my-homelab-configs/security
juvdiaz adb2b921ed Add report-only Lynis host audit 2026-06-29 14:35:12 -06:00
..
README.md Add report-only Lynis host audit 2026-06-29 14:35:12 -06:00
targets.txt Add defensive security scan commands 2026-06-29 14:25:47 -06:00

README.md

Defensive Security Scans

This directory contains defensive scan configuration for the homelab and public website. These checks are for assets owned by this lab only.

Use Jeannie from the Debian homelab host:

./jeannie security-prepare
./jeannie security-scan
./jeannie security-zap
./jeannie security-k8s
./jeannie security-host

The default security-scan runs:

  • Trivy filesystem and IaC/config scans against this repo.
  • OWASP ZAP baseline passive scans against security/targets.txt.

The focused commands are:

  • security-prepare: validate Docker/report prerequisites and pre-pull scanner images.
  • security-zap: OWASP ZAP baseline scan only.
  • security-k8s: kube-bench CIS checks against the kubeadm host.
  • security-host: Lynis host audit summary for Debian. This command is report-only and prints warnings/suggestions.
  • security-trivy: Trivy repo and IaC/config scans only.
  • security-nuclei: low-rate nuclei HTTP exposure scans only.

Reports are written to:

${HOMELAB_STATE_DIR}/security-reports

The ZAP scan uses baseline/passive mode. Do not run active attack scans against public endpoints unless you intentionally schedule a maintenance window and understand the traffic it will generate.

security/targets.txt is the public target allowlist. Keep it limited to services you own.

security-host intentionally does not self-fix Lynis findings. Some hardening recommendations can break SSH access, Docker networking, kubeadm, or public edge routing. Use Lynis output to choose one narrow remediation at a time, then add an explicit Jeannie command for that specific change.