Rescuing a system that boots to emergency mode because /boot ran out of space

When /boot runs out of space and the machine drops into emergency mode

A few minutes after a kernel update, you power on the server and the console shows:

System boot failed.
Emergency mode - type "journalctl -xb" to view logs.

The root filesystem is mounted read‑only, the initramfs cannot be loaded, and the machine refuses to start. The culprit is almost always a full /boot partition. In this post I walk through the exact steps to diagnose, free space, and reboot safely. I’ll cover the most common distributions, show how to keep the system lean, and touch on security best‑practices that come with kernel housekeeping.


Why /boot matters

/boot holds three critical items:

  1. Kernel images (vmlinuz-*) – the code that the BIOS/UEFI loads.
  2. Initramfs archives (initrd.img-*) – a temporary root filesystem that prepares the real root.
  3. Bootloader configuration (grub.cfg, bootctl, etc.) – tells the loader which kernel to start.

If any of these are missing or the partition is full, the boot loader cannot hand control to the kernel. Systemd then drops into emergency mode to protect the filesystem.


Quick sanity check

Boot into the emergency shell (you’ll see a prompt like root@hostname:/#). From there:

# Verify the mount point
mount | grep ' /boot '

# Show free space
df -h /boot

# List the files that occupy the most space
du -sh /boot/* | sort -h

If df reports 100 % usage, you’re in the right place. If /boot is not a separate partition, the problem is usually that the root filesystem is full, but the emergency mode message still points to /boot because the initramfs is missing.


1. Remove old kernels

The most common cause is a backlog of old kernels. Modern distros keep several images for rollback, but you can trim the list safely.

Debian/Ubuntu

# List installed kernels
dpkg -l | awk '/linux-image/ {print $2, $3}'

# Remove the oldest non‑current kernel
apt-get purge linux-image-5.10.0-12-generic

# Clean up automatically
apt-get autoremove --purge

apt-get autoremove will also remove orphaned linux-headers packages. After purging, run update-grub to regenerate the menu:

update-grub

RHEL/CentOS

# Show installed kernels
rpm -qa kernel | sort

# Remove a specific kernel
yum remove kernel-3.10.0-957.el7

# Or use dnf on newer versions
dnf remove kernel-core-5.11.0-12.el8

# Clean up
yum autoremove

The boot loader will automatically prune the menu entries.

Arch Linux

# List installed kernels
pacman -Q linux

# Remove an older kernel
pacman -Rns linux-lts

# Update initramfs for the remaining kernels
mkinitcpio -P

Arch’s pacman -Rns removes the package and its unused dependencies. The -P flag rebuilds all initramfs images.


2. Shrink or remove large initramfs files

Sometimes the initramfs itself is bloated. On systems that use dracut or mkinitcpio, you can rebuild a minimal image.

# Debian/Ubuntu
update-initramfs -u -k all

# RHEL/CentOS
dracut -f

# Arch
mkinitcpio -P

If you still see a huge file (e.g., > 200 MiB), consider disabling modules that are not needed. For example, on Debian you can edit /etc/initramfs-tools/modules and remove entries for unused filesystems or drivers.


3. Verify bootloader configuration

A mis‑configured bootloader can also cause a full‑/boot error if it points to a non‑existent kernel.

GRUB (most distros)

# Show the current config
cat /boot/grub/grub.cfg | grep 'menuentry' | wc -l

# Regenerate the config
grub-mkconfig -o /boot/grub/grub.cfg

If you see duplicate entries or references to kernels that no longer exist, the regeneration step will clean them up.

systemd‑boot

bootctl list

If the listed entries reference missing files, delete the corresponding .conf files in /boot/loader/entries/ and run:

bootctl update

4. Check for accidental data in /boot

Occasionally users copy logs, backups, or other files into /boot by mistake. A quick scan can reveal hidden bloat.

find /boot -type f -size +10M -exec ls -lh {} \;

If you find unexpected files, move them elsewhere:

mv /boot/old_logs.tar.gz /var/backups/

#TAGS: linux, boot, kernel, troubleshooting


See also