Q: A developer provisions an 'AppDatabase' Claim using your platform control plane, but the Claim stays in 'Ready: False' indefinitely. Walk through the exact CLI triage path from Claim to Managed Resource.
Comprehensive diagnostic flow to isolate why a Crossplane Composite Resource (XR) and Claim (XRC) remain permanently stuck in 'Synced=False' or 'Ready=False'.
Want to master this scenario in a live sandbox? KodeKloud's CKA & CKAD Hands-On Certification Track covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Inspect Claim (XRC) and Resolve Composite Resource (XR) Name
Run kubectl describe on the developer's Claim to identify the underlying XR reference and initial condition events.
kubectl get appdatabase.platform.acme.com my-db -n team-checkout -o yaml
# Extract .spec.resourceRef.name (e.g. appdatabase-xr-9x8zk)
kubectl describe appdatabase.platform.acme.com my-db -n team-checkout
Inspect Composite Resource (XR) Composition Status
Check whether the XR found a matching Composition and identify the Managed Resources (MRs) it attempted to render.
kubectl describe xappdatabase.platform.acme.com appdatabase-xr-9x8zk
# Look for: 'CompositionSelected' and .spec.resourceRefs containing RDSInstance, SecurityGroup
Inspect Managed Resource (MR) and Provider Events
Query the concrete cloud resource (e.g. rds.aws.upjet.crossplane.io) to view the exact AWS API rejection error or provider pod panic.
kubectl get rdsinstance.database.aws.upjet.crossplane.io -o wide
kubectl describe rdsinstance.database.aws.upjet.crossplane.io <mr-name>
# Look for Status.Conditions: 'CannotCreateExternalResource: InvalidVpcId'
Verify Provider Pod Health & Controller RBAC
Inspect the Crossplane AWS provider pod logs in crossplane-system namespace to check for IAM authentication failures or throttling.
kubectl logs -n crossplane-system -l pkg.crossplane.io/provider=provider-aws-rds -c provider --tail=100
- Follow the four-level Crossplane abstraction hierarchy: Claim -> Composite Resource -> Managed Resource -> Provider.
- Inspect the XR's CompositionRef to ensure required schema patches and environment variables resolved cleanly.
- Query the concrete Managed Resource status condition to read the exact raw cloud provider API error.