Configure systemd-logind Safely with a Drop-in File
You will finish with a local systemd-logind configuration drop-in that is easy to inspect, override and remove. The examples use the installed systemd 255.4 package on Ubuntu, whose relevant manual is logind.conf(5). Allow about ten minutes, plus a restart if you apply a change.
The route
Jump straight to the step you need, or tick off Done means at the end.
You need shell access and sudo for the changes. This guide uses a harmless setting first, then shows the boundaries around logout cleanup and lid handling. Power, sleep and session settings can disrupt people or terminate processes, so read the warning before applying those examples.
1. Check the installed service and its configuration paths
Start with read-only checks. The main file is normally under /etc/systemd/ or /usr/lib/systemd/. Drop-ins can be supplied by the vendor, by a local administrator, or transiently at runtime:
$ systemd --version | head -n 1
systemd 255 (255.4-1ubuntu8.17)
$ systemctl status systemd-logind --no-pager
$ ls -ld /etc/systemd/logind.conf.d /run/systemd/logind.conf.d /usr/lib/systemd/logind.conf.d 2>/dev/null
A missing directory is normal. Do not create all three. For an administrator change, use /etc/systemd/logind.conf.d/. Files there override the main configuration and are considered alongside drop-ins in the other directories, ordered by filename.
Checkpoint
Write down the systemd version and confirm that the service you are changing is systemd-logind.service. A similarly named desktop setting or display-manager setting is a different control path.
2. Create a small, ordered drop-in
Use a descriptive two-digit prefix. The filename is part of the precedence rule: when the same option appears more than once, the lexicographically last applicable file wins for single-value settings.
$ sudo install -d -m 0755 /etc/systemd/logind.conf.d
$ sudo tee /etc/systemd/logind.conf.d/60-local-login.conf >/dev/null <<'EOF'
[Login]
NAutoVTs=6
EOF
NAutoVTs=6 is the documented default on this system. It controls how many unused virtual terminals can get an automatically spawned login prompt. The example therefore demonstrates the file format without changing the effective value. Replace it only when you have a specific console-login requirement.
The section must be [Login], option names are case-sensitive in practice, and the file must end in .conf. Keep one purpose per file. That makes a later rollback obvious and prevents an unrelated setting from being hidden in a large local copy of the vendor file.
3. Inspect the effective configuration
Ask systemd to show the unit's configuration and the drop-in list:
$ systemctl cat systemd-logind.service
$ systemctl show systemd-logind.service -p DropInPaths --value
/etc/systemd/logind.conf.d/60-local-login.conf
systemctl cat is useful for service-unit drop-ins, but it does not render every key from logind.conf. To inspect the files that can affect logind, search them in precedence order:
$ find /usr/lib/systemd /usr/local/lib/systemd /run/systemd /etc/systemd \
-path '*/logind.conf.d/*.conf' -type f -print 2>/dev/null | sort
$ rg -n '^(NAutoVTs|ReserveVT|KillUserProcesses|KillOnlyUsers|KillExcludeUsers|IdleAction|HandleLidSwitch)=' \
/usr/lib/systemd/logind.conf /usr/local/lib/systemd/logind.conf \
/run/systemd/logind.conf /etc/systemd/logind.conf \
/usr/lib/systemd/logind.conf.d /usr/local/lib/systemd/logind.conf.d \
/run/systemd/logind.conf.d /etc/systemd/logind.conf.d 2>/dev/null
The last matching assignment is the one to investigate for a single-value option. This catches a common trap: creating a correctly named file, then being surprised because a later file with a higher lexical name overrides it.
4. Apply the change carefully
After editing logind.conf or a drop-in, ask the service manager to reload the service configuration:
$ sudo systemctl reload systemd-logind
$ systemctl is-active systemd-logind
active
The reload is service-disrupting in the broad sense: logind manages sessions, seats and power-key handling. Avoid doing it during a critical remote maintenance window. Keep an existing SSH session open until the service is confirmed active. If reload is unsupported or fails on a particular system, inspect the journal before considering a restart:
$ systemctl status systemd-logind --no-pager
$ journalctl -u systemd-logind -b --no-pager -n 40
Do not use systemctl daemon-reload as a substitute for reloading logind's own configuration. That command makes systemd reread unit files; this guide changes logind's separate configuration files.
5. Choose session cleanup deliberately
KillUserProcesses= controls whether processes in a user's session scope are killed at logout. The installed manual defaults it to no, but this is not the whole story: KillOnlyUsers= and KillExcludeUsers= refine the result, and a lingering user manager can keep processes outside the session scope.
Warning
Setting it to yes can terminate work and breaks tools such as screen and tmux unless they have been moved out of the session scope. Do not apply this to a shared or remote machine without checking who relies on persistent sessions.
$ sudo tee /etc/systemd/logind.conf.d/70-session-cleanup.conf >/dev/null <<'EOF'
[Login]
KillUserProcesses=yes
KillExcludeUsers=admin
EOF
$ sudo systemctl reload systemd-logind
Here, admin is an obvious placeholder: replace it with a real account only after deciding why it must be exempted. If KillExcludeUsers is omitted, root is excluded by default. To undo this example, remove that drop-in and reload logind:
$ sudo rm /etc/systemd/logind.conf.d/70-session-cleanup.conf
$ sudo systemctl reload systemd-logind
6. Treat lid and power actions as a safety boundary
Options such as HandleLidSwitch=, HandlePowerKey= and IdleAction= can suspend, power off, reboot or lock the machine. The default lid action is suspend; the external-power lid setting is ignored unless explicitly configured, and a docking station or multiple displays can select HandleLidSwitchDocked= instead.
Use a read-only inspection before changing these settings:
$ rg -n '^(HandleLidSwitch|HandleLidSwitchExternalPower|HandleLidSwitchDocked|HandlePowerKey|IdleAction)=' \
/etc/systemd /run/systemd /usr/local/lib/systemd /usr/lib/systemd 2>/dev/null
If you deliberately want closing the lid to do nothing on a machine that must stay awake, the change is:
$ sudo tee /etc/systemd/logind.conf.d/80-lid-policy.conf >/dev/null <<'EOF'
[Login]
HandleLidSwitch=ignore
EOF
$ sudo systemctl reload systemd-logind
Test it only when you have console or remote recovery access. Undo it with sudo rm /etc/systemd/logind.conf.d/80-lid-policy.conf, then reload again. A setting in logind does not override an application holding an inhibitor lock or a desktop environment that manages the event itself.
7. Done means
- The local change is in
/etc/systemd/logind.conf.d/, uses a.conffilename and has a clear numeric prefix. - The option is under
[Login], and later files have been checked for an override. systemctl is-active systemd-logindreportsactiveafter the reload.- You have recorded the undo command and considered its effect on sessions, remote access and running work.