diff --git a/packaging/llmsproxy.service b/packaging/llmsproxy.service index 26a689c..90b846d 100644 --- a/packaging/llmsproxy.service +++ b/packaging/llmsproxy.service @@ -4,16 +4,15 @@ After=network.target [Service] Type=simple -# Memory tuning (measured on this deployment, see README "内存占用"): +# Memory tuning (measured, see README "内存占用"): # MALLOC_ARENA_MAX=2 caps glibc per-thread malloc arenas. LuaJIT allocates # through cgo -> glibc malloc, and glibc defaults to 8*nproc arenas, so every # OS thread that touches malloc reserved its own ~1 MB arena that is never # returned. Measured: 8-12 arenas -> 0. # GOGC=50 halves the Go heap growth target. On its own it does NOT help (the # saved heap is immediately eaten by extra glibc arenas); combined with -# MALLOC_ARENA_MAX it cut settled RSS by ~19% (24.7 MB -> 19.9 MB on a test -# instance). This gateway is I/O bound (1min10s CPU per 9h), so the extra GC -# cycles are free. +# MALLOC_ARENA_MAX it cut settled RSS by ~19%. This gateway is I/O bound, so +# the extra GC cycles are free. Environment=GOGC=50 Environment=MALLOC_ARENA_MAX=2 ExecStart=/usr/local/bin/llmsproxy -config /etc/llmsproxy/config.yaml @@ -32,10 +31,10 @@ RestartSec=5 # 需求的变更,不该和加固混在一起。 # # 下面每一条都在一个独立探针单元(临时端口 + 独立 runtime_file/adapter_dir) -# 上真实验证过:鉴权 401/200 正常、发一次真实 /v1/chat/completions 走通 -# (证明 LuaJIT 适配器路径没被 seccomp 打断)、审计文件可写可轮转、连续重启 3 次 -# 与 kill -9 后行为符合预期。systemd 对非法指令值不报错只"忽略",所以逐条实测 -# 是唯一可靠做法。 +# 上真实验证过:鉴权 401/200 正常、发一次真实 /v1/chat/completions 走通(证明 +# LuaJIT 适配器路径没被 seccomp 打断)、审计文件可写可轮转、连续重启 3 次与 +# kill -9 后行为符合预期。systemd 对非法指令值不报错只"忽略",逐条实测是唯一 +# 可靠做法。 NoNewPrivileges=yes # 读路径全部落在 /etc/llmsproxy;写路径经核对只有 config.yaml / runtime.json / # audit.jsonl / adapters/*.lua / master.key,全在该目录下(internal/{config,gateway,