Linux SSH hardening baseline that does not lock you out
A practical OpenSSH baseline for reducing password, root-login, forwarding, and brute-force risk while keeping a tested rollback path.
Evergreen defensive playbooks with reasoning, curated snippets, validation checks, and rollback notes.
Prescriptive playbooks with reasoning, snippets, validation checks, and rollback notes.
Showing 1-4 of 4
A practical OpenSSH baseline for reducing password, root-login, forwarding, and brute-force risk while keeping a tested rollback path.
A compact S3 baseline for account-level public access blocking, bucket recovery controls, and evidence that the setting is really applied.
Reduce workflow blast radius with explicit permissions, pinned third-party actions, OIDC deployment credentials, and review around pipeline changes.
A pragmatic Kubernetes baseline: enforce restricted pod behavior where possible, isolate namespaces, and prove workloads still communicate intentionally.