All skills
openshift avatar

/destroy-hc-aws

@cfb745e official
by openshiftopenshift/hypershift543 stars
576

Destroy a HyperShift HostedCluster and all associated AWS infrastructure (VPC, IAM, Route53, etc.).

Use this Skill: https://skilld.dev/gh/openshift/hypershift/destroy-hc-aws

This session only. Nothing lands on disk.

SKILL.md

≈29 tokens always: the name and description. ≈763 when used: this file.

Destroy HostedCluster

This skill destroys a HyperShift HostedCluster and all associated AWS infrastructure.

When to Use This Skill

Use this skill when:

  • You need to clean up a test HostedCluster
  • You want to destroy a HostedCluster and its AWS resources (VPC, subnets, NAT gateways, IAM roles, etc.)
  • You need to remove orphaned HostedClusters from previous test runs

Prerequisites

Source the environment file before using this skill:

source dev/claude-env.sh

Additional requirements:

  • AWS credentials loaded (source $AWS_CREDS_SOURCE)
  • KUBECONFIG pointing to management cluster ($MGMT_KUBECONFIG)
  • hypershift binary built (./bin/hypershift)

Environment Configuration

Environment variables from dev/claude-env.sh:

Variable Description
AWS_CREDENTIALS Path to AWS credentials file
AWS_CREDS_SOURCE Script to source AWS env vars
AWS_REGION AWS region
MGMT_KUBECONFIG Path to management cluster kubeconfig

Command

source $AWS_CREDS_SOURCE && \
KUBECONFIG=$MGMT_KUBECONFIG \
./bin/hypershift destroy cluster aws \
  --name <CLUSTER_NAME> \
  --namespace <NAMESPACE> \
  --aws-creds $AWS_CREDENTIALS \
  --region $AWS_REGION

Parameters

Parameter Description Default
--name Name of the HostedCluster to destroy Required
--namespace Namespace where the HostedCluster exists clusters
--aws-creds Path to AWS credentials file $AWS_CREDENTIALS
--region AWS region $AWS_REGION

What Gets Destroyed

The command destroys:

  • HostedCluster and NodePool resources
  • HostedControlPlane namespace and all resources
  • AWS VPC and subnets
  • NAT gateways and internet gateways
  • Route tables
  • Security groups
  • DHCP options
  • Private hosted zones (Route53)
  • OIDC provider
  • IAM roles and instance profiles
  • VPC endpoints
  • Elastic IPs

Quick Cleanup for Orphaned HCs

If a HostedCluster is stuck deleting, you can force remove it:

# Remove cleanup annotation to skip cloud resource cleanup
KUBECONFIG=$MGMT_KUBECONFIG kubectl annotate hostedcluster <NAME> -n <NAMESPACE> \
  hypershift.openshift.io/cleanup-cloud-resources-

Example Usage

# List existing HostedClusters
KUBECONFIG=$MGMT_KUBECONFIG kubectl get hostedclusters -A

# Destroy a specific HostedCluster
source $AWS_CREDS_SOURCE && \
KUBECONFIG=$MGMT_KUBECONFIG \
./bin/hypershift destroy cluster aws \
  --name my-test-cluster \
  --namespace clusters \
  --aws-creds $AWS_CREDENTIALS \
  --region $AWS_REGION

Troubleshooting

NAT Gateway Still Deleting

NAT gateways take time to delete. The command will retry automatically.

VPC Has Dependencies

The command will retry until all dependencies (subnets, gateways, etc.) are deleted.

HostedCluster Stuck in Deleting

  1. Check if there are stuck finalizers
  2. Remove the cleanup-cloud-resources annotation if you want to skip AWS cleanup
  3. Manually delete AWS resources if needed

Source: SKILL.md on GitHub

1 warning3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    This skill automates the destruction of AWS resources and OpenShift HostedClusters using the hypershift CLI tool. It relies on locally provided binaries and environment-configured credentials. No security risks or malicious behaviors were found.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: MEDIUM · 1 issue

Signed by skilld at cfb745e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 20 hours ago.

Activeupdated 8 months ago
  • Infrastructure
  • hypershift
  • aws
  • kubernetes
  • openshift
  • cluster-management
  • cleanup
  • iam

README badge

README badge for openshift/hypershift/destroy-hc-aws

Destroys a HyperShift HostedCluster on AWS and cleans up all associated infrastructure including VPC, subnets, NAT gateways, IAM roles, Route53 zones, and OIDC providers. Uses the hypershift binary with the management cluster kubeconfig and AWS credentials sourced from environment variables.

Generated from the current SKILL.md.

What AWS resources does this skill delete?
It deletes the VPC, subnets, NAT gateways, internet gateways, route tables, security groups, Route53 private hosted zones, OIDC provider, IAM roles, instance profiles, VPC endpoints, and Elastic IPs associated with the HostedCluster.
What environment setup is required before running this skill?
Source the dev/claude-env.sh file to load AWS credentials, set KUBECONFIG to the management cluster, and ensure the hypershift binary is built in ./bin/hypershift.
What should I do if a HostedCluster is stuck deleting?
Check for stuck finalizers, or remove the hypershift.openshift.io/cleanup-cloud-resources annotation to skip AWS resource cleanup and force-delete the HostedCluster.
What are the required parameters to destroy a HostedCluster?
The cluster name (--name) and namespace (defaults to 'clusters') are required; AWS credentials path and region can be supplied via parameters or environment variables.

Generated from the current SKILL.md. These answers refresh after source changes.