An emptyDir volume with medium Memory uses tmpfs. Its file pages count toward memory use, not the Pod's local ephemeral-storage budget. Data remains for the Pod lifetime, even if a writing container restarts; a restarted process cannot rely on garbage collection to remove old scratch files. Setting a size limit controls volume growth, but it does not replace a realistic container memory limit or a cleanup rule.
Memory-backed emptyDir: budget file bytes as container memory
Operational decision
A claims renderer writes intermediate PDFs into a shared tmpfs volume. The renderer's heap stays near 240 MiB while 420 MiB of old files accumulate after failed attempts. Give the scratch volume a 320 MiB sizeLimit, reserve memory for the process and sidecar, and delete each task's files after its result is committed. Inject a failed render, restart the renderer, and verify the volume still contains the abandoned file until cleanup runs. Measure which container receives the memory charge on the chosen runtime instead of assuming the sidecar owns it. If the files must survive Pod deletion, use durable storage rather than tmpfs.
apiVersion: v1
kind: Pod
metadata:
name: claims-renderer
spec:
containers:
- name: renderer
image: registry.internal/claims-renderer@sha256:1111111111111111111111111111111111111111111111111111111111111111
resources:
requests:
memory: 768Mi
limits:
memory: 1152Mi
volumeMounts:
- name: scratch
mountPath: /work
volumes:
- name: scratch
emptyDir:
medium: Memory
sizeLimit: 320MiCost and verification
A full scan of F scratch files is O(F); recording per-task paths makes targeted cleanup proportional to the files for that task. tmpfs avoids disk I/O but buys that speed with scarce memory and possible OOM kills. Track scratch bytes, failed cleanup attempts, container charge, and node pressure at the same time. A size limit can make writes fail earlier; the application must handle that error without leaving a half-published result.
Common Mistakes
- Do not charge tmpfs scratch to ephemeral-storage quota alone.
- Do not assume a container restart clears an emptyDir volume.
- Do not put irreplaceable output in a Pod-lifetime scratch volume.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Local ephemeral storage: account for logs, writable layers, and emptyDir
- Container OOM attribution: separate a limit kill from node eviction
- Persistent storage: PVC lifecycle and data ownership
