Crossplane's Default Settings Can Hide Failures, Lab Experiment Reveals

A developer built a two-cluster Crossplane lab to test how the open-source control plane manages resources across native and remote clusters. The experiment found that native compositions cannot reach external clusters without provider-kubernetes Objects, and readiness status shows green even when a workload fails to start, because the default policy only confirms successful application, not actual operation. Drift correction, while theoretically supported, requires enabling an alpha feature flag and additional configuration before it functions — without which changes go undetected for up to ten minutes. Credential rotation performed directly on a target database was not detected by the control plane, causing application-level authentication failures despite all status indicators appearing healthy. The key finding is that Crossplane's capabilities exist but require explicit, non-default configuration to behave as most users would expect.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in