Review the StatefulSet PodDisruptionBudget

Define how many voluntary disruptions the stateful application can tolerate.

Description

Simultaneous voluntary evictions, such as during a node drain, can affect StatefulSet availability or replication quorum. A PodDisruptionBudget (PDB) sets availability requirements for disruptions that use the Eviction API.

A PDB does not prevent node failures or restrict every pod deletion. The StatefulSet’s own rolling updates require a separate update strategy.

Potential impact

  • Maintenance can leave too few replicas to serve requests or preserve quorum.
  • An overly restrictive PDB can block node drains and maintenance.

Remediation

  • Define a PDB in the same namespace that selects the actual StatefulSet pods. Set either max_unavailable or min_available according to service and quorum requirements.
  • Check healthy replica counts, readiness and replacement capacity, then test draining. Manage failure-domain distribution and rolling updates separately.

Examples

These existing excerpts omit the pod template, headless Service and other settings. Use kubernetes_pod_disruption_budget_v1 for the current API. With two replicas, max_unavailable of 20% rounds up to one allowed disruption; verify that this meets quorum requirements.

Before

hcl
resource "kubernetes_stateful_set" "example" {
  metadata {
    name = "prometheus"
  }

  spec {
    replicas = 2

    selector {
      match_labels = {
        app = "prometheus"
      }
    }

    service_name = "prometheus"
  }
}

After

hcl
resource "kubernetes_stateful_set" "example" {
  metadata {
    name = "prometheus"
  }

  spec {
    replicas = 2

    selector {
      match_labels = {
        app = "prometheus"
      }
    }

    service_name = "prometheus"
  }
}

resource "kubernetes_pod_disruption_budget" "example" {
  metadata {
    name = "prometheus-pdb"
  }

  spec {
    max_unavailable = "20%"

    selector {
      match_labels = {
        app = "prometheus"
      }
    }
  }
}

Explanation:

  • Before: Two replicas are configured without a PDB. Decide the acceptable disruption budget separately.
  • After: A PDB selects pods labeled app=prometheus. The omitted pod labels must match; this does not prevent every kind of disruption.

References