Debian – Ubuntu CLI Cheat Sheet
Categories
Distributions Linux

Debian – Ubuntu CLI Cheat Sheet

Debian and Ubuntu CLI Cheat Sheet: Essential Commands for Everyday Linux Administration

The terminal is where Debian-family systems really shine. Whether you run Debian, Ubuntu, Linux Mint, Pop!_OS, Zorin OS, or another Debian-based distribution, the commands below cover the everyday administration tasks you will reach for most: installing software, managing users and permissions, controlling services, troubleshooting the network, and keeping the system healthy.

Every command sits in its own copy-ready block, so you can copy it straight into your terminal. Replace placeholders such as package-name, username, host, and /path before running a command, and always review commands that use sudo, delete files, modify networking, or alter disks.


At a Glance

Topic What You Will Find
Compatible systems Debian, Ubuntu, Linux Mint, Pop!_OS, Zorin OS, elementary OS, MX Linux, Kali Linux, Raspberry Pi OS, and related systems
Package management APT, DPKG, installation, upgrades, package search, cleanup, repair, and local .deb files
System administration Users, permissions, processes, systemd services, logs, networking, storage, archives, and recovery
Command safety Notes for destructive commands, root privileges, firewalls, filesystem checks, and remote servers

Tip: Use man command, command --help, or apropos keyword when you need the built-in documentation for a command.


Where This Works

Debian is the upstream distribution for a large ecosystem. The package-management examples are most portable across distributions using APT and DEB packages. For broader distribution comparisons, see the Debian review, Ubuntu review, Linux Mint review, Pop!_OS review, and MX Linux review.

Family or Distribution Compatibility Notes
Debian Native target All core examples apply. Debian Stable may use older but heavily tested package versions.
Ubuntu, Kubuntu, Xubuntu, Lubuntu, Ubuntu MATE, Ubuntu Budgie, Ubuntu Studio Very close Uses APT, DPKG, and systemd. Ubuntu may add tools such as add-apt-repository and may use Snap packages.
Linux Mint, LMDE, Pop!_OS, Zorin OS, elementary OS, KDE neon Very close Most Debian and Ubuntu terminal administration commands work unchanged.
Kali Linux, Parrot OS, Tails Debian-based, specialized Core commands work, but follow each distribution’s security and privacy guidance before changing repositories or services.
MX Linux, antiX, Devuan, SparkyLinux, BunsenLabs, Peppermint OS, Q4OS, PureOS Generally close APT and DPKG commands apply. Devuan and some antiX configurations may not use systemd.
Raspberry Pi OS Very close Debian-based, though hardware utilities and package availability vary by Pi model and release.
Fedora, RHEL, Rocky, AlmaLinux, Arch, Manjaro, openSUSE, Alpine Not directly compatible Many shell, file, process, and network commands still apply, but do not use apt or dpkg.

Fast rule: If apt --version and dpkg --version work, the package commands in this guide are likely relevant. If systemctl fails, check which init system your distribution uses.


Navigation and Files

These commands cover everyday shell movement, file inspection, searching, copying, deletion, and text editing.

Move Around

Show the current directory — prints the path of the current working directory.

pwd

List files with details and hidden files — shows permissions, ownership, sizes, dates, and dotfiles.

ls -lah

Change directory — moves to the selected directory. Use .. for the parent and ~ for home.

cd /path/to/directory

Return home — changes to the current user’s home directory.

cd ~

Create, Copy, Rename, and Remove

Create directories with missing parent directories — creates a project directory and the listed subdirectories.

mkdir -p project/{src,backup,logs}

Copy recursively and preserve metadata — copies a directory tree while retaining useful attributes.

cp -a source/ destination/

Move or rename a file — renames a file or moves it to another location.

mv old-name.txt new-name.txt

Remove an empty directory — deletes a directory only if it is empty.

rmdir empty-directory

Delete a file with confirmation — prompts before deleting the file.

rm -i file.txt

Read and Search Files

Read a long text file — pages through a file; press q to exit.

less /path/to/file

Follow new log lines — shows lines as they are appended to a log.

tail -f /var/log/syslog

Search recursively with line numbers — finds matching text in files below the selected path.

grep -RIn --color=auto 'search text' /path

Find files by name — finds files case-insensitively by name pattern.

find /path -type f -iname '*pattern*'

Edit with Nano — opens a file in the Nano terminal editor.

nano /path/to/file

Safety: Avoid casually using rm -rf, especially with sudo, wildcard paths such as *, or a variable/path you have not printed and checked first.


Packages: APT and DPKG

APT manages repositories and package dependencies. DPKG manages installed .deb packages. In scripts, prefer apt-get and apt-cache; interactively, apt is usually friendlier.

Daily Package Workflow

Refresh package indexes — downloads current package metadata from configured repositories.

sudo apt update

Upgrade installed packages — upgrades packages without removing installed packages.

sudo apt upgrade

Allow dependency changes and removals — performs a more complete upgrade when dependency changes require it.

sudo apt full-upgrade

Install packages — installs one or more requested packages.

sudo apt install package-name

Remove a package but retain configuration — uninstalls the package but retains system-wide configuration files.

sudo apt remove package-name

Purge a package and configuration — removes both the package and its system-wide configuration files.

sudo apt purge package-name

Find and Inspect Packages

Search package descriptions — searches repository package names and descriptions.

apt search keyword

Inspect a package — shows version, dependencies, description, and package metadata.

apt show package-name

List installed matching packages — lists installed packages matching the supplied pattern.

apt list --installed 'package-name*'

Find which package owns a file — identifies the installed package that owns a file path.

dpkg -S /usr/bin/command

List files installed by a package — displays files belonging to an installed package.

dpkg -L package-name

Cleanup, Repair, and Local DEBs

Remove unneeded automatic dependencies — removes packages no longer needed as dependencies.

sudo apt autoremove

Clear downloaded package cache files — deletes cached package archives.

sudo apt clean

Repair broken dependencies — attempts to resolve dependency problems.

sudo apt --fix-broken install

Configure unfinished package installations — completes configuration of unpacked but unconfigured packages.

sudo dpkg --configure -a

Install a downloaded local DEB — installs a local DEB and resolves repository dependencies.

sudo apt install ./package-file.deb

Recommended update routine: Run sudo apt update, review upgrades with apt list --upgradable, then run sudo apt upgrade. Use full-upgrade only after reviewing proposed additions and removals.


Users, Groups, and Permissions

Linux permissions depend on ownership, groups, and mode bits. Check identity and access before changing them.

Identity and Accounts

Show current user and groups — displays UID, GID, and group memberships.

id

Create a normal user — creates an interactive user account.

sudo adduser username

Add a user to a supplementary group — adds the user without removing existing supplementary groups.

sudo usermod -aG groupname username

Set or change a password — sets the specified user’s password.

sudo passwd username

Switch to another user — starts a login shell as the selected user.

sudo -iu username

Ownership and Modes

View permissions and ownership — shows file mode, owner, group, size, and timestamp.

ls -l /path/to/file

Change owner and group — changes ownership of a file or directory.

Get An Easy Personal Loan At Sofi

sudo chown user:group /path/to/file

Change permissions symbolically — sets owner read/write, group read, and no permissions for others.

chmod u=rw,g=r,o= file.txt

Set executable script permissions — sets owner read/write/execute and read/execute for others.

chmod 755 script.sh

Protect a private SSH key — restricts the key to the owner.

chmod 600 ~/.ssh/id_ed25519

Permission shorthand: r means read (4), w means write (2), and x means execute or traverse (1). Therefore, 755 gives the owner rwx, and group and others r-x.


Processes, Services, Logs, and Cron

Use these tools to inspect resource use, control programs, and manage systemd services on most current Debian-family systems.

Processes and Resource Use

Open an interactive process viewer — shows running processes and resource use; press q to exit.

top

Find processes by command line — finds matching processes and displays full command lines.

pgrep -af process-name

Show processes sorted by memory use — lists memory-heavy processes first.

ps aux --sort=-%mem | head

Request graceful termination — sends the standard termination signal to a process.

kill PID

Force-kill as a last resort — sends SIGKILL, which a process cannot handle or clean up after.

kill -9 PID

Systemd Service Control

Show service status — displays service state and recent log output.

systemctl status service-name

Start a service — starts the service now.

sudo systemctl start service-name

Restart a service — restarts a service after a configuration change.

$100 Credit On Linode.com

sudo systemctl restart service-name

Enable a service at boot — enables future startup and starts the service immediately.

sudo systemctl enable --now service-name

Disable and stop a service — prevents future startup and stops the service now.

sudo systemctl disable --now service-name

Logs and Scheduled Work

Show current-boot journal errors — displays error-priority journal messages from the current boot.

journalctl -b -p err

Follow a service log — streams log output from a selected systemd service.

sudo journalctl -u service-name -f

Edit the current user’s cron jobs — opens the current user’s cron table for editing.

crontab -e

List the current user’s cron jobs — displays scheduled cron entries.

crontab -l

Networking and Remote Access

Use these commands to inspect interfaces, routes, DNS, listening ports, and remote connections. Substitute your own host names, addresses, interface names, and paths.

Inspect the Network

Show interfaces and addresses — lists network interfaces and assigned addresses.

ip addr

Show routing table — displays routes and the default gateway.

ip route

Show listening TCP and UDP sockets — lists listening ports and owning processes.

sudo ss -tulpn

Test reachability — sends four ICMP echo requests.

ping -c 4 example.com

Query DNS records — queries DNS; install dnsutils if needed.

dig example.com

SSH and Transfers

Connect over SSH — opens an encrypted remote shell session.

ssh user@host

Copy a file to a remote host — transfers a local file using SSH.

scp local-file user@host:/remote/path/

Synchronize a directory with rsync — copies changes efficiently over SSH; preview with -n first when appropriate.

rsync -avh --progress local-dir/ user@host:/remote/path/

Download a URL — downloads a URL into the current directory.

curl -fLO https://example.com/file

NetworkManager

Show device status — lists NetworkManager-controlled devices and their state.

nmcli device status

List connection profiles — displays saved NetworkManager connection profiles.

nmcli connection show

List nearby Wi-Fi networks — scans and lists available wireless networks.

nmcli device wifi list

Connect to Wi-Fi — connects using the supplied SSID and password.

nmcli device wifi connect 'SSID' password 'PASSWORD'

Storage, Hardware, and Logs

Inspect capacity, mounts, block devices, kernel details, memory, and system logs before making storage or hardware changes.

Space and Mounts

Show free space and filesystem type — displays mounted filesystem capacity in human-readable units.

df -hT

Summarize current-directory item sizes — shows disk use for each visible item.

du -sh ./*

List block devices and filesystems — displays devices, filesystem types, UUIDs, and mount points.

lsblk -f

Show mounted filesystems — displays the active mount tree.

findmnt

Mount valid fstab entries — mounts valid /etc/fstab entries not already mounted.

sudo mount -a

System and Hardware Details

Show distribution metadata — displays distribution name, version, and related identifiers.

cat /etc/os-release

Show kernel and architecture — displays kernel, host, machine architecture, and build information.

uname -a

Show memory and swap — summarizes RAM and swap in human-readable units.

free -h

Show PCI devices — lists PCI hardware such as GPUs, Ethernet adapters, and audio devices.

lspci -nn

Show USB devices — lists connected USB hardware.

lsusb

Diagnostics and Journal

Read kernel messages — shows kernel ring-buffer output with readable timestamps.

dmesg -T | less

Show warnings from the current boot — displays warning-level and more severe journal entries.

Refinance Your Student Loan At Sofi

journalctl -b -p warning

Show journal entries from the last hour — filters journal output to the previous hour.

journalctl --since '1 hour ago'

Follow all journal entries — streams new system journal messages in real time.

sudo journalctl -f

Archives, Checksums, and Text Processing

Use these commands to create and extract archives, verify downloads, and process text through standard shell pipelines.

Archives and Compression

Create a gzip-compressed tar archive — creates a compressed archive of a directory.

tar -czf archive.tar.gz directory/

Extract a gzip-compressed tar archive — extracts a .tar.gz archive into the current directory.

tar -xzf archive.tar.gz

List archive contents — lists files inside the archive without extracting them.

tar -tzf archive.tar.gz

Create a ZIP archive — creates a recursive ZIP archive.

zip -r archive.zip directory/

Extract a ZIP archive — extracts the archive to the specified destination.

unzip archive.zip -d destination/

Integrity and Pipelines

Calculate a SHA-256 checksum — creates a SHA-256 checksum for a file.

sha256sum downloaded-file.iso

Verify checksum entries — checks files against a checksum manifest.

sha256sum -c SHA256SUMS

Sort and remove duplicate lines — sorts input and removes adjacent duplicate lines.

sort input.txt | uniq

Count lines, words, and bytes — displays line, word, and byte counts.

wc -lwm file.txt

Write output to terminal and file — displays command output while also writing it to a file.

command | tee output.txt

Security, Maintenance, and Recovery

These commands are useful for administration but deserve extra care. Back up important data and confirm paths, service names, firewall rules, and device names before applying changes.

Privilege and Firewall Basics

Run one command as root — runs a single command with administrator privileges.

sudo command

Open a root login shell — starts a root shell; exit it when finished.

sudo -i

Install UFW — installs uncomplicated firewall tooling.

sudo apt install ufw

Allow SSH before enabling a remote firewall — allows incoming SSH connections using the OpenSSH application profile.

sudo ufw allow OpenSSH

Enable UFW and show rules — enables the firewall and lists numbered rules.

sudo ufw enable && sudo ufw status numbered

Boot, Shutdown, and Repair

Reboot the system — restarts the machine.

sudo systemctl reboot

Power off the system — shuts down the machine.

sudo systemctl poweroff

Check a filesystem — forces a filesystem check. Use only when the target filesystem is unmounted.

sudo fsck -f /dev/sdXN

Reload systemd units — reloads unit files after editing a service definition.

sudo systemctl daemon-reload

Show failed systemd units — lists services and units currently in a failed state.

systemctl --failed

High-Value Checks

Review available upgrades — lists updates without installing them.

apt list --upgradable

View APT history — reads recent package installation and removal activity.

less /var/log/apt/history.log

See reboot history — lists recorded system reboot times.

last reboot

Check port 80 usage — lists processes with open files or connections on TCP/UDP port 80.

sudo lsof -i :80

Final Thoughts

A cheat sheet is only useful if you trust what you paste. Replace placeholders such as package-name, username, host, and /path, then read each command carefully before pressing Enter. Start with the non-destructive inspection commands whenever possible, and make backups before changing packages, permissions, services, filesystems, or firewall rules.

Remote-server caution: Before enabling a firewall, restarting SSH, changing networking, or rebooting a remote system, keep an existing session open and confirm that you have console or out-of-band access if the change fails.

If you are still choosing a system to run these commands on, our Debian review, Ubuntu review, Linux Mint review, Pop!_OS review, Zorin OS review, and MX Linux review will help you pick the right Debian-family starting point.

Leave a Reply

Your email address will not be published. Required fields are marked *