View logs and open a terminal
Read a component's container logs, and open a shell inside one of its pods from the Components tab — and what a terminal session can reach.
Requires: containerinstance/readLogs
Both start from the instance's Components tab. When a component runs a single pod, the Logs and Terminal buttons are on the component's row. With several pods, open the row: each pod is listed with its status and restart count, and has buttons of its own. With no pod running the buttons are disabled.
Important
The live log stream and the terminal also check a platform permission on the boundary:
kernel/crates/readLogsfor logs,kernel/crates/execfor a terminal. The built-in roles that can read logs or open a terminal include them, but the check passes only when the role is assigned on the boundary. With the role assigned only on the resource group or on the instance, Logs shows an error instead of lines and Terminal does not open.
View logs
Reading logs needs containerinstance/readLogs; the Reader role has it.
Choose Logs. The drawer streams the pod's log lines as they are written:
- Process — shown when the pod runs several containers: one of them, or All processes.
- Tail — how many earlier lines to start with: 100, 500 (the default), 1000 or 5000.
- Show previous instance — the output of the container's previous run, before its last restart. Use it when a container crash-loops and the current run has nothing to say yet.
- Mode — Follow keeps the newest line in view; Paused holds the view where it is while new lines keep arriving. Scrolling up pauses it.
- Clear empties the view; Download saves the lines received as a
.logfile.
When the browser has no live connection to the platform, the drawer shows a one-off copy of the latest lines instead and says so. When the connection is up but the stream is refused, the drawer shows the error.
Open a terminal
Opening a terminal needs containerinstance/exec, and kernel/crates/exec on the boundary — see
above. The Terminal button is shown only to people who have containerinstance/exec, and no
reader role includes it.
Choose Terminal. The drawer starts /bin/sh in the pod; an image without /bin/sh cannot be
opened this way. When the pod runs more than one container, Process chooses which one — init
containers are not offered. The session ends when you close the drawer, when the shell exits, or
when your browser loses its connection to the platform. You can have at most five terminal
sessions open at the same time.
Before you use a terminal
A terminal is a shell inside your workload. It sees every file and environment variable the
container sees — vault secrets included — and can change anything the container can change. That
is why containerinstance/exec is a permission of its own.
- Changes made in a terminal last only as long as the container: when it restarts, or its pod is replaced by a save, a re-deploy or a restart, they are gone — except what was written to a persistent volume.
- Terminal sessions are not recorded in the instance's Activity tab, and the commands typed in them are not stored.
Change files on a persistent volume on the Files tab instead, which records every change — see Browse files on a volume.