The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| List NFS mounts | findmnt -t nfs,nfs4 -o TARGET,SOURCE,FSTYPE,OPTIONS | View examples |
| Show negotiated options | nfsstat --mounts | View examples |
| Query NFSv3 exports | showmount --exports nfs1.example.net | View examples |
| List RPC services | rpcinfo -p nfs1.example.net | View examples |
| Mount NFSv4.1 | sudo mount -t nfs4 -o vers=4.1,sec=krb5p \
nfs1.example.net:/projects /srv/projects | View examples |
| Mount read-only for validation | sudo mount -t nfs4 -o ro,vers=4.1 \
nfs1.example.net:/projects /mnt/nfs-test | View examples |
| Unmount normally | sudo umount /srv/projects | View examples |
| Identify mount users | sudo fuser -vm /srv/projects | View examples |
| Show active exports | sudo exportfs -v | View examples |
| Reload exports | sudo exportfs -ra | View examples |
| Validate export syntax | sudo exportfs -rav | View examples |
| Show server statistics | nfsstat --server | View examples |
| Show client statistics | nfsstat --client | View examples |
| Inspect per-mount statistics | mountstats /srv/projects | View examples |
| Check autofs maps | sudo automount --dumpmaps | View examples |
| Reload autofs | sudo systemctl reload autofs.service | View examples |
| Show automount units | findmnt -t autofs -o TARGET,SOURCE,OPTIONS | View examples |
| Read autofs logs | journalctl -u autofs.service --since today --no-pager | View examples |
| Check NFSv4 id mapping | nfsidmap -l | View examples |
| Inspect GSS services | systemctl status rpc-gssd.service rpc-svcgssd.service \
--no-pager | View examples |
NFS availability depends on DNS, network reachability, RPC services, server exports, client identity, and filesystem health. A hard-mounted production filesystem may intentionally wait indefinitely during an outage, so careless tests can hang shells and services. Prefer NFSv4 with Kerberos where supported, validate changes from a separate session, and never use force or lazy unmount as a first response to an active workload.
Step by step
Detailed examples
Record effective mounts rather than assuming configuration won
findmnt and nfsstat expose live state, including negotiated version, transport, security flavor, caching, and recovery behavior. Compare it with fstab, systemd units, and autofs maps. Do not infer safety from defaults because distributions and nfs-utils versions differ.
findmnt -t nfs,nfs4 -o TARGET,SOURCE,FSTYPE,OPTIONS
nfsstat --mounts
cat /proc/fs/nfsfs/servers
cat /proc/fs/nfsfs/volumes Use protocol-aware discovery
showmount talks to the separate mount protocol and may fail or omit exports on an NFSv4-only server. NFSv4 generally uses TCP 2049 and a pseudo-filesystem; NFSv3 also relies on rpcbind and auxiliary services whose ports complicate firewalls. Treat export listings and RPC inventory as sensitive topology.
getent ahosts nfs1.example.net
rpcinfo -p nfs1.example.net
showmount --exports nfs1.example.net
ss -tn dst nfs1.example.net Test mounts with explicit protocol and security choices
Create an empty dedicated mountpoint, start read-only when possible, and specify the intended NFS version and sec flavor. sec=sys trusts client-supplied numeric identities and is unsuitable across untrusted clients; krb5 authenticates, krb5i adds integrity, and krb5p adds privacy at added cost. Avoid soft for general data mounts because timeout errors can surface as application corruption.
# Confirm /mnt/nfs-test is an empty dedicated directory first.
# sudo mount -t nfs4 -o ro,hard,vers=4.1,sec=krb5p nfs1.example.net:/projects /mnt/nfs-test
# findmnt --target /mnt/nfs-test
# sudo umount /mnt/nfs-test Quiesce consumers before unmounting
A busy mount protects processes from losing their filesystem unexpectedly. Identify open files and current working directories, stop services cleanly, and unmount normally. Lazy unmount only detaches the pathname while references remain; force is protocol-specific and can lose unwritten data. Rebooting with unreachable hard mounts may also stall shutdown.
findmnt --target /srv/projects
sudo fuser -vm /srv/projects
systemctl list-units --type=mount --all
# Stop dependent services, flush application data, then:
# sudo umount /srv/projects Make server export policy narrow and explicit
Exports grant network clients access subject to filesystem and identity semantics. Restrict clients by controlled addresses or Kerberos principals, prefer ro where possible, and understand root_squash before considering no_root_squash, which gives remote root dangerous server-side power. exportfs -r changes live access and needs a rollback copy and client-impact review.
sudo exportfs -v
sudo cat /etc/exports
sudo find /etc/exports.d -maxdepth 1 -type f -name '*.exports' -print
# Applying changes affects clients:
# sudo exportfs -ra Keep automounter maps deterministic
The master map chooses mount roots and map sources; indirect maps resolve keys below a root. Use explicit NFS versions and security flavors, restrict executable program maps, and protect maps containing topology. automount --dumpmaps resolves configured sources but reload behavior and syntax vary by autofs release.
# /etc/auto.master.d/projects.autofs
# /net/projects /etc/auto.projects --timeout=300
# /etc/auto.projects
# design -fstype=nfs4,ro,hard,vers=4.1,sec=krb5p nfs1.example.net:/projects/design
# sudo automount --dumpmaps Expect first-access latency and dependency failures
autofs defers mounting until pathname access, so ls, monitoring, shell completion, and recursive scans can trigger remote I/O. Expiry is not guaranteed while a mount is busy. Configure service ordering carefully, avoid health checks that mount every key, and inspect both the autofs trigger and resulting NFS mount.
findmnt -t autofs -o TARGET,SOURCE,OPTIONS
systemctl status autofs.service --no-pager
journalctl -u autofs.service --since '-15 minutes' --no-pager
# Accessing a key beneath an autofs root may block while it mounts. Align identity, Kerberos, DNS, and time
NFSv4 name mapping and Kerberos depend on consistent domains, forward and reverse DNS, keytabs, service principals, and synchronized time. Numeric UID equality alone is not authorization with Kerberos, while sec=sys has no cryptographic user proof. Never expose keytab contents or enable broad fallback merely to make a mount work.
hostname --fqdn
timedatectl status
klist
nfsidmap -l
systemctl status rpc-gssd.service --no-pager Diagnose layers before changing timeout semantics
Separate name resolution, transport, RPC registration, authentication, mount negotiation, server response, and application I/O. retrans and timeo tuning can amplify load or mask failure; switching hard to soft changes failure semantics. Compare bounded client and server counters and logs while reproducing one controlled request.
nfsstat --client
mountstats /srv/projects
journalctl -k --since '-15 minutes' --no-pager
journalctl -u nfs-server.service --since '-15 minutes' --no-pager Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
- Linux Kernel ProjectNFS Documentationkernel.org
- Linux Kernel Projectautofs: How It Workskernel.org
- Linux man-pages projectnfs(5) Manual Pageman7.org
- Linux man-pages projectexports(5) Manual Pageman7.org
- Linux man-pages projectmount.nfs(8) Manual Pageman7.org
- Linux man-pages projectautomount(8) Manual Pageman7.org
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



