A lightweight Docker image designed for gRPC service debugging.
1.3K
A lightweight Docker image designed for gRPC service debugging and testing within Kubernetes clusters.
grpcurl -plaintext <service>:<port> list
grpcurl -plaintext <service>:<port> describe <service.name>
grpcurl -plaintext -d '{"name": "test"}' \
<service>:<port> <package.Service/Method>
# Copy your .proto files to /home/debugger/protos
grpcurl -import-path ./protos -proto service.proto \
-plaintext -d '{"id": "123"}' \
<service>:<port> <package.Service/Method>
# With TLS
grpcurl -d '{"name": "test"}' <service>:443 <package.Service/Method>
# Skip certificate verification
grpcurl -insecure -d '{"name": "test"}' <service>:443 <package.Service/Method>
# With custom CA certificate
grpcurl -cacert /path/to/ca.crt -d '{"name": "test"}' \
<service>:443 <package.Service/Method>
# With server reflection
grpcui -plaintext <service>:<port>
# With proto files
grpcui -import-path ./protos -proto service.proto \
-plaintext <service>:<port>
# Access at http://localhost:8080
# Basic load test
ghz --insecure --proto ./protos/service.proto \
--call package.Service/Method \
-d '{"name":"test"}' \
-c 10 -n 1000 \
<service>:50051
# With duration and rate limiting
ghz --insecure \
--call package.Service/Method \
-d '{"name":"test"}' \
-c 50 --rps 100 -z 30s \
<service>:50051
# Connect with server reflection (most common)
evans --host <service> --port 50051 -r repl
# Inside evans REPL:
# show package - List available packages
# package <name> - Select a package
# show service - List services in package
# service <name> - Select a service
# show message - List message types
# call <method> - Call an RPC method (interactive prompts)
# exit - Exit REPL
# Example session:
evans --host my-grpc-service --port 50051 -r repl
> show package
> package api.v1
> show service
> service UserService
> call GetUser
# (evans will prompt for field values)
user_id: 123
# Call a method directly without REPL
evans --host <service> --port 50051 \
--package api.v1 \
--service UserService \
--call GetUser \
--json '{"user_id": "123"}'
# With proto files (no reflection)
evans --host <service> --port 50051 \
--path ./protos \
--proto service.proto \
-r repl
# With TLS
evans --host <service> --port 443 \
--tls \
--cacert /path/to/ca.crt \
-r repl
# Plaintext (no TLS)
evans --host <service> --port 50051 \
--plaintext \
-r repl
header command to set metadata: header authorization="Bearer token"--web flag for a web-based UI alternative to terminal REPLif you want to debug using an ephemeral container in an existing pod:
$ kubectl debug mypod -it --image=j4rj4r/grpc-debug
if you want to spin up a throw away pod for debugging.
$ kubectl run tmp-shell --rm -i --tty --image j4rj4r/grpc-debug
if you want to spin up a container on the host's network namespace.
$ kubectl run tmp-shell --rm -i --tty --overrides='{"spec": {"hostNetwork": true}}' --image j4rj4r/grpc-debug
# Deploy the debug pod
kubectl apply -f grpc-debug-pod.yaml
# Exec into pod
kubectl exec -it grpc-debug -- /bin/sh
# List services from a gRPC service
grpcurl -plaintext my-grpc-service:50051 list
# Test an RPC call
grpcurl -plaintext -d '{"user_id": "123"}' \
my-grpc-service:50051 api.v1.UserService/GetUser
# From grpc-debug pod, test service in another namespace
grpcurl -plaintext \
my-service.other-namespace.svc.cluster.local:50051 list
# Test with service mesh (Istio, Linkerd)
# Usually requires proper certificates mounted via volumes
# Check certificate details
openssl s_client -connect my-service:50051 -showcerts
# Test with mTLS
grpcurl -cert /certs/client.crt -key /certs/client.key \
-cacert /certs/ca.crt \
my-service:50051 list
Content type
Image
Digest
sha256:75c072c9c…
Size
46.3 MB
Last updated
12 months ago
docker pull j4rj4r/grpc-debug