Kubernetes and Cloud Native Associate (KCNA)Kubernetes FundamentalsMedium

A cluster administrator is performing maintenance on a Kubernetes worker node and needs to temporarily prevent new Pods from being scheduled onto it without removing existing Pods. Which `kubectl` command should be used?

  1. A`kubectl drain node-name`
  2. B`kubectl cordon node-name`
  3. C`kubectl uncordon node-name`
  4. D`kubectl delete node node-name`
Show answer & explanation

Correct answer: B. `kubectl cordon node-name`

The `kubectl cordon` command marks a node as 'unschedulable', preventing new Pods from being placed on it while allowing existing Pods to continue running. This is ideal for preparatory maintenance.

Why the other options are wrong

  • A. `kubectl drain` marks the node unschedulable AND evicts all Pods from it, which is more aggressive than needed.
  • C. `kubectl uncordon` reverses the `cordon` command, making the node schedulable again.
  • D. `kubectl delete node` removes the node object from Kubernetes, which is not the goal for temporary maintenance.

`kubectl cordon`

The `kubectl cordon` command marks a node as unschedulable, preventing the Kubernetes scheduler from placing new Pods on that node. Existing Pods on the node are unaffected.

  • Marks a node as unschedulable.
  • Prevents new Pods from being scheduled.
  • Does not affect Pods already running on the node.
  • Used for preparatory maintenance.

Memory trick: To 'Cordon' off a node, you 'C'lose it to 'C'oming Pods.

More Kubernetes Fundamentals questions