Description
An excessively long --request-timeout lets kube-apiserver retain slow requests for longer. Abnormal or long-running requests can then occupy API server resources unnecessarily.
Appropriate timeouts help contain failures and protect resources. The current default is one minute; specific request types such as watches can have separate timeouts. Choose values that do not unnecessarily interrupt legitimate requests.
Potential impact
- Long requests can continue occupying API server connections and resources.
- Recovery from abnormal traffic or overload may be slower.
- An excessively short timeout can interrupt normal operations.
Remediation
- Set
--request-timeoutaccording to actual processing times and operational requirements. - Review ordinary requests separately from types such as watches that have other timeouts.
- Monitor load and timeout errors, and test that normal requests complete.
Examples
These command-argument excerpts retain the historical v1.6.0 image; that version is not a deployment recommendation. Apply the setting to a supported version and the actual control-plane configuration, with required certificate and connection settings supplied separately.
Before
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
command: ["kube-apiserver"]
args: ["--request-timeout=6m"]
After
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
command: ["kube-apiserver"]
args: ["--request-timeout=300s"]
Explanation:
- Before: The default timeout for ordinary requests is set to six minutes. Verify that this duration is actually needed.
- After: The value is reduced to 300 seconds, or five minutes. This is illustrative and still exceeds the current one-minute default; it is not a universal recommendation.