How-to guide Operate a cluster
Reconcile drift
Reapply a cluster's desired manifests to heal out-of-band changes.
Use kix deploy --reconcile to reapply every desired resource, including
resources whose activation identity has not changed. Add --force-conflicts
only when you have reviewed fields owned by another manager and intend Kix to
take them back.
Review the drift report
Section titled “Review the drift report”Start by identifying the fields that changed:
❱ kix drift
Connecting to cluster...
16 kix-managed resources
✓ Activation/how-to-application-gb5d6ry45b5l in sync
✓ ConfigMap/preview@how-to-app in sync
✓ ConfigMap/production@how-to-app in sync
✓ ConfigMap/production-health-script@how-to-app in sync
✓ CustomResourceDefinition/activations.kix.run in sync
✓ CustomResourceDefinition/packageinstances.kix.run in sync
✓ Deployment/preview@how-to-app in sync
✗ Deployment/production@how-to-app DRIFTED
spec.replicas taken by kubectl (Update via /scale) at unknown time
✓ Job/production-health@how-to-app in sync
✓ Namespace/how-to-app in sync
✓ Namespace/kube-system in sync
✓ PackageInstance/preview@how-to-app in sync
✓ PackageInstance/production@how-to-app in sync
✓ PackageInstance/platform-dns@kube-system in sync
✓ Service/preview@how-to-app in sync
✓ Service/production@how-to-app in sync
Drift: 15 in sync, 1 drifted
(exit code: 1) Confirm that the checked-in cluster definition still describes the state you want. Reconciliation applies that definition, so review intentional emergency changes before continuing.
Reapply the desired resources
Section titled “Reapply the desired resources”The example drift report attributes spec.replicas to kubectl. Reapply the
cluster and deliberately take ownership of that field:
❱ kix deploy how-to-application --reconcile --force-conflicts -y Show outputHide output · 43 lines
Building cluster 'how-to-application'...
Cluster how-to-application: 16 manifests
Connecting to cluster...
Active activation: how-to-application-gb5d6ry45b5l (gb5d6ry4...)
Plan: 3 unchanged
↻ 1 under the rerun rule (deleted first when live): Job/production-health@how-to-app
plan: 16 nodes
~ Namespace/kube-system configured
✔ Namespace/kube-system ready
~ Namespace/how-to-app configured
✔ Namespace/how-to-app ready
~ ConfigMap/production-health-script@how-to-app configured
✔ ConfigMap/production-health-script@how-to-app ready
~ ConfigMap/production@how-to-app configured
✔ ConfigMap/production@how-to-app ready
~ ConfigMap/preview@how-to-app configured
✔ ConfigMap/preview@how-to-app ready
~ Deployment/preview@how-to-app configured
~ Deployment/production@how-to-app configured
✔ Deployment/preview@how-to-app ready
~ Service/preview@how-to-app configured
✔ Service/preview@how-to-app ready
~ CustomResourceDefinition/packageinstances.kix.run configured
~ CustomResourceDefinition/activations.kix.run configured
✔ CustomResourceDefinition/packageinstances.kix.run ready
✔ CustomResourceDefinition/activations.kix.run ready
~ PackageInstance/platform-dns@kube-system configured
~ PackageInstance/preview@how-to-app configured
✔ PackageInstance/preview@how-to-app ready
✔ PackageInstance/platform-dns@kube-system ready
✔ Deployment/production@how-to-app ready
~ Service/production@how-to-app configured
✔ Service/production@how-to-app ready
+ recreate Job/production-health@how-to-app created
↻ Job/production-health@how-to-app ran again (changed since the last run)
~ PackageInstance/production@how-to-app configured
✔ PackageInstance/production@how-to-app ready
~ Activation/how-to-application-gb5d6ry45b5l configured
✔ Activation/how-to-application-gb5d6ry45b5l ready
• activation 'how-to-application-gb5d6ry45b5l' → Active
Deploy complete: 1 created, 15 configured, 0 unchanged, 0 failed The example begins with a production Deployment that was scaled from two replicas to one outside Kix. Reconciliation reapplies the rendered resources and waits for them to become ready.
Use --context and --flake when the Kubernetes target or source directory
is not the current one:
❱ kix deploy how-to-application --reconcile --force-conflicts -y --flake ./infrastructure --context kind-kix-demo Omit -y when running interactively if you want to review the confirmation
prompt.
Confirm the result
Section titled “Confirm the result”Run the drift check again:
❱ kix drift
Connecting to cluster...
16 kix-managed resources
✓ Activation/how-to-application-gb5d6ry45b5l in sync
✓ ConfigMap/preview@how-to-app in sync
✓ ConfigMap/production@how-to-app in sync
✓ ConfigMap/production-health-script@how-to-app in sync
✓ CustomResourceDefinition/activations.kix.run in sync
✓ CustomResourceDefinition/packageinstances.kix.run in sync
✓ Deployment/preview@how-to-app in sync
✓ Deployment/production@how-to-app in sync
✓ Job/production-health@how-to-app in sync
✓ Namespace/how-to-app in sync
✓ Namespace/kube-system in sync
✓ PackageInstance/preview@how-to-app in sync
✓ PackageInstance/production@how-to-app in sync
✓ PackageInstance/platform-dns@kube-system in sync
✓ Service/preview@how-to-app in sync
✓ Service/production@how-to-app in sync
Drift: 16 in sync The drifted count should be zero. You can also use kix status
to confirm that the reapplied workloads are ready.
--reconcile deliberately reapplies all desired resources. --force-conflicts
also takes fields from other server-side apply managers. Use a normal
kix deploy when you only need to deploy a new rendered activation.