Archived
The nixos flake's create-proxmox-resource.sh runs pvesh/qm/pct over non-interactive SSH, which requires NOPASSWD sudo for those binaries. pvesh moved from /usr/sbin to /usr/bin in PVE 8.x, so the script resolves paths at runtime rather than hardcoding them, preventing the silent NOPASSWD-miss that caused ipcc_send_rec errors. - scripts/setup-admin-sudo.sh: new script, takes username, writes /etc/sudoers.d/<user>-proxmox with correct resolved paths and validates it with visudo -c before leaving it in place - scripts/bootstrap.sh: add setup-admin-sudo.sh to post-steps list - scripts/audit.sh: check that a *-proxmox sudoers file exists with NOPASSWD for all three tools Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
47 lines
1.5 KiB
Bash
Executable File
47 lines
1.5 KiB
Bash
Executable File
#!/bin/bash
|
|
# Stage 1 base config + hardening, end to end, for a single fresh PVE host.
|
|
# Runs the individual scripts in order. Idempotent - safe to re-run.
|
|
#
|
|
# Does NOT create the named admin user (needs a username decision) - run
|
|
# create-admin-user.sh separately afterwards. Run audit.sh at the end to
|
|
# verify.
|
|
#
|
|
# Usage: MGMT_CIDR=192.168.2.0/24 ./bootstrap.sh
|
|
set -euo pipefail
|
|
|
|
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
# shellcheck source=lib/common.sh
|
|
source "${SCRIPT_DIR}/lib/common.sh"
|
|
require_root
|
|
|
|
if [ -z "${MGMT_CIDR:-}" ]; then
|
|
echo "MGMT_CIDR is not set. Example: MGMT_CIDR=192.168.2.0/24 $0" >&2
|
|
exit 1
|
|
fi
|
|
|
|
echo "=== 1/5: remove enterprise repos, switch to no-subscription ==="
|
|
"${SCRIPT_DIR}/switch-to-no-subscription-repo.sh"
|
|
|
|
echo
|
|
echo "=== 2/5: SSH hardening (key-only root login + fail2ban) ==="
|
|
"${SCRIPT_DIR}/harden-ssh.sh"
|
|
|
|
echo
|
|
echo "=== 3/5: unattended security upgrades ==="
|
|
"${SCRIPT_DIR}/setup-unattended-upgrades.sh"
|
|
|
|
echo
|
|
echo "=== 4/5: PVE firewall (mgmt-only SSH/8006) ==="
|
|
MGMT_CIDR="$MGMT_CIDR" "${SCRIPT_DIR}/deploy-firewall.sh"
|
|
|
|
echo
|
|
echo "=== 5/5: disable subscription nag (cosmetic) ==="
|
|
"${SCRIPT_DIR}/disable-subscription-nag.sh"
|
|
|
|
echo
|
|
echo "=== Base hardening applied. Remaining manual/deliberate steps: ==="
|
|
echo " - ${SCRIPT_DIR}/create-admin-user.sh <username>"
|
|
echo " - ${SCRIPT_DIR}/setup-admin-sudo.sh <username> (passwordless sudo for pvesh/qm/pct)"
|
|
echo " - Enable 2FA/TOTP for that user and root@pam via the web UI"
|
|
echo " - ${SCRIPT_DIR}/audit.sh (verify everything above)"
|