空垠尘

Essential Linux & DevOps Commands Handbook

Introduction: Why We Need a Modern Command Handbook

The Linux command-line landscape is vast. Developers often resort to copying and pasting commands mechanically, only to get stuck when dealing with edge cases such as multi-host jump setups, stripped-down containers lacking debugging shells, or silent cron job failures.

This handbook is organized around real-world production scenarios, condensing essential workflows into 5 high-impact modules.

graph TD
    Root["Modern DevOps Command System"]
    
    Root --> A["1. SSH Matrix & Remote Auth"]
    A --> A1["Ed25519 Modern Robust Keys"]
    A --> A2["~/.ssh/config Multi-Host & Jump Hosts"]
    A --> A3["Local & Dynamic Port Forwarding"]
    
    Root --> B["2. Scheduled Jobs & Daemons"]
    B --> B1["Crontab Syntax & Environment Traps"]
    B --> B2["Supervisord Process Auto-Restart"]
    
    Root --> C["3. File & Time Management"]
    C --> C1["ln Symlink Practices & Safe Deletion"]
    C --> C2["date Formatting & Timestamps"]
    C --> C3["Disk & RAM Diagnostics (df / du / free)"]
    
    Root --> D["4. Networking & Namespaces"]
    D --> D1["lsof & ss Port Identification"]
    D --> D2["nsenter Container Namespace Entry"]
    
    Root --> E["5. Modern CLI Toolkit"]
    E --> E1["ripgrep Blazing Text Search"]
    E --> E2["fzf Interactive Fuzzy Filtering"]
    E --> E3["jq Structured JSON Slicing"]

1. SSH Remote Connections & Key Matrices

1. Modern SSH Key Generation (Ed25519 Preferred)

Replace legacy RSA 2048/4096 keys with modern Ed25519 elliptic-curve keys:

1# Generate ed25519 key pair
2ssh-keygen -t ed25519 -C "your_email@example.com" -f ~/.ssh/id_ed25519
3
4# Distribute public key to remote host for passwordless login
5ssh-copy-id -i ~/.ssh/id_ed25519.pub user@192.168.1.100

2. Multi-Host Management with ~/.ssh/config

Configure aliases in ~/.ssh/config to avoid memorizing raw IPs, ports, and credentials:

 1# Cloud Server
 2Host cloud
 3    HostName 1.2.3.4
 4    User root
 5    Port 2222
 6    IdentityFile ~/.ssh/id_ed25519
 7
 8# Local Raspberry Pi
 9Host rpi
10    HostName 192.168.1.100
11    User pi
12    IdentityFile ~/.ssh/id_ed25519
13
14# Jump Host to Internal Network
15Host internal-db
16    HostName 10.0.0.5
17    User dbadmin
18    ProxyJump cloud

Connect instantly with ssh cloud or ssh internal-db.

3. SSH Port Forwarding

1# Local Port Forwarding (-L): Map remote DB (3306) to local 13306
2ssh -N -L 13306:127.0.0.1:3306 user@remote-server
3
4# Dynamic SOCKS5 Proxy (-D): Turn remote server into a secure proxy tunnel
5ssh -N -D 10808 user@remote-server

2. Cron Jobs & Daemon Supervision

1. Crontab Syntax & Critical Pitfalls

Crontab uses 5 time fields: Minute Hour Day Month Weekday Command.

⚠️ Three Major Crontab Pitfalls:

  1. Missing Environment Variables: Cron runs with a minimal PATH. Always specify absolute paths (e.g. /usr/local/bin/python3) or explicitly export PATH in your script.
  2. Working Directory: Cron executes in the user’s home directory by default. Always cd /path/to/workdir inside scripts.
  3. Silent Output Loss: Always redirect stdout and stderr to a log file:
    10 3 * * * /usr/bin/bash /opt/backup.sh >> /var/log/backup.log 2>&1
    

2. Process Supervision with Supervisord

1; /etc/supervisor/conf.d/my-app.conf
2[program:my-app]
3directory=/opt/my-app
4command=/usr/bin/python3 app.py
5autostart=true
6autorestart=true
7stderr_logfile=/var/log/my-app.err.log
8stdout_logfile=/var/log/my-app.out.log
9user=www-data
1sudo supervisorctl reread
2sudo supervisorctl update
3sudo supervisorctl status

1# Create symbolic link: ln -s <target_path> <link_name>
2ln -s /mnt/data/music ~/Music
3
4# Safe deletion: Never include a trailing slash when removing a symlink!
5rm ~/Music      # Correct: deletes the link
6rm -rf ~/Music/ # Dangerous: might delete real contents in the target directory!

2. date Formatting & Timestamp Conversion

1# Format current standard time
2date +"%Y-%m-%d %H:%M:%S"
3
4# Convert Unix timestamp to human-readable date
5date -d @1727258400 +"%Y-%m-%d %H:%M:%S"  # (Linux)
6date -r 1727258400 +"%Y-%m-%d %H:%M:%S"  # (macOS)

4. Container Namespace Penetration (nsenter)

Minimal container images (e.g., Distroless, Alpine) often lack bash, curl, or network debugging utilities. Use nsenter to enter the container’s namespaces directly from the host:

 1# 1. Get container PID on the host
 2PID=$(docker inspect --format '{{ .State.Pid }}' <container_name_or_id>)
 3
 4# 2. Enter container network namespace only
 5# Use host utilities directly inside the container's network stack!
 6sudo nsenter -t $PID -n ss -tulnp
 7sudo nsenter -t $PID -n tcpdump -i eth0 port 80
 8
 9# 3. Enter all container namespaces
10sudo nsenter -t $PID -m -u -i -n -p

5. Modern CLI Toolkit

TaskTraditional ToolModern AlternativeAdvantage
Code / Text Searchgrep -rrg (ripgrep)Rust-based, multithreaded, respects .gitignore
Fuzzy SearchPaging toolsfzfInteractive fuzzy matching for files, history, commits
JSON ProcessingManual parsingjqStructured filtering and slice extraction
Disk Space Analysisdu -sh *ncdu / dustInteractive visual disk usage explorer
System Monitoringtopbtop / htopModern dashboard for CPU, RAM, network, and process tree
1# Power One-Liners:
2rg "DATABASE_URL" /opt/projects/
3history | fzf
4sudo lsof -i :8080
Table of Contents