You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker容器内存与CPU限制问题求助(Docker 1.13.1,RHEL 7)

Hey there, let’s tackle your Docker resource limit issue on RHEL 7 with Docker 1.13.1. I totally get the frustration when standard Stack Overflow answers don’t align with your specific setup—let’s break down targeted checks and configurations tailored to your environment.

First: Verify Your Current Container’s Actual Resource Limits

Before tweaking configs, let’s confirm if your existing limits are actually being applied (it’s common for misconfigs to fly under the radar):

  • From the host, run docker inspect <your-container-name> | grep -A 10 "Resources" to see the limits you defined at startup.
  • Inside the container, check memory constraints with:
    cat /sys/fs/cgroup/memory/memory.limit_in_bytes
    
    This should output the byte equivalent of your memory limit (e.g., 2147483648 for 2GB).
  • For CPU, check the quota and period (these drive CPU core limits):
    cat /sys/fs/cgroup/cpu/cpu.cfs_quota_us
    cat /sys/fs/cgroup/cpu/cpu.cfs_period_us
    
    A quota of 200000 with a default period of 100000 means the container can use 2 full CPU cores.

Correct Resource Limit Configurations for Docker 1.13.1

Docker 1.13.1 introduced the simplified --cpus flag, but it still supports the older cgroup-based parameters. Here’s how to set limits properly:

Memory Limits

  • Hard memory limit: Use --memory to cap the container’s usable memory. Pair it with --memory-swap to limit total memory + swap (by default, swap is double the memory limit):
    docker run -d --name my-app --memory 2g --memory-swap 2g <your-image>
    
  • Soft memory limit: Add --memory-reservation to set a threshold that only enforces limits when the host is low on memory:
    docker run -d --name my-app --memory 2g --memory-reservation 1g --memory-swap 2g <your-image>
    

CPU Limits

  • Limit total CPU cores: Use the --cpus flag (simpler for 1.13+):
    docker run -d --name my-app --cpus 2 <your-image>
    
  • Legacy cgroup syntax (if you prefer granular control):
    docker run -d --name my-app --cpu-period 100000 --cpu-quota 200000 <your-image>
    
  • Pin to specific CPU cores: Use --cpuset-cpus to restrict the container to certain physical cores (great for workloads that benefit from core affinity):
    docker run -d --name my-app --cpuset-cpus 0,1 <your-image>
    

RHEL 7-Specific Troubleshooting Checks

RHEL 7 has a few unique quirks that can break Docker resource limits—let’s rule these out:

  • Check cgroup driver compatibility: RHEL 7 uses systemd, which works best with Docker’s systemd cgroup driver. Verify your current driver:
    docker info | grep Cgroup
    
    If it shows cgroupfs, update /etc/docker/daemon.json with:
    {
      "exec-opts": ["native.cgroupdriver=systemd"]
    }
    
    Then restart Docker: systemctl restart docker.
  • SELinux interference: RHEL 7’s default SELinux enforcement can block Docker from applying cgroup limits. Test temporarily by running setenforce 0 on the host, then restart your container. If limits work, adjust SELinux policies instead of disabling it entirely (look into container-selinux packages).
  • Kernel version: Docker resource limits require a kernel version 3.10 or higher (RHEL 7’s default is 3.10, but older minor versions might have bugs). Run uname -r to check—if you’re on an outdated kernel, update it with yum update kernel.
  • Host resource contention: Ensure your host isn’t already maxed out on memory/CPU. Run free -h to check available memory, and top to see if other processes are hogging CPU. If the host is starved, Docker limits won’t behave as expected.

Validate Limits Are Working

Once you’ve applied the correct configs, test them with stress tools:

  1. Install stress inside the container (for CentOS/RHEL images):
    yum install -y stress
    
  2. Test memory limit: Run stress --vm 1 --vm-bytes 3g—if your limit is 2GB, the container should either be killed by the OOM killer or the stress process will be throttled.
  3. Test CPU limit: Run stress --cpu 4 (simulate 4 CPU-bound threads). On the host, use top and look at the container’s CPU usage—it shouldn’t exceed your core limit (e.g., 200% for 2 cores).

内容的提问来源于stack exchange,提问作者pythonician_plus_plus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:21:57