Kubernetes and Cloud Native Associate (KCNA)Kubernetes FundamentalsMedium

A cluster administrator is performing routine maintenance on a Kubernetes worker node and needs to ensure that no new Pods are scheduled onto this node, but existing Pods should continue to run. Which `kubectl` command should they use?

  1. A`kubectl drain node-1`
  2. B`kubectl cordon node-1`
  3. C`kubectl delete node node-1`
  4. D`kubectl uncordon node-1`
Show answer & explanation

Correct answer: B. `kubectl cordon node-1`

The `kubectl cordon` command marks a node as unschedulable, preventing new Pods from being placed on it while allowing existing Pods to continue their operation. This is ideal for preparatory maintenance.

Why the other options are wrong

  • A. `kubectl drain` not only cordons a node but also evicts all existing Pods, which is not desired in this scenario.
  • C. `kubectl delete node` removes the node from the cluster entirely, which is too aggressive for simple maintenance.
  • D. `kubectl uncordon` reverses the `cordon` operation, making the node schedulable again, which is not the goal here.

kubectl cordon

The `kubectl cordon` command marks a specified node as 'unschedulable', preventing the Kubernetes scheduler from placing new Pods on it.

  • Does not affect Pods already running on the node.
  • Used as a preparatory step before maintenance or draining.
  • The node status changes to `SchedulingDisabled`.
  • Can be reversed with `kubectl uncordon`.

Memory trick: Cordon off the area, then Drain the old ones out.

More Kubernetes Fundamentals questions