3 ms·
"Uses a separate process for every TLS connection" sounds scalable.
by gima 11y ago
"Uses a separate process for every TLS connection" sounds scalable.
- lmm 11y agoIt should be - the OS's whole job is to manage processes. I mean if it's allocating 4kb of physical memory to each then that would scale poorly, but who does that?
- ryanpetrich 11y ago4KB is the size of a page on x86 and most architectures, the smallest unit of memory the OS can dispense. SSL termination is definitely a function you don't want the kernel to swap to disk, therefore each connection would get at least 4KB of physical memory under a process-per-connection model.
- agwa 11y agoThere's a cost to the isolation. It's not for everyone. Ultimately, I'd like to provide a knob to the administrator to control how much isolation they'd like. If you can't afford full isolation, you could tell titus to service multiple connections per process. titus would only do so if the server was under load, and would recycle processes frequently so memory wouldn't stick around for too long. But this would require complicated changes which I haven't had time for yet.