A Deployment can be accepted while some of its Pods never appear. A ResourceQuota limits total resource use or object counts within a namespace. When a Pod creation request would violate a quota, the control plane rejects it with a 403 Forbidden response and an explanation. The Kubernetes scheduler watches for Pods that have already been created and need a node. A quota rejection happens before node placement.
The quota checks
A quota can cap the total CPU or memory requests and limits of Pods in a namespace. It can also cap the number of Pods. It tracks usage against each hard limit. A new Pod is rejected if its declarations would push an applicable total over that limit. A namespace can have more than one quota, and a quota can have a scope that limits which Pods it counts. Read the constraint named in the error before changing a manifest.
Missing declarations can cause a rejection too. When a namespace has a CPU or memory quota, new Pods may need requests or limits for that resource. A LimitRange can supply defaults for containers that omit them. Its constraints also apply during Pod admission, so check it when the error names a LimitRange.
Why the Deployment still exists
Kubernetes documents a case where creating the Deployment succeeds even though it cannot create all its Pods under the available quota. The Deployment object and its desired replica count do not prove that every Pod was admitted. Check the Deployment status to see what happened. ResourceQuota is independent of cluster capacity, so adding nodes alone does not raise a namespace’s hard limit.
What to do
Run kubectl describe deployment <name> -n <namespace> and read the failure message. Then run kubectl describe quota -n <namespace> to compare the relevant Used and Hard values. Check the Pod template’s requests and limits, the desired replica count, and any applicable LimitRange defaults. Adjust the declarations or replica count to fit the namespace’s policy. If the workload needs more of a constrained resource, ask the quota owner to review the hard limit. Retry the rollout and confirm that the expected Pods were created.

The Campfire
No commentsNobody has pulled up a log by this one yet. Be the first to say what you make of it.
Held for the desk. It appears after a look.