تخطي إلى المحتوى الرئيسي
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/lynxroute.joomla-fd2adb38-57f6-43a9-8918-1a38f75ca3ee/image3_Azureready.png

Joomla - Hardened Open-Source CMS

بواسطة Lynxroute

Joomla 5.4.9 - CIS Level 1 hardened open-source CMS on Ubuntu 24.04 LTS, SBOM + CIS

What is Joomla

Joomla is a mature open-source content management system (CMS) for building websites, blogs, corporate portals, and intranets. It is a PHP 8.3 web application served by Nginx with PHP-FPM and backed by a MariaDB database. The bundled feature set covers article and content management with categories and tags, a templating system for site themes, flexible menu management, multilingual sites, fine-grained user management and access control levels (ACL), a media manager, banners, contacts, and news feeds. A powerful extension system of components, modules, and plugins lets you add functionality, with thousands of free and commercial extensions and templates available from the Joomla Extensions Directory. This image ships the Joomla 5.x LTS line. GPL-2.0-or-later license, no per-seat fees, no vendor lock-in.

Why self-host Joomla

Running Joomla on a VM you control keeps every article, user account, and uploaded asset inside your own Azure subscription. Self-hosting suits organisations under GDPR or internal data-residency policies and multi-author teams that want a fully auditable CMS with no per-seat fees and no vendor lock-in.

What this VM image adds

Security hardening:

  • Super User and database credentials generated at first boot - a random admin password, database password, and table prefix are created per instance and written to /root/joomla-credentials.txt (mode 0600); never the same on two deployments
  • Web installer removed automatically - the headless installer runs non-interactively at first boot and the installation/ folder is deleted, so the setup wizard cannot be re-triggered
  • MariaDB listens on localhost only - no exposed database port; the joomla DB user is limited to localhost
  • PHP-FPM bound to loopback - a dedicated joomla pool on 127.0.0.1 behind the Nginx reverse proxy, with pm.max_children sized from instance RAM at first boot
  • Self-signed TLS at first boot - HTTPS on port 443 from launch; port 80 redirects to 443; replace with a CA-signed certificate via Certbot (pre-installed) for production
  • CVE scan - every image is scanned with Trivy before release
  • UFW firewall - only ports 22, 80, and 443 open
  • fail2ban - SSH brute-force protection
  • AppArmor - mandatory access control on system services

OS hardening (CIS Level 1):

  • CIS Ubuntu 24.04 LTS Level 1 Benchmark via ansible-lockdown
  • auditd - system call auditing for critical paths
  • SSH hardening - PasswordAuthentication disabled, key-only access, PermitRootLogin no, LoginGraceTime 60
  • Kernel hardening - SYN cookies, ASLR, rp_filter, IPv6 off
  • /tmp as tmpfs - nosuid, nodev, noexec
  • Azure IMDS endpoints - egress rules pre-configured (169.254.169.254, 168.63.129.16)

Compliance artifacts (inside the VM):

  • SBOM - CycloneDX 1.6 at /etc/lynxroute/sbom.json
  • CIS Conformance Report at /etc/lynxroute/cis-report.html (OpenSCAP, Azure tailoring profile, 0 FAIL rules)
  • Tailored CIS profile at /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
  • Operator credentials file at /root/joomla-credentials.txt (mode 0600) with the public IP, the site URL, and the per-instance Super User and database passwords

Quick Start

  1. Deploy VM from Azure Marketplace (Standard_D2s_v3 or larger recommended)
  2. Open NSG: TCP 443 from your client networks, SSH 22 from your management IPs only
  3. SSH: ssh -i key.pem azureuser@<PUBLIC_IP>, then sudo cat /root/joomla-credentials.txt for the Super User password
  4. Wait 30-90 seconds for first-boot setup; the page shows a "Starting up" splash during this window
  5. Open https://<PUBLIC_IP>/, accept the self-signed certificate warning, then log in to the admin panel at https://<PUBLIC_IP>/administrator/ as "admin" with the generated password
  6. Change the admin password and email after first login; issue a trusted certificate with sudo certbot --nginx -d your.domain.com

MariaDB and PHP-FPM are bound to loopback behind the Nginx TLS perimeter on 443 - do not expose them directly. Restrict NSG port 443 to your own IP until you have changed the admin password. "Joomla!" is a registered trademark of Open Source Matters, Inc. This is an independently hardened build of the GPL-2.0-or-later community edition, not affiliated with or endorsed by Open Source Matters, Inc.

العربية (ليبيا)
أيقونة إلغاء الاشتراك في اختيارات خصوصيتك خيارات خصوصيتك
خصوصية صحة المستهلك خريطة الموقع اتصل بنا الخصوصية وملفات تعريف الارتباط شروط الاستخدام حول إعلاناتنا إدارة ملفات تعريف الارتباط