cgroup on /sys/fs/cgroup/cpuset type cgroup (rw,nosuid,nodev,noexec,relatime,cpuset) cgroup on /sys/fs/cgroup/net_cls,net_prio type cgroup (rw,nosuid,nodev,noexec,relatime,net_prio,net_cls) cgroup on /sys/fs/cgroup/perf_event type cgroup (rw,nosuid,nodev,noexec,relatime,perf_event)...
-CONFIG_CGROUP_PIDS:missing -CONFIG_MEMCG_SWAP:missing -CONFIG_MEMCG_SWAP_ENABLED:missing -CONFIG_BLK_CGROUP:missing -CONFIG_BLK_DEV_THROTTLING:missing -CONFIG_CGROUP_PERF:missing -CONFIG_CGROUP_HUGETLB:missing -CONFIG_NET_CLS_CGROUP:missing -CONFIG_CGROUP_NET_PRIO:missing -CONFIG_CFS_BANDWIDTH:en...
CONFIG_NET_CLS=y CONFIG_NET_CLS_BASIC=m # CONFIG_NET_CLS_ROUTE4 is not set # CONFIG_NET_CLS_FW is not set # CONFIG_NET_CLS_U32 is not set # CONFIG_NET_CLS_RSVP is not set # CONFIG_NET_CLS_RSVP6 is not set # CONFIG_NET_CLS_FLOW is not set # CONFIG_NET_CLS_CGROUP is ...
- CONFIG_BLK_CGROUP: enabled - CONFIG_BLK_DEV_THROTTLING: missing - CONFIG_IOSCHED_CFQ: enabled - CONFIG_CFQ_GROUP_IOSCHED: missing - CONFIG_CGROUP_PERF: enabled - CONFIG_CGROUP_HUGETLB: missing - CONFIG_NET_CLS_CGROUP: missing - CONFIG_CGROUP_NET_PRIO: missing - CONFIG_CFS_BANDWIDTH: ena...
CONFIG_CGROUP_PIDS=y CONFIG_CGROUP_FREEZER=y CONFIG_CGROUP_DEVICE=y CONFIG_CGROUP_CPUACCT=y CONFIG_CGROUP_PERF=y CONFIG_NET_CLS_CGROUP=y CONFIG_CGROUP_NET_PRIO=y CONFIG_CGROUP_BPF=y CONFIG_BPF_SYSCALL=y CONFIG_MEMCG=y CONFIG_NAMESPACES=y CONFIG_USER_NS=y CONFIG_PID_NS=y CONFIG_IPC_NS...
# CONFIG_NET_CLS_CGROUP is not set CONFIG_NET_EMATCH=y CONFIG_NET_EMATCH_STACK=32 # CONFIG_NET_EMATCH_CMP is not set # CONFIG_NET_EMATCH_NBYTE is not set CONFIG_NET_EMATCH_U32=y # CONFIG_NET_EMATCH_META is not set # CONFIG_NET_EMATCH_TEXT is not set CONFIG_NET...
# CONFIG_KERNEL_NET_CLS_CGROUP is not set # CONFIG_KERNEL_CGROUP_NET_CLASSID is not set # CONFIG_KERNEL_CGROUP_NET_PRIO is not set CONFIG_KERNEL_NAMESPACES=y CONFIG_KERNEL_UTS_NS=y CONFIG_KERNEL_IPC_NS=y CONFIG_KERNEL_USER_NS=y CONFIG_KERNEL_PID_NS=y CONFIG_KERNEL_NET_...
# See the CPU limits.ls /sys/fs/cgroup/cpu/docker/${ID} 有趣的是在不明确设置任何资源限制的情况下启动容器都会配置一个 cgroup。实际中我没有检查过,但我的猜测是默认情况下,CPU 和 RAM 消耗不受限制,Cgroups 可能用来限制从容器内部对某些设备的访问。
println "cat /proc/1/cgroup".execute().text 11:hugetlb:/ 10:pids:/ 9:cpu,cpuacct:/ 8:devices:/ 7:perf_event:/ 6:freezer:/ 5:cpuset:/ 4:blkio:/ 3:memory:/ 2:net_cls,net_prio:/ 1:name=systemd:/ println "whoami".execute().text jenkins ...
# CONFIG_KERNEL_NET_CLS_CGROUP is not set # CONFIG_KERNEL_CGROUP_NET_CLASSID is not set # CONFIG_KERNEL_CGROUP_NET_PRIO is not set CONFIG_KERNEL_NAMESPACES=y CONFIG_KERNEL_UTS_NS=y CONFIG_KERNEL_IPC_NS=y CONFIG_KERNEL_USER_NS=y CONFIG_KERNEL_PID_NS=y CONFIG_KERNEL_NET_NS=y CONFIG...