{
 "id": "bash-linux-admin",
 "kind": "skill",
 "name": "Linux and shell administration",
 "description": "Linux server administration and shell scripting (Alma/Rocky/RHEL, Ubuntu/Debian, Fedora) plus Windows cmd/PowerShell basics. Use for shell commands, scripts, services, firewall, SELinux, permissions.",
 "version": "1.0.0",
 "author": "Hexa Hub",
 "files": {
  "SKILL.md": "---\nname: bash-linux-admin\ndescription: Linux server administration and shell scripting (Alma/Rocky/RHEL, Ubuntu/Debian, Fedora) plus Windows cmd/PowerShell basics. Use for shell commands, scripts, services, firewall, SELinux, permissions.\ntitle: Linux and shell administration\nicon: tabler:terminal-2\ncategory: Administration\n---\n\n# Linux admin and shell\n\n## First: know the target\nDistro family changes the answer. RHEL-family (AlmaLinux, Rocky, RHEL, Fedora): `dnf`, `firewalld`, SELinux on.\nDebian-family (Ubuntu, Debian): `apt`, `ufw`/`nftables`, AppArmor. If it matters and is unknown, ask or give both.\n\n## Safety rules for commands that change things\n- Show the command and say what it changes. Prefer read-only checks first (`systemctl status`, `ss -tulpn`, `df -h`).\n- Use dry-run/check modes when they exist (`dnf --assumeno`, `rsync -n`, `ansible --check`).\n- Back up before editing config: `cp -a file file.bak.$(date +%F)`. Validate config before reload (`nginx -t`, `sshd -t`,\n  `apachectl configtest`, `visudo -c`).\n- Never lock yourself out: before firewall/sshd changes, keep a second session open and don't remove the rule you are using.\n- No `curl ... | bash`, no `chmod -R 777`, no `rm -rf` with an unquoted or possibly empty variable.\n\n## Scripts\n```bash\n#!/usr/bin/env bash\nset -euo pipefail\n```\nQuote every variable (`\"$var\"`), use `[[ ]]`, `mktemp` for temp files, `trap` for cleanup, functions for repeated\nlogic, `local` in functions. Check scripts with `shellcheck`. Use `getopts` or a `case` loop for options.\n\n## Handy facts\n- Services: `systemctl status|enable --now|restart <unit>`; logs `journalctl -u <unit> -n 100 --no-pager -f`.\n- Timers over cron when possible (`systemctl list-timers`). Cron: check `crontab -l`, use absolute paths.\n- Ports/processes: `ss -tulpn`, `lsof -i :PORT`. Disk: `df -h`, `du -xh --max-depth=1 / | sort -h`.\n- Permissions: `namei -l path`, `stat`, `getfacl`. Ownership of web roots matters more than modes.\n- SELinux denial suspected: `getenforce`, `ausearch -m avc -ts recent`, `restorecon -Rv <path>`,\n  `semanage fcontext`, `setsebool -P`. Do not just disable SELinux; fix the label or boolean.\n- Firewalld: `firewall-cmd --list-all`, `--permanent --add-service=...`, then `--reload`.\n\n## Windows shell\nPowerShell: objects, not text (`Get-ChildItem | Where-Object ... | Select-Object`), `-WhatIf`/`-Confirm` on changes,\nquote paths with spaces, `$LASTEXITCODE` for native programs. cmd/batch: `%VAR%`, `if errorlevel`, `setlocal`.\nDocs: learn.microsoft.com.\n"
 }
}
