance Report at /etc/lynxroute/cis-report.html (OpenSCAP, Azure tailoring profile, 0 FAIL rules)
  • Tailored CIS profile at /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
  • Operator credentials file at /root/drupal-credentials.txt (mode 0600) with the admin password, the database password and the site HTTPS URL

Quick Start

  1. Deploy VM from Azure Marketplace (Standard_D2s_v3 or larger recommended)
  2. Open NSG: TCP 443 from your trusted sources, TCP 22 from your management IPs only
  3. SSH: ssh -i key.pem azureuser@<PUBLIC_IP>, then sudo cat /root/drupal-credentials.txt for the admin password
  4. Open https://<PUBLIC_IP>/, accept the self-signed certificate warning, and log in at /user/login as admin with that password
  5. The site is already installed - change the admin password and set a real admin email under People after first login

The database and PHP-FPM are bound to 127.0.0.1 behind the nginx TLS perimeter on 443 - do not expose them directly. Restrict NSG port 443 to your own IP until you have changed the admin password, since anyone who reaches the site first can use the shipped credentials. Replace the self-signed certificate with a CA-signed one for production: sudo certbot --nginx -d your.domain.com. Drupal is a registered trademark of Dries Buytaert; this is an independently hardened build, not affiliated with or endorsed by the Drupal Association.

العربية (ليبيا)
أيقونة إلغاء الاشتراك في اختيارات خصوصيتك خيارات خصوصيتك
خصوصية صحة المستهلك خريطة الموقع اتصل بنا الخصوصية وملفات تعريف الارتباط شروط الاستخدام العلامات التجارية حول إعلاناتنا إدارة ملفات تعريف الارتباط