Concept and mechanism
Available host RAM does not rule out pressure in a cgroup with a restrictive memory.max. Correlate memory.events, usage, and load before changing limits or concluding there is a leak. Raising every limit without assessment can move the incident to the host. In networking, a listener on 127.0.0.1 directly serves only that loopback address; a firewall rule does not change the application bind. Confirm network context and intended exposure before opening the service on more interfaces.
Guided application
On a virtual TLS endpoint, SNI helps select the certificate, while chain and hostname verification establish trust in the expected identity. A successful TCP connection does not replace these checks. To reconstruct an incident, inspect the first-symptom window, nearby changes, and the correct unit’s logs. Restarts can create secondary effects and erase context if retention is inadequate. Hand over a chronology of observations, hypotheses, actions, and results, including what remains uncertain and criteria for the next decision.
A service responds locally on 8080, but ss shows only loopback. Review bind before changing DNS. For TLS, send SNI and also verify hostname and chain.
Common pitfalls
Ignoring cgroup limits; opening a firewall without a listener; confusing SNI with verification; automatically treating the latest event as the cause.
Related topics: System and persistent storage · Name resolution and recovery
A useful incident handover preserves reasoning as well as commands.
Reference: Linux cgroup v2 administration · XK0-006 V8