Hands-on Lab·Kubernetes and Cloud Native Security Associate
Denial of Service and Resource Controls
Availability is the third of the three properties, and the one Kubernetes gives away by default: a container with no `resources` block may take the whole node. This guide measures that, then works outward through the container, the namespace, the apiserver and the node - reading each control off a live cluster.
Kubernetes Threat Model Guide 31 of 42 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 18 min
- Reviewed25 August 2026
Written against the versions above. Memory limits are enforced by the kernel's cgroup v2 controller, so exceeding one is an OOM kill at exit 137 rather than a Kubernetes decision. API Priority and Fairness has been on by default since 1.20.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA5001 | 192.168.0.41 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE01 | 192.168.0.42 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE02 | 192.168.0.43 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE03 | 192.168.0.44 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- guide 24 - quotas, which bound the namespace total.
- guide 10 - where the apiserver's own limits live.
-
The default, which is no ceiling at all
-
What the container can see of the node
-
One limit, and the kernel enforcing it
-
The three classes, and the one everybody gets wrong
-
The namespace control that fixes it for everyone
-
The apiserver defends itself, and always has
-
And the node keeps something back for itself