Free systemd first contact
Learn the systemd evidence loop: list units, read state, inspect status, read unit files, control lifecycle, enable boot intent, verify, and read journal logs.
10 focused lessonsTrue zero to service operator
Operate services from state, definition, action, and evidence.
Learn systemd by inspecting units, controlling services safely, reading logs, repairing failures, and handing off verified evidence.
No credit card for the free chapter. Preview what the chapter covers.
By the end
Syllabus
The focused path contains 65 required lessons. The advanced library remains available when your role needs more depth.
Learn the systemd evidence loop: list units, read state, inspect status, read unit files, control lifecycle, enable boot intent, verify, and read journal logs.
10 focused lessonsClassify unit types, separate loaded units from installed unit files, read LOAD, ACTIVE, SUB, and UnitFileState, and inspect failed units without guessing.
5 focused lessons + 7 advanced lessonsRead [Unit], [Service], [Install], Type, ExecStart, User, Restart, result fields, hooks, and repair a broken local service draft with verification.
3 focused lessons + 9 advanced lessonsRead system unit load paths, verify and install a local unit, prove pre-reload versus post-reload manager state, and separate service reload from daemon-reload.
8 focused lessons + 4 advanced lessonsSeparate active from enabled, inspect WantedBy and target membership, use enable --now deliberately, disable without stopping, and mask unwanted activation.
6 focused lessons + 6 advanced lessonsTurn journal output into evidence: scope by unit and boot, filter priority and message, bound time, inspect structured fields, and capture an incident packet.
6 focused lessons + 6 advanced lessonsSeparate need edges from ordering edges, inspect forward and reverse dependency trees, observe Requires and PartOf behavior, and repair a missing After edge with verification.
7 focused lessons + 5 advanced lessonsRead timer and service pairs, list next-run evidence, validate calendar expressions, understand monotonic and persistent timers, and replace a cron-like job safely.
5 focused lessons + 7 advanced lessonsChange package-owned units safely with drop-ins: inspect merge order, reset ExecStart correctly, audit deltas, revert changes, reload, restart, and prove the result.
3 focused lessons + 9 advanced lessonsDiagnose restart loops, rate limits, failed-state cleanup, notify readiness, READY=1 evidence, watchdog timeouts, and safe repaired-service proof.
5 focused lessons + 15 advanced lessonsTriage a broken service from evidence: read status, state, logs, dependencies, unit definitions, and environment; verify the repair, reload, restart, and prove recovery.
7 focused lessons + 15 advanced lessonsThese chapters provide optional drills and reference depth. They are not required to complete the focused path.
Read socket and path trigger units, prove lazy service activation from traffic and filesystem events, handle Accept=yes templates, and repair a broken path activation pair.
12 advanced lessonsRead cgroup placement, slice policy, CPU share and quota, memory throttle and hard limits, task ceilings, live cgroup pressure, and repair a noisy worker with verification.
12 advanced lessonsReduce service blast radius with filesystem isolation, private temp, non-root identity, no-new-privileges, capability bounding, filters, verification, reload, start, security scoring, and journal evidence.
12 advanced lessonsMake service configuration explicit with direct environment, environment files, working directories, runtime files, durable state, cache, logs, configuration directories, curated inheritance, verification, and runtime proof.
12 advanced lessonsUse @.service templates for many similar services, start concrete instances, inspect expanded properties, escape unsafe names, scope drop-ins, enable default instances, debug failed instances, repair templates, and prove runtime behavior.
12 advanced lessonsOperate per-user systemd managers with --user unit paths, default.target enablement, user journals, lingering, user manager reloads, and repaired user service proof.
12 advanced lessonsInvestigate slow boot with timing summaries, blame caveats, critical chains, explicit target proof, target status, job queues, plot artifacts, dependency graphs, and evidence reports.
12 advanced lessonsClassify targets, mounts, automounts, swaps, devices, paths, sockets, slices, and scopes, then prove their state with the right evidence surface.
14 advanced lessonsRun one-off managed work with systemd-run, inspect transient services and scopes, prove resource policy, read logs, and clean up deliberately.
18 advanced lessonsOperate logs as evidence with storage policy, disk usage baselines, boot IDs, structured fields, JSON exports, verification, vacuuming, and audit-ready packets.
17 advanced lessonsShip systemd units safely with package-owned files, administrator boundaries, validation, manager reloads, preset policy, enablement proof, runtime evidence, and rollback notes.
21 advanced lessonsChange a healthy service with baseline evidence, risk review, a minimal drop-in, verification, stale and loaded manager proof, reload, restart, journal evidence, revert, and rollback proof.
22 advanced lessonsProve professional systemd operation by completing inventory, incident repair, validation, recovery proof, scheduled and on-demand activation checks, transient work, resource pressure review, hardening, change control, rollback, and final report evidence.
45 advanced lessonsCollect host-context evidence before acting: version, operating-system identity, unit paths, virtualization, container boundaries, condition-aware units, verification, service inventory, and a final field-readiness report.
13 advanced lessonsReplace environment-secret habits with credential-delivery evidence: risky-unit contrast, LoadCredential review, verification, reload, loaded properties, safe logs, systemd-creds inspection, encrypted metadata, and final report proof.
14 advanced lessonsPrepare service users, groups, runtime directories, durable state paths, log paths, cache cleanup, service verification, manager reload, runtime start, journal proof, and a final declarative host-state report.
17 advanced lessonsTrace fstab-generated mount units from source config through generator execution, daemon-reload, generated fragments, SourcePath and FragmentPath properties, local-fs dependencies, validation, journal evidence, and final report proof.
17 advanced lessonsEnter recovery targets deliberately with default-target proof, target inventory, AllowIsolate properties, rescue and emergency isolation, constrained active-unit evidence, journal proof, return to default, and final report proof.
17 advanced lessonsInvestigate a crashed service from status and journal evidence through coredumpctl inventory, metadata, PID proof, exported core artifacts, debugger stack evidence, retention policy, collector socket proof, service properties, and final report proof.
16 advanced lessonsRead the systemd manager's live operational state, queued jobs, job wait direction, job properties, service status, recent logs, safe cancellation order, degraded state, failed-unit inventory, manager properties, daemon-reload, daemon-reexec, and final health report proof.
17 advanced lessonsInspect systemd through D-Bus with busctl peer discovery, service owner status, object trees, manager introspection, typed manager properties, GetUnit, unit object state, Service MainPID, GetJob, job object state, and final API evidence proof.
15 advanced lessonsWire and inspect failure escalation with OnFailure, OnFailureJobMode, handler templates, specifier context, paired verification, daemon-reload, controlled source failure, handler execution, source and handler journals, completion properties, incident notes, and final gate proof.
14 advanced lessonsApply shared service policy safely with service-wide drop-ins, dash-prefix API drop-ins, handler recursion guards, paired verification, daemon-reload, DropInPaths proof, representative runtime evidence, journal proof, systemd-delta audit, and final fleet policy gate proof.
15 advanced lessonsUse start-time guardrails safely with ConditionPathExists, AssertPathExists, systemd-analyze condition preflight, skipped condition proof, assert-abort proof, exact loaded properties, prerequisite repair, successful retry evidence, journal proof, and final gate proof.
17 advanced lessonsOperate shutdown and signal workflows safely with KillMode, KillSignal, FinalKillSignal, SendSIGKILL, TimeoutStopSec, ControlGroup evidence, graceful stop proof, timeout escalation proof, targeted systemctl kill signals, active-state proof, journal proof, and final gate proof.
15 advanced lessonsUse DynamicUser safely with managed writable directories, loaded property proof, active identity proof, private path proof, unsafe arbitrary-write contrast, repaired managed-path service proof, journal evidence, and final gate proof.
16 advanced lessonsProve service filesystem views with RootDirectory, RootImage, read-only binds, temporary filesystems, explicit writable paths, MountAPIVFS, broken-image contrast, fixed-image repair, loaded property proof, journal evidence, and final gate proof.
17 advanced lessonsHandle memory pressure and OOM behavior with MemoryAccounting, MemoryHigh, MemoryMax, OOMPolicy, Restart, MemoryCurrent, throttling proof, OOM failure proof, repaired limits, loaded property proof, journal evidence, and final gate proof.
17 advanced lessonsProve socket activation and descriptor handoff with ListenStream, Accept=no, Accept=yes, paired services, template instances, sd_listen_fds, FileDescriptorStoreMax, fdstore count, loaded property proof, journal evidence, and final gate proof.
20 advanced lessonsOperate portable service images with portablectl inventory, inspect, runtime attachment, profile and RootImage proof, service execution, read-only and quota policy, versioned reattach, clean detach, and the boundary between portable services and system extensions.
22 advanced lessonsDiagnose systemd networking as separate link, policy, DHCP, DNS, daemon, and ordering layers with networkctl, systemd-networkd, systemd-resolved, resolvectl, wait-online, journals, and explicit readiness limits.
22 advanced lessonsOperate lightweight systemd machines with nspawn image and .nspawn inspection, machined registration, machinectl runtime state, guest access, file transfer, bind exposure, machine-scoped journals, and clean shutdown proof.
22 advanced lessonsDiagnose systemd time as separate clock, NTP policy, timesyncd, source, synchronization, wait-sync, time-sync.target, timestamp parsing, calendar parsing, and consumer-ordering evidence.
21 advanced lessonsTrace kernel device events through systemd-udevd, udev database properties, rules, verification, dry-run testing, reload and scoped trigger planning, queue settlement, systemd .device units, and mount dependency evidence.
21 advanced lessonsTrace early-boot module intent, loader state, modprobe dependency plans, live module presence, sysctl policy and precedence, scoped application, kernel command-line context, udev follow-up timing, and journal-backed kernel readiness.
19 advanced lessonsTrace systemd-boot installation, EFI and entry inventory, normal and recovery payloads, persistent defaults, one-shot selection, kernel image identity, current command-line handoff, and early-boot evidence.
18 advanced lessonsInspect UKI sections, Secure Boot acceptance, TPM capability, current and expected PCR values, signed expectations, event-log correlation, pcrlock prediction, and policy review.
18 advanced lessonsOperate systemd-sysupdate with transfer definitions, A/B versions, acquisition, pending activation, repart previews, discoverable images, Verity pairing, offline installation, and scheduling evidence.
19 advanced lessonsOperate systemd-sysext and systemd-confext with compatibility metadata, image inspection, read-only overlays, merge and unmerge state, visible payload proof, refresh gaps, and service reload boundaries.
21 advanced lessonsInterpret crypttab, inspect LUKS2 metadata, trace generated cryptsetup units, enroll and verify TPM2 policy, prove mapper and journal evidence, preserve recovery paths, remove one token safely, and separate LUKS confidentiality from dm-verity integrity.
21 advanced lessonsInterpret veritytab, trace systemd-veritysetup-generator and generated units, align image and sysupdate Verity resources, issue precise attach requests, prove active mapper and journal evidence, detach safely, inspect explicit root-hash views, and keep dm-verity integrity separate from LUKS encryption and filesystem mounts.
21 advanced lessonsBuild a precise userspace OOM model from PSI and swap policy, verify systemd-oomd availability, trace oomd.conf and drop-in precedence, inspect ManagedOOM policy on a slice, compare oomctl context before and after a bounded pressure scenario, correlate the journal reason with the affected service, audit safety, clean up, and keep userspace oomd separate from kernel OOM, MemoryMax, and OOMPolicy.
21 advanced lessonsBuild a safe post-reboot pstore workflow from zero: verify the systemd-pstore oneshot, separate boot intent from completion, trace pstore.conf and drop-in retention, inspect backend capacity and source records, process fixtures without inducing a panic, correlate journal and external archive evidence, preserve identity, reclaim retained source space, and write an auditable custody report.
21 advanced lessonsBuild a zero-knowledge systemd-homed workflow: verify the manager, separate boot enablement from user state, trace homed.conf defaults and drop-in precedence, inspect a self-contained JSON user record through homectl and userdbctl, compare the NSS projection, activate and prove the home mount, model lock and unlock without exposing credentials, deactivate safely, and verify that inactivity is not deletion.
22 advanced lessonsTrace systemd-userdbd from manager status and static .user and .group sources through userdbctl's multiplexer, membership direction, provider isolation, explicit io.systemd.DropIn selection, nsswitch policy, compact getent projections, journal correlation, and unit verification without confusing lookup with authentication or authorization.
21 advanced lessonsTrace systemd-logind from manager and logind.conf policy through loginctl session, user, seat, and inhibitor records, pam_systemd scope boundaries, journal correlation, and unit verification without confusing login state with authentication, service health, or authorization.
21 advanced lessonsTrace the per-user manager from user@1000.service and user-runtime-dir@1000.service through systemd-analyze --user unit paths, systemctl --user targets and unit files, manager environment, user slice limits, daemon-reload, user journal evidence, linger policy, user-scope verification, and final service state without confusing it with PID 1 or a login session.
21 advanced lessonsTrace systemd-logind and sleep.target through suspend, hibernate, suspend-then-hibernate, sleep.conf precedence, kernel and seat capabilities, authorization outcomes, active inhibitors, PrepareForSleep journal events, transition status, verification, and safe non-destructive power evidence.
21 advanced lessonsTrace safe shutdown and reboot inspection from command surfaces through shutdown, reboot, and poweroff targets, transition services, halt, kexec, soft-reboot, inhibitors, scheduled requests, jobs, journals, final hooks, verification, and non-destructive evidence.
22 advanced lessonsPrepare cloned systems safely by separating machine ID, hostname, machine-info metadata, locale, console keymap, timezone, running-host inspection, offline systemd-firstboot initialization, verification, reset, and report evidence.
24 advanced lessonsTrace early userspace from kernel command-line inputs through initrd markers, special initrd targets, generated sysroot mounts, /sysroot validation, switch-root service evidence, initrd journal chronology, failure recovery, static verification, and the post-handoff boundary.
24 advanced lessonsTrace counted boot entries from /etc/kernel/tries and kernel-install through boot-loader attempt counters, boot-complete.target, no-failures and custom health gates, systemd-bless-boot.service, generator wiring, bootctl entry state, fallback behavior, and journal evidence.
25 advanced lessonsTrace boot randomness from kernel entropy and boot ID through systemd-random-seed.service, /var/lib/systemd/random-seed rotation, systemd-boot-random-seed.service, bootctl random-seed, EFI random-seed state, system token protection, command-line seed warnings, VM virtio-rng evidence, copied-image hygiene, entropy-dependent service ordering, and journal proof.
25 advanced lessonsTrace journal custody from local systemd-journald collection, disk usage, verification, boot IDs, export streams, namespaced journals and LogNamespace, systemd-journal-remote receiving, remote journal file queries, systemd-journal-upload sending, gateway HTTP access, and custody checklist proof.
25 advanced lessonsTrace Forward Secure Sealing from capability checks and Seal policy through journalctl --setup-keys, off-host verification-key custody, rotation, flush, verify-key validation, archived-file verification, tamper failure handling, unsupported-build fallback, off-host archive evidence, limitations, remediation, and final audit checklist.
25 advanced lessonsTrace structured journal evidence from systemd-cat writer options through tagged records, priorities, level-prefix behavior, verbose fields, MESSAGE_ID queries, unit and invocation filters, PID context, time windows, export output, cursor custody, catalog explanations, catalog index updates, redaction policy, and final report proof.
25 advanced lessonsTrace manager environment evidence from show-environment through temporary set/import/unset operations, static /etc/environment and environment.d sources, system environment generators, debug output, runtime overrides, daemon-reload, generated readback, PassEnvironment and UnsetEnvironment service boundaries, runtime journal proof, ordering, masking, safety, and final report readiness.
25 advanced lessonsTrace systemd password prompts from request creation through hidden input, no-tty agent routing, timeout policy, cache key names, pending request listing, agent query and watch modes, cryptsetup waiting status, redacted journal evidence, recovery runbooks, failure taxonomy, incident packets, and final secret-safe reporting.
25 advanced lessonsTrace image transfer custody from importctl help and importd service ownership through machine image baselines, signed pulls, transfer progress, importd journal proof, machinectl handoff, portable raw imports, portablectl inspection, export artifacts, cancellation, sysext pulls, class maps, verification policy, remote boundaries, cleanup, audit packets, and final reporting.
25 advanced lessonsFull access
Every available offer is shown with its exact CAD price and billing model. Checkout opens only after you choose an offer and enter the receipt email.
Questions
Free systemd first contact is free and contains 10 lessons. No credit card is requested before the free workspace opens.
No systemd experience is required. Basic Linux terminal familiarity is helpful.
65 required lessons, with 10 free and 55 included in paid access.
Yes. The course also includes 1224 advanced practice and reference resources. They are available when you need more depth, but they do not lengthen the required path.
Academy Founder Annual: CA$139 per year. Founder Vault: CA$279 one-time.
Academy Founder Annual: Access continues while the annual subscription remains active. Founder Vault: No recurring charge. Coverage includes courses launched during the first 24 months.
The published estimate is 12 to 14 active hours. Your pace will depend on how much you repeat the practice.
No installation is required to start the guided free chapter. Later lessons explain the real tools, files, and operating boundaries relevant to the skill.
The syllabus and these stated outcomes are the source of truth: Explain systemd as the PID 1 manager of units, jobs, runtime state, and boot intent; Inventory units and distinguish load, active, sub-state, and unit-file state; Read service definitions and normalized properties before changing lifecycle state; Verify and load local unit changes with the correct manager reload sequence; Prove enablement, targets, dependencies, ordering, and timer behavior; Build focused journal evidence with unit, boot, priority, message, and time filters; Diagnose restart loops and clear failed state only after preserving the cause; Repair a service incident and deliver an audit-ready troubleshooting handoff.
Use a current browser with JavaScript enabled. The free chapter is the quickest compatibility check for your device.
The reading pages reflow for small screens. Command-heavy practice is more comfortable with a physical keyboard and a larger display.
The practice state is isolated from production systems. Read the resulting evidence, revise the action, and try again.
Use the receipt email on the restore-access page. The sign-in link verifies the account before paid entitlements are loaded.