USERDBCTL(1) userdbctl USERDBCTL(1) (NAME) userdbctl - (SYNOPSIS) userdbctl [OPTIONS...] {COMMAND} [NAME...] (DESCRIPTION) userdbctl ( ) . / / JSON ( JSON User Records[1] JSON Group Records[2] ) UNIX NSS/glibc. User/Group Record Lookup API via Varlink[3] (drop-in) JSON /etc/userdb/, /run/userdb/, /run/host/userdb/, /usr/lib/userdb/ ( drop-in nss-systemd(8) ). (OPTIONS) : --output=MODE . "classic" "friendly" "table" "json" . "classic" /etc/passwd /etc/group . "friendly" . "table" . "json" JSON . / "friendly" "table". . "classic" "table" . . "json" . 245. --json=FORMAT JSON ( --output=json) . "pretty" "short" . "pretty" JSON . "short" . 250. --service=SERVICE[:SERVICE...], -s SERVICE:SERVICE... / . ":" . . . 245. --with-nss=BOOL / glibc/NSS . --with-nss=no / glibc NSS . --with-nss=yes / ( ). 245. --with-varlink=BOOL / Varlink User/Group Record Lookup API via Varlink[3] . --with-varlink=no / Varlink . --with-varlink=yes / ( ). 249. --with-dropin=BOOL / (drop-in) /etc/userdb/, /run/userdb/, /run/host/userdb/, /usr/lib/userdb/ . --with-dropin=no . --with-dropin=yes / ( ). 249. --synthesize=BOOL / root nobody / UID <<>> (foreign) ( ) . ( "yes") . "no" . 245. -N --with-nss=no --synthesize=no . JSON NSS/glibc . 245. --multiplexer=BOOL ( true ) ( false ). (sandbox) . 250. --chain ssh-authorized-keys . SSH . 250. --fuzzy, -z user group () . . . 257. --disposition= user group / (disposition) . "intrinsic" "system" "regular" "dynamic" "container" . . 257. -I, -S, -R --disposition=intrinsic --disposition=system --disposition=regular . 257. --uid-min=, --uid-max= user group UID/GID . UID/GID . . user UID . group GID ( ). 0 ( ) 4294967294 ( ) UID/GID . 257. --uuid= user group UUID . UUID . 259. --boundaries= user group UID/GID . . true . 257. -B --boundaries=no . 257. --from-file=PATH, -F user group JSON . "-" JSON . JSON . 258. --no-pager (pager) . --no-legend (legend) . -h, --help . --version . (COMMANDS) : user [USER...] . --output= . --from-file= JSON . . 245. group [GROUP...] . --output= . --from-file= JSON . . 245. users-in-group [GROUP...] . / . --output= . 245. groups-of-user [USER...] . / ( groups-of-user users-in-group ). --output= . 245. services / . . 245. ssh-authorized-keys SSH . SSH . 245. load-credentials (credentials) : userdb.user.*, userdb.group.* JSON User[1] JSON Group[2] . /etc/userdb/ nss-systemd(8) . UID GID . GID ( UID/GID ). ( "userdb.user.foobar" "foobar" ) . 258. 258. (WELL-KNOWN SERVICES) userdbctl services . : io.systemd.DynamicUser ( PID 1) ( ) DynamicUser= (unit) ( systemd.exec(5) ). 245. io.systemd.Home systemd-homed.service(8) ( ) . 245. io.systemd.Machine systemd-machined.service(8) / (user namespacing) . 246. io.systemd.Multiplexer systemd-userdbd.service(8) / () . / . userdbctl --with-nss= --service= . 245. io.systemd.NameServiceSwitch () systemd- userdbd.service(8) NSS/glibc / JSON . --with-nss=no . : nss- systemd(8) / NSS/glibc / JSON API API NSS/glibc . 245. io.systemd.DropIn () systemd- userdbd.service(8) / JSON /etc/userdb/, /run/userdb/, /run/host/userdb/, /usr/lib/userdb/ . 249. userdbctl NSS . io.systemd.Multiplexer io.systemd.NameServiceSwitch / . SSH (INTEGRATION WITH SSH) userdbctl SSH SSH . sshd_config(5) : ... AuthorizedKeysCommand /usr/bin/userdbctl ssh-authorized-keys %u AuthorizedKeysCommandUser root ... SSH . --chain SSH userdbctl ssh-authorized-keys . : ... AuthorizedKeysCommand /usr/bin/userdbctl ssh-authorized-keys %u --chain /usr/bin/othertool %u AuthorizedKeysCommandUser root ... userdb SSH /usr/bin/othertool . (EXIT STATUS) 0 . (ENVIRONMENT) $SYSTEMD_LOG_LEVEL () ( ). . ( ): emerg alert crit err warning notice info debug 0...7. syslog(3) . console syslog kmsg journal (:) ( SYSTEMD_LOG_LEVEL=debug,console:info debug info ). . $SYSTEMD_LOG_COLOR . tty . journalctl(1) . $SYSTEMD_LOG_TIME . . journalctl(1) . $SYSTEMD_LOG_LOCATION . . . . $SYSTEMD_LOG_TID . (TID) . . . $SYSTEMD_LOG_TARGET . console ( tty ) console-prefixed ( tty "facility" syslog(3) ) kmsg ( ) journal ( ) journal-or-kmsg ( kmsg) auto ( ) null ( ). $SYSTEMD_LOG_RATELIMIT_KMSG (ratelimit) kmsg . . "true" . systemd kmsg . $SYSTEMD_PAGER, $PAGER --no-pager . $SYSTEMD_PAGER $PAGER . $SYSTEMD_PAGER $PAGER less(1) more(1) . . "cat" --no-pager . : $SYSTEMD_PAGERSECURE $SYSTEMD_PAGER $PAGER ( "cat" "") . $SYSTEMD_LESS less ( "FRSXMK"). : K Ctrl+C . less Ctrl+C . $SYSTEMD_LESS "K" less Ctrl+C . X termcap . . () . $LESS less systemd . less(1) . $SYSTEMD_LESSCHARSET (charset) less ( "utf-8" UTF-8 ). $LESSCHARSET less systemd . $SYSTEMD_PAGERSECURE less(1) <<>> . sudo(8) pkexec(1) . . << >> ( ). << >> --no-pager PAGER=cat . . << >> . << >> LESSSECURE=1 . less(1) << >> . . SYSTEMD_PAGERSECURE=0 . $SYSTEMD_PAGERSECURE systemd << >> . UID geteuid(2) sd_pid_get_owner_uid(3) sudo(8) ($SUDO_UID [4]). SYSTEMD_PAGERSECURE=1 << >> . . $SYSTEMD_PAGERSECURE . $SYSTEMD_PAGER $PAGER $SYSTEMD_PAGERSECURE . $SYSTEMD_COLORS . () systemd . $COLORTERM "truecolor" "24bit" 24 256 $NO_COLOR $TERM . true $NO_COLOR . false . "16", "256", "24bit" ANSI . "auto-16", "auto-256", "auto-24bit" $TERM . $SYSTEMD_URLIFY . . systemd $TERM . (SEE ALSO) systemd(1), systemd-userdbd.service(8), systemd-homed.service(8), nss- systemd(8), getent(1) (NOTES) 1. JSON User Records https://systemd.io/USER_RECORD 2. JSON Group Records https://systemd.io/GROUP_RECORD 3. User/Group Record Lookup API via Varlink https://systemd.io/USER_GROUP_API 4. $SUDO_UID . systemd 261.2 USERDBCTL(1)