# Workload Missing Topology Spread | ZopNight

> Replicas can all land on one node or in one zone, so a single failure removes every copy at once. ZopNight finds it across AWS, Azure and Google Cloud.

Source: https://zop.dev/zopnight/rules/workload-missing-topology-spread

---

_Reliability · Medium severity_

## Workload Missing Topology Spread

Replicas can all land on one node or in one zone, so a single failure removes every copy at once.

- 3 — clouds covered
- Medium — severity
- Risk — where it shows up
- Manual — fix, change spelled out

Free to start. No card. The playground just needs your work email.

## Found, explained, handed over.

Exposure and fragility, security posture and single points of failure.

- 01. Detect — ZopNight checks this automatically across AWS, Azure and Google Cloud, with read-only access to the account.
- 02. Explain — Every finding says exactly what to change: Add topology spread constraints to the workload.
- 03. Fix — The finding opens with the change already spelled out, so the fix is one ticket, not an investigation.

- applies_to_fallback: Any resource in the account
- where_it_appears: The Risk tab of Recommendations, with every affected resource listed.

## Related

- [Privileged Container](https://zop.dev/zopnight/rules/privileged-container)
- [Deployment Not Fully Ready](https://zop.dev/zopnight/rules/deployment-not-fully-ready)
- [Liveness and Readiness Share One Handler](https://zop.dev/zopnight/rules/liveness-and-readiness-share-one-handler)
- [Missing CPU/Memory Requests](https://zop.dev/zopnight/rules/missing-cpu-memory-requests)
- [StatefulSet Not Fully Ready](https://zop.dev/zopnight/rules/statefulset-not-fully-ready)
- [Container Running as Root](https://zop.dev/zopnight/rules/container-running-as-root)

## See the reliability findings in your account.

Connect a read-only role and the first pass runs on your own estate. This check, and the rest of the catalogue, with it.

[object Object]
