Schedule icon
Commands icon
Docker icon
If icon
SlackIncomingWebhook icon
Log icon

Audit Kubernetes Resource Quotas

Check namespace resource quota usage against hard limits and alert Slack when a namespace nears the wall.

Categories
CloudInfrastructureinfrastructure

A deploy failing on exceeded quota is a surprise only because nobody watched the ratio. This blueprint reads every resource quota, computes usage against hard limits, and alerts Slack past your threshold.

How it works

  1. audit_quotas (io.kestra.plugin.scripts.shell.Commands on the kubectl image) pulls kubectl get resourcequotas -A -o json and emits the hot namespaces via the ::{"outputs": ...}:: protocol.
  2. hot_found (io.kestra.plugin.core.flow.If) branches to alert_hot or log_ok.
  3. The errors block alerts on failure.
  4. Trigger: a disabled daily Schedule.

What you get

  • Per-namespace pressure visibility.
  • Early warning before deploys block.

Who it's for

  • Multi-tenant clusters with per-namespace quotas.
  • Teams deploying into quota-constrained namespaces.

Why orchestrate this with Kestra

kubectl prints JSON; the flow turns it into a scheduled decision with history. The next step (raise the quota, cordon the namespace, open a ticket) is one task away.

Prerequisites

  • A Kestra Worker with cluster access (kubeconfig or in-cluster service account).
  • A Slack webhook.

Secrets

  • SLACK_WEBHOOK_URL: webhook for hot-quota and failure alerts.

Quick start

  1. Add the Slack webhook secret.
  2. Set threshold_percent.
  3. Run once and read hot_namespaces.
  4. Enable the daily schedule.

How to extend

  • Track quota growth over time in KV.
  • Auto-bump a staging quota and file a ticket.
  • Include LimitRange coverage checks.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.