Description
Kubernetes requests guide scheduling, while limits bound resource use. Without effective required requests or limits, excessive consumption by one container can affect other workloads. Defaults such as LimitRange also affect the configuration, so inspect deployed values.
A CPU limit can cause throttling when usage exceeds it, while exceeding a memory limit can terminate a process. Choose limits according to observed usage and performance requirements.
Potential impact
- Node resource contention can cause response delays and service disruption.
- Unsuitable requests and limits can cause scheduling failures, CPU throttling or OOM termination.
Remediation
- Measure each container’s CPU and memory use, then set requests and the required limits. Keep requests within their corresponding limits and test normal and peak loads.
- Use LimitRange and ResourceQuota for organizational defaults and usage policies. Periodically review injected values and actual consumption.
Examples
The example values are not universal recommendations. Adapt them to actual needs and use a maintained image.
Before
hcl
resource "kubernetes_pod" "pod" {
metadata {
name = "terraform-example"
}
spec {
container {
image = "nginx:1.7.9"
name = "example"
}
}
}
After
hcl
resource "kubernetes_pod" "pod" {
metadata {
name = "terraform-example"
}
spec {
container {
image = "nginx:1.7.9"
name = "example"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
}
}
}
Explanation:
- Before: No resources configuration is explicit. Check namespace defaults as well.
- After: CPU and memory requests and limits are explicit. Validate them against actual performance and usage.