feat(install): security baseline: fail2ban, unattended-upgrades, sshd hardening
Always applied in the Linux block, no prompt, idempotent: - install_fail2ban: fail2ban + nftables, etc/fail2ban/jail.d/local.conf. sshd jail reads the journal (backend systemd, works with or without auth.log) and bans the offender on every port, so the SSH port is irrelevant: the previous server's jail banned 22 while sshd listened on 337. 5 failures / 10 min / 1 h. Loopback + RFC1918 never banned. - install_unattended_upgrades: package + 20auto-upgrades (the file dpkg-reconfigure writes, without the prompt). - harden_sshd: sshd_config.d/20-hardening.conf (PermitRootLogin no, MaxAuthTries 3, LoginGraceTime 20), sshd -t gated: a rejected file is removed and the install continues with a warning. Auth methods, port and user lists untouched. Docs: README table + step 13 + packages, CLAUDE.md layout.
This commit is contained in:
@@ -50,3 +50,13 @@ Root cause: /tmp is tmpfs (50% RAM) → agents fill it → RAM halved + ENOSPC b
|
||||
- [x] reconcile: merge main (a210d01 dtach) into develop via lib helper
|
||||
- [x] gitflow finish feature → develop (explicit user signal: "puis merge")
|
||||
- [x] runbook for live apply on this machine
|
||||
|
||||
## Feature — security baseline in install.sh (2026-09-22)
|
||||
Branch: feature/security-baseline (off develop). Scope approved: fail2ban, unattended-upgrades, sshd hardening. auditd + ufw declined.
|
||||
- [x] etc/fail2ban/jail.d/local.conf — sshd jail, backend systemd, allports ban, RFC1918 ignoreip
|
||||
- [x] etc/apt/apt.conf.d/20auto-upgrades — Periodic Update-Package-Lists + Unattended-Upgrade = 1
|
||||
- [x] etc/ssh/sshd_config.d/20-hardening.conf — PermitRootLogin no, MaxAuthTries 3, LoginGraceTime 20
|
||||
- [x] install.sh: install_fail2ban / install_unattended_upgrades / harden_sshd (sshd -t gated), called in Linux block
|
||||
- [x] README.md (table, step 13, packages) + CLAUDE.md layout
|
||||
- [x] shellcheck + bash -n; stub harness harden_sshd (accept / reject paths); configparser check of jail file
|
||||
- [x] commit; registries (BDR-013, LRN-012); runbook. No finish without explicit signal.
|
||||
|
||||
Reference in New Issue
Block a user