README.md

# Secure Server Bootstrap
A **production-grade automation script** to transform a fresh Linux machine into a complete:

<p align="center">
  <img src="./image.png" alt="DevOps Home Server Architecture" width="950"/>
</p>

* πŸ§ͺ DevOps Lab
* ☁️ Cloud Sandbox
* 🐳 Container Platform
* ☸️ Kubernetes Cluster

---

## πŸ“Œ Overview

This project provides a **one-command bootstrap script** that provisions a fully configured server with:

* Automated system setup & updates
* Developer environments
* Docker + Kubernetes stack
* Web server with SSL support
* Security hardening
* Monitoring dashboards
* Automated backups
* Performance tuning
* Enhanced CLI experience

---

## 🧠 Architecture Flow

```mermaid id="w9qk2x"
graph TD

A[Bootstrap Script] --> B[System Setup]
A --> C[Dev Environment]
A --> D[Web Stack]
A --> E[Container Platform]
A --> F[Kubernetes]
A --> G[Monitoring]
A --> H[Security]
A --> I[Backups]
A --> J[Performance]
A --> K[User Experience]

B --> B1[Auto Updates]

C --> C1[Python]
C --> C2[Node.js]
C --> C3[Java]
C --> C4[Go]

D --> D1[Nginx]
D --> D2[Certbot SSL]

E --> E1[Docker Engine]
E --> E2[Portainer]
E --> E3[Watchtower]

F --> F1[k3s Cluster]

G --> G1[Netdata Dashboard]
G --> G2[CLI Monitoring Tools]

H --> H1[UFW Firewall]
H --> H2[Fail2Ban]
H --> H3[psad]

I --> I1[Daily Backup Cron]

J --> J1[Swap Memory]

K --> K1[Aliases]
K --> K2[Custom MOTD]

```

---

## βš™οΈ Features

### πŸ”Ή System Automation

* Full system update & upgrade
* Automatic security updates (unattended-upgrades)

### πŸ”Ή Developer Environment

* Python (pip, venv)
* Node.js (v20) + npm + PM2 + Yarn
* OpenJDK 17
* Golang

### πŸ”Ή Web Stack

* Nginx (ready for reverse proxy)
* Certbot (Let’s Encrypt SSL support)

### πŸ”Ή Container Platform

* Docker Engine (auto-start enabled)
* Portainer (Docker GUI)
* Watchtower (auto container updates every 5 minutes)

### πŸ”Ή Kubernetes

* Lightweight cluster using **k3s**
* kubectl configured for non-root usage

### πŸ”Ή Monitoring

* Netdata (real-time web dashboard)
* CLI tools: btop, htop, glances, ncdu

### πŸ”Ή Security

* UFW firewall (default deny incoming)
* Fail2Ban (brute-force protection)
* psad (port scan detection)

### πŸ”Ή Performance

* 4GB swap file
* Optimized memory usage

### πŸ”Ή Backups

* Daily automated backups at 2 AM
* 7-day retention policy

### πŸ”Ή UX Enhancements

* Shell aliases (docker, kubectl shortcuts)
* Dynamic MOTD dashboard on login

---

## 🌐 Services & Ports

| Service        | Port  | Description          |
| -------------- | ----- | -------------------- |
| SSH            | 22    | Remote access        |
| HTTP           | 80    | Web traffic          |
| HTTPS          | 443   | Secure web traffic   |
| Portainer      | 9443  | Docker management UI |
| Portainer Edge | 8000  | Edge communication   |
| Netdata        | 19999 | Monitoring dashboard |

---

## πŸš€ Installation

### 1. Clone Repository

```bash id="r5w92k"
git clone https://github.com/yourusername/your-repo.git
cd your-repo
```

### 2. Run Bootstrap Script

```bash id="xw9p3z"
chmod +x bootstrap.sh
sudo ./bootstrap.sh
```

### 3. Reboot System

```bash id="k1m4sz"
sudo reboot
```

---

## πŸ–₯️ Access After Setup

### 🌐 Web Interfaces

* Portainer:
  `https://<server-ip>:9443`

* Netdata Dashboard:
  `http://<server-ip>:19999`

---

### ☸️ Kubernetes

```bash id="r9t2v1"
k get nodes
```

---

### 🐳 Docker

```bash id="j3s8qn"
docker ps
```

---

### πŸ“Š Monitoring

```bash id="g8u1yx"
btop
htop
glances
```

---

## πŸ” Security Notes

* Firewall enabled by default
* Fail2Ban actively protects SSH
* Only required ports are exposed

⚠️ Recommended:

* Configure SSH key authentication
* Disable password login
* Disable root login after setup

---

## πŸ’Ύ Backup System

* Runs daily at **02:00 AM**
* Location:

```id="t8y6bz"
/opt/backups
```

* Automatically deletes backups older than 7 days

---

## 🧩 Use Cases

* DevOps practice lab
* Kubernetes learning environment
* Self-hosted cloud services
* Container experimentation
* Homelab server

---

## πŸ“ˆ Future Improvements

* Reverse proxy automation (Traefik/Nginx configs)
* CI/CD pipeline integration
* Grafana + Prometheus stack
* VPN (WireGuard) setup
* Cloudflare tunnel integration

---

## πŸ“œ License

MIT License

---

## πŸ‘¨β€πŸ’» Author

**Mr. Walia**
DevOps & Cloud Engineering Enthusiast πŸš€

---