From: Tejun Heo <tj@kernel.org>
To: Tim Hockin <thockin@hockin.org>
Cc: Li Zefan <lizefan@huawei.com>,
Containers <containers@lists.linux-foundation.org>,
Cgroups <cgroups@vger.kernel.org>,
bsingharora@gmail.com, dhaval.giani@gmail.com,
Kay Sievers <kay.sievers@vrfy.org>,
jpoimboe@redhat.com, "Daniel P. Berrange" <berrange@redhat.com>,
lpoetter@redhat.com, workman-devel@redhat.com,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>
Subject: Re: cgroup: status-quo and userland efforts
Date: Mon, 22 Apr 2013 14:41:59 -0700 [thread overview]
Message-ID: <20130422214159.GG12543@htj.dyndns.org> (raw)
In-Reply-To: <CAAAKZwvh_R2Xz--bmSLiN33fsqKanOJMq_6+6hoFWFRx38O4gA@mail.gmail.com>
Hello, Tim.
On Mon, Apr 22, 2013 at 11:26:48PM +0200, Tim Hockin wrote:
> We absolutely depend on the ability to split cgroup hierarchies. It
> pretty much saved our fleet from imploding, in a way that a unified
> hierarchy just could not do. A mandated unified hierarchy is madness.
> Please step away from the ledge.
You need to be a lot more specific about why unified hierarchy can't
be implemented. The last time I asked around blk/memcg people in
google, while they said that they'll need different levels of
granularities for different controllers, google's use of cgroup
doesn't require multiple orthogonal classifications of the same group
of tasks.
Also, cgroup isn't dropping multiple hierarchy support over-night.
What has been working till now will continue to work for very long
time. If there is no fundamental conflict with the future changes,
there should be enough time to migrate gradually as desired.
> More, going towards a unified hierarchy really limits what we can
> delegate, and that is the word of the day. We've got a central
> authority agent running which manages cgroups, and we want out of this
> business. At least, we want to be able to grant users a set of
> constraints, and then let them run wild within those constraints.
> Forcing all such work to go through a daemon has proven to be very
> problematic, and it has been great now that users can have DIY
> sub-cgroups.
Sorry, but that doesn't work properly now. It gives you the illusion
of proper delegation but it's inherently dangerous. If that sort of
illusion has been / is good enough for your setup, fine. Delegate at
your own risks, but cgroup in itself doesn't support delegation to
lesser security domains and it won't in the foreseeable future.
> Strong disagreement, here. We use split hierarchies to great effect.
> Containment should be composable. If your users or abstractions can't
> handle it, please feel free to co-mount the universe, but please
> PLEASE don't force us to.
>
> I'm happy to talk more about what we do and why.
Please do so. Why do you need multiple orthogonal hierarchies?
Thanks.
--
tejun
next prev parent reply other threads:[~2013-04-22 21:42 UTC|newest]
Thread overview: 88+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-04-06 1:21 Tejun Heo
2013-04-08 13:46 ` Glauber Costa
2013-04-08 18:00 ` [Workman-devel] " Vivek Goyal
2013-04-08 18:26 ` Tejun Heo
2013-04-08 23:32 ` Lennart Poettering
2013-04-09 7:37 ` Glauber Costa
2013-04-09 19:11 ` Tejun Heo
2013-04-08 17:59 ` [Workman-devel] " Vivek Goyal
2013-04-08 18:16 ` Tejun Heo
2013-04-08 18:49 ` Tejun Heo
2013-04-08 19:11 ` Vivek Goyal
2013-04-08 19:20 ` Tejun Heo
2013-04-08 19:46 ` Vivek Goyal
2013-04-08 20:02 ` Tejun Heo
2013-04-09 9:50 ` Daniel P. Berrange
2013-04-09 19:38 ` Tejun Heo
2013-04-09 19:46 ` Tejun Heo
2013-04-09 21:04 ` Serge Hallyn
2013-04-09 21:11 ` Tejun Heo
2013-04-16 11:17 ` Li Zefan
2013-04-16 17:10 ` Tejun Heo
2013-04-17 1:29 ` Li Zefan
2013-04-22 21:26 ` Tim Hockin
2013-04-22 21:41 ` Tejun Heo [this message]
2013-04-22 22:33 ` Tim Hockin
2013-06-22 23:13 ` Tim Hockin
2013-06-25 0:01 ` Tejun Heo
2013-06-25 4:07 ` Tim Hockin
2013-06-26 21:20 ` Tejun Heo
2013-06-27 0:06 ` Tim Hockin
2013-06-26 23:14 ` David Lang
2013-06-27 1:04 ` Tejun Heo
2013-06-27 3:42 ` Tim Hockin
2013-06-27 17:38 ` Tejun Heo
2013-06-27 20:46 ` Tim Hockin
2013-06-27 21:04 ` Tejun Heo
2013-06-28 18:44 ` Tim Hockin
2013-06-29 16:40 ` Tejun Heo
2015-03-03 21:53 ` Luke Leighton
2015-03-03 21:38 ` Luke Leighton
2015-03-03 21:17 ` Luke Leighton
2015-03-04 5:08 ` David Lang
2015-03-04 11:27 ` Luke Kenneth Casson Leighton
2015-03-04 20:08 ` David Lang
2013-06-27 5:45 ` Mike Galbraith
2013-06-27 13:22 ` Serge Hallyn
2013-06-27 15:29 ` Tim Hockin
2013-06-27 16:18 ` Serge Hallyn
2015-03-03 22:00 ` Luke Leighton
2013-06-27 17:48 ` Tejun Heo
2013-06-27 18:14 ` Serge Hallyn
2013-06-27 18:45 ` Tejun Heo
2013-06-27 18:51 ` Serge Hallyn
2013-06-27 18:52 ` Tejun Heo
2013-06-27 20:52 ` Tim Hockin
2015-03-03 22:08 ` Luke Leighton
2013-06-28 9:09 ` [Workman-devel] " Daniel P. Berrange
2013-06-28 15:53 ` Serge Hallyn
2013-06-28 18:58 ` Tim Hockin
2015-03-03 22:20 ` Luke Leighton
2013-06-27 18:01 ` Tejun Heo
2013-06-28 3:46 ` Mike Galbraith
2013-06-28 4:09 ` Tejun Heo
2013-06-28 4:49 ` Mike Galbraith
2013-06-28 5:01 ` Tejun Heo
2013-06-28 6:00 ` Mike Galbraith
2013-06-28 15:05 ` Michal Hocko
2013-06-28 18:01 ` [Workman-devel] " Vivek Goyal
2013-06-28 19:59 ` Daniel P. Berrange
2013-06-28 22:40 ` Serge Hallyn
2013-06-28 22:43 ` Tejun Heo
2013-06-30 18:38 ` Michal Hocko
2013-07-15 18:49 ` Vivek Goyal
2013-07-23 14:48 ` Michal Hocko
2013-06-28 18:30 ` Tejun Heo
2013-06-28 18:53 ` Tim Hockin
2013-06-29 1:48 ` Lennart Poettering
2013-06-29 3:05 ` Tim Hockin
2013-06-30 19:39 ` Lennart Poettering
2013-07-01 6:06 ` Tim Hockin
2013-07-02 23:57 ` Thomas Gleixner
2013-07-03 0:44 ` Kay Sievers
2013-07-03 7:37 ` Borislav Petkov
2013-07-03 9:30 ` Thomas Gleixner
2013-07-09 23:12 ` Jiri Kosina
2013-07-03 17:11 ` James Bottomley
2013-06-28 19:18 ` Andy Lutomirski
2013-06-28 19:36 ` Serge Hallyn
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20130422214159.GG12543@htj.dyndns.org \
--to=tj@kernel.org \
--cc=berrange@redhat.com \
--cc=bsingharora@gmail.com \
--cc=cgroups@vger.kernel.org \
--cc=containers@lists.linux-foundation.org \
--cc=dhaval.giani@gmail.com \
--cc=jpoimboe@redhat.com \
--cc=kay.sievers@vrfy.org \
--cc=linux-kernel@vger.kernel.org \
--cc=lizefan@huawei.com \
--cc=lpoetter@redhat.com \
--cc=thockin@hockin.org \
--cc=workman-devel@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®