SYSTEMCTL
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Systemctl is the primary tool for managing systemd services, targets, and the system state on modern Linux distributions.
BASIC SERVICE COMMANDS#
systemctl start service # Start a service systemctl stop service # Stop a service systemctl restart service # Restart a service systemctl reload service # Reload configuration systemctl status service # Show service status systemctl is-active service # Check if running systemctl is-enabled service # Check if enabled at boot systemctl is-failed service # Check if failed
ENABLE/DISABLE SERVICES#
systemctl enable service # Enable at boot systemctl disable service # Disable at boot systemctl enable --now service # Enable and start systemctl disable --now service # Disable and stop systemctl reenable service # Disable then enable (reset) systemctl mask service # Completely prevent starting systemctl unmask service # Remove mask
LIST SERVICES#
systemctl list-units # List all loaded units systemctl list-units --type=service # Services only systemctl list-units --state=running # Running only systemctl list-units --state=failed # Failed only systemctl list-unit-files # List all available units systemctl list-unit-files --type=service systemctl list-dependencies service # Show dependencies
COMMON SERVICE EXAMPLES#
# Web servers systemctl status nginx systemctl restart apache2 systemctl reload nginx # SSH systemctl status sshd systemctl restart sshd # Database systemctl status mysql systemctl start postgresql # Firewall systemctl status firewalld systemctl status ufw
VIEWING SERVICE STATUS#
systemctl status service # Detailed status systemctl show service # All properties systemctl show service -p MainPID # Specific property systemctl cat service # View unit file systemctl edit service # Edit unit file (override) systemctl edit --full service # Edit full unit file
SERVICE LOGS (JOURNALCTL)#
journalctl -u service # Logs for service journalctl -u service -f # Follow logs (live) journalctl -u service -n 50 # Last 50 lines journalctl -u service --since today journalctl -u service --since "1 hour ago" journalctl -u service -p err # Errors only journalctl -u nginx -u php-fpm # Multiple services
SYSTEM TARGETS (RUNLEVELS)#
systemctl get-default # Current default target systemctl set-default multi-user.target # CLI mode systemctl set-default graphical.target # GUI mode systemctl isolate multi-user.target # Switch to target systemctl isolate rescue.target # Rescue mode # Common targets: # poweroff.target - Shutdown # rescue.target - Single user/rescue # multi-user.target - Multi-user CLI (runlevel 3) # graphical.target - GUI (runlevel 5) # reboot.target - Reboot
SYSTEM POWER MANAGEMENT#
systemctl poweroff # Shutdown systemctl reboot # Reboot systemctl suspend # Suspend to RAM systemctl hibernate # Suspend to disk systemctl hybrid-sleep # Suspend to both
ANALYZING BOOT#
systemd-analyze # Boot time summary systemd-analyze blame # Time per service systemd-analyze critical-chain # Critical path systemd-analyze plot > boot.svg # Boot chart
CREATING CUSTOM SERVICES#
# Create unit file: /etc/systemd/system/myservice.service [Unit] Description=My Custom Service After=network.target Wants=network-online.target [Service] Type=simple User=myuser Group=mygroup WorkingDirectory=/opt/myapp ExecStart=/opt/myapp/start.sh ExecStop=/opt/myapp/stop.sh ExecReload=/bin/kill -HUP $MAINPID Restart=on-failure RestartSec=5 [Install] WantedBy=multi-user.target # After creating: systemctl daemon-reload # Reload unit files systemctl enable myservice systemctl start myservice
SERVICE TYPES#
Type=simple # Default, ExecStart is main process Type=forking # Process forks, parent exits Type=oneshot # Short-lived task Type=notify # Sends notification when ready Type=dbus # Acquires D-Bus name Type=idle # Delayed until other jobs finish
RESTART OPTIONS#
Restart=no # Never restart Restart=on-success # Exit code 0 Restart=on-failure # Non-zero exit Restart=on-abnormal # Signal/timeout/watchdog Restart=on-watchdog # Watchdog timeout only Restart=on-abort # Signal not caught Restart=always # Always restart RestartSec=5 # Wait 5 seconds before restart StartLimitBurst=3 # Max restarts StartLimitIntervalSec=60 # In this time period
RESOURCE LIMITS#
# In [Service] section MemoryLimit=512M CPUQuota=50% TasksMax=100 LimitNOFILE=65535 LimitNPROC=4096
SECURITY OPTIONS#
# In [Service] section NoNewPrivileges=yes PrivateTmp=yes ProtectSystem=strict ProtectHome=yes ReadOnlyPaths=/etc ReadWritePaths=/var/myapp
TIMERS (CRON REPLACEMENT)#
# Create timer: /etc/systemd/system/mytimer.timer [Unit] Description=Run my task daily [Timer] OnCalendar=daily OnCalendar=*-*-* 02:00:00 # Daily at 2 AM Persistent=true # Run if missed [Install] WantedBy=timers.target # Commands systemctl list-timers # List all timers systemctl enable mytimer.timer systemctl start mytimer.timer
TIMER EXPRESSIONS#
OnCalendar=hourly # Every hour OnCalendar=daily # Every day midnight OnCalendar=weekly # Every Monday OnCalendar=monthly # First of month OnCalendar=*-*-* 04:00:00 # Daily at 4 AM OnCalendar=Mon *-*-* 09:00:00 # Monday 9 AM OnCalendar=*:0/15 # Every 15 minutes OnBootSec=5min # 5 min after boot OnUnitActiveSec=1h # 1 hour after last run
OVERRIDE CONFIGURATIONS#
# Create override without modifying original systemctl edit service # Creates: /etc/systemd/system/service.d/override.conf [Service] Environment="MY_VAR=value" ExecStart= ExecStart=/new/command # View effective configuration systemctl cat service
SOCKET ACTIVATION#
# Create socket: /etc/systemd/system/myservice.socket [Unit] Description=My Service Socket [Socket] ListenStream=8080 Accept=no [Install] WantedBy=sockets.target
TROUBLESHOOTING#
systemctl --failed # List failed units systemctl reset-failed # Clear failed state systemctl daemon-reload # Reload after changes systemctl daemon-reexec # Re-execute systemd journalctl -xe # Recent logs with explanations journalctl -b # Logs from current boot journalctl -b -1 # Logs from previous boot journalctl --disk-usage # Journal disk usage journalctl --vacuum-size=100M # Reduce journal size
QUICK REFERENCE#
systemctl start service # Start systemctl stop service # Stop systemctl restart service # Restart systemctl reload service # Reload config systemctl status service # Status systemctl enable service # Enable at boot systemctl disable service # Disable at boot systemctl enable --now service # Enable + start systemctl is-active service # Check running systemctl is-enabled service # Check enabled systemctl list-units # List loaded systemctl list-unit-files # List available systemctl daemon-reload # Reload unit files journalctl -u service -f # Follow logs