Initial planning docs and hardening scripts for HA rebuild

Covers node 1 hardware/network layout, LVM-thin -> ZFS migration path,
Ceph as the future HA storage upgrade, and baseline SSH/firewall
hardening.
This commit is contained in:
2026-07-20 11:45:54 +10:00
commit a854412117
10 changed files with 414 additions and 0 deletions
+51
View File
@@ -0,0 +1,51 @@
#!/bin/bash
# Apply baseline SSH hardening to a Proxmox VE node: key-only root login
# + fail2ban. Idempotent - safe to re-run. Run as root on the PVE host.
set -euo pipefail
DROPIN_DIR="/etc/ssh/sshd_config.d"
DROPIN_FILE="${DROPIN_DIR}/99-hardening.conf"
if [ "$(id -u)" -ne 0 ]; then
echo "Must run as root." >&2
exit 1
fi
mkdir -p "$DROPIN_DIR"
cat > "$DROPIN_FILE" <<'EOF'
PermitRootLogin prohibit-password
PasswordAuthentication no
EOF
echo "Wrote $DROPIN_FILE"
if ! authorized_keys_present=$(find /root/.ssh/authorized_keys /home/*/.ssh/authorized_keys -type f 2>/dev/null | head -n1); then
authorized_keys_present=""
fi
if [ -z "$authorized_keys_present" ]; then
echo "WARNING: no authorized_keys found for any user yet." >&2
echo "Add your SSH public key before disconnecting, or you'll lock yourself out." >&2
fi
sshd -t
systemctl reload sshd
echo "sshd reloaded with key-only root login."
if ! dpkg -s fail2ban >/dev/null 2>&1; then
apt-get update
apt-get install -y fail2ban
fi
mkdir -p /etc/fail2ban/jail.d
cat > /etc/fail2ban/jail.d/sshd.local <<'EOF'
[sshd]
enabled = true
port = ssh
backend = systemd
maxretry = 5
bantime = 1h
findtime = 10m
EOF
systemctl enable --now fail2ban
systemctl restart fail2ban
echo "fail2ban enabled for sshd."