What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Goldilocks helps you find a practical starting point for Kubernetes CPU and memory requests by showing recommendations produced by Vertical Pod Autoscaler (VPA). Begin in observation mode: compare those recommendations with workload behavior and cluster capacity before deciding whether VPA should change pods automatically. Recommendations are guidance, not a guarantee of lower cost or schedulable pods.

How to right-size workloads with Goldilocks and VPA

Goldilocks creates VPA objects in recommendation mode for workloads in the namespaces you enable, then presents their suggested resource requests in a dashboard. VPA bases recommendations on historical and current consumption; it can suggest reducing requests that exceed observed needs or increasing requests that are too low. Neither tool establishes a guaranteed savings percentage: the result depends on the workload, requests, limits, node capacity, and how you act on the recommendations.

VPA has three relevant components: the recommender calculates recommendations, the updater can update or evict existing pods according to the selected mode, and the admission controller applies requests to newly created pods. You can also inspect recommendations in the VPA object’s status. See the VPA component and architecture documentation and the Goldilocks project repository.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do I set the right CPU and memory requests for Kubernetes workloads?

Use recommendations as evidence to review, not as an unquestioned target. A useful request has to reflect workload demand while still allowing the scheduler to place the pod on available nodes. Review CPU and memory separately, and consider the application’s behavior during peaks as well as typical operation.

  1. Install VPA. Follow the official VPA installation procedure for your cluster and pin compatible versions. Create a VPA resource targeting each controller whose containers you want to observe.
  2. Enable Goldilocks for the namespaces under review. Its workflow creates recommendation-mode VPAs so you can inspect suggested requests in the dashboard. Check the Goldilocks installation instructions for current chart, image, and configuration details. The repository notes that images from v4.15.0 use us-docker.pkg.dev/fairwinds-ops/oss/goldilocks; the previous Quay image is deprecated, and image tags are immutable. Use a full version tag or digest rather than assuming a mutable tag will update.
  3. Compare the suggestion with real workload evidence. Check current requests, peak-period behavior, restart and OOM history, and node and quota headroom. VPA documentation describes memory recommendation adjustments related to OOM events, as well as constraints that can shape recommendations; review the VPA examples and configuration.
  4. Keep the first phase observational. Review the recommendations before enabling updates. Choose an explicit VPA update mode only after considering disruption tolerance, replica capacity, and PodDisruptionBudgets.
  5. Constrain and validate where appropriate. Use VPA resource policies, LimitRange constraints, or maximum-allowed settings where they fit your needs. Then check the sum of requests across all containers in each pod against the largest eligible node and the namespace quota.
  6. Check autoscaling interactions. Ensure an HPA does not control the same CPU or memory metric that VPA is changing. VPA documentation describes using a different resource metric, or custom or external HPA metrics, as the supported pattern.
  7. Monitor after any change. Watch for pending pods, restarts, OOM kills, CPU throttling, and workload latency. Revisit requests if actual behavior shows that the recommendation is unsuitable.

Choose between recommendations and automatic updates

Goldilocks surfaces suggestions; VPA update modes determine whether those suggestions affect pods. The right choice depends on how much operational review the team can provide and how much disruption the application can tolerate.

Approach What happens Trade-off
Observation with Goldilocks VPA reports recommendations for review; you choose whether and when to edit workload requests. Requires human review and a rollout, but avoids VPA-driven pod updates during the observation phase.
VPA updates VPA applies behavior according to its configured update mode; the updater may update or evict existing pods, while admission applies requests to newly created pods. Reduces manual work, but can disrupt workloads and create pods that cannot be scheduled.

The VPA quick start marks Auto deprecated and describes Recreate as the default, including eviction when requests differ significantly from recommendations. Do not rely on an implicit default: select an explicit mode supported by your deployed VPA release, and confirm its behavior in that release’s quick start and documentation.

Recreation or in-place updates?

With recreation, VPA can evict a pod so it can be created again with changed requests. That recreation is not guaranteed to succeed: the pod might remain pending if the new requests exceed available node capacity or quota. Account for replica count, application availability, and PodDisruptionBudgets before enabling a mode that can evict pods.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In-place vertical scaling is not universally available. The VPA features documentation says it requires Kubernetes 1.33 or later with the InPlacePodVerticalScaling feature gate enabled; VPA 1.4.0 requires the InPlaceOrRecreate feature gate. These requirements are version-sensitive, so verify them against the release documentation for both Kubernetes and VPA before planning a rollout. See the VPA features documentation.

Update approach Availability and compatibility What to verify
Recreate Can evict pods and depends on successful rescheduling; disruption is possible. Replica capacity, PodDisruptionBudgets, node fit, quota, and the configured VPA mode.
In-place May avoid pod recreation, but depends on Kubernetes version, VPA version, and feature gates. Version-specific feature requirements and behavior in the deployed release documentation.

Keep recommendations schedulable

A recommendation can be reasonable for an individual container and still make its pod impossible to schedule. Per-container caps do not ensure that a multi-container pod’s aggregate requests fit on the largest node available to it. Check the combined requests of all containers, eligible node sizes, and quota before applying a change.

Resource policies and LimitRange constraints can shape recommendations, while VPA’s max-allowed recommender settings can help limit them. These controls reduce some scheduling risks; they do not replace checking aggregate pod requirements against the actual cluster. VPA documents these options in its examples and API documentation. The API also supports excluding selected containers from recommendations.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check HPA and admission webhook interactions

Do not use VPA and HPA to control the same CPU or memory metric at the same time: their actions can conflict. A documented pattern is to assign them different resource metrics or use custom or external metrics for HPA. Also check whether VPA’s admission webhook conflicts with other admission webhooks in your cluster. Consult the VPA known limitations before rollout.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.