Linux Disk Full: Find What's Using Space and Free It

1. Find what's using the space

df -h                              # which filesystem is full
df -i                              # full of inodes instead of bytes?
sudo du -hxd1 / | sort -h          # biggest folders in /
sudo du -hxd1 /var | sort -h       # drill down into the biggest one
sudo find / -xdev -type f -size +500M -exec ls -lh {} \;

ncdu -x / does the same interactively.

2. Usual suspects

sudo journalctl --vacuum-size=200M          # systemd journal
sudo apt-get clean                          # APT package cache
sudo apt autoremove --purge                 # old kernels and orphan packages
sudo find /var/log -name "*.gz" -delete     # rotated, compressed logs

Old snap revisions:

snap list --all | awk '/disabled/{print $1, $3}' | while read name rev; do sudo snap remove "$name" --revision="$rev"; done
sudo snap set system refresh.retain=2

3. Docker container logs

A chatty container can fill the disk with its JSON log:

sudo du -sh /var/lib/docker/containers/*/*-json.log
sudo truncate -s 0 /var/lib/docker/containers/<id>/<id>-json.log
docker system df

Limit log size for good in /etc/docker/daemon.json:

{
  "log-driver": "json-file",
  "log-opts": {
    "max-size": "100m",
    "max-file": "3"
  }
}

sudo systemctl restart docker. It only applies to containers created after the change, so recreate them (docker compose up -d --force-recreate).

4. Space not freed after deleting?

A process still holds the deleted file open. Find it and restart that service:

sudo lsof +L1

Related: extend the disk instead.

Written by Daniel Ruiz Peláez, Systems & Infrastructure Engineer (Linux, VMware, Proxmox, Active Directory, networking and security). These are notes from real problems I have solved.

← Back to all posts