From 26c8e345c57037c3e4566daea35aa792cd4f1ef9 Mon Sep 17 00:00:00 2001 From: bastien Date: Tue, 22 Sep 2026 17:47:35 +0200 Subject: [PATCH] chore(memory): BDR-013 security baseline, LRN-012 fail2ban port vs allports, journal --- .claude/memory/decisions.md | 10 ++++++++++ .claude/memory/journal.md | 4 ++++ .claude/memory/learnings.md | 8 ++++++++ 3 files changed, 22 insertions(+) diff --git a/.claude/memory/decisions.md b/.claude/memory/decisions.md index e1665c8..9473228 100644 --- a/.claude/memory/decisions.md +++ b/.claude/memory/decisions.md @@ -98,3 +98,13 @@ in repo, live apply = user. main install.sh never aborts; keep-existing [Y/n]; skipped without TTY). Script parses lines (`sed -n s/^KEY=//p`), never sources → no code exec as root from config. Alt rejected: sed placeholders into deployed script — config + code mixed, every re-run overwrites values. Status: done in repo. + +## BDR-013 — security baseline always-on in install.sh: fail2ban (all-ports), unattended-upgrades, sshd limits +2026-09-22. User: "fail2ban and the like, systematically". Chose no-prompt Linux-block steps: (1) fail2ban sshd +jail `backend = systemd` + `banaction = %(banaction_allports)s` → SSH port irrelevant (old server banned 22 while +sshd on 337, LRN-012); `ignoreip` = loopback + RFC1918 static (no LAN detection; trade-off: compromised LAN host +never banned); 5/10m/1h from RECOVERY doc 01. (2) `20auto-upgrades` file instead of interactive dpkg-reconfigure. +(3) sshd drop-in limited to PermitRootLogin/MaxAuthTries/LoginGraceTime, `sshd -t` gated, rejected file removed + +install continues. Declined by user: auditd rules, ufw whitelist (site-specific ports, lockout risk → would be an +offer, not systematic). Not included by design: PasswordAuthentication no / AllowUsers / X11Forwarding no +(lockout or workflow risk). Status: done in repo (feature/security-baseline), live apply = user. diff --git a/.claude/memory/journal.md b/.claude/memory/journal.md index 66b92d9..31d3f08 100644 --- a/.claude/memory/journal.md +++ b/.claude/memory/journal.md @@ -59,3 +59,7 @@ end-of-install offers (BDR-011). cloudpex tracked; site values → /etc/cloudpex main→develop (a210d01 dtach was main-only), feature finished via lib → develop 836bb67. Not applied live. Flagged: secrets in NAS transfert/root (BLK-005), remote-install.sh BRANCH=master stale vs main, gitea-deploy/ untracked, remote feature branch left on origin (lib deletes local only). +Later same day: security baseline always-on in install.sh (fail2ban all-ports + RFC1918 ignore, unattended- +upgrades file, sshd limits drop-in sshd -t gated) on feature/security-baseline (BDR-013, LRN-012: old jail +banned 22 not 337). auditd + ufw declined. shellcheck/bash -n CLEAN, stub harness incl. sshd -t reject path, +configparser + apt-config checks. Branch pushed, NOT finished (no merge signal). Live apply = user runbook. diff --git a/.claude/memory/learnings.md b/.claude/memory/learnings.md index e7e483b..6f5d05e 100644 --- a/.claude/memory/learnings.md +++ b/.claude/memory/learnings.md @@ -85,3 +85,11 @@ here). Old-server earlyoom file valid as-is. Env-file syntax check: `sh -n`. Extract functions (`sed -n '/^fn()/,/^}/p'`) into scratch, define `sudo(){ echo "SUDO: $*"; }` + `systemctl` + `findmnt` stubs, override `confirm` per scenario, ` dump APT::Periodic`. sshd drop-ins can't be `sshd -t`-tested without root (host keys).