Kubernetes and Cloud Native Associate (KCNA)Kubernetes FundamentalsMedium

A cluster administrator needs to ensure that a specific set of Pods within a Deployment always runs on nodes equipped with GPUs. They have already labeled the appropriate nodes with `gpu=true`. Which section of the Pod's YAML manifest should be modified to enforce this scheduling constraint?

  1. A`spec.securityContext`
  2. B`spec.containers.resources.limits`
  3. C`spec.tolerations`
  4. D`spec.affinity.nodeAffinity`
Show answer & explanation

Correct answer: D. `spec.affinity.nodeAffinity`

`nodeAffinity` is the mechanism in Kubernetes to constrain Pods to nodes with specific labels. This is ideal for ensuring Pods run on hardware like GPUs.

Why the other options are wrong

  • A. Security context defines privilege and access control settings for a Pod or container, unrelated to node selection.
  • B. Resource limits control the maximum CPU/memory a container can use, not node placement.
  • C. Tolerations allow Pods to be scheduled on nodes with taints, but do not actively attract them to specific nodes.

Kubernetes Node Affinity

Node affinity is a property of Pods that constrains them to be scheduled on nodes with particular labels. It's used for advanced scheduling based on node characteristics.

  • Replaces the older `nodeSelector` for more expressive rules.
  • Can be 'requiredDuringSchedulingIgnoredDuringExecution' (hard) or 'preferredDuringSchedulingIgnoredDuringExecution' (soft).
  • Allows for 'in', 'NotIn', 'Exists', 'DoesNotExist', 'Gt', 'Lt' operators for label matching.

Memory trick: Affinity Attracts, Tolerations Tolerate

More Kubernetes Fundamentals questions