Description
A PodDisruptionBudget (PDB) limits voluntary disruptions that use the Eviction API, such as node drains. Without a budget suited to StatefulSet availability requirements, maintenance can interrupt several replicas together. A PDB does not prevent direct Pod deletion, node failures or the StatefulSet controller’s own rolling updates.
Potential impact
- Planned node work can reduce available replicas and affect service availability or quorum.
- An overly strict budget or insufficient replacement capacity can block node drains.
Remediation
- Configure a PDB in the same namespace with a selector matching actual Pod labels. Set either minAvailable or maxUnavailable to meet service availability or quorum requirements.
- Check Pod readiness and replacement capacity, and test drains. Configure failure recovery, replica distribution and rolling-update policies separately.
Examples
These existing nginx excerpts add a PDB to a StatefulSet. Provide the nginx headless Service and other environment configuration separately.
Before
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: web
spec:
serviceName: nginx
replicas: 3
selector:
matchLabels:
app: nginx
template:
metadata:
labels:
app: nginx
spec:
containers:
- name: nginx
image: nginx:1.25
Three replicas are defined without a PDB in this excerpt. Check whether another PDB already applies.
After
apiVersion: policy/v1
kind: PodDisruptionBudget
metadata:
name: web-pdb
spec:
maxUnavailable: 1
selector:
matchLabels:
app: nginx
---
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: web
spec:
serviceName: nginx
replicas: 3
selector:
matchLabels:
app: nginx
template:
metadata:
labels:
app: nginx
spec:
containers:
- name: nginx
image: nginx:1.25
maxUnavailable: 1 applies to app: nginx Pods. Already unavailable Pods count against the budget; Eviction API disruptions are allowed only when the budget permits.