Phase C: Security & Observability

Phase C: Security & Observability ⚠️ PARTIAL

Optional hardening and observability features. SSH hardening is complete; remaining items are future enhancements that don’t block production operation.

Checklist

Step Status Description Reference

C.1

[ ]

Threat Intelligence (pfBlockerNG replacement)

Phase 7

C.2

[ ]

Suricata IDS

Phase 8

C.3

[ ]

Monitoring Integration (node_exporter, Wazuh)

Phase 9

C.4

[x]

SSH Hardening

Phase 10

C.5

[ ]

API Access

Phase 11

C.6

[ ]

Git Config Tracking

Phase 12

Checkpoint Validation

# Security features operational
ssh vyos-02.inside.domusdigitalis.dev "show log | grep suricata | tail -5"
curl -s http://vyos-02.inside.domusdigitalis.dev:9100/metrics | head -5  # node_exporter