private-schrijfsels-en-noti.../2025/durian.srv.xor-gate.org.md

569 B

Machine

  • Scaleway Console.net Dedibox 120GB SSD

OS

  • Debian 13 trixie AMD64

Firewall

VPN

Wireguard

SSH

  • Key non-root only (global config)
    • PasswordAuthentication no
    • PubkeyAuthentication yes
    • PermitRootLogin no

Containers

The host OS will be kept clean and all services go into there respective containers. SystemD will be used for frugal container management:

  • systemd-container pkg
  • systemd-nspawn feature