# debian-configuration Configuration, hardening toolsets, and operational docs for Wayne's Debian-based LAN machines. Each subdirectory covers a different host or service type. ## Layout ``` proxmox/ Proxmox VE hosts (pve1 production, pve-test sandbox) pihole/ Pi-hole DNS/DHCP (config snapshots, pull/apply scripts) freeipa/ FreeIPA identity management server (domain-controller.sweet.home) raspberrypi/ Raspberry Pi 4 (Debian 12, IPA-enrolled, Docker host) scripts/ Repo-wide scripts (secret scanning, git hook installer) ``` ## Sections ### `proxmox/` Base configuration and hardening toolset for Proxmox VE hosts. See `proxmox/README.md` for goals, quick-start, and current status. ### `pihole/` Pi-hole v6 configuration management. Stores a sanitised snapshot of the live config and provides scripts to pull from or push to a running instance. See `pihole/README.md` for usage. ### `freeipa/` FreeIPA 4.x identity management server running on Rocky Linux 9 (`domain-controller.sweet.home`, VMID 108 on pve1). Provides Kerberos, LDAP, and integrated DNS for the `sweet.home` realm. See `freeipa/README.md` for the quick-start and `freeipa/docs/install.md` for the full reproduction procedure. ### `raspberrypi/` Raspberry Pi 4 running Debian 12 bookworm (`raspberrypi.tail13f623.ts.net`, reachable from LAN via Tailscale MagicDNS). IPA-enrolled; runs Traefik, Uptime Kuma, CrowdSec, and Beszel. See `raspberrypi/README.md` for setup scripts and current status. ## Secret scanning All commits are scanned for secrets by a CI pipeline that runs on both GitHub Actions and Gitea Actions. The same scan can be run locally: ```bash # One-time setup — installs a pre-commit git hook bash scripts/install-hooks.sh # Manual run against the full git history bash scripts/check-secrets.sh # Requires gitleaks on PATH; falls back to Docker if available # https://github.com/gitleaks/gitleaks#installing ``` `pihole/pull-config.sh` automatically redacts sensitive fields (`pwhash`, `totp_secret`, `app_pwhash`) from `pihole.toml` before writing it to disk, so the repo stays clean by default.