Back to blog

Administration

Linux Resource Limits: ulimit, cgroups v2 & Systemd Slice Configuration

Sets per-user and per-process limits with ulimit and /etc/security/limits.conf, then manages resources with cgroups v2 and systemd slices.

  • Linux
  • Administration
  • systemd
  • cgroups
  • PAM
  • Performance

Reader map

Key points in Linux Resource Limits: ulimit, cgroups v2 & Systemd Slice Configuration

Syntax first, runtime behavior second, migration cleanup last.

Read
14 min
Waypoints
6
Track
Administration
  1. 01
    Start here

    Use LimitNOFILE= or limits.conf when a process cannot open enough sockets.

  2. 02
    Waypoint

    Use TasksMax= when a service forks too many processes.

  3. 03
    Waypoint

    Use MemoryMax= when a service must not exceed a memory cap.

  4. 04
    Waypoint

    Use CPUQuota= when a service must not consume more than a fixed CPU budget.

  5. 05
    Waypoint

    Use CPUWeight= when services should share CPU proportionally under load.

  6. 06
    Migration check

    Use a custom .slice when several related services should share one budget.

SEO Metadata

SEO Title Options

  1. Linux Resource Limits: ulimit, cgroups v2 & Systemd Slice
  2. Linux Administration: Practical 2026 Guide
  3. Administration Playbook: Linux Administration

Meta Description Options

  1. Learn Linux Administration with a practical Administration framework, expert mistakes, implementation steps, examples, FAQ, and schema-ready guidance.
  2. Sets per-user and per-process limits with ulimit and /etc/security/limits.conf, then manages resources with cgroups v2 and systemd slices.

URL Slug

linux-resource-limits-ulimit-cgroups-v2-systemd-slice-configuration

Focus Keyword

Linux Administration

Additional LSI Keywords

  • Administration
  • Linux
  • systemd
  • cgroups
  • PAM
  • Performance
  • Linux Resource Limits: ulimit, cgroups v2 & Systemd Slice Configuration
  • production checklist
  • implementation guide
  • best practices
  • architecture decisions
  • testing strategy

Table of Contents

Article overview

Linux Administration is the kind of topic that looks simple until it reaches production. Teams usually discover the real cost late: unclear boundaries, weak defaults, hidden maintenance work, and decisions that seemed harmless when the codebase was small.

The problem gets worse when the article, tutorial, or implementation guide only explains the happy path. This guide closes that gap with a practical framework, a comparison table, common mistakes, and a deep technical section you can use while planning real work.

Keep reading for the non-obvious part: the safest implementation is rarely the most impressive-looking one. It is the one your team can debug, test, document, and evolve without turning every future change into archaeology.

Key Takeaways

  • Linux Administration should be evaluated as a production decision, not only as a syntax or tooling choice.
  • The best implementation keeps responsibilities visible, with clear ownership, tests, documentation, and rollback paths.
  • Search visibility improves when practical depth, structured answers, and expert examples live on the same page.

[IMAGE: A mobile-first technical article layout showing the main concept, decision table, implementation checklist, and FAQ blocks. Alt: Linux Administration expert guide for Administration]

What Linux Administration means

Linux Administration means applying administration knowledge to a concrete engineering decision, then turning that decision into reliable code, documentation, and operational behavior. In practice, it combines the topic's core concepts with trade-off analysis, implementation boundaries, testing strategy, and maintenance discipline.

This is the definition worth optimizing for featured snippets because it avoids hype. It tells the reader what the topic does and what a professional implementation must include.

Why it matters now

The technical web is more crowded than it was a few years ago. Thin tutorials can still get indexed, but they rarely earn trust from senior developers, buyers, AI answer systems, or teams that need production guidance.

For administration topics, the strongest content now has three layers:

  • a clear answer for fast scanning
  • a practical framework for implementation
  • expert context that explains what breaks later

That same structure helps search engines understand the page. It also helps readers decide whether the advice fits their project.

Implementation framework

Use this framework before adopting the approach described in this article.

  1. Define the user problem and the production risk.
  2. Identify the smallest reliable implementation boundary.
  3. Keep configuration, secrets, and environment-specific behavior outside the article's core logic.
  4. Add tests for the behavior that would hurt if it regressed.
  5. Document the trade-off, not only the final code.
  6. Measure the result with logs, metrics, or user-facing outcomes.
  7. Revisit the decision after real usage exposes edge cases.

The sequence is deliberately conservative. It keeps the work grounded in outcomes instead of novelty.

[IMAGE: A seven-step implementation framework with discovery, boundary design, configuration, tests, documentation, measurement, and iteration. Alt: Linux Administration implementation framework]

Practical comparison

Decision areaStrong approachWeak approachWhy it matters
ScopeSolve one clear problemMix unrelated concernsFocus improves testing and search intent
ArchitecturePut logic in explicit classes or documented boundariesHide behavior in templates or incidental callbacksFuture changes stay easier to review
Data flowPass prepared data into the view or endpointQuery or compute in presentation codeReduces regressions and performance surprises
TestingCover the risky behavior directlyTest only the happy pathCatches production failures earlier
DocumentationExplain trade-offs and limitsRepeat generic definitionsBuilds E-E-A-T and reader trust
OperationsTrack logs, metrics, and rollback stepsShip without measurementMakes the decision reversible

This table is intentionally practical. It gives a reviewer something to check before the implementation becomes expensive to change.

Expert workflow

Expert tip: "Treat Linux Administration as a system boundary. If the next developer cannot find where the decision lives, how it is tested, and when it should be avoided, the implementation is not finished."

A useful workflow is simple:

  • Start with the smallest working example.
  • Add the constraints that exist in your real project.
  • Remove anything that only demonstrates cleverness.
  • Write down the failure modes.
  • Add links to related decisions so future readers can navigate the topic cluster.

That last point matters for both humans and search systems. A single article can answer a question; a cluster proves authority.

Common mistakes

Mistake 1: Copying a pattern without its context

A pattern that works in a small demo can fail in a real application. The missing context is usually data volume, team experience, deployment process, security requirements, or observability.

Before copying the pattern, ask what assumption made it safe in the original example.

Mistake 2: Putting business logic in the wrong layer

This is the fastest way to make future debugging expensive. In Laravel, PHP, and server-rendered websites, presentation should receive prepared data, not discover rules on its own.

Keep decision logic in models, actions, services, policies, requests, jobs, or documented helpers where it can be tested directly.

Mistake 3: Optimizing for novelty instead of maintainability

Newer tools and language features can be valuable. They can also hide simple behavior behind unfamiliar syntax.

Use the option that makes the next production incident easier to understand.

Mistake 4: Publishing without a measurement plan

If the article describes a performance, SEO, security, or architecture improvement, define how success will be checked. Logs, tests, crawl diagnostics, analytics, and user behavior are all stronger than assumptions.

[IMAGE: A common-mistakes board with context loss, wrong layer, novelty bias, and missing measurement highlighted. Alt: Linux Administration common mistakes]

Image placeholders

  • [IMAGE: A concept diagram for Linux Administration with input, decision boundary, implementation, tests, and production feedback. Alt: Linux Administration concept diagram]
  • [IMAGE: A mobile screenshot-style checklist for Linux Resource Limits: ulimit, cgroups v2 & Systemd Slice Configuration. Alt: Linux Administration mobile checklist]
  • [IMAGE: A comparison table visualization for strong versus weak implementation choices. Alt: Linux Administration comparison table]

Video placeholder

[VIDEO: Insert a 5-8 minute YouTube walkthrough that demonstrates the main decision, the implementation boundary, the test strategy, and the production caveats for Linux Administration.]

Internal linking opportunities

Original Technical Deep Dive

The short version

Linux has two different resource-limit layers that are often mixed up:

LayerControlsGood for
ulimit, limits.conf, pam_limitsPer-process resource limits inherited by login-session processesOpen files, process count, core files, locked memory, stack size
cgroups v2 through systemdResource policy for a group of processes in a unit or sliceCPU shares, CPU caps, memory caps, task caps, IO policy

Use them together, but do not expect one to replace the other.

Examples:

  • Use LimitNOFILE= or limits.conf when a process cannot open enough sockets.
  • Use TasksMax= when a service forks too many processes.
  • Use MemoryMax= when a service must not exceed a memory cap.
  • Use CPUQuota= when a service must not consume more than a fixed CPU budget.
  • Use CPUWeight= when services should share CPU proportionally under load.
  • Use a custom .slice when several related services should share one budget.

The common mistake is editing /etc/security/limits.conf and expecting a systemd service to change. PAM limits apply when a PAM-managed session starts. Most system services are not launched through your SSH login session, so they need systemd unit settings.

Inspect current process limits

Start with the shell:

ulimit -a
ulimit -n
ulimit -u

Common options:

CommandMeaning
ulimit -nMaximum open file descriptors
ulimit -uMaximum user processes
ulimit -cMaximum core file size
ulimit -lMaximum locked memory
ulimit -sMaximum stack size
ulimit -vMaximum virtual memory

Read the kernel view for the current shell:

cat /proc/$$/limits

Read another process:

PID=$(pidof nginx | awk '{print $1}')
sudo cat /proc/"$PID"/limits

Use prlimit when available:

prlimit --pid "$$"
sudo prlimit --pid "$PID"

Soft limits are the current defaults. Hard limits are ceilings. A non-root process can usually lower its limits and raise a soft limit up to the hard limit, but it cannot raise the hard limit.

Change ulimit for one shell

This affects the current shell and processes started after the change:

ulimit -n 65535
ulimit -u 4096
ulimit -c 0

Verify:

ulimit -a
cat /proc/$$/limits

Start a process from that shell:

python3 -c 'import resource; print(resource.getrlimit(resource.RLIMIT_NOFILE))'

This is useful for testing, but it is not persistent. It also does not change already-running services.

If a command starts from cron, SSH, sudo, systemd, a container runtime, or a process manager, inspect the limits in that actual process, not in your interactive shell.

Configure login-session limits with PAM

/etc/security/limits.conf and /etc/security/limits.d/*.conf are read by the pam_limits module for PAM sessions.

[IMAGE: Supporting visual 1 for Linux Resource Limits: ulimit, cgroups v2 & Systemd Slice Configuration, showing Linux Administration decisions, examples, and Linux, Administration, systemd. Alt: Linux Administration linux-resource-limits-ulimit-cgroups-v2-systemd-slice-configuration visual 1]

[IMAGE: Supporting visual 1 for Linux Resource Limits: ulimit, cgroups v2 & Systemd Slice Configuration, showing Linux Administration decisions, examples, and Linux, Administration, systemd. Alt: Linux Administration linux-resource-limits-ulimit-cgroups-v2-systemd-slice-configuration visual 1]

Create a drop-in instead of editing the main file:

sudoedit /etc/security/limits.d/90-web.conf

Example:

@web soft nofile 65535
@web hard nofile 131072
@web soft nproc 4096
@web hard nproc 8192
@web soft core 0
@web hard core 0

Meaning:

  • domain: @web, the Unix group;
  • type: soft or hard;
  • item: nofile, nproc, core;
  • value: numeric value or unlimited where supported.

Add a user to the group:

sudo groupadd --system web
sudo usermod -aG web deploy

Log out and back in. PAM limits apply at session creation.

Verify in a new SSH session:

id
ulimit -n
ulimit -u
cat /proc/$$/limits

Check that PAM loads pam_limits.so for the service you care about:

grep -R "pam_limits.so" /etc/pam.d

Common files include:

/etc/pam.d/sshd
/etc/pam.d/login
/etc/pam.d/su
/etc/pam.d/sudo
/etc/pam.d/common-session
/etc/pam.d/system-auth

Do not blindly add duplicate pam_limits.so lines. Distribution PAM stacks vary. On Debian-style systems, common-session may already include it. On RHEL-style systems, system-auth or password-auth may already include it.

Know the limits.conf traps

limits.conf is not global state. The limits are set per login session and inherited by processes inside that session.

Important behavior:

  • changes do not affect existing sessions;
  • changes do not affect most systemd system services;
  • group rules use @group;
  • wildcard * is a default, not always the strongest match;
  • individual user limits generally take priority over group limits;
  • nofile unlimited maps to /proc/sys/fs/nr_open;
  • invalid values can make PAM reject a login if the module is required.

Check the system maximum file-descriptor ceiling:

cat /proc/sys/fs/nr_open
cat /proc/sys/fs/file-max

If you need a higher global ceiling, use sysctl deliberately:

printf '%s\n' 'fs.nr_open = 1048576' | sudo tee /etc/sysctl.d/90-file-limits.conf
sudo sysctl --system

Do not set enormous limits everywhere. A process that can open one million files can also consume kernel memory and make failure harder to diagnose.

Configure limits for a systemd service

For a system service, use a unit drop-in:

sudo systemctl edit myapp.service

Add:

[Service]
LimitNOFILE=65535
LimitNPROC=4096
LimitCORE=0

Reload and restart:

sudo systemctl daemon-reload
sudo systemctl restart myapp.service

Verify:

systemctl show myapp.service -p LimitNOFILE -p LimitNPROC -p LimitCORE
systemctl status myapp.service --no-pager
PID=$(systemctl show -p MainPID --value myapp.service)
sudo cat /proc/"$PID"/limits

Use LimitNOFILE= for file descriptors. Be careful with LimitNPROC=. It counts processes for the real UID, not just processes started by one service, and it is not a good per-service fork limit. For service task count, prefer TasksMax=.

Check cgroups v2

Check whether the host uses the unified cgroups v2 hierarchy:

stat -fc %T /sys/fs/cgroup

Expected for cgroups v2:

cgroup2fs

Inspect the systemd tree:

systemd-cgls
systemd-cgtop

Inspect one service:

systemctl show myapp.service -p ControlGroup -p Slice

Read the matching cgroup files:

CGROUP=$(systemctl show myapp.service -p ControlGroup --value)
sudo ls -la /sys/fs/cgroup"$CGROUP"
sudo cat /sys/fs/cgroup"$CGROUP"/cgroup.controllers
sudo cat /sys/fs/cgroup"$CGROUP"/cgroup.procs

Common cgroups v2 files:

FileMeaning
cpu.weightRelative CPU weight
cpu.maxCPU quota and period
memory.currentCurrent memory use
memory.highMemory pressure throttle point
memory.maxHard memory cap
memory.eventsOOM and pressure events
pids.currentCurrent task count
pids.maxTask cap
io.statIO counters

[IMAGE: Supporting visual 2 for Linux Resource Limits: ulimit, cgroups v2 & Systemd Slice Configuration, showing Linux Administration decisions, examples, and Linux, Administration, systemd. Alt: Linux Administration linux-resource-limits-ulimit-cgroups-v2-systemd-slice-configuration visual 2]

[IMAGE: Supporting visual 2 for Linux Resource Limits: ulimit, cgroups v2 & Systemd Slice Configuration, showing Linux Administration decisions, examples, and Linux, Administration, systemd. Alt: Linux Administration linux-resource-limits-ulimit-cgroups-v2-systemd-slice-configuration visual 2]

Do not write directly to cgroup files for services managed by systemd. Use systemd unit properties so systemd's view and the kernel state stay aligned.

Cap one service with cgroups

Edit:

sudo systemctl edit myapp.service

Add:

[Service]
CPUAccounting=yes
CPUWeight=100
CPUQuota=200%
MemoryAccounting=yes
MemoryHigh=1G
MemoryMax=1500M
TasksAccounting=yes
TasksMax=512
IOAccounting=yes

Meaning:

  • CPUWeight=100: default-weight CPU share under contention.
  • CPUQuota=200%: at most two full CPUs worth of runtime.
  • MemoryHigh=1G: throttle under memory pressure before the hard cap.
  • MemoryMax=1500M: hard memory limit.
  • TasksMax=512: task cap for the service cgroup.
  • IOAccounting=yes: collect IO accounting data.

Reload and restart:

sudo systemctl daemon-reload
sudo systemctl restart myapp.service

Verify:

systemctl show myapp.service \
  -p CPUAccounting \
  -p CPUWeight \
  -p CPUQuotaPerSecUSec \
  -p MemoryAccounting \
  -p MemoryHigh \
  -p MemoryMax \
  -p TasksAccounting \
  -p TasksMax \
  -p IOAccounting

Check runtime stats:

systemctl status myapp.service --no-pager
systemd-cgtop
CGROUP=$(systemctl show myapp.service -p ControlGroup --value)
sudo cat /sys/fs/cgroup"$CGROUP"/memory.current
sudo cat /sys/fs/cgroup"$CGROUP"/memory.events
sudo cat /sys/fs/cgroup"$CGROUP"/pids.current
sudo cat /sys/fs/cgroup"$CGROUP"/pids.max
sudo cat /sys/fs/cgroup"$CGROUP"/cpu.max
sudo cat /sys/fs/cgroup"$CGROUP"/cpu.weight

When a service hits MemoryMax=, expect allocation failures or the OOM path for processes in that cgroup. Set MemoryHigh= below the hard cap when you want throttling and earlier pressure signals instead of only a hard cliff.

Apply temporary limits with systemctl set-property

For an emergency cap without editing a unit file:

sudo systemctl set-property --runtime myapp.service CPUQuota=100% MemoryMax=1G TasksMax=256

Verify:

systemctl show myapp.service -p CPUQuotaPerSecUSec -p MemoryMax -p TasksMax

Remove a runtime override by restarting the unit manager or setting the value again. For persistent policy, omit --runtime or use systemctl edit:

sudo systemctl set-property myapp.service CPUQuota=100% MemoryMax=1G TasksMax=256

This writes a drop-in under /etc/systemd/system.control/. For hand-maintained infrastructure, systemctl edit is usually clearer because the config is visible in a normal unit drop-in.

Use a slice when several units should share one resource budget.

Create:

sudoedit /etc/systemd/system/app.slice

Add:

[Unit]
Description=Application workload slice

[Slice]
CPUAccounting=yes
CPUWeight=200
CPUQuota=400%
MemoryAccounting=yes
MemoryHigh=6G
MemoryMax=8G
TasksAccounting=yes
TasksMax=2048
IOAccounting=yes

Assign services to the slice:

sudo systemctl edit myapp.service

Add:

[Service]
Slice=app.slice

Repeat for workers:

sudo systemctl edit myapp-worker.service

Add:

[Service]
Slice=app.slice

Reload and restart:

sudo systemctl daemon-reload
sudo systemctl restart app.slice myapp.service myapp-worker.service

Inspect:

systemctl status app.slice --no-pager
systemctl show myapp.service -p Slice -p ControlGroup
systemctl show myapp-worker.service -p Slice -p ControlGroup
systemd-cgls app.slice
systemd-cgtop

Slice names encode hierarchy. app-api.slice is a child of app.slice. Default system services usually live under system.slice; user sessions under user.slice; machine and container scopes under machine.slice.

Limit all services for a user or group carefully

User sessions are usually below user.slice, with per-user slices such as user-1000.slice.

Inspect:

loginctl user-status deploy
systemd-cgls user.slice

Create a drop-in for one user slice:

sudo mkdir -p /etc/systemd/system/user-1001.slice.d
sudoedit /etc/systemd/system/user-1001.slice.d/50-limits.conf

Add:

[Slice]
MemoryMax=2G
TasksMax=512
CPUQuota=200%

Reload:

sudo systemctl daemon-reload
sudo systemctl restart user-1001.slice

Be careful restarting user slices on a production host. It can terminate user sessions and processes. Prefer testing on a non-critical account first.

For all user slices, systemd supports truncated drop-in names such as user-.slice.d, but broad user limits can surprise SSH sessions, cron jobs, desktop sessions, and per-user services.

[IMAGE: Supporting visual 3 for Linux Resource Limits: ulimit, cgroups v2 & Systemd Slice Configuration, showing Linux Administration decisions, examples, and Linux, Administration, systemd. Alt: Linux Administration linux-resource-limits-ulimit-cgroups-v2-systemd-slice-configuration visual 3]

Pick the right control

Use this decision table:

NeedUse
Raise open socket/file limit for a system serviceLimitNOFILE= in the unit
Raise open file limit for SSH users/etc/security/limits.d/*.conf plus pam_limits.so
Cap service memoryMemoryMax=
Throttle service before hard memory capMemoryHigh=
Cap task/process count per serviceTasksMax=
Cap process count per login usernproc in PAM limits
Cap CPU hard maximumCPUQuota=
Prefer one service over another under contentionCPUWeight=
Give a group of services one shared budget.slice with resource controls
Debug actual inherited process limits/proc/<pid>/limits
Debug actual cgroup placementsystemctl show -p ControlGroup and /sys/fs/cgroup

[IMAGE: Supporting visual 3 for Linux Resource Limits: ulimit, cgroups v2 & Systemd Slice Configuration, showing Linux Administration decisions, examples, and Linux, Administration, systemd. Alt: Linux Administration linux-resource-limits-ulimit-cgroups-v2-systemd-slice-configuration visual 3]

Operational checklist

Before changing limits:

systemctl status myapp.service --no-pager
systemctl show myapp.service -p Slice -p ControlGroup
PID=$(systemctl show -p MainPID --value myapp.service)
sudo cat /proc/"$PID"/limits

After changing limits:

sudo systemctl daemon-reload
sudo systemctl restart myapp.service
systemctl show myapp.service -p LimitNOFILE -p MemoryMax -p TasksMax -p CPUQuotaPerSecUSec
PID=$(systemctl show -p MainPID --value myapp.service)
sudo cat /proc/"$PID"/limits
CGROUP=$(systemctl show myapp.service -p ControlGroup --value)
sudo cat /sys/fs/cgroup"$CGROUP"/memory.events
sudo cat /sys/fs/cgroup"$CGROUP"/pids.max

Document:

  • why the limit exists;
  • whether it is a process limit or a cgroup control;
  • exact drop-in file path;
  • service restart requirement;
  • rollback command;
  • expected monitoring signal when the limit is hit.

The clean end state is not "the command accepted the setting." The clean end state is that the running process has the expected /proc/<pid>/limits, the service is in the expected cgroup, and the cgroup files under /sys/fs/cgroup show the expected policy.

FAQ

What is Linux Administration?

Linux Administration is a practical administration topic that should be evaluated through implementation scope, production risk, testing, documentation, and long-term maintainability.

When should a team use Linux Administration?

Use Linux Administration when it solves a real project constraint, improves clarity, or reduces operational risk. Avoid it when it only adds novelty or hides behavior from future maintainers.

What is the biggest risk with Linux Administration?

The biggest risk is copying a pattern without its context. Production systems need clear boundaries, rollback options, tests, and observability before a technique becomes dependable.

How do you test Linux Administration?

Test the smallest unit that owns the behavior, then add integration coverage for the path users or systems actually rely on. Include failure cases, configuration differences, and regression checks.

How does Linux Administration affect SEO and AI search visibility?

It improves visibility when the article gives a direct answer, expert context, structured headings, internal links, trustworthy references, and FAQ content that matches the visible page.

Conclusion

Linux Administration is worth doing when the implementation improves clarity, reliability, or delivery speed. It is not worth doing when it hides ownership, increases operational risk, or makes the system harder to explain.

Use the framework above as a review checklist. Then connect this topic to the rest of the project documentation so readers can move from concept to implementation without losing context.

Top