Linux 服务器运维速查
面向 VPS / 云主机上的运维动作。本机桌面命令见 Linux 常用命令速查。
原则:先观察再改动——状态 → 日志 → 资源 → 配置 → 重启。
登录之后先看一眼
Section titled “登录之后先看一眼”| 想做什么 | 命令 |
|---|---|
| 谁、哪台、什么系统 | whoami / hostnamectl / cat /etc/os-release |
| 负载与运行时间 | uptime |
| CPU / 内存 / 磁盘概览 | htop 或 btop;没有就 free -h + df -h |
| 最近有没有人登过 | last -n 20 / lastb(失败登录,需 root) |
| 当前连接 | ss -tnp 或 who |
systemd 服务
Section titled “systemd 服务”| 想做什么 | 命令 |
|---|---|
| 状态 | systemctl status 服务名 |
| 启停重启 | sudo systemctl start|stop|restart 服务名 |
| 开机自启 | sudo systemctl enable --now 服务名 |
| 关掉自启 | sudo systemctl disable --now 服务名 |
| 改完 unit 重载 | sudo systemctl daemon-reload |
| 列失败的服务 | systemctl --failed |
| 看依赖 | systemctl list-dependencies 服务名 |
定时任务优先用 timer,而不是 crontab(更易观测):
systemctl list-timers --allsystemctl status 某.timer日志(journalctl)
Section titled “日志(journalctl)”| 想做什么 | 命令 |
|---|---|
| 跟某个服务 | journalctl -u 服务名 -f |
| 本次开机错误 | journalctl -b -p err |
| 最近 1 小时 | journalctl --since "1 hour ago" |
| 某个时间段 | journalctl --since "2026-10-09 10:00" --until "2026-10-09 12:00" |
| 带解释的最近错误 | journalctl -xe |
| 按优先级过滤 | -p warning / -p err / -p crit |
Nginx / 应用若写文件日志:tail -f /var/log/nginx/error.log。
磁盘与 inode
Section titled “磁盘与 inode”| 想做什么 | 命令 |
|---|---|
| 分区用量 | df -h |
| inode 是否耗尽 | df -ih(很多小文件时常见) |
| 哪个目录最大 | sudo du -xh / --max-depth=1 | sort -h |
| 找大文件 | sudo find /var -type f -size +500M -ls 2>/dev/null |
| 看挂载选项 | findmnt |
磁盘满优先查:/var/log、Docker、备份目录、journal(journalctl --disk-usage,清理:sudo journalctl --vacuum-size=200M)。
网络与防火墙
Section titled “网络与防火墙”| 想做什么 | 命令 |
|---|---|
| 本机地址 | ip -br a |
| 监听端口 | ss -tlnp |
| 路由 | ip r |
| 测出网 | curl -I https://1.1.1.1 / ping -c 3 1.1.1.1 |
| DNS | resolvectl status 或 dig @1.1.1.1 example.com |
firewalld(RHEL 系常见):
sudo firewall-cmd --statesudo firewall-cmd --list-allsudo firewall-cmd --add-service=http --permanentsudo firewall-cmd --reloadufw(Ubuntu 常见):
sudo ufw status verbosesudo ufw allow 80/tcpsudo ufw enable云厂商安全组要和本机防火墙一起看,改了一边不够。
Nginx 速查
Section titled “Nginx 速查”| 想做什么 | 命令 |
|---|---|
| 测配置 | sudo nginx -t |
| 平滑重载 | sudo systemctl reload nginx |
| 站点目录(Debian/Ubuntu) | /etc/nginx/sites-enabled/ |
| 站点目录(RHEL) | /etc/nginx/conf.d/ |
| 看 access / error | tail -f /var/log/nginx/access.log / error.log |
反代模板骨架:
server { listen 80; server_name api.example.com; location / { proxy_pass http://127.0.0.1:3000; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; }}证书常用 certbot:sudo certbot --nginx -d api.example.com。
Docker 上的服务
Section titled “Docker 上的服务”| 想做什么 | 命令 |
|---|---|
| 项目起来 | docker compose up -d |
| 看状态 | docker compose ps |
| 日志 | docker compose logs -f --tail=200 服务名 |
| 进容器 | docker compose exec 服务名 sh |
| 重建某个服务 | docker compose up -d --build 服务名 |
| 磁盘被镜像吃满 | docker system df → docker system prune -a(确认无用镜像) |
生产环境优先 具名 volume + 绑定配置,少用可写容器层。
排障顺序(可照抄)
Section titled “排障顺序(可照抄)”- 还能 SSH 吗? 不行 → 云控制台 VNC / 救援模式。
uptime/free -h/df -h— OOM、磁盘满、load 飙高。systemctl --failed+journalctl -b -p err— 谁挂了。ss -tlnp— 服务端口还在听吗?- 应用日志 / Nginx error — 4xx/5xx、上游连不上。
- 最近改过什么? 配置、发布、证书、安全组。
- 最后才
restart;重启会掩盖现场。
安全底线(简表)
Section titled “安全底线(简表)”| 项 | 建议 |
|---|---|
| SSH | 禁密码、只用密钥;改端口可选;PermitRootLogin no |
| 更新 | 定期打安全补丁 |
| 密钥 | 部署用单独 deploy key,不拿本机私人 key 铺所有机器 |
| 备份 | 数据库逻辑备份 + 恢复演练,比「只快照磁盘」更安心 |
| 密钥进库 | .env 永不进 git;用环境变量或密钥管理 |