﻿# Prepare Linux OS for operation in a high-load cluster

> [HTML Version](preparing-optimized-kernel.html)

To ensure maximum performance and stability of the Kubernetes system, optimize the operating system on which it is running. In this article, we will explore the installation of an optimized kernel using Ubuntu 20.04 as an example.

The optimized Ubuntu kernel is a specially adapted Linux kernel. It includes a set of changes and optimizations aimed at improving the efficiency of resource utilization and enhancing the processing of network requests.

Configuring the optimized Ubuntu kernel for Kubernetes involves two stages:

1. [Install the optimized kernel](#install-optimized-kernel)

2. [Optimize network parameters](#optimization-network-params)

## Step 1. Install the optimized kernel

1. ## nstall the optimized Ubuntu kernel:

````
sudo apt-get install linux-lowlatency-hwe-20.04 -y

2. ````
After successful installation, reboot the system:

````
sudo reboot

## ````
Step 2. Optimize network parameters

1. ## Create a tuned-sysctl.sh file and insert the following script:

````
\#\!/bin/bash  
  
CONNTRACK\_MAX\_PER\_CORE=131072  
CONNTRACK\_MIN=524288  
  
CPU\_NUM=\`cat /proc/cpuinfo | grep -E '^processor\\s+:\\s+\[0-9\]+\$' | wc -l\`  
CONNTRACK\_BY\_CPU=\$(( \$CPU\_NUM \* \$CONNTRACK\_MAX\_PER\_CORE ))  
NF\_CONNTRACK\_MAX=\$(( \$CONNTRACK\_BY\_CPU > \$CONNTRACK\_MIN ? \$CONNTRACK\_BY\_CPU : \$CONNTRACK\_MIN ))  
MEM\_NUM=\`awk '/^MemTotal:/\{print \$2\}' /proc/meminfo\`  
  
sysctl -w net.netfilter.nf\_conntrack\_max=\$NF\_CONNTRACK\_MAX # set the maximum conntrack value  
sysctl -w net.nf\_conntrack\_max=\$NF\_CONNTRACK\_MAX  
echo \$(( \$NF\_CONNTRACK\_MAX / 4 )) > /sys/module/nf\_conntrack/parameters/hashsize # set proportional size hash table for conntrack search  
  
\# General optimization  
sysctl -w vm.swappiness=0  
sysctl -w net.core.somaxconn=1000  
sysctl -w net.core.netdev\_max\_backlog=5000  
sysctl -w net.core.rmem\_max=\$MEM\_NUM  
sysctl -w net.core.wmem\_max=\$MEM\_NUM  
sysctl -w net.ipv4.tcp\_wmem="4096 87380 \$MEM\_NUM"  
sysctl -w net.ipv4.tcp\_rmem="4096 87380 \$MEM\_NUM"  
sysctl -w net.ipv4.tcp\_max\_syn\_backlog=8096  
sysctl -w net.ipv4.tcp\_no\_metrics\_save=1  
sysctl -w net.ipv4.tcp\_slow\_start\_after\_idle=0  
sysctl -w net.ipv4.tcp\_tw\_reuse=1  
sysctl -w net.ipv4.ip\_local\_port\_range="10500 65535"  
sysctl -w net.ipv4.neigh.default.gc\_thresh1=16384  
sysctl -w net.ipv4.neigh.default.gc\_thresh2=28672  
sysctl -w net.ipv4.neigh.default.gc\_thresh3=32768  
sysctl -w net.bridge.bridge-nf-call-iptables=1 # kube-proxy requires this parameter  
sysctl -w net.bridge.bridge-nf-call-arptables=1 # kube-proxy requires this parameter  
sysctl -w net.bridge.bridge-nf-call-ip6tables=1 # kube-proxy requires this parameter  
sysctl -w vm.dirty\_ratio=80  
sysctl -w vm.dirty\_background\_ratio=5  
sysctl -w vm.dirty\_expire\_centisecs=12000  
sysctl -w fs.file-max=1000000  
sysctl -w vm.min\_free\_kbytes=131072  
sysctl -w kernel.numa\_balancing=0  
sysctl -w fs.inotify.max\_user\_watches=524288  
sysctl -w fs.inotify.max\_user\_instances=5120  
sysctl -w kernel.pid\_max=2000000  
  
\# kubelet parameters  
sysctl -w vm.overcommit\_memory=1  
sysctl -w kernel.panic=10  
sysctl -w kernel.panic\_on\_oops=1  
  
\# The nofile parameter sets the maximum number of opened files  
echo -e "\* hard nofile 4194304\\n\* soft nofile 4194304" >> /etc/security/limits.conf

2. ````
Grant permissions to run the created file:

````
sudo chmod +x tuned-sysctl.sh

3. ````
Run the file:

````
sudo ./tuned-sysctl.sh

4. ````
Open the crontab file for editing:

````
sudo crontab -e

5. ````
Add a command to execute the script after reboot:

````
@reboot sleep 180 \&\& /path/to/tuned-sysctl.sh
````