Terminal · server · everyday tasks

Linux / CLI

Everyday shell commands, SSH, and basic administration. Search by task or command. Distribution-specific differences are called out.

Debian / UbuntuFedora / RHELArchcopyable commands

Getting started

Check where you are, which user you are, and what is happening on the system.

Where am I?

orientation
pwd # current directory whoami # current user hostname # machine name date # date and time uname -a # kernel and architecture

Built-in help

documentation
man ssh # manual page ssh --help # program help help cd # shell built-in help apropos filesystem # search manual page descriptions

In man: /word searches, n jumps to the next match, and q quits.

Files & directories

Check paths carefully. Recursive options such as -r affect everything below a directory.

List files

ls
ls -lah # detailed list, including hidden files ls -lt # newest changes first du -sh directory/ # total directory size

Change directory

cd
cd /var/log # absolute path cd .. # parent directory cd ~ # home directory cd - # previous directory

Create a directory or file

mkdir · touch
mkdir notes mkdir -p project/src/components touch todo.txt

The -p flag creates missing parent directories and does not complain if they already exist.

Copy files

cp
cp report.txt backup.txt cp -i file.txt /tmp/ # prompt before overwrite cp -a folder/ folder-copy/ # copy directory and attributes

Move or rename

mv
mv old-name.txt new-name.txt mv file.txt ~/Documents/ mv -i report.txt archive/

Add -i to prompt before overwriting an existing file.

Delete a file or directory

rm · rmdir
rm -i file.txt rmdir empty-directory rm -r directory/ # directory and its contents

Careful: rm has no trash. Check pwd and the target path first.

Create a link

ln
ln -s /path/to/original shortcut readlink -f shortcut

ln -s creates a symbolic link; without -s, it creates a hard link.

tar.gz archives

tar
tar -czf archive.tar.gz directory/ # create tar -tzf archive.tar.gz # list contents tar -xzf archive.tar.gz -C /tmp # extract into directory

Text & search

Use less for large files and pipe commands together with |.

Read a file

cat · less
cat config.conf # print whole file less /var/log/syslog # page through a file head -n 20 file.txt # first 20 lines tail -n 50 file.txt # last 50 lines tail -f application.log # follow new lines

Press q to quit less.

Search text with grep

grep
grep -n "error" app.log grep -Rni "TODO" ./src grep -E "warn|error" app.log command | grep "pattern"

-n shows line numbers, -i ignores case, and -R searches recursively.

Find files

find
find . -name "*.log" find /var/log -type f -mtime -1 find . -type f -size +100M find . -type f -name "*.tmp" -print

Start from the directory you need rather than / to avoid unnecessary output and permission errors.

Redirect output

shell
command > output.txt # overwrite file command >> output.txt # append to file command 2> errors.txt # save errors command 2>&1 | tee run.log # display and save output

Compare and count

diff · wc
diff -u old.conf new.conf wc -l access.log # count lines sort names.txt | uniq # sort and remove duplicates

System, permissions & processes

System changes need administrator privileges. Use sudo only when a command requires it.

File permissions

chmod
chmod u+x script.sh chmod 644 file.txt chmod 755 script.sh

Numeric values: 4 read, 2 write, 1 execute. 755 = owner rwx, others r-x.

Owner and group

chown
sudo chown user:group file sudo chown -R user:group directory/ # recursive

Check the target directory and its contents before a recursive ownership change.

Inspect processes

ps · top
ps aux ps -ef | grep nginx top free -h df -h

top shows processes and load; free -h shows memory; df -h shows filesystem space.

Stop a process

kill
kill PID kill -TERM PID # ask it to exit kill -KILL PID # force stop if TERM did not work pkill -f "process-name"

Find the PID with ps. KILL does not give the process time to save data.

systemd services

systemctl
systemctl status ssh sudo systemctl enable --now ssh sudo systemctl restart ssh journalctl -u ssh -e journalctl -u ssh -f

The OpenSSH service is usually called sshd on Fedora/Arch and ssh on Debian/Ubuntu.

Network & packages

Package commands need root privileges. Use repositories and signing keys you trust.

Network and listening ports

ip · ss
ip addr ip route ss -tulpn curl -I https://example.com ping -c 4 1.1.1.1

ss -tulpn lists TCP/UDP sockets; showing process names may require sudo.

Update packages

by distribution
# Debian / Ubuntu sudo apt update && sudo apt upgrade sudo apt install package # Fedora / RHEL sudo dnf upgrade sudo dnf install package # Arch Linux sudo pacman -Syu sudo pacman -S package

On Arch, upgrade the whole system with pacman -Syu; do not perform partial upgrades.

SSH & file transfers

Install an SSH client locally and the server daemon on the machine you want to reach.

Connect to a server

ssh
ssh user@server.example.com ssh -p 2222 user@203.0.113.10 ssh -v user@server.example.com # verbose diagnostics

Verify the server fingerprint through a trusted channel on your first connection.

Install and enable the SSH server

sshd
# Debian / Ubuntu sudo apt update && sudo apt install openssh-server sudo systemctl enable --now ssh # Fedora / RHEL sudo dnf install openssh-server sudo systemctl enable --now sshd # Arch sudo pacman -S openssh sudo systemctl enable --now sshd

For remote access, also allow the SSH port in the host firewall and your provider's network rules.

Create an SSH key

keys
ssh-keygen -t ed25519 -a 64 -C "device-name" eval "$(ssh-agent -s)" ssh-add ~/.ssh/id_ed25519

Protect the private key with a passphrase. Never share id_ed25519; the server only needs the .pub file.

Install your key on the server

ssh-copy-id
ssh-copy-id user@server.example.com ssh-copy-id -p 2222 user@server.example.com cat ~/.ssh/id_ed25519.pub

If ssh-copy-id is unavailable, add the public key contents to ~/.ssh/authorized_keys on the server.

Transfer files with SCP

scp
scp file.txt user@server:/home/user/ scp -P 2222 archive.tar.gz user@server:/tmp/ scp user@server:/var/log/app.log . scp -r directory/ user@server:/home/user/

SCP uses uppercase -P for the port; SSH uses lowercase -p.

Sync with rsync

rsync
rsync -avh --progress ./site/ user@server:/var/www/site/ rsync -avh --progress user@server:/var/log/app.log .

The trailing slash in ./site/ means “copy the contents.” For a custom SSH port, add -e "ssh -p 2222".

Forward a GUI application

X11 forwarding
ssh -X user@server.example.com ssh -Y user@server.example.com # trusted server only editor

The client needs an X server; the SSH server must allow X11Forwarding yes and set DISPLAY. For a full desktop, use a VPN with RDP (such as xrdp) or a trusted mesh VPN and remote desktop. Never expose unencrypted VNC/RDP directly to the internet.

First-time SSH server setup

Example for a fresh VPS. Replace the username, public IP, hostname, and port. Set up and verify key login before disabling password authentication.

Keep your current SSH session open until a second session successfully connects with the new port and key. A firewall or sshd mistake can lock you out; make sure you have your provider's console access.

01 · Update the system

root or sudo
# Debian / Ubuntu apt update && apt upgrade -y # Fedora / RHEL dnf upgrade --refresh -y # Arch pacman -Syu

Run from the provider console or an existing administrator account.

02 · Create an administrator

user · sudo
# Debian / Ubuntu adduser deploy usermod -aG sudo deploy # Fedora / RHEL / Arch useradd -m -s /bin/bash deploy passwd deploy usermod -aG wheel deploy # Verify group membership id deploy

On Fedora/RHEL and Arch, confirm the wheel group is allowed in sudoers. Use visudo to validate changes; do not edit sudoers without checking its syntax.

03 · Install and enable SSH

sshd
# Debian / Ubuntu apt install openssh-server systemctl enable --now ssh # Fedora / RHEL dnf install openssh-server systemctl enable --now sshd # Arch pacman -S openssh systemctl enable --now sshd

04 · Install your public key

authorized_keys
# On your local computer: ssh-copy-id deploy@server.example.com # To add a key manually, on the server as deploy: mkdir -p ~/.ssh chmod 700 ~/.ssh printf '%s\n' 'PASTE_PUBLIC_KEY_CONTENTS_HERE' >> ~/.ssh/authorized_keys chmod 600 ~/.ssh/authorized_keys

The public key is the line in id_ed25519.pub. Never put the private key (the file without .pub) in authorized_keys.

05 · Change the port and allow it through the firewall

firewall first
# Choose an unused port, for example 2222. # Set this in /etc/ssh/sshd_config: Port 2222 # Allow it before reloading SSH: # Debian / Ubuntu with UFW ufw allow 2222/tcp ufw status # Fedora / RHEL with firewalld firewall-cmd --permanent --add-port=2222/tcp firewall-cmd --reload # Arch: allow it in your configured firewall (nftables/ufw)

Also open the TCP port in your cloud provider's network firewall. On Fedora/RHEL with SELinux, label a custom SSH port with semanage port -a -t ssh_port_t -p tcp 2222 (policy tools required).

06 · Validate and reload

keep session open
sshd -t systemctl reload sshd || systemctl reload ssh

If sshd -t reports an error, do not reload the service. Fix the config first and use the service name for your distribution.

07 · Test a second login

required
ssh -p 2222 deploy@server.example.com

Confirm that key authentication works and the user has sudo access (sudo -v). Keep the first session open.

08 · Disable password and root login

after key login works
# In /etc/ssh/sshd_config: PasswordAuthentication no KbdInteractiveAuthentication no PermitRootLogin no # Validate and apply: sshd -t systemctl reload sshd || systemctl reload ssh

Check for overriding settings in /etc/ssh/sshd_config.d/*.conf and verify the effective config. Open another fresh key-authenticated session before closing the old one.

Service names and firewall tools vary by distribution and provider image. Before finishing, check the active config with sshd -T, the service status, and firewall rules.