Cheatsheets / Linux Cheatsheet
Linux Cheatsheet
Everyday commands for real Linux systems - files, permissions, processes, package managers, and diagnostics, with GNU-specific flags called out.
Commands below assume a modern systemd-based distro (Ubuntu, Debian, Fedora, Arch) with GNU coreutils. Package-manager sections are split by distro family.
Files and directories
ls -la
Lists all files, including hidden dotfiles, in long format with permissions and sizes.
cd -
Jumps back to the previous working directory.
pwd
Prints the current working directory’s full path.
mkdir -p a/b/c
Creates nested directories in one shot, without erroring if they already exist.
cp -r src/ dest/
Copies a directory recursively.
mv old.txt new.txt
Renames or moves a file (same command for both).
rm -rf build/
Deletes a directory and its contents without confirmation. Double-check the path first.
find . -name "*.log" -mtime -7
Finds files named *.log under the current directory modified in the last 7 days.
find . -type f -size +100M
Finds regular files larger than 100 MB.
locate nginx.conf
Searches a prebuilt filename index (fast, but needs sudo updatedb to stay current).
tree -L 2
Shows a directory tree two levels deep (install via apt install tree if missing).
ln -s /path/to/target linkname
Creates a symbolic link.
Viewing and editing files
cat file.txt
Prints a file’s contents to standard output.
less file.txt
Pages through a file; /pattern to search, q to quit.
head -n 20 file.txt
Prints the first 20 lines.
tail -n 20 file.txt
Prints the last 20 lines.
tail -f app.log
Follows a growing log file live; Ctrl+C to stop.
wc -l file.txt
Counts lines in a file (-w for words, -c for bytes).
diff -u old.txt new.txt
Shows a unified diff between two files.
nano file.txt
Opens a beginner-friendly terminal editor (Ctrl+O save, Ctrl+X exit).
Permissions and ownership
chmod 755 script.sh
Sets rwx for owner, rx for group and others (common for executables).
chmod +x script.sh
Adds execute permission without touching the rest of the mode bits.
chown user:group file.txt
Changes both owner and group.
chown -R user:group dir/
Applies ownership recursively to a directory tree.
umask 022
Sets the default permission mask for newly created files in this shell session.
stat file.txt
Shows detailed metadata: size, permissions, timestamps, inode.
Text processing
grep -rn "TODO" src/
Recursively searches for a pattern, printing matching line numbers.
grep -i "error" app.log
Case-insensitive search.
grep -v "DEBUG" app.log
Prints only lines that do NOT match the pattern.
sed -i 's/foo/bar/g' file.txt
In-place, global find-and-replace (GNU sed edits in place with no argument after -i; BSD/macOS needs -i '').
awk '{print $1, $3}' file.txt
Prints the 1st and 3rd whitespace-separated columns of each line.
sort file.txt | uniq -c
Sorts lines, then counts consecutive duplicates.
cut -d',' -f2 data.csv
Extracts the 2nd comma-delimited field from each line.
tr 'a-z' 'A-Z' < file.txt
Translates lowercase to uppercase, reading from a file via stdin redirection.
xargs -I{} echo "found: {}"
Runs a command once per line of input, substituting {} with each line - handy piped from find.
Processes and jobs
ps aux
Lists every running process with user, PID, CPU and memory usage.
top
Live, sortable view of process resource usage; q to quit.
htop
A friendlier, color top replacement (install via your package manager).
kill -9 1234
Force-kills the process with PID 1234. Prefer plain kill 1234 (SIGTERM) first.
killall firefox
Kills every process matching a name.
jobs
Lists jobs running in the current shell session.
command &
Runs a command in the background; combine with bg/fg to move it between foreground and background.
nohup ./long_task.sh &
Runs a command immune to hangups, so it survives you closing the terminal.
nice -n 10 ./cpu_heavy.sh
Runs a command with lower scheduling priority (higher niceness = lower priority).
Disk and filesystem
df -h
Shows disk space usage per mounted filesystem, human-readable.
du -sh dir/
Shows the total size of a directory, human-readable.
du -h --max-depth=1 . | sort -rh
Lists immediate subdirectory sizes, largest first.
lsblk
Lists block devices (disks and partitions) as a tree.
mount | grep /dev/sda1
Shows where a device is currently mounted.
tar -czvf archive.tar.gz dir/
Creates a gzip-compressed tarball.
tar -xzvf archive.tar.gz
Extracts a gzip-compressed tarball.
unzip archive.zip -d dest/
Extracts a zip archive into a target directory.
Package management
sudo apt update && sudo apt upgrade
Debian/Ubuntu: refreshes the package index, then upgrades installed packages.
sudo apt install htop
Debian/Ubuntu: installs a package.
sudo apt remove htop
Debian/Ubuntu: uninstalls a package, keeping its config files.
dpkg -l | grep nginx
Debian/Ubuntu: lists installed packages matching a name.
sudo dnf install htop
Fedora/RHEL: installs a package (older systems use yum with the same syntax).
sudo pacman -S htop
Arch: installs a package.
snap install code --classic
Installs a sandboxed Snap package (distro-agnostic where Snap is set up).
Networking
ip addr show
Lists network interfaces and their IP addresses (modern replacement for ifconfig).
ping -c 4 example.com
Sends 4 ICMP echo requests and stops.
curl -I https://example.com
Fetches only the response headers.
wget https://example.com/file.zip
Downloads a file over HTTP(S)/FTP.
ss -tulpn
Lists listening TCP/UDP sockets with the owning process (modern replacement for netstat).
See networking.md and ssh.md for a deeper cross-OS networking and remote-access reference.
System info and services
uname -a
Prints kernel name, version, and architecture.
hostnamectl
Shows hostname and OS/kernel details (systemd systems).
systemctl status nginx
Shows whether a systemd service is running, and recent log lines.
sudo systemctl restart nginx
Restarts a systemd-managed service.
sudo systemctl enable nginx
Makes a service start automatically on boot.
journalctl -u nginx -f
Follows live logs for a specific systemd unit.
uptime
Shows how long the system has been running plus load averages.
free -h
Shows RAM and swap usage, human-readable.
Users and environment
whoami
Prints the current username.
id
Prints the current user’s UID, GID, and group memberships.
sudo -i
Opens a root login shell (use sparingly; prefer sudo <command>).
export PATH="$HOME/bin:$PATH"
Prepends a directory to the current shell’s PATH.
env
Lists all environment variables in the current shell.
alias ll="ls -la"
Defines a shell shortcut for the current session (add to ~/.bashrc to persist).
history | grep docker
Searches command history for previously run commands.