security: harden lazyworkhorse with firewall, fail2ban, SSH hardening #28
Reference in New Issue
Block a user
No description provided.
Delete Branch "feature/server-hardening-clean"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Adds comprehensive server hardening for internet-facing NixOS host.
Changes
Firewall (default deny)
Fail2ban
SSH Hardening
Kernel Hardening
Dependencies
Merge compose PR first, then this one.
Deployment
Verification
Related
nixos-server-hardeningMerge Priority
This PR is marked as PRIORITY #1 - must merge before other feature PRs to ensure all services are protected.
See merge plan: PR #29 - #29
After Merge
Verify with:
Hermes referenced this pull request2026-05-01 01:38:33 +00:00
8bdd0e352ato5d3bbe99f3