GuidesProduction setup
How the limits add up
A limit applies to each container, it is a maximum, and some programs have no limit.
Three rules
- For each container, not for each service. A service with three instances can use three times its limit. Each job in progress adds one more, because a job gets the limits of its service. Each datastore has its own limits.
- A maximum, not a reservation. Ferry does not check that the sum of the limits fits the host. This is not necessary, because most apps stay far below their limit.
- Some programs have no limit. These are
ferryd,dockerd, the system and the builds. Leave room for them.
The example
The server of this guide has 4 CPUs and 7.8 GiB. Five web services with one instance each, a Postgres and a Redis are seven containers.
With the defaults, they use 3.5 GiB of memory at most. Each container has one CPU at most. About 4 GiB stay free for builds, ferryd, Docker and the system.
The host has no free memory. Then the OOM killer of the kernel chooses a process to stop among all the processes of the host. The line OOMScoreAdjust=-900 of the unit makes it choose containers before ferryd. See Protect ferryd.
The server runs --build-concurrency builds at a time (default 2). They can use all the memory and all the CPU of the host.