{"repo":"HomeSecExplorer/Proxmox-Hardening-Guide","free":true,"listed":false,"github":"https://github.com/HomeSecExplorer/Proxmox-Hardening-Guide","clone":"git clone https://github.com/HomeSecExplorer/Proxmox-Hardening-Guide.git","description":"Security hardening guides for PVE and PBS, built on CIS Debian Benchmark with Proxmox specific best practices.","language":null,"stars":540,"topics":["hardening","pbs","proxmox","proxmox-backup-server","proxmox-ve","pve","security","ceph","cis","debian"],"license":null,"category":"security-tools","readme_excerpt":"Proxmox Hardening Guide The Proxmox Hardening Guide project provides structured, actionable recommendations to secure Proxmox Virtual Environment (PVE 9.x & 8.x) and Proxmox Backup Server (PBS 4.x & 3.x) . These guides are designed for system administrators and security engineers who need step-by-step hardening instructions, compliance alignment with the CIS Debian Benchmark, and best practices for enterprise and homelab deployments . They extend the industry-recognized CIS Debian Benchmark with Proxmox-specific security tasks, practical examples, and real-world best practices. Available Hardening Guides --- Project Status [!WARNING] This project is under active development and some controls are still being validated.\\ Your feedback, testing results, and contributions are strongly encouraged to help improve accuracy, completeness, and reliability. ToDos Some steps are flagged with “Controls have not yet been validated.” If you have a lab environment, I’d love your help testing these and sharing what you find (successes and issues alike). Thank you! PVE 9 guide - items to validate - 1.1.5 - Enable Full-Disk Encryption - 1.2.1.1 - Enable UEFI Secure Boot - 1.2.1.2 - Kernel Lockdown (Integrity Mode) - 1.3 - SDN - 5.3.2 - Rootkit Detection PBS 4 guide - items to validate - 1.1.5 - Enable Full-Disk Encryption (including Ceph OSD impact/performance validation) - 1.2.1.1 - Enable UEFI Secure Boot - 1.2.1.2 - Kernel Lockdown (Integrity Mode) - 1.2.4 - ZFS datasets - 1.2.5 - SMB/CIFS ","default_branch":null,"files":null,"tree":[],"storefront":"/r/HomeSecExplorer","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/HomeSecExplorer/Proxmox-Hardening-Guide/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}