The Secure Way
Linux hosts, the secure way
SSH, sudo, firewalls, mount options, updates and the host basics every engineer should get right.
17 guides
- Auditing a host after a break-in, the secure wayWhat to check on a Linux host you think is compromised: UID 0 accounts, SSH keys, cron, setuid files, changed package files and disguised listeners.
- Container hosts: rootless containers, the secure wayRun containers without root on the host: rootless Podman with subordinate UID ranges, user namespaces, and why the docker group is root. Tested with a real UID map.
- Finding and removing setuid binaries, the secure wayList every setuid, setgid and file-capability binary on a Linux host, remove the ones you do not need, and keep them removed after upgrades with dpkg-statoverride.
- Hunting secrets on a host, the secure wayFind the passwords, tokens and private keys lying around a Linux host: .env files, shell history, process environments, Docker configs and git history. Tested.
- Kernel sysctl hardening, the secure wayA commented sysctl.d file that hides kernel pointers, limits BPF, ptrace and perf for users, and blocks redirects, plus the ip_forward ordering trap. Tested.
- Linux users, groups and file permissions, the secure wayShare files between Linux users without chmod 777: a group-owned setgid directory, the sticky bit, one ACL for a service, and an audit for world-writable files.
- Log review with journalctl, the secure wayReview Linux logs with journalctl: persistent storage, auth and priority filters, trusted fields that expose fake entries, access control, and log sealing.
- Mount options: noexec, nosuid, nodev, the secure wayMount /tmp, /var/tmp, /dev/shm and /home with noexec, nosuid and nodev, and learn what each option stops and what it does not. Tested with findmnt and real escapes.
- nftables default-drop firewall, the secure wayA default-drop nftables ruleset for a Linux server: established traffic, ICMP, SSH from admin networks only, one public port. Tested with real probes.
- Package repository keys and version locks, the secure wayAdd third-party apt repositories with a Signed-By key scoped to that repo, pin what they may install, and lock versions with apt-mark hold or dnf versionlock.
- Scoped sudo rules, the secure wayWrite sudoers rules that give exact commands, not root: no wildcards in arguments, sudoedit for files, NOEXEC as a backstop. Tested with sudo -l and escapes.
- Secure shell scripts, the secure wayWrite Bash scripts that fail safely: set -Eeuo pipefail, quoted variables, ${var:?} before rm, mktemp, globs instead of ls, input checks, and ShellCheck in CI.
- SSH server hardening, the secure wayHarden sshd_config with a drop-in file: keys only, no root login, one allowed group, no forwarding. Proven with sshd -T, including the first-value-wins trap.
- systemd service sandboxing, the secure waySandbox a systemd service with DynamicUser, ProtectSystem=strict, no capabilities and a syscall filter, and gate it in CI with systemd-analyze security --offline.
- Time sync and why security needs it, the secure wayWhy TLS, Kerberos, TOTP and log timelines break when clocks drift, and how to run chrony with NTS-authenticated servers and minsources. Tested with chronyc.
- umask and login.defs, the secure waySet UMASK 027 and HOME_MODE 0700 in login.defs, enable pam_umask so logins use it, and set UMask= for services. Tested on Debian 12 with real file modes.
- Unattended security upgrades, the secure wayInstall security updates automatically with unattended-upgrades on Debian and Ubuntu and dnf-automatic on RHEL and Rocky, with reboots handled. Tested with dry runs.
T Academy
Every guide here is taught hands-on in Foundation: Linux 1, Linux 2 and Linux 3: a real host in your browser, and every objective checked on the machine.
Start free