Description
Without a process limit, a fault or malicious loop can create many processes quickly and exhaust host resources.
Memory and CPU limits alone cannot prevent every form of resource exhaustion. Adding a process limit helps contain runaway activity within a container.
Potential impact
- One container can exhaust host resources by creating too many processes.
- Other services on the host may be affected, causing cascading failures.
- Abnormal process growth may be harder to contain early.
Remediation
- Set a suitable
pids_limitfor each service and avoid unlimited values such as-1. - Manage process limits together with CPU and memory limits in operational standards.
- Measure the workload before adjusting the limit. A limit that is too low can prevent legitimate processes or threads from starting.
Examples
The build context’s Dockerfile is omitted. The value 10 is an example; adjust it to the application’s process and thread requirements.
Before
yaml
services:
auth:
build:
context: .
mem_limit: 500M
After
yaml
services:
auth:
build:
context: .
pids_limit: 10
mem_limit: 500M
Explanation:
- Before: A memory limit is present, but this configuration has no process-count limit.
- After:
pids_limitrestricts process creation. Verify enforcement and normal operation in the actual runtime.