Skip to content

Uninstalling ​

Tear down runs in two phases: remove your Palena CRs (so owned resources are garbage-collected), then remove the operator and CRDs.

Step 1: Delete your Palena CRs ​

Delete higher-level CRs first so finalizers can clean up their children before the gateway disappears:

bash
# 1. Delete leaf CRDs first
kubectl delete palenaui --all -A
kubectl delete palenamodel --all -A
kubectl delete palenaobservability --all -A
kubectl delete palenamcpserver --all -A

# 2. Delete gateways last (they wait for all referencing CRs to go first)
kubectl delete palenagateway --all -A

Palena sets finalizers on every CR. If a gateway is stuck in Terminating, it's waiting for a child CR to be removed. Check with:

bash
kubectl get palenagateway -A
# Look for CRs with DeletionTimestamp set but not yet gone

Step 2: Remove the operator ​

bash
operator-sdk cleanup palena-operator --namespace palena-system
bash
helm uninstall palena-operator --namespace palena-system
bash
make undeploy
make uninstall

Step 3: Verify cleanup ​

bash
kubectl get crd | grep operator.palena.ai
# (should be empty)

kubectl get ns palena-system
# (should be gone or empty)

What's left behind ​

By design, Palena does not delete:

  • User-managed Secrets referenced by SecretKeyRef (API keys, master passwords, etc.). You own these — delete them explicitly if you want them gone.
  • External databases/Redis configured via external specs. Palena never provisioned them, so it won't remove them.
  • PersistentVolumes for managed CNPG, Redis, MongoDB, and MeiliSearch. StorageClass.reclaimPolicy determines whether the underlying volume is released. Check kubectl get pv after uninstall.

If you want a completely clean slate, delete those explicitly:

bash
kubectl delete secret -l app.kubernetes.io/managed-by=palena-operator -A
kubectl delete pvc -l app.kubernetes.io/managed-by=palena-operator -A

Troubleshooting stuck finalizers ​

If a CR refuses to delete because its finalizer can't complete (for example, the upstream LiteLLM Operator is already uninstalled), remove the finalizer manually:

bash
kubectl patch palenagateway production \
  --type='json' \
  -p='[{"op":"remove","path":"/metadata/finalizers"}]'

WARNING

Removing a finalizer bypasses cleanup. Upstream CRs (LiteLLMInstance, LangfuseInstance, CNPG Cluster) may be left behind — delete them manually afterwards.

Released under the Apache 2.0 License. "Palena" is a trademark of bitkaio LLC.