ResourceQuota caps a namespace; LimitRange gives every container sensible defaults.
They act at admission, before the scheduler, which creates two different-looking failures that are easy to confuse.
quota and defaults for namespace shop
kind: ResourceQuota spec: hard: requests.cpu: "20" requests.memory: 40Gi limits.cpu: "40" pods: "50" --- kind: LimitRange spec: limits: - type: Container defaultRequest: {cpu: 250m, memory: 256Mi} default: {cpu: 500m, memory: 512Mi} max: {cpu: "2", memory: 4Gi}
Quota exceeded
Rejected at admission. The Pod object is never created, so kubectl get pods shows nothing. Look at the error and kubectl describe resourcequota.
No node fits
Admitted, created, then Pending with a FailedScheduling event. The Pod exists and can be described.
Why LimitRange
A forgotten resources block would make a Pod BestEffort. The default request lifts it to Burstable automatically.
Quota is a policy decision (this namespace may not have more); scheduling failure is a capacity decision (no node can host this right now).