pods is forbidden: failed quota: must specify limits.cpu,limits.memory,requests.cpu,requests.memory
A ResourceQuota on the namespace covers CPU/memory, so every pod must declare those requests/limits — and this one doesn’t.
Seen on:
Kubernetes
Meaning
When a quota tracks compute resources, pods without explicit values are rejected. Add resources to every container (including init and sidecar containers), or have the admin add a LimitRange with defaults.
Common causes
- Container without resources.requests/limits
- Init or injected sidecar container missing them
- No LimitRange providing defaults
⚡ Quick fix
- Add requests and limits to all containers
- Create a LimitRange with default values
- Check injected sidecars (Istio, Vault)
Detailed fix by platform
YAML
- bash
resources: requests: { cpu: 100m, memory: 128Mi } limits: { cpu: 500m, memory: 256Mi }
Kubernetes
- bash
kubectl create -n app -f - <<'EOF' apiVersion: v1 kind: LimitRange metadata: { name: defaults } spec: limits: - type: Container default: { cpu: 500m, memory: 256Mi } defaultRequest: { cpu: 100m, memory: 128Mi } EOF
How to diagnose
- Containers — Which container lacks resources?
- LimitRange — kubectl get limitrange -n app
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Kubernetes
- error converting YAML to JSON error converting YAML to JSON: yaml: line 12: did not find expected key
- is waiting to start Error from server (BadRequest): container "x" in pod "y" is waiting to start: ContainerCreating
- kubectl connection refused kubectl: The connection to the server localhost:8080 was refused — did you specify the right host or port?
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026