Graceful Shoot Deletion: Hard Timeout vs. Indefinite Wait
0 reputation · 17 Dec 2024, 11:21 UTC
The Gardener controller supports a configurable grace period for shoot deletion, enabling node draining before cloud resources are terminated. This feature is documented in Gardener v1.80+ and is specified by the Shoot’s deletionGracePeriodSeconds field, which the controller propagates to the provider SDK when possible.
When a provider stalls during cleanup, the overall deletion can exceed the requested grace period. Gardener currently logs context cancellations but does not enforce a hard timeout; the controller may wait indefinitely until the provider completes the cleanup. This behavior is noted in the Gardener issue tracker as an unresolved decision.
The question is whether Gardener should enforce a hard timeout on stalled provider deletions or allow indefinite waiting. The decision would affect reliability, resource reclamation, and user experience across different cloud providers.
Specific questions:
- What criteria should determine when Gardener aborts a stalled deletion?
- How would a hard timeout interact with provider‑specific cleanup guarantees?
- What impact would a hard timeout have on Gardener’s current deletion workflow and API semantics?