道場 · Cheat sheet

The Dojo's commands, chapter by chapter

The reminder to keep at hand. 21 chapters (including a bonus one) + the 🎩 RHCSA page · the essential commands with a short explanation.
⬇️ PDF ← The Dojo EN|FR
Notation: <f> = a file · <name> = to replace · [..] = optional · | = "or". Many system commands require sudo (admin rights).
CH 1The foundations⬜
pwdprints the current folder ("where am I?")
whoamithe current user's name
idfull identity: uid, gid, groups
lslists the content of a folder
ls -lalists everything, hidden files + details
man <cmd>a command's manual (q to quit)
<cmd> --helpa command's quick help
CH 2Navigation⬜
cd <folder>enters a folder
cd ..goes up one level
cd ~back to the home folder (or plain cd )
cd /goes to the root
treedisplays the tree
absolute vs relative/home/user (anywhere) vs Documents (from here)
CH 3Files & folders🟩
cat <f>displays a file's content
mkdir <name>creates a folder (-p creates the parents)
touch <f>creates an empty file
cp source destcopies a file
mv old newmoves OR renames
rm <f>deletes (for good!) · rm -r for a folder
wildcards * ?rm *.log act on several files
find <where> -namefinds files by name, in depth
ln -s target linkcreates a shortcut (symbolic link)
mkdir -p d/{a,b,c}several folders at once (braces)
CH 4Users & permissions🟥
ls -lreads the permissions (e.g. -rwxr-xr--)
chmod +x <f>makes a file executable
chmod 755 <f>permissions in digits (r=4, w=2, x=1)
chown user:grp <f>changes the owner (sudo)
sudo <cmd>runs as administrator
chgrp group <f>changes a file's group
umask 077default permissions of new files
CH 5Editors (nano / vim)🟩
nano <f>simple editor (Ctrl+O save, Ctrl+X quit)
vim <f>modal editor (i insert, Esc, :wq save+quit)
echo "txt" > fwrites into a file (overwrites)
echo "txt" >> fappends at the end (without overwriting)
cmd 2> errors.txterrors apart
cmd > f 2>&1output + errors in one file
cmd | tee fshows AND saves
CH 6Search & filtering🟥
head / tail -n <f>the beginning / the end of a file
tail -f <f>follows a log live
grep <pattern> <f>searches for text (-i -n -c -v -r)
cmd1 | cmd2the "pipe": chains commands
wc -lcounts lines
cmd > f · >> fredirects the output into a file
less <f>reads page by page (q = quit)
tac <f>the file backwards
locate <name>finds a file (sudo updatedb)
sed 's/a/b/g' <f>replaces text
awk -F: '{print $1}' <f>extracts columns
… | xargs <cmd>passes a list as arguments
CH 7System processes🟥
ps · ps auxlists the processes
toplive activity (q to quit)
kill <PID>stops a process (kill -9 forces)
cmd & · jobsbackground · list of jobs
fg %1 · bg %1to the foreground · to the background
nohup cmd &survives logging out
kill -15 / -9 <PID>politely (TERM) / by force (KILL)
pstree -pthe process tree
pgrep · pkill <name>finds / stops by name
CH 8User management🟥
cat /etc/passwdthe list of accounts
sudo useradd -m <name>creates a user
sudo passwd <name>sets their password
groupsa user's groups
sudo groupadd <name>creates a group
sudo usermod -aG grp useradds a user to a group
sudo userdel -r <name>deletes a user
sudo -i · sudo su -root session (exit to come back)
su - <n>takes another account's session
sudo -u <n> cmdruns a command as <n>
sudo -l · sudo !!your sudo rights · redo with sudo
CH 9Services & systemd🟧
systemctl status <svc>a service's status
sudo systemctl start/stopstarts / stops a service
sudo systemctl enablelaunches it at boot
files .servicein /etc/systemd/system/ (ExecStart, After)
journalctl -u <svc> -n 20a service's journal
CH 10Deploy a site (nginx)🟧
systemctl status nginxchecks that nginx is running
/etc/nginx/the web server's config
/var/www/html/the site's files
tail -f …/access.logfollows the visits live
curl http://localhosttests the site from the command line
CH 11Network & SSH🟧
ip aIP address / network config
ping <host>tests whether a machine answers
cat /etc/resolv.confthe DNS servers
ssh-keygengenerates an SSH key (~/.ssh/)
ssh user@iplogs into a remote machine
ssh-keygen -t ed25519creates your key pair
ssh-copy-id user@hostinstalls your key on the server
ssh user@hostlogs in (exit to come back)
scp f user@host:/foldercopies over SSH
~/.ssh/configserver nicknames (Host …)
CH 12Security & hardening🟧
sudo ufw statusthe firewall's status
sudo ufw enableenables the firewall · ufw allow <port>
grep Failed …/auth.logspots failed SSH attempts
sudo fail2ban-client status sshdfail2ban: the banned IPs of the SSH jail
/etc/fail2ban/jail.localyour settings (maxretry, bantime) · never jail.conf
fail2ban-client set sshd unbanip <IP>unbans an IP blocked by mistake
/etc/ssh/sshd_configharden SSH access
sudo visudowho is allowed to use sudo
CH 13System & disk🟧
df -hthe available disk space
du -sh <folder>the size of a folder
lscputhe processor's info
free -hmemory (look at available)
uname -athe system version
apt search · apt showsearch · package details
sudo apt install / removeinstall / uninstall
dpkg -l · dpkg -L <p>installed packages · their files
snap find · snap installsnap packages (--classic)
CH 14System monitoring🟧
uptimesince when + system load
w · whowho is logged in
lastthe login history
htopa colored, more readable top
vmstatCPU / memory / disk at a glance
CH 15Scheduling (cron)🟧
crontab -llists your scheduled tasks
crontab -eedits: min h day month weekday cmd
echo '…' | crontab -installs (⚠️ REPLACES the whole crontab)
crontab -l > f then crontab fadd a task without losing anything
*/15 * * * * · 0 7 * * 1-5every 15 min · 7:00 on weekdays
systemctl list-timerssystemd timers (the modern cron)
datethe system's date and time
/etc/anacrontabcatches up missed jobs
echo cmd | at now + 5 minutesa one-off job (atq, atrm)
CH 16Bash scripting🟥
#!/bin/bashthe "shebang": 1st line of a script
VAR=x · $VARvariables (e.g. echo $PATH)
./script.shruns the script (after chmod +x)
echo $?the return code (0 = all good)
$(command)substitution: inserts a command's result
read -p "? " varasks for input
$(( a + b ))integer arithmetic
if [ -f f ]; then …; fia condition
[ $a -gt 5 ] · [ -z "$v" ]tests: numbers / text
case $v in a) …;; esacseveral cases
for i in {1..5}; do …; donea loop
while read l; do …; done < fline by line
$1 $2 · $# · "$@"the script's arguments
f() { …; }a function
a && b · a || bif it works · otherwise
bash -x script.shdebug (trace)
CH 17Git — version control⬛
git initcreates a repository in the folder
git statusthe state of the files (your compass)
git add <f>adds to the index (git add . = everything)
git commit -m "msg"records a snapshot
git logreads the commit history
CH 18Virtualization (KVM)⬛
egrep -c 'vmx|svm' /proc/cpuinfoCPU supports virtualization? (> 0 = yes)
sudo apt install qemu-kvminstalls the hypervisor
sudo systemctl enable --now libvirtdstarts the virtualization daemon
virsh list --alllists the virtual machines
virsh start <vm>starts a VM
CH 19Archives & compression⬛
tar czf a.tar.gz <folder>creates a compressed archive
tar xzf a.tar.gzextracts an archive
the lettersc=create, x=extract, z=gzip, f=file
gzip f · gunzip f.gzcompress · decompress
zip -r a.zip d · unzip a.zip.zip archive
CH 21Proxy & reverse proxy🟥
ss -tlnpthe listening ports and their program
proxy_pass <url>;nginx relays to the app, e.g. http://127.0.0.1:3000
ln -s <target> <link>enables a site in sites-enabled/ (target as an absolute path!)
sudo nginx -ttests the config before loading it
systemctl reload nginxreloads without cutting the visitors off (sudo)
proxy_set_headerpasses Host, X-Real-IP, X-Forwarded-For on to the app
upstream <name> { }spreads the load across instances (server ip:port;)
502 errorthe app behind doesn't answer → /var/log/nginx/error.log
curl -x <proxy> <url>goes through an outgoing proxy (Squid, port 3128)
export http_proxy=…proxy for the whole system (+ https_proxy)
RHCSA R1·R2Red Hat: packages, firewalld, SELinux🎩
cat /etc/redhat-releasewhich distribution of the Red Hat family
dnf install / search / info.rpm packages (the equivalent of apt)
rpm -q <package>is it installed? (-qa = all)
systemctl enable --nowstarts now AND at boot (nothing starts by itself)
-G wheelthe admins group (instead of sudo)
firewall-cmd --add-service=httpopens the web (firewalld)
--permanent then --reloadotherwise the rule disappears at the reload
getenforce · ls -ZSELinux mode · file labels
restorecon -Rv <path>puts back the right labels (after an mv)
semanage fcontext -a -tnew labeling rule, then restorecon
setsebool -P <boolean> onturns on a planned SELinux permission
403 on Red HatUnix permissions OK? → /var/log/audit/audit.log
RHCSA R3·R5Red Hat: network, accounts, boot🎩
nmcli device · ip athe cards · the active addresses
nmcli con mod enp0s3 ipv4.…saves (addresses with /24, gateway, dns, method manual)
nmcli con up enp0s3applies; +ipv4.dns adds instead of replacing
hostnamectl set-hostnamepermanent hostname (writes /etc/hostname)
… | sudo tee -a /etc/hostswrite into a system file (not sudo echo >>)
groupadd -g · useradd -u -Gimposed GID / UID, secondary group
chage -M 90 -W 7 · -d 0password lifetime · change at 1st login
useradd -r -s /sbin/nologinservice account, no login
chgrp + chmod 2770shared folder: the set-GID keeps the group
/etc/sudoers.d/ · visudo -cone rule per file, in chmod 440, syntax checked
systemctl set-defaultmulti-user.target (text) or graphical.target
journalctl -u sshd -p erra service's logs · the errors
mkdir /var/log/journal+ restart systemd-journald = persistent logs
tuned-adm recommend / profilethe recommended performance profile
RHCSA LABSOn your VM: disks, NFS, rescue, podman, scripts🖥️
parted /dev/sdb mklabel gptthen mkpart, set 1 lvm on (or fdisk + w)
vgcreate -s 8M vg /dev/sdb1imposed extent size; lvcreate -l 50 = 50 extents
lvextend -r -L 600Mgrows the LV AND the filesystem, live
mkswap · swapon -apermanent swap: line UUID=… none swap defaults 0 0
mount -a · findmnt --verifytest fstab BEFORE rebooting
/etc/exports · exportfs -rvNFS share; showmount -e server
defaults,_netdevNFS mount in fstab (waits for the network)
/etc/auto.master.d/x.autofsautofs; wildcard map * -rw srv:/homes/&
rd.break → chroot /sysrootpasswd root then touch /.autorelabel
podman run -d -p 8080:8080 -v ~/web:…:Zrootless container, SELinux-labeled volume
~/.config/containers/systemd/*.containerQuadlet: the container becomes a user service
loginctl enable-linger kaitheir services start at boot, without a login
$# · "$@" · exit 1 · $?arguments, a script's exit codes
crontab -e · at now + 1 minuterepeated task · one-off task (full paths!)
BONUS🧰 Toolbox🎁
calthe month's calendar
seq 1 10a sequence of numbers
echo "2+2" | bcthe terminal as a calculator
which <cmd>where a command lives
stat <f>detailed info on a file
file <f>the type of a file
sort · uniqsorts / deduplicates lines
cut -d: -f1extracts a column
tr a breplaces characters
revreverses each line
factor 60breaks into prime factors
aliasyour shortcuts (e.g. ll=ls -la)
cowsay txtthe talking cow 🐄
alias name='cmd'your own shortcut
source ~/.bashrcreloads your config
PS1='\u@\h:\w\$ 'customises the prompt
printenv · export V=xthe environment
道 · The Linux Dojo — コマンドは力なり · The command is power