Harden the Nezha Monitor by Disabling Web SSH (for most)

in #blogyesterday

Last weekend: https://steemit.com/blog/@justyy/nezha-monitor-security-cve-please-update-to-2-0-13-or-above-asap

I have reinstalled and upgraded both the Nezha Agent and Nezha Dashboard to the latest version, 2.2.3.

For security reasons, I have disabled Web SSH on 23 of the 24 servers. The only exception is the Raspberry Pi Model B Rev 2, which has only 400 MB of RAM and is kept as a clean, minimal server with no additional services running.

I intend to use this Raspberry Pi as an SSH jump box. No SSH keys are installed on it, and authentication is handled using a secure password.

Authentication is restricted to a strong password, with additional hardening such as limited users, non-root login, firewall restrictions, and fail2ban/rate limiting.

image.png

Steem to the Moon🚀!

Support me, thank you!

Why you should vote me? My contributions
Please vote me as a witness or set me as a proxy via https://steemitwallet.com/~witnesses

image.png

Sort:  

I'm curious - do you have a plan in place for how you'll handle SSH connections to the Raspberry Pi jump box, such as enabling it for specific users or using a VPN? 🔒🐳