Skrypty operacyjne
A set of a dozen-plus diagnostic scripts that watch the health of our infrastructure. They catch config drift, secrets committed to repos, expiring certs, dead links, missing backups and occupied ports. Routine work that used to eat hours, reduced to a single command.
A dozen-plus diagnostic scripts under one command. Expiring certs, missing backups, secrets committed to a repo, dead links, occupied ports - the things easy to put off until something breaks. One command, a non-zero exit code, and the end of guessing whether someone remembered to check.
Overview
Every infrastructure has a layer of work that is boring right up to the moment it becomes critical. A cert that expires on a Sunday. A backup that has been firing into the void for a month. A secret accidentally committed to a repo. An occupied port that should not be listening. None of it shouts until it is too late.
We gathered those checks into a dozen small scripts and hid them behind one command. The goal was not technical but human: to make infrastructure hygiene stop depending on whether someone remembered to do it. Because memory, as it turns out in practice, is the worst safety mechanism you could pick.
The routine that always loses to deadlines
Infrastructure hygiene is the kind of work you can always do tomorrow. Boring while everything runs, so it politely gives way to things that have a deadline. The trouble is that it has no deadline of its own - until it suddenly has a hard one: the cert expires today, the backup was needed yesterday.
This is not a technical problem. Each of these checks can be done by hand in a minute. The problem is that they require someone to remember them, regularly, in the background of other work - and that is exactly what people do badly. The more things there are to remember, the more surely one drops out, usually the one that would have caught something this time.
One command, one pass
So we reduced the whole routine to a single command that depends on no one's memory. You run it by hand before a deploy or wire it into a schedule and forget it - and that is precisely the intended effect.
What one pass catches
| Check | Catches |
|---|---|
| Certificates | expiring in fewer than N days |
| Backups | last one older than the threshold, or empty |
| Secrets | keys and tokens committed to a repo |
| Links | dead references in docs and config |
| Ports | occupied or listening where they should not be |
| Config drift | one thing in the repo, another on the server |
The contract: the exit code says everything
For anything to plug into CI or cron, it has to speak in an exit code, not a paragraph of text. Zero means clean, anything else means go look. That is the whole contract, and its very simplicity is what makes the tool automatable without any tricks.
The same command has two faces. For a human it prints a readable report - what was checked, what passed, what needs attention. For a machine it returns JSON that can be parsed and hooked into an alert. One entry point, two output forms, no text meant for humans pretending to be an interface for machines.
An alarm that does not ring for no reason
The hardest part of a tool like this is not the checks themselves but the thresholds. An alarm that always rings is worth as much as an alarm turned off - people simply stop reading it, and then it will miss the one time something is genuinely wrong. That is the most common way monitoring goes quiet: not through failure, but through noise.
So every check has a threshold set so the command stays quiet when things are fine. A cert expiring in six months is not an alarm. A cert expiring in a week is. A backup from an hour ago is fine; from a month ago it is not. Thresholds exist so that silence means something.
A tool's silence is only valuable when it is credible. If the command speaks up over trivia, people learn to ignore it, and then it will not warn during a fire. Set the thresholds so that the absence of an alarm genuinely means clean - otherwise you are building noise, not monitoring.
What is left of it
It is not a flashy tool, and it does not need to be. There is no dashboard, no charts, nothing to show in a screenshot. Its whole value is that the routine stopped depending on anyone's memory - it runs itself, and when it stays quiet, that quiet genuinely means clean.
The difference is that the class of problems that used to surface only at failure now surfaces earlier - at a plain pass before a deploy or at a fixed time from cron. An expiring cert gives notice a week ahead, not on a Sunday at three in the morning. That is the whole job of this tool: to turn silence born of ignorance into silence born of certainty.
More projects
More work from the same category - see how we tackle similar challenges.
Have a similar project?
Get in touch - a quote is free and comes back within an hour.



