🛡
INFRASTRUCTURE SECURITY OPERATIONS WALLBOARD KIOSK
Autonomous Threat Defense Telemetry · HOST: ssdnode-kitkit
🛡️
Public Attack Surface: 100% Shielded SECURE
All 30 listening ports are strictly isolated by Docker iptables, Tailscale mesh, or localhost. 0 ports exposed directly to public internet.
🛑
Intrusion Shield & UFW Filter ACTIVE
Fail2ban active; 18,120 malicious automated reconnaissance probes dropped by UFW in the past 24 hours.
🔑
SSH Access & Identity Control 0 FAILURES
1,681 authorized Tailscale sessions authenticated in 24h. No brute-force anomalies detected.
🐳
Docker Workload Hardening ISOLATED
10 production containers active. Docker daemon TCP socket (2375/2376) is strictly restricted from external networks.
☁️
Cloudflare Zero Trust Ingress ONLINE
4 HA tunnel connections active (3 edge nodes); 61 exploit probes intercepted at Cloudflare edge in 7 days.
Host System Vitals STABLE
RAM 7% (2.0Gi/30Gi) • Load Avg: 8.39 • Disk: 62G/473G (14% used) • up 2 weeks, 4 days, 22 hours, 56 minutes
Security Posture
SECURE
All controls active
Exposed Ports
0
30 monitored & shielded
UFW Blocks (24h)
18,120
Dropped scanning probes
SSH Failed (24h)
0
1,681 authorized logins
Containers
10
Docker daemon isolated
Tailscale Mesh
11 / 18
Encrypted mesh peers
CF Tunnel
ONLINE
HA edge nodes active
RAM / Load
7% / 8.39
Disk: 62G/473G
📡

Network Attack Surface & Listening Ports

30 Ports Monitored
ufw-docker is ACTIVE: Docker bridge ports bound to 0.0.0.0 are intercepted by iptables DOCKER-USER chain and blocked from external ingress.
Listening AddressService / ProcessSecurity Classification
127.0.0.1:6012cloudflaredLoopback 127.0.0.1
100.80.139.9:22sshdTailscale Mesh
10.0.0.1:22sshdPrivate Network
127.0.0.1:39681agy-binLoopback 127.0.0.1
100.80.139.9:36486tailscaledTailscale Mesh
127.0.0.1:24543moshi-hookLoopback 127.0.0.1
100.80.139.9:18443tailscaledTailscale Mesh
127.0.0.1:22sshdLoopback 127.0.0.1
127.0.0.53%lo:53systemd-resolveLoopback 127.0.0.1
127.0.0.1:34893agy-binLoopback 127.0.0.1
127.0.0.54:53systemd-resolveLoopback 127.0.0.1
0.0.0.0:8080docker-proxyDocker 0.0.0.0 (ufw-docker isolated)
0.0.0.0:8000docker-proxyDocker 0.0.0.0 (ufw-docker isolated)
100.80.139.9:8443tailscaledTailscale Mesh
100.80.139.9:8317cli-proxy-apiTailscale Mesh
0.0.0.0:6001docker-proxyDocker 0.0.0.0 (ufw-docker isolated)
0.0.0.0:6002docker-proxyDocker 0.0.0.0 (ufw-docker isolated)
10.0.1.1:22sshdPrivate Network
0.0.0.0:443docker-proxyDocker 0.0.0.0 (ufw-docker isolated)
0.0.0.0:80docker-proxyDocker 0.0.0.0 (ufw-docker isolated)
[fd7a:115c:a1e0::533b:8b09]:8443tailscaledTailscale Mesh
[fd7a:115c:a1e0::533b:8b09]:43591tailscaledTailscale Mesh
[::]:8080docker-proxyDocker Internal Bridge
[::]:8000docker-proxyDocker Internal Bridge
[::]:6001docker-proxyDocker Internal Bridge
[::]:6002docker-proxyDocker Internal Bridge
[fd7a:115c:a1e0::533b:8b09]:22sshdTailscale Mesh
[::]:443docker-proxyDocker Internal Bridge
[::]:80docker-proxyDocker Internal Bridge
[fd7a:115c:a1e0::533b:8b09]:18443tailscaledTailscale Mesh
🔐

SSH Authentication & Access Audit

0 Failures 1,681 Sessions

🔒 Tailscale SSH Sessions (Recent)

TimeClient IPHostTailscale UserSource Node
09/09 05:43100.123.239.87kitmbp16tagged-deviceskitmbp16
09/09 05:45100.123.239.87kitmbp16tagged-deviceskitmbp16
09/09 10:01100.123.239.87kitmbp16tagged-deviceskitmbp16
09/09 12:36100.123.239.87kitmbp16tagged-deviceskitmbp16
09/09 12:42100.123.239.87kitmbp16tagged-deviceskitmbp16
09/09 12:45100.123.239.87kitmbp16tagged-deviceskitmbp16
09/09 12:58100.123.239.87kitmbp16tagged-deviceskitmbp16
09/09 15:19100.123.239.87kitmbp16tagged-deviceskitmbp16

🔑 External / Host SSH Sessions

TimeClient IPHostPort
09/07 06:1910.0.0.210.0.0.247692
09/07 06:2510.0.0.210.0.0.253134
09/07 06:3110.0.0.210.0.0.233110
09/07 06:3710.0.0.210.0.0.237992
09/07 06:4310.0.0.210.0.0.253322
09/07 06:4910.0.0.210.0.0.259920
09/07 06:5510.0.0.210.0.0.242722
09/07 07:0110.0.0.210.0.0.238526
⚙️

System Workload & Process Monitor

Top Consumers
High CPU (>50%):
UserPIDCPUCommand
root1713216158%/root/.local/bin/agy-bin
99991750369114%/usr/local/bin/php
9999175038485.0%/bin/sh
Memory Allocation Stable: No individual processes exceeding memory bounds.
☁️

Cloudflare Zero Trust Ingress Tunnel

0 Domains Routed
4
HA Tunnels
3
Edge Nodes
98
Errors
0
Sessions

Active Edge PoPs: sin07, sin20, sin21

Ingress HostnameRouting Security
Intercepted Exploits (7 Days): 61 attack signatures blocked at edge.
Exploit SignatureIntercepted Count
Other59
App probe1
AWS credential probe1
🛡️

UFW Threat Intelligence & Inbound Attacks (24h)

18,120 Intercepted Probes
Top Attacking Source IPs
1897 10.0.0.3
   1477 2001
   1325 204.76.203.4
    615 2
    611 77.239.124.253
    517 10.0.1.9
    343 79.124.62.230
    312 79.124.62.134
    262 79.124.62.126
    175 2604
Top Targeted Ports
1901 8000
    882 22
    387 23
    219 3389
    156 3000
    150 1080
    147 2000
    143 1337
    133 4153
     81 8443
🐳

Docker Container Fleet

10 Active Containers
Docker Daemon Isolated: TCP socket (2375/2376) is not exposed to any network.
Container NameRuntime StatusPort Mappings
coolifyUp 2 days (healthy)8000/tcp, 8443/tcp, 9000/tcp, 0.0.0.0:8000->8080/tcp, [::]:8000->8080/tcp
coolify-dbUp 2 days (healthy)5432/tcp
coolify-redisUp 2 days (healthy)6379/tcp
coolify-realtimeUp 2 days (healthy)0.0.0.0:6001-6002->6001-6002/tcp, [::]:6001-6002->6001-6002/tcp
coolify-proxyUp 2 days (healthy)0.0.0.0:80->80/tcp, [::]:80->80/tcp, 0.0.0.0:443->443/tcp, [::]:443->443/tcp, 0.0.0.0:8080->8080/tcp, [::]:8080->8080/tcp, 0.0.0.0:443->443/udp, [::]:443->443/udp
so13t9jiakgbyzwp863dmvzu-103035573499Up 2 days3000/tcp
lijg3ncf0yp8on32jagmeg0yUp 2 days (healthy)5432/tcp
lkn2msiqhoymcuyaa64cnazj-065012572847Up 2 days3000/tcp
ithh2dbx1jyjl6dejr3mre1kUp 2 days (healthy)5432/tcp
enthri8p43s4atofatobcunp-232449789422Up 2 days3000/tcp
🌐

Tailscale Encrypted Mesh Network

11 / 18 Peers Online
Node NameTailscale IPOS PlatformStatus
ssdnode THIS MACHINE100.80.139.9linuxOnline
box100.86.226.66linuxOnline
contabo100.111.135.6linuxOnline
glkvm100.123.198.85linuxOnline
hkrouter100.66.31.7linuxOnline
ipad13tv100.117.146.121iOSOnline
ipadpro100.65.224.43iOSOnline
iphone-14-pro-max100.92.136.103iOSOnline
iphoneair100.95.106.126iOSOnline
kitai100.97.4.90linuxOnline
kitmbp16100.123.239.87macOSOnline
tencent100.109.227.19linuxOnline
appletv100.108.161.6tvOSOffline
kit100.66.166.71macOSOffline
kitlegiongo100.67.231.89windowsOffline
kits-macbook-air100.127.101.27macOSOffline
mobilerouter100.127.101.21linuxOffline
node100.97.174.121iOSOffline
virtualkit100.88.89.61macOSOffline
🧱

Firewall Access Control Policy (UFW • 12 Active Rules)

Policy Enforced ↓
Rule / ProtocolActionInterfaceSource MatchRule Note
41641/udpALLOWAnywhere
22/tcpALLOWtailscale0AnywhereSSH via Tailscale only
AnywhereALLOWtailscale0Anywhere
60000:61000/udpALLOWtailscale0AnywhereMosh via Tailscale
22/tcpALLOWdocker0Anywhere
41642/udpALLOWAnywhereTailscale peer relay
41641/udp (v6)ALLOWAnywhere (v6)
22/tcp (v6)ALLOWtailscale0Anywhere (v6)SSH via Tailscale only
Anywhere (v6)ALLOWtailscale0Anywhere (v6)
60000:61000/udp (v6)ALLOWtailscale0Anywhere (v6)Mosh via Tailscale
22/tcp (v6)ALLOWdocker0Anywhere (v6)
41642/udp (v6)ALLOWAnywhere (v6)Tailscale peer relay
🗄️

Historical Security Audit Archives

98 Reports Preserved