Skip to content

feat(mcp): add k8s_logs — pod container logs for k8s-runtime fleets - #157

Merged
brettchien merged 1 commit into
mainfrom
orca/k8s-pod-logs
Sep 13, 2026
Merged

brettchien merged 1 commit into
mainfrom
orca/k8s-pod-logs

Conversation

@brettchien

Copy link
Copy Markdown
Contributor

Summary

  • deploy_events (ECS control-plane events, archived via EventBridge) has no k8s equivalent — it explicitly refuses k8s-runtime fleets. There's no archival system to build for k8s: the k8s API serves pod logs directly.
  • studio-cp: extracted find_k8s_pods() (deployment lookup + live pod list) out of observe_k8s_deployment so both it and the new fetch_k8s_pod_logs() share the same selector logic instead of duplicating it.
  • fetch_k8s_pod_logs() disambiguates by instance_id (the same pod uid deploy_get/get_agent_states already surface as InstancePhase.id) when more than one pod matches — exactly the shape hit debugging seaturtle's 0.9.0 → 0.10.0-beta.4 image swap, where a crashed pod sat next to its replacement mid-rollout.
  • Supports previous (kubectl logs -p) to read a CrashLoopBackOff pod's last terminated container — its current log is empty post-restart, so this is the only way to see why it died.
  • oab-mcp: new k8s_logs tool. Requires fleet naming a k8s-runtime fleet, same convention deploy_get/deploy_list already use for their k8s dispatch (no bare-cluster k8s path exists for those either).

Context

Found while live-debugging the seaturtle test agent this session (see #155 for the related — but independent — finding that k8s-runtime agents also have zero ACP network exposure; that's about reaching the pod, this is about reading its logs, which works today via the k8s API regardless of that gap).

Test plan

  • cargo check -p studio-cp -p oab-mcp — clean
  • cargo test -p studio-cp -p oab-mcp --lib — hit the same aws-sdk-ec2 test-cfg OOM on this box that PR fix(console): pin Beta channel to a versioned release, default ACP deploys to it #153 already documented and deferred to CI (unrelated to this change; cargo check compiles the same code cleanly). Deferring to CI here too.
  • Manual: k8s_logs against a live k8s-runtime fleet with a crashed pod, both with and without previous

🤖 Generated with Claude Code

deploy_events (ECS control-plane events, archived via EventBridge) has no
k8s equivalent and explicitly refuses k8s-runtime fleets — there's no
archival system to read because the k8s API serves pod logs directly.
Adds a k8s_logs tool built on the kube client k8s_client_for() already
wires (list_k8s_contexts/list_namespaces/fleet_config's k8s dispatch):

- studio-cp: extract find_k8s_pods() (deployment lookup + live pod list)
  out of observe_k8s_deployment so both it and the new fetch_k8s_pod_logs()
  share the same selector logic. fetch_k8s_pod_logs() disambiguates by
  instance_id (the same pod uid deploy_get/get_agent_states already
  surface) when more than one pod matches — the shape hit debugging
  seaturtle's image swap, where a crashed pod sat next to its replacement
  mid-rollout — and supports `previous` (kubectl logs -p) to read a
  CrashLoopBackOff pod's last terminated container, since its current log
  is empty post-restart.
- oab-mcp: new k8s_logs tool, dispatched the same way deploy_get/deploy_list
  require `fleet` for k8s (no bare-cluster k8s path exists for those either).

Test plan:
- cargo check -p studio-cp, -p oab-mcp: clean
- cargo test -p studio-cp/-p oab-mcp --lib: hits the same aws-sdk-ec2
  test-cfg OOM on this box PR #153 already documented and deferred to CI
  (unrelated to this change — cargo check compiles the same code cleanly)

🤖 Generated with Claude Code
@brettchien
brettchien merged commit 8f08ee4 into main Sep 13, 2026
2 checks passed
@brettchien
brettchien deleted the orca/k8s-pod-logs branch September 13, 2026 13:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant