projects
contact
vicont
EleanorMay
Back

vps-hardening-toolkit

Solo Project DevOps Bash / Python
Automated, zero-dependency production Linux VPS security baseline: nftables firewall, sysctl hardening, SSH certificate enforcement, and auditd monitoring.
Author: vicont • Date: 02.09.2026 • Platform: Debian 12 / Ubuntu 22.04+ / Alpine
Overview (English)
vps-hardening-toolkit is a battle-tested automation script built for rapid deployment on bare-metal and cloud VPS servers. It applies CIS-benchmark aligned hardening profiles in seconds: disabling legacy protocols, locking down OpenSSH, generating restrictive nftables policies, enabling kernel panic protections via sysctl, and configuring Fail2ban jail triggers.
Key Capabilities
✓ Modern nftables Ruleset
Stateful drop-by-default packet filter with SYN flood mitigation and brute-force throttling.
✓ Kernel Sysctl Optimization
Hardens TCP stack against spoofing, enables ASLR, restricts dmesg, and disables core dumps.
✓ OpenSSH Lockdown
Enforces Ed25519 public keys only, disables password authentication, root logins, and weak ciphers.
✓ Unattended Security Updates
Configures automatic upstream security patching and daily reboot triggers if required.
Repository vicont / vps-hardening-toolkit
Language Bash / POSIX sh / Python 3
Dependencies Zero external dependencies
License MIT