Organizing Manifests

Organizing BookNest's Manifests by Namespace

BookNest's manifests name no namespace, so the same files can deploy a copy into booknest-staging with kubectl 5,150 apply -n; Jenkins 8,793 has its own namespace (Connecting Jenkins). What is missing is the booknest namespace itself in Git 1,932 , created by hand in kubectl and kubeconfig, with limits that stop one workload from taking the whole worker:

k8s/namespace.yaml: the namespace, per-container defaults and a quotaYAML
apiVersion: v1
kind: Namespace
metadata: { name: booknest, labels: { app: booknest } }
---
apiVersion: v1
kind: LimitRange
metadata: { name: defaults, namespace: booknest }
spec:
  limits:
  - { type: Container, defaultRequest: { cpu: 50m, memory: 64Mi }, default: { memory: 256Mi } }
---
apiVersion: v1
kind: ResourceQuota
metadata: { name: booknest, namespace: booknest }
spec:
  hard: { requests.cpu: "1", requests.memory: 1Gi, limits.memory: 3Gi, pods: "20" }

The quota covers six API replicas plus a surge Pod, PostgreSQL 1,289 and the front end. Since it limits CPU requests, every Pod must now state one, and the LimitRange fills them in:

Applying the namespace policies and testing themShell
kubectl apply -f k8s/namespace.yaml 2>/dev/null
kubectl run defaults --image=localhost:33500/booknest-api:1.4 --restart=Never \
  -- sleep 1 >/dev/null
kubectl get pod defaults -o jsonpath='{.spec.containers[0].resources}{"\n"}'
kubectl run big --image=localhost:33500/booknest-api:1.4 --restart=Never --overrides='{"spec":
  {"containers": [{"name": "big", "image": "localhost:33500/booknest-api:1.4",
  "resources": {"requests": {"cpu": "2"}}}]}}' 2>&1 | fold -s -w 90
kubectl describe resourcequota booknest | tail -n +3
kubectl delete pod defaults >/dev/null
git add k8s/namespace.yaml
git commit -qm "Put the booknest namespace, its defaults and a quota in Git"
Output
namespace/booknest configured
limitrange/defaults created
resourcequota/booknest created
{"limits":{"memory":"256Mi"},"requests":{"cpu":"50m","memory":"64Mi"}}
Error from server (Forbidden): pods "big" is forbidden: exceeded quota: booknest,
requested: requests.cpu=2, used: requests.cpu=270m, limited: requests.cpu=1
Resource         Used    Hard
--------         ----    ----
limits.memory    1152Mi  3Gi
pods             6       20
requests.cpu     270m    1
requests.memory  480Mi   1Gi

kubectl apply adopted the hand-made namespace, with a warning about its missing last-applied annotation. The quota rejected the two-CPU Pod at admission, before scheduling. A Deployment that hits a quota reports it only as a FailedCreate event on its ReplicaSet, so check events when replicas go missing.