Description
The EventRateLimit admission plugin limits Event requests stored through the API server. Without suitable limits, repeatedly failing workloads or controllers can burden the API server and etcd. It does not limit all other API requests; review existing protections alongside actual Event volume.
Potential impact
- Excessive Event generation can increase API server and storage load.
- Important Events can be obscured by noise.
Remediation
- To use this plugin on a self-managed API server, check support in the installed version and configure EventRateLimit together with its limits through AdmissionConfiguration. For managed services, check the controls the provider offers.
- Investigate workloads producing many Events and test limits to avoid dropping too many legitimate Events. Monitor this alpha feature’s behavior and rejected requests in operation.
Examples
These historical excerpts compare API server arguments for Kubernetes v1.30.0. Actual use needs a supported version, complete control-plane configuration and mounted configuration files. The configured path must provide AdmissionConfiguration referencing the EventRateLimit policy.
Before
apiVersion: v1
kind: Pod
metadata:
name: kube-apiserver
spec:
containers:
- name: kube-apiserver
image: registry.k8s.io/kube-apiserver:v1.30.0
command:
- kube-apiserver
args:
- --enable-admission-plugins=AlwaysAdmit
AlwaysAdmit is added, but this plugin does not limit Event volume. This does not mean all other default admission plugins are disabled.
After
apiVersion: v1
kind: Pod
metadata:
name: kube-apiserver
spec:
containers:
- name: kube-apiserver
image: registry.k8s.io/kube-apiserver:v1.30.0
command:
- kube-apiserver
args:
- --enable-admission-plugins=EventRateLimit
- --admission-control-config-file=/etc/kubernetes/eventratelimit.yaml
EventRateLimit and a configuration file path are specified. The intended limits require a valid policy and the actual file.