Sitelet https://github.com/kubernetes/kops/pull/18679
Skip to content

coredns: Tighten PDB to maxUnavailable 33% and always allow unhealthy pod eviction - #18679

Merged
kubernetes-prow[bot] merged 2 commits into
kubernetes:masterfrom
hakman:coredns-pdb-max-unavailable
Aug 10, 2026
Merged

kubernetes-prow[bot] merged 2 commits into
kubernetes:masterfrom
hakman:coredns-pdb-max-unavailable

Conversation

@hakman

@hakman hakman commented Aug 10, 2026 •

Copy link
Copy Markdown
Member

The PodDisruptionBudget exists to guarantee DNS serving capacity, and a single CoreDNS instance handles far more QPS than clusters of this size generate, so the meaningful floor is redundancy: voluntary disruptions should never reduce the deployment below two pods. With 50%, a cluster running three replicas allows two simultaneous evictions, leaving a single DNS pod. 33% is the largest percentage that keeps at least two pods whenever the dns-autoscaler runs three or more replicas, while still scaling the number of allowed disruptions with the deployment. This also matches the availability posture EKS converged on for its managed CoreDNS add-on.

unhealthyPodEvictionPolicy: AlwaysAllow lets a running-but-not-ready CoreDNS pod be evicted even when the budget is exhausted, so a wedged pod no longer blocks the drain of its own node. A pod that is not ready serves no traffic, so evicting it never reduces capacity.

Replicas Nodes maxUnavailable: 50% maxUnavailable: 33%
2 2 1 1
3 33 2 1
4 49 2 2
5 65 3 2
8 113 4 3
22 337 11 8

/cc @rifelpet @ameukam

Refs: #18677

hakman added 2 commits August 10, 2026 08:40
… pod eviction

The PodDisruptionBudget exists to guarantee DNS serving capacity, and a
single CoreDNS instance handles far more QPS than clusters of this size
generate, so the meaningful floor is redundancy: voluntary disruptions
should never reduce the deployment below two pods. With 50%, a cluster
running three replicas allows two simultaneous evictions, leaving a
single DNS pod. 33% is the largest percentage that keeps at least two
pods whenever the dns-autoscaler runs three or more replicas, while
still scaling the number of allowed disruptions with the deployment.
This also matches the availability posture EKS converged on for its
managed CoreDNS add-on.

unhealthyPodEvictionPolicy: AlwaysAllow lets a running-but-not-ready
CoreDNS pod be evicted even when the budget is exhausted, so a wedged
pod no longer blocks the drain of its own node. A pod that is not ready
serves no traffic, so evicting it never reduces capacity. The field is
GA and locked on since Kubernetes 1.31, below the oldest version kOps
supports.
@kubernetes-prow
kubernetes-prow Bot requested review from ameukam and rifelpet August 10, 2026 08:46
@kubernetes-prow kubernetes-prow Bot added area/addons cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. area/documentation size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Aug 10, 2026
@hakman

hakman commented Aug 10, 2026

Copy link
Copy Markdown
Member Author

/test all

@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Aug 10, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: rifelpet

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Aug 10, 2026
@kubernetes-prow
kubernetes-prow Bot merged commit 8b9ba82 into kubernetes:master Aug 10, 2026
29 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/addons area/documentation cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants