Vault - sysctl.conf (kernel parameters)
Vault Solution · Config document · referenced from Linux hardening
The kernel parameter file of the Vault nodes as built in 2023, hardening and network tuning in one file. It is kept as the record of what ran. For a new build start from the two maintained profiles instead: Linux kernel hardening with sysctl and Linux kernel performance tuning with sysctl.
| Item | Value |
|---|---|
| Path on the host | /etc/sysctl.conf |
| Shown here | Vault node |
| Deployed on | every server, with the differences listed below |
| Applied with | sysctl -p |
The file
#------------------------------------------------------------------------------ # File: sysctl.conf # Description: Hardened kernel configuration # Author: admin01 # Date: 2023 #------------------------------------------------------------------------------ #------------------------------------------------------------------------------ # Tweak virtual memory #------------------------------------------------------------------------------ # Default: 30 # 0 - Never swap under any circumstances. # 1 - Do not swap unless there is an out-of-memory (OOM) condition. vm.swappiness=0 # vm.dirty_background_ratio is used to adjust how the kernel handles dirty pages that must be flushed to disk. # Default value is 10. # The value is a percentage of the total amount of system memory, and setting this value to 5 is appropriate in many situations. # This setting should not be set to zero. vm.dirty_background_ratio=5 # The total number of dirty pages that are allowed before the kernel forces synchronous operations to flush them to disk # can also be increased by changing the value of vm.dirty_ratio, increasing it to above the default of 30 (also a percentage of total system memory) # vm.dirty_ratio value in-between 60 and 80 is a reasonable number. vm.dirty_ratio=60 # vm.max_map_count will calculate the current number of memory-mapped files. # The minimum value for mmap limit (vm.max_map_count) is the number of open files ulimit (cat /proc/sys/fs/file-max). # map_count should be around 1 per 128 KB of system memory. Therefore, max_map_count will be 262144 on a 32 GB system. # Reference: https://docs.confluent.io/current/kafka/deployment.html # Default: 65530 vm.max_map_count=2097152 #------------------------------------------------------------------------------ # Tweak file descriptors #------------------------------------------------------------------------------ # Increases the size of file descriptors and inode cache and restricts core dumps. fs.file-max=2097152 fs.suid_dumpable=0 #------------------------------------------------------------------------------ # Tweak network settings #------------------------------------------------------------------------------ # Default amount of memory allocated for the send and receive buffers for each socket. # This will significantly increase performance for large transfers. net.core.wmem_default=25165824 net.core.rmem_default=25165824 # Maximum amount of memory allocated for the send and receive buffers for each socket. # This will significantly increase performance for large transfers. net.core.wmem_max=25165824 net.core.rmem_max=25165824 # In addition to the socket settings, the send and receive buffer sizes for # TCP sockets must be set separately using the net.ipv4.tcp_wmem and net.ipv4.tcp_rmem parameters. # These are set using three space-separated integers that specify the minimum, default, and maximum sizes, respectively. # The maximum size cannot be larger than the values specified for all sockets using net.core.wmem_max and net.core.rmem_max. # A reasonable setting is a 4 KiB minimum, 64 KiB default, and 2 MiB maximum buffer. net.ipv4.tcp_wmem=20480 12582912 25165824 net.ipv4.tcp_rmem=20480 12582912 25165824 # Increase the maximum total buffer-space allocatable # This is measured in units of pages (4096 bytes) net.ipv4.tcp_mem=65536 25165824 262144 net.ipv4.udp_mem=65536 25165824 262144 # Minimum amount of memory allocated for the send and receive buffers for each socket. net.ipv4.udp_wmem_min=16384 net.ipv4.udp_rmem_min=16384 # Enabling TCP window scaling by setting net.ipv4.tcp_window_scaling to 1 will allow # clients to transfer data more efficiently, and allow that data to be buffered on the broker side. net.ipv4.tcp_window_scaling=1 # Increasing the value of net.ipv4.tcp_max_syn_backlog above the default of 1024 will allow # a greater number of simultaneous connections to be accepted. net.ipv4.tcp_max_syn_backlog=10240 # Increasing the value of net.core.netdev_max_backlog to greater than the default of 1000 # can assist with bursts of network traffic, specifically when using multigigabit network connection speeds, # by allowing more packets to be queued for the kernel to process them. net.core.netdev_max_backlog=65536 # Increase the maximum amount of option memory buffers net.core.optmem_max=25165824 # Number of times SYNACKs for passive TCP connection. net.ipv4.tcp_synack_retries=2 # Allowed local port range. net.ipv4.ip_local_port_range=2048 65535 # Protect Against TCP Time-Wait # Default: net.ipv4.tcp_rfc1337 = 0 net.ipv4.tcp_rfc1337=1 # Decrease the time default value for tcp_fin_timeout connection net.ipv4.tcp_fin_timeout=15 # The maximum number of backlogged sockets. # Default is 128. net.core.somaxconn=4096 # Turn on syncookies for SYN flood attack protection. net.ipv4.tcp_syncookies=1 # Avoid a smurf attack net.ipv4.icmp_echo_ignore_broadcasts=1 # Turn on protection for bad icmp error messages net.ipv4.icmp_ignore_bogus_error_responses=1 # Enable automatic window scaling. # This will allow the TCP buffer to grow beyond its usual maximum of 64K if the latency justifies it. # Turn on and log spoofed, source routed, and redirect packets net.ipv4.conf.all.log_martians=1 net.ipv4.conf.default.log_martians=1 # Tells the kernel how many TCP sockets that are not attached to any # user file handle to maintain. In case this number is exceeded, # orphaned connections are immediately reset and a warning is printed. # Default: net.ipv4.tcp_max_orphans = 65536 net.ipv4.tcp_max_orphans=65536 # Do not cache metrics on closing connections net.ipv4.tcp_no_metrics_save=1 # Disable timestamps as defined in RFC1323: # Default: net.ipv4.tcp_timestamps = 1 net.ipv4.tcp_timestamps=0 # Enable select acknowledgments. # Default: net.ipv4.tcp_sack = 1 net.ipv4.tcp_sack=1 # Increase the tcp-time-wait buckets pool size to prevent simple DOS attacks. # net.ipv4.tcp_tw_recycle has been removed from Linux?4.12. Use net.ipv4.tcp_tw_reuse instead. net.ipv4.tcp_max_tw_buckets=1440000 net.ipv4.tcp_tw_reuse=1 # The accept_source_route option causes network interfaces to accept packets with the Strict Source Route (SSR) or Loose Source Routing (LSR) option set. # The following setting will drop packets with the SSR or LSR option set. net.ipv4.conf.all.accept_source_route=0 net.ipv6.conf.all.accept_source_route=0 net.ipv4.conf.default.accept_source_route=0 net.ipv6.conf.default.accept_source_route=0 # Turn on reverse path filtering net.ipv4.conf.all.rp_filter=1 net.ipv4.conf.default.rp_filter=1 # Disable ICMP redirect acceptance net.ipv4.conf.all.accept_redirects=0 net.ipv6.conf.all.accept_redirects=0 net.ipv4.conf.default.accept_redirects=0 net.ipv6.conf.default.accept_redirects=0 net.ipv4.conf.all.secure_redirects=0 net.ipv4.conf.default.secure_redirects=0 # Disables sending of all IPv4 ICMP redirected packets. net.ipv4.conf.all.send_redirects=0 net.ipv4.conf.default.send_redirects=0 # Set ICMP ratemask net.ipv4.icmp_ratemask=88089 # Disable IP forwarding. # IP forwarding is the ability for an operating system to accept incoming network packets on one interface, # recognize that it is not meant for the system itself, but that it should be passed on to another network, and then forwards it accordingly. net.ipv4.ip_forward=0 net.ipv6.conf.all.forwarding=0 # Disable IPv6 net.ipv6.conf.all.disable_ipv6=1 net.ipv6.conf.default.disable_ipv6=1 # Disable acceptance of IPv6 router advertisements net.ipv6.conf.all.accept_ra=0 net.ipv6.conf.default.accept_ra=0 # ARP related hardening net.ipv4.conf.default.arp_announce=2 net.ipv4.conf.all.arp_announce=2 net.ipv4.conf.default.arp_ignore=2 net.ipv4.conf.all.arp_ignore=2 # Disable shared media net.ipv4.conf.default.shared_media=0 net.ipv4.conf.all.shared_media=0 #------------------------------------------------------------------------------ # Tweak kernel parameters #------------------------------------------------------------------------------ # Address Space Layout Randomization (ASLR) is a memory-protection process for operating systems that guards against buffer-overflow attacks. # It helps to ensure that the memory addresses associated with running processes on systems are not predictable, # thus flaws or vulnerabilities associated with these processes will be more difficult to exploit. # Accepted values: 0 = Disabled, 1 = Conservative Randomization, 2 = Full Randomization kernel.randomize_va_space=2 # Allow for more PIDs (to reduce rollover problems) kernel.pid_max=65536
Per-role differences
| Role | Setting | Value |
|---|---|---|
| Vault node, bastion | net.ipv4.ip_forward | 0 |
| Load balancer | net.ipv4.ip_forward | 1 |
| Load balancer | net.ipv4.ip_nonlocal_bind | 1, in the separate file /etc/sysctl.d/haproxy.conf, so HAProxy can bind the virtual address on the node that does not hold it |
Reading it today
net.ipv4.tcp_timestamps=0was a 2023 compliance item. It disables PAWS and round-trip measurement and makestcp_tw_reuseineffective; the maintained performance profile turns timestamps back on.vm.swappiness=0andvm.dirty_ratio=60are aggressive. Vault with Integrated Storage runs withmlockdisabled, so the documented requirement is no swap or encrypted swap, not a swappiness value.- IPv6 is disabled twice, here and on the kernel command line (
ipv6.disable=1). One of the two is enough. - The 24 MB socket buffers and the 1.44 million time-wait buckets come from a high-concurrency web profile. A Vault node serving two API clients never came near them.