Description
Without an effective memory limit, one workload can consume excessive node memory and affect others. LimitRange can supply a default even when no explicit limit is present, so inspect the deployed configuration.
Exceeding a memory limit can result in OOM process termination. An overly low limit can disrupt the application, and limits do not prevent every instance of node memory pressure.
Potential impact
- Memory spikes can degrade other pods or cause eviction.
- An overly low limit can terminate processes and interrupt service.
Remediation
- Set
resources.limits.memoryaccording to actual usage and peak load, and review it together with the request. - Monitor OOM terminations and node memory pressure and adjust the values. Use LimitRange to manage defaults and allowed ranges, and verify the effective limits.
Examples
The existing 50Mi and 512Mi values are illustrative. Adapt them to the workload and use a maintained image for deployment.
Before
hcl
resource "kubernetes_pod" "pod" {
metadata {
name = "terraform-example"
}
spec {
container {
image = "nginx:1.7.9"
name = "example"
resources {
requests = {
memory = "50Mi"
}
}
}
}
}
After
hcl
resource "kubernetes_pod" "pod" {
metadata {
name = "terraform-example"
}
spec {
container {
image = "nginx:1.7.9"
name = "example"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
}
}
}
Explanation:
- Before: Only a memory request is explicit. Check whether another policy supplies a limit.
- After: A 512Mi memory limit and requests are explicit. Verify that the limit accommodates actual peak usage.