Ubuntu Community · Help: Ubuntu fails to start intermittently in containers, logs inside

391
Ubr/ubuntu·posted by nikic·3 hours agoTooling

Help: Ubuntu fails to start intermittently in containers, logs inside

Most Ubuntu articles stop at "how to use it" and never cover "when not to use it". This is an attempt at the second half.

We also fixed monitoring along the way: replaced average-based alerts with percentiles and split them per endpoint. False alerts dropped by about seventy percent and the on-call rotation visibly cheered up.

The first thing was to collapse the variables. We were changing config and upgrading the version at the same time, and afterwards nobody could say which change caused what. We rolled back to moving one variable at a time, re-ran three times, and only then did the curve settle. Tedious, but not skippable.

Sstackoverflow.comExternal link · opens in a new tab
176 comments

176 comments

· first 120 loaded
M
Cchen_devOPMod·just now

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

503
Llinlin·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

477
Oops_wang·2 days ago

One counter-example: below Ubuntu 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

472
Cchen_dev·3 minutes ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

469
Hhuang_ke·yesterday

One counter-example: below Ubuntu 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

122
Zzhou_yiOP·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

307
Lli_ming·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

99
NnikicMod·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

34
Rrase·2 days agoedited

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

7
WwinterMod·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

3
Rran_bo·2 days ago

I just read the Ubuntu source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

134
Llinlin·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

70
Sswoole_lee·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

488
Nnikic·2 days agoLevel 6

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

138
Rran_bo·2 days agoLevel 6

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

1
Rran_bo·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

436
Hhuang_ke·just now

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

42
Ttang_hao·just now

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

34
Sswoole_lee·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

51
Bbob_chenOP·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

106
Zzhu_zong·2 days agoLevel 6

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

9
Mmike_xu·2 days agoedited

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

84
Rrase·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

465
Ttang_hao·2 hours ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

23
Zzhu_zong·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

106
Mmike_xuOP·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

158
Rran_bo·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

1
WwinterOP·3 minutes ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

396
Rrase·2 days agoedited

This is not a Ubuntu problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

195
Mmike_xu·2 days ago

One counter-example: below Ubuntu 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

70
Cchen_devMod·2 days ago

This is not a Ubuntu problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

13
Ttang_hao·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

513
Rrase·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

435
Sswoole_lee·3 minutes ago

One counter-example: below Ubuntu 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

415
Cchen_dev·2 days agoedited

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

1
Cchen_dev·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

415
Rran_bo·2 days ago

This is not a Ubuntu problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

408
Nnikic·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

377
Oops_wangOP·1 hour agoedited

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

314
Rrase·3 minutes ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

373
Cchen_dev·12 minutes ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

48
Mmike_xu·2 days agoedited

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

414
Cchen_dev·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

1
Mmike_xuOP·28 minutes ago

One counter-example: below Ubuntu 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

305
Rrase·28 minutes ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

43
Zzhou_yi·2 days ago

I just read the Ubuntu source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

145
Rran_bo·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

20
Sswoole_lee·2 days agoLevel 6

I just read the Ubuntu source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

129
Oops_wang·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

10
Rrase·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

221
Cchen_dev·2 days ago

I just read the Ubuntu source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

324
Nnikic·yesterday

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

260
Mmike_xu·5 hours ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

165
Mmike_xu·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

7
Aalice_dev·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

4
Rrase·5 hours ago

This is not a Ubuntu problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

219
Aalice_dev·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

441
Kkernel_panicOP·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

209
Sslow_query·2 days agoLevel 6

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

357
Sswoole_lee·2 days agoedited

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

100
Sslow_query·2 days agoedited

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

44
Oops_wang·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

97
Rrase·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

96
Kkite·2 days agoedited

I just read the Ubuntu source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

90
Oops_wang·just now

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

367
Sslow_query·just nowedited

This is not a Ubuntu problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

253
Kkite·1 hour agoedited

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

494
Aalice_dev·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

370
Lli_ming·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

113
Lli_ming·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

15
Aalice_devOP·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

97
Oops_wangMod·12 minutes ago

One counter-example: below Ubuntu 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

33
Rrase·2 days agoedited

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

41
Sswoole_lee·yesterday

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

32
Llinlin·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

436
KkiteOP·2 days ago

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

148
Ttang_hao·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

190
Aalice_devOPMod·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

69
Lli_ming·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

118
Sslow_query·2 hours ago

This is not a Ubuntu problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

230
WwinterOP·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

49
Ddev_zhou·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

18
Cchen_dev·2 days ago

One counter-example: below Ubuntu 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

2
Rran_bo·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

103
Cchen_dev·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

103
Aalice_dev·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

94
Sslow_query·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

115
Zzhu_zong·2 days ago

This is not a Ubuntu problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

89
Rran_bo·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

85
Kkite·2 days ago

One counter-example: below Ubuntu 7.4 the semantics of that code are different, so do not copy it verbatim. We got burned in staging and rolled back once.

414
RraseOP·5 hours ago

I just read the Ubuntu source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

1
Aalice_devOP·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

208
Kkite·2 days agoedited

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

59
RraseOP·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

14
Sswoole_lee·2 days ago

Worth learning from this debugging approach. We went straight at the logs and took a much longer route.

47
Llinlin·12 minutes ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

42
Lli_ming·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

42
Bbob_chen·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

38
Oops_wang·2 days ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

37
Rrase·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

126
Sslow_query·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

1
Rran_bo·2 days ago

I see point 3 differently. The trade-off depends on your read/write ratio: read-heavy with little writing means caching actually widens the inconsistency window.

33
Wwinter·3 minutes ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

31
Rrase·2 days agoedited

This is not a Ubuntu problem, it is a usage problem. The docs say this API is not thread-safe and you must lock around it yourself.

30
Kkite·12 minutes ago

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

26
Ttang_hao·2 days ago

Has anyone run a controlled experiment? I did, reducing it to a single variable, and the difference was 4% — within noise. So I suspect the main cause is something else.

69
Llinlin·2 days agoedited

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

18
WwinterMod·2 days ago

Sharing our numbers, 8 cores 16GB, same scenario:

| Concurrency | P50 | P99 |
|---|---|---|
| 200 | 12ms | 88ms |
| 500 | 31ms | 340ms |

P99 clearly collapses at 500 concurrency, which lines up with your knee point.

7
Ddev_zhou·28 minutes ago

I just read the Ubuntu source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

25
Lli_ming·yesterday

We have run this in production for two years without hitting it. That said, we never reached this scale, so our experience is not really evidence here.

20
Ddev_zhouMod·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

434
Kkite·just now

I just read the Ubuntu source — the author actually explains the reasoning in a comment, roughly "so that it degrades into predictable behaviour in extreme cases".

346
Mmike_xu·3 minutes ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

30
Kkernel_panic·2 days ago

Agreeing with the above. One addition: with this option enabled the GC count in your metrics doubles, so adjust the alert threshold at the same time or it will keep firing.

7
Hhuang_ke·12 minutes agoedited

There is actually a simpler fix that needs no architecture change: move this check up to the gateway and the problem disappears. The cost is one extra lookup at the gateway.

3
RraseMod·2 days ago

Can you give a minimal reproduction? I ran it locally for ten minutes and could not reproduce on macOS with the latest version.

2
Mmike_xu·2 days ago

Thanks for sharing real numbers — far more useful than the articles that only cover concepts.

113
Kkite·2 days ago

Saved. I am reworking this area this week — this saves a lot of wrong turns.

1
Rrase·2 days ago

This matches what we see in production. We only hit it past 3k QPS; the earlier load tests showed nothing — the test traffic was too clean, with no long-tail requests.

1
Rran_bo·2 days ago

A question: what changes in a container with a 512Mi memory limit? That is how we run it in production.

1

This is the post detail page /en/c/ubuntu/post/p11. Posts and comments are generated deterministically from a seeded PRNG, so the same post always renders the same content and the link can be shared, reloaded and indexed. In production this page reads MySQL for the post, Redis for hot-post caching, and fetches the whole comment tree in a single query on the path column.

See the database schema →