Add the files that land in the image, organised as layered rootfs trees (base first, then the edition layer wins on conflict). - base: hardened kernel cmdline + sysctl, default-deny nftables, key-only ssh, persistent journald, module blacklist, no core dumps, snapshot timer units, motd. - server: Prometheus + auto-provisioned Grafana + Loki + promtail. - workstation: dev profile and desktop sysctl relaxations (perf, rootless containers). - cloud: cloud-init provisioning config.
9 lines
267 B
Plaintext
9 lines
267 B
Plaintext
|
|
Welcome to Arcline OS
|
|
|
|
Secure by default. Zero telemetry. Self-hosted by principle.
|
|
|
|
* hardening guide: man arcline-hardening (or docs/hardening.md)
|
|
* manage snapshots: arcline-snapshot snapshot|list|prune
|
|
* check firewall: nft list ruleset
|