The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
List NFS mountsfindmnt -t nfs,nfs4 -o TARGET,SOURCE,FSTYPE,OPTIONSView examples
Show negotiated optionsnfsstat --mountsView examples
Query NFSv3 exportsshowmount --exports nfs1.example.netView examples
List RPC servicesrpcinfo -p nfs1.example.netView examples
Mount NFSv4.1sudo mount -t nfs4 -o vers=4.1,sec=krb5p \ nfs1.example.net:/projects /srv/projectsView examples
Mount read-only for validationsudo mount -t nfs4 -o ro,vers=4.1 \ nfs1.example.net:/projects /mnt/nfs-testView examples
Unmount normallysudo umount /srv/projectsView examples
Identify mount userssudo fuser -vm /srv/projectsView examples
Show active exportssudo exportfs -vView examples
Reload exportssudo exportfs -raView examples
Validate export syntaxsudo exportfs -ravView examples
Show server statisticsnfsstat --serverView examples
Show client statisticsnfsstat --clientView examples
Inspect per-mount statisticsmountstats /srv/projectsView examples
Check autofs mapssudo automount --dumpmapsView examples
Reload autofssudo systemctl reload autofs.serviceView examples
Show automount unitsfindmnt -t autofs -o TARGET,SOURCE,OPTIONSView examples
Read autofs logsjournalctl -u autofs.service --since today --no-pagerView examples
Check NFSv4 id mappingnfsidmap -lView examples
Inspect GSS servicessystemctl status rpc-gssd.service rpc-svcgssd.service \ --no-pagerView examples

NFS availability depends on DNS, network reachability, RPC services, server exports, client identity, and filesystem health. A hard-mounted production filesystem may intentionally wait indefinitely during an outage, so careless tests can hang shells and services. Prefer NFSv4 with Kerberos where supported, validate changes from a separate session, and never use force or lazy unmount as a first response to an active workload.

Step by step

Detailed examples

01

Record effective mounts rather than assuming configuration won

findmnt and nfsstat expose live state, including negotiated version, transport, security flavor, caching, and recovery behavior. Compare it with fstab, systemd units, and autofs maps. Do not infer safety from defaults because distributions and nfs-utils versions differ.

Capture client state
findmnt -t nfs,nfs4 -o TARGET,SOURCE,FSTYPE,OPTIONS
nfsstat --mounts
cat /proc/fs/nfsfs/servers
cat /proc/fs/nfsfs/volumes
Back to quick reference ↑
02

Use protocol-aware discovery

showmount talks to the separate mount protocol and may fail or omit exports on an NFSv4-only server. NFSv4 generally uses TCP 2049 and a pseudo-filesystem; NFSv3 also relies on rpcbind and auxiliary services whose ports complicate firewalls. Treat export listings and RPC inventory as sensitive topology.

Compare discovery signals
getent ahosts nfs1.example.net
rpcinfo -p nfs1.example.net
showmount --exports nfs1.example.net
ss -tn dst nfs1.example.net
Back to quick reference ↑
03

Test mounts with explicit protocol and security choices

Create an empty dedicated mountpoint, start read-only when possible, and specify the intended NFS version and sec flavor. sec=sys trusts client-supplied numeric identities and is unsuitable across untrusted clients; krb5 authenticates, krb5i adds integrity, and krb5p adds privacy at added cost. Avoid soft for general data mounts because timeout errors can surface as application corruption.

Review a controlled validation mount
# Confirm /mnt/nfs-test is an empty dedicated directory first.
# sudo mount -t nfs4 -o ro,hard,vers=4.1,sec=krb5p nfs1.example.net:/projects /mnt/nfs-test
# findmnt --target /mnt/nfs-test
# sudo umount /mnt/nfs-test
Back to quick reference ↑
04

Quiesce consumers before unmounting

A busy mount protects processes from losing their filesystem unexpectedly. Identify open files and current working directories, stop services cleanly, and unmount normally. Lazy unmount only detaches the pathname while references remain; force is protocol-specific and can lose unwritten data. Rebooting with unreachable hard mounts may also stall shutdown.

Find consumers before maintenance
findmnt --target /srv/projects
sudo fuser -vm /srv/projects
systemctl list-units --type=mount --all
# Stop dependent services, flush application data, then:
# sudo umount /srv/projects
Back to quick reference ↑
05

Make server export policy narrow and explicit

Exports grant network clients access subject to filesystem and identity semantics. Restrict clients by controlled addresses or Kerberos principals, prefer ro where possible, and understand root_squash before considering no_root_squash, which gives remote root dangerous server-side power. exportfs -r changes live access and needs a rollback copy and client-impact review.

Audit active policy before reload
sudo exportfs -v
sudo cat /etc/exports
sudo find /etc/exports.d -maxdepth 1 -type f -name '*.exports' -print
# Applying changes affects clients:
# sudo exportfs -ra
Back to quick reference ↑
06

Keep automounter maps deterministic

The master map chooses mount roots and map sources; indirect maps resolve keys below a root. Use explicit NFS versions and security flavors, restrict executable program maps, and protect maps containing topology. automount --dumpmaps resolves configured sources but reload behavior and syntax vary by autofs release.

Example indirect map for review
# /etc/auto.master.d/projects.autofs
# /net/projects /etc/auto.projects --timeout=300
# /etc/auto.projects
# design -fstype=nfs4,ro,hard,vers=4.1,sec=krb5p nfs1.example.net:/projects/design
# sudo automount --dumpmaps
Back to quick reference ↑
07

Expect first-access latency and dependency failures

autofs defers mounting until pathname access, so ls, monitoring, shell completion, and recursive scans can trigger remote I/O. Expiry is not guaranteed while a mount is busy. Configure service ordering carefully, avoid health checks that mount every key, and inspect both the autofs trigger and resulting NFS mount.

Inspect triggers without walking them
findmnt -t autofs -o TARGET,SOURCE,OPTIONS
systemctl status autofs.service --no-pager
journalctl -u autofs.service --since '-15 minutes' --no-pager
# Accessing a key beneath an autofs root may block while it mounts.
Back to quick reference ↑
08

Align identity, Kerberos, DNS, and time

NFSv4 name mapping and Kerberos depend on consistent domains, forward and reverse DNS, keytabs, service principals, and synchronized time. Numeric UID equality alone is not authorization with Kerberos, while sec=sys has no cryptographic user proof. Never expose keytab contents or enable broad fallback merely to make a mount work.

Inspect identity prerequisites
hostname --fqdn
timedatectl status
klist
nfsidmap -l
systemctl status rpc-gssd.service --no-pager
Back to quick reference ↑
09

Diagnose layers before changing timeout semantics

Separate name resolution, transport, RPC registration, authentication, mount negotiation, server response, and application I/O. retrans and timeo tuning can amplify load or mask failure; switching hard to soft changes failure semantics. Compare bounded client and server counters and logs while reproducing one controlled request.

Collect scoped evidence
nfsstat --client
mountstats /srv/projects
journalctl -k --since '-15 minutes' --no-pager
journalctl -u nfs-server.service --since '-15 minutes' --no-pager
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Linux Kernel ProjectNFS Documentationkernel.org
  2. Linux Kernel Projectautofs: How It Workskernel.org
  3. Linux man-pages projectnfs(5) Manual Pageman7.org
  4. Linux man-pages projectexports(5) Manual Pageman7.org
  5. Linux man-pages projectmount.nfs(8) Manual Pageman7.org
  6. Linux man-pages projectautomount(8) Manual Pageman7.org

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback