Q: Your organization has 4,500 GitHub repositories, but only 1,800 have valid catalog-info.yaml files in Backstage. How do you detect 'ghost services' actively running in Kubernetes clusters that lack catalog ownership, and automate catalog adoption?
Detecting and remediating orphaned repositories, decommissioned infrastructure, and shadow services missing catalog-info.yaml metadata.
Want to master this scenario in a live sandbox? KodeKloud's CKA & CKAD Hands-On Certification Track covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Correlate Kubernetes Runtime Deployments with Backstage API
Run a nightly reconciliation script querying the Kubernetes API across all clusters. Extract `app.kubernetes.io/name` from active deployments and query Backstage's `/api/catalog/entities/by-name/component/default/{name}`. Any cluster deployment missing from Backstage is flagged as an unregistered ghost service.
# Query Backstage API to verify registration
curl -s -H "Authorization: Bearer $BACKSTAGE_TOKEN" \
https://backstage.acme.com/api/catalog/entities/by-name/component/default/checkout-api | jq .metadata.name
Automate Catalog-Info Generation via GitHub PRs
For repositories without catalog files, run an automated script that inspects package.json / pom.xml / go.mod and git commit history to infer service name and primary contributors, opening automated PRs containing a valid `catalog-info.yaml`.
apiVersion: backstage.io/v1alpha1
kind: Component
metadata:
name: checkout-api
description: Checkout core transaction service
spec:
type: service
lifecycle: production
owner: team-checkout
Enforce Admission Webhook for Production Namespaces
Deploy a Kyverno / OPA policy in production clusters blocking deployment manifests that do not include the annotation `backstage.io/kubernetes-id` matching a verified registered service in Backstage.
- Run automated cron auditors comparing active cluster deployment names against Backstage entity APIs.
- Generate automated pull requests creating default catalog-info.yaml files based on repository commit history.
- Enforce production Kyverno policies requiring verified Backstage catalog ownership annotations.