Review container process limits

Limit process counts to workload needs to reduce the risk of host resource exhaustion.

Description

Without a process limit, a fault or malicious loop can create many processes quickly and exhaust host resources.

Memory and CPU limits alone cannot prevent every form of resource exhaustion. Adding a process limit helps contain runaway activity within a container.

Potential impact

  • One container can exhaust host resources by creating too many processes.
  • Other services on the host may be affected, causing cascading failures.
  • Abnormal process growth may be harder to contain early.

Remediation

  • Set a suitable pids_limit for each service and avoid unlimited values such as -1.
  • Manage process limits together with CPU and memory limits in operational standards.
  • Measure the workload before adjusting the limit. A limit that is too low can prevent legitimate processes or threads from starting.

Examples

The build context’s Dockerfile is omitted. The value 10 is an example; adjust it to the application’s process and thread requirements.

Before

yaml
services:
  auth:
    build:
      context: .
    mem_limit: 500M

After

yaml
services:
  auth:
    build:
      context: .
    pids_limit: 10
    mem_limit: 500M

Explanation:

  • Before: A memory limit is present, but this configuration has no process-count limit.
  • After: pids_limit restricts process creation. Verify enforcement and normal operation in the actual runtime.

References