Skip to content

Instantly share code, notes, and snippets.

@fulgorek
Last active May 6, 2016 03:31
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save fulgorek/5384261734d9e8096c40f345e249f929 to your computer and use it in GitHub Desktop.
Save fulgorek/5384261734d9e8096c40f345e249f929 to your computer and use it in GitHub Desktop.
To do in Itamae
ntp ✓
ntpdate ✓
sysstat
molly-guard
rsyslog
ssh (the SSH server) ✓
clamav
freshclam (service should be disabled)
locales ✓
time zone (TZ) ✓
motd (should include tresspassing/private system note)
apt ✓
sysctl
sysfs
haveged (should remove rng-tools)
hostname ✓
disable ipv6 (sysctl and /etc/modules, etc.)
elasticsearch (including clustering)
consul (including clustering)
ruby ✓
nodejs ✓
mounts ✓
iptables (should probably disable ufw)
samhain (or AIDE, etc.)
postfix (including /etc/aliases update)
haproxy
nginx ✓
collectd
awscli ✓
swap ✓
java
jenkins (including the master / slave)
openvpn ✓
netdata
memcached
docker ✓
docker-compose ✓
zfs native
redis (including cluster setup) ✓
skylight
aws-cloudwatch
mongod (including Replica Set setup) ✓
mongoid ✓
graphite
kibana
monit ✓
unicorn ✓
nscd
sudo (should support /etc/sudoers.d include directory)
resolver (/etc/resolv.conf including resolvconf template files)
cloudwatch (from Amazon AWS) ✓
mecab
Also, manage the following files:
/etc/nsswitch.conf
/etc/resolv.conf
/etc/gai.conf (disable IPv6 and favour IPv4)
/etc/fstab (should make shm/tmpfs noexec)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment