Where am I?
orientationpwd # current directory
whoami # current user
hostname # machine name
date # date and time
uname -a # kernel and architectureEveryday shell commands, SSH, and basic administration. Search by task or command. Distribution-specific differences are called out.
Check where you are, which user you are, and what is happening on the system.
pwd # current directory
whoami # current user
hostname # machine name
date # date and time
uname -a # kernel and architectureman ssh # manual page
ssh --help # program help
help cd # shell built-in help
apropos filesystem # search manual page descriptionsIn man: /word searches, n jumps to the next match, and q quits.
Check paths carefully. Recursive options such as -r affect everything below a directory.
ls -lah # detailed list, including hidden files
ls -lt # newest changes first
du -sh directory/ # total directory sizecd /var/log # absolute path
cd .. # parent directory
cd ~ # home directory
cd - # previous directorymkdir notes
mkdir -p project/src/components
touch todo.txtThe -p flag creates missing parent directories and does not complain if they already exist.
cp report.txt backup.txt
cp -i file.txt /tmp/ # prompt before overwrite
cp -a folder/ folder-copy/ # copy directory and attributesmv old-name.txt new-name.txt
mv file.txt ~/Documents/
mv -i report.txt archive/Add -i to prompt before overwriting an existing file.
rm -i file.txt
rmdir empty-directory
rm -r directory/ # directory and its contentsCareful: rm has no trash. Check pwd and the target path first.
ln -s /path/to/original shortcut
readlink -f shortcutln -s creates a symbolic link; without -s, it creates a hard link.
tar -czf archive.tar.gz directory/ # create
tar -tzf archive.tar.gz # list contents
tar -xzf archive.tar.gz -C /tmp # extract into directoryUse less for large files and pipe commands together with |.
cat config.conf # print whole file
less /var/log/syslog # page through a file
head -n 20 file.txt # first 20 lines
tail -n 50 file.txt # last 50 lines
tail -f application.log # follow new linesPress q to quit less.
grep -n "error" app.log
grep -Rni "TODO" ./src
grep -E "warn|error" app.log
command | grep "pattern"-n shows line numbers, -i ignores case, and -R searches recursively.
find . -name "*.log"
find /var/log -type f -mtime -1
find . -type f -size +100M
find . -type f -name "*.tmp" -printStart from the directory you need rather than / to avoid unnecessary output and permission errors.
command > output.txt # overwrite file
command >> output.txt # append to file
command 2> errors.txt # save errors
command 2>&1 | tee run.log # display and save outputdiff -u old.conf new.conf
wc -l access.log # count lines
sort names.txt | uniq # sort and remove duplicatesSystem changes need administrator privileges. Use sudo only when a command requires it.
chmod u+x script.sh
chmod 644 file.txt
chmod 755 script.shNumeric values: 4 read, 2 write, 1 execute. 755 = owner rwx, others r-x.
sudo chown user:group file
sudo chown -R user:group directory/ # recursiveCheck the target directory and its contents before a recursive ownership change.
ps aux
ps -ef | grep nginx
top
free -h
df -htop shows processes and load; free -h shows memory; df -h shows filesystem space.
kill PID
kill -TERM PID # ask it to exit
kill -KILL PID # force stop if TERM did not work
pkill -f "process-name"Find the PID with ps. KILL does not give the process time to save data.
systemctl status ssh
sudo systemctl enable --now ssh
sudo systemctl restart ssh
journalctl -u ssh -e
journalctl -u ssh -fThe OpenSSH service is usually called sshd on Fedora/Arch and ssh on Debian/Ubuntu.
Package commands need root privileges. Use repositories and signing keys you trust.
ip addr
ip route
ss -tulpn
curl -I https://example.com
ping -c 4 1.1.1.1ss -tulpn lists TCP/UDP sockets; showing process names may require sudo.
# Debian / Ubuntu
sudo apt update && sudo apt upgrade
sudo apt install package
# Fedora / RHEL
sudo dnf upgrade
sudo dnf install package
# Arch Linux
sudo pacman -Syu
sudo pacman -S packageOn Arch, upgrade the whole system with pacman -Syu; do not perform partial upgrades.
Install an SSH client locally and the server daemon on the machine you want to reach.
ssh user@server.example.com
ssh -p 2222 user@203.0.113.10
ssh -v user@server.example.com # verbose diagnosticsVerify the server fingerprint through a trusted channel on your first connection.
# Debian / Ubuntu
sudo apt update && sudo apt install openssh-server
sudo systemctl enable --now ssh
# Fedora / RHEL
sudo dnf install openssh-server
sudo systemctl enable --now sshd
# Arch
sudo pacman -S openssh
sudo systemctl enable --now sshdFor remote access, also allow the SSH port in the host firewall and your provider's network rules.
ssh-keygen -t ed25519 -a 64 -C "device-name"
eval "$(ssh-agent -s)"
ssh-add ~/.ssh/id_ed25519Protect the private key with a passphrase. Never share id_ed25519; the server only needs the .pub file.
ssh-copy-id user@server.example.com
ssh-copy-id -p 2222 user@server.example.com
cat ~/.ssh/id_ed25519.pubIf ssh-copy-id is unavailable, add the public key contents to ~/.ssh/authorized_keys on the server.
scp file.txt user@server:/home/user/
scp -P 2222 archive.tar.gz user@server:/tmp/
scp user@server:/var/log/app.log .
scp -r directory/ user@server:/home/user/SCP uses uppercase -P for the port; SSH uses lowercase -p.
rsync -avh --progress ./site/ user@server:/var/www/site/
rsync -avh --progress user@server:/var/log/app.log .The trailing slash in ./site/ means “copy the contents.” For a custom SSH port, add -e "ssh -p 2222".
ssh -X user@server.example.com
ssh -Y user@server.example.com # trusted server only
editorThe client needs an X server; the SSH server must allow X11Forwarding yes and set DISPLAY. For a full desktop, use a VPN with RDP (such as xrdp) or a trusted mesh VPN and remote desktop. Never expose unencrypted VNC/RDP directly to the internet.
Example for a fresh VPS. Replace the username, public IP, hostname, and port. Set up and verify key login before disabling password authentication.
# Debian / Ubuntu
apt update && apt upgrade -y
# Fedora / RHEL
dnf upgrade --refresh -y
# Arch
pacman -SyuRun from the provider console or an existing administrator account.
# Debian / Ubuntu
adduser deploy
usermod -aG sudo deploy
# Fedora / RHEL / Arch
useradd -m -s /bin/bash deploy
passwd deploy
usermod -aG wheel deploy
# Verify group membership
id deployOn Fedora/RHEL and Arch, confirm the wheel group is allowed in sudoers. Use visudo to validate changes; do not edit sudoers without checking its syntax.
# Debian / Ubuntu
apt install openssh-server
systemctl enable --now ssh
# Fedora / RHEL
dnf install openssh-server
systemctl enable --now sshd
# Arch
pacman -S openssh
systemctl enable --now sshd# On your local computer:
ssh-copy-id deploy@server.example.com
# To add a key manually, on the server as deploy:
mkdir -p ~/.ssh
chmod 700 ~/.ssh
printf '%s\n' 'PASTE_PUBLIC_KEY_CONTENTS_HERE' >> ~/.ssh/authorized_keys
chmod 600 ~/.ssh/authorized_keysThe public key is the line in id_ed25519.pub. Never put the private key (the file without .pub) in authorized_keys.
# Choose an unused port, for example 2222.
# Set this in /etc/ssh/sshd_config:
Port 2222
# Allow it before reloading SSH:
# Debian / Ubuntu with UFW
ufw allow 2222/tcp
ufw status
# Fedora / RHEL with firewalld
firewall-cmd --permanent --add-port=2222/tcp
firewall-cmd --reload
# Arch: allow it in your configured firewall (nftables/ufw)Also open the TCP port in your cloud provider's network firewall. On Fedora/RHEL with SELinux, label a custom SSH port with semanage port -a -t ssh_port_t -p tcp 2222 (policy tools required).
sshd -t
systemctl reload sshd || systemctl reload sshIf sshd -t reports an error, do not reload the service. Fix the config first and use the service name for your distribution.
ssh -p 2222 deploy@server.example.comConfirm that key authentication works and the user has sudo access (sudo -v). Keep the first session open.
# In /etc/ssh/sshd_config:
PasswordAuthentication no
KbdInteractiveAuthentication no
PermitRootLogin no
# Validate and apply:
sshd -t
systemctl reload sshd || systemctl reload sshCheck for overriding settings in /etc/ssh/sshd_config.d/*.conf and verify the effective config. Open another fresh key-authenticated session before closing the old one.
sshd -T, the service status, and firewall rules.No matches. Try a different command or search term.