Say what RouteDNS holds, and how to bound it - #659
Merged
Merged
Conversation
The two levers that decide what the process occupies on a small machine both exist already and neither was written down anywhere an operator would look. The memory cache grows without limit unless a size is given, and the Go runtime holds about twice the live data unless GOMEMLIMIT says otherwise. The overview gains a section on it with the figures measured on this version: a cached answer for a single A record is about 214 bytes, a domain rule 31.8 and a compact one 8.8, so a 200,000 rule list is 6.4 MB in one format and 1.8 in the other. It also says the thing that makes GOMEMLIMIT a footgun rather than a setting, that it is soft, so a figure below what the lists and the cache hold buys nothing and costs continuous collection. The systemd unit carries the two directives commented out next to the hardening it already explains, with MemoryMax alongside as the hard limit to leave room under. No code changes. Both the config shown and the environment variable were run against the binary as written.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The two levers that decide what the process occupies on a small machine both exist already, and neither was written down anywhere an operator would look. The memory cache grows without limit unless a size is given, and the Go runtime holds about twice the live data unless
GOMEMLIMITsays otherwise.The overview gains a section on it, with the figures measured on this version:
domainorhostsruledomain-compactruleSo a 200,000 rule list is 6.4 MB in one format and 1.8 MB in the other, and a cache left to grow reaches tens of megabytes on a busy resolver.
It also says the thing that makes
GOMEMLIMITa footgun rather than a setting: it is soft, so a figure below what the lists and the cache actually hold buys nothing and costs continuous collection. The advice is to set it above the resident data and control the resident data with the cachesizeand the blocklist format.The systemd unit carries
Environment=GOMEMLIMIT=andMemoryMax=commented out, next to the hardening it already explains, with a note that the second is the hard limit to leave room under.No code changes. The config shown was run through
--check, and the environment variable was confirmed to reach the runtime as an effective limit.