I assume that the Web Interface should be the primary user interface and only expert should use ssh / smbd ?!
In this case the user has no possibility to close the doors for SMB and ssh. There is an on/off switch for the web-terminal ssh, but no switch to disable ssh from the gui.
I think KODI has here a very good setup possibility to hardening the system: you could enable/disable the sshd/smbd from the gui and even disallow login with passwords ( so use ssh only with PKI)
The smbd on moOde also present the attached music source. While I have my server connected only with NFS to the MoOde devices, the MoOde devices present the NFS share under SMB as a guest (no password required). To access the a music source from moOde, you would not need the smbd running. So there should be also an option to enable/disable the SMB Server on the MoOde HW.
In this case the user has no possibility to close the doors for SMB and ssh. There is an on/off switch for the web-terminal ssh, but no switch to disable ssh from the gui.
I think KODI has here a very good setup possibility to hardening the system: you could enable/disable the sshd/smbd from the gui and even disallow login with passwords ( so use ssh only with PKI)
The smbd on moOde also present the attached music source. While I have my server connected only with NFS to the MoOde devices, the MoOde devices present the NFS share under SMB as a guest (no password required). To access the a music source from moOde, you would not need the smbd running. So there should be also an option to enable/disable the SMB Server on the MoOde HW.