Skip to content
@dev-sec

DevSec Hardening Framework

Security + DevOps: Automatic Server Hardening

DevSec Hardening Framework

banner

Challenge

Running secure infrastructure is a difficult task. Although server hardening is a well-known topic with many guides out in the wild, it is still very cumbersome to apply and verify secure configuration. If you manage many server, they need to be configured properly and maintained, which is difficult and time-consuming to get right. To answer these needs for security, compliance, and maintainability, we decided to launch this project as a common ground for requirements and their fulfillment.

Vision / Goal

Our goal is simple: Create a common layer for operating system and services hardening. Even if you aren’t knee-deep in configuration manuals for services or the latest security recommendations, you will be able to implement and use this framework with ease.

Pinned Loading

  1. ansible-collection-hardening ansible-collection-hardeningPublic

    This Ansible collection provides battle tested hardening for Linux, SSH, nginx, MySQL

    Jinja 4k 729

  2. chef-os-hardening chef-os-hardeningPublic

    This chef cookbook provides numerous security-related configurations, providing all-round base protection.

    Ruby 438 133

  3. puppet-os-hardening puppet-os-hardeningPublic

    This puppet module provides numerous security-related configurations, providing all-round base protection.

    Puppet 281 101

  4. linux-baseline linux-baselinePublic

    DevSec Linux Baseline - InSpec Profile

    Ruby 778 187

  5. cis-docker-benchmark cis-docker-benchmarkPublic

    CIS Docker Benchmark - InSpec Profile

    Ruby 488 114

  6. cis-kubernetes-benchmark cis-kubernetes-benchmarkPublic

    CIS Kubernetes Benchmark - InSpec Profile

    Ruby 294 78

Repositories

Showing 10 of 51 repositories