Mechanism of Project-Level Quotas
Rancher implements a static propagation model rather than a dynamic shared pool. When a Resource Quota is defined at the Project level, the Rancher Project controller automatically creates or updates a native Kubernetes ResourceQuota object within every namespace associated with that project.
Each namespace receives its own individual quota based on the project's specification. This means the limits are not "shared" in real-time across the project; instead, each namespace is independently capped by the values defined at the project level.
Consistency and Propagation Behavior
Because Rancher relies on a controller to reconcile the state between the Project object and the individual namespaces, updates are eventually consistent. The following behavior is expected during updates:
- Propagation Delay: When a project-level limit is changed, the controller must iterate through all member namespaces to update their respective
ResourceQuota objects. In environments with dozens or hundreds of namespaces, there is a measurable window where some namespaces reflect the new limit while others still hold the old one.
- Conflict Resolution: If a namespace already contains a manually defined
ResourceQuota, Rancher typically merges the two, enforcing the most restrictive (lowest) limit for each resource type.
- API Dependency: This process uses the standard Kubernetes ResourceQuota API. Rancher acts as the orchestrator, but the enforcement is handled natively by the Kubernetes API server.
Verification Steps
To verify how a project quota has been distributed to a specific namespace, use the following scoped commands:
# Identify the project quota via the Rancher API or UI, then check the namespace:
kubectl get resourcequota -n <namespace-name>
Compare the Hard limits in the output to the values set in the Rancher Project settings. If the values differ, check for a manually created quota in that namespace that may be overriding the project default.
Diagnostic Requirement
To provide a more precise estimate of propagation latency, please specify the Rancher version and the average number of namespaces per project, as controller reconciliation loops vary by version and scale.