Skip to main content
Version: 1.3.3 (Latest)

Uninstall from Kubernetes with Istio

This page removes a Kamiwaza installation from the kamiwaza namespace. It does not change the platform around it: the namespace, the service mesh and gateway, storage classes, DNS, and certificates belong to the platform administrator and stay in place.

This is destructive. Uninstalling deletes Kamiwaza's databases, stored objects, and model files along with the platform. Back up anything you need before you begin.

Step 1: Back up​

Export or copy any data you need to keep, such as documents in workrooms, configuration, and anything in the platform databases. Step 3 deletes the platform databases and object store, and they cannot be recovered after it.

Step 2: Remove apps and models​

Remove what you deployed through Kamiwaza while the platform is still running:

  1. Log in as admin.
  2. In the App Garden, stop every deployed app. In the Tool Shed, stop every tool server.
  3. On the Models page, stop every model deployment.
  4. Confirm that all three lists are empty.

Step 3: Uninstall the release​

Run as the installer identity. This deletes the volume claims for the platform databases and the object store; step 4 describes what happens to the disks behind them:

helm uninstall kamiwaza --namespace kamiwaza --wait --timeout 15m

Step 4: Delete the remaining volumes​

Two kinds of volume outlive the release: the model registry cache, which the chart keeps on purpose, and the configuration store's volumes, which Kubernetes keeps for any StatefulSet. Delete them:

kubectl -n kamiwaza get persistentvolumeclaims
kubectl -n kamiwaza delete persistentvolumeclaims --all

Whether the underlying disks are also deleted depends on the StorageClass's reclaimPolicy. With Retain, the platform administrator deletes the released PersistentVolumes.

Step 5: Verify​

Run as the platform administrator, since the installer identity may not be able to list every kind:

kubectl api-resources --verbs=list --namespaced -o name \
| grep -v -E '^events(\.events\.k8s\.io)?$' \
| xargs -n 1 kubectl -n kamiwaza get --ignore-not-found -o name 2>/dev/null

Expect only the platform prerequisites and what Kubernetes and Istio create in every namespace:

  • the installer's ServiceAccount, Roles, and RoleBindings;
  • the kamiwaza-license Secret, and your pull Secret if you use one;
  • the kamiwaza-edge-trust ConfigMap, if you use one;
  • the kube-root-ca.crt, istio-ca-root-cert, and (on Istio versions that publish one) istio-ca-crl ConfigMaps, and the default ServiceAccount.

If anything else remains, contact Kamiwaza support with the list before reinstalling into the same namespace.

Removing the platform prerequisites​

If Kamiwaza will not be installed again, the platform administrator can remove what was prepared for it, following their own procedures for the mesh, storage, DNS, and certificates:

  • the kamiwaza namespace, which removes the installer identity, license Secret, and everything else in it:

    kubectl delete namespace kamiwaza
  • the Istio Gateway and edge certificate Secret, if they serve only Kamiwaza;

  • the DNS records for the Kamiwaza domain, including any in-cluster DNS entry;

  • the inotify settings in /etc/sysctl.d/99-kamiwaza-inotify.conf on each node, if nothing else relies on them.

To install again after deleting the namespace, start from Platform Prerequisites.