FerryDocs

Protect ferryd when the server runs out of memory

A low OOM score in the unit makes the kernel stop containers before ferryd.

Edit on GitHub
KernelOOM killerContainerscore 0ferrydscore -900

The server has no free memory. The kernel must stop one process.

1 / 3
/etc/systemd/system/ferryd.service (excerpt)
# When the host runs out of memory, let the kernel kill containers before ferryd.
OOMScoreAdjust=-900

Why systemd sets the score

At startup, ferryd tries to lower its own to -500 (--oom-score-adj, FERRY_OOM_SCORE_ADJ). This needs root or the CAP_SYS_RESOURCE, and the user ferry has neither. Thus systemd sets the score.

Without this line, ferryd writes a warning: it could not set its OOM score adjustment.

Memory settings of the unit

SettingEffect
OOMScoreAdjust=-900Only ferryd keeps the low score. The processes that it starts (git, the docker CLI) go back to 0. Thus a git that uses too much memory gets no protection at the cost of your apps and databases.
MemoryMin=It does nothing unless the parent slice (system.slice) reserves memory too.
MemoryMax=Do not use it on this unit. When ferryd gets to this limit, the stops ferryd itself.

Containers and builds run inside Docker, in the of Docker. They are not in this unit. Thus the memory settings here cover only ferryd and the processes that it starts.

To limit the apps, use --default-memory-limit or a limit for each service.

On this page