Bound resource requests, namespace consumption, and autoscaling so workloads cannot exhaust cluster or cloud capacity.
Bound Workload Resource Consumption
CCC.K8S.CN13 · Resource
Related Capabilities
| ID | Title | Description |
|---|---|---|
| CCC.Core.CP04 | Transaction Rate Limits | The service can throttle, delay, or reject excess requests when transactions exceed a user-specified rate limit, and always provides industry-standard throughput up to that limit. |
| CCC.Core.CP16 | Budgeting | The service may be configured to take a user-specified action when a spending threshold is met or exceeded on a child or networked resource. |
| CCC.Core.CP19 | Child Resource Scaling | The service may be configured to scale child resources automatically or on-demand. |
Related Threats
| ID | Title | Description |
|---|---|---|
| CCC.Core.TH12 | Resource Constraints are Exhausted | Exceeding the resource constraints through excessive consumption, resource-intensive operations, or lowering of rate-limit thresholds can impact the availability of elements such as memory, CPU, or storage. This may disrupt availability of the service or child resources by denying the associated functionality to users. If the impacted system is not designed to expect such a failure, the effect could also cascade to other services and resources. |
Assessment Requirements
| ID | Text | Applicability |
|---|---|---|
| CCC.K8S.CN13.AR01 | When a workload is admitted, every container MUST define approved CPU and memory requests and limits. | tlp-clear, tlp-green, tlp-amber, tlp-red |
| CCC.K8S.CN13.AR02 | When a user workload namespace is active, ResourceQuota objects MUST bound its aggregate CPU, memory, storage, workload count, and externally exposed services. | tlp-clear, tlp-green, tlp-amber, tlp-red |
| CCC.K8S.CN13.AR03 | When workload or node autoscaling is enabled, every autoscaler MUST define an approved maximum replica or capacity boundary. | tlp-clear, tlp-green, tlp-amber, tlp-red |
Guideline Mappings
| Framework | ID | Remarks |
|---|---|---|
| NIST_800_53 | SC-5 | Denial-of-service Protection |