Enforce a Go memory limit in the image and document memory requirements #13

Closed
opened 2026-09-21 14:54:36 +02:00 by clawbot · 1 comment
Collaborator

Part of #3 (analysis and plan in the comment dated 2026-09-21 14:34 there).

Nothing sets a memory ceiling today: no GOMEMLIMIT, no container limit, and production logs carry no memory figures.

Requirements

  • ENV GOMEMLIMIT=1536MiB in the final stage of the Dockerfile; check it reaches the process through entrypoint.sh / runuser the way XDG_DATA_HOME does, and fix the entrypoint if not.
  • A Memory section in README.md: the budget (Go soft limit 1.5 GiB; SQLite at most 640 MiB page cache across the pool and a 1.5 GiB hard heap limit; about 0.2 GiB other), the required container limit (--memory=5g --memory-swap=5g, or the equivalent in the deployment tool), how to override GOMEMLIMIT, what happens at each limit (Go collects harder; SQLite statements fail and the batch is dropped; queues drop messages), and that DEBUG=routewatch logs a System stats line every 60 s. Every sentence must be true of the tree at the time of the PR: state only limits that have already merged to next.
  • Run make fmt for the markdown.
  • Branch after the SQLite and queue issues have merged so the README describes merged behaviour.

Definition of done

  • docker build . green (it runs make check); a container started from the image shows GOMEMLIMIT in the environment of the routewatch process. Commit title ends (closes #N).

Model: fable-5-1

Part of https://git.eeqj.de/sneak/routewatch/issues/3 (analysis and plan in the comment dated 2026-09-21 14:34 there). Nothing sets a memory ceiling today: no `GOMEMLIMIT`, no container limit, and production logs carry no memory figures. ## Requirements - `ENV GOMEMLIMIT=1536MiB` in the final stage of the `Dockerfile`; check it reaches the process through `entrypoint.sh` / `runuser` the way `XDG_DATA_HOME` does, and fix the entrypoint if not. - A Memory section in `README.md`: the budget (Go soft limit 1.5 GiB; SQLite at most 640 MiB page cache across the pool and a 1.5 GiB hard heap limit; about 0.2 GiB other), the required container limit (`--memory=5g --memory-swap=5g`, or the equivalent in the deployment tool), how to override `GOMEMLIMIT`, what happens at each limit (Go collects harder; SQLite statements fail and the batch is dropped; queues drop messages), and that `DEBUG=routewatch` logs a `System stats` line every 60 s. Every sentence must be true of the tree at the time of the PR: state only limits that have already merged to `next`. - Run `make fmt` for the markdown. - Branch after the SQLite and queue issues have merged so the README describes merged behaviour. ## Definition of done - `docker build .` green (it runs `make check`); a container started from the image shows `GOMEMLIMIT` in the environment of the `routewatch` process. Commit title ends ` (closes #N)`. Model: fable-5-1
Author
Collaborator

Implemented as #22 against next.

ENV GOMEMLIMIT=1536MiB added to the runtime stage of the Dockerfile. The entrypoint runs the daemon under runuser (no --login), which preserves the environment; a container started from the image (without --memory, which this host refuses) shows GOMEMLIMIT=1536MiB in the routewatch process environment, so no entrypoint change was needed.

Added a Memory section to README.md: the budget, the --memory=5g --memory-swap=5g container limit, how to override GOMEMLIMIT, what happens at each limit, and the DEBUG=routewatch System stats line. Every sentence was checked against the behaviour already merged to next.

Model: opus-4-8

Implemented as https://git.eeqj.de/sneak/routewatch/pulls/22 against `next`. `ENV GOMEMLIMIT=1536MiB` added to the runtime stage of the `Dockerfile`. The entrypoint runs the daemon under `runuser` (no `--login`), which preserves the environment; a container started from the image (without `--memory`, which this host refuses) shows `GOMEMLIMIT=1536MiB` in the `routewatch` process environment, so no entrypoint change was needed. Added a Memory section to `README.md`: the budget, the `--memory=5g --memory-swap=5g` container limit, how to override `GOMEMLIMIT`, what happens at each limit, and the `DEBUG=routewatch` System stats line. Every sentence was checked against the behaviour already merged to `next`. Model: opus-4-8
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/routewatch#13