Guides

Uninstall Telark

Remove the Telark release, and optionally every Telark resource and volume.

helm uninstall removes the services but keeps the CRDs, every Telark custom resource and a few Secrets and volumes, so a reinstall picks up where you left off. A full teardown is a separate step.

1. Prepare

  1. Cancel active protection plans, so their Kyverno policies are removed.
  2. Wait for any rollback in progress to finish.
  3. Back up what you want to keep. The uninstall deletes the exporter's snapshot and report volumes. See Back up Telark.

2. Uninstall the release

helm uninstall telark -n telark

This removes every Telark service, the bundled Kyverno, and the exporter's snapshot and report volumes. These stay:

  • The CRDs and every Telark custom resource (helm.sh/resource-policy: keep).
  • The service-token, NATS and OIDC trust Secrets.
  • The Redis and NATS volumes, and the Ollama model volume.

Stop here if you plan to reinstall.

3. Full teardown

Run these after step 2, in this order. Users, groups and access roles carry telark.io/*-cleanup finalizers that only the auth service clears, and it is gone now, so deleting the CRDs first would hang in Terminating. Clearing the finalizers is safe here because the teardown deletes everything they protect.

# 1. Clear the cleanup finalizers
for crd in $(kubectl get crd -l app.kubernetes.io/part-of=telark -o name | cut -d/ -f2); do
  kubectl get "$crd" -A -o jsonpath='{range .items[*]}{.metadata.namespace} {.metadata.name}{"\n"}{end}' |
    while read -r ns name; do
      kubectl patch "$crd" "$name" -n "$ns" --type merge -p '{"metadata":{"finalizers":null}}'
    done
done

# 2. Delete the CRDs, and with them every Telark custom resource
kubectl delete crd -l app.kubernetes.io/part-of=telark

# 3. Only if you run your own Kyverno (app.kyverno.enabled=false): leftover plan policies
kubectl delete policies.kyverno.io -A -l telark.io/protection-plan

# 4. The remaining volumes and Secrets
kubectl delete namespace telark

4. Check that nothing is left

kubectl get crd -l app.kubernetes.io/part-of=telark
kubectl get namespace telark

Both commands should report that nothing was found.

Stuck in Terminating

If you deleted the CRDs or the namespace before clearing the finalizers, run step 1 of the teardown. The pending deletions then complete on their own.