Linux is the preferred operating system for the vast majority of web servers. Its reliability, flexibility, and zero cost make it ideal for both small businesses and large organizations. In this guide, we cover the fundamentals and best practices of Linux server management.
Essential Linux Commands
Frequently used commands in server management:
File and Directory Operations
ls -la /var/www/ # Detailed file listing
cd /etc/nginx/ # Change directory
cp -r source/ target/ # Copy directory
mv file.conf file.bak # Move/rename
rm -rf /tmp/temporary/ # Delete directory (use carefully!)
find / -name "*.log" -mtime +30 # Log files older than 30 days
File Content Operations
cat /var/log/syslog # View file contents
tail -f /var/log/nginx/error.log # Live log monitoring
grep "error" /var/log/syslog # Text search
nano /etc/nginx/nginx.conf # File editing
System Information
uname -a # System information
df -h # Disk usage
free -m # Memory usage
top # Real-time system status
uptime # System uptime
User and Permission Management
User management is critical for a secure server:
User Operations
adduser newuser # Create new user
usermod -aG sudo newuser # Add to sudo group
passwd newuser # Change password
deluser olduser # Delete user
File Permissions
- chmod: Change file permissions (e.g.,
chmod 755 script.sh) - chown: Change file ownership (e.g.,
chown www-data:www-data file) - Octal notation: 4=read, 2=write, 1=execute
Avoid working directly as the root user. Always create a regular user account and use sudo for privilege escalation.
Security Settings
Cornerstones of server security:
SSH Security
- Change the default port: Use a different port instead of 22
- Disable password login: Use SSH key-based authentication
- Block root login: Set
PermitRootLogin no - Install Fail2Ban: Protection against brute-force attacks
SSH Key Generation
ssh-keygen -t ed25519 -C "email@example.com"
ssh-copy-id -i ~/.ssh/id_ed25519.pub user@server
Firewall (UFW)
ufw default deny incoming # Block incoming traffic
ufw default allow outgoing # Allow outgoing traffic
ufw allow 22/tcp # SSH port
ufw allow 80/tcp # HTTP
ufw allow 443/tcp # HTTPS
ufw enable # Enable firewall
ufw status verbose # View rules
Update Management
apt update && apt upgrade -y # Debian/Ubuntu
dnf update -y # RHEL/CentOS/Fedora
Enable automatic security updates:
apt install unattended-upgrades
dpkg-reconfigure -plow unattended-upgrades
Backup Strategies
Regular backups are essential to prevent data loss:
Backup Types
- Full backup: Copy of all data
- Incremental backup: Data changed since the last backup
- Differential backup: Data changed since the last full backup
Backup Tools
- rsync: File synchronization and incremental backup
- tar: Archive creation and compression
- cron: Automated backup scheduling
- rclone: Backup to cloud storage
Example Backup Script
#!/bin/bash
DATE=$(date +%Y%m%d)
tar -czf /backup/site-$DATE.tar.gz /var/www/html/
mysqldump -u root database > /backup/db-$DATE.sql
# Clean up backups older than 30 days
find /backup/ -mtime +30 -delete
Monitoring and Performance
For continuous server health monitoring:
System Monitoring Tools
- htop: Advanced process monitoring
- iotop: Disk I/O monitoring
- nethogs: Network traffic monitoring (per process)
- journalctl: Systemd log examination
Log Management
- /var/log/syslog: General system logs
- /var/log/auth.log: Authentication logs
- /var/log/nginx/: Web server logs
- logrotate: Automatic log rotation and compression
Disk Monitoring
df -h # Disk usage percentage
du -sh /var/log/ # Directory size
ncdu / # Interactive disk analysis
Service Management (systemd)
Service management in modern Linux distributions:
systemctl start nginx # Start service
systemctl stop nginx # Stop service
systemctl restart nginx # Restart service
systemctl status nginx # Check service status
systemctl enable nginx # Auto-start on boot
systemctl disable nginx # Disable auto-start
Best Practices
- Always back up: Take a backup before making any changes
- Document changes: Record what changed and when
- Use a test environment: Try changes in a test environment first
- Principle of least privilege: Give users only the permissions they need
- Don't neglect updates: Apply security patches in a timely manner
Conclusion
Although Linux server management may seem complex initially, you can build a powerful and reliable infrastructure once you learn the fundamental principles. At BUZ Yazilim, we offer server setup, configuration, and maintenance services to our clients. Contact us if you need support for your server infrastructure.