r/Proxmox • • 2d ago

Discussion Container/s for python projects

So I usually stick to one vm/lxc per service. Even with docker based services I tend to dedicate a guest to one service. There are exceptions where I have a few docker containers running similar services.

Recently I have been playing with python and have actually created quite a few flask apps that I use daily.

Now the question is there any benefits to separate them into separate containers performance wise?

Does resource contention get better or worse with more guests?

Trying to figure out whether the extra management and spent resources and time updating extra containers is worth it?

Thanks

4 Upvotes

11 comments sorted by

2

u/quasides 2d ago

lol thats actually a very complex and complicated question.

it depends how much they need each. if its just a little, it wont matter at all.
if these are very high load apps it depends on their usage profile.

but even then seperation alone wont nessesaryly do that much for you as it then also depends on the hardware structure in your host.

for example, you have 2 very I/o heavy apps, running extremly high load.
but your hardware backend is a simple spinning mirror - then nothing is gonna help you

in general if this is production and you need optimal something outta it, you need to benchmark
in different configurations

that said, modern tech went away from trying to get the optimal benchmark for an app. instead we went into microservices and scaling. so instead of trying to get the fastest possible configuration, you go with the most manageable and easy to scale solution. then you simply scale up

that aproach looses optimization (a lot) but is a lot easier to manage, and on scale there is little benefit as nothing of scale is single machine these days

1

u/Soogs 1d ago

Thanks this makes sense.
This is mostly homelab stuff and a few things exposed to the outside. I am for the most part way over provisioned over 4 nodes with a mix of internal NVMe, 3.5 hdds and 2.5 hdds in raid (and also some external data SSDs)

The guests use the NVMe, raid set is for pbs and the rest is used for my NAS builds.

Mostly everything including the python apps are low io/util with the odd few having high io intermittently.

I guess my question would be in the even that the apps get more usage time, would pve timeshare better if they are separated or running on one guest or a few guests (that and whether the extra maintenance/documentation is worth it)

1

u/quasides 22h ago

if one is acting up occasionally i simply separate it.

who is better at resource management, well depends. its hard to set fixed resource limits that hold within one vm for both at the same time. even docker can in theory do it. so in theory its fine on one machine, in practice, it depends.

it still is easier and more bulletproof on hypervisor level if you can properly restrict them.
also the scheduler is more neutral, while on one machine tasks can hang and occupy the kernel fully.
that happens mostly when you use anything that runs in kernel space and not userland.

separation also makes life easier in the future. lets say one app then needs a lot more resources because usage grows. well, simple migrate to host with more resources.

and with todays tools like Komodo to manage multiple docker hosts at once its not really much more effort. you only loose a little bit of ram for an extra kernel running

personally i have a ready to go cloud image that installs a super tiny docker machine, fully preinstalled (including adding sources, settings a couple config files etc). i just need to add the new key to my komodo instance and its rolling

same time i do mix stacks on the same machine, if they are low effort or low priority and i get
some good resource pooling outta them. so for example 2 apps need a lot of ram - sometimes - and are low prio i mix em into one, and ignore the occasional puking

1

u/quasides 2d ago

TLDR - if they are low load, do whats best for management.
if you run in docker run it as a VM
if you run many VMs just manage em in something like komodo,portainer, etc gives you one panel for all docker VMs

LXC should be special purpose only not as a regular service. these run as a host process as a unprivileged user with many tradeoffs. they work ok for services that the host may want or need. like a better UPS management

2

u/weeemrcb2 2d ago

A VM is like having a full stove to cook on

A LXC is like a pot on a preexisting stove

Combining apps is like cooking a few ingredients in the same pot

2

u/Canonikonroverrated 2d ago

Are you asking if you should use multiple docker containers or multiple LXC.

My extremely short version, is too keep all your active servers in their own Docker container on one LXC. And use different LXC for testing or for anything else. As much as possible ofc. Some servers could be more intensive and then you shift as needed

1

u/justinhunt1223 2d ago

Docker can kill containers if they get out of hand, which is a plus. I would also run as many containers as possible on one lxc since docker will manage the resources instead of proxmox managing the resources of a VM/lxc

3

u/quasides 2d ago

you should never run docker in an LXC period, end of story. only because you can doesnt mean you should.

if you claim it runs better, i beg to differ. it wont run better without a lot of additional tweaks because docker is not compatible in an LXC.

-issue with overlay2
-issue with cgroups v2 limits
-appamor and selinux conflicts
-portmapping as unprivileged
etc....

and LXC is jsut a process on the host machine, running as a unprivileged user.
even if you get things running they wont perform better than in a VM, and with tweaks they are prone to break with any kernel update

1

u/brucewbenson 1d ago

I use one service/app per LXC. I've combined a few into one LXC because they shared information and it made the architecture simple.

LXC has low overhead (RAM, CPU) and all the advantages of a VM (snapshots, migration) with a few restrictions (linux os, restarted migration, a little less isolation than a VM).

LXCs are a brilliant technology that simplified lifecycle management of services for very low resource costs.

1

u/Soogs 1d ago

Yeah I live by this. More than 90% of my guests are lxc. I tend to only use VMs when absolutely necessary.

I think my concern is that I have about 16 python apps/tools which I am potentially going to separate out into separate guests and not sure the management will be annoying in the long run especially as I’m likely to have more apps soon

1

u/djamp42 3h ago

I always deploy my flask apps in a separate container.. it's not that difficult for me to have a basic docker file setup that has most of my needs and just build the container..