Story #3826

Updated by Tom Clegg over 5 years ago

cgroups doesn't provide a nice way to monitor network usage, but we can use iptables to set up accounting rules to monitor network usage for the docker virtual network device. Figure out how to do that.

(TC) sysfs provides seems to provide an easy way to get traffic statistics. I tried this in a docker container, after doing a few pings:

# head /sys/devices/virtual/net/*/statistics/*_bytes
==> /sys/devices/virtual/net/eth0/statistics/rx_bytes <==

==> /sys/devices/virtual/net/eth0/statistics/tx_bytes <==

==> /sys/devices/virtual/net/lo/statistics/rx_bytes <==

==> /sys/devices/virtual/net/lo/statistics/tx_bytes <==

This does require that we run crunchstat inside docker, instead of monitoring statistics from outside using cgroups. Fortunately this is easy and greatly simplifies crunchstat (e.g., call runtime.NumCPU() instead of reading and parsing @/sys/fs/cgroup/..../cpuset/cpus@, and read from predictable parts of @/sys@ instead of requiring the caller to specify parts of the cgroup path).

docker run --volume=/usr/bin/crunchstat:/usr/bin/crunchstat ... /usr/bin/crunchstat {command...}