Skip to content
kix /docs
Install the CLI

Reference Annotations and CRDs

Annotation and label catalog

The metadata Kix writes on rendered and live Kubernetes objects, including ownership, graph, lifecycle, import, and policy markers.

Kix uses the kix.run domain for its annotations, labels, and CRD API group. Most entries in this catalog are compiler or deploy-engine records. Package authors should use the helper that produces a marker instead of writing its serialized value by hand.

This page is hand-maintained. The canonical key lists are kix/lib/core/annotations.nix and cli/kix/src/manifest/keys.rs.

LabelWritten onMeaning
app.kubernetes.io/managed-by=kixManaged resources and Kix recordsSelects the objects Kix may inspect. This label alone does not prove that Kix applied an object; the identity and activation annotations provide that evidence.
kix.run/clusterActivation recordsNames the Kix cluster that owns the record. The CLI uses it to isolate several Kix clusters sharing one Kubernetes cluster.
pod-security.kubernetes.io/enforceNamespaces Kix createsThe Pod Security Admission level derived from package meta.podSecurity declarations. See meta.podSecurity.

Kix also applies ordinary recommended Kubernetes labels, such as app.kubernetes.io/name and app.kubernetes.io/instance. Their exact set depends on the resource builder and package, so they are not control-plane stamps.

AnnotationMeaning
kix.run/identity-hashIdentity of the sealed manifest in the Nix store. Dependency hashes make this change when an input resource changes, even if the manifest body does not.
kix.run/packageOwning package instance name.
kix.run/package-namespaceNamespace of the owning package instance.
kix.run/lifecyclePackage lifecycle classification, used when Kix detects stateful migration pairs.
kix.run/built-viaBuild result path from which an Activation can reload manifests.
kix.run/activationsComma-separated activation identity hashes that currently reference a live object. This is the authority used for pruning and garbage collection.
kix.run/applied-hashHash of the fields Kix owned after its last apply. kix drift compares the current owned fields with this value.

The CLI adds the identity and package annotations when it loads a build. It updates activations and applied-hash on the live object after applying it. Do not use either live annotation as package input.

AnnotationMeaning
kix.run/depends-onComma-separated typed identity hashes that form the deployment DAG. Kix derives this from Nix string context and explicit resource dependencies.
kix.run/readinessJSON readiness rule for a custom resource. See kix.run/readiness.
kix.run/rerunon-change on a Job that must be deleted and created again instead of patched.
kix.run/cede-fieldsField paths another server-side apply manager may own. See kix.run/cede-fields.
kix.run/expectsObjects that a controller or hook must create before this resource can proceed. See kix.run/expects.

The Kix operator also places kix.run/operator-gc in an Activation’s metadata.finalizers. It is a finalizer value, not an annotation. It keeps the record present until the operator has cleaned up the resources for which that Activation was responsible.

AnnotationMeaning
kix.run/rootRoot resource of a PackageInstance.
kix.run/inverse-depsResources outside the instance that depend on it. Recorded for package graph metadata; the CLI does not currently interpret this annotation.
kix.run/package-requiresAdditional resources in the package’s forward closure. The CLI does not currently give this annotation separate scheduling behavior.
kix.run/post-hooksResources designated as post-hooks by the package. The CLI does not currently schedule them after the rest of the package.
kix.run/previousActivation superseded by this Activation.
kix.run/deployed-atRFC 3339 deployment timestamp.
kix.run/modeimport on a PackageInstance that represents an object Kix references but does not own.
kix.run/auto-instantiatedtrue when Kix created the instance from availablePackages.
kix.run/optional-activatedtrue when dependency demand activated an instance declared with optional = true.

An imported object is represented by a PackageInstance marker. These annotations preserve enough of the external object’s contract for dependency resolution and readiness checks.

AnnotationMeaning
kix.run/import-kindImported object’s kind.
kix.run/import-apiversionImported object’s apiVersion.
kix.run/import-nameImported object’s name.
kix.run/import-fqdnFully qualified domain name of an imported Service.
kix.run/import-secret-keysComma-separated keys an imported Secret must contain.
kix.run/service-selectorImported Service selector encoded as JSON.
kix.run/service-portsImported Service ports encoded as JSON.
kix.run/service-labelsImported Service labels encoded as JSON.
kix.run/crd-kindKind a CRD ref marker (scope.mkCRDRef) declares.
kix.run/crd-versionAPI version a CRD ref marker declares for its kind.
kix.run/crd-served-versionsAPI versions a CRD ref marker declares as served, comma separated, crd-version among them.
kix.run/crd-scopeNamespaced or Cluster, as a CRD ref marker declares.
AnnotationMeaning
kix.run/sops-sourceNix store path of the SOPS file decrypted at apply time.
kix.run/content-hashHash of decrypted Secret content.
kix.run/secret-keysComma-separated keys the Secret declares.
kix.run/secret-typeKubernetes Secret type.
kix.run/classificationData classification supplied by the package.
kix.run/rotation-policyRotation policy supplied by the package.

Derived resources and package-specific markers

Section titled “Derived resources and package-specific markers”
AnnotationMeaning
kix.run/derivedtrue when Kix derived the resource instead of the package author declaring it directly.
kix.run/policy-typeDerivation rule that produced a NetworkPolicy or another policy resource.
kix.run/operand-of<group>/<Kind>/<name> of the operator-managed custom resource whose pods a Service selects.
kix.run/monitors-external-servicetrue on a ServiceMonitor that deliberately selects a Service outside Kix; suppresses the normal selector validation.
kix.run/roleRole a resource plays within its package.
kix.run/db-clusterDatabase cluster name attached by database packages.

Kix reserves its current domain and retired domains such as kix.dev. Package-owned annotations should use a domain declared through meta.annotationDomains, not the kix.run namespace.