Resource Limits
Cgroups v2 provides a unified interface for managing resource limits and scheduling policies for processes and containers. This section demonstrates how to enforce CPU shares, memory limits, and throttling using cgroups v2 controllers. These techniques are critical for isolating workloads, preventing resource starvation, and ensuring predictable performance in multi-tenant environments.
CPU Limiting¶
Absolute CPU Limits¶
To enforce an absolute CPU limit (e.g., 50% of a single CPU), use the cpu.max property. This sets a hard cap on CPU time consumption, measured in microseconds per CPU.
# Create a cgroup and set CPU limit
sudo cgcreate -g cpu:/mycpu_limit
echo 500000 | sudo tee /sys/fs/cgroup/cpu/mycpu_limit/cpu.max
500000microseconds = 0.5 seconds per CPU cycle.- This limits the group to 50% of a single CPU core.
Relative CPU Shares¶
For relative CPU allocation (e.g., 2x the default share), use cpu.weight (0–100000). This is useful for prioritizing workloads without absolute caps.
# Set relative CPU weight (2x default)
echo 200000 | sudo tee /sys/fs/cgroup/cpu/mycpu_limit/cpu.weight
Note: Absolute limits (
cpu.max) take precedence over relative weights.
Memory Limiting¶
Memory Usage Limits¶
Set a hard limit on memory consumption using memory.max. This prevents processes from exceeding the specified size.
# Create a cgroup and set memory limit
sudo cgcreate -g memory:/mymem_limit
echo 1073741824 | sudo tee /sys/fs/cgroup/memory/mymem_limit/memory.max
1073741824bytes = 1 GiB.- Exceeding this limit triggers the OOM killer, which may terminate processes in the group.
OOM Control¶
Adjust how the OOM killer handles memory limits using memory.oom_control:
# Prevent OOM killer from killing processes in this group
echo 0 | sudo tee /sys/fs/cgroup/memory/mymem_limit/memory.oom_control
0disables OOM killer intervention (high risk for system instability).1enables OOM killer (default behavior).
Throttling¶
CPU Throttling¶
Limit CPU usage rate using cpu.throttling. This is useful for preventing processes from monopolizing CPU cycles.
# Set CPU throttling rate (e.g., 1000 cycles per second)
echo 1000 | sudo tee /sys/fs/cgroup/cpu/mycpu_limit/cpu.throttling
- This enforces a maximum of 1000 cycles per second, effectively capping CPU usage.
Memory Throttling¶
Memory throttling is less common but can be achieved via memory.throttling (requires kernel support). It limits memory bandwidth usage, useful for I/O-bound workloads.
# Set memory throttling rate (e.g., 1000 bytes per second)
echo 1000 | sudo tee /sys/fs/cgroup/memory/mymem_limit/memory.throttling
Key takeaways¶
- Use
cpu.maxfor absolute CPU limits andcpu.weightfor relative shares. - Set
memory.maxto enforce hard memory limits and usememory.oom_controlto manage OOM behavior. - Throttling via
cpu.throttlingandmemory.throttlingensures controlled resource consumption. - Always verify cgroup paths and kernel support for cgroups v2 before applying limits.