Troubleshooting¶
Controller not Ready¶
kubectl -n image-inventory-system get deploy,pods
kubectl -n image-inventory-system describe deploy/image-inventory-controller
kubectl -n image-inventory-system logs deploy/image-inventory-controller --tail=100
| Symptom | Check |
|---|---|
| ImagePullBackOff | Image tag on GHCR / local load |
| CrashLoop | Logs; --leader-elect-namespace vs RBAC |
| Pending | Node capacity; NetworkPolicy |
/readyz waits for cache sync; /healthz is a ping.
Empty inventory¶
- Controller Ready
- Workloads present in the namespace
- Allow time for reconcile after create/delete
- If
--namespacesis set, only those namespaces are inventoried
kubectl -n image-inventory-system get deploy image-inventory-controller -o jsonpath='{.spec.template.spec.containers[0].args}'
echo
kubectl get deploy,sts,ds,job,cronjob,pod -n <ns>
Missing API resource¶
Re-apply the install manifest or config/crd/.
KINDS blank or unexpected¶
status.kinds is a string column. Empty status usually means reconcile has not completed — check controller logs.
CronJob-owned Jobs are skipped when a live CronJob with the same name exists and the owner UID is empty or matches. Details: Architecture.
RBAC¶
Controller requires list/watch on workloads and create/update/delete on images.imageinventory.io. Re-apply config/rbac/ if needed.
Tenant access: RoleBinding to image-inventory-viewer in the tenant namespace (Usage).
Reporting issues¶
Include kubectl version, controller logs, and relevant kubectl get … -o yaml (redact secrets).