Documentation
¶
Overview ¶
Package securitybaseline renders the canonical Architecture v2 universal host policy script (security-only unattended upgrades and managed kernel parameters). Firewall, sshd and fail2ban are owned per site kind by the Home and Cloud host-security owners, not by this script.
Index ¶
Constants ¶
View Source
const ( EvidenceSchemaVersionArchitectureV2 = "stackkit.security-baseline/v2" EvidenceModeArchitectureV2 = "architecture-v2-foundation" )
Variables ¶
This section is empty.
Functions ¶
func ContractHash ¶
ContractHash returns the canonical sha256-prefixed digest of an exact rendered policy. It can be stored directly alongside a render unit for drift detection.
func RenderV2HostPolicy ¶
RenderV2HostPolicy renders the canonical, self-contained architecture-v2 host policy. Renderers should use this convenience instead of constructing a v2 Config so the policy and its package-manager safety prelude cannot drift.
Types ¶
Click to show internal directories.
Click to hide internal directories.