Sign inSign up

basilcrow/crisis-tools

By basilcrow

•Updated about 1 year ago

Linux crisis tools for debugging performance issues in Kubernetes production environments

Image
Monitoring & observability
0

494

basilcrow/crisis-tools repository overview

⁠Linux Crisis Tools

This repository provides a Dockerfile to create a container image with pre-installed Linux crisis tools, as recommended in Brendan Gregg’s blog post “Linux Crisis Tools⁠.” The image is designed for debugging performance issues in Kubernetes production environments, ensuring essential diagnostic tools are readily available without installation delays during outages. The source code is available in GitHub⁠.

⁠Purpose

When a performance issue causes an outage in a Kubernetes cluster, installing diagnostic tools on the fly can waste critical time. This Docker image pre-installs a comprehensive set of Linux crisis tools to enable rapid debugging of performance bottlenecks in Kubernetes production environments.

⁠Tools Included

The Dockerfile installs the following packages, as recommended by Brendan Gregg, on an Ubuntu base image:

PackageProvidesNotes
procpsps(1), vmstat(1), uptime(1), top(1)Basic stats
util-linuxdmesg(1), lsblk(1), lscpu(1)System log, device info
sysstatiostat(1), mpstat(1), pidstat(1), sar(1)Device stats
iproute2ip(1), ss(8), nstat(8), tc(8)Preferred net tools
numactlnumastat(8)NUMA stats
tcpdumptcpdump(8)Network sniffer
linux-tools-common, linux-tools-$(uname -r)perf(1), turbostat(8)Profiler and PMU stats
bpfcc-toolsopensnoop(1), execsnoop(8), runqlat(8), biotop(8), biosnoop(8), biolatency(8), tcptop(8), tcplife(8), trace(8), argdist(8), funccount(8), profile(8), etc.Canned eBPF tools
bpftracebpftrace(8), basic versions of opensnoop(8), execsnoop(8), runqlat(8), biosnoop(8), etc.eBPF scripting
trace-cmdtrace-cmd(1)Ftrace CLI
nicstatnicstat(1)Net device stats
ethtoolethtool(8)Net device info
tiptoptiptop(1)PMU/PMC top

Note

Some tools (e.g., `bpfcc-tools`, `bpftrace`) require kernel headers and specific privileges to function fully. Ensure your Kubernetes environment grants necessary permissions (e.g., `SYS_ADMIN` capabilities or privileged mode) for eBPF and tracing tools.

⁠Prerequisites

  • Kubernetes cluster for deploying the container.
  • Familiarity with Kubernetes debugging workflows (e.g., kubectl exec for accessing containers).
  • For eBPF tools (e.g., bpfcc-tools, bpftrace), ensure the Kubernetes node kernel supports BPF and the container has appropriate capabilities.

⁠Usage in Kubernetes

To use this image in a Kubernetes cluster for debugging:

  1. Create a pod manifest to run the image with appropriate permissions. For example:

    apiVersion: v1
    kind: Pod
    metadata:
      name: crisis-tools-pod
    spec:
      hostPID: true
      containers:
        - name: crisis-tools
          image: docker.io/basilcrow/crisis-tools:latest
          command: ["sleep", "infinity"]
          securityContext:
            privileged: true
            capabilities:
              add:
                - SYS_ADMIN
                - SYS_PTRACE
    
  2. Apply the pod manifest:

    $ kubectl apply -f crisis-tools-pod.yaml
    
  3. Use kubectl exec to access the pod and run diagnostic commands:

    $ kubectl exec -it crisis-tools-pod -- bash
    
  4. Inside the pod, you can run diagnostic commands like:

    $ iostat -xz 1
    $ tcpdump -i eth0
    $ perf stat -a sleep 10
    $ bpftrace -e 'tracepoint:raw_syscalls:sys_enter { @[comm] = count(); }'
    

Warning

Running privileged containers or granting capabilities like `SYS_ADMIN` can pose security risks. Use this image only in controlled debugging scenarios and remove the pod after use.

⁠Contributing

If you believe additional crisis tools should be included or have improvements to the Dockerfile, please open an issue or submit a pull request. Ensure any suggested tools align with the goal of lightweight, essential diagnostics for Kubernetes production environments.

⁠License

This repository is licensed under the Apache License, Version 2.0. See the LICENSE⁠ file for details.

Tag summary

Content type

Image

Digest

sha256:e0294c687…

Size

148.2 MB

Last updated

about 1 year ago

docker pull basilcrow/crisis-tools