linux-sysadmin-skills / rules
HermeticOrmus/linux-sysadmin-skills/.cursor/rules/linux-sysadmin.mdc
Linux sysadmin workflows for Debian/Ubuntu (apt, systemd, journalctl) covering security, performance, diagnose, monitor, maintain. Confirm before destructive operations.
Cursor rule4 starsChanged 4 months ago
--- description: Linux sysadmin workflows for Debian/Ubuntu (apt, systemd, journalctl) covering security, performance, diagnose, monitor, maintain. Confirm before destructive operations. alwaysApply: false --- # Linux sysadmin workflows Five checklist-driven system administration workflows for Debian/Ubuntu-family machines. Package operations use `apt`; service and log operations use `systemd` and `journalctl`. **Safety rule**: confirm before any destructive operation. Removing packages, editing SSH or firewall config, changing kernel parameters, killing processes, and clearing caches are explained first (including lock-out risk) and wait for approval. Read-only inspection runs without prompting. ## 1. Security Audit and harden: user and access control, SSH hardening, firewall (UFW), updates and patches, services and open ports, file permissions (including SUID/SGID), logs, application and network security, backups. Explain each change's security benefit and lock-out risk before applying. ## 2. Performance Assess CPU, memory, disk, network, and processes. Identify the bottleneck before tuning. Apply targeted changes (kernel parameters in `/etc/sysctl.conf`, service trimming, resource limits) and measure before and after. ## 3. Diagnose Hypothesis-driven loop for a failing service or issue: describe the problem, gather evidence (`journalctl -xe`, `systemctl status <service>`), find patterns, check recent changes, form and test a hypothesis, apply the fix, verify resolution. ## 4. Monitor Read-only health sweep: CPU, memory, disk, network, processes, critical services, temperatures, recent log errors. End with a summary that flags concerns. Make no changes. ## 5. Maintain Routine pass: `apt update && apt upgrade`, `apt autoremove`, clean cache, scan logs (`journalctl -p 3 -b`), check disk (`df -h`), verify critical services, confirm backups. Ask before destructive steps.
Discussion
Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.
Posts are public.Sign in to post
No one has posted yet. Be the first.

