VM bootstrap bits

Info

Reusable snippets for setting up a new guest — operator dotfiles, ssh bootstrap, disk resize. Salvaged from the old setup notes; the deprecated podman/authentik material moved to archive/.

.bash_aliases

# SYSTEM CONFIGS
alias cl='clear'
alias fb='update-binfmts --disable cli; reset'
alias eb='exec bash'
alias ba='vim ~/.bash_aliases'
alias bh='vim ~/.bash_history'
alias brc='vim ~/.bashrc'
alias vrc='vim ~/.vimrc'
alias up='apt update; apt upgrade -y; apt autoremove -y'
alias ll='cl; pwd; ls -lah --color=always'
alias lll='cl; pwd; ls -lah --color=always | less -R'
alias home='cd ~; cl'
alias temp='cd ~/temp; cl'

# APPS
alias rr=". ranger"

# PYTHON
alias py="python3"

.vimrc

let data_dir = has('nvim') ? stdpath('data') . '/site' : '~/.vim'
if empty(glob(data_dir . '/autoload/plug.vim'))
  silent execute '!curl -fLo '.data_dir.'/autoload/plug.vim --create-dirs  https://raw.githubusercontent.com/junegunn/vim-plug/master/plug.vim'
  autocmd VimEnter * PlugInstall --sync | source $MYVIMRC
endif

call plug#begin(has('nvim') ? stdpath('data') . '/plugged' : '~/.vim/plugged')

Plug 'vim-airline/vim-airline'
Plug 'vim-airline/vim-airline-themes'
Plug 'preservim/nerdtree'

call plug#end()

set number relativenumber
set ignorecase smartcase
set ttimeoutlen=100
set nohlsearch
set tabstop=4 shiftwidth=4 expandtab

noremap <leader>s :source ~/.vimrc<CR>
noremap <leader>n :NERDTreeFocus<CR>
noremap <leader>f :NERDTreeFind<CR>

let g:airline_theme='deus'
set noshowmode

.tmux.conf

set -g mouse on

Wheel scroll enters copy-mode and scrolls the pane’s scrollback instead of emitting Up/Down arrow keys into the application (breaks REPL-style TUIs). Hold Shift for the terminal’s native select/copy.

Operator-side ssh bootstrap

Run on the operator machine to refresh host keys and push dotfiles:

#!/bin/sh
ssh-keygen -f '«OPERATOR_HOME_PATH_1»/.ssh/known_hosts' -R '«PUBLIC_IP»'
ssh-keygen -f '«OPERATOR_HOME_PATH_1»/.ssh/known_hosts' -R '«HOSTNAME»'
ssh -o StrictHostKeyChecking=accept-new «HOSTNAME» "uname -a; exit"
scp .bash_aliases «HOSTNAME»:~/.
scp .vimrc «HOSTNAME»:~/.
scp .tmux.conf «HOSTNAME»:~/.
ssh «HOSTNAME» "cd ~; echo \"export EDITOR=vim\" >> .bashrc; apt update; apt install -y ranger tldr vim; mkdir -p /root/.local/share/tldr; tldr -u; apt upgrade -y; apt autoremove -y; exit"

Guest-side ssh enable (console)

Run in the PVE console to enable ssh into a fresh guest:

apt update
apt install dos2unix -y
apt-get update
apt-get install -y openssh-server
cp /etc/ssh/sshd_config /etc/ssh/sshd_config.BACKUP
cat <<EOF >> "/etc/ssh/sshd_config"
PermitRootLogin yes
PasswordAuthentication yes
EOF
systemctl restart sshd

note

PermitRootLogin yes + PasswordAuthentication yes is convenience- over-hardening — acceptable because guests are unreachable from the internet, but tighten if the model ever changes (TODO).

Disk resize after growing the virtual disk

apt update
apt install -y parted
parted /dev/sda resizepart 1 100%
reboot