feat(install): security baseline: fail2ban, unattended-upgrades, sshd hardening
Always applied in the Linux block, no prompt, idempotent: - install_fail2ban: fail2ban + nftables, etc/fail2ban/jail.d/local.conf. sshd jail reads the journal (backend systemd, works with or without auth.log) and bans the offender on every port, so the SSH port is irrelevant: the previous server's jail banned 22 while sshd listened on 337. 5 failures / 10 min / 1 h. Loopback + RFC1918 never banned. - install_unattended_upgrades: package + 20auto-upgrades (the file dpkg-reconfigure writes, without the prompt). - harden_sshd: sshd_config.d/20-hardening.conf (PermitRootLogin no, MaxAuthTries 3, LoginGraceTime 20), sshd -t gated: a rejected file is removed and the install continues with a warning. Auth methods, port and user lists untouched. Docs: README table + step 13 + packages, CLAUDE.md layout.
This commit is contained in:
@@ -0,0 +1,4 @@
|
||||
// Automatic security updates, deployed by install.sh. Same content as
|
||||
// `dpkg-reconfigure -plow unattended-upgrades` writes, without the prompt.
|
||||
APT::Periodic::Update-Package-Lists "1";
|
||||
APT::Periodic::Unattended-Upgrade "1";
|
||||
@@ -0,0 +1,20 @@
|
||||
# fail2ban local settings, deployed by install.sh. Debian's defaults-debian.conf
|
||||
# enables the sshd jail; this file decides how it bans.
|
||||
[DEFAULT]
|
||||
# Never ban loopback or the private LAN ranges: five typos from the LAN must not
|
||||
# lock the admin out for an hour. Trade-off: a compromised LAN host is never banned.
|
||||
ignoreip = 127.0.0.1/8 ::1 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16
|
||||
bantime = 1h
|
||||
findtime = 10m
|
||||
maxretry = 5
|
||||
banaction = nftables
|
||||
banaction_allports = nftables[type=allports]
|
||||
|
||||
[sshd]
|
||||
enabled = true
|
||||
# Read the journal directly: works with or without /var/log/auth.log (rsyslog).
|
||||
backend = systemd
|
||||
journalmatch = _SYSTEMD_UNIT=ssh.service + _COMM=sshd
|
||||
# Ban the offender on every port, so the port sshd listens on is irrelevant. The
|
||||
# previous server's jail banned port 22 only while sshd listened on 337.
|
||||
banaction = %(banaction_allports)s
|
||||
@@ -0,0 +1,5 @@
|
||||
# sshd hardening, deployed by install.sh. Only settings that cannot lock anyone
|
||||
# out: authentication methods, ports and user lists are left to the host.
|
||||
PermitRootLogin no
|
||||
MaxAuthTries 3
|
||||
LoginGraceTime 20
|
||||
Reference in New Issue
Block a user