user/dev discussion of public-inbox itself
 help / color / mirror / code / Atom feed
* public-inbox.org VPS hopefully stable, now...
@ 2024-10-14 22:48 Eric Wong
  2025-03-18 18:28 ` robots.txt ignored (was: public-inbox.org VPS hopefully stable, now...) Eric Wong
  0 siblings, 1 reply; 3+ messages in thread
From: Eric Wong @ 2024-10-14 22:48 UTC (permalink / raw)
  To: meta

I've got a lot of orphaned sockets and OOM from the kernel the
past few days.  It's a combination of kernel TCP memory use,
OpenSSL, zlib, glibc malloc, Perl 5, and probably other things...

It looks like a lot of bot traffic trying to scrape IMAP(S),
too :<

WolfSSL might be an option via Inline::C *shrug*

I've cut down on connections and via iptables/ip6tables
connlimit and state modules; still not sure where they
should be atm..

Current sysctls are here, many limits lowered from defaults.
Mostly going off Documentation/networking/ip-sysctl.rst in
linux.git

I'm not 100% sure about many of these so holler if you see anything
amiss...

	net.core.somaxconn = 128
	net.ipv4.tcp_timestamps = 1
	net.ipv4.tcp_tw_reuse = 1
	net.ipv4.tcp_fin_timeout = 20
	net.ipv4.tcp_slow_start_after_idle = 0
	net.ipv4.tcp_retries2 = 8 # default 15
	net.ipv4.tcp_orphan_retries = 1 # default 8
	net.ipv4.tcp_max_orphans = 2048 # default 4096

	# Things will probably be worse for LFNs w/ smaller tcp_wmem
	net.ipv4.tcp_rmem = 4096 16384 65536
	net.ipv4.tcp_wmem = 4096 16384 65536

	# tcp_mem thresholds untouched atm..

	net.netfilter.nf_conntrack_tcp_timeout_established = 600

	# can probably drop this...
	net.netfilter.nf_conntrack_max = 30000

I "only" have 1GB of RAM since it's the cheapest available
(32-bit userspace, x86_64 kernel).  Getting more RAM or CPU
is absolutely NOT an option; optimizing data structures,
code and tweaking knobs are the only ways to fix this.

Down with consumerism!

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2025-03-20  0:05 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-10-14 22:48 public-inbox.org VPS hopefully stable, now Eric Wong
2025-03-18 18:28 ` robots.txt ignored (was: public-inbox.org VPS hopefully stable, now...) Eric Wong
2025-03-20  0:05   ` [RFC] plack_limiter: middleware to limit concurrency Eric Wong

Code repositories for project(s) associated with this public inbox

	https://80x24.org/public-inbox.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).