chore(memory): BDR-013 security baseline, LRN-012 fail2ban port vs allports, journal
This commit is contained in:
@@ -98,3 +98,13 @@ in repo, live apply = user.
|
||||
main install.sh never aborts; keep-existing [Y/n]; skipped without TTY). Script parses lines
|
||||
(`sed -n s/^KEY=//p`), never sources → no code exec as root from config. Alt rejected: sed placeholders into
|
||||
deployed script — config + code mixed, every re-run overwrites values. Status: done in repo.
|
||||
|
||||
## BDR-013 — security baseline always-on in install.sh: fail2ban (all-ports), unattended-upgrades, sshd limits
|
||||
2026-09-22. User: "fail2ban and the like, systematically". Chose no-prompt Linux-block steps: (1) fail2ban sshd
|
||||
jail `backend = systemd` + `banaction = %(banaction_allports)s` → SSH port irrelevant (old server banned 22 while
|
||||
sshd on 337, LRN-012); `ignoreip` = loopback + RFC1918 static (no LAN detection; trade-off: compromised LAN host
|
||||
never banned); 5/10m/1h from RECOVERY doc 01. (2) `20auto-upgrades` file instead of interactive dpkg-reconfigure.
|
||||
(3) sshd drop-in limited to PermitRootLogin/MaxAuthTries/LoginGraceTime, `sshd -t` gated, rejected file removed +
|
||||
install continues. Declined by user: auditd rules, ufw whitelist (site-specific ports, lockout risk → would be an
|
||||
offer, not systematic). Not included by design: PasswordAuthentication no / AllowUsers / X11Forwarding no
|
||||
(lockout or workflow risk). Status: done in repo (feature/security-baseline), live apply = user.
|
||||
|
||||
@@ -59,3 +59,7 @@ end-of-install offers (BDR-011). cloudpex tracked; site values → /etc/cloudpex
|
||||
main→develop (a210d01 dtach was main-only), feature finished via lib → develop 836bb67. Not applied live.
|
||||
Flagged: secrets in NAS transfert/root (BLK-005), remote-install.sh BRANCH=master stale vs main, gitea-deploy/
|
||||
untracked, remote feature branch left on origin (lib deletes local only).
|
||||
Later same day: security baseline always-on in install.sh (fail2ban all-ports + RFC1918 ignore, unattended-
|
||||
upgrades file, sshd limits drop-in sshd -t gated) on feature/security-baseline (BDR-013, LRN-012: old jail
|
||||
banned 22 not 337). auditd + ufw declined. shellcheck/bash -n CLEAN, stub harness incl. sshd -t reject path,
|
||||
configparser + apt-config checks. Branch pushed, NOT finished (no merge signal). Live apply = user runbook.
|
||||
|
||||
@@ -85,3 +85,11 @@ here). Old-server earlyoom file valid as-is. Env-file syntax check: `sh -n`.
|
||||
Extract functions (`sed -n '/^fn()/,/^}/p'`) into scratch, define `sudo(){ echo "SUDO: $*"; }` + `systemctl`
|
||||
+ `findmnt` stubs, override `confirm` per scenario, `</dev/null` for no-TTY. Covers every branch, prints exact
|
||||
sudo calls, `set -e` behaviour included. Gotcha: `unset -f` on an overridden fn removes it entirely.
|
||||
|
||||
## LRN-012 — fail2ban jail must match the real sshd port, or ban all ports
|
||||
2026-09-22. Old server: sshd `Port 337`, fail2ban sshd jail with default `port = ssh` (=22) → bans hit port 22
|
||||
only, SSH on 337 stayed open to the banned IP. Silent, no error. Fix options: `port = 337` (needs detection /
|
||||
templating, drifts if port changes) or `banaction = %(banaction_allports)s` (offender blocked everywhere, port
|
||||
irrelevant) — chose allports. Offline checks without fail2ban installed: python `configparser` with
|
||||
BasicInterpolation resolves `%(x)s` refs and proves the file parses; apt.conf → `apt-config
|
||||
--config-file=<f> dump APT::Periodic`. sshd drop-ins can't be `sshd -t`-tested without root (host keys).
|
||||
|
||||
Reference in New Issue
Block a user