sudo
- Pronunciation
- SOO-doo
In short
sudo lets a permitted user run a single command with root's or another user's privileges, after confirming their own password, and logs what was run.
What is sudo?
On Linux, macOS and other Unix-like systems the root user can do anything, so working as root all the time is risky: one mistyped command can damage the whole system. With sudo you work as an ordinary user and raise your privileges only for the commands that need them, by putting sudo in front, as in sudo apt update. It asks for your own password, not root's, and then runs that one command as root.
Who may use sudo, and for which commands, is set in the sudoers file, /etc/sudoers. On many distributions the members of a group such as sudo or wheel may run anything, but rules can also be narrow, such as letting a deploy user restart one service and nothing else. The file is edited with visudo, which checks the syntax before saving, since a broken sudoers file can lock everyone out of administration. Every use is logged, so administrators can see who ran what.
Its name is usually read as superuser do, and with -u it runs a command as any user, as in sudo -u postgres psql. After you type your password, sudo remembers it for a few minutes, 5 by default, so a series of commands doesn't keep asking. sudo was first written around 1980 at SUNY Buffalo, and today it is why systems such as Ubuntu and macOS can keep the root account locked: administrators work through sudo instead.
Key takeaways
- sudo runs one command with root's, or another user's, privileges.
- It asks for your own password and logs every use.
- The sudoers file, edited with
visudo, says who may run what. - Working as an ordinary user and using sudo only when needed limits the damage of mistakes.
Example
apt update # as an ordinary user: fails with "Permission denied"
sudo apt update # asks for your password, then runs as root
sudo -u postgres psql # run a command as another user
sudo -l # list what you are allowed to run
sudo visudo # edit /etc/sudoers, with a syntax check before savingReaders ask
What is the difference between sudo and su?
su switches to another account, usually root, and needs that account's password; you then stay root until you exit. sudo runs one command with raised privileges and needs your own password, so root's password never has to be shared and every command is logged.
Why does sudo say I am not in the sudoers file?
Your account hasn't been given sudo rights on that machine. An administrator can add you to the admin group, such as sudo on Ubuntu or wheel on Fedora, or add a rule for you to the sudoers file.
See also
- LinuxDevOps & Cloud, p. 33Linux is an open-source operating system kernel that powers most servers, cloud platforms, containers, and Android phones, usually packaged as a distribution.
- UnixOperating Systems, p. 34Unix is a family of operating systems that began at Bell Labs in 1969 and whose design, with small tools, files and a shell, lives on in Linux and macOS.
- File PermissionsOperating Systems, p. 11File permissions are rules stored with each file that decide which users may read it, change it, or run it, enforced by the operating system on every access.
- ShellOperating Systems, p. 27A shell is a program that reads commands typed by a user or written in a script and asks the operating system to run them, usually through a text interface.
- TerminalOperating Systems, p. 32A terminal is the program that shows a text interface, passing your keystrokes to a shell or command-line program and displaying the text it sends back.
- Principle of Least PrivilegeSecurity, p. 28The principle of least privilege is a security rule that every user, program, and service gets only the minimum access it needs to do its job, and no more.
- Command Line InterfaceOperating Systems, p. 2A command line interface (CLI) is a text-based way of using a computer: you type a command with options and arguments, press Enter, and read its output.
Sources
Spotted a mistake or something missing on this page?Suggest an edit