Linux

Linux is the operating system of the internet. It runs the vast majority of web servers, every major cloud's infrastructure, Android phones, embedded devices, and — through the kernel features behind containers — every Kubernetes cluster. Even developers who work on macOS or Windows deploy to Linux, so knowing how to navigate, configure, and debug a Linux server is a core engineering skill.

Strictly, Linux is the kernel; a distribution combines it with GNU tools, a package manager, an init system, and defaults. The fundamentals — files, permissions, processes, services, and networking — are the same across distributions, and they're what this page covers.

TL;DR

Quick Example

A first-five-minutes triage on a server that's "slow":

Running an application as a hardened systemd service:

Core Concepts

Distributions

Prefer LTS releases for servers and use minimal or distroless base images for containers.

The Filesystem Hierarchy

Users, Groups, and Permissions

Every file has an owner, a group, and permission bits for owner, group, and others. ls -l shows them as rwxr-x---; numerically that's 750.

Special bits include setuid, setgid, and the sticky bit (/tmp). Access control lists (setfacl) and security modules (SELinux, AppArmor) add finer control.

Processes and Signals

Each process has a PID and a parent. Signals control them: SIGTERM (15) asks a process to exit gracefully, SIGKILL (9) forces it, SIGHUP often reloads configuration. ps aux, pgrep, top, and /proc/<pid>/ inspect them; strace shows system calls and lsof shows open files and sockets.

systemd and the Journal

systemd starts services in dependency order, restarts them on failure, applies resource limits and sandboxing, and schedules jobs with timers (a modern cron alternative). journalctl queries structured logs by unit, priority, and time.

Networking Tools

ip addr and ip route show interfaces and routes; ss lists sockets; dig and resolvectl debug DNS; curl -v tests HTTP; tcpdump captures packets; nft or iptables (often via ufw or firewalld) filter traffic.

Kernel Features Behind Containers

Namespaces isolate what a process can see (PIDs, network, mounts), and cgroups limit what it can use (CPU, memory). Docker, Podman, and Kubernetes are built on them. eBPF lets safe programs run in the kernel for observability, networking, and security.

Best Practices

Use Key-Based SSH and Disable Root Login

Set PasswordAuthentication no and PermitRootLogin no, use SSH keys or an SSH certificate authority, and consider SSM Session Manager or a bastion instead of exposing port 22.

Run Services as Unprivileged Users

Give each service its own user and minimal file permissions, and use systemd sandboxing options.

Patch Regularly and Automatically

Enable unattended security updates (unattended-upgrades, dnf-automatic) and schedule reboots for kernel updates.

Configure Servers With Code

Use Ansible, cloud-init, or immutable images instead of hand-editing files on each server. See Infrastructure as Code.

Centralize Logs and Metrics

Ship the journal and application logs to a central system and monitor CPU, memory, disk, and network with alerts. See Monitoring.

Watch Disk and Inodes

Rotate logs with logrotate or journald limits; a full disk or exhausted inodes breaks almost everything.

Common Mistakes

chmod 777 to "Fix" Permissions

It makes files writable by everyone. Find the right owner and minimal permissions instead.

Killing With -9 First

SIGKILL skips cleanup, leaving temp files, locks, or corrupted state. Send SIGTERM, wait, then escalate.

Misreading Memory Usage

Linux uses free memory for page cache, so "used" looks high. Check the "available" column and watch for OOM kills in dmesg.

Editing Production Servers by Hand

Manual changes drift and disappear when servers are replaced. Change configuration through code and redeploy.

Ignoring Load Average Context

A load average of 8 is alarming on 2 CPUs and fine on 16. Compare it to nproc and check whether processes wait on CPU or I/O.

FAQ

Why do servers run Linux?

It's free, open source, stable, efficient, highly configurable, and supported by every cloud provider and container platform, with decades of tooling built around it.

Which Linux distribution should I learn?

Ubuntu or Debian is the easiest starting point and the most common in the cloud. Learning RHEL-family tools (dnf, SELinux) is useful for enterprise environments.

What is systemd?

The init system and service manager on most modern distributions. It starts and supervises services, manages logging through the journal, and handles timers, mounts, and resource limits.

How do I find what's using a port?

Run sudo ss -tulpn | grep :8080 or sudo lsof -i :8080 to see the process listening on that port.

What's the difference between Linux and Unix?

Unix is the family of operating systems from Bell Labs and its descendants (BSD, macOS, Solaris). Linux is a Unix-like kernel written independently, following the same design principles and POSIX standards.

Related Topics

References