memlimit

package
v0.49.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0, MIT Imports: 5 Imported by: 0

Documentation

Overview

Package memlimit derives a soft heap ceiling (GOMEMLIMIT) for a tapes server process from the cgroup memory limit its orchestrator already set, so a transient allocation spike is GC-paced under the container budget instead of OOMKilling the process.

A large session allocates transiently far above its live set. The derive worker re-parses an O(N) request per wire turn because every turn re-sends the whole prior conversation, and the API server builds the same session's traces and export bundle in one response; in both the per-request garbage piles up faster than the GC reclaims it. Under the default GOGC=100 the heap is allowed to roughly DOUBLE its live size before a collection, so a big session's transient peak runs ~2x its (already large) live set and can exceed the container memory limit in a brief spike, getting the process OOM-killed even though its steady-state live set fits the budget (PCC-767).

The live set itself fits the budget; only the transient overshoot does not. A soft memory limit (GOMEMLIMIT) is the right tool: it makes the GC pace against a ceiling instead of against live-heap-times-GOGC, so the peak collapses back toward the live set, trading some extra GC CPU for a bounded heap. We derive the ceiling from the cgroup memory limit the orchestrator already sets, so it tracks the container budget without a second knob to keep in sync.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func ApplySoftMemoryLimit

func ApplySoftMemoryLimit(log *slog.Logger) int64

ApplySoftMemoryLimit sets a soft heap ceiling (GOMEMLIMIT) derived from the cgroup memory limit, so a large session's transient allocation overshoot is GC-paced under the container budget instead of OOMKilling the process. Call it once at startup, before the process has a heap worth pacing. It is a no-op — leaving the Go default in place — when the operator already pinned GOMEMLIMIT, when no cgroup memory limit is readable (local dev, unconstrained container), or on non-Linux.

Returns the soft limit applied in bytes, or 0 when none was set.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL