Odoo - Hardened ERP and CRM Suite
بواسطة Lynxroute
Odoo 18.0 - CIS Level 1 hardened ERP and CRM business suite on Ubuntu 24.04 LTS, SBOM
What is Odoo
Odoo Community Edition is an open-source, all-in-one ERP and CRM business suite. It runs as a Python application backed by a PostgreSQL database, organised into integrated apps you install on demand: CRM, Sales, Invoicing, Inventory, Accounting, Project, Manufacturing, Website and more. They share one data model, so a lead can flow through to a quotation, a delivery and an invoice without re-keying. Reports render to PDF via wkhtmltopdf. This image ships Odoo 18.0 Community Edition from the official Odoo apt repository, with a dedicated local PostgreSQL 16 backing store and the file store persisting on the instance disk. LGPL-3.0 license, no vendor lock-in.
Why self-host Odoo
Running Odoo on a VM you control keeps every customer record, quotation, invoice and document inside your own Azure tenant rather than a managed SaaS. Self-hosting suits organisations under GDPR, SOC 2 or internal compliance, and teams moving off per-user subscription suites to a self-hosted equivalent with no per-seat fees. The Community Edition source is fully auditable.
What this VM image adds
Security hardening:
- Per-instance admin and master passwords - the Odoo admin password and the master (database-management) password are generated at first boot and stored in /root/odoo-credentials.txt (mode 0600)
- Initial database created at first boot - you log in and start working; no web installer is exposed to the internet
- Database manager disabled - list_db is off, so the database list and backup/restore screens are not reachable from the browser
- Loopback binding - Odoo listens on 127.0.0.1:8069 (web) and 127.0.0.1:8072 (websocket) only; PostgreSQL listens on 127.0.0.1 only; nginx terminates TLS on 443, so the app and database ports are never exposed
- Per-instance database password - the PostgreSQL role password is rotated at first boot, internal only
- Worker count auto-sized to the instance at first boot for correct PDF report rendering
- Self-signed TLS certificate on port 443 from launch; replaceable with your own CA-signed certificate (certbot pre-installed)
- UFW firewall - TCP 443 for the web UI, TCP 22 for SSH; all other inbound dropped
- fail2ban - SSH brute-force protection
- AppArmor - mandatory access control on system services
- CVE scan - every image is scanned with Trivy before release
OS hardening (CIS Level 1):
- CIS Ubuntu 24.04 LTS Level 1 Benchmark via ansible-lockdown
- auditd - system call auditing for critical paths
- SSH hardening - PasswordAuthentication disabled, key-only access, PermitRootLogin no, LoginGraceTime 60
- Kernel hardening - SYN cookies, ASLR, rp_filter, IPv6 off
- /tmp as tmpfs - nosuid, nodev, noexec
- Azure IMDS endpoints - egress rules pre-configured (169.254.169.254, 168.63.129.16)
Compliance artifacts (inside the VM):
- SBOM - CycloneDX 1.6 at /etc/lynxroute/sbom.json
- CIS Conformance Report at /etc/lynxroute/cis-report.html (OpenSCAP, Azure tailoring profile, 0 FAIL rules)
- Tailored CIS profile at /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
- Operator credentials file at /root/odoo-credentials.txt (mode 0600) with the Odoo HTTPS URL, the admin login, the master password and the PostgreSQL password
Quick Start
- Deploy VM from Azure Marketplace (Standard_D2s_v3 or larger recommended)
- Open NSG: TCP 443 from your client networks, TCP 22 from your management IPs only
- SSH: ssh -i key.pem azureuser@<PUBLIC_IP>, then sudo cat /root/odoo-credentials.txt for the admin and master passwords
- Open https://<PUBLIC_IP>/, accept the self-signed certificate warning; Odoo shows its login page and an initial database is already created
- Log in as admin with the generated password; keep the master password private
- Install apps from the Apps menu (for example CRM, Sales, Inventory, Accounting, Project); each activates in place, no restart needed
Odoo and PostgreSQL stay bound to loopback behind the nginx TLS perimeter on 443 - do not expose 8069 directly. Replace the self-signed certificate with a CA-signed one for production: sudo certbot --nginx -d your.domain.com. "Odoo" is a trademark of Odoo S.A.; this is an independently hardened build of the Community Edition, not affiliated with or endorsed by Odoo S.A.