Skip to content

fix(kafka): bump default resourcesPreset to medium - #2537

Merged
Andrei Kvapil (kvaps) merged 1 commit into
mainfrom
fix/kafka-default-preset-medium
May 4, 2026
Merged

Andrei Kvapil (kvaps) merged 1 commit into
mainfrom
fix/kafka-default-preset-medium

Conversation

@IvanHunters

@IvanHunters IvanHunters commented Apr 29, 2026 •

Copy link
Copy Markdown
Collaborator

What this PR does

Changes the default resourcesPreset for both kafka and zookeeper in the Kafka managed application from small (1 CPU / 512Mi) to medium (1 CPU / 1Gi).

The small preset is no longer sufficient for the current Strimzi 0.45 / Kafka 3.9 image baseline:

  • Strimzi sets JVM heap to 50% of the container memory limit for Kafka and 75% for ZooKeeper. With a 512Mi limit that leaves only 256Mi (Kafka) or 128Mi (ZooKeeper) for the JVM non-heap.
  • Actual non-heap usage in the Kafka 3.9 image (Metaspace, code cache, direct buffers, JMX javaagent, embedded Jetty admin server for /v1/ready and KRaft migration endpoints, thread stacks) systematically exceeds those budgets at startup, triggering a cgroup OOM kill (exit 137) before the broker can connect to ZooKeeper.

Result on a fresh deployment with the previous default: every Kafka broker and every ZooKeeper pod ends up in CrashLoopBackOff, with lastState.terminated.reason: OOMKilled. ZooKeeper occasionally hits OOMKilled once quorum traffic ramps up, breaking the quorum and causing Kafka brokers to fail with ZooKeeperClientTimeoutException.

The medium preset (1Gi) is the smallest preset that gives both Kafka (heap 512Mi + ~500Mi non-heap budget) and ZooKeeper (heap 768Mi + 256Mi non-heap budget) enough headroom to start cleanly. Users who need more can still pick large, xlarge, or 2xlarge, or override resources explicitly.

The small preset is intentionally kept in the enum so existing deployments that pin resourcesPreset: small are not broken; only the default changes.

Release note

fix(kafka): default `resourcesPreset` for both Kafka and ZooKeeper is now `medium` (1 CPU / 1Gi). The previous default (`small`, 512Mi) is no longer sufficient under the current Strimzi 0.45 / Kafka 3.9 image and caused OOMKilled CrashLoopBackOff on fresh deployments. Existing deployments that explicitly set `resourcesPreset` are unaffected.

Summary by CodeRabbit

  • Chores

    • Updated default resource allocation preset from "small" to "medium" for Kafka and ZooKeeper components across CRD type definitions, Helm chart values, and JSON schema configurations.
  • Documentation

    • Updated parameter reference tables to reflect the new default resource preset values for both Kafka and ZooKeeper.

The `small` preset (512Mi) is not sufficient for the Strimzi 0.45 /
Kafka 3.9 image baseline. With the default Strimzi heap formula
(Kafka 50%, ZooKeeper 75% of container memory limit), the remaining
non-heap budget (Metaspace, code cache, direct buffers, JMX
javaagent, embedded Jetty admin server, KRaft migration endpoints,
thread stacks) consistently overflows the 512Mi cgroup limit at
startup, leading to OOMKilled (exit 137) and CrashLoopBackOff for
both Kafka and ZooKeeper pods.

Bump the default `resourcesPreset` for kafka and zookeeper from
`small` (512Mi) to `medium` (1Gi). The `small` preset stays in the
enum so existing deployments that pin it are unaffected; only the
default changes.

Signed-off-by: Ivan Okhotnikov <[email protected]>
@coderabbitai

coderabbitai Bot commented Apr 29, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 0f5971de-585c-487e-a9b3-a7387f48d6cf

📥 Commits

Reviewing files that changed from the base of the PR and between f45facc and c2884ea.

📒 Files selected for processing (5)
  • api/apps/v1alpha1/kafka/types.go
  • packages/apps/kafka/README.md
  • packages/apps/kafka/values.schema.json
  • packages/apps/kafka/values.yaml
  • packages/system/kafka-rd/cozyrds/kafka.yaml

📝 Walkthrough

Walkthrough

This pull request updates the default resourcesPreset value from "small" to "medium" for both Kafka and ZooKeeper components across the CRD type definitions, Helm chart configuration files, JSON schema, and documentation.

Changes

Cohort / File(s) Summary
CRD Type Definitions
api/apps/v1alpha1/kafka/types.go
Updated kubebuilder default annotations for Kafka.ResourcesPreset and ZooKeeper.ResourcesPreset from "small" to "medium".
Helm Chart Configuration
packages/apps/kafka/values.yaml, packages/apps/kafka/values.schema.json, packages/apps/kafka/README.md
Updated default value for kafka.resourcesPreset and zookeeper.resourcesPreset from "small" to "medium" in Helm values, schema defaults, and documentation reference tables.
CRD Schema Definition
packages/system/kafka-rd/cozyrds/kafka.yaml
Updated OpenAPI schema defaults for spec.application.kafka.resourcesPreset.default and spec.application.zookeeper.resourcesPreset.default from "small" to "medium".

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Poem

🐰 Hoppity-hop, the defaults align,
From small to medium, a change so fine!
Kafka and ZooKeeper now stand tall,
With balanced resources for one and all! 🎉

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: updating the default resourcesPreset for Kafka from small to medium, which is the primary modification across all affected files.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/kafka-default-preset-medium

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
Review rate limit: 7/8 reviews remaining, refill in 7 minutes and 30 seconds.

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions github-actions Bot added area/database Issues or PRs related to managed databases (postgres, mariadb, redis, etcd, kafka, clickhouse) kind/bug Categorizes issue or PR as related to a bug labels Apr 29, 2026
@IvanHunters
IvanHunters marked this pull request as ready for review April 29, 2026 14:50
@dosubot dosubot Bot added the size/M This PR changes 30-99 lines, ignoring generated files label Apr 29, 2026
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request addresses stability issues in fresh Kafka deployments caused by insufficient memory resources under the previous default configuration. By increasing the default resource preset, the application now provides adequate headroom for the JVM non-heap requirements in modern Kafka/Strimzi images, preventing startup failures while maintaining backward compatibility for existing deployments.

Highlights

  • Default Resource Preset Update: Updated the default resourcesPreset for both Kafka and ZooKeeper from small to medium to prevent OOMKilled errors on fresh deployments.
  • Documentation and Schema Updates: Synchronized the documentation, JSON schema, and default configuration values to reflect the new medium default.

🧠 New Feature in Public Preview: You can now enable Memory to help Gemini Code Assist learn from your team's feedback. This makes future code reviews more consistent and personalized to your project's style. Click here to enable Memory in your admin console.

Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment Gemini (@gemini-code-assist) Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on Gemini (@gemini-code-assist) comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the default resource preset for Kafka and ZooKeeper from "small" to "medium" across the API types, Helm chart values, schema, and documentation. I have no feedback to provide.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Clean default change. All generated artifacts (CRD types, JSON schema, cozyrd OpenAPI, README, values.yaml) are consistent, and existing deployments with an explicit resourcesPreset are unaffected since kubebuilder defaults only apply on CREATE. The Strimzi heap-fraction reasoning (50% Kafka, 75% ZooKeeper) matches upstream DYNAMIC_HEAP_FRACTION defaults; at 512Mi the non-heap budget (256Mi for Kafka, 128Mi for ZooKeeper) is too tight for the Java 17 footprint of Strimzi 0.45 / Kafka 3.9, and doubling memory while holding CPU is a conservative, reversible fix. LGTM.

@dosubot dosubot Bot added the lgtm This PR has been approved by a maintainer label Apr 29, 2026
@kvaps
Andrei Kvapil (kvaps) merged commit 0b70197 into main May 4, 2026
21 of 23 checks passed
@kvaps
Andrei Kvapil (kvaps) deleted the fix/kafka-default-preset-medium branch May 4, 2026 18:40
@myasnikovdaniil myasnikovdaniil added the kind/backport Categorizes issue or PR as requiring a backport to the current release line label May 7, 2026
@github-actions

github-actions Bot commented May 7, 2026

Copy link
Copy Markdown

Backport failed for release-untagged-34c5e929a0cb9154bef0.undefined: couldn't find remote ref release-untagged-34c5e929a0cb9154bef0.undefined.
Please ensure that this Github repo has a branch named release-untagged-34c5e929a0cb9154bef0.undefined.

@myasnikovdaniil myasnikovdaniil added kind/backport Categorizes issue or PR as requiring a backport to the current release line and removed kind/backport Categorizes issue or PR as requiring a backport to the current release line labels May 7, 2026
@github-actions

github-actions Bot commented May 7, 2026

Copy link
Copy Markdown

Successfully created backport PR for release-1.3:

myasnikovdaniil added a commit that referenced this pull request May 7, 2026
…dium (#2589)

# Description
Backport of #2537 to `release-1.3`.
Aleksei Sviridkin (lexfrei) added a commit that referenced this pull request Sep 18, 2026
## What this PR does

The barman-cloud plugin injects its sidecar with no resource requests or
limits. What that means depends on the namespace. A tenant with
`resourceQuotas` set ships a `LimitRange` that defaults containers to
128Mi (`packages/apps/tenant/templates/quota.yaml`), so there the
sidecar inherits that default and is OOMKilled mid-backup. A namespace
without a `LimitRange`, which is `cozy-keycloak` and any tenant that
leaves `resourceQuotas` empty, gave the sidecar no requests and no limit
at all, so nothing reserved memory for it and nothing bounded it. The
failure on the tenant path is quiet from the control plane: the
`ObjectStore` stays healthy, the `Cluster` stays `Ready`, and only the
backup fails.

Observed on a 1.6 cluster while backing up a 38 MB database:
`lastState.terminated.reason: OOMKilled`, `exit 137`, four restarts on
the sidecar, and a cgroup high-water mark of 254 MiB.
`container_memory_working_set_bytes` peaked at only 64 MiB over the same
window — it is sampled, and it misses the spike that actually triggers
the kill, which is why the working-set number does not explain the
failure on its own.

Both paths that build an ObjectStore now carry resources:

- `cozy-lib.barman.sidecarConfiguration`, used by
`packages/apps/postgres` for the backup and recovery ObjectStores and by
`packages/system/keycloak`;
- `barmanSidecarConfiguration()` in
`internal/backupcontroller/cnpgstrategy_controller.go`, which builds the
platform's own ObjectStore on the `useSystemBucket=true` path.

Requests are 100m/256Mi with a 1Gi memory limit on every caller: 256Mi
holds the measured working set and 1Gi is four times the measurement,
which is also the ceiling a caller without a LimitRange gets where it
had none. No CPU limit is set, following the `entityOperator` precedent
in `packages/apps/kafka/templates/kafka.yaml`: a throttled sidecar
stalls WAL archiving instead of failing it, which is harder to notice
than an outright failure. Measured CPU peak was 50 mCPU. Inside a tenant
the limit is charged against the `ResourceQuota` `limits.memory` budget,
1Gi per instance pod; a 4Gi tenant spends a quarter of it per Postgres
instance.

The helper is renamed from `checksumSidecarConfiguration` to
`sidecarConfiguration`, because it no longer carries only the checksum
pin and its name and doc comment would otherwise be wrong.

Tests cover both paths and both render sites: a new helm suite in
`packages/apps/postgres`, extra assertions in the existing keycloak
suite, an assertion in the controller test, and a deepcopy test for the
new field. Each of them fails against the unfixed sources.

One thing this PR deliberately does not do. This is the fifth time the
128Mi tenant default has been worked around per component — kafka and
zookeeper presets (#2537), the kafka entity-operator (#2934), the
cert-manager cainjector (#3199), and the note carried in the
etcd-operator values. Whether the default itself should move looks like
your call rather than something to fold into a fix for one sidecar, so
it is left alone here.

### Screenshots

Not a UI change.

### Downstream repositories

Walked the trigger map in `docs/agents/contributing.md` against the
diff, entry by entry. The change touches one cozy-lib helper, the two
chart templates that include it, one Go function, and tests. It adds,
renames or removes no package; changes no `values.yaml`,
`values.schema.json`, `Chart.yaml` or `README.md`, so no version enum,
default or generated artifact moves; changes no `ApplicationDefinition`
semantics, no `release.prefix`, no output Secret or Service name;
touches no CRD, no namespace, no `hack/` file, no telemetry metric or
label, no `cozy-proxy` annotation, no node or network requirement, and
no commit or PR convention. No entry matches.

- [x] No downstream repository is affected by this change

### Release note

```release-note
fix(backups): give the barman-cloud sidecar its own resources
The barman-cloud sidecar was injected without resource requests or limits, so in tenant namespaces it inherited the 128Mi `LimitRange` default and was OOMKilled during backups while the `ObjectStore` and the `Cluster` both stayed healthy. It now requests 100m/256Mi and caps memory at 1Gi on the chart path and on the platform's Go path alike; in namespaces without a LimitRange the sidecar had no limit before and gets the same 1Gi ceiling.
```


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added explicit CPU and memory resource settings for barman-cloud
backup and recovery sidecars.
- Backup sidecars request 100m CPU and 256Mi memory, with a 1Gi memory
limit.
  - Recovery sidecars receive a 1Gi memory limit.
  - Preserved the S3 checksum configuration.

- **Bug Fixes**
- Prevented sidecars from inheriting unsuitable tenant resource limits.
- Ensured resource settings are preserved when backup configuration is
copied.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/database Issues or PRs related to managed databases (postgres, mariadb, redis, etcd, kafka, clickhouse) kind/backport Categorizes issue or PR as requiring a backport to the current release line kind/bug Categorizes issue or PR as related to a bug lgtm This PR has been approved by a maintainer size/M This PR changes 30-99 lines, ignoring generated files

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants