Docker compose hardening — cap_drop, security_opt, resource limits
Install and run Lynis — target score 80+ on all servers
Set up audit logging for tool calls — gateway stdout
Kernel sysctl hardening — ip_forward, accept_redirects, log_martians
✓
Watchman Audit cron — sweeps all 3 servers every 4h ✓
✓
mintgeodude.com v1 — terminal security console live ✓