1.5 KiB
1.5 KiB
Scripts
This directory is for operational scripts used after Atlas is installed.
What Belongs Here
- Backup scripts.
- Restore scripts.
- Deployment scripts.
- Maintenance scripts.
- Monitoring scripts.
- Service validation helpers.
- Read-only system discovery and host validation scripts.
What Must Not Be Stored Here
- Installation phase scripts. Those belong in
install/. - Secrets or credentials.
- Generated logs.
- Temporary files.
- Build artefacts.
- One-off experimental commands.
Naming Conventions
- Use lower-case hyphenated names.
- Prefer verb-target names, such as
backup-sql.shorcheck-disk-space.sh. - Group scripts by operational area when useful.
- Executable permissions should be used only for scripts intended to run directly.
Expected Future Structure
Current planned areas include:
scripts/backup/
scripts/development/
scripts/deploy/
scripts/maintenance/
scripts/monitoring/
scripts/restore/
scripts/sql/
scripts/system/
Additional areas may be added when a repeated operational need exists.
Security Considerations
- Do not print secrets.
- Do not store credentials in scripts.
- Make destructive actions explicit and documented.
- Include validation and rollback guidance for service-affecting scripts.
- Discovery and validation scripts must not dump environment variables, private keys, tokens, or complete sensitive configuration files.
- SQL helper scripts must not embed or print SQL administrator passwords.
- Firewall inspection should use
sudo ufw status numbered.