srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/data/packs/sysadmin.json
blob: 15f29a555ae62a3ffe424a70a28491c86314b3cf (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
[
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "systemd",
    "explanation": "Why a unit failed, without paging through the whole journal. -u scopes to the unit, -n limits the lines, --no-pager keeps it in the pipeline.",
    "content": "journalctl -u nginx -n 50 --no-pager -p err"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "systemd",
    "explanation": "Lists units that failed at boot. The first thing to run on a machine that came up wrong.",
    "content": "systemctl --failed --no-pager"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "systemd",
    "explanation": "Shows what a unit will actually run, including drop-ins, after every override has been merged.",
    "content": "systemctl cat sshd.service && systemctl show sshd -p ExecStart"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "systemd",
    "explanation": "Ranks services by how long they delayed boot. The usual answer to a slow start is one unit near the top.",
    "content": "systemd-analyze blame | head -15"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "Disk",
    "explanation": "Largest directories at this level, human readable. -x stays on one filesystem so it does not wander into /proc or a mount.",
    "content": "du -xh --max-depth=1 / 2>/dev/null | sort -rh | head -15"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "Disk",
    "explanation": "A disk that reports free space but still refuses writes is usually out of inodes, not bytes.",
    "content": "df -i | awk '$5+0 > 80 {print}'"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "Disk",
    "explanation": "Finds space held by deleted files that a process still has open. Deleting the file does not free the space until the handle closes.",
    "content": "lsof +L1 2>/dev/null | awk '$7 > 100000000 {print $1, $7, $NF}'"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "Processes",
    "explanation": "The heaviest processes by resident memory. --sort takes a minus for descending order.",
    "content": "ps -eo pid,user,rss,pcpu,comm --sort=-rss | head -12"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "Processes",
    "explanation": "What a process is actually waiting on. Reading its file descriptors and stack says more than another look at top.",
    "content": "ls -l /proc/$PID/fd | head && cat /proc/$PID/wchan"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "Processes",
    "explanation": "Traces the system calls a command makes, with a count and timing summary rather than a wall of output.",
    "content": "strace -c -f -p $PID 2>&1 | tail -20"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "Network",
    "explanation": "Listening sockets with the process behind each one. The modern replacement for netstat -tulpn.",
    "content": "ss -ltnp | awk 'NR>1 {print $4, $6}'"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "Network",
    "explanation": "Which route the kernel will actually use for a destination, including the source address it will pick.",
    "content": "ip route get 8.8.8.8"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "Network",
    "explanation": "Captures the start of connections only. -n skips DNS lookups, which otherwise generate the traffic you are trying to read.",
    "content": "tcpdump -ni any 'tcp[tcpflags] & tcp-syn != 0' -c 20"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "Network",
    "explanation": "Resolves a name through a specific server, which is how you tell a stale local cache from a stale zone.",
    "content": "dig +short @1.1.1.1 example.com A"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "Permissions",
    "explanation": "World-writable files outside the places that are meant to be. A common way a service ends up modifiable by anyone.",
    "content": "find /etc /usr -type f -perm -o+w -ls 2>/dev/null"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "Permissions",
    "explanation": "Copies the ownership and mode of one file onto another, rather than typing the numbers and getting them wrong.",
    "content": "chmod --reference=/etc/passwd /etc/passwd.new && chown --reference=/etc/passwd /etc/passwd.new"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "Users",
    "explanation": "Accounts with a real login shell, which is the set that can actually sign in.",
    "content": "awk -F: '$7 !~ /(nologin|false)$/ {print $1, $7}' /etc/passwd"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "Users",
    "explanation": "Accounts with an empty password field. Should return nothing on any machine you care about.",
    "content": "sudo awk -F: '$2 == \"\" {print $1}' /etc/shadow"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "SSH",
    "explanation": "Reuses one connection for subsequent sessions, so every later ssh or scp to the same host skips the handshake.",
    "content": "ssh -o ControlMaster=auto -o ControlPersist=10m -o ControlPath=~/.ssh/cm-%r@%h:%p host"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "SSH",
    "explanation": "Forwards a remote port to the local machine, so a service bound to localhost on the server is reachable here.",
    "content": "ssh -N -L 5432:127.0.0.1:5432 dbhost"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "Backup",
    "explanation": "Mirrors a tree, deletes what no longer exists on the source, and shows what it would do first. Never run this without -n the first time.",
    "content": "rsync -avhn --delete /src/ /dest/"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "Backup",
    "explanation": "Streams a directory to another host without a temporary archive on either side.",
    "content": "tar czf - /var/www | ssh backup 'cat > www-$(date +%F).tar.gz'"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "Scheduling",
    "explanation": "A cron entry that logs both streams. Without the redirect, cron mails the output to a mailbox nobody reads.",
    "content": "0 3 * * * /usr/local/bin/backup.sh >> /var/log/backup.log 2>&1"
  },
  {
    "category": "sysadmin",
    "language": "shell",
    "attribution": "Containers",
    "explanation": "Removes stopped containers, unused networks and dangling images. The usual cause of a full disk on a build host.",
    "content": "docker system prune -af --volumes --filter 'until=168h'"
  },
  {
    "category": "sysadmin",
    "content": "rsync -avz --delete --exclude='.git' ./site/ deploy@host:/var/www/site/",
    "attribution": "rsync",
    "explanation": "The trailing slash on the source copies the contents rather than the directory itself. --delete removes files on the far side that no longer exist locally, which makes the copy a mirror.",
    "language": "shell"
  },
  {
    "category": "sysadmin",
    "content": "ss -tulpn | awk 'NR > 1 {print $1, $5, $7}' | sort -u",
    "attribution": "ss",
    "explanation": "ss has replaced netstat on Linux. -tulpn lists listening TCP and UDP sockets with the owning process, and the awk trims it to protocol, address and program.",
    "language": "shell"
  },
  {
    "category": "sysadmin",
    "content": "systemctl list-units --type=service --state=failed --no-legend | awk '{print $1}'",
    "attribution": "systemctl",
    "explanation": "--no-legend drops the header and footer that are meant for a human reader, which leaves output a script can consume directly.",
    "language": "shell"
  },
  {
    "category": "sysadmin",
    "content": "find /var/log -type f -size +100M -exec ls -lh {} + | awk '{print $5, $9}'",
    "attribution": "find",
    "explanation": "-exec with a trailing plus batches many paths into one command, rather than the semicolon form that starts a fresh process for every file.",
    "language": "shell"
  },
  {
    "category": "sysadmin",
    "content": "dig +short TXT _dmarc.example.com @1.1.1.1",
    "attribution": "dig",
    "explanation": "+short prints the record value alone. Naming a resolver after the at sign asks that server directly, which bypasses whatever the local system has cached.",
    "language": "shell"
  },
  {
    "category": "sysadmin",
    "content": "openssl x509 -in cert.pem -noout -subject -issuer -dates",
    "attribution": "openssl",
    "explanation": "Reads a certificate without connecting to anything. -dates prints notBefore and notAfter, which is the quickest way to answer when a certificate expires.",
    "language": "shell"
  },
  {
    "category": "sysadmin",
    "content": "df -h --output=source,pcent,target | awk 'NR > 1 && $2+0 > 80'",
    "attribution": "df",
    "explanation": "Adding zero to a field forces awk to treat it as a number, so the percent sign is discarded and the comparison works. This lists only filesystems over 80 percent full.",
    "language": "shell"
  },
  {
    "category": "sysadmin",
    "content": "ip -br -c addr show | awk '$2 == \"UP\" {print $1, $3}'",
    "attribution": "ip",
    "explanation": "-br is brief output, one line per interface, which is far easier to parse than the default. This prints the name and address of every interface currently up.",
    "language": "shell"
  },
  {
    "category": "sysadmin",
    "content": "lsof -nP -iTCP -sTCP:LISTEN | awk 'NR > 1 {print $1, $2, $9}'",
    "attribution": "lsof",
    "explanation": "-n and -P stop lsof resolving names and ports, which is much faster and gives numbers you can match against configuration.",
    "language": "shell"
  },
  {
    "category": "sysadmin",
    "content": "for u in $(cut -d: -f1 /etc/passwd); do echo \"$u $(crontab -lu \"$u\" 2>/dev/null | grep -c '^[^#]')\"; done",
    "attribution": "shell",
    "explanation": "Walks every account and counts its active cron entries. Redirecting standard error hides the complaint for users who have no crontab at all.",
    "language": "shell"
  }
]