Skip to content

cgroups Limits

Linux systems can leverage cgroups (control groups) to enforce memory limits on processes, preventing out-of-memory (OOM) conditions in containerized environments. By restricting memory usage per process or group, cgroups act as a safety net against runaway applications. This section explains how to configure memory limits and OOM behavior using cgroups.


Configuring Memory Limits

To enforce memory limits, use the memory.limit_in_bytes parameter in the cgroup. This parameter defines the maximum amount of memory a process or group can use. For example:

# Create a cgroup named "mygroup" in the memory controller
sudo cgcreate -g memory:/mygroup

# Set a memory limit of 512MiB
sudo cgset -r memory.limit_in_bytes=536870912 mygroup

Verification:

cat /sys/fs/cgroup/memory/mygroup/memory.limit_in_bytes

This returns 536870912 (512MiB). If a process in this group exceeds the limit, the kernel will trigger the OOM killer.


Controlling OOM Behavior

The memory.oom_control interface allows fine-grained control over OOM behavior. Key parameters include:

  • oom_kill_disable: Disables the OOM killer for the cgroup. Use with caution, as it can lead to system instability if memory is exhausted.

    echo 1 | sudo tee /sys/fs/cgroup/memory/mygroup/memory.oom_control/oom_kill_disable
    

  • oom_score_adj: Adjusts the OOM score (lower values make processes less likely to be killed). Valid range: -1000 to 1000.

    echo -500 | sudo tee /sys/fs/cgroup/memory/mygroup/memory.oom_control/oom_score_adj
    


Best Practices for Containerized Environments

  1. Use container runtimes: Most container runtimes (e.g., Docker, containerd) automatically manage cgroups. For example, Docker's --memory flag sets memory.limit_in_bytes for containers.
  2. Combine with memory.swappiness: Reduce swapping to minimize OOM risk:
    echo 0 | sudo tee /proc/sys/vm/swappiness
    
  3. Monitor with tools: Use cgexec to run processes under cgroups and cgget to inspect limits:
    cgexec -g memory:mygroup myapp
    cgget -g memory:mygroup
    

Key takeaways

  • Use memory.limit_in_bytes to enforce strict memory boundaries for processes or groups.
  • Disable the OOM killer selectively with oom_kill_disable for critical workloads, but avoid this in production without safeguards.
  • Pair cgroups with memory.swappiness tuning to prioritize memory over swap usage.
  • In containerized environments, rely on runtime tools (e.g., Docker) to abstract cgroup configuration, but understand the underlying mechanics for troubleshooting.
  • Always validate cgroup settings with cgget or direct sysfs reads to ensure they are applied correctly.