> For the complete documentation index, see [llms.txt](https://docs.e6data.com/query-engine/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.e6data.com/query-engine/guides/deployment/azure-in-vpc/delete-workspace.md).

# Delete workspace

Tear down an e6data workspace in your AKS cluster with kubectl and az, and what to intentionally leave in place.

Removing a workspace deletes its Kubernetes resources but leaves the cluster's base setup (Karpenter, cert-manager, CRDs, operator) intact for other workspaces. Set `WORKSPACE_NAME`, `PREFIX`, and `RESOURCE_GROUP` to the values you used to deploy it.

## Step 1: Delete the namespace

Deleting the namespace removes the namespaced resources - the `NamespaceConfig`, `QueryRouter`, `AccessToken`, service accounts, namespaced RBAC, console, Envoy, xDS, metadata services, compaction job, and the load balancer service. The operator tears down internal services as the NamespaceConfig is removed.

```bash
kubectl delete namespace ${WORKSPACE_NAME}
```

## Step 2: Delete cluster-scoped resources

Some workspace resources are cluster-scoped and are not removed with the namespace:

```bash
# Workspace cluster-scoped RBAC
kubectl delete clusterrole ${WORKSPACE_NAME}-monitoring-role ${WORKSPACE_NAME}-console-warmnodepools-role --ignore-not-found
kubectl delete clusterrolebinding ${WORKSPACE_NAME}-monitoring-role-binding ${WORKSPACE_NAME}-console-warmnodepools-role-binding --ignore-not-found

# Engine NodeClass and NodePool (Karpenter)
kubectl delete nodepool.karpenter.sh ${WORKSPACE_NAME}-nodepool --ignore-not-found
kubectl delete aksnodeclass.karpenter.azure.com ${WORKSPACE_NAME}-nodeclass --ignore-not-found
```

## Step 3: Delete the DNS record

```bash
az network dns record-set a delete \
  --resource-group <dns-zone-rg> \
  --zone-name <your-dns-zone> \
  --name "<hostname-without-zone>" --yes
```

## What's not deleted

These are preserved by default - they may be shared, expensive to recreate, or hold data:

| Resource                    | Why preserved                               | What to do                                   |
| --------------------------- | ------------------------------------------- | -------------------------------------------- |
| Workspace Managed Identity  | May be reused if you recreate the workspace | Delete manually if no longer needed (below). |
| ADLS Gen2 storage account   | Often shared; may contain data you want     | Delete manually if no longer needed.         |
| Role assignments on storage | Tied to the Managed Identity                | Removed when you delete the identity.        |
| TLS certificate secret      | Removed with the namespace                  | Recreate it when you redeploy.               |

To remove the workspace Managed Identity and its federated credentials (if nothing else uses it):

```bash
az identity delete \
  --name ${PREFIX}-${WORKSPACE_NAME}-engine-identity \
  --resource-group ${RESOURCE_GROUP}
```

## Verify deletion

```bash
kubectl get namespace ${WORKSPACE_NAME}
```

This should return `NotFound` once cleanup completes (removal can take 1–2 minutes if finalizers are processing). If the namespace stays in `Terminating`, see [Troubleshooting](/query-engine/guides/deployment/azure-in-vpc/troubleshooting.md).

## Re-creating a deleted workspace

Redeploy from [Deploy workspace and e6data](/query-engine/guides/deployment/azure-in-vpc/deploy-workspace-and-e6data.md). If the Managed Identity still exists it is reused; otherwise recreate it (Part 1 Step 8). Catalogs and clusters from the previous workspace are not restored - they're rebuilt as part of normal usage after re-creation.

## See also

* [Deploy workspace and e6data](/query-engine/guides/deployment/azure-in-vpc/deploy-workspace-and-e6data.md)
* [Troubleshooting](/query-engine/guides/deployment/azure-in-vpc/troubleshooting.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.e6data.com/query-engine/guides/deployment/azure-in-vpc/delete-workspace.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
