SecureBaseline Cloud

Updated April 10, 2026

SecureBaseline Cloud is an automated hardening platform for Linux servers based on CIS Benchmarks. The solution identifies and remediates OS configuration vulnerabilities, ensuring compliance with information security requirements.

What’s New

Problems It Solves

  • Manual security configuration — automates routine operations for configuring hundreds of OS security parameters
  • Lack of a unified standard — applies recognized CIS Benchmarks across all servers in the infrastructure
  • Audit complexity — automatic generation of compliance reports with per-rule detail
  • Risk of human error — uses proven roles instead of manual changes
  • Lack of visibility — centralized dashboard with compliance metrics across the entire infrastructure

Key Capabilities

Compliance Scanning

  • Server scanning for CIS Benchmark compliance
  • Support for virtually all popular Linux distributions
  • Detailed reports
  • Compliance score trend tracking

Automated Hardening

  • Automatic application of CIS recommendations
  • Granular control: enable/disable individual rules
  • CIS Level 1 and Level 2 profiles and many others
  • Safe preview mode before applying changes

Centralized Management

  • Web interface for managing hosts and tasks
  • Scheduler for regular scanning (cron)
Deployment instructions
  • Create a Yandex Virtual Private Cloud network and two subnets in the ru-central1-a and ru-central1-b availability zones. You may also use existing ones if desired. All subnets must belong to the same VPC network.

  • Create a Yandex Lockbox secret with the database password:

DB_PASSWORD=$(openssl rand -base64 32 | tr -d '\n')
yc lockbox secret create \
  --name haas-db-password \
  --payload "[{\"key\": \"password\", \"text_value\": \"$DB_PASSWORD\"}]"
  • Create a Yandex Lockbox secret with the administrator password:
yc lockbox secret create \
  --name haas-admin-password \
  --payload "[{\"key\": \"password\", \"text_value\": \"YOUR_ADMIN_PASSWORD\"}]"

Warning

Warning: use strong passwords. The minimum length is 9 characters.

  • In the management console, select the folder where you want to deploy the application.

  • Navigate to the Cloud Apps service.

  • In the left panel, select Marketplace.

  • Select SecureBaseline Cloud and click Use.

  • Specify:

    • Prefix for resource naming
    • Subnet in the ru-central1-a zone
    • Subnet in the ru-central1-b zone
    • Select the Yandex Lockbox secret with the PostgreSQL password
    • Public SSH key
    • Maximum number of agents
    • Administrator email
    • Select the Yandex Lockbox secret with the administrator password
    • Select the Environment type
  • Click Install and wait for the installation to complete. The process takes approximately 10–15 minutes.

  • Go to the console, open the Virtual Machines section, and select the virtual machine whose name starts with control-plane. Open its public IP address in a browser and log in using the credentials specified earlier.

from $276.68 / per month

The usage cost for the product and the minimum required resource configuration
Starting May 1, 2026, new prices will apply to certain Yandex Cloud services.Learn more in the blog
Create an application
Сost details
Product$229.00 / per month
Managed Service for PostgreSQL. Host computing resources, Intel Broadwell, 100% vCPU
$55.48
Public IP address (dynamic or static)
$1.56
Managed Service for PostgreSQL. Storage on network HDD disks
$3.07
Managed Service for PostgreSQL. Host computing resources, Intel Broadwell, RAM
$50.87
SecureBaseline Cloud
$118.03
Required resources$47.69 / per month
Regular VM computing resources, Intel Ice Lake, 100% vCPU
$29.27
Regular VM computing resources, Intel Ice Lake, RAM
$15.58
Standard disk drive (HDD)
$2.83
Billing type
Hourly (Pay as you go)
Type
Cloud Apps
Category
Security
Admin tools and DevOps
ML & AI
Publisher
OpenNix Cloud security
Use cases
  1. Security Audit Preparation

    • Full infrastructure scanning
    • Compliance report generation
    • Remediation of identified non-conformities
  2. Regular Monitoring

    • Weekly scheduled scanning
    • Compliance trend tracking
    • Alerting on metric degradation
  3. Mass Hardening

    • Centralized policy application
    • Phased implementation (Level 1 to Level 2)
    • Rollback capability when needed
Technical support

OpenNix provides technical support to users in Yandex Cloud. You can contact their technical support by email at support@opennix.ru. Support engineers are available on business days from 9 am to 6 pm GMT+3.

Application resources
Resource typeQuantity
Access rights for folder9
Virtual machine1
Instance group1
PostgreSQL database1
PostgreSQL user1
PostgreSQL cluster1
Lockbox secret version1
Lockbox secrets2
Object Storage bucket1
Message queues2
Service account1
Service account static access key1
Terms
By using this product you agree to the Yandex Cloud Marketplace Terms of Service and the terms and conditions of the following software: End user license agreement

from $276.68 / per month

The usage cost for the product and the minimum required resource configuration
Starting May 1, 2026, new prices will apply to certain Yandex Cloud services.Learn more in the blog
Create an application
Сost details
Product$229.00 / per month
Managed Service for PostgreSQL. Host computing resources, Intel Broadwell, 100% vCPU
$55.48
Public IP address (dynamic or static)
$1.56
Managed Service for PostgreSQL. Storage on network HDD disks
$3.07
Managed Service for PostgreSQL. Host computing resources, Intel Broadwell, RAM
$50.87
SecureBaseline Cloud
$118.03
Required resources$47.69 / per month
Regular VM computing resources, Intel Ice Lake, 100% vCPU
$29.27
Regular VM computing resources, Intel Ice Lake, RAM
$15.58
Standard disk drive (HDD)
$2.83
Billing type
Hourly (Pay as you go)
Type
Cloud Apps
Category
Security
Admin tools and DevOps
ML & AI
Publisher
OpenNix Cloud security