learninfra · Linux · Networking · Kubernetes · System Design · AI Infrastructure · Exam blueprints · Drills

Users, Groups & sudo

A user is a number, a group is a list of numbers, and sudo is a rule file. Read all three and you can say exactly who may do what.

An interactive Linux lesson: 25 steps, about 32 minutes, on a live simulation in your browser.

You are alice, the administrator of web01, the machine that serves the shop's website. Three jobs are waiting: a new hire needs an account, bob needs to restart the web server without being handed the whole machine, and a contractor has left.

Every one of those is a question about identity, so start with your own. whoami prints a name. id prints what the kernel actually holds for this shell.

What you will learn

  1. You are a number

    • Who does the machine think you are?: Every process carries one uid and a list of group ids. Those numbers, and nothing else, are who you are to the kernel.
    • The name is a lookup: Files and processes store uids. Names exist in one lookup table and are translated only when something is printed.
  2. Three files hold every account

    • /etc/passwd, field by field: /etc/passwd is name:x:uid:gid:comment:home:shell. It answers who an account is, never what its password is.
    • Where the password really lives: /etc/passwd is public so that names can be looked up. The hashes were moved to /etc/shadow so that only root can read them.
    • Groups: one primary, any number more: Primary group: one, from /etc/passwd, stamped on the files you create. Supplementary groups: many, from /etc/group. Access checks use all of them.
    • Accounts nobody logs in to: A system user is an identity for a program. A nologin shell stops anyone logging in as it and changes nothing about what it may run as.
  3. Creating and changing accounts

    • Break it: useradd with no flags
    • useradd -m -s, then passwd: useradd writes lines in three files. -m is what creates the home directory; without it the home is only a field.
    • Put people in groups: Grant access to groups, then manage people by moving them in and out of groups.
    • usermod -G without -a: usermod -G means "the supplementary groups are exactly these". Only -aG means "add these".
    • Drill: put bob back
  4. Groups are fixed at login

    • In the group, and still refused: A process's groups are a copy taken at login. Changing /etc/group changes the next login, never a running shell.
    • newgrp, or log in again
  5. Becoming someone else

    • Break it: su asks for their password: su asks for the target account's password. If you would need to share a password to use it, it is the wrong tool.
    • su versus su -: su NAME changes the uid and keeps where you were. su - NAME starts that user's login shell from scratch.
    • sudo: one command, as root, logged: sudo checks your identity against a rule file, runs one command as the target user and writes down who asked.
  6. How sudo decides

    • The rule that makes you an admin: A sudoers rule reads: who, on which host = (as which user) which commands. Being an admin on Ubuntu means being in group sudo.
    • Break it: bob restarts nginx
    • Grant one command, to a group: Least privilege in sudo is a rule that names a group and the full path of one command, not membership of the sudo group.
    • How narrow is narrow?
  7. When someone leaves

    • Lock first, delete later: Locking an account puts ! in front of its hash. It blocks the password and leaves every other way in open.
    • Drill: close the other door
    • Delete the user, keep the number: Deleting a user deletes a name. Files keep the uid, and the next account given that uid owns them.
  8. Recap & playground

    • Cheat sheet
    • Playground