🧰 Stop fixing what isn't broken — 33 free tools + the 6-step check that proves it first

:toolbox: Prove it first — one real server day where doing nothing was the fix

One day on a company server: a web page answering with an error, a request that timed out, and drives labelled as something they were not.

All three looked like faults, and all three were fine — the move that saved the data was the move nobody made.

The habit that told them apart — six steps you can run on your own machine.

:brain: My rule for the whole day — the same six steps you tick below, in my own capitals:

OBSERVE -> PROVE -> PASS
DOCUMENT -> CHANGE -> VERIFY AGAIN

:world_map: The day in one glance

digraph day { rankdir=LR; graph [bgcolor="transparent", pad="0.25", nodesep="0.5", ranksep="0.95"]; node [shape=box, style="rounded,filled", fillcolor="#f4f5f3", color="#1c2a2e", fontcolor="#1c2a2e", fontname="Helvetica", fontsize=12, margin="0.2,0.14", penwidth=1.2]; edge [color="#a89a7c", penwidth=1.3, arrowsize=0.8, fontcolor="#6b6a5f", fontname="Helvetica", fontsize=10]; day [label="one day, five problems", fillcolor="#1c2a2e", fontcolor="#f4f5f3"]; a [label="two cables, one link\nproved by a restart", fillcolor="#eaf0ea", color="#4f6b52"]; b [label="the files were fine\nleft alone", fillcolor="#f2efe9", color="#8a7f63"]; c [label="18 live pages changed\nold copy kept", fillcolor="#eef1f4", color="#41586b"]; d [label="two fixes held back\nreasons written down", fillcolor="#f0eaea", color="#8f5f68"]; o [label="nothing lost\none real gap found", fillcolor="#f4f5f3", color="#a89a7c"]; day -> a; day -> b; day -> c; day -> d; a -> o; b -> o; c -> o; d -> o; }

:receipt: What the wrong move would have cost

What it looked like What the wrong move costs What the machine proved
Two cables that should work as one internet drops at the next restart both came back as one link
Hard drives carrying old labels from a past job healthy storage erased for good nothing was touched
A folder called backup a restore with nothing in it gap found, plan fixed
A path between two machines the reason hidden, not solved left as it is, reason written down
A page that did not exist yet eighteen live pages edited with no way back page built, eighteen pages updated

:white_check_mark: The six steps, and why each one exists

  • Look first — note what you see before you touch it; that note is your way back
  • Prove it — the machine’s own report settles what a guess cannot
  • Let it pass — anything a restart forgets is unfinished work
  • Write it down — the reason goes on the record before the change
  • Change one thing — two changes hide which one mattered
  • Check again — that is the proof it worked
📦 The day's own toolkit — 33 free tools, sorted by the six steps

:gem_stone: rare find · :green_circle: nothing to install, it is already on the box · take what you need and skip the rest

Pick one, run it once, and you have done that step for real.

1 · OBSERVE — look first: see what is really there. (that day: drives wearing someone else’s labels)

2 · PROVE — ask the machine, not a guess. (that day: a backup path that answered nothing)

3 · PASS — let it prove itself. (that day: a reboot that brought everything back)

4 · DOCUMENT — write it down before you change it. (that day: a reason written down instead of a route typed)

5 · CHANGE — one thing at a time. (that day: eighteen pages edited with a copy kept)

6 · VERIFY AGAIN — check it after. (that day: the same check, run again)

Same method, already on this board, written by me: onehack.st/t/325503 — my two-minute self-undo timer for a live network change · onehack.st/t/325527 — my updater that finds every copy and undoes a failed update · onehack.st/t/326190 — my router rebuild on this same server


:joker: The answer came from the machine, not a guess — and the day’s best work was touching nothing.


:postbox: Your problem, worked live

Send a machine, a script, a route that goes somewhere impossible to Ask Us Live.

Picked for what they teach, then solved live on 2026-10-17T18:30:00Z — nothing staged, nothing rehearsed.

Open ones stay up with the notes.

Bring it in onehack.st/tag/help.

🔍 The day, problem by problem

Two network cards bonded into one link. I wanted two physical cards working as one link, the 802.3ad/LACP setup in the kernel’s own bonding document. The file said the bond existed. Reality had both cards answering on their own while the bond sat with no working members. I read it, rebuilt it, then rebooted: the bond, both members, the address, the route and the internet all came back by themselves. A configuration that survives a restart is the one worth keeping.

A tunnel with its own identity. A remote host needed management access through an existing WireGuard tunnel into the OPNsense edge. Copying an existing client configuration was the fast move, and the wrong one: every client needs its own cryptographic identity. So the host got a unique private key, a unique public key, a unique tunnel address and its own peer entry — and the private key stayed on the machine, out of the conversation. I brought the tunnel up by hand first, not at boot. Prove it, then make it permanent.

The remote host that runs production. This host runs production infrastructure on pve.proxmox.com, so before a single backup command I inventoried everything: the backup filesystem held 1.1 TB total, about 250 GB used and 793 GB free; the root filesystem sat healthy at 94 GB total with 76 GB free; and the thin pool held far less real data than the sum of all provisioned disk sizes suggested. Provisioned capacity is not allocated blocks. Running on it: one OPNsense virtual machine and fifteen containers.

Drives wearing someone else’s labels. Several drives carried old Linux RAID labels from an earlier life, so I left those labels alone and asked the storage itself: two OpenZFS mirrors, both pools ONLINE, zero read errors, zero write errors, zero checksum errors, healthy SMART status, so nothing was touched.

The path that needed proving. The remote host needed to reach the independent backup server at home. Ten packets sent, none received, 100% loss. The easy move was to say “it just needs a static route” and type one. I did not.

Following the traffic to the next hop. The remote host has an internal transit network to its OPNsense VM. I identified the OPNsense address on that network and tested that address alone — which explained the path. The route stayed unwritten on purpose, with the reason written down instead: a route typed to quieten a symptom hides why the symptom came.

A folder named backup, one machine away from being real. A directory by that name held copies on the same machine: useful staging, and one failure away from being the only copy. Following where the data would actually travel after a failure showed the gap, in writing. The return path is scheduled now, which is worth more than a green tick on a status page.

The page the day built. The day’s other half was a public page where people send in a problem — I called it Ask Us Live. Deploying it immediately demonstrated the method: one deploy, then the same check again. Then the production navigation: I searched the live document root first and found 18 pages carrying the sequence, updated all 18, verified all 18 links, and kept the previous version for a rollback.

Nine things I deliberately did not touch: the disks with strange labels, the WireGuard tunnel at boot, the bond before its reboot, backups written onto the root filesystem, a static route, NGINX answering 404 and then 301, the firewall during a timed-out test, and eighteen production pages without a way back. In several cases the best engineering decision of the day was: leave it alone until the proof says otherwise.

What ChatGPT actually did. It held the context, questioned my assumptions and built the safe step-by-step checks.

It administered nothing: I had the consoles and the commands.

Where a suggestion met a system that proved otherwise, the suggestion changed — the reading did not.[1]

Tomorrow: prove the backup return path end to end, then install it. Something else will break soon enough, and I would rather prove why before I fix it.


  1. The useful question about an assistant is not was it right the first time — it is did the process end up agreeing with the machine. ↩︎

:top_arrow: The post above is now a clearer version, upgraded with AI by the Core-Community.