Always applied in the Linux block, no prompt, idempotent:
- install_fail2ban: fail2ban + nftables, etc/fail2ban/jail.d/local.conf.
sshd jail reads the journal (backend systemd, works with or without
auth.log) and bans the offender on every port, so the SSH port is
irrelevant: the previous server's jail banned 22 while sshd listened
on 337. 5 failures / 10 min / 1 h. Loopback + RFC1918 never banned.
- install_unattended_upgrades: package + 20auto-upgrades (the file
dpkg-reconfigure writes, without the prompt).
- harden_sshd: sshd_config.d/20-hardening.conf (PermitRootLogin no,
MaxAuthTries 3, LoginGraceTime 20), sshd -t gated: a rejected file is
removed and the install continues with a warning. Auth methods, port
and user lists untouched.
Docs: README table + step 13 + packages, CLAUDE.md layout.