Kubernetes

Pod Scheduling & Security Context

Build nodeSelector, affinity, tolerations and security contexts as one pod-spec fragment.

Node placement

Exact matches only. Use affinity below for ranges, alternatives or soft preferences.

Affinity
Rule 1
Tolerations
Security context
Output · pod spec
  • readOnlyRootFilesystem means any path the process writes to needs a volume. Mount an emptyDir at /tmp if the application or its runtime writes there.