grep -rl "sysadmin" ./blog

Linux System Administration

Running and maintaining Linux systems: services, users, storage, logs, backups, and the recovery procedures you want to have read before you need them.

136 articles

Core Dumps on Linux: Debugging Crashes With coredumpctl When a program crashes, Linux can save a snapshot of its memory. How core dumps work, where systemd-coredump stores them, how to list and inspect crashes with coredumpctl and gdb, get debug symbols with debuginfod, and control disk use. CrowdSec vs Fail2ban: Blocking Attackers on Linux Servers Fail2ban bans IPs that fail too often in your logs. CrowdSec does the same and shares signals with every other CrowdSec user. How each works, setup for SSH, the bouncer model, privacy trade-offs, and which to run. Gitea vs Forgejo: Which Self-Hosted Git Forge Should You Run? Forgejo began as a fork of Gitea and is now a separate project. How they differ in governance, licensing, features, and federation, how hard it is to switch, and which one fits a homelab, a team, or a public instance. Malware Scanning on Linux: ClamAV, rkhunter, and Lynis Compared Three different tools that are often lumped together as Linux antivirus. What ClamAV, rkhunter, chkrootkit, and Lynis each actually detect, how to run them, how to read their false positives, and when scanning is worth it. The nmap Command Explained: Scanning Your Own Network the Right Way How to use nmap to discover devices on your network, find open ports, identify services and versions, and read the results, with the scan types that matter and the legal line you should not cross. OpenTofu vs Terraform: Licensing, Compatibility, and How to Switch OpenTofu forked from Terraform after HashiCorp moved to the Business Source License in 2023. How the two differ now, what OpenTofu adds such as state encryption, how compatible they remain, and how to migrate a project. How to Reset a Forgotten Root or User Password on Linux Locked out of your own Linux machine? How to reset the root or a user password from the GRUB menu with init=/bin/bash or rd.break, from Ubuntu's recovery mode, or from a live USB, including SELinux and encrypted-disk caveats. Speeding Up Linux Boot With systemd-analyze Find out where boot time actually goes with systemd-analyze time, blame, critical-chain, and plot, then fix the usual culprits: network-wait services, slow firmware, unneeded services, and timeouts on missing disks. Two-Factor Authentication for SSH: TOTP Codes and FIDO2 Security Keys Add a second factor to SSH logins two ways: time-based one-time codes with pam_google_authenticator, or hardware-backed ed25519-sk keys on a YubiKey. Exact sshd configuration, how to avoid locking yourself out, and which to choose. systemd User Services: Running Your Own Services Without Root systemctl --user lets any user run background services and timers under their own account, with logging, restarts, and dependencies. Where unit files go, how lingering keeps them running after logout, and common pitfalls over SSH. How to Upgrade Ubuntu 24.04 LTS to 26.04 LTS Safely A step-by-step guide to upgrading Ubuntu 24.04 to 26.04 on desktops and servers: what to check first, how to handle PPAs and third-party repositories, running the upgrade over SSH, and what to do if it goes wrong. How to Check Whether Your Linux Kernel Is Patched Against a CVE uname -r does not tell you whether a fix is in your kernel, because distributions backport patches without changing the version. How to check a specific CVE on Debian, Ubuntu, Fedora, RHEL, and Arch, and how to confirm you are actually running the fixed kernel. Dinit Explained: The Small Init System Chimera, Artix, and KaOS Chose Over systemd Dinit is a dependency-based init and service manager that fits between runit and systemd. How it boots a system, how service files and dinitctl work, how it compares to systemd, OpenRC and runit, and why distros are adopting it. The ip Command Explained: Addresses, Routes, Links, and Neighbours ip replaced ifconfig, route, and arp as the standard Linux networking tool. How its object and command structure works, the commands you will actually use for addresses, links, routes, and neighbours, and why changes do not survive a reboot. NixOS Explained: A Linux Distro You Configure in One File and Roll Back in One Command NixOS builds your entire system from a declarative configuration, keeps every previous version bootable, and never installs packages into /usr. How the Nix store works, what configuration.nix looks like, what flakes are, and the trade-offs. run0 vs sudo-rs vs sudo: The Three Ways to Get Root on Modern Linux sudo is being rewritten in Rust, and systemd now ships run0, which gets root without a setuid binary at all. How each one works, what they do differently, what sudo-rs leaves out, and which to use. MariaDB and MySQL on Linux: Setup, Users and the Settings That Matter Installing is one command. What follows is the part that bites: unix socket authentication, why utf8 is not UTF-8, the one buffer pool setting worth changing, and a backup that actually restores. nsswitch.conf, getent and SSSD: Where User Accounts Come From Users do not have to live in /etc/passwd. One file decides which sources the system consults for accounts, groups and hostnames, getent shows you the answer, and SSSD is what plugs a directory in. PAM Explained: How Linux Actually Decides Who Gets In Every login, sudo and ssh session runs through a stack of PAM modules before it succeeds. The four module types, what required and sufficient really do, why order changes the outcome, and how to edit it without locking yourself out. Sending Mail From a Server: msmtp, Postfix Relay and Cron Alerts Running a full mail server to send yourself alerts is the wrong amount of work. Relaying through an existing provider takes ten minutes, and there is one setting that stops your credentials being world readable. tcpdump Explained: Capturing Packets and Reading What You Caught When the logs say a connection failed and both sides insist they are fine, the packets settle it. Filter syntax that actually narrows things down, reading a TCP handshake, and why you capture to a file and analyse it elsewhere. cron vs systemd Timers: Which to Use Why a cron job that fails silently is the default behaviour, what timers give you that cron cannot, and when cron is still the right answer. Hardware vs Software RAID Why the controller that was supposed to be faster is now usually the liability, what a BBU actually buys you, and where hardware RAID still wins. SSH Certificate Authorities: Access Control That Scales How SSH certificates replace authorized_keys sprawl, why they solve revocation and host key verification at once, and how to set up a CA properly. Cockpit: A Web Console for Linux Servers What Cockpit gives you, why it does not maintain its own state, the security considerations of exposing it, and when a web console beats SSH. Filesystem Quotas Explained Setting per-user and per-group disk limits on ext4 and XFS, the difference between soft and hard limits, and why inode quotas matter as much as block quotas. lnav: Log Analysis Without grep Gymnastics A log viewer that parses timestamps, merges files into one timeline, and lets you query logs with SQL, which is what you actually wanted when you started piping grep into awk. Nginx vs Apache vs Caddy: Choosing a Web Server How the three differ architecturally, why Apache is not actually slow any more, what Caddy automates, and which to pick for a given job. PostgreSQL on Linux: Install, Secure, Back Up Getting PostgreSQL running on Linux, understanding peer and md5 authentication in pg_hba.conf, the settings worth tuning, and backups that actually restore. restic vs Borg: Choosing a Backup Tool How both deduplicate and encrypt, where Borg is faster and restic is more portable, and the operational differences that decide it. rsync Explained: Flags, Trailing Slashes, and Not Deleting Your Data How the delta algorithm works, what the trailing slash actually changes, why --delete needs --dry-run first, and the flag combinations for backups, mirrors, and migrations. screen vs tmux: Which Terminal Multiplexer Why a multiplexer keeps your session alive when SSH drops, where screen still wins, and how to reattach to the session you left running last week. ssh-agent and Agent Forwarding Explained How ssh-agent holds your decrypted keys, why agent forwarding is convenient and risky, and what ProxyJump does instead. Network Bonding on Linux: Combining Interfaces for Redundancy or Speed Bonding aggregates several network interfaces into one. Some modes give failover with no switch configuration, others give more bandwidth and need the switch to cooperate. Traffic Shaping with tc: Fixing Bufferbloat and Limiting Bandwidth tc controls how the kernel queues outgoing packets. The most valuable thing it does is not limiting bandwidth but fixing the latency spikes that make a saturated link feel broken. IPv6 on Linux: Addresses, Autoconfiguration, and Why Your Firewall Might Be Open IPv6 is on by default and most people never configure it, which is exactly how a machine ends up firewalled on IPv4 and reachable on IPv6. Here is what the address types mean and what to check. nvme-cli: Managing and Monitoring NVMe Drives SMART attributes on NVMe live in a different place and speak a different language. nvme-cli reads wear percentage, temperature, and error counts, and handles secure erase and firmware updates. VLANs and Bridges on Linux: Segmenting a Network on One Cable A bridge is a software switch and a VLAN tags traffic so one physical link carries several logical networks. Together they are how virtual machines and containers reach a real network. fio: Benchmarking Disks Properly dd measures one thing badly. fio measures what you actually care about: random IOPS, latency percentiles, and behaviour under concurrency. Here is how to run it without fooling yourself. fsck: Checking and Repairing Linux Filesystems Never run it on a mounted filesystem. Beyond that one rule, here is how to force a check at boot, what the repair prompts actually mean, and when a filesystem problem is really a disk problem. DKMS Explained: Why Your Driver Breaks on Kernel Updates Out-of-tree kernel modules have to be rebuilt for every kernel. DKMS automates that, and understanding it is the difference between a routine update and booting to a black screen. Linux I/O Schedulers: mq-deadline, BFQ, Kyber, and none The scheduler decides the order requests reach your disk. On spinning rust it matters enormously, on NVMe it often should be switched off, and the right default differs per device. Exit Codes Explained: What $? Is Telling You Every command returns a number. Zero means success and everything else means something specific, including the codes that encode which signal killed a process. Bash Arrays and Parameter Expansion Arrays handle lists of things without word splitting bugs, and parameter expansion does substring, default, and pattern operations without launching sed. Both remove whole categories of shell mistakes. tee Command Explained: Writing to a File and the Screen at Once tee splits a stream so it goes to a file and onward down the pipeline. It is also the standard way to write to a root-owned file without running your editor as root. cloud-init: Configuring a Machine on Its First Boot The standard mechanism for turning a generic cloud image into a configured machine. It sets hostnames, installs SSH keys, creates users, and runs commands, once, before you ever log in. Linux Namespaces Explained: What a Container Actually Is A container is not a thing the kernel knows about. It is a normal process with a restricted view of the system, built from namespaces, cgroups, and a changed root. Here is what each piece does. Nested Virtualization: Running a Hypervisor Inside a Virtual Machine Testing Proxmox, building a Kubernetes lab, or running Docker Desktop inside a VM all need the guest to be a hypervisor itself. Here is how to enable it and what it costs. KVM, QEMU, and libvirt: What Each One Actually Does Three names get used interchangeably for Linux virtualization and they are three different layers. Understanding which does what makes the whole stack considerably less confusing. virt-manager and virsh: Running Virtual Machines on Linux One is a graphical console for libvirt and the other is its command line. Here is how to create, manage, snapshot, and connect to virtual machines with both. Monitoring a Home Server: Netdata, Prometheus, and Grafana One tool gives you everything in five minutes, the other gives you history and alerting but takes an afternoon. Here is which to pick and how the pieces fit together. zram and Swap Tuning: Compressed Memory Instead of Disk zram gives you swap that lives in RAM, compressed. On machines with limited memory it is dramatically faster than swapping to disk, and most distributions now enable it by default. GRUB Explained: Configuration, Kernel Parameters, and Repair GRUB is the last thing that runs before the kernel and the first thing to blame when a machine will not boot. Here is how its configuration actually works and why editing the generated file is the wrong move. initramfs Explained: The Tiny Filesystem That Boots Your Real One Between the kernel starting and your root filesystem mounting sits a small temporary system that loads the drivers needed to find the real disk. Here is what it does and how to rebuild it when it breaks. The First Ten Minutes on a New Linux Server A fresh VPS is reachable from the entire internet within seconds of provisioning. Here is the short, ordered list of things to do before you install anything else. firewalld Explained: Zones, Services, and Runtime vs Permanent Fedora and RHEL ship firewalld rather than ufw, and its zone model confuses people arriving from other distributions. Here is how zones work and why half your rules disappear on reboot. Software RAID with mdadm: Levels, Setup, and What RAID Does Not Do Linux software RAID is mature, fast, and free. Here is what each level actually gives you, how to build and monitor an array, and why RAID is not a backup. Bash Error Handling: set -euo pipefail and Why Your Script Needs It By default a bash script that fails halfway through keeps running as if nothing happened. Three options change that, and knowing exactly what each one does is the difference between safety and mystery. ldd and Shared Libraries: Why Your Binary Says No Such File A program that exists, is executable, and still reports file not found is almost always missing a shared library. Here is how dynamic linking works and how to find what is missing. udev Rules Explained: Making Devices Behave the Way You Want Device names are not stable, permissions default to root, and nothing happens automatically when you plug something in unless you tell it to. udev rules fix all three. ulimit Explained: Per-Process Resource Limits and Why Services Ignore Them Too many open files is one of the most common server errors, and raising the limit is more subtle than it looks. Here is how soft and hard limits work, and why the shell setting does not apply to your systemd service. cgroups Explained: Limiting CPU, Memory, and I/O With systemd Control groups are the kernel mechanism behind container resource limits, and you can use them directly on any service. Here is what cgroups v2 does and how to cap a process without writing a container. dmesg Explained: Reading Kernel Messages When Hardware Misbehaves When a disk fails, a USB device does not enumerate, or the kernel kills a process for using too much memory, it says so in the kernel ring buffer. dmesg is how you read it. jq Explained: Querying JSON From the Command Line APIs, container tooling, and cloud CLIs all speak JSON, and grep is the wrong tool for structured data. jq is a small language for filtering and reshaping it, and a handful of patterns cover most real use. lsof Explained: Finding What Has a File, Port, or Mount Open Everything on Linux is a file, which means one tool can answer what is using this port, why can I not unmount this disk, and what is holding onto deleted data. That tool is lsof. nice, renice, and ionice: Controlling Process Priority on Linux A backup job should not make your desktop stutter. Priority tools let you tell the kernel which work matters less, for both CPU time and disk access, and the disk one is usually the fix people actually need. sysctl Explained: Reading and Changing Kernel Parameters IP forwarding, swappiness, file descriptor limits, and connection backlogs are all kernel parameters you can read and change at runtime. Here is how sysctl works and which settings are actually worth touching. SSH Keys Explained: Generating, Using, and Not Losing Them Password authentication over SSH is a liability on any internet-facing server. Key authentication is better in every way and takes two minutes to set up. Here is how keys work, which type to generate, and how to manage them properly. Linux ACLs Explained: getfacl and setfacl Beyond rwx Permissions Standard permissions give you one owner, one group, and everyone else. Access control lists let you grant specific users and groups their own permissions on a file, and getfacl and setfacl are how you manage them. Rescuing an Unbootable Linux System with chroot When Linux will not boot, a live USB plus chroot lets you enter the broken installation as if it were running: fix the bootloader, roll back a bad kernel, reset a password, and reinstall packages from inside. Kernel Modules Explained: lsmod, modprobe, and DKMS Most drivers on Linux are kernel modules, loaded and unloaded at runtime. Here is how to inspect them with lsmod and modinfo, manage them with modprobe, blacklist the troublesome ones, and understand what DKMS rebuilds. logrotate Explained: Keeping Log Files From Eating Your Disk logrotate renames, compresses, and eventually deletes aging log files on a schedule, and nearly every distro ships it preconfigured. Here is how the rotation cycle works and how to write configs for your own apps. NFS vs Samba Explained: Sharing Files Between Machines NFS and Samba both put one machine s storage on another machine s filesystem, but they come from different worlds. Here is how each works, which to choose, and minimal working configs for both. Monitoring Disk Health with smartctl: Reading SMART Before the Drive Dies Every drive tracks its own health through SMART. smartctl reads those attributes, runs self-tests, and, read correctly, gives you warning before a disk fails. Here is what to check and which numbers actually predict death. Building Software From Source on Linux When software is not packaged for your distribution, or you need a newer version, compiling from source is the fallback. This guide covers the standard configure/make/install workflow, installing build dependencies, and cleanly uninstalling afterward. Checking Network Connections: ss and nmcli Explained ss inspects active sockets and connections, and nmcli configures and queries NetworkManager. Together they cover the two most common modern network troubleshooting and configuration tasks on Linux. The dd Command Explained dd copies raw data block by block, which makes it the standard tool for writing bootable USB drives, cloning disks, and wiping data securely. It is also famous for having no confirmation prompt, this guide covers safe usage and why it earned the nickname "disk destroyer." Docker and Podman: Container Basics on Linux An introduction to running containers on Linux with Docker and Podman: images, containers, the core commands you need day to day, and how the two tools differ. ext4 vs Btrfs vs XFS Explained Choosing a Linux filesystem matters more than most default-accepting installs suggest. This guide compares ext4, Btrfs, and XFS on stability, snapshots, scalability, and which one fits which use case. GPG Basics on Linux GPG provides encryption and digital signatures using public-key cryptography, and it underlies how Linux package repositories verify software has not been tampered with. This guide covers generating a key pair, encrypting and decrypting files, and signing and verifying. Hardware Info Commands: lscpu, lsblk, lspci, lsusb, and dmidecode How to inspect your CPU, storage devices, PCI hardware, USB devices, and full system hardware inventory from the Linux command line, without opening a graphical tool. journalctl and /var/log Explained Linux logs live in two places on most modern systems: the systemd journal, queried with journalctl, and traditional plain-text files under /var/log. This guide covers reading, filtering, and following logs in both. LVM (Logical Volume Manager) Explained LVM adds a flexible layer between raw disks and filesystems, letting you resize, combine, and snapshot storage without being locked into fixed-size partitions. This guide covers physical volumes, volume groups, logical volumes, and common resizing operations. Managing User Accounts on Linux How to create, modify, and remove user accounts on Linux with useradd, usermod, userdel, and passwd, plus what actually lives inside /etc/passwd and /etc/shadow. The /proc Filesystem Explained /proc is a virtual filesystem that exposes live kernel and process information as ordinary files, and it is what tools like ps, free, and top actually read from. This guide covers what /proc is, its most useful files, and how to read it directly. strace and ltrace Explained When a program fails with no useful error message, strace and ltrace show exactly what system calls and library calls it is making, often revealing the real problem in seconds. This guide covers reading their output and common debugging patterns. Swap Space Explained What swap actually does on Linux, how it differs from RAM, how to create a swap partition or swapfile, and how to tune swappiness for desktops, laptops, and servers. timedatectl and NTP Explained Accurate system time matters more than most people realize, from TLS certificate validation to log ordering across servers. This guide covers checking and setting time and timezone with timedatectl, and how NTP keeps clocks synchronized automatically. Understanding Process Signals on Linux Signals are how Linux tells a running process to stop, reload, or respond to an event. This guide covers the most important signals, the real difference between SIGTERM and SIGKILL, and how to send and handle them. Writing systemd Service Files Explained Beyond using systemctl to manage existing services, writing your own .service unit file lets you run any script or program as a properly managed systemd service. This guide covers unit file structure, common directives, and enabling a custom service. The /var Directory Explained /var holds the data that changes constantly while Linux runs: logs, caches, spools, and databases. This guide explains what lives in /var, why it grows over time, and how to manage its disk usage. Automated Backups on Linux A practical guide to setting up automated backups on Linux using rsync, tar, and dedicated tools like restic and Borg, following the 3-2-1 rule, scheduling with cron or systemd timers, and actually verifying backups work. CPU Monitoring on Linux A practical guide to monitoring CPU usage on Linux, covering top, htop, and mpstat, how to read user/system/wait time breakdowns, per-core versus aggregate views, and identifying whether a bottleneck is CPU-bound or I/O-bound. The free Command Explained free is the fastest way to check RAM and swap usage on Linux. This guide covers every column in its output, why "available" matters more than "free", and how to read swap usage correctly. iostat Explained iostat reports per-device disk I/O statistics, showing throughput, request sizes, queue depth, and utilization. This guide covers installing sysstat, reading iostat -x output, and identifying which disk is actually the bottleneck. Monitoring Disk Usage on Linux A practical guide to checking disk space on Linux using df and du, understanding the difference between filesystem-level and directory-level usage, tracking down what is actually filling a disk, and watching out for inode exhaustion. Monitoring Memory Usage on Linux A practical guide to checking memory usage on Linux: reading /proc/meminfo, understanding what counts as "used" memory, finding which process is consuming RAM, and recognizing real memory pressure versus normal cache behavior. Writing Scheduled Scripts That Actually Work on Linux Scripts that run fine interactively often fail silently when triggered by cron or systemd timers. This guide covers the practical differences: environment variables, working directories, logging, locking, and failure notification for scripts meant to run unattended. Understanding Load Average on Linux Load average is one of the most misread numbers in Linux administration. This guide explains what it actually measures, why Linux counts differently from other Unix systems, and how to judge whether a load average is actually a problem. The uptime Command Explained uptime is the fastest way to check how long a Linux system has been running and how busy it is. This guide covers reading its output, the three load average numbers, and how uptime relates to system reboots and patching. vmstat Explained vmstat reports processes, memory, swap, I/O, and CPU activity in one compact table, sampled at an interval you choose. This guide breaks down every column and how to spot memory pressure, I/O bottlenecks, and CPU contention from its output. AppArmor Explained AppArmor is a mandatory access control system for Linux that confines programs to a limited set of resources using per-application profiles. This guide covers how AppArmor works, how to read and write profiles, and how to move from complain mode to enforce mode. APT Guide (Debian/Ubuntu) APT is the package manager for Debian, Ubuntu, and their derivatives. This guide covers everything from daily commands through repository management, pinning, held packages, and dpkg for when you need to go lower level. Checking Open Ports on Linux Knowing which ports are open and which processes are listening on them is essential for security audits, debugging, and firewall configuration. This guide covers ss, lsof, nmap, and related tools. Cron Jobs Explained Cron is the classic Unix job scheduler. This guide covers the crontab syntax, the five time fields, user and system crontabs, the cron.d and cron.daily directories, environment variables, logging, and common pitfalls. DNF Guide (Fedora/RHEL) DNF is the package manager for Fedora, RHEL, AlmaLinux, and Rocky Linux. This guide covers daily commands, module streams, COPR repositories, version locking, and the rpm layer underneath. DNS Explained DNS translates human-readable hostnames into IP addresses. This guide covers how the resolution process works, the most important record types, and the Linux tools used to query and debug DNS. Fail2Ban Setup Fail2ban monitors log files for repeated authentication failures and automatically bans the offending IP addresses using firewall rules. This guide covers installation, configuration, and managing jails for SSH, nginx, and other services. How Linux Permissions Work Linux permissions control who can read, write, and execute every file and directory on the system. This guide explains the permission model from the basics through to special bits, umask, and ACLs. IP Addresses Explained IP addresses are how devices on a network identify themselves. This guide covers IPv4 and IPv6 addressing, CIDR notation, public vs private addresses, subnetting basics, and how Linux assigns and displays addresses. Keeping Linux Updated Staying current with security patches is the single highest-impact thing you can do to protect a Linux system. This guide covers update commands for every major distro, how to automate security updates, and how to handle kernel updates safely. Killing Processes in Linux Killing a process on Linux means sending it a signal. Understanding the difference between SIGTERM and SIGKILL, how to find the right process to target, and what to do when a process refuses to die covers everything you need. Linux Boot Process Explained From pressing the power button to a login prompt, a Linux system goes through a precise sequence of steps. Understanding each stage -- firmware, bootloader, kernel, initrd, and systemd -- demystifies boot failures and makes the system less of a black box. Linux Desktop vs Linux Server: What Is the Difference? Linux desktop and Linux server share the same kernel but diverge sharply in defaults, software, use cases, and administration. Here is a practical breakdown of what separates them. Linux File System Hierarchy Explained Linux puts every file in a specific place for a reason. This guide walks through the Filesystem Hierarchy Standard, explains what belongs where, and covers the modern changes that have reshaped the traditional layout. Linux Firewall Basics Linux firewalls control which network traffic is allowed in and out of your system. This guide covers the concepts, ufw for simple setups, and an introduction to the underlying nftables rules that power them all. Linux Malware Myths The idea that Linux cannot get malware is dangerously wrong. Linux systems -- especially servers -- are actively targeted. This guide covers what real Linux malware looks like, how it gets in, and how to detect and prevent it. Linux Networking Basics Understanding how Linux handles networking -- interfaces, IP addresses, routing, DNS, and the tools to inspect all of it -- is foundational for anyone administering a Linux system or working with servers. Linux Security Best Practices A practical security checklist for Linux systems -- covering user privileges, SSH hardening, firewall setup, automatic updates, file integrity monitoring, and auditing tools like Lynis. Linux Users, Groups, and Ownership Explained Linux is a multi-user operating system built around a clear identity model. Understanding users, groups, UIDs, GIDs, sudo, and the root account is essential for administering any Linux system. Managing Services with systemctl systemctl is the command-line interface to systemd. This guide covers starting, stopping, enabling, inspecting, and troubleshooting services, along with the most useful systemctl commands for daily system administration. Network Troubleshooting Commands A practical guide to diagnosing Linux network problems -- from basic connectivity checks with ping, through route tracing with mtr and traceroute, to packet capture with tcpdump and DNS debugging with dig. nftables vs iptables nftables replaced iptables as the standard Linux packet filtering framework. This guide explains the differences, how to use both, and how to migrate from iptables rules to nftables. Pacman Guide (Arch Linux) Pacman is the package manager for Arch Linux, Manjaro, EndeavourOS, and other Arch-based distributions. This guide covers sync, query, remove, AUR helpers, makepkg, and keeping a rolling-release system healthy. ps vs top vs htop: Monitoring Linux Processes ps, top, and htop are the three main tools for inspecting running processes on Linux. Each serves a different purpose. This guide covers what each tool is best for, the most useful commands and keyboard shortcuts, and how to get the information you actually need. Scheduling Tasks with systemd Timers systemd timers are the modern alternative to cron for scheduling tasks on Linux. They offer better logging, dependency support, randomisation, and integration with the rest of the systemd ecosystem. SCP vs SFTP vs rsync SCP, SFTP, and rsync are the three main tools for transferring files over SSH on Linux. This guide covers when to use each, how they work, and practical command examples for common transfer scenarios. SELinux Explained SELinux (Security-Enhanced Linux) is a mandatory access control system built into the Linux kernel. This guide explains how SELinux works, what contexts and policies mean, how to read denials, and how to write rules with audit2allow. SSH Beginner's Guide SSH (Secure Shell) lets you log into remote Linux systems, run commands, and transfer files over an encrypted connection. This guide covers key-based authentication, the SSH config file, port forwarding, and common SSH patterns. SSH Hardening Guide SSH is the most commonly attacked service on internet-facing Linux servers. This guide covers every important sshd_config setting, key management practices, and tools like fail2ban to reduce your exposure. Sudo Explained sudo lets non-root users run commands with elevated privileges in a controlled, auditable way. This guide covers how sudo works, how to configure /etc/sudoers, and common patterns for granting the right level of access. Understanding Linux Packages and Repositories Linux software is distributed as packages, installed from signed repositories, and managed by package managers. This guide explains how the whole system works, from .deb and .rpm files through to Flatpak, Snap, and building from source. Understanding Linux Processes Every running program on Linux is a process. Understanding process IDs, states, parent-child relationships, signals, and how the kernel schedules work is essential for diagnosing problems and administering any Linux system. Updating Linux Safely Keeping a Linux system updated is straightforward -- until an update breaks something. This guide covers how to update safely, how to snapshot before major changes, how to hold back problematic packages, and how to recover when something goes wrong. What Is systemd? systemd is the init system and service manager used by most major Linux distributions. Understanding what it does, how it is structured, and why it replaced older init systems explains a lot about how modern Linux works. Zypper Guide (openSUSE) Zypper is the package manager for openSUSE Leap, openSUSE Tumbleweed, and SUSE Linux Enterprise. This guide covers installation, repository management, patterns, locks, and distribution upgrades.