feat(install): offer /tmp on disk + SSH memory guard, deploy cloudpex helper
/tmp is a RAM-backed tmpfs on Ubuntu (50% of RAM). Agent runs fill it: half the RAM goes, then every temp-file creation fails with ENOSPC and shells break. Swap does not lift the cap, so the fix is /tmp on disk. End-of-install offers (Linux, [y/N], skipped without a terminal, idempotent): - offer_tmp_on_disk: mask tmp.mount + etc/tmpfiles.d/tmp.conf (wipe at boot, 10-day purge, /var/tmp rule kept). Effective at next reboot. - offer_ssh_memory_guard: the previous server's rules. ssh.service drop-in (OOMScoreAdjust=-1000, MemoryMin=256M) + earlyoom with --avoid sshd and --prefer node/java. MemoryMin covers sshd only; earlyoom is the real guard. install_cloudpex deploys the NAS mount helper in the Linux block. Docs: README steps 12-14 + table, CLAUDE.md layout + lint command.
This commit is contained in:
@@ -0,0 +1,8 @@
|
||||
# earlyoom settings, sourced by earlyoom.service (rules of the previous server).
|
||||
# -r 60 memory report in the journal every minute
|
||||
# -m 10 act when available RAM drops under 10% ...
|
||||
# -s 10 ... and free swap under 10% (both conditions)
|
||||
# --avoid never kill sshd, systemd, logind, dbus, containerd
|
||||
# --prefer kill the agent runtimes first: java, node, pnpm, esbuild
|
||||
# Quotes inside the value are honoured by systemd's $VAR word splitting.
|
||||
EARLYOOM_ARGS="-r 60 -m 10 -s 10 --avoid '^(sshd|systemd|systemd-logind|dbus-daemon|containerd)$' --prefer '^(java|node|pnpm|esbuild)$'"
|
||||
@@ -0,0 +1,8 @@
|
||||
# ssh.service drop-in: keep sshd alive when RAM runs out (rules of the previous server).
|
||||
# OOMScoreAdjust=-1000 the kernel OOM killer never selects sshd.
|
||||
# MemoryMin=256M reclaim protection for the daemon's own cgroup. Login sessions
|
||||
# live in user.slice (logind), so this cannot reserve RAM for an
|
||||
# interactive shell — earlyoom is what frees memory in time.
|
||||
[Service]
|
||||
MemoryMin=256M
|
||||
OOMScoreAdjust=-1000
|
||||
@@ -0,0 +1,5 @@
|
||||
# /tmp on disk (install.sh masks tmp.mount): keep the tmpfs semantics — wipe /tmp
|
||||
# at boot (D) and purge entries untouched for 10 days. Same file name as
|
||||
# /usr/lib/tmpfiles.d/tmp.conf, so this REPLACES it: the /var/tmp rule must stay.
|
||||
D /tmp 1777 root root 10d
|
||||
q /var/tmp 1777 root root 30d
|
||||
Reference in New Issue
Block a user