Linux, Web Server & Database
Create Linux User
Create a new Linux user account with the correct permissions for its intended purpose.
The Problem
You need a new user account on your server — for a team member, a specific application, or to stop using root directly — but getting the permissions, home directory and shell access right takes a bit more than a single command.
About this problem
Creating a Linux user is simple on the surface, but getting it right for a specific purpose (an application service account that shouldn't have a login shell, versus a team member who needs sudo and SSH key access) involves several small decisions that are easy to get wrong if you're not used to it.
This comes up whenever a new person joins a project, or when setting up a dedicated account for a specific application or service to run under, rather than root.
What's Included
- Creating the user account with an appropriate home directory and shell
- Setting up sudo access if the account needs administrative privileges
- Configuring SSH key-based access for the new user
- Setting correct group memberships for anything the account needs to access
What's NOT Included
- Setting up the actual application or service the account will run (separate service)
- Ongoing user account management after initial creation
- Password policy/complexity enforcement beyond a reasonable initial setup
How It Works
- Create the user account with useradd (or adduser) specifying an appropriate home directory and shell.
- Add the user to the sudo group if administrative access is required, or deliberately leave it out for a restricted service account.
- Set up the user's SSH authorized_keys for key-based login rather than a password.
- Add the user to any additional groups needed for specific file or service access (e.g. docker, www-data).
- Test login and, if applicable, sudo access to confirm everything works as intended.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- What's the difference between useradd and adduser?
- useradd is a lower-level command with fewer defaults set automatically; adduser (available on Debian/Ubuntu) is a friendlier script that sets up a home directory and prompts for details automatically.
- Should a new user have sudo access?
- Only if they genuinely need administrative privileges — accounts meant only for running a specific application are usually best left without sudo, limiting the damage if that account is ever compromised.
- Can I create a user without a login shell?
- Yes, setting the shell to /usr/sbin/nologin or /bin/false is standard for service accounts that should never be used for interactive login.
- How do I give a new user SSH key access instead of a password?
- By placing their public key in ~/.ssh/authorized_keys under their home directory with the correct permissions, then optionally disabling password authentication entirely.
- What groups does a new user need to access a website's files?
- Typically the group that owns the web root (often www-data or similar), so the user can read/write files without needing broader permissions.
- How do I remove a user account later?
- userdel (with the -r flag to also remove their home directory) cleanly removes the account, though it's worth checking for any files or cron jobs owned by that user first.