fix(k8s): Recreate singletons and trim requests for scheduler headroom
ci / lint-compose (push) Successful in 3s
ci / lint-actionlint (push) Successful in 1s
ci / lint-shellcheck (push) Successful in 2s
ci / lint-prettier (push) Successful in 3s
ci / lint-ruff (push) Successful in 1s
ci / lint-yaml (push) Successful in 2s
ci / lint-dockerfiles (push) Successful in 2s
ci / scan-deps (push) Successful in 18s
ci / test-backend (push) Successful in 8s
ci / test-frontend (push) Successful in 11s
ci / validate (push) Successful in 3s
renovate-ci / validate-renovate (push) Successful in 13s
ci / build (push) Successful in 1m30s

RollingUpdate with default maxSurge needs a spare pod the single node does not have (99% CPU requested), so multi-workload restarts end Pending and verify times out. Recreate on all replicas:1 Deployments (immich-server and bentopdf keep RollingUpdate at replicas 2). Also trims CPU/memory requests toward measured use (adguard, authentik, gitea, netbox, uptime-kuma, netbird-server) and gives traefik requests/limits so it is no longer BestEffort.
This commit is contained in:
forust committed 2026-09-28 22:36:46 +02:00
1 parent 76f39da90c
commit a6af69dca0
29 files changed
+79 -7

No files matched your search

+3 -1
View File
@@ -58,6 +58,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: adguard app: adguard
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
@@ -73,7 +75,7 @@ spec:
memory: "1.5Gi" memory: "1.5Gi"
cpu: "300m" cpu: "300m"
requests: requests:
memory: "1Gi" memory: "512Mi"
cpu: "50m" cpu: "50m"
ports: ports:
- containerPort: 3000 - containerPort: 3000
+6 -2
View File
@@ -34,6 +34,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: authentik-server app: authentik-server
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
@@ -53,7 +55,7 @@ spec:
resources: resources:
requests: requests:
memory: "768Mi" memory: "768Mi"
cpu: "300m" cpu: "100m"
limits: limits:
memory: "1.5Gi" memory: "1.5Gi"
cpu: "1000m" cpu: "1000m"
@@ -68,6 +70,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: authentik-worker app: authentik-worker
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
@@ -87,7 +91,7 @@ spec:
resources: resources:
requests: requests:
memory: "320Mi" memory: "320Mi"
cpu: "300m" cpu: "100m"
limits: limits:
memory: "768Mi" memory: "768Mi"
cpu: "700m" cpu: "700m"
+2
View File
@@ -9,6 +9,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: cfddns app: cfddns
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+2
View File
@@ -24,6 +24,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: checkmk app: checkmk
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+2
View File
@@ -9,6 +9,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: cloudflared app: cloudflared
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+2
View File
@@ -20,6 +20,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: convertx app: convertx
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+2
View File
@@ -20,6 +20,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: downtify app: downtify
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+2
View File
@@ -10,6 +10,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: edu-master-playwright app: edu-master-playwright
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+2
View File
@@ -10,6 +10,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: edu-master-session-keeper app: edu-master-session-keeper
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+2
View File
@@ -10,6 +10,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: edu-master-webinar-checker app: edu-master-webinar-checker
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+2
View File
@@ -20,6 +20,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: error-pages app: error-pages
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+3 -1
View File
@@ -24,6 +24,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: gitea app: gitea
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
@@ -48,7 +50,7 @@ spec:
resources: resources:
requests: requests:
memory: "320Mi" memory: "320Mi"
cpu: "300m" cpu: "100m"
limits: limits:
memory: "1Gi" memory: "1Gi"
cpu: "1300m" cpu: "1300m"
+2
View File
@@ -20,6 +20,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: glance app: glance
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+4
View File
@@ -20,6 +20,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: forust-homepage app: forust-homepage
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
@@ -67,6 +69,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: xdfnx-homepage app: xdfnx-homepage
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+2
View File
@@ -23,6 +23,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: immich-machine-learning app: immich-machine-learning
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+2
View File
@@ -20,6 +20,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: kener app: kener
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+2
View File
@@ -20,6 +20,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: metube app: metube
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+2
View File
@@ -20,6 +20,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: n8n app: n8n
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+5 -1
View File
@@ -39,6 +39,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: netbird-server app: netbird-server
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
@@ -92,7 +94,7 @@ spec:
resources: resources:
requests: requests:
memory: "128Mi" memory: "128Mi"
cpu: "250m" cpu: "100m"
limits: limits:
memory: "384Mi" memory: "384Mi"
cpu: "1000m" cpu: "1000m"
@@ -131,6 +133,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: netbird-dashboard app: netbird-dashboard
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+1 -1
View File
@@ -97,7 +97,7 @@ spec:
resources: resources:
requests: requests:
cpu: "100m" cpu: "100m"
memory: "1Gi" memory: "512Mi"
limits: limits:
cpu: "2" cpu: "2"
memory: "2Gi" memory: "2Gi"
+2
View File
@@ -23,6 +23,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: netronome app: netronome
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+2
View File
@@ -20,6 +20,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: portainer app: portainer
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+2
View File
@@ -20,6 +20,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: searxng app: searxng
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+2
View File
@@ -20,6 +20,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: termix app: termix
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+10
View File
@@ -36,6 +36,16 @@ additionalVolumeMounts:
- name: plugins - name: plugins
mountPath: /plugins-storage mountPath: /plugins-storage
# BestEffort (no requests) meant kubelet squeezed traefik first under node
# pressure, down to /ping timeouts and liveness restarts. Burstable instead.
resources:
requests:
cpu: "200m"
memory: "256Mi"
limits:
cpu: "1000m"
memory: "1Gi"
providers: providers:
kubernetesIngress: kubernetesIngress:
enabled: true enabled: true
+3 -1
View File
@@ -20,6 +20,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: uptime-kuma app: uptime-kuma
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
@@ -34,7 +36,7 @@ spec:
memory: "1Gi" memory: "1Gi"
cpu: "1" cpu: "1"
requests: requests:
memory: "512Mi" memory: "320Mi"
cpu: "100m" cpu: "100m"
ports: ports:
- containerPort: 3001 - containerPort: 3001
+4
View File
@@ -15,6 +15,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: forust-userbot app: forust-userbot
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
@@ -86,6 +88,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: anna-userbot app: anna-userbot
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+2
View File
@@ -20,6 +20,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: vaultwarden app: vaultwarden
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
+2
View File
@@ -27,6 +27,8 @@ spec:
selector: selector:
matchLabels: matchLabels:
app: xui app: xui
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels: