Essential Linux & DevOps Commands Handbook
Introduction: Why We Need a Modern Command Handbook
The Linux command-line landscape is vast. Developers often resort to copying and pasting commands mechanically, only to get stuck when dealing with edge cases such as multi-host jump setups, stripped-down containers lacking debugging shells, or silent cron job failures.
This handbook is organized around real-world production scenarios, condensing essential workflows into 5 high-impact modules.
graph TD
Root["Modern DevOps Command System"]
Root --> A["1. SSH Matrix & Remote Auth"]
A --> A1["Ed25519 Modern Robust Keys"]
A --> A2["~/.ssh/config Multi-Host & Jump Hosts"]
A --> A3["Local & Dynamic Port Forwarding"]
Root --> B["2. Scheduled Jobs & Daemons"]
B --> B1["Crontab Syntax & Environment Traps"]
B --> B2["Supervisord Process Auto-Restart"]
Root --> C["3. File & Time Management"]
C --> C1["ln Symlink Practices & Safe Deletion"]
C --> C2["date Formatting & Timestamps"]
C --> C3["Disk & RAM Diagnostics (df / du / free)"]
Root --> D["4. Networking & Namespaces"]
D --> D1["lsof & ss Port Identification"]
D --> D2["nsenter Container Namespace Entry"]
Root --> E["5. Modern CLI Toolkit"]
E --> E1["ripgrep Blazing Text Search"]
E --> E2["fzf Interactive Fuzzy Filtering"]
E --> E3["jq Structured JSON Slicing"]
1. SSH Remote Connections & Key Matrices
1. Modern SSH Key Generation (Ed25519 Preferred)
Replace legacy RSA 2048/4096 keys with modern Ed25519 elliptic-curve keys:
1# Generate ed25519 key pair
2ssh-keygen -t ed25519 -C "your_email@example.com" -f ~/.ssh/id_ed25519
3
4# Distribute public key to remote host for passwordless login
5ssh-copy-id -i ~/.ssh/id_ed25519.pub user@192.168.1.100
2. Multi-Host Management with ~/.ssh/config
Configure aliases in ~/.ssh/config to avoid memorizing raw IPs, ports, and credentials:
1# Cloud Server
2Host cloud
3 HostName 1.2.3.4
4 User root
5 Port 2222
6 IdentityFile ~/.ssh/id_ed25519
7
8# Local Raspberry Pi
9Host rpi
10 HostName 192.168.1.100
11 User pi
12 IdentityFile ~/.ssh/id_ed25519
13
14# Jump Host to Internal Network
15Host internal-db
16 HostName 10.0.0.5
17 User dbadmin
18 ProxyJump cloud
Connect instantly with ssh cloud or ssh internal-db.
3. SSH Port Forwarding
1# Local Port Forwarding (-L): Map remote DB (3306) to local 13306
2ssh -N -L 13306:127.0.0.1:3306 user@remote-server
3
4# Dynamic SOCKS5 Proxy (-D): Turn remote server into a secure proxy tunnel
5ssh -N -D 10808 user@remote-server
2. Cron Jobs & Daemon Supervision
1. Crontab Syntax & Critical Pitfalls
Crontab uses 5 time fields: Minute Hour Day Month Weekday Command.
⚠️ Three Major Crontab Pitfalls:
- Missing Environment Variables: Cron runs with a minimal
PATH. Always specify absolute paths (e.g./usr/local/bin/python3) or explicitly exportPATHin your script.- Working Directory: Cron executes in the user’s home directory by default. Always
cd /path/to/workdirinside scripts.- Silent Output Loss: Always redirect stdout and stderr to a log file:
10 3 * * * /usr/bin/bash /opt/backup.sh >> /var/log/backup.log 2>&1
2. Process Supervision with Supervisord
1; /etc/supervisor/conf.d/my-app.conf
2[program:my-app]
3directory=/opt/my-app
4command=/usr/bin/python3 app.py
5autostart=true
6autorestart=true
7stderr_logfile=/var/log/my-app.err.log
8stdout_logfile=/var/log/my-app.out.log
9user=www-data
1sudo supervisorctl reread
2sudo supervisorctl update
3sudo supervisorctl status
3. Symlinks & System Timestamps
1. Symbolic Links (ln -s)
1# Create symbolic link: ln -s <target_path> <link_name>
2ln -s /mnt/data/music ~/Music
3
4# Safe deletion: Never include a trailing slash when removing a symlink!
5rm ~/Music # Correct: deletes the link
6rm -rf ~/Music/ # Dangerous: might delete real contents in the target directory!
2. date Formatting & Timestamp Conversion
1# Format current standard time
2date +"%Y-%m-%d %H:%M:%S"
3
4# Convert Unix timestamp to human-readable date
5date -d @1727258400 +"%Y-%m-%d %H:%M:%S" # (Linux)
6date -r 1727258400 +"%Y-%m-%d %H:%M:%S" # (macOS)
4. Container Namespace Penetration (nsenter)
Minimal container images (e.g., Distroless, Alpine) often lack bash, curl, or network debugging utilities. Use nsenter to enter the container’s namespaces directly from the host:
1# 1. Get container PID on the host
2PID=$(docker inspect --format '{{ .State.Pid }}' <container_name_or_id>)
3
4# 2. Enter container network namespace only
5# Use host utilities directly inside the container's network stack!
6sudo nsenter -t $PID -n ss -tulnp
7sudo nsenter -t $PID -n tcpdump -i eth0 port 80
8
9# 3. Enter all container namespaces
10sudo nsenter -t $PID -m -u -i -n -p
5. Modern CLI Toolkit
| Task | Traditional Tool | Modern Alternative | Advantage |
|---|---|---|---|
| Code / Text Search | grep -r | rg (ripgrep) | Rust-based, multithreaded, respects .gitignore |
| Fuzzy Search | Paging tools | fzf | Interactive fuzzy matching for files, history, commits |
| JSON Processing | Manual parsing | jq | Structured filtering and slice extraction |
| Disk Space Analysis | du -sh * | ncdu / dust | Interactive visual disk usage explorer |
| System Monitoring | top | btop / htop | Modern dashboard for CPU, RAM, network, and process tree |
1# Power One-Liners:
2rg "DATABASE_URL" /opt/projects/
3history | fzf
4sudo lsof -i :8080