Skip to main content
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/lynxroute.ferretdb-fd967f79-8c21-4b2e-8f8c-dbf395a3caea/image3_Azureready.png

FerretDB - Hardened MongoDB-Compatible Document Database

by Lynxroute

FerretDB 2.7.0 - CIS Level 1 hardened document database on Ubuntu 24.04 LTS, SBOM + CIS

What is FerretDB

FerretDB is an open-source document database that implements the MongoDB wire protocol, so standard MongoDB drivers, shells and application code connect to it without changes. Documents are stored in PostgreSQL through the open-source DocumentDB extension rather than in a storage engine of its own. You get document collections, secondary and compound indexes, TTL indexes, aggregation pipelines, geospatial operators and vector search, while the data itself sits in a database your team already knows how to back up, replicate and audit.

FerretDB is an independent open-source project licensed under Apache-2.0; the DocumentDB extension is licensed under MIT. Neither is affiliated with or endorsed by the owner of the MongoDB trademark, which is referenced here only to describe protocol and driver compatibility.

Why self-host FerretDB

Document workloads often hold the most sensitive records an organisation has. Self-hosting keeps them inside your own subscription and network boundary, so data-residency and GDPR questions stay answerable from your own records. The storage layer is plain PostgreSQL, so existing backup, monitoring and compliance tooling applies directly.

What this VM image adds

Security hardening:

  • TLS-only wire protocol - port 27017 accepts only TLS connections; a plaintext client is refused, so credentials never cross the network in the clear
  • Per-instance certificate - a unique self-signed certificate with your instance address in its SAN is generated on first boot; no private key is shared between deployments
  • Bundled database on loopback - PostgreSQL 17, the plaintext wire port and the diagnostics server all bind 127.0.0.1 only and are blocked in the firewall
  • No default credentials - the published image contains no working password at all; every credential is generated uniquely on first boot and written to a root-only file
  • SCRAM-SHA-256 authentication - no trust authentication anywhere; anonymous clients are refused
  • Telemetry disabled - the upstream usage beacon is switched off, verified in the running process state; nothing leaves the instance
  • Authenticated ops console - liveness, readiness and Prometheus metrics are exposed over HTTPS behind HTTP Basic Auth; profiling and debug archives are blocked at the perimeter
  • CVE scan - every image is scanned for vulnerabilities with Trivy before release
  • UFW firewall - 22, 80, 443 and 27017 open; 5432, 8088 and 27018 blocked externally
  • fail2ban - SSH brute-force protection
  • AppArmor - mandatory access control

OS hardening (CIS Level 1):

  • CIS Level 1 hardened - CIS Ubuntu 24.04 LTS Level 1 Benchmark via ansible-lockdown
  • auditd - system call auditing for critical paths
  • SSH hardening - PasswordAuthentication disabled, key-only access
  • Kernel hardening - SYN cookies, ASLR, rp_filter, TCP BBR
  • /tmp as tmpfs - nosuid, nodev, noexec
  • Azure IMDS endpoints - egress rules pre-configured (169.254.169.254, 168.63.129.16)

Compliance artifacts (inside the VM):

  • SBOM - CycloneDX 1.6 at /etc/lynxroute/sbom.json
  • CIS Conformance Report - OpenSCAP HTML at /etc/lynxroute/cis-report.html
  • Tailored CIS profile - /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
  • Certbot pre-installed - replace the self-signed console certificate with a trusted one in a single command

Quick Start

  1. Deploy the VM from Azure Marketplace (Standard_D2s_v3 or larger recommended)
  2. SSH: ssh -i key.pem <username>@<PUBLIC_IP> (username set during VM creation, default: azureuser)
  3. Check status: the login banner shows the FerretDB version, service state and connection string
  4. Read the generated credentials: sudo cat /root/ferretdb-credentials.txt
  5. Connect any MongoDB client to <PUBLIC_IP>:27017 with TLS enabled, using the username and password from that file
  6. Open https://<PUBLIC_IP>/ for the ops console (liveness, readiness, Prometheus metrics)
  7. Enable a trusted certificate on the console: sudo certbot --nginx -d yourdomain.com

Port 27017 is your database: restrict it in the Network Security Group to the addresses that actually need it before going to production.

English (United States)
Your Privacy Choices Opt-Out Icon Your Privacy Choices
Consumer Health Privacy Sitemap Contact Us Privacy & Cookies Terms of Use About our ads Manage cookies