تخطي إلى المحتوى الرئيسي
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/lynxroute.tomcat-36c0cb3f-748d-4556-8c3b-e56f6096ac77/image1_Azureready.png

Apache Tomcat - Hardened Jakarta EE Java Application Server

بواسطة Lynxroute

Apache Tomcat 11.0.26 - CIS Level 1 hardened Java application server on Ubuntu 24.04 LTS

What is Apache Tomcat

Apache Tomcat is the world's most widely deployed Java application server and the reference implementation of the Jakarta EE Servlet, JSP, Expression Language, WebSocket and Authentication specifications, maintained by the Apache Software Foundation. Tomcat 11 targets Jakarta EE 11 (the jakarta.* namespace, not the legacy javax.*) and requires Java 17 or newer. It runs servlet/JSP web applications and WAR files with a small footprint, fast startup and a mature, battle-tested codebase. This image ships the official Apache binary distribution (verified against the upstream SHA-512 checksum) on OpenJDK 17, running as a non-root service. Apache-2.0 license, no vendor lock-in.

Why self-host Apache Tomcat

Running Tomcat on a VM you control keeps your application code, session data and configuration inside your own tenant rather than a managed application-hosting service. Self-hosting suits teams with data residency requirements, organisations operating under GDPR, HIPAA or ISO 27001, and any workload where the runtime and its deployed WARs must stay within your own perimeter with no per-request fees. Tomcat is Apache-2.0, fully auditable, with no vendor lock-in.

What this VM image adds

Security hardening:

  • Manager admin password generated uniquely per instance at first launch - no default credential - written to /root/tomcat-credentials.txt (mode 0600)
  • HTTP connector bound to 127.0.0.1:8080 (loopback only) - the connector is never exposed directly; nginx terminates TLS on port 443 and reverse-proxies to it
  • Manager and Host-Manager locked down - nginx returns 403 for them at the perimeter, and Tomcat additionally restricts both apps to localhost connections; reach them only over an SSH tunnel
  • Insecure examples webapp removed - the bundled sample servlets with known demo vulnerabilities are deleted
  • Self-signed TLS certificate generated at first launch and replaceable with your own CA-signed certificate (certbot is pre-installed)
  • JVM heap (-Xms/-Xmx) auto-sized to the instance RAM at first boot
  • Runs as a non-root tomcat system user with UMask 0027
  • UFW firewall - TCP 443 open externally for buyer use, TCP 22 for SSH; all other inbound dropped; Azure IMDS and WireServer egress pre-configured
  • fail2ban - SSH brute-force protection
  • AppArmor - mandatory access control
  • CVE scan - every image is scanned with Trivy before release

OS hardening (CIS Level 1):

  • CIS Ubuntu 24.04 LTS Level 1 Benchmark via ansible-lockdown
  • auditd for system call auditing of critical paths
  • SSH hardening - PasswordAuthentication disabled, key-only access, PermitRootLogin no, LoginGraceTime 60
  • Kernel hardening - SYN cookies, ASLR, rp_filter, kexec disabled, IPv6 off
  • /tmp as tmpfs with nosuid, nodev, noexec

Compliance artifacts (inside the VM):

  • SBOM - CycloneDX 1.6 at /etc/lynxroute/sbom.json with Tomcat pinned by version, PURL, Apache-2.0 license, supplier, and hash
  • CIS Conformance Report at /etc/lynxroute/cis-report.html (OpenSCAP, Azure tailoring profile, 0 FAIL rules)
  • Tailored CIS profile at /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
  • Operator credentials file at /root/tomcat-credentials.txt (mode 0600) with the Manager admin username and password and the HTTPS Web UI URL

Quick Start

  1. Deploy VM from Azure Marketplace (Standard_D2s_v3 recommended)
  2. Open NSG: TCP 443 from your trusted sources, TCP 22 from your management IPs only
  3. SSH: ssh -i key.pem azureuser@<PUBLIC_IP>, then sudo cat /root/tomcat-credentials.txt for the Manager admin password
  4. Open https://<PUBLIC_IP>/ in your browser and accept the self-signed certificate warning - the default Tomcat landing page (ROOT app) is served over TLS
  5. Deploy your own application: copy a .war into /opt/tomcat/webapps/ (auto-deploys), then browse https://<PUBLIC_IP>/<app-name>/

Tomcat's HTTP connector listens on 127.0.0.1:8080 only; nginx is the TLS perimeter on port 443 - do not expose 8080 directly. The Manager and Host-Manager apps are localhost-only: reach them over an SSH tunnel (ssh -i key.pem -L 8080:127.0.0.1:8080 azureuser@<PUBLIC_IP>, then open http://127.0.0.1:8080/manager/html). Replace the self-signed certificate with a CA-signed one for production, then run sudo systemctl reload nginx.

العربية (ليبيا)
أيقونة إلغاء الاشتراك في اختيارات خصوصيتك خيارات خصوصيتك
خصوصية صحة المستهلك خريطة الموقع اتصل بنا الخصوصية وملفات تعريف الارتباط شروط الاستخدام حول إعلاناتنا إدارة ملفات تعريف الارتباط