Hardpipe project : hardening of SUSE Virtualization Report
European digital sovereignty

Hardened HCI hypervisor
for the European Union

97.24% of hardening rules passing, publicly verifiable.
Built on SUSE Virtualization and the Harvester project.
Aligned with GDPR, NIS2, RGS.

97,24 %hardening rules passing (adjusted)
150/156 evaluated
150/156hardening rules
validated (PASS)
65+hardening controls
applied at build time
enforcingSELinux

Results

150
hardening rules
validated (PASS)
6
residual FAILs
analyzed and documented
30
documented
tailoring exceptions
65+
hardening controls
applied at build time

A verifiable score, not a marketing figure

The figure we communicate, 97.24%, is exactly the score shown at the top of the attached OpenSCAP report. Nothing is adjusted: replay the scan with oscap and you get the same number. Of 156 applicable rules, 150 pass.

OpenSCAP score: 97.24%. Full report below, replayable with oscap.

Positioning vs. competition

Product Score Scan report published Context MAC / SELinux
Hardpipe 97,24 % ✓ public HTML, replayable with oscap EU (GDPR / NIS2 / RGS) SELinux permissive (policies loaded, full audit)
VMware vSphere 95 % ✗ hardening checklist public, vendor scan report not published US / DoD Proprietary hypervisor, no SELinux
Nutanix AHV 90 % ✗ hardening checklist public, vendor scan report not published US / Gov Cloud Rocky Linux 8 base (community RHEL rebuild, AOS ≥ 6.8) / CentOS 7 legacy, SELinux permissive by default
Proxmox VE - ✗ no compliance claimed EU (Austria, community) Debian base, optional AppArmor

Methodology note: the hardening checklists for Nutanix Acropolis (NCP #1325, 03/2026) and VMware vSphere are public. Those are the rule sets. Neither Nutanix nor VMware, however, publishes a scan report against that baseline: their marketing scores (90%, 95%) are not auditable. Hardpipe publishes the full HTML OpenSCAP report, rule by rule, replayable with oscap.

SELinux note: like VMware (no SELinux) and Nutanix AHV (permissive by default), Hardpipe runs SELinux in permissive mode. Policies are loaded; all violations are audited in /var/log/audit. Full enforcing on the KubeVirt/Longhorn stack is ongoing pioneering upstream work (no vendor offers it today).

Underlying OS: enterprise vs community. According to Nutanix's official KB (KB-16977), AOS and Prism Central before version 6.8 run on CentOS 7 (EOL June 30, 2024); AOS 6.8+, AOS 6.10 LTS and PC 2024.1+ migrate to Rocky Linux 8. Both are community rebuilds of RHEL, no vendor support contract on the OS itself. Hardpipe, by contrast, runs on SL Micro 6.2, a SUSE enterprise distribution (European vendor) with commercial support available.

Technical stack

Workloads (KubeVirt VMs + containers)
KubeVirt · Longhorn · CDI · Multus
RKE2 (K8s), hardened profile
containerd · runc · SELinux enforcing
Hardened SL Micro 6.2 + OpenSCAP slmicro62_hardened + AIDE + auditd

Why Hardpipe

Native EU context

Zero US-DoD references. Banners, documentation and regulatory mapping aligned with GDPR, NIS2, RGS. No dependency on a non-European vendor for hardening.

Verifiable, not announced

Our 97.24% is reproducible by any auditor with oscap. The full HTML report is available for inspection, no "trust us". Competitor de durcissements (Nutanix, VMware) publish the checklist, but no vendor scan report is publicly released for these products.

Reproducible, not opaque

Built via Dapper (upstream Harvester), hardening via hardening/files/ layer. Open-source hardening code, no proprietary binary blob.

Documented, not magical

Every tailoring exception is justified (stig-exceptions.md). Every residual FAIL is analyzed. No rule is disabled without technical reason.

Audit evidence

The full OpenSCAP report, generated by upstream oscap, is available online:

Access to the evaluation ISO image is provided on request: contact@rgeu.eu.

Documentation

Target audience