I have noticed that my home server is strangely using lots of swap (~5 GB), despite having only a few lightweight processes running and loads of RAM installed (32 GB).

Upon configuring Grafana + Prometheus, I noticed a trend where cache + buffer will progressively increase until swap starts to be used. My system and services combined will use ~8 GB RAM. Upon rebooting, the cache + buffer will start anywhere from 3–10 GB, progressively ramp up to ~25 GB in 1–2h, where swap will start to be needed (~3 GB). See the image attached for reference.

My swap filesystem is on an expensive (to me) SSD, and I would like to reduce its wear by as much as possible. I understand that swap can introduce only minimal wear on SSDs depending on its nature and that it can be harmless, but I am still not sure what is causing this behavior (and why) and whether I should worry about it or not. So I figured I should investigate what is happening here.

My main question is, how can I figure out what is causing this behavior? Is it expected? I am looking for guidance from others who are more experienced than me in the topic.

A little bit about my system:

I am running Debian 12 on an NVMe SSD containing the root partition (btrfs) and docker services. I also have two HDDs, one with persistent data (ext4), and the other with backups (ext4). This is majoritarily a single-user machine. I tried using the following kernel parameters, but it hasn’t helped:

vm.swappiness=10
vm.vfs_cache_pressure=200

My docker services are:

  • *arr stack
  • jellyfin
  • nextcloud
  • immich
  • open-webui + ollama
  • pi-hole
  • invidious
  • romm
  • nginx proxy manager
  • grafana + prometheus
  • other minor services that I don’t think are doing much (uptime-kuma, stirlingpdf, vaultwarden, etc)
  • notabot@piefed.social
    link
    fedilink
    English
    arrow-up
    17
    ·
    5 hours ago

    Seeing high cache and buffer numbers is usually a good sign, as it means the system is making full use of the memory you have. It’ll automatically deallocate it if something actually needs the memory, but until then it’s using it to store data you might need.

    Swap’s a funny one, and whilst you can tune it to an astonishing degree, the decisions the kernel makes aren’t always what you’d want. With this little actual memory usage, compared to the installed RAM, you might be able to run without swap at all, unless you want something like hibernate. If you want to test that, you can run (as root) swapoff -a, which should disable all swap devices, pushing needed pages back in to RAM, but only until you reboot. If it’s stable, you can consider removing the swap partition(s) later.

    • A9nWGzYt@lemmy.dbzer0.comOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 hour ago

      I agree with you that my server specs are a little bit excessive for my usual workload. I have disabled swap in the past with swapoff -a and removed the partition from /etc/fstab under a similar usage, and no issues were observed.

      I am just leaving it there now for the rare instance when I run the occasional lightweight local LLM model (on CPU) for light tasks such as spell checking, which might need some RAM and I don’t risk crashing due to OOM issues.

      However, I still want to understand what is happening here to learn a little bit about my system. My intuition can be wrong here, but I find it strange that my laptop with similar specs and the same OS (but reasonably distinct workloads, to be fair) almost never swaps nor reaches those ridiculous levels of buffer + cache usage, so I think I might find one “offender” container to blame.

      • notabot@piefed.social
        link
        fedilink
        English
        arrow-up
        1
        ·
        10 minutes ago

        The cache usage being higher on a server than a laptop seems fairly likely as more disk accesses are occurring. When data is loaded from disk, the linux kernel will keep it in memory even after the original requester is done with it, on the principal that it might need it again. This is the cache you’re seeing. If the kernel detects high memory utilisation it will free cache pages before anything else, so you actually want to see near 100% memory utilisation all the time, as it means fewer accesses to disk.

        The swap usage is harder to diagnose without more detailed diagnostic work, but you can see from the graph you posted that, even what swap is being used, you have a little free memory. This may well be the kernel preemptively moving little used memory pages to the swap cache so tgat they can be evicted from memory quickly if needed. You could investigate thus by adjusting the ‘swapiness’ value closer to 0, to see if that delays the swap usage and reduces the peak.

      • noahm@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        47 minutes ago

        Very basically, what’s happening is that every file that is read (including the binaries and libraries that make up the services you run, etc) is loaded into memory and stays there until that memory needs to be reclaimed for something else. It’s a good thing. It means that the next time that file is needed, it can be accessed directly in RAM rather than reaching out to the filesystem.

  • marcos@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    3 hours ago

    IMO, the easiest way to make your system not swap into some disk you don’t want it to is to not enable any swap partition on that disk.

    If it’s using that much RAM for cache, it will survive not having a swap with a minimum impact on performance.

  • thelittleblackbird@lemmy.world
    link
    fedilink
    English
    arrow-up
    22
    ·
    7 hours ago

    The amount of swap used is not a good indicative, you need to check if there is a big exchange of data per second/minute. This is the only indicative of an out of memory system.

    Sometimes, some regions of data memory “age” in ram without any access for a long periods of time, the the kernel here has two options, it could destroy the region knowing it could recreate it when needed (with some cpu overhead) or moved this to a swap file when the ram structure already in the swap file and release than section.

    Which regions are good candidates for this? Buffers, specially in the fs, code region used for processes or even data sections of a long sleeping process…

    Checking your data, if those 5gb are created over a long period of time I would not care a lot about it. Remeber how big the swap is, isn’t that important vs real traffic (in or out) to it

  • Overspark@piefed.social
    link
    fedilink
    English
    arrow-up
    14
    ·
    edit-2
    7 hours ago

    Yeah that’s completely normal, looks absolutely fine to me. For more info on how linux uses memory I suggest reading https://www.linuxatemyram.com/

    To add: that link suggests looking if your swap usage is changing. Linux is quite happy to stuff some memory that isn’t actually used in swap. If it was right about it not being used you should see the swap usage not changing much, so your SSD isn’t really being used either apart from the initial swap-out. If your swap usage keeps fluctuating wildly there is more going on which might warrant further investigation.

  • frongt@lemmy.zip
    link
    fedilink
    English
    arrow-up
    5
    ·
    6 hours ago

    That’s low utilization. If your ram was fully used and stuff was being frequently stopped, that’s when I would be concerned (and when you would experience wear on your SSD).

    Right now you have less than a quarter used, and a couple things the kernel decided to swap out. Perfectly normal.

  • Eager Eagle@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    1
    ·
    edit-2
    5 hours ago

    No point in messing with swappiness settings, trust me. You want to address the reason this happens in the first place, not disable to reduce swap.

    I’ve had a nearly identical scenario at work. The reason? A data verification process that went through 100s of thousands of files to run their checksums and check integrity. This was working as intended, but the system alerts were firing because of that high buffer/cache utilization. So check which processes have highest IO and you might find the answer. Swap is just a side effect.

  • irmadlad@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    1
    ·
    7 hours ago

    Huh…

    
      System load:  1.26                Temperature:           57.0 C
      Usage of /:   20.4% of 454.86GB   Processes:             527
      Memory usage: 44%                 Users logged in:       1
      Swap usage:   0%                  IPv4 address for eno1: 192.168.1.190
    

    Ubuntu 22.04.5 - 32 GB RAM - 53 total containers

    cat /proc/sys/vm/swappiness: 60 (pretty much default)
    
    cat /proc/pressure/cpu: some avg10=0.68 avg60=0.62 avg300=0.67 total=960097774
    full avg10=0.00 avg60=0.00 avg300=0.00 total=0
    cat /proc/pressure/memory: some avg10=0.00 avg60=0.00 avg300=0.00 total=0
    full avg10=0.00 avg60=0.00 avg300=0.00 total=0
    cat /proc/pressure/io: some avg10=1.16 avg60=4.88 avg300=3.85 total=2831425045
    full avg10=1.11 avg60=4.54 avg300=3.58 total=2653626377
    
    • A9nWGzYt@lemmy.dbzer0.comOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 hour ago

      Well, here I have 41 containers and:

      free -hm
                     total        used        free      shared  buff/cache   available
      Mem:            31Gi       5.7Gi       426Mi       207Mi        25Gi        25Gi
      Swap:           31Gi       3.7Gi        28Gi
      

      As well as

      cat /proc/sys/vm/swappiness: 10
      

      and

      $ cat /proc/pressure/cpu
      some avg10=0.00 avg60=0.00 avg300=0.00 total=302436406
      full avg10=0.00 avg60=0.00 avg300=0.00 total=0
      
      $ cat /proc/pressure/memory
      some avg10=0.00 avg60=0.00 avg300=0.00 total=64263542
      full avg10=0.00 avg60=0.00 avg300=0.00 total=63043120
      
      $ cat /proc/pressure/io
      some avg10=1.99 avg60=1.67 avg300=1.61 total=1844790000
      full avg10=1.90 avg60=1.59 avg300=1.56 total=1788451770
      
      • irmadlad@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        23 minutes ago

        41 containers:

        Are you noticing any stalling or stuttering when running apps or using multiple apps? If ‘no’ then I’d agree with the ones that are telling you it’s fine. Dats how Linux do. I’ve always been told to let Linux handle that unless it’s causing problems for you. And even then, after exhausting all other things that may cause this. Now whether that is sage advice, I couldn’t comment to that, however and anecdotally, it’s served me well.

  • brucethemoose@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    5
    ·
    edit-2
    5 hours ago

    I disagree with most here.

    You need to reduce swappiness even more, and tweak some other variables (like the memory “threshold” Linux starts to swap, and disk cache aggressiveness) to stop Linux from swapping so opportunistically under such a light load.

    IMO, Linux is configured for “old” systems by default: slow HDDs, and constrained RAM pools, where disk IO really, really needs caching, and where idle background processes take a large fraction of RAM.

    You have superfluous RAM for your workload. And very fast disk IO that isn’t such a hindrance to apps anyway. And a disk you don’t want to wear. This is the opposite scenario: you don’t want Linux to swap unless it absolutely has to.

    For reference, this is part of my config. It’s rather niche and you probably shouldn’t use it, but you should consider looking up the variables:

    # Keep min reserve reasonable for 8GB usable space
    vm.min_free_kbytes = 262144        # Lower absolute minimum to 256MB
    
    vm.watermark_scale_factor = 10     # Lower to 0.1% (which is ~128MB on 128GB)
    
    # Disable watermark boosting completely
    vm.watermark_boost_factor = 0
    
    # Normal-ish metadata pressure so desktop doesn't stutter on disk reads
    vm.vfs_cache_pressure = 120
    
    # Allow reasonable swapping of inactive anonymous desktop pages, could be lower
    vm.swappiness = 10
    
    # Dirty bytes limits to limit caching
    vm.dirty_background_bytes = 67108864
    vm.dirty_bytes = 268435456
    
    # Disable compaction & proactive scans to stop freezing with large portions of RAM mlocked
    vm.compaction_proactiveness = 0
    vm.compact_unevictable_allowed = 0
    
    vm.page-cluster = 0 # 4kb pages for SSD
    

    My system still uses RAM as disk cache with this config, it just won’t go out of its way to swap just to keep that cache, especially I lower swappiness to 1-3.

    I also have a 1GB zram pool, prioritized over ssd swap. But you should make yours even larger (maybe 4GB?). This will intercept anything that does swap first.

    I also start some applications with systemd-run and specify memory caps and swap limits (often forbidding them from swapping entirely).

    It makes a night-and-day difference for some workloads on my system, that would otherwise swap pointlessly, just tank performance and even de-stabilize the system.

    • non_burglar@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      5 hours ago

      I agree that hitting swap is not ideal, but messing with swappiness sysctl is almost never the answer and very often leads to more problems than it solves.

      If you want to tune for workload without needing fairly deep understanding of how Linux manages memory, use a sysctl that sets a whole system behaviour like CPU governor presets.

      IMO, Linux is configured for “old” systems by default: slow HDDs, and constrained RAM pools, where disk IO really, really needs caching, and where idle background processes take a large fraction of RAM.

      Not really a matter of opinion, and not true since kernel 5.1 when ssds became first class citizens.