From 2a4f215546d7c5c9b1d2fdea5afa8fe7ed2f4811 Mon Sep 17 00:00:00 2001 From: mr-forust Date: Mon, 28 Sep 2026 10:20:24 +0200 Subject: [PATCH] fix(k8s): bring the over-reserved memory limits down to measured use Six pods reserved far more memory than they have ever touched. uptime-kuma held a 3Gi limit against 469M of measured p95, metube 2Gi against 72M, convertx 1.5Gi against 85M, netbird-server 1Gi against 97M, searxng 700Mi against 134M and bentopdf 700Mi against 4M. Every one of them is a ceiling the scheduler counts against the node while the memory sits unused. Requests move down with the limits but never below the measured p95, so none of these becomes an eviction candidate as a side effect of being right-sized. The limits keep between 2.2x and 11.6x over the observed max, which is the figure that decides whether a pod gets OOM-killed during a burst. Net effect across the six: requests -557M, limits -4.6Gi, all of it ceiling that was never in use. This is the first change that actually gives memory back. CPU limits are left exactly as they were. They were not part of the sizing pass, they are not being hit on a node sitting at 5% CPU, and removing them is a separate decision from moving memory. Verified: each limit is above the container's own observed max and each request is above its p95, and 16/16 local gates pass. --- converters/k8s/bentopdf.yaml | 5 +++-- converters/k8s/convertx.yaml | 5 +++-- metube/k8s/metube.yaml | 5 +++-- netbird/k8s/netbird.yaml | 5 +++-- searxng/k8s/searxng.yaml | 5 +++-- uptime-kuma/k8s/uptime-kuma.yaml | 3 ++- 6 files changed, 17 insertions(+), 11 deletions(-) diff --git a/converters/k8s/bentopdf.yaml b/converters/k8s/bentopdf.yaml index 702bc2b..1a8d19c 100644 --- a/converters/k8s/bentopdf.yaml +++ b/converters/k8s/bentopdf.yaml @@ -31,12 +31,13 @@ spec: name: bentopdf ports: - containerPort: 8080 + # p95 4M, max 11M over 7 days. Was 50Mi/700Mi. resources: requests: - memory: "50Mi" + memory: "32Mi" cpu: "50m" ephemeral-storage: "100Mi" limits: - memory: "700Mi" + memory: "128Mi" cpu: "700m" ephemeral-storage: "5Gi" diff --git a/converters/k8s/convertx.yaml b/converters/k8s/convertx.yaml index 9fc3fec..cf37271 100644 --- a/converters/k8s/convertx.yaml +++ b/converters/k8s/convertx.yaml @@ -38,13 +38,14 @@ spec: volumeMounts: - mountPath: /data name: data + # p95 85M, max 136M over 7 days, spikes while converting. Was 250Mi/1.5Gi. resources: requests: - memory: "250Mi" + memory: "128Mi" cpu: "100m" limits: cpu: "1500m" - memory: "1.5Gi" + memory: "512Mi" volumes: - name: data persistentVolumeClaim: diff --git a/metube/k8s/metube.yaml b/metube/k8s/metube.yaml index e8389cc..eacb87a 100644 --- a/metube/k8s/metube.yaml +++ b/metube/k8s/metube.yaml @@ -36,12 +36,13 @@ spec: volumeMounts: - name: downloads mountPath: /downloads + # p95 72M, max 80M over 7 days. Was 600Mi/2Gi. resources: requests: - memory: "600Mi" + memory: "96Mi" cpu: "400m" limits: - memory: "2Gi" + memory: "384Mi" cpu: "1700m" volumes: - name: downloads diff --git a/netbird/k8s/netbird.yaml b/netbird/k8s/netbird.yaml index 3e19fe7..cd76e91 100644 --- a/netbird/k8s/netbird.yaml +++ b/netbird/k8s/netbird.yaml @@ -88,12 +88,13 @@ spec: periodSeconds: 30 timeoutSeconds: 5 failureThreshold: 5 + # p95 97M, max 102M over 7 days. Was 256Mi/1Gi. resources: requests: - memory: "256Mi" + memory: "128Mi" cpu: "250m" limits: - memory: "1Gi" + memory: "384Mi" cpu: "1000m" volumes: - name: netbird-data diff --git a/searxng/k8s/searxng.yaml b/searxng/k8s/searxng.yaml index 23f1d1c..4f5957b 100644 --- a/searxng/k8s/searxng.yaml +++ b/searxng/k8s/searxng.yaml @@ -38,12 +38,13 @@ spec: volumeMounts: - name: cache mountPath: /var/cache/searxng + # p95 134M, max 145M over 7 days. Was 300Mi/700Mi. resources: requests: - memory: "300Mi" + memory: "160Mi" cpu: "30m" limits: - memory: "700Mi" + memory: "512Mi" cpu: "500m" volumes: - name: cache diff --git a/uptime-kuma/k8s/uptime-kuma.yaml b/uptime-kuma/k8s/uptime-kuma.yaml index f2e1055..33dfde8 100644 --- a/uptime-kuma/k8s/uptime-kuma.yaml +++ b/uptime-kuma/k8s/uptime-kuma.yaml @@ -28,9 +28,10 @@ spec: containers: - name: uptime-kuma image: louislam/uptime-kuma:2.5.5 + # p95 469M, max 471M over 7 days. Was a 3Gi limit on 469M of real use. resources: limits: - memory: "3Gi" + memory: "1Gi" cpu: "1" requests: memory: "512Mi"