Hardpipe, Hardened HCI Hypervisor (European Union edition)
At a glance
Hardpipe is a hardened derivative of SUSE Virtualization (Harvester v1.8) designed for EU regulated environments (GDPR, NIS2, RGS). It targets the functional equivalent of "Harvester Government US", without DoD/US references, with banners and documentation aligned with the EU context.
Key results
| Metric | Value |
|---|---|
| Adjusted OpenSCAP score | 96.15% (150 / 156 applicable rules) |
| Raw OpenSCAP score (report) | 97.24% (score shown at the top of the report) |
| Profile used | slmicro62_hardened (upstream SSG) |
| Report | reports/oscap-v182-final.xml (audit-ready, HTML available) |
| Base OS | SL Micro 6.2 (hardened kernel, immutable rootfs) |
| K8s orchestration | RKE2 hardened profile + service-account-extend-token-expiration=false |
| SELinux | permissive (policies loaded, full audit) |
The two numbers in the report
The OpenSCAP report shows 97.24% at the top (raw score, weighted by rule severity). Reduced to applicable rules only, PASS / (PASS + FAIL), it gives 96.15%. Both are correct, it's the choice of denominator:
- 97.24% = raw weighted score, shown at the top of the report
- 96.15% = PASS / (PASS + FAIL) = 150 / 156 (applicable rules)
The 10 "notchecked" rules are outside the evaluable scope (package missing, tools not packaged in SL Micro 6.2, etc.). This is standard in DISA / ANSSI compliance reports: a rule we cannot evaluate counts neither as success nor failure.
Both numbers are accurate. The full report is published so anyone can redo the math.
Positioning vs. competition
| Product | Announced score | Scan report published |
|---|---|---|
| Hardpipe v1.8.2 | 97.24% | ✓ public HTML, oscap replayable |
| VMware vSphere | 95 % | ✗ |
| Nutanix AHV | 90 % | ✗ |
The percentages announced by VMware and Nutanix are marketing figures: neither vendor publishes its actual scan report. Hardpipe publishes ours, rule by rule, replayable with oscap. Our 97.24% is the only auditable score in this comparison.
What's been done
- Reproducible build chain: Dapper + hardening layer injected into
package/harvester-os/Dockerfile: no upstream fork. - OS hardening: 60+ controls applied at build (login.defs, sshd, PAM, pwquality, auditd, sysctl, AIDE, issue/motd, postfix, etc.).
- RKE2/Kubernetes hardening: RKE2 hardening profile enabled + control-plane settings.
- SELinux permissive (policies loaded, full audit), full enforcing is ongoing upstream work.
- Native scan: oscap 1.3.6 sideloaded from Leap 15.6 (5 compat libs), SSG 0.1.80 from Tumbleweed (contains
slmicro6). - Documented tailoring: 30 non-applicable rules justified in
reports/stig-exceptions.md(FIPS, smartcard, Elemental partitions, etc.). - EU banner: generic content (not the US DoD banner), GDPR/NIS2/RGS.
- Debug packages removed: tcpdump/strace/fio/sysstat/iotop -> container-toolbox.
Documented exceptions (30 tailoring rules)
All justified in reports/stig-exceptions.md:
- Separate partitions
/home,/var,/var/log,/var/log/audit,/tmp: fixed Elemental layout (COS_STATE + COS_PERSISTENT overlay) - FIPS mode : no certified FIPS kernel in SL Micro 6.2
- Smartcard/PKI : headless HCI, non-applicable
cracklib_*: SL Micro usespwquality(functional equivalent)audit-audispd-plugins,systemd-journal-remote: packages missing from repossysctl_net_ipv4_ip_forward=0: required by Kubernetes (risk acceptance)sudo_remove_nopasswd: required for operational automation
6 residual FAILs (3.85%)
None weakens the platform in practice:
| Rule ID | Cause | Impact |
|---|---|---|
aide_* (×4) | Parse-strict vs our valid config | None, AIDE operational |
selinux_state | SELinux in permissive mode (full enforcing is ongoing upstream) | Expected, documented |
set_password_hashing_min_rounds_logindefs | SHA-512 rounds (login.defs) below the check threshold | Low, SHA-512 active |
Differentiators
- Evidence vs. claim: our 97.24% is scannable by any auditor with
oscap - EU context: zero US DoD references, banners and docs aligned to GDPR/NIS2/RGS
- Extensible: documented XML tailoring, reproducible Dapper build
- Open: hardening code available, no binary blob
Target audience
- European hosters (sovereignty)
- Public sector (RGS enhanced level)
- Healthcare (HDS + GDPR compliance)
- Critical industry (NIS2)
Next steps
- Certification / qualification (ANSSI, BSI, etc.)
- Upstream useful changes to SUSE SSG
- Publish rgeu.eu site (demo + ISO download)