Commit Graph

  • a6f5adde00 Space before nullok Tommy 2024-02-13 16:50:28 -07:00
  • 3f9d70c9f1 Update on Friday instead Tommy 2024-02-13 16:33:31 -07:00
  • bb9719eff6 Implement /etc/issue Tommy 2024-02-13 16:01:42 -07:00
  • 472dd72cc6 Rename VM to QEMU Tommy 2024-02-13 15:09:49 -07:00
  • baf5ca9334 Remove more packages Tommy 2024-02-13 14:18:04 -07:00
  • c8611cf3dd Typo fix Tommy 2024-02-11 04:27:32 -07:00
  • 6e0729b203 Remove more unneeded packages Tommy 2024-02-11 04:21:48 -07:00
  • e0c04ff5b6 Update gvisor-downloader.service description Tommy 2024-02-07 19:52:02 -07:00
  • 2155a601e1 Typo fix Tommy 2024-02-07 12:54:33 -07:00
  • 96e6a41ec6 Update kargs Tommy 2024-02-07 12:41:30 -07:00
  • 30896a69c8 Cleaup .gitignore Tommy 2024-02-07 12:39:48 -07:00
  • a939832941 Remove workspace config Tommy 2024-02-07 12:39:14 -07:00
  • 8c627c88d9 docker-compose-updater requires docker.service Tommy 2024-02-07 12:38:17 -07:00
  • d61e21c966 Reimplement Docker Compose Plugin in Generic.yml Tommy 2024-02-07 12:32:49 -07:00
  • e06a0066f7 Update README.md Tommy 2024-02-07 12:22:37 -07:00
  • f7a8f005b6 Let zincati use "localtime" because TZ is alr MST Tommy 2024-02-07 12:22:24 -07:00
  • 9ddc479705 Update copyright year Tommy 2024-02-07 12:13:26 -07:00
  • 34712aa7bf Reconfigure Zincati Tommy 2024-02-07 12:03:47 -07:00
  • d48591d194 Fix gVisor downloader Tommy 2024-02-07 11:33:33 -07:00
  • dc0a155c30 More typo fixes Tommy 2024-02-07 11:20:52 -07:00
  • dca71564e7 Typo fix Tommy 2024-02-07 10:54:09 -07:00
  • 461e4bca05 Fix gVisor Updater Tommy 2024-02-07 10:37:36 -07:00
  • 4bad3e63a0 Split out configs Tommy 2024-02-07 10:02:45 -07:00
  • 89b9395dfe Code cleanup Tommy 2024-02-07 07:27:18 -07:00
  • 8b6b26ad75 Fix unbound config typo Tommy 2024-01-26 06:36:59 -07:00
  • ef4d004c52 Add No-Config Tommy 2024-01-16 14:21:28 -07:00
  • 9e687de707 Fix chrony.conf Tommy 2024-01-16 02:29:26 -07:00
  • 57f6171df3 Bug fixes Tommy 2024-01-15 08:49:56 -07:00
  • 2617245427 Remove auditd Tommy 2023-12-31 00:17:47 -07:00
  • 0090193dfc Remove non-functional /etc/issue Tommy 2023-12-18 13:44:17 -07:00
  • 1a4336a20f Firewalld lockdown mode Tommy 2023-12-12 07:40:17 -07:00
  • fdb0e8aac1 Upstream Docker Tommy 2023-12-12 07:31:17 -07:00
  • a74ca44f68 Typo Fix Tommy 2023-12-07 17:07:37 -07:00
  • 1923f85786 Add license notice Tommy 2023-12-06 22:46:17 -07:00
  • 06bc0cce39 Fix missing efi=disable_early_pci_dma Tommy 2023-12-06 15:09:54 -07:00
  • 03fa2b6b8d Bump Butane version to 1.5.0 Tommy 2023-12-06 14:11:25 -07:00
  • cd5cbb61fe Update styling Tommy 2023-12-06 14:10:56 -07:00
  • 7796e161c8 IOMMU Fix Tommy 2023-12-06 13:56:57 -07:00
  • 5201fedaae Run curl unprivileged Tommy 2023-12-02 08:15:27 -07:00
  • 7999d90e6c Fix 990-security-misc path Tommy 2023-11-15 14:18:29 -07:00
  • e7b703615d Fix runsc path Tommy 2023-11-06 18:40:04 -07:00
  • 1c70f5040c Update SSH Key Tommy 2023-11-04 13:54:13 -07:00
  • 0f478ae5d1 Add auditd Thien Tran 2023-11-01 16:09:46 -07:00
  • 447136c03b Update KickSecure configuration paths Thien Tran 2023-10-31 09:23:35 -07:00
  • 7ccba15df9 Mask ctrl-alt-del.target Thien Tran 2023-10-25 16:41:48 -07:00
  • b26e2d7379 Disable CtrlAltDelBurstAction Thien Tran 2023-10-25 16:12:34 -07:00
  • caeeefc990 Mask debug shell Thien Tran 2023-10-25 16:07:17 -07:00
  • ce5d43d097 Typo Fixes Thien Tran 2023-10-25 15:43:51 -07:00
  • e348ca1b9b /etc/issue(.net) Thien Tran 2023-10-25 15:18:07 -07:00
  • c4a0207da6 Update UTM config Thien Tran 2023-10-21 18:11:27 -07:00
  • d2f65d8b2e Remove outdated ZRAM comment Thien Tran 2023-10-11 23:39:44 -07:00
  • 00dfed479b Update README.md Tommy 2023-10-11 23:19:54 -07:00
  • 1498126454 ZRAM Compression Thien Tran 2023-10-11 23:19:11 -07:00
  • e275349bb5 Update README.md Tommy 2023-10-11 23:08:23 -07:00
  • 746ec7425b Update SSH Hardening Thien Tran 2023-10-10 12:29:15 -07:00
  • a99d1f5e1d Update SSH Hardening Thien Tran 2023-10-10 12:05:22 -07:00
  • 3ffaeccc7f Update runtimes Thien Tran 2023-10-10 10:18:35 -07:00
  • 56aec4db80 Change sshd hardening filename Thien Tran 2023-09-07 15:02:25 -07:00
  • 53e864b380 Update SSH Key Thien Tran 2023-08-27 06:25:44 -07:00
  • 4eaf4eee81 Consistency fixes Thien Tran 2023-08-16 03:37:26 -07:00
  • 3ee9f7c9d1 Setup Chrony seccomp filter Thien Tran 2023-08-15 18:23:38 -07:00
  • f66bce02e9 Use 1.1.1.2 for badness enumeration Thien Tran 2023-07-27 04:58:07 -07:00
  • f244a338d0 Fix DNS resolution Thien Tran 2023-06-26 07:21:23 -07:00
  • 40bc7f18b4 Update UTM deployment Thien Tran 2023-06-26 06:29:56 -07:00
  • 4dad452714 Add UTM Ignition Thien Tran 2023-06-26 04:50:15 -07:00
  • b5afd8e0d5 Switch to Cloudflare DNS Thien Tran 2023-06-25 13:19:57 -07:00
  • 45fa68d5c9 Typo fix Thien Tran 2023-06-11 03:48:51 -07:00
  • 05b2df9c8b Use systrap by default Thien Tran 2023-06-08 16:06:20 -07:00
  • b057975c8a Add workspace config Thien Tran 2023-06-08 14:26:54 -07:00
  • 996c4a331e Update Ignition files Tommy 2023-04-15 04:24:16 -04:00
  • af51a505ae Fix gVisor SELinux context Tommy 2023-04-15 04:22:01 -04:00
  • 6a0f4afe1d Add missing sed in-place flag (#1) Robin Ophalvens 2023-04-15 10:05:22 +02:00
  • a71b39940e Unbound systemd overrides affect Service section, not the Unit (#2) Robin Ophalvens 2023-04-12 13:16:14 +02:00
  • 3b845ea7d2 Indentcation fix Tommy 2023-03-29 11:49:12 -04:00
  • 92fc6758d3 Regornaize the postinst service Tommy 2023-03-29 01:07:50 -04:00
  • 6393fd4f75 Allow ICMP Tommy 2023-03-20 13:59:24 -04:00
  • 948aaf845d Remove remote filesystems Tommy 2023-03-19 22:05:31 -04:00
  • fd4cd807fc Use runc for watchtower Tommy 2023-03-17 18:45:07 -04:00
  • db59e93bbd Change watchtower schedule Tommy 2023-03-17 18:40:22 -04:00
  • e04ff2250e Enable gvisor updater Tommy 2023-03-16 14:03:16 -04:00
  • e1bb116517 Allow ptrace Tommy 2023-03-16 13:59:34 -04:00
  • 5b9605128f Disable rollout wariness Tommy 2023-03-15 19:07:01 -04:00
  • c593f64c5c Use host network for gVisor Tommy 2023-03-15 19:03:29 -04:00
  • 041b880c09 Fix deletion command Tommy 2023-03-15 03:28:08 -04:00
  • a81fa14ebf Add 5 seconds sleep Tommy 2023-03-15 02:10:09 -04:00
  • 0826c5962c Use gVisor Tommy 2023-03-15 01:38:02 -04:00
  • 30196a1409 Remove do-not-query-localhost Tommy 2023-03-11 11:00:35 -05:00
  • be7393ba04 Update Kicksecure sysctl Tommy 2023-02-04 05:26:13 -05:00
  • b2bfd7df0a Remove unnecessary unbound configs Tommy 2023-01-24 09:10:51 -05:00
  • 73855406f7 Update unbound configuration Tommy 2023-01-24 07:50:03 -05:00
  • c2dc6c9363 Use link for unbound Tommy 2023-01-24 02:33:44 -05:00
  • 3148545adf Enable DNSSEC and DOT Tommy 2023-01-24 01:07:16 -05:00
  • 31d030ef1a Add VerifyHostKeyDNS Tommy 2023-01-18 06:53:12 -05:00
  • 66846eacc7 Use SSHD socket Tommy 2022-12-26 10:17:18 -05:00
  • 28f36ae0aa Typo fix Tommy 2022-12-14 01:41:07 -05:00
  • e91473fe24 Additional hardening Tommy 2022-12-01 14:47:50 -05:00
  • f6393dc6fa Add auto-updater.service to Docker-Compose files Tommy 2022-11-25 02:39:56 -05:00
  • 59fcc5ba77 Requires=network-online.target Tommy 2022-09-16 04:23:35 -04:00
  • b436314d54 kernel.yama.ptrace_scope=3 Tommy 2022-09-16 04:20:37 -04:00
  • 3f3cbd4bd3 Fix invalid config Tommy 2022-09-12 19:01:25 -04:00