Urgent.News

What's breaking now, across thousands of outlets.

Tech

I Replaced My Manual 15-Step Linux Hardening Runbook with Ansible

Whenever I used to spin up a new Linux server, my manual setup routine was always the same: SSH in, update system packages, configure UFW firewall rules, set up Fail2ban jails, write Nginx proxy configurations with security headers, and verify that services were enabled at boot. Manually running through that checklist took roughly 25 minutes per machine . On a single test box it wasn't a blocker,…

In the past, creating a new Linux server involved a repetitive and error-prone manual process. This routine included updating system packages, configuring firewalls, setting up fail2ban, writing Nginx proxy configurations, and verifying services. This process took about 25 minutes per machine. However, as the number of environments grew, so did the tediousness and potential for mistakes.

Studies show that over 80% of unauthorized access incidents on internet-facing compute nodes are caused by basic configuration drift and missed hardening steps. To address this issue, the author decided to automate the entire setup using an Ansible playbook, which proved to be a significant improvement. The playbook was designed to enforce a consistent target state for the Linux node, ensuring that all necessary packages were updated, firewalls were correctly configured, and Nginx was set up as a reverse proxy with security headers.

The automation target included installing core tools like UFW, Fail2ban, Nginx, curl, htop, and logrotate. The firewall was configured to block all inbound traffic by default, only allowing ports 22, 80, and 443. A custom Fail2ban jail was implemented to protect SSH access. Nginx was set up with standard security headers and a /healthz endpoint for monitoring.

The project structure consisted of an inventory file, the main playbook, template files for Nginx and Fail2ban configurations, and a README.md. The inventory.ini defined the target test node and variable overrides. The templates contained Jinja2 templates for configuring Nginx and Fail2ban. The playbook.yml file outlined the entire automation process, including system package updates, package installation, firewall configuration, Fail2ban deployment, and Nginx proxy setup.

Handlers were used to ensure services only restarted when necessary. After structuring the project, the author validated the playbook syntax and ran a dry-run before executing it live. The live run showed successful changes, including package updates, firewall configuration, Fail2ban deployment, and Nginx proxy setup.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Linux Buddy: A Linux Learning Buddy for Students 🐧

This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend What I Built I built Linux Buddy, a simple learning assistant for students who are starting with Linux.

  • Linux Buddy assists students new to Linux
  • Focuses on learning concepts, troubleshooting, labs, interviews
  • Uses open-source Gemma model for AI functionality

How to reliably identify trustworthy websites

As online fraud increases, these signals help you find reputable providers. Look for a legal notice, privacy policy, secure payment, licenses and fair terms and conditions.

  • Legitimate websites display full company name, address, contact info, registration number, VAT ID
  • Review privacy policy for vague language, different company names, unclear data storage
  • Use secure payment methods with buyer protection, avoid prepayment or cryptocurrencies

Team Kenya Robotics Departs for South Korea for 2026 FIRST Global Challenge

Team Kenya Robotics has departed for Incheon, Republic of Korea, where it will represent the country at the 2026 FIRST Global Challenge.

  • Team Kenya Robotics heads to South Korea for 2026 FIRST Global Challenge
  • Cabinet Secretary William Kabogo flags off the team for international competition
  • Team aims to represent Kenya with pride in "Igniting Innovation" theme

More from Sunday 4 October →