Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Manager Flags

The CAPTF controller manager (manager) is a Kubernetes controller-runtime binary, built on cobra and k8s.io/component-base, following the same flag conventions as kube-controller-manager and friends. Flags below use dashes; the command line also accepts underscores (cliflag.WordSepNormalizeFunc).

CAPTF

FlagTypeDefaultDescription
--cluster-operation-gatebooltrueKeep a TerraformCluster’s apply or destroy and its machines’ applies and destroys from running at once, through a per-Cluster write Lease. The per-object run Lease is always on.
--drift-default-intervalduration30m0sDrift check interval for objects that set none.
--runner-eventsbooltrueHave Job runners emit progress events (RunStarted, Step*, PlanSummary, ResourcesChanged, RunFinished) on the owning Terraform* object. Needs events create in the runner ClusterRole.
--runner-imagestringImage of the init container that injects the runner binary into Jobs. Defaults to $CAPTF_MANAGER_IMAGE, the manager’s own image.
--state-backupsint5State backups to keep per object: every new state serial is copied into captf-state-backup-* Secrets and older copies are pruned. 0 takes no backups (existing ones stay and can still be restored).

Controllers and concurrency

FlagTypeDefaultDescription
--namespacestringNamespace that the controller watches to reconcile objects. If unspecified, the controller watches all namespaces.
--sync-periodduration10m0sThe minimum interval at which watched resources are reconciled (e.g. 15m)
--terraformcluster-concurrencyint10Number of TerraformClusters to process simultaneously
--terraformmachine-concurrencyint10Number of TerraformMachines to process simultaneously
--terraformmachinepool-concurrencyint10Number of TerraformMachinePools to process simultaneously
--terraformmachinetemplate-concurrencyint10Number of TerraformMachineTemplates to process simultaneously
--watch-filterstringLabel value that the controller watches to reconcile objects. Label key is always cluster.x-k8s.io/watch-filter. If unspecified, the controller watches all objects.

Leader election

FlagTypeDefaultDescription
--leader-electboolfalseEnable leader election for the controller manager, ensuring there is only one active manager.
--leader-elect-lease-durationduration15sInterval at which non-leader candidates will wait to force acquire leadership (duration string)
--leader-elect-renew-deadlineduration10sDuration that the leading controller manager will retry refreshing leadership before giving up (duration string)
--leader-elect-retry-periodduration2sDuration the LeaderElector clients should wait between tries of actions (duration string)

Webhooks

FlagTypeDefaultDescription
--webhook-cert-dirstring/tmp/k8s-webhook-server/serving-certs/Directory holding the webhook server’s serving certificate and key (mounted from the cert-manager Secret).
--webhook-cert-namestringtls.crtFile name of the serving certificate in –webhook-cert-dir.
--webhook-key-namestringtls.keyFile name of the serving key in –webhook-cert-dir.
--webhook-portint9443Port the webhook server listens on.

Diagnostics and TLS (CAPI)

FlagTypeDefaultDescription
--diagnostics-addressstring:8443The address the diagnostics endpoint binds to. Per default metrics are served via https and withauthentication/authorization. To serve via http and without authentication/authorization set –insecure-diagnostics. If –insecure-diagnostics is not set the diagnostics endpoint also serves pprof endpoints and an endpoint to change the log level.
--insecure-diagnosticsboolfalseEnable insecure diagnostics serving. For more details see the description of –diagnostics-address.
--tls-cipher-suitesstringSlice[]Comma-separated list of cipher suites for the webhook server and metrics server (the latter only if –insecure-diagnostics is not set to true). If omitted, the default Go cipher suites will be used. Preferred values: TLS_AES_128_GCM_SHA256, TLS_AES_256_GCM_SHA384, TLS_CHACHA20_POLY1305_SHA256, TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA, TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305, TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305, TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256. Insecure values: TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_RSA_WITH_RC4_128_SHA, TLS_RSA_WITH_3DES_EDE_CBC_SHA, TLS_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_128_CBC_SHA256, TLS_RSA_WITH_AES_128_GCM_SHA256, TLS_RSA_WITH_AES_256_CBC_SHA, TLS_RSA_WITH_AES_256_GCM_SHA384, TLS_RSA_WITH_RC4_128_SHA.
--tls-curve-preferencesint32Slice[]Comma-separated list of numeric Go crypto/tls CurveID values, as the allowed key exchange mechanisms for the webhook server and metrics server (the latter only if –insecure-diagnostics is not set to true). The supported values depend on the Go version used. See https://pkg.go.dev/crypto/tls#CurveID for values supported for each Go version. The order of the list is ignored, and key exchange mechanisms are chosen by Go from this list using an internal preference order. If omitted, the default Go curves will be used.
--tls-min-versionstringVersionTLS12The minimum TLS version in use by the webhook server and metrics server (the latter only if –insecure-diagnostics is not set to true). Possible values are VersionTLS10, VersionTLS11, VersionTLS12, VersionTLS13.

Logging

FlagTypeDefaultDescription
--feature-gatesmapStringBoolA set of key=value pairs that describe feature gates for alpha/experimental features. Options are: AllAlpha=true|false (ALPHA - default=false) AllBeta=true|false (BETA - default=false) ContextualLogging=true|false (BETA - default=true) LoggingAlphaOptions=true|false (ALPHA - default=false) LoggingBetaOptions=true|false (BETA - default=true)
--log-flush-frequencyduration5sMaximum number of seconds between log flushes
--log-json-info-buffer-sizequantity0[Alpha] In JSON format with split output streams, the info messages can be buffered for a while to increase performance. The default value of zero bytes disables buffering. The size can be specified as number of bytes (512), multiples of 1000 (1K), multiples of 1024 (2Ki), or powers of those (3M, 4G, 5Mi, 6Gi). Enable the LoggingAlphaOptions feature gate to use this.
--log-json-split-streamboolfalse[Alpha] In JSON format, write error messages to stderr and info messages to stdout. The default is to write a single stream to stdout. Enable the LoggingAlphaOptions feature gate to use this.
--log-text-info-buffer-sizequantity0[Alpha] In text format with split output streams, the info messages can be buffered for a while to increase performance. The default value of zero bytes disables buffering. The size can be specified as number of bytes (512), multiples of 1000 (1K), multiples of 1024 (2Ki), or powers of those (3M, 4G, 5Mi, 6Gi). Enable the LoggingAlphaOptions feature gate to use this.
--log-text-split-streamboolfalse[Alpha] In text format, write error messages to stderr and info messages to stdout. The default is to write a single stream to stdout. Enable the LoggingAlphaOptions feature gate to use this.
--logging-formatstringtextSets the log format. Permitted formats: “json” (gated by LoggingBetaOptions), “text”.
-v, --vLevel2number for the log level verbosity
--vmodulepattern=N,...comma-separated list of pattern=N settings for file-filtered logging (only works for text log format)

Other

FlagTypeDefaultDescription
--health-addrstring:9440The address the health endpoint binds to.
-h, --helpboolfalsehelp for manager
--kubeconfigstringPaths to a kubeconfig. Only required if out-of-cluster.
--profiler-addressstringBind address to expose the pprof profiler (e.g. localhost:6060)
--versionversionfalse–version, –version=raw prints version information and quits; –version=vX.Y.Z… sets the reported version

Feature gates

--feature-gates takes a comma-separated Key=value list. v1 registers no CAPTF feature of its own; the gates below are the component-base logging gates, which logsv1.ValidateAndApply reads.

NameDefaultMaturity
AllAlphafalseALPHA
AllBetafalseBETA
ContextualLoggingtrueBETA
LoggingAlphaOptionsfalseALPHA
LoggingBetaOptionstrueBETA

Environment variables

This list is maintained by hand in internal/docsgen/manager.go, alongside the flags it documents.

VariableDescription
CAPTF_MANAGER_IMAGEDefault of –runner-image, the image of the init container that injects the runner binary into Jobs. Set by the shipped Deployment to the manager’s own image.
KUBECONFIGRead by controller-runtime’s –kubeconfig flag handling (ctrl.RegisterFlags) when –kubeconfig is not given and the manager runs out-of-cluster.

version

manager version and manager --version (or --version=raw) both print the build stamp and exit.

Shipped manifest

config/manager/manager.yaml sets these arguments on the manager container:

FlagValue
--leader-elect
--diagnostics-address:8443
--insecure-diagnosticsfalse
--webhook-port9443