Command Reference
Quick lookup for every command covered across all 90 levels.
Navigation
Section titled “Navigation”ls # list directoryls -l # long format (permissions, owner, size)ls -la # long format + hidden filesls -lh # long format + human-readable sizespwd # print working directorycd dir # change directorycd ~ / cd # go homecd - # go back to previous directorycd .. # go up one levelmkdir dir # make directorymkdir -p a/b/c # make nested directoriesrmdir dir # remove empty directorytree # show directory tree (if installed)cat file # print fileless file # page through file (q=quit, /=search)head -n 10 file # first 10 linestail -n 10 file # last 10 linestail -f file # follow file livetouch file # create empty file / update timestampcp src dst # copy filecp -r src/ dst/ # copy directory recursivelymv src dst # move or renamerm file # delete (permanent)rm -r dir # delete directory recursivelyrm -rf dir # delete without confirmation (dangerous)ln -s target link # create symbolic linkfile path # show file typewc -l file # count lineswc -w file # count wordswc -c file # count bytesArchives & Compression
Section titled “Archives & Compression”# tartar -czf out.tar.gz dir/ # create gzip archivetar -cjf out.tar.bz2 dir/ # create bzip2 archivetar -cJf out.tar.xz dir/ # create xz archivetar -xzf file.tar.gz # extract gziptar -xzf file.tar.gz -C /path/ # extract to directorytar -tzf file.tar.gz # list contents
# gzipgzip file # compress (replaces original)gzip -k file # compress, keep originalgunzip file.gz # decompresszcat file.gz # read without decompressingzgrep ERR file.gz # grep inside .gz file
# bzip2bzip2 file # compressbunzip2 file.bz2 # decompressbzcat file.bz2 # read
# xzxz file # compressxz -9 file # maximum compressionunxz file.xz # decompress
# zipzip -r out.zip dir/ # create zipunzip out.zip # extractunzip -l out.zip # list contentsSearch & Filter
Section titled “Search & Filter”grep pattern file # search for patterngrep -i pattern file # case-insensitivegrep -v pattern file # invert: lines NOT matchinggrep -n pattern file # show line numbersgrep -c pattern file # count matching linesgrep -l pattern dir/ # list filenames onlygrep -r pattern . # recursive searchgrep -A 3 pattern file # 3 lines after matchgrep -B 3 pattern file # 3 lines before matchgrep -C 3 pattern file # 3 lines context (both)grep -E 'pat1|pat2' file # extended regexgrep -o pattern file # print only matched partgrep -w word file # whole word match onlygrep --include='*.txt' -r pattern . # search only .txt files
find . -name '*.log' # find by namefind . -type f # files onlyfind . -type d # directories onlyfind . -size +10M # larger than 10MBfind . -mtime -1 # modified in last 1 dayfind . -mmin -60 # modified in last 60 minutesfind . -exec cat {} \; # run command on each found filefind . -exec cat {} + # run command with all files batchedfind . -name '*.tmp' -delete # delete found filesfind . -print0 | xargs -0 grep ERROR # safe with spaces in namesText Processing
Section titled “Text Processing”# cutcut -d: -f1 file # field 1, delimiter :cut -d, -f1,3 file # fields 1 and 3, delimiter ,cut -c1-5 file # characters 1–5
# sortsort file # alphabeticalsort -n file # numericsort -r file # reversesort -rn file # reverse numericsort -rh file # reverse human-readable (1G > 100M)sort -u file # sort + deduplicatesort -k2 file # sort by field 2sort -t: -k3 -n file # field 3, delimiter :, numeric
# uniquniq file # remove adjacent duplicatesuniq -c file # count duplicatesuniq -d file # show only duplicates
# sedsed 's/old/new/' file # replace first per linesed 's/old/new/g' file # replace allsed 's/old/new/2' file # replace 2nd occurrencesed '/pattern/d' file # delete matching linessed -n '5p' file # print line 5 onlysed -n '2,8p' file # print lines 2–8sed -n '/START/,/END/p' file # print between patternssed -i.bak 's/old/new/g' file # edit in-place (backup .bak)
# awkawk '{print $1}' file # print field 1awk -F: '{print $1}' file # field separator :awk '{print NR, $0}' file # line numbersawk '$2 > 50' file # filter by conditionawk '{sum += $2} END{print sum}' f # sum columnawk 'BEGIN{print "Header"} {print}' fileawk '{printf "%-10s %d\n", $1, $2}' file
# trtr 'a-z' 'A-Z' # lowercase to uppercasetr -d '\r' # delete carriage returnstr -s ' ' # squeeze multiple spaces to one
# teecmd | tee file # write to file AND pass throughcmd | tee -a file # append to file AND pass throughPipes & Redirection
Section titled “Pipes & Redirection”cmd1 | cmd2 # pipe stdout of cmd1 to stdin of cmd2cmd > file # redirect stdout (overwrite)cmd >> file # redirect stdout (append)cmd < file # use file as stdincmd 2> file # redirect stderrcmd > file 2>&1 # redirect both to filecmd &> file # same (bash shorthand)cmd > /dev/null 2>&1 # discard all output
# xargsfind . -name '*.txt' | xargs wc -lfind . -name '*.log' | xargs -I{} cp {} {}.bakfind . -print0 | xargs -0 grep ERRORecho "a b c" | xargs -n1 echo # one arg per linePermissions
Section titled “Permissions”chmod 755 file # rwxr-xr-xchmod 644 file # rw-r--r--chmod 600 file # rw------- (private key)chmod 700 dir # rwx------ (private dir)chmod +x file # add execute for allchmod -w file # remove write for allchmod u+x file # add execute for ownerchown user file # change ownerchown user:group file # change owner and groupchown -R user dir/ # recursivewhoami # print current usernameid # print UID, GID, groupsid username # print another user's IDsProcesses
Section titled “Processes”ps aux # all processes, all usersps -ef # all processes (BSD vs GNU)ps aux | grep name # find process by nametop # live process viewerhtop # better live viewer (if installed)kill PID # SIGTERM (polite stop)kill -9 PID # SIGKILL (force stop)killall name # kill all processes with namejobs # list background jobsbg # resume stopped job in backgroundfg # bring job to foregroundfg %2 # bring job 2 to foregroundcommand & # start command in backgroundnohup command & # survive terminal closeDisk & System
Section titled “Disk & System”df -h # free disk space, all filesystemsdf -h /var # free space for specific filesystemdu -sh dir/ # total directory sizedu -sh * # size of all items heredu -sh * | sort -rh # largest items firstlsblk # list block devicesfindmnt # show mount treemount # list all mountsuname -a # kernel and architectureuptime # uptime and load averagesfree -h # RAM usage (Linux)vm_stat # memory stats (macOS)lsof # list open files and socketslsof -i :80 # what's using port 80who # currently logged in usersw # users + what they're doingNetworking
Section titled “Networking”ping -c 4 host # test connectivity, 4 packetscurl url # HTTP GET, print responsecurl -o file url # download to filecurl -I url # headers onlycurl -s url # silent (no progress)curl -L url # follow redirectscurl -X POST -d 'data' urlwget url # download (saves to file)ssh user@host # connect to serverssh -i key user@host # specific keyssh -L 8080:localhost:80 user@host # port forwardscp file user@host:/path/ # copy to remotescp user@host:/path/file . # copy from remotess -tlnp # listening TCP ports + processnetstat -tlnp # same (older tool)Users & Groups
Section titled “Users & Groups”useradd -m username # create user with home dirpasswd username # set passwordusermod -aG group user # add to group (always use -a)usermod -L username # lock accountusermod -U username # unlock accountuserdel -r username # delete user + homegroups username # show group membershipsid username # show UID, GID, groupssu - username # switch user (full login shell)sudo command # run as rootvisudo # safely edit sudoersSSH Keys
Section titled “SSH Keys”ssh-keygen -t ed25519 -C 'email' # generate key pairchmod 600 ~/.ssh/id_ed25519 # fix private key permschmod 700 ~/.ssh # fix .ssh dir permsssh-copy-id user@host # copy pubkey to servercat ~/.ssh/id_ed25519.pub # view public keyssh-add ~/.ssh/id_ed25519 # add key to agentEnvironment & Shell
Section titled “Environment & Shell”echo $PATH # show PATHexport PATH=/new:$PATH # prepend to PATHexport VAR=value # set environment variablealias ll='ls -lah' # create aliasalias # list all aliasesunalias ll # remove aliassource ~/.bashrc # reload config. ~/.bashrc # sameexport PS1='\u@\h:\w\$ ' # set promptenv # show all environment variablesprintenv VAR # print one variableunset VAR # remove variablecrontab -l # list cron jobscrontab -e # edit crontabcrontab -r # remove ALL cron jobs
# Syntax: MIN HOUR DAY MON WEEKDAY command* * * * * /script.sh # every minute0 2 * * * /backup.sh # daily at 2am*/15 * * * * /sync.sh # every 15 minutes0 9 * * 1-5 /report.sh # 9am weekdays0 0 1 * * /monthly.sh # first of month at midnightLogs & Journalctl
Section titled “Logs & Journalctl”journalctl # all journal entriesjournalctl -f # follow livejournalctl -u servicename # service logsjournalctl -fu servicename # follow service livejournalctl -n 50 # last 50 linesjournalctl --since '1 hour ago' # time filterjournalctl --since '2024-01-15' # since datejournalctl -b # this bootjournalctl -b -1 # previous bootjournalctl -p err # errors and abovejournalctl --disk-usage # journal disk usagelogger 'message' # write to system loglogger -t tag 'message' # with tagSystemd
Section titled “Systemd”systemctl status service # status + recent logssudo systemctl start service # start nowsudo systemctl stop service # stop nowsudo systemctl restart service # stop + startsudo systemctl reload service # reload config (no downtime)sudo systemctl enable service # enable on bootsudo systemctl disable service # disable on bootsudo systemctl enable --now service # enable + startsudo systemctl disable --now service# disable + stopsystemctl list-units --type=service # list all servicessystemctl --state=failed # show failed unitssudo systemctl daemon-reload # reload unit filesBash Scripting
Section titled “Bash Scripting”# Safety header: use on every production script#!/bin/bashset -euo pipefail
# VariablesNAME="value"echo "$NAME"CMD=$(date) # capture output
# Conditionalsif [ -f "$FILE" ]; then echo "exists"; fiif [ "$A" -eq "$B" ]; then echo "equal"; fi[ -z "$VAR" ] && echo "empty"[ -n "$VAR" ] && echo "not empty"
# Loopsfor i in 1 2 3; do echo $i; donefor f in *.txt; do echo "$f"; donefor item in "${ARRAY[@]}"; do echo "$item"; donewhile read -r line; do echo "$line"; done < file
# Functionsmyfunc() { local arg="$1" echo "$arg" return 0}
# Error handlingtrap 'echo "Cleaning up"; rm -rf "$TMPDIR"' EXITcommand || { echo "failed" >&2; exit 1; }
# String operations${#VAR} # length${VAR:0:5} # substring${VAR%.gz} # strip .gz suffix${VAR##*/} # basename (strip up to last /)${VAR//old/new} # replace all${VAR:-default} # default if unset
# ArraysARR=(a b c)echo ${ARR[0]} # first elementecho ${ARR[@]} # all elementsecho ${#ARR[@]} # countARR+=(d) # appendfor i in "${ARR[@]}"; do echo "$i"; doneStorage & LVM
Section titled “Storage & LVM”fdisk -l /dev/sda # partition table (MBR/GPT)parted -l # partition table, GPT-nativeblkid # device, UUID, filesystem typelsblk -f # block tree with filesystem/mountmkfs.ext4 /dev/sdb1 # format ext4mkfs.xfs /dev/sdc1 # format XFSmkswap /dev/sdb2 && swapon /dev/sdb2 # create + activate swapmount /dev/sdb1 /mnt/data # mountmount -a # test /etc/fstab without rebootingpvcreate /dev/sdb1 # physical volumevgcreate data_vg /dev/sdb1 # volume grouplvcreate -L 10G -n data_lv data_vg # logical volumelvextend -L +5G /dev/data_vg/data_lv # grow itresize2fs /dev/data_vg/data_lv # grow the filesystem to matchlvcreate -L 2G -s -n snap /dev/data_vg/data_lv # snapshotFile Editing & Sharing
Section titled “File Editing & Sharing”vim file # i = insert, Esc = normal mode, :wq = save+quitdd # delete line (vim, normal mode)/pattern # search forward (vim):%s/foo/bar/g # replace every occurrence (vim)getfacl file # view ACLssetfacl -m u:alice:rw file # grant a user accesssetfacl -b file # strip all ACLsumask 027 # tighten default permissionstestparm # validate smb.confsmbpasswd -a alice # set a Samba passwordmount -t cifs //host/share /mnt/win -o username=aliceexportfs -ra # apply /etc/exports changesshowmount -e host # see what a server exportsmount -t nfs host:/data /mnt/nfsrsync -avz --delete home/ /mnt/backup/ # mirror, remove extrasrsync -avz -e ssh home/ user@host:/data/ # sync over SSHNetworking (Advanced)
Section titled “Networking (Advanced)”ip addr # every address on every interfaceip link set eth0 up # bring an interface upip route # routing tableip route add default via 192.168.1.1traceroute host # hop-by-hop pathmtr host # live combined trace + pingdig domain # DNS querydig domain MX # specific record typedig -x ip # reverse lookupiptables -L -n # list firewall rulesiptables -A INPUT -p tcp --dport 22 -j ACCEPTufw allow 22 && ufw enable # simple firewallip link add link eth0 name eth0.10 type vlan id 10 # VLAN subinterfacetcpdump -i eth0 port 443 # capture traffic on a portip -s link show eth0 # interface error/drop countersStorage Networking & SAN
Section titled “Storage Networking & SAN”iscsiadm -m discovery -t sendtargets -p host # discover iSCSI targetsiscsiadm -m node -T <iqn> -p host --login # log into a targetiscsiadm -m session # list active sessionstargetcli # configure a target (server side)systemctl status autofs # check autofsmultipath -ll # list multipath devicesls -la /dev/disk/by-id/ # devices by WWNmultipath -f mpatha # flush one device maplsscsi # list SCSI/FC devicescat /sys/class/fc_host/host0/port_state # FC HBA port statusBoot Process & Kernel
Section titled “Boot Process & Kernel”systemctl get-default # default boot targetsystemd-analyze # boot time breakdownsystemd-analyze blame # slowest units to startupdate-grub # regenerate grub.cfg (Debian)grub2-mkconfig -o /boot/grub2/grub.cfg # same, RHELgrub-install /dev/sda # reinstall GRUB to a diskbootctl status # systemd-boot statusbootctl update # update systemd-boot binariesjournalctl -b -1 # previous boot's logs (post-panic)dmesg # kernel ring bufferupdate-initramfs -u # rebuild initramfs (Debian)dracut -f # rebuild initramfs (RHEL)touch /forcefsck # force fsck on next bootmake menuconfig # configure a kernel buildmake -j$(nproc) # compile using every coremake modules_install && make install # install modules + kernelMedia Management
Section titled “Media Management”ffmpeg -i in.mp4 out.mkv # convert containerffmpeg -i in.mp4 -vn audio.mp3 # extract audioffmpeg -i in.mp4 -c:v libx264 -crf 23 out.mp4 # re-encodeffmpeg -i in.mp4 -ss 00:00:10 -vframes 1 thumb.jpg # grab a frameffprobe in.mp4 # inspect a media filefind . -iname "*.mkv" # find by patternsha256sum *.mkv > checksums.sha256 # generate checksumssha256sum -c checksums.sha256 # verify checksumsiotop # live per-process disk I/ODesktop Ricing
Section titled “Desktop Ricing”echo $XDG_SESSION_TYPE # X11 or Waylandloginctl list-sessions # active login sessionsi3-msg reload # apply i3 config livei3-msg restart # restart i3, keep the layoutbindsym $mod+Return exec alacritty # i3: bind a terminalbindsym $mod+2 workspace 2 # i3: bind a workspace switchpicom & # launch a compositorpicom --config ~/.config/picom.confgit init --bare $HOME/.dotfiles # dotfiles as a bare repoalias config='/usr/bin/git --git-dir=$HOME/.dotfiles/ --work-tree=$HOME'stow nvim # deploy a dotfiles packagegsettings set org.gnome.desktop.interface gtk-theme "Nordic"feh --bg-fill ~/Pictures/wallpaper.jpg # set wallpaperGit & Version Control
Section titled “Git & Version Control”git init # turn a directory into a repogit config --global user.name "You" # set your identitygit config --global user.email "you@example.com"git status # what's changed/staged/untrackedgit status -s # compact one-line-per-file status
git add file # stage a filegit add . # stage everythinggit commit -m "message" # commit staged changesgit commit -am "message" # stage tracked changes + commitgit diff # unstaged changesgit diff --staged # staged changes (--cached also works)
git log # full commit historygit log --oneline # compact historygit show <hash> # inspect one commitgit blame file # who last changed each line
git branch # list branchesgit branch name # create a branchgit switch name # switch branches (or: git checkout name)git switch -c name # create + switch (or: git checkout -b name)git merge name # merge a branch into the current onegit branch -d name # delete a merged branch
git clone url # copy a remote repo locallygit remote add origin url # register a remotegit remote -v # list remotesgit push -u origin main # push + track upstreamgit pull # fetch + mergegit fetch # download without merging
git restore --staged file # unstage (keep the edits)git restore file # discard uncommitted editsgit reset --soft HEAD~1 # undo last commit, keep it stagedgit revert HEAD # undo a commit with a new commit (safe for pushed history)git stash # shelve uncommitted changesgit stash pop # bring them backecho node_modules >> .gitignore # stop tracking a path foreverDocker & Containers
Section titled “Docker & Containers”docker pull nginx # download an imagedocker run -d nginx # run detacheddocker run -d -p 8080:80 nginx # run detached, publish a portdocker ps # running containersdocker ps -a # every container, running or notdocker images # local images
docker logs -f web # follow a container's logsdocker exec -it web bash # interactive shell inside a containerdocker inspect web # full container detail (JSON)docker stats # live resource usagedocker stop web # stop cleanlydocker rm web # remove a stopped containerdocker rm -f web # force-stop and remove
# Dockerfile: FROM sets the base imagedocker build -t myapp:latest . # build from the current directorydocker tag myapp:latest myapp:v2 # add a second tagdocker push myrepo/myapp:latest # push to a registry
docker volume create dbdata # named volumedocker run -d -v dbdata:/var/lib/postgresql/data postgresdocker volume ls # list volumesdocker network create appnet # custom networkdocker run -d --network appnet redis # attach a container to it
docker compose up -d # bring up the whole stack, detacheddocker compose logs -f # follow every service's logsdocker compose up -d --scale worker=3 # scale one servicedocker compose down # tear the stack down
docker container prune # remove stopped containersdocker image prune # remove dangling imagesdocker system prune # remove all of the above at oncedocker system df # see what's using disk spaceUniversal Packages (Snap & Flatpak)
Section titled “Universal Packages (Snap & Flatpak)”snap install spotify # install a snapsnap list # installed snapssnap info spotify # details before installingsnap remove spotify # uninstallsnap install code --classic # full-system-access confinement
snap refresh # update every installed snapsnap install mytool --channel=edge # track a specific release channelsnap list --all mytool # every kept revisionsnap revert mytool # roll back a bad updatesnap disable mytool # disable without uninstalling
flatpak install flathub org.gimp.GIMP # install from a remoteflatpak run org.gimp.GIMP # launch by app IDflatpak list # installed flatpaksflatpak uninstall org.gimp.GIMP # remove an appflatpak uninstall --unused # clean up orphaned runtimes
flatpak remote-add --if-not-exists flathub https://flathub.org/repo/flathub.flatpakrepoflatpak remotes # configured remotesflatpak update # update everythingflatpak search video editor # search flathubTerminal Multiplexing (tmux)
Section titled “Terminal Multiplexing (tmux)”tmux new -s deploy # start a named sessiontmux ls # list sessionstmux attach -t deploy # reattach to a sessiontmux kill-session -t deploy # end a session entirely
tmux new-window # new window in the sessiontmux new-window -n logs # create + name it in one steptmux rename-window deploy # rename the current windowtmux next-window # cycle to the next windowtmux list-windows # list windows in the session
tmux split-window -h # split side by sidetmux split-window -v # split stackedtmux select-pane -R # move focus right (-L/-U/-D too)tmux resize-pane -R 10 # resize by 10 cellstmux kill-pane # close the current pane
tmux detach # leave the session running, disconnect (Ctrl-b d)tmux attach # reattach to the most recent sessiontmux attach -d # reattach, kicking other clients offTUI Toolbelt
Section titled “TUI Toolbelt”# ranger - keyboard-driven file managerranger # launch in the current directoryranger /var/log # launch in a specific directory# hjkl = down/up/back/into (same as vim), S = drop to a shell here, / = search
# cmus - terminal music playercmus # launch:add ~/Music # command mode: add a library path# c = play/pause, b = next trackcmus-remote -n # control a detached instance from another terminal
# mpd/mpc - background music daemon + clientmpd # start the daemonmpc update # rescan the music directorympc add "Artist/Album/Track.flac"mpc play # start playbackmpc status # what's playing right nowmpc random # toggle shuffle
# btop - modern resource monitorbtop # launch# / = filter processes, k = kill selected, p = cycle presetsbtop -p 2 # launch straight into preset 2
# fzf - fuzzy findergit branch | fzf # fuzzy-pick from any piped list# Ctrl-R = fuzzy search shell history, Ctrl-T = fuzzy-insert a file pathfzf --preview 'cat {}' # preview the highlighted item liveps aux | fzf | awk '{print $2}' | xargs kill # fuzzy-pick a process to killModern TUI Tools
Section titled “Modern TUI Tools”# Yazi - the newer, Rust-built file manager (ranger's spiritual successor)yazi # launch in the current directoryyazi ~/Downloads # launch in a specific directory# hjkl navigation (same as ranger), y/p = yank/paste, t = new tab
# lazygit - a full-screen TUI for the daily git looplazygit # launch in the current repo# space = stage/unstage, c = commit, P = push, p = pull, 1-5 = jump to a panel
# lazydocker - a live dashboard for containers, images, and logslazydocker # launch# Enter = view logs, d = delete, Tab = switch panels, r = restart
# zellij - the newer, Rust-built terminal multiplexerzellij # start a new sessionzellij --session deploy # start a named session (or: zellij -s deploy)zellij list-sessions # list sessionszellij attach deploy # reattach to a named session# Ctrl-p = pane mode, Ctrl-o d = detach (a two-step chord, unlike tmux's single prefix)