Appliance Security & Hardening

This section covers security considerations for the HPE Morpheus Software appliance installation, including database encryption, key rotation, and hardening recommendations.

Compliance and Control Boundaries

This guidance is not a statement that the VME Manager or every HVM Host image is certified against a CIS Benchmark, DISA STIG, or another compliance framework. No benchmark name/version, assessment report, automated remediation profile, compliance dashboard, or centralized host-firewall policy is bundled as evidence for such a claim in this documentation.

The customer owns selection of the applicable control framework, operating-system baseline, network policy, identity controls, vulnerability management, evidence collection, and exception process. Validate controls against the exact Manager release, HVM OS release, cluster layout, and enabled integrations. Where a contract requires a certification or attestation, obtain the current artifact from HPE rather than treating these recommendations as an attestation.

The product exposes security-related capabilities, but capability is not certification:

  • Manager TLS, authentication, RBAC, encrypted credential storage, and audit/activity data can contribute to a customer control implementation.

  • HVM host firewall policy remains environment- and image-specific; see Preparing HVM Hosts and validate every required cluster communication before enforcement.

  • FIPS-related packages or modes must be evaluated for the exact release and cryptographic boundary. Enabling a FIPS mode does not by itself make the complete deployment compliant.

  • No shipped evidence in this guide establishes integrated Manager orchestration of host firewall rules, automated CIS/STIG scanning, compliance scoring, or automatic remediation.

Apply hardening first in a non-production environment. Record the previous configuration and maintain console access or another tested recovery path. If a control interrupts Manager, Agent quorum, Corosync, storage, migration, or workload networking, restore the approved configuration and investigate before continuing.

Database Encryption

HPE Morpheus Software automatically encrypts all sensitive data stored in the application database using AES-256-GCM encryption. This includes:

  • Cloud integration credentials (service passwords, API keys)

  • Compute server access passwords and console passwords

  • Integration and storage provider credentials

  • Container registry passwords

  • Security endpoint credentials

  • All credential store entries

Encryption is transparent — data is encrypted on write and decrypted on read at the application layer. The database itself only stores ciphertext.

Encryption Key Architecture

The encryption system uses a two-part key:

  • Base key — Built into the application

  • Key suffix — A customer-configurable value set in /etc/morpheus/morpheus.rb

When a key suffix is configured, it is appended to the base key before deriving the AES-256 encryption key. Each encrypted value also includes a unique random salt, ensuring that identical plaintext values produce different ciphertext.

Configuring the Encryption Key Suffix

To set or change the encryption key suffix:

  1. Edit /etc/morpheus/morpheus.rb

  2. Add or update the encryption key suffix setting:

    morpheus['encryptionKeySuffix'] = 'your-unique-secret-value'
    
  3. Run reconfigure to apply:

    sudo morpheus-ctl reconfigure
    
  4. Restart the application:

    sudo morpheus-ctl restart morpheus-ui
    

On the next application startup, HPE Morpheus Software automatically re-encrypts all sensitive database fields using the new key. This process runs once during bootstrap and covers all credential types across the system.

Important

Store the encryption key suffix securely. If this value is lost and the database needs to be restored to a new appliance, encrypted credentials cannot be recovered without the original key suffix.

Warning

In a high-availability (HA) deployment, all application nodes must have the same encryptionKeySuffix value in their morpheus.rb. Mismatched keys between nodes will cause decryption failures.

Rotating the Encryption Key

To rotate the encryption key:

  1. Choose a new key suffix value

  2. Update /etc/morpheus/morpheus.rb on all appliance nodes with the new value

  3. Restart the application on each node

The application will detect the key change and re-encrypt all sensitive fields with the new key on startup. No manual migration is required.

Note

Key rotation requires a brief application restart. During the re-encryption process (which runs at startup), the application is not serving requests. For large deployments with many stored credentials, this may take a few minutes.

Cypher Secrets Engine

In addition to database-level encryption, HPE Morpheus Software provides a dedicated secrets engine called Cypher (accessible at Tools > Cypher). Cypher provides:

  • Per-secret encryption with unique per-item keys

  • TTL-based lease management with automatic expiration

  • Mount-path-based access control

  • Integration with infrastructure credential management (see Device Credential Management)

Cypher secrets are encrypted independently from database field encryption and use their own key material.

Hardening Recommendations

Network Access

  • Restrict management access (ports 443, 80) to authorized networks only

  • Use a firewall or security group to limit access to the appliance

  • Place the appliance behind a load balancer with TLS termination for HA deployments

  • Restrict SSH access (port 22) to administrative users only

TLS Configuration

  • Replace the self-signed certificate with a valid CA-signed certificate

  • Configure TLS in /etc/morpheus/morpheus.rb:

    nginx['ssl_certificate'] = '/etc/morpheus/ssl/cert.pem'
    nginx['ssl_certificate_key'] = '/etc/morpheus/ssl/key.pem'
    
  • Run sudo morpheus-ctl reconfigure after certificate changes

Authentication

  • Integrate with an enterprise identity provider (Active Directory, LDAP, SAML, or OIDC) rather than relying solely on local accounts

  • Enforce MFA through your identity provider

  • Set strong password policies for any local accounts

  • Disable or lock unused default accounts

  • Use API tokens with appropriate expiration for service integrations

Role-Based Access

  • Apply the principle of least privilege — assign the minimum permissions required for each role

  • Use Tenant Roles to restrict Subtenant capabilities

  • Audit role assignments regularly

  • Set sensitive permissions (Admin: Appliance Settings, Admin: Backup Settings) to None or Read for non-administrator roles

Service Account Security

  • Always configure the encryptionKeySuffix in production deployments (do not rely on the default key alone)

  • Use Cypher or an external credential store for integration passwords rather than entering them inline

  • Rotate cloud integration credentials periodically

  • Audit integration credential access through the activity log

Appliance Updates

  • Keep the HPE Morpheus Software appliance on the latest supported release

  • Subscribe to security advisories for timely awareness of vulnerabilities

  • Test updates in a non-production environment before applying to production

Backup Security

  • Encrypt appliance backups at rest

  • Store backups in a separate location from the appliance

  • Protect backup storage with access controls — backups contain encrypted credentials that could be targeted

  • Test backup restoration periodically to verify encryption key availability