Telecom vendors have adopted containerization to improve their software for heterogeneous edge-to-cloud networks. Container orchestration platforms face however challenges when adapting to the dynamic demands of multi-tenancy, often leading to performance and security conflicts between Cluster Administrators (CAs) and applications administrators. In this paper, we propose that network security and performance constraints should be directly integrated into the scheduler. By dynamically determining preferred network segments for each application, this approach will reduce the network attack surface, enhance resource utilization, and ensure improved performance. The presented prototype and evaluation is just a first step. A comprehensive solution must also support an intent-based interface to the scheduler that simplifies expression of cluster node segmentation constraints and thus frees the CA from node-level management. We outline the vision for such an intent-based interface and emulate it by means of traditional security groups.