The tar Command Explained

The tar Command Explained

tar is one of the oldest tools still in daily use on Linux, and its name is a fossil from an era of sequential tape backups. Today it’s the standard way to bundle a directory tree into a single portable file, almost always paired with a compression tool to shrink the result.

Core Concept: Archiving Is Not Compression

tar on its own just concatenates files together into one archive, preserving directory structure, permissions, ownership, and timestamps. It does not shrink the data. Compression is a separate step, which tar can invoke automatically via a flag, piping the archive stream through gzip, bzip2, or xz before writing it to disk.

Basic Flags

FlagMeaning
-cCreate a new archive
-xExtract files from an archive
-tList archive contents without extracting
-fSpecifies the filename (almost always required, must come right before the filename)
-vVerbose, prints each file as it’s processed
-zCompress/decompress with gzip
-jCompress/decompress with bzip2
-JCompress/decompress with xz
-CChange to a directory before extracting (or before adding files, when creating)

Flags are commonly combined without dashes, like tar xzvf instead of tar -x -z -v -f, a holdover from early Unix tar conventions that GNU tar (used on virtually every Linux distro) still accepts alongside the dash-prefixed form.

Creating an Archive

# plain archive, no compression
tar -cvf archive.tar /data

# compressed with gzip
tar -czvf archive.tar.gz /data

# compressed with bzip2
tar -cjvf archive.tar.bz2 /data

# compressed with xz
tar -cJvf archive.tar.xz /data

The compression flag must match the extension convention you’re using; tar doesn’t infer compression from the filename, it only compresses if you pass the corresponding flag.

Extracting an Archive

tar -xzvf archive.tar.gz

tar can usually auto-detect the compression type from the archive’s contents even without the exact matching flag, so tar -xvf archive.tar.gz (without -z) often works too on GNU tar. Being explicit is still good practice for clarity and portability to systems with a stricter tar implementation.

To extract into a specific directory:

tar -xzvf archive.tar.gz -C /opt/target/

The target directory must already exist. tar will not create it for you.

Listing Contents Without Extracting

tar -tzvf archive.tar.gz
-rw-r--r-- user/user   4096 2026-07-01 10:22 data/config.yml
-rw-r--r-- user/user 891200 2026-07-01 10:22 data/export.csv
drwxr-xr-x user/user      0 2026-07-01 10:20 data/logs/

Checking contents before extracting is a good habit, especially for archives from an untrusted source, since it shows exactly what paths will be written without committing to the extraction.

Extracting Just One File

tar -xzvf archive.tar.gz path/inside/archive/file.txt

Specify the exact path as it appears in the archive listing (from -t). tar extracts only that file, leaving the rest of the archive untouched on disk.

Choosing a Compression Format

FormatSpeedRatioTypical Use
.tar.gzFastModerateGeneral-purpose default
.tar.bz2SlowerBetterMiddle ground, less common today
.tar.xzSlowestBestSoftware releases, long-term archives

Dedicated articles on gzip, bzip2, and xz cover each compressor’s tradeoffs and standalone usage in more depth.

Excluding Files When Creating an Archive

tar -czvf archive.tar.gz --exclude='*.log' --exclude='node_modules' /project

Useful for skipping large, regenerable, or irrelevant directories (build artifacts, dependency folders, log files) when archiving a project directory.

Frequently Asked Questions

What does tar stand for and what does it actually do?

tar stands for tape archive, a name inherited from its original purpose of writing files to sequential tape drives. Today it bundles multiple files and directories into a single archive file, preserving directory structure, permissions, ownership, and timestamps. tar itself does not compress data; compression is applied separately, typically through gzip, bzip2, or xz, either as a follow-up step or via a flag that pipes the archive through a compressor automatically.

What is the difference between tar.gz, tar.bz2, and tar.xz?

All three are tar archives compressed with a different tool: gzip for .tar.gz, bzip2 for .tar.bz2, and xz for .tar.xz. gzip is fastest but produces the largest files, xz produces the smallest files but is slowest to compress, and bzip2 sits in between on both speed and compression ratio. For most everyday use, tar.gz is a reasonable default; tar.xz is preferable when file size matters more than compression time, such as software release archives.

What do the tar flags c, x, t, and f actually mean?

c creates a new archive, x extracts files from an existing archive, t lists the contents of an archive without extracting, and f specifies the archive filename that follows. These are almost always combined, for example tar -xvf archive.tar.gz to extract with verbose output, or tar -tvf archive.tar.gz to list contents verbosely without extracting anything.

Why do people write tar flags without a leading dash, like tar xvf instead of tar -xvf?

This is a historical convention from early Unix tar implementations that predates the more standard dash-prefixed flag style used by most modern command-line tools. GNU tar, used on virtually all Linux distributions, accepts both forms interchangeably, so tar xvf file.tar.gz and tar -xvf file.tar.gz behave identically. The no-dash form persists mostly out of habit and muscle memory passed down through documentation and tutorials.

How do I extract a tar archive into a specific directory instead of the current one?

Use the -C flag followed by the target directory, for example tar -xzvf archive.tar.gz -C /opt/target/. The target directory must already exist; tar will not create it automatically. This is useful for extracting software releases or backups directly into their intended install location without needing a separate move step afterward.

How can I see what is inside a tar archive without extracting it?

Use tar -tvf archive.tar.gz (add z for gzip, j for bzip2, or J for xz to match the compression used) to list the full contents with file permissions, sizes, and timestamps, without writing anything to disk. This is worth doing before extracting an unfamiliar archive, particularly one from an untrusted source, to check what it actually contains and whether paths look reasonable before committing to extraction.