Secure VPS Infrastructure Initialization (7 Nodes)

Job ID: 39578720

Budget: $30 – $250 USD

I DO NOT ACCEPT PLACEHOLDER BIDS. DO NOT, I REPEAT,.DO NOT PUT IN PLACEHOLDER BIDS.

Objective:
You will provision and deploy a fully hardened server setup across 7 VPS instances:

1 primary node

5 worker nodes

1 backup node


Your sole role is to execute the provided scripts to harden and configure each server based on strict security parameters and infrastructure requirements. The application layer is not your concern.


---

Scope of Work

1. Provision or access 7 clean VPS instances


2. For each server, execute the provided setup script which will:

Install core OS packages

Set strict file and process-level permissions

Configure iptables firewall

Deploy WireGuard and configure secure mesh networking

Set up TOR hidden service (on 5 worker nodes only)

Disable root login and enforce key-based access

Set up specific folder structures, environment configs, and logging systems



3. Verification tasks:

Ensure all 7 VPS are hardened and reachable via the secure channel (WireGuard or .onion)

Confirm no open ports or vulnerable services

Send terminal logs and screenshots showing success per node



---

Tech Stack / Dependencies (Installed via script)

Layer Tools / Configurations

OS Alpine Linux 3.18 (minimal)
VPN WireGuard (mesh topology)
Firewall iptables
Privacy Layer TOR (for 5 worker nodes only, using v3 Hidden Services)
Runtime Python 3.12
Core Packages uvicorn, fastapi, web3, redis, cryptography, requests, hdwallet, torpy, etc.
Logging Custom encrypted logging via Fernet encryption
Backup Mechanism rsync or SSH tunnel (production → backup every 6 hours)
Networking Hardened DNS, disabled IPv6, strict WireGuard peer configs
Security All processes run as non-root users, chmod restrictions, no public SSH


All of the above will be preconfigured in the script bundle provided to you.


---
Important Notes

You do not need to develop anything.

You do not need to troubleshoot the codebase or application.

You must not retain copies of any setup after deployment is verified.

All encryption keys, RPC endpoints, tokens, etc., will be inserted manually after your work is complete.



---

Deliverables

Each VPS fully hardened with:

All ports/services strictly controlled

Encrypted log folder in place

VPN interfaces reachable and functional

TOR .onion address generated and shared (for relayer nodes)

Deployment log (script output) + screenshot per VPS showing:

wg show output

systemctl status of key services

IP and hostname verification

Confirmation of blocked inbound ports


Quick summary report of setup confirmation



---
Requirements

Strong Linux sysadmin skills (especially Alpine or Debian minimal)

Experience with WireGuard, iptables, TOR hidden services

Able to complete within 1–2 days once VPS and script are provided

Total discretion



---

What You'll Receive Upon Agreement

Access to the 7 VPS instances (root or sudoer)

Script bundle (ZIP)

Idiot-proof Markdown deployment guide (step-by-step instructions)

Pre-configured WireGuard + TOR configs per node