Docs

Uninstall

Uninstalling takes two steps. First remove the operator from the customer environment. Then retire its registration in Alien, which deletes the deployment record and its API key. Do the second step only after the first succeeds.

A dedicated Kubernetes release and an ECS stack retain identity storage after uninstall, so an accidental removal does not immediately destroy that identity. Uninstalling the whole product release deletes its operator identity volume and records. A retired installation cannot be installed again from its old values; to install again, register a new installation.

Kubernetes: dedicated release

On the setup page, open Uninstall this operator release and run the command. For a dedicated release it is:

helm uninstall operator-<installation-id> --namespace <namespace> --kube-context '<context>' --wait --timeout 5m

Helm deletes the operator workloads and RBAC. It keeps:

  • The identity PersistentVolumeClaim from templates/byoc-operator.yaml.
  • The installation records, the ConfigMaps operator-<installation-id>-installation-record and operator-<installation-id>-installation-record-complete.
  • The credentials Secret operator-<installation-id>-credentials, the namespace, the shared access-request CRD, access requests, and anything else the chart did not create.

Never run this command against your application release.

When you are sure the installation is retired for good and needs no recovery, delete the kept PersistentVolumeClaim, the two ConfigMaps, and the setup-owned Secret. If Terraform owns the Secret, remove it through its Terraform configuration after reviewing the plan. Old values cannot restore a deleted identity.

Kubernetes: product release

The operator in a product release belongs to that release. You have two options:

  • To remove only the operator and keep the application, upgrade with remoteOperator.confirmRemoval. See Remove only the operator.
  • To remove the whole product, uninstall the product release:
helm uninstall <release> --namespace <namespace> --kube-context '<context>' --wait

Uninstalling the product release removes the application and the operator together. Before Helm deletes the release, a cleanup Job stops the operator and deletes its identity PersistentVolumeClaim and identity records, so this release is retired for good. The credentials Secret and the shared access-request CRD stay. When you no longer need the Secret, delete a setup-owned Secret with kubectl or remove a Terraform-owned Secret through its Terraform configuration after reviewing the plan.

Amazon ECS

On the setup page, open Uninstall this exact stack and type the confirmation it shows:

DELETE <account-id>/<region>/<stack-name>

The page then shows the Uninstall command. Run it. It checks the AWS account and the stack outputs, asks you to type the same confirmation again, and then:

  1. Deletes the CloudFormation stack and waits until the delete completes.
  2. Schedules the registration secret for deletion with a 7-day recovery window.
  3. Prints the IDs of the EFS filesystem and access point it kept.

The ECS cluster, subnets, and security groups stay. So do the EFS filesystem and access point that hold the operator identity. If you supplied existing EFS storage, it remains customer-owned; do not delete it as part of this uninstall. If the stack created EFS storage for this installation, delete it in AWS only after confirming that no other workload uses it and the identity is no longer needed.

If stack deletion succeeds but scheduling the registration secret for deletion fails, the generated command cannot be rerun because the stack is gone. In the same AWS account and Region, verify the exact <stack>-registration secret, then schedule its deletion with the same seven-day recovery window:

aws_account="$(aws sts get-caller-identity --query Account --output text)"
if [ "$aws_account" = '<account-id>' ]; then
  aws secretsmanager delete-secret --region '<region>' --secret-id '<stack>-registration' --recovery-window-in-days 7
else
  printf 'AWS account mismatch: %s\n' "$aws_account" >&2
fi

Retire the Alien registration only after the secret deletion is scheduled.

Retire the Alien registration

After the uninstall succeeds, retire the registration from the setup page:

  • On Kubernetes, in Retire the Alien registration, type the release name and select Uninstall succeeded — revoke Alien registration.
  • On ECS, select AWS teardown succeeded — revoke Alien registration.

This deletes the Alien deployment record and removes its deployment-scoped API key at once. The installation disappears from Deployments.

On this page