A 3-part security series deployed on a live Arch Linux server with 7.3TB shared storage. Covers WireGuard VPN for encrypted remote access, SSH hardening with key-only auth and fail2ban, firewall rules restricting SMB ports to LAN/VPN only, and Bash automation for security operations.
Highlights
- Live production deployment — not a tutorial exercise
- Layered security model separating internet, VPN, firewall, and service tiers
- Automated security scripts: user lifecycle, permission auditing, log monitoring
- Part of a 3-repo series covering VPN, access control, and security automation
