# kejilion/sh: an all-in-one Linux management script for servers

> kejilion/sh bundles system status, network tests, Docker management, an LDNMP website stack, backups and BBR tuning into one interactive shell menu. It is convenient if you want a guided path, and risky if you want a small, auditable tool.

**kejilion/sh** — KEJILION.SH Linux An all-in-one Linux management script!

- Repository: https://github.com/kejilion/sh
- Website: https://kejilion.sh
- Stars: 3,175 · Forks: 1,028
- Language: Shell
- License: Apache-2.0
- Published: 2026-08-08 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/kejilion-sh

## What kejilion/sh replaces, and for whom

The README describes the project as an all-in-one toolbox for Linux monitoring, testing and server management, bringing Docker management, LDNMP website deployment, optimization, protection, backup, restoration, migration and common server applications into one interactive tool. That sentence is the whole pitch. The target user is someone who administers a server without wanting to assemble a dozen separate utilities: a status view, a speed test, a route trace, a container list, a way to stand up Nginx, MySQL, PHP and Redis, and a backup path, all behind one menu.

That framing also defines the cost. A tool that covers system info, network testing, Docker, website deployment, anti-CC protection, backup and migration, BBR tuning and an app market is not a small script. The repository layout confirms it: top-level entries include ldnmp.sh, network-optimize.sh, beifen.sh, upgrade_openssh9.8p1.sh, fail2ban-nginx-cc.conf, optimized_php.ini, valkey.conf and per-region directories such as cn/, en/, jp/, kr/ and ru/. This is a collection, not a single-purpose utility.

If your problem is "I have one VPS and I want a guided path through common admin chores", the project is aimed at you. If your problem is "I want one narrow, well-understood change I can review in five minutes", it is not.

## How the script is organised: one entry point, many modules

The mechanism visible in the repository is a dispatcher. kejilion.sh is the entry point; the README shows it being invoked directly from the network, and it presents an interactive main menu. Behind that menu sit separate scripts and configuration files for each domain of work. ldnmp.sh handles the Nginx, MySQL, PHP and Redis stack. network-optimize.sh covers network acceleration and TCP congestion control. beifen.sh is the backup path. fail2ban-nginx-cc.conf and www.conf are configuration assets pulled in when the script configures a web environment. Language and region directories (cn/, en/, jp/, kr/, ru/, tw/, ir/) hold localised variants.

So the data flow is: you launch kejilion.sh, choose a numbered item, and the script either performs an operation directly or fetches and runs the relevant module. The README states the script adapts which features it offers based on the current system's capabilities, because distributions differ in packages, network stack and service management. That is a real design constraint rather than a marketing line: the same menu will not expose identical options on every distribution.

The README also notes an update detection mechanism that checks the script version and offers an update entry. The project keeps a changelog in kejilion_sh_log.txt, which is where release-level detail lives rather than in the README.

## Installing kejilion/sh and running the first menu

The README says to run the following as the root user. The Chinese version is the bare command; the English version appends an argument.

```bash
bash <(curl -sL kejilion.sh)
```

```bash
bash <(curl -sL kejilion.sh) en
```

This downloads the script and executes it in the current shell. You should see the interactive main menu rather than a silent exit. If nothing appears, the download failed or the environment blocked it; the README does not document a fallback path for that case.

After the first run, the README says you can set the k shortcut command at the script's prompt. From then on, typing a single letter opens the main menu.

```bash
k
```

The README adds an important warning before you go further: the script performs system-level operations covering software installation, networking, firewall, disk and website environment, so you should read the terminal prompts and back up important sites, databases, containers and configuration first. That warning is not boilerplate. It is the project telling you that a menu selection can change the machine.

For a browser-based alternative, the README documents deploying KPanel through the app entry.

```bash
bash <(curl -sL kejilion.sh) app kpanel
```

KPanel is described as the modern web management form of kejilion.sh, and the README states that resources created by the script, SSH, Docker Compose and KPanel can discover each other and continue to be managed. That is a specific claim about shared state, and it is the part worth checking on your own machine before you commit to the panel.

## The LDNMP stack and why one-click deployment is a trade-off

LDNMP stands for the Nginx, MySQL, PHP and Redis combination that the README lists as a one-click deployment. For someone who has never assembled that stack by hand, the appeal is obvious: a menu item instead of a sequence of package installs, virtual host configuration, PHP-FPM tuning and database initialisation.

The repository shows how much is being decided on your behalf. optimized_php.ini is a tuned PHP configuration. custom_mysql_config.cnf is a prepared MySQL configuration. valkey.conf suggests a Redis-compatible configuration asset. www.conf and nginx.local are web server configuration. fail2ban-nginx-cc.conf is a protection profile. When you accept the one-click path, you accept these files as your starting point.

That is the trade-off, stated plainly. You get a working stack quickly, and you also get a stack whose defaults were chosen by someone else for a general case. If you later need to explain why a PHP setting has a particular value, the answer is in optimized_php.ini, not in your own notes. The README does not document a rollback procedure for the LDNMP deployment, so the practical safety net is the backup feature, not an undo command.

If your workload has unusual database tuning needs or a compliance requirement to justify every configuration line, building the stack yourself will cost more time and produce a system you can defend. That is not a criticism of the script; it is the boundary of what a one-click installer can give you.

## Where kejilion/sh is the wrong tool

The clearest failure mode is scope. The README's own warning says the script touches software installation, networking, firewall, disk and website environment. A single menu can therefore reach into several subsystems at once. On a production server where changes are reviewed individually, that coupling is a problem: you cannot easily isolate the one line that altered a firewall rule from the dozen other things the same run did.

A second limitation is the delivery method. The documented install pipes a remote script into bash. The README's security section responds to this directly: obtain the script only from the official domain and this repository, and review the source before executing. That advice is sound, but it also means the operator carries the verification burden. If your organisation forbids curl-to-bash entirely, the documented install path does not fit, and the README does not offer a signed-package or pinned-commit alternative.

Third, distribution coverage is conditional. The README says the script opens features according to the current system's capabilities because packages, network stack and service management differ between distributions. It does not publish a supported-system matrix in the text provided. Before relying on a specific feature, you need to confirm it appears on your distribution, which is a step the README leaves to the user.

Finally, treat the project's maintenance cadence as a fact to check rather than assume. The most recent release listed is v4.4.1, dated 2026-03-01, and the last push to the repository was on 2026-03-01. That is the state of the repository, and it is what you should weigh when deciding how much of your server's configuration to delegate to it.

## Alternatives: Webmin, Cockpit and doing it by hand

The closest comparison is a general-purpose web control panel such as Webmin or Cockpit. Both take a browser-first approach: you install a service, it runs persistently, and you manage the machine through a web interface with its own authentication. kejilion/sh inverts that. It is a shell script you invoke when you need it, with no long-running daemon by default, and the interactive menu is the interface. KPanel narrows the gap by adding a web form, but the README presents it as an entry deployed through the script rather than as the project's primary mode.

The practical difference is state and privilege. A persistent panel holds credentials and listens on a port continuously, which is a standing attack surface you must patch. A script you run on demand has no listening service, but it also has no audit trail beyond your shell history, and it runs with whatever privileges you gave it, which the README says should be root.

The other alternative is not installing anything. Docker Compose files you write yourself, a Makefile of documented commands, or Ansible playbooks give you a small, reviewable unit of change. They cost more setup time and they will not test your network route or show your disk usage. If your team already has configuration management, adding kejilion/sh on top creates a second source of truth for the same machine, and the two will drift.

## Licence, upgrades and the cost of staying current

The project is licensed under Apache License 2.0, per the README and the LICENSE file at the repository root. Apache-2.0 is a permissive licence that includes an explicit patent grant, and it permits commercial use and modification provided you keep the licence and notices intact. That matters here because the repository contains configuration assets (fail2ban-nginx-cc.conf, optimized_php.ini, valkey.conf, www.conf) that you may end up shipping as part of your own server setup. Redistributing those files carries the same notice obligations as redistributing the script. This is a description of the licence, not legal advice; if you are embedding the files in a product, have your own counsel read the LICENSE.

Upgrade cost is where an all-in-one script asks for ongoing attention. The README describes an update detection mechanism that checks the script version and offers an update entry, and the project maintains a changelog in kejilion_sh_log.txt. The releases listed run v4.3.2 (2026-01-13), v4.3.7 (2026-02-03) and v4.4.1 (2026-03-01), which is a steady cadence across that window. A project that ships changes that often will, at some point, change the behaviour of a menu item you depend on.

The README does not document a downgrade path or a version-pinning mechanism for the script itself. The practical consequence is that you should read kejilion_sh_log.txt before accepting an update on a machine you care about, and keep your own record of what the script configured, because the script's changelog will not tell you what it did to your server last month.

## Conclusion

Adopt kejilion/sh if you run a small number of servers, want a menu-driven path to Docker, LDNMP or backups, and are willing to read the terminal prompts before confirming. Do not adopt it if you need a minimal, auditable unit of change, or if your policy forbids piping a remote script into bash; the README itself says to obtain the script only from the official domain and this repository, and to review the source first. Verify the current release tag in kejilion_sh_log.txt, check that your distribution is supported before running anything, and confirm you have a backup of sites, databases and containers before touching disk or firewall options.

## FAQ

### How do I install kejilion/sh?

Run the documented command as root: bash <(curl -sL kejilion.sh) for the Chinese version, or bash <(curl -sL kejilion.sh) en for English. The README says you can then set the k shortcut at the script's prompt, after which typing k opens the main menu.

### Which Linux distributions does kejilion/sh support?

The README states that distributions differ in packages, network stack and service management, and that the script opens features according to the current system's capabilities. It does not publish a supported-system list in the text available, so confirm the features you need appear on your distribution before relying on them.

### Is kejilion/sh safe to run on a production server?

The README warns that the script includes system-level operations covering software installation, networking, firewall, disk and website environment, and says to read the terminal prompts and back up important sites, databases, containers and configuration first. It also says to obtain the script only from the official domain and this repository, and to review the source before executing.

### What is KPanel in kejilion/sh?

The README describes KPanel as the modern web management form of kejilion.sh, deployed through the app entry with bash <(curl -sL kejilion.sh) app kpanel. It states that resources created by the script, SSH, Docker Compose and KPanel can discover each other and continue to be managed.

## Sources

- [Official documentation](https://kejilion.sh)
- [Official README](https://github.com/kejilion/sh#readme)
- [Project repository](https://github.com/kejilion/sh)
- [Release notes](https://github.com/kejilion/sh/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/kejilion-sh
