maqpna support-bundle
Collect a redacted diagnostics archive for support
Synopsis#
maqpna support-bundle [--out FILE.tar.gz|-] [--release maqpna] [-n NS] [--kube-context C] [--tail 2000]
[--since 24h] [--agent-namespaces] [--gateway URL --token T] [-o json]Description#
Secret values are never collected (only Secret names and key names). Logs, values, ConfigMaps and custom resources are redacted: bearer and basic credentials, JWTs, passwords in URLs and DSNs, PEM private keys, values of keys named like token/secret/password/dsn/hmac/apiKey, and cloud API keys. Review the archive before sending it.
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--agent-namespaces | switch | also collect pod lists and events of agent namespaces (no agent logs) | none |
--debug | switch | print Helm's debug log to stderr | none |
--gateway | string | gateway base URL: adds the gateway posture to doctor.json | none |
--kube-context | string | kubeconfig context (default: the maqpna context's) | none |
-n, --namespace | string | namespace of the MAQPNA control plane (the Helm release) | maqpna-system |
--oidc-token-file | string | OIDC access token file (auditor/admin) | none |
--out | string | archive to write (default maqpna-support-YYYYMMDD-HHMMSS.tar.gz; - for stdout) | none |
--release | string | Helm release name | maqpna |
--since | duration | only logs newer than this (e.g. 24h; 0: no limit) | none |
--tail | int | log lines per container | 2000 |
--timeout | duration | timeout of Kubernetes operations (CRDs Established, --wait) | 10m0s |
--token | string | static admin token for the gateway posture (env MAQPNA_ADMIN_TOKEN) | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna support-bundle
maqpna support-bundle --since 2h --agent-namespaces --out bundle.tar.gzWhat happens when you run it#
- Uses the Kubernetes API of your kubeconfig (
--kubeconfig,--kube-context, or the current context). - Talks to the gateway:
--gateway, elseMAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context). - Authenticates to the admin API with the token stored by
maqpna login,--oidc-token-file, or a static--token(MAQPNA_ADMIN_TOKEN). - Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |
Terminal demo#
This command needs a Kubernetes cluster with MAQPNA installed, so the recording shows its help. Try it against a cluster from Install.