The CAPTF controller manager (manager) is a Kubernetes controller-runtime binary, built on cobra and k8s.io/component-base, following the same flag conventions as kube-controller-manager and friends. Flags below use dashes; the command line also accepts underscores (cliflag.WordSepNormalizeFunc).
Keep a TerraformCluster’s apply or destroy and its machines’ applies and destroys from running at once, through a per-Cluster write Lease. The per-object run Lease is always on.
--drift-default-interval
duration
30m0s
Drift check interval for objects that set none.
--runner-events
bool
true
Have Job runners emit progress events (RunStarted, Step*, PlanSummary, ResourcesChanged, RunFinished) on the owning Terraform* object. Needs events create in the runner ClusterRole.
--runner-image
string
Image of the init container that injects the runner binary into Jobs. Defaults to $CAPTF_MANAGER_IMAGE, the manager’s own image.
--state-backups
int
5
State backups to keep per object: every new state serial is copied into captf-state-backup-* Secrets and older copies are pruned. 0 takes no backups (existing ones stay and can still be restored).
Namespace that the controller watches to reconcile objects. If unspecified, the controller watches all namespaces.
--sync-period
duration
10m0s
The minimum interval at which watched resources are reconciled (e.g. 15m)
--terraformcluster-concurrency
int
10
Number of TerraformClusters to process simultaneously
--terraformmachine-concurrency
int
10
Number of TerraformMachines to process simultaneously
--terraformmachinepool-concurrency
int
10
Number of TerraformMachinePools to process simultaneously
--terraformmachinetemplate-concurrency
int
10
Number of TerraformMachineTemplates to process simultaneously
--watch-filter
string
Label value that the controller watches to reconcile objects. Label key is always cluster.x-k8s.io/watch-filter. If unspecified, the controller watches all objects.
The address the diagnostics endpoint binds to. Per default metrics are served via https and withauthentication/authorization. To serve via http and without authentication/authorization set –insecure-diagnostics. If –insecure-diagnostics is not set the diagnostics endpoint also serves pprof endpoints and an endpoint to change the log level.
--insecure-diagnostics
bool
false
Enable insecure diagnostics serving. For more details see the description of –diagnostics-address.
--tls-cipher-suites
stringSlice
[]
Comma-separated list of cipher suites for the webhook server and metrics server (the latter only if –insecure-diagnostics is not set to true). If omitted, the default Go cipher suites will be used. Preferred values: TLS_AES_128_GCM_SHA256, TLS_AES_256_GCM_SHA384, TLS_CHACHA20_POLY1305_SHA256, TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA, TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305, TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305, TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256. Insecure values: TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_ECDSA_WITH_RC4_128_SHA, TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_RSA_WITH_RC4_128_SHA, TLS_RSA_WITH_3DES_EDE_CBC_SHA, TLS_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_128_CBC_SHA256, TLS_RSA_WITH_AES_128_GCM_SHA256, TLS_RSA_WITH_AES_256_CBC_SHA, TLS_RSA_WITH_AES_256_GCM_SHA384, TLS_RSA_WITH_RC4_128_SHA.
--tls-curve-preferences
int32Slice
[]
Comma-separated list of numeric Go crypto/tls CurveID values, as the allowed key exchange mechanisms for the webhook server and metrics server (the latter only if –insecure-diagnostics is not set to true). The supported values depend on the Go version used. See https://pkg.go.dev/crypto/tls#CurveID for values supported for each Go version. The order of the list is ignored, and key exchange mechanisms are chosen by Go from this list using an internal preference order. If omitted, the default Go curves will be used.
--tls-min-version
string
VersionTLS12
The minimum TLS version in use by the webhook server and metrics server (the latter only if –insecure-diagnostics is not set to true). Possible values are VersionTLS10, VersionTLS11, VersionTLS12, VersionTLS13.
A set of key=value pairs that describe feature gates for alpha/experimental features. Options are: AllAlpha=true|false (ALPHA - default=false) AllBeta=true|false (BETA - default=false) ContextualLogging=true|false (BETA - default=true) LoggingAlphaOptions=true|false (ALPHA - default=false) LoggingBetaOptions=true|false (BETA - default=true)
--log-flush-frequency
duration
5s
Maximum number of seconds between log flushes
--log-json-info-buffer-size
quantity
0
[Alpha] In JSON format with split output streams, the info messages can be buffered for a while to increase performance. The default value of zero bytes disables buffering. The size can be specified as number of bytes (512), multiples of 1000 (1K), multiples of 1024 (2Ki), or powers of those (3M, 4G, 5Mi, 6Gi). Enable the LoggingAlphaOptions feature gate to use this.
--log-json-split-stream
bool
false
[Alpha] In JSON format, write error messages to stderr and info messages to stdout. The default is to write a single stream to stdout. Enable the LoggingAlphaOptions feature gate to use this.
--log-text-info-buffer-size
quantity
0
[Alpha] In text format with split output streams, the info messages can be buffered for a while to increase performance. The default value of zero bytes disables buffering. The size can be specified as number of bytes (512), multiples of 1000 (1K), multiples of 1024 (2Ki), or powers of those (3M, 4G, 5Mi, 6Gi). Enable the LoggingAlphaOptions feature gate to use this.
--log-text-split-stream
bool
false
[Alpha] In text format, write error messages to stderr and info messages to stdout. The default is to write a single stream to stdout. Enable the LoggingAlphaOptions feature gate to use this.
--logging-format
string
text
Sets the log format. Permitted formats: “json” (gated by LoggingBetaOptions), “text”.
-v, --v
Level
2
number for the log level verbosity
--vmodule
pattern=N,...
comma-separated list of pattern=N settings for file-filtered logging (only works for text log format)
--feature-gates takes a comma-separated Key=value list. v1 registers no CAPTF feature of its own; the gates below are the component-base logging gates, which logsv1.ValidateAndApply reads.
This list is maintained by hand in internal/docsgen/manager.go, alongside the flags it documents.
Variable
Description
CAPTF_MANAGER_IMAGE
Default of –runner-image, the image of the init container that injects the runner binary into Jobs. Set by the shipped Deployment to the manager’s own image.
KUBECONFIG
Read by controller-runtime’s –kubeconfig flag handling (ctrl.RegisterFlags) when –kubeconfig is not given and the manager runs out-of-cluster.