Welcome to Linux Kernel Tuning for High-Performance Web Servers. Standard Linux distributions ship with kernel settings optimized for general-purpose workloads. If you are running high-traffic Nginx, HAProxy, or Node.js servers, you are leaving massive performance gains on the table by not tuning `sysctl` parameters.
1. Expanding File Descriptors
Everything in Linux is a file, including network sockets. When a web server handles thousands of concurrent connections, it quickly exhausts the default file descriptor limits. By editing /etc/security/limits.conf and setting fs.file-max in sysctl.conf to a much higher value (e.g., 2097152), you prevent "Too many open files" errors during traffic spikes.
2. Tuning the TCP/IP Stack
The default TCP settings are conservative. To handle high concurrency, you need to adjust how the kernel manages connection states. Increasing the net.core.somaxconn (the maximum number of queued connections) and net.ipv4.tcp_max_syn_backlog ensures that the kernel doesn't drop packets before the web server can process them during a SYN flood or a sudden traffic surge.
3. Optimizing TIME_WAIT States
When a server closes a TCP connection, the socket remains in the TIME_WAIT state for a specified duration (usually 60 seconds). On busy load balancers or proxy servers, these lingering sockets can consume all available ephemeral ports, leading to port exhaustion. Enabling net.ipv4.tcp_tw_reuse allows the kernel to safely recycle these sockets for new outgoing connections.
4. BBR Congestion Control
Traditional TCP congestion control algorithms (like CUBIC) rely on packet loss to detect congestion, which performs poorly on modern high-speed, long-distance networks. By enabling TCP BBR (Bottleneck Bandwidth and Round-trip propagation time) via net.ipv4.tcp_congestion_control=bbr, servers can push data significantly faster, drastically reducing load times for users on less stable connections.
5. Virtual Memory and Swappiness
For database and application servers, aggressive swapping to disk will destroy performance. By lowering vm.swappiness from the default 60 to 10 (or even 1 for dedicated databases), you instruct the kernel to prefer dropping filesystem cache over swapping active memory pages out to the disk.
Conclusion
Kernel tuning is an iterative process. You must benchmark your specific workloads before and after making sysctl changes. However, implementing these baseline network and memory optimizations is the first step toward extracting every ounce of performance from your cloud infrastructure.