Ansible Role linuxfabrik.lfops.kernel_settings¶
This role configures kernel settings. The settings are made permanently and activated simultaneously at runtime.
The role does nothing on its own and relies on the linux_system_roles.kernel_settings role.
Available since LFOps 2.0.0.
How the Role Behaves¶
- If any
sunrpc.*setting is configured (the mariadb_server role setssunrpc.tcp_slot_table_entries), the role loads thesunrpckernel module and lists it in/etc/modules-load.d/sunrpc.conf, since thesunrpc.*settings only exist while the module is loaded and nothing else loads it at boot on a host without NFS.options sunrpclines in/etc/modprobe.d/are commented out in the process. The file stays in place when thesunrpc.*settings are removed later. - On Ubuntu 22.04 the role removes
kernel.sched_min_granularity_nsandkernel.sched_wakeup_granularity_nsfrom the TuneD profile it builds on (adropentry in its own profile). The TuneD release of Ubuntu 22.04 sets them although its 5.15 kernel has neither, and TuneD's own verification would otherwise fail on every run.
Known Limitations¶
- TuneD applies the settings when its daemon starts, and systemd starts
tuned.servicein parallel with other services. A service that reads kernel parameters at its own startup can therefore come up before TuneD has applied the profile and then keeps the old values for its whole runtime.sysctlandtuned-adm verifyreport the new values in the meantime, because both look at the current kernel state rather than at the state the service saw. - Example: the kernel applies the
net.core.somaxconnclamp insidelisten(), so Redis keeps the old accept queue size until it is restarted. - Wherever a service depends on a parameter this role sets, that service needs a systemd drop-in ordering it after TuneD.
- Put the ordering into the consuming unit rather than collecting a
Before=list in a drop-in fortuned.service: the requirement belongs to the service that has it, a central list has to be kept in sync with every host, and a longBefore=list invites ordering cycles, which systemd resolves by silently dropping an arbitrary edge. An ordering dependency on a unit that is not installed is ignored without a warning, so the same drop-in is safe on hosts without TuneD. - The ordering works because
tuned.serviceisType=dbusand TuneD claimscom.redhat.tunedonly after the profile has been applied. That guarantee comes from the TuneD implementation, not from a documented contract, so it is worth re-checking after a major TuneD version jump. - Ordering only applies while systemd computes a transaction. Restarting
tuned.serviceon a running host does not restart the consuming services, so they keep their stale values until they are restarted themselves.
Example:
# /etc/systemd/system/redis.service.d/z00-after-tuned.conf
# TuneD claims its D-Bus name only after applying the profile, so ordering
# this service After=tuned.service guarantees the sysctls are in place first.
# Verified against tuned 2.22.1 on Rocky 8: daemon.py calls start_tuning()
# before exports.start(), which reaches dbus.service.BusName() in
# dbus_exporter.py, where Type=dbus readiness is signalled.
[Unit]
After=tuned.service
Requirements¶
Manual steps:
- Install the Linux System Roles on the Ansible control node, for example by calling
ansible-galaxy collection install fedora.linux_system_roles.
Tags¶
kernel_settings
- Configures kernel settings.
- Triggers: none.
Optional Role Variables¶
These variables are intended to be used in a host / group variable file in the Ansible inventory. Note that the group variable can only be used in one group at a time. For details on the values have a look at the linux_system_roles.kernel_settings role.
kernel_settings__sysctl__host_var / kernel_settings__sysctl__group_var
- sysctl settings. Entries are identified by
name, so an entry from the inventory is merged into the default entry of the same name. - Type: List of dictionaries.
-
Default: on Ubuntu 22.04
yaml - name: 'drop' value: 'kernel.sched_min_granularity_ns,kernel.sched_wakeup_granularity_ns'[]on all other platforms. -
Deviates from the upstream default
[]on Ubuntu 22.04: the TuneD profile there sets two scheduler sysctls that the 5.15 kernel does not have, and TuneD's own verification would fail on every run (see "How the Role Behaves"). -
Subkeys:
-
name:- Mandatory. Name of the sysctl, or
dropto remove options from the TuneD profile the role builds on. An inventory entry nameddropreplaces the value of the default one, so list the two scheduler sysctls there as well on Ubuntu 22.04. - Type: String.
- Mandatory. Name of the sysctl, or
-
state:- Optional.
presentorabsent.absentremoves the setting from the profile. - Type: String.
- Default:
'present'
- Optional.
-
value:- Mandatory for
state: 'present'entries. Value of the sysctl, or the comma-separated options fordrop. - Type: String or Number.
- Mandatory for
-
kernel_settings__sysfs__host_var / kernel_settings__sysfs__group_var
- sysfs settings. Entries are identified by
name. - Type: List of dictionaries.
- Default:
[] -
Subkeys:
-
name:- Mandatory. Path below
/sys. - Type: String.
- Mandatory. Path below
-
state:- Optional.
presentorabsent.absentremoves the setting from the profile. - Type: String.
- Default:
'present'
- Optional.
-
value:- Mandatory for
state: 'present'entries. Value to write. - Type: String or Number.
- Mandatory for
-
kernel_settings__systemd_cpu_affinity__host_var / kernel_settings__systemd_cpu_affinity__group_var
- The CPUs systemd pins its processes to, for example
'1,3,5,7'. - Type: String.
- Default:
''(not set by the role, the TuneD profile's value applies)
kernel_settings__transparent_hugepages__host_var / kernel_settings__transparent_hugepages__group_var
- The transparent hugepages mode.
- Type: String. One of
always,madvise,never. - Default:
''(not set by the role, the TuneD profile's value applies)
kernel_settings__transparent_hugepages_defrag__host_var / kernel_settings__transparent_hugepages_defrag__group_var
- The transparent hugepages defrag mode.
- Type: String. One of
always,defer,defer+madvise,madvise,never. - Default:
''(not set by the role, the TuneD profile's value applies)
Example:
# optional
kernel_settings__sysctl__group_var:
- name: 'vm.overcommit_memory'
value: 1
- name: 'net.core.somaxconn'
value: 1024
kernel_settings__sysfs__group_var:
- name: '/sys/kernel/debug/x86/pti_enabled'
value: 0
- name: '/sys/kernel/debug/x86/retp_enabled'
value: 0
kernel_settings__systemd_cpu_affinity__group_var: '1,3,5,7'
kernel_settings__transparent_hugepages__group_var: 'madvise'
kernel_settings__transparent_hugepages_defrag__group_var: 'defer'