Interactive Linux server automation toolkit — one unified launcher, 39 scripts across 10 categories: system setup, security hardening, databases, app runtimes, cloud panels, network & tunneling, monitoring, observability, CI/CD runners, and AI & agents.
Run scripts individually, use install.sh, or use ./wf, a zero-dependency
portable keyboard-driven dual-pane TUI dashboard. It features live search,
category sidebars, code inspector (v), batch multi-select (b), and runs 100%
portably in-place without polluting system directories or requiring root.
No authentication required — public repo, served via GitHub Pages at scripts.wanforge.asia.
Scripts are organized under script/linux/<category>/, structured so future
macOS or Windows scripts can be added alongside without changing the layout.
- OS: Linux (currently). Scripts live under
script/linux/; macOS/Windows variants would go inscript/macos//script/windows/when added. - Portability: 100% portable. Runs in-place from repo or isolated user-space cache (
~/.cache/wanforge-scripts). No dependencies to install the TUI. - Package manager:
apt,dnf,yum,pacman,zypper, orapk. Some scripts are Debian/Ubuntu only (noted in the table below). - Tools:
curlandsudo(or root). Node.js, Composer, and PM2 install user-local — nosudoneeded for those. - Terminal: interactive TTY (scripts read input from
/dev/tty).
A minimal install may not ship curl. Install it for your distro:
# Debian / Ubuntu
sudo apt update && sudo apt install -y curl
# Fedora / RHEL / CentOS / Rocky / Alma
sudo dnf install -y curl # or: sudo yum install -y curl
# Arch / Manjaro
sudo pacman -Sy --noconfirm curl
# openSUSE
sudo zypper install -y curl
# Alpine
sudo apk add curlIf you are root (e.g. a fresh container/VM), drop the sudo. No package
manager handy? curl usually rides along with wget — see the wget alternative
below.
# Remote one-liner (Zero installation, runs in memory/user-space cache)
curl -fsSL https://scripts.wanforge.asia/install.sh | bash
# Or via cloned repository
./wf # or: ./install.shNo curl? Use wget instead (present on many minimal images):
wget -qO- https://scripts.wanforge.asia/install.sh | bashThe new keyboard-driven TUI provides a dual-pane interface with alternate screen buffering (leaves your terminal prompt 100% clean upon exit):
| Key / Shortcut | Action |
|---|---|
↑ / ↓ / k/j |
Move selection in the active pane |
Tab / ← / → |
Switch focus between Category pane and Tools pane |
Enter |
Run selected script (or focus tools pane from category) |
v |
View Code: Inspect script source in pager without running |
/ or s |
Live Search: Instant real-time filter across all 39 tools |
b |
Batch Mode: Multi-select and run several tools in order |
i |
System Snapshot: Instant audit popup (OS, RAM, CPU, IP) |
1 – 9, 0 |
Direct jump to category index 1 to 10 |
q / Esc |
Cleanly exit back to original shell prompt |
All scripts can also be invoked non-interactively without the TUI:
# List all 39 tools with indices and descriptions
./wf list
# Run a specific script directly by name or global number
./wf setup-motd
./wf docker
./wf 6 # Global #6 (setup-motd)
# Open a category submenu directly (1-10)
./wf 1 # System category
./wf 2 # Security category
# Run a specific script by category & tool number
./wf 1 6 # Category 1 (System), Tool 6 (setup-motd)
# Search tools by keyword non-interactively
./wf search docker
# Server quick status audit
./wf info
# Classic prompt menu fallback (if running on primitive terminal)
./wf --classicSelect scripts to run:
↑/↓ move · SPACE toggle · A all · ENTER confirm · Q quit
── System ──
❯ [✓] install-packages Update system + base essentials (micro, curl, wget, git)
[✓] set-timezone Set timezone (UTC recommended for servers)
[✓] backup-tools Backup manager: S3 / FTP / SFTP — named profiles, cron, dry-run
[✓] sys-troubleshoot Diagnostics & troubleshooting: CPU, RAM, services, OOM, logs, firewall, network
[✓] hardware-info Hardware audit: CPU, RAM, disks, GPU, firmware, NIC, sensors, virt
[✓] setup-motd Custom dynamic SSH login banner (MOTD) with live system KPIs
── Security ──
[✓] install-firewall Install & configure ufw firewall
[✓] firewall-manager Full ufw manager: allow/deny IP/port, multiple, rate-limit
[✓] install-fail2ban Install, optimize & manage Fail2Ban (progressive ban, recidive)
[✓] secure-ssh Harden SSH: audit, port change, root/pw lockdown, SELinux & firewall
[✓] generate-ssh-key Generate an ed25519 SSH key (user-local)
[✓] manage-users Manage Linux users, sudo access & SSH keys
[✓] ssl-toolkit SSL/TLS diagnostics & management: remote/local audit, self-signed SAN, TLS handshake debug, Certbot
── Panel & Console ──
[✓] install-cloudpanel Install CloudPanel CE v2 (Ubuntu 24 only)
[✓] clpctl-manager Manage CloudPanel via clpctl (sites, db, users, certs)
[✓] install-cockpit Install Cockpit web console, plugins, proxy & optimized PCP logger
── Database ──
[✓] install-postgresql Install PostgreSQL + create roles + remote access
[✓] enable-mysql-remote Allow remote MySQL/MariaDB access (sensitive)
[✓] database-toolkit Monitor, optimize, config, datetime (MySQL/PostgreSQL)
── App Runtime ──
[✓] install-nodejs Install Node.js via nvm (user-local) + PM2
[✓] install-python Install Python 3 + pip, venv, dev, pipx
[✓] install-composer Install Composer (user-local, signature-verified)
[✓] setup-pm2-app Configure pm2-logrotate + register an app (ecosystem)
[✓] install-docker Docker Engine & Docker Compose (with UFW security patch & container diagnostics)
── Monitoring ──
[✓] monitor-system CPU, RAM, storage, processes, network (snapshot or realtime)
── Network ──
[✓] net-tools Local/public IP, ports, speedtest, ping, dig, scan
[✓] install-cloudflared Install and configure Cloudflare Tunnel daemon
── Proxmox ──
[✓] proxmox-toolkit PVE: node/VM/CT resources, storage, realtime dashboard
── CI/CD ──
[✓] install-github-runner GitHub Actions self-hosted runner (avoid billed minutes)
[✓] install-gitlab-runner GitLab CI/CD self-hosted runner
── Observability ──
[✓] install-prometheus Prometheus + node_exporter (+ Alertmanager)
[✓] install-grafana Grafana + Prometheus data source
[✓] install-zabbix Zabbix agent or server (official repo)
[✓] install-uptime-kuma Uptime Kuma beautiful self-hosted status page
[✓] install-loki Loki + Promtail log aggregator & forwarding agent
[✓] install-goaccess GoAccess real-time web log analyzer (terminal & HTML daemon)
── AI & Agents ──
[✓] install-ai-agents Modular AI stack: Hermes, Claude Code, AGY, 9Router
[✓] setup-hermes-telegram Setup Telegram bot, user/group whitelist, optimizations
[✓] setup-9router-tunnel Cloudflare Tunnel & custom domain reverse proxy for 9Router
flowchart TD
A(["curl | bash install.sh"])
B["TUI Checkbox Menu\n↑/↓ Space A Enter Q\n─ grouped by category ─"]
C(["bash script.sh"])
D["Management Menu\ninstall · stop · start · restart\nenable · disable · status\nremove-cron · uninstall"]
E(["bash script.sh --flag"])
IW["Install / Configure Wizard\n(interactive prompts)"]
SVC["systemctl action\n(stop / start / restart /\nenable / disable / status)"]
CRON["crontab cleanup\n(user + root)"]
RM["Removal Wizard\n(purge packages,\nrepo, firewall rules)"]
A --> B
B -->|"bash script.sh --install\n(skips management menu)"| IW
C -->|no args| D
D -->|install| IW
D -->|stop · start · restart\nenable · disable · status| SVC
D -->|remove-cron| CRON
D -->|uninstall| RM
E -->|"--stop / --start\n--restart / --enable\n--disable / --status"| SVC
E -->|--remove-cron| CRON
E -->|--uninstall| RM
E -->|"--install (or unknown flag)"| IW
style A fill:#1e3a5f,color:#fff,stroke:#4a9eff
style C fill:#1e3a5f,color:#fff,stroke:#4a9eff
style E fill:#1e3a5f,color:#fff,stroke:#4a9eff
style B fill:#2d4a1e,color:#fff,stroke:#6abf40
style D fill:#2d4a1e,color:#fff,stroke:#6abf40
style IW fill:#3a2d1e,color:#fff,stroke:#bf8c40
style SVC fill:#1e2d3a,color:#fff,stroke:#40a0bf
style CRON fill:#1e2d3a,color:#fff,stroke:#40a0bf
style RM fill:#3a1e1e,color:#fff,stroke:#bf4040
Service scripts (fail2ban, grafana, prometheus, zabbix, cockpit, postgresql) use
systemctlfor stop/start/restart/enable/disable/status. backup-tools and setup-pm2-app have their own action sets (backup engine / pm2 commands). Non-service scripts (nodejs, composer, python, ssh-key) only expose install + uninstall.
Every script shares one verbosity control (defined in lib.sh). Set it with an
environment variable (recommended — it also propagates through the launcher) or
a flag:
| Mode | Shows | How |
|---|---|---|
silent |
Errors and final result only, no banner | MODE=silent · QUIET=1 · -q |
normal |
Banner + info/ok/warn/err (default) | MODE=normal (default) |
verbose |
Normal + extra dbg detail |
MODE=verbose · VERBOSE=1 · -v |
debug |
Verbose + shell trace (set -x) |
MODE=debug · DEBUG=1 · --debug |
# silent (good for automation / cron)
curl -fsSL https://scripts.wanforge.asia/install.sh | MODE=silent bash
# verbose
curl -fsSL .../script/linux/monitoring/monitor-system.sh | VERBOSE=1 bashDRY_RUN=1 (or --dry-run / -n) makes every script print the
state-changing commands instead of running them — defined once in lib.sh, so
it works the same everywhere:
curl -fsSL .../script/linux/security/install-fail2ban.sh | DRY_RUN=1 bash
# → [dry-run] sudo apt-get install -y fail2ban
# [dry-run] sudo systemctl start fail2banDry-run covers system mutations: package managers (install/upgrade/remove),
services (systemctl/rc-service), ufw, sed -i, tee config writes,
timedatectl, file ops, and PostgreSQL VACUUM/REINDEX. Read-only commands
still run so you see real state. A few user-local installs (nvm/Node, Composer,
PM2) and MySQL client mutations execute as normal.
| Variable / flag | Effect |
|---|---|
ASSUME_YES=1 · YES=1 · -y |
ask returns the default answer without prompting (non-interactive) |
LOG_FILE=/path |
Appends a plain-text (no-color) copy of every log line |
NO_COLOR=1 |
Disables colors in any mode |
# fully unattended, dry-run, logged
curl -fsSL .../script/linux/security/install-fail2ban.sh | ASSUME_YES=1 DRY_RUN=1 LOG_FILE=/var/log/wf.log bashNote: ASSUME_YES only fills prompts that have a safe default; password prompts
and free-text inputs (e.g. role names) still need real input or are skipped.
The user-local scripts (install-nodejs, install-composer, setup-pm2-app)
install into a user's home — not the system. When you run them as root, they
ask which user to install for (or set TARGET_USER=<name> / --user=<name>) and
re-run themselves as that user via sudo -u, so Node/Composer/PM2 land in that
user's home. Perfect for CloudPanel site users:
# install Node + PM2 into the CloudPanel site user 'john'
curl -fsSL .../script/linux/runtime/install-nodejs.sh | TARGET_USER=john bashAll menus (launcher and the clpctl / database / firewall managers) are
arrow-key TUIs — ↑/↓ to move, ENTER to select, Q to go back.
Install scripts support sub-commands for granular lifecycle control.
Download the script first (pipe discards $1), then run with a flag:
curl -fsSL .../install-grafana.sh -o install-grafana.sh
bash install-grafana.sh --stop # stop service only
bash install-grafana.sh --disable # stop + disable autostart
bash install-grafana.sh --enable # enable + start
bash install-grafana.sh --restart # restart
bash install-grafana.sh --status # systemctl status (no-pager)
bash install-grafana.sh --remove-cron # remove related cron entries
bash install-grafana.sh --uninstall # full removal (packages, repo, firewall rules)Available flags per script:
| Script | stop | start | restart | enable | disable | status | remove-cron | uninstall |
|---|---|---|---|---|---|---|---|---|
install-fail2ban.sh |
✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
install-grafana.sh |
✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
install-prometheus.sh |
✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
install-zabbix.sh |
✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
install-uptime-kuma.sh |
✓ | ✓ | ✓ | — | — | ✓ | — | ✓ |
install-loki.sh |
✓ | ✓ | ✓ | ✓ | ✓ | ✓ | — | ✓ |
install-goaccess.sh |
✓ | ✓ | ✓ | ✓ | ✓ | ✓ | — | ✓ |
install-cockpit.sh |
✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
install-postgresql.sh |
✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ ⚠ |
install-firewall.sh |
--disable |
--enable |
— | --enable |
--disable |
✓ | ✓ | ✓ |
install-firewall.sh (extra) |
--reload · --reset (wipes all rules) |
|||||||
setup-pm2-app.sh |
✓ | ✓ | ✓ | — | — | ✓ | ✓ | ✓ |
setup-pm2-app.sh (extra) |
--logs (tail app logs) |
|||||||
install-nodejs.sh |
— | — | — | — | — | — | ✓ | ✓ |
install-composer.sh |
— | — | — | — | — | — | — | ✓ |
install-python.sh |
— | — | — | — | — | — | — | ✓ |
enable-mysql-remote.sh |
— | — | — | — | — | — | — | ✓ (rollback) |
secure-ssh.sh |
— | — | — | — | — | — | — | ✓ (restore backup) |
generate-ssh-key.sh |
— | — | — | — | — | — | — | ✓ |
install-cloudpanel.sh |
— | — | — | — | — | — | — | ✓ (manual steps) |
install-docker.sh |
✓ | ✓ | ✓ | ✓ | ✓ | ✓ | — | ✓ |
install-cloudflared.sh |
✓ | ✓ | ✓ | ✓ | ✓ | ✓ | — | ✓ |
install-github-runner.sh |
✓ | ✓ | ✓ | — | — | ✓ | — | ✓ |
install-gitlab-runner.sh |
✓ | ✓ | ✓ | — | — | ✓ | — | ✓ |
Service scripts (--stop/start/restart/enable/disable/status) use systemctl and
operate on all services the script manages (e.g. prometheus also controls
prometheus-node-exporter and prometheus-alertmanager).
--remove-cron scans both the current user's and root's crontab for entries
matching the service name and removes them.
PostgreSQL
--uninstall: prompts twice — once for package removal, once for/var/lib/postgresqldata deletion. Answer carefully.
Each script can also be run directly without the launcher.
# System
curl -fsSL https://scripts.wanforge.asia/script/linux/system/install-packages.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/system/set-timezone.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/system/install-firewall.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/system/backup-tools.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/system/sys-troubleshoot.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/system/hardware-info.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/system/hardware-info.sh | bash -s -- --summary
curl -fsSL https://scripts.wanforge.asia/script/linux/system/hardware-info.sh | bash -s -- --json
curl -fsSL https://scripts.wanforge.asia/script/linux/system/hardware-info.sh | bash -s -- --markdown
# Security
curl -fsSL https://scripts.wanforge.asia/script/linux/security/firewall-manager.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/security/install-fail2ban.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/security/secure-ssh.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/security/generate-ssh-key.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/security/manage-users.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/security/ssl-toolkit.sh | bash
# Panels & consoles
curl -fsSL https://scripts.wanforge.asia/script/linux/cloud/install-cloudpanel.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/cloud/clpctl-manager.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/cloud/install-cockpit.sh | bash
# Databases
curl -fsSL https://scripts.wanforge.asia/script/linux/database/install-postgresql.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/database/enable-mysql-remote.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/database/database-toolkit.sh | bash
# Monitoring & network
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/monitor-system.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/network/net-tools.sh | bash
# Proxmox (run on a PVE node)
curl -fsSL https://scripts.wanforge.asia/script/linux/network/proxmox-toolkit.sh | bash
# CI/CD
curl -fsSL https://scripts.wanforge.asia/script/linux/cicd/install-github-runner.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/cicd/install-gitlab-runner.sh | bash
# Observability stack
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-prometheus.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-grafana.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-zabbix.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-uptime-kuma.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-loki.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-goaccess.sh | bash
# App runtime
curl -fsSL https://scripts.wanforge.asia/script/linux/runtime/install-nodejs.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/runtime/install-python.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/runtime/install-composer.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/runtime/setup-pm2-app.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/runtime/install-docker.sh | bash
# Network & Tunnel
curl -fsSL https://scripts.wanforge.asia/script/linux/network/net-tools.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/network/install-cloudflared.sh | bash
# AI & Agents
curl -fsSL https://scripts.wanforge.asia/script/linux/ai/install-ai-agents.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/ai/setup-hermes-telegram.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/ai/setup-9router-tunnel.sh | bash| Group | Script | Purpose | Sudo | Distro |
|---|---|---|---|---|
| — | install.sh |
Grouped checkbox launcher that runs the other scripts | — | Any |
| System | install-packages.sh |
Update/upgrade system, install base essentials (micro/curl/wget/git) | Yes | Multi |
| System | set-timezone.sh |
Set timezone via timedatectl (default Asia/Jakarta) |
Yes | Any (systemd) |
| System | backup-tools.sh |
Backup manager: S3 / FTP / SFTP — named profiles, cron, dry-run | No | Any |
| System | sys-troubleshoot.sh |
Diagnostics & troubleshooting: CPU, RAM, services, OOM, logs, firewall, net | Yes | Any |
| System | hardware-info.sh |
Hardware audit: CPU, RAM, disks, GPU, firmware, NIC, sensors, virt | Some | Any |
| System | setup-motd.sh |
Custom dynamic SSH login banner (MOTD) with live system KPIs | Yes | Any |
| Security | install-firewall.sh |
Install ufw, open SSH/http/https, add custom ports, enable |
Yes | Mainly Deb/Ubu |
| Security | firewall-manager.sh |
Full ufw manager: allow/deny IP & port, multi-IP, rate-limit | Yes | Any (ufw) |
| Security | install-fail2ban.sh |
Install, optimize & manage Fail2Ban (progressive ban, recidive) | Yes | Multi |
| Security | secure-ssh.sh |
Audit, port change, root/pw lockdown, passwordless sudo, CIS, SELinux/fw | Yes | Any (OpenSSH) |
| Security | manage-users.sh |
Manage Linux users, sudo access, passwords, shells, and SSH keys | Yes | Any |
| Security | generate-ssh-key.sh |
Generate an ed25519 SSH key, fix perms, print public key | No | Any |
| Security | ssl-toolkit.sh |
SSL/TLS diagnostics: remote/local audit, self-signed SAN, handshake, Certbot | Yes | Any |
| Panel & Console | install-cloudpanel.sh |
Install CloudPanel CE v2, choose DB engine, verify checksum | Yes | Ubuntu 24 |
| Panel & Console | clpctl-manager.sh |
Manage CloudPanel via clpctl: sites, db, users, certs, vhosts |
Yes | CloudPanel |
| Panel & Console | install-cockpit.sh |
Install Cockpit + modules, reverse-proxy config, optimized PCP logger, port 9090 | Yes | Debian/Ubuntu/RHEL |
| Database | install-postgresql.sh |
Install latest PostgreSQL (PGDG), create roles, remote access | Yes | Debian/Ubuntu |
| Database | enable-mysql-remote.sh |
Remote MySQL/MariaDB: bind-address, firewall, create users | Yes | Debian/Ubuntu |
| Database | database-toolkit.sh |
Monitor / optimize / config / datetime — MySQL & PostgreSQL | Yes | Any (DB client) |
| App Runtime | install-nodejs.sh |
Install Node.js via nvm (user-local), choose version, PM2 | No | Any |
| App Runtime | install-python.sh |
Python 3 + pip, venv/virtualenv, dev headers, pipx (multi-distro) | Yes | Multi |
| App Runtime | install-composer.sh |
Install Composer to ~/.local/bin, verify signature |
No | Any (needs PHP) |
| App Runtime | setup-pm2-app.sh |
Configure pm2-logrotate + register an app (ecosystem.config.js) | No | Any |
| App Runtime | install-docker.sh |
Container runtimes: Docker & Podman, docker CLI alias/socket, diagnostics, UFW | Yes | Multi |
| Monitoring | monitor-system.sh |
CPU/RAM/storage/processes/network — snapshot or realtime watch | Some | Any |
| Network | net-tools.sh |
Local/public IP, ports, speedtest, ping/traceroute/dig/whois/scan | Some | Any |
| Network | install-cloudflared.sh |
Install & configure Cloudflare Tunnel daemon (named / quick / token) | Yes | Multi |
| Proxmox | proxmox-toolkit.sh |
PVE node/VM/CT resources, storage, cluster, realtime dashboard | Yes | Proxmox VE |
| CI/CD | install-github-runner.sh |
GitHub Actions self-hosted runner as a systemd service (avoid billed minutes) | Yes | Linux |
| CI/CD | install-gitlab-runner.sh |
GitLab CI/CD self-hosted runner manager | Yes | Linux |
| Observability | install-prometheus.sh |
Prometheus + node_exporter + Alertmanager (alerts, notification wizard, audit) | Yes | Debian/Ubuntu |
| Observability | install-grafana.sh |
Grafana (official repo) + datasource/dashboard provisioning, proxy & audit | Yes | Debian/Ubuntu |
| Observability | install-zabbix.sh |
Zabbix 7.0 LTS Server or Agent 2 (official repo, MySQL schema, multi-fw) | Yes | Debian/Ubuntu |
| Observability | install-uptime-kuma.sh |
Uptime Kuma status page & endpoint monitor (Node.js + PM2) | No | Linux |
| Observability | install-loki.sh |
Loki + Promtail log aggregator & forwarding agent | Yes | Debian/Ubuntu |
| Observability | install-goaccess.sh |
GoAccess real-time web log analyzer (terminal & HTML daemon) | Yes | Debian/Ubuntu |
| AI & Agents | install-ai-agents.sh |
Modular AI stack: Hermes, Claude Code, AGY, 9Router, token optimization | Some | Linux |
| AI & Agents | setup-hermes-telegram.sh |
Configure Hermes Telegram Bot: token, whitelist, group policy, 9Router backend | No | Linux |
| AI & Agents | setup-9router-tunnel.sh |
Cloudflare Tunnel & custom domain reverse proxy for 9Router & AI agents | Some | Linux |
- Detects the package manager:
apt,dnf,yum,pacman,zypper,apk. - Grouped checkbox menu (default all on, uncheck to skip): System actions
(update / upgrade / cleanup) plus base essentials —
micro,curl,wget,git,tmux(with tuned~/.tmux.conf). Package names are resolved per distro. - Python lives in
install-python.sh;speedtest-cliis innet-tools.sh.
- Multi-distro. Checkbox: Python 3 interpreter,
pip,venv/virtualenv, dev headers (build C extensions), andpipx(install Python CLI apps isolated). - Resolves package names per distro;
pipxfalls back topip --userwhere the repo has no package, then runspipx ensurepath.
- Sets the timezone with
timedatectlvia an arrow-key menu: UTC (recommended for servers & databases — no DST, consistent logs),Asia/Jakarta, a custom zone, or skip. Best practice: keep the OS and DB in UTC and format to local time in the application. - Databases follow the same rule —
database-toolkit.sh's date/time action reminds you to run MySQL/PostgreSQL in UTC.
-
Multi-destination backup manager. Manages named profiles (
~/.config/wanforge-scripts/backup-profiles/<name>.conf, chmod 600). No global config, no cron clutter. -
Two source types — chosen when adding a profile:
-
Directory / files — syncs a folder (supports home-dir picker with checkbox multi-user selection).
-
Database — dumps the DB then uploads the dump file; supported engines:
Engine Tool Default port Notes MySQL/MariaDB mysqldump3306 --all-databasesor single DB, gzip-compressedPostgreSQL pg_dump/pg_dumpall5432 single DB or all, gzip-compressed SQLite sqlite3(file path) .dumppiped through gzipMongoDB mongodump27017 per-DB or all, tar.gz archive Redis redis-cli6379 BGSAVE→ copies RDB, gzip-compressed
-
-
Encryption — optional per-profile AES-256-CBC (
openssl enc -pbkdf2). Enabled in the wizard; passphrase stored in profile (chmod 600). Encrypted files get.encsuffix. Applied automatically on every run/cron. -
Destination types — same for both directory and DB profiles:
Type Tool Notes s3awsCLI (pip3 install awscli)Custom --endpoint-url→ AWS, IDCloudHost, MinIO, Backblaze B2, etc.ftplftp(apt install lftp)lftp mirror -R(dir) orput(DB dump); SSL: off / explicit / implicitsftprsync(apt install rsync)rsync -avz -e ssh; SSH key path or agent;--deletefor dir profiles -
TUI menu (arrow-key, loops until Q):
- Add profile — source type first (dir or DB), then wizard collects credentials (secrets via masked input, saved securely). For dir: checkbox multi-user home-dir picker. For DB: engine, connection, optional encryption, then destination.
- List — shows every profile with type tag and
source → targetsummary. - Delete — checkbox multi-select, delete multiple profiles at once.
- Run — real transfer for one profile (dir sync or DB dump → upload).
- Run all — all profiles in sequence; DB profiles auto-dump and auto-encrypt before upload.
- Dry-run — simulates (no bytes moved).
- Dump (local) — dumps a DB profile to a local file only, no upload (respects encryption setting).
- Cron — injects a
crontabentry for a profile; runs via--runnon-interactively. - Cron status — shows all active backup cron jobs (current user + root).
-
Wizard defaults are remembered so adding a second profile to the same server skips re-typing.
-
Non-interactive / cron / scripted flags:
# Directory backup bash backup-tools.sh --run web-daily # sync dir → S3/FTP/SFTP bash backup-tools.sh --run-all # run all profiles bash backup-tools.sh --test web-daily # dry-run # DB backup (dump + optional encrypt + upload) bash backup-tools.sh --run mysql-daily # dump MySQL → upload bash backup-tools.sh --run-all # all profiles incl. DB # Dump to local file only (no upload) bash backup-tools.sh --dump mysql-daily # → ~/mysql-daily_20260623_020000.sql.gz bash backup-tools.sh --dump mysql-daily /tmp # custom output dir bash backup-tools.sh --dump-all /backups/local # dump all DB profiles locally # Schedule bash backup-tools.sh --cron mysql-daily 2 # daily at 02:00 bash backup-tools.sh --remove-cron mysql-daily # remove its cron entry # Profile management bash backup-tools.sh --list bash backup-tools.sh --delete old-profile another-profile # run manually (TUI) curl -fsSL https://scripts.wanforge.asia/script/linux/system/backup-tools.sh | bash
-
DB dump filenames include a timestamp — each run creates a new file, old ones are not overwritten:
<profile>_YYYYMMDD_HHMMSS.sql.gz(or.tar.gz,.rdb.gz,.sql.gz.encfor encrypted).
- Diagnostics and troubleshooting utility that checks server health and audits common issues.
- Audits:
- CPU load, RAM usage, swap space, and disk utilization.
- Failed systemd units (
systemctl --failed). - Out-of-memory (OOM) events from kernel ring buffer and logs.
- Nginx error logs (scans
/var/log/nginx/for 502/504 gateways, timeouts, connection refused, or permissions issues and displays recent logs). - Reachability of database ports (checks MySQL 3306 and PostgreSQL 5432 socket listeners).
- Fail2ban status (displays list of jails, active bans, and provides a TUI option to unban any blocked IP).
- Internet connection latency and DNS resolution check.
- Comprehensive read-only hardware audit and system specifications inspector.
- Hardware Coverage:
- CPU: Model, vendor, architecture, sockets, cores, threads, scaling governor, base/max/current frequencies, L1/L2/L3 cache, virtualization flags (VT-x / AMD-V / nested), and mitigation status for CPU vulnerabilities (
/sys/devices/system/cpu/vulnerabilities). - Memory (RAM): Total, used, free, available, buffers, cached, swap usage, and physical DIMM slot details (type, speed, manufacturer, part number via
dmidecode -t 17when root/sudo). - Storage & Disks: Block device tree (
lsblk), transport type (NVMe, SATA, USB, SCSI), SSD/NVMe vs HDD (rotational check), filesystem types, mount points, capacity, I/O schedulers, and SMART health/temperature status viasmartctl. - GPU & Video: Integrated and discrete GPU detection via
lspci, active kernel drivers (nvidia,amdgpu,i915,xe,nouveau), and integration withnvidia-smi/rocm-smiif present. - Motherboard & BIOS/UEFI: Board manufacturer and model, BIOS/UEFI vendor, version, and release date, chassis type, boot mode (UEFI vs Legacy BIOS), and Secure Boot state.
- Network (NIC): Physical and virtual interfaces, MAC addresses, link speeds (1G/2.5G/10G), duplex, carrier state, driver module, firmware version via
ethtool, and Wi-Fi chipset details. - PCI & USB Peripherals: High-level PCI device summary and complete USB device hierarchy (
lsusb -t). - Thermal & Sensors: CPU package/core temperatures, GPU temperature, NVMe temperature, fan RPM, and laptop battery statistics (charging status, capacity, cycle count, health, and wear level).
- Virtualization & Platform: Hypervisor detection (bare-metal, KVM, Proxmox, VMware, Docker, LXC via
systemd-detect-virt), OS release, Linux kernel, uptime, and load averages.
- CPU: Model, vendor, architecture, sockets, cores, threads, scaling governor, base/max/current frequencies, L1/L2/L3 cache, virtualization flags (VT-x / AMD-V / nested), and mitigation status for CPU vulnerabilities (
- Output Formats & Flags:
(no flag): Full-color interactive CLI display styled withlib.sh.--summaryor-s: Compact 1-page overview of key hardware specifications.--jsonor-j: Valid, machine-parseable JSON object for automation or API integration.--markdownor-m: Clean Markdown report ready for documentation or GitHub issues.
- Privilege & Safety: Fully read-only, non-destructive, and executes safely as both root and non-root users. Automatically checks
sudo -nfor privileged tools (dmidecode,smartctl) without prompting for passwords or blocking execution.
- Custom dynamic SSH login banner (MOTD) with live system KPIs:
- Dynamic System Metrics: Displays hostname, distro, kernel, CPU processor model & cores, load averages, memory usage (RAM), swap usage, root disk usage (
/), private LAN IP, public IP (fast 1-hr cached lookup), SSH listening port, active firewall status (firewalld,ufw,nftables,iptables), active user sessions, and service status badges (sshd,firewall,fail2ban,docker,podman,9router). - Ultra-Fast & Lightweight: Pure bash and
/procinspection executing in under 0.05 seconds with zero external network bloat or login lag. - Spam Silencer: Automatically disables annoying Ubuntu Pro / ESM promotional spam scripts (
10-help-text,50-motd-news,88-esm-announce,91-release-upgrade). - Multi-Distro: Integrates natively with
/etc/update-motd.d/(Debian/Ubuntu) or/etc/profile.d/(Fedora/RHEL/CentOS/Arch). - Actions:
preview(instant test render),install(set up system-wide),clean(silence Ubuntu ads only),uninstall(restore stock distro MOTD).
- Dynamic System Metrics: Displays hostname, distro, kernel, CPU processor model & cores, load averages, memory usage (RAM), swap usage, root disk usage (
- Installs
ufwif missing, allows OpenSSH, http, https. - Prompts for extra ports (e.g.
8443/tcp 3000/tcp). - Optionally enables the firewall and shows verbose status.
-
Full interactive
ufwmanager (installs ufw if missing). Looping menu:- View & control: status (verbose + numbered), enable, disable, reload, reset, default policy (incoming/outgoing/routed × allow/deny/reject), logging level.
- Ports: allow port, deny port, rate-limit port (brute-force protection).
- IP / subnet: allow IP/CIDR, deny IP/CIDR, allow multiple IPs, deny multiple IPs (space/comma separated), allow IP→port, deny IP→port.
- Apps & rules: list/allow application profiles, delete a rule by number.
-
Addresses are validated; multiple-IP actions report applied/skipped counts.
-
Warns to allow your SSH port before enabling, to avoid lockout.
-
Dry-run: set
DRY_RUN=1to print everyufwcommand without executing — safe to try the menus and inputs first:curl -fsSL https://scripts.wanforge.asia/script/linux/security/firewall-manager.sh | DRY_RUN=1 bash
- Multi-distro Installation: Installs Fail2Ban across Debian, Ubuntu, RHEL/Fedora/CentOS/Rocky, Arch Linux, openSUSE, and Alpine.
- Aggressive & Progressive Banning:
bantime.increment = true: Applies exponential progressive bans for recidivists (1h → 2h → 4h up to 4 weeks).- Default timers:
bantime = 1h,findtime = 15m,maxretry = 4. - Repeat offender jail (
[recidive]): Traps and bans persistent attackers across all services for 2 weeks.
- Smart System Detection:
- Dynamic SSH port discovery: protects both port 22 and any custom SSH ports detected via
ssandsshd_config. - Systemd Journal backend (
backend = systemd): provides zero-lag log parsing immune to log rotation. - Firewall integration: auto-detects
ufw,firewallcmd-richrules,nftables-multiport, oriptables-multiport. - Anti-lockout whitelist: auto-detects current admin SSH connection IP (
SSH_CLIENT) and RFC 1918 subnets intoignoreip. - Web server jails: automatically enables
[nginx-http-auth],[nginx-botsearch], and[nginx-bad-request]if Nginx or CloudPanel is detected.
- Dynamic SSH port discovery: protects both port 22 and any custom SSH ports detected via
- Management CLI & Interactive Menu:
status: Real-time audit of service state, active jails, and currently banned IPs.optimize: Applies production hardening presets with automatic config backup.unban <ip>: Unbans an IP address across all jails or selected jail.ban <ip> [jail]: Manually bans an IP address in a specific jail.logs: Inspects the last 35 Ban/Unban events from/var/log/fail2ban.logor journalctl.
- Hardening and security auditing wizard for OpenSSH server:
- Audit Mode (
status): Inspects active daemon status, listening ports, effective directives (PermitRootLogin,PubkeyAuthentication,PasswordAuthentication,X11Forwarding,MaxAuthTries), registered keys inauthorized_keys, firewall state, and SELinux enforcement. - Port Configuration: Changes the SSH port (default
22— keep it or set custom1-65535). - Passwordless Sudo (VPS Standard): Option to configure
/etc/sudoers.d/99-wanforge-nopasswdwithNOPASSWD: ALL(validated withvisudo), allowingsudo suand root commands without password prompts (default cloud VPS behavior). - Multi-Distro Firewall: Opens the new port in
ufw(Ubuntu/Debian) orfirewalld(RHEL/Fedora/Rocky/AlmaLinux) before restarting sshd. - SELinux Support: Automatically registers custom SSH ports into SELinux policy (
semanage port -a -t ssh_port_t -p tcp <port>) to prevent permission denied bind errors. - Modern Systemd Socket Activation: Handles Ubuntu 24.04
ssh.socketmigration tossh.serviceso custom ports take effect immediately. - Anti-Lockout Protection: Scans
~/.ssh/authorized_keysand/root/.ssh/authorized_keysbefore allowing password authentication to be disabled; offers on-the-spot key paste ored25519key generation if missing. - CIS Hardening Directives: Disables root login (
no/prohibit-password), enforcesPubkeyAuthentication yes, disables password auth, disables PAM keyboard-interactive fallback, disablesX11Forwarding, setsMaxAuthTries 3,LoginGraceTime 30, and keeps sessions alive (ClientAliveInterval 300,ClientAliveCountMax 2). - Safe Architecture: Uses drop-in
/etc/ssh/sshd_config.d/99-wanforge-hardening.conf, automatically backs up configurations, tests syntax withsshd -t, and offers rollback (--uninstall/rollback).
- Audit Mode (
- Interactive Linux user manager for server and SSH users.
- Creates and deletes users, changes passwords, locks/unlocks accounts, and changes login shells.
- Grants or removes sudo/wheel access depending on the distro group that exists.
- Manages SSH public keys under
~/.ssh/authorized_keysand can show per-user status (sudo, locked, SSH keys).
- Generates an
ed25519key in~/.ssh(no sudo). Prompts for the file path, comment (defaultwanforge-asia@<hostname>), and an optional passphrase. - Refuses to overwrite an existing key without confirmation. Sets
~/.sshto700, the private key to600, the public key to644. - Prints the fingerprint and the public key to paste into GitHub/GitLab (Settings → SSH/Deploy Keys).
- Diagnostics and helper utility for managing and troubleshooting SSL/TLS certificates.
- Features:
- Inspect Remote Certificates: Scan any domain and port via OpenSSL to view expiration dates, issuers, and SANs.
- Inspect Local Certificate Files: Reads local
.crtor.pemfiles and parses their metadata. - Generate Self-Signed Certificates: Generates a standard RSA-2048 certificate with SAN support (including wildcard) acceptable in modern web browsers for local development.
- SSL Handshake Debugger: Connects via different TLS versions (TLS 1.0 - 1.3) to isolate cipher or version mismatch issues.
- Provision Certbot: Installs Certbot and the Nginx plugin (
certbot python3-certbot-nginx) to auto-provision SSL certificates.
- Supported OS: Ubuntu 24.04 LTS strictly mandatory. The script checks
/etc/os-releaseand aborts immediately if the host is not Ubuntu 24. - Database Engine: Defaults to
MARIADB_12.3, with support forMARIADB_11.8,MARIADB_11.4,MARIADB_10.11,MYSQL_8.4, andMYSQL_8.0. - Integrity Verification: Downloads installer from
https://installer.cloudpanel.io/ce/v2/install.sh, pipes checksum verification against8146dbe0a488e7088b04071b0c34d59aa0ab1fe9dcec382d395fd155c9e6c476, and executes viasudo DB_ENGINE=MARIADB_12.3 bash install.sh. - Web console available upon completion at
https://<server-ip>:8443.
- Requires CloudPanel (
clpctl). Interactive menu over the documented v2 CLI (reference). Loops until you quit. - CloudPanel: enable/disable basic auth, Cloudflare IP update.
- Database: show master credentials, add, export, import.
- Certificates: Let's Encrypt install (with SAN), install custom certificate.
- Sites: add PHP / Node.js / Python / Static / Reverse Proxy, delete site.
- Users: add (admin/site-manager/user roles), delete, list, reset password, disable MFA.
- vHost templates: list, import, add, delete, view.
- System: reset permissions, purge Varnish cache.
- Passwords are entered interactively (not stored). Note they are passed to
clpctlas flags, so they may briefly appear in the process list.
- Full Suite & Modular Setup: Debian, Ubuntu, and Fedora/RHEL support.
- Core Web Console: Installs Cockpit, enables socket activation (
cockpit.socket) on port9090. - Plugin Suite:
cockpit-networkmanager: Network interfaces, IP/DNS, bridges, VLANs, bonds.cockpit-storaged: Disks, partitions, LVM volume groups, RAID, NFS mounts, SMART drive health.cockpit-sosreport: Diagnostic system state and support reports.cockpit-pcp: Performance Co-Pilot integration for live & historical metrics graphing.cockpit-machines: KVM / QEMU virtual machines management via libvirt.cockpit-podman: Podman container images and container lifecycle management.
- Optimized Performance Logger (PCP):
- Automatically enables & starts
pmcdandpmloggerdaemons. - Refreshes complete metric definitions via
pmlogconf -r(CPU, memory, disk I/O, network, filesystems). - Sets primary logger control to capture 10s interval historical performance data.
- Enables
pmlogger_daily.timerandpmlogger_check.timerfor automatic archive rotation. - Ensures persistent systemd journal storage so historical logs are fully available in Cockpit's System Logs viewer.
- Automatically enables & starts
- Reverse Proxy Wizard:
- Interactive config generator for
/etc/cockpit/cockpit.conf(Origins,AllowOrigins,ProtocolHeader = X-Forwarded-Proto,AllowUnencrypted = true). - Tailored for SSL-terminating proxies (CloudPanel, Nginx, Caddy).
- Interactive config generator for
- Firewall Integration:
- Opens port
9090/tcpin UFW or Firewalld with an explicit note that it can remain closed if accessed exclusively via reverse proxy.
- Opens port
- Audit & Status (
status):- Audits socket state, active plugins in
/usr/share/cockpit/, PCP logger status, archive disk footprint, and reverse proxy rules.
- Audits socket state, active plugins in
- Core Web Console: Installs Cockpit, enables socket activation (
- Debian/Ubuntu only. Adds the official PGDG APT repository to install the
latest PostgreSQL, plus
postgresql-contrib. - Creates login roles interactively — usernames and passwords are entered at
runtime and never stored in the script. Optional
SUPERUSER(default off). - Optional remote access: configures
pg_hba.conf+listen_addresses(paths resolved viaSHOW hba_file/config_file), restarts, and opens5432for a chosen source CIDR.
- Debian/Ubuntu only. Auto-detects the MySQL/MariaDB config file, backs it up,
sets
bind-address = 0.0.0.0, restarts the service, and opens3306for a chosen source CIDR. - Optionally creates remote DB users: connects as admin (root socket via
sudo, or a root password), then loops to createuser@hostwith a password and a grant on a chosen database (or all). Host defaults to%(any client). Passwords are entered interactively and never stored.
- Works with MySQL/MariaDB and PostgreSQL (auto-detects the client; asks which engine when both are present). Looping action menu.
- MySQL/MariaDB: status (version, uptime, threads, connections), databases
by size, full process list, date/time + timezone check, key config variables,
slow-query-log status, optimize + analyze (
mysqlcheck), MySQLTuner. - PostgreSQL: status (version, uptime, connections), databases by size,
pg_stat_activity, date/time + timezone check, key settings, cache hit ratio,VACUUM ANALYZE+ optionalREINDEX. - Connects via root socket (
sudo) or a prompted password (MySQL) / thepostgressystem user (PostgreSQL). Read-only actions are safe; optimize actions modify tables.
-
Grouped checkbox snapshot (default all on): uptime & load, CPU, memory, disk usage + inodes, largest directories, top processes by CPU/memory, network interfaces + listening sockets, temperatures (
lm-sensors). -
Realtime / watch mode: refreshes the selected sections on an interval until
Ctrl-C. Enable with the prompt,WATCH=1, or-w/--watch; set the cadence withINTERVAL=<seconds>(default 2).bigdirsis skipped while watching. Updates happen in place — the cursor homes and overwrites each line (no full-screen clear), so the values refresh without flicker or a "page reload".curl -fsSL .../script/linux/monitoring/monitor-system.sh | WATCH=1 INTERVAL=2 bash -
Optional Tools section installs
htop,btop,ncdu,glances,iotop— full-screen realtime monitors if you prefer a TUI.
- Arrow-key TUI network toolkit, grouped:
- Addresses — local interfaces/IPs, public IP (v4/v6) + geo/ISP, routes & default gateway, DNS resolvers, ARP/neighbours.
- Ports & connections — listening sockets, established connections, check a
local port, check a remote
host:port, scan ports (nmapor/dev/tcp). - Diagnostics — ping, traceroute/
mtr, DNS lookup (dig), whois, HTTP headers (curl -I), interface traffic stats. - Speed — internet speed test (
speedtest/speedtest-cli). - Tools — install the network tooling (iproute2, net-tools, dnsutils, traceroute, mtr, nmap, whois, speedtest-cli).
- Each tool falls back gracefully when a binary is missing.
- Run on a Proxmox VE node (detects
pvesh/qm//etc/pve). Arrow-key TUI:- Overview — version, node status, cluster (
pvecm), recent tasks, HA. - Resources — memory (RAM + swap), CPU load/usage, disk +
pvesmstorage, top processes, disk I/O. - Guests — list VMs (
qm) and containers (pct); manage one VM/CT (status / start / shutdown / stop / reboot / config /vzdumpbackup). - Realtime — live dashboard refreshing in place: CPU/load, RAM, root FS, Proxmox storage, and running-vs-total VMs/containers.
- Overview — version, node status, cluster (
- Mutating actions (start/stop/backup) honor
DRY_RUN.
A single-select TUI manager for GitHub Actions self-hosted runners.
Jobs with runs-on: self-hosted execute on your machine, so GitHub-hosted
runner minutes are not consumed — self-hosted runners are
free of per-minute billing.
Menu actions:
| Action | What it does |
|---|---|
| Install | Register a new runner and install it as a systemd service |
| List | Show every runner on this host (name, service state, user, target URL, dir) |
| Status | systemctl status of a chosen runner service |
| Logs | journalctl -u <svc> (last 100 lines) for a chosen runner |
| Start / Stop / Restart | Control a chosen runner service via svc.sh |
| Remove | Stop + uninstall the service, unregister from GitHub, optionally delete the dir |
-
Scope: a single repo (
owner/name) or a whole org. Fetches the latestactions/runnerrelease for your arch (x64/arm64/arm), or prompts for a version if the GitHub API is unreachable. -
Tokens (both short-lived — copy them just before running):
- Registration token (Install) — Settings → Actions → Runners → New runner.
- Removal token (Remove) — the runner's ⋯ → Remove dialog.
-
Service user: creates a dedicated
--systemuser (defaultgithub-runner); GitHub forbids running the service as root. Override the user at the prompt. -
Install layout: each runner lives in
${RUNNER_ROOT}/<name>(defaultRUNNER_ROOT=/opt/actions-runner), so multiple runners coexist. Install runsbin/installdependencies.sh(libicu etc.),config.sh --unattended --replace(with optional--ephemeral,--labels,--runnergroup,--work), thensvc.sh install <user>+svc.sh start. -
Use in a workflow:
jobs: build: runs-on: [self-hosted, linux, x64] # or a custom label you set at install
-
Security: see hardening for self-hosted runners — avoid self-hosted runners on public repos (untrusted forks can run code).
A single-select TUI manager for GitLab CI/CD self-hosted runners. Allows registering runners to execute CI/CD jobs on your own machine.
Menu actions:
- Install: Add the official GitLab runner repository, install
gitlab-runner, and register a new runner with the GitLab instance (supports shell and docker executors, tags, and description). - List: List registered runners on this host.
- Status: Show systemd service status.
- Logs: Tail journald logs (last 100 lines).
- Start / Stop / Restart: Control the gitlab-runner service.
- Remove: Unregister runners from GitLab and optionally purge the gitlab-runner package and repository.
- Debian/Ubuntu. Checkbox components: Prometheus (
:9090), node_exporter (:9100, host CPU/RAM/disk metrics), Alertmanager (:9093), and firewall (UFW & Firewalld). - Installs from distro packages, enables services, and adds a node_exporter scrape job to
/etc/prometheus/prometheus.yml. - System Alerts: Automatically provisions
/etc/prometheus/alert.rules.ymlcontaining pre-configured rules (Host down, high CPU/RAM, low disk space) and links them to Prometheus. - Alertmanager Notification Wizard: Offers interactive setup for Alertmanager notifications including Slack/Discord webhooks, Telegram bots, generic webhook URLs, and SMTP emails.
- Diagnostics & Audit (
status): Audits running services, open ports (9090, 9100, 9093), configured scrape jobs, and active alert rules.
- Debian/Ubuntu. Adds the official Grafana APT repo, installs and enables
grafana-server(:3000), and opens the firewall (UFW & Firewalld). - Datasource Provisioning: Optionally auto-provisions a Prometheus data source (
http://localhost:9090). - Dashboard Provisioning: Optionally auto-provisions the "Node Exporter Full" dashboard (ID 1860) and binds it to the Prometheus datasource so metrics are visible immediately out-of-the-box.
- Reverse Proxy Wizard (
proxy): Configuresdomainandroot_urlin/etc/grafana/grafana.inifor SSL reverse proxies (CloudPanel / Nginx / Caddy). - Admin Password Reset (
reset-pass): Resets the Grafanaadminuser password directly from CLI usinggrafana-cli. - Diagnostics & Audit (
status): Auditsgrafana-serverstate, listening port 3000, provisioned datasources, and dashboards.
- Debian/Ubuntu. Adds the official Zabbix 7.0 LTS repo (auto-detected for Ubuntu 24.04/22.04, Debian 12/11):
- Agent —
zabbix-agent2with plugins, sets server polling IP + hostname, opens port:10050in UFW / Firewalld. - Server — server + PHP frontend + MySQL/MariaDB: creates the
zabbixdatabase, imports schema, configuresDBPassword, starts everything. Frontend athttp://<ip>/zabbix, default loginAdmin/zabbix. - Diagnostics & Audit (
status): Audits Zabbix server, agent, database connectivity, and listening ports (10051, 10050, 80).
- Agent —
- Multi-distro. Installs Uptime Kuma using Node.js + PM2 (run
install-nodejs.shfirst to set up the Node environment). - Features: Clones Uptime Kuma repository, runs installation setup, registers the server with PM2 (supports custom port mapping and ufw firewall rules), and manages service lifecycle.
- Debian/Ubuntu. Installs Grafana Loki (log aggregation server) and/or Promtail (log collection agent).
- Loki Server: Runs on port
3100, storing indices and chunks persistently at/var/lib/loki. Optionally registers as a Grafana datasource. - Promtail Agent: Scrapes
/var/log/*logandsystemd-journal(system unit logs), then forwards them to a central Loki URL. Allows setting up distributed logging (pushing to a remote Loki server).
- Debian/Ubuntu. Installs GoAccess real-time web log analyzer.
- Console TUI: Run directly in terminal to analyze Nginx/Apache logs with live updates.
- HTML Daemon: Configures a systemd service (
goaccess.service) that runs in the background, reading access logs and generating a real-time HTML report on a selected web directory (e.g./var/www/html/report.html), utilizing WebSockets on port7890for live browser updates.
# 1) On each host to monitor (metrics + log agents):
# Installs node_exporter to export metrics and Promtail to forward logs
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-prometheus.sh | bash # pick node_exporter
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-loki.sh | bash # pick promtail, point to Loki server URL
# 2) On the central monitoring host (Prometheus server, Loki server, Grafana):
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-prometheus.sh | bash # pick prometheus + Alertmanager
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-loki.sh | bash # pick loki (server)
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-grafana.sh | bash # installs Grafana, auto-adds Prometheus datasource, auto-imports Dashboard 1860
# 3) Open Grafana (http://host:3000)
# - Dashboards -> Node Exporter Full dashboard is ready.
# - Explore -> Select 'Loki' data source -> Browse and query your system and journal logs in real-time.
# Alternative standalone status page:
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-uptime-kuma.sh | bash # install Uptime Kuma on port 3001- Installs
nvminto$HOME/.nvm(no sudo) and the chosen Node version (18,20,lts,latest). Sets it as the default + stable alias. - Optionally installs PM2 +
pm2-logrotate, runspm2 save, and (optionally) sets up boot startup via systemd (this single step needs sudo).
- Requires PHP. Installs Composer into
~/.local/bin/composer(no sudo), verifying the installer SHA-384 signature before running it. - Adds
~/.local/bintoPATHin~/.bashrcand runscomposer self-update.
- Requires PM2 (run
install-nodejs.shfirst). Sources nvm to find PM2. - Optionally configures
pm2-logrotate(max size, retention, compression, daily rotation). - Registers an application by generating
ecosystem.config.js(name, cwd, script, args, instances/cluster,NODE_ENV, memory restart limit), then runspm2 start+pm2 save.
- Container runtimes and management suite for Docker Engine & Podman:
- Multi-Distro Engine Support: Installs official Docker Engine and Docker Compose plugins across Debian, Ubuntu, Fedora, RHEL, CentOS, Rocky Linux, AlmaLinux, Arch, and Alpine.
- Podman Runtime: Installs rootless and daemonless Podman + Podman Compose.
- Podman as Docker CLI & Socket: Configures
podman-dockerpackage or symlinks/usr/local/bin/docker -> podman, installs global shell aliases (alias docker=podman), silences emulation notice (/etc/containers/nodocker), configures default registries (docker.io,quay.io), and enables Podman API socket (systemctl enable --now podman.socket) linked to/var/run/docker.sockfor seamless compatibility with Docker-dependent tools and SDKs. - Container Diagnostics: Audits running containers across either active engine, inspects resource usage snapshots (
stats --no-stream), and detects containers caught in restart loops or exited with non-zero error codes. - Storage Cleanup: Automated prune of stopped containers, unused networks, dangling images, and build caches (
system prune -a --volumes). - UFW Security Patch: Fixes Docker's default iptables routing that exposes container ports directly to the internet by routing container traffic through
/etc/ufw/after.rules.
- Installs official Cloudflare Tunnel client (
cloudflared) on Debian/Ubuntu/RHEL/Arch. - Modes:
- Quick Tunnel: Ephemeral
trycloudflare.comtunnel for instant testing without an account. - Named Tunnel: Authenticated persistent tunnel with custom domain DNS routing and local ingress rules.
- Service Token: Headless one-liner installation using Cloudflare Zero Trust tunnel connector token.
- Quick Tunnel: Ephemeral
- Fully integrated with systemd service lifecycle (
--start,--stop,--restart,--status,--uninstall).
- Modular autonomous AI coding and messaging environment installer and auditor (select individually):
- 9Router: Installs
9routerAI gateway, creates9router.servicesystemd daemon on port20128, configures multi-provider models (Anthropic, OpenAI, DeepSeek, Google Gemini) with automated fallback combos. - Claude Code CLI: Installs via official installer (
curl -fsSL https://claude.ai/install.sh | bashwith npm fallback), configures~/.claude/settings.jsonwith 9Router base URL, 998k context window, and permission whitelist for automated execution. - Antigravity CLI: Installs via official Google installer (
curl -fsSL https://antigravity.google/cli/install.sh | bash), wires binary to PATH, and configures RTK hooks in~/.gemini/settings.json. - Hermes Agent: Installs via official installer (
curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash), bootstraps Python environment, and provisions user systemd service. - Token Optimization: Integrates Caveman CLI (
@caveman-ai/cli) and prompt compression tools. - Doctor Mode: Runs comprehensive health check verifying node, python, tmux, agent binaries, port availability, and AI proxy latency.
- 9Router: Installs
- Interactive setup and hardening wizard for Hermes Agent Telegram gateway:
- Credential Security: Saves bot tokens with restricted file permissions (
chmod 600) in~/.hermes/.env. - Access Control & Whitelist: Restricts direct messages to authorized Telegram user IDs (
allowed_users) to prevent unauthorized command execution. - Telegram Groups Protection: Configures allowed group chat IDs (
allowed_chats) and optional mention enforcement (require_mention: true) to prevent agent runaway in active groups. - 9Router Proxy Routing: Automatically wires
model.base_urlto local or remote 9Router endpoints. - Context & Memory Tuning: Tunes compression thresholds, context window limits, and secret redaction guards.
- Daemonization: Manages user systemd unit
hermes-gateway.serviceand enables persistent linger vialoginctl.
- Credential Security: Saves bot tokens with restricted file permissions (
- Dedicated Cloudflare Tunnel integration and custom domain proxy for 9Router:
- Generates Cloudflare ingress rules mapping public HTTPS endpoints (e.g.,
ai.wanforge.asia) to local 9Router port20128. - Automatically adds Cloudflare DNS CNAME records.
- Updates Hermes Agent and Claude Code configuration to use the public secure domain URL.
- Manages background tunnel daemon via systemd.
- Generates Cloudflare ingress rules mapping public HTTPS endpoints (e.g.,
- Public repo: never store credentials, tokens, or sensitive data in this
folder. See
.gitignorefor the blocked patterns. - Database credentials:
install-postgresql.shasks for role names and passwords interactively. No passwords are stored in these scripts. - Remote database access:
install-postgresql.shandenable-mysql-remote.shexpose the database to the network. Prefer a restricted source CIDR over0.0.0.0/0, and place the server behind a firewall or private network. - SSH hardening:
secure-ssh.shcan lock you out. It opens the new port inufwbefore restarting, validates withsshd -t, backs up the config, and refuses to disable password auth without anauthorized_keyspresent. Keep your current session open and test the new port before closing it. - CloudPanel: fails closed when the installer checksum does not match.
- Cockpit:
AllowUnencrypted = trueis only safe when TLS is terminated by the proxy (e.g. CloudPanel) in front of Cockpit. - Node.js / Composer: installed in the current user's home, no
sudo. PM2 boot startup (pm2 startup) is optional and needssudofor systemd.
The banner, colors, logging helpers, prompts, and TUI menus live once in
script/linux/lib.sh. Every script sources it.
| Helper | Purpose |
|---|---|
hd "Title" |
Centered fill-line section header (───── Title ─────) |
info "…" |
• info line |
ok "…" |
✓ success line |
warn "…" |
⚠ warning line |
err "…" |
✖ error line (always prints, ignores LOG_LEVEL) |
step N "…" |
[N] task name numbered step indicator |
hr |
────────── horizontal rule separator |
pause |
Press Enter to continue (reads from /dev/tty) |
dbg "…" |
Debug line (only at LOG_LEVEL ≥ 2) |
ask "prompt" "default" |
› interactive prompt; auto-fills default in ASSUME_YES mode |
asks "prompt" |
Same but masked input (for secrets) |
checkbox "title" |
Arrow-key grouped checkbox with [✓] toggles |
menu_select "title" |
Arrow-key single-select menu |
TASK="my-script"
__LIB="https://scripts.wanforge.asia/script/linux/lib.sh"
__d="$(cd "$(dirname "${BASH_SOURCE[0]:-$0}")" 2>/dev/null && pwd || true)"
if [ -r "${__d}/../lib.sh" ]; then . "${__d}/../lib.sh"
else . <(curl -fsSL "${__LIB}"); fiLooks for lib.sh one directory up (cloned repo: script/linux/<category>/),
otherwise fetches from the public repo over HTTPS. Set TASK before sourcing —
the banner subtitle uses it. To add a script: copy the header, fill in TASK,
place under script/linux/<os>/<category>/, register in install.sh.
GNU General Public License v3.0 (GPL-3.0). Copyright (c) 2026 Sugeng Sulistiyawan.
See LICENSE.