Transparency
Exactly what the scan does
Review the script before you run it. Every command it runs is read-only and listed below.
Binary checksums per architecture
amd644e25ddc2805491f8…69c7
arm6476cda3e894b2f828…2b96
| Section | Purpose | Command | Notes |
|---|---|---|---|
| facts | Basic host facts: OS, kernel, hostname, uptime, package manager. | cat /etc/os-release 2>/dev/null && echo '@@OPSDECK:os_release:RC=0@@' || echo '@@OPSDECK:os_release:RC=1@@' uname -m; uname -r; hostname; id -u; id -un; nproc && echo '@@OPSDECK:ident:RC=0@@' || echo '@@OPSDECK:ident:RC=1@@' cat /proc/meminfo && echo '@@OPSDECK:meminfo:RC=0@@' || echo '@@OPSDECK:meminfo:RC=1@@' df -P && echo '@@OPSDECK:disks:RC=0@@' || echo '@@OPSDECK:disks:RC=1@@' command -v apt-get; command -v dnf; command -v yum; command -v apk && echo '@@OPSDECK:pkg_which:RC=0@@' || echo '@@OPSDECK:pkg_which:RC=1@@' cat /proc/1/comm; test -d /run/systemd/system && echo OPSDECK_SYSTEMD_DIR=1 || echo OPSDECK_SYSTEMD_DIR=0 && echo '@@OPSDECK:init:RC=0@@' || echo '@@OPSDECK:init:RC=1@@' command -v python3 && echo '@@OPSDECK:python3:RC=0@@' || echo '@@OPSDECK:python3:RC=1@@' cat /proc/uptime && echo '@@OPSDECK:uptime:RC=0@@' || echo '@@OPSDECK:uptime:RC=1@@' cat /proc/loadavg && echo '@@OPSDECK:loadavg:RC=0@@' || echo '@@OPSDECK:loadavg:RC=1@@' cat /etc/timezone 2>/dev/null || timedatectl show -p Timezone --value 2>/dev/null || date +%Z && echo '@@OPSDECK:timezone:RC=0@@' || echo '@@OPSDECK:timezone:RC=1@@' uname -s; uname -r; uname -m && echo '@@OPSDECK:platform_uname:RC=0@@' || echo '@@OPSDECK:platform_uname:RC=1@@' if [ -r "/etc/alpine-release" ]; then printf "@@F:%s@@\n" "/etc/alpine-release"; head -n 3 "/etc/alpine-release"; fi; if [ -r "/etc/system-release" ]; then printf "@@F:%s@@\n" "/etc/system-release"; head -n 3 "/etc/system-release"; fi; if [ -r "/etc/redhat-release" ]; then printf "@@F:%s@@\n" "/etc/redhat-release"; head -n 3 "/etc/redhat-release"; fi; if [ -r "/etc/SuSE-release" ]; then printf "@@F:%s@@\n" "/etc/SuSE-release"; head -n 3 "/etc/SuSE-release"; fi; if [ -r "/etc/debian_version" ]; then printf "@@F:%s@@\n" "/etc/debian_version"; head -n 3 "/etc/debian_version"; fi; if [ -r "/etc/arch-release" ]; then printf "@@F:%s@@\n" "/etc/arch-release"; head -n 3 "/etc/arch-release"; fi; if command -v freebsd-version >/dev/null 2>&1; then printf "@@F:freebsd-version -ku@@\n"; freebsd-version -k; freebsd-version -u; fi && echo '@@OPSDECK:platform_release:RC=0@@' || echo '@@OPSDECK:platform_release:RC=1@@' command -v apt-get >/dev/null 2>&1 && echo apt-get; command -v dpkg >/dev/null 2>&1 && echo dpkg; command -v dnf >/dev/null 2>&1 && echo dnf; command -v dnf5 >/dev/null 2>&1 && echo dnf5; command -v yum >/dev/null 2>&1 && echo yum; command -v rpm >/dev/null 2>&1 && echo rpm; command -v zypper >/dev/null 2>&1 && echo zypper; command -v apk >/dev/null 2>&1 && echo apk; command -v pacman >/dev/null 2>&1 && echo pacman; command -v pkg >/dev/null 2>&1 && echo pkg; command -v systemctl >/dev/null 2>&1 && echo systemctl; command -v rc-service >/dev/null 2>&1 && echo rc-service; command -v rc-update >/dev/null 2>&1 && echo rc-update; command -v openrc >/dev/null 2>&1 && echo openrc; command -v sysrc >/dev/null 2>&1 && echo sysrc; command -v service >/dev/null 2>&1 && echo service; command -v ufw >/dev/null 2>&1 && echo ufw; command -v firewall-cmd >/dev/null 2>&1 && echo firewall-cmd; command -v nft >/dev/null 2>&1 && echo nft; command -v iptables >/dev/null 2>&1 && echo iptables; command -v pfctl >/dev/null 2>&1 && echo pfctl; command -v ipfw >/dev/null 2>&1 && echo ipfw; command -v getenforce >/dev/null 2>&1 && echo getenforce; command -v sestatus >/dev/null 2>&1 && echo sestatus; command -v aa-status >/dev/null 2>&1 && echo aa-status; command -v aa-enabled >/dev/null 2>&1 && echo aa-enabled; command -v sudo >/dev/null 2>&1 && echo sudo; command -v doas >/dev/null 2>&1 && echo doas; command -v su >/dev/null 2>&1 && echo su; command -v runuser >/dev/null 2>&1 && echo runuser; command -v python3 >/dev/null 2>&1 && echo python3; command -v python >/dev/null 2>&1 && echo python; command -v busybox >/dev/null 2>&1 && echo busybox; command -v ss >/dev/null 2>&1 && echo ss; command -v sockstat >/dev/null 2>&1 && echo sockstat; command -v netstat >/dev/null 2>&1 && echo netstat; command -v ip >/dev/null 2>&1 && echo ip; command -v ifconfig >/dev/null 2>&1 && echo ifconfig; command -v curl >/dev/null 2>&1 && echo curl; command -v wget >/dev/null 2>&1 && echo wget; command -v fetch >/dev/null 2>&1 && echo fetch; command -v base64 >/dev/null 2>&1 && echo base64; command -v openssl >/dev/null 2>&1 && echo openssl; command -v sha256sum >/dev/null 2>&1 && echo sha256sum; command -v sha256 >/dev/null 2>&1 && echo sha256; command -v crontab >/dev/null 2>&1 && echo crontab; command -v chronyd >/dev/null 2>&1 && echo chronyd; command -v ntpd >/dev/null 2>&1 && echo ntpd; command -v pro >/dev/null 2>&1 && echo pro; command -v SUSEConnect >/dev/null 2>&1 && echo SUSEConnect; command -v needs-restarting >/dev/null 2>&1 && echo needs-restarting; command -v useradd >/dev/null 2>&1 && echo useradd; command -v adduser >/dev/null 2>&1 && echo adduser; command -v pw >/dev/null 2>&1 && echo pw; command -v getent >/dev/null 2>&1 && echo getent; command -v stat >/dev/null 2>&1 && echo stat; command -v cloud-init >/dev/null 2>&1 && echo cloud-init && echo '@@OPSDECK:platform_tools:RC=0@@' || echo '@@OPSDECK:platform_tools:RC=1@@' cat /proc/1/comm 2>/dev/null || ps -p 1 -o comm= 2>/dev/null; test -d /run/systemd/system && echo OPSDECK_SYSTEMD_DIR=1 || echo OPSDECK_SYSTEMD_DIR=0; test -d /run/openrc && echo OPSDECK_OPENRC_DIR=1 || echo OPSDECK_OPENRC_DIR=0; test -f /run/openrc/softlevel && echo OPSDECK_OPENRC_BOOTED=1 || echo OPSDECK_OPENRC_BOOTED=0; test -f /etc/rc.conf && test -d /etc/rc.d && echo OPSDECK_BSDRC=1 || echo OPSDECK_BSDRC=0; test -d /etc/init.d && echo OPSDECK_SYSVINIT=1 || echo OPSDECK_SYSVINIT=0 && echo '@@OPSDECK:platform_init:RC=0@@' || echo '@@OPSDECK:platform_init:RC=1@@' ls /lib/ld-musl-*.so.1 >/dev/null 2>&1 && echo musl; getconf GNU_LIBC_VERSION 2>/dev/null && echo '@@OPSDECK:platform_libc:RC=0@@' || echo '@@OPSDECK:platform_libc:RC=1@@' getenforce 2>/dev/null || cat /sys/fs/selinux/enforce 2>/dev/null; echo ---; cat /etc/selinux/config 2>/dev/null; echo ---; cat /sys/module/apparmor/parameters/enabled 2>/dev/null; test -d /sys/kernel/security/apparmor && echo OPSDECK_APPARMOR_SECFS=1 && echo '@@OPSDECK:platform_mac:RC=0@@' || echo '@@OPSDECK:platform_mac:RC=1@@' printf "login_shell=%s\n" "${SHELL:-}"; readlink /bin/sh 2>/dev/null; ls --version 2>&1 | head -n1; ls --help 2>&1 | head -n1 && echo '@@OPSDECK:platform_shell:RC=0@@' || echo '@@OPSDECK:platform_shell:RC=1@@' systemd-detect-virt 2>/dev/null; test -e /proc/sys/fs/binfmt_misc/WSLInterop && echo OPSDECK_WSL=1; grep -qi microsoft /proc/sys/kernel/osrelease 2>/dev/null && echo OPSDECK_WSL=1; test -e /.dockerenv && echo OPSDECK_DOCKER=1; test -e /run/.containerenv && echo OPSDECK_PODMAN=1; printf "OPSDECK_JAIL=%s\n" "$(sysctl -n security.jail.jailed 2>/dev/null || echo 0)" && echo '@@OPSDECK:platform_virt:RC=0@@' || echo '@@OPSDECK:platform_virt:RC=1@@' cat /usr/local/etc/opnsense-version 2>/dev/null && echo OPSDECK_APPLIANCE=opnsense; test -f /etc/platform && echo OPSDECK_MANAGED=truenas; test -f /usr/local/cpanel/version && echo OPSDECK_MANAGED=cpanel; test -f /usr/local/psa/version && echo OPSDECK_MANAGED=plesk; grep -h "^[[:space:]]*Include" /etc/ssh/sshd_config /usr/etc/ssh/sshd_config 2>/dev/null; getent group wheel sudo 2>/dev/null && echo '@@OPSDECK:platform_extras:RC=0@@' || echo '@@OPSDECK:platform_extras:RC=1@@' OPSDECK_OS_ID=$(sed -n 's/^ID=//p' /etc/os-release 2>/dev/null | tr -d '"'); case "$OPSDECK_OS_ID" in ubuntu|sles|debian|rhel|ol|centos) timeout 15 pro status --format json 2>/dev/null | head -c 65536; timeout 15 SUSEConnect -s 2>/dev/null | head -c 65536; grep -rhs extended-lts /etc/apt/sources.list /etc/apt/sources.list.d 2>/dev/null; { dnf -C -q repolist enabled 2>/dev/null || yum -C -q repolist enabled 2>/dev/null; } | grep -i -- '-els' ;; esac && echo '@@OPSDECK:platform_esm:RC=0@@' || echo '@@OPSDECK:platform_esm:RC=1@@' sysctl -n hw.physmem hw.ncpu vm.loadavg kern.boottime kern.securelevel 2>/dev/null; pkg -N >/dev/null 2>&1 && echo OPSDECK_PKG_BOOTSTRAPPED=1; pkg which -q /bin/sh >/dev/null 2>&1 && echo OPSDECK_PKGBASE=1 && echo '@@OPSDECK:platform_bsd:RC=0@@' || echo '@@OPSDECK:platform_bsd:RC=1@@' sw_vers -productName 2>/dev/null; sw_vers -productVersion 2>/dev/null; sw_vers -buildVersion 2>/dev/null; sysctl -n hw.memsize hw.ncpu kern.boottime hw.machine 2>/dev/null; csrutil status 2>/dev/null; command -v brew 2>/dev/null && echo '@@OPSDECK:platform_darwin:RC=0@@' || echo '@@OPSDECK:platform_darwin:RC=1@@' test -f /run/ostree-booted && echo OPSDECK_OSTREE=1; test -f /etc/NIXOS && echo OPSDECK_NIXOS=1; test -d /usr/share/flatcar && echo OPSDECK_FLATCAR=1; test -f /.bottlerocket && echo OPSDECK_BOTTLEROCKET=1; command -v transactional-update >/dev/null 2>&1 && echo OPSDECK_TRANSACTIONAL=1; grep -h "^VARIANT_ID=" /etc/os-release 2>/dev/null; test -w /usr && echo OPSDECK_USR_WRITABLE=1 || echo OPSDECK_USR_WRITABLE=0 && echo '@@OPSDECK:platform_immutable:RC=0@@' || echo '@@OPSDECK:platform_immutable:RC=1@@' | minimised |
| sshd | Whether an SSH server is installed. | PATH="$PATH:/usr/local/sbin:/usr/sbin:/sbin"; export PATH; command -v sshd | |
| sshd | Effective SSH server settings (root login, password login, port). | PATH="$PATH:/usr/local/sbin:/usr/sbin:/sbin"; export PATH; sshd -T 2>&1 | |
| sshd | Raw sshd_config (fallback when 'sshd -T' is unavailable). | cat /etc/ssh/sshd_config | |
| network | Listening sockets (fact gathering round trip). | ss -tulpnH | |
| network | Listening sockets (fallback when 'ss' is unavailable). | netstat -tulpn | |
| network | Listening TCP/UDP ports and the process that owns each one. | PATH="$PATH:/usr/local/sbin:/usr/sbin:/sbin"; export PATH; ss -tulpn 2>/dev/null | |
| network | Listening ports (fallback when 'ss' is unavailable). | PATH="$PATH:/usr/local/sbin:/usr/sbin:/sbin"; export PATH; netstat -tulpn 2>/dev/null | |
| firewall | Which firewall tools are installed. | PATH="$PATH:/usr/local/sbin:/usr/sbin:/sbin"; export PATH; command -v ufw; command -v firewall-cmd; command -v iptables; command -v nft | |
| firewall | ufw status and rules. | PATH="$PATH:/usr/local/sbin:/usr/sbin:/sbin"; export PATH; ufw status verbose | |
| firewall | ufw rules configured while ufw is inactive. | PATH="$PATH:/usr/local/sbin:/usr/sbin:/sbin"; export PATH; ufw show added 2>/dev/null | |
| firewall | ufw's own default-policy configuration. | cat /etc/default/ufw 2>/dev/null | |
| firewall | Whether firewalld is running. | PATH="$PATH:/usr/local/sbin:/usr/sbin:/sbin"; export PATH; firewall-cmd --state 2>&1 | |
| firewall | firewalld's active zone configuration. | PATH="$PATH:/usr/local/sbin:/usr/sbin:/sbin"; export PATH; firewall-cmd --list-all | |
| firewall | Legacy iptables INPUT chain rules. | PATH="$PATH:/usr/local/sbin:/usr/sbin:/sbin"; export PATH; iptables -S INPUT | |
| firewall | nftables ruleset (modern firewall backend). | PATH="$PATH:/usr/local/sbin:/usr/sbin:/sbin"; export PATH; nft list ruleset | |
| updates | Packages with a pending update (Debian/Ubuntu). | apt list --upgradable | |
| updates | Simulated upgrade (fallback when 'apt list' output cannot be trusted). | apt-get -s -q upgrade | |
| updates | Whether unattended-upgrades is installed and enabled. | echo __OPSDECK_ITEM__installed; dpkg-query -W -f '${Status}' unattended-upgrades 2>/dev/null; echo __OPSDECK_ITEM__conf; grep -hs Unattended-Upgrade /etc/apt/apt.conf.d/* 2>/dev/null; echo __OPSDECK_ITEM__reboot; test -f /var/run/reboot-required && echo yes || echo no; echo __OPSDECK_ITEM__age; stat -c %Y /var/lib/apt/lists 2>/dev/null; date +%s | minimised |
| updates | Packages with a pending update (dnf). | dnf -q check-update | repo refresh |
| updates | Packages with a pending update (yum). | yum -q check-update | repo refresh |
| updates | Which pending updates are security updates (dnf). | dnf -q updateinfo list --security 2>/dev/null | repo refresh |
| updates | Which pending updates are security updates (yum). | yum -q updateinfo list --security 2>/dev/null | repo refresh |
| updates | Whether dnf-automatic is installed and enabled. | echo __OPSDECK_ITEM__installed; rpm -q dnf-automatic >/dev/null 2>&1 && echo yes || echo no; echo __OPSDECK_ITEM__timers; systemctl is-enabled dnf-automatic-install.timer dnf-automatic.timer 2>/dev/null; echo __OPSDECK_ITEM__conf; grep -hsiE '^[[:space:]]*apply_updates' /etc/dnf/automatic.conf 2>/dev/null; echo __OPSDECK_ITEM__reboot; PATH="$PATH:/usr/local/sbin:/usr/sbin:/sbin"; export PATH; needs-restarting -r >/dev/null 2>&1; echo $? | minimised |
| ssl | Discover TLS certificates referenced by nginx/Apache or Let's Encrypt. | echo __OPSDECK_ITEM__config; grep -rhsE '^\s*(ssl_certificate|SSLCertificateFile)\s' /etc/nginx /etc/apache2 /etc/httpd 2>/dev/null; echo __OPSDECK_ITEM__live; ls -1 /etc/letsencrypt/live 2>/dev/null | |
| users | Local accounts, home directories, shells and the default umask (no full names). | echo __OPSDECK_ITEM__passwd; (getent passwd 2>/dev/null || cat /etc/passwd) | awk -F: 'BEGIN{OFS=":"} {$5=""; print}'; echo __OPSDECK_ITEM__login_defs; grep -E '^[[:space:]]*UMASK' /etc/login.defs 2>/dev/null | minimised |
| users | Accounts with an empty or locked password and NOPASSWD sudo rules (no password hashes). | echo __OPSDECK_ITEM__shadow; test -r /etc/shadow && echo 'opsdeck-scan:x:'; echo __OPSDECK_ITEM__sudoers; grep -hs NOPASSWD /etc/sudoers /etc/sudoers.d/* 2>/dev/null; echo '# opsdeck-scan: sudoers readable' | minimised |
| permissions | Permissions of the core account and SSH configuration files. | stat -c '%a|%U|%G|%n' /etc/shadow /etc/passwd /etc/group /etc/gshadow /etc/ssh/sshd_config 2>/dev/null | |
| permissions | World-writable files under /etc. | find /etc -xdev ! -type l -perm -0002 2>/dev/null | |
| permissions | SUID binaries (compared against a known-safe baseline). | find / -xdev -type f -perm -4000 2>/dev/null | |
| services | Whether fail2ban/auditd/NTP are active, and which services are running. | echo __OPSDECK_ITEM__active; systemctl is-active fail2ban auditd chrony chronyd systemd-timesyncd ntp ntpd ntpsec openntpd 2>/dev/null; echo __OPSDECK_ITEM__running; systemctl list-units --type=service --state=running --no-legend --no-pager --plain 2>/dev/null | |
| sysctl | Security-relevant kernel parameters (hardening flags only). | sysctl -a 2>/dev/null | grep -E '^(kernel\.randomize_va_space|kernel\.kptr_restrict|kernel\.dmesg_restrict|kernel\.yama\.ptrace_scope|kernel\.sysrq|kernel\.core_uses_pid|fs\.suid_dumpable|fs\.protected_hardlinks|fs\.protected_symlinks|net\.ipv4\.ip_forward|net\.ipv4\.conf\.all\.rp_filter|net\.ipv4\.conf\.default\.rp_filter|net\.ipv4\.conf\.all\.accept_redirects|net\.ipv4\.conf\.default\.accept_redirects|net\.ipv4\.conf\.all\.secure_redirects|net\.ipv4\.conf\.default\.secure_redirects|net\.ipv4\.conf\.all\.send_redirects|net\.ipv4\.conf\.default\.send_redirects|net\.ipv4\.conf\.all\.accept_source_route|net\.ipv4\.conf\.default\.accept_source_route|net\.ipv4\.conf\.all\.log_martians|net\.ipv4\.conf\.default\.log_martians|net\.ipv4\.icmp_echo_ignore_broadcasts|net\.ipv4\.icmp_ignore_bogus_error_responses|net\.ipv4\.tcp_syncookies|net\.ipv6\.conf\.all\.accept_redirects|net\.ipv6\.conf\.default\.accept_redirects|net\.ipv6\.conf\.all\.accept_ra|net\.ipv6\.conf\.default\.accept_ra|net\.ipv6\.conf\.all\.accept_source_route|net\.ipv6\.conf\.all\.forwarding|net\.ipv6\.conf\.default\.accept_source_route) =' | minimised |
| packages | Installed package inventory (Debian/Ubuntu). | dpkg-query -W -f '${db:Status-Abbrev}\t${Package}\t${Version}\n' 2>/dev/null | |
| packages | Installed package inventory (RHEL family). | rpm -qa --qf 'ii \t%{NAME}\t%{VERSION}-%{RELEASE}\n' 2>/dev/null | |
| stack | Detect the installed web server, runtimes and databases (Debian/Ubuntu). | export PATH="$PATH:/usr/local/sbin:/usr/sbin:/sbin"; echo __OPSDECK_PROBE__nginx; command -v nginx >/dev/null 2>&1 && nginx -v 2>&1; echo __OPSDECK_PROBE__apache2; command -v apache2 >/dev/null 2>&1 && apache2 -v 2>&1; echo __OPSDECK_PROBE__httpd; command -v httpd >/dev/null 2>&1 && httpd -v 2>&1; echo __OPSDECK_PROBE__caddy; command -v caddy >/dev/null 2>&1 && caddy version 2>&1; echo __OPSDECK_PROBE__node; command -v node >/dev/null 2>&1 && node -v 2>&1; echo __OPSDECK_PROBE__php; command -v php >/dev/null 2>&1 && php -v 2>&1; echo __OPSDECK_PROBE__python3; command -v python3 >/dev/null 2>&1 && python3 --version 2>&1; echo __OPSDECK_PROBE__ruby; command -v ruby >/dev/null 2>&1 && ruby -v 2>&1; echo __OPSDECK_PROBE__go; command -v go >/dev/null 2>&1 && go version 2>&1; echo __OPSDECK_PROBE__java; command -v java >/dev/null 2>&1 && java -version 2>&1; echo __OPSDECK_PROBE__mysql; command -v mysql >/dev/null 2>&1 && mysql --version 2>&1; echo __OPSDECK_PROBE__psql; command -v psql >/dev/null 2>&1 && psql --version 2>&1; echo __OPSDECK_PROBE__mongod; command -v mongod >/dev/null 2>&1 && mongod --version 2>&1; echo __OPSDECK_PROBE__redis-server; command -v redis-server >/dev/null 2>&1 && redis-server --version 2>&1; echo __OPSDECK_PROBE__pm2; command -v pm2 >/dev/null 2>&1 && pm2 -v 2>&1; echo __OPSDECK_PROBE__docker; command -v docker >/dev/null 2>&1 && docker -v 2>&1; echo __OPSDECK_PROBE__composer; command -v composer >/dev/null 2>&1 && composer --version 2>&1; echo __OPSDECK_PROBE__packages; dpkg-query -W -f '.\n' 2>/dev/null | wc -l; echo __OPSDECK_PROBE__unit_files; systemctl list-unit-files --type=service --no-legend --no-pager 2>/dev/null; echo __OPSDECK_PROBE__running; systemctl list-units --type=service --state=running --no-legend --no-pager --plain 2>/dev/null | |
| stack | Detect the installed web server, runtimes and databases (RHEL family). | export PATH="$PATH:/usr/local/sbin:/usr/sbin:/sbin"; echo __OPSDECK_PROBE__nginx; command -v nginx >/dev/null 2>&1 && nginx -v 2>&1; echo __OPSDECK_PROBE__apache2; command -v apache2 >/dev/null 2>&1 && apache2 -v 2>&1; echo __OPSDECK_PROBE__httpd; command -v httpd >/dev/null 2>&1 && httpd -v 2>&1; echo __OPSDECK_PROBE__caddy; command -v caddy >/dev/null 2>&1 && caddy version 2>&1; echo __OPSDECK_PROBE__node; command -v node >/dev/null 2>&1 && node -v 2>&1; echo __OPSDECK_PROBE__php; command -v php >/dev/null 2>&1 && php -v 2>&1; echo __OPSDECK_PROBE__python3; command -v python3 >/dev/null 2>&1 && python3 --version 2>&1; echo __OPSDECK_PROBE__ruby; command -v ruby >/dev/null 2>&1 && ruby -v 2>&1; echo __OPSDECK_PROBE__go; command -v go >/dev/null 2>&1 && go version 2>&1; echo __OPSDECK_PROBE__java; command -v java >/dev/null 2>&1 && java -version 2>&1; echo __OPSDECK_PROBE__mysql; command -v mysql >/dev/null 2>&1 && mysql --version 2>&1; echo __OPSDECK_PROBE__psql; command -v psql >/dev/null 2>&1 && psql --version 2>&1; echo __OPSDECK_PROBE__mongod; command -v mongod >/dev/null 2>&1 && mongod --version 2>&1; echo __OPSDECK_PROBE__redis-server; command -v redis-server >/dev/null 2>&1 && redis-server --version 2>&1; echo __OPSDECK_PROBE__pm2; command -v pm2 >/dev/null 2>&1 && pm2 -v 2>&1; echo __OPSDECK_PROBE__docker; command -v docker >/dev/null 2>&1 && docker -v 2>&1; echo __OPSDECK_PROBE__composer; command -v composer >/dev/null 2>&1 && composer --version 2>&1; echo __OPSDECK_PROBE__packages; rpm -qa 2>/dev/null | wc -l; echo __OPSDECK_PROBE__unit_files; systemctl list-unit-files --type=service --no-legend --no-pager 2>/dev/null; echo __OPSDECK_PROBE__running; systemctl list-units --type=service --state=running --no-legend --no-pager --plain 2>/dev/null | |
| metrics | Load average, memory and disk usage, uptime. | echo __OPSDECK_SECTION__loadavg; cat /proc/loadavg; echo __OPSDECK_SECTION__meminfo; cat /proc/meminfo; echo __OPSDECK_SECTION__df; df -P -k /; echo __OPSDECK_SECTION__uptime; cat /proc/uptime; echo __OPSDECK_SECTION__nproc; nproc | |
| metrics | A 200ms CPU utilisation sample. | head -n1 /proc/stat; sleep 0.20; head -n1 /proc/stat | |
| cis | A few baseline CIS hardening checks (core dumps, umask, pre-login banner). | echo __OPSDECK_ITEM__limits; grep -rhsE '^\s*\*\s+hard\s+core\s+0' /etc/security/limits.conf /etc/security/limits.d 2>/dev/null; echo __OPSDECK_ITEM__umask; grep -hsE '^\s*umask\s+[0-7]{3,4}' /etc/profile /etc/bash.bashrc /etc/bashrc /etc/profile.d/*.sh 2>/dev/null; echo __OPSDECK_ITEM__issue; cat /etc/issue.net 2>/dev/null | |
| sshd | Contents of sshd_config Include files (used only when 'sshd -T' fails). | cat "$ITEM" | per-item |
| ssl | Expiry date, issuer and subject of each certificate found. | openssl x509 -noout -enddate -issuer -subject -in "$ITEM" 2>/dev/null | per-item |
| permissions | Ownership and permission mode of each account's SSH key material. | stat -c '%a|%u|%U|%n' "$ITEM/.ssh" "$ITEM/.ssh/authorized_keys" "$ITEM/.ssh/authorized_keys2" "$ITEM/.ssh/id_rsa" "$ITEM/.ssh/id_ecdsa" "$ITEM/.ssh/id_ed25519" "$ITEM/.ssh/id_dsa" 2>/dev/null | per-item |
Privacy
What leaves your server
Minimised before it's sent
File paths, package names and versions, listening ports, config flags, and truncated command output. Long values and free-text fields are minimised — only what's needed to evaluate a check is kept.
Never collected
Password hashes, private keys, full GECOS names, and private/internal IP addresses are never read or sent. See the Privacy Policy for the complete list.
On RHEL-family hosts (RHEL, Rocky, AlmaLinux, CentOS), a small number of checks refresh the local package-manager cache (e.g. dnf makecache) before reading installed package versions — this only reads from your already-configured repositories and installs nothing.
Retention
How long we keep it
Verified scans are kept for 30 days; unverified scans for 7 days. You can delete a scan and its report at any time from the report page.