Docker容器内存与CPU限制问题求助(Docker 1.13.1,RHEL 7)
Hey there, let’s tackle your Docker resource limit issue on RHEL 7 with Docker 1.13.1. I totally get the frustration when standard Stack Overflow answers don’t align with your specific setup—let’s break down targeted checks and configurations tailored to your environment.
First: Verify Your Current Container’s Actual Resource Limits
Before tweaking configs, let’s confirm if your existing limits are actually being applied (it’s common for misconfigs to fly under the radar):
- From the host, run
docker inspect <your-container-name> | grep -A 10 "Resources"to see the limits you defined at startup. - Inside the container, check memory constraints with:
This should output the byte equivalent of your memory limit (e.g.,cat /sys/fs/cgroup/memory/memory.limit_in_bytes2147483648for 2GB). - For CPU, check the quota and period (these drive CPU core limits):
A quota ofcat /sys/fs/cgroup/cpu/cpu.cfs_quota_us cat /sys/fs/cgroup/cpu/cpu.cfs_period_us200000with a default period of100000means the container can use 2 full CPU cores.
Correct Resource Limit Configurations for Docker 1.13.1
Docker 1.13.1 introduced the simplified --cpus flag, but it still supports the older cgroup-based parameters. Here’s how to set limits properly:
Memory Limits
- Hard memory limit: Use
--memoryto cap the container’s usable memory. Pair it with--memory-swapto limit total memory + swap (by default, swap is double the memory limit):docker run -d --name my-app --memory 2g --memory-swap 2g <your-image> - Soft memory limit: Add
--memory-reservationto set a threshold that only enforces limits when the host is low on memory:docker run -d --name my-app --memory 2g --memory-reservation 1g --memory-swap 2g <your-image>
CPU Limits
- Limit total CPU cores: Use the
--cpusflag (simpler for 1.13+):docker run -d --name my-app --cpus 2 <your-image> - Legacy cgroup syntax (if you prefer granular control):
docker run -d --name my-app --cpu-period 100000 --cpu-quota 200000 <your-image> - Pin to specific CPU cores: Use
--cpuset-cpusto restrict the container to certain physical cores (great for workloads that benefit from core affinity):docker run -d --name my-app --cpuset-cpus 0,1 <your-image>
RHEL 7-Specific Troubleshooting Checks
RHEL 7 has a few unique quirks that can break Docker resource limits—let’s rule these out:
- Check cgroup driver compatibility: RHEL 7 uses systemd, which works best with Docker’s
systemdcgroup driver. Verify your current driver:
If it showsdocker info | grep Cgroupcgroupfs, update/etc/docker/daemon.jsonwith:
Then restart Docker:{ "exec-opts": ["native.cgroupdriver=systemd"] }systemctl restart docker. - SELinux interference: RHEL 7’s default SELinux enforcement can block Docker from applying cgroup limits. Test temporarily by running
setenforce 0on the host, then restart your container. If limits work, adjust SELinux policies instead of disabling it entirely (look intocontainer-selinuxpackages). - Kernel version: Docker resource limits require a kernel version 3.10 or higher (RHEL 7’s default is 3.10, but older minor versions might have bugs). Run
uname -rto check—if you’re on an outdated kernel, update it withyum update kernel. - Host resource contention: Ensure your host isn’t already maxed out on memory/CPU. Run
free -hto check available memory, andtopto see if other processes are hogging CPU. If the host is starved, Docker limits won’t behave as expected.
Validate Limits Are Working
Once you’ve applied the correct configs, test them with stress tools:
- Install
stressinside the container (for CentOS/RHEL images):yum install -y stress - Test memory limit: Run
stress --vm 1 --vm-bytes 3g—if your limit is 2GB, the container should either be killed by the OOM killer or the stress process will be throttled. - Test CPU limit: Run
stress --cpu 4(simulate 4 CPU-bound threads). On the host, usetopand look at the container’s CPU usage—it shouldn’t exceed your core limit (e.g., 200% for 2 cores).
内容的提问来源于stack exchange,提问作者pythonician_plus_plus

