A volume is declared in spec.volumes and mounted by any of the Pod's containers. An emptyDir is created empty when the Pod lands on a node and deleted when the Pod leaves it; containers restart around it:
kubectl apply -f - >/dev/null <<'EOF'
apiVersion: v1
kind: Pod
metadata: { name: scratch }
spec:
containers:
- name: logger
image: localhost:33500/booknest-web:1.3
command: [sh, -c, 'date +%T >> /cache/starts; echo $(cat /cache/starts); sleep 5']
volumeMounts: [{ name: cache, mountPath: /cache }]
volumes: [{ name: cache, emptyDir: { sizeLimit: 64Mi } }]
EOF
sleep 30; kubectl get pod scratch; kubectl logs scratch
kubectl delete pod scratch --nowOutput
NAME READY STATUS RESTARTS AGE scratch 1/1 Running 2 (19s ago) 31s 16:15:00 16:15:06 16:15:25 pod "scratch" deleted from booknest namespace
The logger exits after five seconds and restarts with back-off, and its latest start found the earlier timestamps. emptyDir suits caches and files shared between containers (medium: Memory uses tmpfs). A hostPath volume mounts a node directory: it ties the Pod to one node and can expose the node, so the Baseline Pod Security Standard (Pod Security and Policies) forbids it. Node agents (Common DaemonSet Workloads) use it; applications should not.