Conditions
Every condition CAPTF sets, per object kind, its polarity, and the meaning of each reason it can carry. See Observability for how conditions surface in kubectl describe and events.
Ready
Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool, TerraformClusterIdentity.
Polarity: normal (True is healthy).
| Status | Reason | Meaning |
|---|---|---|
| True | Ready | The Ready reason when every input is healthy. |
| True | SecretFound | The True reason when the identity’s credentials Secret exists. |
| False | NotReady | The Ready reason when an input is False. |
| False | SecretNotFound | The False reason when the identity’s Secret does not exist. |
| Unknown | ReadyUnknown | The Ready reason when an input is Unknown. |
DependenciesReady
Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.
Polarity: normal (True is healthy).
| Status | Reason | Meaning |
|---|---|---|
| True | DependenciesReady | The True reason. |
| False | ClusterNotTerraform | The False reason when the owning Cluster’s infrastructureRef is not a TerraformCluster; nothing is rendered or run. |
| False | OwnerMismatch | The False reason when an ownerRef of the expected kind resolves to an object that does not reference this one back (wrong or missing infrastructureRef, a UID mismatch, or a cluster-name label that disagrees with the owner): the ownerRef is forged or stale, so the object is treated as having no valid owner; no Job runs and nothing is written to the named owner or its Cluster. |
| False | OwnerNotFound | The False reason when the owner object is gone. |
| False | VariablesInvalid | The False reason when a variablesFrom source has a key that is not a Terraform identifier or is reserved, or a value that is not UTF-8 or (format JSON) not valid JSON. The message names the key, never the value; no Job starts. |
| False | VariablesSourceNotFound | The False reason when a ConfigMap or Secret named by spec.variablesFrom (not optional) is missing or does not carry captf.io/variables=true; no Job starts. |
| False | WaitingForOwnerMachine | The False reason when a fresh TerraformMachine has only a non-controller control-plane ownerRef and no Machine ownerRef yet. |
| False | WaitingForOwnerMachinePool | The False reason when a TerraformMachinePool has ownerRefs but no MachinePool ownerRef yet. |
| Unknown | WaitingForBootstrapData | The Unknown reason while the Machine’s or MachinePool’s bootstrap data Secret is not set or not found. |
| Unknown | WaitingForClusterExports | The Unknown reason while the cluster module’s exports output is not readable. |
| Unknown | WaitingForClusterInfrastructure | The Unknown reason while the TerraformCluster is not provisioned. |
| Unknown | WaitingForOwner | The Unknown reason while the owner is not set. |
IdentityAllowed
Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.
Polarity: normal (True is healthy).
| Status | Reason | Meaning |
|---|---|---|
| True | IdentityAllowed | The True reason. |
| False | IdentityNotFound | The False reason when the identity does not exist. |
| False | NamespaceNotAllowed | The False reason when allowedNamespaces excludes this namespace. |
| False | SecretNotFound | The False reason when the identity’s Secret does not exist. |
| Unknown | IdentityCheckFailed | The Unknown reason when the check could not be completed. |
CredentialsMirrored
Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.
Polarity: normal (True is healthy).
| Status | Reason | Meaning |
|---|---|---|
| True | Mirrored | The True reason. |
| False | MirrorFailed | The False reason when mirroring failed. |
| Unknown | MirrorPending | The Unknown reason before the first mirror. |
RunnerRBACReady
Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.
Polarity: normal (True is healthy).
| Status | Reason | Meaning |
|---|---|---|
| True | RBACReady | The True reason. |
| False | RBACFailed | The False reason when creating the binding failed. |
| False | ServiceAccountNotOptedIn | The False reason when an override ServiceAccount lacks the captf.io/runner=true label. |
ApplyJobSucceeded
Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.
Polarity: normal (True is healthy).
| Status | Reason | Meaning |
|---|---|---|
| True | ApplySucceeded | The True reason after an apply. |
| True | DestroySucceeded | The True reason after a destroy. |
| False | ApplyFailed | The False reason when an apply Job failed. |
| False | DestroyFailed | The False reason when a destroy Job failed. |
| False | DestructivePlanBlocked | The False reason when a TerraformCluster apply (including a drift remediation) stopped before a plan that deletes or replaces resources: the captf.io/approve-destructive-plan annotation does not name the inputs hash it renders. No apply of that hash runs until it does, or the inputs change. |
| False | IdentityNotAllowed | The False reason when no Job could be created because the identity is not allowed. |
| False | ImageInvalid | The False reason when the runner reported an image-layout error (missing /captf/module or a non-executable command). |
| False | ImagePullFailed | The False reason when the pod stayed in ErrImagePull/ImagePullBackOff past activeDeadlineSeconds. |
| False | InputsTooLarge | The False reason when the rendered root module and variables exceed the size a Secret can carry, so no Job starts. |
| False | JobDeadlineExceeded | The False reason when the Job hit activeDeadlineSeconds. |
| Unknown | NoApplyYet | The Unknown reason before the first apply completes. |
| Unknown | PlanAwaitingApproval | The Unknown reason while a TerraformCluster with applyPolicy Manual waits for the approval of the plan in status.plan (the captf.io/approve-plan annotation naming its hash). Unknown, so waiting never turns Ready False. |
| Unknown | PlanChanged | The Unknown reason when an approved apply planned other changes than the approved plan and stopped before applying them; the new plan in status.plan waits for its approval. |
| Unknown | WaitingForClusterOperation | The Unknown reason while a machine’s or pool’s apply or destroy waits for its TerraformCluster’s apply or destroy to finish. |
| Unknown | WaitingForMachineOperations | The Unknown reason while a TerraformCluster’s apply or destroy waits for its machines’ and pools’ applies and destroys in flight to finish; new ones wait for it meanwhile. |
| Unknown | WaitingForRunLease | The Unknown reason while the object’s run lease is held by another live Job, for example one another manager instance started: no Job starts until it finishes. It is also the DriftJobSucceeded reason for a refresh or drift that waits. |
StateReadable
Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.
Polarity: normal (True is healthy).
| Status | Reason | Meaning |
|---|---|---|
| True | StateRead | The True reason. |
| False | StateCorrupt | The False reason when the state cannot be decoded. |
| False | StateEncrypted | The False reason for OpenTofu-encrypted state, which v1 does not support. |
| False | StateInconsistent | The False reason when state chunks disagree. |
| False | StateLocked | The False reason while the state lock is held by something other than the object’s own runner, such as a workstation; every Job waits lockTimeoutSeconds for it and then fails. |
| False | StateLost | The False reason when a provisioned object’s state Secret is missing, or carries no inputs hash for an immutable kind: no Job runs until the state is restored. |
| Unknown | StateNotFound | The Unknown reason when no state exists yet. |
RestoreJobSucceeded
Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.
Polarity: normal (True is healthy).
| Status | Reason | Meaning |
|---|---|---|
| True | StateRestored | The True reason: the restore Job pushed the backup into the backend. |
| False | RestoreBackupNotFound | The False reason when the annotation names no existing backup (or is not a serial); no Job starts. |
| False | RestoreFailed | The False reason when the restore Job failed. It is not retried for the same serial until the annotation changes or the failed Job is deleted. |
| Unknown | WaitingForClusterOperation | The Unknown reason while a machine’s or pool’s apply or destroy waits for its TerraformCluster’s apply or destroy to finish. |
| Unknown | WaitingForMachineOperations | The Unknown reason while a TerraformCluster’s apply or destroy waits for its machines’ and pools’ applies and destroys in flight to finish; new ones wait for it meanwhile. |
| Unknown | WaitingForRunLease | The Unknown reason while the object’s run lease is held by another live Job, for example one another manager instance started: no Job starts until it finishes. It is also the DriftJobSucceeded reason for a refresh or drift that waits. |
OutputsValid
Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.
Polarity: normal (True is healthy).
| Status | Reason | Meaning |
|---|---|---|
| True | InstancesTruncated | A True reason: the machinepool role’s instances output had more entries than the controller keeps (internal/outputs.MaxInstances) and was shortened. The pool still provisions; nothing else about its outputs is invalid. |
| True | OutputsValid | The True reason. |
| False | FailureDomainMismatch | The False reason when a machine’s failure_domain output differs from the requested failure domain. |
| False | OutputsInvalid | The False reason when an output violates the contract or a Cluster API marker. |
| False | OutputsMissing | The False reason when a required output is not declared. |
| False | ProviderIDChanged | The False reason when provider_id changed after it was first written. |
| Unknown | OutputsPending | The Unknown reason while required outputs are null. |
InfrastructureHealthy
Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.
Polarity: normal (True is healthy).
| Status | Reason | Meaning |
|---|---|---|
| True | Healthy | The True reason (state running, healthy true). |
| False | InstanceDegraded | The False reason for health state degraded. |
| False | InstancePending | The False reason for health state pending. |
| False | InstanceStopped | The False reason for health state stopped. |
| False | InstanceTerminated | The False reason for health state terminated or a vanished instance. |
| False | InstanceUnhealthy | The False reason for state running, healthy false. |
| False | Provisioning | The False reason from the first apply start until provisioned. |
| Unknown | HealthUnknown | The Unknown reason for health state unknown. |
| Unknown | WaitingForProvisioning | The Unknown reason before the first apply. |
DriftJobSucceeded
Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.
Polarity: normal (True is healthy).
| Status | Reason | Meaning |
|---|---|---|
| True | DriftChecked | The True reason. |
| False | DriftJobDeadlineExceeded | The False reason when the drift Job hit activeDeadlineSeconds. |
| False | DriftJobFailed | The False reason when the drift Job failed. |
| Unknown | DriftJobRunning | The Unknown reason while a drift Job runs. |
| Unknown | DriftNotChecked | The Unknown reason before the first drift check (also used by DriftDetected). |
| Unknown | WaitingForRunLease | The Unknown reason while the object’s run lease is held by another live Job, for example one another manager instance started: no Job starts until it finishes. It is also the DriftJobSucceeded reason for a refresh or drift that waits. |
DriftDetected
Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.
Polarity: negative (True is the problem).
| Status | Reason | Meaning |
|---|---|---|
| True | DriftPending | The True reason while remediation is pending, and after a failed cluster re-apply. |
| True | DriftRemediating | The True reason while a remediation apply runs. |
| True | DriftReported | The True reason with drift action Report. |
| False | NoDrift | The False reason. |
| Unknown | DriftNotChecked | The Unknown reason before the first drift check (also used by DriftDetected). |
DeletionBlocked
Carried by: TerraformCluster.
Polarity: negative (True is the problem).
| Status | Reason | Meaning |
|---|---|---|
| True | DependentsExist | The True reason. |
| False | NotBlocked | The False reason. |
EndpointAvailable
Carried by: TerraformCluster.
Polarity: normal (True is healthy).
| Status | Reason | Meaning |
|---|---|---|
| True | EndpointAvailable | The True reason. |
| False | WaitingForEndpoint | The False reason when the cluster is provisioned and neither the module output nor Cluster.spec has a valid endpoint. |
AutoscalingActive
Carried by: TerraformMachinePool.
Polarity: normal (True is healthy).
| Status | Reason | Meaning |
|---|---|---|
| True | ReplicasManagedByModule | The True reason: both annotations are present and valid, and the controller writes the observed replicas back to MachinePool.spec.replicas. |
| False | AutoscalingAnnotationsInvalid | The False reason when an annotation is present but the pair is incomplete, unparsable, or min > max; the message names the problem. The pool still applies without autoscaling. |
| False | AutoscalingDisabled | The False reason when neither annotation is set: MachinePool.spec.replicas is the sole source of desired capacity. |
CapacityResolved
Carried by: TerraformMachineTemplate.
Polarity: normal (True is healthy).
| Status | Reason | Meaning |
|---|---|---|
| True | CapacityNotDeclared | The True reason when the image carries neither label. |
| True | CapacityResolved | The True reason when both labels parsed. |
| False | CapacityLabelInvalid | The False reason when a label is present but invalid. |
| False | ImageInspectFailed | The False reason when the registry fetch or authentication failed. |
Paused
Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.
Polarity: normal (True is healthy).
| Status | Reason | Meaning |
|---|---|---|
| True | Paused | When an object is paused. |
| False | NotPaused | When an object is not paused. |
Deleting
Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.
Polarity: negative (True is the problem).
| Status | Reason | Meaning |
|---|---|---|
| True | Deleting | When an object is deleting because the DeletionTimestamp is set; used if none of the more specific reasons apply. |
| True | DeletionCompleted | When the deletion process has completed; set right after the corresponding finalizer is removed. |
| False | NotDeleting | When an object is not deleting because the DeletionTimestamp is not set. |
Ready summarization
Ready summarizes other conditions (sigs.k8s.io/cluster-api/util/conditions.SetSummaryCondition); it is the only condition Cluster API itself reads, mirrored into the Cluster’s or Machine’s InfrastructureReady. Which conditions feed it depends on the kind and on whether status.initialization.provisioned has latched true.
Before provisioning, every kind below summarizes the same inputs:
DependenciesReadyIdentityAllowedCredentialsMirroredRunnerRBACReadyApplyJobSucceededStateReadableOutputsValidInfrastructureHealthyDeleting
After provisioning, the inputs differ per kind:
- TerraformCluster:
InfrastructureHealthy,Deleting - TerraformMachine:
InfrastructureHealthy,Deleting - TerraformMachinePool:
InfrastructureHealthy,ApplyJobSucceeded,Deleting
TerraformMachinePool includes ApplyJobSucceeded after provisioning (unlike the cluster and the machine): a pool is mutable and re-applied on bootstrap rotation, so a failed re-apply must be visible in Ready.
TerraformClusterIdentity has a Ready condition of its own, set directly from whether its credentials Secret exists (SecretFound/SecretNotFound), not summarized from other conditions.