MAQPNADocs

maqpna support-bundle

Collect a redacted diagnostics archive for support

Operate-o json | yaml

Synopsis#

maqpna support-bundle [--out FILE.tar.gz|-] [--release maqpna] [-n NS] [--kube-context C] [--tail 2000]
                      [--since 24h] [--agent-namespaces] [--gateway URL --token T] [-o json]

Description#

Secret values are never collected (only Secret names and key names). Logs, values, ConfigMaps and custom resources are redacted: bearer and basic credentials, JWTs, passwords in URLs and DSNs, PEM private keys, values of keys named like token/secret/password/dsn/hmac/apiKey, and cloud API keys. Review the archive before sending it.

Flags#

FlagTypeDescriptionDefault
--agent-namespacesswitchalso collect pod lists and events of agent namespaces (no agent logs)none
--debugswitchprint Helm's debug log to stderrnone
--gatewaystringgateway base URL: adds the gateway posture to doctor.jsonnone
--kube-contextstringkubeconfig context (default: the maqpna context's)none
-n, --namespacestringnamespace of the MAQPNA control plane (the Helm release)maqpna-system
--oidc-token-filestringOIDC access token file (auditor/admin)none
--outstringarchive to write (default maqpna-support-YYYYMMDD-HHMMSS.tar.gz; - for stdout)none
--releasestringHelm release namemaqpna
--sincedurationonly logs newer than this (e.g. 24h; 0: no limit)none
--tailintlog lines per container2000
--timeoutdurationtimeout of Kubernetes operations (CRDs Established, --wait)10m0s
--tokenstringstatic admin token for the gateway posture (env MAQPNA_ADMIN_TOKEN)none

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna support-bundle
maqpna support-bundle --since 2h --agent-namespaces --out bundle.tar.gz

What happens when you run it#

  • Uses the Kubernetes API of your kubeconfig (--kubeconfig, --kube-context, or the current context).
  • Talks to the gateway: --gateway, else MAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context).
  • Authenticates to the admin API with the token stored by maqpna login, --oidc-token-file, or a static --token (MAQPNA_ADMIN_TOKEN).
  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna support-bundle --help.cast

This command needs a Kubernetes cluster with MAQPNA installed, so the recording shows its help. Try it against a cluster from Install.