Projects with this topic
-
Ansible baseline for FreeBSD hosts: OS defaults, users, sysctl, chrony, ZFS boot environments, and a single-owner pf firewall that apps extend.
Updated -
Ansible hardening for FreeBSD: SSH and 2FA, sshguard, CrowdSec, OpenBSM audit, AIDE, Lynis. Runs after ansible-base-freebsd, with an at(1) rollback to avoid lockouts.
Updated -
Foreman 3.19 + Katello 4.21 on AlmaLinux 9 via Ansible - content management (repo sync, content views, lifecycle envs), Proxmox-provisioned and hardened.
Updated -
Ansible hardening for Enterprise Linux hosts: SSH/2FA, auditd, AIDE, CrowdSec, fail2ban, scanners, reporting, and rollback safety.
Updated -
Ansible baseline for Enterprise Linux hosts: users, packages, dotfiles, sysctl, dnf-automatic, and nftables.
Updated -
Ansible deployer for a grommunio all-in-one groupware/mail server on openSUSE Leap — MariaDB/redis/TLS/MTA/antispam + all grommunio components, on the acidnetworks.base_suse + hardening_suse collections
Updated -
-
openSUSE Leap Ansible hardening collection: SSH + 2FA, auditd, AIDE, CrowdSec, fail2ban, rootkit scanners, Lynis, with a systemd-timer rollback dead-man's-switch
Updated -
Ansible: self-hosted addy.io (AnonAddy) anonymous email forwarding on Debian 13 - Postfix + rspamd + Laravel, adopts the acidnetworks base/hardening collections.
Updated -
Ansible: self-hosted grommunio groupware (Exchange/M365 alternative) on Debian 13 - mail/calendar/chat/files, adopts the acidnetworks base/hardening collections.
Updated -
Ansible automation to deploy an apt-cacher-ng caching proxy in a Debian Proxmox LXC container.
Updated -
Ansible hardening for Debian 13 hosts: SSH, CrowdSec/fail2ban, auditd/AIDE, sysctl, and PAM 2FA-- lockout-safe, runs after ansible-base-debian
Updated -
Ansible automation to deploy Nextcloud on Debian 13/Proxmox — rootless Podman + Quadlet app tier behind a rootful gVisor-sandboxed Caddy + Coraza WAF edge, mTLS between tiers
Updated -
Ansible: self-hosted ownCloud Infinite Scale (oCIS) on Debian 13 - rootless Podman/Quadlet, Caddy edge, optional Collabora + ClamAV, adopts the acidnetworks base/hardening collections.
Updated -
Ansible: self-hosted KMS (py-kms volume-activation) on Debian 13 — single rootless Podman/Quadlet container, adopts the acidnetworks base/hardening collections.
Updated -
Ansible: self-hosted Seafile (Pro/CE) on Debian 13 - rootless Podman/Quadlet stack, Caddy TLS proxy, optional LDAP/AD, adopts the acidnetworks base/hardening collections.
Updated -
Ansible: self-hosted Ente Photos (E2E) on Debian 13 - rootless Podman/Quadlet app tier, MinIO storage, gVisor + Coraza WAF edge, adopts the acidnetworks base/hardening collections.
Updated -
Ansible: self-hosted Immich (photos) on Debian 13 - rootless Podman/Quadlet app tier, gVisor + Coraza WAF Caddy edge, adopts the acidnetworks base/hardening collections.
Updated -
Ansible baseline for Debian 13 hosts: users, packages, sysctl, auto-updates, and a single-owner nftables firewall apps extend
Updated -