Files
linux-sysadmin-journey/projects/01-homelab-setup
2025-02-09 00:31:34 -06:00
..
2025-02-08 23:27:46 -06:00
2025-02-09 00:31:34 -06:00
2025-02-09 00:31:34 -06:00
2025-02-09 00:31:34 -06:00

Project 1: Home Lab Setup

Project Overview

This project documents the setup of a basic home lab environment using VirtualBox and Ubuntu Server 22.04 LTS.

Environment Details

  • Host System: Windows 11
  • Hypervisor: Oracle VirtualBox
  • Guest OS: Ubuntu Server 22.04 LTS
  • Resources Allocated:
    • CPU: 2 cores
    • RAM: 2GB
    • Storage: 20GB
    • Network: NAT + Host-only adapter

Setup Steps

1. VirtualBox Installation

  • Successfully installed VirtualBox
  • Created project directory structure

2. Ubuntu Server VM Creation

  • Download Ubuntu Server 22.04 LTS ISO
  • Create new VM in VirtualBox
    • Configure VM settings (CPU, RAM, Storage)
    • Configure network adapters
  • Install Ubuntu Server
    • Basic system configuration
    • Network setup

3. Network Configuration

  • Configure NAT adapter for internet access

    1. Verify IP address configuration
    2. Test internet connectivity
      ping 8.8.8.8      # Success
      ping google.com    # Success
      
  • Configure Host-only adapter for direct host communication

    1. Verify second network interface
      ip addr show enp0s8
      # Output shows:
      # inet 169.254.0.2/16 brd 169.254.255.255 scope global enp0s8
      
    2. Test host connectivity
      # Successfully pinged host (169.254.167.242)
      # Round-trip time (RTT) avg: 2.846ms
      
  • Document network configuration:

    • NAT adapter IP (enp0s3): 10.0.2.15/24
    • Host-only adapter IP (enp0s8): 169.254.0.2/16
    • Default gateway: 10.0.2.2
    • Host IP: 169.254.167.242

Current Status

  • NAT adapter: Working (Internet access)
  • Host-only adapter: Working (Host communication)
  • Network connectivity: Verified

Next Steps

Now that networking is configured, we can proceed to:

  1. Basic Security Setup
    • Create non-root user with sudo privileges
    • Configure SSH access
    • Set up UFW firewall

4. Basic Security Setup

  • User Management

    • Created sysadmin user with sudo privileges
    • Enhanced hugh user security
  • SSH Configuration

    • Installed and configured OpenSSH server
    • Implemented key-based authentication
    • Disabled password authentication
    • Applied security hardening settings
  • UFW Firewall Setup

    • Installed and configured UFW
    • Set default policies (deny incoming, allow outgoing)
    • Allowed required services:
      • SSH (port 22)
      • HTTP (port 80)
      • HTTPS (port 443)
      • Host machine access (169.254.167.242)
    • Verified connectivity

5. System Monitoring and Maintenance

  • Monitoring Tools

    • Installed and configured htop
    • Set up Netdata for system metrics
    • Configured Logwatch for log monitoring
  • Maintenance Procedures

    • Implemented backup strategy with rsync
    • Configured automated updates
    • Set up log rotation

Current Status

  • Basic VM Setup: Complete
  • Network Configuration: Complete
  • Security Measures: Complete
  • System Monitoring: Complete

Next Steps

  1. Service Deployment

    • Web server setup (Apache/Nginx)
    • Database server
    • Basic web application
  2. Automation and Scripting

    • Shell scripting basics
    • Automated maintenance tasks
    • System health checks
  3. Advanced Networking

    • DNS configuration
    • Network services
    • Advanced firewall rules

Security Configuration Status

  • User Management
    • Admin user created
    • Sudo privileges configured
  • SSH Access
    • SSH server installed
    • Key-based authentication configured
    • Root login disabled
  • Firewall
    • UFW installed
    • Basic rules configured
    • SSH access allowed

Commands and Configurations

Network Configuration Commands


### SSH Configuration
```conf
# Key SSH configuration settings (/etc/ssh/sshd_config)
PermitRootLogin no
PasswordAuthentication no
AllowUsers admin

UFW Rules

# View UFW status
sudo ufw status verbose

# Basic allowed services
sudo ufw status numbered

Additional Documentation