Dynatrace Managed Q&A
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Looking to upgrade from Dynatrace Managed to SaaS? See how

Best Practices & Scripts for OS / CIS Hardening on Dynatrace Managed Clusters

PradeepGM
Newcomer

Hi Everyone,

We are working on bringing our infrastructure into strict alignment with industry security standards (such as CIS Benchmarks, NIST, and DISA STIG). Our core objective is to apply a robust security posture to the underlying Linux operating systems hosting our Dynatrace Managed clusters.

Since Dynatrace Managed deploys embedded components like Apache Cassandra, Elasticsearch, and its own NGINX gateway, aggressive out-of-the-box OS hardening can sometimes disrupt internal node communication or service permissions.

I would appreciate guidance or shared experiences from the community on the following:

1. Hardening Check Scripts/Commands: Do you utilize specific OpenSCAP profiles, Ansible playbooks, or custom bash scripts to audit and remediate the underlying OS without breaking Dynatrace cluster services?

2. Component-Specific Exceptions: Are there specific CIS rules we should avoid or modify? For example, how do you handle constraints around the unprivileged dynatrace user/group, database auditing, or internal firewall settings?

3. Official Guidelines: Is there an updated, official technical guide or a list of supported hardening metrics specific to Dynatrace Managed environments?

Any scripts, command snippets, or lessons learned from passing compliance audits with Dynatrace Managed would be incredibly helpful.

Thank you!


0 REPLIES 0

Featured Posts