- DOCS/Operations: current-state SUMMARY of the ENTRY deployment (access,
install, egress via Hysteria2, security findings and fixes, risk
assessment, commits/backups, open items), the Hysteria chain manifest
with an OpenVPN Monitor section, reboot test results, and the plan and
rollout records for settings validation and privilege separation.
- Link them from README and DOCS/General/Index.md.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
- Profiler: when not root, render server.conf to the staging dir and let
the root helper validate (directive allowlist) and install it; control
the openvpn service through the helper (doas, fixed commands).
- Add ovpmon-helper and doas rules under DOCS/General/privilege-separation.
- Document the design, rollout, results and limitations.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
- README: short overview, quick start, config table and links.
- DOCS/General: Deployment_Docker.md and Deployment_Native.md (system
services, HTTPS, host hardening); refresh Index.md.
- DOCS/Changes: security hardening, admin username change and egress
via Hysteria2 with results and verification.
- Drop mentions of the built-in admin/password account.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>