This repository has been archived on 2026-08-17. You can view files and clone it. You cannot open issues or pull requests or push a commit.
beatzaplentyandClaude Sonnet 4.6 57ef1fd7be proxmox: allow beszel agent port 45876 from mgmt network
Adds an inbound ACCEPT rule for TCP 45876 so the beszel hub
can poll the agent running on pve1. Scoped to +mgmt (192.168.2.0/24)
to stay consistent with the existing default-deny policy.

Rule applied live on pve1 via pve-firewall restart (2026-07-24).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-24 06:09:25 +10:00

debian-configuration

Configuration, hardening toolsets, and operational docs for Wayne's Debian-based LAN machines. Each subdirectory covers a different host or service type.

Layout

proxmox/   Proxmox VE hosts (pve1 production, pve-test sandbox)
pihole/    Pi-hole DNS/DHCP (config snapshots, pull/apply scripts)
scripts/   Repo-wide scripts (secret scanning, git hook installer)

Sections

proxmox/

Base configuration and hardening toolset for Proxmox VE hosts. See proxmox/README.md for goals, quick-start, and current status.

pihole/

Pi-hole v6 configuration management. Stores a sanitised snapshot of the live config and provides scripts to pull from or push to a running instance. See pihole/README.md for usage.

Secret scanning

All commits are scanned for secrets by a CI pipeline that runs on both GitHub Actions and Gitea Actions. The same scan can be run locally:

# One-time setup — installs a pre-commit git hook
bash scripts/install-hooks.sh

# Manual run against the full git history
bash scripts/check-secrets.sh

# Requires gitleaks on PATH; falls back to Docker if available
# https://github.com/gitleaks/gitleaks#installing

pihole/pull-config.sh automatically redacts sensitive fields (pwhash, totp_secret, app_pwhash) from pihole.toml before writing it to disk, so the repo stays clean by default.

S
Description
No description provided
Readme
195 KiB
Languages
Shell 100%