kubectl debug

kubectl debug and Ephemeral Containers

BookNest's API image has no ps or curl 3,008 . An ephemeral container (stable since Kubernetes 1.25 5,150 ) joins a running Pod without a restart, from any image, and --target shares a container's process namespace:

Looking inside a running API Pod with a busybox ephemeral containerYAML
P=$(kubectl get pod -l tier=api --sort-by=.metadata.creationTimestamp -o name | head -1)
kubectl exec $P -c api -- ps 2>&1 | grep -o 'exec: .*'
D="kubectl debug $P -q --image=busybox:1.37 --target=api -c debugger"
$D -- true 2>&1 | fold -s -w 95
$D --profile=baseline 2>/dev/null -- sh -c \
  'ps -o pid,user,comm; netstat -tln | grep 3000; wget -qO- localhost:3000/version; echo'
until kubectl logs $P -c debugger 2>/dev/null | grep -q version; do sleep 1; done
kubectl logs $P -c debugger
Output
exec: "ps": executable file not found in $PATH
Error from server (Forbidden): pods "api-b4bc995c9-xpntb" is forbidden: violates PodSecurity
"baseline:v1.37": non-default capabilities (container "debugger" must not include "SYS_PTRACE"
in securityContext.capabilities.add)
PID   USER     COMMAND
    1 1000     MainThread
   48 root     sh
   58 root     ps
tcp        0      0 :::3000                 :::*                    LISTEN
{"version":"1.4.0"}

The default general profile adds SYS_PTRACE, which the namespace's baseline Pod Security Standard (Pod Security and Policies) refused; --profile=baseline passed, and the debugger saw the API's process (UID 1000, named after Node's main thread) and its port 3000. For a Pod that will not start, --copy-to clones it with a new command.