feat: Add galactic-debug image for kubectl debug troubleshooting - #611
Merged
Merged
Conversation
Two production incidents needed live eBPF map dumps and direct FRR/GoBGP queries that no image in this stack could provide. One of them was only worked around with a privileged hostPID pod just to find a process id for nsenter. Add containers/galactic-debug, built on nicolaka/netshoot with bpftool, bpftrace, vtysh, the gobgp CLI, kubectl, crictl, yq, and a new galactic-usid CLI wrapping the base62/hex uSID codec. Publish it via the same CI pipeline as every other component image, and swap it in for nicolaka/netshoot in every containerlab tenant pod so it gets exercised before an incident ever needs it. See containers/galactic-debug/README.md for the two kubectl debug usage modes and the operational caveats carried over from the incident notes that motivated this image. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
privateip
marked this pull request as ready for review
September 25, 2026 17:25
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Two production incidents needed live eBPF map dumps and direct FRR/GoBGP queries, and nothing in the stack's existing tooling could do either.
One of them was only worked around with a privileged debug pod just to find a process id for nsenter.
This adds a purpose-built debug image, published like every other component image in this repo, and wires it into the lab environment so it gets exercised before an incident ever needs it.
Test plan
🤖 Generated with Claude Code