<f> = a file · <name> = to replace · [..] = optional · | = "or". Many system commands require sudo (admin rights).pwd | prints the current folder ("where am I?") |
whoami | the current user's name |
id | full identity: uid, gid, groups |
ls | lists the content of a folder |
ls -la | lists everything, hidden files + details |
man <cmd> | a command's manual (q to quit) |
<cmd> --help | a command's quick help |
cd <folder> | enters a folder |
cd .. | goes up one level |
cd ~ | back to the home folder (or plain cd ) |
cd / | goes to the root |
tree | displays the tree |
| absolute vs relative | /home/user (anywhere) vs Documents (from here) |
cat <f> | displays a file's content |
mkdir <name> | creates a folder (-p creates the parents) |
touch <f> | creates an empty file |
cp source dest | copies a file |
mv old new | moves OR renames |
rm <f> | deletes (for good!) · rm -r for a folder |
wildcards * ? | rm *.log act on several files |
find <where> -name | finds files by name, in depth |
ln -s target link | creates a shortcut (symbolic link) |
mkdir -p d/{a,b,c} | several folders at once (braces) |
ls -l | reads the permissions (e.g. -rwxr-xr--) |
chmod +x <f> | makes a file executable |
chmod 755 <f> | permissions in digits (r=4, w=2, x=1) |
chown user:grp <f> | changes the owner (sudo) |
sudo <cmd> | runs as administrator |
chgrp group <f> | changes a file's group |
umask 077 | default permissions of new files |
nano <f> | simple editor (Ctrl+O save, Ctrl+X quit) |
vim <f> | modal editor (i insert, Esc, :wq save+quit) |
echo "txt" > f | writes into a file (overwrites) |
echo "txt" >> f | appends at the end (without overwriting) |
cmd 2> errors.txt | errors apart |
cmd > f 2>&1 | output + errors in one file |
cmd | tee f | shows AND saves |
head / tail -n <f> | the beginning / the end of a file |
tail -f <f> | follows a log live |
grep <pattern> <f> | searches for text (-i -n -c -v -r) |
cmd1 | cmd2 | the "pipe": chains commands |
wc -l | counts lines |
cmd > f · >> f | redirects the output into a file |
less <f> | reads page by page (q = quit) |
tac <f> | the file backwards |
locate <name> | finds a file (sudo updatedb) |
sed 's/a/b/g' <f> | replaces text |
awk -F: '{print $1}' <f> | extracts columns |
… | xargs <cmd> | passes a list as arguments |
ps · ps aux | lists the processes |
top | live activity (q to quit) |
kill <PID> | stops a process (kill -9 forces) |
cmd & · jobs | background · list of jobs |
fg %1 · bg %1 | to the foreground · to the background |
nohup cmd & | survives logging out |
kill -15 / -9 <PID> | politely (TERM) / by force (KILL) |
pstree -p | the process tree |
pgrep · pkill <name> | finds / stops by name |
cat /etc/passwd | the list of accounts |
sudo useradd -m <name> | creates a user |
sudo passwd <name> | sets their password |
groups | a user's groups |
sudo groupadd <name> | creates a group |
sudo usermod -aG grp user | adds a user to a group |
sudo userdel -r <name> | deletes a user |
sudo -i · sudo su - | root session (exit to come back) |
su - <n> | takes another account's session |
sudo -u <n> cmd | runs a command as <n> |
sudo -l · sudo !! | your sudo rights · redo with sudo |
systemctl status <svc> | a service's status |
sudo systemctl start/stop | starts / stops a service |
sudo systemctl enable | launches it at boot |
files .service | in /etc/systemd/system/ (ExecStart, After) |
journalctl -u <svc> -n 20 | a service's journal |
systemctl status nginx | checks that nginx is running |
/etc/nginx/ | the web server's config |
/var/www/html/ | the site's files |
tail -f …/access.log | follows the visits live |
curl http://localhost | tests the site from the command line |
ip a | IP address / network config |
ping <host> | tests whether a machine answers |
cat /etc/resolv.conf | the DNS servers |
ssh-keygen | generates an SSH key (~/.ssh/) |
ssh user@ip | logs into a remote machine |
ssh-keygen -t ed25519 | creates your key pair |
ssh-copy-id user@host | installs your key on the server |
ssh user@host | logs in (exit to come back) |
scp f user@host:/folder | copies over SSH |
~/.ssh/config | server nicknames (Host …) |
sudo ufw status | the firewall's status |
sudo ufw enable | enables the firewall · ufw allow <port> |
grep Failed …/auth.log | spots failed SSH attempts |
sudo fail2ban-client status sshd | fail2ban: the banned IPs of the SSH jail |
/etc/fail2ban/jail.local | your settings (maxretry, bantime) · never jail.conf |
fail2ban-client set sshd unbanip <IP> | unbans an IP blocked by mistake |
/etc/ssh/sshd_config | harden SSH access |
sudo visudo | who is allowed to use sudo |
df -h | the available disk space |
du -sh <folder> | the size of a folder |
lscpu | the processor's info |
free -h | memory (look at available) |
uname -a | the system version |
apt search · apt show | search · package details |
sudo apt install / remove | install / uninstall |
dpkg -l · dpkg -L <p> | installed packages · their files |
snap find · snap install | snap packages (--classic) |
uptime | since when + system load |
w · who | who is logged in |
last | the login history |
htop | a colored, more readable top |
vmstat | CPU / memory / disk at a glance |
crontab -l | lists your scheduled tasks |
crontab -e | edits: min h day month weekday cmd |
echo '…' | crontab - | installs (⚠️ REPLACES the whole crontab) |
crontab -l > f then crontab f | add a task without losing anything |
*/15 * * * * · 0 7 * * 1-5 | every 15 min · 7:00 on weekdays |
systemctl list-timers | systemd timers (the modern cron) |
date | the system's date and time |
/etc/anacrontab | catches up missed jobs |
echo cmd | at now + 5 minutes | a one-off job (atq, atrm) |
#!/bin/bash | the "shebang": 1st line of a script |
VAR=x · $VAR | variables (e.g. echo $PATH) |
./script.sh | runs the script (after chmod +x) |
echo $? | the return code (0 = all good) |
$(command) | substitution: inserts a command's result |
read -p "? " var | asks for input |
$(( a + b )) | integer arithmetic |
if [ -f f ]; then …; fi | a condition |
[ $a -gt 5 ] · [ -z "$v" ] | tests: numbers / text |
case $v in a) …;; esac | several cases |
for i in {1..5}; do …; done | a loop |
while read l; do …; done < f | line by line |
$1 $2 · $# · "$@" | the script's arguments |
f() { …; } | a function |
a && b · a || b | if it works · otherwise |
bash -x script.sh | debug (trace) |
git init | creates a repository in the folder |
git status | the state of the files (your compass) |
git add <f> | adds to the index (git add . = everything) |
git commit -m "msg" | records a snapshot |
git log | reads the commit history |
egrep -c 'vmx|svm' /proc/cpuinfo | CPU supports virtualization? (> 0 = yes) |
sudo apt install qemu-kvm | installs the hypervisor |
sudo systemctl enable --now libvirtd | starts the virtualization daemon |
virsh list --all | lists the virtual machines |
virsh start <vm> | starts a VM |
tar czf a.tar.gz <folder> | creates a compressed archive |
tar xzf a.tar.gz | extracts an archive |
| the letters | c=create, x=extract, z=gzip, f=file |
gzip f · gunzip f.gz | compress · decompress |
zip -r a.zip d · unzip a.zip | .zip archive |
ss -tlnp | the listening ports and their program |
proxy_pass <url>; | nginx relays to the app, e.g. http://127.0.0.1:3000 |
ln -s <target> <link> | enables a site in sites-enabled/ (target as an absolute path!) |
sudo nginx -t | tests the config before loading it |
systemctl reload nginx | reloads without cutting the visitors off (sudo) |
proxy_set_header | passes Host, X-Real-IP, X-Forwarded-For on to the app |
upstream <name> { } | spreads the load across instances (server ip:port;) |
| 502 error | the app behind doesn't answer → /var/log/nginx/error.log |
curl -x <proxy> <url> | goes through an outgoing proxy (Squid, port 3128) |
export http_proxy=… | proxy for the whole system (+ https_proxy) |
cat /etc/redhat-release | which distribution of the Red Hat family |
dnf install / search / info | .rpm packages (the equivalent of apt) |
rpm -q <package> | is it installed? (-qa = all) |
systemctl enable --now | starts now AND at boot (nothing starts by itself) |
-G wheel | the admins group (instead of sudo) |
firewall-cmd --add-service=http | opens the web (firewalld) |
--permanent then --reload | otherwise the rule disappears at the reload |
getenforce · ls -Z | SELinux mode · file labels |
restorecon -Rv <path> | puts back the right labels (after an mv) |
semanage fcontext -a -t | new labeling rule, then restorecon |
setsebool -P <boolean> on | turns on a planned SELinux permission |
| 403 on Red Hat | Unix permissions OK? → /var/log/audit/audit.log |
nmcli device · ip a | the cards · the active addresses |
nmcli con mod enp0s3 ipv4.… | saves (addresses with /24, gateway, dns, method manual) |
nmcli con up enp0s3 | applies; +ipv4.dns adds instead of replacing |
hostnamectl set-hostname | permanent hostname (writes /etc/hostname) |
… | sudo tee -a /etc/hosts | write into a system file (not sudo echo >>) |
groupadd -g · useradd -u -G | imposed GID / UID, secondary group |
chage -M 90 -W 7 · -d 0 | password lifetime · change at 1st login |
useradd -r -s /sbin/nologin | service account, no login |
chgrp + chmod 2770 | shared folder: the set-GID keeps the group |
/etc/sudoers.d/ · visudo -c | one rule per file, in chmod 440, syntax checked |
systemctl set-default | multi-user.target (text) or graphical.target |
journalctl -u sshd -p err | a service's logs · the errors |
mkdir /var/log/journal | + restart systemd-journald = persistent logs |
tuned-adm recommend / profile | the recommended performance profile |
parted /dev/sdb mklabel gpt | then mkpart, set 1 lvm on (or fdisk + w) |
vgcreate -s 8M vg /dev/sdb1 | imposed extent size; lvcreate -l 50 = 50 extents |
lvextend -r -L 600M | grows the LV AND the filesystem, live |
mkswap · swapon -a | permanent swap: line UUID=… none swap defaults 0 0 |
mount -a · findmnt --verify | test fstab BEFORE rebooting |
/etc/exports · exportfs -rv | NFS share; showmount -e server |
defaults,_netdev | NFS mount in fstab (waits for the network) |
/etc/auto.master.d/x.autofs | autofs; wildcard map * -rw srv:/homes/& |
rd.break → chroot /sysroot | passwd root then touch /.autorelabel |
podman run -d -p 8080:8080 -v ~/web:…:Z | rootless container, SELinux-labeled volume |
~/.config/containers/systemd/*.container | Quadlet: the container becomes a user service |
loginctl enable-linger kai | their services start at boot, without a login |
$# · "$@" · exit 1 · $? | arguments, a script's exit codes |
crontab -e · at now + 1 minute | repeated task · one-off task (full paths!) |
cal | the month's calendar |
seq 1 10 | a sequence of numbers |
echo "2+2" | bc | the terminal as a calculator |
which <cmd> | where a command lives |
stat <f> | detailed info on a file |
file <f> | the type of a file |
sort · uniq | sorts / deduplicates lines |
cut -d: -f1 | extracts a column |
tr a b | replaces characters |
rev | reverses each line |
factor 60 | breaks into prime factors |
alias | your shortcuts (e.g. ll=ls -la) |
cowsay txt | the talking cow 🐄 |
alias name='cmd' | your own shortcut |
source ~/.bashrc | reloads your config |
PS1='\u@\h:\w\$ ' | customises the prompt |
printenv · export V=x | the environment |