Log Rotation Basics
logrotate compresses, renames and deletes old logs on a schedule — without it, log files grow until your disk dies at 3 AM.
Introduction
logrotate compresses, renames and deletes old logs on a schedule — without it, log files grow until your disk dies at 3 AM.
Beginner analogy: think of Unix as a kitchen. The shell is the chef who reads your order, the kernel is the stove and fridge that actually cook and store, files are the ingredients, and pipes are the conveyor belts moving food from one chef to the next. Every Unix command you learn is one well-designed kitchen tool.
In this lesson we will walk through Log Rotation Basics step by step, see exactly how Linux handles it under the hood, look at the practical commands you will type every day on real servers, study a real-world DevOps scenario, and finish with the interview questions you will absolutely face when applying to AWS, Google Cloud, Red Hat, Netflix, Stripe and every modern infrastructure team.
Understanding the topic
Core concepts to understand:
- 🧠 Clear definition and mental model of log rotation basics.
- 🐧 How the Linux kernel and shell collaborate to make it happen.
- 📂 Where files, processes and configuration live on a standard Linux server.
- 🔁 How log rotation basics fits inside scripts, cron jobs and CI/CD pipelines.
- 🛡 Permissions, users, groups and least-privilege practices around log rotation basics.
- 🚧 Common pitfalls: missing quotes, unset variables, wrong exit codes, dangerous
rm -rf. - 🏢 Real production scenarios at AWS, Netflix, Stripe and modern SaaS DevOps teams.
Syntax reference
Visual workflow / architecture:
User Command|vShell Interpreter|vCommand Parsing|vKernel Interaction|vSystem Resources|vCommand Execution|vTerminal Output
df -h && free -m && uptimePull live metrics from /proc and standard tools.
Informative example
Hands-on commands you can copy-paste:
A 5-line monitoring script can replace expensive tools. df -P outputs portable disk usage, awk filters partitions over the threshold, logger writes to syslog and mail alerts the on-call.
#!/bin/bash# disk-watch.sh — alert when any partition > 90%THRESH=90df -P | awk 'NR>1 {gsub("%","",$5); if ($5+0 > '$THRESH') print $6, $5"%"}' \| while read mount usage; dologger -t disk-watch "ALERT $mount at $usage"echo "ALERT: $mount $usage" | mail -s "disk full" ops@codone
Sample terminal output:
disk-watch[1234]: ALERT /var at 92%disk-watch[1234]: ALERT /home at 95%
Walk-through: notice how every Unix tool prints structured text and returns an exit code (0 = success, anything else = failure). That is the contract that lets you chain commands with &&, pipe them with |, and trust them inside automation. Reading these messages carefully is the difference between a senior Linux engineer and a junior one.
Real-world use
In production, Log Rotation Basics is part of every infrastructure engineer's daily flow at companies like AWS, Google Cloud, Netflix, Stripe, Shopify, GitHub and Red Hat. Engineers SSH into Linux servers, write small focused bash scripts, schedule them with cron or systemd timers, monitor them in Grafana and ship them through CI/CD. Mastering log rotation basics means safer deploys, faster incident response and dramatically fewer 3 AM pages.
Best practices
- Always start scripts with
#!/bin/bashandset -euo pipefailso they fail fast on errors and unset variables. - Quote variables:
"$file"not$file— protects against spaces and word-splitting bugs. - Use absolute paths in cron, scripts and systemd units —
$PATHis minimal in those environments. - Log to
/var/log/<app>/and rotate withlogrotateso disks never fill up. - Run as the least-privileged user; reserve
sudofor the few commands that truly need root.
Common mistakes
rm -rf $VAR/when$VARis empty — wipes the whole filesystem. Always quote and validate.- Cron jobs that run from a fresh shell with no
$PATH— your script works manually but fails at 2 AM. - Forgetting
2>&1on logs — silent failures because stderr was thrown away. - Editing config files without taking a backup (
cp file file.bak) — no way to roll back.
Hands-on exercise
Interview preparation — practice these questions:
- Q1. Explain Log Rotation Basics in one sentence as if to a junior teammate.
- Q2. Walk through the exact Linux commands you would run for log rotation basics on a production server.
- Q3. What is the difference between Unix and Linux, and where does log rotation basics live in the stack?
- Q4. How would log rotation basics behave inside a cron job vs an interactive shell, and why?
- Q5. Name two security or permission concerns around log rotation basics and how you would mitigate them.
- Q6. How does log rotation basics integrate with monitoring, logging and a CI/CD pipeline?
- Q7. Scenario: a 3 AM PagerDuty alert says log rotation basics failed in production. Walk me through your debugging.