Disable automated start of X after boot
sudo systemctl set-default multi-user.targetAlternatively, if the above does not work:
sudo systemctl enable multi-user.target --force
sudo systemctl set-default multi-user.targetTo re-enable the login GUI:
sudo systemctl set-default graphical.targetDo not clear contents of the console/terminal after boot
mkdir /etc/systemd/system/getty@.service.d
cat >/etc/systemd/system/getty@.service.d/noclear.conf <<EOF
[Service]
TTYVTDisallocate=no
EOF
systemctl daemon-reloadDisable cupsd from starting during boot
Try first by disabling the deamons:
systemctl disable cups.service cups.socket cups-browsed.serviceIf that does not work then you can check why cupsd is starting (even if the service was disabled with "systemctl disable cups") with:
systemctl --reverse list-dependencies cups.serviceIf another service depends on it (e.g. in the case of "cupsd" its start might be triggered by "multi-user.target"), you can still disable it with:
systemctl mask cupsDisable automated "trim"/"discard"
systemctl disable fstrim.timer fstrim.serviceRegenerate "/boot/grub/grub.cfg"
update-grubDisable splash screen
In "/etc/default/grub" (or your own one in "/etc/default/grub.d/99-mygrub.cfg") get rid of "splash" in "GRUB_CMDLINE_LINUX_DEFAULT":
GRUB_CMDLINE_LINUX_DEFAULT="quiet"Display GRUB's menu before booting (suppress hiding it)
Change in "/etc/default/grub"...
GRUB_TIMEOUT_STYLE=hidden...to...
GRUB_TIMEOUT_STYLE=menuConnect from the host to the libvirt's VM tty boot terminal
(this will as well display all VM boot messages)
- In the VM: add the parameter "console=ttyS0" to the list of Linux kernel parameters.
- On the host: execute "virsh console vmcont1"
Disable ssh logins that use passwords
Create the file "/etc/ssh/sshd_config.d/000-MY_CUSTOM_SETTINGS.conf" with e.g. the following:
PasswordAuthentication no
ChallengeResponseAuthentication noWARNING! Usually programs use the last entries of config files if the parameters are present multiple times, but if I remember correctly in the case of ssh it's the opposite (the first entry that is read rules), therefore keep this in mind if you want to override a parameter which is already defined in e.g. the main config file ("/etc/ssh/sshd_config") -> usually in that main config file the "Include /etc/ssh/sshd_config.d/*.conf" should already be located at its very top which would mean that the settings that you define in your custom file would rule, but better to doublecheck.
Don't forget to then restart sshd ("systemd restart ssh")
Make "systemd" delete automatically its old logs
Create a custom directory and copy the original config file into the new directory (to avoid conflicts during upgrades):
mkdir /etc/systemd/journald.conf.d
cp -iv /etc/systemd/journald.conf /etc/systemd/journald.conf.d/000-mycustom-journald.confEdit "/etc/systemd/journald.conf.d/000-mycustom-journald.conf" and change the parameter "MaxRetentionSec" (valid suffixes are "s" / "m" / "h" / "d" / "w" / "month" / "year"):
MaxRetentionSec=11dFinally enable the changes with:
systemctl restart systemd-journald