[{"data":1,"prerenderedAt":1528},["ShallowReactive",2],{"navigation_docs_en":3,"-en-general-linux-handy-tools-":377,"-en-general-linux-handy-tools--surround":1523},[4,16,94,262,271,332],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":15},"About","i-noto-star","\u002Fen\u002Fabout","en\u002F1.about",[10],{"title":11,"path":12,"stem":13,"icon":14},"Welcome","\u002Fen\u002Fabout\u002Fwelcome","en\u002F1.about\u002F1.welcome","i-lucide-home",false,{"title":17,"icon":18,"path":19,"stem":20,"children":21,"page":15},"General","i-noto-open-book","\u002Fen\u002Fgeneral","en\u002F2.general",[22,26,44,58,76],{"title":17,"path":23,"stem":24,"icon":25},"\u002Fen\u002Fgeneral\u002Fsummary","en\u002F2.general\u002F1.summary","i-lucide-bookmark",{"title":27,"icon":28,"path":29,"stem":30,"children":31,"page":15},"Networking","i-lucide-network","\u002Fen\u002Fgeneral\u002Fnetworking","en\u002F2.general\u002F2.networking",[32,36,40],{"title":33,"path":34,"stem":35},"NAT & DHCP","\u002Fen\u002Fgeneral\u002Fnetworking\u002Fnat","en\u002F2.general\u002F2.networking\u002F1.nat",{"title":37,"path":38,"stem":39},"DNS Zone","\u002Fen\u002Fgeneral\u002Fnetworking\u002Fdns","en\u002F2.general\u002F2.networking\u002F2.dns",{"title":41,"path":42,"stem":43},"Samba","\u002Fen\u002Fgeneral\u002Fnetworking\u002Fsamba","en\u002F2.general\u002F2.networking\u002F3.samba",{"title":45,"icon":46,"path":47,"stem":48,"children":49,"page":15},"Storage","i-lucide-hard-drive","\u002Fen\u002Fgeneral\u002Fstorage","en\u002F2.general\u002F3.storage",[50,54],{"title":51,"path":52,"stem":53},"RAID","\u002Fen\u002Fgeneral\u002Fstorage\u002Fraid","en\u002F2.general\u002F3.storage\u002F1.raid",{"title":55,"path":56,"stem":57},"ZFS","\u002Fen\u002Fgeneral\u002Fstorage\u002Fzfs","en\u002F2.general\u002F3.storage\u002F2.zfs",{"title":59,"icon":60,"path":61,"stem":62,"children":63,"page":15},"Hardware","i-lucide-server","\u002Fen\u002Fgeneral\u002Fhardware","en\u002F2.general\u002F4.hardware",[64,68,72],{"title":65,"path":66,"stem":67},"The Basics","\u002Fen\u002Fgeneral\u002Fhardware\u002Fbasics","en\u002F2.general\u002F4.hardware\u002F1.basics",{"title":69,"path":70,"stem":71},"Network","\u002Fen\u002Fgeneral\u002Fhardware\u002Fnetwork","en\u002F2.general\u002F4.hardware\u002F2.network",{"title":73,"path":74,"stem":75},"The ProloNAS","\u002Fen\u002Fgeneral\u002Fhardware\u002Fprolonas","en\u002F2.general\u002F4.hardware\u002F3.prolonas",{"title":77,"icon":78,"path":79,"stem":80,"children":81,"page":15},"Linux tips for dummies","i-lucide-terminal","\u002Fen\u002Fgeneral\u002Flinux","en\u002F2.general\u002F5.linux",[82,86,90],{"title":83,"path":84,"stem":85},"Command line basics","\u002Fen\u002Fgeneral\u002Flinux\u002Fcli-basics","en\u002F2.general\u002F5.linux\u002F1.cli-basics",{"title":87,"path":88,"stem":89},"Folders and partitions","\u002Fen\u002Fgeneral\u002Flinux\u002Ffilesystem","en\u002F2.general\u002F5.linux\u002F2.filesystem",{"title":91,"path":92,"stem":93},"Handy CLI tools","\u002Fen\u002Fgeneral\u002Flinux\u002Fhandy-tools","en\u002F2.general\u002F5.linux\u002F3.handy-tools",{"title":95,"icon":96,"path":97,"stem":98,"children":99,"page":15},"Serveex","i-noto-microscope","\u002Fen\u002Fserveex","en\u002F3.serveex",[100,104,126,144,170,188,202,216,234,248],{"title":101,"path":102,"stem":103,"icon":25},"Introduction","\u002Fen\u002Fserveex\u002Fintroduction","en\u002F3.serveex\u002F1.introduction",{"title":105,"icon":106,"path":107,"stem":108,"children":109,"page":15},"Server core","i-lucide-server-cog","\u002Fen\u002Fserveex\u002Fcore","en\u002F3.serveex\u002F2.core",[110,114,118,122],{"title":111,"path":112,"stem":113},"Debian 13","\u002Fen\u002Fserveex\u002Fcore\u002Finstallation","en\u002F3.serveex\u002F2.core\u002F1.installation",{"title":115,"path":116,"stem":117},"Docker","\u002Fen\u002Fserveex\u002Fcore\u002Fdocker","en\u002F3.serveex\u002F2.core\u002F2.docker",{"title":119,"path":120,"stem":121},"Wireguard","\u002Fen\u002Fserveex\u002Fcore\u002Fwireguard","en\u002F3.serveex\u002F2.core\u002F3.wireguard",{"title":123,"path":124,"stem":125},"SWAG","\u002Fen\u002Fserveex\u002Fcore\u002Fswag","en\u002F3.serveex\u002F2.core\u002F4.swag",{"title":127,"icon":128,"path":129,"stem":130,"children":131,"page":15},"Security","i-lucide-shield","\u002Fen\u002Fserveex\u002Fsecurity","en\u002F3.serveex\u002F3.security",[132,136,140],{"title":133,"path":134,"stem":135},"Cloudflare Zero Trust","\u002Fen\u002Fserveex\u002Fsecurity\u002Fcloudflare","en\u002F3.serveex\u002F3.security\u002F2.cloudflare",{"title":137,"path":138,"stem":139},"TinyAuth","\u002Fen\u002Fserveex\u002Fsecurity\u002Ftinyauth","en\u002F3.serveex\u002F3.security\u002F3.tinyauth",{"title":141,"path":142,"stem":143},"Pocket ID","\u002Fen\u002Fserveex\u002Fsecurity\u002Fpocket-id","en\u002F3.serveex\u002F3.security\u002F4.pocket-id",{"title":145,"icon":146,"path":147,"stem":148,"children":149,"page":15},"Monitoring","i-lucide-chart-no-axes-column","\u002Fen\u002Fserveex\u002Fmonitoring","en\u002F3.serveex\u002F4.monitoring",[150,154,158,162,166],{"title":151,"path":152,"stem":153},"Uptime-Kuma","\u002Fen\u002Fserveex\u002Fmonitoring\u002Fuptime-kuma","en\u002F3.serveex\u002F4.monitoring\u002F1.uptime-kuma",{"title":155,"path":156,"stem":157},"Dozzle","\u002Fen\u002Fserveex\u002Fmonitoring\u002Fdozzle","en\u002F3.serveex\u002F4.monitoring\u002F2.dozzle",{"title":159,"path":160,"stem":161},"Speedtest Tracker","\u002Fen\u002Fserveex\u002Fmonitoring\u002Fspeedtest-tracker","en\u002F3.serveex\u002F4.monitoring\u002F3.speedtest-tracker",{"title":163,"path":164,"stem":165},"Beszel","\u002Fen\u002Fserveex\u002Fmonitoring\u002Fbeszel","en\u002F3.serveex\u002F4.monitoring\u002F4.beszel",{"title":167,"path":168,"stem":169},"UpSnap","\u002Fen\u002Fserveex\u002Fmonitoring\u002Fupsnap","en\u002F3.serveex\u002F4.monitoring\u002F5.upsnap",{"title":171,"icon":172,"path":173,"stem":174,"children":175,"page":15},"Media & Seedbox","i-lucide-list-video","\u002Fen\u002Fserveex\u002Fmedia","en\u002F3.serveex\u002F5.media",[176,180,184],{"title":177,"path":178,"stem":179},"Jellyfin","\u002Fen\u002Fserveex\u002Fmedia\u002Fjellyfin","en\u002F3.serveex\u002F5.media\u002F1.jellyfin",{"title":181,"path":182,"stem":183},"Qbittorrent","\u002Fen\u002Fserveex\u002Fmedia\u002Fqbittorrent","en\u002F3.serveex\u002F5.media\u002F2.qbittorrent",{"title":185,"path":186,"stem":187},"Automation","\u002Fen\u002Fserveex\u002Fmedia\u002Fservarr","en\u002F3.serveex\u002F5.media\u002F3.servarr",{"title":189,"icon":190,"path":191,"stem":192,"children":193,"page":15},"Cloud Drive & Photos","i-lucide-cloud-upload","\u002Fen\u002Fserveex\u002Fcloud","en\u002F3.serveex\u002F6.cloud",[194,198],{"title":195,"path":196,"stem":197},"Immich","\u002Fen\u002Fserveex\u002Fcloud\u002Fimmich","en\u002F3.serveex\u002F6.cloud\u002F1.immich",{"title":199,"path":200,"stem":201},"Nextcloud","\u002Fen\u002Fserveex\u002Fcloud\u002Fnextcloud","en\u002F3.serveex\u002F6.cloud\u002F2.nextcloud",{"title":203,"icon":204,"path":205,"stem":206,"children":207,"page":15},"File & share","i-lucide-folder-tree","\u002Fen\u002Fserveex\u002Ffiles","en\u002F3.serveex\u002F7.files",[208,212],{"title":209,"path":210,"stem":211},"File Browser Quantum","\u002Fen\u002Fserveex\u002Ffiles\u002Ffile-browser-quantum","en\u002F3.serveex\u002F7.files\u002F1.file-browser-quantum",{"title":213,"path":214,"stem":215},"Pingvin","\u002Fen\u002Fserveex\u002Ffiles\u002Fpingvin","en\u002F3.serveex\u002F7.files\u002F2.pingvin",{"title":217,"icon":218,"path":219,"stem":220,"children":221,"page":15},"Developpement","i-lucide-code-xml","\u002Fen\u002Fserveex\u002Fdevelopment","en\u002F3.serveex\u002F8.development",[222,226,230],{"title":223,"path":224,"stem":225},"Code-Server","\u002Fen\u002Fserveex\u002Fdevelopment\u002Fcode-server","en\u002F3.serveex\u002F8.development\u002F1.code-server",{"title":227,"path":228,"stem":229},"Forgejo","\u002Fen\u002Fserveex\u002Fdevelopment\u002Fforgejo","en\u002F3.serveex\u002F8.development\u002F2.forgejo",{"title":231,"path":232,"stem":233},"IT Tools","\u002Fen\u002Fserveex\u002Fdevelopment\u002Fit-tools","en\u002F3.serveex\u002F8.development\u002F3.it-tools",{"title":235,"icon":236,"path":237,"stem":238,"children":239,"page":15},"Useful Apps","i-lucide-award","\u002Fen\u002Fserveex\u002Fapps","en\u002F3.serveex\u002F9.apps",[240,244],{"title":241,"path":242,"stem":243},"Adguard Home","\u002Fen\u002Fserveex\u002Fapps\u002Fadguard","en\u002F3.serveex\u002F9.apps\u002F1.adguard",{"title":245,"path":246,"stem":247},"Vaultwarden","\u002Fen\u002Fserveex\u002Fapps\u002Fvaultwarden","en\u002F3.serveex\u002F9.apps\u002F2.vaultwarden",{"title":249,"icon":250,"path":251,"stem":252,"children":253,"page":15},"Advanced","i-lucide-flask-conical","\u002Fen\u002Fserveex\u002Fadvanced","en\u002F3.serveex\u002F91.advanced",[254,258],{"title":255,"path":256,"stem":257},"Authentik","\u002Fen\u002Fserveex\u002Fadvanced\u002Fauthentik","en\u002F3.serveex\u002F91.advanced\u002F1.authentik",{"title":259,"path":260,"stem":261},"Arcane","\u002Fen\u002Fserveex\u002Fadvanced\u002Farcane","en\u002F3.serveex\u002F91.advanced\u002F2.arcane",{"title":263,"icon":264,"path":265,"stem":266,"children":267,"page":15},"Stockeex","i-noto-computer-disk","\u002Fen\u002Fstockeex","en\u002F4.stockeex",[268],{"title":101,"path":269,"stem":270,"icon":25},"\u002Fen\u002Fstockeex\u002Fintroduction","en\u002F4.stockeex\u002F1.introduction",{"title":272,"icon":273,"path":274,"stem":275,"children":276,"page":15},"My nonsense","i-noto-test-tube","\u002Fen\u002Fnonsense","en\u002F5.nonsense",[277,280,302],{"title":272,"path":278,"stem":279,"icon":25},"\u002Fen\u002Fnonsense\u002Fsummary","en\u002F5.nonsense\u002F1.summary",{"title":281,"icon":282,"path":283,"stem":284,"children":285,"page":15},"Python","i-lucide-file-code-2","\u002Fen\u002Fnonsense\u002Fpython","en\u002F5.nonsense\u002F2.python",[286,290,294,298],{"title":287,"path":288,"stem":289},"Nvidia Stock Bot","\u002Fen\u002Fnonsense\u002Fpython\u002Fnvidia-stock-bot","en\u002F5.nonsense\u002F2.python\u002F1.nvidia-stock-bot",{"title":291,"path":292,"stem":293},"Adguard CIDRE","\u002Fen\u002Fnonsense\u002Fpython\u002Fadguard-cidre","en\u002F5.nonsense\u002F2.python\u002F2.adguard-cidre",{"title":295,"path":296,"stem":297},"Lumeex","\u002Fen\u002Fnonsense\u002Fpython\u002Flumeex","en\u002F5.nonsense\u002F2.python\u002F3.lumeex",{"title":299,"path":300,"stem":301},"Instameex","\u002Fen\u002Fnonsense\u002Fpython\u002Finstameex","en\u002F5.nonsense\u002F2.python\u002F4.instameex",{"title":303,"icon":304,"path":305,"stem":306,"children":307,"page":15},"Bash","i-lucide-file-terminal","\u002Fen\u002Fnonsense\u002Fbash","en\u002F5.nonsense\u002F3.bash",[308,312,316,320,324,328],{"title":309,"path":310,"stem":311},"Servarr corrector","\u002Fen\u002Fnonsense\u002Fbash\u002Fservarr-duplicates","en\u002F5.nonsense\u002F3.bash\u002F1.servarr-duplicates",{"title":313,"path":314,"stem":315},"LUKS Backup","\u002Fen\u002Fnonsense\u002Fbash\u002Fluks-backup","en\u002F5.nonsense\u002F3.bash\u002F2.luks-backup",{"title":317,"path":318,"stem":319},"Socat Proxy","\u002Fen\u002Fnonsense\u002Fbash\u002Fsocat-proxy","en\u002F5.nonsense\u002F3.bash\u002F3.socat-proxy",{"title":321,"path":322,"stem":323},"HotDisk","\u002Fen\u002Fnonsense\u002Fbash\u002Fhotdisk","en\u002F5.nonsense\u002F3.bash\u002F4.hotdisk",{"title":325,"path":326,"stem":327},"Backrest Docker Stop","\u002Fen\u002Fnonsense\u002Fbash\u002Fbackrest-docker-stop","en\u002F5.nonsense\u002F3.bash\u002F5.backrest-docker-stop",{"title":329,"path":330,"stem":331},"rm Confirmation Guard","\u002Fen\u002Fnonsense\u002Fbash\u002Frm-confirmation","en\u002F5.nonsense\u002F3.bash\u002F6.rm-confirmation",{"title":333,"icon":334,"path":335,"stem":336,"children":337,"page":15},"Recycled","i-noto-recycling-symbol","\u002Fen\u002Frecycled","en\u002F6.recycled",[338,341,355],{"title":333,"path":339,"stem":340,"icon":25},"\u002Fen\u002Frecycled\u002Fsummary","en\u002F6.recycled\u002F1.summary",{"title":342,"icon":343,"path":344,"stem":345,"children":346,"page":15},"Deprecated","i-lucide-trash-2","\u002Fen\u002Frecycled\u002Fdeprecated","en\u002F6.recycled\u002F2.deprecated",[347,351],{"title":348,"path":349,"stem":350},"Wireguard 14","\u002Fen\u002Frecycled\u002Fdeprecated\u002Fwireguard-14","en\u002F6.recycled\u002F2.deprecated\u002F1.wireguard-14",{"title":352,"path":353,"stem":354},"File Browser","\u002Fen\u002Frecycled\u002Fdeprecated\u002Ffile-browser","en\u002F6.recycled\u002F2.deprecated\u002F2.file-browser",{"title":356,"icon":357,"path":358,"stem":359,"children":360,"page":15},"Alternatives","i-lucide-arrow-left-right","\u002Fen\u002Frecycled\u002Falternatives","en\u002F6.recycled\u002F3.alternatives",[361,365,369,373],{"title":362,"path":363,"stem":364},"Plex","\u002Fen\u002Frecycled\u002Falternatives\u002Fplex","en\u002F6.recycled\u002F3.alternatives\u002F1.plex",{"title":366,"path":367,"stem":368},"Qbittorrent for Plex","\u002Fen\u002Frecycled\u002Falternatives\u002Fqbittorrent-for-plex","en\u002F6.recycled\u002F3.alternatives\u002F2.qbittorrent for plex",{"title":370,"path":371,"stem":372},"Servarr for Plex","\u002Fen\u002Frecycled\u002Falternatives\u002Fservarr-for-plex","en\u002F6.recycled\u002F3.alternatives\u002F3.servarr for plex",{"title":374,"path":375,"stem":376},"Gitea","\u002Fen\u002Frecycled\u002Falternatives\u002Fgitea","en\u002F6.recycled\u002F3.alternatives\u002F4.gitea",{"id":378,"title":91,"body":379,"contributors":1515,"description":1517,"extension":1518,"hideCopyPage":15,"hideHeader":15,"hideToc":15,"links":1519,"meta":1520,"navigation":1466,"path":92,"seo":1521,"stem":93,"__hash__":1522},"docs_en\u002Fen\u002F2.general\u002F5.linux\u002F3.handy-tools.md",{"type":380,"value":381,"toc":1499},"minimark",[382,390,403,410,431,436,554,558,561,611,617,625,695,701,709,760,766,779,847,853,866,926,932,935,1257,1263,1279,1495],[383,384],"ellipsis",{"blur":385,"left":386,"top":387,"width":388,"z-index":389},"140px","0px","10rem","40rem","60",[391,392,393,394,398,399,402],"p",{},"A minimal Debian install ships with the strict minimum, which means the tools you get are the ones from 1995. They work, but reading ",[395,396,397],"code",{},"df"," output or hunting for what filled a disk with ",[395,400,401],{},"du"," is needlessly painful when better versions exist and cost nothing to install.",[391,404,405,406,409],{},"Everything below except the last one comes straight from Debian's repositories, so there's no third-party source to trust and ",[395,407,408],{},"apt"," keeps them updated along with the rest of the system.",[411,412,414,415,418,419,421,422,425,426,430],"note",{"to":413},"\u002Fgeneral\u002Flinux\u002Fcli-basics","Every command here is typed in a terminal over SSH. If ",[395,416,417],{},"sudo",", ",[395,420,408],{}," and ",[395,423,424],{},"cd"," don't mean much yet, start with the ",[427,428,429],"strong",{},"command line basics",".",[432,433,435],"h2",{"id":434},"the-short-version","The short version",[437,438,439,455],"table",{},[440,441,442],"thead",{},[443,444,445,449,452],"tr",{},[446,447,448],"th",{},"Tool",[446,450,451],{},"Replaces",[446,453,454],{},"What for",[456,457,458,477,492,507,522,538],"tbody",{},[443,459,460,466,474],{},[461,462,463],"td",{},[395,464,465],{},"btop",[461,467,468,418,471],{},[395,469,470],{},"top",[395,472,473],{},"htop",[461,475,476],{},"Watching CPU, RAM and processes",[443,478,479,484,489],{},[461,480,481],{},[395,482,483],{},"duf",[461,485,486],{},[395,487,488],{},"df -h",[461,490,491],{},"Free space, readable",[443,493,494,499,504],{},[461,495,496],{},[395,497,498],{},"ncdu",[461,500,501],{},[395,502,503],{},"du -sh",[461,505,506],{},"Finding what filled the disk",[443,508,509,514,519],{},[461,510,511],{},[395,512,513],{},"tldr",[461,515,516],{},[395,517,518],{},"man",[461,520,521],{},"The five commands you actually need",[443,523,524,529,535],{},[461,525,526],{},[395,527,528],{},"lazydocker",[461,530,531,534],{},[395,532,533],{},"docker ps"," and friends",[461,536,537],{},"Managing containers over SSH",[443,539,540,545,551],{},[461,541,542],{},[395,543,544],{},"ufw",[461,546,547,548],{},"raw ",[395,549,550],{},"iptables",[461,552,553],{},"A firewall you can actually read",[432,555,557],{"id":556},"the-impatient-version","The impatient version",[391,559,560],{},"One line installs all the packaged ones, and each section below explains what you just got.",[562,563,569],"pre",{"className":564,"code":565,"filename":566,"language":567,"meta":568,"style":568},"language-bash shiki shiki-themes github-dark material-theme github-dark","sudo apt update\nsudo apt install btop duf ncdu tealdeer ufw\n","Terminal","bash","",[395,570,571,586],{"__ignoreMap":568},[572,573,576,579,583],"span",{"class":574,"line":575},"line",1,[572,577,417],{"class":578},"sEgDM",[572,580,582],{"class":581},"s11XM"," apt",[572,584,585],{"class":581}," update\n",[572,587,589,591,593,596,599,602,605,608],{"class":574,"line":588},2,[572,590,417],{"class":578},[572,592,582],{"class":581},[572,594,595],{"class":581}," install",[572,597,598],{"class":581}," btop",[572,600,601],{"class":581}," duf",[572,603,604],{"class":581}," ncdu",[572,606,607],{"class":581}," tealdeer",[572,609,610],{"class":581}," ufw\n",[432,612,614,616],{"id":613},"btop-watching-what-the-machine-is-doing",[395,615,465],{},", watching what the machine is doing",[391,618,619,620,421,622,624],{},"The modern replacement for ",[395,621,470],{},[395,623,473],{},": CPU, RAM, disks, network and processes on one screen, with graphs, colors and a working mouse. This is what you open when something feels slow.",[626,627,629,634,650,654,665,672,691],"steps",{"level":628},"4",[630,631,633],"h4",{"id":632},"install-it","Install it",[562,635,637],{"className":564,"code":636,"filename":566,"language":567,"meta":568,"style":568},"sudo apt install btop\n",[395,638,639],{"__ignoreMap":568},[572,640,641,643,645,647],{"class":574,"line":575},[572,642,417],{"class":578},[572,644,582],{"class":581},[572,646,595],{"class":581},[572,648,649],{"class":581}," btop\n",[630,651,653],{"id":652},"run-it","Run it",[562,655,657],{"className":564,"code":656,"filename":566,"language":567,"meta":568,"style":568},"sudo btop\n",[395,658,659],{"__ignoreMap":568},[572,660,661,663],{"class":574,"line":575},[572,662,417],{"class":578},[572,664,649],{"class":581},[391,666,667],{},[668,669],"img",{"alt":670,"src":671},"btop showing CPU, memory, disks, network and processes","\u002Fimg\u002Fglobal\u002Flinux\u002Fbtop.png",[391,673,674,675,679,680,683,684,421,687,690],{},"Click a process to select it, ",[676,677],"kbd",{"value":678},"Esc"," opens the menu, ",[676,681],{"value":682},"Q"," quits. The ",[395,685,686],{},"+",[395,688,689],{},"-"," keys fold and unfold the panels if the screen feels crowded.",[630,692,694],{"id":693},"done","Done !",[432,696,698,700],{"id":697},"duf-disk-space-that-reads-like-a-table",[395,699,483],{},", disk space that reads like a table",[391,702,703,705,706,708],{},[395,704,488],{}," prints every loop device Docker ever created and leaves you squinting at the columns. ",[395,707,483],{}," shows the same information grouped, aligned and colored, with a usage bar per filesystem.",[626,710,711,714,730,733,744,750,757],{"level":628},[630,712,633],{"id":713},"install-it-1",[562,715,717],{"className":564,"code":716,"filename":566,"language":567,"meta":568,"style":568},"sudo apt install duf\n",[395,718,719],{"__ignoreMap":568},[572,720,721,723,725,727],{"class":574,"line":575},[572,722,417],{"class":578},[572,724,582],{"class":581},[572,726,595],{"class":581},[572,728,729],{"class":581}," duf\n",[630,731,653],{"id":732},"run-it-1",[562,734,736],{"className":564,"code":735,"filename":566,"language":567,"meta":568,"style":568},"sudo duf\n",[395,737,738],{"__ignoreMap":568},[572,739,740,742],{"class":574,"line":575},[572,741,417],{"class":578},[572,743,729],{"class":581},[391,745,746],{},[668,747],{"alt":748,"src":749},"duf listing local, network and special filesystems","\u002Fimg\u002Fglobal\u002Flinux\u002Fduf.png",[391,751,752,753,756],{},"Local disks, network shares and system mounts are grouped separately. Add ",[395,754,755],{},"--only local"," to hide the pseudo-filesystems Docker leaves behind.",[630,758,694],{"id":759},"done-1",[432,761,763,765],{"id":762},"ncdu-finding-what-ate-the-disk",[395,764,498],{},", finding what ate the disk",[391,767,768,769,771,772,774,775,778],{},"When ",[395,770,483],{}," tells you the disk is full, ",[395,773,498],{}," tells you why. It walks a folder, sorts everything by real size, and lets you drill down with the arrow keys instead of running ",[395,776,777],{},"du -sh *"," twenty times.",[626,780,781,784,800,804,818,832,844],{"level":628},[630,782,633],{"id":783},"install-it-2",[562,785,787],{"className":564,"code":786,"filename":566,"language":567,"meta":568,"style":568},"sudo apt install ncdu\n",[395,788,789],{"__ignoreMap":568},[572,790,791,793,795,797],{"class":574,"line":575},[572,792,417],{"class":578},[572,794,582],{"class":581},[572,796,595],{"class":581},[572,798,799],{"class":581}," ncdu\n",[630,801,803],{"id":802},"point-it-at-a-folder","Point it at a folder",[562,805,807],{"className":564,"code":806,"filename":566,"language":567,"meta":568,"style":568},"sudo ncdu \u002Fsrv\u002Fdocker\n",[395,808,809],{"__ignoreMap":568},[572,810,811,813,815],{"class":574,"line":575},[572,812,417],{"class":578},[572,814,604],{"class":581},[572,816,817],{"class":581}," \u002Fsrv\u002Fdocker\n",[391,819,820,821,824,825,828,829,831],{},"Arrows to move, ",[676,822],{"value":823},"Enter"," to open a folder, ",[676,826],{"value":827},"D"," to delete the selected item, ",[676,830],{"value":682}," to quit. On a big disk the first scan takes a moment, it's reading everything.",[833,834,835,837,838,840,841,843],"warning",{},[676,836],{"value":827}," deletes immediately, with a single confirmation and no recycle bin. Run ",[395,839,498],{}," without ",[395,842,417],{}," when you're only looking, so a mistyped key can't touch anything the system owns.",[630,845,694],{"id":846},"done-2",[432,848,850,852],{"id":849},"tldr-the-manual-without-the-400-lines",[395,851,513],{},", the manual without the 400 lines",[391,854,855,858,859,862,863,430],{},[395,856,857],{},"man tar"," is exhaustive and unreadable. ",[395,860,861],{},"tldr tar"," gives you the five commands people actually type, with a one-line explanation each. It's community-maintained examples rather than a substitute for the real manual, and on Debian the client is packaged as ",[395,864,865],{},"tealdeer",[626,867,868,871,887,891,904,907,911,923],{"level":628},[630,869,633],{"id":870},"install-it-3",[562,872,874],{"className":564,"code":873,"filename":566,"language":567,"meta":568,"style":568},"sudo apt install tealdeer\n",[395,875,876],{"__ignoreMap":568},[572,877,878,880,882,884],{"class":574,"line":575},[572,879,417],{"class":578},[572,881,582],{"class":581},[572,883,595],{"class":581},[572,885,886],{"class":581}," tealdeer\n",[630,888,890],{"id":889},"download-the-page-cache","Download the page cache",[562,892,894],{"className":564,"code":893,"filename":566,"language":567,"meta":568,"style":568},"tldr --update\n",[395,895,896],{"__ignoreMap":568},[572,897,898,900],{"class":574,"line":575},[572,899,513],{"class":578},[572,901,903],{"class":902},"sJWha"," --update\n",[391,905,906],{},"The examples are fetched once and stored locally, so the command works offline afterwards. Run it again every few months.",[630,908,910],{"id":909},"ask-it-something","Ask it something",[562,912,914],{"className":564,"code":913,"filename":566,"language":567,"meta":568,"style":568},"tldr rsync\n",[395,915,916],{"__ignoreMap":568},[572,917,918,920],{"class":574,"line":575},[572,919,513],{"class":578},[572,921,922],{"class":581}," rsync\n",[630,924,694],{"id":925},"done-3",[432,927,929,931],{"id":928},"lazydocker-managing-containers-from-the-terminal",[395,930,528],{},", managing containers from the terminal",[391,933,934],{},"The one exception: it isn't packaged by Debian. It's a full text interface for Docker, containers, images, volumes and logs in one screen, with keys to restart, stop or follow the logs of anything. Handy when you're already in SSH and don't feel like opening Dockge.",[626,936,937,941,967,986,990,1024,1033,1037,1049,1052,1063,1069,1079,1225,1235,1244,1254],{"level":628},[630,938,940],{"id":939},"download-the-latest-release","Download the latest release",[562,942,944],{"className":564,"code":943,"filename":566,"language":567,"meta":568,"style":568},"curl -Lo \u002Ftmp\u002Flazydocker.tar.gz \"https:\u002F\u002Fgithub.com\u002Fjesseduffield\u002Flazydocker\u002Freleases\u002Flatest\u002Fdownload\u002Flazydocker_0.25.2_Linux_x86_64.tar.gz\"\n",[395,945,946],{"__ignoreMap":568},[572,947,948,951,954,957,961,964],{"class":574,"line":575},[572,949,950],{"class":578},"curl",[572,952,953],{"class":902}," -Lo",[572,955,956],{"class":581}," \u002Ftmp\u002Flazydocker.tar.gz",[572,958,960],{"class":959},"s8K8j"," \"",[572,962,963],{"class":581},"https:\u002F\u002Fgithub.com\u002Fjesseduffield\u002Flazydocker\u002Freleases\u002Flatest\u002Fdownload\u002Flazydocker_0.25.2_Linux_x86_64.tar.gz",[572,965,966],{"class":959},"\"\n",[391,968,969,970,977,978,981,982,985],{},"Check the ",[971,972,976],"a",{"href":973,"rel":974},"https:\u002F\u002Fgithub.com\u002Fjesseduffield\u002Flazydocker\u002Freleases",[975],"nofollow","releases page"," for the current version number, and take ",[395,979,980],{},"arm64"," instead of ",[395,983,984],{},"x86_64"," if the server is a Raspberry Pi or similar.",[630,987,989],{"id":988},"install-the-binary","Install the binary",[562,991,993],{"className":564,"code":992,"filename":566,"language":567,"meta":568,"style":568},"sudo tar -xzf \u002Ftmp\u002Flazydocker.tar.gz -C \u002Fusr\u002Flocal\u002Fbin lazydocker\nrm \u002Ftmp\u002Flazydocker.tar.gz\n",[395,994,995,1016],{"__ignoreMap":568},[572,996,997,999,1002,1005,1007,1010,1013],{"class":574,"line":575},[572,998,417],{"class":578},[572,1000,1001],{"class":581}," tar",[572,1003,1004],{"class":902}," -xzf",[572,1006,956],{"class":581},[572,1008,1009],{"class":902}," -C",[572,1011,1012],{"class":581}," \u002Fusr\u002Flocal\u002Fbin",[572,1014,1015],{"class":581}," lazydocker\n",[572,1017,1018,1021],{"class":574,"line":588},[572,1019,1020],{"class":578},"rm",[572,1022,1023],{"class":581}," \u002Ftmp\u002Flazydocker.tar.gz\n",[391,1025,1026,1029,1030,1032],{},[395,1027,1028],{},"\u002Fusr\u002Flocal\u002Fbin"," is the folder meant for software you install yourself, which is why ",[395,1031,408],{}," never touches it.",[630,1034,1036],{"id":1035},"check-it-landed","Check it landed",[562,1038,1040],{"className":564,"code":1039,"filename":566,"language":567,"meta":568,"style":568},"lazydocker --version\n",[395,1041,1042],{"__ignoreMap":568},[572,1043,1044,1046],{"class":574,"line":575},[572,1045,528],{"class":578},[572,1047,1048],{"class":902}," --version\n",[630,1050,653],{"id":1051},"run-it-2",[562,1053,1055],{"className":564,"code":1054,"filename":566,"language":567,"meta":568,"style":568},"sudo lazydocker\n",[395,1056,1057],{"__ignoreMap":568},[572,1058,1059,1061],{"class":574,"line":575},[572,1060,417],{"class":578},[572,1062,1015],{"class":581},[391,1064,1065],{},[668,1066],{"alt":1067,"src":1068},"lazydocker showing services, containers, images, volumes and a container's config","\u002Fimg\u002Fglobal\u002Flinux\u002Flazydocker.png",[391,1070,1071,1072,1074,1075,1078],{},"It needs access to the Docker socket, hence the ",[395,1073,417],{}," unless your user is in the ",[395,1076,1077],{},"docker"," group. The keys worth knowing:",[437,1080,1081,1091],{},[440,1082,1083],{},[443,1084,1085,1088],{},[446,1086,1087],{},"Key",[446,1089,1090],{},"What it does",[456,1092,1093,1107,1115,1127,1137,1147,1163,1173,1183,1193,1203,1215],{},[443,1094,1095,1104],{},[461,1096,1097,1100,1101],{},[395,1098,1099],{},"1"," to ",[395,1102,1103],{},"6",[461,1105,1106],{},"Jump to a panel: projects, services, containers, images, volumes, networks",[443,1108,1109,1112],{},[461,1110,1111],{},"Arrows",[461,1113,1114],{},"Move inside the panel, the right side follows the selection",[443,1116,1117,1121],{},[461,1118,1119],{},[676,1120],{"value":823},[461,1122,1123,1124,1126],{},"Focus the main panel on the right, ",[676,1125],{"value":678}," comes back",[443,1128,1129,1134],{},[461,1130,1131],{},[395,1132,1133],{},"x",[461,1135,1136],{},"Open the menu of everything you can do with what's selected",[443,1138,1139,1144],{},[461,1140,1141],{},[395,1142,1143],{},"m",[461,1145,1146],{},"Follow the logs",[443,1148,1149,1160],{},[461,1150,1151,1154,1155,1154,1158],{},[395,1152,1153],{},"s"," \u002F ",[395,1156,1157],{},"r",[395,1159,391],{},[461,1161,1162],{},"Stop, restart, pause the selected container",[443,1164,1165,1170],{},[461,1166,1167],{},[395,1168,1169],{},"E",[461,1171,1172],{},"Open a shell inside the container",[443,1174,1175,1180],{},[461,1176,1177],{},[395,1178,1179],{},"d",[461,1181,1182],{},"Remove it",[443,1184,1185,1190],{},[461,1186,1187],{},[395,1188,1189],{},"b",[461,1191,1192],{},"Bulk commands, pruning images and volumes among others",[443,1194,1195,1200],{},[461,1196,1197],{},[395,1198,1199],{},"\u002F",[461,1201,1202],{},"Filter the list",[443,1204,1205,1212],{},[461,1206,1207,421,1209],{},[395,1208,686],{},[395,1210,1211],{},"_",[461,1213,1214],{},"Grow or shrink the panels",[443,1216,1217,1222],{},[461,1218,1219],{},[395,1220,1221],{},"q",[461,1223,1224],{},"Quit",[391,1226,1227,1228,1230,1231,1234],{},"Case matters: ",[395,1229,1169],{}," opens a shell in the container, ",[395,1232,1233],{},"e"," hides the stopped ones.",[391,1236,1237,1238,1243],{},"The ",[971,1239,1242],{"href":1240,"rel":1241},"https:\u002F\u002Fgithub.com\u002Fjesseduffield\u002Flazydocker\u002Fblob\u002Fmaster\u002Fdocs\u002Fkeybindings\u002FKeybindings_en.md",[975],"full list"," is in the project's documentation.",[411,1245,1246,1247,1249,1250,1253],{},"Being outside ",[395,1248,408],{}," also means it won't be updated by ",[395,1251,1252],{},"apt full-upgrade",". Repeat these steps when you want a newer version.",[630,1255,694],{"id":1256},"done-4",[432,1258,1260,1262],{"id":1259},"ufw-a-firewall-you-can-actually-read",[395,1261,544],{},", a firewall you can actually read",[391,1264,1265,1266,1199,1268,1271,1272,418,1274,1278],{},"Debian's firewall (",[395,1267,550],{},[395,1269,1270],{},"nftables"," under the hood) is powerful and unreadable directly. ",[395,1273,544],{},[1275,1276,1277],"em",{},"uncomplicated firewall",", is a thin layer on top that turns it into short, plain-English rules, block everything by default and open only what you actually expose.",[626,1280,1281,1284,1299,1303,1338,1341,1345,1372,1390,1397,1401,1415,1419,1436,1492],{"level":628},[630,1282,633],{"id":1283},"install-it-4",[562,1285,1287],{"className":564,"code":1286,"filename":566,"language":567,"meta":568,"style":568},"sudo apt install ufw\n",[395,1288,1289],{"__ignoreMap":568},[572,1290,1291,1293,1295,1297],{"class":574,"line":575},[572,1292,417],{"class":578},[572,1294,582],{"class":581},[572,1296,595],{"class":581},[572,1298,610],{"class":581},[630,1300,1302],{"id":1301},"set-the-default-policy","Set the default policy",[562,1304,1306],{"className":564,"code":1305,"filename":566,"language":567,"meta":568,"style":568},"sudo ufw default deny incoming\nsudo ufw default allow outgoing\n",[395,1307,1308,1324],{"__ignoreMap":568},[572,1309,1310,1312,1315,1318,1321],{"class":574,"line":575},[572,1311,417],{"class":578},[572,1313,1314],{"class":581}," ufw",[572,1316,1317],{"class":581}," default",[572,1319,1320],{"class":581}," deny",[572,1322,1323],{"class":581}," incoming\n",[572,1325,1326,1328,1330,1332,1335],{"class":574,"line":588},[572,1327,417],{"class":578},[572,1329,1314],{"class":581},[572,1331,1317],{"class":581},[572,1333,1334],{"class":581}," allow",[572,1336,1337],{"class":581}," outgoing\n",[391,1339,1340],{},"Nothing gets in unless a rule says so, everything the server itself initiates still goes out normally.",[630,1342,1344],{"id":1343},"allow-what-you-actually-need","Allow what you actually need",[562,1346,1348],{"className":564,"code":1347,"filename":566,"language":567,"meta":568,"style":568},"sudo ufw allow OpenSSH\nsudo ufw allow 443\u002Ftcp\n",[395,1349,1350,1361],{"__ignoreMap":568},[572,1351,1352,1354,1356,1358],{"class":574,"line":575},[572,1353,417],{"class":578},[572,1355,1314],{"class":581},[572,1357,1334],{"class":581},[572,1359,1360],{"class":581}," OpenSSH\n",[572,1362,1363,1365,1367,1369],{"class":574,"line":588},[572,1364,417],{"class":578},[572,1366,1314],{"class":581},[572,1368,1334],{"class":581},[572,1370,1371],{"class":581}," 443\u002Ftcp\n",[391,1373,1374,1377,1378,1381,1382,1385,1386,1389],{},[395,1375,1376],{},"OpenSSH"," is a built-in profile that matches the SSH port, no need to remember which one. Add one ",[395,1379,1380],{},"allow"," per port you expose, ",[971,1383,123],{"href":1384},"\u002Fserveex\u002Fcore\u002Fswag"," on ",[395,1387,1388],{},"443"," for instance.",[833,1391,1392,1393,1396],{},"Allow SSH ",[427,1394,1395],{},"before"," enabling the firewall, in the next step. Enable it first and the very connection you're typing in gets cut, with no screen left plugged in to fix it.",[630,1398,1400],{"id":1399},"enable-it","Enable it",[562,1402,1404],{"className":564,"code":1403,"filename":566,"language":567,"meta":568,"style":568},"sudo ufw enable\n",[395,1405,1406],{"__ignoreMap":568},[572,1407,1408,1410,1412],{"class":574,"line":575},[572,1409,417],{"class":578},[572,1411,1314],{"class":581},[572,1413,1414],{"class":581}," enable\n",[630,1416,1418],{"id":1417},"check-the-rules","Check the rules",[562,1420,1422],{"className":564,"code":1421,"filename":566,"language":567,"meta":568,"style":568},"sudo ufw status verbose\n",[395,1423,1424],{"__ignoreMap":568},[572,1425,1426,1428,1430,1433],{"class":574,"line":575},[572,1427,417],{"class":578},[572,1429,1314],{"class":581},[572,1431,1432],{"class":581}," status",[572,1434,1435],{"class":581}," verbose\n",[562,1437,1442],{"className":1438,"code":1439,"filename":1440,"language":1441,"meta":568,"style":568},"language-console shiki shiki-themes github-dark material-theme github-dark","Status: active\nLogging: on (low)\nDefault: deny (incoming), allow (outgoing), disabled (routed)\n\nTo                         Action      From\n--                         ------      ----\n22\u002Ftcp (OpenSSH)           ALLOW IN    Anywhere\n443\u002Ftcp                    ALLOW IN    Anywhere\n","Output","console",[395,1443,1444,1450,1455,1461,1468,1474,1480,1486],{"__ignoreMap":568},[572,1445,1446],{"class":574,"line":575},[572,1447,1449],{"class":1448},"s8-mJ","Status: active\n",[572,1451,1452],{"class":574,"line":588},[572,1453,1454],{"class":1448},"Logging: on (low)\n",[572,1456,1458],{"class":574,"line":1457},3,[572,1459,1460],{"class":1448},"Default: deny (incoming), allow (outgoing), disabled (routed)\n",[572,1462,1464],{"class":574,"line":1463},4,[572,1465,1467],{"emptyLinePlaceholder":1466},true,"\n",[572,1469,1471],{"class":574,"line":1470},5,[572,1472,1473],{"class":1448},"To                         Action      From\n",[572,1475,1477],{"class":574,"line":1476},6,[572,1478,1479],{"class":1448},"--                         ------      ----\n",[572,1481,1483],{"class":574,"line":1482},7,[572,1484,1485],{"class":1448},"22\u002Ftcp (OpenSSH)           ALLOW IN    Anywhere\n",[572,1487,1489],{"class":574,"line":1488},8,[572,1490,1491],{"class":1448},"443\u002Ftcp                    ALLOW IN    Anywhere\n",[630,1493,694],{"id":1494},"done-5",[1496,1497,1498],"style",{},"html pre.shiki code .sEgDM, html code.shiki .sEgDM{--shiki-light:#B392F0;--shiki-default:#FFCB6B;--shiki-dark:#B392F0}html pre.shiki code .s11XM, html code.shiki .s11XM{--shiki-light:#9ECBFF;--shiki-default:#C3E88D;--shiki-dark:#9ECBFF}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sJWha, html code.shiki .sJWha{--shiki-light:#79B8FF;--shiki-default:#C3E88D;--shiki-dark:#79B8FF}html pre.shiki code .s8K8j, html code.shiki .s8K8j{--shiki-light:#9ECBFF;--shiki-default:#89DDFF;--shiki-dark:#9ECBFF}html pre.shiki code .s8-mJ, html code.shiki .s8-mJ{--shiki-light:#79B8FF;--shiki-default:#EEFFFF;--shiki-dark:#79B8FF}",{"title":568,"searchDepth":588,"depth":588,"links":1500},[1501,1502,1503,1505,1507,1509,1511,1513],{"id":434,"depth":588,"text":435},{"id":556,"depth":588,"text":557},{"id":613,"depth":588,"text":1504},"btop, watching what the machine is doing",{"id":697,"depth":588,"text":1506},"duf, disk space that reads like a table",{"id":762,"depth":588,"text":1508},"ncdu, finding what ate the disk",{"id":849,"depth":588,"text":1510},"tldr, the manual without the 400 lines",{"id":928,"depth":588,"text":1512},"lazydocker, managing containers from the terminal",{"id":1259,"depth":588,"text":1514},"ufw, a firewall you can actually read",[1516],"Djeex","A handful of terminal tools worth installing on a home server, what each one replaces, and step-by-step instructions to install and use them.","md",null,{},{"title":91,"description":1517},"5yuNcsLkLrI2ZUiIM6r1qAhkCTvt4_x0hCj8yOPTJuA",[1524,1526],{"title":87,"path":88,"stem":89,"description":1525,"children":-1},"How the Debian filesystem is organised, what each top-level folder holds, how partitions differ from folders, and the habits that keep a server tidy.",{"title":101,"path":102,"stem":103,"description":1527,"icon":25,"children":-1},"Introduction to Serveex, a personal homelab project to self-host everyday services using Debian and Docker, replacing cloud services as Google, Apple or Netflix.",1788645845081]