Introduction to System Administration: Fundamentals of Unix OS System Administration

Users, groups, permissions and ACLs on a real Linux server, taught the way I teach BIT students in Kampala.

I built this course for the students I meet every semester at MUBS and Nkumba who can open a terminal but freeze the moment root access or a broken home directory shows up. It is not a slideshow about Linux history. You work a single case, Nile Creative Studio, a small Kampala design shop that needs a clean multi-user file server. By the last lesson you can create accounts, put people in the right groups, set directory permissions that survive a busy Monday, and apply ACLs when two teams must share the same folder without sharing every secret. We start with what the kernel and the shell actually do for you, then move into first commands, root versus sudo, user accounts, passwords, groups, basic permissions, sticky bits and setgid directories, and ACLs. Each lesson keeps a short story about Kirabo and Joshua at the studio, then the exact commands, then a lab you can run on any Ubuntu or Debian box you control. There is no browser terminal sandbox here. You type on your own machine or a cheap VPS the same way a junior sysadmin does on day one at a helpdesk. I wrote the wording after watching the same mistakes repeat in class: students who chmod 777 everything, who leave unused accounts unlocked, who cannot read ls -l output under pressure. If you are a helpdesk trainee, a BIT student preparing for systems labs, or someone who inherited a Linux box at a Kampala SME, this course gives you the judgement those roles need. Finish it and you will not need to call a senior every time a permission denied error appears. You will know where to look, what to change, and how to leave the system safer than you found it.

Curriculum Outline

Module 1: Fundamentals of Unix OS System Administration

  • What is Unix and Linux? (text)

    Time: 40 minutes

    What you will learn

    • Where Unix came from and how Linux is related to it
    • The four layers of a Linux system: hardware, kernel, shell, applications
    • Why servers are multi-user systems, and why that needs an administrator
    • What a distribution is, and why we use Ubuntu Server

    1.1 A short story of Unix

    In 1969, at Bell Labs in the USA, Ken Thompson and Dennis Ritchie built an operating system called Unix. It had a few ideas that were new at the time:

    1. Many people can use one computer at the same time (multi-user). 2. Many programs can run at the same time (multi-tasking). 3. Everything is a file. Documents, folders, even hardware devices are treated like files. 4. Small tools that each do one job well, which you combine to do big jobs.

    In 1991, a Finnish student called Linus Torvalds wrote a free kernel inspired by Unix. He called it Linux. Combined with free tools from the GNU project, it became a complete, free, Unix-like operating system.

    Today Linux runs most of the world's servers, all of the top 500 supercomputers, and every Android phone.

    UNIX TO LINUX EVOLUTION TIMELINE 1969 Unix Bell Labs 1983 GNU Project Free software tools 1991 Linux Kernel Linus Torvalds 2004 Ubuntu Desktop & server Linux Today Global Tech Servers, Cloud, Android

    Think of it like this

    Think of Unix as the original recipe for a famous dish. Linux is a new chef who cooked the same dish from scratch, using the same recipe ideas, and gave it away free. That is why the commands you learn on Linux also work on most Unix systems.

    1.2 The layers of a Linux system

    LayerWhat it doesExample
    HardwareThe physical machineCPU, RAM, disk, network card
    KernelThe core of the OS. Talks to hardware, manages memory, decides which program runsThe Linux kernel
    ShellThe program that reads your commands and asks the kernel to do thembash
    ApplicationsPrograms you runls, nano, a web server

    Think of it like this

    Think of a restaurant. The kitchen equipment is the hardware. The head chef is the kernel, deciding who uses which stove. The waiter is the shell, taking your order in plain words and passing it to the kitchen. You are the user giving orders.

    THE LAYERS OF A LINUX SYSTEM USER / LEARNER Types commands, runs scripts, interacts with apps APPLICATIONS Web servers (Nginx), databases (PostgreSQL), editors (vim) SHELL (bash, zsh) Command interpreter: translates human words to system calls KERNEL (Linux) Memory management, CPU scheduling, drivers, filesystems HARDWARE CPU, RAM, NVMe/SSDs, Network Cards, Motherboard

    1.3 Why servers need an administrator

    A server is shared by many people. At Nile Creative Studio, Kirabo and Joshua share design files. An auditor wants to look at them. A freelancer needs to edit some of them. Nobody should see the manager's payroll files.

    Unix solves this with three ideas you will master in this module:

    1. Users: every person gets their own account. 2. Groups: people who work together are put in the same group. 3. Permissions: every file and folder says who can read it, change it, or open it.

    The system administrator (sysadmin) is the person who sets these up and keeps them correct.

    1.4 Distributions and Ubuntu Server

    Linux comes packaged in distributions (distros). A distro is the Linux kernel plus tools, an installer, and default settings.

    DistroCommon use
    Ubuntu / Ubuntu ServerVery popular, beginner friendly, used a lot in cloud servers
    DebianStable base that Ubuntu is built on
    Red Hat Enterprise Linux, Rocky LinuxBanks and large companies
    FedoraDesktop and developers

    In this module we use Ubuntu Server. It has no graphical desktop. You control it only by typing commands. That is how real servers are run.

    Note

    Almost every command in this module also works on Debian, Red Hat and other Linux systems. A few helper commands such as adduser and deluser are Debian/Ubuntu friendly extras, and we will point those out.

    Quiz: Lesson 1

    Key takeaways

    • Linux is a free, Unix-like operating system.
    • The kernel talks to hardware; the shell talks to you.
    • Servers are shared, so we need users, groups and permissions.
    • We will use Ubuntu Server, controlled only by commands.

  • Your First Steps in the Terminal (text)

    Time: 60 minutes

    What you will learn

    • How to read the command prompt
    • The shape of every Linux command
    • How to find where you are, look around, and move between folders
    • The main folders of a Linux system
    • How to get help without Google

    2.1 Reading the prompt

    When you open the terminal you see something like this:

    ssendi@studio-server:~$
    PartMeaning
    ssendiThe user you are logged in as
    studio-serverThe name of the computer (hostname)
    ~The folder you are in. ~ is short for your home folder
    $You are a normal user. If you see #, you are root, the all-powerful administrator

    Careful

    When the prompt ends in #, every command you type has full power over the whole system. Slow down and read before pressing Enter.

    2.2 The shape of a command

    Almost every command follows this pattern:

    command  -options  arguments
    ExampleCommandOptionArgument
    ls -l /homels (list)-l (long format)/home (which folder)
    mkdir -p /srv/studiomkdir (make directory)-p (create parents too)/srv/studio

    Think of it like this

    A command is like a sentence to a helper. The command is the verb ("list"). The options are adverbs ("in detail"). The arguments are the object ("the /home folder"). "List, in detail, the /home folder" becomes ls -l /home.

    Note

    Linux is case sensitive. ls works. LS does not. A user called Kirabo is different from kirabo. We always use lowercase usernames.

    2.3 Where am I? pwd

    pwd means print working directory. It tells you the folder you are standing in.

    $ pwd
    /home/student

    2.4 What is here? ls

    ls lists the contents of a folder.

    CommandWhat it shows
    lsNames of files and folders
    ls -lLong list: permissions, owner, group, size, date
    ls -aAlso shows hidden files (names starting with .)
    ls -laBoth together
    ls -ld /homeDetails of the folder itself, not what is inside it
    ls /etcContents of another folder without going there

    Pro tip

    Remember ls -ld. You will use it a lot later to check folder permissions. Without the d, ls -l /home shows what is inside /home. With the d, it shows /home itself.

    2.5 Moving around: cd

    cd means change directory.

    CommandWhere it takes you
    cd /etcStraight to /etc (absolute path, starts with /)
    cd DocumentsInto Documents inside the current folder (relative path)
    cd ..Up one level
    cd ~ or just cdBack to your home folder
    cd -Back to the previous folder you were in

    2.6 The Linux folder map

    Linux has one big tree that starts at / (called root directory, not to be confused with the root user).

    FolderWhat lives thereWhy a sysadmin cares
    /The top of everything
    /homePersonal folders of normal users, e.g. /home/kiraboNew users get a folder here
    /rootHome folder of the root userOnly root can enter
    /etcSystem settings (configuration files)User, password and group files live here
    /srvData served by this serverWe will build the team folder here
    /varChanging data such as logs/var/log holds system logs
    /bin, /usr/binPrograms (commands)Where ls, chmod live
    /tmpTemporary files, anyone can writeCleaned on reboot
    LINUX DIRECTORY TREE (KEY BRANCHES) / /bin Commands /etc Config files /home User accounts /srv Service data /var Logs & spool /tmp Temporary

    2.7 Getting help

    You do not need to memorise every option.

    CommandWhat it does
    man lsOpens the manual page for ls. Press q to quit, /word to search
    ls --helpShort help printed on screen
    whatis chmodOne-line description
    historyShows commands you typed before
    clear or Ctrl+LClears the screen
    Tab keyCompletes a command or file name for you. Press twice to see options
    Up arrowBrings back your last command
    Ctrl+CStops a command that is running or stuck

    Lab 2: Explore the server

    1. Print your current folder. 2. List the contents of /etc in long format. 3. Show the details of the /home folder itself (not what is inside). 4. Go to /srv, then return to your home folder in one short command.

    Quiz: Lesson 2

    Key takeaways

    • pwd = where am I, ls = what is here, cd = go somewhere.
    • ls -ld folder describes the folder itself.
    • /home for users, /etc for settings, /srv for served data.
    • man and --help are your built-in teachers.

  • The Superuser: root and sudo (text)

    Time: 40 minutes

    What you will learn

    • Who root is and why it is dangerous
    • How sudo lets you borrow root's power for one command
    • How to open and leave a root shell
    • The principle of least privilege

    3.1 Meet root

    Every Linux system has one special account called root (user ID 0). Root can read any file, change any password, and delete anything, including the whole system.

    Think of it like this

    Root is the master key of a hostel. It opens every room, the store and the office. You do not carry the master key around all day. You collect it from the office when you need it, use it, and hand it back.

    3.2 sudo: borrow root's power

    On Ubuntu you do not log in as root. Instead, trusted users put sudo (superuser do) in front of a command.

    $ cat /etc/shadow
    cat: /etc/shadow: Permission denied
    
    $ sudo cat /etc/shadow
    [sudo] password for ssendi:
    root:*:19876:0:99999:7:::
    ...

    1. Linux asks for your own password, not root's. 2. It remembers for about 15 minutes, so the next sudo does not ask again. 3. Every sudo command is recorded in the system log. Admins are accountable.

    Note

    Only users in the sudo group can use sudo on Ubuntu. That is why a new user cannot suddenly run admin commands.

    3.3 A root shell: sudo -i

    When you have many admin commands to run, you can open a root shell:

    ssendi@studio-server:~$ sudo -i
    root@studio-server:~# whoami
    root
    root@studio-server:~# exit
    logout
    ssendi@studio-server:~$

    Notice the prompt changes from $ to #. Inside a root shell you do not type sudo. Type exit to go back to your normal account.

    CommandResult
    sudo commandRun one command as root
    sudo -iOpen a root shell (root's environment)
    sudo suAlso opens a root shell
    exitLeave the root shell

    Careful

    In this course, we write sudo in front of admin commands. If you are already in a root shell (# prompt), leave the sudo out. Both give the same result.

    3.4 Least privilege

    The principle of least privilege says: give every person and program only the access they need, and nothing more. Use sudo only for commands that need it. This one idea explains almost everything else in this module.

    Quiz: Lesson 3

    Key takeaways

    • root can do anything, so we avoid using it directly.
    • sudo command runs one command as root.
    • sudo -i opens a root shell, exit closes it.
    • Least privilege: only the access you need.

  • Creating User Accounts (text)

    Time: 75 minutes

    What you will learn

    • What a Linux user account is made of
    • How to read /etc/passwd
    • How to create users with useradd and adduser
    • How to check that a user was created correctly with id, getent and grep

    4.1 What is a user account?

    Ssendi Samuel's first job at Nile Creative Studio is to create accounts for the two designers, Kirabo and Joshua.

    Every account has:

    PartMeaningExample for kirabo
    UsernameLogin namekirabo
    UIDUser ID number. Linux really uses this number, not the name1001
    GIDID of the user's primary group1001
    Comment (GECOS)Full name or notesKirabo, Graphic Designer
    Home directoryPersonal folder/home/kirabo
    Login shellProgram started at login/bin/bash

    Think of it like this

    An account is like a staff ID card. The name is printed on the front, but the office system actually uses the ID number on the back (the UID). The card also says which department you belong to (primary group), which desk is yours (home directory), and which door you use to enter (shell).

    4.2 The account book: /etc/passwd

    Linux keeps every account in the text file /etc/passwd. Each line is one account, with 7 fields separated by colons :.

    kirabo:x:1001:1001:Kirabo Designer:/home/kirabo:/bin/bash
    #FieldValue
    1Usernamekirabo
    2Password placeholderx means "the real password is in /etc/shadow"
    3UID1001
    4GID (primary group)1001
    5Comment (GECOS)Kirabo Designer
    6Home directory/home/kirabo
    7Login shell/bin/bash
    ANATOMY OF AN /etc/passwd ENTRY kirabo:x:1001:1001:Kirabo Lead Designer:/home/kirabo:/bin/bash 1. Username Login ID 2. Password In /etc/shadow 3. UID User ID 4. GID Primary group 5. GECOS (Comment) Full name / title 6. Home Directory User folder 7. Shell Default binary

    Note

    UIDs below 1000 are system accounts (for services like the web server). Normal human users start at 1000 on Ubuntu.

    4.3 Creating a user with useradd

    useradd is the standard low-level tool that exists on every Linux system.

    sudo useradd -m -s /bin/bash kirabo
    PartMeaning
    sudoCreating users needs root
    useraddThe command
    -mMake the home directory /home/kirabo
    -s /bin/bashSet the shell to bash
    kiraboThe new username

    Other useful options:

    OptionMeaningExample
    -c "text"Comment / full name-c "Kirabo Designer"
    -G groupAdd to extra groups at creation-G designers
    -u 1500Choose the UID

    Careful

    Plain sudo useradd kirabo (no -m, no -s) creates a half-finished account on Ubuntu: no home folder, and the shell is /bin/sh, not bash. When Kirabo logs in she gets an error about her home directory. Always use -m -s /bin/bash.

    4.4 The friendly way: adduser

    Ubuntu and Debian also have adduser, a friendly script that asks you questions:

    $ sudo adduser joshua
    info: Adding user `joshua' ...
    info: Adding new group `joshua' (1002) ...
    info: Adding new user `joshua' (1002) with group `joshua (1002)' ...
    info: Creating home directory `/home/joshua' ...
    New password:
    Retype new password:
    passwd: password updated successfully
    Full Name []: Joshua
    ...
    Is the information correct? [Y/n] Y

    adduser creates the home folder, sets bash, and asks for a password, all in one go.

    useraddadduser
    Available onAll Linux systemsDebian and Ubuntu
    Home folderOnly with -mAutomatically
    ShellOnly with -sbash automatically
    PasswordSeparate passwd stepAsked during creation
    Best forScripts, exams on any LinuxQuick interactive work on Ubuntu

    Pro tip

    Learn useradd -m -s /bin/bash well. It works everywhere. Use adduser when you are on Ubuntu and want speed.

    4.5 Checking your work

    A professional never assumes. After creating a user, verify.

    CommandWhat it shows
    id kiraboUID, primary group, and all groups
    getent passwd kiraboThe full /etc/passwd line: UID, GID, home, shell
    grep kirabo /etc/passwdSame line, found by searching the file
    ls -ld /home/kiraboProves the home folder exists and who owns it
    $ id kirabo
    uid=1001(kirabo) gid=1001(kirabo) groups=1001(kirabo)
    
    $ getent passwd kirabo
    kirabo:x:1001:1001::/home/kirabo:/bin/bash

    Note

    id shows numbers and groups but not the home folder. Use getent passwd when you need to prove the home directory and shell.

    Think of it like this

    Ubuntu gave Kirabo a group with her own name (kirabo). This is called a user private group. Think of it as a personal locker that only she uses, before she joins any team.

    Lab 4

    Create a user called okello with a home folder, bash shell, and the comment "Okello Video Editor". Verify it with getent passwd okello and ls -ld /home/okello.

    Quiz: Lesson 4

    Key takeaways

    • /etc/passwd has 7 fields: name, x, UID, GID, comment, home, shell.
    • sudo useradd -m -s /bin/bash name creates a complete account.
    • sudo adduser name is the friendly Ubuntu way.
    • Verify with id, getent passwd, and ls -ld /home/name.

  • Passwords and the Shadow File (text)
  • Becoming Another User (text)
  • Groups: Putting People in Teams (text)
  • When Staff Leave: Remove, Lock, Record (text)
  • File and Folder Permissions (text)
  • Special Permissions: setgid and the Sticky Bit (text)
  • Access Control Lists (ACLs) (text)
  • Verify Like a Professional (text)
  • Capstone Lab: Set Up the Nile Creative Studio Photo Lab (text)
  • Final Module Quiz (quiz)