DevOps Professional · Module 1: Platform design and tenancy · Lab
Verify Quota and Limit Policy with Small Namespace Tasks
45 min hands-on · Core
A local KinD or k3d cluster; a demo namespace with a measured usage profile from a small fixture workload.
Local guide: run the steps below on your own machine in order, then check the validation list.
Objectives
- Set quota and limit ranges from the measured profile
- Show in-quota work accepted and over-quota rejected with numbers
- Trigger a policy rejection and quote its rule and fix
Step 1
Measure then bound
Run the fixture workload, record its requests profile, and set quota (need plus headroom) and limit ranges from the numbers. Write the profile and the chosen bounds down.
Step 2
Prove the bounds bite
Deploy inside quota and quote acceptance. Stage an oversized reservation and quote the rejection with its numbers. Attempt a forbidden image and quote the policy rule with its fix.
Step 3
Write the capacity path
Record where a quota rejection routes: what data a raise request needs, what right-sizing looks like, and why self-raising must not exist.
How to confirm it worked
- Measured profile with quota derived from it
- Acceptance and two rejections quoted with numbers
- Policy rejection quotes the rule and the fix
- Capacity path written, no self-raise route