⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All Platform Engineering & IDP Interview Questions Scenario 2 of 50 in Platform Engineering & IDP
Senior Platform Engineer Platform Engineering Control Planes & Crossplane Kubernetes Control Plane
🎯 Target Role / Context: Platform Engineering Technical Round · Control Plane Architecture

Q: A developer provisions an 'AppDatabase' Claim using your platform control plane, but the Claim stays in 'Ready: False' indefinitely. Walk through the exact CLI triage path from Claim to Managed Resource.

Comprehensive diagnostic flow to isolate why a Crossplane Composite Resource (XR) and Claim (XRC) remain permanently stuck in 'Synced=False' or 'Ready=False'.

#Crossplane #Kubernetes #IaC #AWS Provider #Composite Resources #Platform Engineering
🎙️ Candidate Opening & Architectural Context
"Crossplane abstracts cloud infrastructure into a multi-tiered hierarchy: Claim (XRC) -> Composite Resource (XR) -> Composition -> Managed Resources (MR). When a Claim hangs, the failure is diagnosed by traversing downward through this exact chain of Kubernetes custom resources."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's CKA & CKAD Hands-On Certification Track covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1

Inspect Claim (XRC) and Resolve Composite Resource (XR) Name

Run kubectl describe on the developer's Claim to identify the underlying XR reference and initial condition events.

kubectl get appdatabase.platform.acme.com my-db -n team-checkout -o yaml
# Extract .spec.resourceRef.name (e.g. appdatabase-xr-9x8zk)
kubectl describe appdatabase.platform.acme.com my-db -n team-checkout
2

Inspect Composite Resource (XR) Composition Status

Check whether the XR found a matching Composition and identify the Managed Resources (MRs) it attempted to render.

kubectl describe xappdatabase.platform.acme.com appdatabase-xr-9x8zk
# Look for: 'CompositionSelected' and .spec.resourceRefs containing RDSInstance, SecurityGroup
Advertisement
3

Inspect Managed Resource (MR) and Provider Events

Query the concrete cloud resource (e.g. rds.aws.upjet.crossplane.io) to view the exact AWS API rejection error or provider pod panic.

kubectl get rdsinstance.database.aws.upjet.crossplane.io -o wide
kubectl describe rdsinstance.database.aws.upjet.crossplane.io <mr-name>
# Look for Status.Conditions: 'CannotCreateExternalResource: InvalidVpcId'
4

Verify Provider Pod Health & Controller RBAC

Inspect the Crossplane AWS provider pod logs in crossplane-system namespace to check for IAM authentication failures or throttling.

kubectl logs -n crossplane-system -l pkg.crossplane.io/provider=provider-aws-rds -c provider --tail=100
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Crossplane triage must follow the strict hierarchy: Claim -> XR -> Composition -> Managed Resource -> Provider Controller logs."
⚡ 60-Second Elevator Pitch Talking Points
  • Follow the four-level Crossplane abstraction hierarchy: Claim -> Composite Resource -> Managed Resource -> Provider.
  • Inspect the XR's CompositionRef to ensure required schema patches and environment variables resolved cleanly.
  • Query the concrete Managed Resource status condition to read the exact raw cloud provider API error.
Advertisement
Want more Platform Engineering & IDP scenarios?
Explore our complete collection of scenario-based Platform Engineering & IDP interview runbooks.
Browse All Platform Engineering & IDP Questions →