Uninstall the Components and Clean Up the Cluster
Use this procedure to return the cluster to a clean state, for example before a fresh installation.
Before uninstalling, check whether the release owns any persistent data. In the reference environment there were no PersistentVolumeClaims or externally managed secrets, so uninstall and reinstall were non-destructive. This must be re-verified in every environment.
Step 1 — Record the current configuration
helm list -A
helm get values kron-aapm-agent -n ns-agent
helm get values aapm-service -n kron-pam-aapm
helm get values kron-aapm-sidecar -n ns-sidecar
kubectl get all,pvc,secret,cm -n ns-agent
kubectl get all,pvc,secret,cm -n kron-pam-aapm
kubectl get all,pvc,secret,cm -n ns-sidecarStep 2 — Uninstall the releases (injector first)
Uninstall in reverse order of installation, so that dependent components are removed before the Agent they rely on.
helm uninstall kron-aapm-sidecar -n ns-sidecar
helm uninstall aapm-service -n kron-pam-aapm
helm uninstall kron-aapm-agent -n ns-agentStep 3 — Remove leftover cluster-scoped resources
helm uninstall normally removes these, but they must be verified: a leftover webhook configuration blocks pod creation in labeled namespaces.
kubectl get mutatingwebhookconfiguration | grep -i aapm
kubectl get clusterrole,clusterrolebinding | grep -i aapmDelete any remaining objects explicitly:
kubectl delete mutatingwebhookconfiguration <name>
kubectl delete clusterrole <name>
kubectl delete clusterrolebinding <name>Step 4 — Remove namespaces, labels, and secrets
kubectl label namespace <TARGET_NAMESPACE> aapm-injection-
kubectl delete secret aapm-client-secret -n <TARGET_NAMESPACE>
kubectl delete namespace ns-agent kron-pam-aapm ns-sidecarStep 5 - Stop background port-forwards
pkill -f "kubectl port-forward" || true
ss -tlnp | grep -E ':8443|:8080'Step 6 — Verify the cluster is clean
helm list -A
kubectl get ns
kubectl get mutatingwebhookconfigurationSuccess criteria:helm list -A returns empty, the three namespaces are gone, and no AAPM-related mutating webhook configuration remains.
Uninstalling the Agent doesn't remove its registration from the Kron PAM console. Remove or re-use the agent entry on the Kron PAM side as well; otherwise a reinstallation using the same agentName may conflict.