Skip to main content
In this guide, you will learn how to work with taints and tolerations in Kubernetes. We start by inspecting the cluster nodes, then proceed to apply a taint to a node and create pods with and without the appropriate tolerations.

Step 1: Count the Nodes

Begin by verifying the total number of nodes (including the control plane) in your cluster. Run the following command:
There are two nodes in the cluster.
This output confirms that both the control plane and node01 are active and ready.

Step 2: Check Taints on node01

Next, examine node01 for any existing taints. Use the kubectl describe command:
Since there are no taints on node01, you can conclude that there are no scheduling constraints for pods on this node at this moment.

Step 3: Apply a Taint on node01

Now, add a taint to node01 by specifying a key-value pair and an effect. The command below applies a taint with the key “spray”, a value of “mortein”, and an effect of “NoSchedule”:
This taint ensures that only pods with a matching toleration will be scheduled on node01.

Step 4: Create the “mosquito” Pod Without a Toleration

Create a pod named “mosquito” using the nginx image without specifying any toleration:
After creating the pod, check its status:
Since the pod lacks a toleration for the taint applied on node01, it remains in a pending state. To investigate further, describe the pod:
The event message clarifies that “mosquito” cannot be scheduled due to the untolerated “spray” taint on node01.
Ensure that you add the proper tolerations when you need a pod to be scheduled on a tainted node.

Step 5: Create the “bee” Pod With a Toleration

To schedule a pod on node01 despite the taint, create a new pod named “bee” with a toleration for “spray”. Follow these steps:
  1. Generate an initial YAML manifest using dry-run:
  2. Open the generated bee.yaml file and add a tolerations section under the spec. The corrected YAML should resemble the following:
  3. Apply the manifest to create the pod:
  4. Monitor the pod creation:
After a few seconds, you should see the “bee” pod transition to the Running state. Verify the status by running:
The “bee” pod successfully schedules on node01 because it contains the correct toleration, while “mosquito” continues to remain pending.

Step 6: Remove the Taint from the Control Plane

Finally, inspect the control plane node to confirm it has a taint restricting regular pod scheduling:
To allow pods to be scheduled on the control plane, remove its taint with the following command:
Once the taint is removed, the “mosquito” pod can now find a suitable node. Confirm the new pod status:
Now, “mosquito” is running on the control plane since the scheduling conflict has been resolved.

Summary

This walkthrough demonstrates the use of taints and tolerations to control pod placement in a Kubernetes cluster:
  • Initially, node01 had a taint (spray=mortein:NoSchedule) and the control plane had the default master taint, which prevented the “mosquito” pod from scheduling.
  • Creating the “bee” pod with the appropriate toleration allowed it to be scheduled on node01.
  • Removing the taint from the control plane enabled the “mosquito” pod to be scheduled there.
Using taints and tolerations effectively can help you control where pods are deployed and maintain a balanced and secure Kubernetes environment.

Watch Video