MariaDB Server - Hardened SQL Database
by Lynxroute
MariaDB 12.3.3 - CIS Level 1 hardened SQL database + phpMyAdmin on Ubuntu 24.04 LTS
What is MariaDB Community Server
MariaDB Community Server is a free, open-source relational database server, implemented in C/C++ as a multi-threaded daemon (mariadbd) and maintained by the MariaDB Foundation. It provides ACID transactions with the InnoDB storage engine, native JSON, window functions, common table expressions, full-text and spatial indexes, stored procedures, views, triggers, and replication. It speaks the MySQL wire protocol, so existing clients, drivers and tools connect unchanged. This image ships the 12.3 long-term-support line from the MariaDB Foundation apt repository and bundles mariadb-backup for hot, non-blocking physical backups. GPL-2.0 license, fully auditable, no vendor lock-in.
Why self-host MariaDB
Running MariaDB on a VM you control keeps your data inside your own Azure tenant rather than a managed service. Self-hosting suits teams with data residency requirements, organisations under GDPR or ISO 27001, and any architecture where the database must sit next to the workloads it serves. You administer it through the bundled phpMyAdmin web UI or any MySQL-protocol client.
What this VM image adds
Security hardening:
- A root password and a sample application database plus user are generated at first boot - never a default or empty password; written to /root/mariadb-credentials.txt
- Anonymous users and the test database are removed (secure-installation equivalent); root is restricted to localhost
- Native TLS enabled at first boot with a per-instance self-signed certificate - no shared private key is baked into the image; clients connect with --ssl
- Bound to the private interface and loopback only - port 3306 is governed by your Network Security Group
- certbot and the Nginx plugin pre-installed - one-command CA-signed HTTPS to replace the self-signed certificate
- UFW firewall - SSH on 22, plus 80 and 443 only; Azure IMDS and WireServer egress pre-configured
- fail2ban - SSH brute-force protection
- AppArmor - mandatory access control
- CVE scan - every image is scanned with Trivy before release
Web administration (phpMyAdmin):
- phpMyAdmin 5.2.3 web UI - browse tables, run SQL, import/export and manage users from your browser
- Served only over HTTPS behind an Nginx TLS proxy on 443 (per-instance self-signed certificate; swap in your own with certbot)
- Authenticates against MariaDB (cookie auth) - no separate account store; the setup script is removed and the cookie blowfish secret is generated per instance at first boot
- No new database port is opened - the UI is reached on 443, governed by your Network Security Group
OS hardening (CIS Level 1):
- CIS Ubuntu 24.04 LTS Level 1 Benchmark via ansible-lockdown
- auditd for system call auditing of critical paths
- SSH hardening - PasswordAuthentication disabled, key-only access, PermitRootLogin no, LoginGraceTime 60
- Kernel hardening - SYN cookies, ASLR, rp_filter, kexec disabled, IPv6 off
- /tmp as tmpfs with nosuid, nodev, noexec
Compliance artifacts (inside the VM):
- SBOM - CycloneDX 1.6 at /etc/lynxroute/sbom.json with MariaDB pinned by version, PURL, GPL-2.0 license and SHA-256 hash
- CIS Conformance Report at /etc/lynxroute/cis-report.html (OpenSCAP, Azure tailoring profile, 0 FAIL rules)
- Tailored CIS profile at /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
Quick Start
- Deploy VM from Azure Marketplace (Standard_D2s_v3 recommended)
- SSH: ssh -i key.pem azureuser@<PUBLIC_IP>, then sudo cat /root/mariadb-credentials.txt for the root password and sample database credentials
- Open NSG: TCP 443 and TCP 22 from your trusted management IPs only; open TCP 3306 only to trusted app-tier sources in the same VNet
- Open https://<PUBLIC_IP>/phpmyadmin/, accept the self-signed certificate warning, and log in with any MariaDB account (e.g. appuser)
- Connect an app from the same VNet with mariadb -h <PRIVATE_IP> -P 3306 -u appuser -p --ssl appdb
The database requires password authentication, native TLS is enabled, and root is restricted to localhost. Access to port 3306 is governed by your Network Security Group - never expose 3306 to the public internet. This image does not include MaxScale or any MariaDB Enterprise component.