# Nofile -\> limit for open file under docker container for elasticsearch user

**URL:** <https://discuss.elastic.co/t/nofile-limit-for-open-file-under-docker-container-for-elasticsearch-user/299764>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Tags:** docker\
**Created:** [March 15, 2022, 4:39pm UTC](https://discuss.elastic.co/t/nofile-limit-for-open-file-under-docker-container-for-elasticsearch-user/299764 "2022-03-15T16:39:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![INS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ins/32/92827_2.png) [@INS](https://discuss.elastic.co/u/INS)\
**Post date:** [March 15, 2022, 4:39pm UTC](https://discuss.elastic.co/t/nofile-limit-for-open-file-under-docker-container-for-elasticsearch-user/299764/1 "2022-03-15T16:39:33Z")

</div>

Hi I read this post https://discuss.elastic.co/t/docs-nofile-or-nproc/142049/2 regarding construct for nofile vs nproc.  
Let me describe my case  
I've provisioned by docker compose service for elasticsearch:

```auto
ulimits:
      memlock:
        soft: -1
        hard: -1
      nofile:
        soft: 65535
        hard: 65535
    deploy:

```

at least I saw in docker container that I have

> open files (-n) 1048576

```auto

elasticsearch@441ecdf403aa:~$ ulimit -a
core file size (blocks, -c) unlimited
data seg size (kbytes, -d) unlimited
scheduling priority (-e) 0
file size (blocks, -f) unlimited
pending signals (-i) 1029415
max locked memory (kbytes, -l) 64
max memory size (kbytes, -m) unlimited
open files (-n) 1048576
pipe size (512 bytes, -p) 8
POSIX message queues (bytes, -q) 819200
real-time priority (-r) 0
stack size (kbytes, -s) 8192
cpu time (seconds, -t) unlimited
max user processes (-u) unlimited
virtual memory (kbytes, -v) unlimited
file locks (-x) unlimited

```

from elaticsearch point of view it's also doesn't look as expected:

```auto
"wOMZvpx7QkW1IoDB9-hv5A" : {
      "timestamp" : 1647361899514,
      "name" : "es_coordination_1",
      "transport_address" : "10.0.9.187:9300",
      "host" : "10.0.9.187",
      "ip" : "10.0.9.187:9300",
      "roles" : [
        "data",
        "data_cold",
        "data_content",
        "data_frozen",
        "data_hot",
        "data_warm",
        "ingest",
        "master",
        "remote_cluster_client",
        "transform"
      ],
      "attributes" : {
        "xpack.installed" : "true",
        "transform.node" : "true"
      },
      "process" : {
        "timestamp" : 1647361899516,
        "open_file_descriptors" : 1771,
        "max_file_descriptors" : 1048576,

```

on the system I've also:  
config in /etc/security/limits.conf

```auto
elasticsearch soft nofile 65535
elasticsearch hard nofile 65535
elasticsearch soft memlock unlimited
elasticsearch hard memlock unlimited

```

Have You ever met such kind of case?

---

<div class="post-metadata">

**Author:** ![INS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ins/32/92827_2.png) [@INS](https://discuss.elastic.co/u/INS)\
**Post date:** [March 15, 2022, 5:49pm UTC](https://discuss.elastic.co/t/nofile-limit-for-open-file-under-docker-container-for-elasticsearch-user/299764/2 "2022-03-15T17:49:42Z")

</div>

doesn't swarm support `ulimits:` ??? yet

> <https://stackoverflow.com/questions/55500300/elastic-in-docker-stack-swarm>

---

<div class="post-metadata">

**Author:** ![INS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ins/32/92827_2.png) [@INS](https://discuss.elastic.co/u/INS)\
**Post date:** [March 15, 2022, 6:51pm UTC](https://discuss.elastic.co/t/nofile-limit-for-open-file-under-docker-container-for-elasticsearch-user/299764/3 "2022-03-15T18:51:46Z")

</div>

Already found the solution

> <https://github.com/docker/cli/pull/2712>
>
> carries https://github.com/docker/cli/pull/2660
> closes https://github.com/docke…r/cli/pull/2660
> 
> \*\*- What I did\*\*
> 
> 1. ~Bump docker/docker to my own fork to have API changes regarding ulimits support on service endpoints ;~
> 2. Add \`--ulimit\` to \`docker service create\` ;
> 3. Add \`--ulimit-add\` and \`--ulimit-rm\` options to \`docker service update\` ;
> 4. Add \`Ulimits\` to \`docker service inspect --pretty\` ;
> 5. Support ulimits in docker-compose files, to make them work with \`docker stack deploy\` ;
> 
> This is related to moby/moby#40639.
> 
> \*\*- How I did it\*\*
> 
> \*\*- How to verify it\*\*
> 
> Given the following \`docker-compose.yaml\`:
> 
> \`\`\`yaml
> version: "3"
> 
> services:
> test:
> image: debian
> command: /bin/bash -c "ulimit -a && sleep 15"
> ulimits:
> nofile: 100
> deploy:
> mode: replicated
> \`\`\`
> 
> \<details\>
> \<summary\>\<code\>docker service create\</code\>\</summary\>
> 
> \`\`\`
> $ docker service create --name t2 --ulimit=nofile=100 debian /bin/bash -c "ulimit -a && sleep 30"
> $ docker service logs -f t2
> ...
> t2.1.dkm9duj5i4rq@aker | open files (-n) 100
> t2.1.dkm9duj5i4rq@aker | real-time priority (-r) 0
> ...
> \`\`\`
> \</details\>
> 
> \<details\>
> \<summary\>\<code\>docker service update\</code\>\</summary\>
> 
> \`\`\`
> $ docker service update --ulimit-rm nofile --ulimit-add rtprio=1 t2
> $ docker service logs -f t2
> ...
> t2.1.dkm9duj5i4rq@aker | open files (-n) 1048576
> t2.1.dkm9duj5i4rq@aker | real-time priority (-r) 1
> ...
> \`\`\`
> \</details\>
> 
> \<details\>
> \<summary\>\<code\>docker service inspect\</code\>\</summary\>
> 
> \`\`\`
> $ docker service update --ulimit-add nofile=100:200 t2
> $ docker service inspect --pretty t2
> ...
> Ulimits:
> nofile: 100:200
> nproc: -1:-1
> ...
> 
> $ docker service inspect t2
> ...
> "Ulimits": \[
> {
> "Name": "nproc",
> "Hard": -1,
> "Soft": -1
> },
> {
> "Name": "nofile",
> "Hard": 200,
> "Soft": 100
> }
> \]
> ...
> \`\`\`
> \</details\>
> 
> \<details\>
> \<summary\>\<code\>docker stack deploy\</code\>\</summary\>
> 
> \`\`\`
> $ cat docker-compose.yaml
> version: "3"
> 
> services:
> test:
> image: debian
> command: /bin/bash -c "ulimit -a && sleep 15"
> ulimits:
> nofile: 100
> deploy:
> mode: replicated
> 
> $ docker stack deploy --compose-file docker-compose.yaml test
> $ docker service logs -f test\_test | grep "open files"
> test\_test.1.jezlw4wt08rz@aker | open files (-n) 100
> $ docker inspect $(docker ps --filter=name=test\_test -q)
> ...
> "Ulimits": \[
> {
> "Name": "nofile",
> "Hard": 100,
> "Soft": 100
> }
> \],
> ...
> \`\`\`
> \</details\>
> 
> \*\*- Description for the changelog\*\*
> 
> Add \`ulimits\` support to \`docker service create|update|inspect\` and \`docker stack deploy\`
> 
> \*\*- A picture of a cute animal (not mandatory but encouraged)\*\*

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2022, 6:51pm UTC](https://discuss.elastic.co/t/nofile-limit-for-open-file-under-docker-container-for-elasticsearch-user/299764/4 "2022-04-12T18:51:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
