← All cheat sheets

SYSTEMCTL

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Systemctl is the primary tool for managing systemd services,
targets, and the system state on modern Linux distributions.

BASIC SERVICE COMMANDS#

systemctl start service         # Start a service
systemctl stop service          # Stop a service
systemctl restart service       # Restart a service
systemctl reload service        # Reload configuration
systemctl status service        # Show service status
systemctl is-active service     # Check if running
systemctl is-enabled service    # Check if enabled at boot
systemctl is-failed service     # Check if failed

ENABLE/DISABLE SERVICES#

systemctl enable service        # Enable at boot
systemctl disable service       # Disable at boot
systemctl enable --now service  # Enable and start
systemctl disable --now service # Disable and stop
systemctl reenable service      # Disable then enable (reset)
systemctl mask service          # Completely prevent starting
systemctl unmask service        # Remove mask

LIST SERVICES#

systemctl list-units            # List all loaded units
systemctl list-units --type=service     # Services only
systemctl list-units --state=running    # Running only
systemctl list-units --state=failed     # Failed only
systemctl list-unit-files       # List all available units
systemctl list-unit-files --type=service
systemctl list-dependencies service     # Show dependencies

COMMON SERVICE EXAMPLES#

# Web servers
systemctl status nginx
systemctl restart apache2
systemctl reload nginx

# SSH
systemctl status sshd
systemctl restart sshd

# Database
systemctl status mysql
systemctl start postgresql

# Firewall
systemctl status firewalld
systemctl status ufw

VIEWING SERVICE STATUS#

systemctl status service        # Detailed status
systemctl show service          # All properties
systemctl show service -p MainPID   # Specific property
systemctl cat service           # View unit file
systemctl edit service          # Edit unit file (override)
systemctl edit --full service   # Edit full unit file

SERVICE LOGS (JOURNALCTL)#

journalctl -u service           # Logs for service
journalctl -u service -f        # Follow logs (live)
journalctl -u service -n 50     # Last 50 lines
journalctl -u service --since today
journalctl -u service --since "1 hour ago"
journalctl -u service -p err    # Errors only
journalctl -u nginx -u php-fpm  # Multiple services

SYSTEM TARGETS (RUNLEVELS)#

systemctl get-default           # Current default target
systemctl set-default multi-user.target     # CLI mode
systemctl set-default graphical.target      # GUI mode
systemctl isolate multi-user.target         # Switch to target
systemctl isolate rescue.target             # Rescue mode

# Common targets:
# poweroff.target   - Shutdown
# rescue.target     - Single user/rescue
# multi-user.target - Multi-user CLI (runlevel 3)
# graphical.target  - GUI (runlevel 5)
# reboot.target     - Reboot

SYSTEM POWER MANAGEMENT#

systemctl poweroff              # Shutdown
systemctl reboot                # Reboot
systemctl suspend               # Suspend to RAM
systemctl hibernate             # Suspend to disk
systemctl hybrid-sleep          # Suspend to both

ANALYZING BOOT#

systemd-analyze                 # Boot time summary
systemd-analyze blame           # Time per service
systemd-analyze critical-chain  # Critical path
systemd-analyze plot > boot.svg # Boot chart

CREATING CUSTOM SERVICES#

# Create unit file: /etc/systemd/system/myservice.service

[Unit]
Description=My Custom Service
After=network.target
Wants=network-online.target

[Service]
Type=simple
User=myuser
Group=mygroup
WorkingDirectory=/opt/myapp
ExecStart=/opt/myapp/start.sh
ExecStop=/opt/myapp/stop.sh
ExecReload=/bin/kill -HUP $MAINPID
Restart=on-failure
RestartSec=5

[Install]
WantedBy=multi-user.target

# After creating:
systemctl daemon-reload         # Reload unit files
systemctl enable myservice
systemctl start myservice

SERVICE TYPES#

Type=simple       # Default, ExecStart is main process
Type=forking      # Process forks, parent exits
Type=oneshot      # Short-lived task
Type=notify       # Sends notification when ready
Type=dbus         # Acquires D-Bus name
Type=idle         # Delayed until other jobs finish

RESTART OPTIONS#

Restart=no                  # Never restart
Restart=on-success          # Exit code 0
Restart=on-failure          # Non-zero exit
Restart=on-abnormal         # Signal/timeout/watchdog
Restart=on-watchdog         # Watchdog timeout only
Restart=on-abort            # Signal not caught
Restart=always              # Always restart

RestartSec=5                # Wait 5 seconds before restart
StartLimitBurst=3           # Max restarts
StartLimitIntervalSec=60    # In this time period

RESOURCE LIMITS#

# In [Service] section
MemoryLimit=512M
CPUQuota=50%
TasksMax=100
LimitNOFILE=65535
LimitNPROC=4096

SECURITY OPTIONS#

# In [Service] section
NoNewPrivileges=yes
PrivateTmp=yes
ProtectSystem=strict
ProtectHome=yes
ReadOnlyPaths=/etc
ReadWritePaths=/var/myapp

TIMERS (CRON REPLACEMENT)#

# Create timer: /etc/systemd/system/mytimer.timer

[Unit]
Description=Run my task daily

[Timer]
OnCalendar=daily
OnCalendar=*-*-* 02:00:00     # Daily at 2 AM
Persistent=true                # Run if missed

[Install]
WantedBy=timers.target

# Commands
systemctl list-timers          # List all timers
systemctl enable mytimer.timer
systemctl start mytimer.timer

TIMER EXPRESSIONS#

OnCalendar=hourly             # Every hour
OnCalendar=daily              # Every day midnight
OnCalendar=weekly             # Every Monday
OnCalendar=monthly            # First of month
OnCalendar=*-*-* 04:00:00     # Daily at 4 AM
OnCalendar=Mon *-*-* 09:00:00 # Monday 9 AM
OnCalendar=*:0/15             # Every 15 minutes

OnBootSec=5min                # 5 min after boot
OnUnitActiveSec=1h            # 1 hour after last run

OVERRIDE CONFIGURATIONS#

# Create override without modifying original
systemctl edit service

# Creates: /etc/systemd/system/service.d/override.conf
[Service]
Environment="MY_VAR=value"
ExecStart=
ExecStart=/new/command

# View effective configuration
systemctl cat service

SOCKET ACTIVATION#

# Create socket: /etc/systemd/system/myservice.socket

[Unit]
Description=My Service Socket

[Socket]
ListenStream=8080
Accept=no

[Install]
WantedBy=sockets.target

TROUBLESHOOTING#

systemctl --failed              # List failed units
systemctl reset-failed          # Clear failed state
systemctl daemon-reload         # Reload after changes
systemctl daemon-reexec         # Re-execute systemd

journalctl -xe                  # Recent logs with explanations
journalctl -b                   # Logs from current boot
journalctl -b -1                # Logs from previous boot
journalctl --disk-usage         # Journal disk usage
journalctl --vacuum-size=100M   # Reduce journal size

QUICK REFERENCE#

systemctl start service         # Start
systemctl stop service          # Stop
systemctl restart service       # Restart
systemctl reload service        # Reload config
systemctl status service        # Status
systemctl enable service        # Enable at boot
systemctl disable service       # Disable at boot
systemctl enable --now service  # Enable + start
systemctl is-active service     # Check running
systemctl is-enabled service    # Check enabled
systemctl list-units            # List loaded
systemctl list-unit-files       # List available
systemctl daemon-reload         # Reload unit files
journalctl -u service -f        # Follow logs