Skip to main content
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/lynxroute.meilisearch-dad56ba7-f754-4c14-b98d-8cbf88be2f92/image3_Azureready.png

Meilisearch - Hardened Self-Hosted Search Engine

by Lynxroute

Meilisearch 1.54.3 - CIS Level 1 hardened search engine on Ubuntu 24.04 LTS, SBOM + CIS

What is Meilisearch

Meilisearch is a fast, typo-tolerant open-source search engine written in Rust and shipped as a single statically linked binary, purpose-built for the search-as-a-feature use case. It serves a developer-friendly REST API over indexed documents with sub-50ms query latency and supports prefix search, typo tolerance, faceting and filtering, sorting, geo search, synonyms, stop words, and semantic and hybrid search via vector embeddings. Documents and indexes are persisted to an embedded LMDB store on the local filesystem. Applications integrate through official client SDKs for JavaScript, Python, PHP, Ruby, Go, Rust, Java and .NET, authenticating with the master key or scoped API keys minted from it. This image runs the single-node Community Edition, which is fully MIT licensed - a self-hosted instant-search backend for any application, with no per-query fees and no vendor lock-in.

Why self-host Meilisearch

Self-hosting keeps your index, document content, and query traffic inside your own tenant - no per-query SaaS fees, no third-party access to what your users search for, no data leaving your region. Ideal for teams with data residency requirements (GDPR, ISO 27001), site and in-app search over confidential content, and product teams that need predictable latency and full control over ranking.

What this VM image adds

Security hardening:

  • Strong random master key generated per instance - 48-character key written at first boot, never the same on two deployments; production mode rejects unauthenticated calls. Stored in /root/meilisearch-credentials.txt readable only by root
  • Engine bound to 127.0.0.1 only - nginx terminates TLS on 443 and reverse-proxies to it; HTTP on 80 redirects to HTTPS
  • certbot and the nginx plugin pre-installed - enable a CA-signed Let's Encrypt certificate with one command
  • Anonymous analytics disabled - no telemetry leaves the VM
  • Meilisearch runs as non-root - dedicated meilisearch system user, UMask=0027, ProtectSystem=full, NoNewPrivileges
  • CVE scan - every image is scanned for vulnerabilities with Trivy before release
  • UFW firewall - only ports 443 and 80 open externally, SSH on 22
  • fail2ban - SSH brute-force protection
  • AppArmor - mandatory access control

OS hardening (CIS Level 1):

  • CIS Level 1 hardened - CIS Ubuntu 24.04 LTS Level 1 Benchmark via ansible-lockdown
  • auditd - system call auditing for critical paths
  • SSH hardening - PasswordAuthentication disabled, key-only access
  • Kernel hardening - SYN cookies, ASLR, rp_filter, TCP BBR
  • /tmp as tmpfs - nosuid, nodev, noexec
  • Azure IMDS endpoints - egress rules pre-configured (169.254.169.254, 168.63.129.16)

Compliance artifacts (inside the VM):

  • SBOM - CycloneDX 1.6 at /etc/lynxroute/sbom.json with the Meilisearch binary pinned by version, PURL, MIT license, supplier and SHA-256 hash
  • CIS Conformance Report - OpenSCAP HTML at /etc/lynxroute/cis-report.html (Azure tailoring profile, 0 FAIL rules)
  • Tailored CIS profile - /usr/share/doc/lynxroute/CIS_TAILORED_PROFILE.md
  • Server credentials file - /root/meilisearch-credentials.txt with the public URL, health URL and the per-instance master key

Quick Start

  1. Deploy VM from Azure Marketplace (Standard_D2s_v3 or larger recommended)
  2. Open NSG: TCP 443 from your client networks - SSH 22 from your management IPs only
  3. SSH: ssh -i key.pem <username>@<PUBLIC_IP> (default username: azureuser)
  4. Read the master key: sudo cat /root/meilisearch-credentials.txt
  5. Call the API over HTTPS with the master key as a Bearer token: curl -k -H "Authorization: Bearer <MASTER_KEY>" https://<PUBLIC_IP>/keys
  6. Create an index and search via the REST API or an official client SDK

Meilisearch runs API-first in production mode - there is no browser dashboard; manage it through the REST API. The site uses a self-signed certificate by default - for production, replace it with a CA-signed certificate: sudo certbot --nginx -d yourdomain.com

English (United States)
Your Privacy Choices Opt-Out Icon Your Privacy Choices
Consumer Health Privacy Sitemap Contact Us Privacy & Cookies Terms of Use About our ads Manage cookies