title: "VPS Self-Hosted Runner Hardening Playbook: Reproducible Architecture for Stall Detection + Production Hardening"
description: "Reproducible architecture for self-hosted GitHub Actions / GitLab / Jenkins runners on a VPS. TCP-level stall detection, 3-layer watchdog, systemd hardening cascade (capabilities, namespaces, kernel locks), auditd + sshd + sysctl layers. Production-tested patterns + 10 cross-cutting lessons learned from a real hardening sweep."
author: "David Mireles (@louzt)"
email: "[email protected]"
license: "MIT-0"
canonical_repo: "https://github.com/LOUST-PRO/lzt-broker-stall-reaper"
tags: ["self-hosted-runner", "github-actions", "vps-hardening", "systemd", "stall-detection", "prometheus", "auditd", "sshd", "sysctl", "ci-cd", "devops", "sre", "infosec"]
keywords: ["self hosted runner hardening", "vps hardening playbook", "tcp stall detection", "github actions runner hung", "systemd capability bounding set", "protect system strict", "memory deny write execute v8", "auditd rules", "ss