feat: cap log and cache disk use, tune swap and writeback #7
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/perf-tuning"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Performance and disk-space tuning across four roles, plus a zram install fix
found while testing.
systemd-journaldthrough a handler. Until now the size limits waited fora reboot. Adds
RuntimeMaxUse=64M(the volatile journal in/run) andMaxRetentionSec=1month, ashardening_journald_runtime_max_useandhardening_journald_max_retention.os-updatesrunsapt autocleanas its own task(the apt module runs only one of autoclean/autoremove per task).
unattended-upgradessetsAPT::Periodic::AutocleanInterval "7"(
unattended_upgrades_autoclean_interval), checked in theapt-config dumpread-back. autoclean rather than clean: the current
.debof each packagestays.
zram_enabledgetsvm.swappiness = 150(hardening_sysctl_vm_swappiness_zram) andvm.page-cluster = 0. It no longer has to be overridden in host_vars by No changes this sessionhand. hardening-basic stays the only owner of sysctl, and a host_vars value
still wins.
vm.dirty_background_bytes = 64Mandvm.dirty_bytes = 256Mon every host, replacing the kernel's 10%/20% ofreclaimable memory, which lets gigabytes of unwritten data build up on
large-RAM hosts.
nullomits either line.log-driver: json-fileandlog-opts(10m x 3) into/etc/docker/daemon.json. Other keys (NVIDIAruntime, mirrors) are kept, and the merged file is checked with
dockerd --validatebefore it is written. It is never rewritten when it alreadyagrees. Assert mode is untouched.
package_factsguard, which needspython3-aptand failed the role on a minimal host (and in molecule) before anything had
installed it. The install is idempotent on its own.
Considered and dropped:
systemd-coredump Storage=none, becausekernel.core_pattern=|/bin/falsealready discards cores.Blast radius
sysctl apply-and-verify step. Journald restarts once, and log streams
survive the restart. Nothing here can lock anyone out. No changes this session
zram_enabledand no host_vars override: swappiness goesfrom 0 to 150 on the run. Before merging, check that no such host swaps to
disk with zramswap down.
restart stops every container and can cost swarm quorum. The run says a
restart is pending. The new limits apply from the next engine restart, and
only to containers created after it (
docker compose up -d --force-recreate, ordocker service update --force <svc>in swarm).Services with their own
logging:(ai-stack) keep it.zramswapis now enabled on every run, including hostswhere it had been disabled by hand.