Container Basics On Linux (Namespaces/Cgroups)
Stop guessing why your containers are hitting invisible walls
🧩 The Challenge
You ever have a container that just decides to throttle itself to death while the CPU usage looks perfectly fine? It usually happens when you think you set a memory limit but forgot the OOM killer is lurking in the background.
💡 The Fix
Just peek into the cgroup filesystem directly instead of relying on whatever half-baked metric your dashboard is spitting out at you. It is the only way to see what the kernel is actually enforcing in real-time.
cat /sys/fs/cgroup/memory/system.slice/docker-<container_id>.scope/memory.stat | grep failcnt
⚙️ Why It Works
By looking at the failcnt file, you can tell if the process has been hitting its memory ceiling and getting throttled. The kernel increments this counter every single time a request gets denied, which is a goldmine when you are trying to debug phantom performance hits.
🚀 Pro-Tip: Always check memory.oom_control inside that same directory to see if the kernel is configured to kill your processes or just pause them.
Linux Tips & Tricks | © ngelinux.com | 10/1/2026
