diff --git a/source/clear-linux/guides/maintenance/resource-limits.rst b/source/clear-linux/guides/maintenance/resource-limits.rst new file mode 100644 index 00000000..c753992f --- /dev/null +++ b/source/clear-linux/guides/maintenance/resource-limits.rst @@ -0,0 +1,123 @@ +.. _resource-limits: + +Resource limits +############### + +Linux systems employ limiting or quota mechanisms to provide quality of +service for system resources and contain rogue processes. + +These limits are layered at the system-level and user-level. If these limits +need to be modified, it is useful to understand the different limit +configurations. + +.. contents:: :local: + :depth: 2 + + +System-wide limits +================== + +Some global resource limits are implemented in the Linux kernel and are +controllable with kernel parameters. + +For example, a global limit for the maximum number of open files is set with +the *fs.file-max* parameter. This limit applies to all processes and users an +cannot be exceeded other limit values. + +Checking limit +************** + +You can check a current value with :command:`sysctl -n `. For +example: + +.. code:: bash + + sysctl -n fs.file-max + + +This *fs.file-max* value is set intentionally high on |CL| systems by +default. You can check the maximum value supported by the system with: + +.. code:: + + cat /proc/sys/fs/file-max + + +Overriding limit +**************** + +You can override a value with :command:`sysctl -w `. For +example: + +.. code:: bash + + sudo sysctl -w fs.file-max= + +If needed permanently, the value can be set by creating a +:file:`/etc/sysctl.d/*.conf` file (see :command:`man sysctl.d` for details). +For example: + +.. code:: bash + + sudo mkdir -p /etc/sysctl.d/ + + sudo tee /etc/sysctl.d/fs-file-max.conf > /dev/null <<'EOF' + fs.file-max= + EOF + + + + + +Per-user limits +=============== + +For processes not managed by systemd, resource limits can be set for PAM +logins on a per-user basis with upper and lower limits in the +:file:`/etc/security/limits.conf` file. + +You can set temporary values and check the current values with the +:command:`ulimit` command. For example, to change the soft limit of maximum +number of open file descriptors for the current user: + +.. code:: + + ulimit -S -n + +See :command:`man limits.conf` for details. + + +Service limits +============== + +Resource limits for services started with systemd units do not follow normal +user limits because the process is started in a seperate `Linux control group +(cgroup) `_ Linux +cgroups associate related process groups and provide resource accounting. + +Resource limits for individual systemd services can be controlled inside their +unit files or its configuration drop-in directory with the resource Limit +directives. See `process properties section of the systemd.exec man page +`_. + +Resource limits for all systemd services can be controlled with a file in the +:file:`/etc/systemd/system.conf.d/` directory. For example, to have no +restriction on the number of open files: + +.. code:: + + sudo mkdir -p /etc/systemd/system.conf.d/ + + sudo tee /etc/systemd/system.conf.d/50-nfiles.conf > /dev/null <<'EOF' + [Manager] + DefaultLimitNOFILE=infinity + EOF + + + + + + + + + diff --git a/source/tooling/swupd-guide.rst b/source/tooling/swupd-guide.rst index e7ae06b9..b7ae2a41 100644 --- a/source/tooling/swupd-guide.rst +++ b/source/tooling/swupd-guide.rst @@ -149,6 +149,8 @@ on demand. sudo swupd autoupdate + Output: + .. code-block:: console Enabled @@ -159,6 +161,8 @@ on demand. sudo swupd autoupdate --disable + Output: + .. code-block:: console Warning: disabling automatic updates may take you out of compliance with your IT policy @@ -214,7 +218,8 @@ number of dependencies. Also, check out our tutorial: :ref:`kata`. Bundle with the best search result: - containers-virt - Run container applications from Dockerhub in lightweight virtual machines + containers-virt - Run container applications from Dockerhub in + lightweight virtual machines This bundle can be installed with: diff --git a/source/tutorials/nvidia.rst b/source/tutorials/nvidia.rst index 94a2fe34..5473bed9 100644 --- a/source/tutorials/nvidia.rst +++ b/source/tutorials/nvidia.rst @@ -20,8 +20,8 @@ require a manual installation. Software installed outside of :ref:`swupd ` is not updated with |CL| updates and must be updated and maintained manually. - For example, the file :file:`/usr/lib/libGL.so` conflicts between the one - provided by the mesa package in |CL| and the one NVIDIA provides. If a |CL| + For example, the file :file:`/usr/lib/libGL.so` conflicts with the file + provided by the mesa package in |CL| and the file NVIDIA provides. If a |CL| update overwrites these files, a reinstallation of the NVIDIA driver might be required. @@ -58,14 +58,14 @@ Install the appropriate DKMS bundle using the instructions below: :end-before: kernel-modules-dkms-install-end: -Download and install the NVIDIA Drivers +Download and install the NVIDIA drivers *************************************** -Download the NVIDIA Drivers for Linux +Download the NVIDIA drivers for Linux ===================================== -#. Identify the model of NVIDIA GPU that is installed. +#. Identify the NVIDIA GPU model that is installed. .. code-block:: bash @@ -73,7 +73,7 @@ Download the NVIDIA Drivers for Linux #. Go to the `NVIDIA Driver Downloads website`_ . Search for and download the - appropriate driver based on the model of NVIDIA GPU you have with *Linux + appropriate driver based on the NVIDIA GPU model you have with *Linux 64-bit* selected as the Operating System . @@ -92,7 +92,7 @@ Download the NVIDIA Drivers for Linux chmod +x :file:`NVIDIA-Linux-x86_64-.run` -Disable the nouveau Driver +Disable the nouveau driver ========================== The proprietary NVIDIA driver is incompatible with the nouveau driver and @@ -114,10 +114,10 @@ must be disabled before installation can continue. -Configure Alternative Software Paths +Configure alternative software paths ==================================== -The NVIDIA installer will be directed to install files under +The NVIDIA installer is directed to install files under :file:`/opt/nvidia` as much as possible to keep its contents isolated from the rest of the |CL| system files under :file:`/usr`. The dynamic linker and X server must be configured to use the content under @@ -156,7 +156,7 @@ server must be configured to use the content under EOF -Install the NVIDIA Drivers +Install the NVIDIA drivers ========================== @@ -165,7 +165,7 @@ Install the NVIDIA Drivers :command:`CTRL + ALT + F2` or remotely login over SSH. -#. Navigate into the directory where the NVIDIA installer was downloaded. +#. Navigate to the directory where the NVIDIA installer was downloaded. .. code-block:: bash @@ -217,14 +217,14 @@ Install the NVIDIA Drivers .. note:: The NVIDIA software places some files under the :file:`/usr` subdirectory - which are not managed by |CL| and conflict with the |CL| stateless design. + that are not managed by |CL| and conflict with the |CL| stateless design. Although a limited version of :command:`swupd repair` is run above, other uses of the :command:`swupd repair` command should be avoided with the proprietary NVIDIA drivers installed. -Updating the NVIDIA Drivers +Updating the NVIDIA drivers *************************** The proprietary NVIDIA drivers are installed manually outside of :ref:`swupd @@ -261,7 +261,7 @@ not in use. #. Reboot the system and log back in. -#. Trigger a flatpak update which will download the runtime corresponding +#. Trigger a flatpak update that will download the runtime corresponding with the new NVIDIA drivers for the flatpak apps that require it. .. code-block:: bash @@ -269,7 +269,7 @@ not in use. flatpak update -Uninstalling the NVIDIA Drivers +Uninstalling the NVIDIA drivers ******************************* The NVIDIA drivers and associated software can be uninstalled and nouveau @@ -293,7 +293,7 @@ driver restored with the instructions in this section. #. Follow the prompts on the screen and reboot the system. -Debugging Installation of NVIDIA Drivers +Debugging installation of NVIDIA drivers **************************************** * The NVIDIA driver places installer and uninstaller logs under