Always applied in the Linux block, no prompt, idempotent: - install_fail2ban: fail2ban + nftables, etc/fail2ban/jail.d/local.conf. sshd jail reads the journal (backend systemd, works with or without auth.log) and bans the offender on every port, so the SSH port is irrelevant: the previous server's jail banned 22 while sshd listened on 337. 5 failures / 10 min / 1 h. Loopback + RFC1918 never banned. - install_unattended_upgrades: package + 20auto-upgrades (the file dpkg-reconfigure writes, without the prompt). - harden_sshd: sshd_config.d/20-hardening.conf (PermitRootLogin no, MaxAuthTries 3, LoginGraceTime 20), sshd -t gated: a rejected file is removed and the install continues with a warning. Auth methods, port and user lists untouched. Docs: README table + step 13 + packages, CLAUDE.md layout.
67 lines
3.4 KiB
Markdown
67 lines
3.4 KiB
Markdown
# CLAUDE.md — config (personal dotfiles)
|
|
|
|
Project context for Claude. Global preferences in `~/.claude/CLAUDE.md` apply on top.
|
|
|
|
## What this is
|
|
|
|
Personal dotfiles repo. **Archetype: dotfiles-meta** (meta/config, not an application).
|
|
Produces vim + bash configuration deployed by `install.sh`. Private/personal audience.
|
|
|
|
- Public: no
|
|
- Database: none
|
|
- Stack: POSIX/bash shell scripts + vimscript
|
|
- Distribution: `git clone` + `./install.sh` (OS auto-detected)
|
|
|
|
## Layout
|
|
|
|
```
|
|
remote-install.sh curl|bash bootstrap: ensure git, clone/pull, run install.sh
|
|
install.sh one-shot installer (OS auto-detected)
|
|
vim/vimrc vim config (pathogen, molokai, syntastic, NERDTree)
|
|
vim/autoload/ pathogen loader (committed)
|
|
vim/colors/ molokai colorscheme (committed)
|
|
bash/bashrc-{linux,osx} OS-detected bashrc
|
|
bin/{dt,dtach-router,claude-provider} CLI scripts deployed to ~/.local/bin
|
|
etc/profile.d/disk-usage-warning.sh login-time low-disk warning → /etc/profile.d (Linux only)
|
|
etc/tmpfiles.d/tmp.conf disk-backed /tmp cleanup rules (offer: /tmp on disk)
|
|
etc/systemd/ssh.service.d/override.conf sshd OOM-exempt drop-in (offer: SSH memory guard)
|
|
etc/default/earlyoom earlyoom args, spare sshd / kill node first (same offer)
|
|
etc/fail2ban/jail.d/local.conf sshd jail: journal backend, all-ports ban, LAN ignored (always)
|
|
etc/apt/apt.conf.d/20auto-upgrades unattended security upgrades on (always)
|
|
etc/ssh/sshd_config.d/20-hardening.conf sshd limits that cannot lock out, sshd -t gated (always)
|
|
cloudpex/{cloudpex,install.sh,README.md} on-demand SMB mount helper → /usr/local/bin; site values
|
|
prompted at install → /etc/cloudpex.conf, never in the script (FR docs)
|
|
.claude/{tasks,memory,audits}/ Claude working state
|
|
```
|
|
|
|
`/tmp` is a RAM-backed tmpfs on Ubuntu (50% of RAM): agent runs fill it, which is why
|
|
install.sh offers to mask `tmp.mount`. Swap is not the fix (the cap and ENOSPC stay).
|
|
|
|
`pymupdf`/`markdown_py` are NOT tracked — they are pipx entry-point shims,
|
|
recreated by `pipx install PyMuPDF Markdown` in install.sh.
|
|
`claude-provider` reads `$OPENROUTER_API_KEY` from the env — never hardcode it (the
|
|
original had a live key; it was scrubbed — see decisions/blockers).
|
|
|
|
## Commands
|
|
|
|
| Task | Command |
|
|
| ----- | ---------------------------------------- |
|
|
| Lint | `shellcheck *.sh cloudpex/install.sh cloudpex/cloudpex bash/bashrc-*` |
|
|
| Syntax check | `bash -n install.sh remote-install.sh cloudpex/install.sh` |
|
|
| Install | `./install.sh` (OS auto-detected) |
|
|
| Remote install | `curl -fsSL <raw>/remote-install.sh \| bash` |
|
|
|
|
No build, no test suite. Lint = shellcheck.
|
|
|
|
## Conventions
|
|
|
|
- Shell scripts: `#!/usr/bin/env bash`, `set -euo pipefail`, quote all expansions, keep shellcheck clean.
|
|
- Installer must stay **idempotent** (re-runnable without breaking state) and use `$SCRIPT_DIR`-relative paths.
|
|
- bashrc files: tabs for indentation (existing style). Style nits (legacy backticks) tolerated — don't churn.
|
|
- No secrets in any tracked file. Use placeholders if config ever needs tokens.
|
|
|
|
## Known issues (see .claude/audits/ONBOARD_REPORT.md)
|
|
|
|
- `vim/vimrc` `GenerateClassC` uses bare `name` instead of `a:name` → `:ClassC` errors (E121). Vim domain, not yet fixed.
|
|
- bashrc files use legacy backticks (`SC2006`) — cosmetic.
|