Work outside in: get, then describe and events, then logs, then debug. An API canary asking for two CPUs fails before any Pod exists:
kubectl create deployment api-canary --image=localhost:33500/booknest-api:1.4 \
--dry-run=client -o yaml \
| yq '.spec.template.spec.containers[0].resources.requests.cpu = "2"' \
| kubectl apply -f - >/dev/null 2>&1
sleep 5; kubectl get deployment api-canary; kubectl get pods -l app=api-canary
kubectl events --for=replicaset/$(kubectl get rs -l app=api-canary -o name | cut -d/ -f2) \
| grep -m1 -o 'exceeded quota: .*' | fold -s -w 95
kubectl delete deployment api-canary >/dev/nullOutput
NAME READY UP-TO-DATE AVAILABLE AGE api-canary 0/1 0 0 5s No resources found in booknest namespace. exceeded quota: booknest, requested: requests.cpu=2, used: requests.cpu=520m, limited: requests.cpu=1
The quota of Namespaces and Labels rejected every Pod at admission; only the ReplicaSet's FailedCreate event says so. A Pending Pod points to the scheduler (FailedScheduling), one Running but not Ready to its readiness probe (Unhealthy).