Idempotent VPS hardening for Ubuntu — SSH, firewall, fail2ban, kernel tuning, auditd, SOPS secrets, and optional AI agent workspace security. Dry-run first, lockout protection built in.
-
Updated
Feb 18, 2026 - Shell
Idempotent VPS hardening for Ubuntu — SSH, firewall, fail2ban, kernel tuning, auditd, SOPS secrets, and optional AI agent workspace security. Dry-run first, lockout protection built in.
Automated Debian server post-installation script with intelligent profile-based configuration, VPS-safe security hardening, and granular network protection. Supports multiple firewall engines, Docker integration, and 10 specialized package profiles from minimal to enterprise compliance.
Ansible playbook that applies CIS Benchmark (v4.x) and NSA/CISA hardening controls to Cisco ISR 4000 series routers running IOS XE.
Complete Linux system hardening tool with 12+ security checks - CIS benchmark aligned
Complete Windows security hardening script with 15+ checks - CIS benchmark aligned
Add a description, image, and links to the hardening-script topic page so that developers can more easily learn about it.
To associate your repository with the hardening-script topic, visit your repo's landing page and select "manage topics."