Debian – Ubuntu CLI Cheat Sheet
Debian and Ubuntu CLI Cheat Sheet: Essential Commands for Everyday Linux Administration
The terminal is where Debian-family systems really shine. Whether you run Debian, Ubuntu, Linux Mint, Pop!_OS, Zorin OS, or another Debian-based distribution, the commands below cover the everyday administration tasks you will reach for most: installing software, managing users and permissions, controlling services, troubleshooting the network, and keeping the system healthy.
Every command sits in its own copy-ready block, so you can copy it straight into your terminal. Replace placeholders such as package-name, username, host, and /path before running a command, and always review commands that use sudo, delete files, modify networking, or alter disks.
At a Glance
| Topic | What You Will Find |
|---|---|
| Compatible systems | Debian, Ubuntu, Linux Mint, Pop!_OS, Zorin OS, elementary OS, MX Linux, Kali Linux, Raspberry Pi OS, and related systems |
| Package management | APT, DPKG, installation, upgrades, package search, cleanup, repair, and local .deb files |
| System administration | Users, permissions, processes, systemd services, logs, networking, storage, archives, and recovery |
| Command safety | Notes for destructive commands, root privileges, firewalls, filesystem checks, and remote servers |
Tip: Use man command, command --help, or apropos keyword when you need the built-in documentation for a command.
Where This Works
Debian is the upstream distribution for a large ecosystem. The package-management examples are most portable across distributions using APT and DEB packages. For broader distribution comparisons, see the Debian review, Ubuntu review, Linux Mint review, Pop!_OS review, and MX Linux review.
| Family or Distribution | Compatibility | Notes |
|---|---|---|
| Debian | Native target | All core examples apply. Debian Stable may use older but heavily tested package versions. |
| Ubuntu, Kubuntu, Xubuntu, Lubuntu, Ubuntu MATE, Ubuntu Budgie, Ubuntu Studio | Very close | Uses APT, DPKG, and systemd. Ubuntu may add tools such as add-apt-repository and may use Snap packages. |
| Linux Mint, LMDE, Pop!_OS, Zorin OS, elementary OS, KDE neon | Very close | Most Debian and Ubuntu terminal administration commands work unchanged. |
| Kali Linux, Parrot OS, Tails | Debian-based, specialized | Core commands work, but follow each distribution’s security and privacy guidance before changing repositories or services. |
| MX Linux, antiX, Devuan, SparkyLinux, BunsenLabs, Peppermint OS, Q4OS, PureOS | Generally close | APT and DPKG commands apply. Devuan and some antiX configurations may not use systemd. |
| Raspberry Pi OS | Very close | Debian-based, though hardware utilities and package availability vary by Pi model and release. |
| Fedora, RHEL, Rocky, AlmaLinux, Arch, Manjaro, openSUSE, Alpine | Not directly compatible | Many shell, file, process, and network commands still apply, but do not use apt or dpkg. |
Fast rule: If apt --version and dpkg --version work, the package commands in this guide are likely relevant. If systemctl fails, check which init system your distribution uses.
Navigation and Files
These commands cover everyday shell movement, file inspection, searching, copying, deletion, and text editing.
Move Around
Show the current directory — prints the path of the current working directory.
pwd
List files with details and hidden files — shows permissions, ownership, sizes, dates, and dotfiles.
ls -lah
Change directory — moves to the selected directory. Use .. for the parent and ~ for home.
cd /path/to/directory
Return home — changes to the current user’s home directory.
cd ~
Create, Copy, Rename, and Remove
Create directories with missing parent directories — creates a project directory and the listed subdirectories.
mkdir -p project/{src,backup,logs}
Copy recursively and preserve metadata — copies a directory tree while retaining useful attributes.
cp -a source/ destination/
Move or rename a file — renames a file or moves it to another location.
mv old-name.txt new-name.txt
Remove an empty directory — deletes a directory only if it is empty.
rmdir empty-directory
Delete a file with confirmation — prompts before deleting the file.
rm -i file.txt
Read and Search Files
Read a long text file — pages through a file; press q to exit.
less /path/to/file
Follow new log lines — shows lines as they are appended to a log.
tail -f /var/log/syslog
Search recursively with line numbers — finds matching text in files below the selected path.
grep -RIn --color=auto 'search text' /path
Find files by name — finds files case-insensitively by name pattern.
find /path -type f -iname '*pattern*'
Edit with Nano — opens a file in the Nano terminal editor.
nano /path/to/file
Safety: Avoid casually using rm -rf, especially with sudo, wildcard paths such as *, or a variable/path you have not printed and checked first.
Packages: APT and DPKG
APT manages repositories and package dependencies. DPKG manages installed .deb packages. In scripts, prefer apt-get and apt-cache; interactively, apt is usually friendlier.
Daily Package Workflow
Refresh package indexes — downloads current package metadata from configured repositories.
sudo apt update
Upgrade installed packages — upgrades packages without removing installed packages.
sudo apt upgrade
Allow dependency changes and removals — performs a more complete upgrade when dependency changes require it.
sudo apt full-upgrade
Install packages — installs one or more requested packages.
sudo apt install package-name
Remove a package but retain configuration — uninstalls the package but retains system-wide configuration files.
sudo apt remove package-name
Purge a package and configuration — removes both the package and its system-wide configuration files.
sudo apt purge package-name
Find and Inspect Packages
Search package descriptions — searches repository package names and descriptions.
apt search keyword
Inspect a package — shows version, dependencies, description, and package metadata.
apt show package-name
List installed matching packages — lists installed packages matching the supplied pattern.
apt list --installed 'package-name*'
Find which package owns a file — identifies the installed package that owns a file path.
dpkg -S /usr/bin/command
List files installed by a package — displays files belonging to an installed package.
dpkg -L package-name
Cleanup, Repair, and Local DEBs
Remove unneeded automatic dependencies — removes packages no longer needed as dependencies.
sudo apt autoremove
Clear downloaded package cache files — deletes cached package archives.
sudo apt clean
Repair broken dependencies — attempts to resolve dependency problems.
sudo apt --fix-broken install
Configure unfinished package installations — completes configuration of unpacked but unconfigured packages.
sudo dpkg --configure -a
Install a downloaded local DEB — installs a local DEB and resolves repository dependencies.
sudo apt install ./package-file.deb
Recommended update routine: Run sudo apt update, review upgrades with apt list --upgradable, then run sudo apt upgrade. Use full-upgrade only after reviewing proposed additions and removals.
Users, Groups, and Permissions
Linux permissions depend on ownership, groups, and mode bits. Check identity and access before changing them.
Identity and Accounts
Show current user and groups — displays UID, GID, and group memberships.
id
Create a normal user — creates an interactive user account.
sudo adduser username
Add a user to a supplementary group — adds the user without removing existing supplementary groups.
sudo usermod -aG groupname username
Set or change a password — sets the specified user’s password.
sudo passwd username
Switch to another user — starts a login shell as the selected user.
sudo -iu username
Ownership and Modes
View permissions and ownership — shows file mode, owner, group, size, and timestamp.
ls -l /path/to/file
Change owner and group — changes ownership of a file or directory.
Get An Easy Personal Loan At Sofi
sudo chown user:group /path/to/file
Change permissions symbolically — sets owner read/write, group read, and no permissions for others.
chmod u=rw,g=r,o= file.txt
Set executable script permissions — sets owner read/write/execute and read/execute for others.
chmod 755 script.sh
Protect a private SSH key — restricts the key to the owner.
chmod 600 ~/.ssh/id_ed25519
Permission shorthand: r means read (4), w means write (2), and x means execute or traverse (1). Therefore, 755 gives the owner rwx, and group and others r-x.
Processes, Services, Logs, and Cron
Use these tools to inspect resource use, control programs, and manage systemd services on most current Debian-family systems.
Processes and Resource Use
Open an interactive process viewer — shows running processes and resource use; press q to exit.
top
Find processes by command line — finds matching processes and displays full command lines.
pgrep -af process-name
Show processes sorted by memory use — lists memory-heavy processes first.
ps aux --sort=-%mem | head
Request graceful termination — sends the standard termination signal to a process.
kill PID
Force-kill as a last resort — sends SIGKILL, which a process cannot handle or clean up after.
kill -9 PID
Systemd Service Control
Show service status — displays service state and recent log output.
systemctl status service-name
Start a service — starts the service now.
sudo systemctl start service-name
Restart a service — restarts a service after a configuration change.
sudo systemctl restart service-name
Enable a service at boot — enables future startup and starts the service immediately.
sudo systemctl enable --now service-name
Disable and stop a service — prevents future startup and stops the service now.
sudo systemctl disable --now service-name
Logs and Scheduled Work
Show current-boot journal errors — displays error-priority journal messages from the current boot.
journalctl -b -p err
Follow a service log — streams log output from a selected systemd service.
sudo journalctl -u service-name -f
Edit the current user’s cron jobs — opens the current user’s cron table for editing.
crontab -e
List the current user’s cron jobs — displays scheduled cron entries.
crontab -l
Networking and Remote Access
Use these commands to inspect interfaces, routes, DNS, listening ports, and remote connections. Substitute your own host names, addresses, interface names, and paths.
Inspect the Network
Show interfaces and addresses — lists network interfaces and assigned addresses.
ip addr
Show routing table — displays routes and the default gateway.
ip route
Show listening TCP and UDP sockets — lists listening ports and owning processes.
sudo ss -tulpn
Test reachability — sends four ICMP echo requests.
ping -c 4 example.com
Query DNS records — queries DNS; install dnsutils if needed.
dig example.com
SSH and Transfers
Connect over SSH — opens an encrypted remote shell session.
ssh user@host
Copy a file to a remote host — transfers a local file using SSH.
scp local-file user@host:/remote/path/
Synchronize a directory with rsync — copies changes efficiently over SSH; preview with -n first when appropriate.
rsync -avh --progress local-dir/ user@host:/remote/path/
Download a URL — downloads a URL into the current directory.
curl -fLO https://example.com/file
NetworkManager
Show device status — lists NetworkManager-controlled devices and their state.
nmcli device status
List connection profiles — displays saved NetworkManager connection profiles.
nmcli connection show
List nearby Wi-Fi networks — scans and lists available wireless networks.
nmcli device wifi list
Connect to Wi-Fi — connects using the supplied SSID and password.
nmcli device wifi connect 'SSID' password 'PASSWORD'
Storage, Hardware, and Logs
Inspect capacity, mounts, block devices, kernel details, memory, and system logs before making storage or hardware changes.
Space and Mounts
Show free space and filesystem type — displays mounted filesystem capacity in human-readable units.
df -hT
Summarize current-directory item sizes — shows disk use for each visible item.
du -sh ./*
List block devices and filesystems — displays devices, filesystem types, UUIDs, and mount points.
lsblk -f
Show mounted filesystems — displays the active mount tree.
findmnt
Mount valid fstab entries — mounts valid /etc/fstab entries not already mounted.
sudo mount -a
System and Hardware Details
Show distribution metadata — displays distribution name, version, and related identifiers.
cat /etc/os-release
Show kernel and architecture — displays kernel, host, machine architecture, and build information.
uname -a
Show memory and swap — summarizes RAM and swap in human-readable units.
free -h
Show PCI devices — lists PCI hardware such as GPUs, Ethernet adapters, and audio devices.
lspci -nn
Show USB devices — lists connected USB hardware.
lsusb
Diagnostics and Journal
Read kernel messages — shows kernel ring-buffer output with readable timestamps.
dmesg -T | less
Show warnings from the current boot — displays warning-level and more severe journal entries.
Refinance Your Student Loan At Sofi
journalctl -b -p warning
Show journal entries from the last hour — filters journal output to the previous hour.
journalctl --since '1 hour ago'
Follow all journal entries — streams new system journal messages in real time.
sudo journalctl -f
Archives, Checksums, and Text Processing
Use these commands to create and extract archives, verify downloads, and process text through standard shell pipelines.
Archives and Compression
Create a gzip-compressed tar archive — creates a compressed archive of a directory.
tar -czf archive.tar.gz directory/
Extract a gzip-compressed tar archive — extracts a .tar.gz archive into the current directory.
tar -xzf archive.tar.gz
List archive contents — lists files inside the archive without extracting them.
tar -tzf archive.tar.gz
Create a ZIP archive — creates a recursive ZIP archive.
zip -r archive.zip directory/
Extract a ZIP archive — extracts the archive to the specified destination.
unzip archive.zip -d destination/
Integrity and Pipelines
Calculate a SHA-256 checksum — creates a SHA-256 checksum for a file.
sha256sum downloaded-file.iso
Verify checksum entries — checks files against a checksum manifest.
sha256sum -c SHA256SUMS
Sort and remove duplicate lines — sorts input and removes adjacent duplicate lines.
sort input.txt | uniq
Count lines, words, and bytes — displays line, word, and byte counts.
wc -lwm file.txt
Write output to terminal and file — displays command output while also writing it to a file.
command | tee output.txt
Security, Maintenance, and Recovery
These commands are useful for administration but deserve extra care. Back up important data and confirm paths, service names, firewall rules, and device names before applying changes.
Privilege and Firewall Basics
Run one command as root — runs a single command with administrator privileges.
sudo command
Open a root login shell — starts a root shell; exit it when finished.
sudo -i
Install UFW — installs uncomplicated firewall tooling.
sudo apt install ufw
Allow SSH before enabling a remote firewall — allows incoming SSH connections using the OpenSSH application profile.
sudo ufw allow OpenSSH
Enable UFW and show rules — enables the firewall and lists numbered rules.
sudo ufw enable && sudo ufw status numbered
Boot, Shutdown, and Repair
Reboot the system — restarts the machine.
sudo systemctl reboot
Power off the system — shuts down the machine.
sudo systemctl poweroff
Check a filesystem — forces a filesystem check. Use only when the target filesystem is unmounted.
sudo fsck -f /dev/sdXN
Reload systemd units — reloads unit files after editing a service definition.
sudo systemctl daemon-reload
Show failed systemd units — lists services and units currently in a failed state.
systemctl --failed
High-Value Checks
Review available upgrades — lists updates without installing them.
apt list --upgradable
View APT history — reads recent package installation and removal activity.
less /var/log/apt/history.log
See reboot history — lists recorded system reboot times.
last reboot
Check port 80 usage — lists processes with open files or connections on TCP/UDP port 80.
sudo lsof -i :80
Final Thoughts
A cheat sheet is only useful if you trust what you paste. Replace placeholders such as package-name, username, host, and /path, then read each command carefully before pressing Enter. Start with the non-destructive inspection commands whenever possible, and make backups before changing packages, permissions, services, filesystems, or firewall rules.
Remote-server caution: Before enabling a firewall, restarting SSH, changing networking, or rebooting a remote system, keep an existing session open and confirm that you have console or out-of-band access if the change fails.
If you are still choosing a system to run these commands on, our Debian review, Ubuntu review, Linux Mint review, Pop!_OS review, Zorin OS review, and MX Linux review will help you pick the right Debian-family starting point.