تخطي إلى المحتوى الرئيسي
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/lynxroute.flowable-9aaa49b2-a239-4e80-8a4d-b73660d07539/image1_Azureready.png

Flowable - Hardened BPMN, CMMN and DMN Process Engine

بواسطة Lynxroute

Need custom pricing or terms? Request a private offer directly from the seller - tailored for your organization.

Flowable 8.0.0 - CIS Level 1 hardened BPMN process engine on Ubuntu 24.04 LTS, SBOM + CIS

What is Flowable

Flowable is an open-source process automation platform written in Java. It runs BPMN 2.0 process definitions, CMMN 1.1 cases, DMN 1.3 decision tables and an event registry from a single compact engine, and exposes all of them over a documented REST API. Applications deploy process definitions as standard BPMN XML, start instances, drive user tasks, evaluate decisions and query full audit history through that API. Maintained by Flowable AG under the Apache License 2.0, it is widely embedded in order management, onboarding, claims handling, approval routing and other long-running business workflows.

Why self-host Flowable

Business processes encode how an organisation operates, and their audit history often carries retention and regulatory obligations. Self-hosting keeps process definitions, task assignments and the full historical record inside your own subscription and region, which simplifies GDPR data-residency arguments. Cost is the VM you choose rather than per-user fees, and because the engine speaks standard BPMN, CMMN and DMN, process assets stay portable.

What this VM image adds

Security hardening:

  • No credentials in the image - the REST admin password and the database password are generated per instance at first boot; the upstream defaults never reach a running machine
  • Loopback-only engine - Flowable binds 127.0.0.1:8080; nginx terminates TLS on 443 and is the only public listener
  • Authentication on every route - the REST API requires a user holding the rest-api privilege; only the API explorer is anonymous
  • Actuator surface narrowed - management endpoints are limited to health and info, so configuration and heap-dump endpoints are not mounted
  • Java object deserialization disabled - serializable REST variables are turned off
  • Production database - PostgreSQL on localhost instead of the default file-backed H2 demo database
  • CVE scan - OS packages are scanned for vulnerabilities with Trivy before release
  • UFW firewall - only SSH 22 and HTTPS 443 accepted; the engine and database ports are unreachable off-box
  • fail2ban - SSH brute-force protection
  • AppArmor - mandatory access control

OS hardening (CIS Level 1):

  • CIS Level 1 hardened - CIS Ubuntu 24.04 LTS Level 1 Benchmark via ansible-lockdown
  • auditd - system call auditing for critical paths
  • SSH hardening - PasswordAuthentication disabled, key-only access
  • Kernel hardening - SYN cookies, ASLR, rp_filter
  • /tmp as tmpfs - nosuid, nodev, noexec
  • Azure IMDS endpoints - egress rules pre-configured (169.254.169.254, 168.63.129.16)

Compliance artifacts (inside the VM):

  • SBOM - CycloneDX 1.6 at /etc/lynxroute/sbom.json
  • CIS Conformance Report - OpenSCAP HTML at /etc/lynxroute/cis-report.html
  • Tailored CIS profile - /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
  • Checksum-verified engine - the Flowable WAR is installed from Maven Central and verified against its published SHA-256

Scope of the open-source distribution

Flowable 7.0 removed the UI applications from the open-source distribution. This image ships what upstream publishes today: the BPMN, CMMN, DMN, event registry and IDM engines, their REST APIs, and the built-in API explorer. It does not include a graphical process modeller. Author your diagrams in any BPMN 2.0 editor and deploy the XML through the REST API.

Quick Start

  1. Deploy the VM (Standard_D2s_v3 or larger recommended - the JVM and the bundled PostgreSQL want 8 GB)
  2. Allow TCP 443 from your address in the network security group
  3. SSH: ssh -i key.pem <username>@<PUBLIC_IP> (username set during VM creation, default: azureuser)
  4. Read the generated credentials: sudo cat /root/flowable-credentials.txt
  5. Open https://<PUBLIC_IP>/ and sign in to the API explorer; first boot takes 2-4 minutes while the engine creates its schema, and a progress page is shown until it is ready
  6. Deploy a process: POST /flowable-rest/service/repository/deployments, then start it with POST /flowable-rest/service/runtime/process-instances

The self-signed certificate should be replaced before production use - run sudo certbot --nginx -d yourdomain.com.

العربية (ليبيا)
أيقونة إلغاء الاشتراك في اختيارات خصوصيتك خيارات خصوصيتك
خصوصية صحة المستهلك خريطة الموقع اتصل بنا الخصوصية وملفات تعريف الارتباط شروط الاستخدام العلامات التجارية حول إعلاناتنا إدارة ملفات تعريف الارتباط