fix(ops): run heavy commands under a hard memory cap to stop host OOM kills
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 35s
CI / tests-integration (push) Successful in 2m5s
CI / tests-unit (push) Successful in 2m30s
CI / tests-ui (push) Successful in 3m3s
CI / preflight (push) Skipped
CI / deploy (push) Failing after 44s
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 35s
CI / tests-integration (push) Successful in 2m5s
CI / tests-unit (push) Successful in 2m30s
CI / tests-ui (push) Successful in 3m3s
CI / preflight (push) Skipped
CI / deploy (push) Failing after 44s
The host runs with vm.overcommit_memory=0 and no swap, so a process that
grows past free memory makes the kernel OOM-kill across the whole machine
-- the Turbopack build (commit 3d828a61) could take out the database,
nginx or the live release.
Add scripts/with-memory-cap.sh: it moves a command into its own systemd
scope with MemoryMax, so only that cgroup gets OOM-killed (verified: a
Turbopack build died at its 6GB cap, host untouched). Build/analyze/dev/
test*/typecheck now run under explicit caps; ulimit -v is only an explicit
opt-in because it bounds virtual address space per process and 10g/20g both
break V8-based builds. Docker and GitLab builds run in their own isolated
containers with a read-only cgroupfs and opt out explicitly (webpack +
--max-old-space-size stay their bound).
Measured: webpack build peaks ~6.5GB RSS, so 10GB leaves headroom within
the 23.5GB host.
This commit is contained in:
1 parent
3265c149da
commit
0845f80768
8 files changed
+563
-393
No files matched your search
@@ -266,7 +266,7 @@ function scanModuleAccesses(source: string): ModuleAccessScan {
|
||||
} else if (value.type === "ImportExpression") {
|
||||
recordArgument(value.source, "import");
|
||||
} else if (value.type === "TSImportType") {
|
||||
recordArgument(value.argument, "import");
|
||||
recordArgument(value.source ?? value.argument, "import");
|
||||
} else if (
|
||||
value.type === "CallExpression" ||
|
||||
value.type === "OptionalCallExpression"
|
||||
|
||||
@@ -255,7 +255,7 @@ function scanModuleAccesses(source: string): ModuleAccessScan {
|
||||
} else if (value.type === "ImportExpression") {
|
||||
recordArgument(value.source, "import");
|
||||
} else if (value.type === "TSImportType") {
|
||||
recordArgument(value.argument, "import");
|
||||
recordArgument(value.source ?? value.argument, "import");
|
||||
} else if (
|
||||
value.type === "CallExpression" ||
|
||||
value.type === "OptionalCallExpression"
|
||||
|
||||
Reference in new issue
Block a user