Before changes
Schema validation, business-rule validation, secret-reference checks and read-only host diagnostics identify blockers before installation.
Server5 provides configuration validation, host diagnostics, idempotent installation, production-readiness checks, recovery evidence and reproducible delivery packages for Ubuntu, Docker, Proxmox and K3s environments.
Server5 turns infrastructure preparation into a controlled sequence rather than a collection of unrelated shell commands. One JSON configuration describes the intended edition, license holder, topology, network, host, virtualization, cluster and backup settings. The CLI validates that contract, inspects the target machine, explains required changes, applies approved actions and records evidence.
Schema validation, business-rule validation, secret-reference checks and read-only host diagnostics identify blockers before installation.
Plans are explicit, actions are idempotent and completed work is recorded in an atomic journal without copying secrets.
Readiness checks cover services, nodes, resources, firewall, DNS, TLS, endpoints and backup configuration.
Secret-safe JSON and HTML reports accompany reproducible edition archives, manifests and SHA-256 checksums.
| Capability | Medium | Enterprise |
|---|---|---|
| License holder | One individual | One named company or organization |
| Permitted use | Private, non-business use | Internal organizational use |
| Topology | One Ubuntu Server host with Docker | Ubuntu/Docker or Proxmox/K3s |
| Multi-node growth | Not included | Included for controlled servers |
| Recovery layers | Application data | Application, etcd and VM where configured |
| License term | Perpetual delivered version | Perpetual delivered version |
A company must use Enterprise even when it runs Server5 on one Ubuntu host. Edition is determined by buyer and purpose, not merely server size.
The direct-host path prepares one Ubuntu Server machine for Docker workloads, establishes project directories and validates the operating system, runtime, firewall and application endpoints.
The Enterprise path prepares a VM on Proxmox, bootstraps K3s, supports additional server or agent nodes and separates recovery into virtual-machine, etcd and application-data layers.
Server5 does not hide the underlying platforms. Reports identify actual component versions and preserve operational context for diagnosis and rebuilds.
A single JSON document uses schema version 1. Unknown fields, incompatible edition/topology combinations, invalid networks and plaintext secrets are rejected.
{
"schema_version": 1,
"edition": "medium",
"license_holder": { "type": "individual" },
"topology": "ubuntu-docker",
"host": { "admin_user": "serveradmin", "projects_dir": "/srv/projects" },
"network": { "lan_cidr": "192.168.1.0/24" }
}Start from the edition example included with Server5 and validate before resolving secrets or contacting a target host.
validate.preflight and resolve blockers.plan.install --yes only on the intended target.verify for every applicable target.From the repository root use python product/server5.py. In a delivered Linux package use ./server5. Both expose the same commands.
python product/server5.py --version
python product/server5.py validate --config server5.json
python product/server5.py validate --config server5.json --resolve-secretspython product/server5.py preflight --config server5.json --target auto
python product/server5.py preflight --config server5.json --json --output preflight.jsonpython product/server5.py plan --config server5.json --target auto
sudo ./server5 install --config server5.json --target auto --yessudo ./server5 verify --config server5.json --target ubuntu
sudo ./server5 verify --config server5.json --target k3s-server --json --output verify.json./server5 recovery plan --config server5.json --layer application
sudo ./server5 recovery record --config server5.json --layer application \
--result passed --started-at 2026-10-07T08:00:00Z \
--ended-at 2026-10-07T08:30:00Z --backup-at 2026-10-07T07:45:00Z \
--evidence /srv/evidence/restore.log
./server5 recovery status --config server5.jsonsudo ./server5 report --config server5.json --target auto --output delivery/final
sudo ./server5 monitor --config server5.json --target auto --json
sudo ./server5 update plan --config server5.json --target auto --to-version 1.1.0python product/server5.py release build --edition medium --output-dir dist
python product/server5.py release verify \
--archive dist/server5-1.0.0-rc.1-medium.zip \
--checksum dist/server5-1.0.0-rc.1-medium.zip.sha256| Target | Purpose |
|---|---|
auto | Selects Ubuntu or Proxmox from topology. |
ubuntu | Docker host preparation and platform checks. |
proxmox | VM, storage, bridge and backup-job checks. |
k3s-server | K3s server, etcd and optional S3 snapshots. |
Enterprise evidence may require both Proxmox and K3s reports. One target does not replace another.
{
"token_ref": "file:/root/.server5/secrets/k3s-token",
"access_key_ref": "env:SERVER5_S3_ACCESS_KEY"
}env:NAME resolves an environment variable.file:/absolute/path reads a protected file.0600 and are removed after success or failure.Verification checks resulting state rather than assuming a successful command means a healthy platform. Depending on target, it checks services, Docker, K3s node readiness, workloads, storage, backups, firewall, DNS, TLS and external health endpoints.
Accepted exceptions remain warnings and never convert a failed check into success. Offline mode records that external checks were skipped.
A backup is not treated as proven until a restoration drill is recorded.
Recovery records calculate observed RPO and RTO. Enterprise status requires current successful evidence for every configured layer.
The final delivery report is generated as JSON for automation and HTML for review. It combines configuration identity, inventory, preflight, verification, recovery status, component versions, accepted exceptions and outstanding risks.
Evidence from multiple machines can be imported. Imported documents are validated and secret-like values are removed.
--yes.Medium and Enterprise packages are built separately. Medium excludes Proxmox/K3s content; Enterprise contains the complete topology. File order, timestamps and permissions are normalized so identical sources produce identical bytes.
Every archive includes RELEASE-MANIFEST.json and an external SHA-256. A delivered archive must never be silently replaced under the same version.
| Symptom | Action |
|---|---|
| Configuration rejected | Run validate and correct the reported JSON path. |
| Preflight returns 1 | Resolve every blocker before installation. |
| VMID conflict | Select an unused ID; Server5 will not overwrite a foreign VM. |
| Installation interrupted | Review state, rerun plan, then repeat installation. Completed actions are skipped. |
| Verification blocked | Use JSON output to identify the failing check; do not hide it as an exception. |
| Update blocked | Complete current recovery drills first. |
| Checksum mismatch | Do not use the archive; obtain a verified copy. |
A Server5 license covers the delivered software version and documentation. Unless separately agreed, it does not include installation services, continuous operation, monitoring, maintenance, incident response, future upgrades, hosting or hardware.
The holder remains responsible for access, backups, change windows, application data, compliance and testing before critical changes. Questions may be sent to support@server5.org.