Hands-on Lab·Certified Kubernetes Administrator
Topology Spread Constraints
Nine replicas, maxSkew of 1, and only three ever schedule. The tainted control plane counts as a topology domain holding zero Pods, so a fourth would breach the skew. One field fixes it and the scheduler says so if you read the message.
Scheduling and Placement Guide 42 of 103 Advanced
- Kubernetes1.36.4
- Cluster4 nodes
- Runtimecontainerd 2.2.6
- CNICalico v3.32.1
- TimeAbout 35 min
- Reviewed21 August 2026
Written against the versions above. nodeTaintsPolicy needs 1.26 or newer. On older clusters the workaround is a nodeSelector.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA1001 | 192.168.0.175 | Ubuntu 26.04 LTS | Control Plane Node | 2 Core | 4 GB | 50 GB |
| CKA1001-NODE01 | 192.168.0.176 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA1001-NODE02 | 192.168.0.177 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA1001-NODE03 | 192.168.0.178 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- The labels and nodeSelector guide, and the node affinity guide.
- The taints and tolerations guide. The control plane's taint is the cause of this guide's central surprise.
- The Pod stuck Pending guide, for reading the scheduler's tally.
-
Six replicas, maxSkew 1, and three that never start
-
The scheduler explains it, and the answer is the control plane
-
nodeTaintsPolicy: Honor, and all nine schedule
-
ScheduleAnyway, and what the scheduler does unaided