It should be based on local SSH key & some dummy password (though hopefully I shouldn't need it). Or, just setup teleport and skip the ssh part - [ ] Setup SSH based on local public key OR setup teleport and skip the ssh part - [ ] basic UFW config - [ ] disable password auth - [ ] unattended-upgrades - [ ] install docker & docker-compose