Compare commits

...

6 Commits

Author SHA1 Message Date
oysteikt b350554bf3 bicep/mysql: enable hugepages
Eval nix flake / evals (push) Successful in 7m27s
Eval nix flake / evals (pull_request) Successful in 8m43s
2026-07-21 19:42:15 +09:00
oysteikt f41e6c0a74 bicep/postgresql: enable hugepages 2026-07-21 19:38:30 +09:00
oysteikt 8bb86ef634 modules/hugepages: init 2026-07-21 18:18:06 +09:00
oysteikt 9a837d210d bicep/postgres: log connections/disconnections
Build topology graph / evals (push) Successful in 3m23s
Eval nix flake / evals (push) Successful in 8m59s
2026-07-21 16:39:25 +09:00
oysteikt d3c9fabbc2 base/irqbalance: only start on multi-socket machines 2026-07-21 16:38:38 +09:00
oysteikt 950b163869 bicep/postgresql: use scram-sha-256 as default password algorithm 2026-07-21 16:32:49 +09:00
5 changed files with 87 additions and 3 deletions
+20 -2
View File
@@ -1,4 +1,22 @@
{ ... }:
{ config, pkgs, lib, ... }:
let
cfg = config.services.irqbalance;
in
{
services.irqbalance.enable = true;
}
# irqbalance only has meaningful work to do on multi-socket machines, so
# skip starting it pointlessly everywhere else.
systemd.services.irqbalance.serviceConfig.ExecCondition = let
isMultiSocket = pkgs.writeShellApplication {
name = "irqbalance-is-multi-socket";
runtimeInputs = [ pkgs.coreutils ];
text = ''
sockets=$(cat /sys/devices/system/cpu/cpu*/topology/physical_package_id | sort -u | wc -l)
[ "$sockets" -gt 1 ]
'';
};
in lib.mkIf cfg.enable [
(lib.getExe isMultiSocket)
];
}
+2
View File
@@ -197,6 +197,7 @@
inputs.pvv-calendar-bot.nixosModules.default
inputs.minecraft-heatmap.nixosModules.default
self.nixosModules.gickup
self.nixosModules.hugepages
self.nixosModules.matrix-ooye
];
overlays = [
@@ -309,6 +310,7 @@
bluemap = ./modules/bluemap.nix;
drumknotty = ./modules/drumknotty;
gickup = ./modules/gickup;
hugepages = ./modules/hugepages.nix;
matrix-ooye = ./modules/matrix-ooye.nix;
python-http-handlers = ./modules/python-http-handlers.nix;
robots-txt = ./modules/robots-txt.nix;
+10
View File
@@ -2,6 +2,8 @@
let
cfg = config.services.mysql;
dataDir = "/data/mysql";
innodbBufferPoolMB = 128;
in
{
imports = [ ./backup.nix ];
@@ -26,6 +28,10 @@ in
# Useful for the mysqld prometheus exporter
userstat = 1;
# Memory settings
innodb_buffer_pool_size = "${toString innodbBufferPoolMB}M";
"large-pages" = 1;
# This was needed in order to be able to use all of the old users
# during migration from knakelibrak to bicep in Sep. 2023
secure_auth = 0;
@@ -47,6 +53,10 @@ in
}];
};
boot.kernel.hugepages.reservations.mysql = lib.mkIf cfg.enable (
builtins.ceil (innodbBufferPoolMB / config.boot.kernel.hugepages.size)
);
networking.firewall.allowedTCPPorts = lib.mkIf cfg.enable [ 3306 ];
systemd.tmpfiles.settings."10-mysql".${dataDir}.d = lib.mkIf cfg.enable {
+17 -1
View File
@@ -1,6 +1,8 @@
{ config, lib, pkgs, values, ... }:
let
cfg = config.services.postgresql;
sharedBuffersMB = 8192;
in
{
imports = [
@@ -14,6 +16,7 @@ in
extensions = ps: with ps; [ pg_repack ];
enableTCPIP = true;
# NOTE: md5 accepts both md5 and scram-sha-256
authentication = ''
host all all ${values.ipv4-space} md5
host all all ${values.ipv6-space} md5
@@ -28,7 +31,7 @@ in
superuser_reserved_connections = 3;
# Memory Settings
shared_buffers = "8192 MB";
shared_buffers = "${toString sharedBuffersMB} MB";
work_mem = "32 MB";
maintenance_work_mem = "420 MB";
effective_cache_size = "22 GB";
@@ -76,6 +79,15 @@ in
maintenance_io_concurrency = 100;
wal_recycle = true;
# -------------------------------- #
# Authentication
password_encryption = "scram-sha-256";
# Logging
log_connections = "authorization";
log_disconnections = true;
# SSL
ssl = true;
ssl_cert_file = "/run/credentials/postgresql.service/cert";
@@ -83,6 +95,10 @@ in
};
};
boot.kernel.hugepages.reservations.postgresql = lib.mkIf cfg.enable (
builtins.ceil (sharedBuffersMB / config.boot.kernel.hugepages.size)
);
systemd.tmpfiles.settings."10-postgresql"."/data/postgresql".d = lib.mkIf cfg.enable {
user = config.systemd.services.postgresql.serviceConfig.User;
group = config.systemd.services.postgresql.serviceConfig.Group;
+38
View File
@@ -0,0 +1,38 @@
{ config, lib, ... }:
let
cfg = config.boot.kernel.hugepages;
in
{
options.boot.kernel.hugepages = {
size = lib.mkOption {
type = lib.types.enum [ 2 1024 ];
default = 2;
description = ''
Hugepage size in MB.
You can use this value to calculate the amount of memory you will have available as hugepages.
'';
};
reservations = lib.mkOption {
type = lib.types.attrsOf lib.types.ints.unsigned;
default = { };
description = ''
Number of hugepages each service wants reserved in vm.nr_hugepages,
keyed by service name.
'';
};
};
config = {
boot.kernelParams = let
num = {
"2" = "2M";
"1024" = "1G";
}.${toString cfg.size};
in [ "hugepagesz=${num}" ];
boot.kernel.sysctl."vm.nr_hugepages" =
lib.foldl' (a: b: a + b) 0 (lib.attrValues cfg.reservations);
};
}