System Hardening
System Hardening reviews and applies host-level protections for kernel behavior, temporary filesystems, and out-of-memory handling, with separate visibility for current runtime state and persistent policy.
Where to find it: Sign in as root, open Server > Configuration, then choose System Hardening.
Available to: Root only.
What this page does
Use it to check whether the supported hardening controls are available, preview their current state, apply runtime or persistent changes, repair drift, and revert supported runtime changes when a new policy causes trouble.
Before you start
This page is root-only and affects the whole server. Capture the current state, confirm application compatibility, keep console or recovery access, and schedule a maintenance window before persistent changes. Hardening should reduce risk without turning the host into a very secure paperweight.
Hardening areas
| Area | What it controls | What to verify |
|---|---|---|
| Overview | Availability, current compliance, drift, and recommended actions. | The page can read the expected files and runtime values. |
| Kernel Security | Supported sysctl protections, including process-tracing restrictions such as ptrace policy. | SHM and customer processes still operate as intended. |
| Temporary Filesystems | Supported mount and permission hardening for temporary locations. | Applications that legitimately use temporary files can still create and execute only what policy allows. |
| OOM Protection | Out-of-memory preference for protected SHM and service processes. | The intended services receive the configured protection without hiding real memory pressure. |
| Runtime Actions | Recheck, runtime apply, persistent apply, repair, and supported runtime revert. | The action reaches a final state and a fresh check agrees. |
Runtime versus persistent
A runtime apply changes the active host state and is useful for controlled validation. A persistent apply also prepares the policy to survive reboot. Recheck reads state without changing it; Repair reconciles supported drift; Revert Runtime rolls back supported active changes but should not be treated as a substitute for a planned recovery procedure.
How to use it
- Open Overview and run Recheck.
- Read each mismatch and its expected compatibility impact.
- Apply runtime policy first when the page offers that safer validation path.
- Test SHM, websites, mail, databases, jobs, and required account applications.
- Apply persistent policy only after runtime validation, then recheck.
Result and next check
The current and persistent state should match the selected supported policy, with no unexplained drift. Verify again after reboot during the next planned maintenance window.
Theme color