1.2 KiB
1.2 KiB
Objectives
-
To have a secure, private workstation with protection from:
- accidental deletion
- loss
- theft
- remote attacks
- software exploits
- malware
-
To have a secure gaming machine with emphasis on performance
-
To have a secure, private storage server with protection from:
- accidental deletion
- theft
- remote attacks
- software exploits
- malware
-
To have a secure, private hosting solution with emphasis on:
- reliability
- ease-of-backup
- ease-of-restore
Workstation
https://wiki.archlinux.org/title/security
It will use Arch linux.
It must support podman and qemu/kvm.
It will use the standard linux kernel.
-
accidental deletion
- BTRFS with snapshots
-
loss
- BTRFS with backups
-
theft
- luks encryption with tpm2 decryption + secure boot
-
remote attacks
- UFW firewall
-
software exploits
- apparmor with custom profiles
-
malware
- ClamAV with periodic scans
Gaming
Arch will be used as the starting point with the default linux kernel.
Storage
Truenas will handle storage with encrypted partitions.
Hosting
K3S installed on Arch will be the hosting solution starting point.