diff --git a/docs/cloudlinuxos/cloudlinux_installation/README.md b/docs/cloudlinuxos/cloudlinux_installation/README.md index f9491a6a3..1feef794c 100644 --- a/docs/cloudlinuxos/cloudlinux_installation/README.md +++ b/docs/cloudlinuxos/cloudlinux_installation/README.md @@ -393,7 +393,7 @@ This is an exception path for an unsafe or unknown state. For an eligible server #### Server panics or reboots during conversion on Intel CPUs with IBT -When converting **AlmaLinux 10 to CloudLinux 10** on a server that Intel CPU supports **IBT** (Indirect Branch Tracking), the server may panic and reboot during the LVE setup step of `cldeploy`, leaving a half-converted system that may not boot back up. +During **AlmaLinux 10 to CloudLinux 10** conversion, loading the LVE module while the running kernel enforces **IBT** (Indirect Branch Tracking) can cause a kernel panic and leave the server partially converted. An Intel CPU's IBT flag alone does not mean that the running kernel enforces IBT. The kernel message (visible on the console, in `/var/log/messages`, or in a kdump vmcore) looks like: @@ -403,29 +403,26 @@ kernel BUG at arch/x86/kernel/cet.c:102! ... mount_cgroup_root_fs+0x209/0x260 [kmodlve] ``` -**Cause.** The CloudLinux LVE kernel module (`kmod-lve`) requires Intel CET/IBT to be disabled. -The CloudLinux `tuned` profile turns it off via the `ibt=off` kernel boot parameter, but that takes effect only after a reboot. -If the module is loaded while IBT is still active - before that reboot - the CPU raises a control-protection fault and the -kernel panics. +**Cause.** The LVE kernel module (`kmodlve`) cannot be loaded safely while the running kernel enforces Intel IBT. The `ibt=off` kernel boot parameter takes effect only after a reboot; loading the module before that can raise a control-protection fault and panic the kernel. -**Recovery for an affected server.** Boot once with IBT disabled: +**Recovery for an affected server.** Add `ibt=off` at the GRUB menu for a single boot: 1. At the GRUB boot menu, highlight the default entry and press `e` to edit it. 2. Find the line that starts with `linux` (the kernel command line) and append ` ibt=off` to its end. 3. Press `Ctrl+X` (or `F10`) to boot with that parameter. -Once the server is back up, verify that the conversion left the CloudLinux `tuned` profile active - it sets `ibt=off` permanently, so the parameter is applied automatically on every subsequent boot: +The GRUB edit above affects one boot only. After a normal reboot, check the active `tuned` profile and whether `ibt=off` is present as a separate argument on the running kernel's command line: ```bash -tuned-adm active # expect a "cloudlinux-*" profile -grep -o 'ibt=off' /proc/cmdline # after a normal reboot, expect: ibt=off +tuned-adm active # check for a "cloudlinux-*" profile +grep -qE '(^| )ibt=off( |$)' /proc/cmdline && echo 'ibt=off is on the kernel command line' ``` -If the conversion did not finish, or `ibt=off` is not applied on a normal boot, attach +If the conversion did not finish, or `ibt=off` is absent from the kernel command line after a normal reboot, attach `/var/log/cldeploy.log` and contact [CloudLinux support](https://cloudlinux.zendesk.com/hc/en-us). :::tip Note -Up-to-date versions of `cldeploy` and the CloudLinux LVE packages avoid this by not loading the LVE module until after the post-conversion reboot, when `ibt=off` is already in effect. +When the LVE service detects kernel IBT enforcement and `ibt=off` is absent, it reports a deferred module load and exits successfully. A successful `lve.service` start does not by itself mean `kmodlve` is loaded. After reboot, check with `lsmod | grep '^kmodlve '`; if the module is absent, review the LVE service logs and contact support instead of manually loading it while IBT is enforced. ::: ### How to enable Secure Boot for CloudLinux 9+ diff --git a/docs/cloudlinuxos/command-line_tools/README.md b/docs/cloudlinuxos/command-line_tools/README.md index 5750117fa..5fe0d7ef5 100644 --- a/docs/cloudlinuxos/command-line_tools/README.md +++ b/docs/cloudlinuxos/command-line_tools/README.md @@ -2904,7 +2904,7 @@ cldeploy --hostinglimits # update httpd and install m **Per-domain commands** -These manage [CloudLinux Isolates](/cloudlinuxos/isolates/#lve-per-domain) — resource limits for an individual website rather than for the whole account. They require a kernel with per-domain LVE support; on a kernel without it every one of them exits with code `38` and the message `Domain limits are not supported by this kernel`. +These manage [CloudLinux Isolates](/cloudlinuxos/isolates/#lve-per-domain) — resource limits for an individual website rather than for the whole account. They require a compatible LVE library and running kernel. On an initialized LVE system without the per-domain interface, `list-domains`, `allow-domain-limits`, `deny-domain-limits`, `enable-domain-limits` and `disable-domain-limits` exit with code `38` and report `Domain limits are not supported by this kernel (requires lve_lvp_create2)`. `regenerate-domains` can return without updating anything when that interface is unavailable; its exit status does not verify that a domain LVE exists. | | | |--|--| @@ -2916,7 +2916,7 @@ These manage [CloudLinux Isolates](/cloudlinuxos/isolates/#lve-per-domain) — r | `regenerate-domains --username [--domain ] [--old-domain ] [--old-docroot ]` |update the domain configuration and id mapping after a domain rename, a document root change, or a user rename. `--username` is required| :::tip Note -Under a control panel you normally do not call these directly — `cagefsctl --site-isolation-allow`, `--site-isolation-deny`, `--site-isolation-enable` and `--site-isolation-disable` invoke the matching `lvectl` command for you, and the panel hooks call `regenerate-domains` on rename and document-root changes. Use `lvectl` directly for integration scripts and for inspecting or repairing state. See [CloudLinux Isolates](/cloudlinuxos/isolates/#lve-per-domain). +Under a supported control panel you normally do not call these directly — `cagefsctl --site-isolation-allow`, `--site-isolation-deny`, `--site-isolation-enable` and `--site-isolation-disable` manage filesystem isolation and conditionally call the matching `lvectl` command when the panel and running kernel permit it; automatic enablement also requires a statistics backend with per-domain support. Panel hooks call `regenerate-domains` on rename and document-root changes when applicable. Use `lvectl` directly for integration scripts and for inspecting or repairing state where the kernel supports per-domain LVPs; verify the statistics prerequisite before enabling domain limits. See [CloudLinux Isolates](/cloudlinuxos/isolates/#lve-per-domain). ::: **Options** diff --git a/docs/cloudlinuxos/isolates/README.md b/docs/cloudlinuxos/isolates/README.md index 5ffae2979..17613a05c 100644 --- a/docs/cloudlinuxos/isolates/README.md +++ b/docs/cloudlinuxos/isolates/README.md @@ -1,6 +1,6 @@ -# CloudLinux Isolates (BETA) +# CloudLinux Isolates -CloudLinux Isolates isolates the individual websites of a single hosting account from one another. It has two layers, which are described in turn below: +CloudLinux Isolates can isolate websites within one hosting account when its [CageFS prerequisites](#prerequisites) are met. Per-domain LVE resource limits have [additional prerequisites](#per-domain-prerequisites). The two layers are described in turn below: * **[CageFS per domain](#cagefs-per-domain)** — *filesystem* isolation, so that a compromised website cannot reach another site's files. * **[LVE per domain](#lve-per-domain)** — *resource* isolation, so that one website's CPU, memory and I/O usage is limited and accounted for on its own. @@ -877,8 +877,8 @@ CloudLinux Isolates integrates automatically with supported control panels. When CloudLinux Isolates also allows resource limits — CPU, memory, I/O, processes and entry processes — to be applied to an *individual website* rather than to the hosting account as a whole. A single busy or misbehaving site is then throttled on its own, without consuming the resources its sibling sites on the same account depend on. -:::warning BETA -Per-domain LVE limits are a BETA feature, supported on CloudLinux OS 8 and 9. +:::warning +Per-domain LVE limits have [additional prerequisites](#per-domain-prerequisites) on CloudLinux OS 8 and 9, including a compatible running kernel, an LVE-capable panel and a statistics backend that supports per-domain reporting. Enabling filesystem isolation alone does not establish per-domain resource limits. ::: ### How it relates to CageFS per domain @@ -887,14 +887,14 @@ The two halves of CloudLinux Isolates are separate layers and can be reasoned ab | | | |-|-| -|[CageFS per domain](#cagefs-per-domain) | *Filesystem* isolation — a compromised website cannot read another site's files. Always available where CageFS is.| -|LVE per domain | *Resource* isolation — a website has its own CPU, memory, I/O and process limits. Requires CloudLinux OS 8 or 9 and the package versions listed under [Per-Domain Prerequisites](#per-domain-prerequisites).| +|[CageFS per domain](#cagefs-per-domain) | *Filesystem* isolation — a compromised website cannot read another site's files when the [CageFS prerequisites](#prerequisites), including a compatible web server, PHP handler and panel, are met.| +|LVE per domain | *Resource* isolation — a website can have its own CPU, memory, I/O and process limits where the [per-domain prerequisites](#per-domain-prerequisites) are met. These instructions cover CloudLinux OS 8 and 9; confirm the kernel and panel capabilities before relying on this layer.| -In practice you do not enable them separately. The `cagefsctl --site-isolation-*` commands documented above drive both: each one invokes the matching `lvectl` per-domain command for you when the prerequisites are met, and silently skips that step when they are not. So on a server that does not support per-domain LVEs, website isolation still works — you get the filesystem separation without the resource limits, rather than an error. +The `cagefsctl --site-isolation-*` management commands handle the CageFS layer. On a panel that supports LVE, allow/enable operations also call `lvectl` when the running kernel supports per-domain limits and the statistics backend has the required capability. If these conditions are not met, a successful filesystem-isolation command does not establish that a domain LVE was created. Deny/disable operations attempt LVE cleanup when the panel and kernel permit it; check for remaining domain LVEs rather than assuming cleanup succeeded. ### Per-Domain Prerequisites -Per-domain LVE limits are supported on CloudLinux OS 8 and 9. CloudLinux OS 7 predates the required kernel interface; on it, commands that need per-domain support fail with exit code `38` and the message `Domain limits are not supported by this kernel`. +For per-domain LVE limits on CloudLinux OS 8 or 9, a running kernel with per-domain LVP support is required. On CloudLinux OS 7, the CageFS filesystem layer is separate and remains subject to its own [prerequisites](#prerequisites); do not assume per-domain LVE support. On an initialized LVE system lacking the per-domain interface, the `lvectl` commands that require it report `Domain limits are not supported by this kernel (requires lve_lvp_create2)` with exit code `38`; see [lvectl](/cloudlinuxos/command-line_tools/#lvectl). In addition to the [CloudLinux Isolates prerequisites](#prerequisites), per-domain LVE limits require: @@ -935,9 +935,9 @@ Because the websites are siblings of the account's own container rather than nes ### Enabling per-domain limits -Under a control panel, use the [`cagefsctl --site-isolation-*` commands](#command-reference) — they enable both isolation layers together and are the supported administrator path. +Under a supported control panel, use the [`cagefsctl --site-isolation-*` commands](#command-reference) as the administrator path for filesystem isolation. They attempt to manage per-domain LVEs only when the [additional prerequisites](#per-domain-prerequisites) and the panel's LVE capability are present; verify that the domain LVE exists before setting its limits. -The underlying `lvectl` commands are available for integration scripts, and for inspecting or repairing state: +The underlying `lvectl` commands are available for integration scripts and for inspecting or repairing state when the running kernel supports per-domain LVPs. Before using them to enable domain limits, also check the statistics prerequisite: | | | |-|-| @@ -951,7 +951,7 @@ The underlying `lvectl` commands are available See [lvectl](/cloudlinuxos/command-line_tools/#lvectl) for the full syntax. :::tip Note -`lvectl list-domains` lists the members of an account's LVP. For a *reseller*, that LVP holds the reseller's member accounts rather than domains, so the command's output alone does not tell you whether an account is isolated. A member account resolves in `/etc/passwd`; a domain LVE id never does. +`lvectl list-domains` lists the members of an account's LVP. For a *reseller*, that LVP holds the reseller's member accounts rather than domains, so the command's output alone does not tell you whether an account is isolated. Do not use a `/etc/passwd` lookup alone to decide whether a numeric ID represents an account or a domain. If an ID appears to identify both, stop and contact support before changing its limits. ::: The domain renaming, document root changes and account renames performed through a supported control panel are handled by the panel hooks, which call `lvectl regenerate-domains` automatically. Run it by hand only after changing these outside the panel. @@ -1007,7 +1007,7 @@ account = the account's own work + site1.com + site2.com + ... ### Fault notifications -When a website hits one of its own limits, the notification sent to the account owner names the website that faulted, alongside the limit it hit. Notifications continue to be addressed per account, and the thresholds and period that govern the account-level notification govern the per-domain section too — so enabling per-domain limits does not, by itself, change who is emailed or how often. +When fault notifications to account owners are enabled and a website hits one of its own limits, the notification names the website that faulted, alongside the limit it hit. Notifications continue to be addressed per account and follow the configured thresholds and period; enabling per-domain limits does not itself enable notifications or change who receives them. Administrators customising the email templates should see the `domain_faults` variable in [Customize LVE-stats2 notifications](/cloudlinuxos/cloudlinux_os_components/#customize-lve-stats2-notifications). @@ -1015,17 +1015,17 @@ Administrators customising the email templates should see the `cagefsctl --site-isolation-*` commands always apply the filesystem layer, and add the per-domain LVE only when the [prerequisites](#per-domain-prerequisites) are met. Check the installed versions: +`cagefsctl --site-isolation-enable` can configure filesystem isolation without creating a domain LVE. Automatic LVE enablement also requires an LVE-capable panel, a compatible running kernel and [per-domain prerequisites](#per-domain-prerequisites). Check the installed packages: ``` rpm -q lve-stats3 lve-utils ``` -If either is below the minimum, update it and then re-run `cagefsctl --site-isolation-enable `. Removing isolation is never gated this way, so any containers created by an earlier version can always be torn down. +If either package is below the required minimum and a compatible update is available for your OS and panel, update it and re-run `cagefsctl --site-isolation-enable `. Disabling filesystem isolation does not guarantee cleanup of an existing domain LVE if the panel or running kernel lacks the required capability. If a domain LVE remains, stop and contact support rather than assuming it was removed. **"No domain limits configured for UID *N*"** diff --git a/docs/cloudlinuxos/limits/README.md b/docs/cloudlinuxos/limits/README.md index d15a0496b..9faaf4c20 100644 --- a/docs/cloudlinuxos/limits/README.md +++ b/docs/cloudlinuxos/limits/README.md @@ -89,31 +89,24 @@ Each LVE limits amount of entry processes (Apache processes entering into LVE) t ### Checking if LVE is installed -To use LVE you should have CloudLinux OS kernel installed, and LVE module loaded. You can check the kernel by running the following command: +To use LVE, the `kmodlve` kernel module must be loaded. The name shown by `uname -r` does not verify whether the LVE module is loaded; check the module directly. On RPM-based systems, check the installed packages and the loaded module:
``` -uname -r +rpm -q lve +rpm -q --whatprovides kmod-lve +lsmod | grep '^kmodlve ' ```
-You should see something like 2.6.32-896.16.1.lve1.4.53.el6.x86_64. The kernel should have lve in its name. To see if lve kernel module is loaded run: - -
- -``` -lsmod|grep lve - -lve 46496 0 -``` -
+If the module is absent, inspect the `lve.service` logs and check `LVE_ENABLE=yes` in the file the loader uses: `/etc/sysconfig/lve` on RPM-based CloudLinux systems, or `/etc/default/lve` if the first file is absent. A successful service start can also mean that loading was deferred on a kernel that enforces Intel IBT; see [conversion troubleshooting](/cloudlinuxos/cloudlinux_installation/#server-panics-or-reboots-during-conversion-on-intel-cpus-with-ibt). Starting from kernels lve1.4.x iolimits module is a part of kmod-lve and could not be used separately. -* You can toggle LVE on/off by editing `/etc/sysconfig/lve` and setting `LVE_ENABLE` variable to `yes` or `no`. +* On RPM-based CloudLinux systems, you can control whether the LVE service attempts to load the module by setting `LVE_ENABLE` in `/etc/sysconfig/lve` to `yes` or `no`. If that file is absent, the loader checks `/etc/default/lve` instead. - Setting it to `yes` will enable LVE, setting it to `no` will disable LVE. + `yes` permits a load when other prerequisites are met; `no` skips the load at service start. After reboot, check that the module is loaded rather than assuming that the setting makes LVE active. * You can toggle IO limits by editing `/etc/sysconfig/iolimits` and setting `IO_LIMITS_ENABLED` variable to `yes` or `no`.