Introduction to System Administration: Fundamentals of Unix OS System Administration
Users, groups, permissions and ACLs on a real Linux server, taught the way I teach BIT students in Kampala.
I built this course for the students I meet every semester at MUBS and Nkumba who can open a terminal but freeze the moment root access or a broken home directory shows up. It is not a slideshow about Linux history. You work a single case, Nile Creative Studio, a small Kampala design shop that needs a clean multi-user file server. By the last lesson you can create accounts, put people in the right groups, set directory permissions that survive a busy Monday, and apply ACLs when two teams must share the same folder without sharing every secret. We start with what the kernel and the shell actually do for you, then move into first commands, root versus sudo, user accounts, passwords, groups, basic permissions, sticky bits and setgid directories, and ACLs. Each lesson keeps a short story about Kirabo and Joshua at the studio, then the exact commands, then a lab you can run on any Ubuntu or Debian box you control. There is no browser terminal sandbox here. You type on your own machine or a cheap VPS the same way a junior sysadmin does on day one at a helpdesk. I wrote the wording after watching the same mistakes repeat in class: students who chmod 777 everything, who leave unused accounts unlocked, who cannot read ls -l output under pressure. If you are a helpdesk trainee, a BIT student preparing for systems labs, or someone who inherited a Linux box at a Kampala SME, this course gives you the judgement those roles need. Finish it and you will not need to call a senior every time a permission denied error appears. You will know where to look, what to change, and how to leave the system safer than you found it.
Curriculum Outline
Module 1: Fundamentals of Unix OS System Administration
-
What is Unix and Linux? (text)
Time: 40 minutes
What you will learn
- Where Unix came from and how Linux is related to it
- The four layers of a Linux system: hardware, kernel, shell, applications
- Why servers are multi-user systems, and why that needs an administrator
- What a distribution is, and why we use Ubuntu Server
1.1 A short story of Unix
In 1969, at Bell Labs in the USA, Ken Thompson and Dennis Ritchie built an operating system called Unix. It had a few ideas that were new at the time:
1. Many people can use one computer at the same time (multi-user). 2. Many programs can run at the same time (multi-tasking). 3. Everything is a file. Documents, folders, even hardware devices are treated like files. 4. Small tools that each do one job well, which you combine to do big jobs.
In 1991, a Finnish student called Linus Torvalds wrote a free kernel inspired by Unix. He called it Linux. Combined with free tools from the GNU project, it became a complete, free, Unix-like operating system.
Today Linux runs most of the world's servers, all of the top 500 supercomputers, and every Android phone.
Think of it like this
Think of Unix as the original recipe for a famous dish. Linux is a new chef who cooked the same dish from scratch, using the same recipe ideas, and gave it away free. That is why the commands you learn on Linux also work on most Unix systems.
1.2 The layers of a Linux system
Layer What it does Example Hardware The physical machine CPU, RAM, disk, network card Kernel The core of the OS. Talks to hardware, manages memory, decides which program runs The Linux kernel Shell The program that reads your commands and asks the kernel to do them bashApplications Programs you run ls,nano, a web serverThink of it like this
Think of a restaurant. The kitchen equipment is the hardware. The head chef is the kernel, deciding who uses which stove. The waiter is the shell, taking your order in plain words and passing it to the kitchen. You are the user giving orders.
1.3 Why servers need an administrator
A server is shared by many people. At Nile Creative Studio, Kirabo and Joshua share design files. An auditor wants to look at them. A freelancer needs to edit some of them. Nobody should see the manager's payroll files.
Unix solves this with three ideas you will master in this module:
1. Users: every person gets their own account. 2. Groups: people who work together are put in the same group. 3. Permissions: every file and folder says who can read it, change it, or open it.
The system administrator (sysadmin) is the person who sets these up and keeps them correct.
1.4 Distributions and Ubuntu Server
Linux comes packaged in distributions (distros). A distro is the Linux kernel plus tools, an installer, and default settings.
Distro Common use Ubuntu / Ubuntu Server Very popular, beginner friendly, used a lot in cloud servers Debian Stable base that Ubuntu is built on Red Hat Enterprise Linux, Rocky Linux Banks and large companies Fedora Desktop and developers In this module we use Ubuntu Server. It has no graphical desktop. You control it only by typing commands. That is how real servers are run.
Note
Almost every command in this module also works on Debian, Red Hat and other Linux systems. A few helper commands such as
adduseranddeluserare Debian/Ubuntu friendly extras, and we will point those out.Quiz: Lesson 1
Key takeaways
- Linux is a free, Unix-like operating system.
- The kernel talks to hardware; the shell talks to you.
- Servers are shared, so we need users, groups and permissions.
- We will use Ubuntu Server, controlled only by commands.
-
Your First Steps in the Terminal (text)
Time: 60 minutes
What you will learn
- How to read the command prompt
- The shape of every Linux command
- How to find where you are, look around, and move between folders
- The main folders of a Linux system
- How to get help without Google
2.1 Reading the prompt
When you open the terminal you see something like this:
ssendi@studio-server:~$Part Meaning ssendiThe user you are logged in as studio-serverThe name of the computer (hostname) ~The folder you are in. ~is short for your home folder$You are a normal user. If you see #, you are root, the all-powerful administratorCareful
When the prompt ends in
#, every command you type has full power over the whole system. Slow down and read before pressing Enter.2.2 The shape of a command
Almost every command follows this pattern:
command -options argumentsExample Command Option Argument ls -l /homels(list)-l(long format)/home(which folder)mkdir -p /srv/studiomkdir(make directory)-p(create parents too)/srv/studioThink of it like this
A command is like a sentence to a helper. The command is the verb ("list"). The options are adverbs ("in detail"). The arguments are the object ("the /home folder"). "List, in detail, the /home folder" becomes
ls -l /home.Note
Linux is case sensitive.
lsworks.LSdoes not. A user calledKirabois different fromkirabo. We always use lowercase usernames.2.3 Where am I?
pwdpwdmeans print working directory. It tells you the folder you are standing in.$ pwd /home/student2.4 What is here?
lslslists the contents of a folder.Command What it shows lsNames of files and folders ls -lLong list: permissions, owner, group, size, date ls -aAlso shows hidden files (names starting with .)ls -laBoth together ls -ld /homeDetails of the folder itself, not what is inside it ls /etcContents of another folder without going there Pro tip
Remember
ls -ld. You will use it a lot later to check folder permissions. Without thed,ls -l /homeshows what is inside/home. With thed, it shows/homeitself.2.5 Moving around:
cdcdmeans change directory.Command Where it takes you cd /etcStraight to /etc(absolute path, starts with/)cd DocumentsInto Documentsinside the current folder (relative path)cd ..Up one level cd ~or justcdBack to your home folder cd -Back to the previous folder you were in 2.6 The Linux folder map
Linux has one big tree that starts at
/(called root directory, not to be confused with the root user).Folder What lives there Why a sysadmin cares /The top of everything /homePersonal folders of normal users, e.g. /home/kiraboNew users get a folder here /rootHome folder of the root user Only root can enter /etcSystem settings (configuration files) User, password and group files live here /srvData served by this server We will build the team folder here /varChanging data such as logs /var/logholds system logs/bin,/usr/binPrograms (commands) Where ls,chmodlive/tmpTemporary files, anyone can write Cleaned on reboot 2.7 Getting help
You do not need to memorise every option.
Command What it does man lsOpens the manual page for ls. Pressqto quit,/wordto searchls --helpShort help printed on screen whatis chmodOne-line description historyShows commands you typed before clearor Ctrl+LClears the screen Tab key Completes a command or file name for you. Press twice to see options Up arrow Brings back your last command Ctrl+C Stops a command that is running or stuck Lab 2: Explore the server
1. Print your current folder. 2. List the contents of
/etcin long format. 3. Show the details of the/homefolder itself (not what is inside). 4. Go to/srv, then return to your home folder in one short command.Quiz: Lesson 2
Key takeaways
pwd= where am I,ls= what is here,cd= go somewhere.ls -ld folderdescribes the folder itself./homefor users,/etcfor settings,/srvfor served data.manand--helpare your built-in teachers.
-
The Superuser: root and sudo (text)
Time: 40 minutes
What you will learn
- Who root is and why it is dangerous
- How
sudolets you borrow root's power for one command - How to open and leave a root shell
- The principle of least privilege
3.1 Meet root
Every Linux system has one special account called root (user ID 0). Root can read any file, change any password, and delete anything, including the whole system.
Think of it like this
Root is the master key of a hostel. It opens every room, the store and the office. You do not carry the master key around all day. You collect it from the office when you need it, use it, and hand it back.
3.2
sudo: borrow root's powerOn Ubuntu you do not log in as root. Instead, trusted users put
sudo(superuser do) in front of a command.$ cat /etc/shadow cat: /etc/shadow: Permission denied $ sudo cat /etc/shadow [sudo] password for ssendi: root:*:19876:0:99999:7::: ...1. Linux asks for your own password, not root's. 2. It remembers for about 15 minutes, so the next
sudodoes not ask again. 3. Everysudocommand is recorded in the system log. Admins are accountable.Note
Only users in the
sudogroup can use sudo on Ubuntu. That is why a new user cannot suddenly run admin commands.3.3 A root shell:
sudo -iWhen you have many admin commands to run, you can open a root shell:
ssendi@studio-server:~$ sudo -i root@studio-server:~# whoami root root@studio-server:~# exit logout ssendi@studio-server:~$Notice the prompt changes from
$to#. Inside a root shell you do not typesudo. Typeexitto go back to your normal account.Command Result sudo commandRun one command as root sudo -iOpen a root shell (root's environment) sudo suAlso opens a root shell exitLeave the root shell Careful
In this course, we write
sudoin front of admin commands. If you are already in a root shell (#prompt), leave thesudoout. Both give the same result.3.4 Least privilege
The principle of least privilege says: give every person and program only the access they need, and nothing more. Use
sudoonly for commands that need it. This one idea explains almost everything else in this module.Quiz: Lesson 3
Key takeaways
- root can do anything, so we avoid using it directly.
sudo commandruns one command as root.sudo -iopens a root shell,exitcloses it.- Least privilege: only the access you need.
-
Creating User Accounts (text)
Time: 75 minutes
What you will learn
- What a Linux user account is made of
- How to read
/etc/passwd - How to create users with
useraddandadduser - How to check that a user was created correctly with
id,getentandgrep
4.1 What is a user account?
Ssendi Samuel's first job at Nile Creative Studio is to create accounts for the two designers, Kirabo and Joshua.
Every account has:
Part Meaning Example for kirabo Username Login name kiraboUID User ID number. Linux really uses this number, not the name 1001GID ID of the user's primary group 1001Comment (GECOS) Full name or notes Kirabo, Graphic DesignerHome directory Personal folder /home/kiraboLogin shell Program started at login /bin/bashThink of it like this
An account is like a staff ID card. The name is printed on the front, but the office system actually uses the ID number on the back (the UID). The card also says which department you belong to (primary group), which desk is yours (home directory), and which door you use to enter (shell).
4.2 The account book:
/etc/passwdLinux keeps every account in the text file
/etc/passwd. Each line is one account, with 7 fields separated by colons:.kirabo:x:1001:1001:Kirabo Designer:/home/kirabo:/bin/bash# Field Value 1 Username kirabo2 Password placeholder xmeans "the real password is in /etc/shadow"3 UID 10014 GID (primary group) 10015 Comment (GECOS) Kirabo Designer6 Home directory /home/kirabo7 Login shell /bin/bashNote
UIDs below 1000 are system accounts (for services like the web server). Normal human users start at 1000 on Ubuntu.
4.3 Creating a user with
useradduseraddis the standard low-level tool that exists on every Linux system.sudo useradd -m -s /bin/bash kiraboPart Meaning sudoCreating users needs root useraddThe command -mMake the home directory /home/kirabo-s /bin/bashSet the shell to bash kiraboThe new username Other useful options:
Option Meaning Example -c "text"Comment / full name -c "Kirabo Designer"-G groupAdd to extra groups at creation -G designers-u 1500Choose the UID Careful
Plain
sudo useradd kirabo(no-m, no-s) creates a half-finished account on Ubuntu: no home folder, and the shell is/bin/sh, not bash. When Kirabo logs in she gets an error about her home directory. Always use-m -s /bin/bash.4.4 The friendly way:
adduserUbuntu and Debian also have
adduser, a friendly script that asks you questions:$ sudo adduser joshua info: Adding user `joshua' ... info: Adding new group `joshua' (1002) ... info: Adding new user `joshua' (1002) with group `joshua (1002)' ... info: Creating home directory `/home/joshua' ... New password: Retype new password: passwd: password updated successfully Full Name []: Joshua ... Is the information correct? [Y/n] Yaddusercreates the home folder, sets bash, and asks for a password, all in one go.useraddadduserAvailable on All Linux systems Debian and Ubuntu Home folder Only with -mAutomatically Shell Only with -sbash automatically Password Separate passwdstepAsked during creation Best for Scripts, exams on any Linux Quick interactive work on Ubuntu Pro tip
Learn
useradd -m -s /bin/bashwell. It works everywhere. Useadduserwhen you are on Ubuntu and want speed.4.5 Checking your work
A professional never assumes. After creating a user, verify.
Command What it shows id kiraboUID, primary group, and all groups getent passwd kiraboThe full /etc/passwd line: UID, GID, home, shell grep kirabo /etc/passwdSame line, found by searching the file ls -ld /home/kiraboProves the home folder exists and who owns it $ id kirabo uid=1001(kirabo) gid=1001(kirabo) groups=1001(kirabo) $ getent passwd kirabo kirabo:x:1001:1001::/home/kirabo:/bin/bashNote
idshows numbers and groups but not the home folder. Usegetent passwdwhen you need to prove the home directory and shell.Think of it like this
Ubuntu gave Kirabo a group with her own name (
kirabo). This is called a user private group. Think of it as a personal locker that only she uses, before she joins any team.Lab 4
Create a user called
okellowith a home folder, bash shell, and the comment "Okello Video Editor". Verify it withgetent passwd okelloandls -ld /home/okello.Quiz: Lesson 4
Key takeaways
/etc/passwdhas 7 fields: name, x, UID, GID, comment, home, shell.sudo useradd -m -s /bin/bash namecreates a complete account.sudo adduser nameis the friendly Ubuntu way.- Verify with
id,getent passwd, andls -ld /home/name.
- Passwords and the Shadow File (text)
- Becoming Another User (text)
- Groups: Putting People in Teams (text)
- When Staff Leave: Remove, Lock, Record (text)
- File and Folder Permissions (text)
- Special Permissions: setgid and the Sticky Bit (text)
- Access Control Lists (ACLs) (text)
- Verify Like a Professional (text)
- Capstone Lab: Set Up the Nile Creative Studio Photo Lab (text)
- Final Module Quiz (quiz)