Q: You deploy a Kratix Promise for a 'Redis-as-a-Service' capability on your Platform cluster. When a developer submits a Resource Request, the promise workflow pod errors with 'forbidden: cannot create customresourcedefinitions' and no destination cluster sync occurs. How do you triage Kratix multi-cluster reconciliation?
Triage and architectural resolution when a Kratix Promise fails to generate Destination resources across worker clusters due to pipeline pod RBAC errors.
Want to master this scenario in a live sandbox? KodeKloud's CKA & CKAD Hands-On Certification Track covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Inspect Resource Request Status and Workflow Pipeline Pod
Check the status of the developer request and query the ephemeral workflow pod generated by Kratix in the `kratix-platform` namespace.
kubectl describe redis.marketplace.acme.com my-cache -n team-cart
# Find matching pipeline pod:
kubectl get pods -n kratix-platform -l kratix.io/promise-name=redis
kubectl logs -n kratix-platform <pipeline-pod-name> -c promise-workflow
Correct Pipeline Pod ServiceAccount RBAC Bindings
Kratix pipeline pods execute within a dedicated ServiceAccount. If the Promise pipeline requires reading Secrets or generating CRDs, bind a ClusterRole to the Promise's execution ServiceAccount in the platform cluster.
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: kratix-redis-promise-binding
subjects:
- kind: ServiceAccount
name: redis-promise-pipeline-sa
namespace: kratix-platform
roleRef:
kind: ClusterRole
name: kratix-promise-pipeline-role
apiGroup: rbac.authorization.k8s.io
Verify Kratix WorkPlacement and Destination StateStore Sync
Inspect the generated `Work` and `WorkPlacement` CRDs. Confirm that the StateStore (Git repo or S3 bucket) is receiving the output manifests and that the destination cluster's Flux/ArgoCD agent is pulling updates.
kubectl get works.platform.kratix.io -A
kubectl get workplacements.platform.kratix.io -A -o wide
- Examine ephemeral pipeline pod logs in kratix-platform to capture raw container script execution errors.
- Ensure ServiceAccounts assigned to the Promise have sufficient RBAC permissions to read platform secrets.
- Validate WorkPlacements and Destination StateStore sync targets to confirm delivery to worker clusters.