# Unstick a Kubernetes namespace hanging in Terminating

## TL;DR
Something left in the namespace has a finalizer whose controller is gone, so cleanup never finishes. List what remains, fix or remove the blocking finalizer, and let termination complete on its own. Only clear the namespace finalizers directly as a last resort, after you have confirmed nothing important remains.

```text
Kubernetes namespace stuck in Terminating: safe force-delete steps
```

## Steps

1. **Confirm the state.** Run `kubectl get namespace [name] -o yaml` and check the status conditions and spec finalizers.
   Expected: status shows Terminating with the standard Kubernetes finalizer still present.

2. **Find what is stuck inside.** List namespaced resources still present, for example by iterating api-resources against the namespace.
   Expected: one or more resources still listed. Those are blocking termination.

3. **Inspect the stuck resource's finalizers.** Run `kubectl get [kind] [name] -n [namespace] -o yaml` and look at the finalizers list.
   Expected: you see a third-party finalizer (backup tool, service mesh, operator) whose controller is no longer running.

4. **Fix it properly first.** If the owning operator still exists, let it finish cleanup. If the operator is gone for good, patch the finalizer off the stuck resource.
   Expected: the resource deletes, and the namespace proceeds on its own.

5. **Last resort: clear namespace finalizers via the finalize subresource.** Start `kubectl proxy` in one terminal, then PUT the namespace object with an empty finalizers list to the finalize endpoint.
   Expected: the namespace disappears. Do this only after step 2 shows nothing valuable remains.

## Use this when
- A namespace sits in Terminating for hours
- Cleaning up after uninstalling an operator or service mesh
- Test namespaces that will not go away

## Not for this skill when
- Individual pods are stuck Terminating (different fix, usually node or volume related)
- Nodes are stuck or NotReady
- You just want to learn what finalizers are in general

## Variant phrasings
- kubernetes namespace terminating forever
- delete namespace stuck kubernetes
- namespace finalizer removal
- namespace will not delete

## Why it happens
Finalizers are cleanup hooks: the namespace controller waits until every resource in the namespace is gone before finishing termination. If the controller that honors a resource's finalizer was deleted first (uninstalled operator), the hook never runs and deletion blocks forever.

## Edge cases
- Never force-delete a namespace that still holds real workloads. You will orphan resources that are painful to clean up later.
- Some cloud controllers re-add finalizers after you remove them. Check for a running controller before patching.
- The proxy plus finalize trick bypasses safety checks entirely. Verify emptiness first, every time.
- A namespace with zero resources but stuck finalizers usually means the API server never got the final update. Retry the finalize PUT once before assuming worse.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_obF5oIB9YWrraxwSoYoK9g
