Description
ResourceQuota limits aggregate resource requests or object counts within a namespace. Without needed quotas, one team or workload can request excessive resources. CPU and memory request quotas do not directly cap actual runtime usage or reserve capacity.
Potential impact
- Excessive resource requests or Pod creation can affect placement of other workloads.
- An undersized quota can reject necessary object creation or changes.
Remediation
- Set ResourceQuota for the namespace’s purpose and capacity. When using CPU or memory request quotas, specify the required requests on Pods or provide LimitRange defaults.
- Manage runtime usage separately with container limits and verify which new requests are allowed or rejected. Adding a quota does not itself terminate existing Pods.
Examples
The mynewpod namespace is assumed to exist. Replace the image and values for actual requirements. cpu: "1000" means 1000 CPUs, not 1000m. This example limits only CPU/memory requests and Pod count.
Before
apiVersion: v1
kind: Pod
metadata:
name: pod1
namespace: mynewpod
spec:
containers:
- name: app
image: images.my-company.example/app:v4
The excerpt creates a Pod without showing a namespace quota. Check separately configured policies and actual usage.
After
apiVersion: v1
kind: ResourceQuota
metadata:
name: pods-high
namespace: mynewpod
spec:
hard:
cpu: "1000"
memory: 200Gi
pods: "10"
---
apiVersion: v1
kind: Pod
metadata:
name: pod1
namespace: mynewpod
spec:
containers:
- name: app
image: images.my-company.example/app:v4
resources:
requests:
cpu: "250m"
memory: "64Mi"
ResourceQuota and Pod requests are explicit. The aggregate CPU/memory requests and Pod count are limited; this does not set individual containers’ runtime usage limits.