Clean up
When you no longer need your Wazuh Kubernetes deployment, or you want a fresh deployment, remove all its resources. Otherwise, orphaned configurations and volumes keep consuming cluster resources.
This section deletes the Wazuh workloads, Services, Secrets, network policies, and persistent volumes. It also deletes the Traefik ingress controller and the Wazuh agent examples. Run every command from the root of the wazuh-kubernetes repository.
Follow the steps below to delete all deployments, services, and volumes.
Remove the Wazuh agent deployment (if you deployed the example).
$ kubectl delete namespace wazuh-daemonset wazuh-sidecar
Then remove
/var/lib/wazuhon each node where you deployed a DaemonSet agent.Remove the entire cluster
The Wazuh manager cluster deployment uses different StatefulSet elements, as well as ConfigMaps and services.
To delete your Wazuh cluster, execute the following command from the repository directory.
$ kubectl delete -k envs/eks/
$ kubectl delete -k envs/local-env/
This will remove every resource defined in the
kustomization.ymlfile.Note
Deleting the wazuh namespace can race ahead of the individual resource deletes it triggers, occasionally printing
Error from server (NotFound)for a resource that has been deleted. This is expected and does not indicate a failed cleanup.Run the following command from your repository directory to delete the Traefik ingress controller (EKS cluster).
$ kubectl delete -k traefik/runtime/ $ kubectl delete -f traefik/crd/kubernetes-crd-definition-v1.yml
On other cluster types, only the Traefik CRDs were applied. Delete them with the following command:
$ kubectl delete -f traefik/crd/
Run the command below to check if any persistent volumes remain after deleting the cluster.
$ kubectl get persistentvolume
The command output looks similar to this:
NAME CAPACITY ACCESS MODES RECLAIM POLICY STATUS CLAIM STORAGECLASS REASON AGE pvc-024466da-f7c5-11e8-b9b8-022ada63b4ac 10Gi RWO Retain Released wazuh/wazuh-manager-worker-wazuh-manager-worker-1-0 gp2-encrypted-retained 6d pvc-b3226ad3-f7c4-11e8-b9b8-022ada63b4ac 30Gi RWO Retain Bound wazuh/wazuh-indexer-wazuh-indexer-0 gp2-encrypted-retained 6d pvc-fb821971-f7c4-11e8-b9b8-022ada63b4ac 10Gi RWO Retain Released wazuh/wazuh-manager-master-wazuh-manager-master-0 gp2-encrypted-retained 6d pvc-ffe7bf66-f7c4-11e8-b9b8-022ada63b4ac 10Gi RWO Retain Released wazuh/wazuh-manager-worker-wazuh-manager-worker-0-0 gp2-encrypted-retained 6d
On EKS, a Retain reclaim policy is common. Volumes typically transition to the Released state rather than being removed automatically, preserving the underlying data until you explicitly delete the volumes.
On a local cluster, the default StorageClass uses a Delete reclaim policy, which is intended to remove volumes automatically. However, this behavior depends on the storage provisioner.
Note
A volume still bound to a claim cannot be deleted. Delete the claim or its namespace first. The "Remove the entire cluster" step above already does this for a full cleanup.
Run the command below to explicitly delete the volumes.
$ kubectl delete persistentvolume <PV_NAME>
Replace
<PV_NAME>with the name of the persistent volume, for examplepvc-b3226ad3-f7c4-11e8-b9b8-022ada63b4ac.Repeat the
kubectl deletecommand to delete all Wazuh-related persistent volumes.Warning
Do not forget to delete the volumes manually where necessary.
Stop the port-forwards and remove the local files. Keep
/etc/wazuh/caonly if you plan to redeploy with the same CA.$ pkill -f 'kubectl -n wazuh port-forward' $ sudo rm -rf wazuh/config/credentials wazuh/wazuh-certificates $ sudo rm -rf /etc/wazuh/ca