The Linux filesystem: where things live and why
Once you know where configuration, data and logs live, most troubleshooting becomes a question of looking in the right directory.
The map
| Path | What lives there | Typical task |
|---|---|---|
/etc | System-wide configuration, plain text | Edit a service's config, then restart it |
/var | Variable data: logs, mail spools, databases, web roots | Check /var/log first when something fails |
/home | User home directories | Per-user settings in dotfiles like ~/.bashrc |
/usr | Installed software and libraries (read-mostly) | Rarely edit by hand; use the package manager |
/opt | Third-party software installed outside the package system | Vendor agents, self-contained apps |
/tmp | Temporary files, often cleared at boot | Scratch space; never store anything you need |
/proc, /sys | Virtual views of the kernel and hardware | cat /proc/cpuinfo, /proc/meminfo |
/dev | Device files: disks, terminals, random | lsblk to see disks before touching /dev/sdX |
/boot | Kernel and bootloader | Keep free space; old kernels pile up here |
Three rules of thumb
- Configuration is text in
/etc. Back it up before editing:cp -a file file.bak-$(date +%F). - Anything that grows lives in
/var. A full disk is almost always/var/logor a database. - Do not install software by copying files into
/usr. Use apt or dnf so updates and removals stay clean.
Everything is a file
Devices, kernel settings and even running processes are exposed as files. cat /sys/class/net/eth0/operstate tells you whether a network interface is up; ls /proc/1234/fd shows what process 1234 has open. This is why text tools like grep and less are enough for a surprising amount of administration.
Exercise: find the configuration file for the SSH server, the log it writes to, and the directory where a web server would serve files from. Verify each one exists on your system.