Browse Docs

OS

In this section

  • ๐Ÿ‘ข Boot

    The Boot - starting process

    - The BIOS is started automatically and detects the peripherals.
    - Loads the boot routine from the MBR (Master Boot Record) - it is the boot disk, located on the first sector of the hard disk.
    - The MBR contains a loader that loads the "second stage loader": this is the "boot loader" specific to the system being loaded.
    	-> Linux uses LILO (Linux Loader) or GRUB (Grand Unified Bootloader).
    - LILO loads the kernel into memory, decompresses it, and passes it the parameters.
    - The kernel mounts the `/` filesystem (from there, the commands in `/sbin` and `/bin` are available).
    - The kernel runs its first process: `init`.
    

    LILO configuration

    LILO can offer several kernels as choices. The default choice: “Linux”. /etc/lilo.conf : configuration of the kernel parameters. /sbin/lilo : to write the new parameters to disk. -> creates the /boot/map file, which contains the physical blocks where the boot program is located.

  • โš™๏ธ Systemd

    systemd replaces the SysV init system: services are managed with systemctl, and runlevels map to targets.

    1systemctl status <unit>                   # status of a service.
    2systemctl start|stop|restart <unit>      # run / stop / restart.
    3systemctl enable|disable <unit>          # start at boot (or not).
    4systemctl isolate multi-user.target      # equivalent of runlevel 3.
    5systemctl set-default multi-user.target  # change the default target.
    6systemctl get-default
    

    See the Runlevels & Shutdown page for the classic runlevel table.

  • ๐Ÿ” Runlevels & Shutdown

    Shutdown / reboot

    SolarisRed HatUbuntu / DebianHP-UXAIX
    Power downshutdown -i5 -g0 -yshutdown -hshutdown -hshutdown -h nowshutdown -F
    Rebootshutdown -i6 -g0 -yshutdown -rshutdown -rshutdown -r nowshutdown -Fr
    OK promptshutdown -i0 -g0 -yโ€”โ€”โ€”โ€”
    Fastreboot -- -r (reconfigure)shutdown -f (no fsck)shutdown -P (power off)shutdown -F (force fsck)โ€”
    Force fscktouch /reconfiguretouch /forcefsckedit /etc/default/rcS โ†’ FSCKFIX=yesโ€”โ€”

    Change runlevel

    ToolSolarisRed HatUbuntu / DebianHP-UXAIX
    haltโœ…โœ…โœ…โœ…โœ…
    initโœ…โœ…โœ…โœ…โœ…
    poweroffโœ…โœ…โœ…โœ…โœ…
    rebootโœ…โœ…โœ…โœ…โœ…
    shutdownโœ…โœ…โœ…โœ…โœ…
    telinitโœ…โœ…โœ…โ€”โœ…
    uadminโœ…โ€”โ€”โ€”โ€”

    Runlevels

    LevelSolarisRed HatUbuntu / DebianHP-UXAIX
    0shutdownhalthalthaltreserved
    1single usersingle usersingle usersingle userreserved
    2n/amultiuser (no networking)multiuser (default)multiuser (networking)multiuser + NFS
    3multi-usermultiuser (networking)same as 2multiuser + NFS + CDE GUI (default)user defined
    4n/aunusedsame as 2multiuser + NFS + VUE GUIuser defined
    5power offGUIsame as 2n/auser defined
    6rebootrebootrebootn/auser defined
    7-9โ€”โ€”โ€”โ€”user defined

    Change the default runlevel

    • Solaris / Red Hat / HP-UX / AIX : edit the initdefault line in vi /etc/inittab.
    • Ubuntu / Debian : edit vi /etc/event.d/rc-default.
  • โ˜๏ธ Cloud-Init

    Troubleshooting

    • cloud-init status --wait usefull for scripting, waiting cloud-init to finish before going to next step.

    • cloud-init status --long

    1status: done
    2extended_status: done
    3boot_status_code: enabled-by-generator
    4last_update: Thu, 01 Jan 1970 00:00:55 +0000
    5detail: DataSourceNoCloud [seed=/dev/sr0]
    6errors: []
    7recoverable_errors: {}
    
    • sudo cloud-init analyze show
     1-- Boot Record 01 --
     2The total time elapsed since completing an event is printed after the "@" character.
     3The time the event takes is printed after the "+" character.
     4
     5Starting stage: init-local
     6|`->no cache found @00.00600s +00.00000s
     7|`->found local data from DataSourceNoCloud @00.01500s +00.12600s
     8Finished stage: (init-local) 00.75400 seconds
     9
    10Starting stage: init-network
    11|`->restored from cache with run check: DataSourceNoCloud [seed=/dev/sr0] @04.21100s +00.00200s
    12|`->setting up datasource @04.22800s +00.00000s
    13|`->reading and applying user-data @04.23400s +00.00500s
    14|`->reading and applying vendor-data @04.23900s +00.00000s
    15|`->reading and applying vendor-data2 @04.23900s +00.00000s
    16|`->activating datasource @04.27100s +00.00100s
    17|`->config-seed_random ran successfully and took 0.000 seconds @04.29500s +00.00100s
    18|`->config-write_files ran successfully and took 0.001 seconds @04.29600s +00.00100s
    19|`->config-growpart ran successfully and took 0.562 seconds @04.29700s +00.56200s
    20|`->config-resizefs ran successfully and took 0.193 seconds @04.86000s +00.19200s
    21|`->config-mounts ran successfully and took 0.001 seconds @05.05200s +00.00100s
    22|`->config-set_hostname ran successfully and took 0.004 seconds @05.05300s +00.00500s
    23|`->config-update_hostname ran successfully and took 0.001 seconds @05.05800s +00.00100s
    24|`->config-update_etc_hosts ran successfully and took 0.005 seconds @05.05900s +00.00500s
    25|`->config-users_groups ran successfully and took 0.216 seconds @05.06400s +00.21600s
    26|`->config-ssh ran successfully and took 0.404 seconds @05.28100s +00.40400s
    27|`->config-set_passwords ran successfully and took 0.001 seconds @05.68500s +00.00200s
    28Finished stage: (init-network) 01.50000 seconds
    29
    30Starting stage: modules-config
    31|`->config-ssh_import_id ran successfully and took 0.001 seconds @07.43300s +00.00100s
    32|`->config-locale ran successfully and took 0.003 seconds @07.43400s +00.00300s
    33|`->config-grub_dpkg ran successfully and took 0.352 seconds @07.43700s +00.35200s
    34|`->config-apt_configure ran successfully and took 0.049 seconds @07.79000s +00.04800s
    35|`->config-timezone ran successfully and took 0.007 seconds @07.83900s +00.00700s
    36|`->config-runcmd ran successfully and took 0.001 seconds @07.84600s +00.00100s
    37|`->config-byobu ran successfully and took 0.000 seconds @07.84700s +00.00100s
    38Finished stage: (modules-config) 00.45400 seconds
    39
    40Starting stage: modules-final
    41|`->config-package_update_upgrade_install ran successfully and took 26.632 seconds @20.56700s +26.63300s
    42|`->config-write_files_deferred ran successfully and took 0.001 seconds @47.20000s +00.00200s
    43|`->config-reset_rmc ran successfully and took 0.000 seconds @47.20200s +00.00100s
    44|`->config-scripts_vendor ran successfully and took 0.001 seconds @47.20300s +00.00000s
    45|`->config-scripts_per_once ran successfully and took 0.000 seconds @47.20300s +00.00100s
    46|`->config-scripts_per_boot ran successfully and took 0.000 seconds @47.20400s +00.00000s
    47|`->config-scripts_per_instance ran successfully and took 0.000 seconds @47.20400s +00.00100s
    48|`->config-scripts_user ran successfully and took 0.558 seconds @47.20500s +00.55800s
    49|`->config-ssh_authkey_fingerprints ran successfully and took 0.005 seconds @47.76400s +00.00500s
    50|`->config-keys_to_console ran successfully and took 0.054 seconds @47.76900s +00.05500s
    51|`->config-install_hotplug ran successfully and took 0.001 seconds @47.82400s +00.00100s
    52|`->config-final_message ran successfully and took 0.001 seconds @47.82500s +00.00100s
    53Finished stage: (modules-final) 27.29600 seconds
    
    • Check the logs: sudo tail -n 50 /var/log/cloud-init-output.log

  • ๐ŸŽซ Certificates Authority

    Trust a CA on Linux host

    1# [RHEL] RootCA from DC need to be installed on host: 
    2cp my-domain-issuing.crt /etc/pki/ca-trust/source/anchors/my_domain_issuing.crt
    3cp my-domain-rootca.crt /etc/pki/ca-trust/source/anchors/my_domain_rootca.crt
    4update-ca-trust extract
    5
    6# [Ubuntu] 
    7sudo apt-get install -y ca-certificates
    8sudo cp local-ca.crt /usr/local/share/ca-certificates
    9sudo update-ca-certificates
    
  • ๐Ÿ–ฅ Out-of-Band Management

    Out-of-band management refers to accessing and controlling a server (console, power on/off, BIOS, remote media) through a dedicated management channel that is separate from the normal data path. “In-band” means going through the OS and its network interface; “out-of-band” uses an independent controller (a BMC โ€” Baseboard Management Controller) with its own network port, so it still works even when the OS is down, the machine is hung, or the network stack is broken. RSA is one vendor/technology family of out-of-band access.

  • ๐Ÿ” ISO Checksum

    Verify an ISO image

    To verify that an ISO image is good: compute its checksum with a sha1 or sha256 key, then compare it with the key published on the official website.

    1sha256sum image.iso
    2sha1sum image.iso
    
  • ๐Ÿ“œ Logrotate
    1logrotate -d /etc/logrotate.d/app   # test a new configuration.
    2reading config info for /data/log/app
    3Handling 1 logs
    4rotating pattern: /data/log/app  after 1 days (10 rotations)
    5empty log files are rotated, old logs are removed
    

    Options

    Usage: logrotate [OPTION...] <configfile>
      -d, --debug               Don't do anything, just test (implies -v)
      -f, --force               Force file rotation
      -m, --mail=command        Command to send mail (instead of `/bin/mail')
      -s, --state=statefile     Path of state file
      -v, --verbose             Display messages during rotation
    
  • ๐Ÿ• NTP & Time Synchronisation

    Client verification (ntpd / chrony)

    1ntpstat    # see which NTP server we synchronise with, and whether the sync is good.
    
    1synchronised to NTP server (192.168.1.12) at stratum 4
    2   time correct to within 68 ms
    3   polling server every 1024 s
    
    1ntpq -p     # see the state of the peers.
    2ntpq -c peers
    
         remote           refid      st t when poll reach   delay   offset  jitter
    ==============================================================================
    +192.168.1.11     192.168.2.4    4 u  259 1024  373    0.731   -0.980   0.557
    *192.168.1.12     192.168.3.21   3 u  385 1024  377    0.773    0.146   0.365
     192.168.4.255    .BCST.         16 u    -   64    0    0.000    0.000   0.000
    
    • The server preceded by an asterisk (*) is the one being used.
    • Those preceded by a - are currently discarded by the server-selection algorithm.
    • Those whose name is preceded by a + are possible synchronisation candidates.
    • A server preceded by a space is either unreachable or too distant.

    Column meaning

    • remote โ€” the server name.
    • refid โ€” the parent server’s identifier.
    • st โ€” the server’s stratum.
    • t โ€” the server type.
    • when โ€” seconds elapsed since the last contact.
    • poll โ€” seconds between each contact.
    • reach โ€” bitmask of successful contacts (octal): the server considers itself synchronised when reach reaches 177; a quality, stable connection shows 377.
    • delay โ€” estimated round-trip time (ms) of the UDP packet.
    • offset โ€” estimated difference between the peer’s clock and the internal clock.
    • jitter โ€” dispersion of the reference values obtained from this peer.

    Restart the NTP daemon

    1service ntpd restart      # or: systemctl restart ntpd
    

    Configuration & logs

    1cat /etc/ntp.conf    # "server example.com" + restart ntpd + enable
    2/var/log/ntpstats
    

    ntpdate (legacy)

    Old service that synchronises NTP at boot (install the package first).

Sunday, October 4, 2026 Monday, January 1, 1