تخطي إلى المحتوى الرئيسي
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/lynxroute.ghost-d6a65167-23f2-467f-a518-b106b1148ebc/image2_Azureready.png

Ghost - Hardened Self-Hosted Publishing Platform

بواسطة Lynxroute

Ghost 6.57.1 - CIS Level 1 hardened publishing platform on Ubuntu 24.04 LTS, SBOM + CIS

What is Ghost

Ghost is an open-source professional publishing platform built as a Node.js application. It pairs a clean, modern writing and editing experience with customizable themes and templating, native membership and subscription management, email newsletters, SEO controls, and a full Content API and Admin API plus webhooks for integrations. Content, settings, and members are persisted in a MySQL database; images and themes live on the local filesystem. Ghost is a self-hosted publishing and newsletter platform with no per-seat fees and no vendor lock-in. This image runs Ghost on Node.js 22 with a bundled MySQL 8.0 database. MIT license, fully auditable.

Why self-host Ghost

Running Ghost on a VM you control keeps your content, your member list, and your newsletter subscribers inside your own tenant rather than a managed publishing service. You avoid per-member and per-email premiums, retain full control over themes, integrations, and upgrade timing, and keep audience data inside your own perimeter. Ideal for publishers and teams with data residency requirements and organisations operating under regulated frameworks such as GDPR or ISO 27001. The MIT license is permissive and fully auditable.

What this VM image adds

Security hardening:

  • Unique database password at first boot - the bundled MySQL password is generated per instance at first boot, never a default or empty password
  • TLS terminated at Nginx on 443 - Ghost is bound to 127.0.0.1:2368 only and is never exposed directly; Nginx reverse-proxies to it
  • Bundled MySQL 8.0 bound to 127.0.0.1 - the database listens on loopback only and is governed by your network security group, never the public internet
  • You own the first account - the site Owner is created by you on the first visit to the admin panel; no pre-seeded administrator credential is shipped
  • Staff device verification disabled by default - the appliance ships without an outbound mail server, so emailed login codes would not deliver; re-enable it after configuring SMTP
  • Update-check telemetry disabled - no phone-home from the publishing platform
  • CVE scan - every image is scanned for vulnerabilities with Trivy before release
  • UFW firewall - SSH on 22, HTTP on 80 (redirect plus certificate validation), and HTTPS on 443 only
  • fail2ban - SSH brute-force protection
  • AppArmor - mandatory access control

OS hardening (CIS Level 1):

  • CIS Level 1 hardened - CIS Ubuntu 24.04 LTS Level 1 Benchmark via ansible-lockdown
  • auditd - system call auditing for critical paths
  • SSH hardening - PasswordAuthentication disabled, key-only access
  • Kernel hardening - SYN cookies, ASLR, rp_filter, TCP BBR
  • /tmp as tmpfs - nosuid, nodev, noexec
  • Azure IMDS endpoints - egress rules pre-configured (169.254.169.254, 168.63.129.16)

Compliance artifacts (inside the VM):

  • SBOM - CycloneDX 1.6 at /etc/lynxroute/sbom.json
  • CIS Conformance Report - OpenSCAP HTML at /etc/lynxroute/cis-report.html (Azure tailoring profile, 0 FAIL rules)
  • Tailored CIS profile - /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
  • Operator credentials file - /root/ghost-credentials.txt (mode 0600) with the bundled MySQL database credentials

Quick Start

  1. Deploy VM from Azure Marketplace (Standard_D2s_v3 or larger recommended)
  2. Open NSG: TCP 443 (and TCP 80 for certificate validation) from your trusted IPs, TCP 22 from your management IPs
  3. SSH: ssh -i key.pem azureuser@<PUBLIC_IP>; the MOTD shows the Ghost version and service state on login
  4. Open https://<PUBLIC_IP>/ghost/ and complete the one-time setup screen - the first account you create becomes the site Owner (you choose the email and password)
  5. Your public site is live at https://<PUBLIC_IP>/; operators can read the bundled database credentials with sudo cat /root/ghost-credentials.txt

For production, replace the self-signed certificate with a CA-signed one using the pre-installed certbot (sudo certbot --nginx), then point Ghost at your domain.

العربية (ليبيا)
أيقونة إلغاء الاشتراك في اختيارات خصوصيتك خيارات خصوصيتك
خصوصية صحة المستهلك خريطة الموقع اتصل بنا الخصوصية وملفات تعريف الارتباط شروط الاستخدام العلامات التجارية حول إعلاناتنا إدارة ملفات تعريف الارتباط