Skip to content
Shellbay

Server workflows

Guided recipes that set up a server for you. Shellbay asks for everything up front, checks your server before changing anything, and shows the exact script before it runs. Browse every workflow and read its script for free in the app; running them is part of Shellbay Pro.

25 workflows

  • Web & TLS · about 2 min

    Nginx web server

    Installs Nginx from your distribution's packages, starts it and keeps it running after reboots.

  • Web & TLS · about 3 min

    HTTPS certificate with Certbot

    Gets a free Let's Encrypt certificate for your domain, turns on HTTPS in Nginx and renews it automatically.

  • Web & TLS · about 1 min

    Nginx reverse proxy

    Sends visitors of your domain to an app running on this server, such as a Node.js or Python service.

  • Web & TLS · about 2 min

    Caddy web server

    Installs Caddy, a web server that gets and renews HTTPS certificates by itself.

  • Web & TLS · about 2 min

    Apache HTTP Server

    Installs the Apache web server from your distribution, starts it and keeps it running.

  • Runtimes · about 2 min

    Node.js LTS

    Installs a long-term-support release of Node.js and npm from NodeSource.

  • Runtimes · about 2 min

    Python 3 with venv and pipx

    Installs Python 3, virtual environments and pipx for installing Python command-line tools safely.

  • Runtimes · about 2 min

    Go

    Installs Go 1.27.1 from go.dev into /usr/local/go, checked against a pinned SHA-256.

  • Runtimes · about 3 min

    Java 21 (OpenJDK)

    Installs the OpenJDK 21 long-term-support release, headless, for running Java services.

  • Runtimes · about 2 min

    PHP-FPM

    Installs PHP with the FastCGI process manager, and a ready-to-include Nginx snippet if Nginx is installed.

  • Containers · about 4 min

    Docker Engine and Compose

    Installs Docker Engine with the Compose plugin from Docker's official repository.

  • Containers · about 2 min

    Portainer CE

    Runs Portainer, a web interface for managing Docker, reachable only through an SSH port forward.

  • Databases · about 3 min

    PostgreSQL

    Installs PostgreSQL from your distribution, listening on this server only.

  • Databases · about 3 min

    MariaDB (secured)

    Installs MariaDB listening on this server only, with anonymous users, remote root and the test database removed.

  • Databases · about 2 min

    Redis (or Valkey)

    Installs Redis, or Valkey where the system replaced Redis with it, listening on this server only.

  • Databases · about 4 min

    MongoDB Community 8.0

    Installs MongoDB Community 8.0 from MongoDB's repository, listening on this server only.

  • Security & Hardening · about 2 min

    Firewall baseline

    Blocks incoming connections except SSH and the ports you choose. Outgoing traffic is allowed.

    High risk: confirms before running

  • Security & Hardening · about 2 min

    Fail2ban for SSH

    Blocks addresses that repeatedly fail to sign in over SSH, for an hour at a time.

  • Security & Hardening · about 1 min

    SSH hardening

    Turns off root sign-in and password sign-in, so only SSH keys can sign in.

    High risk: confirms before running

  • Security & Hardening · about 2 min

    Automatic security updates

    Installs security updates automatically every day.

  • Server Operations · about 1 min

    Create a sudo user

    Adds an account that signs in with your SSH key and can use sudo, so you don't need root.

  • Server Operations · about 3 min

    Swap file

    Adds a swap file so the server slows down instead of stopping programs when memory runs out.

  • Server Operations · about 1 min

    Time zone and time sync

    Sets the server's time zone and keeps its clock accurate with network time.

  • Server Operations · about 3 min

    Netdata monitoring

    Installs Netdata for live CPU, memory, disk and network charts, reachable only through an SSH port forward.

  • Server Operations · about 2 min

    Tailscale

    Installs Tailscale to reach this server over your private tailnet; you sign in with a link it prints.

Supported distributions

Shellbay detects the server's distribution and checks it before changing anything.

DistributionFamilyMinimum version
UbuntuDebian / Ubuntu22.04
DebianDebian / Ubuntu12
Raspberry Pi OSDebian / Ubuntu12
Red Hat Enterprise LinuxRHEL / Fedora9
Rocky LinuxRHEL / Fedora9
AlmaLinuxRHEL / Fedora9
CentOS StreamRHEL / Fedora9
Oracle LinuxRHEL / Fedora9
FedoraRHEL / Fedora43
Alpine LinuxAlpine3.19