Linux Fleet Toolkit lfu.kosir.info

RHEL 9 fleet tooling · over SSH

linux-users

Audit accounts, sudoers, and SSH keys across the fleet, then retire the stale ones. Locks and expires. Never deletes.

$ git clone https://github.com/vikozs/linux-users

How it works

01

discover

accounts, sudoers, keys, last login

02

review

read the stale candidates

03

apply

lock or expire, re-validated live

What it does

Real staleness

Stale means a login account past your last-login threshold. Accounts whose last login is unknown or never are never auto-locked.

Can't lock you out

root, UID < 1000, the account you connect as, and any --protect names are excluded and re-checked at apply time.

Finds the sharp edges

Duplicate UID 0, empty passwords, never-expiring passwords, NOPASSWD sudo, and weak ssh-dss keys.

Never deletes

apply only locks and optionally expires. No userdel, no key removal, no sudoers edits. Shadow hashes are never collected.

Output

A report you can hand to anyone

A formatted Excel workbook plus a machine-readable JSON plan. Sheets:

SummaryAccountsStale CandidatesSudoersSSH KeysIssuesErrorsAbout

Safety

GUARDED

apply only locks or expires, re-validating last login first. Protected accounts can never enter the apply set.

The rest of the family