More aggressive oomkiller and cgroups have helped in recent years
Edit: systemd-oomd is what I was thinking of