Review Kubernetes kubelet event rate settings

Balance event visibility against API server load.

Description

The kubelet’s eventRecordQPS caps event creations per second; 0 disables this rate limit. An overly low value can suppress needed events, while removing the limit can increase API server load during an event burst. Zero is not a universal security requirement.

Potential impact

  • Missing events can make incident diagnosis harder.
  • Excessive event requests can burden the API server and event storage or collection systems.

Remediation

  • Choose eventRecordQPS in KubeletConfiguration based on observed event volume and API server capacity. Review eventBurst as well when using a positive value.
  • Select 0 only when removing the limit is required, and test event bursts. Check precedence between configuration files and existing --event-qps arguments, then verify effective node settings and event collection.

Examples

These kubelet excerpts show only the event rate setting. A value of 0 removes this limit; it does not guarantee that every event is collected or retained.

Before

yaml
apiVersion: kubelet.config.k8s.io/v1beta1
kind: KubeletConfiguration
eventRecordQPS: 2

eventRecordQPS: 2 limits the event creation rate. Burst capacity depends on the separate eventBurst setting.

After

yaml
apiVersion: kubelet.config.k8s.io/v1beta1
kind: KubeletConfiguration
eventRecordQPS: 0

eventRecordQPS: 0 removes this kubelet rate limit. Limits and retention policies at other layers, including the API server, still apply.

References