← RETURN TO CITADEL

♜ LINUX HARDENING LAB

SSH CONFIGURATION · FIREWALL RULES · ACCESS CONTROL · SECURITY MONITORING

STATUS: ACTIVE

PROJECT SNAPSHOT

STARTED

May 2026

STATUS

Active and operational

PUBLIC SITE

rootandrook.com

TECH STACK

Ubuntu · SSH · UFW · Fail2Ban · Docker · NGINX · Cloudflare

PROJECT OVERVIEW

The Linux Hardening Lab is the foundation of The Citadel project. It focuses on configuring and securing an Ubuntu Linux environment for remote administration, public hosting, and security operations practice.

IMPLEMENTED CONTROLS

SECURITY VALUE

This lab demonstrates hands-on Linux administration, basic host hardening, firewall management, remote access control, and the beginning of authentication telemetry.

COMMAND AREAS PRACTICED

systemctl status ssh
sudo ufw status verbose
journalctl -u ssh
tail -f /var/log/auth.log
sudo docker ps

CURRENT CAPABILITIES

STATUS

Active and operational. The Linux Hardening Lab serves as the foundation of The Citadel, providing secure remote administration, firewall enforcement, containerized hosting, Cloudflare connectivity, and operational monitoring.

CURRENT CAPABILITIES

NEXT OBJECTIVES

Citadel Project Switchboard

Module Links Active
01 //
Linux Hardening
SSH, UFW, Fail2Ban, permissions, and operating guardrails.
Open Module →
02 //
Cloudflare Tunnel
Secure public access without exposing the VM directly.
Open Module →
03 //
Docker Lab
Containerization practice, deployment notes, and recovery workflows.
Open Module →
04 //
Auth Monitor
Authentication visibility and login monitoring foundation.
Open Module →
05 //
SIEM Sandbox
Security monitoring lab and future detection engineering space.
Open Module →
06 //
Auto Deploy
Automation pipeline for future repeatable deployment workflows.
Open Module →
07 //
Odysseus
AI assistant prototype, RAG memory core, and hardware roadmap.
Open Module →
08 //
B-MAK
Private operations case study using sanitized public-safe data only.
Open Module →