# ============================================================================= # settings.conf - every tunable value for the LDAP kit, in one place # ============================================================================= # Both start-ldap.sh and test-ldap.sh read this file. # Edit a value here, then re-run ./start-ldap.sh so the server picks it up. # # Any value can also be overridden for a single run from the command line: # DURATION=30 CLIENTS=100 ./test-ldap.sh search # ============================================================================= # ----------------------------------------------------------------------------- # 1. Where the LDAP server is reached # ----------------------------------------------------------------------------- # All test traffic stays on this machine (loopback). No traffic leaves the host. # Port 389 is the standard LDAP port; SELinux already allows the server to use it. # If you change the port after the first start, run "./start-ldap.sh cleanup" first. LDAP_HOST="${LDAP_HOST:-127.0.0.1}" LDAP_PORT="${LDAP_PORT:-389}" # ----------------------------------------------------------------------------- # 2. The directory server instance # ----------------------------------------------------------------------------- # RHEL 9 ships "389 Directory Server" (package 389-ds-base) as its LDAP server. # The kit creates its own instance with this name, so it never touches another # instance that may already exist on the host. # "./start-ldap.sh cleanup" removes the instance and all its data again. INSTANCE="${INSTANCE:-perftest}" # The top of the test directory tree. The ".test" top-level domain is reserved # for testing (RFC 6761), so it can never clash with a real name. SUFFIX="${SUFFIX:-dc=perf,dc=test}" # Where each part of the instance lives (standard 389 DS locations; they # already have the correct SELinux labels). DS_CONFIG_DIR="/etc/dirsrv/slapd-$INSTANCE" DS_LOG_DIR="/var/log/dirsrv/slapd-$INSTANCE" DS_DB_DIR="/var/lib/dirsrv/slapd-$INSTANCE/db" DS_PID_FILE="/run/dirsrv/slapd-$INSTANCE.pid" DS_SERVICE="dirsrv@$INSTANCE" # The test data, in LDIF format (LDAP's plain-text file format). TEST_LDIF="/var/lib/dirsrv/slapd-$INSTANCE/ldif/perf-test-data.ldif" # Password of the "cn=Directory Manager" super user. It is generated randomly # when the instance is created, and saved in this root-only file. The kit # itself never needs it: as root it uses the local socket (LDAPI) instead. ADMIN_PASSWORD_FILE="$DS_CONFIG_DIR/perf-test-directory-manager.pw" # ----------------------------------------------------------------------------- # 3. Test data # ----------------------------------------------------------------------------- # Number of user entries (uid=user1 ... uid=userN) under ou=people. USER_COUNT="${USER_COUNT:-100000}" # Number of groups under ou=groups. Every user is a member of exactly one # group, so each group has USER_COUNT / GROUP_COUNT members. GROUP_COUNT="${GROUP_COUNT:-1000}" # Password of every test user. Test-only data, never use a real password here. USER_PASSWORD="${USER_PASSWORD:-Perf-User-Pass-1}" # How user passwords are stored (hashed). Empty = the server's default, # which is PBKDF2-SHA512 on RHEL 9 - deliberately slow, to resist password # cracking. It decides the speed of the "bind" test. Other choices: # SSHA512, SSHA256, PBKDF2-SHA256, CRYPT-SHA512 ... PASSWORD_SCHEME="${PASSWORD_SCHEME:-}" # The account the test "application" logs in with (like SSSD or a web # application). It may read the whole tree and write under ou=people. SERVICE_DN="uid=perf-app,ou=services,$SUFFIX" SERVICE_PASSWORD="${SERVICE_PASSWORD:-Perf-App-Pass-1}" # ----------------------------------------------------------------------------- # 4. 389 Directory Server settings # ----------------------------------------------------------------------------- # Worker threads that process LDAP operations. # Empty = automatic (389 DS picks one per CPU core, which is usually right). DS_THREADS="${DS_THREADS:-}" # Memory for the entry cache (entries kept ready in RAM), in MB. # Empty = automatic (389 DS uses a share of the machine's RAM). ENTRY_CACHE_MB="${ENTRY_CACHE_MB:-}" # Access log: one line per LDAP operation. "on" is the normal setting on a # production server and costs a little performance; "off" shows the maximum. ACCESS_LOG="${ACCESS_LOG:-on}" # ----------------------------------------------------------------------------- # 5. How hard and how long each test runs # ----------------------------------------------------------------------------- DURATION="${DURATION:-10}" # seconds of load for each test run # Simultaneous clients = open LDAP connections. Each client sends one # operation, waits for the answer, then sends the next (like a real program). CLIENTS="${CLIENTS:-50}" CLIENT_LEVELS="${CLIENT_LEVELS:-1 10 50 100 200 500}" # "concurrency" test steps LATENCY_TEST_RATE="${LATENCY_TEST_RATE:-5000}" # "latency": steady searches/s (normal load) WRITE_TEST_ENTRIES="${WRITE_TEST_ENTRIES:-5000}" # "write": entries added, changed, deleted CONNECTION_TEST_COUNT="${CONNECTION_TEST_COUNT:-2000}" # "connections": connections held open at once CONNECTION_TEST_RATE="${CONNECTION_TEST_RATE:-2000}" # "connections": searches/s spread over them STARTUP_ROUNDS="${STARTUP_ROUNDS:-3}" # restarts measured by the "startup" test OPERATION_TIMEOUT="${OPERATION_TIMEOUT:-5}" # seconds without an answer = operation lost # The "cache" test restarts the server so its caches are empty. The Linux # page cache (database files kept in RAM by the kernel) survives a restart. # "yes" also empties the page cache, for a truly cold start. It affects every # program on the machine for a moment, so it is off by default. DROP_OS_CACHE="${DROP_OS_CACHE:-no}" # Worker processes of the load generator (lib/ldapload.py). Each one uses up # to one CPU core. Default: a quarter of the CPU cores (1 to 8), so the LDAP # server keeps most of the CPUs. DEFAULT_LOAD_PROCESSES=$(( $(nproc) / 4 )) (( DEFAULT_LOAD_PROCESSES < 1 )) && DEFAULT_LOAD_PROCESSES=1 (( DEFAULT_LOAD_PROCESSES > 8 )) && DEFAULT_LOAD_PROCESSES=8 LOAD_PROCESSES="${LOAD_PROCESSES:-$DEFAULT_LOAD_PROCESSES}" # ----------------------------------------------------------------------------- # 6. Pass / fail targets # ----------------------------------------------------------------------------- # Sensible starting points for a small RHEL 9 directory server with 100,000 # users, tested over localhost. Adjust them to your own hardware and # service requirements. A result that misses its target is reported as FAIL; # see PERFORMANCE-METRICS.md for what each number means. TARGET_STARTUP_MAX_MS="${TARGET_STARTUP_MAX_MS:-15000}" # start until first answer TARGET_IMPORT_MIN_EPS="${TARGET_IMPORT_MIN_EPS:-2000}" # bulk import, entries/s, at least TARGET_CACHE_WARM_P95_MAX_MS="${TARGET_CACHE_WARM_P95_MAX_MS:-5}" # searches from a warm cache, p95 TARGET_CACHE_WARM_HIT_MIN_PCT="${TARGET_CACHE_WARM_HIT_MIN_PCT:-90}" # warm entry cache hit ratio, at least TARGET_SEARCH_MIN_OPS="${TARGET_SEARCH_MIN_OPS:-5000}" # searches/s, at least TARGET_LATENCY_P95_MAX_MS="${TARGET_LATENCY_P95_MAX_MS:-5}" # 95% of searches faster than TARGET_LATENCY_P99_MAX_MS="${TARGET_LATENCY_P99_MAX_MS:-10}" # 99% of searches faster than TARGET_SCALING_MIN_PCT="${TARGET_SCALING_MIN_PCT:-50}" # throughput kept at top level vs peak TARGET_BIND_MIN_OPS="${TARGET_BIND_MIN_OPS:-200}" # logins/s, new connection each TARGET_WRITE_MIN_OPS="${TARGET_WRITE_MIN_OPS:-200}" # slowest of add/modify/delete, per s TARGET_ERROR_MAX_PCT="${TARGET_ERROR_MAX_PCT:-0.1}" # failed operations in any load run TARGET_CPU_MAX_PCT="${TARGET_CPU_MAX_PCT:-90}" # share of all CPUs ns-slapd may use TARGET_MEMORY_MAX_MB="${TARGET_MEMORY_MAX_MB:-4096}" # peak ns-slapd memory, at most