Skip to content

Troubleshooting

Controller not Ready

kubectl -n image-inventory-system get deploy,pods
kubectl -n image-inventory-system describe deploy/image-inventory-controller
kubectl -n image-inventory-system logs deploy/image-inventory-controller --tail=100
Symptom Check
ImagePullBackOff Image tag on GHCR / local load
CrashLoop Logs; --leader-elect-namespace vs RBAC
Pending Node capacity; NetworkPolicy

/readyz waits for cache sync; /healthz is a ping.

Empty inventory

  1. Controller Ready
  2. Workloads present in the namespace
  3. Allow time for reconcile after create/delete
  4. If --namespaces is set, only those namespaces are inventoried
kubectl -n image-inventory-system get deploy image-inventory-controller -o jsonpath='{.spec.template.spec.containers[0].args}'
echo
kubectl get deploy,sts,ds,job,cronjob,pod -n <ns>

Missing API resource

error: the server doesn't have a resource type "images"

Re-apply the install manifest or config/crd/.

KINDS blank or unexpected

status.kinds is a string column. Empty status usually means reconcile has not completed — check controller logs.

CronJob-owned Jobs are skipped when a live CronJob with the same name exists and the owner UID is empty or matches. Details: Architecture.

RBAC

Controller requires list/watch on workloads and create/update/delete on images.imageinventory.io. Re-apply config/rbac/ if needed.

Tenant access: RoleBinding to image-inventory-viewer in the tenant namespace (Usage).

Reporting issues

Include kubectl version, controller logs, and relevant kubectl get … -o yaml (redact secrets).