Ubuntu Root Filesystem Space Exhaustion: A Runbook from Immediate Containment to Capacity Governance
Insufficient space on the root filesystem can prevent services from writing data, cause package updates to fail, result in lost logs, and even disrupt databases. This article explains how to confirm the affected filesystem, identify the source of growth, safely reclaim package-cache and log space, handle deleted files that remain open by processes, and establish monitoring, retention, and expansion plans. It emphasizes collecting evidence before deleting data and validating recovery before closing the incident, helping prevent cleanup from causing a secondary incident or creating gaps in investigative evidence.