A junior administrator is trying to remove the `devops` group from a Linux system. They attempt to use `groupdel devops` but receive an error indicating the group is still the primary group for one or more users. Which of the following is the correct sequence of actions to safely remove the `devops` group?
- A1. Identify users in `devops` group. 2. Remove users from `devops` supplementary group. 3. `groupdel devops`.
- B1. Identify users with `devops` as primary group. 2. Change primary group for those users. 3. `groupdel devops`.
- C1. `userdel -r` for all users in `devops`. 2. `groupdel devops`.
- D1. `groupmod -g` to change GID of `devops`. 2. `groupdel devops`.
Show answer & explanationAnswer & explanation
Correct answer: B. 1. Identify users with `devops` as primary group. 2. Change primary group for those users. 3. `groupdel devops`.
A group cannot be deleted if it is still the primary group for any user. The correct procedure involves first identifying which users have `devops` as their primary group (e.g., by checking `/etc/passwd` or using `getent passwd | grep ':x:.*:.*:.*:/home/:/bin/bash$' | awk -F: '{print $1,$4}' | while read user gid; do if [ "$(getent group $gid | cut -d: -f1)" = "devops" ]; then echo $user; fi; done`). Then, change the primary group for those users to another existing group (e.g., `usermod -g newgroup user_name`). Finally, `groupdel devops` can be executed.
Why the other options are wrong
- A. Removing users from a supplementary group is not sufficient if `devops` is still their *primary* group. The error explicitly states 'primary group'.
- C. `userdel -r` deletes user accounts and their home directories, which is an extreme and often unnecessary action just to delete a group. It doesn't directly solve the primary group issue for other users.
- D. Changing the GID of the group (`groupmod -g`) does not resolve the issue of users still having that group (even with a new GID) as their primary group. The group still exists and is still primary for those users.
Group Deletion Prerequisites
To successfully delete a group using `groupdel`, no user should have that group assigned as their primary group.
- Users' primary group is stored in `/etc/passwd` (GID field).
- Use `usermod -g` to change a user's primary group.
- Use `groupdel` to remove a group.
Memory trick: PRIMARY users must LEAVE before the GROUP can be gone!