Uninstalling
Tear down runs in two phases: remove your Palena CRs (so owned resources are garbage-collected), then remove the operator and CRDs.
Step 1: Delete your Palena CRs
Delete higher-level CRs first so finalizers can clean up their children before the gateway disappears:
# 1. Delete leaf CRDs first
kubectl delete palenaui --all -A
kubectl delete palenamodel --all -A
kubectl delete palenaobservability --all -A
kubectl delete palenamcpserver --all -A
# 2. Delete gateways last (they wait for all referencing CRs to go first)
kubectl delete palenagateway --all -APalena sets finalizers on every CR. If a gateway is stuck in Terminating, it's waiting for a child CR to be removed. Check with:
kubectl get palenagateway -A
# Look for CRs with DeletionTimestamp set but not yet goneStep 2: Remove the operator
operator-sdk cleanup palena-operator --namespace palena-systemhelm uninstall palena-operator --namespace palena-systemmake undeploy
make uninstallStep 3: Verify cleanup
kubectl get crd | grep operator.palena.ai
# (should be empty)
kubectl get ns palena-system
# (should be gone or empty)What's left behind
By design, Palena does not delete:
- User-managed Secrets referenced by
SecretKeyRef(API keys, master passwords, etc.). You own these — delete them explicitly if you want them gone. - External databases/Redis configured via
externalspecs. Palena never provisioned them, so it won't remove them. - PersistentVolumes for managed CNPG, Redis, MongoDB, and MeiliSearch.
StorageClass.reclaimPolicydetermines whether the underlying volume is released. Checkkubectl get pvafter uninstall.
If you want a completely clean slate, delete those explicitly:
kubectl delete secret -l app.kubernetes.io/managed-by=palena-operator -A
kubectl delete pvc -l app.kubernetes.io/managed-by=palena-operator -ATroubleshooting stuck finalizers
If a CR refuses to delete because its finalizer can't complete (for example, the upstream LiteLLM Operator is already uninstalled), remove the finalizer manually:
kubectl patch palenagateway production \
--type='json' \
-p='[{"op":"remove","path":"/metadata/finalizers"}]'WARNING
Removing a finalizer bypasses cleanup. Upstream CRs (LiteLLMInstance, LangfuseInstance, CNPG Cluster) may be left behind — delete them manually afterwards.