feat(install): security baseline: fail2ban, unattended-upgrades, sshd hardening
Always applied in the Linux block, no prompt, idempotent: - install_fail2ban: fail2ban + nftables, etc/fail2ban/jail.d/local.conf. sshd jail reads the journal (backend systemd, works with or without auth.log) and bans the offender on every port, so the SSH port is irrelevant: the previous server's jail banned 22 while sshd listened on 337. 5 failures / 10 min / 1 h. Loopback + RFC1918 never banned. - install_unattended_upgrades: package + 20auto-upgrades (the file dpkg-reconfigure writes, without the prompt). - harden_sshd: sshd_config.d/20-hardening.conf (PermitRootLogin no, MaxAuthTries 3, LoginGraceTime 20), sshd -t gated: a rejected file is removed and the install continues with a warning. Auth methods, port and user lists untouched. Docs: README table + step 13 + packages, CLAUDE.md layout.
This commit is contained in:
@@ -26,6 +26,9 @@ etc/profile.d/disk-usage-warning.sh login-time low-disk warning → /etc/pro
|
||||
etc/tmpfiles.d/tmp.conf disk-backed /tmp cleanup rules (offer: /tmp on disk)
|
||||
etc/systemd/ssh.service.d/override.conf sshd OOM-exempt drop-in (offer: SSH memory guard)
|
||||
etc/default/earlyoom earlyoom args, spare sshd / kill node first (same offer)
|
||||
etc/fail2ban/jail.d/local.conf sshd jail: journal backend, all-ports ban, LAN ignored (always)
|
||||
etc/apt/apt.conf.d/20auto-upgrades unattended security upgrades on (always)
|
||||
etc/ssh/sshd_config.d/20-hardening.conf sshd limits that cannot lock out, sshd -t gated (always)
|
||||
cloudpex/{cloudpex,install.sh,README.md} on-demand SMB mount helper → /usr/local/bin; site values
|
||||
prompted at install → /etc/cloudpex.conf, never in the script (FR docs)
|
||||
.claude/{tasks,memory,audits}/ Claude working state
|
||||
|
||||
Reference in New Issue
Block a user