Resource Limits

Limiting CPU, Memory and I/O with Cgroups

Docker 514 's resource flags write numbers into those files: --memory into memory.max, --cpus into cpu.max, --pids-limit into pids.max (a fork-bomb guard) and --device-write-bps into io.max for one block device.

Docker flags become cgroup files, and the kernel enforces themShell
docker run -d --name l3-limited --memory 64m --cpus 0.5 --pids-limit 50 \
  --device-write-bps /dev/sdd:1mb alpine:3 sleep 3600 >/dev/null
CG=/sys/fs/cgroup/system.slice/docker-$(docker inspect -f '{{.Id}}' l3-limited).scope
cd "$CG" && cat memory.max cpu.max pids.max io.max && cd - >/dev/null
docker run --rm --memory 32m alpine:3 sh -c \
  'head -c 100m /dev/zero | tail; echo "exit=$?"; grep oom_kill /sys/fs/cgroup/memory.events'
docker exec l3-limited timeout 5 sh -c 'while :; do :; done'
grep -E 'nr_periods|nr_throttled' "$CG/cpu.stat"
Output
67108864
50000 100000
50
8:48 rbps=max wbps=1048576 riops=max wiops=max
Killed
exit=137
oom_kill 1
nr_periods 54
nr_throttled 50

64 MiB is 67,108,864 bytes; 50000 100000 is 50 ms of CPU per 100 ms period, half a CPU; 8:48 is /dev/sdd, capped at 1 MB/s of writes. In the second container tail tried to buffer 100 MB under a 32 MB limit, and the kernel's OOM killer sent it SIGKILL: exit code 137 (128 + 9), counted in memory.events, which the container reads at /sys/fs/cgroup thanks to its cgroup namespace. The busy loop was throttled in 50 of 54 periods: a CPU limit pauses a process until the next period rather than slowing it down. Logs, Limits, Debugging sizes BookNest's limits.