All articles

The Linux Sysadmin Command Map: 39 Safe Starting Points

16 minutes read


Linux publication

Share this article

𝕏✉

Illustration for The Linux Sysadmin Command Map: 39 Safe Starting Points

The fastest way to make an incident harder is to start changing things before you know which system, path, process, or package you are looking at. This map puts inspection first. It then names the small set of mutations that belong in a disposable directory or an approved change window.

The lab behind this guide used the official debian:13.6 image at digest sha256:34cd9e9fd437c0a095ec39cb2e73422c9f30821b0d0848ed74fd0d43bae4d958 and alpine:3.24.1 at digest sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b. Debian used /bin/sh → Dash 0.5.12-12; Alpine used BusyBox ash 1.37.0. The GNU Coreutils manual and BusyBox applet list explain why a familiar command can have different flags or be missing in a small image.

How to read the map

GNU means the GNU or named upstream implementation normally supplied by a Debian package. BusyBox means the applet is available in a BusyBox build such as Alpine’s; a vendor can compile a smaller BusyBox. yes does not mean the command is installed in every base image. The task verification record records the exact base-image result and exit code.

Inspection — start here

These commands read state. Capture their output with the hostname, timestamp, working directory, and command line so another operator can reproduce the observation.

Command Side effect GNU / BusyBox
pwd Read-only shell builtin; prints the current directory. shell builtin / shell builtin
uname -a Read-only; prints kernel and machine fields. yes / yes
cat /etc/os-release Read-only; prints distribution identity. yes / yes
command -v ls Read-only shell lookup; does not execute the result. shell builtin / shell builtin
env Read-only; prints the process environment, which can contain secrets. yes / yes

Treat environment output as sensitive. Do not paste tokens, credentials, or full production paths into an incident channel.

Files — inspect, then change one named path

The first five file commands are read-only. find is recursive by default, so bound it to a known root and depth. GNU find and BusyBox find do not have identical predicates; check --help before copying a long expression.

Command Side effect GNU / BusyBox
ls -lah /path Read-only directory and metadata listing. yes / yes
stat /path Read-only inode, mode, size, and timestamp inspection. yes / yes
find /path -maxdepth 1 -type f Read-only bounded walk; can be expensive on a large root. yes / yes
grep -n pattern file Read-only file scan; output can expose secrets. yes / yes
sed -n 1,20p file Read-only bounded text display. yes / yes

Caution: The next three commands mutate or remove entries. Run them only in a directory you own, name every path, and preview with ls or stat first. Never turn a printed path into an unreviewed recursive rm.

Command Side effect GNU / BusyBox
mkdir -p /tmp/lab Mutates the filesystem by creating directories; -p can create parents. yes / yes
cp source destination Mutates the filesystem by copying bytes and metadata conventions. yes / yes
rm -- file Destructive; unlinks the named path and can make data unrecoverable. yes / yes

The lab created source, copied it to copy, printed its size, then removed only those two files and the printed temporary directory. It did not run a recursive removal against a host path.

Processes — observe before signalling

ps, pgrep, and top show snapshots. kill -0 asks the kernel whether a signal could be delivered; it does not deliver a signal.

Caution: top -b -n 1 samples processes and repeated polling can add load. nice changes the priority of the command it starts. Do not use a priority change or a real signal on a production process without an owner, expected effect, and rollback.

Command Side effect GNU / BusyBox
ps Read-only process snapshot; available after installing procps-ng on minimal Debian. procps-ng / yes
pgrep -a 1 Read-only process-name and PID match. procps-ng / yes
top -b -n 1 Read-only snapshot that samples process and scheduler data. procps-ng / yes
kill -0 PID Read-only permission/existence probe; signal number zero is not delivered. shell builtin / shell builtin
nice -n 5 command Changes the child command’s scheduling niceness. yes / yes

Storage — compare scope and units

All four commands below are read-only. df reports filesystem accounting; du walks a directory tree. Their scopes can disagree when mounts, deleted-open files, sparse files, or container layers are involved.

Command Side effect GNU / BusyBox
df -hT / Read-only mounted-filesystem capacity and type. yes / yes
du -sh /usr Read-only directory walk; can be expensive or incomplete with permissions. yes / yes
findmnt -T / Read-only mount lookup; common in util-linux, not base BusyBox. util-linux / no applet
lsblk Read-only block-device inventory; may need a util-linux package. util-linux / no applet

Do not “fix” a full filesystem by deleting the largest path until you have aligned the mount namespace, filesystem, units, and ownership.

Networking — identify first, generate traffic deliberately

ip, ss, and getent inspect local addresses, sockets, and name-service results. wget --help only checks the interface. ping below sends one packet to loopback in the lab; a remote target creates network traffic and may trigger alerts.

Caution: A connectivity probe is not free. Use an approved destination, a bounded count and timeout, and never use an unbounded download while diagnosing a service.

Command Side effect GNU / BusyBox
ip addr Read-only interface and address listing. iproute2 / yes
ss -lnt Read-only listening TCP socket listing; install iproute2 if absent. iproute2 / no applet
getent hosts localhost Read-only name-service lookup. libc utility / yes
ping -c 1 -W 1 127.0.0.1 Generates one loopback packet; network side effect. iputils / yes
wget --help Read-only help; an actual URL fetch has network and file side effects. GNU Wget / yes

Logs — know which store you are reading

dmesg reads the kernel ring buffer and can be denied by kernel policy. journalctl reads a systemd journal only; its absence is not a broken command if the host uses another init or logging stack. logread needs a BusyBox syslogd buffer, and tail reads a text log only when that path exists.

Command Side effect GNU / BusyBox
dmesg Read-only kernel-buffer read; access may require privileges. util-linux / yes
journalctl --no-pager -n 3 Read-only structured-journal query; systemd only. systemd / no applet
logread Read-only BusyBox syslog buffer query; fails when no buffer exists. no / yes
tail -n 5 /var/log/messages Read-only text-log read; the file is distribution and daemon dependent. yes / yes

Do not restart a service just to create a log line. Preserve the original timestamps and query filters in the evidence.

Users — identity and account data

These commands read identity state. Account databases can contain personal or operational information; restrict the output to the records needed for the question.

Command Side effect GNU / BusyBox
whoami Read-only effective-user name. yes / yes
id Read-only UID, GID, and group membership. yes / yes
getent passwd Read-only account lookup through configured NSS or BusyBox sources. libc utility / yes
last -n 3 Read-only login-history query; output depends on a wtmp database. util-linux / yes

Packages — inspect the local database, do not update it by accident

Package metadata commands below are read-only. apt-cache and apk policy can report only what their local indexes know; refreshes and installations are separate, state-changing operations.

Command Side effect GNU / BusyBox
dpkg-query -W base-files Read-only Debian package database query. dpkg / no applet
apt-cache policy base-files Read-only Debian candidate/version query; no download. apt / no applet
apk info Read-only Alpine installed-package listing; may warn when indexes are absent. no / apk utility
apk policy busybox Read-only Alpine version/source query; does not install. no / apk utility

Avoid running apt update, apk update, apt install, or apk add merely to make a diagnostic command available. Record the missing tool, then decide whether installing it in a disposable copy is worth changing the evidence.

A repeatable first pass

For an unfamiliar host, save a bounded report in an access-controlled location:

pwd
cat /etc/os-release
uname -a
id
df -hT /
du -sh /var 2>/dev/null
ps 2>/dev/null || true
ip addr 2>/dev/null || true

Then choose one narrow branch from the map. A command’s exit status is part of the result: 127 usually means the command was not found, while a permission error or an empty log store is a different operational fact.

The map is a starting point, not a promise that every flag is portable. Read the installed implementation’s manual, keep inspection ahead of mutation, and write down the exact command, shell, release, exit status, and bounded output before someone acts on it.

Sources and further reading
  1. GNU Coreutils manual
  2. BusyBox applet documentation
  3. procps-ng — ps(1)
  4. util-linux — findmnt(8)
  5. iproute2 — ip(8)
  6. systemd — journalctl(1)
  7. Alpine Linux — Alpine Package Keeper