Kubernetes and Cloud Native Associate (KCNA)Kubernetes FundamentalsHard

A platform engineer needs to temporarily prevent new Pods from being scheduled onto a specific Kubernetes worker node to perform maintenance, while allowing existing Pods to continue running. Which `kubectl` command should they use?

  1. A`kubectl delete node my-node`
  2. B`kubectl uncordon my-node`
  3. C`kubectl drain my-node`
  4. D`kubectl cordon my-node`
Show answer & explanation

Correct answer: D. `kubectl cordon my-node`

The `kubectl cordon` command marks a node as unschedulable, meaning no new Pods will be placed on it. Existing Pods will continue to run, which is ideal for preparatory maintenance without disrupting running applications.

Why the other options are wrong

  • A. `kubectl delete node` would remove the node from the cluster entirely, which is not the goal.
  • B. `kubectl uncordon` reverses the `cordon` command, allowing Pods to be scheduled again, but it's not the initial action needed.
  • C. `kubectl drain` would cordon the node AND evict all existing Pods, which is more disruptive than intended for temporary maintenance.

kubectl cordon

A `kubectl` command that marks a Kubernetes node as 'unschedulable', preventing new Pods from being placed on it.

  • Existing Pods on the node continue to run.
  • Used as a preliminary step for node maintenance.
  • Can be reversed with `kubectl uncordon`.

Memory trick: Cordon off the node, no new friends allowed!

More Kubernetes Fundamentals questions