# My Object Will Not Delete

An object with a `deletionTimestamp` that does not go away is waiting on one of a short list of things. Read the object first:

```sh
kubectl get <kind> -n <ns> <name> -o yaml
```

Look at `metadata.finalizers` (CAPTF’s must be the one holding it), the `Deleting` condition’s message, `DeletionBlocked`, `StateReadable` and `ApplyJobSucceeded`, then follow the chart.

```
%%{init: {"themeVariables": {"fontSize": "13px"}, "flowchart": {"nodeSpacing": 28, "rankSpacing": 34, "padding": 10}}}%%
flowchart TD
    S[Object has a deletionTimestamp<br/>and the finalizer stays] --> P{Paused=True?}
    P -- yes --> P1[Unpause the Cluster or remove<br/>the paused annotation]
    P -- no --> D{DeletionBlocked=True?}
    D -- yes --> D1[Delete the machines and pools<br/>it counts, then wait]
    D -- no --> J{A Job is running?}
    J -- yes --> J1[Wait: the destroy starts after it]
    J -- no --> W{ApplyJobSucceeded<br/>is a lease wait?}
    W -- yes --> W1[Wait or inspect the lease holder]
    W -- no --> R{StateReadable<br/>False?}
    R -- "StateLocked" --> R1[Stale lock runbook]
    R -- "Lost, Corrupt,<br/>Encrypted, Inconsistent" --> R2[Restore a backup,<br/>or abandon]
    R -- no --> C{Deleting message says<br/>it waits for credentials?}
    C -- yes --> C1[Fix the named condition,<br/>or abandon]
    C -- no --> F{ApplyJobSucceeded<br/>False?}
    F -- "IdentityNotAllowed" --> F1[Allow the namespace again,<br/>or abandon]
    F -- "DestroyFailed" --> F2[Fix the failure,<br/>or abandon]
    F -- "JobDeadlineExceeded" --> F3[Raise the deadline]
    F -- no --> Z[No condition explains it:<br/>check the manager]
```

## Symptom to action

| What you see | Meaning | Action |
| --- | --- | --- |
| `Paused=True`, or the Cluster has `spec.paused: true`; `Deleting` says `Deletion waits until the object is unpaused` | A paused object runs only bookkeeping, so it never destroys; `clusterctl move` relies on this | Unpause. See [Order](<https://captf.io/docs/concepts/deletion/order/#pause-stops-a-deletion>) |
| `kubectl delete terraformmachine` is refused: `delete the Machine <name> instead` | A live Machine references it | Delete the Machine; see [Order](<https://captf.io/docs/concepts/deletion/order/#the-webhook-refuses-a-direct-machine-delete>) |
| `DeletionBlocked=True`/`DependentsExist` on a `TerraformCluster` | Machines or pools with its cluster label still exist | List them with `-l cluster.x-k8s.io/cluster-name=<name>`; they delete through their Machines. If one is stuck, work on that object first |
| A Job is running (`status.activeJob`) | The destroy waits for it | Wait; see [Slow Jobs](<https://captf.io/docs/operator-guide/runbooks/slow-jobs/index.md>) |
| `ApplyJobSucceeded=Unknown`/`WaitingForRunLease`, `WaitingForClusterOperation` or `WaitingForMachineOperations` | The destroy waits for a lease | Wait; see [Leases](<https://captf.io/docs/concepts/lifecycle/#run-leases-and-the-cluster-operation-gate>) |
| `StateReadable=False`/`StateLost`, `StateCorrupt`, `StateEncrypted` or `StateInconsistent` | Held on the state | [Restore](<https://captf.io/docs/concepts/deletion/held/#restore-then-destroy>) or [abandon](<https://captf.io/docs/concepts/deletion/held/#abandon>). See [Unreadable State](<https://captf.io/docs/operator-guide/runbooks/state-unreadable/index.md>) |
| `StateReadable=False`/`StateLocked` | A foreign holder has the state lock; the destroy Job will wait and fail | [Stale State Lock](<https://captf.io/docs/operator-guide/runbooks/stale-lock/index.md>) |
| `Deleting` message `The destroy Job waits for its credentials: …` | Credentials cannot be prepared, often in a terminating namespace | Fix the named condition ([identities](<https://captf.io/docs/operator-guide/runbooks/identity-and-credentials/index.md>)), or [abandon](<https://captf.io/docs/concepts/deletion/held/#abandon>). See [Terminating namespaces](<https://captf.io/docs/concepts/deletion/namespaces/index.md>) |
| `ApplyJobSucceeded=False`/`IdentityNotAllowed` | The identity no longer allows the namespace, or is gone | Allow the namespace again, or abandon |
| `ApplyJobSucceeded=False`/`DestroyFailed` with a Job | The destroy failed; it retries with backoff forever | [Failing Jobs](<https://captf.io/docs/operator-guide/runbooks/job-failures/index.md>), then [Stuck Destroy](<https://captf.io/docs/operator-guide/runbooks/stuck-destroy/index.md>) |
| `DestroyFailed`, message `The durable inputs Secret is missing` | The destroy cannot be rendered | [Restore the Secret](<https://captf.io/docs/operator-guide/runbooks/stuck-destroy/#the-durable-inputs-secret-is-missing>), or abandon |
| `ApplyJobSucceeded=False`/`JobDeadlineExceeded` | The destroy ran out of time | Raise `activeDeadlineSeconds`; see [Tuning Jobs](<https://captf.io/docs/user-guide/job-tuning/#deadlines-and-lock-waits>) |
| `ApplyJobSucceeded=False`/`ImagePullFailed` or `ImageInvalid` | The pinned image cannot run | [Failing Jobs](<https://captf.io/docs/operator-guide/runbooks/job-failures/index.md>) |
| Nothing explains it | The manager is not reconciling | [Reconcile Errors](<https://captf.io/docs/operator-guide/runbooks/reconcile-errors/index.md>), [Webhook Unavailable](<https://captf.io/docs/operator-guide/runbooks/webhook-unavailable/index.md>) |

> [!NOTE]
>
> **A message that names the abandon annotation**
>
> It tells you the controller sees no way to proceed alone. The [abandon](<https://captf.io/docs/concepts/deletion/held/#abandon>) page lists exactly which cases the annotation releases, and an object whose state reads and whose destroy can start is destroyed anyway.

> [!CAUTION]
>
> **Abandoning or stripping leaves cloud resources running**
>
> A destroy that cannot be completed and an object that must go anyway end the same way: back up what you need, clean up the cloud resources, then either [abandon](<https://captf.io/docs/concepts/deletion/held/#abandon>) or [strip the finalizer](<https://captf.io/docs/concepts/deletion/manual-finalizer/index.md>).

> [!NOTE]
>
> **See also**
>
> - [Stuck Destroy](<https://captf.io/docs/operator-guide/runbooks/stuck-destroy/index.md>).
> - [Runbooks](<https://captf.io/docs/operator-guide/runbooks/index.md>).
