Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Runner CLI

runner is the Job entrypoint the manager copies into every source image’s init container and runs as the main container’s command (copy, then run); it is not a tool operators invoke directly. See Image Contract for how the image and the runner fit together.

Global flags

Every subcommand inherits these (component-base logging and version flags, as every Kubernetes component registers them).

FlagTypeDefaultDescription
--feature-gatesmapStringBoolA set of key=value pairs that describe feature gates for alpha/experimental features. Options are: AllAlpha=true|false (ALPHA - default=false) AllBeta=true|false (BETA - default=false) ContextualLogging=true|false (BETA - default=true) LoggingAlphaOptions=true|false (ALPHA - default=false) LoggingBetaOptions=true|false (BETA - default=true)
--log-flush-frequencyduration5sMaximum number of seconds between log flushes
--log-json-info-buffer-sizequantity0[Alpha] In JSON format with split output streams, the info messages can be buffered for a while to increase performance. The default value of zero bytes disables buffering. The size can be specified as number of bytes (512), multiples of 1000 (1K), multiples of 1024 (2Ki), or powers of those (3M, 4G, 5Mi, 6Gi). Enable the LoggingAlphaOptions feature gate to use this.
--log-json-split-streamboolfalse[Alpha] In JSON format, write error messages to stderr and info messages to stdout. The default is to write a single stream to stdout. Enable the LoggingAlphaOptions feature gate to use this.
--log-text-info-buffer-sizequantity0[Alpha] In text format with split output streams, the info messages can be buffered for a while to increase performance. The default value of zero bytes disables buffering. The size can be specified as number of bytes (512), multiples of 1000 (1K), multiples of 1024 (2Ki), or powers of those (3M, 4G, 5Mi, 6Gi). Enable the LoggingAlphaOptions feature gate to use this.
--log-text-split-streamboolfalse[Alpha] In text format, write error messages to stderr and info messages to stdout. The default is to write a single stream to stdout. Enable the LoggingAlphaOptions feature gate to use this.
--logging-formatstringtextSets the log format. Permitted formats: “json” (gated by LoggingBetaOptions), “text”.
-v, --vLevel0number for the log level verbosity
--versionversionfalse–version, –version=raw prints version information and quits; –version=vX.Y.Z… sets the reported version
--vmodulepattern=N,...comma-separated list of pattern=N settings for file-filtered logging (only works for text log format)

copy <dest>

Copy this binary to <dest> (init container).

run

Run one operation in the Job’s main container.

FlagTypeDefaultDescription
--allow-deletes-hashstringinputs hash approved for a destructive plan
--backend-configstringArray[]init -backend-config value (repeatable)
--binstringArray[]runtime command, one flag per element (default /captf/runtime)
--configstring/captf/configdirectory holding the rendered root module and tfvars (the per-run Secret’s mount)
--event-objectstringemit progress events about <apiVersion>/<kind>/<namespace>/<name>/<uid> (none when unset)
--expect-planstringapply: the approved plan hash; stop with error kind plan-changed unless the plan’s hash is this one
--force-unlockstringstale lock to force-unlock after init
--guard-deletesboolfalseapply: stop before a plan that deletes or replaces a resource unless –allow-deletes-hash is –inputs-hash
--imagestringsource image reference, echoed in the result
--inputs-hashstringhash of the inputs the Job renders
--job-namestringthe Job the events relate to
--lock-timeoutduration5m0sstate lock timeout
--modulestring/captf/modulemodule directory
--opstringoperation: apply, destroy, refresh, drift, restore or plan
--providersstring/captf/providersprovider mirror directory (optional)
--restore-chunksint0restore: the number of backup chunks under <config>/restore
--restore-resourcesint0restore: the backup’s managed resource count; state list must show one when it is not 0
--resultstring/dev/termination-logwhere to write the result
--stop-timeoutduration1m0stime an interrupted step gets to stop before SIGKILL
--workdirstring/captf/workwritable work directory

version

Print the version and exit.

Exit codes

CodeNameMeaning
0ExitOKEvery step succeeded, or an apply’s plan had no changes to apply.
1ExitFailureA step failed, was interrupted, stopped before a destructive plan (blocked), or found its approved plan had changed; or preflight/prepare itself failed. max(runtime exit, 1) when the failing step’s own exit code is not already at least 1.
2ExitUsageBad input: an –op Steps does not recognize, a bad flag, unexpected arguments, or invalid logging flags.

Result error kinds

runner run always writes a result document (--result, the termination log by default); a failed run’s error.kind is one of:

KindMeaning
image-layoutThe image does not follow the image contract (a Preflight check failed): the module or runtime is not where the contract puts it.
stepA runtime step (init, plan, apply, …) failed, or the runner’s own setup (Prepare, a restore assembly) failed.
interruptedThe run’s context was canceled (a drain, eviction or deletion) while a step was running; counts toward no retry backoff.
blockedA guarded apply stopped before a plan that deletes or replaces resources, without an approval for its inputs hash. It changed nothing and is not retried until the inputs or the approval change.
plan-changedAn apply approved for one plan (–expect-plan) found its plan is now another. It changed nothing, carries the new plan, and waits for its approval.