{
  "id": 11893166,
  "title": "I Replaced My Manual 15-Step Linux Hardening Runbook with Ansible",
  "url": "https://urgent.news/2026/10/04/i-replaced-my-manual-15-step-linux-hardening-runbook-with-ansible",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-04T09:31:34.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/pawanshinde/i-replaced-my-manual-15-step-linux-hardening-runbook-with-ansible-3gbk"
  },
  "original_language": "en",
  "account": "In the past, creating a new Linux server involved a repetitive and error-prone manual process. This routine included updating system packages, configuring firewalls, setting up fail2ban, writing Nginx proxy configurations, and verifying services. This process took about 25 minutes per machine. However, as the number of environments grew, so did the tediousness and potential for mistakes. Studies show that over 80% of unauthorized access incidents on internet-facing compute nodes are caused by basic configuration drift and missed hardening steps. To address this issue, the author decided to automate the entire setup using an Ansible playbook, which proved to be a significant improvement. The playbook was designed to enforce a consistent target state for the Linux node, ensuring that all necessary packages were updated, firewalls were correctly configured, and Nginx was set up as a reverse proxy with security headers. The automation target included installing core tools like UFW, Fail2ban, Nginx, curl, htop, and logrotate. The firewall was configured to block all inbound traffic by default, only allowing ports 22, 80, and 443. A custom Fail2ban jail was implemented to protect SSH access. Nginx was set up with standard security headers and a /healthz endpoint for monitoring. The project structure consisted of an inventory file, the main playbook, template files for Nginx and Fail2ban configurations, and a README.md. The inventory.ini defined the target test node and variable overrides. The templates contained Jinja2 templates for configuring Nginx and Fail2ban. The playbook.yml file outlined the entire automation process, including system package updates, package installation, firewall configuration, Fail2ban deployment, and Nginx proxy setup. Handlers were used to ensure services only restarted when necessary. After structuring the project, the author validated the playbook syntax and ran a dry-run before executing it live. The live run showed successful changes, including package updates, firewall configuration, Fail2ban deployment, and Nginx proxy setup.",
  "summary": "Whenever I used to spin up a new Linux server, my manual setup routine was always the same: SSH in, update system packages, configure UFW firewall rules, set up Fail2ban jails, write Nginx proxy configurations with security headers, and verify that services were enabled at boot. Manually running through that checklist took roughly 25 minutes per machine . On a single test box it wasn't a blocker,…",
  "key_points": [
    "Replaced manual 15-step Linux hardening with Ansible playbook",
    "Automated setup ensures consistent target state for Linux nodes",
    "Project includes inventory, playbooks, templates, and README"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}