Skip to main content
rightsizing · gcp

GKE clusters where pod CPU requests fill little of the node capacity paid for

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

GKE Standard clusters pay for node VMs by machine type, while namespace quotas and pod requests decide how much of that capacity is used. ZopNight measures how much allocatable node CPU pod requests cover, but raises no finding yet: it prices a saving only from reclaimable node capacity, never from the $0.10-per-hour management fee.

Signal and threshold

How ZopNight evaluates GKE clusters where pod CPU requests fill little of the node capacity paid for.
Field Value
Rule IDsRC-1227
Categoryrightsizing
Severitylow
Metricnone — pure configuration read
Thresholdlow ratio of pod CPU requests to allocatable node CPU
SourceZopNight
Permissions usedcontainer.clusters.list · container.clusters.get · container.resourceQuotas.list · container.pods.list

Quota headroom that turns into idle nodes

A ResourceQuota caps what a namespace may request, for example requests.cpu, and a LimitRange sets defaults. When quotas are set far above real need, teams size node pools to honour the quota rather than the workload, and the nodes run mostly empty.

On GKE Standard the nodes are Compute Engine VMs billed by machine type. The cluster itself adds a flat management fee that GKE pricing puts at $0.10 per cluster per hour, whatever its size. Tightening quotas cannot reduce that fee; it can only let you run fewer or smaller nodes.

Comparing requests with node capacity

Terminal window
kubectl get resourcequota -A
kubectl describe quota --namespace=NAMESPACE
kubectl describe nodes | grep -A6 "Allocated resources"

The first two show each quota’s hard limits and current use. The third shows, per node, how much of the allocatable CPU and memory pods have requested.

How ZopNight measures packing

During inventory ZopNight adds up pod CPU requests across the cluster and divides by the nodes’ allocatable CPU. A low ratio means the cluster pays for far more node capacity than its workloads ask for, and the cluster is marked as overprovisioned. That mark is internal: no finding is raised yet, as the next section explains.

Why overprovisioned clusters show no dollar figure yet

The saving is node capacity that could be released: the unrequested share of allocatable CPU, priced at the node pool’s machine rate. ZopNight does not yet record the reclaimable quantity or price it against node pool cost. It will not use the cluster’s management fee as the base, and it will not report a $0 placeholder, so for now an overprovisioned cluster produces no finding. The commands above are the way to check packing by hand.

Reclaimable capacity at node rates

Terminal window
reclaimable CPU = allocatable node CPU x (1 - pod CPU requests / allocatable node CPU)
saving = reclaimable CPU priced at the node pool's machine rate

Tightening quotas and shrinking the pool

  1. List quotas and LimitRange objects per namespace and compare hard values with actual use.
  2. Lower quotas and default requests toward observed usage, one namespace at a time.
  3. Let the cluster autoscaler remove the nodes that empty out, or reduce the node pool size.
  4. For per-pool downsizing, see GKE Node Pool Machine Type Rightsizing.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·