← LFCS: Linux administration in production
06 / 7 · 25 MIN

Commands and operational evidence

Interpret capacity, processes, certificates, and automation outcomes.

Concept and mechanism

No space left on device does not alone identify the exhausted resource. If df shows free blocks and df -i shows exhausted inodes, investigate file population and retention policy. Do not delete data without understanding purpose. A removed log may still occupy space when a process holds an open descriptor to the object whose last name was deleted. Coordinate the supported reopen mechanism or a controlled restart and validate space and service. A signal used by one application is not automatically safe for another. Load average also needs context: it includes tasks in uninterruptible wait and may rise with low CPU; it is not a percentage of core utilization.

Guided application

Evidence should match the question. A certificate within its dates does not prove hostname or trust chain; reproduce the application’s SNI and verification. A Git revert commit records an inverse change without rewriting shared history, but does not deploy itself. In Bash without pipefail, the last pipeline stage may succeed after its input producer failed. Analyze status and completeness: a valid compressed file may contain only part of an export. For incidents before reboot, select the relevant boot’s journals when retained, plus unit and time window. Preserve facts, observation commands, and limits of conclusions for the next team.

IN PRACTICE

export_data fails and gzip succeeds: the file can be readable and incomplete at the same time.

Common pitfalls

Free space as free inodes; unlink as immediate reclamation; load as CPU; presented certificate as trusted; final status as completeness.

Related topics: Identities, ACLs, and resource limits · Services, scheduling, and persistent configuration

Take this idea with you

Use commands to obtain specific evidence and validate functional outcomes they do not establish.

Create account

Reference: journalctl(1): query the journal · LFCS current five-domain outline; exact edition date unconfirmed