Pod Pending Due to Master Taint
A pod is stuck in 'Pending' state. 'kubectl describe pod' shows '0/1 nodes are available: 1 node(s) had taint {node-role.kubernetes.io/master: }, that the pod didn't tolerate'. What is the most likely cause?
Quick Answer
The answer is that the pod is stuck in a Pending state because it does not tolerate the node-role.kubernetes.io/master taint present on the control plane node. This occurs because the Kubernetes scheduler evaluates node taints against pod tolerations; when a node has a taint that a pod lacks a matching toleration for, the scheduler excludes that node from placement. In this scenario, the master node’s default taint repels all pods without an explicit toleration, leaving zero available nodes and causing the pod to remain Pending. On the CKA exam, this tests your understanding of taints and tolerations as core scheduling constraints, often appearing in troubleshooting scenarios where a pod refuses to land on a specific node. A common trap is assuming the master node is always available for workloads, but by design it is tainted to reserve it for system components. Memory tip: “Taint without toleration equals no destination.”
⚠ Common exam trap
Many exam-takers confuse taints with node cordoning or resource constraints, but the specific error message about 'taint that the pod didn't tolerate' directly points to a toleration mismatch, not a resource or node readiness issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The pod does not tolerate the node's taint.
The pod is stuck in 'Pending' because the scheduler cannot find a node that satisfies its scheduling constraints. The 'kubectl describe pod' output explicitly states that 1 node has a taint (node-role.kubernetes.io/master) that the pod does not tolerate. By default, pods do not tolerate the master taint, so they are not scheduled onto master nodes unless a toleration is added. This is the direct cause of the pending state.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The pod is missing resource requests.
Why it's wrong here
Resource requests would cause insufficient CPU/memory, not taint tolerance.
- ✓
The pod does not tolerate the node's taint.
Why this is correct
The taint is preventing scheduling unless the pod has a toleration.
- ✗
The node is cordoned.
Why it's wrong here
Cordoning shows 'SchedulingDisabled', not taint messages.
- ✗
The kubelet is not running on the node.
Why it's wrong here
If kubelet is not running, the node would be 'NotReady'.
Go deeper
Related to this question
Learn chapter
Kubernetes Architecture Overview
Key term
Ingress Resources
Ingress Resources are Kubernetes API objects that manage external access to services inside a cluster, typically HTTP and HTTPS traffic, by defining rules for routing requests based on hostnames and paths.
Key term
Network Policies
A Kubernetes resource that controls how pods communicate with each other and with other network endpoints, acting as a firewall for pod-to-pod traffic.
About these practice questions
Courseiva writes every CKA question from scratch — 302 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CKA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A pod is stuck in 'Pending' state. 'kubectl describe pod' shows '0/1 nodes are available: 1 node(s) had taint {node.kubernetes.io/unreachable: }, that the pod didn't tolerate'. What does this indicate?
hard- A.The pod has been successfully scheduled to the node
- B.The node has insufficient resources and is tainted
- ✓ C.The node is not reachable by the control plane
- D.The node does not exist
Why C: The error message indicates that the node has a taint of `node.kubernetes.io/unreachable`, which is automatically added by the node controller when the control plane cannot communicate with the node (e.g., due to network failure or kubelet being down). The pod remains in 'Pending' because no node is available that tolerates this taint, meaning the node is unreachable from the control plane. This matches option C.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKA exam.