Chapter 4: Linux Ops Refresh for DevOps
4.2 Paths and permissions — enough to stay safe
You move through directories all day.
pwd # where am I?
ls -la # list including hidden; see permissions
cd /var/log # absolute path
cd ~/badge-api-hello # home-relative
Permission triplet on a file (simplified): owner / group / others, each with read (r), write (w), execute (x). Directories need execute to "enter."
| Habit | Why |
|---|---|
| Prefer ownership fix over world-writable | Shared write for everyone is unsafe |
| App files: sensible owner (e.g. service user) | Matches how Nginx / Node / Python run |
| Secrets: tight mode (owner read only) | .env and keys are not public pages |
Do not "fix" permission problems with world-writable modes for everyone. Prefer chown to the correct user/group and modest modes (for example directories traversable by the service user, files readable as needed). The style we follow on this site: never teach reckless open permissions as a shortcut.
Ravindra Bagale's Tip
Khup students permission error yetach saglyana write open kartat. Te fix nahi — risk aahe. chown / correct user, mag ls -la ne verify. Bilkul visru naka.
Practice task
Read ls -la on any project folder. Name the owner column, the group column, and one file you would not want every user on the machine to write.