GoogleCloudPlatform / GoogleCloudPlatform/pcap-sidecar

Allow sidecar to trigger pcap dump based on Cloud Logging entry

Open
#40 1 comment 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Go
Stars
25
Forks
5
PR merge metrics
No merged PRs in 30d

Description

**Problem:** Oftentimes an issue we want to troubleshoot is not easily triggered and can be weeks between occurrences. Keeping a pcap sidecar actively pushing captures into cloud logging for weeks might become expensive.

**Potential solution:**

If the sidecar could dump the last X minutes of buffered packet capture data when any container on the same instance logged a given text/json payload, it would allow for these longer term sidecar deployments to debug such intermittent issues.

We would want to be able to configure at least:
- Length of time to buffer captures (potentially also maximum size of that buffered data - warning log if the max size is reached)
- Length of time to continue dumping capture data after the triggering event (default to above buffer length)
- What log message to watch for (usually the error text that we expect the main container to output) - This could be read via shared volume for logging, or a [streaming read from cloud logging](https://cloud.google.com/logging/docs/view/streaming-live-tailing#live_tailing_library)
- Might benefit from a safety config to prevent accidental multiple triggers from causing large logging bills - i.e if the trigger event occurred continuously for a week before being looked at.

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the sidecar's existing packet-capture buffering and Cloud Logging behavior; the issue names no files, tests, or entry points. Clarify the configuration and design for buffer duration or size, post-trigger dumping, log matching, and safeguards against repeated triggers, then define tests for each behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, google-cloud
Domain
cloud, networking, observability
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.