Disks & storage
df, du, lsblk, partitions, filesystems, mount and /etc/fstab, and finding what fills a disk.
"No space left on device" is one of the most common production incidents. It breaks databases, deploys and even logins. In this lesson you'll learn how Linux sees disks, partitions and filesystems, how to check and investigate disk usage, and how to add and mount a new disk, including making it permanent with /etc/fstab.
Disks, partitions and filesystems#
- A block device is a disk:
/dev/sda(SATA/SCSI/virtio-scsi),/dev/nvme0n1(NVMe),/dev/vda(virtio, common in cloud VMs), or/dev/xvda(older AWS). - A disk is split into partitions:
/dev/sda1,/dev/sda2, or/dev/nvme0n1p1,/dev/nvme0n1p2(NVMe adds ap). Modern systems use a GPT partition table. - Each partition holds a filesystem: ext4 (the Debian/Ubuntu default), xfs (the RHEL default), btrfs (the Fedora Workstation default, with snapshots), or
vfat(the EFI boot partition). - A filesystem is attached to the directory tree at a mount point. There are no drive letters: a second disk might appear at
/dataor/mnt/backup.
Layers like LVM (logical volumes you can resize) and LUKS (encryption) can sit between partitions and filesystems.
lsblk: what disks do I have?#
Here sdb is a new, empty 100 GB disk with no partitions or mount point yet. Add -f to see filesystems and UUIDs:
sudo blkid also prints UUIDs, and sudo fdisk -l shows detailed partition tables.
df: how full are my filesystems?#
-hgives human-readable sizes;-Tadds the filesystem type;df -h /varreports just the filesystem that holds/var.tmpfsfilesystems live in RAM and vanish at reboot.- Ext4 reserves about 5% for root by default, so
Used + Availcan be less thanSize.
Inodes can run out too. Millions of tiny files (cache, sessions, mail queues) can exhaust inodes while plenty of bytes are free. You'll still get "No space left on device":
du: what is using the space?#
df tells you that a disk is full; du tells you what filled it. Let's create some test data:
-sgives a summary (one total),-hhuman-readable sizes, and--max-depth=1(or-d 1) one level of subdirectories.sort -hunderstandsK,M,Gsuffixes, so the biggest items end up at the bottom.
The classic "who's eating my disk?" hunt on a server:
Usual suspects are /var/log (logs), /var/lib/docker (images and containers), /var/lib/mysql or /var/lib/postgresql (databases), /var/cache/apt (sudo apt clean), old kernels (sudo apt autoremove), ~/.cache, and core dumps.
Find large individual files with find:
💡
ncdu(sudo apt install ncdu) is an interactive, navigabledu, the fastest way to explore a full disk.
The deleted-but-open file trap
If df says the disk is full but du doesn't add up, a process may still be writing to a file you deleted (commonly a huge log removed with rm). The space is only freed when the process closes it:
Restart that service to release the space. Next time, truncate instead of deleting a live log: sudo truncate -s 0 /var/log/app.log (or : > file).
Adding a new disk#
Suppose you attached the 100 GB sdb from above (a cloud volume, say). The steps are partition, format, mount, then make it permanent.
⚠️ Double-check the device name with lsblk first. These commands destroy any data on the device you point them at.
1. Partition it
(sudo fdisk /dev/sdb and sudo cfdisk /dev/sdb are interactive alternatives.)
2. Create a filesystem
3. Mount it
findmnt /data or plain mount | grep sdb shows what's mounted where. Unmount with sudo umount /data. If you get "target is busy", something is using it: cd out of it, or find the culprit with sudo lsof +f -- /data or fuser -vm /data.
4. Make it permanent with /etc/fstab
/etc/fstab lists filesystems to mount at boot. Get the UUID with sudo blkid /dev/sdb1, then add a line:
Test before you reboot. A broken fstab can drop the machine into emergency mode:
Swap#
Swap is disk space used as overflow when RAM is full. It's slow, but it prevents sudden out-of-memory kills. Check it with swapon --show and free -h. To add a 2 GB swap file:
(On btrfs, swap files need extra steps. Fedora uses compressed RAM swap, zram, by default.)
Health and maintenance#
sudo smartctl -a /dev/sda(packagesmartmontools) shows a physical disk's SMART health and error counters.sudo fsck -f /dev/sdb1checks and repairs an unmounted filesystem. Never run it on a mounted one.- Growing a cloud disk: resize the volume in the provider's console, then run
sudo growpart /dev/sda 3andsudo resize2fs /dev/sda3(ext4) orsudo xfs_growfs /(xfs). With LVM, usesudo lvextend -r -l +100%FREE /dev/ubuntu-vg/ubuntu-lv.
Common mistakes#
- Running
mkfs,partedorddon the wrong device. Always checklsblkfirst;/dev/sdais often your system disk. - Using
/dev/sdXnames in fstab. UseUUID=. - Rebooting without
mount -aafter editing fstab, and finding an unbootable server. - Deleting a live log file with
rmand wondering why space didn't come back. Truncate it instead, or restart the writer. - Forgetting inodes. Check
df -iwhen "disk full" makes no sense. - Mounting over a non-empty directory. The old files are hidden (not deleted) until you unmount.
What's next#
A lot of disk space goes to logs, and they're also your best debugging tool. Next: where logs live, how to search them, and how logrotate keeps them under control.
Check your understanding
Quick quiz
1.Which command shows free space per mounted filesystem in human-readable units?
2.Why should /etc/fstab entries use
UUID=...rather than/dev/sdb1?3.
dfsays the disk is full, butduon all your directories adds up to much less. A likely cause?
Finished reading?
Mark this lesson complete to track your progress.