Skip to content

Say what RouteDNS holds, and how to bound it - #659

Merged
folbricht merged 1 commit into
masterfrom
small-hardware-docs
Sep 27, 2026
Merged

folbricht merged 1 commit into
masterfrom
small-hardware-docs

Conversation

@folbricht

Copy link
Copy Markdown
Owner

The two levers that decide what the process occupies on a small machine both exist already, and neither was written down anywhere an operator would look. The memory cache grows without limit unless a size is given, and the Go runtime holds about twice the live data unless GOMEMLIMIT says otherwise.

The overview gains a section on it, with the figures measured on this version:

cost
a cached answer, single A record ~214 B
a domain or hosts rule 31.8 B
a domain-compact rule 8.8 B

So a 200,000 rule list is 6.4 MB in one format and 1.8 MB in the other, and a cache left to grow reaches tens of megabytes on a busy resolver.

It also says the thing that makes GOMEMLIMIT a footgun rather than a setting: it is soft, so a figure below what the lists and the cache actually hold buys nothing and costs continuous collection. The advice is to set it above the resident data and control the resident data with the cache size and the blocklist format.

The systemd unit carries Environment=GOMEMLIMIT= and MemoryMax= commented out, next to the hardening it already explains, with a note that the second is the hard limit to leave room under.

No code changes. The config shown was run through --check, and the environment variable was confirmed to reach the runtime as an effective limit.

The two levers that decide what the process occupies on a small machine both
exist already and neither was written down anywhere an operator would look. The
memory cache grows without limit unless a size is given, and the Go runtime
holds about twice the live data unless GOMEMLIMIT says otherwise.

The overview gains a section on it with the figures measured on this version: a
cached answer for a single A record is about 214 bytes, a domain rule 31.8 and
a compact one 8.8, so a 200,000 rule list is 6.4 MB in one format and 1.8 in
the other. It also says the thing that makes GOMEMLIMIT a footgun rather than a
setting, that it is soft, so a figure below what the lists and the cache hold
buys nothing and costs continuous collection.

The systemd unit carries the two directives commented out next to the hardening
it already explains, with MemoryMax alongside as the hard limit to leave room
under.

No code changes. Both the config shown and the environment variable were run
against the binary as written.
@folbricht
folbricht merged commit aa8bdd6 into master Sep 27, 2026
16 checks passed
@folbricht
folbricht deleted the small-hardware-docs branch September 27, 2026 15:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant