Documentation
¶
Overview ¶
Package servicelimits generates the systemd drop-in that bounds the memory a miren daemon may use, so a runaway control process degrades miren instead of taking the whole machine down with it.
What the limit covers ¶
The miren.service cgroup holds the coordinator process, the containerd daemon it manages, and one containerd-shim per container. It does NOT hold the containers themselves: sandboxes are created at /miren/sandbox-<id> and every other containerd workload at /<namespace>/<id>, both absolute paths that runc resolves against the cgroup root. So /miren is a top-level cgroup, a sibling of system.slice, holding app payloads, addon databases, etcd, buildkit and the two Victoria services.
Capping miren.service therefore cannot kill user workloads, which is what makes this safe to apply by default.
What the limit is sized against ¶
Not the coordinator. A production coordinator holds 489 MB of anonymous memory against 39 GB of page cache, because memory.max applies to memory.current and containerd charges every image layer it touches to this cgroup. Cache is reclaimable and anon is not, so the part a leak grows is the small one — but the limit governs the total.
That cuts both ways. The limit has to sit far enough above normal cache to avoid trimming it for no reason, and far enough below the host to stop a runaway before the machine dies. See memoryFraction.
Why a drop-in rather than the unit itself ¶
The base unit is written only when it is absent or --force is passed, so a change to the unit template never reaches a host that already has miren installed — precisely the hosts at risk. A drop-in can be rewritten unconditionally on install and on upgrade, leaves operator edits to the base unit alone, and keeps `systemctl edit` free as an override: that writes override.conf, which sorts after the 10- prefix used here and therefore wins.
Index ¶
- Constants
- func DetectSystemRAMBytes() int64
- func DropInDir(unit string) string
- func ExistingStatePath(unit string) (string, bool)
- func Remove(unit string) error
- func Render(unit string, statePath string, l Limits) string
- func UnitShortName(unit string) string
- func Write(unit string, statePath string, l Limits) (bool, error)
- type Limits
Constants ¶
const DropInFileName = "10-miren-resources.conf"
DropInFileName is the drop-in this package manages. The numeric prefix orders it before `systemctl edit`'s override.conf, so an operator override wins.
Variables ¶
This section is empty.
Functions ¶
func DetectSystemRAMBytes ¶
func DetectSystemRAMBytes() int64
DetectSystemRAMBytes reads total system memory from /proc/meminfo, returning 0 when it cannot be determined.
func ExistingStatePath ¶
ExistingStatePath returns the record directory recorded in a unit's managed drop-in, if there is one.
Install knows the effective data path (from the server's config, or the runner's --data-path). Upgrade does not, and recomputing it there would overwrite a correct custom path with the compiled-in default — the hook would then write records somewhere the daemon never reads, and restarts would go unreported with nothing to show for it. So upgrade reuses whatever install worked out, which also preserves a path an operator edited by hand.
func Remove ¶
Remove deletes the managed drop-in and, if it is then empty, the drop-in directory. A directory left behind by an operator override is kept.
func Render ¶
Render returns the drop-in body for a unit. statePath is where the ExecStopPost hook writes its record; an empty statePath omits the hook.
OOMPolicy is deliberately left at its default. OOMPolicy=kill would take the containerd shims down along with the coordinator, disrupting apps that the cap is specifically meant to spare.
func UnitShortName ¶
UnitShortName is the name an operator types, e.g. "miren" for "miren.service". An empty unit falls back to the server, so a record written before the unit name was stored still yields a usable instruction.
func Write ¶
Write renders the drop-in for a unit and installs it, replacing any previous version. It creates the drop-in directory if needed and writes atomically, so a crash mid-write cannot leave systemd with a truncated file.
It reports false when it deliberately left an existing drop-in in place: with unknown limits Render omits the memory directives, and overwriting a host's working limit with none would silently remove the protection it already had. Losing RAM detection is far more likely to be a passing oddity than a real change, so the existing file wins. A host with no drop-in yet still gets one, since even without a limit it carries the ExecStopPost hook.
Types ¶
type Limits ¶
type Limits struct {
// SystemRAMBytes is the detected host memory, or 0 when it could not be
// read.
SystemRAMBytes int64
// MemoryMaxBytes and MemoryHighBytes are 0 when host memory is unknown. In
// that case the memory directives are omitted rather than guessed: a limit
// picked blind could be far too tight and would turn a diagnostic gap into
// an outage.
MemoryMaxBytes int64
MemoryHighBytes int64
}
Limits is the set of cgroup limits computed for a host.