Free Server Tool — 100% In-Browser

Initial Server Setup Assistant — Web Builder

The Systron Initial Server Setup Assistant for AlmaLinux and Rocky Linux asks a dozen questions in the terminal. Answer them here with dropdowns and validation instead of typos — then copy the exact command with every parameter filled in, or share a pre-configured link with your team.

setup-assistant --build hostname = server1.example.com timezone = Asia/Kolkata ssh-port = 2222 webserver = nginx generated locally

Answer the Questions Once, Correctly

The Systron Initial Server Setup Assistant hardens a fresh AlmaLinux or Rocky Linux server in 25 guided steps — but it needs several values from you: FQDN, timezone, administrator username and email, SSH port and the web server to install. Typing those by hand at each prompt is where mistakes creep in: a wrong timezone, an invalid username, a forgotten SELinux port.

This builder turns every question into a form field with validation and dropdowns (including the full IANA timezone list), then generates the ready-to-paste command with all parameters — plus a shareable URL that pre-fills this page for the next run. Everything is computed in your browser.

1. Fill the Form

Every question the assistant asks — FQDN, timezone, admin account, SSH port, web server, run mode — as validated fields with safe defaults.

2. Copy the Command

The exact download + run command with all --flags filled in. The script still shows each value and lets you confirm interactively.

3. Or Share the Link

A URL like ?hostname=...&timezone=Asia/Kolkata that pre-fills this page — perfect for handing a repeatable setup to a colleague.

4. Review & Run

Review the downloaded script, then run it as root. Lockout-sensitive SSH changes still require explicit confirmation in the terminal.

Initial Server Setup Builder

This page is plain JavaScript in your browser. Nothing you type — hostnames, emails, IPs — is uploaded anywhere. The generated commands download the script from the official Systron GitHub repository.

The 25 Steps Your Generated Command Unlocks

The Systron Initial Server Setup Assistant (v1.1.1, MIT) runs this sequence on a fresh AlmaLinux or Rocky Linux server. Your answers pre-fill the values used in steps 3–4, 8–9, 11–14, 22 and 24.

1
OS & kernel checkVerifies AlmaLinux/Rocky version and kernel before any change
2
System updatesRefreshes repository metadata and installs security updates
3
Hostname (FQDN)Sets your --hostname value with hostnamectl
4
TimezoneSets your --timezone after validating it exists
5
ChronyInstalls and verifies network time synchronization
6
Admin utilitiesnano, vim, curl, rsync, git, bind-utils, lsof and more
7
EPELEnables the EPEL repository where available
8
Non-root adminCreates --admin-user with wheel-group sudo
9
SSH keysCopies root authorized_keys to the new admin safely
10
OpenSSH hardeningDisables root/password login — only after key login is verified
11
SSH portOptional --ssh-port change with firewalld + SELinux handling
12
FirewalldEnables the host firewall; opens SSH, HTTP, HTTPS for web servers
13
SELinuxVerifies enforcing mode; installs troubleshooting utilities
14
Fail2BanSSH jail on your port — 5 retries, 10 min window, 1 h ban
15
SwapInspects swap; optionally creates a 2G file with disk-space guard
16
Auto security updatesdnf-automatic with security-only upgrade type
17
DNS & routingChecks addressing, routes, resolver and public IPv4
18
Ports & servicesLists listening sockets, running and failed units
19
ResourcesDisk, inode, RAM, CPU and load overview
20
Critical logsRecent error-priority journal entries from this boot
21
Reverse DNS / PTRChecks the PTR record of your public IP
22
Web serverInstalls your --webserver: Nginx, Apache or OpenLiteSpeed
23
MariaDB (optional)Local database only when the application needs it
24
Root login alertsEmails --admin-email on interactive root SSH logins
25
Final health reportOne-screen summary: SSH, Chrony, firewalld, SELinux, swap

Safety design (built into the assistant)

  • Potential SSH lockout changes require explicit confirmation — even in Run All mode
  • Existing configuration files are backed up before risky edits
  • The script continues past non-critical package failures where safe
  • A dry-run mode previews every command without changing the server

What the Assistant Does With Your Answers

Your answerParameterUsed by the assistant for
Server FQDN--hostnamehostnamectl set-hostname — logging, TLS and mail identity
Timezone--timezonetimedatectl set-timezone — logs, cron, TLS validity, databases
Admin username--admin-userNon-root sudo account in the wheel group; SSH keys copied from root
Admin email--admin-emailOptional root-SSH-login email alerts; shown in the final health report
SSH port--ssh-portOptional port change with firewalld + SELinux handling; Fail2Ban jail port
Web server--webserverInstalls Nginx, Apache or OpenLiteSpeed (official LiteSpeed repo)
Run mode--modestep confirms each section; all runs the safe baseline end-to-end
Dry run--dry-runPrints every command without executing anything — ideal first review

Initial Server Setup Builder — FAQ

Does the generated command run the script automatically?

No — and by design. The command downloads the assistant, makes it executable and runs it with your parameters as defaults. The assistant still displays each value and lets you accept or change it interactively, and lockout-sensitive SSH steps always require explicit confirmation in the terminal.

Which Linux distributions does the assistant support?

AlmaLinux 8/9/10 and Rocky Linux 8/9/10. The script verifies the OS from /etc/os-release and exits on anything else. It uses dnf, firewalld, SELinux and systemd throughout.

What does the shareable URL contain?

Only the answers you entered, as query parameters — hostname, timezone, username, email, port, web server, mode and the optional IP. When someone opens that link, this page pre-fills the form from the URL. Nothing is stored on any server; the parameters simply travel inside the link you share.

Why should I run the dry-run first?

The dry-run prints every command the assistant would execute — package installs, firewall rules, sshd edits — without changing the server. It is the fastest way to review the full plan, and it is exactly how the assistant itself is designed to be audited.

Is changing the SSH port worth it?

It reduces automated noise in your logs but is not a security fix on its own — real protection comes from SSH keys, disabling password login, firewalld and Fail2Ban, all of which the assistant sets up. If you do change the port, the assistant handles firewalld and SELinux labels and keeps port 22 open until you verify the new port works.

Can I trust running a script downloaded from GitHub?

The generated commands download from the official Systron repository, but you should always review the script before running it with root privileges — the recommended command includes that review step. The assistant is MIT-licensed and its full source is public on GitHub.

Related Free Server Tools

24/7 Support Available:

Our support team is here to assist you around the clock. Get Expert Help, Anytime.