Description
Kubernetes uses container memory requests when scheduling pods onto nodes. Requests below actual needs can permit crowded placement and increase the risk of memory shortages.
LimitRange can supply a default request. If only a memory limit is specified and no other request default applies, Kubernetes uses that limit as the request. An omitted declaration is therefore different from an absent effective request.
Potential impact
- Requests below actual usage can cause memory contention and degraded performance on the node.
- Memory pressure can lead to pod eviction or process termination.
Remediation
- Set
resources.requests.memoryusing observed usage, startup needs and peak load, and adjust it together with the limit. - Review LimitRange defaults and ResourceQuota, and inspect effective requests on deployed pods. Do not copy the example values to every workload.
Examples
The existing values are illustrative; use a maintained image for deployment. Without a separate request default, the before memory limit of 512Mi is also used as the request.
Before
hcl
resource "kubernetes_pod" "pod" {
metadata {
name = "terraform-example"
}
spec {
container {
image = "nginx:1.7.9"
name = "example"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
}
}
}
}
After
hcl
resource "kubernetes_pod" "pod" {
metadata {
name = "terraform-example"
}
spec {
container {
image = "nginx:1.7.9"
name = "example"
resources {
limits = {
cpu = "0.5"
memory = "512Mi"
}
requests = {
cpu = "250m"
memory = "50Mi"
}
}
}
}
}
Explanation:
- Before: No explicit request is provided, but the 512Mi memory limit can supply it.
- After: The memory request is explicitly set to 50Mi. A lower value is not always appropriate; verify actual needs.