* prevent the kernel from OOMKilling embassyd * privilege embassyd with respect to cpu usage * add a docker slice