Currently ENABLED — anyone who guesses your root password can SSH in
⏱ 5 min
⚠️ Run on VPS: echo 'PasswordAuthentication no' >> /etc/ssh/sshd_config && systemctl restart sshd — verify key SSH still works before closing terminal.
Rotate Forge API keys
GOOGLE_API_KEY, Supabase service role — if any were ever visible in logs/chat
⏱ 15 min
Enable 2FA on Google account
forge4j@gmail.com — if not already on
⏱ 10 min
📱 Tailscale — Full Access Mode
Enable VPS as Tailscale exit node
VPS advertising exit node — confirmed ✓
✅ VPS configured
Approve exit node in Tailscale admin + test on Chromebook