Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Conditions

Every condition CAPTF sets, per object kind, its polarity, and the meaning of each reason it can carry. See Observability for how conditions surface in kubectl describe and events.

Ready

Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool, TerraformClusterIdentity.

Polarity: normal (True is healthy).

StatusReasonMeaning
TrueReadyThe Ready reason when every input is healthy.
TrueSecretFoundThe True reason when the identity’s credentials Secret exists.
FalseNotReadyThe Ready reason when an input is False.
FalseSecretNotFoundThe False reason when the identity’s Secret does not exist.
UnknownReadyUnknownThe Ready reason when an input is Unknown.

DependenciesReady

Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.

Polarity: normal (True is healthy).

StatusReasonMeaning
TrueDependenciesReadyThe True reason.
FalseClusterNotTerraformThe False reason when the owning Cluster’s infrastructureRef is not a TerraformCluster; nothing is rendered or run.
FalseOwnerMismatchThe False reason when an ownerRef of the expected kind resolves to an object that does not reference this one back (wrong or missing infrastructureRef, a UID mismatch, or a cluster-name label that disagrees with the owner): the ownerRef is forged or stale, so the object is treated as having no valid owner; no Job runs and nothing is written to the named owner or its Cluster.
FalseOwnerNotFoundThe False reason when the owner object is gone.
FalseVariablesInvalidThe False reason when a variablesFrom source has a key that is not a Terraform identifier or is reserved, or a value that is not UTF-8 or (format JSON) not valid JSON. The message names the key, never the value; no Job starts.
FalseVariablesSourceNotFoundThe False reason when a ConfigMap or Secret named by spec.variablesFrom (not optional) is missing or does not carry captf.io/variables=true; no Job starts.
FalseWaitingForOwnerMachineThe False reason when a fresh TerraformMachine has only a non-controller control-plane ownerRef and no Machine ownerRef yet.
FalseWaitingForOwnerMachinePoolThe False reason when a TerraformMachinePool has ownerRefs but no MachinePool ownerRef yet.
UnknownWaitingForBootstrapDataThe Unknown reason while the Machine’s or MachinePool’s bootstrap data Secret is not set or not found.
UnknownWaitingForClusterExportsThe Unknown reason while the cluster module’s exports output is not readable.
UnknownWaitingForClusterInfrastructureThe Unknown reason while the TerraformCluster is not provisioned.
UnknownWaitingForOwnerThe Unknown reason while the owner is not set.

IdentityAllowed

Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.

Polarity: normal (True is healthy).

StatusReasonMeaning
TrueIdentityAllowedThe True reason.
FalseIdentityNotFoundThe False reason when the identity does not exist.
FalseNamespaceNotAllowedThe False reason when allowedNamespaces excludes this namespace.
FalseSecretNotFoundThe False reason when the identity’s Secret does not exist.
UnknownIdentityCheckFailedThe Unknown reason when the check could not be completed.

CredentialsMirrored

Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.

Polarity: normal (True is healthy).

StatusReasonMeaning
TrueMirroredThe True reason.
FalseMirrorFailedThe False reason when mirroring failed.
UnknownMirrorPendingThe Unknown reason before the first mirror.

RunnerRBACReady

Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.

Polarity: normal (True is healthy).

StatusReasonMeaning
TrueRBACReadyThe True reason.
FalseRBACFailedThe False reason when creating the binding failed.
FalseServiceAccountNotOptedInThe False reason when an override ServiceAccount lacks the captf.io/runner=true label.

ApplyJobSucceeded

Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.

Polarity: normal (True is healthy).

StatusReasonMeaning
TrueApplySucceededThe True reason after an apply.
TrueDestroySucceededThe True reason after a destroy.
FalseApplyFailedThe False reason when an apply Job failed.
FalseDestroyFailedThe False reason when a destroy Job failed.
FalseDestructivePlanBlockedThe False reason when a TerraformCluster apply (including a drift remediation) stopped before a plan that deletes or replaces resources: the captf.io/approve-destructive-plan annotation does not name the inputs hash it renders. No apply of that hash runs until it does, or the inputs change.
FalseIdentityNotAllowedThe False reason when no Job could be created because the identity is not allowed.
FalseImageInvalidThe False reason when the runner reported an image-layout error (missing /captf/module or a non-executable command).
FalseImagePullFailedThe False reason when the pod stayed in ErrImagePull/ImagePullBackOff past activeDeadlineSeconds.
FalseInputsTooLargeThe False reason when the rendered root module and variables exceed the size a Secret can carry, so no Job starts.
FalseJobDeadlineExceededThe False reason when the Job hit activeDeadlineSeconds.
UnknownNoApplyYetThe Unknown reason before the first apply completes.
UnknownPlanAwaitingApprovalThe Unknown reason while a TerraformCluster with applyPolicy Manual waits for the approval of the plan in status.plan (the captf.io/approve-plan annotation naming its hash). Unknown, so waiting never turns Ready False.
UnknownPlanChangedThe Unknown reason when an approved apply planned other changes than the approved plan and stopped before applying them; the new plan in status.plan waits for its approval.
UnknownWaitingForClusterOperationThe Unknown reason while a machine’s or pool’s apply or destroy waits for its TerraformCluster’s apply or destroy to finish.
UnknownWaitingForMachineOperationsThe Unknown reason while a TerraformCluster’s apply or destroy waits for its machines’ and pools’ applies and destroys in flight to finish; new ones wait for it meanwhile.
UnknownWaitingForRunLeaseThe Unknown reason while the object’s run lease is held by another live Job, for example one another manager instance started: no Job starts until it finishes. It is also the DriftJobSucceeded reason for a refresh or drift that waits.

StateReadable

Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.

Polarity: normal (True is healthy).

StatusReasonMeaning
TrueStateReadThe True reason.
FalseStateCorruptThe False reason when the state cannot be decoded.
FalseStateEncryptedThe False reason for OpenTofu-encrypted state, which v1 does not support.
FalseStateInconsistentThe False reason when state chunks disagree.
FalseStateLockedThe False reason while the state lock is held by something other than the object’s own runner, such as a workstation; every Job waits lockTimeoutSeconds for it and then fails.
FalseStateLostThe False reason when a provisioned object’s state Secret is missing, or carries no inputs hash for an immutable kind: no Job runs until the state is restored.
UnknownStateNotFoundThe Unknown reason when no state exists yet.

RestoreJobSucceeded

Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.

Polarity: normal (True is healthy).

StatusReasonMeaning
TrueStateRestoredThe True reason: the restore Job pushed the backup into the backend.
FalseRestoreBackupNotFoundThe False reason when the annotation names no existing backup (or is not a serial); no Job starts.
FalseRestoreFailedThe False reason when the restore Job failed. It is not retried for the same serial until the annotation changes or the failed Job is deleted.
UnknownWaitingForClusterOperationThe Unknown reason while a machine’s or pool’s apply or destroy waits for its TerraformCluster’s apply or destroy to finish.
UnknownWaitingForMachineOperationsThe Unknown reason while a TerraformCluster’s apply or destroy waits for its machines’ and pools’ applies and destroys in flight to finish; new ones wait for it meanwhile.
UnknownWaitingForRunLeaseThe Unknown reason while the object’s run lease is held by another live Job, for example one another manager instance started: no Job starts until it finishes. It is also the DriftJobSucceeded reason for a refresh or drift that waits.

OutputsValid

Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.

Polarity: normal (True is healthy).

StatusReasonMeaning
TrueInstancesTruncatedA True reason: the machinepool role’s instances output had more entries than the controller keeps (internal/outputs.MaxInstances) and was shortened. The pool still provisions; nothing else about its outputs is invalid.
TrueOutputsValidThe True reason.
FalseFailureDomainMismatchThe False reason when a machine’s failure_domain output differs from the requested failure domain.
FalseOutputsInvalidThe False reason when an output violates the contract or a Cluster API marker.
FalseOutputsMissingThe False reason when a required output is not declared.
FalseProviderIDChangedThe False reason when provider_id changed after it was first written.
UnknownOutputsPendingThe Unknown reason while required outputs are null.

InfrastructureHealthy

Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.

Polarity: normal (True is healthy).

StatusReasonMeaning
TrueHealthyThe True reason (state running, healthy true).
FalseInstanceDegradedThe False reason for health state degraded.
FalseInstancePendingThe False reason for health state pending.
FalseInstanceStoppedThe False reason for health state stopped.
FalseInstanceTerminatedThe False reason for health state terminated or a vanished instance.
FalseInstanceUnhealthyThe False reason for state running, healthy false.
FalseProvisioningThe False reason from the first apply start until provisioned.
UnknownHealthUnknownThe Unknown reason for health state unknown.
UnknownWaitingForProvisioningThe Unknown reason before the first apply.

DriftJobSucceeded

Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.

Polarity: normal (True is healthy).

StatusReasonMeaning
TrueDriftCheckedThe True reason.
FalseDriftJobDeadlineExceededThe False reason when the drift Job hit activeDeadlineSeconds.
FalseDriftJobFailedThe False reason when the drift Job failed.
UnknownDriftJobRunningThe Unknown reason while a drift Job runs.
UnknownDriftNotCheckedThe Unknown reason before the first drift check (also used by DriftDetected).
UnknownWaitingForRunLeaseThe Unknown reason while the object’s run lease is held by another live Job, for example one another manager instance started: no Job starts until it finishes. It is also the DriftJobSucceeded reason for a refresh or drift that waits.

DriftDetected

Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.

Polarity: negative (True is the problem).

StatusReasonMeaning
TrueDriftPendingThe True reason while remediation is pending, and after a failed cluster re-apply.
TrueDriftRemediatingThe True reason while a remediation apply runs.
TrueDriftReportedThe True reason with drift action Report.
FalseNoDriftThe False reason.
UnknownDriftNotCheckedThe Unknown reason before the first drift check (also used by DriftDetected).

DeletionBlocked

Carried by: TerraformCluster.

Polarity: negative (True is the problem).

StatusReasonMeaning
TrueDependentsExistThe True reason.
FalseNotBlockedThe False reason.

EndpointAvailable

Carried by: TerraformCluster.

Polarity: normal (True is healthy).

StatusReasonMeaning
TrueEndpointAvailableThe True reason.
FalseWaitingForEndpointThe False reason when the cluster is provisioned and neither the module output nor Cluster.spec has a valid endpoint.

AutoscalingActive

Carried by: TerraformMachinePool.

Polarity: normal (True is healthy).

StatusReasonMeaning
TrueReplicasManagedByModuleThe True reason: both annotations are present and valid, and the controller writes the observed replicas back to MachinePool.spec.replicas.
FalseAutoscalingAnnotationsInvalidThe False reason when an annotation is present but the pair is incomplete, unparsable, or min > max; the message names the problem. The pool still applies without autoscaling.
FalseAutoscalingDisabledThe False reason when neither annotation is set: MachinePool.spec.replicas is the sole source of desired capacity.

CapacityResolved

Carried by: TerraformMachineTemplate.

Polarity: normal (True is healthy).

StatusReasonMeaning
TrueCapacityNotDeclaredThe True reason when the image carries neither label.
TrueCapacityResolvedThe True reason when both labels parsed.
FalseCapacityLabelInvalidThe False reason when a label is present but invalid.
FalseImageInspectFailedThe False reason when the registry fetch or authentication failed.

Paused

Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.

Polarity: normal (True is healthy).

StatusReasonMeaning
TruePausedWhen an object is paused.
FalseNotPausedWhen an object is not paused.

Deleting

Carried by: TerraformCluster, TerraformMachine, TerraformMachinePool.

Polarity: negative (True is the problem).

StatusReasonMeaning
TrueDeletingWhen an object is deleting because the DeletionTimestamp is set; used if none of the more specific reasons apply.
TrueDeletionCompletedWhen the deletion process has completed; set right after the corresponding finalizer is removed.
FalseNotDeletingWhen an object is not deleting because the DeletionTimestamp is not set.

Ready summarization

Ready summarizes other conditions (sigs.k8s.io/cluster-api/util/conditions.SetSummaryCondition); it is the only condition Cluster API itself reads, mirrored into the Cluster’s or Machine’s InfrastructureReady. Which conditions feed it depends on the kind and on whether status.initialization.provisioned has latched true.

Before provisioning, every kind below summarizes the same inputs:

  • DependenciesReady
  • IdentityAllowed
  • CredentialsMirrored
  • RunnerRBACReady
  • ApplyJobSucceeded
  • StateReadable
  • OutputsValid
  • InfrastructureHealthy
  • Deleting

After provisioning, the inputs differ per kind:

  • TerraformCluster: InfrastructureHealthy, Deleting
  • TerraformMachine: InfrastructureHealthy, Deleting
  • TerraformMachinePool: InfrastructureHealthy, ApplyJobSucceeded, Deleting

TerraformMachinePool includes ApplyJobSucceeded after provisioning (unlike the cluster and the machine): a pool is mutable and re-applied on bootstrap rotation, so a failed re-apply must be visible in Ready.

TerraformClusterIdentity has a Ready condition of its own, set directly from whether its credentials Secret exists (SecretFound/SecretNotFound), not summarized from other conditions.