Commit Graph
11 Commits
Author SHA1 Message Date
bastien 55ede6f08c feat(install): security baseline: fail2ban, unattended-upgrades, sshd hardening
Always applied in the Linux block, no prompt, idempotent:
- install_fail2ban: fail2ban + nftables, etc/fail2ban/jail.d/local.conf.
  sshd jail reads the journal (backend systemd, works with or without
  auth.log) and bans the offender on every port, so the SSH port is
  irrelevant: the previous server's jail banned 22 while sshd listened
  on 337. 5 failures / 10 min / 1 h. Loopback + RFC1918 never banned.
- install_unattended_upgrades: package + 20auto-upgrades (the file
  dpkg-reconfigure writes, without the prompt).
- harden_sshd: sshd_config.d/20-hardening.conf (PermitRootLogin no,
  MaxAuthTries 3, LoginGraceTime 20), sshd -t gated: a rejected file is
  removed and the install continues with a warning. Auth methods, port
  and user lists untouched.
Docs: README table + step 13 + packages, CLAUDE.md layout.
2026-09-22 17:47:34 +02:00
bastien 4f8bb61458 feat(cloudpex): site values out of the script, prompted at install into /etc/cloudpex.conf
cloudpex/cloudpex no longer carries the NAS host, share name, SMB user,
mount point or SMB version. It reads /etc/cloudpex.conf (root:root 0600,
KEY=value) line by line, never sources it, and dies with a hint when the
file is missing, incomplete or has a relative mount point.

cloudpex/install.sh prompts for the five values (regex-validated, re-asked
on bad input so the main installer never aborts), shows and keeps an
existing config unless answered n, and skips the config when no terminal
is attached. README (FR) + root README + CLAUDE.md updated.
2026-09-22 17:34:18 +02:00
bastien 872079bafb feat(install): offer /tmp on disk + SSH memory guard, deploy cloudpex helper
/tmp is a RAM-backed tmpfs on Ubuntu (50% of RAM). Agent runs fill it: half
the RAM goes, then every temp-file creation fails with ENOSPC and shells
break. Swap does not lift the cap, so the fix is /tmp on disk.

End-of-install offers (Linux, [y/N], skipped without a terminal, idempotent):
- offer_tmp_on_disk: mask tmp.mount + etc/tmpfiles.d/tmp.conf (wipe at
  boot, 10-day purge, /var/tmp rule kept). Effective at next reboot.
- offer_ssh_memory_guard: the previous server's rules. ssh.service drop-in
  (OOMScoreAdjust=-1000, MemoryMin=256M) + earlyoom with --avoid sshd and
  --prefer node/java. MemoryMin covers sshd only; earlyoom is the real guard.

install_cloudpex deploys the NAS mount helper in the Linux block.
Docs: README steps 12-14 + table, CLAUDE.md layout + lint command.
2026-09-22 16:57:08 +02:00
Bastien ChanotandClaude Opus 4.8 e37eb77ed5 fix(dtach): wire resume menu into ~/.bashrc for non-login VS Code shells
VS Code Remote-SSH integrated terminals are non-login interactive shells:
they source ~/.bashrc but never ~/.profile, where the resume menu was wired
(login-scope, BDR-007). The auto-check therefore never fired in the user's
actual environment, even after install.sh.

Source dtach-router from bashrc-linux (every interactive shell) instead, and
turn install.sh's wire_dtach_profile() into unwire_dtach_profile(): it now
strips any stale ~/.profile block so a plain SSH login (which reads ~/.bashrc
via ~/.profile) does not prompt twice. README updated to match.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CN1KSmsuLG6TxSeN5m8xvM
2026-06-26 00:09:16 +02:00
Bastien ChanotandClaude Opus 4.8 00d88f723f docs(readme): document code-server + RDP, add License section
The feature batch in 0bd936b shipped code-server and gnome-remote-desktop
RDP login, but the later README edit (46512ee) only fixed the package list,
leaving both features undocumented.

- Add install steps for code-server (browser VS Code) and gnome-remote-desktop
  RDP remote login.
- Add a "Remote access" bullet to the apt package list (gnome-remote-desktop,
  openssl, code-server).
- Broaden the install.sh summary row in "What's inside".
- Replace the Lint section with a License section (GPL-3.0-or-later).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P8QfqokDoggsPVhEp7FnCa
2026-06-25 11:19:21 +02:00
Bastien ChanotandClaude Opus 4.8 46512ee2de docs(readme): fix stale wkhtmltopdf -> weasyprint in package list
install.sh installs weasyprint (HTML/CSS->PDF), not wkhtmltopdf; the apt package list in README was stale. Mirror the installer verbatim.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CN1KSmsuLG6TxSeN5m8xvM
2026-06-24 18:02:23 +02:00
Bastien ChanotandClaude Opus 4.8 dafe9ea185 fix(install): source dtach-router at login instead of executing it
Executing dtach-router broke its return-based interactive guard and
errored on /dev/tty in non-interactive login shells (bash -lc, cron,
scp). It is now sourced via a guarded, idempotent ~/.profile block
(case $- in *i*) ... . dtach-router) installed by wire_dtach_profile(),
which migrates the old execute-based block. Also adds cc (create) and
d (re-summon) aliases to bashrc-linux.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CN1KSmsuLG6TxSeN5m8xvM
2026-06-24 18:00:52 +02:00
Bastien ChanotandClaude Opus 4.8 c0fddc6f94 feat(install): system-wide low-disk login warning via /etc/profile.d
Add etc/profile.d/disk-usage-warning.sh (POSIX sh) that warns in bold
red at login when / or /home cross 85% usage. Deployed system-wide via
install_disk_warning() (sudo install -D -m 0644), gated inside the
apt-get block since df --output=pcent and /etc/profile.d are GNU/Debian
conventions absent on macOS. Idempotent and re-runnable.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CN1KSmsuLG6TxSeN5m8xvM
2026-06-24 18:00:17 +02:00
Bastien ChanotandClaude Opus 4.7 262862c1b9 fix(bashrc): add ~/.local/bin to PATH in deployed bashrc
The bin/ scripts and pipx CLIs land in ~/.local/bin, which was not on
PATH in either deployed bashrc. Add an idempotent PATH guard to
bashrc-linux and bashrc-osx so dt, claude-provider, pymupdf, etc. are
found after login. Update the install.sh and README notes to match.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-27 18:56:56 +02:00
Bastien ChanotandClaude Opus 4.7 f574554ade feat(install): expand apt packages, Docker, pipx CLIs, deploy bin/
- broaden the apt-get set: git-filter-repo, valgrind, shellcheck, gnupg,
  ca-certificates, apt-transport-https, tree, tmux, fzf, dtach, net-tools,
  openssh-server, cifs-utils, lftp, ftp, nodejs, python3-pip, pipx, php-cli,
  ffmpeg, wkhtmltopdf, poppler-utils, qpdf, webp, libavif-bin
- set up Docker's official Ubuntu repo and install engine + compose plugin
  (idempotent: skipped if docker is already present)
- install pipx CLIs PyMuPDF (pymupdf) and Markdown (markdown_py)
- deploy bin/ scripts to ~/.local/bin
- document the package set and CLI tools in README and CLAUDE.md

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-27 18:51:13 +02:00
Bastien ChanotandClaude Opus 4.7 8769eb9bdb docs: add README and project CLAUDE.md
README documents the curl|bash one-liner (with a remote-exec
warning), the manual clone, and OS auto-detection. CLAUDE.md
records the dotfiles-meta archetype, commands, conventions, and
known issues for future sessions.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-27 18:28:37 +02:00