Apache Syncope on Ubuntu 24.04 by cloudimg
by cloudimg
Open source identity management and governance, preinstalled and secured by cloudimg.
Apache Syncope on Ubuntu 24.04 LTS
Apache Syncope is the open source identity management and identity governance platform maintained by the Apache Software Foundation. It manages the full lifecycle of users, groups and accounts across an organisation: creating and updating identities, provisioning and reconciling them against directories, databases and SaaS applications, running approval workflows for access requests, enforcing password and account policies, and keeping an auditable record of who has access to what. It fills the identity governance gap that single sign on products do not cover.
This image runs Apache Syncope 4.1.2, installed from the official Apache release and verified against its published SHA 512 checksum, on a hardened, fully patched Ubuntu 24.04 LTS base. All three web applications, the Core REST engine, the administrator console and the self service portal, run in a single Apache Tomcat 10.1 instance on OpenJDK 21, backed by a local PostgreSQL 16 database, with nginx serving them on port 80. The Flowable workflow engine is included for approval and user request workflows, and sixteen ConnId connector bundles ship ready to configure, covering LDAP, Active Directory, relational databases, CSV, SCIM, REST, SOAP, Azure, Okta, Google Apps and ServiceNow.
Secure by default
Apache Syncope publishes a well known default administrator account and a set of published signing and encryption keys. None of them survives into a running instance of this image. On the first boot of every VM, a one shot service generates a fresh administrator password, anonymous key, JWT signing key, AES encryption key and database password, and writes the administrator credential to a file only root can read.
Syncope is held back until that has happened. Its systemd unit will not start until first boot has written a bootstrap marker, so the platform can never come up on the upstream defaults even though the unit is enabled and survives a reboot. Two VMs launched from this image receive different secrets. Tomcat binds to the loopback interface only and is never exposed directly; all traffic arrives through nginx.
What you get
- Apache Syncope 4.1.2 Core, administrator console and self service portal on Apache Tomcat 10.1 and OpenJDK 21
- PostgreSQL 16 holding the identity store, tuned to run alongside the JVM with no swap on the operating system disk
- Sixteen ConnId provisioning connector bundles including LDAP, Active Directory, database, CSV, SCIM, REST and SOAP
- The Flowable workflow engine for approval and user request workflows
- Per instance administrator password and cryptographic keys generated on first boot, in a root only file
- nginx serving the console and portal on port 80, with Tomcat kept on loopback only
- A fully patched Ubuntu 24.04 LTS base with unattended security upgrades enabled
- A step by step deployment guide and 24/7 cloudimg support
Licensing
Apache Syncope is free and open source under the Apache License 2.0, with no per user, per identity or per connector fee. The cloudimg charge of 0.04 US dollars per vCPU hour covers packaging, security patching, image maintenance and 24/7 support. Put Syncope behind HTTPS, using Azure Application Gateway or a certificate on the bundled nginx, before exposing it to the internet.