Linux
Linux is the operating system of the internet. It runs the vast majority of web servers, every major cloud's infrastructure, Android phones, embedded devices, and — through the kernel features behind containers — every Kubernetes cluster. Even developers who work on macOS or Windows deploy to Linux, so knowing how to navigate, configure, and debug a Linux server is a core engineering skill.
Strictly, Linux is the kernel; a distribution combines it with GNU tools, a package manager, an init system, and defaults. The fundamentals — files, permissions, processes, services, and networking — are the same across distributions, and they're what this page covers.
TL;DR
- Everything is a file: configuration in
/etc, logs in/var/log(or the journal), processes in/proc. - Permissions: owner, group, and others × read, write, execute; use
sudorather than logging in as root. - Processes have PIDs, parents, and signals;
ps,top/htop, andkillmanage them. - systemd manages services (
systemctl) and logs (journalctl) on most modern distributions. - Install software with the package manager (
apt,dnf,apk), not by copying binaries around. - Debug top-down: what changed → resources (CPU, memory, disk, network) → logs → the process itself.
Quick Example
A first-five-minutes triage on a server that's "slow":
Running an application as a hardened systemd service:
Core Concepts
Distributions
Prefer LTS releases for servers and use minimal or distroless base images for containers.
The Filesystem Hierarchy
Users, Groups, and Permissions
Every file has an owner, a group, and permission bits for owner, group, and others. ls -l shows them as rwxr-x---; numerically that's 750.
Special bits include setuid, setgid, and the sticky bit (/tmp). Access control lists (setfacl) and security modules (SELinux, AppArmor) add finer control.
Processes and Signals
Each process has a PID and a parent. Signals control them: SIGTERM (15) asks a process to exit gracefully, SIGKILL (9) forces it, SIGHUP often reloads configuration. ps aux, pgrep, top, and /proc/<pid>/ inspect them; strace shows system calls and lsof shows open files and sockets.
systemd and the Journal
systemd starts services in dependency order, restarts them on failure, applies resource limits and sandboxing, and schedules jobs with timers (a modern cron alternative). journalctl queries structured logs by unit, priority, and time.
Networking Tools
ip addr and ip route show interfaces and routes; ss lists sockets; dig and resolvectl debug DNS; curl -v tests HTTP; tcpdump captures packets; nft or iptables (often via ufw or firewalld) filter traffic.
Kernel Features Behind Containers
Namespaces isolate what a process can see (PIDs, network, mounts), and cgroups limit what it can use (CPU, memory). Docker, Podman, and Kubernetes are built on them. eBPF lets safe programs run in the kernel for observability, networking, and security.
Best Practices
Use Key-Based SSH and Disable Root Login
Set PasswordAuthentication no and PermitRootLogin no, use SSH keys or an SSH certificate authority, and consider SSM Session Manager or a bastion instead of exposing port 22.
Run Services as Unprivileged Users
Give each service its own user and minimal file permissions, and use systemd sandboxing options.
Patch Regularly and Automatically
Enable unattended security updates (unattended-upgrades, dnf-automatic) and schedule reboots for kernel updates.
Configure Servers With Code
Use Ansible, cloud-init, or immutable images instead of hand-editing files on each server. See Infrastructure as Code.
Centralize Logs and Metrics
Ship the journal and application logs to a central system and monitor CPU, memory, disk, and network with alerts. See Monitoring.
Watch Disk and Inodes
Rotate logs with logrotate or journald limits; a full disk or exhausted inodes breaks almost everything.
Common Mistakes
chmod 777 to "Fix" Permissions
It makes files writable by everyone. Find the right owner and minimal permissions instead.
Killing With -9 First
SIGKILL skips cleanup, leaving temp files, locks, or corrupted state. Send SIGTERM, wait, then escalate.
Misreading Memory Usage
Linux uses free memory for page cache, so "used" looks high. Check the "available" column and watch for OOM kills in dmesg.
Editing Production Servers by Hand
Manual changes drift and disappear when servers are replaced. Change configuration through code and redeploy.
Ignoring Load Average Context
A load average of 8 is alarming on 2 CPUs and fine on 16. Compare it to nproc and check whether processes wait on CPU or I/O.
FAQ
Why do servers run Linux?
It's free, open source, stable, efficient, highly configurable, and supported by every cloud provider and container platform, with decades of tooling built around it.
Which Linux distribution should I learn?
Ubuntu or Debian is the easiest starting point and the most common in the cloud. Learning RHEL-family tools (dnf, SELinux) is useful for enterprise environments.
What is systemd?
The init system and service manager on most modern distributions. It starts and supervises services, manages logging through the journal, and handles timers, mounts, and resource limits.
How do I find what's using a port?
Run sudo ss -tulpn | grep :8080 or sudo lsof -i :8080 to see the process listening on that port.
What's the difference between Linux and Unix?
Unix is the family of operating systems from Bell Labs and its descendants (BSD, macOS, Solaris). Linux is a Unix-like kernel written independently, following the same design principles and POSIX standards.
Related Topics
- Bash — Scripting and automation on Linux
- Command Line — Shell productivity and core tools
- Docker — Containers built on Linux namespaces and cgroups
- eBPF — Programmable kernel observability and networking
- Windows Server Administration — The Windows counterpart