CreaRack-SL

SSH Script Library

What it is

The SSH Script Library stores reusable lists of CLI commands you run on network devices. Instead of typing the same show sequence on every switch, you save it once and run it with one click.

A script is plain text: one command per line. No variables, no logic — just the commands, in order. Scripts belong to your organization, and any system-wide templates appear in the same list.

You open the library from the Terminal page: in the Terminal Tools section of the sidebar, click Script Manager. The SSH Script Library window opens.

How to create and manage scripts

  1. On the Terminal page, click Script Manager.
  2. Click New Script.
  3. Fill in Name, an optional Description, and Commands (one per line).
  4. Click Save Script.

Each script in the list shows its command count plus Edit and Delete buttons. Use the Search scripts… box to filter by name or description.

If the library is empty, click Load Default Scripts to seed five starters: Show Version, Show Interfaces, Show Running Config, Check Uptime, and Disk Usage.

Permissions: creating and editing scripts requires edit rights on the Network module (Admin or Operator role). Deleting a script is Admin-only.

How to run a script

In a single SSH session. Open a terminal tab, pick a script from the toolbar dropdown, and click Run Script. The commands are sent into your live session one by one, exactly as if you typed them yourself.

From the Rack Editor SSH window. The — Quick Scripts — dropdown next to the embedded terminal works the same way.

On many devices at once. Turn on Cluster Mode, pick a script in the — Broadcast Script — dropdown, and click Run Script. The script is sent to every active session in parallel. See [[crearack—terminal—cluster-mode]].

Directly against a device (API execution). When CreaRack runs a script against a device server-side, it picks the route for you: devices with a public IP are executed from the CreaRack server, devices with a private IP are handed to the Local Agent inside your network.

What scripts can and cannot do

Server-side script execution is deliberately conservative:

  • Scripts run in exec mode — each command is sent as a read-style command. The script runner does not enter configuration mode on the device.
  • Every command is validated before anything reaches the device. Read-only commands (show, display, get, ping, traceroute) are always allowed. Destructive commands (reload, reboot, write erase, format, delete, factory resets) are always blocked. Anything else must match a short per-vendor safe list.
  • Each line must be a single command. Separators like ;, &, redirections (>, <), command substitution or embedded newlines are rejected, so a “safe” line cannot smuggle a second, dangerous one. The one exception is a single output filter on a show command, such as show running-config | include interface (include, exclude, begin or section, up to 64 characters). Any other pipe is rejected, and so is a filter pattern with parentheses such as | include (error|down); use two filtered commands instead. Commands must be plain ASCII.
  • Every execution is recorded in the network audit log.

One honest caveat: when you run a script inside an open terminal session, the commands are typed into that session — whatever your SSH user is allowed to do on the device applies. Stick to show commands unless you know exactly what you are sending, and test on one device before broadcasting in Cluster Mode.

Troubleshooting

  • Script missing from the terminal dropdown — the dropdown loads when the tab opens. Save the script, then open a new tab or reconnect.
  • “Blocked command” or “Command not in whitelist” — the validator rejected a line. Keep one command per line and prefer read-only commands.
  • Nothing happens on Run Script — the session must be connected. Check the tab status and click Reconnect if needed.
  • Wrong output on some devices — scripts are not translated between vendors. A Cisco show running-config will fail on Juniper; keep one script per platform.
  • [[crearack—terminal—que-es-terminal]] — the Terminal page where scripts run
  • [[crearack—terminal—cluster-mode]] — broadcast scripts to many sessions
  • [[crearack—network—auto-provision-wizard]] — discover the devices you script against
  • [[crearack—network—mibs-and-vendor-profiles]] — extend what CreaRack knows about each vendor

Véase también

  • [[crearack—terminal—que-es-terminal]]
  • [[crearack—terminal—cluster-mode]]
  • [[crearack—network—mibs-and-vendor-profiles]]
  • [[crearack—network—auto-provision-wizard]]