Delete a container instance
Delete a container instance, and what is removed with it — its identity, its endpoints, the vault of a blueprint instance — and what stays, such as kept persistent volumes.
Requires: containerinstance/delete
Deleting an instance needs containerinstance/delete; the Owner, Contributor, Apps Operator and
Blueprints Operator roles have it.
Delete it
- On the instance page, open the Danger Zone tab and choose Delete.
- Read what the dialog says will be deleted with the instance, type the instance's name, and choose Delete Permanently.
With the CLI:
stsh ci delete worker -g my-resource-group --yesWhat goes with it
- Every component's pods and in-cluster names, its autoscalers and the objects that hold its
filesvolumes. - Its endpoints: routes, certificates and sign-in protection.
- Its managed identity. Role assignments made to the identity are not removed with it; remove them where you made them.
- Its snapshot schedule.
- Persistent volumes declared with
retainOnDelete: false.
What stays
- Persistent volumes are kept by default. A kept volume stays in the resource group, but it is not attached to a new instance created later under the same name — that instance gets new, empty volumes.
- For an instance deployed from a blueprint, the managed resources the blueprint provisioned, such as databases, stay.
- Its snapshots stay in the backup store until they expire, with the secrets and configuration they copied. Without the instance they can no longer be listed, restored or deleted through the platform. An instance created later under the same name lists them again, but restoring one of them into it fails, because its volumes are new ones.
An instance deployed from a blueprint
A blueprint deployment creates a vault for the instance, named <instance>-secrets. Deleting the
instance deletes that vault too, with every secret in it, for good; the Danger Zone says so
before you confirm.
That also needs permission to delete the vault. When you may delete the instance but not the vault, the platform refuses the delete before touching anything. The dialog then offers to request temporary Contributor access on the vault: an owner approves it, you activate it, and then you delete — see Request access.