Skip to content
kix /docs
Install the CLI

How-to guide Operate a cluster

Reconcile drift

Reapply a cluster's desired manifests to heal out-of-band changes.

Use kix deploy --reconcile to reapply every desired resource, including resources whose activation identity has not changed. Add --force-conflicts only when you have reviewed fields owned by another manager and intend Kix to take them back.

Start by identifying the fields that changed:

kix-examples/
❱ kix drift
Connecting to cluster...
16 kix-managed resources

  ✓ Activation/how-to-application-gb5d6ry45b5l         in sync
  ✓ ConfigMap/preview@how-to-app                       in sync
  ✓ ConfigMap/production@how-to-app                    in sync
  ✓ ConfigMap/production-health-script@how-to-app      in sync
  ✓ CustomResourceDefinition/activations.kix.run       in sync
  ✓ CustomResourceDefinition/packageinstances.kix.run  in sync
  ✓ Deployment/preview@how-to-app                      in sync
  ✗ Deployment/production@how-to-app                   DRIFTED
      spec.replicas taken by kubectl (Update via /scale) at unknown time
  ✓ Job/production-health@how-to-app                   in sync
  ✓ Namespace/how-to-app                               in sync
  ✓ Namespace/kube-system                              in sync
  ✓ PackageInstance/preview@how-to-app                 in sync
  ✓ PackageInstance/production@how-to-app              in sync
  ✓ PackageInstance/platform-dns@kube-system           in sync
  ✓ Service/preview@how-to-app                         in sync
  ✓ Service/production@how-to-app                      in sync

Drift: 15 in sync, 1 drifted
(exit code: 1)

Confirm that the checked-in cluster definition still describes the state you want. Reconciliation applies that definition, so review intentional emergency changes before continuing.

The example drift report attributes spec.replicas to kubectl. Reapply the cluster and deliberately take ownership of that field:

kix-examples/ live capture
❱ kix deploy how-to-application --reconcile --force-conflicts -y
Show outputHide output · 43 lines
Building cluster 'how-to-application'...
Cluster how-to-application: 16 manifests
Connecting to cluster...
Active activation: how-to-application-gb5d6ry45b5l (gb5d6ry4...)

  Plan: 3 unchanged
  ↻ 1 under the rerun rule (deleted first when live): Job/production-health@how-to-app
plan: 16 nodes
  ~ Namespace/kube-system configured
  ✔ Namespace/kube-system ready
  ~ Namespace/how-to-app configured
  ✔ Namespace/how-to-app ready
  ~ ConfigMap/production-health-script@how-to-app configured
  ✔ ConfigMap/production-health-script@how-to-app ready
  ~ ConfigMap/production@how-to-app configured
  ✔ ConfigMap/production@how-to-app ready
  ~ ConfigMap/preview@how-to-app configured
  ✔ ConfigMap/preview@how-to-app ready
  ~ Deployment/preview@how-to-app configured
  ~ Deployment/production@how-to-app configured
  ✔ Deployment/preview@how-to-app ready
  ~ Service/preview@how-to-app configured
  ✔ Service/preview@how-to-app ready
  ~ CustomResourceDefinition/packageinstances.kix.run configured
  ~ CustomResourceDefinition/activations.kix.run configured
  ✔ CustomResourceDefinition/packageinstances.kix.run ready
  ✔ CustomResourceDefinition/activations.kix.run ready
  ~ PackageInstance/platform-dns@kube-system configured
  ~ PackageInstance/preview@how-to-app configured
  ✔ PackageInstance/preview@how-to-app ready
  ✔ PackageInstance/platform-dns@kube-system ready
  ✔ Deployment/production@how-to-app ready
  ~ Service/production@how-to-app configured
  ✔ Service/production@how-to-app ready
  + recreate Job/production-health@how-to-app created
  ↻ Job/production-health@how-to-app ran again (changed since the last run)
  ~ PackageInstance/production@how-to-app configured
  ✔ PackageInstance/production@how-to-app ready
  ~ Activation/how-to-application-gb5d6ry45b5l configured
  ✔ Activation/how-to-application-gb5d6ry45b5l ready
  • activation 'how-to-application-gb5d6ry45b5l' → Active

Deploy complete: 1 created, 15 configured, 0 unchanged, 0 failed

The example begins with a production Deployment that was scaled from two replicas to one outside Kix. Reconciliation reapplies the rendered resources and waits for them to become ready.

Use --context and --flake when the Kubernetes target or source directory is not the current one:

❱ kix deploy how-to-application --reconcile --force-conflicts -y --flake ./infrastructure --context kind-kix-demo

Omit -y when running interactively if you want to review the confirmation prompt.

Run the drift check again:

kix-examples/
❱ kix drift
Connecting to cluster...
16 kix-managed resources

  ✓ Activation/how-to-application-gb5d6ry45b5l         in sync
  ✓ ConfigMap/preview@how-to-app                       in sync
  ✓ ConfigMap/production@how-to-app                    in sync
  ✓ ConfigMap/production-health-script@how-to-app      in sync
  ✓ CustomResourceDefinition/activations.kix.run       in sync
  ✓ CustomResourceDefinition/packageinstances.kix.run  in sync
  ✓ Deployment/preview@how-to-app                      in sync
  ✓ Deployment/production@how-to-app                   in sync
  ✓ Job/production-health@how-to-app                   in sync
  ✓ Namespace/how-to-app                               in sync
  ✓ Namespace/kube-system                              in sync
  ✓ PackageInstance/preview@how-to-app                 in sync
  ✓ PackageInstance/production@how-to-app              in sync
  ✓ PackageInstance/platform-dns@kube-system           in sync
  ✓ Service/preview@how-to-app                         in sync
  ✓ Service/production@how-to-app                      in sync

Drift: 16 in sync

The drifted count should be zero. You can also use kix status to confirm that the reapplied workloads are ready.

--reconcile deliberately reapplies all desired resources. --force-conflicts also takes fields from other server-side apply managers. Use a normal kix deploy when you only need to deploy a new rendered activation.