Description
Without a CPU usage limit, a container can consume excessive available CPU capacity. A CPU reservation differs from a maximum usage limit.
Potential impact
A busy service can slow or prevent responses from other services on the same host.
Remediation
Set a supported CPU limit, such as deploy.resources.limits.cpus, and verify that the runtime applies it. Use load tests to balance the limit with required throughput.
Examples
The example sets a 0.3-CPU limit and a 0.1-CPU reservation. Replace example/app with the actual image and check deploy support in the Compose runtime you use.
Before
yaml
version: "3.7"
services:
app:
image: example/app
deploy:
resources:
limits:
memory: 256M
reservations:
cpus: "0.1"
After
yaml
version: "3.7"
services:
app:
image: example/app
deploy:
resources:
limits:
cpus: "0.3"
memory: 256M
reservations:
cpus: "0.1"
memory: 128M