Using Pod Overhead and Kata Containers to Isolate Kernel Memory and Stop Container Slab Leaks
The article explains how intensive file‑system reads in a Kubernetes pod cause kernel slab memory to balloon, why standard cgroup limits cannot contain the leak, and demonstrates step‑by‑step how configuring Pod Overhead with Kata containers creates a separate sandbox cgroup that isolates kernel memory, preventing host‑level OOM.
