A company's security policy specifies that development and production containers must run on separate nodes in a given Swarm cluster.
Can this be used to schedule containers to meet the security policy requirements?
Solution: node affinities
They provide granular control over where pods (or in this case, containers) are scheduled, based on the labels of the nodes1. In the context of Docker Swarm, this means that you could use node affinities to ensure that development and production containers are scheduled on separate nodes, thus meeting the company's security policy requirements12345.
Limited Time Offer
25%
Off
Omega
2 months agoCandida
18 days agoWerner
19 days agoAlita
1 months agoFiliberto
2 months agoBenton
2 months agoMarkus
2 months agoPatti
2 months agoKatie
24 days agoJanna
27 days agoDana
1 months agoMona
2 months agoMyong
2 months agoAdelle
2 months agoPura
2 months agoDeja
2 months ago