servicelimits

package
v0.16.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 29, 2026 License: Apache-2.0 Imports: 5 Imported by: 0

Documentation

Overview

Package servicelimits generates the systemd drop-in that bounds the memory a miren daemon may use, so a runaway control process degrades miren instead of taking the whole machine down with it.

What the limit covers

The miren.service cgroup holds the coordinator process, the containerd daemon it manages, and one containerd-shim per container. It does NOT hold the containers themselves: sandboxes are created at /miren/sandbox-<id> and every other containerd workload at /<namespace>/<id>, both absolute paths that runc resolves against the cgroup root. So /miren is a top-level cgroup, a sibling of system.slice, holding app payloads, addon databases, etcd, buildkit and the two Victoria services.

Capping miren.service therefore cannot kill user workloads, which is what makes this safe to apply by default.

What the limit is sized against

Not the coordinator. A production coordinator holds 489 MB of anonymous memory against 39 GB of page cache, because memory.max applies to memory.current and containerd charges every image layer it touches to this cgroup. Cache is reclaimable and anon is not, so the part a leak grows is the small one — but the limit governs the total.

That cuts both ways. The limit has to sit far enough above normal cache to avoid trimming it for no reason, and far enough below the host to stop a runaway before the machine dies. See memoryFraction.

Why a drop-in rather than the unit itself

The base unit is written only when it is absent or --force is passed, so a change to the unit template never reaches a host that already has miren installed — precisely the hosts at risk. A drop-in can be rewritten unconditionally on install and on upgrade, leaves operator edits to the base unit alone, and keeps `systemctl edit` free as an override: that writes override.conf, which sorts after the 10- prefix used here and therefore wins.

Index

Constants

View Source
const DropInFileName = "10-miren-resources.conf"

DropInFileName is the drop-in this package manages. The numeric prefix orders it before `systemctl edit`'s override.conf, so an operator override wins.

Variables

This section is empty.

Functions

func DetectSystemRAMBytes

func DetectSystemRAMBytes() int64

DetectSystemRAMBytes reads total system memory from /proc/meminfo, returning 0 when it cannot be determined.

func DropInDir

func DropInDir(unit string) string

DropInDir returns the systemd drop-in directory for a unit.

func ExistingStatePath

func ExistingStatePath(unit string) (string, bool)

ExistingStatePath returns the record directory recorded in a unit's managed drop-in, if there is one.

Install knows the effective data path (from the server's config, or the runner's --data-path). Upgrade does not, and recomputing it there would overwrite a correct custom path with the compiled-in default — the hook would then write records somewhere the daemon never reads, and restarts would go unreported with nothing to show for it. So upgrade reuses whatever install worked out, which also preserves a path an operator edited by hand.

func Remove

func Remove(unit string) error

Remove deletes the managed drop-in and, if it is then empty, the drop-in directory. A directory left behind by an operator override is kept.

func Render

func Render(unit string, statePath string, l Limits) string

Render returns the drop-in body for a unit. statePath is where the ExecStopPost hook writes its record; an empty statePath omits the hook.

OOMPolicy is deliberately left at its default. OOMPolicy=kill would take the containerd shims down along with the coordinator, disrupting apps that the cap is specifically meant to spare.

func UnitShortName

func UnitShortName(unit string) string

UnitShortName is the name an operator types, e.g. "miren" for "miren.service". An empty unit falls back to the server, so a record written before the unit name was stored still yields a usable instruction.

func Write

func Write(unit string, statePath string, l Limits) (bool, error)

Write renders the drop-in for a unit and installs it, replacing any previous version. It creates the drop-in directory if needed and writes atomically, so a crash mid-write cannot leave systemd with a truncated file.

It reports false when it deliberately left an existing drop-in in place: with unknown limits Render omits the memory directives, and overwriting a host's working limit with none would silently remove the protection it already had. Losing RAM detection is far more likely to be a passing oddity than a real change, so the existing file wins. A host with no drop-in yet still gets one, since even without a limit it carries the ExecStopPost hook.

Types

type Limits

type Limits struct {
	// SystemRAMBytes is the detected host memory, or 0 when it could not be
	// read.
	SystemRAMBytes int64

	// MemoryMaxBytes and MemoryHighBytes are 0 when host memory is unknown. In
	// that case the memory directives are omitted rather than guessed: a limit
	// picked blind could be far too tight and would turn a diagnostic gap into
	// an outage.
	MemoryMaxBytes  int64
	MemoryHighBytes int64
}

Limits is the set of cgroup limits computed for a host.

func Compute

func Compute(ramBytes int64) Limits

Compute derives the cgroup limits for a host with ramBytes of memory. A ramBytes of 0 means the host's memory could not be determined.

func (Limits) Known

func (l Limits) Known() bool

Known returns whether a memory limit could be computed.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL