تخطي إلى المحتوى الرئيسي
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/lynxroute.odoo-590835d7-db6f-45f0-8dd5-9034b74ca1e2/image2_Azureready.png

Odoo - Hardened ERP and CRM Suite

بواسطة Lynxroute

Odoo 18.0 - CIS Level 1 hardened ERP and CRM business suite on Ubuntu 24.04 LTS, SBOM

What is Odoo

Odoo Community Edition is an open-source, all-in-one ERP and CRM business suite. It runs as a Python application backed by a PostgreSQL database, organised into integrated apps you install on demand: CRM, Sales, Invoicing, Inventory, Accounting, Project, Manufacturing, Website and more. They share one data model, so a lead can flow through to a quotation, a delivery and an invoice without re-keying. Reports render to PDF via wkhtmltopdf. This image ships Odoo 18.0 Community Edition from the official Odoo apt repository, with a dedicated local PostgreSQL 16 backing store and the file store persisting on the instance disk. LGPL-3.0 license, no vendor lock-in.

Why self-host Odoo

Running Odoo on a VM you control keeps every customer record, quotation, invoice and document inside your own Azure tenant rather than a managed SaaS. Self-hosting suits organisations under GDPR, SOC 2 or internal compliance, and teams moving off per-user subscription suites to a self-hosted equivalent with no per-seat fees. The Community Edition source is fully auditable.

What this VM image adds

Security hardening:

  • Per-instance admin and master passwords - the Odoo admin password and the master (database-management) password are generated at first boot and stored in /root/odoo-credentials.txt (mode 0600)
  • Initial database created at first boot - you log in and start working; no web installer is exposed to the internet
  • Database manager disabled - list_db is off, so the database list and backup/restore screens are not reachable from the browser
  • Loopback binding - Odoo listens on 127.0.0.1:8069 (web) and 127.0.0.1:8072 (websocket) only; PostgreSQL listens on 127.0.0.1 only; nginx terminates TLS on 443, so the app and database ports are never exposed
  • Per-instance database password - the PostgreSQL role password is rotated at first boot, internal only
  • Worker count auto-sized to the instance at first boot for correct PDF report rendering
  • Self-signed TLS certificate on port 443 from launch; replaceable with your own CA-signed certificate (certbot pre-installed)
  • UFW firewall - TCP 443 for the web UI, TCP 22 for SSH; all other inbound dropped
  • fail2ban - SSH brute-force protection
  • AppArmor - mandatory access control on system services
  • CVE scan - every image is scanned with Trivy before release

OS hardening (CIS Level 1):

  • CIS Ubuntu 24.04 LTS Level 1 Benchmark via ansible-lockdown
  • auditd - system call auditing for critical paths
  • SSH hardening - PasswordAuthentication disabled, key-only access, PermitRootLogin no, LoginGraceTime 60
  • Kernel hardening - SYN cookies, ASLR, rp_filter, IPv6 off
  • /tmp as tmpfs - nosuid, nodev, noexec
  • Azure IMDS endpoints - egress rules pre-configured (169.254.169.254, 168.63.129.16)

Compliance artifacts (inside the VM):

  • SBOM - CycloneDX 1.6 at /etc/lynxroute/sbom.json
  • CIS Conformance Report at /etc/lynxroute/cis-report.html (OpenSCAP, Azure tailoring profile, 0 FAIL rules)
  • Tailored CIS profile at /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
  • Operator credentials file at /root/odoo-credentials.txt (mode 0600) with the Odoo HTTPS URL, the admin login, the master password and the PostgreSQL password

Quick Start

  1. Deploy VM from Azure Marketplace (Standard_D2s_v3 or larger recommended)
  2. Open NSG: TCP 443 from your client networks, TCP 22 from your management IPs only
  3. SSH: ssh -i key.pem azureuser@<PUBLIC_IP>, then sudo cat /root/odoo-credentials.txt for the admin and master passwords
  4. Open https://<PUBLIC_IP>/, accept the self-signed certificate warning; Odoo shows its login page and an initial database is already created
  5. Log in as admin with the generated password; keep the master password private
  6. Install apps from the Apps menu (for example CRM, Sales, Inventory, Accounting, Project); each activates in place, no restart needed

Odoo and PostgreSQL stay bound to loopback behind the nginx TLS perimeter on 443 - do not expose 8069 directly. Replace the self-signed certificate with a CA-signed one for production: sudo certbot --nginx -d your.domain.com. "Odoo" is a trademark of Odoo S.A.; this is an independently hardened build of the Community Edition, not affiliated with or endorsed by Odoo S.A.

العربية (ليبيا)
أيقونة إلغاء الاشتراك في اختيارات خصوصيتك خيارات خصوصيتك
خصوصية صحة المستهلك خريطة الموقع اتصل بنا الخصوصية وملفات تعريف الارتباط شروط الاستخدام حول إعلاناتنا إدارة ملفات تعريف الارتباط