Definition. A machine (physical or virtual) on which Kubernetes actually runs pods. Worker nodes run a kubelet, a container runtime and a network plugin and are controlled by the control plane. Unlike the control plane, they are the layer where workloads actually consume resources.
Why it matters. Security and performance decisions take effect here first. Kernel CVEs, pod isolation, eBPF-based detection, node autoscaling and lifecycle patching all act at the worker level.
Related. Kubernetes, Pod Security Standards, Kernel Hardening, Cluster Autoscaler, Karpenter