Linux has one directory tree that starts at / (root), and every disk, partition and virtual filesystem is attached somewhere in it. There are no drive letters. The FHS (Filesystem Hierarchy Standard) describes what belongs where. Because nearly every distribution follows it, knowing the layout tells you where to look for a config file, a log or a device on any system you log into, and it helps you plan which directories deserve their own partitions.
/etc holds host-specific configuration, almost all of it plain text: /etc/fstab, /etc/passwd, /etc/ssh/sshd_config, /etc/hosts. If you want to change how something behaves on this machine, the file is probably under /etc, and it is the most important directory to back up. Many services also read drop-in directories such as /etc/sysctl.d/ or /etc/sudoers.d/, so local changes live in their own small files. /var holds variable data that grows while the system runs: logs in /var/log, mail and print spools in /var/spool, package caches in /var/cache, and application state such as databases and container storage in /var/lib. A full /var is a classic cause of failing services, which is why servers often give it a separate partition.
/usr contains the bulk of installed, read-only software and data shared by users: programs in /usr/bin, system administration programs in /usr/sbin, libraries in /usr/lib and /usr/lib64, and documentation and man pages in /usr/share. Software you compile yourself traditionally goes under /usr/local so the package manager never overwrites it. On most modern distributions /bin, /sbin and /lib are symbolic links into /usr (the 'usr merge'). /opt is for add-on software packages that install as a self-contained bundle, such as a vendor application in /opt/vendorapp with its own bin and lib inside.
/home holds users' personal directories, such as /home/alice, while the root user's home is /root, kept on the root filesystem so it is available even when /home fails to mount. /boot holds what the boot loader needs: kernel images (vmlinuz-*), initramfs images, and the GRUB configuration; on UEFI systems the ESP is mounted beneath it at /boot/efi. If /boot fills up with old kernels, updates can fail. Other directories worth knowing are /tmp for temporary files (often cleared at boot, and sometimes a RAM-backed tmpfs), /var/tmp for temporary files that must survive a reboot, /mnt for temporary manual mounts, /media for removable media, /srv for data served by the system, and /run for runtime data like PID files and sockets, which lives in RAM.
Three directories are virtual: they are not on disk at all but are generated by the kernel each boot. /proc is the process filesystem: each running process has a numbered directory such as /proc/1234 containing its command line, environment and open files, and files like /proc/cpuinfo, /proc/meminfo and /proc/sys/... expose kernel information and tunable parameters. /sys (sysfs) presents a structured view of devices, drivers and kernel objects, and it is where udev and tools like lsblk get their data. /dev contains device files, managed by udev, that represent hardware and pseudo-devices: /dev/sda and /dev/nvme0n1 for disks, /dev/null to discard output, /dev/zero for a stream of zero bytes, and /dev/urandom for random bytes.
Consider a worked example. A web server stops accepting uploads. You run df -h and see the filesystem mounted at /var is 100 percent full. du -sh /var/* | sort -h points to /var/log, and a second du shows one application's debug log has grown to many gigabytes. You rotate and compress the log, fix its logging level in the application's config under /etc, and uploads work again. Knowing the hierarchy took you straight to the right place instead of searching the whole disk.
Common mistakes: putting locally compiled programs in /usr/bin, where a package update can overwrite them, instead of /usr/local/bin; trying to free disk space by deleting files in /proc (they take no space and cannot be removed); storing data that must survive reboot in /tmp or /run; and confusing /root (root's home) with / (the root of the tree). Use man hier or man file-hierarchy to see the layout documented for your own system.
Exam questions usually give a file type and ask where it lives, or describe a symptom and ask which directory to check. 'Configuration for this host' means /etc. 'Logs, spools, growing data' means /var. 'Third-party self-contained application' means /opt. 'Kernel images and initramfs' means /boot. 'View CPU, memory or process details' or 'kernel tunables' point to /proc, 'device and driver attributes' point to /sys, and 'device files such as disks or /dev/null' point to /dev.
Key terms
- FHS
- Filesystem Hierarchy Standard: the convention that defines the purpose of top-level Linux directories.
- /etc
- The directory for host-specific configuration files.
- /var
- The directory for variable data such as logs, spools, caches and application state.
- /usr/local
- The area reserved for locally installed software that the package manager will not touch.
- /proc
- A virtual filesystem exposing process and kernel information, including tunables under /proc/sys.
- /sys
- Sysfs, a virtual filesystem exposing devices, drivers and kernel objects.
- /dev
- The directory of device files, such as /dev/sda and /dev/null, maintained by udev.
A web server stops accepting uploads. You run df -h and see that the filesystem mounted at /var is 100 percent full. du -sh /var/* points to /var/log, where an application's debug log has grown to many gigabytes. Rotating and compressing that log frees space, you lower the application's log level in its file under /etc, and uploads work again.
Check yourself
Where would you expect to find a program you compiled from source yourself, and why?
Under /usr/local (for example /usr/local/bin), because that area is reserved for locally installed software the package manager will not overwrite.
Which directory holds kernel images and initramfs files?
/boot, which the boot loader reads before the rest of the system is available.
What is /dev/null used for?
It is a device file that discards anything written to it, commonly used to throw away unwanted command output.
A vendor ships an application as a self-contained bundle with its own bin and lib folders. Where does the FHS say it belongs?
/opt, for example /opt/vendorapp, which is intended for add-on software packages.