Cloud

rpk sql debug bundle

Collect a read-only diagnostic bundle from a Redpanda SQL cluster and write it to a ZIP file. Redpanda Support uses the bundle to troubleshoot Redpanda SQL, which runs only on Redpanda Cloud BYOC clusters.

The bundle contains each node’s configuration, logs, crash reports, resource usage, and metrics samples, plus the cluster topology. It also includes active and recent queries, with SQL text masked unless you pass --include-sql-text raw. Collecting it doesn’t change the cluster. If a node can’t be reached, the bundle still includes the data from the other nodes.

Redpanda Support runs this command from inside a Redpanda SQL pod. It connects to the admin API at localhost:9090 by default and discovers the other nodes from there. The --admin-hosts flag sets a different starting endpoint, but the other nodes are still reached at their in-cluster addresses, so collection from outside the cluster is incomplete.

This command was introduced in version v26.2.2.

Usage

rpk sql debug bundle [flags]

Flags

Value Type Description

--admin-hosts

stringSlice

Comma-separated admin API endpoints (host:port) to start from; rpk discovers the other nodes from the first one.

--cpu-profile-seconds

uint

Collect a CPU profile of this duration per node (0 = skip).

--include-sql-text

string

SQL text in query artifacts: masked|raw.

--include-vmstat

bool

Include vmstat in host probes (~1s slower).

--log-since

duration

Collect log lines newer than this (0 = server default window).

--log-size-limit

uint64

Max log bytes per node (0 = server default).

--metrics-interval

duration

Interval between metrics samples.

--metrics-port

uint16

Per-node Prometheus metrics port.

--metrics-samples

int

Number of metrics samples to take per node (at the interval of --metrics-interval). Must be > 0.

-n, --namespace

string

Kubernetes namespace to collect resources from (K8s only; default: the pod’s own namespace).

-o, --output

string

Output ZIP path.

--password

string

HTTP Basic password.

--timeout

duration

Per-RPC timeout.

--tls

bool

Use HTTPS for admin endpoints.

--tls-ca

string

PEM CA bundle for server verification.

--tls-cert

string

Client certificate for mTLS.

--tls-insecure-skip-verify

bool

Skip TLS certificate verification.

--tls-key

string

Client key for mTLS.

--token

string

Bearer token (mutually exclusive with --user/--password).

--upload-url

string

If provided, where to upload the bundle in addition to creating a copy on disk.

--user

string

HTTP Basic username.

Global flags

Value Type Description

--config

string

Redpanda or rpk config file; default search paths are ~/.config/rpk/rpk.yaml, $PWD/redpanda.yaml, and /etc/redpanda/redpanda.yaml.

-X, --config-opt

stringArray

Override rpk configuration settings; -X help for detail or -X list for terser detail.

--ignore-profile

bool

Ignore rpk.yaml and redpanda.yaml; use default settings.

--profile

string

rpk profile to use.

-v, --verbose

bool

Enable verbose logging.