Logs & Debugging (CKAD)
Five broken pods, one routine: get, describe, logs, events, exec. Learn which one answers which question.
An interactive Kubernetes lesson: 21 steps, about 30 minutes, on a live simulation in your browser.
You are on call for a small shop. web serves the pages, api serves product data and ledger stores orders. Requests are flowing and every one comes back 200. This is what healthy looks like, so look at it before anything breaks.
kubectl get pods prints three columns that matter. READY is how many containers pass their readiness check, out of how many the pod has. STATUS is what the pod is doing right now. RESTARTS is how many times a container in it has died and been started again.
What you will learn
First look
- Three columns tell you where to look: READY: is it serving. STATUS: what is it doing now. RESTARTS: how often has it died. Three columns pick your next command.
- The same object, in more detail
The cluster's side of the story
- A pod that never started: Logs are the app talking. Events are the cluster talking. If the container never started, only the cluster has anything to say.
- describe: the cluster's account: describe is one object's spec, state and recent events on one screen. The answer is usually in the last five lines.
- Break it: a pod with no node: Every component reports by writing events: scheduler, kubelet, controllers. They are kept for about an hour, then they are gone.
The app's side of the story
- Logs: what the app wrote: kubectl logs reads a file on the node: whatever the container wrote to stdout and stderr. An app that logs to a file inside the container shows you nothing.
- The instance before this one: RESTARTS above zero means there is a dead container with a story. kubectl logs -p reads its last words.
- Which container, which pod
Getting inside
- exec: see what the app sees: exec runs your command inside the container's own world: same files, same env, same DNS, same network. It answers "what does the app actually see?"
- Break it: no shell to exec into
- kubectl debug: bring your own tools: An ephemeral container is a temporary toolbox bolted onto a running pod: your image, the pod's network and, with --target, the app's processes.
- Debug a copy, debug a node
Tunnels and meters
- port-forward: a tunnel to one pod: port-forward is a private tunnel from your machine to one pod. It needs no Service and changes nothing in the cluster.
- top: who is using what: kubectl top shows live usage and needs metrics-server. describe shows requests and limits. Usage against request is the comparison that matters.
The triage order
- One routine for every ticket: get, describe, logs, logs -p, events, exec, fix. Read before you touch, and let STATUS choose where you start.
- Running, not Ready, no restarts
- Drill: the crashed container's logs
- Drill: events in order
- Drill: a toolbox for a bare image
Recap & playground
- Cheat sheet
- Playground