This repository has been archived on 2026-07-30. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Files
nixos/docs/internal/runbooks/proxmox-hardening.md
T
beatzaplentyandClaude Sonnet 4.6 f85c65870f Initial infrastructure mono-repo scaffold
Consolidates nixos, docker, raspi, and debian-configuration into a single
infrastructure-as-code repo. Includes:

- ansible/: full inventory + proxmox-hardening, freeipa, and raspberrypi
  roles (converted from debian-configuration bash scripts)
- terraform/: Proxmox VMs, Dynu DNS, Pi-hole (decommissioned stub),
  Docker container catalog — migrated from docker/infrastructure/terraform/
- stacks/docker/, stacks/raspi/, nixos/: placeholder READMEs pending
  git subtree population (see implementation plan)
- docs/: internal MkDocs site with architecture, network topology, runbooks,
  and drift-detection guide; external sanitized site
- scripts/: drift-detect.sh, docs-build.sh, install-hooks.sh, check-secrets.sh
- CI: secret-scan (push/PR), drift-detect (daily), docs-build (on change)
- Pi-hole removed throughout — DNS is FreeIPA, DHCP is router

See docs/internal/implementation-plan.md for the phased rollout after
pushing to Gitea.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UvNjoxTWEDkhXsd1Dq2ETP
2026-07-30 07:07:47 +10:00

1.8 KiB

Runbook: Proxmox VE Hardening

Applies Stage 1 hardening to a fresh Proxmox VE node using the proxmox-hardening Ansible role.

Pre-conditions

  • Fresh PVE install with root SSH access
  • SSH key already added to root's authorized_keys
  • Host added to ansible/inventory/hosts.yml under the proxmox group

Steps

# 1. Verify connectivity
cd ansible
ansible-playbook playbooks/ping.yml --limit <hostname>

# 2. Dry-run to preview changes
ansible-playbook playbooks/proxmox.yml --limit <hostname> --check --diff

# 3. Review the diff output, then apply
ansible-playbook playbooks/proxmox.yml --limit <hostname>

# 4. Verify hardening state
ansible-playbook playbooks/proxmox.yml --limit <hostname> --tags audit --check

What gets applied

  1. APT repos — enterprise source disabled, no-subscription source enabled
  2. SSH hardeningPermitRootLogin prohibit-password, PasswordAuthentication no, fail2ban
  3. Datacenter firewall — default-deny inbound; SSH (22) and web UI (8006) from management CIDR only
  4. Unattended upgrades — security-only origins, no auto-reboot
  5. Named admin user<proxmox_admin_username>@pve with Administrator role (one-time)
  6. IPA sudoadmins group gets NOPASSWD sudo for shell and PVE tools
  7. Subscription nag — cosmetic patch to remove the nag dialog

Variables to set per-host

In ansible/inventory/hosts.yml:

pve1.sweet.home:
  proxmox_mgmt_cidr: "192.168.2.0/24"
  proxmox_admin_username: wayne

After hardening

  • Log into the PVE web UI as the named admin, change the initial password
  • Enable TOTP/2FA for both the named admin and root@pam
  • Verify with the audit script: cd /home/wayne/repos/debian-configuration && proxmox/scripts/audit.sh (will migrate to an Ansible audit task in a future iteration)