OnCallReady

Lesson 1.20 · First Login · 11 min read

The disk you were given

In plain words

Imagine a notebook the size of 40 pages that only uses real paper when you write on a page. Blank pages cost nothing. That is a thin-provisioned disk: UTM promised your VM 40G, but the file on your Mac only grows as the VM writes. A thick one would cut all 40 pages from the forest up front.

Inside the notebook, Ubuntu drew a flexible box (LVM) and put your main folder / in only half of it, keeping the rest in reserve so it can grow later without redrawing everything. That is why lsblk shows a 40G vda but df -h / shows about 18G. And no lock on the cover: no LUKS encryption, so the notebook opens without a secret word at every boot.

You gave the VM a 40G disk. The login banner says Usage of /: 40.4% of 18.01GB. Where did the other 22G go? When a disk fills up at 3am, the first question is always "which disk, which piece of it, and how big is it really" - this lesson teaches you to read that stack.

What you need to know already: 1.3 The tree (mount points), 1.15 Who's in charge (boot, initramfs).

The layers, bottom to top

Ubuntu adds one more layer in between, LVM (below).

40G on paper, 18G to use

lsblk (list block devices - disks and anything built on them) draws that stack as a tree:

$ lsblk
NAME                      MAJ:MIN RM  SIZE RO TYPE MOUNTPOINTS
vda                       253:0    0   40G  0 disk
├─vda1                    253:1    0    1G  0 part /boot/efi
├─vda2                    253:2    0    2G  0 part /boot
└─vda3                    253:3    0 36.9G  0 part
  └─ubuntu--vg-ubuntu--lv 252:0    0   18G  0 lvm  /
vdb                       253:16   0   50G  0 disk
└─vdb1                    253:17   0   50G  0 part /data
...

The columns: NAME (indented under what it sits on), MAJ:MIN (the kernel's internal device numbers - ignore), RM (removable? 0 = no), SIZE, RO (read-only? 0 = no), TYPE (disk, part = partition, lvm = logical volume), and MOUNTPOINTS (where it is attached, if anywhere).

vda is the virtual disk UTM gave the VM. The "v" is for virtio: a virtual device the guest knows is virtual, so it talks to the hypervisor directly instead of pretending to drive real hardware - much faster. vda1, vda2, vda3 are its three partitions: two small ones for boot files (/boot/efi for the firmware, /boot for the kernel), and one big one.

LVM: the flexible layer

LVM (Logical Volume Manager) puts a flexible layer between partitions and filesystems. Three words:

(In lsblk and df the name shows as ubuntu--vg-ubuntu--lv: the VG and LV names joined by -, with the dashes inside each name doubled so they can be told apart.)

The part that surprises everyone: Ubuntu's guided install gives the root LV only half the pool by default (on disks between about 20G and 200G; above that the root LV is capped at 100G). The rest stays free in the VG, so you can grow / later without repartitioning:

sudo vgs                        list VGs; the VFree column = pool space not yet handed out
sudo lvextend -l +100%FREE /dev/ubuntu-vg/ubuntu-lv    grow the LV by all the free space
sudo resize2fs /dev/ubuntu-vg/ubuntu-lv                grow the ext4 filesystem to fill it

(Two steps, because the LV and the filesystem on it are separate layers: first make the volume bigger, then tell the filesystem it may use the new room.)

That is why df -h / says ~19G while the disk says 40G. Nothing is wrong.

df: how full is each filesystem

df (disk free) reports every mounted filesystem; -h = human sizes:

$ df -h /
Filesystem                         Size  Used Avail Use% Mounted on
/dev/mapper/ubuntu--vg-ubuntu--lv   19G  7.7G  9.5G  45% /

Filesystem is the device it lives on (/dev/mapper/... is how LVM volumes appear), then total Size, Used, Available, Use%, and the mount point. Used + Avail is a bit less than Size: ext4 keeps about 5% back for root (chapter 4).

df -h with no path lists every mounted filesystem. Lines of type tmpfs are filesystems that live in memory, not on disk (/run holds files that only matter until the next reboot) - you can ignore them for now.

Thin vs thick provisioning

You told UTM "40G". It did not take 40G from your Mac. The VM's whole disk is one file on the Mac, in a format called qcow2, which starts at a few hundred MB and grows as the guest writes - thin provisioning.

Note also that qcow2 does not shrink when you delete files inside the guest. Freeing 10G in the VM does not give 10G back to macOS until the image is compacted (rewritten without the empty space).

No LUKS

You chose guided storage without encryption. LUKS is Linux's standard disk encryption: everything on the volume is scrambled until you type a passphrase at boot. That protects a stolen disk - and means the box cannot boot unattended. Correct choice for a lab VM, wrong choice for a laptop.

What you can now do

Why it helps

Disk questions come up in every "the server is out of space" incident: which disk, which partition or volume, which filesystem is full? lsblk plus df -h answers that in two commands. Knowing that Ubuntu leaves half the volume group free turns a full / at 2am into a two-line fix (lvextend + resize2fs) instead of a rebuild.

Thin versus thick provisioning is a trade-off you will meet wherever storage is shared: over-promising saves money until the real storage fills up and everything on it fails at once. And the LUKS choice - encrypted disks that need a passphrase at boot - explains why servers that must restart unattended handle encryption differently from laptops.

Commands in this lesson

df lsblk

FAQ

Why does df show 18G when the disk is 40G?

Because the filesystem only fills the logical volume, and Ubuntu's guided install only gave that volume part of the volume group. lsblk shows the disk (40G), the partition handed to LVM (about 37G) and the logical volume (18G). The rest sits unallocated in the volume group, visible with sudo vgs in the VFree column. You can grow the LV and then the filesystem, even while in use, with lvextend and resize2fs.

What is LVM for, if I could just partition the disk?

LVM adds a layer between disks and filesystems: partitions become physical volumes, which are pooled into a volume group, from which you cut logical volumes. You can grow volumes while they are in use, add another disk to the pool, and take snapshots (frozen copies), none of which plain partitions allow easily. The cost is one more layer to understand when you read lsblk.

If I delete files in the VM, does my Mac get the space back?

Not automatically. The qcow2 image file grows when the VM writes new data, but deleting a file only marks space as free inside the VM's filesystem; the image file on the Mac stays the same size. To reclaim it, the VM has to tell the virtual disk which space is free (sudo fstrim -av does that, if the disk supports it), or you compact the image with UTM's tools while the VM is off.

What does v in vda mean?

virtio: a virtual device designed for VMs. Instead of pretending to be a real disk controller, which the guest would have to drive step by step as if it were hardware, the guest uses a driver that knows it is virtual and talks to the hypervisor directly. It is much faster. lspci shows these as "Virtio block device". On other machines you will see names like sda or nvme0n1 for other kinds of disk.

Is thin provisioning dangerous?

It is a bet. You promise more space than really exists, betting the guests will not all fill up at once. It saves a lot of space and most setups use it. The danger is that when the real storage runs out, every guest on it gets write errors at the same moment, which is much worse than one full disk. Thin works when someone watches the real free space; thick buys predictability at the cost of paying for empty space.

In an interview Junior

What is the difference between a disk, a partition, a filesystem and a mount point, and how do you see them?

Ubuntu puts LVM in between: a partition becomes a PV, PVs form a pool (VG), and slices of it (LVs) carry the filesystems and can be grown later.

lsblk draws the whole stack as a tree with sizes and mount points; df -h shows how full each mounted filesystem is. That is why the VM's / is 18G on a 40G disk: the installer gave the root LV only half the pool.

Also asked: What is the difference between thin and thick provisioning? · The root filesystem is full but the volume group has free space. How do you grow it? · What is LUKS, and when would you not use it?

Practise this lesson in the terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.