Appliance Security & Hardening¶
This section covers security considerations for the HPE Morpheus Software appliance installation, including database encryption, key rotation, and hardening recommendations.
Compliance and Control Boundaries¶
This guidance is not a statement that the VME Manager or every HVM Host image is certified against a CIS Benchmark, DISA STIG, or another compliance framework. No benchmark name/version, assessment report, automated remediation profile, compliance dashboard, or centralized host-firewall policy is bundled as evidence for such a claim in this documentation.
The customer owns selection of the applicable control framework, operating-system baseline, network policy, identity controls, vulnerability management, evidence collection, and exception process. Validate controls against the exact Manager release, HVM OS release, cluster layout, and enabled integrations. Where a contract requires a certification or attestation, obtain the current artifact from HPE rather than treating these recommendations as an attestation.
The product exposes security-related capabilities, but capability is not certification:
Manager TLS, authentication, RBAC, encrypted credential storage, and audit/activity data can contribute to a customer control implementation.
HVM host firewall policy remains environment- and image-specific; see Preparing HVM Hosts and validate every required cluster communication before enforcement.
FIPS-related packages or modes must be evaluated for the exact release and cryptographic boundary. Enabling a FIPS mode does not by itself make the complete deployment compliant.
No shipped evidence in this guide establishes integrated Manager orchestration of host firewall rules, automated CIS/STIG scanning, compliance scoring, or automatic remediation.
Apply hardening first in a non-production environment. Record the previous configuration and maintain console access or another tested recovery path. If a control interrupts Manager, Agent quorum, Corosync, storage, migration, or workload networking, restore the approved configuration and investigate before continuing.
Database Encryption¶
HPE Morpheus Software automatically encrypts all sensitive data stored in the application database using AES-256-GCM encryption. This includes:
Cloud integration credentials (service passwords, API keys)
Compute server access passwords and console passwords
Integration and storage provider credentials
Container registry passwords
Security endpoint credentials
All credential store entries
Encryption is transparent — data is encrypted on write and decrypted on read at the application layer. The database itself only stores ciphertext.
Encryption Key Architecture¶
The encryption system uses a two-part key:
Base key — Built into the application
Key suffix — A customer-configurable value set in
/etc/morpheus/morpheus.rb
When a key suffix is configured, it is appended to the base key before deriving the AES-256 encryption key. Each encrypted value also includes a unique random salt, ensuring that identical plaintext values produce different ciphertext.
Configuring the Encryption Key Suffix¶
To set or change the encryption key suffix:
Edit
/etc/morpheus/morpheus.rbAdd or update the encryption key suffix setting:
morpheus['encryptionKeySuffix'] = 'your-unique-secret-value'Run reconfigure to apply:
sudo morpheus-ctl reconfigureRestart the application:
sudo morpheus-ctl restart morpheus-ui
On the next application startup, HPE Morpheus Software automatically re-encrypts all sensitive database fields using the new key. This process runs once during bootstrap and covers all credential types across the system.
Important
Store the encryption key suffix securely. If this value is lost and the database needs to be restored to a new appliance, encrypted credentials cannot be recovered without the original key suffix.
Warning
In a high-availability (HA) deployment, all application nodes must have the same encryptionKeySuffix value in their morpheus.rb. Mismatched keys between nodes will cause decryption failures.
Rotating the Encryption Key¶
To rotate the encryption key:
Choose a new key suffix value
Update
/etc/morpheus/morpheus.rbon all appliance nodes with the new valueRestart the application on each node
The application will detect the key change and re-encrypt all sensitive fields with the new key on startup. No manual migration is required.
Note
Key rotation requires a brief application restart. During the re-encryption process (which runs at startup), the application is not serving requests. For large deployments with many stored credentials, this may take a few minutes.
Cypher Secrets Engine¶
In addition to database-level encryption, HPE Morpheus Software provides a dedicated secrets engine called Cypher (accessible at Tools > Cypher). Cypher provides:
Per-secret encryption with unique per-item keys
TTL-based lease management with automatic expiration
Mount-path-based access control
Integration with infrastructure credential management (see Device Credential Management)
Cypher secrets are encrypted independently from database field encryption and use their own key material.
Hardening Recommendations¶
Network Access¶
Restrict management access (ports 443, 80) to authorized networks only
Use a firewall or security group to limit access to the appliance
Place the appliance behind a load balancer with TLS termination for HA deployments
Restrict SSH access (port 22) to administrative users only
TLS Configuration¶
Replace the self-signed certificate with a valid CA-signed certificate
Configure TLS in
/etc/morpheus/morpheus.rb:nginx['ssl_certificate'] = '/etc/morpheus/ssl/cert.pem' nginx['ssl_certificate_key'] = '/etc/morpheus/ssl/key.pem'Run
sudo morpheus-ctl reconfigureafter certificate changes
Authentication¶
Integrate with an enterprise identity provider (Active Directory, LDAP, SAML, or OIDC) rather than relying solely on local accounts
Enforce MFA through your identity provider
Set strong password policies for any local accounts
Disable or lock unused default accounts
Use API tokens with appropriate expiration for service integrations
Role-Based Access¶
Apply the principle of least privilege — assign the minimum permissions required for each role
Use Tenant Roles to restrict Subtenant capabilities
Audit role assignments regularly
Set sensitive permissions (Admin: Appliance Settings, Admin: Backup Settings) to None or Read for non-administrator roles
Service Account Security¶
Always configure the
encryptionKeySuffixin production deployments (do not rely on the default key alone)Use Cypher or an external credential store for integration passwords rather than entering them inline
Rotate cloud integration credentials periodically
Audit integration credential access through the activity log
Appliance Updates¶
Keep the HPE Morpheus Software appliance on the latest supported release
Subscribe to security advisories for timely awareness of vulnerabilities
Test updates in a non-production environment before applying to production
Backup Security¶
Encrypt appliance backups at rest
Store backups in a separate location from the appliance
Protect backup storage with access controls — backups contain encrypted credentials that could be targeted
Test backup restoration periodically to verify encryption key availability