google-cloud-filestore-log-troubleshooting
Diagnoses and resolves Filestore client mount failures on Google Cloud, permission errors (EACCES), and network timeouts (ETIMEDOUT). Use when an NFS mount hangs or fails from a Compute Engine VM, GKE pod, Cloud Run service, or Vertex AI workload, when `mount.nfs` reports "Connection timed out" or "
- 0
- Installs
- —
- Rating
- —
- Success rate
- 7
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 70db1a7484f23d3c… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Filestore Log-Based Troubleshooting
Diagnoses, troubleshoots, and remediates Filestore client mount failures, permission errors (EACCES), and network timeouts (ETIMEDOUT) across projects.
Prerequisites & Quick Start
Required IAM roles on target project(s) (and Shared VPC host project if applicable):
- Read:
roles/file.viewer(instance & export ACLs),roles/compute.networkViewer(VPC firewall rules),roles/logging.viewer(Cloud Audit & GKE CSI logs),roles/mcp.toolUser(if using MCP tools). - Write (Remediation only):
roles/file.editor(export ACL updates),roles/compute.securityAdmin(firewall rule creation).
Authenticate, verify billing/APIs, and configure your environment:
gcloud auth login && gcloud auth application-default login
gcloud billing projects describe {project_id} --format="value(billingEnabled)"
gcloud services enable file.googleapis.com compute.googleapis.com logging.googleapis.com --quiet
gcloud config set project {project_id} && gcloud config set compute/region {region}
Attribution
Prefix every gcloud command provided or executed with the skill metrics environment:
CLOUDSDK_METRICS_ENVIRONMENT="gcs-skills gcs-skills/1.0 (skill:google-cloud-filestore-log-troubleshooting)" \
gcloud filestore instances describe ...
On direct REST API calls, append HTTP header: User-Agent: gcs-skills/1.0 (skill:google-cloud-filestore-log-troubleshooting).
Conceptual & Informational Queries (CRITICAL)
For purely conceptual, architectural, or educational questions (e.g., "What causes EACCES on Filestore?", "Why does GKE Node IP appear instead of Pod IP?", "What ports does Filestore require?", "Explain root squash"):
- Rule: Answer immediately using pre-trained knowledge and the workflow rules below. Answering directly minimizes tool latency and token usage when the user only seeks architectural guidance.
- Constraint: Do not execute external tool calls or API requests for basic knowledge questions.
Handling "No-Command" Constraints (CRITICAL)
If the user prompt contains constraints like "Do not execute commands", "without executing", or "read-only":
- Rule: Strictly avoid calling
run_commandto execute any shell, Python, orgcloudcommands. - Discovery:
- First, check if Filestore MCP tools (
get_instance,list_instances) are available and use them (API calls, not command executions). - If MCP tools are unavailable, read
references/mock-fleet-data.mdonly if the requested instance matches one of the evaluation scenarios (finance-share,shared-nfs,ml-data,data-hub,prod-share). Never report mock data as live production state. If the instance is not listed there, state that live access is required and provide the exact commands for the user to run. - Fast-Path Stop Rule: Once you locate the target instance in
references/mock-fleet-data.md, stop reading additional files immediately and formulate your response. Do NOT readscripts/quick_diagnose.py,scripts/diagnose_lib.py,_internal/quick_diagnose_test.py, orEVAL.*files when command execution is disabled, as inspecting code/test files wastes turns and triggers timeouts. - Explain the required diagnostic steps and output the exact attributed commands for manual execution.
- First, check if Filestore MCP tools (
- Mandatory User Confirmation Requirement: Even when command execution is disabled or the user asks only for recommendations, your response MUST STILL end with a clear question prompting the user for explicit confirmation before applying any remediation (e.g., "Would you like me to proceed with creating the VPC ingress firewall rule
[rule_name]? Please confirm to proceed.").
Multi-Runtime Execution Options
Option 1: Bundled Python CLI Script (Recommended for CLI / Terminal Agents)
# Single instance diagnosis
python3 scripts/quick_diagnose.py --instance="<INSTANCE_ID>" --location="<LOCATION_OR_ZONE>" \
[--project="<PROJECT_ID>"] [--client-ip="<CLIENT_IP>"] [--client-subnet="<CLIENT_SUBNET_CIDR>"]
# Bulk project-wide fleet diagnosis
python3 scripts/quick_diagnose.py --all --project="<PROJECT_ID>" [--json]
| Flag | Purpose |
|---|---|
--instance, --location | Filestore instance ID and region/zone (--zone is a legacy alias). Required unless --all. |
--project | GCP project ID (defaults to active gcloud project). |
--client-ip / --client-subnet | Client IP or CIDR to evaluate against export ACLs and ingress firewall rules. |
--json | Emit machine-readable JSON on stdout (narrative report goes to stderr). |
--apply-fix | Execute generated remediation commands. Only pass after explicit user confirmation. |
Option 2: Filestore MCP Tools / REST API / gcloud CLI
- MCP Tools: Call
get_instance(name='projects/{project_id}/locations/{location}/instances/{instance_id}')and inspectfileShares[0].nfsExportOptionsandnetworks[0].network. - Native REST API (
call_gcp_api): Invokeservice="file",version="v1",resource_path="projects/{project_id}/locations/{location}/instances/{instance_id}". - Standard
gcloud:CLOUDSDK_METRICS_ENVIRONMENT="gcs-skills gcs-skills/1.0 (skill:google-cloud-filestore-log-troubleshooting)" \ gcloud filestore instances describe {instance_id} --location={location} --project={project_id} --format=json
Core Operational Workflow
Step 1: Parameter Extraction & GKE Node Architecture
- Extract
instance,location(region/zone),project, andclient_ip/client_subnet. If target parameters are missing, list instances or ask the user to confirm. - GKE Architecture Rule: PersistentVolumes are mounted by the Linux kernel on the GKE Worker Node, not inside the Pod network namespace. Even if Pod IPs (
10.4.0.0/14) are allowlisted, the NFS server sees traffic originating from the GKE Node Internal IP. Always evaluate and allowlist the GKE Node Subnet CIDR innfsExportOptionsand VPC firewall rules.
Step 2: Instance Metadata & Shared VPC Resolution
- Verify instance
stateisREADY(report state blocker ifCREATING,DELETING, orERROR). - Extract primary Filestore IP (
networks[0].ipAddresses[0]) and VPC network URI. - If
networks[0].networkreferencesprojects/{host_project}/global/networks/{network}, resolve{host_project}as the Shared VPC host project for firewall queries.
Step 3: Export ACL Evaluation (EACCES vs EROFS)
- Inspect
fileShares[0].nfsExportOptions(if empty, default0.0.0.0/0READ_WRITENO_ROOT_SQUASHapplies). EACCES (Permission Denied by Server): Triggered when the client IP or subnet CIDR is not covered by anyipRangesentry.- Remediation: Non-destructively append the client IP/subnet CIDR to
nfsExportOptions, preserving all existing export rules to avoid breaking active mounts.
- Remediation: Non-destructively append the client IP/subnet CIDR to
EROFS (Read-only file system): Triggered whenaccessModeisREAD_ONLYbut client writes are attempted.
Step 4: VPC Ingress Firewall Inspection (ETIMEDOUT)
- Query ingress firewall rules in the VPC network (in the host project if Shared VPC).
ETIMEDOUT (Connection Timed Out): Triggered when priority-sorted ingress rules block or fail to allow TCP port2049(NFS) and TCP/UDP port111(rpcbind) from the client CIDR.- Remediation: Create an ingress firewall rule (
ALLOWtcp:2049,udp:2049,tcp:111,udp:111) from the client subnet CIDR.
- Remediation: Create an ingress firewall rule (
Step 5: Cloud Audit Logs & Configuration Drift Scanning
Query Cloud Audit Admin Activity logs (file.googleapis.com) over the past 24 hours to check if an UpdateInstance operation modified export ACLs or networks:
CLOUDSDK_METRICS_ENVIRONMENT="gcs-skills gcs-skills/1.0 (skill:google-cloud-filestore-log-troubleshooting)" \
gcloud logging read 'logName="projects/{project_id}/logs/cloudaudit.googleapis.com%2Factivity" AND protoPayload.serviceName="file.googleapis.com" AND protoPayload.resourceName=~".*{instance}.*"' \
--project="{project_id}" --freshness="1d" --limit=5 --format="json"
- Scope to Admin Activity: Always include
cloudaudit.googleapis.com%2FactivityinlogNameso read-onlyGetInstance/ListInstancescalls (data_access) are not falsely flagged as administrative drift. - Drift is Informational: Recent
UpdateInstanceevents explain when and by whom (principalEmail,timestamp) configuration changed, but only a failed export ACL or firewall check constitutes a mount blocker. - Single Bulk Query Rule: When scanning multiple instances (
--all), issue a single project-wide audit log query rather than per-instance queries in a loop. - GKE CSI Driver Logs: Optionally inspect
resource.labels.container_name="gcp-filestore-driver"(severity>=ERROR) for client-side mount errors.
Output Format & Mandatory Confirmation Gate
Every diagnostic report MUST include a structured summary table and root cause analysis:
### Filestore Diagnostic Report: `[instance-name]`
| Parameter | Value |
| :--- | :--- |
| **Instance ID** | `[instance-name]` (`[location]`, Tier: `[tier]`, State: `READY`) |
| **Filestore IP & Network** | `[filestore-ip]` on VPC `[network-name]` (Host Project: `[host-project]`) |
| **Port 2049 & Export ACL** | Port 2049: `OPEN / BLOCKED` \| Export ACL: `PASS / REJECTED` |
| **Diagnostic Verdict** | **HEALTHY** or **BLOCKED: [Root Cause]** |
#### Root Cause Analysis & Recommended Remediation
- [Explanation of ETIMEDOUT (missing firewall rule on port 2049) vs EACCES (missing export ACL rule) and any recent UpdateInstance audit drift]
```bash
CLOUDSDK_METRICS_ENVIRONMENT="gcs-skills gcs-skills/1.0 (skill:google-cloud-filestore-log-troubleshooting)" \
gcloud compute firewall-rules create ...
```
Interactive Remediation Confirmation Gate (MANDATORY)
- NEVER execute write or remediation commands without explicit user confirmation.
- Always conclude your response with an explicit confirmation question:
"Would you like me to proceed with executing this remediation command for you? Please confirm to proceed."
References & Bundled Scripts
- Error Signatures & Architecture Matrix
- Cloud Logging & Audit Drift Queries
- VPC Network & Firewall Specification
- Mock Fleet Data for Evaluations
scripts/quick_diagnose.py&scripts/diagnose_lib.py: Zero-dependency CLI runner and pure-Python evaluation engine.
Files
7- SKILL.md
38881f97b111.5 KB - references/error-signatures.md
c370ca66ff9.4 KB - references/logging-and-audit-queries.md
f15f47d5b25.4 KB - references/mock-fleet-data.md
62a92771876.9 KB - references/network-firewall-spec.md
74f12112458.1 KB - scripts/diagnose_lib.py
1d4720a06114.2 KB - scripts/quick_diagnose.py
76eadda43913.4 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from google/skills8
Configures best-practice alerting policies for AI agents using OpenTelemetry (OTel) metrics, generating output as Terraform (.tf) configuration files. Use when analyzing, writing, or deploying alerting policies to monitor agent latency, error rates, token usage, and quality metrics. Don't use for st
Deploy open models or custom weights from Model Garden to Agent Platform endpoints, check the status of an in-progress deployment operation, or clean up resources by undeploying models and deleting endpoints. Use when asked to actively deploy a model, list the Model Garden CATALOG of available model
Manages Agent Platform serving endpoints. Use when you need to create, list, describe, update, or delete serving endpoints for model deployment on Agent Platform. Also use when troubleshooting endpoint permission, quota, or resource busy errors. Don't use for deploying models to endpoints or for run
Measures and improves the quality of AI models and agents on Google Cloud using the Eval Quality Flywheel methodology. Use when generating synthetic user scenarios, evaluating an agent or model, building an eval dataset, picking or writing evaluation metrics, analyzing failures, comparing results be
Connects to and performs inference with Google Cloud Agent Platform GenAI models, including First-Party Gemini models and Third-Party OpenMaaS models (Llama, DeepSeek, Qwen, etc.). Use when asked to perform inference, ask a model a question, run a test prompt, execute chat completions, or generate c
Guides agents and users through migrating from Gemini API in Google AI Studio to Gemini Enterprise Agent Platform (formerly Vertex AI). Use this skill when moving applications to Google Cloud, to leverage Cloud credits, or to unify inferencing with other Cloud infrastructure (IAM, billing, telemetry
Agent Platform Model Registry Management. Use when you need to upload, list, describe, update, or delete machine learning models (and their versions) in the Agent Platform Model Registry. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform models.
Manages and orchestrates prompts in Agent Platform. Use when you need to create, list, retrieve, version, or delete managed prompts in Agent Platform. Don't use for model training, model deployment to endpoints, or managing non-Agent Platform prompts.
Related ai-ml skillsscan passed
为 OpenClaw AI Agent 锻造完整的龙虾灵魂方案。根据用户偏好或随机抽卡, 输出身份定位、灵魂描述(SOUL.md)、角色化底线规则、名字和头像生图提示词。 如当前环境提供已审核的生图 skill,可自动生成统一风格头像图片。 当用户需要创建、设计或定制 OpenClaw 龙虾灵魂时使用。 不适用于:微调已有 SOUL.md、非 OpenClaw 平台的角色设计、纯工具型无性格 Agent。 触发词:龙虾灵魂、虾魂、OpenClaw 灵魂、养虾灵魂、龙虾角色、龙虾定位、 龙虾剧本杀角色、龙虾游戏角色、龙虾 NPC、龙虾性格、龙虾背景故事、 lobster soul、lobster
Pair a remote AI agent with your browser. (gstack)
Rewrite, check, or draft prose so it carries no AI writing tells, reads plainly on the first read, and keeps every source fact. Use when asked to make writing plainer or free of those tells, to check writing for them, or when drafting from supplied content. Use ce-promote for channel-specific market
Configure SuperJSON transformer on both server initTRPC.create({ transformer: superjson }) and every client terminating link (httpBatchLink, httpLink, wsLink, httpSubscriptionLink) to support Date, Map, Set, BigInt over the wire. Transformer must match on both sides. In v11, transformer goes on indi
Connects AI agents to remote Windows desktop applications on Amazon WorkSpaces Applications (AppStream 2.0) through the managed Agent Access MCP server, and guides reliable desktop automation. Covers connecting an agent to the MCP endpoint (SigV4, streaming URL, and Active Directory SAML/Domain Join
Validates the user's environment for SageMaker AI operations — checks SDK version, AWS region, and execution role. Use when the user says "set up", "getting started", "check my environment", "configure SDK", or as the first step in any plan involving SageMaker/Bedrock training, evaluation, or deploy