Contents

Infrastructure & Operations › Linux & Servers

Users and Groups

How Linux controls who can do what.

Also known as: users and groups, uid gid, useradd usermod

Linux decides who can do what using users and groups. Every process runs as a user (a numeric UID) and one or more groups (a GID); root is UID 0 and can do almost anything. Each file has an owner, a group, and permission bits for reading, writing and executing — so “Permission denied” almost always comes down to identity plus permissions.

id                 # who am I: uid, gid, groups
whoami             # just the username
ls -l file.txt     # owner, group, bits
chmod 640 file.txt      # owner rw, group r, others none
chown app:app file.txt  # change owner and group
sudo -u app whoami      # run as another user

Creating and managing accounts:

useradd -m alice        # create a user with a home directory
passwd alice            # set a password
groupadd dev
usermod -aG dev alice   # add to a group (-a, or you replace the list)
groups alice

The -a in usermod -aG matters: without it you overwrite every group the user had.

The classic mistake is reaching for chmod 777 to make a permission error go away. It grants everyone full access and hides the real problem — usually the wrong owner. Fix the ownership or the group instead, and avoid running services as root; use a dedicated user and sudo only when needed (see sudo and root and least privilege).

Two details that bite: changing groups takes effect only after a fresh login, because the shell keeps its old membership; and a recursive chown -R on the wrong directory can break a system. Containers use the same model — a process runs as some UID, often root unless you say otherwise (see non-root containers). See file permissions.