# Resource Limits

HakoRun caps every function run on CPU, memory, request size, and time.

## Limits at a Glance

| Limit | Default | Setting | When Exceeded | Platform |
|-------|---------|---------|---------------|----------|
| CPU | 1 core (`CPUQuota=100%`) | `MAX_CPUS` | Throttled by cgroup | Linux |
| Memory | `128M`, swap 0 | `MAX_MEMORY` | Killed by cgroup OOM | Linux |
| Request body | 256 KiB | `CODE_MAX_SIZE` | HTTP 400 | All |
| Execution time | 30 s + 5 s | `TIMEOUT_SCRIPT` | Process killed; 500 in non-stream, `error` event in stream | All |

## systemd Slice

At startup `sandbox.NewSlice()` writes `~/.config/systemd/user/hakorun.slice`, then runs `systemctl --user daemon-reload` and `start`:

```ini
[Unit]
Description=FaaS Sandbox

[Slice]
CPUQuota=100%
MemoryMax=128M
MemorySwapMax=0
```

Each sandbox process joins this slice through `systemd-run --scope --slice=hakorun.slice`, so the caps are **shared by all concurrently running functions**, not allotted per function. A failed slice setup only logs a warning and the server still starts, without CPU or memory caps.

## Time and Size

- Timeout: `TIMEOUT_SCRIPT` seconds plus a 5-second buffer form the context deadline; in stream mode a client disconnect also kills the process immediately.
- Request size: `http.MaxBytesReader` applies to `/run` and `/run-now` bodies; `/upload` is not limited.

## Related Pages

- [Sandbox](/sandbox)
- [Configuration](/configuration)
