removed more ts bs
This commit is contained in:
@@ -18,20 +18,6 @@ DEBIAN_FRONTEND=noninteractive apt install -y \
|
|||||||
unattended-upgrades \
|
unattended-upgrades \
|
||||||
apt-listchanges
|
apt-listchanges
|
||||||
|
|
||||||
# Create non-root user
|
|
||||||
#if ! id "$USERNAME" &>/dev/null; then
|
|
||||||
# useradd -m -s /bin/bash -G sudo "$USERNAME"
|
|
||||||
# echo "$USERNAME ALL=(ALL) NOPASSWD:ALL" > /etc/sudoers.d/$USERNAME
|
|
||||||
# chmod 0440 /etc/sudoers.d/$USERNAME
|
|
||||||
#fi
|
|
||||||
|
|
||||||
## SSH key for user
|
|
||||||
#USER_HOME="/home/$USERNAME"
|
|
||||||
#mkdir -p "$USER_HOME/.ssh"
|
|
||||||
#echo "$SSH_PUBLIC_KEY" > "$USER_HOME/.ssh/authorized_keys"
|
|
||||||
#chmod 700 "$USER_HOME/.ssh"
|
|
||||||
#chmod 600 "$USER_HOME/.ssh/authorized_keys"
|
|
||||||
#chown -R "$USERNAME:$USERNAME" "$USER_HOME/.ssh"
|
|
||||||
|
|
||||||
# SSH hardening
|
# SSH hardening
|
||||||
cat > /etc/ssh/sshd_config.d/hardening.conf << 'EOF'
|
cat > /etc/ssh/sshd_config.d/hardening.conf << 'EOF'
|
||||||
@@ -139,11 +125,4 @@ EOF
|
|||||||
|
|
||||||
sysctl -p /etc/sysctl.d/99-security.conf
|
sysctl -p /etc/sysctl.d/99-security.conf
|
||||||
|
|
||||||
## Tailscale (optional)
|
|
||||||
#if [ -n "$TAILSCALE_AUTH_KEY" ]; then
|
|
||||||
# curl -fsSL https://tailscale.com/install.sh | sh
|
|
||||||
# tailscale up --authkey="$TAILSCALE_AUTH_KEY" --ssh
|
|
||||||
# echo "Tailscale installed and connected"
|
|
||||||
#fi
|
|
||||||
|
|
||||||
echo "=== Cloud-init completed at $(date) ==="
|
echo "=== Cloud-init completed at $(date) ==="
|
||||||
Reference in New Issue
Block a user