Hserver Monitoring: Docker & Containers · advanced
CPU by Container Is Useful Only Beside Limits
A container using one full CPU may be expected on an unrestricted worker and catastrophic for a service capped at a fraction of a core.
A container using one full CPU may be expected on an unrestricted worker and catastrophic for a service capped at a fraction of a core. What made the issue measurable was container CPU usage with declared CPU limits. Absolute usage lacks capacity context; utilization relative to configured quota tells whether the container is near its own ceiling.
I classify this as resource-budget monitoring. The useful debugging sequence is to confirm the signal, compare it with the neighboring subsystem, then look at logs or detailed metrics only after the failure domain is smaller.
The production rule that came out of it is: Inventory CPU limits with runtime usage and flag both saturation and containers that accidentally have no intended production limit. This is deliberately more specific than adding another broad alert with no response procedure.
Commit b65d5d4 is the repository evidence behind the note. It provides the concrete configuration or fix that turned the observation into a repeatable monitoring control.