kubelet使用了一个Node Allocatable

/var/lib/kubectl/config.yaml

#添加限制kube资源

enforceNodeAllocatable:

 - pods

 - kube-reserved

kubeReserved:

 cpu: 1000m

 memory: 1Gi

kubeReservedCgroup: /kube.slice

kubelet启动二进制文件添加

ExecStartPre=-/bin/mkdir /sys/fs/cgroup/cpu,cpetacct/kube.slice

ExecStartPre=-/bin/mkdir /sys/fs/cgroup/systemd/kube.slice

ExecStartPre=-/bin/mkdir /sys/fs/cgroup/pids/kube.slice

ExecStartPre=-/bin/mkdir /sys/fs/cgroup/hugetlb/kube.slice

ExecStartPre=-/bin/mkdir /sys/fs/cgroup/cpu,cpuacct/kube.slice

ExecStartPre=-/bin/mkdir /sys/fs/cgroup/cpuset/kube.slice

ExecStartPre=-/bin/mkdir /sys/fs/cgroup/memory/kube.slice

参考https://www.cnblogs.com/apink/p/15138971.html 

测试有效能有效限制