تخطي إلى المحتوى الرئيسي
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/lynxroute.matomo-2f9521d1-99d4-4792-82b7-38c436df2ee7/image0_Azureready.png

Matomo - Hardened Privacy-Friendly Web Analytics

بواسطة Lynxroute

Matomo 5.14.0 - CIS Level 1 hardened self-hosted web analytics on Ubuntu 24.04, SBOM + CIS

What is Matomo

Matomo is the leading open-source, privacy-friendly web analytics platform, used on over one million websites. It is a PHP application served by Nginx with PHP-FPM and backed by MariaDB. The bundled feature set covers visits and pageview reporting, real-time analytics, visitor logs and profiles, acquisition and campaign tracking, goals and e-commerce conversion, custom segments and dimensions, a JavaScript tracker (matomo.js) and a server-side tracking API (matomo.php), an HTTP Reporting API, and a built-in Tag Manager.

Why self-host Matomo

Self-hosting keeps all visitor data inside your own subscription - no data sharing with third parties, no sampling, and 100% data ownership. That makes GDPR, CCPA, and data-residency compliance straightforward for organisations that cannot send analytics data to external processors. GPL-3.0 license with no vendor lock-in; premium features are optional separate plugins and are not required to run Matomo.

What this VM image adds

Security hardening:

  • Per-instance MariaDB password rotated at first boot - never the same on two deployments, stored in /root/matomo-credentials.txt
  • Your own super user via the upstream Matomo install wizard - no analytics admin baked into the image, you create the first user during the wizard
  • MariaDB bound to 127.0.0.1 only - no exposed database port, Matomo database user limited to localhost
  • PHP-FPM auto-tuned at first boot - workers and OPcache memory sized from instance RAM
  • Hourly report archiving as a scheduled task - browser-triggered archiving disabled for predictable performance, gated until the install wizard has completed
  • Trivy CVE scan - every image is scanned for vulnerabilities before release
  • UFW firewall - only ports 80, 443, and 22 open
  • fail2ban - SSH brute-force protection
  • AppArmor - mandatory access control on system services

OS hardening (CIS Level 1):

  • CIS Level 1 hardened - CIS Ubuntu 24.04 LTS Level 1 Benchmark applied via ansible-lockdown
  • auditd - system call auditing for critical paths
  • SSH hardening - PasswordAuthentication disabled, key-only access, MaxAuthTries 4
  • Kernel hardening - SYN cookies, ASLR, rp_filter, TCP BBR
  • /tmp as tmpfs - nosuid, nodev, noexec
  • Azure IMDS endpoints - egress rules pre-configured (169.254.169.254, 168.63.129.16)

Compliance artifacts (inside the VM):

  • SBOM - CycloneDX 1.6 at /etc/lynxroute/sbom.json with SHA-256 hashes
  • CIS Conformance Report - OpenSCAP HTML at /etc/lynxroute/cis-report.html, 0 FAIL rules on the tailored profile
  • Tailored CIS profile - /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md with documented exceptions
  • Credentials file - /root/matomo-credentials.txt with the public IP, the web UI URL, and the per-instance MariaDB password (the super user is created by you in the install wizard, never written to disk by us)

Quick Start

  1. Deploy VM from Azure Marketplace (Standard_D2s_v3 or larger recommended)
  2. Open NSG: TCP 443 (and 80 for the HTTP-to-HTTPS redirect) from your IP only until the install wizard is complete, then widen to your audience - SSH 22 from your management IPs
  3. SSH: ssh -i key.pem <username>@<PUBLIC_IP> (username set during VM creation, default: azureuser)
  4. Read credentials: sudo cat /root/matomo-credentials.txt - contains the MariaDB password to paste into the wizard
  5. Open https://<PUBLIC_IP>/ - accept the self-signed certificate; the Matomo install wizard starts automatically
  6. Database step: copy the MariaDB credentials from the credentials file. Super User step: enter YOUR real email and a strong password - the first super user you create owns this Matomo
  7. Issue an HTTPS certificate for production: sudo apt install certbot python3-certbot-nginx && sudo certbot --nginx -d your.domain.com

No analytics admin exists until you create one in the wizard. Restrict NSG access to ports 443 and 80 to your own IP until the wizard is complete to prevent strangers from claiming the super user.

العربية (ليبيا)
أيقونة إلغاء الاشتراك في اختيارات خصوصيتك خيارات خصوصيتك
خصوصية صحة المستهلك خريطة الموقع اتصل بنا الخصوصية وملفات تعريف الارتباط شروط الاستخدام حول إعلاناتنا إدارة ملفات تعريف الارتباط