ConceptsSelf-healing
When a container crashes
Docker starts a crashed container again, and the proxy uses the other instances during that time.
Two instances answer the requests.
1 / 5
The containers of a service have the restart policy unless-stopped of Docker. Thus Docker repairs most crashes, and the reconciler repairs the others.
Three cases
| What occurs | The repair | Time |
|---|---|---|
| The process exits or crashes | Docker restarts the container. | Immediately |
| The container disappears: you removed it, or its restart failed | The next pass of the reconciler starts a new instance. | About 10 seconds |
| The container has no memory left | The kernel stops it at its memory limit. Docker restarts it as for each crash. | Immediately |
For the last case, see Out-of-memory kills.
See it
ferry status apiThe command shows the number of restarts of each instance. The service is degraded while it has fewer instances than you asked for.
A service with one instance
During the repair, requests get the answer 503 until the instance is back.
ferry status shows OOM killed on the instance while it restarts. ferryd writes each kill in its server log.