Approved access

This document is available to approved evaluators. Access is requested once per organisation and typically reviewed within one business day.

OS hardening profile

Describes the layered confinement shipped with the daemon — the hardened systemd sandbox, mandatory access control policies for both SELinux and AppArmor platforms, and syscall filtering — plus the Ansible role that deploys the full stack onto a STIG-baseline host. Written for system administrators and accreditation teams deploying Atlas in hardened environments; the public deployment guide covers installation, while this document covers why each layer is shaped the way it is and how to prove it on a live system.

What the full document covers:

  • The systemd sandbox directive by directive — including the deliberate exceptions and their rationale
  • SELinux policy module and AppArmor profile internals
  • Syscall-filter design and its planned tightening
  • Verification commands and expected results on a live host
  • STIG-baseline composition via the Ansible role

Request access to this document.

Tell us who you are and what you are integrating. Approval covers your whole evaluation — downloads, security documentation and field data are granted together.

Request access
Esc
↑ ↓ navigateEnter — openEsc — close