Skip to content

task: measure the resource cost of the host-hardening baseline #20

Description

@tucktuck101

Parent PRD

#5

Objective

Produce a report, attached to this issue, recording the memory, disk and CPU overhead that a minimum internet-facing hardening baseline adds to a host with the cohort VPS's specification.

Definition of done

  • The baseline under measurement is stated as an explicit package list before any measurement is taken
  • Steady-state RSS is recorded for each added service individually, not only as a total
  • Peak memory during an unattended-upgrades run is recorded — this is a spike rather than a steady cost, and is the measurement most likely to change the sizing verdict
  • Peak memory is recorded with the hardening baseline and the full Buzz stack running together, since that combination is what the VPS must survive
  • Additional disk consumed by the baseline, including log and journal growth over a stated observation window, is recorded
  • The report states whether the combined footprint fits 1.9 Gi with 496 MB of swap, citing measurements rather than judgement
  • Every measurement is taken on the spec-matched VM and the method is reproducible by a reviewer
  • Any component in the stated baseline that was not measured is listed as unmeasured

Impacted components

launchpad/deploy/    will consume this report when host hardening is automated

No repository files change — this issue produces evidence, not code.

Out of scope


Filed by an AI agent (Claude Opus 5) on behalf of @tucktuck101. Parented to #5 rather than #2 because #2 lists hardening as an explicit non-goal and defers it here; measuring what hardening costs is not "security controls as code", so it does not pre-empt #5's implementation scope either. Its output is what makes the sizing verdict for #2 trustworthy. Drafted, not executed — no measurement here has been run. Reparent if the cohort would rather this sat under #2.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:deployVPS, Ansible, host configuration, hardeningby:agentFiled or authored by an AI agent, not a humantype:taskBounded work with no children of its own. The default type.wontfixThis will not be worked on

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions