Review StatefulSet PodDisruptionBudget settings

Configure a disruption budget to retain required replicas during planned maintenance.

Description

A PodDisruptionBudget (PDB) limits voluntary disruptions that use the Eviction API, such as node drains. Without a budget suited to StatefulSet availability requirements, maintenance can interrupt several replicas together. A PDB does not prevent direct Pod deletion, node failures or the StatefulSet controller’s own rolling updates.

Potential impact

  • Planned node work can reduce available replicas and affect service availability or quorum.
  • An overly strict budget or insufficient replacement capacity can block node drains.

Remediation

  • Configure a PDB in the same namespace with a selector matching actual Pod labels. Set either minAvailable or maxUnavailable to meet service availability or quorum requirements.
  • Check Pod readiness and replacement capacity, and test drains. Configure failure recovery, replica distribution and rolling-update policies separately.

Examples

These existing nginx excerpts add a PDB to a StatefulSet. Provide the nginx headless Service and other environment configuration separately.

Before

yaml
apiVersion: apps/v1
kind: StatefulSet
metadata:
  name: web
spec:
  serviceName: nginx
  replicas: 3
  selector:
    matchLabels:
      app: nginx
  template:
    metadata:
      labels:
        app: nginx
    spec:
      containers:
        - name: nginx
          image: nginx:1.25

Three replicas are defined without a PDB in this excerpt. Check whether another PDB already applies.

After

yaml
apiVersion: policy/v1
kind: PodDisruptionBudget
metadata:
  name: web-pdb
spec:
  maxUnavailable: 1
  selector:
    matchLabels:
      app: nginx
---
apiVersion: apps/v1
kind: StatefulSet
metadata:
  name: web
spec:
  serviceName: nginx
  replicas: 3
  selector:
    matchLabels:
      app: nginx
  template:
    metadata:
      labels:
        app: nginx
    spec:
      containers:
        - name: nginx
          image: nginx:1.25

maxUnavailable: 1 applies to app: nginx Pods. Already unavailable Pods count against the budget; Eviction API disruptions are allowed only when the budget permits.

References