← CKAD: Kubernetes applications in production
06 / 7 · 24 MIN

Resources, security, and extensions

Distinguish admission, execution, and reconciliation constraints.

Concept and mechanism

Requests express resources requested for scheduling; limits constrain execution according to resource and runtime. ResourceQuota limits accounted aggregate usage within a namespace and can reject creation before a Pod runs. A quota rejection is not automatically resolved by the scheduler. Check requested values, accounted usage, and capacity policy before lowering requests merely to make a manifest pass. Resource commitments should match observed application behavior and business needs.

Guided application

SecurityContext applies controls at Pod or container level according to the field. Running without root, preventing escalation, and making the root filesystem read-only are separate decisions. If the application needs /tmp caching, a writable volume at that path can preserve the restriction elsewhere. Check compatibility instead of removing every control at the first error. For custom resources, a CRD registers the type but does not implement behavior. Inspect the controller, permissions, and reconciliation when an accepted object does not produce the expected result.

IN PRACTICE

A 4 CPU quota, accounted usage of 3.5, and a new 750m request total 4.25 CPU. Creation exceeds quota even if a node has instantly free CPU.

Common pitfalls

Confusing quota with instantaneous measurement; using privileged to fix every error; assuming a CRD installs the operator.

Related topics: Services, DNS, and isolation · Reproducible images and finite work

Take this idea with you

Locate the layer rejecting or failing to execute intent before changing permissions.

Create account

Reference: Resource quotas · CKAD Kubernetes v1.35