Review Kubernetes namespace resource quotas

Manage namespace allocation separately from individual container limits.

Description

ResourceQuota limits aggregate resource requests or object counts within a namespace. Without needed quotas, one team or workload can request excessive resources. CPU and memory request quotas do not directly cap actual runtime usage or reserve capacity.

Potential impact

  • Excessive resource requests or Pod creation can affect placement of other workloads.
  • An undersized quota can reject necessary object creation or changes.

Remediation

  • Set ResourceQuota for the namespace’s purpose and capacity. When using CPU or memory request quotas, specify the required requests on Pods or provide LimitRange defaults.
  • Manage runtime usage separately with container limits and verify which new requests are allowed or rejected. Adding a quota does not itself terminate existing Pods.

Examples

The mynewpod namespace is assumed to exist. Replace the image and values for actual requirements. cpu: "1000" means 1000 CPUs, not 1000m. This example limits only CPU/memory requests and Pod count.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: pod1
  namespace: mynewpod
spec:
  containers:
    - name: app
      image: images.my-company.example/app:v4

The excerpt creates a Pod without showing a namespace quota. Check separately configured policies and actual usage.

After

yaml
apiVersion: v1
kind: ResourceQuota
metadata:
  name: pods-high
  namespace: mynewpod
spec:
  hard:
    cpu: "1000"
    memory: 200Gi
    pods: "10"
---
apiVersion: v1
kind: Pod
metadata:
  name: pod1
  namespace: mynewpod
spec:
  containers:
    - name: app
      image: images.my-company.example/app:v4
      resources:
        requests:
          cpu: "250m"
          memory: "64Mi"

ResourceQuota and Pod requests are explicit. The aggregate CPU/memory requests and Pod count are limited; this does not set individual containers’ runtime usage limits.

References