127 lines
5.0 KiB
Markdown
127 lines
5.0 KiB
Markdown
# Scripts: DevOps Toolbox
|
|
|
|
A personal collection of standalone scripts for Linux server and desktop management:
|
|
diagnostics, first-time server and workstation setup, routine cleanup, and an
|
|
inference server deployment. Every script is Perl, every one runs on the interpreter's
|
|
own builtins, and none of them needs a module installed beside it.
|
|
|
|
## Features
|
|
|
|
- **Diagnostics**: `network-diag.pl` measures latency, packet loss, DNS resolution,
|
|
MTU and dual-stack reachability and grades the connection; `system-diag.pl` reads
|
|
the whole machine (CPU, memory, disk, network, GPU, services, security, performance)
|
|
and grades its health.
|
|
- **Security audit**: `security-audit.pl` grades the machine's defences A to F from the
|
|
state it is actually in: the effective sshd configuration, the running firewalld
|
|
checked against the sockets that really listen, SELinux now and at the next boot,
|
|
pending security updates, accounts and sudo, kernel hardening, and an opt-in deep
|
|
scan of the file system. A critical finding is a non-zero exit, so a cron job fails
|
|
loudly.
|
|
- **Setup**: `server-setup.pl` takes a fresh server to a working state (packages,
|
|
firewall with the SSH rule verified before the service is enabled, SELinux, Podman,
|
|
automatic updates); `workstation-setup.pl` sets up a Fedora desktop (Brave, the
|
|
official Go toolchain, Rust, GoLand, Flatpak applications, firewall, SELinux).
|
|
- **Deployment**: `sglang-deploy.pl` puts an SGLang inference server on an AMD GPU
|
|
behind nginx with HTTPS and an API key, runs the engine from the project's ROCm
|
|
container image, and downloads the model weights from ModelScope.
|
|
- **Maintenance**: `system-optimise.pl` removes old kernels (the running one and one
|
|
fallback always stay), vacuums journals, clears temporary files and core dumps, and
|
|
audits the installed packages against their repositories.
|
|
- **Idempotent by construction**: every operation checks the current state before
|
|
acting, so a second run reports what is already in place and changes nothing.
|
|
|
|
## Install
|
|
|
|
The scripts are single files. Take the repository, or take one script with `curl`:
|
|
|
|
```sh
|
|
git clone https://sourcedock.dev/petrbalvin/scripts.git
|
|
cd scripts
|
|
```
|
|
|
|
Requirements: Perl, which every supported system ships. Nothing else: the scripts
|
|
drive the system's own tools (`dnf`, `systemctl`, `podman`, `openssl`, `curl`) rather
|
|
than carrying a library layer, and where a language has no builtin for a job the
|
|
script does the work itself.
|
|
|
|
## Quick start
|
|
|
|
```sh
|
|
# Network diagnostics, no root needed
|
|
perl network-diag.pl
|
|
|
|
# System health, no root needed
|
|
perl system-diag.pl
|
|
|
|
# Security audit, deeper answers as root
|
|
sudo perl security-audit.pl --deep
|
|
|
|
# Server setup, as root
|
|
sudo perl server-setup.pl --dry-run
|
|
|
|
# SGLang on an AMD GPU, as root
|
|
sudo perl sglang-deploy.pl --model ZhipuAI/GLM-5.3
|
|
```
|
|
|
|
Any script can also be fetched and run in one step:
|
|
|
|
```sh
|
|
curl -sSf https://petrbalvin.org/scripts/system-diag.pl | perl
|
|
```
|
|
|
|
#### Integrity verification
|
|
|
|
A single `SHA256SUMS` file covers every published script. Verify before running:
|
|
|
|
```sh
|
|
curl -sSfO https://petrbalvin.org/scripts/server-setup.pl
|
|
curl -sSfO https://petrbalvin.org/scripts/SHA256SUMS
|
|
sha256sum -c --ignore-missing SHA256SUMS
|
|
sudo perl server-setup.pl --dry-run
|
|
```
|
|
|
|
## Usage
|
|
|
|
Each script documents its own flags; `--help` prints them and `--dry-run` shows what
|
|
a change would do without doing it.
|
|
|
|
| Script | Version | Purpose |
|
|
|---|---|---|
|
|
| `network-diag.pl` | 2.0.0 | Network latency, DNS, MTU, packet loss and dual-stack on Linux and FreeBSD |
|
|
| `system-diag.pl` | 2.0.0 | System health with a grade from A to F. Linux only |
|
|
| `security-audit.pl` | 2.0.0 | Security posture with a grade from A to F and an exit code for cron. Linux only |
|
|
| `server-setup.pl` | 2.0.0 | Server initial setup for Fedora, CentOS Stream and openEuler |
|
|
| `workstation-setup.pl` | 2.0.0 | Fedora desktop setup |
|
|
| `sglang-deploy.pl` | 2.0.0 | SGLang inference server on an AMD GPU, behind nginx with HTTPS |
|
|
| `system-optimise.pl` | 2.0.0 | System cleanup; refuses rpm-ostree systems |
|
|
|
|
The full flag reference is in [docs/CLI.md](docs/CLI.md).
|
|
|
|
## Development
|
|
|
|
```sh
|
|
perl -c network-diag.pl # every script compiles
|
|
perl tests/network-diag.pl # that script's checks
|
|
perl tests/system-diag.pl # and so on for each script
|
|
```
|
|
|
|
The local gates are the syntax check, the seven test files, the licence header and the
|
|
punctuation rule; the container rigs that verify a script against a real system are
|
|
described in [docs/DEVELOPMENT.md](docs/DEVELOPMENT.md). See
|
|
[CONTRIBUTING.md](CONTRIBUTING.md) for how to contribute.
|
|
|
|
## Documentation
|
|
|
|
- [docs/ARCHITECTURE.md](docs/ARCHITECTURE.md): the shared shape of the scripts and
|
|
what each one owns
|
|
- [docs/CLI.md](docs/CLI.md): every flag of every script
|
|
- [docs/DEPLOYMENT.md](docs/DEPLOYMENT.md): how the scripts are published, and what
|
|
they deploy on a host
|
|
- [docs/DEVELOPMENT.md](docs/DEVELOPMENT.md): prerequisites, commands and verification
|
|
|
|
## Licence
|
|
|
|
MIT. See [LICENSE](LICENSE).
|
|
|
|
Copyright © 2026 [Petr Balvín](https://petrbalvin.org)
|