scripts

wanforge/scripts

Interactive Linux server automation toolkit — one unified launcher, 39 scripts across 10 categories: system setup, security hardening, databases, app runtimes, cloud panels, network & tunneling, monitoring, observability, CI/CD runners, and AI & agents.

Run scripts individually, use install.sh, or use ./wf, a zero-dependency portable keyboard-driven dual-pane TUI dashboard. It features live search, category sidebars, code inspector (v), batch multi-select (b), and runs 100% portably in-place without polluting system directories or requiring root. No authentication required — public repo, served via GitHub Pages at scripts.wanforge.asia.

Scripts are organized under script/linux/<category>/, structured so future macOS or Windows scripts can be added alongside without changing the layout.

Requirements

Install curl first (fresh systems)

A minimal install may not ship curl. Install it for your distro:

# Debian / Ubuntu
sudo apt update && sudo apt install -y curl

# Fedora / RHEL / CentOS / Rocky / Alma
sudo dnf install -y curl          # or: sudo yum install -y curl

# Arch / Manjaro
sudo pacman -Sy --noconfirm curl

# openSUSE
sudo zypper install -y curl

# Alpine
sudo apk add curl

If you are root (e.g. a fresh container/VM), drop the sudo. No package manager handy? curl usually rides along with wget — see the wget alternative below.

Run via the Portable TUI Launcher

# Remote one-liner (Zero installation, runs in memory/user-space cache)
curl -fsSL https://scripts.wanforge.asia/install.sh | bash

# Or via cloned repository
./wf            # or: ./install.sh

No curl? Use wget instead (present on many minimal images):

wget -qO- https://scripts.wanforge.asia/install.sh | bash

Interactive TUI Controls & Shortcuts

The new keyboard-driven TUI provides a dual-pane interface with alternate screen buffering (leaves your terminal prompt 100% clean upon exit):

Key / Shortcut Action
↑ / ↓ / k/j Move selection in the active pane
Tab / ← / → Switch focus between Category pane and Tools pane
Enter Run selected script (or focus tools pane from category)
v View Code: Inspect script source in pager without running
/ or s Live Search: Instant real-time filter across all 39 tools
b Batch Mode: Multi-select and run several tools in order
i System Snapshot: Instant audit popup (OS, RAM, CPU, IP)
1 – 9, 0 Direct jump to category index 1 to 10
q / Esc Cleanly exit back to original shell prompt

CLI Command Options (Headless / Pipelines)

All scripts can also be invoked non-interactively without the TUI:

# List all 39 tools with indices and descriptions
./wf list

# Run a specific script directly by name or global number
./wf setup-motd
./wf docker
./wf 6                              # Global #6 (setup-motd)

# Open a category submenu directly (1-10)
./wf 1                              # System category
./wf 2                              # Security category

# Run a specific script by category & tool number
./wf 1 6                            # Category 1 (System), Tool 6 (setup-motd)

# Search tools by keyword non-interactively
./wf search docker

# Server quick status audit
./wf info

# Classic prompt menu fallback (if running on primitive terminal)
./wf --classic
Select scripts to run:
  ↑/↓ move · SPACE toggle · A all · ENTER confirm · Q quit

  ── System ──
❯ [✓] install-packages     Update system + base essentials (micro, curl, wget, git)
  [✓] set-timezone         Set timezone (UTC recommended for servers)
  [✓] backup-tools         Backup manager: S3 / FTP / SFTP — named profiles, cron, dry-run
  [✓] sys-troubleshoot     Diagnostics & troubleshooting: CPU, RAM, services, OOM, logs, firewall, network
  [✓] hardware-info        Hardware audit: CPU, RAM, disks, GPU, firmware, NIC, sensors, virt
  [✓] setup-motd           Custom dynamic SSH login banner (MOTD) with live system KPIs
  ── Security ──
  [✓] install-firewall     Install & configure ufw firewall
  [✓] firewall-manager     Full ufw manager: allow/deny IP/port, multiple, rate-limit
  [✓] install-fail2ban     Install, optimize & manage Fail2Ban (progressive ban, recidive)
  [✓] secure-ssh           Harden SSH: audit, port change, root/pw lockdown, SELinux & firewall
  [✓] generate-ssh-key     Generate an ed25519 SSH key (user-local)
  [✓] manage-users         Manage Linux users, sudo access & SSH keys
  [✓] ssl-toolkit          SSL/TLS diagnostics & management: remote/local audit, self-signed SAN, TLS handshake debug, Certbot
  ── Panel & Console ──
  [✓] install-cloudpanel   Install CloudPanel CE v2 (Ubuntu 24 only)
  [✓] clpctl-manager       Manage CloudPanel via clpctl (sites, db, users, certs)
  [✓] install-cockpit      Install Cockpit web console, plugins, proxy & optimized PCP logger
  ── Database ──
  [✓] install-postgresql   Install PostgreSQL + create roles + remote access
  [✓] enable-mysql-remote  Allow remote MySQL/MariaDB access (sensitive)
  [✓] database-toolkit     Monitor, optimize, config, datetime (MySQL/PostgreSQL)
  ── App Runtime ──
  [✓] install-nodejs       Install Node.js via nvm (user-local) + PM2
  [✓] install-python       Install Python 3 + pip, venv, dev, pipx
  [✓] install-composer     Install Composer (user-local, signature-verified)
  [✓] setup-pm2-app        Configure pm2-logrotate + register an app (ecosystem)
  [✓] install-docker       Docker Engine & Docker Compose (with UFW security patch & container diagnostics)
  ── Monitoring ──
  [✓] monitor-system       CPU, RAM, storage, processes, network (snapshot or realtime)
  ── Network ──
  [✓] net-tools            Local/public IP, ports, speedtest, ping, dig, scan
  [✓] install-cloudflared  Install and configure Cloudflare Tunnel daemon
  ── Proxmox ──
  [✓] proxmox-toolkit      PVE: node/VM/CT resources, storage, realtime dashboard
  ── CI/CD ──
  [✓] install-github-runner GitHub Actions self-hosted runner (avoid billed minutes)
  [✓] install-gitlab-runner GitLab CI/CD self-hosted runner
  ── Observability ──
  [✓] install-prometheus   Prometheus + node_exporter (+ Alertmanager)
  [✓] install-grafana      Grafana + Prometheus data source
  [✓] install-zabbix       Zabbix agent or server (official repo)
  [✓] install-uptime-kuma  Uptime Kuma beautiful self-hosted status page
  [✓] install-loki         Loki + Promtail log aggregator & forwarding agent
  [✓] install-goaccess     GoAccess real-time web log analyzer (terminal & HTML daemon)
  ── AI & Agents ──
  [✓] install-ai-agents    Modular AI stack: Hermes, Claude Code, AGY, 9Router
  [✓] setup-hermes-telegram Setup Telegram bot, user/group whitelist, optimizations
  [✓] setup-9router-tunnel Cloudflare Tunnel & custom domain reverse proxy for 9Router

Launcher Flow

flowchart TD
    A(["curl | bash install.sh"])
    B["TUI Checkbox Menu\n↑/↓ Space A Enter Q\n─ grouped by category ─"]
    C(["bash script.sh"])
    D["Management Menu\ninstall · stop · start · restart\nenable · disable · status\nremove-cron · uninstall"]
    E(["bash script.sh --flag"])

    IW["Install / Configure Wizard\n(interactive prompts)"]
    SVC["systemctl action\n(stop / start / restart /\nenable / disable / status)"]
    CRON["crontab cleanup\n(user + root)"]
    RM["Removal Wizard\n(purge packages,\nrepo, firewall rules)"]

    A --> B
    B -->|"bash script.sh --install\n(skips management menu)"| IW

    C -->|no args| D
    D -->|install| IW
    D -->|stop · start · restart\nenable · disable · status| SVC
    D -->|remove-cron| CRON
    D -->|uninstall| RM

    E -->|"--stop / --start\n--restart / --enable\n--disable / --status"| SVC
    E -->|--remove-cron| CRON
    E -->|--uninstall| RM
    E -->|"--install (or unknown flag)"| IW

    style A fill:#1e3a5f,color:#fff,stroke:#4a9eff
    style C fill:#1e3a5f,color:#fff,stroke:#4a9eff
    style E fill:#1e3a5f,color:#fff,stroke:#4a9eff
    style B fill:#2d4a1e,color:#fff,stroke:#6abf40
    style D fill:#2d4a1e,color:#fff,stroke:#6abf40
    style IW fill:#3a2d1e,color:#fff,stroke:#bf8c40
    style SVC fill:#1e2d3a,color:#fff,stroke:#40a0bf
    style CRON fill:#1e2d3a,color:#fff,stroke:#40a0bf
    style RM fill:#3a1e1e,color:#fff,stroke:#bf4040

Service scripts (fail2ban, grafana, prometheus, zabbix, cockpit, postgresql) use systemctl for stop/start/restart/enable/disable/status. backup-tools and setup-pm2-app have their own action sets (backup engine / pm2 commands). Non-service scripts (nodejs, composer, python, ssh-key) only expose install + uninstall.

Output Modes

Every script shares one verbosity control (defined in lib.sh). Set it with an environment variable (recommended — it also propagates through the launcher) or a flag:

Mode Shows How
silent Errors and final result only, no banner MODE=silent · QUIET=1 · -q
normal Banner + info/ok/warn/err (default) MODE=normal (default)
verbose Normal + extra dbg detail MODE=verbose · VERBOSE=1 · -v
debug Verbose + shell trace (set -x) MODE=debug · DEBUG=1 · --debug
# silent (good for automation / cron)
curl -fsSL https://scripts.wanforge.asia/install.sh | MODE=silent bash

# verbose
curl -fsSL .../script/linux/monitoring/monitor-system.sh | VERBOSE=1 bash

Dry-run (all scripts)

DRY_RUN=1 (or --dry-run / -n) makes every script print the state-changing commands instead of running them — defined once in lib.sh, so it works the same everywhere:

curl -fsSL .../script/linux/security/install-fail2ban.sh | DRY_RUN=1 bash
# →  [dry-run] sudo apt-get install -y fail2ban
#    [dry-run] sudo systemctl start fail2ban

Dry-run covers system mutations: package managers (install/upgrade/remove), services (systemctl/rc-service), ufw, sed -i, tee config writes, timedatectl, file ops, and PostgreSQL VACUUM/REINDEX. Read-only commands still run so you see real state. A few user-local installs (nvm/Node, Composer, PM2) and MySQL client mutations execute as normal.

Automation & logging

Variable / flag Effect
ASSUME_YES=1 · YES=1 · -y ask returns the default answer without prompting (non-interactive)
LOG_FILE=/path Appends a plain-text (no-color) copy of every log line
NO_COLOR=1 Disables colors in any mode
# fully unattended, dry-run, logged
curl -fsSL .../script/linux/security/install-fail2ban.sh | ASSUME_YES=1 DRY_RUN=1 LOG_FILE=/var/log/wf.log bash

Note: ASSUME_YES only fills prompts that have a safe default; password prompts and free-text inputs (e.g. role names) still need real input or are skipped.

Target user (install for a CloudPanel / site user)

The user-local scripts (install-nodejs, install-composer, setup-pm2-app) install into a user’s home — not the system. When you run them as root, they ask which user to install for (or set TARGET_USER=<name> / --user=<name>) and re-run themselves as that user via sudo -u, so Node/Composer/PM2 land in that user’s home. Perfect for CloudPanel site users:

# install Node + PM2 into the CloudPanel site user 'john'
curl -fsSL .../script/linux/runtime/install-nodejs.sh | TARGET_USER=john bash

All menus (launcher and the clpctl / database / firewall managers) are arrow-key TUIs — ↑/↓ to move, ENTER to select, Q to go back.

Uninstall / rollback

Install scripts support sub-commands for granular lifecycle control. Download the script first (pipe discards $1), then run with a flag:

curl -fsSL .../install-grafana.sh -o install-grafana.sh
bash install-grafana.sh --stop        # stop service only
bash install-grafana.sh --disable     # stop + disable autostart
bash install-grafana.sh --enable      # enable + start
bash install-grafana.sh --restart     # restart
bash install-grafana.sh --status      # systemctl status (no-pager)
bash install-grafana.sh --remove-cron # remove related cron entries
bash install-grafana.sh --uninstall   # full removal (packages, repo, firewall rules)

Available flags per script:

Script stop start restart enable disable status remove-cron uninstall
install-fail2ban.sh ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓
install-grafana.sh ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓
install-prometheus.sh ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓
install-zabbix.sh ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓
install-uptime-kuma.sh ✓ ✓ ✓ — — ✓ — ✓
install-loki.sh ✓ ✓ ✓ ✓ ✓ ✓ — ✓
install-goaccess.sh ✓ ✓ ✓ ✓ ✓ ✓ — ✓
install-cockpit.sh ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓
install-postgresql.sh ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ⚠
install-firewall.sh --disable --enable — --enable --disable ✓ ✓ ✓
install-firewall.sh (extra) --reload · --reset (wipes all rules)              
setup-pm2-app.sh ✓ ✓ ✓ — — ✓ ✓ ✓
setup-pm2-app.sh (extra) --logs (tail app logs)              
install-nodejs.sh — — — — — — ✓ ✓
install-composer.sh — — — — — — — ✓
install-python.sh — — — — — — — ✓
enable-mysql-remote.sh — — — — — — — ✓ (rollback)
secure-ssh.sh — — — — — — — ✓ (restore backup)
generate-ssh-key.sh — — — — — — — ✓
install-cloudpanel.sh — — — — — — — ✓ (manual steps)
install-docker.sh ✓ ✓ ✓ ✓ ✓ ✓ — ✓
install-cloudflared.sh ✓ ✓ ✓ ✓ ✓ ✓ — ✓
install-github-runner.sh ✓ ✓ ✓ — — ✓ — ✓
install-gitlab-runner.sh ✓ ✓ ✓ — — ✓ — ✓

Service scripts (--stop/start/restart/enable/disable/status) use systemctl and operate on all services the script manages (e.g. prometheus also controls prometheus-node-exporter and prometheus-alertmanager).

--remove-cron scans both the current user’s and root’s crontab for entries matching the service name and removes them.

PostgreSQL --uninstall: prompts twice — once for package removal, once for /var/lib/postgresql data deletion. Answer carefully.

Run a Single Script

Each script can also be run directly without the launcher.

# System
curl -fsSL https://scripts.wanforge.asia/script/linux/system/install-packages.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/system/set-timezone.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/system/install-firewall.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/system/backup-tools.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/system/sys-troubleshoot.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/system/hardware-info.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/system/hardware-info.sh | bash -s -- --summary
curl -fsSL https://scripts.wanforge.asia/script/linux/system/hardware-info.sh | bash -s -- --json
curl -fsSL https://scripts.wanforge.asia/script/linux/system/hardware-info.sh | bash -s -- --markdown

# Security
curl -fsSL https://scripts.wanforge.asia/script/linux/security/firewall-manager.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/security/install-fail2ban.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/security/secure-ssh.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/security/generate-ssh-key.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/security/manage-users.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/security/ssl-toolkit.sh | bash

# Panels & consoles
curl -fsSL https://scripts.wanforge.asia/script/linux/cloud/install-cloudpanel.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/cloud/clpctl-manager.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/cloud/install-cockpit.sh | bash

# Databases
curl -fsSL https://scripts.wanforge.asia/script/linux/database/install-postgresql.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/database/enable-mysql-remote.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/database/database-toolkit.sh | bash

# Monitoring & network
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/monitor-system.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/network/net-tools.sh | bash

# Proxmox (run on a PVE node)
curl -fsSL https://scripts.wanforge.asia/script/linux/network/proxmox-toolkit.sh | bash

# CI/CD
curl -fsSL https://scripts.wanforge.asia/script/linux/cicd/install-github-runner.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/cicd/install-gitlab-runner.sh | bash

# Observability stack
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-prometheus.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-grafana.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-zabbix.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-uptime-kuma.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-loki.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-goaccess.sh | bash

# App runtime
curl -fsSL https://scripts.wanforge.asia/script/linux/runtime/install-nodejs.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/runtime/install-python.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/runtime/install-composer.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/runtime/setup-pm2-app.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/runtime/install-docker.sh | bash

# Network & Tunnel
curl -fsSL https://scripts.wanforge.asia/script/linux/network/net-tools.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/network/install-cloudflared.sh | bash

# AI & Agents
curl -fsSL https://scripts.wanforge.asia/script/linux/ai/install-ai-agents.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/ai/setup-hermes-telegram.sh | bash
curl -fsSL https://scripts.wanforge.asia/script/linux/ai/setup-9router-tunnel.sh | bash

Scripts Overview

Group Script Purpose Sudo Distro
— install.sh Grouped checkbox launcher that runs the other scripts — Any
System install-packages.sh Update/upgrade system, install base essentials (micro/curl/wget/git) Yes Multi
System set-timezone.sh Set timezone via timedatectl (default Asia/Jakarta) Yes Any (systemd)
System backup-tools.sh Backup manager: S3 / FTP / SFTP — named profiles, cron, dry-run No Any
System sys-troubleshoot.sh Diagnostics & troubleshooting: CPU, RAM, services, OOM, logs, firewall, net Yes Any
System hardware-info.sh Hardware audit: CPU, RAM, disks, GPU, firmware, NIC, sensors, virt Some Any
System setup-motd.sh Custom dynamic SSH login banner (MOTD) with live system KPIs Yes Any
Security install-firewall.sh Install ufw, open SSH/http/https, add custom ports, enable Yes Mainly Deb/Ubu
Security firewall-manager.sh Full ufw manager: allow/deny IP & port, multi-IP, rate-limit Yes Any (ufw)
Security install-fail2ban.sh Install, optimize & manage Fail2Ban (progressive ban, recidive) Yes Multi
Security secure-ssh.sh Audit, port change, root/pw lockdown, passwordless sudo, CIS, SELinux/fw Yes Any (OpenSSH)
Security manage-users.sh Manage Linux users, sudo access, passwords, shells, and SSH keys Yes Any
Security generate-ssh-key.sh Generate an ed25519 SSH key, fix perms, print public key No Any
Security ssl-toolkit.sh SSL/TLS diagnostics: remote/local audit, self-signed SAN, handshake, Certbot Yes Any
Panel & Console install-cloudpanel.sh Install CloudPanel CE v2, choose DB engine, verify checksum Yes Ubuntu 24
Panel & Console clpctl-manager.sh Manage CloudPanel via clpctl: sites, db, users, certs, vhosts Yes CloudPanel
Panel & Console install-cockpit.sh Install Cockpit + modules, reverse-proxy config, optimized PCP logger, port 9090 Yes Debian/Ubuntu/RHEL
Database install-postgresql.sh Install latest PostgreSQL (PGDG), create roles, remote access Yes Debian/Ubuntu
Database enable-mysql-remote.sh Remote MySQL/MariaDB: bind-address, firewall, create users Yes Debian/Ubuntu
Database database-toolkit.sh Monitor / optimize / config / datetime — MySQL & PostgreSQL Yes Any (DB client)
App Runtime install-nodejs.sh Install Node.js via nvm (user-local), choose version, PM2 No Any
App Runtime install-python.sh Python 3 + pip, venv/virtualenv, dev headers, pipx (multi-distro) Yes Multi
App Runtime install-composer.sh Install Composer to ~/.local/bin, verify signature No Any (needs PHP)
App Runtime setup-pm2-app.sh Configure pm2-logrotate + register an app (ecosystem.config.js) No Any
App Runtime install-docker.sh Container runtimes: Docker & Podman, docker CLI alias/socket, diagnostics, UFW Yes Multi
Monitoring monitor-system.sh CPU/RAM/storage/processes/network — snapshot or realtime watch Some Any
Network net-tools.sh Local/public IP, ports, speedtest, ping/traceroute/dig/whois/scan Some Any
Network install-cloudflared.sh Install & configure Cloudflare Tunnel daemon (named / quick / token) Yes Multi
Proxmox proxmox-toolkit.sh PVE node/VM/CT resources, storage, cluster, realtime dashboard Yes Proxmox VE
CI/CD install-github-runner.sh GitHub Actions self-hosted runner as a systemd service (avoid billed minutes) Yes Linux
CI/CD install-gitlab-runner.sh GitLab CI/CD self-hosted runner manager Yes Linux
Observability install-prometheus.sh Prometheus + node_exporter + Alertmanager (alerts, notification wizard, audit) Yes Debian/Ubuntu
Observability install-grafana.sh Grafana (official repo) + datasource/dashboard provisioning, proxy & audit Yes Debian/Ubuntu
Observability install-zabbix.sh Zabbix 7.0 LTS Server or Agent 2 (official repo, MySQL schema, multi-fw) Yes Debian/Ubuntu
Observability install-uptime-kuma.sh Uptime Kuma status page & endpoint monitor (Node.js + PM2) No Linux
Observability install-loki.sh Loki + Promtail log aggregator & forwarding agent Yes Debian/Ubuntu
Observability install-goaccess.sh GoAccess real-time web log analyzer (terminal & HTML daemon) Yes Debian/Ubuntu
AI & Agents install-ai-agents.sh Modular AI stack: Hermes, Claude Code, AGY, 9Router, token optimization Some Linux
AI & Agents setup-hermes-telegram.sh Configure Hermes Telegram Bot: token, whitelist, group policy, 9Router backend No Linux
AI & Agents setup-9router-tunnel.sh Cloudflare Tunnel & custom domain reverse proxy for 9Router & AI agents Some Linux

Script Details

install-packages.sh

install-python.sh

set-timezone.sh

backup-tools.sh

sys-troubleshoot.sh

hardware-info.sh

setup-motd.sh

install-firewall.sh

firewall-manager.sh

install-fail2ban.sh

secure-ssh.sh

manage-users.sh

generate-ssh-key.sh

ssl-toolkit.sh

install-cloudpanel.sh

clpctl-manager.sh

install-cockpit.sh

install-postgresql.sh

enable-mysql-remote.sh

database-toolkit.sh

monitor-system.sh

net-tools.sh

proxmox-toolkit.sh

install-github-runner.sh

A single-select TUI manager for GitHub Actions self-hosted runners. Jobs with runs-on: self-hosted execute on your machine, so GitHub-hosted runner minutes are not consumed — self-hosted runners are free of per-minute billing.

Menu actions:

Action What it does
Install Register a new runner and install it as a systemd service
List Show every runner on this host (name, service state, user, target URL, dir)
Status systemctl status of a chosen runner service
Logs journalctl -u <svc> (last 100 lines) for a chosen runner
Start / Stop / Restart Control a chosen runner service via svc.sh
Remove Stop + uninstall the service, unregister from GitHub, optionally delete the dir

install-gitlab-runner.sh

A single-select TUI manager for GitLab CI/CD self-hosted runners. Allows registering runners to execute CI/CD jobs on your own machine.

Menu actions:

install-prometheus.sh

install-grafana.sh

install-zabbix.sh

install-uptime-kuma.sh

install-loki.sh

install-goaccess.sh

Monitoring & Logging stack — quick walkthrough

# 1) On each host to monitor (metrics + log agents):
# Installs node_exporter to export metrics and Promtail to forward logs
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-prometheus.sh | bash      # pick node_exporter
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-loki.sh | bash            # pick promtail, point to Loki server URL

# 2) On the central monitoring host (Prometheus server, Loki server, Grafana):
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-prometheus.sh | bash      # pick prometheus + Alertmanager
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-loki.sh | bash            # pick loki (server)
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-grafana.sh | bash         # installs Grafana, auto-adds Prometheus datasource, auto-imports Dashboard 1860

# 3) Open Grafana (http://host:3000)
# - Dashboards -> Node Exporter Full dashboard is ready.
# - Explore -> Select 'Loki' data source -> Browse and query your system and journal logs in real-time.

# Alternative standalone status page:
curl -fsSL https://scripts.wanforge.asia/script/linux/monitoring/install-uptime-kuma.sh | bash     # install Uptime Kuma on port 3001

install-nodejs.sh

install-composer.sh

setup-pm2-app.sh

install-docker.sh

install-cloudflared.sh

install-ai-agents.sh

setup-hermes-telegram.sh

setup-9router-tunnel.sh

Security Notes

Shared library

The banner, colors, logging helpers, prompts, and TUI menus live once in script/linux/lib.sh. Every script sources it.

Helper Purpose
hd "Title" Centered fill-line section header (───── Title ─────)
info "…" • info line
ok "…" ✓ success line
warn "…" ⚠ warning line
err "…" ✖ error line (always prints, ignores LOG_LEVEL)
step N "…" [N] task name numbered step indicator
hr ────────── horizontal rule separator
pause Press Enter to continue (reads from /dev/tty)
dbg "…" Debug line (only at LOG_LEVEL ≥ 2)
ask "prompt" "default" › interactive prompt; auto-fills default in ASSUME_YES mode
asks "prompt" Same but masked input (for secrets)
checkbox "title" Arrow-key grouped checkbox with [✓] toggles
menu_select "title" Arrow-key single-select menu
TASK="my-script"
__LIB="https://scripts.wanforge.asia/script/linux/lib.sh"
__d="$(cd "$(dirname "${BASH_SOURCE[0]:-$0}")" 2>/dev/null && pwd || true)"
if [ -r "${__d}/../lib.sh" ]; then . "${__d}/../lib.sh"
else . <(curl -fsSL "${__LIB}"); fi

Looks for lib.sh one directory up (cloned repo: script/linux/<category>/), otherwise fetches from the public repo over HTTPS. Set TASK before sourcing — the banner subtitle uses it. To add a script: copy the header, fill in TASK, place under script/linux/<os>/<category>/, register in install.sh.

License

GNU General Public License v3.0 (GPL-3.0). Copyright (c) 2026 Sugeng Sulistiyawan. See LICENSE.