# 🧰 Stop fixing what isn't broken — 33 free tools + the 6-step check that proves it first

**URL:** <https://onehack.st/t/stop-fixing-what-isnt-broken-33-free-tools-the-6-step-check-that-proves-it-first/326198>\
**Category:** Tutorials & Methods\
**Tags:** networking, tips-tricks, self-hosted-tools\
**Created:** [October 3, 2026, 2:25pm UTC](https://onehack.st/t/stop-fixing-what-isnt-broken-33-free-tools-the-6-step-check-that-proves-it-first/326198 "2026-10-03T14:25:23Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![BCBC](https://onehack.st/user_avatar/onehack.st/bcbc/32/174133_2.png) [@BCBC](https://onehack.st/u/BCBC)\
**Post date:** [October 3, 2026, 2:25pm UTC](https://onehack.st/t/stop-fixing-what-isnt-broken-33-free-tools-the-6-step-check-that-proves-it-first/326198/1 "2026-10-03T14:25:24Z")

</div>

### 🧰 Prove it first — one real server day where doing nothing was the fix

One day on a company server: a web page answering with an error, a request that timed out, and drives labelled as something they were not.

All three looked like faults, and all three were fine — the move that saved the data was the move nobody made.

The habit that told them apart — six steps you can run on your own machine.

**🧠 My rule for the whole day** — the same six steps you tick below, in my own capitals:

```auto
OBSERVE -> PROVE -> PASS
DOCUMENT -> CHANGE -> VERIFY AGAIN

```

* * *

**🗺 The day in one glance**

digraph day { rankdir=LR; graph [bgcolor="transparent", pad="0.25", nodesep="0.5", ranksep="0.95"]; node [shape=box, style="rounded,filled", fillcolor="#f4f5f3", color="#1c2a2e", fontcolor="#1c2a2e", fontname="Helvetica", fontsize=12, margin="0.2,0.14", penwidth=1.2]; edge [color="#a89a7c", penwidth=1.3, arrowsize=0.8, fontcolor="#6b6a5f", fontname="Helvetica", fontsize=10]; day [label="one day, five problems", fillcolor="#1c2a2e", fontcolor="#f4f5f3"]; a [label="two cables, one link\nproved by a restart", fillcolor="#eaf0ea", color="#4f6b52"]; b [label="the files were fine\nleft alone", fillcolor="#f2efe9", color="#8a7f63"]; c [label="18 live pages changed\nold copy kept", fillcolor="#eef1f4", color="#41586b"]; d [label="two fixes held back\nreasons written down", fillcolor="#f0eaea", color="#8f5f68"]; o [label="nothing lost\none real gap found", fillcolor="#f4f5f3", color="#a89a7c"]; day -\> a; day -\> b; day -\> c; day -\> d; a -\> o; b -\> o; c -\> o; d -\> o; }

* * *

**🧾 What the wrong move would have cost**

| What it looked like | What the wrong move costs | What the machine proved |
| --- | --- | --- |
| Two cables that should work as one | internet drops at the next restart | both came back as one link |
| Hard drives carrying old labels from a past job | healthy storage erased for good | nothing was touched |
| A folder called _backup_ | a restore with nothing in it | gap found, plan fixed |
| A path between two machines | the reason hidden, not solved | left as it is, reason written down |
| A page that did not exist yet | eighteen live pages edited with no way back | page built, eighteen pages updated |

* * *

**✅ The six steps, and why each one exists**

- **Look first** — note what you see before you touch it; that note is your way back
- **Prove it** — the machine’s own report settles what a guess cannot
- **Let it pass** — anything a restart forgets is unfinished work
- **Write it down** — the reason goes on the record before the change
- **Change one thing** — two changes hide which one mattered
- **Check again** — that is the proof it worked

> **📦 The day's own toolkit — 33 free tools, sorted by the six steps**
>
> 💎 rare find · 🟢 nothing to install, it is already on the box · take what you need and skip the rest
> 
> Pick one, run it once, and you have done that step for real.
> 
> **1 · OBSERVE — look first: see what is really there.** _(that day: drives wearing someone else’s labels)_
> 
> - 💎 **See what every network card is really doing** — nic-xray · [github.com/ciroiriarte/nic-xray](https://github.com/ciroiriarte/nic-xray)
> - **Ask the switch what that cable is plugged into** — lldpd · [github.com/lldpd/lldpd](https://github.com/lldpd/lldpd)
> - 🟢 **Find out what an old RAID label really is** — mdadm --examine · [man7.org/linux/man-pages/man8/mdadm.8](https://www.man7.org/linux/man-pages/man8/mdadm.8.html)
> - 🟢 **Read the storage’s own record without touching it** — zdb -l · [openzfs.github.io — zdb.8](https://openzfs.github.io/openzfs-docs/man/master/8/zdb.8.html)
> - 💎 **Take a ZFS disk apart on paper, trusting no pool** — zfs-forensic · [github.com/SecurityRonin/zfs-forensic](https://github.com/SecurityRonin/zfs-forensic)
> - **Watch a drive’s health over months, not minutes** — Scrutiny · [github.com/AnalogJ/scrutiny](https://github.com/AnalogJ/scrutiny)
> - **See the honest free-space numbers at a glance** — duf · [github.com/muesli/duf](https://github.com/muesli/duf)
> 
> **2 · PROVE — ask the machine, not a guess.** _(that day: a backup path that answered nothing)_
> 
> - **Watch one hop alone, with loss per hop** — trippy · [github.com/fujiapple852/trippy](https://github.com/fujiapple852/trippy)
> - 💎 **See the whole route drawn on a map, in a window** — OpenTrace · [github.com/Archeb/opentrace](https://github.com/Archeb/opentrace)
> - **Read the bond’s own negotiation frames** — termshark · [github.com/gcla/termshark](https://github.com/gcla/termshark)
> - **Name the process sending packets that go unanswered** — bandwhich · [github.com/imsnif/bandwhich](https://github.com/imsnif/bandwhich)
> - **Get a shell that already holds every network tool** — netshoot · [github.com/nicolaka/netshoot](https://github.com/nicolaka/netshoot)
> 
> **3 · PASS — let it prove itself.** _(that day: a reboot that brought everything back)_
> 
> - **Check a backup archive without restoring it** — vma verify · [pve.proxmox.com/wiki/VMA](https://pve.proxmox.com/wiki/VMA)
> - 🟢 **See what is really mounted, not what the config says** — findmnt --verify · [man7.org/linux/man-pages/man8/findmnt.8](https://man7.org/linux/man-pages/man8/findmnt.8.html)
> - **Test a drive before it holds anything you care about** — disk-burnin-and-testing · [github.com/Spearfoot/disk-burnin-and-testing](https://github.com/Spearfoot/disk-burnin-and-testing)
> 
> **4 · DOCUMENT — write it down before you change it.** _(that day: a reason written down instead of a route typed)_
> 
> - 🟢 **Put your whole settings folder in git** — etckeeper · [etckeeper.branchable.com](https://etckeeper.branchable.com/)
> - 💎 **Freeze a machine’s entire configuration into one file** — cfg2html · [github.com/cfg2html/cfg2html](https://github.com/cfg2html/cfg2html)
> - **Record the session so you can replay what you did** — asciinema · [github.com/asciinema/asciinema](https://github.com/asciinema/asciinema)
> - **Know the moment a backup stops reporting** — Healthchecks · [github.com/healthchecks/healthchecks](https://github.com/healthchecks/healthchecks) with 💎 runitor · [github.com/bdd/runitor](https://github.com/bdd/runitor)
> 
> **5 · CHANGE — one thing at a time.** _(that day: eighteen pages edited with a copy kept)_
> 
> - **Rehearse a whole change and read what it would do** — ansible --check --diff · [docs.ansible.com — check mode](https://docs.ansible.com/projects/ansible/latest/playbook_guide/playbooks_checkmode.html)
> - 🟢 **Test a web-server config before you reload it** — nginx -t · [nginx.org/en/docs/switches](https://nginx.org/en/docs/switches.html)
> - **Snapshot and replicate ZFS on a schedule** — sanoid with syncoid · [github.com/jimsalterjrs/sanoid](https://github.com/jimsalterjrs/sanoid)
> - **Make that replication continuous** — zrepl · [github.com/zrepl/zrepl](https://github.com/zrepl/zrepl)
> - **Browse a snapshot and restore one file in a browser** — Backrest · [github.com/garethgeorge/backrest](https://github.com/garethgeorge/backrest)
> 
> **6 · VERIFY AGAIN — check it after.** _(that day: the same check, run again)_
> 
> - 🟢 **List the services still running an old library** — needrestart · [github.com/liske/needrestart](https://github.com/liske/needrestart)
> - **Undo exactly the changes between two snapshots** — snapper undochange · [manpages.opensuse.org — snapper.8](https://manpages.opensuse.org/Tumbleweed/snapper/snapper.8.en.html)
> - **Check the redirect and the certificate honestly** — testssl.sh · [github.com/testssl/testssl.sh](https://github.com/testssl/testssl.sh)
> - **Run real HTTP checks from a text file** — hurl · [github.com/Orange-OpenSource/hurl](https://github.com/Orange-OpenSource/hurl)
> - **Prove every link on a site still works** — lychee · [github.com/lycheeverse/lychee](https://github.com/lycheeverse/lychee)
> - 💎 **Read a web-server config and catch what eyes slide past** — gixy-next · [github.com/MegaManSec/Gixy-Next](https://github.com/MegaManSec/Gixy-Next)
> - **Test one hostname against one address, DNS untouched** — xh --resolve · [github.com/ducaale/xh](https://github.com/ducaale/xh)
> - 💎 **See the redirect chain and handshake phase by phase** — httptap · [github.com/ozeranskii/httptap](https://github.com/ozeranskii/httptap)
> 
> **Same method, already on this board, written by me:** [onehack.st/t/325503](https://onehack.st/t/change-your-servers-network-over-ssh-without-locking-yourself-out-2-minute-self-undo-timer-live-proxmox-opnsense-vlan-migration-zero-downtime/325503) — my two-minute self-undo timer for a live network change · [onehack.st/t/325527](https://onehack.st/t/same-app-on-many-machines-one-script-finds-every-copy-updates-it-undoes-a-failed-one/325527) — my updater that finds every copy and undoes a failed update · [onehack.st/t/326190](https://onehack.st/t/i-can-read-my-router-now-five-jobs-on-my-server-one-cable-out-everything-still-online/326190) — my router rebuild on this same server

* * *

🃏 The answer came from the machine, not a guess — and the day’s best work was touching nothing.

* * *

**📮 Your problem, worked live**

Send a machine, a script, a route that goes somewhere impossible to **Ask Us Live**.

Picked for what they teach, then solved live on 2026-10-17T18:30:00Z — nothing staged, nothing rehearsed.

Open ones stay up with the notes.

Bring it in [onehack.st/tag/help](https://onehack.st/tag/help).

> **🔍 The day, problem by problem**
>
> **Two network cards bonded into one link.** I wanted two physical cards working as one link, the [802.3ad/LACP setup in the kernel’s own bonding document](https://docs.kernel.org/networking/bonding.html). The file said the bond existed. Reality had both cards answering on their own while the bond sat with no working members. I read it, rebuilt it, then rebooted: the bond, both members, the address, the route and the internet all came back by themselves. A configuration that survives a restart is the one worth keeping.
> 
> **A tunnel with its own identity.** A remote host needed management access through an existing [WireGuard tunnel](https://www.wireguard.com/quickstart/) into the [OPNsense edge](https://docs.opnsense.org/). Copying an existing client configuration was the fast move, and the wrong one: every client needs its own cryptographic identity. So the host got a unique private key, a unique public key, a unique tunnel address and its own peer entry — and the private key stayed on the machine, out of the conversation. I brought the tunnel up by hand first, not at boot. Prove it, then make it permanent.
> 
> **The remote host that runs production.** This host runs production infrastructure on [pve.proxmox.com](https://pve.proxmox.com/pve-docs/), so before a single backup command I inventoried everything: the backup filesystem held 1.1 TB total, about 250 GB used and 793 GB free; the root filesystem sat healthy at 94 GB total with 76 GB free; and the thin pool held far less real data than the sum of all provisioned disk sizes suggested. Provisioned capacity is not allocated blocks. Running on it: one OPNsense virtual machine and fifteen containers.
> 
> **Drives wearing someone else’s labels.** Several drives carried old Linux RAID labels from an earlier life, so I left those labels alone and asked the storage itself: two [OpenZFS mirrors](https://openzfs.github.io/openzfs-docs/), both pools ONLINE, zero read errors, zero write errors, zero checksum errors, healthy [SMART status](https://www.smartmontools.org/), so nothing was touched.
> 
> **The path that needed proving.** The remote host needed to reach the independent backup server at home. Ten packets sent, none received, 100% loss. The easy move was to say “it just needs a static route” and type one. I did not.
> 
> **Following the traffic to the next hop.** The remote host has an internal transit network to its OPNsense VM. I identified the OPNsense address on that network and tested that address alone — which explained the path. The route stayed unwritten on purpose, with the reason written down instead: a route typed to quieten a symptom hides why the symptom came.
> 
> **A folder named backup, one machine away from being real.** A directory by that name held copies on the same machine: useful staging, and one failure away from being the only copy. Following where the data would actually travel after a failure showed the gap, in writing. The return path is scheduled now, which is worth more than a green tick on a status page.
> 
> **The page the day built.** The day’s other half was a public page where people send in a problem — I called it **Ask Us Live**. Deploying it immediately demonstrated the method: one deploy, then the same check again. Then the production navigation: I searched the live document root first and found 18 pages carrying the sequence, updated all 18, verified all 18 links, and kept the previous version for a rollback.
> 
> **Nine things I deliberately did not touch:** the disks with strange labels, the WireGuard tunnel at boot, the bond before its reboot, backups written onto the root filesystem, a static route, [NGINX](https://nginx.org/en/docs/) answering 404 and then 301, the firewall during a timed-out test, and eighteen production pages without a way back. In several cases the best engineering decision of the day was: **leave it alone until the proof says otherwise.**

**What ChatGPT actually did.** It held the context, questioned my assumptions and built the safe step-by-step checks.

It administered nothing: I had the consoles and the commands.

Where a suggestion met a system that proved otherwise, the suggestion changed — the reading did not.\[1\]

**Tomorrow:** prove the backup return path end to end, then install it. Something else will break soon enough, and I would rather prove why before I fix it.

* * *

1. The useful question about an assistant is not _was it right the first time_ — it is _did the process end up agreeing with the machine_.

---

<div class="post-metadata">

**Author:** ![system](https://onehack.st/user_avatar/onehack.st/system/32/165705_2.png) [@system](https://onehack.st/u/system)\
**Post date:** [October 3, 2026, 2:26pm UTC](https://onehack.st/t/stop-fixing-what-isnt-broken-33-free-tools-the-6-step-check-that-proves-it-first/326198/2 "2026-10-03T14:26:29Z")

</div>

> [@BCBC](#):
>
> 🧰 Prove it first — one real server day where doing nothing was the fix One day on a company server: a web page answering with an error, a requ…

**🔝 The post above is now a clearer version, upgraded with AI by the Core-Community.**
