Once you're satisfied that it's working correctly, could you share your options/settings in this thread? I know I (and probably others) will be coming to this point Real Soon Now and the additional knowledge would be helpful.
Thanks, --Dave -- DAVID A. CURRY, CISSP *DIRECTOR OF INFORMATION SECURITY* INFORMATION TECHNOLOGY 71 FIFTH AVE., 9TH FL., NEW YORK, NY 10003 +1 212 229-5300 x4728 • [email protected] [image: The New School] On Thu, Dec 21, 2017 at 12:42 PM, William E. <[email protected]> wrote: > Thanks Uxio. > > Luckily, since changing to delegating IDP functions to Shibboleth, as it > was on cas 3 setup on this same server, memory seems to be stable. That > and adding the -XX:-UseCompressedOops opt recommended by Unicon > support(many thanks!). Not entirely sure which item gets the kudos, > perhaps both, but I will test a bit more with one or the other over the > holidays to try and determine which was the factor. > > Screenshot of stats. > > Primary server now has 8GB of swap. Added to server while up without > disruption. Linux rocks! > > Thanks, > William > > > > > > On Thursday, December 21, 2017 at 11:10:40 AM UTC-6, Uxío Prego wrote: >> >> Swap is good, generally, but as more dedicated is the server, it should >> make less of a difference, because of your -Xmx configuration. >> >> I don't know about the specific numbers of version 5, but (pending >> knowing how many concurrent sessions do you normally manage) maybe the >> server is having a deployment problem (maybe not). >> >> I think 8G should be enough for your case, but I don't really know. While >> you keep investigating, maybe adding swap and more memory can help you... >> maybe not! >> >> Good luck with it, >> >> Uxío Prego >> >> >> >> Madiva Soluciones >> CL / SERRANO GALVACHE 56 >> <https://maps.google.com/?q=CL+/+SERRANO+GALVACHE+56&entry=gmail&source=g> >> BLOQUE ABEDUL PLANTA 4 >> 28033 MADRID >> +34 917 56 84 94 >> www.madiva.com >> www.bbva.com >> >> The activity of email inboxes can be systematically tracked by >> colleagues, business partners and third parties. Turn off automatic loading >> of images to hamper it. >> >> 2017-12-21 16:45 GMT+00:00 William E. <[email protected]>: >> >>> Martin, >>> >>> Thank you. You might be on to something. I was quoting from memory and >>> I was wrong on swap. Of the two nodes, both in my mind identical VM's, the >>> secondary node has 8GB of swap and a tiny bit used, but the primary, the >>> one that is crashing, has no swap configured. I have requested our systems >>> team add 8GB of swap to the primary. >>> >>> Primary server: >>> >>> total used free shared buff/cache >>> available >>> Mem: 8010840 4872660 420488 107484 2717692 >>> 2679336 >>> Swap: 0 0 0 >>> >>> >>> >>> Secondary server: >>> >>> total used free shared buff/cache >>> available >>> Mem: 8010972 1192296 1530500 23196 5288176 >>> 6449948 >>> Swap: 8388604 4604 8384000 >>> >>> >>> Not sure I understand why it would matter since in theory swap should >>> not be needed on a server with 8GB of ram with jvm limit set to 6GB >>> though. Any more insight on why, because I would really like to understand >>> the reason. >>> >>> >>> Additionally, I've put the shibboleth IDP back into play, effectively >>> rendering the saml services in cas "unused". I am using proxy_ajp to front >>> tomcat with apache so it was easy to copy the idp.war into tomcat and >>> re-enable the shib-cas-authenticator. I guess my hope of moving from >>> cas+shibb. to just cas will have to wait.... >>> >>> >>> Thanks, >>> William >>> >>> P.S. Jeff, thank you for posting your catalina opts! >>> >>> >>> On Wednesday, December 20, 2017 at 11:30:40 PM UTC-6, Martin Bohun wrote: >>>> >>>> I have seen the behavior you are describing when people ran cas >>>> (tomcat, mysql, etc.) on a (what I would consider a misconfigured) Linux >>>> box with 0 swap. >>>> However you are saying you have 4gb of swap. >>>> I still do prefer to set my swap to 2 * $MY_RAM; can you try that? >>>> adjust or add a swapfile to your swap (so you have 8gb RAM / 16gb swap), I >>>> am curious if that would help / solve your problem? >>>> What error messages are you getting in the jvm and syslog/systemd >>>> journal from the OS? >>>> >>>> regards, >>>> >>>> martin >>>> >>>> On Thursday, December 21, 2017 at 1:35:45 PM UTC+11, William E. wrote: >>>>> >>>>> RHEL 7, 8GB ram, swap is 4GB. It's a VM in our vSphere cluster+SAN. >>>>> I actually have three, two PROD nodes behind a load balancer and one test >>>>> node. All have same specs and all show the issue. Steadily chews up >>>>> memory until eventual crash, 1-6 hours depending on load. >>>>> >>>>> The asme servers were running cas 3.6 . + shibboleth 3.3.x for quite a >>>>> while without memory issues. Upgraded and tried to consolidate to just >>>>> cas >>>>> 5, using it's saml2 capabilities to replace the shibboleth component. >>>>> But, >>>>> it's not going as well as I had hoped. >>>>> >>>>> Been working with Unicon Support on it, but it appears to be a memory >>>>> leak in cas 5.2, based on heap analysis. So I am kinda of stuck. >>>>> >>>>> Thanks for your help! >>>>> >>>>> >>>>> >>>>> On Wednesday, December 20, 2017 at 6:49:39 PM UTC-6, Martin Bohun >>>>> wrote: >>>>>> >>>>>> What is your: >>>>>> 1. operation system >>>>>> 2. how much RAM do you have >>>>>> 3. how much swap do you have >>>>>> >>>>>> if you are on Linux you can do: >>>>>> 1. uname -a >>>>>> 2-3. free -m >>>>>> >>>>>> and post the output here >>>>>> >>>>>> regards, >>>>>> >>>>>> martin >>>>>> >>>>>> On Thursday, December 21, 2017 at 11:00:30 AM UTC+11, William E. >>>>>> wrote: >>>>>>> >>>>>>> Does anyone have any recommendations for CATALINA_OPTS for cas 5.x >>>>>>> on tomcat 8? >>>>>>> >>>>>>> I am finding that our setup steadily eats up memory to the point >>>>>>> that it eventually crashes from out of memory and has to be restarted. >>>>>>> >>>>>>> Current settings: >>>>>>> >>>>>>> CATALINA_OPTS="-Djava.awt.headless=true -Dfile.encoding=UTF-8 >>>>>>> -server -Xms1g -Xmx6g -XX:-UseGCOverheadLimit -XX:+UseConcMarkSweepGC >>>>>>> -XX:-UseCompressedOops" >>>>>>> >>>>>>> JAVA_OPTS=$CATALINA_OPTS >>>>>>> >>>>>>> >>>>>>> Thanks, >>>>>>> William >>>>>>> >>>>>>> -- >>> - Website: https://apereo.github.io/cas >>> - Gitter Chatroom: https://gitter.im/apereo/cas >>> - List Guidelines: https://goo.gl/1VRrw7 >>> - Contributions: https://goo.gl/mh7qDG >>> --- >>> You received this message because you are subscribed to the Google >>> Groups "CAS Community" group. >>> To unsubscribe from this group and stop receiving emails from it, send >>> an email to [email protected]. >>> To view this discussion on the web visit https://groups.google.com/a/ap >>> ereo.org/d/msgid/cas-user/7e36f7d2-3bf7-49d2-bcd8-bbc0e22b90 >>> 1b%40apereo.org >>> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/7e36f7d2-3bf7-49d2-bcd8-bbc0e22b901b%40apereo.org?utm_medium=email&utm_source=footer> >>> . >>> >> >> -- > - Website: https://apereo.github.io/cas > - Gitter Chatroom: https://gitter.im/apereo/cas > - List Guidelines: https://goo.gl/1VRrw7 > - Contributions: https://goo.gl/mh7qDG > --- > You received this message because you are subscribed to the Google Groups > "CAS Community" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > To view this discussion on the web visit https://groups.google.com/a/ > apereo.org/d/msgid/cas-user/0a78c6f4-9f32-4456-8adc- > 9f82ff6d7c56%40apereo.org > <https://groups.google.com/a/apereo.org/d/msgid/cas-user/0a78c6f4-9f32-4456-8adc-9f82ff6d7c56%40apereo.org?utm_medium=email&utm_source=footer> > . > -- - Website: https://apereo.github.io/cas - Gitter Chatroom: https://gitter.im/apereo/cas - List Guidelines: https://goo.gl/1VRrw7 - Contributions: https://goo.gl/mh7qDG --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/CA%2Bd9XAO2dS0JZwV-utpNNWi3GkxKvJ2GtBo6WyNUXB0hEwp2rg%40mail.gmail.com.
