iptables/netfilter firewall for Linux servers with stateful filtering, trust system, ipset block lists, SYN flood protection, VNET per-IP policies, and Docker support
-
Updated
Apr 24, 2026 - Shell
iptables/netfilter firewall for Linux servers with stateful filtering, trust system, ipset block lists, SYN flood protection, VNET per-IP policies, and Docker support
This script automates the scanning process using the OpenSCAP Security Guid to hardening Ubuntu systems, aligning with DISA-STIG compliance for Ubuntu 24.04. LTS minimum. It includes a range of security enhancements and configurations designed to strengthen the security posture of Ubuntu servers.
🧑💻 A comprehensive guide to Linux system administration, covering: 📜 Commands 👥 User Management 🌐 Networking 🔐 Permissions 📦 Package Management 💽 Disk Management 🛡️ Security 🤖 Automation ✅
Idempotent VPS hardening for Ubuntu — SSH, firewall, fail2ban, kernel tuning, auditd, SOPS secrets, and optional AI agent workspace security. Dry-run first, lockout protection built in.
An nftables configuration file with layer 7 filtering and DDoS protection for a Minecraft server. Includes rules for blocking fake sessions, query floods, and bot attacks, as well as filtering for IP addresses and port numbers.
Automated, hardened OpenClaw setup for Ubuntu 24.04 VPS
Security hardening kit for OpenClaw servers. UFW firewall, fail2ban, Tailscale-only access, unattended upgrades, exposure verification.
WordPress security benchmark: prescriptive full-stack hardening controls for current supported WordPress releases on Linux.
Ghost-mode transformation for cloud servers with extreme kernel tuning and zero-bloat philosophy.
Harden a VPS and deploy self-hosted apps in one command.
Coleta read-only para hardening, capacidade e plano de acao.
Harden Linux and Windows origins so HTTP(S) traffic only comes from Cloudflare IP ranges, with nftables, Windows Firewall, and safe apply/update/revert flows.
One-command Ubuntu Server hardening to achieve cutting-edge security, with ZERO ongoing maintenance required.
Ansible infrastructure-as-code for Linux server provisioning, hardening, and lifecycle management. 27 production-ready roles covering security, networking, databases, VPN, monitoring, and automated upgrades across Debian, RedHat, OpenBSD, FreeBSD, and macOS.
Comprehensive POSIX shell server hardening toolkit with automatic rollback, SSH safety, and Ansible automation for Debian-based systems
Strengthen the security of your Ubuntu system with this powerful hardening tool based on CIS benchmarks.
One-command Linux server audit. Security score, fix commands included. Bilingual EN/RU.
Linux server hardening
Automated, Military-Grade Infrastructure as Code (IaC) blueprint for provisioning Zero-Trust Linux VPS. Features integrated out-of-band monitoring (Prometheus/Grafana), Tailscale VPN, and CrowdSec AI. Engineered by Nexlogiq AI
Automated Linux server provisioning, hardening, and configuration with a structured, role-based workflow.
Add a description, image, and links to the server-hardening topic page so that developers can more easily learn about it.
To associate your repository with the server-hardening topic, visit your repo's landing page and select "manage topics."