Q: A service is being killed randomly every few days by the OOM Killer, but monitoring shows the machine has plenty of free RAM available. Why?
If the host has free memory but a process is still OOM killed, the limitation is artificially imposed or architectural:
#Linux #Linux / SRE — Scenario-Based Interview Questions #L3 #SRE #Systems #Troubleshooting
🎙️ Candidate Opening & Architectural Context
""During an on-call shift, our alerts triggered when a critical Linux production server exhibited this behavior. The interviewer is testing: Cgroups, NUMA architectures, or memory fragmentation.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
If the host has free memory but a process is still OOM killed, the limitation is artificially imposed or architectural:
- Cgroups: If the process runs in a Docker container or a systemd slice with strict
MemoryLimit=or--memory, the cgroup will trigger the kernel OOM killer on the process specifically when it breaches its localized limit, regardless of host free memory. Checkdmesg -T | grep -i oom. - NUMA Nodes: On large multi-socket servers, memory is tied to specific CPU sockets (NUMA nodes). If the application sets strict
numactlpolicies to pin memory to a specific node, and *that* node runs out of memory, it may OOM kill rather than fetch memory across the slow QPI link from another socket. - 32-bit Architecture constraints: Though rare nowadays, 32-bit apps max out around 3-4GB of accessible address space.
2️⃣
Remediation & Permanent Safeguards
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Cgroups: If the process runs in a Docker container or a systemd slice with strict MemoryLimit= or --memory, the cgroup will trigge."
⚡ 60-Second Elevator Pitch Talking Points
- Cgroups: If the process runs in a Docker container or a systemd slice with strict MemoryLimit= or...
- NUMA Nodes: On large multi-socket servers, memory is tied to specific CPU sockets (NUMA nodes). I...
- 32-bit Architecture constraints: Though rare nowadays, 32-bit apps max out around 3-4GB of access...
Advertisement