Archived
Stage 1 base config/hardening toolset, applied and verified on pve1
Splits the repo into Stage 1 (base host config/hardening, applies to any node) and Stage 2 (future HA/Ceph cluster, deferred - pve1's mini-PC hardware can't support the assumed split-disk/multi-NIC layout). Adds the Stage 1 toolset: firewall deploy, named admin user creation, unattended security upgrades, subscription-nag removal (with an apt hook so the patch survives package updates), and a read-only audit script. Fixes switch-to-no-subscription-repo.sh, which only handled the legacy .list format and silently no-op'd against PVE 9's deb822 .sources files; it now removes enterprise sources outright rather than commenting them out. Shared logic (root check, idempotent file writes, backups) factored into scripts/lib/common.sh. Ran the full sequence against pve1 via scripts/bootstrap.sh + create-admin-user.sh; scripts/audit.sh confirms all checks pass.
This commit is contained in:
@@ -1,5 +1,10 @@
|
||||
# Storage: LVM-thin → ZFS → Ceph
|
||||
|
||||
**Stage 2 (future).** Describes the target storage model once dedicated
|
||||
cluster hardware exists. `pve1`'s current single ZFS mirror (boot + VM
|
||||
storage combined, see `01-hardware-node1.md`) is the Stage 1 end state for
|
||||
now, not an intermediate step being actively migrated from.
|
||||
|
||||
## Why move off LVM-thin
|
||||
|
||||
Neither ZFS nor LVM-thin is shared storage — both are node-local. HA needs
|
||||
|
||||
Reference in New Issue
Block a user