A service quota limits a resource count or capacity, while a request-rate limit governs how quickly API calls can be made. An otherwise correct deployment can stall when it needs another public address, volume, load balancer, or compute unit. Recovery capacity must be considered separately from steady state: a canary, replacement, and rollback may coexist for a period.
Provider quota preflight: reserve capacity for rollback and recovery
Operational decision
Before replacing a payment API node group, calculate peak simultaneous demand: existing nodes plus rollout surge plus the reserved recovery slice. Compare that demand with account and regional quota, current use, subnet addresses, and any organization policy that narrows eligibility. The read-only command lists an approved account's EC2 quota catalog; select and verify the exact quota code for the resource in use rather than assuming the catalog entry measures current consumption. Submit a limit change early when required and run a small allocation test in the target zone. Leave room for rollback after the new revision is placed. When capacity is unavailable during an incident, reduce nonessential workloads through a documented priority order instead of deleting healthy recovery assets at random. Record the accepted limit, observed use, and region for the release gate.
aws service-quotas list-service-quotas --service-code ec2 --query 'Quotas[].{Name:QuotaName,Code:QuotaCode,Value:Value}' --output table
aws ec2 describe-subnets --query 'Subnets[].{Subnet:SubnetId,Available:AvailableIpAddressCount,Zone:AvailabilityZone}' --output tableCost and verification
Holding spare address and compute capacity costs money, but a failed surge can prolong an outage. A quota listing alone cannot prove a resource can be allocated in the chosen zone or subnet. Reconcile actual use from the resource inventory and test the exact placement path. A rollback can need additional capacity even while the failed revision exists, so a plan that only fits steady state is incomplete.
Common Mistakes
- Do not confuse a rate throttle with an exhausted resource quota.
- Do not size only for the final replica count when old and new revisions overlap.
- Do not treat a quota listing as proof of zone-level availability.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Node autoscaling: make pending Pods schedulable before traffic rises
- Capacity and load tests: identify the next bottleneck
- Multi-region failover: define write ownership before moving traffic
- Terraform state: shared ownership and safe plans
