Alibaba Cloud Account How to Find What Is Taking Up Disk Space on ECS Linux

Alibaba Cloud / 2026-05-14 19:06:03

{ "description": "Feeling overwhelmed as your ECS Linux disk space vanishes faster than snacks at a birthday party? Fear not! This guide arms you with battle-tested commands (du, df, find) and GUI tools to track down disk hogs with surgical precision. We’ll walk you through common pitfalls, safe cleanup techniques, and pro tips to prevent future space crises. No confusing jargon—just straightforward steps to keep your server running smoothly. Grab your virtual shovel and dig into the details below!", "content": "

Introduction: When Your Disk Space Disappears Like Magic

\n

Picture this: you're working on your ECS Linux server, minding your own business, when suddenly your disk usage shoots up to 99%. Panic sets in—did you just get hacked? Did a ghost start hoarding files? Well, maybe not a ghost, but definitely a hidden culprit. This guide is your detective toolkit to track down those space-eating monsters without needing a PhD in sysadmin stuff.

\n

Whether you're dealing with a production server or just a personal cloud instance, knowing how to find what's eating up disk space is like having a flashlight in a pitch-black room. Let's get to it—no more guessing, no more guessing, just cold, hard facts from the command line (and a few GUI tools for the faint of heart).

\n\n

Du: Your Disk Usage Sidekick

\n

The du command is like the Swiss Army knife for disk analysis. Short for \"disk usage,\" it's your first port of call when things get messy. The beauty of du is its simplicity: throw it at a directory, and it'll spit out how much space everything inside is using. But don't just run du willy-nilly—let's walk through the essentials.

\n\n

Basic du Command

\n

Start with the basics: du -sh /path/to/directory. The -s flag gives you a summary, and -h makes it human-readable (like KB, MB, GB). For example, if you want to check your home directory:

\n
du -sh /home/
\n

This gives a quick overview. To see individual subdirectories, omit the -s flag:

\n
du -h /home/
\n

But this output can be messy. Pipe it to sort for clarity:

\n
du -h /home/ | sort -h
\n

Now the biggest folders appear at the bottom. For a focused view, use --max-depth=1 to avoid drowning in tiny files:

\n
du -h --max-depth=1 /home/ | sort -h
\n

This shows only top-level directories in /home, making it easy to spot the real offenders. Remember: -x keeps du on the same filesystem, so it doesn’t wander into mounted drives like NFS shares.

\n\n

Going Deeper with du

\n

Hidden files are the silent assassins of disk space. To reveal them, add the -a flag:

\n
du -ah /home/ | sort -h
\n

This lists every single file and directory, including those starting with a dot. For a more interactive experience, install ncdu (sudo apt install ncdu for Debian/Ubuntu, or sudo yum install ncdu for RHEL/CentOS). Run ncdu /home, and you'll navigate through directories using arrow keys—press d to delete files directly from the interface (with confirmation!). It’s like a GPS for your disk usage, showing you exactly where to point your cleanup shovel.

\n\n

Df: The Big Picture Commander

\n

Alibaba Cloud Account While du zooms in, df gives you the helicopter view. Short for \"disk free,\" it shows all mounted filesystems and their usage stats. Run df -h for human-readable output:

\n
Filesystem      Size  Used Avail Use% Mounted on\n/dev/vda1        50G   48G    2G  96% /\n/dev/vdb1       100G   60G   40G  60% /data
\n

See that /dev/vda1 is at 96%? That’s your problem child. But df doesn’t tell you what’s filling it up—only where it’s happening. So first use df to find the full partition, then dive into it with du or find to pinpoint the culprit.

\n

A useful tip: df -i checks inodes (not just space). Sometimes your disk seems full because you’ve run out of inodes, often due to millions of tiny files. This is common with log files or email servers. If Use% for inodes hits 100%, you’ll need to delete small files even if space seems available.

\n\n

Alibaba Cloud Account Find: The Grand File Hunter

\n

When you suspect a massive file hiding somewhere but don’t know where, find is your best friend. It searches based on size, name, or modification time. Here’s how to track down the big guns.

\n\n

Locating Large Files

\n

To find files larger than 100MB across your system:

\n
find / -type f -size +100M -exec ls -lh {} \; 2>/dev/null
\n

Let’s break this down:

\n
    \n
  • / searches from the root directory (adjust this for targeted searches).
  • \n
  • -type f ensures only files (not directories) are checked.
  • \n
  • -size +100M finds files bigger than 100MB.
  • \n
  • -exec ls -lh {} \; lists each found file with details.
  • \n
  • 2>/dev/null silences permission errors—no need to see \"Permission denied\" for system files.
  • \n
\n

For sorted results, pipe to sort:

\n
find / -type f -size +100M -exec du -h {} \; 2>/dev/null | sort -h
\n

This shows files from smallest to largest, so the biggest ones appear last. To narrow the search to specific directories (e.g., /var/log), replace the / with the path:

\n
find /var/log -type f -name \"*.log\" -size +50M -ls
\n

This lists all .log files over 50MB in /var/log, with details like size, permissions, and path.

\n\n

Finding Hidden or Recent Files

\n

Need to find files modified in the last week? Use -mtime:

\n
find /home -type f -mtime -7
\n

Or find files larger than 1GB in /tmp with:

\n
find /tmp -type f -size +1G -delete
\n

Alibaba Cloud Account But caution! Always test with -ls first to avoid accidental deletions. For example:

\n
find /tmp -type f -size +1G -ls
\n

Alibaba Cloud Account This shows what will be deleted before you actually delete it. Smart, right?

\n\n

GUI Tools for Visual Thinkers

\n

If the terminal makes you sweat, GUI tools are your lifeline. They transform abstract numbers into colorful, clickable visuals—perfect for those who prefer dragging sliders to typing commands.

\n\n

Baobab (Disk Usage Analyzer)

\n

Install Baobab on Ubuntu-based systems with sudo apt install baobab. Launch it from the terminal or app menu, and it shows a pie chart of your disk usage. Click any slice to drill down into subdirectories, and watch the chart update in real time. It’s like a GPS for your disk: if a slice looks suspiciously large, you can navigate straight to it. Bonus: it highlights hidden files automatically, so no more \"where’d that 10GB file go?\" moments.

\n\n

NCurses Disk Usage (ncdu)

\n

Even though it runs in the terminal, ncdu is shockingly user-friendly. Install it via your package manager, then run ncdu /. Use arrow keys to navigate directories, and press ? for a help menu. It shows a clean, sortable list of directories by size, and you can delete files directly by pressing d. The interface is clean, intuitive, and far less intimidating than raw command-line outputs. Pro tip: press g to sort by size for instant clarity.

\n\n

Filelight and KDirStat

\n

For KDE users, Filelight offers a sunburst diagram where each ring represents a directory level. Bigger wedges mean more space used. KDirStat is another option that uses rectangular trees, where larger rectangles equal larger files. Both are great for visual learners who want to \"see\" disk usage like a map of a city, where the tallest buildings are the biggest space hogs.

\n\n

Cleaning Up: Because It's Time to Tidy Up

\n

You’ve found the problem—now it’s cleanup time. But don’t just go deleting everything willy-nilly; that’s how servers end up crying in a corner. Here’s how to clean smartly.

\n\n

Log Files: The Silent Space Eaters

\n

Log files grow like weeds. Check /var/log for huge logs with:

\n
du -sh /var/log/* | sort -h
\n

Common offenders include application logs, syslog, and nginx/apache logs. To trim systemd logs:

\n
sudo journalctl --vacuum-size=100M
\n

For traditional logs, use logrotate to automate compression and deletion. Edit the config in /etc/logrotate.d/ to set limits (e.g., rotate weekly and keep 4 copies). Pro tip: check Docker logs in /var/lib/docker/containers/—they can balloon quickly if not configured for rotation.

\n\n

Package Manager Cleanup

\n

Linux distributions accumulate old package files like squirrels stash nuts. In Debian/Ubuntu:

\n
sudo apt clean
\n

removes cached .deb files, often freeing several gigabytes. For RHEL-based systems:

\n
sudo dnf clean all
\n

Also, remove unused packages with:

\n
sudo apt autoremove --purge
\n

or

\n
sudo dnf remove $(dnf repoquery --unneeded)
\n

This cleans up libraries and packages no longer needed by your system.

\n\n

Old Kernels and Snapshots

\n

After updates, old kernel versions linger. List them with:

\n
dpkg --list | grep linux-image
\n

Keep 1-2 recent kernels (for safety), then purge the rest:

\n
sudo apt purge linux-image-5.4.0-123-generic
\n

For Snap users, check installed versions with snap list and remove old ones using snap remove --revision=123 for specific revisions. Snap often keeps multiple versions by default, eating space without you noticing.

\n\n

Docker and Container Cleanup

\n

Docker can be a space monster. To clean up unused images, containers, and volumes:

\n
docker system prune -a
\n

Warning: This deletes all stopped containers and unused images. For a gentler approach, use docker system prune (without -a) to only remove dangling images. Also, check container logs in /var/lib/docker/containers/—they can be massive. To limit logs per container, configure Docker’s daemon.json with max-size and max-file limits (e.g., 10MB per log, keep 3 files).

\n\n

The rm Command: A Double-Edged Sword

\n

Before using rm, remember: rm -rf / is the digital equivalent of setting your house on fire. Always double-check paths! To stay safe:

\n
    \n
  • Use rm -i for interactive confirmation: rm -i /path/to/big/file
  • \n
  • Move files to a temporary directory first: mkdir ~/temp_deletion; mv /big/file ~/temp_deletion/
  • \n
  • Check disk space before and after: df -h
  • \n
\n

For bulk deletions, always test with find ... -ls first. Example:

\n
find /tmp -name \"*.tmp\" -ls
\n

Then delete with:

\n
find /tmp -name \"*.tmp\" -delete
\n

But be careful: -delete is permanent. No \"undo\" button here!

\n\n

Common Mistakes and How to Avoid Them

\n

Even experienced admins mess up disk space management. Here’s how to dodge the pitfalls.

\n\n

Mistake 1: Ignoring Hidden Files

\n

Files starting with a dot (e.g., .cache, .ssh) are easy to overlook. Use ls -la to see them, and check their size with:

\n
du -sh .*
\n

in your home directory. That \"hidden\" 5GB cache in ~/.cache could be eating up space right now.

\n\n

Mistake 2: Forgetting About Deleted-but-Still-Open Files

\n

Here’s a sneaky one: a file gets deleted, but a process is still using it—so the space isn’t freed. Check for these with:

\n
lsof | grep deleted
\n

This lists deleted files still held open by processes. To free space, restart the process or kill it. Example: if a log file is deleted but an app keeps writing to it, restarting the app releases the file handle. It’s like a ghost in the machine—visible only to lsof!

\n\n

Mistake 3: Not Checking Mounted Drives

\n

df shows all mounted filesystems, but people often ignore them. A USB drive or NFS share might be full, but you didn’t notice. Always run df -h to check every partition, not just / and /home.

\n\n

Mistake 4: Overlooking Home Directories

\n

Users store huge files in home directories—movies, backups, old projects. Run:

\n
du -sh /home/*
\n

and check hidden folders like ~/.local/share or ~/.cache. That 20GB movie download from 2018 might still be lurking there, waiting to ruin your day.

\n\n

Mistake 5: Skipping System Logs and Docker

\n

System logs grow unnoticed. Use journalctl --disk-usage to see log size. For Docker, check /var/lib/docker/containers/ for huge log files. Rotate logs with Docker’s daemon.json settings to prevent this.

\n\n

Mistake 6: Assuming \"It’s Not That Big\"

\n

One massive file can be the culprit. Use find / -type f -size +5G to hunt for files over 5GB. They could be database dumps, virtual machine images, or corrupted backups. Don’t assume directory sizes—check individual files too!

\n\n

Conclusion: Becoming a Disk Space Ninja

\n

Now you’re armed with tools to track down disk space hogs like a pro. Start with df to see the big picture, then use du and find to drill down. For visual learners, GUI tools like Baobab or ncdu make the process painless. Clean up smartly: prune logs, old kernels, and Docker cruft—but always double-check before deleting.

\n

Remember: disk space management isn’t a one-time task. Schedule regular checks, set up log rotation, and monitor space proactively. The key is to stay vigilant. Don’t wait until your server’s disk is 99% full to take action. Keep those disks tidy, and you’ll avoid the panic of a midnight disk-full emergency. Go forth and conquer your storage woes—you’ve got this!

" }
TelegramContact Us
CS ID
@cloudcup
TelegramSupport
CS ID
@yanhuacloud