Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Annotations, Labels and Finalizers

Every annotation, label and finalizer key CAPTF sets or reads, generated from internal/docsgen’s registry, which references the real Go constants so a rename cannot leave this page stale.

User-facing keys

Keys the operator sets or reads.

KeyKindOnSet byRead byMeaning
captf.io/approve-destructive-planannotationTerraformCluster, TerraformMachine, TerraformMachinePoolthe operatorinternal/controllers/shared (the reconcile loop’s destructive-plan guard)Approves one destructive apply or drift remediation by naming the inputs hash it must render; the controller removes the annotation once an apply that used it succeeded.
captf.io/approve-planannotationTerraformCluster (applyPolicy Manual)the operatorinternal/controllers/shared (plan-preview approval check)Approves one plan by naming its hash (status.plan.planHash); the apply runs only if it plans exactly the same changes again. The controller removes the annotation once the apply succeeded.
captf.io/restore-stateannotationTerraformCluster, TerraformMachine, TerraformMachinePoolthe operatorinternal/controllers/shared (the restore path)Requests a state restore by naming the serial of a backup in status.stateBackups; the controller removes the annotation once the restore Job succeeded. Deletion wins over a pending restore.
captf.io/variableslabela ConfigMap or Secret named by spec.variablesFromthe operator, on their own ConfigMap or Secretinternal/controllers/shared (variables resolution) and the manager’s cache/watch selectorOpts a ConfigMap or Secret in as a variablesFrom source; CAPTF only reads objects that carry it. It is a standing opt-in, never removed by the controller.
captf.io/runnerlabela ServiceAccount named by spec.jobs.serviceAccountNamethe operator, on their own ServiceAccountinternal/rbac (the opt-in check gating whether a Job is created with it)Opts a custom runner ServiceAccount in, besides the default captf-runner. Without it the controller reports ServiceAccountNotOptedIn and creates no Job.

Internal keys

Keys CAPTF sets and reads itself; do not edit them.

KeyKindOnSet byRead byMeaning
captf.io/managedlabelevery object CAPTF owns (state Secrets, Leases, mirrors, run Jobs, the default runner ServiceAccount)the controllerthe manager’s cache and sweep selectors (internal/manager/cache.go)Selects everything CAPTF owns.
captf.infrastructure.cluster.x-k8s.io/owner-kindlabelstate Secrets and Leasesinternal/state.BackendLabelsinternal/state.Selector and internal/runleaseThe owning TerraformCluster/Machine/MachinePool’s kind, for backend and lease lookups.
captf.infrastructure.cluster.x-k8s.io/owner-namelabelstate Secrets and Leasesinternal/state.BackendLabelsinternal/state.Selector and internal/runleaseThe owning object’s name, for backend and lease lookups.
captf.io/inputs-hashannotationthe base state Secret (and chunk 0 of a state backup)internal/state (adopt) and internal/jobs.Buildinternal/state and internal/controllers/shared (blocked-apply and approval messages)The inputs hash of the state currently adopted. It is an annotation, not a label.
captf.io/state-backuplabela state backup chunk Secretinternal/state.TakeBackupinternal/state.BackupSelectorMarks a Secret as a state backup chunk.
captf.io/state-backup-suffixlabela state backup chunk Secretinternal/state.TakeBackupinternal/state.BackupSelectorThe backend Secret suffix the backup was taken from.
captf.io/state-backup-serialannotationa state backup chunk Secretinternal/state.TakeBackupinternal/state (ListBackups, FindBackup)The backup’s state serial.
captf.io/state-backup-lineageannotationa state backup chunk Secretinternal/state.TakeBackupinternal/state (ListBackups, FindBackup)The backend state’s lineage ID at backup time.
captf.io/state-backup-taken-atannotationa state backup chunk Secretinternal/state.TakeBackupinternal/state (ListBackups, FindBackup)When the backup was taken.
captf.io/state-backup-source-jobannotationa state backup chunk Secretinternal/state.TakeBackupinternal/state (ListBackups, FindBackup)The Job whose apply produced the backed-up state.
captf.io/state-backup-digestannotationa state backup chunk Secretinternal/state.TakeBackupinternal/state (conflict detection, FindBackup)A digest of the backed-up state, used to detect a concurrent conflicting backup.
captf.io/state-backup-resourcesannotationa state backup chunk Secretinternal/state.TakeBackupinternal/state (FindBackup)The backup’s managed resource count.
captf.io/state-backup-setannotationa state backup chunk Secretinternal/state.TakeBackupinternal/state.ListBackupsGroups a backup’s chunk Secrets into one backup.
captf.io/state-backup-chunkannotationa state backup chunk Secretinternal/state.TakeBackupinternal/state (FindBackup)The chunk’s index within its backup set.
captf.io/state-backup-chunksannotationa state backup chunk Secretinternal/state.TakeBackupinternal/state (FindBackup)The backup set’s total chunk count.
captf.io/leaselabela coordination.k8s.io Leaseinternal/runlease.Acquireinternal/runleaseDistinguishes a CAPTF run or cluster lease from the backend’s own lock Lease.
captf.io/lease-opannotationa coordination.k8s.io Leaseinternal/runlease.Acquireinternal/runleaseThe operation the lease holder is running, for diagnostics.
captf.io/lease-acquired-atannotationa coordination.k8s.io Leaseinternal/runlease.Acquireinternal/runlease.AcquiredAtWhen the lease was acquired.
captf.io/mirroredlabelthe identity credential mirror Secretinternal/identity.EnsureMirrorinternal/identity (conflict detection, Revoke)Marks a Secret as an identity credential mirror.
captf.io/source-hashannotationthe identity credential mirror Secretinternal/identity.EnsureMirrorinternal/identity.EnsureMirrorA hash of the source TerraformClusterIdentity’s credentials, so a change is detected and the mirror rewritten.
captf.io/bookkeptannotationa run Jobinternal/controllers/shared.MarkBookkeptinternal/controllers/shared (collectFinished)Marks a finished Job as already accounted for in status, so it is not double-counted.
captf.io/interruptedannotationa run Jobinternal/controllers/shared.MarkBookkeptinternal/controllers/shared (collectFinished, countFailures)Marks a Job that stopped without a clean result (for example, evicted mid-run).
captf.io/drift-remediationannotationa run Jobinternal/controllers/shared (Job creation on the drift-remediation path)internal/controllers/shared.applyDestroyMarks a Job as a drift-remediation apply, distinct from an ordinary apply.
captf.io/destructive-plan-blockedannotationa run Jobinternal/controllers/shared.MarkBookkeptinternal/controllers/shared (collectFinished, countFailures, DecideOp)Marks an apply that stopped because its plan was destructive and unapproved.
captf.io/plan-changedannotationa run Jobinternal/controllers/shared.MarkBookkeptinternal/controllers/shared (collectFinished, countFailures)Marks an apply that stopped because a re-plan under Manual applyPolicy no longer matched the approved plan.
captf.io/plan-unreadableannotationa run Jobinternal/controllers/shared.MarkBookkeptinternal/controllers/shared (collectFinished)Marks a Job whose plan result could not be parsed.
captf.io/approved-planannotationa run Jobinternal/controllers/shared (apply-Job creation under Manual applyPolicy)internal/controllers/shared (plan-approval comparison)Records the plan hash an apply Job was created to satisfy.
captf.io/restore-serialannotationa restore Jobinternal/jobs.Buildinternal/controllers/shared (the restore path)The state backup serial the restore Job pushes.
captf.infrastructure.cluster.x-k8s.io/oplabela run Job and its podinternal/jobs.Labelsinternal/jobs and internal/controllers/shared (listing/filtering Jobs by operation)The operation the Job runs (apply, destroy, refresh, drift, restore or plan).
captf.infrastructure.cluster.x-k8s.io/attemptlabela run Job and its podinternal/jobs.Labelsinternal/jobs and internal/controllers/shared (retry/attempt tracking)The Job’s attempt number.
captf.io/endpoint-sourceannotationTerraformClusterinternal/controllers/terraformcluster (EndpointInput, ModuleEndpoint)internal/controllers/terraformclusterRecords whether the control-plane endpoint came from the user or the module; written at most once.
captf.io/remediation-requestedannotationMachine (the CAPI object, not TerraformMachine)internal/controllers/terraformmachine.patchRemediationinternal/controllers/terraformmachine.patchRemediationMarks that CAPTF itself set clusterv1.RemediateMachineAnnotation, so it only ever clears an annotation it set.
captf.io/imageannotationthe durable inputs Secretinternal/inputsinternal/inputsRecords spec.source.image as last written, for digest pinning.
captf.io/image-digestannotationthe durable inputs Secretinternal/inputsinternal/inputsRecords the resolved image digest, so a floating tag is pinned across reconciles.
captf.io/identityannotationthe durable inputs Secret and the identity credential mirror Secretinternal/inputs and internal/identityinternal/inputs and internal/identityNames the TerraformClusterIdentity the credentials came from.

Finalizers

TerraformClusterIdentity has no finalizer: nothing external depends on it directly, so its controller deletes cleanly without one.

KeyKindOnSet byRead byMeaning
terraformcluster.infrastructure.cluster.x-k8s.iofinalizerTerraformClusterinternal/controllers/terraformclusterKubernetes garbage collectionBlocks deletion until the controller has torn down the cluster’s Terraform-managed resources.
terraformmachine.infrastructure.cluster.x-k8s.iofinalizerTerraformMachineinternal/controllers/terraformmachineKubernetes garbage collectionBlocks deletion until the controller has torn down the machine’s Terraform-managed resources.
terraformmachinepool.infrastructure.cluster.x-k8s.iofinalizerTerraformMachinePoolinternal/controllers/terraformmachinepoolKubernetes garbage collectionBlocks deletion until the controller has torn down the pool’s Terraform-managed resources.

Cluster API and clusterctl keys

Keys owned by Cluster API or clusterctl that CAPTF reads or writes, imported as their real constants rather than retyped.

KeyKindOnSet byRead byMeaning
cluster.x-k8s.io/cluster-namelabelTerraformCluster, TerraformMachine, TerraformMachinePool, run Jobs, state Secrets, LeasesCluster APIinternal/state, internal/jobs, internal/runlease and internal/controllers/shared, to scope objects to their owning ClusterThe owning Cluster’s name.
cluster.x-k8s.io/remediate-machineannotationMachine (the CAPI object)internal/controllers/terraformmachine.patchRemediation (guarded by RequestedByAnnotation)Cluster API’s machine health check / remediationRequests Cluster API remediate (replace) the Machine.
cluster.x-k8s.io/replicas-managed-byannotationTerraformMachinePoolinternal/controllers/terraformmachinepool.replicas (value “captf”)the cluster-autoscaler and Cluster APITells Cluster API and the autoscaler that CAPTF, not the autoscaler’s default path, owns spec.replicas.
cluster.x-k8s.io/cluster-api-autoscaler-node-group-min-sizeannotationTerraformMachinePoolthe operator (autoscaler contract)internal/controllers/terraformmachinepool.ParseAutoscalingThe pool’s minimum replica count under autoscaling.
cluster.x-k8s.io/cluster-api-autoscaler-node-group-max-sizeannotationTerraformMachinePoolthe operator (autoscaler contract)internal/controllers/terraformmachinepool.ParseAutoscalingThe pool’s maximum replica count under autoscaling.
clusterctl.cluster.x-k8s.io/movelabelstate Secrets and Leasesinternal/state.BackendLabelsclusterctl moveIncludes state Secrets and Leases in a clusterctl move.
clusterctl.cluster.x-k8s.io/delete-for-moveannotationTerraformMachineclusterctl moveinternal/webhooks (ValidateDelete, recognizes a move-driven delete when the Cluster is paused)Marks a delete that clusterctl move issues as part of moving the Cluster, not an ordinary delete.
clusterctl.cluster.x-k8s.io/move-hierarchylabelthe TerraformClusterIdentity CRD itselfconfig/crd/patches/move-hierarchy_terraformclusteridentities.yaml (a static kustomize patch)clusterctl moveTells clusterctl move to bring along objects that reference a TerraformClusterIdentity, not just the identity object.

captf_tags keys

The fixed keys internal/contract.Tags renders into every module’s captf_tags input variable (a Terraform tag map, not Kubernetes object metadata).

KeyKindOnSet byRead byMeaning
captf.io/clustertagcaptf_tags (every module)internal/contract.Tagsthe moduleThe owning Cluster’s name.
captf.io/namespacetagcaptf_tags (every module)internal/contract.Tagsthe moduleThe owning object’s namespace.
captf.io/kindtagcaptf_tags (every module)internal/contract.Tagsthe moduleThe owning object’s kind (TerraformCluster, TerraformMachine or TerraformMachinePool).
captf.io/nametagcaptf_tags (every module)internal/contract.Tagsthe moduleThe owning object’s name.
captf.io/managed-bytagcaptf_tags (every module)internal/contract.Tagsthe moduleAlways captf: marks infrastructure CAPTF manages.
captf.io/templatetagcaptf_tags (every module)internal/contract.Tagsthe moduleThe object’s cluster.x-k8s.io/cloned-from-name annotation, or empty when absent.