A Hardened System Foundation for the Modern Defender.
Blue Basalt is a manual, multi-phase deployment stack for Debian 13 (Trixie). This repository provides a structured sequence for establishing a hardened system environment—integrating network-level intrusion detection (PSAD), brute-force mitigation (Fail2Ban), and encrypted system alerting (msmtp) alongside a modernized suite of local AI, development, and geospatial tools. It serves as a comprehensive guide for transforming a base OS into a fortified and fully-equipped workstation.
🟦 Phase 1: Repository & System Prep
Configure system sources and install the official Docker engine.
Open the sources list:
sudo nano /etc/apt/sources.listPaste exactly:
deb http://deb.debian.org/debian/ trixie main contrib non-free non-free-firmware
deb http://security.debian.org/debian-security trixie-security main contrib non-free non-free-firmware
deb http://deb.debian.org/debian/ trixie-updates main contrib non-free non-free-firmwareUpdate the package database:
sudo apt update Remove conflicting legacy packages:
sudo apt remove docker.io docker-doc docker-compose podman-docker containerd runc Install requirements and set up the repository:
sudo apt install ca-certificates curl sudo install -m 0755 -d /etc/apt/keyrings sudo curl -fsSL https://download.docker.com/linux/debian/gpg -o /etc/apt/keyrings/docker.asc sudo chmod a+r /etc/apt/keyrings/docker.asc echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/debian trixie stable" | sudo tee /etc/apt/sources.list.d/docker.list > /dev/null Install Docker Engine:
sudo apt update && sudo apt install -y docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin 🟦 Phase 2: Software & Permissions
Deployment of core security tools and firmware.
-
Direct .debs: Install Google Earth Pro and VirtualBox 7.2 using
wgetandsudo apt install ./*.deb -
Master Package List:
sudo apt install firmware-misc-nonfree firmware-realtek build-essential wireshark vlc mpv gimp keepassxc thunderbird hexchat gh nmap arp-scan btop ufw fail2ban flowblade audacity ffmpeg npm qgis librecad kiwix filezilla qbittorrent
-
Wireshark Fix:
sudo dpkg-reconfigure wireshark-commonand select YES.
-
Permissions: Add user to necessary security and virtualization groups:
sudo usermod -aG docker,vboxusers,wireshark,plugdev,dialout $USER
🟦 Phase 3: Deno, Ollama & yt-dlp Configuration
Modern runtimes and media extraction settings.
-
Deno:
curl -fsSL https://deno.land/install.sh | sh
-
Brave:
curl -fsS https://dl.brave.com/install.sh | sh
-
Ollama:
curl -fsSL https://ollama.com/install.sh | sh
Install the latest binary:
sudo wget "https://github.com/yt-dlp/yt-dlp/releases/latest/download/yt-dlp" -O "/usr/local/bin/yt-dlp" sudo chmod +x "/usr/local/bin/yt-dlp" Configure yt-dlp:
mkdir -p ~/.config/yt-dlp && nano ~/.config/yt-dlp/config Paste content exactly:
--js-runtime deno
-f "bestvideo[ext=mp4]+bestaudio[ext=m4a]/best[ext=mp4]/best"
-o "~/Downloads/YouTube/%(uploader)s/%(playlist_title|'Misc')s/%(upload_date)s - %(title)s [%(id)s].%(ext)s"
--embed-metadata
--write-subs
--sub-langs "en.*"
🟦 Phase 4: Secure Mail Transport (msmtp)
Configuring secure system mail alerts.
-
Install:
sudo apt install msmtp msmtp-mta ca-certificates -
Config:
sudo nano /etc/msmtprc -
Settings:
defaults auth on tls on tls_trust_file /etc/ssl/certs/ca-certificates.crt logfile /var/log/msmtp.log account default host smtp.gmail.com port 587 from your-email@example.com user your-email@example.com password your-app-password -
Secure Permissions:
sudo chown root:msmtp /etc/msmtprc
sudo chmod 640 /etc/msmtprc
sudo touch /var/log/msmtp.log
sudo chown root:msmtp /var/log/msmtp.log
sudo chmod 660 /var/log/msmtp.log
sudo usermod -aG msmtp $USER(Note: You must log out and back in for group changes to take effect).
-
Fix AppArmor: Create a local override to allow logging:
sudo nano /etc/apparmor.d/local/usr.bin.msmtp
Add:
/var/log/msmtp.log rwkl,Reload:
sudo apparmor_parser -r /etc/apparmor.d/usr.bin.msmtp
🟦 Phase 5: Log Analysis (Logwatch)
Automated system security reporting.
-
Install:
sudo apt install logwatch -
Override:
sudo mkdir -p /etc/logwatch/conf && sudo nano /etc/logwatch/conf/logwatch.conf -
Paste content:
Output = mail MailTo = your-email@example.com MailFrom = Logwatch Detail = High Range = yesterday Service = All mailer = "/usr/sbin/sendmail -t"
🟦 Phase 6: Active Defense (fail2ban & ufw)
Hardening the network perimeter.
-
Install:
sudo apt install fail2ban ufw -
Config:
sudo nano /etc/fail2ban/jail.local -
Paste Jail Settings:
[DEFAULT] ignoreip = 127.0.0.1/8 ::1 192.168.1.0/24 bantime = 1h findtime = 10m maxretry = 5 destemail = your-personal-email@example.com sender = your-secondary-email@gmail.com mta = sendmail action = %(action_mwl)s [sshd] enabled = true port = ssh logpath = %(sshd_log)s backend = %(sshd_backend)s -
Activate:
sudo systemctl restart fail2ban
sudo systemctl enable --now ufwsudo ufw enablesudo ufw allow ssh
sudo ufw logging medium
🟦 Phase 7: Environment Polish & Cleanup
Optimizing user workflow and removing bloat.
-
Bash Aliases: Add to ~/.bashrc:
alias ai='ollama run gemma4:e2b' alias ytdlp-other='yt-dlp --js-runtime deno --no-config -o "~/Downloads/Videos/%(extractor_key)s/%(uploader|Unknown Uploader)s/%(title)s [%(id)s].%(ext)s"'
-
Cleanup:
sudo apt purge evolution
sudo apt purge yt-dlp
sudo apt autoremove && sudo apt clean -
Verification:
-
Test Mail:
echo "Subject: Stack Test" | sendmail -v your-email@example.com
-
Test Fail2ban:
sudo fail2ban-client status sshd
🟦 Phase 8: Intrusion Detection (psad)
Detecting port scans and suspicious activity.
-
Install:
sudo apt install psad iproute2 -
Config:
sudo nano /etc/psad/psad.conf -
Primary Settings:
- EMAIL_ADDRESSES: your-email@example.com; - HOME_NET: 192.168.1.0/24, 172.17.0.0/16, 10.0.2.0/24, 192.168.56.0/24; - IFCFGTYPE: iproute2; - IPT_SYSLOG_FILE: /var/log/ufw.log; - ALERT_ALL: N; - EMAIL_LIMIT: 5; - MIN_DANGER_LEVEL: 3;
-
Interface Monitoring: Add to bottom of file:
PROTECT_INTERFACE enp2s0,wlp0s20f3; HOME_NET_INTERFACES enp2s0,wlp0s20f3;
-
Start & Check:
sudo psad --sig-update
sudo systemctl restart psad
sudo psad -S