Exhaust disk space and inodes, and find what filled them
Task
Give a service a small volume for its logs, then exhaust it twice -- once by filling the space, once by exhausting its inodes with many tiny files while space remains -- and diagnose each from the application's failure back to the cause. The second case is the one that fools people: df -h says there is room.
Steps
- Create and mount the volume, and write a small script
/usr/local/bin/applog.shthat appends a timestamped line to/srv/applogs/app.logevery second and logs to the journal if the write fails. Run it as a systemd service. - Fill the space: write one large file with
fallocateuntil the volume is full. Savedf -h /srv/applogs,du -sh /srv/applogs/*and the service's journal errors tolab/exhaust/space.txt. Delete the file. - Exhaust the inodes: create empty files in a loop until creation fails. Save
df -h /srv/applogs,df -i /srv/applogsand the service's errors tolab/exhaust/inodes.txt. - Find the directory holding most files with
find /srv/applogs -xdev -type f | cut -d/ -f1-4 | sort | uniq -c | sort -n | tail, save it tolab/exhaust/culprit.txt, and clean it up. - Record in
lab/exhaust/alerts.txtthe two monitoring thresholds that would have warned before either failure.
Verify
These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.
grep -Eic 'No space left on device' lab/exhaust/space.txt lab/exhaust/inodes.txt
grep -E '100%' lab/exhaust/inodes.txt | head -2
awk '/IUse%/ {getline; print "inode use: "$5}' lab/exhaust/inodes.txt
grep -Eic 'inode' lab/exhaust/alerts.txt
Both failures report no space left on device, but the inode capture shows space still free with inode use at 100 per cent. A monitoring system watching only disk space would have stayed silent through the second failure, which is why the alerts file must include an inode threshold.
Notes
Memory leaks are the third common exhaustion: a process whose memory grows without levelling off until the kernel's out-of-memory killer ends something, recorded as an Out of memory: Killed process line in journalctl -k.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.