Kubernetes and Cloud Native Associate (KCNA)Kubernetes FundamentalsHard
A cluster operator is observing high resource usage on one of their Kubernetes worker nodes. They need to temporarily prevent new Pods from being scheduled onto this specific node while allowing existing Pods to continue running. Which `kubectl` command should be used?
- A`kubectl drain <node-name>`
- B`kubectl taint node <node-name> NoSchedule`
- C`kubectl cordon <node-name>`
- D`kubectl delete node <node-name>`
Show answer & explanationAnswer & explanation
Correct answer: C. `kubectl cordon <node-name>`
The `kubectl cordon` command marks a node as 'unschedulable', preventing new Pods from being placed on it. Existing Pods on the node continue to run undisturbed, which perfectly matches the requirement.
Why the other options are wrong
- A. `kubectl drain` marks a node as unschedulable AND evicts all Pods from it, which is not desired as existing Pods should continue running.
- B. `kubectl taint` adds a taint, which Pods must explicitly tolerate to be scheduled. While it can prevent scheduling, `cordon` is the more direct and appropriate command for marking a node unschedulable without affecting existing Pods or requiring Pod modifications.
- D. `kubectl delete node` removes the node from the cluster entirely, which is too drastic for a temporary scheduling prevention.
`kubectl cordon`
A `kubectl` command that marks a specified Node as 'unschedulable'. This prevents the Kubernetes scheduler from placing new Pods onto that Node, while allowing all existing Pods to continue running without interruption.
- Marks a Node as unschedulable.
- Does not affect existing Pods.
- Useful for maintenance without downtime for running applications.
Memory trick: Cordon for Caution, Drain for Down, Taint for Tolerance.