The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Show running kerneluname -rView examples
List loaded moduleslsmodView examples
Inspect module metadatamodinfo e1000eView examples
Simulate module loadsudo modprobe --dry-run --verbose e1000eView examples
Load a modulesudo modprobe e1000eView examples
Remove a module safelysudo modprobe --remove e1000eView examples
Inspect effective modprobe configmodprobe --show-configView examples
List boot-load entriessystemd-analyze cat-config modules-load.dView examples
Read one sysctlsysctl vm.swappinessView examples
Change a runtime sysctlsudo sysctl -w vm.swappiness=10View examples
Check a staged sysctl filesystemd-analyze cat-config sysctl.dView examples
Apply system sysctl filessudo sysctl --systemView examples
Inspect kernel messagesjournalctl --dmesg --boot --no-pagerView examples
Read live module parametersfind /sys/module/e1000e/parameters -maxdepth 1 -type f \ -printView examples

Kernel modules extend a running kernel, while sysctl exposes selected runtime parameters through /proc/sys. Treat both as host-wide configuration: identify the exact kernel and parameter, inspect effective state, stage persistent files under configuration management, and keep a tested rollback path. Never force an incompatible module or copy tuning values between workloads without measuring their effect.

Step by step

Detailed examples

01

Match modules to the running kernel before changing state

Modules are normally installed below /lib/modules for a specific kernel release. lsmod shows live state; modinfo reads packaged metadata and may describe a module that is not loaded. Confirm the running release, module filename, dependencies, license, signature, aliases, and supported parameters. A present device or alias does not prove that unloading its driver is safe.

Build a read-only module inventory
uname -r
lsmod | head
modinfo e1000e
modprobe --show-depends e1000e
Back to quick reference ↑
02

Use modprobe for dependency-aware loading

modprobe resolves aliases and dependencies using the installed module database; insmod accepts a file directly and is rarely the right administrative interface. Start with --dry-run --verbose, then load normally and inspect the kernel log. Do not use --force, --force-vermagic, or --force-modversion to bypass compatibility checks on production systems.

Preview, load, and verify a driver
sudo modprobe --dry-run --verbose e1000e
sudo modprobe e1000e
lsmod | grep '^e1000e '
journalctl --dmesg --boot --no-pager | tail -n 40
Back to quick reference ↑
03

Unload only after proving every consumer can tolerate it

Removing a storage, network, filesystem, cryptographic, or console driver can immediately disrupt the host. Stop dependent workloads, confirm the device is not carrying root storage or management connectivity, and use modprobe --remove without force. A nonzero use count is a safety signal, not an obstacle to override. Schedule a reboot when clean unload is uncertain.

Review dependencies before an approved removal
lsmod | grep '^e1000e '
modinfo -F depends e1000e
sudo modprobe --dry-run --verbose --remove e1000e
# Run the real --remove only from resilient out-of-band access.
Back to quick reference ↑
04

Persist module policy with small, attributable configuration files

Place module options and aliases in /etc/modprobe.d/*.conf. Use /etc/modules-load.d/*.conf only for modules that must be loaded unconditionally at boot; hardware aliases usually trigger automatic loading. A blacklist affects alias-based loading but is not a universal security boundary because explicit or dependency-driven loading may still occur. Rebuild the initramfs when early-boot policy must change, using the distribution's supported tool.

Example managed configuration
# /etc/modprobe.d/90-storage-policy.conf
options nvme_core io_timeout=60

# /etc/modules-load.d/90-observability.conf
# Load only when automatic device/module discovery cannot do so.
msr
Back to quick reference ↑
05

Change one measured runtime parameter at a time

sysctl translates dotted names to files beneath /proc/sys. Read the current value and relevant kernel documentation, record a baseline, then apply a reversible runtime change. Availability and semantics depend on kernel configuration and version. A permission error may reflect namespaces, lockdown, or an intentionally read-only interface; do not weaken those controls merely to force a setting.

Record and test a reversible tuning change
previous=$(sysctl -n vm.swappiness)
printf 'baseline vm.swappiness=%s\n' "$previous"
sudo sysctl -w vm.swappiness=10
# Observe workload behavior, then restore the recorded baseline.
sudo sysctl -w "vm.swappiness=$previous"
Back to quick reference ↑
06

Persist validated settings with explicit ownership and rollback

Use a late, purpose-named file such as /etc/sysctl.d/90-application.conf, and include only settings justified for that host role. systemd-sysctl and sysctl --system process multiple directories with precedence rules; inspect the merged configuration before applying it. Applying all files changes the running host immediately, so use a maintenance window for networking, memory, or security-sensitive values.

Stage and review persistent tuning
# /etc/sysctl.d/90-application.conf
# Owner: platform team; rollback: remove this file and reload.
vm.swappiness = 10
fs.inotify.max_user_watches = 524288

# Review with: systemd-analyze cat-config sysctl.d
# Apply only after change approval: sudo sysctl --system
Back to quick reference ↑
07

Correlate configuration, live sysfs state, and kernel messages

A load can fail because the module is missing for the running kernel, its dependencies are unavailable, its signature is rejected, parameters are invalid, or hardware probing failed. Compare modprobe's effective configuration with /sys/module and the current boot's kernel messages. Some module parameters are read-only or load-time-only; changing a config file does not retroactively change an already-loaded module.

Collect a non-destructive diagnostic bundle
modprobe --show-config | grep -E '(^options|^blacklist).*e1000e'
modinfo e1000e
find /sys/module/e1000e/parameters -maxdepth 1 -type f -print 2>/dev/null
journalctl --dmesg --boot --no-pager | grep -i e1000e
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Linux Kernel documentationThe kernel's command-line parameterskernel.org
  2. Linux Kernel documentationDocumentation for /proc/syskernel.org
  3. kmod Project via Linux man-pagesmodprobe(8)man7.org
  4. procps-ng Project via Linux man-pagessysctl(8)man7.org
  5. systemd Projectmodules-load.d(5)freedesktop.org

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback