ResourceQuota for the whole vcluster¶
One ResourceQuota caps the entire virtual cluster. vcluster renders policies.resourceQuota as a real ResourceQuota in the host namespace, so the sum of every pod across every virtual namespace is bounded by one object.
- enable the quota and set the ceilings.
- enable a LimitRange too. A CPU or memory quota only admits a pod that declares requests; a pod with no requests is rejected by the quota. The LimitRange supplies default requests so those pods still count against the quota instead of being denied.
- apply with Helm.
- both objects land in the host namespace.
- watch the ephemeral-storage default on small nodes. vcluster's default LimitRange requests 3Gi ephemeral-storage per container. On a node with little disk, a handful of pods can exhaust it and go
Pending. LowerdefaultRequest.ephemeral-storageif that bites.
Set limitRange.enabled: auto to turn the LimitRange on automatically whenever the ResourceQuota is on.
Manifests¶
values.yaml
https://www.vcluster.com/docs/vcluster/configure/vcluster-yaml/policies/resource-quota https://www.vcluster.com/docs/vcluster/configure/vcluster-yaml/policies/limit-range