Skip to content

feat(cloud-agent-next): cap control-plane Kilo memory with cgroups - #6650

Merged
eshurakov merged 3 commits into
mainfrom
eshurakov/control-plane-workload-cgroups
Sep 23, 2026
Merged

eshurakov merged 3 commits into
mainfrom
eshurakov/control-plane-workload-cgroups

Conversation

@eshurakov

Copy link
Copy Markdown
Contributor

Summary

  • The control-plane wrapper now puts kilo serve and the commands it starts under a cgroup memory cap, the same way the legacy wrapper turns the memory controller on.
  • If the container cannot enforce that cap, Kilo still starts. The wrapper does not claim the limit is on.
  • When the container has no finite cgroup memory size, the cap uses the same memory total the legacy path uses. CONTROL_WORKLOAD_CGROUP=0 can be passed from the worker into the container to turn the cap off. It is not set in wrangler, so the default stays on.

A real Cloudflare container was not run.

Test plan

  • Wrapper unit tests: pnpm --filter @kilocode/cloud-agent-wrapper exec bun test src/control/workload-cgroup.test.ts src/control/owned-processes.test.ts
  • Launch-env test: pnpm --filter cloud-agent-next exec vitest run src/sandbox-control/wrapper-launch-env.test.ts
  • On a Cloudflare control-plane container, confirm a heavy Kilo command can OOM without stopping the wrapper, or that Kilo still starts if the cap cannot be applied
  • Confirm CONTROL_WORKLOAD_CGROUP=0 on the worker reaches the container and starts Kilo without the cap

Turn the memory controller on in the control wrapper, the same way the legacy path does. If the container cannot enforce the cap, start Kilo without claiming protection.
@eshurakov
eshurakov force-pushed the eshurakov/control-plane-workload-cgroups branch from 63bd07d to 69dec21 Compare September 23, 2026 13:57
Comment thread services/cloud-agent-next/wrapper/src/control/owned-processes.ts
Comment thread services/cloud-agent-next/wrapper/src/control/workload-cgroup.ts
@kilo-code-bot

kilo-code-bot Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Summary

Status: No Issues Found | Recommendation: Merge

Executive Summary

Incremental change only deletes the now-obsolete cgroup implementation plan doc; no runtime or test code changed and no new issues found.

Files Reviewed (1 file)
  • docs/plans/cloud-agent-control-plane-cgroups.md (deleted)
Previous Review Summaries (2 snapshots, latest commit bd9a1a3)

Current summary above is authoritative. Previous snapshots are kept for context only.

Previous review (commit bd9a1a3)

Status: No Issues Found | Recommendation: Merge

Files Reviewed (4 files)
  • services/cloud-agent-next/wrapper/src/control/owned-processes.ts
  • services/cloud-agent-next/wrapper/src/control/owned-processes.test.ts
  • services/cloud-agent-next/wrapper/src/control/workload-cgroup.ts
  • services/cloud-agent-next/wrapper/src/control/workload-cgroup.test.ts

Previous review (commit 69dec21)

Status: 2 Issues Found | Recommendation: Address before merge

Overview

Severity Count
CRITICAL 0
WARNING 0
SUGGESTION 2
Issue Details (click to expand)

SUGGESTION

File Line Issue
services/cloud-agent-next/wrapper/src/control/owned-processes.ts 662 serverPids is computed but never migrated; a server-chain process born under the tools cgroup stays under memory.oom.group=1
services/cloud-agent-next/wrapper/src/control/workload-cgroup.ts 129 Dedupe key omits toolCount/serverCount/migratedCount/cpuController, suppressing changed stats diagnostics
Files Reviewed (11 files)
  • services/cloud-agent-next/wrapper/src/control/owned-processes.ts - 1 issue
  • services/cloud-agent-next/wrapper/src/control/workload-cgroup.ts - 1 issue
  • services/cloud-agent-next/wrapper/src/control/workload-cgroup.test.ts - 0 issues
  • services/cloud-agent-next/wrapper/src/control/owned-processes.test.ts - 0 issues
  • services/cloud-agent-next/wrapper/src/control/main.ts - 0 issues
  • services/cloud-agent-next/wrapper/src/control/worktree-runtime.ts - 0 issues
  • services/cloud-agent-next/src/persistence/SandboxControl.ts - 0 issues
  • services/cloud-agent-next/src/sandbox-control/wrapper-launch-env.ts - 0 issues
  • services/cloud-agent-next/src/sandbox-control/wrapper-launch-env.test.ts - 0 issues
  • services/cloud-agent-next/src/shared/control-diagnostics.ts - 0 issues
  • docs/plans/cloud-agent-control-plane-cgroups.md - 0 issues

Fix these issues in Kilo Cloud


Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0

Review guidance: REVIEW.md from base branch main

A Kilo server born under the tool group was left there, so a tool OOM could kill it. Stats diagnostics also hid a changed tool or server count.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants