Hands-on Lab·Certified Kubernetes Administrator
Taints and Tolerations
A nodeSelector says where a Pod wants to go. A taint says who a node will accept, and the node wins. Taint a worker, watch an identical Pod stay Pending on it, then add four lines of toleration and watch it schedule.
Scheduling and Placement Guide 41 of 103 Intermediate
- Kubernetes1.36.4
- Cluster4 nodes
- Runtimecontainerd 2.2.6
- CNICalico v3.32.1
- TimeAbout 30 min
- Reviewed21 August 2026
Written against the versions above. Node names are this lab's. Scheduler messages are quoted exactly as they appeared.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA1001 | 192.168.0.175 | Ubuntu 26.04 LTS | Control Plane Node | 2 Core | 4 GB | 50 GB |
| CKA1001-NODE01 | 192.168.0.176 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA1001-NODE02 | 192.168.0.177 | Ubuntu 26.04 LTS | Worker Node (tainted in this guide) | 2 Core | 4 GB | 50 GB |
| CKA1001-NODE03 | 192.168.0.178 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- A cluster with more than one worker, so a tainted node can be avoided.
- Permission to taint and label nodes, which is a cluster-level operation.
- The Pods guide. Tolerations are a field on the Pod spec.
-
You already have a taint
-
Taint a worker
-
A Pod that asks for the node and is refused
-
The same Pod, with a toleration
-
Remove the taint
-
Clean up