- arch-setup.sh now takes a fresh Arch box to a locked-down base, nothing else
(omaterm one-shot now lives in the sibling omaserver project)
- Port proven UX from omaserver's install-server.sh: machine name asked once
(hostname + ssh alias), answers persist across the kernel-upgrade reboot
via /root/.arch-setup.conf, reboot offered in-script, public IP detected
early, ufw tailscale0 pre-allow (dormant), default-yes prompts
- MIT license, README with usage + Arch-specific notes
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>