⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All Kubernetes Interview Questions Scenario 193 of 194 in Kubernetes
Senior DevOps / SRE Kubernetes Pod Scheduling & EKS Triage Operations & Support Loop

Q: During an EKS deployment across multiple namespaces, one pod gets stuck in Pending state. Walk me through your troubleshooting approach.

Systematic diagnostic workflow when a Kubernetes deployment across multiple namespaces leaves exactly one pod stuck in Pending state.

#Kubernetes #EKS #Pending Pod #Node Affinity #Taints #Subnet Exhaustion #Troubleshooting
🎙️ Candidate Opening & Architectural Context
"When a multi-namespace EKS rollout succeeds across almost all services but leaves a single pod stuck in Pending, the Kubernetes scheduler cannot find a suitable worker node that satisfies that specific pod's resource requests, node selectors, taints/tolerations, or VPC IP allocations."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's CKA & CKAD Hands-On Certification Track covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1

Execute kubectl describe pod for Scheduler Verdict

Inspect the Events table in `kubectl describe pod -n `. The `default-scheduler` explicitly records why each candidate node was rejected.

kubectl describe pod <pod-name> -n <namespace>
# Common output:
# 0/12 nodes are available: 3 Insufficient cpu, 5 node(s) had untolerated taint, 4 node(s) didn't match PodTopologySpread.
2

Check Node Affinity, Selectors & Taints/Tolerations

Check whether the failing pod spec has specific constraints that other namespaces don't: - `nodeSelector` or `nodeAffinity` targeting an instance group that doesn't exist (e.g. `topology.kubernetes.io/zone=us-east-1a`). - Missing tolerations for dedicated node pool taints (e.g. `dedicated=gpu:NoSchedule` or `spot=true:NoSchedule`).

kubectl get nodes --show-labels
kubectl get nodes -o custom-columns=NAME:.metadata.name,TAINTS:.spec.taints
Advertisement
3

Check AWS VPC CNI Subnet IP Exhaustion

On Amazon EKS using AWS VPC CNI, every pod receives a real secondary private IP from the node's VPC subnet. If one specific Availability Zone's subnet runs out of available IP addresses (`AvailableIpAddressCount: 0`), new pods targeting that subnet are stuck in Pending.

aws ec2 describe-subnets \
  --subnet-ids subnet-0123456789abcdef0 \
  --query "Subnets[*].[SubnetId,AvailableIpAddressCount,CidrBlock]"
4

Check Resource Requests vs. Cluster Autoscaler / Karpenter

Check if the pod requests excessive CPU or Memory (`requests.memory: 32Gi`) that exceeds the capacity of available node sizes. Check whether Karpenter or Cluster Autoscaler is failing to spin up new nodes due to AWS EC2 service quotas.

💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Isolate the scheduler constraint via 'kubectl describe pod'. Investigate node selectors, taints/tolerations, VPC subnet IP address exhaustion in AWS VPC CNI, or Karpenter node provisioning errors."
⚡ 60-Second Elevator Pitch Talking Points
  • Run kubectl describe pod to inspect the scheduler's rejection reasons.
  • Verify nodeSelectors, nodeAffinity rules, and taints/tolerations on worker node groups.
  • Check AWS VPC subnet IP availability to ensure the CNI has free IP addresses for new pods.
  • Inspect Karpenter/Cluster Autoscaler logs to verify if autoscaling is blocked by AWS capacity quotas.
Advertisement
📥 FREE DOWNLOAD · 101-PAGE COMPANION HANDBOOK
Studying for Kubernetes & SRE Technical Rounds?
Download the complete 100-question PDF field guide covering all 11 core modules with offline diagnostic runbooks.
📥 Download PDF (Free) Read Online Guide →
Want more Kubernetes scenarios?
Explore our complete collection of scenario-based Kubernetes interview runbooks.
Browse All Kubernetes Questions →