A company's security policy specifies that development and production containers must run on separate nodes in a given Swarm cluster.
Can this be used to schedule containers to meet the security policy requirements?
Solution: node affinities
They provide granular control over where pods (or in this case, containers) are scheduled, based on the labels of the nodes1. In the context of Docker Swarm, this means that you could use node affinities to ensure that development and production containers are scheduled on separate nodes, thus meeting the company's security policy requirements12345.
Limited Time Offer
25%
Off
Omega
2 months agoCandida
27 days agoWerner
28 days agoAlita
2 months agoFiliberto
2 months agoBenton
2 months agoMarkus
3 months agoPatti
3 months agoKatie
1 months agoJanna
1 months agoDana
2 months agoMona
2 months agoMyong
2 months agoAdelle
2 months agoPura
3 months agoDeja
3 months ago