Taints repel; tolerations are permission slips
A taint is a key, value and effect attached to a node that repels Pods. A toleration on a Pod says it is allowed to ignore a matching taint. The default is closed: a tainted node accepts only Pods that tolerate it. Unlike affinity, which is the Pod choosing nodes, a taint is the node choosing which Pods it accepts.
There are three effects. NoSchedule blocks new Pods that lack the toleration but leaves running Pods alone. PreferNoSchedule is a soft version the scheduler tries to honour. NoExecute also evicts running Pods without the toleration, which is how not-ready nodes and kubectl drain clear a node.
The most common use is dedicating hardware: taint GPU nodes so that ordinary web Pods do not waste them, and give the GPU workloads the matching toleration. Note the subtlety shown on the slide: a toleration only permits scheduling, it does not attract. To make the GPU Pods land only on those nodes, combine the toleration with node affinity or a nodeSelector.
On managed platforms you set taints on node pools: GKE node pool taints, EKS managed node group taints and Karpenter NodePool taints. Spot and preemptible pools are often tainted so that only interruption-tolerant workloads run there.