NOTE
Linux cgroup
1. History of Linux cgroup Google engineers developed process containers, which were later renamed control groups. Linux kernel version 2.6 supported cgroup. 2. What Is Linux cgroup? limits how much you can use A Linux kernel feature that limits proc
This is a historical learning note and may contain outdated or incomplete understanding.
1. History of Linux cgroup
- Google engineers developed process containers, which were later renamed control groups.
- Linux kernel version 2.6 supported cgroup.
2. What Is Linux cgroup?
limits how much you can use A Linux kernel feature that limits process resource usage. These resources include CPU, memory, disk I/O, networking, etc.
3. Why Linux cgroup Is Needed
Support virtualization by limiting resource usage, such as container technology.
4. How to Use Linux cgroup
The interface cgroup exposes to users consists of operating-system files under /sys/fs/cgroup.
4.1. View the cgroups a process belongs to
/proc/[pid]/cgroup
4.2. Limit the CPU Available to a Process
- Create a control group.
cd /sys/fs/cgroup/cpu
mkdir container
ls container/
cgroup.clone_children cpu.cfs_period_us cpu.rt_period_us cpu.shares notify_on_release
cgroup.procs cpu.cfs_quota_us cpu.rt_runtime_us cpu.stat tasks
- Write and run an infinite-loop program.
while : ; do : ; done &
[1] 226
- Configure the CPU subsystem: in each 100 ms period, the processes limited by this control group can use only 20 ms of CPU time. In other words, this process can use only 20% of CPU bandwidth.
echo 100000 > container/cpu.cfs_period_us
echo 20000 > container/cpu.cfs_quota_us
- Have cgroup limit a task.
echo 226 > /sys/fs/cgroup/cpu/container/tasks
# or
cgexec -g cpu:container ./program-to-limit
- Verify using the top or time command.
5. Disadvantages of Linux cgroup
5.1. /proc
Under Linux, the /proc directory stores a series of special files that record the current running state of the kernel. Users can access these files to view information about the system and currently running processes, such as CPU usage and memory usage. These files are also the main data source used by the top command to view system information.
However, if you run the top command inside a container, you will find that the information it displays is actually the host machine’s CPU and memory data, rather than the current container’s data.
The reason is that the /proc filesystem does not know what resource limits the user has imposed on this container through Cgroups. That is, the /proc filesystem is unaware of the existence of Cgroups limits.
Discussion
Sign in with GitHub to comment. Discussions are stored as GitHub Issues.View on GitHub