Hardening a Raspberry Pi 5: SSH keys, UFW, fail2ban — and the trap where IPv6 comes back after a reboot
A freshly set up Raspberry Pi 5 is wide open: password auth enabled, no firewall, 172 pending updates. We harden it with SSH key-only auth, UFW, fail2ban, and automatic updates, disable IPv6, and verify it all with real reboots — including the trap where IPv6 comes back after a reboot.