🎓 LEVEL 46 DEBRIEF: Taints & Tolerations¶
Congratulations! You've mastered taints and tolerations - the gatekeepers of node scheduling!
📊 What You Fixed¶
Problem: Node tainted, pod has no toleration
Solution: Added matching toleration
Result: Pod schedules successfully
🎯 Understanding Taints & Tolerations¶
Taints (Node-level)¶
Purpose: Repel pods from nodes
Effects: - NoSchedule: New pods can't schedule - PreferNoSchedule: Avoid scheduling (soft) - NoExecute: Evict existing + block new
Tolerations (Pod-level)¶
Purpose: Allow scheduling on tainted nodes
🔧 Common Patterns¶
Dedicated Nodes¶
# Taint GPU nodes
kubectl taint nodes gpu-node dedicated=gpu:NoSchedule
# Only GPU workloads tolerate
tolerations:
- key: "dedicated"
value: "gpu"
effect: "NoSchedule"
Maintenance Mode¶
# Drain node (NoExecute)
kubectl taint nodes node1 maintenance=true:NoExecute
# Evicts all pods without toleration
Spot Instances¶
# Mark as spot
kubectl taint nodes spot-1 node.kubernetes.io/instance-type=spot:PreferNoSchedule
# Dev workloads tolerate
tolerations:
- key: "node.kubernetes.io/instance-type"
operator: "Exists"
💥 Common Mistakes¶
- Missing effect: Must match taint effect
- Typo in key/value: Case-sensitive!
- Wrong operator: "Equal" needs value, "Exists" doesn't
- Forgetting NoExecute: Evicts running pods
🎯 Key Takeaways¶
- Taints repel, tolerations allow
- All parts must match: key, value, effect
- NoExecute evicts existing pods
- operator: Exists tolerates any value
- Use for: dedicated nodes, maintenance, special hardware
🚀 Next Steps¶
- Level 47: PodDisruptionBudget
- Level 48: Admission Webhooks
- Level 49: PriorityClass
- Level 50: CHAOS FINALE!
Excellent work! 🎉⚡