skip to content
Alvin Lucillo

InsufficientVCPUQuota error during aks creation

/ 3 min read

Just because a VM is listed in the SKU list for the region does not mean it can be used immediately. For example, when Standard_D2s_v5 was used in the aks create command, an error returned that there’s insufficient vCPU quota.

az vm list-skus \
  --location southindia \
  --resource-type virtualMachines \
  --size Standard_D2s \
  --output table
ResourceType     Locations    Name             Zones    Restrictions
---------------  -----------  ---------------  -------  --------------
virtualMachines  SouthIndia   Standard_D2s_v3           None
virtualMachines  SouthIndia   Standard_D2s_v4           None
virtualMachines  SouthIndia   Standard_D2s_v5           None
virtualMachines  SouthIndia   Standard_D2s_v6           None
az aks create \
  --resource-group rg-aks-demo \
  --location southindia \
  --name aks-demo-cluster \
  --node-count 1 \
  --node-vm-size Standard_D2s_v5 \
  --tier free \
  --vm-set-type VirtualMachineScaleSets \
  --load-balancer-sku standard \
  --enable-managed-identity \
  --network-plugin azure \
  --no-ssh-key \
  --attach-acr acrdemoregistry
The behavior of this command has been altered by the following extension: aks-preview
The new node pool will enable SSH access, recommended to use '--ssh-access disabled' option to disable SSH access for the node pool to make it more secure.
(ErrCode_InsufficientVCPUQuota) Insufficient vcpu quota requested 2, remaining 0 for family standardDSv5Family for region southindia. If you want to increase the quota, please follow this instruction: https://learn.microsoft.com/en-us/azure/quotas/view-quotas. Surge nodes would also consume vcpu quota, please consider use smaller maxSurge or use maxUnavailable to proceed upgrade without surge nodes, details: aka.ms/aks/maxUnavailable.
Code: ErrCode_InsufficientVCPUQuota
Message: Insufficient vcpu quota requested 2, remaining 0 for family standardDSv5Family for region southindia. If you want to increase the quota, please follow this instruction: https://learn.microsoft.com/en-us/azure/quotas/view-quotas. Surge nodes would also consume vcpu quota, please consider use smaller maxSurge or use maxUnavailable to proceed upgrade without surge nodes, details: aka.ms/aks/maxUnavailable.

To find out why, we need to get the VM family of that VM and also of others so we could check them as well.

az vm list-skus \
  --location southindia \
  --resource-type virtualMachines \
  --query "[?starts_with(name, 'Standard_D2s_')].{
    Size:name,
    Family:family
  }" \
  --output table
Size             Family
---------------  ------------------
Standard_D2s_v3  standardDSv3Family
Standard_D2s_v4  standardDSv4Family
Standard_D2s_v5  standardDSv5Family
Standard_D2s_v6  StandardDsv6Family

Using az vm list-usage, we can see that standardDSv5Family has no available CPU for the region, but standardDSv4Family is available.

az vm list-usage \
  --location southindia \
  --query "[?name.value=='cores' || name.value=='standardDSv5Family' || name.value=='standardDSv4Family'].{Quota:name.localizedValue,Used:currentValue,Limit:limit}" \
  --output table
Quota                       Used    Limit
--------------------------  ------  -------
Total Regional vCPUs        0       10
Standard DSv4 Family vCPUs  0       10
Standard DSv5 Family vCPUs  0       0

Now after using the right VM, the AKS cluster has been created successfully.

az aks create \
  --resource-group rg-aks-demo \
  --location southindia \
  --name aks-demo-cluster \
  --node-count 1 \
  --node-vm-size Standard_D2s_v4 \
  --tier free \
  --vm-set-type VirtualMachineScaleSets \
  --load-balancer-sku standard \
  --enable-managed-identity \
  --network-plugin azure \
  --no-ssh-key \
  --attach-acr acrdemoregistry
The behavior of this command has been altered by the following extension: aks-preview
The new node pool will enable SSH access, recommended to use '--ssh-access disabled' option to disable SSH access for the node pool to make it more secure.
AAD role propagation done[############################################]  100.0000%
{
  "agentPoolProfiles": [
    {
      "count": 1,
      "name": "nodepool1",
      "provisioningState": "Succeeded",
      "vmSize": "Standard_D2s_v4"
    }
  ],
  "currentKubernetesVersion": "1.35.7",
  "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-aks-demo/providers/Microsoft.ContainerService/managedClusters/aks-demo-cluster",
  "identity": {
    "type": "SystemAssigned"
  },
  "location": "southindia",
  "name": "aks-demo-cluster",
  "networkProfile": {
    "loadBalancerSku": "standard",
    "networkPlugin": "azure"
  },
  "nodeResourceGroup": "MC_rg-aks-demo_aks-demo-cluster_southindia",
  "provisioningState": "Succeeded",
  "resourceGroup": "rg-aks-demo",
  "sku": {
    "name": "Base",
    "tier": "Free"
  }
}