<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Secure Server Breaking Access]]></title><description><![CDATA[Secure Server Breaking Access]]></description><link>https://server-crack.hashnode.dev</link><image><url>https://cdn.hashnode.com/res/hashnode/image/upload/v1593680282896/kNC7E8IR4.png</url><title>Secure Server Breaking Access</title><link>https://server-crack.hashnode.dev</link></image><generator>RSS for Node</generator><lastBuildDate>Mon, 28 Sep 2026 09:41:01 GMT</lastBuildDate><atom:link href="https://server-crack.hashnode.dev/rss.xml" rel="self" type="application/rss+xml"/><language><![CDATA[en]]></language><ttl>60</ttl><item><title><![CDATA[Building a GCP System Monitoring & Auto-Healing Script with Slack Alerts (Beginner-Friendly DevOps Project)]]></title><description><![CDATA[Introduction
When you're starting out in DevOps, it's easy to get overwhelmed by tools like Kubernetes, Prometheus, or Terraform. But real DevOps thinking starts much simpler:
👉 Can your system detec]]></description><link>https://server-crack.hashnode.dev/building-a-gcp-system-monitoring-auto-healing-script-with-slack-alerts-beginner-friendly-devops-project</link><guid isPermaLink="true">https://server-crack.hashnode.dev/building-a-gcp-system-monitoring-auto-healing-script-with-slack-alerts-beginner-friendly-devops-project</guid><category><![CDATA[monitoring tool]]></category><dc:creator><![CDATA[BOLAJI OPATOLA]]></dc:creator><pubDate>Sun, 03 May 2026 19:03:30 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/69f63c0e0ab374db99206bd4/92999a4b-f691-4673-b098-95f941cd6f45.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Introduction</p>
<p>When you're starting out in DevOps, it's easy to get overwhelmed by tools like Kubernetes, Prometheus, or Terraform. But real DevOps thinking starts much simpler:</p>
<p>👉 Can your system detect problems?</p>
<p>👉 Can it alert you?</p>
<p>👉 Can it fix itself?</p>
<p>In this project, we built a System Monitoring + Auto-Healing Script on Google Cloud (GCP) that:</p>
<p>Monitors CPU, Memory, and Disk usage. Detects if Nginx goes down. Automatically restarts it, sends alerts to Slack, logs everything for visibility</p>
<p>This is a hands-on beginner project that introduces you to observability and self-healing systems, which are core DevOps concepts.</p>
<p><strong>Project Architecture</strong></p>
<p>We used a simple setup:</p>
<p>GCP Virtual Machine (Ubuntu) Bash script for monitoring Cron job for automation, Slack webhook for alerts, Log file for tracking events</p>
<p><em><strong>Step 1:</strong></em> Create a GCP VM</p>
<p>We created a virtual machine using Google Cloud:</p>
<p>OS: Ubuntu 22.04</p>
<p>Machine type: e2-micro (free tier friendly)</p>
<p>Enabled HTTP traffic</p>
<p>Then connected via SSH:</p>
<p><code>gcloud compute ssh your-instance-name</code></p>
<p><em><strong>Step 2:</strong></em> Install Required Tools</p>
<p>We installed Nginx (for simulation) and sysstat:</p>
<p><code>sudo apt update sudo apt install -y nginx sysstat</code></p>
<p>Start and enable Nginx:</p>
<p><code>sudo systemctl start nginx sudo systemctl enable nginx</code></p>
<p><em><strong>Step 3:</strong></em> Create the Monitoring Script</p>
<p>We created a Bash script:</p>
<p><code>nano monitor.sh</code></p>
<p>The script performs:</p>
<p>i. CPU Check</p>
<p><code>CPU_USAGE=\((top -bn1 | grep "Cpu(s)" | awk '{print 100 - \)8}' | cut -d. -f1)</code></p>
<p>ii. Memory Check</p>
<p><code>MEM_USAGE=\((free | awk '/Mem/ {printf("%.0f"), \)3/$2 * 100.0}')</code></p>
<p>iii. Disk Check</p>
<p><code>DISK_USAGE=\((df / | awk 'NR==2 {print \)5}' | sed 's/%//')</code></p>
<p>iv. Nginx Health Check</p>
<p><code>if ! systemctl is-active --quiet nginx; then</code></p>
<p><code>sudo systemctl restart nginx</code></p>
<p><code>fi</code></p>
<p>v. Slack Alerts</p>
<p>We used a Slack webhook:</p>
<p><code>curl -X POST -H 'Content-type: application/json'   --data '{"text":"Alert message"}' YOUR_WEBHOOK_URL</code></p>
<p><em><strong>Step 4:</strong></em> Make Script Executable</p>
<p><code>chmod +x</code> <a href="http://monitor.sh"><code>monitor.sh</code></a></p>
<p><em><strong>Step 5:</strong></em> Automate with Cron</p>
<p>We scheduled the script to run every minute:</p>
<p><code>crontab -e</code></p>
<p>Add:</p>
<ul>
<li><p><code>* * * * * /home/your-username/monitor.sh</code></p>
</li>
<li><p><em><strong>Step 6:</strong></em> Simulate Failures Nginx Failure</p>
</li>
<li><p><code>sudo systemctl stop nginx</code></p>
</li>
</ul>
<p>Result:</p>
<p>Script detects failure Restarts Nginx Sends Slack alert 🔥 High CPU Usage yes &gt; /dev/null &amp;</p>
<p>This project teaches real DevOps fundamentals:</p>
<p><mark class="bg-yellow-200 dark:bg-yellow-500/30">Observability Metrics (CPU, memory, disk) Logs Alerts</mark></p>
<p><mark class="bg-yellow-200 dark:bg-yellow-500/30">Automation Cron jobs Continuous monitoring</mark></p>
<p><mark class="bg-yellow-200 dark:bg-yellow-500/30">Self-Healing Systems Detect failure Recover automatically</mark></p>
<p><mark class="bg-yellow-200 dark:bg-yellow-500/30">Production Thinking Don’t wait for users to report issues Systems should detect and react</mark></p>
<p>🎥 Full Walkthrough Video<br /><a href="https://drive.google.com/drive/folders/1OAXNUZsIjBp7igSE%5C_Xz608shn-hV2pQo?usp=sharing">https://drive.google.com/drive/folders/1OAXNUZsIjBp7igSE\_Xz608shn-hV2pQo?usp=sharing</a></p>
<p><strong>Final Thoughts</strong></p>
<p>This project may look simple, but it introduces the mindset that defines DevOps:</p>
<p>Build systems that monitor themselves, alert you, and recover automatically</p>
<p>If you're new to DevOps, this is one of the best practical starting points.</p>
]]></content:encoded></item><item><title><![CDATA[Server Hardening & Recovery Drill on GCP (From Setup to Total Lockout and Recovery)]]></title><description><![CDATA[This wasn’t just a setup tutorial. This was a controlled disaster.
In this guide, I’ll walk you through:

Setting up a VM on GCP

Hardening it like a real server

Breaking it (intentionally)

And reco]]></description><link>https://server-crack.hashnode.dev/server-hardening-recovery-drill-on-gcp-from-setup-to-total-lockout-and-recovery</link><guid isPermaLink="true">https://server-crack.hashnode.dev/server-hardening-recovery-drill-on-gcp-from-setup-to-total-lockout-and-recovery</guid><category><![CDATA[secure server]]></category><dc:creator><![CDATA[BOLAJI OPATOLA]]></dc:creator><pubDate>Sat, 02 May 2026 18:58:43 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/69f63c0e0ab374db99206bd4/71289faa-413c-44f3-a221-d72e012ce1c1.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This wasn’t just a setup tutorial. This was a <strong>controlled disaster</strong>.</p>
<p>In this guide, I’ll walk you through:</p>
<ul>
<li><p>Setting up a VM on GCP</p>
</li>
<li><p>Hardening it like a real server</p>
</li>
<li><p>Breaking it (intentionally)</p>
</li>
<li><p>And recovering it like an SRE</p>
</li>
</ul>
<hr />
<h2>Project Overview</h2>
<p>The goal was simple:</p>
<blockquote>
<p>Build a secure server → break it → recover it.</p>
</blockquote>
<p>But what actually happened?</p>
<ul>
<li><p>I locked myself out of SSH completely</p>
</li>
<li><p>Even GCP browser SSH stopped working</p>
</li>
<li><p>I had to mount the disk on another VM to recover it</p>
</li>
</ul>
<p>This is real-world failure simulation.</p>
<hr />
<h2>Step 1: VM Setup on GCP</h2>
<p>I created a VM instance using Ubuntu.</p>
<p>Immediately after setup, I ran a custom <strong>bash script</strong> to prepare the system:</p>
<pre><code class="language-bash">#!/bin/bash
sudo apt update &amp;&amp; sudo apt upgrade -y
</code></pre>
<p>This ensured the system was up-to-date from the start.</p>
<hr />
<h2>Step 2: Install Nginx</h2>
<pre><code class="language-bash">sudo apt install nginx -y
sudo systemctl status nginx
</code></pre>
<p>At this point, the server was live and accessible via its public IP.</p>
<hr />
<h2>Step 3: Server Hardening</h2>
<p>This is where things got serious.</p>
<hr />
<h3>Create a new user</h3>
<pre><code class="language-bash">sudo adduser devops
sudo usermod -aG sudo devops
</code></pre>
<hr />
<h3>Setup SSH Key Authentication (Ed25519)</h3>
<p>On my local machine:</p>
<pre><code class="language-bash">ssh-keygen -t ed25519 -C "devops-access"
</code></pre>
<p>Then I added the public key to:</p>
<pre><code class="language-bash">/home/devops/.ssh/authorized_keys
</code></pre>
<p>And fixed permissions:</p>
<pre><code class="language-bash">chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys
</code></pre>
<hr />
<h3>Disable Password Login</h3>
<p>Edited:</p>
<pre><code class="language-bash">sudo nano /etc/ssh/sshd_config
</code></pre>
<p>Set:</p>
<pre><code class="language-text">PasswordAuthentication no
PermitRootLogin no
PubkeyAuthentication yes
</code></pre>
<hr />
<h3>Firewall Setup (UFW)</h3>
<pre><code class="language-bash">sudo ufw allow OpenSSH
sudo ufw allow 'Nginx Full'
sudo ufw enable
</code></pre>
<hr />
<h3>Install Fail2Ban</h3>
<pre><code class="language-bash">sudo apt install fail2ban -y
sudo systemctl enable fail2ban
</code></pre>
<hr />
<h2>Step 4: Breaking the System (The Fun Part)</h2>
<p>This is where things went sideways—in a good way.</p>
<hr />
<h3>❌ SSH Lockout</h3>
<p>I added this to my SSH config:</p>
<pre><code class="language-text">AllowUsers somefakeuser
</code></pre>
<p>Then restarted SSH:</p>
<pre><code class="language-bash">sudo systemctl restart ssh
</code></pre>
<p>Result:</p>
<ul>
<li><p>SSH access denied</p>
</li>
<li><p>GCP browser SSH failed</p>
</li>
<li><p>Total lockout</p>
</li>
</ul>
<hr />
<h3>❌ Kill Nginx</h3>
<pre><code class="language-bash">sudo pkill nginx
</code></pre>
<p>Now:</p>
<ul>
<li><p>Website down</p>
</li>
<li><p>Server inaccessible</p>
</li>
</ul>
<hr />
<h2>What Went Wrong?</h2>
<p>The line:</p>
<pre><code class="language-text">AllowUsers somefakeuser
</code></pre>
<p>Whitelists SSH users.</p>
<p>Since <code>somefakeuser</code> didn’t exist: 👉 <strong>No one could log in</strong></p>
<hr />
<h2>🛠️ Step 5: Recovery (The Real Learning)</h2>
<p>At this point, normal recovery methods failed.</p>
<p>Even GCP SSH depends on a working SSH config.</p>
<p>So I had to go deeper.</p>
<hr />
<h3>Disk Recovery Strategy</h3>
<ol>
<li><p>Stopped the original VM</p>
</li>
<li><p>Detached its boot disk</p>
</li>
<li><p>Attached it to a rescue VM</p>
</li>
<li><p>Mounted it manually</p>
</li>
</ol>
<pre><code class="language-bash">sudo mount /dev/sdb1 /mnt/recovery
</code></pre>
<hr />
<h3>Fix SSH Config Offline</h3>
<pre><code class="language-bash">sudo nano /mnt/recovery/etc/ssh/sshd_config
</code></pre>
<p>Removed:</p>
<pre><code class="language-text">AllowUsers somefakeuser
</code></pre>
<p>Replaced with safe config:</p>
<pre><code class="language-text">PasswordAuthentication yes
PermitRootLogin no
PubkeyAuthentication yes
</code></pre>
<hr />
<h3>Restore VM</h3>
<ul>
<li><p>Detached disk from rescue VM</p>
</li>
<li><p>Reattached it as boot disk</p>
</li>
<li><p>Restarted original VM</p>
</li>
</ul>
<hr />
<h2>Result</h2>
<ul>
<li><p>SSH access restored ✅</p>
</li>
<li><p>Nginx restarted ✅</p>
</li>
<li><p>Server fully recovered ✅</p>
</li>
</ul>
<hr />
<h2>Key Lessons</h2>
<h3>1. SSH Misconfiguration = Total Outage</h3>
<p>One wrong line can lock you out completely.</p>
<hr />
<h3>2. Always Test Before Restarting SSH</h3>
<pre><code class="language-bash">sudo sshd -t
</code></pre>
<hr />
<h3>3. Keep a Backup Access Path</h3>
<p>Cloud console ≠ guaranteed access.</p>
<hr />
<h3>4. Disk Recovery is a Lifesaver</h3>
<p>Mounting a disk on another VM is a <strong>real-world recovery technique</strong>.</p>
<hr />
<h3>5. Think Like an SRE</h3>
<p>This wasn’t just setup—it was:</p>
<ul>
<li><p>Failure simulation</p>
</li>
<li><p>Incident response</p>
</li>
<li><p>System recovery</p>
</li>
</ul>
<hr />
<h2>Final Thoughts</h2>
<p>This project changed how I think about servers.</p>
<p>It’s easy to follow tutorials. It’s different when:</p>
<ul>
<li><p>You break things</p>
</li>
<li><p>You get locked out</p>
</li>
<li><p>And you still recover</p>
</li>
</ul>
<p>That’s where real learning happens.</p>
<hr />
]]></content:encoded></item></channel></rss>