Uninstall from Kubernetes with Istio
This page removes a Kamiwaza installation from the kamiwaza namespace. It does
not change the platform around it: the namespace, the service mesh and gateway,
storage classes, DNS, and certificates belong to the platform administrator and
stay in place.
This is destructive. Uninstalling deletes Kamiwaza's databases, stored objects, and model files along with the platform. Back up anything you need before you begin.
Step 1: Back up
Export or copy any data you need to keep, such as documents in workrooms, configuration, and anything in the platform databases. Step 3 deletes the platform databases and object store, and they cannot be recovered after it.
Step 2: Remove apps and models
Remove what you deployed through Kamiwaza while the platform is still running:
- Log in as
admin. - In the App Garden, stop every deployed app. In the Tool Shed, stop every tool server.
- On the Models page, stop every model deployment.
- Confirm that all three lists are empty.
Step 3: Uninstall the release
Run as the installer identity. This deletes the volume claims for the platform databases and the object store; step 4 describes what happens to the disks behind them:
helm uninstall kamiwaza --namespace kamiwaza --wait --timeout 15m
Step 4: Delete the remaining volumes
Two kinds of volume outlive the release: the model registry cache, which the chart keeps on purpose, and the configuration store's volumes, which Kubernetes keeps for any StatefulSet. Delete them:
kubectl -n kamiwaza get persistentvolumeclaims
kubectl -n kamiwaza delete persistentvolumeclaims --all
Whether the underlying disks are also deleted depends on the StorageClass's
reclaimPolicy. With Retain, the platform administrator deletes the released
PersistentVolumes.
Step 5: Verify
Run as the platform administrator, since the installer identity may not be able to list every kind:
kubectl api-resources --verbs=list --namespaced -o name \
| grep -v -E '^events(\.events\.k8s\.io)?$' \
| xargs -n 1 kubectl -n kamiwaza get --ignore-not-found -o name 2>/dev/null
Expect only the platform prerequisites and what Kubernetes and Istio create in every namespace:
- the installer's ServiceAccount, Roles, and RoleBindings;
- the
kamiwaza-licenseSecret, and your pull Secret if you use one; - the
kamiwaza-edge-trustConfigMap, if you use one; - the
kube-root-ca.crt,istio-ca-root-cert, and (on Istio versions that publish one)istio-ca-crlConfigMaps, and thedefaultServiceAccount.
If anything else remains, contact Kamiwaza support with the list before reinstalling into the same namespace.
Removing the platform prerequisites
If Kamiwaza will not be installed again, the platform administrator can remove what was prepared for it, following their own procedures for the mesh, storage, DNS, and certificates:
-
the
kamiwazanamespace, which removes the installer identity, license Secret, and everything else in it:kubectl delete namespace kamiwaza -
the Istio
Gatewayand edge certificate Secret, if they serve only Kamiwaza; -
the DNS records for the Kamiwaza domain, including any in-cluster DNS entry;
-
the inotify settings in
/etc/sysctl.d/99-kamiwaza-inotify.confon each node, if nothing else relies on them.
To install again after deleting the namespace, start from Platform Prerequisites.