# Debug Kubernetes "exceeded quota" ResourceQuota failures

## TL;DR
Run `kubectl describe quota -n [namespace]` and find the resource sitting at its hard limit. Free it up (delete completed jobs, drop unused PVCs, scale down) or ask the cluster admin to raise that specific limit. Admission control blocks the create the instant any tracked resource hits its cap, so there is no partial success to debug.

```text
Kubernetes "exceeded quota": ResourceQuota debugging for failed creates
```

## Steps

1. **Read the quota table.** Run `kubectl describe quota -n [namespace]` (or `kubectl describe resourcequota`).
   Expected: a used-vs-hard table where one line is at 100 percent. That line is your blocker.

2. **Find what is eating the quota.** Run `kubectl get pods,pvc,configmaps,secrets,services -n [namespace]` and compare against the maxed-out row.
   Expected: you identify the resource type that is actually exhausted.

3. **Free usage short-term.** Delete completed jobs, unused PVCs, stale configmaps, or scale a deployment down a notch.
   Expected: usage drops below hard and creates succeed again.

4. **Raise the quota long-term.** Send the cluster admin the numbers from step 1 and request an increase on the specific hard limit.
   Expected: the admin raises that limit and the namespace breathes again.

5. **Prevent recurrence.** Ask for a LimitRange with sane defaults so new workloads request reasonable amounts instead of burning quota by accident.
   Expected: future creates stay comfortably under quota.

## Use this when
- Creates fail with "exceeded quota" or "forbidden: exceeded quota"
- A new namespace with strict quotas blocks your first deploy
- CI suddenly cannot create jobs or pods that used to work

## Not for this skill when
- The error is a LimitRange rejection (that names min/max, not quota)
- Nodes are out of capacity (that is scheduling, not quota)
- The error is Forbidden for RBAC reasons (that is permissions)

## Variant phrasings
- kubernetes quota exceeded
- forbidden exceeded quota
- resourcequota debugging
- failed to create: exceeded quota

## Why it happens
ResourceQuota is enforced by admission control on every create, update, or delete that changes counted usage. The error names the quota object but not always which resource tripped it, which is why you have to read the used-vs-hard table yourself.

## Edge cases
- Terminated pods can still count against quota until they are fully removed from the API.
- Quotas count requests, not actual usage. Over-requesting burns quota even if the pod idles.
- Namespace quotas and cluster-scoped quotas are different objects. Make sure you are reading the right one.
- `kubectl describe quota` shows every quota in the namespace. The failing create may be blocked by one you were not watching.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_bGvsja3IWj2r7_RrQr9egw
