Kubernetes and Cloud Native Associate (KCNA)Kubernetes FundamentalsMedium
A cluster administrator needs to ensure that a specific set of Pods within a Deployment always runs on nodes equipped with GPUs. They have already labeled the appropriate nodes with `gpu=true`. Which section of the Pod's YAML manifest should be modified to enforce this scheduling constraint?
- A`spec.securityContext`
- B`spec.containers.resources.limits`
- C`spec.tolerations`
- D`spec.affinity.nodeAffinity`
Show answer & explanationAnswer & explanation
Correct answer: D. `spec.affinity.nodeAffinity`
`nodeAffinity` is the mechanism in Kubernetes to constrain Pods to nodes with specific labels. This is ideal for ensuring Pods run on hardware like GPUs.
Why the other options are wrong
- A. Security context defines privilege and access control settings for a Pod or container, unrelated to node selection.
- B. Resource limits control the maximum CPU/memory a container can use, not node placement.
- C. Tolerations allow Pods to be scheduled on nodes with taints, but do not actively attract them to specific nodes.
Kubernetes Node Affinity
Node affinity is a property of Pods that constrains them to be scheduled on nodes with particular labels. It's used for advanced scheduling based on node characteristics.
- Replaces the older `nodeSelector` for more expressive rules.
- Can be 'requiredDuringSchedulingIgnoredDuringExecution' (hard) or 'preferredDuringSchedulingIgnoredDuringExecution' (soft).
- Allows for 'in', 'NotIn', 'Exists', 'DoesNotExist', 'Gt', 'Lt' operators for label matching.
Memory trick: Affinity Attracts, Tolerations Tolerate