問題文
A single namespace creates thousands of Pods and the nodes become unable to schedule anything else. Which combination of objects most directly limits this class of resource exhaustion?
選択肢
- An audit policy at the RequestResponse level for Pod creation, so each new Pod is recorded in full.
- A NetworkPolicy that denies egress from the namespace, together with a PriorityClass that gives the other namespaces a higher value, and their Pods are placed first when the scheduler has to choose.
- A readiness probe on every container in the namespace, so unhealthy Pods stop receiving traffic.
- A ResourceQuota that caps the object counts and the aggregate compute resources, together with a LimitRange that gives each container a default and a maximum.