gitleaks, web stack (mariadb-server, imagemagick, unversioned php-* modules),
ubuntu-desktop-minimal before the RDP setup, and a lspci-gated
install_nvidia_driver() that runs ubuntu-drivers install. README + TODO updated.
Always applied in the Linux block, no prompt, idempotent:
- install_fail2ban: fail2ban + nftables, etc/fail2ban/jail.d/local.conf.
sshd jail reads the journal (backend systemd, works with or without
auth.log) and bans the offender on every port, so the SSH port is
irrelevant: the previous server's jail banned 22 while sshd listened
on 337. 5 failures / 10 min / 1 h. Loopback + RFC1918 never banned.
- install_unattended_upgrades: package + 20auto-upgrades (the file
dpkg-reconfigure writes, without the prompt).
- harden_sshd: sshd_config.d/20-hardening.conf (PermitRootLogin no,
MaxAuthTries 3, LoginGraceTime 20), sshd -t gated: a rejected file is
removed and the install continues with a warning. Auth methods, port
and user lists untouched.
Docs: README table + step 13 + packages, CLAUDE.md layout.
cloudpex/cloudpex no longer carries the NAS host, share name, SMB user,
mount point or SMB version. It reads /etc/cloudpex.conf (root:root 0600,
KEY=value) line by line, never sources it, and dies with a hint when the
file is missing, incomplete or has a relative mount point.
cloudpex/install.sh prompts for the five values (regex-validated, re-asked
on bad input so the main installer never aborts), shows and keeps an
existing config unless answered n, and skips the config when no terminal
is attached. README (FR) + root README + CLAUDE.md updated.
/tmp is a RAM-backed tmpfs on Ubuntu (50% of RAM). Agent runs fill it: half
the RAM goes, then every temp-file creation fails with ENOSPC and shells
break. Swap does not lift the cap, so the fix is /tmp on disk.
End-of-install offers (Linux, [y/N], skipped without a terminal, idempotent):
- offer_tmp_on_disk: mask tmp.mount + etc/tmpfiles.d/tmp.conf (wipe at
boot, 10-day purge, /var/tmp rule kept). Effective at next reboot.
- offer_ssh_memory_guard: the previous server's rules. ssh.service drop-in
(OOMScoreAdjust=-1000, MemoryMin=256M) + earlyoom with --avoid sshd and
--prefer node/java. MemoryMin covers sshd only; earlyoom is the real guard.
install_cloudpex deploys the NAS mount helper in the Linux block.
Docs: README steps 12-14 + table, CLAUDE.md layout + lint command.
- BDR-009: reverses BDR-007; menu moved to ~/.bashrc because VS Code
Remote-SSH terminals are non-login; per-tab firing accepted over a
once-per-connection sentinel.
- LRN-008: VS Code Remote-SSH (Linux) terminals are non-login -> skip
~/.profile; hook ~/.bashrc for "run once at session start"; diagnose via
VSCODE_IPC_HOOK_CLI + no login-bash ancestry + shopt -q login_shell.
- journal: 2026-06-25 session entry.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CN1KSmsuLG6TxSeN5m8xvM
Executing dtach-router broke its return-based interactive guard and
errored on /dev/tty in non-interactive login shells (bash -lc, cron,
scp). It is now sourced via a guarded, idempotent ~/.profile block
(case $- in *i*) ... . dtach-router) installed by wire_dtach_profile(),
which migrates the old execute-based block. Also adds cc (create) and
d (re-summon) aliases to bashrc-linux.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CN1KSmsuLG6TxSeN5m8xvM
Add etc/profile.d/disk-usage-warning.sh (POSIX sh) that warns in bold
red at login when / or /home cross 85% usage. Deployed system-wide via
install_disk_warning() (sudo install -D -m 0644), gated inside the
apt-get block since df --output=pcent and /etc/profile.d are GNU/Debian
conventions absent on macOS. Idempotent and re-runnable.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CN1KSmsuLG6TxSeN5m8xvM
Record the architecture decision (rationale + rejected alternatives) behind
replacing xrdp with gnome-remote-desktop system "Remote Login" on Wayland-only
GNOME. Cross-refs LRN-004 / BLK-004.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JSFhCiEgndbRrMf7s8mmth
xrdp was found incompatible with Wayland-only GNOME and replaced by
gnome-remote-desktop system "Remote Login". Add BLK-004 (mstsc 0x904/0x7 root
cause: empty gate credentials) and LRN-004 (g-r-d --system recipe + two-layer
auth), both superseding the now-outdated xrdp entries BLK-003/LRN-003, plus a
journal line. RDP connection confirmed working live.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JSFhCiEgndbRrMf7s8mmth
Onboard scaffolding for the dotfiles repo: 5 memory registries,
TODO backlog, onboard audit report, and .gitignore (ignores
Oldconfig, vim swap, .claude/settings.local.json).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>