Namespace stuck in Terminating
A deleted namespace never disappears because some resource inside it, or the namespace’s own finalizer, can’t be cleaned up.
Seen on:
Kubernetes
Meaning
Namespace deletion waits until every object inside is gone. Unavailable aggregated APIs (metrics.k8s.io, a removed webhook/CRD controller) or custom resources with finalizers block it. kubectl describe ns shows NamespaceContentRemaining / NamespaceFinalizersRemaining conditions.
Common causes
- CRD instances with finalizers whose controller was uninstalled
- Unavailable APIService (e.g. v1beta1.metrics.k8s.io)
- Stuck PVCs/pods inside
⚡ Quick fix
- kubectl describe ns to see what remains
- Fix or delete broken APIServices
- Remove finalizers from leftover resources (only if their controller is gone)
Detailed fix by platform
Kubernetes
- bash
kubectl describe ns old-app | sed -n '/Conditions/,$p' kubectl get apiservice | grep False kubectl api-resources --verbs=list --namespaced -o name | xargs -n1 kubectl get -n old-app --ignore-not-found --show-kind
How to diagnose
- Conditions — What content/finalizers remain?
- APIs — Unavailable APIServices?
- CRDs — Controllers still installed?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- admission webhook denied the request Error from server: admission webhook "validate.nginx.ingress.kubernetes.io" denied the request
- CrashLoopBackOff Kubernetes: CrashLoopBackOff
- failed calling webhook Internal error occurred: failed calling webhook "x": ... connection refused / context deadline exceeded
Most viewed in Kubernetes
- error converting YAML to JSON error converting YAML to JSON: yaml: line 12: did not find expected key
- kubectl connection refused kubectl: The connection to the server localhost:8080 was refused — did you specify the right host or port?
- CreateContainerConfigError Kubernetes: CreateContainerConfigError — secret / configmap not found
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026