The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Create a tar archive | tar -cf project.tar project/ | View examples |
| Archive relative names | tar -C /srv/app -cf app.tar config public | View examples |
| Exclude generated files | tar --exclude='*.log' --exclude='cache/' -cf app.tar \
app/ | View examples |
| List archive members | tar -tf project.tar | View examples |
| Inspect stored metadata | tar -tvf project.tar | View examples |
| Extract an archive | tar -xf project.tar -C destination/ | View examples |
| Extract one member | tar -xf project.tar project/README.md | View examples |
| Remove a leading directory | tar -xf release.tar -C destination/ --strip-components=1 | View examples |
| Ignore stored ownership | tar -xf backup.tar -C destination/ --no-same-owner | View examples |
| Create a gzip tarball | tar -czf project.tar.gz project/ | View examples |
| Create an xz tarball | tar -cJf project.tar.xz project/ | View examples |
| Select compression by suffix | tar -caf project.tar.gz project/ | View examples |
| Extract compressed tar | tar -xf project.tar.gz -C destination/ | View examples |
| Compress and keep a file | gzip -k report.csv | View examples |
| Decompress to standard output | gzip -dc report.csv.gz | head | View examples |
| Compress with xz | xz -k report.csv | View examples |
| Test gzip integrity | gzip -t project.tar.gz | View examples |
| Test xz integrity | xz -t project.tar.xz | View examples |
| Verify a checksum file | sha256sum --check project.tar.gz.sha256 | View examples |
| Review before extraction | file release.tar.gz && gzip -t release.tar.gz && tar -tf \
release.tar.gz | View examples |
Archiving combines files and metadata; compression reduces the resulting stream. List unfamiliar archives before extraction, choose an explicit destination, distrust embedded paths and ownership, and verify checksums from an authenticated source before treating an archive as genuine.
Step by step
Detailed examples
Store useful relative names and intentional content
tar records a tree of member names and metadata. Use -C to avoid archiving long host-specific source prefixes, and inspect exclusion patterns because they match stored names according to tar's rules. Do not archive a growing archive into itself, and remember an archive is not an independent backup until copied to appropriate separate storage.
mkdir -p project/config project/cache
printf '%s\n' 'mode=production' > project/config/app.conf
printf '%s\n' 'temporary' > project/cache/state.log
tar --exclude='cache/' -C project -cf project.tar config tar -tf project.tar config/
config/app.confList before extracting unfamiliar content
tar -t reads the archive table of contents; -v adds metadata useful for spotting absolute-looking paths, unexpected parent traversal, device entries, ownership, or modes. Treat archive names and symlink targets as untrusted input. Listing reduces risk but does not replace using an updated extraction tool and an isolated destination.
tar -tf project.tar
tar -tvf project.tar config/
config/app.conf
# Verbose output also includes type, mode, owner, size, and timestamp.Extract into a prepared destination
Create and inspect a destination, then pass it with -C rather than relying on the current directory. An exact member name extracts a subset. --strip-components is useful for release archives wrapped in one top-level directory, but can cause collisions after components are removed. Non-root extraction normally avoids restoring foreign owners; --no-same-owner makes that intent explicit.
mkdir -p restored
tar -xf project.tar -C restored --no-same-owner
find restored -type f -print restored/config/app.confCombine tar with an appropriate compressor
The z and J options filter an archive through gzip and xz respectively; -a asks GNU tar to infer compression from the output suffix. gzip is commonly fast and compatible, while xz often trades more CPU for smaller output. GNU tar can usually recognize compression when reading a seekable file, so -xf is sufficient for extraction.
tar -czf project.tar.gz project/
tar -cJf project.tar.xz project/
tar -tf project.tar.gz | head
tar -tf project.tar.xz | head project/
project/config/
project/config/app.conf
project/cache/
project/cache/state.log
project/
project/config/
project/config/app.conf
project/cache/
project/cache/state.logCompress a single stream without wrapping it in tar
gzip and xz compress individual byte streams and normally replace a named input with a suffixed file. -k retains the original; -d decompresses and -c writes to standard output. Use tar first when directory structure, several files, permissions, or other metadata must travel together.
printf '%s\n' alpha beta gamma > report.csv
gzip -k report.csv
gzip -dc report.csv.gz | head -n 2
xz -k report.csv
ls report.csv report.csv.gz report.csv.xz alpha
beta
report.csv
report.csv.gz
report.csv.xzSeparate integrity checks from authenticity
gzip -t and xz -t detect corruption according to the compression format but do not establish who produced a file. sha256sum --check detects any byte change relative to a checksum list, but that list must arrive through a trusted channel or be authenticated by a signature. Verify before extraction and retain the exact failure output for diagnosis.
sha256sum project.tar.gz > project.tar.gz.sha256
sha256sum --check project.tar.gz.sha256
gzip -t project.tar.gz project.tar.gz: OKUse a review-first extraction workflow
Identify the file, test compression, list members, create a dedicated directory, extract without foreign ownership, and inspect the resulting tree. Never extract an untrusted archive as root merely to avoid permission errors. For hostile input, use a disposable sandbox with filesystem and privilege isolation appropriate to the threat model.
file release.tar.gz
gzip -t release.tar.gz
tar -tvf release.tar.gz | less
mkdir -p release-review
tar -xf release.tar.gz -C release-review --no-same-owner
find release-review -maxdepth 2 -print # Inspect each result before advancing to extraction.Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



