Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Linux disk pressure: explain missing space before deleting application data

Last updated: 5 Oct 20267 min read
tutorial
AdvancedBy AITrove Editorial

Filesystem free-block accounting and a walk of visible directory entries answer different questions. df reports the mounted filesystem's space; du sums files it can traverse under a path. If an application keeps a deleted log open, the directory entry disappears while the file's blocks stay allocated until the descriptor closes. Reserved blocks, snapshots, container layers, quotas, and mount boundaries can produce other differences. Inode exhaustion is a separate failure: a filesystem can have free bytes yet refuse to create another file. First identify the filesystem and its workload, then attribute usage by visible data, open unlinked files, and account-level limits.

Operational decision

A ledger API stops accepting writes with 23 GiB apparently free under the operator's home directory. The actual database mount is 99% full. The responder records df for bytes and inodes, confirms the mount source, and compares du only inside that mount so a nested backup mount does not distort totals. They find a deleted 41 GiB audit file still held by the writer process. Rather than killing the database or removing random files, they coordinate a supported log reopen or controlled restart, check the recovery window, and verify free space plus a real write. If the missing space is instead an immutable snapshot, they follow its retention owner and recovery policy before removal.

bash
df -hT /srv/ledger
df -i /srv/ledger
findmnt /srv/ledger
lsof +L1

Cost and verification

A directory scan can consume I/O and take minutes on a large tree, so run it with a bounded scope during an incident. Reopening a log may briefly interrupt work; deleting files without ownership evidence can destroy recovery material. Track free bytes, free inodes, growth rate, and the oldest recoverable backup. A dashboard that reports only percent used may miss a small absolute reserve on a large volume. The operator should record the file owner, process ID, and expected release of any unlinked blocks before changing process state.

Common Mistakes

  • Do not run du across a different mounted filesystem and compare it with one df row.
  • Do not assume deleting an open file releases its blocks immediately.
  • Do not erase backups or database files solely to clear an alert.

Connected lessons

Practice and check

devops
linux
storage-operations
Storage details