Documentation
¶
Overview ¶
Package memlimit derives a soft heap ceiling (GOMEMLIMIT) for a tapes server process from the cgroup memory limit its orchestrator already set, so a transient allocation spike is GC-paced under the container budget instead of OOMKilling the process.
A large session allocates transiently far above its live set. The derive worker re-parses an O(N) request per wire turn because every turn re-sends the whole prior conversation, and the API server builds the same session's traces and export bundle in one response; in both the per-request garbage piles up faster than the GC reclaims it. Under the default GOGC=100 the heap is allowed to roughly DOUBLE its live size before a collection, so a big session's transient peak runs ~2x its (already large) live set and can exceed the container memory limit in a brief spike, getting the process OOM-killed even though its steady-state live set fits the budget (PCC-767).
The live set itself fits the budget; only the transient overshoot does not. A soft memory limit (GOMEMLIMIT) is the right tool: it makes the GC pace against a ceiling instead of against live-heap-times-GOGC, so the peak collapses back toward the live set, trading some extra GC CPU for a bounded heap. We derive the ceiling from the cgroup memory limit the orchestrator already sets, so it tracks the container budget without a second knob to keep in sync.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func ApplySoftMemoryLimit ¶
ApplySoftMemoryLimit sets a soft heap ceiling (GOMEMLIMIT) derived from the cgroup memory limit, so a large session's transient allocation overshoot is GC-paced under the container budget instead of OOMKilling the process. Call it once at startup, before the process has a heap worth pacing. It is a no-op — leaving the Go default in place — when the operator already pinned GOMEMLIMIT, when no cgroup memory limit is readable (local dev, unconstrained container), or on non-Linux.
Returns the soft limit applied in bytes, or 0 when none was set.
Types ¶
This section is empty.