BookNest's manifests name no namespace, so the same files can deploy a copy into booknest-staging with kubectl 5,150 apply -n; Jenkins 8,793 has its own namespace (Connecting Jenkins). What is missing is the booknest namespace itself in Git 1,932 , created by hand in kubectl and kubeconfig, with limits that stop one workload from taking the whole worker:
apiVersion: v1
kind: Namespace
metadata: { name: booknest, labels: { app: booknest } }
---
apiVersion: v1
kind: LimitRange
metadata: { name: defaults, namespace: booknest }
spec:
limits:
- { type: Container, defaultRequest: { cpu: 50m, memory: 64Mi }, default: { memory: 256Mi } }
---
apiVersion: v1
kind: ResourceQuota
metadata: { name: booknest, namespace: booknest }
spec:
hard: { requests.cpu: "1", requests.memory: 1Gi, limits.memory: 3Gi, pods: "20" }The quota covers six API replicas plus a surge Pod, PostgreSQL 1,289 and the front end. Since it limits CPU requests, every Pod must now state one, and the LimitRange fills them in:
kubectl apply -f k8s/namespace.yaml 2>/dev/null
kubectl run defaults --image=localhost:33500/booknest-api:1.4 --restart=Never \
-- sleep 1 >/dev/null
kubectl get pod defaults -o jsonpath='{.spec.containers[0].resources}{"\n"}'
kubectl run big --image=localhost:33500/booknest-api:1.4 --restart=Never --overrides='{"spec":
{"containers": [{"name": "big", "image": "localhost:33500/booknest-api:1.4",
"resources": {"requests": {"cpu": "2"}}}]}}' 2>&1 | fold -s -w 90
kubectl describe resourcequota booknest | tail -n +3
kubectl delete pod defaults >/dev/null
git add k8s/namespace.yaml
git commit -qm "Put the booknest namespace, its defaults and a quota in Git"namespace/booknest configured
limitrange/defaults created
resourcequota/booknest created
{"limits":{"memory":"256Mi"},"requests":{"cpu":"50m","memory":"64Mi"}}
Error from server (Forbidden): pods "big" is forbidden: exceeded quota: booknest,
requested: requests.cpu=2, used: requests.cpu=270m, limited: requests.cpu=1
Resource Used Hard
-------- ---- ----
limits.memory 1152Mi 3Gi
pods 6 20
requests.cpu 270m 1
requests.memory 480Mi 1Gikubectl apply adopted the hand-made namespace, with a warning about its missing last-applied annotation. The quota rejected the two-CPU Pod at admission, before scheduling. A Deployment that hits a quota reports it only as a FailedCreate event on its ReplicaSet, so check events when replicas go missing.