NOTE

Linux cgroup

1. History of Linux cgroup Google engineers developed process containers, which were later renamed control groups. Linux kernel version 2.6 supported cgroup. 2. What Is Linux cgroup? limits how much you can use A Linux kernel feature that limits proc

Operating Systems / LinuxCreated Updated 2 min readhistorical

This is a historical learning note and may contain outdated or incomplete understanding.

1. History of Linux cgroup

  • Google engineers developed process containers, which were later renamed control groups.
  • Linux kernel version 2.6 supported cgroup.

2. What Is Linux cgroup?

limits how much you can use A Linux kernel feature that limits process resource usage. These resources include CPU, memory, disk I/O, networking, etc.

3. Why Linux cgroup Is Needed

Support virtualization by limiting resource usage, such as container technology.

4. How to Use Linux cgroup

The interface cgroup exposes to users consists of operating-system files under /sys/fs/cgroup.

4.1. View the cgroups a process belongs to

/proc/[pid]/cgroup

4.2. Limit the CPU Available to a Process

  1. Create a control group.
cd  /sys/fs/cgroup/cpu
mkdir container
ls container/
cgroup.clone_children cpu.cfs_period_us cpu.rt_period_us  cpu.shares notify_on_release
cgroup.procs      cpu.cfs_quota_us  cpu.rt_runtime_us cpu.stat  tasks
  1. Write and run an infinite-loop program.
while : ; do : ; done &
[1] 226
  1. Configure the CPU subsystem: in each 100 ms period, the processes limited by this control group can use only 20 ms of CPU time. In other words, this process can use only 20% of CPU bandwidth.
echo 100000 > container/cpu.cfs_period_us
echo 20000 > container/cpu.cfs_quota_us
  1. Have cgroup limit a task.
echo 226 > /sys/fs/cgroup/cpu/container/tasks
# or
cgexec -g cpu:container ./program-to-limit
  1. Verify using the top or time command.

5. Disadvantages of Linux cgroup

5.1. /proc

Under Linux, the /proc directory stores a series of special files that record the current running state of the kernel. Users can access these files to view information about the system and currently running processes, such as CPU usage and memory usage. These files are also the main data source used by the top command to view system information.

However, if you run the top command inside a container, you will find that the information it displays is actually the host machine’s CPU and memory data, rather than the current container’s data.

The reason is that the /proc filesystem does not know what resource limits the user has imposed on this container through Cgroups. That is, the /proc filesystem is unaware of the existence of Cgroups limits.

6. Linux cgroup Principle

7. References

Discussion

Sign in with GitHub to comment. Discussions are stored as GitHub Issues.View on GitHub