cgroups Limits
Linux systems can leverage cgroups (control groups) to enforce memory limits on processes, preventing out-of-memory (OOM) conditions in containerized environments. By restricting memory usage per process or group, cgroups act as a safety net against runaway applications. This section explains how to configure memory limits and OOM behavior using cgroups.
Configuring Memory Limits¶
To enforce memory limits, use the memory.limit_in_bytes parameter in the cgroup. This parameter defines the maximum amount of memory a process or group can use. For example:
# Create a cgroup named "mygroup" in the memory controller
sudo cgcreate -g memory:/mygroup
# Set a memory limit of 512MiB
sudo cgset -r memory.limit_in_bytes=536870912 mygroup
Verification:
This returns 536870912 (512MiB). If a process in this group exceeds the limit, the kernel will trigger the OOM killer.
Controlling OOM Behavior¶
The memory.oom_control interface allows fine-grained control over OOM behavior. Key parameters include:
-
oom_kill_disable: Disables the OOM killer for the cgroup. Use with caution, as it can lead to system instability if memory is exhausted. -
oom_score_adj: Adjusts the OOM score (lower values make processes less likely to be killed). Valid range:-1000to1000.
Best Practices for Containerized Environments¶
- Use container runtimes: Most container runtimes (e.g., Docker, containerd) automatically manage cgroups. For example, Docker's
--memoryflag setsmemory.limit_in_bytesfor containers. - Combine with
memory.swappiness: Reduce swapping to minimize OOM risk: - Monitor with tools: Use
cgexecto run processes under cgroups andcggetto inspect limits:
Key takeaways¶
- Use
memory.limit_in_bytesto enforce strict memory boundaries for processes or groups. - Disable the OOM killer selectively with
oom_kill_disablefor critical workloads, but avoid this in production without safeguards. - Pair cgroups with
memory.swappinesstuning to prioritize memory over swap usage. - In containerized environments, rely on runtime tools (e.g., Docker) to abstract cgroup configuration, but understand the underlying mechanics for troubleshooting.
- Always validate cgroup settings with
cggetor direct sysfs reads to ensure they are applied correctly.