Kubernetes
Pod Scheduling & Security Context
Build nodeSelector, affinity, tolerations and security contexts as one pod-spec fragment.
Node placement
Exact matches only. Use affinity below for ranges, alternatives or soft preferences.
Affinity
Rule 1
Tolerations
Security context
Output · pod spec
- readOnlyRootFilesystem means any path the process writes to needs a volume. Mount an emptyDir at /tmp if the application or its runtime writes there.