Bug 1397538 - [RFE] [Supportability] pod to pod diagnostics infrastructure
Summary: [RFE] [Supportability] pod to pod diagnostics infrastructure
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: rhel-tools-container
Version: 7.3
Hardware: Unspecified
OS: Unspecified
unspecified
high
Target Milestone: rc
: ---
Assignee: Jindrich Novy
QA Contact: atomic-bugs@redhat.com
Vikram Goyal
URL:
Whiteboard:
Depends On:
Blocks: 1397539 1420851
TreeView+ depends on / blocked
 
Reported: 2016-11-22 18:27 UTC by Eric Rich
Modified: 2021-08-30 11:53 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-01-15 07:28:46 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Knowledge Base (Solution) 1611883 0 None None None 2016-11-22 22:54:58 UTC

Description Eric Rich 2016-11-22 18:27:45 UTC
The rhel/tools container (https://access.redhat.com/containers/#/repo/57ea8cf09c624c035f96f3bb) needs a "pod to pod diagnostics infrastructure" (shipped with the rhel/tools container), and a set of defined "plugins" (enabled either based on options for the diagnostics infrastructure, or through auto discovery, based on the pod[s] being diagnosed). 

Execution of this diagnostics infrastructure should takes a given container, or set of containers (on the same host), and validate that the diagnostics infrastructure can reach all of the containers independently. 

The primary reason for using the "rhel/tools" container (as the entry point) for this, is that it provides a mechanism for Red Hat to address shipping and providing a single solution ("pod to pod diagnostics infrastructure") for diagnosing common issues with pods.

Making the pod to pod diagnostics infrastructure "plug-able" keeps every pod[s] diagnostics steps from being a cookie cutter shell when information is collected. In short, Python container issues are likely to be very different from JBoss container issues, and as such what diagnostics are done (or get enabled) need to be treated differently.

Comment 3 Daniel Walsh 2016-11-22 22:40:33 UTC
You should strace the pid from the outside.  not necessary to enter the container.  But this is generally a problem of debugging across mnt namespaces.

Comment 9 Eric Rich 2016-11-30 21:15:29 UTC
Could this RFE ue the same mechanism as atomic scan? http://developers.redhat.com/blog/2016/05/02/introducing-atomic-scan-container-vulnerability-detection/

This might remove the need for a tools container?

Comment 13 RHEL Program Management 2021-01-15 07:28:46 UTC
After evaluating this issue, there are no plans to address it further or fix it in an upcoming release.  Therefore, it is being closed.  If plans change such that this issue will be fixed in an upcoming release, then the bug can be reopened.


Note You need to log in before you can comment on or make changes to this bug.