GuidesProduction setup
Protect ferryd when the server runs out of memory
A low OOM score in the unit makes the kernel stop containers before ferryd.
The server has no free memory. The kernel must stop one process.
1 / 3
# When the host runs out of memory, let the kernel kill containers before ferryd.
OOMScoreAdjust=-900Why systemd sets the score
At startup, ferryd tries to lower its own OOM score to -500 (--oom-score-adj, FERRY_OOM_SCORE_ADJ). This needs root or the capability CAP_SYS_RESOURCE, and the user ferry has neither. Thus systemd sets the score.
Without this line, ferryd writes a warning: it could not set its OOM score adjustment.
Memory settings of the unit
| Setting | Effect |
|---|---|
OOMScoreAdjust=-900 | Only ferryd keeps the low score. The processes that it starts (git, the docker CLI) go back to 0. Thus a git that uses too much memory gets no protection at the cost of your apps and databases. |
MemoryMin= | It does nothing unless the parent slice (system.slice) reserves memory too. |
MemoryMax= | Do not use it on this unit. When ferryd gets to this limit, the kernel stops ferryd itself. |
Containers and builds run inside Docker, in the cgroups of Docker. They are not in this unit. Thus the memory settings here cover only ferryd and the processes that it starts.
To limit the apps, use --default-memory-limit or a limit for each service.