Skip to content

doc: add note about CIS hardening with USG#1430

Open
elijahgreenstein wants to merge 2 commits into
canonical:mainfrom
elijahgreenstein:cis-hardening
Open

doc: add note about CIS hardening with USG#1430
elijahgreenstein wants to merge 2 commits into
canonical:mainfrom
elijahgreenstein:cis-hardening

Conversation

@elijahgreenstein

Copy link
Copy Markdown
Contributor

Checklist

Signed-off-by: Elijah Greenstein <elijah.greenstein@canonical.com>
@github-actions github-actions Bot added the Documentation Documentation needs updating label Jun 25, 2026

MicroCloud runs on Ubuntu and benefits from all [Ubuntu platform security measures](https://ubuntu.com/security), including kernel hardening, signed packages, and continuous security maintenance. For production environments, we recommend using a recent Ubuntu LTS release to ensure long-term support and predictable security updates.

Ubuntu LTS releases subscribed to Ubuntu Pro can use the [Ubuntu Security Guide (USG)](https://documentation.ubuntu.com/security/compliance/usg/) for CIS hardening. Refer to the LXD documentation on {ref}`lxd:howto-security-harden-cis` for related details about auditing LXD hosts with USG.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are there also some hardening guides in MicroCeph/MicroOVN we should link to?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There are links to the hardening guides for MicroCeph and MicroOVN (and again for LXD) farther down the page. The MicroCeph and MicroOVN docs don't seem to have content specific to USG, as far as I can tell, which is what I've linked to here for LXD>

Looking at the MicroCeph and MicroOVN docs, though, I saw there's another security-relevant MicroOVN link worth adding, so I've added it to the MicroOVN section of the page.

Signed-off-by: Elijah Greenstein <elijah.greenstein@canonical.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Documentation Documentation needs updating

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants