Lộ trình
Cloud Native Computing FoundationAssociateTuần 2: Đào sâu dịch vụ cốt lõiBài 10 / 30

Ngày 10: Scheduling nâng cao

Thời lượng: 45 phút
Mục tiêu: 2 nhiệm vụ chính
Tiến độ lộ trình
ckangày 10
hoàn thành10 / 30 bài
Bối cảnh bài học

Điều khiển scheduling bằng nodeSelector, affinity/anti-affinity, taints/tolerations, resources và topology; debug Pod Pending bằng evidence.

đọc hiểuthực hànhcheckpoint
Bài giảng hôm nay

Học hiểu, rồi mới thực hành

Điều khiển scheduling bằng nodeSelector, affinity/anti-affinity, taints/tolerations, resources và topology; debug Pod Pending bằng evidence.

Bắt đầu đọc bài giảng

Nhiệm vụ bài học hôm nay

  • Học nodeSelector, nodeAffinity, taints và tolerations
  • Thực hành ép Pod chạy trên node cụ thể
Instructor walkthrough

Bài giảng chi tiết: từ bài toán đến bằng chứng

Scenario xuyên suốt

Pod Pending vì nodeSelector không tồn tại, một workload nhạy cảm bị dồn cùng node và toleration được thêm rộng để “chạy cho được”. Bài học biến placement thành constraint có lý do, không phải sửa Pending bằng wildcard.

01Đọc bài toán

Xác định actor, workload, constraint và trạng thái cuối cần đạt.

02Vẽ luồng / boundary

Chỉ ra request, dependency, identity và failure domain trước khi chọn công cụ.

03Chọn và thực hành

Thay đổi nhỏ nhất trong lab cô lập; command nào cũng phải nói rõ nó kiểm tra điều gì.

04Kiểm chứng / recovery

Đối chiếu trạng thái thực tế, tạo một failure variant và ghi cách hoàn tác.

Cách nối lý thuyết với thực tế
  • nodeSelector là equality constraint đơn giản; node affinity hỗ trợ required/preferred và topology; pod affinity/anti-affinity điều khiển co-location/spread.
  • Taint trên node repel Pod; toleration chỉ cho phép schedule, không buộc Pod vào node và không thay resources/affinity.
  • Scheduler xét resources, taint, affinity, topology, volume và policy; Pod Pending cần đọc events/reason.
  • Preferred vs required là availability/operational trade-off; anti-affinity có thể làm unschedulable nếu cluster nhỏ.

Scheduler đọc constraints

Scheduler cần tìm node thỏa resources, taint/toleration, node/pod affinity, topology, volume và policy. nodeSelector đơn giản; affinity linh hoạt hơn; anti-affinity/spread cải thiện failure distribution nhưng có thể làm cluster nhỏ không schedule được.

Taint và Pending

Taint repel Pod; toleration chỉ cho phép, không chỉ định placement. Khi Pod Pending, dùng describe/events để thấy constraint cụ thể. Thay đổi node label/taint phải có inventory, owner và rollback vì ảnh hưởng workload khác.

Bài tập

Tạo hai node label scenario, một taint/toleration scenario và một anti-affinity scenario. Ghi expected placement, Pending evidence, remediation và cleanup restore. Pass khi giải thích được vì sao một constraint là required hay preferred.

Terminal reference

Command list và cách dùng

Chạy từng lệnh theo đúng thứ tự. Trước các lệnh có thể tạo hoặc thay đổi tài nguyên, hãy kiểm tra profile, account và region.

Commands · read-only checkpoints
kubectl get nodes --show-labels
kubectl describe node NODE_NAME | sed -n "/Taints:/,/Unschedulable:/p"
kubectl get pod POD_NAME -n cka-day10 -o yaml
kubectl get events -n cka-day10 --sort-by=.lastTimestamp
kubectl taint nodes NODE_NAME workload=training:NoSchedule-
Hands-on lab

Thực hành theo scenario

  1. Gán label node lab `workload=training`, tạo Pod có nodeSelector rồi verify node; thêm required/preferred affinity và anti-affinity trên hai Pod.
  2. Taint một node lab với key/value/effect, quan sát Pod Pending, thêm toleration đúng scope rồi verify; không taint production node.
  3. Cố ý dùng label/taint không tồn tại, thu `describe/events`, xác định constraint làm Pending và sửa manifest tối thiểu.
  4. Cleanup Pod/Deployment, xóa taint/label lab theo giá trị đã lưu, kiểm tra nodes và workload không còn constraint mồ côi.
Evidence checkpoint

Kiểm chứng kết quả

Không coi lệnh chạy thành công là đủ. Hãy đối chiếu output với trạng thái mong đợi:

  • nodeSelector/affinity/anti-affinity phân biệt đúng.
  • Taint/toleration behavior có evidence.
  • Pending reason đến từ events/conditions.
  • Required/preferred và topology trade-off rõ.
  • Node mutation cleanup khôi phục state.
Transfer to exam / production

Bẫy thường gặp và trade-off

Toleration không “đẩy” Pod lên node; nó chỉ cho phép đi qua taint. Khi Pending, đọc scheduler events trước khi thêm toleration hoặc nới constraint.

Checkpoint · 3 phút

Kiểm tra nhanh

Câu hỏi: Pod Pending sau khi node bị taint `dedicated=team:NoSchedule`. Toleration có tác dụng gì?

Kết thúc bài

Checklist trước khi sang Ngày 2