Part 1 · 1 chapters · ~8 min

cgroups v2

The unified hierarchy, creating a cgroup by making a directory, moving processes with cgroup.procs, CPU, memory, I/O and PID controllers, memory.high versus memory.max, memory.events and PSI, delegation to unprivileged users, and how systemd and container runtimes manage the tree.

2

Limiting a process with mkdir and echo

code
# Linux only, cgroups v2 mounted at /sys/fs/cgroup
sudo mkdir /sys/fs/cgroup/demo
echo "+cpu +memory +pids" | sudo tee /sys/fs/cgroup/cgroup.subtree_control
echo "50000 100000" | sudo tee /sys/fs/cgroup/demo/cpu.max        # half a CPU
echo 256M           | sudo tee /sys/fs/cgroup/demo/memory.max
echo 100            | sudo tee /sys/fs/cgroup/demo/pids.max
echo $$             | sudo tee /sys/fs/cgroup/demo/cgroup.procs   # move this shell (and its children) in
stress-ng --cpu 2 --timeout 10s &  cat /sys/fs/cgroup/demo/cpu.stat   # nr_throttled grows
cat /sys/fs/cgroup/demo/memory.events                                 # oom_kill counts when memory.max is hit
CGROUPS V2 CONTROLLERS
the files that limit a container
cpu.max"quota period": 50000 100000 =half a CPU. Throttles whenexceeded.cpu.weightRelative share under contention(1-10000, default 100).memory.maxHard limit: reclaim, then OOM killinside the group.memory.highSoft limit: throttle and reclaimbefore the hard limit.io.maxPer-device read and write bytesand IOPS limits.pids.maxCap on processes: stops forkbombs.
swipe the figure sideways, or tap expand for full screen
1/4
cpu
cpu.max caps CPU time per period; cpu.weight shares CPU proportionally when there is contention. Kubernetes maps limits and requests to these (Kernel P7).
cap and sharelimits and requests