Size the container limits
Each container has a memory limit, a CPU limit and a process limit, thus one bad app cannot stop the server.
Each container that Ferry starts has its own limits.
Each container that Ferry starts has four guards: a memory limit, a CPU limit, a process limit and log rotation. This applies to service instances, one-off jobs, cron runs and datastores.
An app can leak memory, use all the CPU or start processes without end. Ferry stops or slows down only this app. The server, ferryd and your databases continue.
The three limits
| Flag and variable | Default | What it limits (0 turns it off) |
|---|---|---|
--default-memory-limit FERRY_DEFAULT_MEMORY_LIMIT | 512M | The memory of each container whose service or datastore sets no limit of its own (512M, 1G, 1.5G). No swap above it. |
--default-cpu-limit FERRY_DEFAULT_CPU_LIMIT | 1 | The CPUs of each such container (0.5, 2, 500m). The kernel can throttle a busy container, but never stops it. |
--pids-limit FERRY_PIDS_LIMIT | 1024 | The processes and threads of each container. It is a guard against a fork bomb. |
See the defaults
ferry info shows the defaults next to what the Docker host has.
Default limits: 512 MiB memory, 1 CPU per container
Docker host: 4 CPUs, 7.8 GiB memoryBuilds have no limit
docker build runs in BuildKit, which has no limit for each build.
Resource limits explains how the limits work. The next pages help you choose them for your server.