The filesystem tour
You can walk around with cd. Now let's find out what all those folders under / are actually for. Once you know the map, you can guess where anything lives on any Linux machine, from a Raspberry Pi to a bank's servers.
You will learn
- What every top-level folder is for, and the standard that keeps them the same everywhere
- The folders where Rocky and Ubuntu do things differently
- “Everything is a file”: devices in
/dev, and the live kernel info in/procand/sys - The file types you'll see in
ls -l, and where your own files and scripts should go
One map for every Linux
The folder layout follows a standard called the FHS (Filesystem Hierarchy Standard), so Rocky and Ubuntu look almost the same at the top. Run ls -l / on either one:
lrwxrwxrwx 1 root root 7 Apr 22 bin -> usr/bin
drwxr-xr-x 4 root root 4096 Sep 27 boot
drwxr-xr-x 19 root root 4000 Sep 27 dev
drwxr-xr-x 107 root root 4096 Sep 27 etc
drwxr-xr-x 3 root root 4096 Sep 27 home
lrwxrwxrwx 1 root root 7 Apr 22 lib -> usr/lib
…
Notice the arrows. /bin, /sbin and /lib are just links into /usr (lesson 9 covers links). Long ago they were separate, and old tutorials still talk about them that way. Both Rocky and Ubuntu have now merged them, so /bin/ls and /usr/bin/ls are the same file.
| Folder | What lives there | Think of it as… |
|---|---|---|
/ | The root: the top of the whole tree | The front door |
/etc | Settings files for the whole system: users, network, services | The control room |
/home | One folder per user: /home/student is ~ | Everyone's bedroom |
/root | The root user's home folder (not the same as /!) | The principal's office |
/usr | Installed programs (bin, sbin), libraries (lib), docs and icons (share) | The library |
/usr/local | Software and scripts you add by hand, not the package manager | Your shelf in the library |
/var | Things that change: logs, caches, databases, mail, websites (/var/www) | The filing cabinets |
/tmp | Scratch space anyone can use. Old files get cleaned out automatically | The whiteboard |
/boot | The kernel and the bootloader: what starts the computer | The ignition key |
/dev | Hardware, shown as files: disks, terminals, even “nothing” (/dev/null) | The plugs and sockets |
/proc, /sys | Live information from the kernel. Not stored on disk at all | The dashboard gauges |
/run | Info about what's running right now. Wiped at every boot | Sticky notes |
/opt | Add-on programs that aren't part of the distro, one folder per company: /opt/google/chrome, or your own /opt/cht/ourapp (Linux Sysadmin, lesson 9) | The storage unit |
/srv | Data this server serves to others (some admins use it instead of /var/www) | The shop counter |
/mnt, /media | Mount points for extra disks and USB sticks (Linux Sysadmin, lesson 7) | The loading dock |
The manual has the official map: man hier (short for “hierarchy”).
Where Rocky and Ubuntu differ
The top level is the same, but a few folders one level down are family-specific. These trip people up when a tutorial is written for the other family:
| What | Rocky / RHEL | Ubuntu / Debian |
|---|---|---|
| Extra service settings | /etc/sysconfig/ | /etc/default/ |
| Software sources (repos) | /etc/yum.repos.d/*.repo | /etc/apt/sources.list.d/ |
| Database of installed packages | /var/lib/rpm/ | /var/lib/dpkg/ |
| Downloaded package cache | /var/cache/dnf/ | /var/cache/apt/ |
| Which release is this? | /etc/redhat-release | /etc/lsb-release, /etc/debian_version |
| Bootloader files | /boot/grub2/ + /boot/loader/entries/ | /boot/grub/ |
| Startup RAM disk | /boot/initramfs-*.img | /boot/initrd.img-* |
| Security system settings | /etc/selinux/ (SELinux) | /etc/apparmor.d/ (AppArmor) |
| Network settings | /etc/NetworkManager/ | /etc/netplan/ (Linux Sysadmin, lesson 1) |
| Main log files | /var/log/messages, secure | /var/log/syslog, auth.log (Linux Sysadmin, lesson 4) |
| Web pages | /var/www/html on both (lesson 14) | |
| Extra top-level folders | /afs (empty, for a network filesystem) | /snap (Snap apps), /lost+found (ext4 repairs) |
Everything is a file
This is Linux's big idea: almost everything, including hardware and the kernel's own status, appears as a file you can read with ordinary tools like cat and ls.
/dev: hardware as files
ls -l /dev/sda* /dev/null echo "gone" > /dev/null # the black hole: anything written here disappears find / -name "*.conf" 2>/dev/null # the classic use: throw away error messages
brw-rw---- 1 root disk 8, 0 Sep 27 09:51 /dev/sda brw-rw---- 1 root disk 8, 1 Sep 27 09:51 /dev/sda1 crw-rw-rw- 1 root root 1, 3 Sep 27 09:51 /dev/null
/proc and /sys: the kernel's dashboard
These folders take up zero space on the disk. The kernel makes up their contents on the spot every time you read them.
grep "model name" /proc/cpuinfo # what CPU is this? (one line per core) grep MemTotal /proc/meminfo # how much memory? cat /proc/version # the exact kernel build cat /proc/1/comm # every process has a folder. PID 1 is systemd cat /sys/class/net/enp0s3/address # the network card's hardware (MAC) address
Commands like free, ps and uptime are really just reading /proc and printing it nicely. (Lesson 15 explains PID 1, and sysctl settings live in /proc/sys.)
Reading the first letter of ls -l
| First letter | Type | Example |
|---|---|---|
- | Regular file | /etc/passwd |
d | Directory (folder) | /home |
l | Symbolic link | /bin -> usr/bin |
b | Block device (disks: data in chunks) | /dev/sda |
c | Character device (a stream of bytes) | /dev/null, /dev/tty |
Not sure what something is? file NAME tells you, whatever its name or extension. Linux doesn't care about extensions like .txt. They're only a hint for humans.
Where should my stuff go?
- Personal files: your home folder. Always.
- Your own scripts, for everyone on the server:
/usr/local/bin. It's already in everyone's$PATH, so the script runs by name. Never put your own files in/usr/bin: that belongs to the package manager, which may overwrite or delete them. - Just for you:
~/binor~/.local/bin. - Your company's own app: the program in
/opt/COMPANY/APP, its settings in/etc/opt/…, and its data in/var/opt/…. Linux Sysadmin, lesson 9 does exactly that. - A website:
/var/www(or/srv). - Throwaway files:
/tmp. Anyone can write there, but thanks to the “sticky bit” (thetindrwxrwxrwt, see lesson 10) nobody can delete anyone else's files.
sudo and /usr/local/binFor safety, sudo ignores your $PATH and uses its own list, called secure_path. Ubuntu's list includes /usr/local/bin. Rocky's doesn't, so sudo mytool says “command not found” even though mytool works without sudo. The fix is to use the full path: sudo /usr/local/bin/mytool. See the list with sudo -l.
Try it: a guided tour 🗺️
Quick check
1. You need to change a setting for the SSH server. Which folder do you look in first?
✓ Settings live in /etc. For SSH that's /etc/ssh/sshd_config.
2. du -sh /proc says it's almost empty, but /proc is full of files. How?
✓ It's a virtual filesystem, and so is /sys.
3. You wrote a handy script for everyone on the server. Where should it go?
✓ /usr/bin belongs to the package manager, and /tmp gets cleaned out.
4. An Ubuntu tutorial says to edit /etc/default/grub. You're on Rocky. Where would the equivalent “extra settings” folder usually be?
✓ Rocky keeps most of these in /etc/sysconfig. grub is an exception: its file is /etc/default/grub on both.