The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Show synchronization statechronyc trackingView examples
List source selectionchronyc -n sources -vView examples
Show source statisticschronyc -n sourcestats -vView examples
Count source activitychronyc activityView examples
Wait for bounded accuracychronyc waitsync 60 0.01 0.1 10View examples
Explain source statechronyc selectdata -aView examples
Refresh source addressessudo chronyc refreshView examples
Mark sources onlinesudo chronyc onlineView examples
Collect measurements quicklysudo chronyc burst 4/4View examples
Step remaining correctionsudo chronyc makestepView examples
Print parsed configurationsudo chronyd -p -f /etc/chrony.confView examples
Configure an NTP poolpool time.example.net iburst maxsources 4View examples
Limit startup steppingmakestep 1.0 3View examples
Enable RTC synchronizationrtcsyncView examples
Read leap seconds from tzdataleapsectz right/UTCView examples
Persist NTS statentsdumpdir /var/lib/chronyView examples

Correct time is a dependency for authentication, TLS, databases, distributed systems, and incident timelines. Diagnose source reachability and selection before forcing a clock correction. A backward or forward step can break leases, timeouts, logs, and clustered software, so coordinate changes and prefer normal slewing after startup. chrony paths, service names, compiled features, and defaults vary across distributions and releases.

Step by step

Detailed examples

01

Read tracking and source state together

tracking describes the system clock's current reference and correction, while sources shows candidate reachability and selection. The sources reach register is octal history, not latency; a selected source is marked with an asterisk. Do not declare health from stratum alone. Numeric output avoids reverse-DNS delays, and a leap status of Not synchronised should fail a readiness gate.

Collect a read-only time snapshot
date --iso-8601=ns
timedatectl status
chronyc tracking
chronyc -n sources -v
chronyc -n sourcestats -v
chronyc activity
Back to quick reference ↑
02

Gate workloads on an explicit accuracy objective

A running daemon is not proof that the clock is synchronized. Define maximum remaining correction and skew appropriate to the workload, then use waitsync as a bounded readiness check. The command's arguments are maximum tries, correction seconds, skew ppm, and poll interval seconds. Avoid an unlimited default wait in orchestration and account for isolated networks and cold-start measurement time.

Fail a deployment when time does not converge
if ! chronyc waitsync 60 0.01 0.1 10; then
  echo 'clock failed to reach the required accuracy' >&2
  exit 1
fi
chronyc tracking
Back to quick reference ↑
03

Separate DNS, UDP reachability, and source-selection failures

An unresolved source, zero reach, and a reachable but rejected source are different failures. Check activity, numeric source state, chronyd logs, firewall policy, and DNS independently. NTP normally uses UDP port 123, but cloud and enterprise networks may require approved internal servers. Marking sources online or refreshing names is safe only after the underlying network condition is understood.

Troubleshoot without changing the clock
chronyc activity
chronyc -n sources -v
chronyc selectdata -a
journalctl --unit=chronyd.service --since today --no-pager
getent ahosts time.example.net
Back to quick reference ↑
04

Treat forced stepping as a coordinated production change

chronyd normally slews the clock to preserve continuity. makestep cancels the remaining slew and jumps time immediately; this can invalidate authentication tokens, reorder logs, fire timers unexpectedly, or violate database and consensus assumptions. Use a bounded startup makestep directive where justified. For a live system, drain sensitive workloads, capture offsets, collect fresh measurements, step only with approval, and verify every dependent service.

Document a controlled correction sequence
chronyc tracking
chronyc -n sources -v
sudo chronyc burst 4/4
# Obtain change approval and drain time-sensitive workloads before this command.
sudo chronyc makestep
chronyc waitsync 30 0.01 0.1 10
Back to quick reference ↑
05

Use controlled sources and validate the parsed configuration

Prefer organizational or vendor-approved pools with at least several independent sources. iburst improves initial convergence without continuous burst traffic. A pool name depends on DNS, and maxsources bounds addresses used. The common configuration path is /etc/chrony.conf, but Debian-family packages may use /etc/chrony/chrony.conf and unit names differ. chronyd -p is a parse-only check; review its output before restarting a critical time service.

Minimal client policy
pool time.example.net iburst maxsources 4
driftfile /var/lib/chrony/drift
makestep 1.0 3
rtcsync
logdir /var/log/chrony
Parse before deployment
sudo chronyd -p -f /etc/chrony.conf
systemctl cat chronyd.service
systemctl status chronyd.service --no-pager
Back to quick reference ↑
06

Use NTS when authenticated time is required

Network Time Security authenticates NTP server negotiation and protects against off-path manipulation, but it adds TLS, DNS, certificate-time, and feature dependencies. Confirm the installed chrony build supports NTS, use trusted NTS endpoints, protect persisted cookie/key state, and monitor fallback behavior. A badly wrong bootstrap clock can prevent certificate validation; solve bootstrap deliberately rather than disabling verification.

NTS-enabled source policy
server nts1.example.net iburst nts
server nts2.example.net iburst nts
ntsdumpdir /var/lib/chrony
Inspect NTS source data
chronyc -N sources -v
chronyc -N authdata
Back to quick reference ↑
07

Define RTC, timezone, and leap-second ownership

Keep the hardware RTC in UTC on Linux unless dual-boot constraints require otherwise. rtcsync lets the kernel periodically synchronize the RTC where supported; it is not a substitute for network sources. Leap-second handling must be consistent with upstream servers and applications. leapsectz relies on a current timezone database and is inappropriate when another leap-smearing policy is in use.

Inspect RTC and leap status
timedatectl status
chronyc tracking
hwclock --show --utc
zdump -v right/UTC | tail -4
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. chrony Projectchronyc(1) Manual Pagechrony-project.org
  2. chrony Projectchrony.conf(5) Manual Pagechrony-project.org
  3. chrony Projectchronyd(8) Manual Pagechrony-project.org
  4. chrony Projectchrony FAQchrony-project.org
  5. Internet Engineering Task ForceNetwork Time Security for NTPrfc-editor.org

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback