Interactive Bash toolkit for Debian server administration.
Admin Tools provides an interactive menu for common administration tasks on a Debian VPS or server. It manages SSH settings and users, installs selected packages and applications, configures UFW, and exposes lightweight monitoring and diagnostic tools.
It is a focused convenience script, not a configuration-management framework or a replacement for Ansible. Operations are performed locally on the server and remain under the administrator's control.
| Section | What it does |
|---|---|
| SSH | Changes selected SSH options, shows effective settings, validates restarts, edits drop-ins, and lists backups. |
| Users | Creates sudo users, prepares protected SSH paths, and adds validated public keys. |
| Docker | Installs Docker Engine and the Compose plugin from Docker's Debian repository. |
| UFW | Installs or removes UFW, manages port rules and defaults, and shows firewall status. |
| Fail2Ban | Installs, enables, and starts Fail2Ban. |
| Applications | Installs OpenCode, Ollama, and Open WebUI, with a combined status view. |
| System Monitor | Shows load, memory, disk usage, and the top CPU-consuming processes. |
| Network Tools | Shows IP addresses, listeners, connection counts, and basic ping, HTTP, and DNS tests. |
| Service Manager | Shows service state and performs guarded bulk restart or non-SSH stop operations. |
Download and run the script with root privileges:
curl -fsSL https://raw.githubusercontent.com/dimadr/admintools/main/admin-tools.sh -o admin-tools.sh
sudo bash admin-tools.shThe script exits immediately when it is not running as root. Review the script before using it on an important server.
[1] SSH
[2] Users
[3] Docker
[4] UFW
[5] Fail2Ban
[6] Apps
[7] System Monitor
[8] Network Tools
[9] Service Manager
[0] Exit
Submenus are interactive. End-of-file closes the current menu instead of repeatedly prompting, and a failed action returns control to the menu.
SSH-changing operations include local safeguards intended to reduce obvious lockout and unsafe file-update risks:
.sshandauthorized_keysmust be real, user-owned objects rather than symlinks; user SSH files are updated as the target user.- Existing and candidate SSH configurations are checked with
sshd -tbefore they are applied or restarted. - Relevant applied values are checked against the effective configuration from
sshd -T. - SSH port changes verify the resulting local
sshdlistener; a failed application triggers rollback of the managed drop-in. - Authentication changes require a locally detectable alternative admin login method before disabling password or public-key authentication.
- Timestamped backups under
/etc/ssh/sshd_config.bak.*are created before actual configuration changes and are visible through SSH → Backup list. - Stop services always excludes SSH.
- Bulk service restart validates SSH configuration before restarting SSH.
Automatic option management uses /etc/ssh/sshd_config.d/00-admin-tools.conf. If the script detects a non-standard SSH layout that it cannot handle simply, it refuses the automatic change and asks for manual administration.
These checks validate local configuration and service state. They do not guarantee that a new SSH session can reach the server from an external network.
The Applications menu contains three installers:
| Application | Behavior |
|---|---|
| OpenCode | Runs the upstream installer after an explicit warning and confirmation. |
| Ollama | Runs the upstream installer after an explicit warning and confirmation. |
| Open WebUI | Runs the Docker image on host port 3000 using a persistent Docker volume. |
The same menu can report the detected state of OpenCode, Ollama, Docker, Open WebUI, Fail2Ban, and UFW.
The interactive interface retains concise command references for:
- SSH
- Docker
- UFW
- Fail2Ban
- Applications
Use the Reference entry in the corresponding menu for commands that are useful outside the script.
- A Debian server or VPS
- Bash 4 or newer
- Root privileges
- Standard Debian administration tools used by the selected operation
systemdfor service-management functions- Internet access when downloading packages, installers, images, or public network information
Docker installation explicitly requires ID=debian in /etc/os-release. Docker and application-specific functions may have additional requirements that the menu reports when invoked.
The following behaviors are intentional and should be considered before use:
- OpenCode and Ollama use their upstream
curl | bash/shinstallation pipelines after confirmation. - Membership in the
dockergroup provides root-equivalent control of the host. The installer adds only a detected, non-rootSUDO_USER; direct root execution does not addrootto the group. - Open WebUI is published on all interfaces as
0.0.0.0:3000. - Open WebUI uses the rolling image tag
ghcr.io/open-webui/open-webui:main. - An existing container named
open-webuimay be replaced withdocker rm -f open-webui; its named data volume is retained. - UFW enable and default-deny operations verify a standard local UFW state and the effective SSH port rule, but do not test access from outside the server.
Admin Tools can validate local files, effective SSH settings, listeners, services, and standard UFW output. It cannot guarantee:
- reachability through an external firewall, security group, NAT, or VPS provider network;
- possession of the correct private key by the SSH client;
- availability of the provider network or the administrator's connection;
- recovery access through a VPS provider console.
The script deliberately refuses some non-standard OpenSSH configurations instead of attempting to interpret every possible Include, Match, or listener arrangement. It also does not provide a general transaction or rollback framework for UFW.
Admin Tools targets Debian with Bash 4+, GNU userland tools, OpenSSH, and the standard systemd service model. The repository does not currently document a verified Debian version matrix.
Ubuntu and distributions that only report Debian through ID_LIKE are not claimed as supported.
This repository currently does not include a license file. Until a license is added, no open-source license grant should be assumed.