Debugging Kubernetes nodes with crictl

FEATURE STATE: Kubernetes v1.11 [stable]

crictl is a command-line interface for CRI-compatible container runtimes. You can use it to inspect and debug container runtimes and applications on a Kubernetes node. crictl and its source are hosted in the cri-tools repository.

Before you begin

crictl requires a Linux operating system with a CRI runtime.

Installing crictl

You can download a compressed archive crictl from the cri-tools release page, for several different architectures. Download the version that corresponds to your version of Kubernetes. Extract it and move it to a location on your system path, such as /usr/local/bin/.

General usage

The crictl command has several subcommands and runtime flags. Use crictl help or crictl <subcommand> help for more details.

You can set the endpoint for crictl by doing one of the following:

  • Set the --runtime-endpoint and --image-endpoint flags.
  • Set the CONTAINER_RUNTIME_ENDPOINT and IMAGE_SERVICE_ENDPOINT environment variables.
  • Set the endpoint in the configuration file /etc/crictl.yaml. To specify a different file, use the --config=PATH_TO_FILE flag when you run crictl.

Note:

If you don’t set an endpoint, crictl attempts to connect to a list of known endpoints, which might result in an impact to performance.

You can also specify timeout values when connecting to the server and enable or disable debugging, by specifying timeout or debug values in the configuration file or using the --timeout and --debug command-line flags.

To view or edit the current configuration, view or edit the contents of /etc/crictl.yaml. For example, the configuration when using the containerd container runtime would be similar to this:

  1. runtime-endpoint: unix:///var/run/containerd/containerd.sock
  2. image-endpoint: unix:///var/run/containerd/containerd.sock
  3. timeout: 10
  4. debug: true

To learn more about crictl, refer to the crictl documentation.

Example crictl commands

The following examples show some crictl commands and example output.

List pods

List all pods:

  1. crictl pods

The output is similar to this:

  1. POD ID CREATED STATE NAME NAMESPACE ATTEMPT
  2. 926f1b5a1d33a About a minute ago Ready sh-84d7dcf559-4r2gq default 0
  3. 4dccb216c4adb About a minute ago Ready nginx-65899c769f-wv2gp default 0
  4. a86316e96fa89 17 hours ago Ready kube-proxy-gblk4 kube-system 0
  5. 919630b8f81f1 17 hours ago Ready nvidia-device-plugin-zgbbv kube-system 0

List pods by name:

  1. crictl pods --name nginx-65899c769f-wv2gp

The output is similar to this:

  1. POD ID CREATED STATE NAME NAMESPACE ATTEMPT
  2. 4dccb216c4adb 2 minutes ago Ready nginx-65899c769f-wv2gp default 0

List pods by label:

  1. crictl pods --label run=nginx

The output is similar to this:

  1. POD ID CREATED STATE NAME NAMESPACE ATTEMPT
  2. 4dccb216c4adb 2 minutes ago Ready nginx-65899c769f-wv2gp default 0

List images

List all images:

  1. crictl images

The output is similar to this:

  1. IMAGE TAG IMAGE ID SIZE
  2. busybox latest 8c811b4aec35f 1.15MB
  3. k8s-gcrio.azureedge.net/hyperkube-amd64 v1.10.3 e179bbfe5d238 665MB
  4. k8s-gcrio.azureedge.net/pause-amd64 3.1 da86e6ba6ca19 742kB
  5. nginx latest cd5239a0906a6 109MB

List images by repository:

  1. crictl images nginx

The output is similar to this:

  1. IMAGE TAG IMAGE ID SIZE
  2. nginx latest cd5239a0906a6 109MB

Only list image IDs:

  1. crictl images -q

The output is similar to this:

  1. sha256:8c811b4aec35f259572d0f79207bc0678df4c736eeec50bc9fec37ed936a472a
  2. sha256:e179bbfe5d238de6069f3b03fccbecc3fb4f2019af741bfff1233c4d7b2970c5
  3. sha256:da86e6ba6ca197bf6bc5e9d900febd906b133eaa4750e6bed647b0fbe50ed43e
  4. sha256:cd5239a0906a6ccf0562354852fae04bc5b52d72a2aff9a871ddb6bd57553569

List containers

List all containers:

  1. crictl ps -a

The output is similar to this:

  1. CONTAINER ID IMAGE CREATED STATE NAME ATTEMPT
  2. 1f73f2d81bf98 busybox@sha256:141c253bc4c3fd0a201d32dc1f493bcf3fff003b6df416dea4f41046e0f37d47 7 minutes ago Running sh 1
  3. 9c5951df22c78 busybox@sha256:141c253bc4c3fd0a201d32dc1f493bcf3fff003b6df416dea4f41046e0f37d47 8 minutes ago Exited sh 0
  4. 87d3992f84f74 nginx@sha256:d0a8828cccb73397acb0073bf34f4d7d8aa315263f1e7806bf8c55d8ac139d5f 8 minutes ago Running nginx 0
  5. 1941fb4da154f k8s-gcrio.azureedge.net/hyperkube-amd64@sha256:00d814b1f7763f4ab5be80c58e98140dfc69df107f253d7fdd714b30a714260a 18 hours ago Running kube-proxy 0

List running containers:

  1. crictl ps

The output is similar to this:

  1. CONTAINER ID IMAGE CREATED STATE NAME ATTEMPT
  2. 1f73f2d81bf98 busybox@sha256:141c253bc4c3fd0a201d32dc1f493bcf3fff003b6df416dea4f41046e0f37d47 6 minutes ago Running sh 1
  3. 87d3992f84f74 nginx@sha256:d0a8828cccb73397acb0073bf34f4d7d8aa315263f1e7806bf8c55d8ac139d5f 7 minutes ago Running nginx 0
  4. 1941fb4da154f k8s-gcrio.azureedge.net/hyperkube-amd64@sha256:00d814b1f7763f4ab5be80c58e98140dfc69df107f253d7fdd714b30a714260a 17 hours ago Running kube-proxy 0

Execute a command in a running container

  1. crictl exec -i -t 1f73f2d81bf98 ls

The output is similar to this:

  1. bin dev etc home proc root sys tmp usr var

Get a container’s logs

Get all container logs:

  1. crictl logs 87d3992f84f74

The output is similar to this:

  1. 10.240.0.96 - - [06/Jun/2018:02:45:49 +0000] "GET / HTTP/1.1" 200 612 "-" "curl/7.47.0" "-"
  2. 10.240.0.96 - - [06/Jun/2018:02:45:50 +0000] "GET / HTTP/1.1" 200 612 "-" "curl/7.47.0" "-"
  3. 10.240.0.96 - - [06/Jun/2018:02:45:51 +0000] "GET / HTTP/1.1" 200 612 "-" "curl/7.47.0" "-"

Get only the latest N lines of logs:

  1. crictl logs --tail=1 87d3992f84f74

The output is similar to this:

  1. 10.240.0.96 - - [06/Jun/2018:02:45:51 +0000] "GET / HTTP/1.1" 200 612 "-" "curl/7.47.0" "-"

What’s next