Review container memory limits

Check memory limits and their effective values against actual usage.

Description

Without an effective memory limit, one workload can consume excessive node memory and affect others. LimitRange can supply a default even when no explicit limit is present, so inspect the deployed configuration.

Exceeding a memory limit can result in OOM process termination. An overly low limit can disrupt the application, and limits do not prevent every instance of node memory pressure.

Potential impact

  • Memory spikes can degrade other pods or cause eviction.
  • An overly low limit can terminate processes and interrupt service.

Remediation

  • Set resources.limits.memory according to actual usage and peak load, and review it together with the request.
  • Monitor OOM terminations and node memory pressure and adjust the values. Use LimitRange to manage defaults and allowed ranges, and verify the effective limits.

Examples

The existing 50Mi and 512Mi values are illustrative. Adapt them to the workload and use a maintained image for deployment.

Before

hcl
resource "kubernetes_pod" "pod" {
  metadata {
    name = "terraform-example"
  }

  spec {
    container {
      image = "nginx:1.7.9"
      name  = "example"

      resources {
        requests = {
          memory = "50Mi"
        }
      }
    }
  }
}

After

hcl
resource "kubernetes_pod" "pod" {
  metadata {
    name = "terraform-example"
  }

  spec {
    container {
      image = "nginx:1.7.9"
      name  = "example"

      resources {
        limits = {
          cpu    = "0.5"
          memory = "512Mi"
        }

        requests = {
          cpu    = "250m"
          memory = "50Mi"
        }
      }
    }
  }
}

Explanation:

  • Before: Only a memory request is explicit. Check whether another policy supplies a limit.
  • After: A 512Mi memory limit and requests are explicit. Verify that the limit accommodates actual peak usage.

References