Spotting leaked container resources without the guessing game
Container Basics On Linux (Namespaces/Cgroups)
Spotting leaked container resources without the guessing game
🧩 The Challenge
Dealing with abandoned cgroups that don’t die after a container crashes is a total headache. You end up with phantom memory accounting that messes with your monitoring and leaves the system state looking like a wreck.
💡 The Fix
Just peek into the cgroup filesystem directly to see what processes are actually still hanging on. It clears up the confusion when your metrics don’t match reality.
find /sys/fs/cgroup/memory -name "*docker*" -exec grep -l "tasks" {}/cgroup.procs \; | xargs -r ls -lh
⚙️ Why It Works
By iterating through the hierarchy, you can isolate specific subdirectories that still have active process IDs associated with them. It cuts through the abstraction layer so you can see exactly which cgroup is refusing to exit.
🚀 Pro-Tip: Alias this search to a quick command if you’re stuck debugging a host that hits its memory ceiling despite having zero active containers.
Linux Tips & Tricks | © ngelinux.com | 10/6/2026
