Mercator Cartography on Ubuntu 24.04 LTS by cloudimg
by cloudimg
Map your information systems, data flows, and risks for security and GDPR compliance.
Mercator is an open source application for mapping the cartography of an information system, following the guidance published by ANSSI (the French national cybersecurity agency). It gives security, risk and architecture teams a single place to describe what a system is made of and how the pieces relate: business processes and the applications that support them, application modules and services, logical and physical servers, databases, the information they hold, networks and network equipment, sites and buildings, and the security controls and risks attached to each. Those relationships are then rendered as cartography diagrams, so a complex estate becomes something a team can actually see, review and keep current. This image delivers the whole application assembled and hardened, so a working cartography instance is answering requests within minutes of launch instead of after an afternoon of manual installation.
A self managed deployment of this stack means installing and tuning a web server, a specific PHP version and a dozen extensions, a database engine and a graph rendering toolchain, then fetching the application, installing its dependencies, setting file ownership correctly, creating a database and a database user, running the migrations and seeders, and finally hardening every credential involved. This image completes all of that before first boot. Compared with a community image you also get 24/7 expert support from cloudimg covering configuration, directory integration, upgrades and performance.
Application stack: Mercator 2026.06.28 running on the Laravel framework, served by nginx and PHP 8.4 FPM, with MariaDB holding the cartography data and Graphviz rendering the diagrams. The document root is the Laravel public directory and nothing above it, so the application source, its dependencies and its environment file are not addressable by any URL. Only the framework front controller is allowed to execute PHP, so a file placed anywhere else in the web root is refused rather than run. The database listens on loopback only and is never exposed to the network.
Secure by default: no default, shared or blank credentials ship in the image. Mercator normally seeds a documented default administrator account, so the image is shipped with no application environment file, no application encryption key, and no database schema at all - which means that default account does not exist anywhere in the image. On the first boot of your instance a one shot service generates a unique application encryption key, a unique database password and a unique administrator password, creates the database schema, rotates the seeded administrator to your per instance password, and then proves the new credentials work by signing in through the real login form and confirming that the upstream default and other common passwords are rejected. The web server and PHP runtime are gated on a bootstrap marker that this service writes only after every credential is in place, so no service can ever serve an unprovisioned instance.
Key capabilities: an application and infrastructure inventory covering processes, applications, modules, services, logical and physical servers, databases, information, networks, VLANs, sites and buildings; relationship modelling between all of them; automatic cartography diagram generation; data protection and processing records; a security controls and maturity model with reports; a documents library; a REST API with configurable rate limiting; audit logging of changes; multi language support (English and French); local accounts with roles and fine grained permissions; and optional LDAP or Keycloak single sign on against your own directory.
Get started: read the per instance administrator password from the root only credentials file, browse to the instance address, sign in, change that password, then start describing your first application and the servers it runs on and generate your first cartography diagram. cloudimg engineers can help with domain and certificate setup, mail delivery, LDAP or SSO integration and upgrades after purchase.
Mercator is free software licensed under the GNU General Public License version 3. All product and company names are trademarks or registered trademarks of their respective holders. Use of them does not imply any affiliation with or endorsement by them.