Edited a sysctl.d file and wondered why nothing changed: systemd-sysctl only writes the live kernel on boot or when you tell it to reload. By the end of this guide you will have put one kernel setting in a local sysctl.d file, applied it without rebooting, checked the live value, and removed the change cleanly if you do not want it. Allow about 10 minutes; you need a shell and sudo for the configuration and reload steps.
systemd-sysctl.service is an early-boot, one-shot service. It runs /usr/lib/systemd/systemd-sysctl, which reads the available sysctl.d configuration and writes values into the live kernel interface under /proc/sys/. Editing a file alone never changes the running kernel.
This machine has systemd 255, package version 255.4-1ubuntu8.17. The service is ordered after systemd-modules-load.service, before sysinit.target, and only starts when /proc/sys/net/ is writable. The commands and option notes below describe that installed systemd 255 behaviour.
First, find the current value and confirm the command is present, with a read-only check:
/usr/lib/systemd/systemd-sysctl --version
sysctl kernel.hostname
The first command reports systemd 255 on the reference machine. The second prints the current hostname setting, for example:
kernel.hostname = example-host
Warning: do not put a random example value into production. Kernel parameters can affect networking, routing, memory, security policy and crash handling. Confirm the exact key and value for your workload before writing anything.
Local administrator settings belong in /etc/sysctl.d/, and files must end in .conf. Names are sorted lexicographically across the configuration directories, so a later filename can override an earlier assignment; a two-digit prefix makes that order visible. Create a file with a name specific to your change:
sudoedit /etc/sysctl.d/60-example-kernel.conf
Add one assignment appropriate to your host. This deliberately uses a placeholder key and value, not a command that silently changes a real security or networking policy:
# Replace this example with a verified parameter for this host.
# kernel.example_parameter = example-value
The commented example is safe but does nothing. Replace it only once you have checked the parameter exists in /proc/sys/ and that the value has the effect you want. For a real setting, the syntax is a key, an equals sign and a value, such as kernel.domainname = example.com. Dots and slashes can both separate path components, but the conventional dotted form is easier to review.
Save the file, then check the effective configuration before applying anything. This does not write kernel values:
sudo /usr/lib/systemd/systemd-sysctl --cat-config --no-pager | sed -n '/60-example-kernel.conf/,$p'
--cat-config prints the contents of the configuration files and labels each file with a comment. The related --tldr option skips comments and blank lines. If your new file is missing from the output, check the spelling, the .conf suffix and its permissions before going further.
Apply every setting on the service's normal search path by restarting the one-shot service:
sudo systemctl restart systemd-sysctl.service
A successful restart normally produces no output. Check the unit result straight away:
systemctl is-active systemd-sysctl.service
systemctl status --no-pager systemd-sysctl.service
Expect active from the first command. The unit stays active after its one-shot process exits, so this means the service completed successfully, not that a daemon is still running. On a failure, read the recent log before touching more files:
journalctl -u systemd-sysctl.service -b --no-pager -n 80
A missing kernel variable is commonly caused by a module or device that is not available yet. The early-boot service cannot set a parameter that only appears after a later module load. The sysctl.d documentation recommends a udev rule for a setting that becomes available with a device or module; loading the module early through modules-load.d is another option, but that changes boot behaviour and should be a deliberate decision, not a quick fix.
Read the specific key after the reload. Use sysctl for a human-readable result:
sysctl kernel.example_parameter
Or read the matching procfs path directly. Dots in a sysctl name become slashes in /proc/sys/:
cat /proc/sys/kernel/example_parameter
Replace both placeholders with the same real parameter. The output must contain the value you intended. If the file and service both succeeded but the value is unchanged, look for a later configuration file overriding it. Display the complete effective input and search for the key:
sudo /usr/lib/systemd/systemd-sysctl --tldr --no-pager | grep -F 'kernel.example_parameter'
For a narrow, repeatable update, the binary also accepts --prefix=. This applies matching rules from the configuration search path rather than every rule:
sudo /usr/lib/systemd/systemd-sysctl --prefix=kernel.example_parameter
Passing a configuration filename is narrower still. The name resolves through the sysctl.d directories, with higher-precedence locations winning:
sudo /usr/lib/systemd/systemd-sysctl 60-example-kernel.conf
Use the service restart for an ordinary full reload, and a prefix or filename when you are deliberately limiting the change. The --strict= option, available since systemd 252, makes failures such as an invalid variable or insufficient permission produce a non-zero exit status. A setting whose name begins with a single minus is the documented exception, kept intentionally non-fatal.
If this was a temporary test, remove or comment out the assignment in the file. This changes system state, so review the target before deleting anything:
sudoedit /etc/sysctl.d/60-example-kernel.conf
sudo systemctl restart systemd-sysctl.service
Removing the assignment stops this file setting the value on the next reload and future boots. It does not necessarily restore the old live value: the kernel keeps the current value until another rule writes it or the system reboots. Restore a known previous value explicitly if that matters, and verify it:
sudo /usr/lib/systemd/systemd-sysctl --prefix=kernel.example_parameter
sysctl kernel.example_parameter
If a vendor file must be disabled rather than overridden, the documented mechanism is a symlink with the same filename pointing to /dev/null in /etc/sysctl.d/. Treat that as a persistent policy change, record why it exists, and remember an initrd may need regenerating when it embeds the vendor file.
/proc/sys/ until the service or the binary is run.active does not prove every optional parameter was available. Read the target value and the journal too.--cat-config./etc/sysctl.d/*.conf file.systemctl is-active systemd-sysctl.service reports active.sysctl or /proc/sys has the intended live value.