Restrict services to worker nodesEstimated reading time: 1 minute
You can configure UCP to only allow users to deploy and run services in worker nodes. This ensures all cluster management functionality stays performant, and makes the cluster more secure.
If a user deploys a malicious service that can affect the node where it is running, they won’t be able to affect other nodes in the cluster, or any cluster management functionality.
To restrict users from deploying to manager nodes, log in with administrator credentials to the UCP web UI, navigate to the Admin Settings page, and choose Scheduler.
You can then choose if user services should be allowed to run on manager nodes or not.