Safely Drain a Node [page]deterministic
This page shows how to safely drain a [node](#gloss:node), optionally respecting the PodDisruptionBudget you have defined.
##
This task assumes that you have met the following prerequisites: 1. You do not require your applications to be highly available during the node drain, or 1. You have read about the [PodDisruptionBudget](/docs/concepts/workloads/pods/disruptions/) concept, and have [configured PodDisruptionBudgets](/docs/tasks/run-application/configure-pdb/) for applications that need them.
## (Optional) Configure a disruption budget {#configure-poddisruptionbudget}
To ensure that your workloads remain available during maintenance, you can configure a [PodDisruptionBudget](/docs/concepts/workloads/pods/disruptions/).
If availability is important for any applications that run or could run on the node(s) that you are draining, [configure a PodDisruptionBudgets](/docs/tasks/run-application/configure-pdb/) first and then continue following this guide.
It is recommended to set `AlwaysAllow` [Unhealthy Pod Eviction Policy](/docs/tasks/run-application/configure-pdb/#unhealthy-pod-eviction-policy) to your PodDisruptionBudgets to support eviction of misbehaving applications during a node drain. The default behavior is to wait for the application pods to become [healthy](/docs/tasks/run-application/configure-pdb/#healthiness-of-a-pod) before the drain can proceed.
## Use `kubectl drain` to remove a node from service
You can use `kubectl drain` to safely evict all of your pods from a node before you perform maintenance on the node (e.g. kernel upgrade, hardware maintenance, etc.). Safe evictions allow the pod's containers to [gracefully terminate](/docs/concepts/workloads/pods/pod-lifecycle/#pod-termination) and will respect the PodDisruptionBudgets you have specified.
> Note: By default `kubectl drain` ignores certain system pods on the node that cannot be killed; see the [kubectl drain](/docs/reference/generated/kubectl/kubectl-commands/#drain) documentation for more details.
When `kubectl drain` returns successfully, that indicates that all of the pods (except the ones excluded as described in the previous paragraph) have been safely evicted (respecting the desired graceful termination period, and respecting the PodDisruptionBudget you have defined). It is then safe to bring down the node by powering down its physical machine or, if running on a cloud platform, deleting its virtual machine.
> Note: If any new Pods tolerate the `node.kubernetes.io/unschedulable` taint, then those Pods might be scheduled to the node you have drained. Avoid tolerating that taint other than for DaemonSets.
If you or another API user directly set the [`nodeName`](/docs/concepts/scheduling-eviction/assign-pod-node/#nodename) field for a Pod (bypassing the scheduler), then the Pod is bound to the specified node and will run there, even though you have drained that node and marked it unschedulable.
First, identify the name of the node you wish to drain. You can list all of the nodes in your cluster with
```shell kubectl get nodes ```
Next, tell Kubernetes to drain the node:
```shell kubectl drain --ignore-daemonsets <node name> ```
If there are pods managed by a DaemonSet, you will need to specify `--ignore-daemonsets` with `kubectl` to successfully drain the node. The `kubectl drain` subcommand on its own does not actually drain a node of its DaemonSet pods: the DaemonSet controller (part of the control plane) immediately replaces missing Pods with new equivalent Pods. The DaemonSet controller also creates Pods that ignore unschedulable taints, which allows the new Pods to launch onto a node that you are draining.
Once it returns (without giving an error), you can power down the node (or equivalently, if on a cloud platform, delete the virtual machine backing the node). If you leave the node in the cluster during the maintenance operation, you need to run
```shell kubectl uncordon <node name> ``` af …(trimmed)