Q: You have a DaemonSet but some nodes aren't getting a pod. Why?
Common reasons:
#Kubernetes #Deployments & Workloads #L2 #Container Orchestration #K8s
🎙️ Candidate Opening & Architectural Context
""When troubleshooting Kubernetes, I always follow a structured layered model: Pod status -> Events -> Logs -> Network. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
Common reasons:
- Node selector or affinity mismatch — DaemonSet has a
nodeSelectoror affinity rule that doesn't match those nodes. - Node has a taint — the DaemonSet pods don't have a matching toleration. Add the toleration to the DaemonSet spec.
- Node is cordoned —
kubectl cordonprevents any new pod scheduling.
2️⃣
Remediation & Permanent Safeguards
Check: kubectl describe daemonset — look at the Selector and Tolerations. Compare with kubectl describe node .
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Node selector or affinity mismatch — DaemonSet has a nodeSelector or affinity rule that doesn't match those nodes.."
⚡ 60-Second Elevator Pitch Talking Points
- Node selector or affinity mismatch — DaemonSet has a nodeSelector or affinity rule that doesn't m...
- Node has a taint — the DaemonSet pods don't have a matching toleration. Add the toleration to the...
- Node is cordoned — kubectl cordon prevents any new pod scheduling.
Advertisement